Privacy Policy
Last updated · May 25, 2026
1. The short version
GTA Companion is an unofficial fan companion app for Grand Theft Auto Online. We collect as little personal data as possible, and we never sell it.
You can use the entire app anonymously without an account. If you create one, the only required personal data is your email address.
This policy explains, in detail, what we collect, why, on what legal basis, who we share it with, how long we keep it, and what rights you have. It is written to comply with the EU General Data Protection Regulation (GDPR), the Dutch Implementation Act (Uitvoeringswet AVG), and Apple's App Store privacy requirements.
2. Who we are (the controller)
GTA Companion is operated by an individual developer based in the Netherlands. The "controller" of your personal data — the party that decides how and why it is processed — can be reached at:
Email: privacy@gtacompanion.com
We do not currently meet the threshold that requires appointing a Data Protection Officer under GDPR Art 37. For any privacy question, rights request, or complaint, write to the email above and we will respond within 30 days.
3. What we collect, why, and on what legal basis
Under GDPR Art 13(1)(c), every category of data we process is listed below together with its purpose, legal basis, and retention period.
3.1 Account data
What: email address, password (stored only as a salted hash by Supabase Auth — we never see the plaintext), the OAuth provider you used (Google, if you sign in that way), and the unique user ID Supabase issues to your account.
Why: to register and authenticate you, to let you sync preferences across devices, and to email you transactional messages such as verification codes and password-reset codes.
Legal basis: performance of our contract with you under GDPR Art 6(1)(b) (the contract being these Terms of Service together with this policy).
Retention: for as long as your account exists. When you ask us to delete the account, identifiers are anonymized immediately and the anonymization propagates to backups within 30 days.
3.2 Server logs
What: request timestamp, IP address, HTTP method and path, response status, user-agent string. No request bodies. No URL query parameters that could contain credentials.
Why: rate-limiting, abuse prevention, and operational troubleshooting.
Legal basis: our legitimate interest under GDPR Art 6(1)(f) in keeping the service secure and available, balanced against your right to privacy.
Retention: 30 days, after which logs are permanently deleted.
3.3 Product analytics
What: counters of which screens were viewed and which features were used. Before you sign in, events are tied only to a random per-install identifier. After you sign in, events are tied to your Supabase user ID and email so we can locate and delete your events when you ask. No IP address, no advertising identifiers, no third-party trackers.
Processor: PostHog, EU region (eu.i.posthog.com).
Why: to understand which features are useful and which are not.
Legal basis: your explicit consent under GDPR Art 6(1)(a). On first launch you'll see a consent screen with three options: Accept all, Decline (essentials only), or Customize. You can change your mind any time in Settings → Manage Permissions; opt-out takes effect immediately and your existing PostHog identity is reset on the device.
Retention: 12 months.
3.4 Push notification tokens (only if you opt in)
What: the opaque APNs / FCM device token that lets us send a notification to your device.
Why: to deliver the alerts you signed up for (sales, daily resets).
Legal basis: consent (Art 6(1)(a)). Disabled by default. Revoke at any time in your device's notification settings or in Settings → Manage Permissions.
Retention: until you revoke or the token is invalidated by the OS.
4. What we do not collect
We do not collect your precise location, contacts, photos, microphone audio, camera input, health data, financial data, or any biometric identifiers. We do not access your Rockstar / Social Club account. We do not use the device's advertising identifier (IDFA / Android Ad ID). We do not embed third-party advertising or marketing trackers.
5. Recipients (who we share data with)
We share your personal data only with the processors below, each bound by a Data Processing Agreement that mirrors the obligations of GDPR Art 28:
Supabase Inc. — managed Postgres database, authentication, and Edge Functions hosting. Region: EU (Ireland, eu-west-1). Used for: storing your account data, authenticating sign-ins, running the news pipeline.
Upstash Inc. — managed Redis used for rate-limiting. Region: EU. Used for: short-lived counters keyed on hashed IP addresses (no email or other account data).
Resend — transactional email delivery for verification codes and password resets. Region: EU (Ireland, eu-west-1). The email subject, body, and your address are processed solely for delivery and not for marketing.
Apple Push Notification Service / Google Firebase Cloud Messaging — only if you have enabled push notifications. We send the token plus the message contents to APNs/FCM, which delivers it to your device.
We do not sell, rent, or otherwise commercially share personal data with third parties. Where law enforcement or a court orders disclosure under valid legal process, we will comply only to the extent strictly required and will notify you unless legally prohibited.
6. International transfers
We default to EU-region hosting at Supabase. If a processor moves data outside the EEA (for example, APNs / FCM may route through US infrastructure), the transfer is covered by the European Commission's Standard Contractual Clauses (2021/914) or the EU-US Data Privacy Framework, depending on the recipient. You can request a copy of the relevant safeguards by emailing privacy@gtacompanion.com.
7. How long we keep your data
See section 3 for category-by-category retention. In summary: account data lives as long as your account does and is removed within 30 days of deletion; logs live for 30 days; aggregated analytics for 12 months; consent records (proving you opted in to optional processing) for 3 years after withdrawal.
8. Your rights
Under GDPR Articles 15–22 you have the right to:
Access (Art 15): ask for a copy of all personal data we hold about you. Use Settings → Data & Privacy → "Download my data" or email us.
Rectification (Art 16): correct inaccurate data. Most fields are editable directly in Settings; for anything else, email us.
Erasure (Art 17): have your personal data removed. We satisfy this right by irreversibly anonymizing your account rather than deleting the row outright — your email, password hash, linked OAuth providers, and optional profile fields are wiped, and what remains contains nothing that identifies you (GDPR Recital 26). Settings → Data & Privacy → Delete Account.
Restriction (Art 18) and Objection (Art 21): ask us to pause or stop processing based on legitimate interest. Email us.
Portability (Art 20): receive your data in a structured, machine-readable JSON format and have it transmitted to another controller.
Withdraw consent (Art 7(3)): for any processing based on consent (analytics, push, optional profile fields). Withdrawal does not affect lawful processing that already happened.
Lodge a complaint (Art 77): with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens). https://autoriteitpersoonsgegevens.nl
We respond to rights requests within 30 days, free of charge for the first request per year (GDPR Art 12(5)). To exercise any right, write to privacy@gtacompanion.com with enough information to identify you (typically your account email).
9. Children
The Service is intended for general audiences. Grand Theft Auto Online itself carries an age rating (PEGI 18 / ESRB Mature) and we expect the same of our users. We do not knowingly collect personal data from children under 16, and we do not target the Service at them. If you become aware that a child has provided us with personal data, please contact privacy@gtacompanion.com and we will promptly delete the account and any associated data.
10. Cookies and similar technologies
The mobile app does not set browser cookies. We do store a small amount of information on your device so the app can function and remember your preferences between launches. The exhaustive list:
Strictly necessary — used to provide a service you have explicitly requested. No consent required (Dutch Telecommunications Act Art 11.7a(3)(b)):
- Supabase session token — kept in the device's secure storage (Keychain on iOS, EncryptedSharedPreferences on Android) so you stay signed in.
- Onboarding state (intro seen, welcome flow completed) so we don't re-prompt you on every launch.
- Push permission flag — remembers whether we have already asked you for notification permission, so we don't ask again.
- Last error reference — the most recent server-error request id and the path it failed on, kept locally so the bug-report screen can attach it automatically. Cleared after each successful report.
- App preferences — your chosen units (mph / kph) and similar UI toggles.
Consent record — the version of this policy you accepted and whether you opted into analytics. Stored locally so we don't re-prompt and so analytics can be paused immediately if you withdraw. Required by GDPR Art 7(1) (proof of consent).
Optional, only with your consent:
- PostHog distinct id — a random per-install identifier used by the analytics SDK while the analytics toggle is on. Cleared on opt-out.
- Push notification token — the opaque APNs / FCM token described in §3.4, only present if you enabled notifications.
Nothing here is shared with third parties for advertising. There are no cross-site trackers, no ad SDKs, and no fingerprinting. You can wipe everything in this list at any time by deleting the app, signing out, or — for the analytics-related items only — toggling analytics off in Settings.
11. Security
All traffic between the app and our servers uses TLS 1.2+. Passwords are hashed with bcrypt (handled by Supabase). API access requires a shared secret plus a valid Supabase JWT for authenticated endpoints. Database access is restricted by Row-Level Security policies. We will notify affected users and the Dutch DPA within 72 hours of becoming aware of any personal-data breach that is likely to result in a risk to your rights and freedoms (GDPR Art 33–34).
12. Automated decision-making
We do not make decisions about you that produce legal or similarly significant effects based solely on automated processing (GDPR Art 22).
13. Changes to this policy
Material changes will be highlighted in-app on next launch and the "last updated" date at the top will move forward. Non-material changes (typo fixes, link updates) we may make without notice. Continuing to use the app after a material change constitutes acceptance of the revised policy.
14. Contact
Privacy questions, rights requests, or complaints: privacy@gtacompanion.com.
Anything else: Settings → Report a bug or Settings → Leave a Review.
GTA Companion is an unofficial, fan-made companion app and is not affiliated with, endorsed by, or sponsored by Rockstar Games, Take-Two Interactive, or any of their affiliates. All Grand Theft Auto trademarks and copyrights are property of their respective owners.
GTA