Privacy Policy
Last updated: 5 August 2026
🛡️ In short: the desktop app processes your replays entirely on your own PC. The web app analyses uploaded replays on our server — the replay file itself is not retained, but the result of the analysis is stored. Analytics run only with your consent.
This privacy policy is a translation of the German original. In case of discrepancies, the German version shall prevail.
1. Data Controller
Mick Gottschalk
An der Hermannshöhe 7
58640 Iserlohn, Germany
Email: mick.gottsch@gmail.com
2. Data We Collect
2.1 Desktop App (Fortiq)
The desktop app processes all data exclusively on your local PC:
- Match analyses and replay data
- Performance scores and statistics
- Biometric data (opt-in only; not stored persistently)
- Chat history with the coaching assistant
This data is not transmitted to any server.
2.2 Web App & Website
When you visit our website, we collect:
- Landing page: no analytics. The landing page and the info pages embed no third-party service — no analytics, no fonts from foreign servers, no CDN. Simply opening them does not make your browser leave our own delivery.
- Analytics (PostHog, Web App): Only with your explicit consent via the consent banner. Autocapture and session recording are disabled, your IP address is suppressed on capture, and the EU region is used. You can revoke your consent at any time. Without consent PostHog is neither loaded nor contacted.
- Error reports (Sentry): If the web app or the backend crashes, we send a technical error report to Sentry: error message, stack trace, the kind of page you were on (the route pattern, e.g.
/matches/:id— never the concrete address), program version, and a correlation ID.
What is not included: no IP address, no user identifier, no session replay, no recording of your clicks or input, no browser identifier (User-Agent), no address bar and no parameters from it. As long as nothing crashes, Sentry is not contacted at all — merely loading a page triggers no transmission. Sentry stores nothing on your device: no cookie, no entry in your browser's storage.
The backend is configured withsend_default_pii=falseand therefore sends no user data. Legal basis is our legitimate interest in a working application (Art. 6(1)(f) GDPR); because nothing is stored on or read from your device, no consent under § 25 TDDDG is required for it. You may object to this processing under Art. 21 GDPR. - Account Creation: Email, username, hashed password
2.3 Backend Services
Once you register an account and use the web app, we store on our server:
- Account data: email, username, password hash (bcrypt), and optionally display name, bio, avatar URL, Epic ID, Fortnite name and time zone, plus your tier status
- Match results: match ID, playlist, duration, placement, kills, assists, damage, and the scores derived from them
- Match detail: where your analysis provides it, we additionally store position tracks, fight locations, weapon identifiers and information about your team-mates in a match. This is raw data, not merely aggregates.
- Usage telemetry: event type, a pseudonymous session hash, app version and an operating-system identifier. Any properties sent along are filtered server-side against a fixed allow-list — anything not on that list is discarded and never stored. Free text is not on the list.
- Feedback and NPS ratings
- Chat ratings: if you rate a coach answer with thumbs up or down, we store your question in full, an excerpt of the answer, and your comment. This rating is stored without a link to your account.
- Consent records (category, timestamp, version) as evidence
2.4 Uploaded replay files
When you upload a .replay file in the web app, it is transferred to our server for analysis (50 MB maximum). The file is processed in memory only and is not stored persistently; it is discarded once the analysis completes. Only the result is stored (see 2.3).
Other players' data: a Fortnite replay inherently also contains information about your team-mates and opponents, such as their player names. These people have not consented to the processing. We evaluate this information solely to analyse your play, do not pass it on, and do not use it to build profiles about those people. Affected persons may object at the address given in section 1.
2.5 AI coach
When you ask the coach a question, your input is passed to a language model together with the context of your match. Depending on the deployment this happens on our own infrastructure (a local model) or — when no local model is reachable — at an external AI provider (OpenAI — contracting entity OpenAI Ireland Ltd., processing also in the USA — or Anthropic PBC, USA). In that case your question leaves the EU. Please do not enter anything into the coach chat that you would not want transferred to a US provider. We do not store the conversation on our server (exception: the chat rating in 2.3).
2.6 Stats pre-fill during onboarding
If you supply your Epic name during onboarding, we use it to request publicly available Fortnite statistics from fortnite-api.com in order to pre-fill your dashboard. Only the player name you entered and the platform are transmitted.
3. Legal Basis
- Art. 6(1)(b) GDPR (performance of contract) for the account, match analysis, coach and billing
- Art. 6(1)(a) GDPR (consent) for PostHog analytics and local storage of the chat history
- Art. 6(1)(f) GDPR (legitimate interest) for error reports, abuse prevention and IT security
- Art. 6(1)(c) GDPR (legal obligation) for tax retention duties
4. Recipients and processors
We do not sell your data and do not pass it on for purposes of our own choosing. We use the following service providers to operate the product:
- Vercel Inc. (web app hosting) — servers in EU/US
- Render Services, Inc. (API hosting) — instance in the Frankfurt region; under the data processing agreement processing also takes place in the US
- Databricks, Inc. (Neon) (database hosting) — holds account, match and consent data. Servers in US
- PostHog, Inc. (product analytics) — EU region, only with consent, autocapture and session recording disabled
- Functional Software, Inc. (Sentry) (error reports) — only in case of an error, scope as described in section 2.2
- Brevo (Sendinblue) (email delivery) — receives your email address and the content of the message (verification, password reset). Privacy Policy
- Lemon Squeezy (Sold through Link, LLC) (payment processing, merchant of record) — paid tiers only. Your email address is passed at checkout; we neither collect nor process payment details ourselves.
- OpenAI Ireland Ltd. or Anthropic PBC (the coach's language model) — see section 2.5
- fortnite-api.com (public game statistics) — see section 2.6
4.1 Transfers to third countries
Some of these providers are based in, or process data in, the United States. This constitutes a transfer to a third country within the meaning of Art. 44 et seq. GDPR.
The basis differs by recipient:
- Adequacy decision (Art. 45 GDPR): Vercel Inc., Render Services, Inc., Functional Software, Inc. (Sentry) and Databricks, Inc. with Neon, LLC as a covered entity are certified under the EU-US Data Privacy Framework. For them the European Commission's decision of 10 July 2023 carries the transfer.
- Standard Contractual Clauses (Art. 46(2)(c) GDPR, Implementing Decision (EU) 2021/914): OpenAI, Anthropic PBC and Lemon Squeezy are not certified. Their data processing terms incorporate the Standard Contractual Clauses, which are the basis of the transfer.
We last checked the certification status on 28 August 2026 against the public list at dataprivacyframework.gov. A certification can lapse or be withdrawn; if that happens, the Standard Contractual Clauses apply to the recipient concerned and we update this section.
4a. Retention
- Account, match and consent data: until you delete your account. Deleting the account removes them immediately and completely.
- Uploaded replay files: for the duration of the analysis only, then discarded.
- Usage telemetry: events linked to an account are deleted with the account. Events without an account link cannot be attributed to a person and remain in the analysis.
- Chat ratings: stored without an account link and therefore not covered by account deletion.
- Invoicing and accounting data: statutory retention periods remain unaffected.
For events without an account link, expired sign-in tokens and accounts that have gone unused for a longer period, no automatic deletion runs at present. That data stays until you delete your account or ask us to delete it. We will state a period here once it actually runs — not while it is merely planned.
5. Your Rights
You have the right to:
- Access your stored data
- Rectification of inaccurate data
- Erasure of your data (“right to be forgotten”)
- Restriction of processing
- Data portability
- Object to processing
- Withdraw a consent you have given, with effect for the future (Art. 7(3) GDPR)
- Lodge a complaint with a data protection supervisory authority (Art. 77 GDPR)
Contact us by email for all requests: mick.gottsch@gmail.com
5.1 Competent supervisory authority
The authority at the controller's place of establishment is competent:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen
Kavalleriestraße 2–4, 40213 Düsseldorf, Germany
Postfach 20 04 44, 40102 Düsseldorf, Germany
Phone: +49 211 38424-0
Email: poststelle@ldi.nrw.de
Under Art. 77(1) GDPR you may instead contact the supervisory authority of your place of residence or of your workplace.
5.2 Self-Service (Deletion & Data Export)
- Account Deletion: You can delete your account and all associated data (profile, sessions, subscription) at any time via your account settings. Deletion is immediate and irreversible. Statutory retention periods (e.g. invoicing data) remain unaffected.
- Data Export: You can export the data stored about you as a JSON file via your account settings (Art. 15, 20 GDPR). The export includes your profile data, match results, licence, consent and subscription information — but no passwords and no security-related fields. If the scope of the self-service export is not sufficient for you, request full access informally by email; we will provide it within the statutory deadline.
The coach's chat history is stored only locally in your browser and is therefore not part of the server export. You can clear it under Settings → Privacy.
6. Local Storage & Cookies
Our website and web app use localStorage and in-memory state for technically necessary functions:
- Language preference (
coach_language) - Consent decision per category (
fortiq_analytics_consent,fortiq_consent_marketing,fortiq_consent_functional) - Chat history (stored locally, only where functional consent has been given)
- UI preferences and session state (not persistent, in-memory only)
These entries are not transmitted to our servers and can be deleted at any time via your browser settings. If you consent to analytics, PostHog additionally writes its own entry (ph_…_posthog) to localStorage and sessionStorage; it disappears when you withdraw consent and clear your browser data. Sentry stores nothing — no cookie, no localStorage or sessionStorage entry.
For sign-in we set two technically necessary cookies:
fortiq_refresh_token— HttpOnly and Secure, manages your login session, cannot be read by JavaScript, and is cleared on logout.fortiq_has_session— holds only the value1and is deliberately not HttpOnly, because the app has to read it to know whether a session can be restored. It contains no identifier and no token.
No authentication tokens are stored in localStorage.
7. Data Security
We use SSL/TLS encryption for all data transfers. Passwords are hashed with bcrypt. JWT tokens have a limited validity period.
8. B2B Data Export API
For users on the Pro or Team tier, we offer an optional B2B export API:
- Activation: Only via explicit API key request (opt-in)
- Exported data: match summaries, aggregated performance statistics, and on request the full timeline of an individual match
- Scoped to your own account: an API key returns only matches belonging to the account it was issued for. Other users' data cannot be retrieved through this interface.
- Authentication: Access only with a valid API key (revocable)
- Legal basis: Art. 6(1)(b) GDPR (performance of contract) or Art. 6(1)(a) GDPR (consent)
9. Language Note
This privacy policy is a translation of the German original. In case of discrepancies between the translated version and the German version, the German version shall prevail.
10. Changes to This Policy
We reserve the right to update this privacy policy as needed. The current version is always available on this page.