GOALDEN — Privacy Policy

Effective: 17 June 2026

GOALDEN turns your selfie into an AI-generated football trading card. We built it to be private by design: your photo is used to create your card and is never stored on our servers. This policy explains exactly what we process, who is involved, and the choices and rights you have.

GOALDEN is operated by SerryPlay / Serge Spijkstra ("SerryPlay", "we", "us", "our"), based in Amsterdam, the Netherlands. This policy applies specifically to the GOALDEN app. By using GOALDEN, you agree to the processing described here.

The short version

Your photo (selfie)

When you create a card, your selfie is handled as follows:

A note on biometric data: your selfie contains your face. We process it solely to generate your card, do not store it, and do not use it to identify you, build a face database, or for any purpose other than creating the card you requested.

AI generation (xAI / Grok)

To create your card, your processed selfie is sent to xAI (the "Grok" image service). xAI receives the resized, metadata-stripped image, generates the card artwork, and returns it to us. We then store only the generated artwork (see above) — we receive no copy of your original photo back, and we do not log the image.

xAI's handling and retention of the image it receives is governed by xAI's own privacy policy and terms, not by us. We have configured our xAI access with event logging turned off as our processing choice; however, we cannot make guarantees on xAI's behalf about their internal retention. If this matters to you, please review xAI's policy before creating a card.

Face data and your photo

To create your card, GOALDEN asks you to upload a single photo of your own face (a "selfie"). This photo is face data, and we handle it as sensitive information. This section explains exactly what we do with it.

What we collect. We collect the photo you choose to upload, for the sole purpose of generating your stylized football card. We do not create, derive, or store any biometric template, faceprint, face-geometry map, or facial-recognition data from your photo. We do not use your photo to identify, authenticate, track, or recognize you, and we do not use it for advertising or to train any model.

How it is used. When you tap to create a card, your photo is sent — in-flight only — from the app to our generation service and on to our AI image provider, xAI (the company behind Grok), which produces the stylized artwork. We then store only that generated artwork. We do not receive a copy of your original photo back, and we do not log or save the photo on our servers at any point.

Who it is shared with. Your photo is transmitted to xAI solely to generate your card. It is shared with no other third party. xAI's handling and retention of the image it receives is governed by xAI's own privacy policy and terms. We have configured our xAI access with event logging turned off as our processing choice; however, we cannot make guarantees on xAI's behalf about their internal retention. We do not enroll your photo in any data-sharing or model-training program.

Where it is stored and how long it is retained. Your photo is never written to persistent storage — not on your device's server account, not in our database, and not in our file storage. It exists only in memory for the few seconds it takes to generate your card, and is then discarded. The only thing retained is the generated card artwork, which lives in your account until you delete the card or your account.

If you upload a photo that is not of yourself, or you wish to have a generated card removed, you can delete any card from within the app, and you can delete your entire account (which removes all cards, images, credit history, and share pages) from the app's settings.

What we store

DataWhy
The generated card image (AI artwork of your face)So your card appears in your gallery. Stored privately; accessible only via short-lived secure links.
Card details: the name you type, chosen country, style, rating, edition, serialTo display and identify your card. The name is one you enter yourself (up to 24 characters); it becomes visible to others only if you choose to share that card.
A shared card imageCreated only if you tap "share". This is the finished card you chose to share — not your selfie. It is publicly accessible via the share link until you delete the card.
Your credit balance and historyTo run the in-app credit system (free welcome credits, purchases, rewarded-ad credits).
An anonymized device fingerprint (a salted, irreversible hash)To prevent abuse of the free welcome-credit offer. Your raw device identifier is never stored — only a one-way hash that cannot identify you.

Your account is anonymous: we do not collect or store your name (beyond the card name you type), email address, phone number, or any real-world identity.

Advertising and tracking

GOALDEN is free and supported in part by ads (rewarded video you choose to watch, and occasional full-screen ads). Ads are provided by Google AdMob.

You can change your choice anytime: iOS → Settings → Privacy & Security → Tracking.

Purchases

Credit packs are sold as in-app purchases. Payment is processed by Apple through the App Store — we never see your payment-card details. We use RevenueCat to validate purchases; RevenueCat receives your anonymous account identifier and the transaction details, not your name or email.

Because your account is anonymous and credit packs are consumable, credits are tied to your installation. If you delete and reinstall the app or switch devices, unused credits cannot be transferred or recovered automatically. If you lose paid credits this way, contact us at the address below and we'll help.

Third parties that process your data

ProviderRole
SupabaseOur backend, database, storage, and anonymous authentication.
xAI (Grok)Generates your card from your processed selfie.
Google AdMobServes ads.
RevenueCatValidates in-app purchases.
Apple (App Store / DeviceCheck)Processes payments; provides the anti-abuse device check.

GOALDEN does not use Firebase, Crashlytics, Unity, or any analytics or crash-reporting SDK. We do not run third-party analytics or behavioral tracking inside the app.

Anti-abuse

To stop abuse of the free welcome-credit offer (for example, repeatedly reinstalling to claim free credits), we use Apple's DeviceCheck and, as a fallback, a salted one-way hash of your device's vendor identifier. The raw identifier is never stored — only the irreversible hash, used solely for fraud prevention. This is first-party anti-abuse, not cross-app tracking.

Deleting your account and data

You can delete your account and data at any time from inside the app (Credits tab → "Delete account & data"). This permanently removes your cards, card images, any shared images, and your credit history.

For abuse-prevention reasons, we retain one anonymized, irreversible device fingerprint (a salted hash) after deletion. It is unlinked from your deleted account, is not reversible to a person, and exists only to prevent re-claiming the free welcome credits. It cannot identify you.

Children

GOALDEN is intended for a general audience and is not directed at children under 13 (or the minimum age in your country). We do not knowingly collect data from children under that age. If you believe a child has used the app and provided data, contact us and we will delete it.

Your rights (GDPR)

If you are in the EU/EEA (or a region with similar laws), you have the right to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. The fastest way to exercise deletion is the in-app "Delete account & data" feature; for any other request, contact us below. You also have the right to lodge a complaint with your local data protection authority (in the Netherlands, the Autoriteit Persoonsgegevens).

Our legal basis for processing is your consent (for ads/tracking where required) and the performance of the service you request (generating and storing the cards you create).

Data retention

We keep your cards and credit history for as long as your account exists. When you delete your account, this data is removed as described above. Your selfie is never retained at all. The anonymized anti-abuse hash is retained as described above.

International transfers

Some of our providers (for example xAI, Google, Apple, RevenueCat) may process data on servers outside your country, including outside the EU/EEA. Where required, these transfers rely on appropriate safeguards under applicable data-protection law.

Security

We use reasonable technical and organizational measures to protect your data, including encrypted connections and private storage with access via short-lived secure links. No method of transmission or storage is ever completely secure, but we design GOALDEN to hold as little personal data as possible.

Changes to this policy

We may update this policy. The "Effective" date above shows the latest revision. Significant changes will be reflected here; continued use after an update means you accept the revised policy.

Contact

Questions about this policy or your data in GOALDEN: