← 8nOut

Privacy Policy

Version 3.40 · Last updated 6 October 2026

Plain-language summary (not a substitute for the full text below): 8nOut is a map-based app for the One Pocket pool community, worldwide. We store only what the app needs to work. We do not run ads. The 8nOut apps, including the web app, use no third-party analytics; our public website uses Google Analytics to count visits only if you accept it in its cookie banner. We never sell or rent your personal data. Your home-table address stays private and is revealed only to a specific connection you accept, on a grant you can revoke. You can delete your account and everything in it from inside the app, or ask us to by email (a short-lived encrypted backup is the one exception — section 10 explains it).

1. Who we are (the controller)

The "data controller" for your personal data is:

8nOut is operated by a sole proprietor, not a large platform. We are not required to appoint a Data Protection Officer, and we have not appointed one, because our processing does not meet the thresholds in Article 37 GDPR. You can always reach a real person at the contact above.

Because we are established in the Netherlands, your data is handled under the EU General Data Protection Regulation (GDPR) and the Dutch GDPR Implementation Act (Uitvoeringswet AVG, "UAVG"), under the supervision of the Dutch Data Protection Authority (Autoriteit Persoonsgegevens, "AP").

2. Scope

This policy covers the 8nOut iOS app, the 8nOut Android app, the 8nOut web app / PWA (currently 8nout.pages.dev, later 8nout.com), and the public 8nOut website, together "the Service".

It does not cover CueScore, Apple, Google, or any other third-party service you may reach from 8nOut. Those services have their own privacy policies and are independent controllers of the data you give them directly (see section 7).

3. What we collect, why, and our legal basis

We only collect data you give us or that the app needs to function. We collect device GPS location in a small, named set of places, each described below — composing a Shout-out and placing your home table using "use my current location" — and nowhere else in the app. We do not collect advertising identifiers, and the 8nOut apps (iPhone, Android and the web app) collect no analytics. The one exception is statistics about visits to our public website pages, and only if you accept them — see "Website statistics (Google Analytics)" below and section 8.

DataWhat it isWhy we process itLegal basis (GDPR Art. 6)
Account identifiersYour account ID (a UUID), the email address from Sign in with Apple (which may be Apple's private-relay address) or GoogleTo create and secure your account and sign you inArt. 6(1)(b) — performance of the contract (our Terms of Service)
ProfileDisplay name (set at signup; may later be set from your first and last name — see "First and last name" below), optional home town / country, optional bio, optional avatar photo, optional self-reported Fargo Rating, optional linked CueScore player ID. Your profile link code: a permanent 8-character code that makes up your public profile link (8nout.com/p/…)To show your profile to other players in the app, and to anyone who opens your public profile link, whether or not they have an 8nOut account, so people can recognise and find you. Anyone who has your link can open it. It only reaches people you share it with, or who are passed it on: we never show your code to other members, and search engines are always told not to list the code link. If you're under 18, or haven't told us your age group, your link opens only for signed-in 8nOut members. If your link has reached someone it shouldn't, contact us at privacy@8nout.com and we'll issue a new one; the old link stops workingArt. 6(1)(b) — contract
Public profile name and search enginesOnly if you claim a profile name for your link, and only if you've told us you're 18 or over. Your profile name (the part after 8nout.com/p/); a record of each claim or change: the name, which version of the Public Profile Name Terms you accepted, when, and on which app; whether "Let search engines find my profile" is on; and, after you change or remove a name, a hold that stops anyone claiming it for a while, kept only as a scrambled one-way code of the name (a keyed hash), never the name itself and never linked to youTo give you an easy-to-share address for your profile, and, while your switch is on, to let search engines list it. At that address anyone can see: your display name (exactly as it shows in the app, which may be your real first and last name), photo, town / country, bio, Ready to play, win–loss record, self-reported Fargo Rating, your CueScore link and your clubs. Anyone who types the address can open it, even with search engines switched off. While the switch is on, search engines can list the page, and we include the address in a public sitemap with only the date you last claimed, changed or switched on listing, never your activity. Claiming a name switches listing on; you can switch it off at any time. Search engines decide for themselves how they handle their own index: after you switch off or remove the name, listings can take days to weeks to drop, and copies others have made are outside our control. You can remove the name at any time with "Remove my profile name" on your profile: the address stops working at once, and your code link keeps working. We can also remove a name that breaks the rules, and we tell you why. How long we keep each part: section 10Art. 6(1)(b) — contract: a service you ask for when you claim a name and accept the Public Profile Name Terms. Checked every time the page is opened: if you're no longer shown as 18 or over, the page stops opening and drops out of search listings and our sitemap
Dominant hand and pocket preferenceYour optional, self-reported dominant hand (left, right, or ambidextrous) and preferred pocket (left or right). You can set, change, or clear either at any timeReal gameplay facts for One Pocket, not general personalisation. We keep them for your own record, and to show back to you on your profile — never shown to another player by name, and not included on your public profile share link. These two fields may also contribute to a separate, suppressed, non-identifying community-wide statistic — for example, whether players with a particular dominant hand tend to win more often from a particular pocket choice — shown only as a rounded, group-level number that can never be traced back to any one player. Any visibility beyond that suppressed aggregate — for example, showing your own hand or pocket choice to another player individually — remains a separate decision that would need its own update to this policy first. You can set, change, or clear either field at any time, whether or not it has ever contributed to that statisticArt. 6(1)(b) — contract, for keeping your own record and showing it back to you. Art. 6(1)(f) — legitimate interest, for the suppressed, non-identifying community-wide statistic described alongside
Play locations — clubsThe pool clubs you say you frequent. Shown on the map at the club's own address — a pool club is a public business, so there is no private location to obscure. Never your home addressTo let players discover each other by clubArt. 6(1)(b) — contract
Play locations — home tableWhether you have a home table, its name if you give it one, its precise address/coordinates, and the approximate point we show on the map instead of the address. Also whether you have made it visible to all membersTo let you optionally host games. By default, only you and your accepted connections see that you have a home table, as an approximate point, never the address. If you are 18 or older, you can choose to make a home table visible to all members instead (see section 4). The precise address is private either way, and is shared only via a grant you control (see section 5)Art. 6(1)(b) — contract, for your home table and for showing it to your connections. Art. 6(1)(a) — consent, for showing it to all members: you give it by turning on "Visible to all members", and you can withdraw it at any time by turning that off (see section 4)
Contact infoOptional phone numberShown only to players you have accepted as connections, so you can arrange a gameArt. 6(1)(b) — contract
Social graphConnection requests, personal invite links, and game invitations ("challenges")To operate the connect-first social featuresArt. 6(1)(b) — contract
Messages (chat)The text messages you exchange one-to-one with a connection you have accepted, and the system cards a challenge writes into that chat. Text only — no photos, no attachmentsTo deliver your messages and show both of you your own conversation, so you can talk and arrange gamesArt. 6(1)(b) — contract, for delivering messages and your own chat history; Art. 6(1)(f) — legitimate interest (community safety), for the fixed 60-day retention, for keeping a reported or deleted message reviewable (see section 5), and for a moderator's report-gated read (see "Moderator access")
Device location (Shout-out only)A one-time, reduced-accuracy read of your device's current position — city-level, never street-level — taken only when you tap "use my current location" while composing a Shout-out. On iPhone it is resolved to a city and country on your own device, and only that city/country is ever sent to us. On the website, which has no on-device equivalent, your browser rounds your position to roughly a 1 km grid before it ever leaves your device, and our server resolves that already-rounded position to a city/country and discards it in the same request. We never store the coordinate itself, on either platform — there is no column in our database that could hold one.So a Shout-out sent from where you are right now can use your actual current city instead of only the city you told us you live in.Art. 6(1)(f) — legitimate interest (a live "where am I right now, for this one action" signal, in the same family as Presence). We never request more than reduced/coarse accuracy and never in the background — see section 4.
Local availability calls — Shout-out and BroadcastIf you send a Shout-out or a Broadcast — a short, one-way call for a game, matched by city rather than by connection — we store its kind, the city/country it targets (either the device location above or your declared home town), the dates you're free, your short note, when you sent it, and when it expires. If another player responds, we store who responded and when. If you pick a respondent, we store who you picked.To deliver the call to the right players, show you who responded, and connect you with whoever you pick.Art. 6(1)(b) — contract, for sending, receiving and resolving a call. Art. 6(1)(f) — legitimate interest, for the audience-matching itself where it reaches players you have not connected with, and for the retention/hold rule that applies to it — see sections 5 and 10.
Match resultsWho won, the score, discipline, date; and, for results imported from CueScore, the opponent's CueScore name and ID (see section 6). Live scoreboard sessions (an optional live, in-match tracker for a race-to-N One Pocket match) additionally capture rack-by-rack detail — who broke each rack, who won it, and the score. That detail is always visible to the two players in the match; whether anyone else can watch it live, and what they see, is a separate opt-in setting described in the next rowTo build your win/loss record; the live-scoreboard detail is captured because you or your opponent chose to track the match that way, and is used to compute the match statistics shown to the two of youArt. 6(1)(b) — contract (for you); Art. 6(1)(f) — legitimate interest (for non-member opponent data — see section 6; and, for the counterparty's own side of a live-scoreboard record, the same legitimate-interest basis that already covers a Match result row generally)
Live match watching (optional, off by default)If you turn on "Let my connections discover and watch my live matches" in Settings, one of your own accepted connections may find your live scoreboard session while it is still in progress and watch it update in real time, the way your opponent already can. This works independently for each player: a given watcher sees your identity and live score only if (a) you turned this setting on, and (b) that specific watcher holds an accepted connection with you — a connection with your opponent never extends to you, and a connection with you never extends to your opponent. If either condition is not met, that player is shown to the watcher only as "Opponent," never by name and never worked out indirectly. A watcher's access ends the instant the match stops being in progress — there is no grace period, and it is re-checked on every read, so revoking the connection or turning the setting back off closes access immediately, mid-match. We also keep a record of which of your connections watched which of your matches, but never as a named list shown to anyone, including you or your opponent — a watcher may see only a bare, unnamed count of how many people are watching that match right nowTo let a member who chooses to be watchable share the same live, in-match viewing experience with their own existing connections — a bounded, opt-in, one-match-at-a-time spectator amenity, never a public or map-wide oneArt. 6(1)(f) — legitimate interest, for both sides: the disclosing player's own bounded, revocable, opt-in choice, and the watch record itself (see section 10 for how long it is kept)
Live match scoring by an invited scorer (optional, off by default)If you and your opponent both turn on "Allow a scorer" in Settings, either of you can invite one specific person who does not have an 8nOut account to keep score for that match, including declaring who won. You do this by sharing a link or QR code; before you can generate it, we show you plainly what you're agreeing to — that this person will be able to finish the match on their own. Your opponent has to separately agree too, with their own genuine yes/no choice, so nothing is shared until both of you have said yes. The person you invite sees both your real names before they accept, and is asked to give us a name so you both know who's scoring (for example, "Priya K. is scoring this match") — we don't create an account for them, and we don't ask them for anything else. The link only works for the first person who uses it. Once accepted, they are the only one who can enter scores until the invite ends. When they declare a winner, it is not official right away — either of you has 2 minutes to object, and if neither of you does, it is confirmed automatically. Either of you can end the invite at any time — before it's accepted, or once it's active — which hands scoring control straight back to you and discards any result that was still waiting to be confirmedTo let two players who want a hands-free scorer at the table — the same role a referee or a friend keeping score on paper already plays — track their match live, without giving that person an 8nOut account or any access beyond this one matchArt. 6(1)(a) — consent: each of you is choosing to share your own name and live match data with one specific person you picked, for this one match only, and you can withdraw that choice at any time. The underlying match record continues to rest on the same Art. 6(1)(b)/(f) bases as the Match results row above
Device push tokenAn Apple (APNs) or web-push token for your device, if you enable notificationsTo send you the notifications you asked for (new connection, invitation, etc.)Art. 6(1)(b) — contract; the operating-system permission prompt is your opt-in
Moderation dataBlocks you set, and reports you file (reason, optional detail)To keep the community safe and to act on abuseArt. 6(1)(f) — legitimate interest (community safety and lawful, abuse-free operation)
Agreement / consent recordYour account ID, which documents you agreed to, the document versions, the timestamp, and the IP address the agreement was sent fromTo prove you agreed to the Terms and this Policy, and to prevent abuse of the sign-upArt. 6(1)(f) — legitimate interest (accountability under Art. 5(2), evidence of agreement, security) — see section 9 for IP specifics
Technical logsStandard security/error logs generated by our hosting providers (may include IP address and request metadata)To keep the Service secure and workingArt. 6(1)(f) — legitimate interest (security, availability)
Presence (activity status)Whether you are currently active in the app, shown to other signed-in members as a coarse status only — "online" (active in the last few minutes) or "recently active" (active in the last 24 hours). It is worked out from the app noting when it is open on your screen; there is no GPS or device location, and we keep only your most recent activity time — no history.To let members see who in the community is around and reachable now, so they can arrange an in-person gameArt. 6(1)(f) — legitimate interest (a live "who's around to play?" signal for the community). Presence is on by default; you can switch it off for everyone at any time with "Go invisible" (see section 4).
Connection count on your profileThe number of connections you have accepted, worked out from your connections each time your profile is viewed. It is only ever a number: never a list, and it never shows who your connections are. Pending, declined or removed requests are never counted. We keep no separate record of itSo members arranging an in-person game can see whether a profile belongs to an established member of the communityArt. 6(1)(f) — legitimate interest. Who sees it: you, always. Other signed-in members who can open your profile, unless you turn off "Show my connection count" in Settings. It is never on your public profile link and never shown to search engines. It is never shown to others for members under 18, or for members who have not told us their age group. It is shown to others only after we have told you about it in the app. Turning it off is your right to object under Art. 21, and we act on it in full, straight away
New-joiner labelA coarse "New" label shown next to your name in Find Players and the Connections screen for the first 14 days after you join — worked out from your account's own creation date, which we already have (see "Account identifiers" above). It never shows your join date or a day count, only the single word "New," and it clears on its own once the 14 days pass; there is no separate record kept for itTo help other members notice and welcome new joiners to the communityArt. 6(1)(f) — legitimate interest (a coarse, community-welcome signal, the same family as Presence above). No new data is collected for this — it is worked out from the account-creation date already processed under the Account identifiers row
Age groupWhether you're 16–17 or 18 or older — self-reported once, either at sign-up or in a one-time prompt you can skip if you joined before this feature existedTo set your read-receipts default correctly — on if you're 18 or older, off if you're 16 or 17 or you skip the question (see section 5) — and to keep anything that would show you or your data beyond your own connections switched off unless you've told us you're 18 or older: sending or receiving Shout-outs and Broadcasts that reach players you aren't connected with, making your home table visible to all members, and showing your connection count to other members. Used for nothing else.Art. 6(1)(f) — legitimate interest (letting us turn read receipts on by default for the community generally, while keeping younger members on a protective off-by-default setting instead of one opt-in-only rule for everyone)
Where you usually playWhether you told us you mainly play at a club, at home, or both — asked once, and skippable, during account setupTo help us decide whether a home-table feature is worth building. Used for nothing else, and never shown to any other player or moderatorArt. 6(1)(f) — legitimate interest (understanding demand for a possible future feature). Skipping the question changes nothing else about your account.
Onboarding progressWhich step of account setup you were on the last time you tapped "Finish later" — for example, the name step, the city step, or the club step. We keep only your most recent position, not a history: it is overwritten (never appended) each time you tap "Finish later" again, and is not updated if you later come back and answer more questions without leaving againTo understand where members leave the profile-completion sequence, so we can improve its design. Never shown back to you, to any other player, or to a moderator individually — a moderator can only see a floor-suppressed, population-level count across many members, never a number small enough to point at one personArt. 6(1)(f) — legitimate interest (improving the onboarding sequence's own design). Tapping "Finish later" is the same equally-weighted exit control every screen in account setup already has; nothing about it changes because of this.
City Ladder — your rating, your position, and past seasonsOnly if you join a ladder. We work out a rating for you — a single number, starting at 1500 for everyone, that moves up or down with each match you play against another member of the same city ladder — and from it, your position on that city's board. We keep how many ladder matches you have played and the date of your most recent one. When a season closes we save a permanent snapshot of the board: your name, your position and your rating on that day. We do not use your self-reported Fargo Rating for any of this, and there is no photo on the boardTo give you the thing you asked for when you joined: an ordered ranking of the players in your city, and a lasting record of how each season finished. Your rating and position are shown to the other members of your own city's ladder — not to the public, not to search engines, and not to signed-in members who have not joined that ladder. They do not appear on your profileArt. 6(1)(b) — contract, for your membership, your rating, the board, and a season snapshot taken while you are still on the ladder: joining is a request for a service, not consent, and the ranking is the service. Art. 6(1)(f) — legitimate interest, for keeping a past season's snapshot after you leave the ladder (a season board is a record of the whole board, and removing one row would change everyone else's position) — you can object to that at any time, in the app, by choosing to appear as "Former member" (see sections 10 and 11)
First and last nameYour first and last name, asked as part of account setup. If you fill in both, this becomes your public display name — shown wherever your name appears to other members (chat, map, connections, challenges, and more), the same as the rest of your profileTo help us prepare for a possible future ratings-lookup feature, and for sorting the player list by nameArt. 6(1)(f) — legitimate interest (preparing a possible future ratings-lookup feature, and enabling name-based sorting of the player list)
Feedback you send usThe category you pick (bug / idea / question / other) and the free text you write, when you use the in-app feedback form (Settings, or the Help centre's "Still stuck?" block, on iPhone; your Profile page on the web)To let us read and act on bugs, ideas and questions members send us. Read only by us — never shown to any other memberArt. 6(1)(f) — legitimate interest (operating a feedback channel and improving the Service)
Activity — points, badges and a status tierA participation score, separate from the City Ladder rating above: points for things like sending a challenge, playing a match (won or lost), linking CueScore, making a connection, joining a group, or sending a Shout-out/Broadcast; a small set of one-time badges for participation milestones (a first challenge, a first win, a busy week, a win streak, playing in more than one city, five or more connections, having a home table, linking CueScore); and a tier name derived purely from your total points. None of this measures how good you are at pool — that is what the City Ladder and your self-reported Fargo Rating are forTo recognise showing up and taking part, not winning. Visible to you, always on your own profile. Whether anyone else can see it is your own choice — a three-way setting (Connections / Everyone / Private, default Connections) you control in Settings → Privacy, the same place as Read receipts and Typing indicators. One badge is different: whether you have a home table is never shown to a stranger through this feature, even if your setting is Everyone, and even if you have made the table itself visible to all members. Who can see a home table is decided only by that table's own setting (see section 4), never by your Activity setting — a viewer who does not hold an accepted connection with you simply sees one fewer badge in the total, not a locked or masked oneArt. 6(1)(b) — contract, for keeping your own points/badges/tier and showing them back to you. Art. 6(1)(f) — legitimate interest, for showing your points/badges/tier to another member only when your own setting allows it — recognising participation across the community is a legitimate purpose, and the default (Connections-only) and the Home Table carve-out are both there to keep that purpose from becoming a wider disclosure than you chose
Website statistics (Google Analytics) — only if you acceptOnly on our public website pages (the home page, Info, Help, the blog, the Privacy, Terms, Accessibility and Child Safety pages, and our "page not found" page) at 8nout.com — never in the web app, the admin pages, public profile pages, or invite and share links, and never in the iPhone or Android app. If you accept: the pages you view (the address without anything after "?" or "#", and the page title), the page you came from (same rule), when you scroll, click a link to another site or download a file, your approximate location (city, region and country, worked out by Google from your IP address — Google does not store the IP address itself), your device type, browser, operating system, screen size and language, and a random identifier kept in two cookies on your device (_ga and _ga_<ID>). Not linked to your 8nOut account: we never send Google your account, your name or anything from your profile, even if you are signed inTo count visits and see which public pages are used and how people find them, so we can improve the websiteArt. 6(1)(a) — your consent, given in the website's cookie banner (the same consent the Dutch Telecommunications Act requires for placing these cookies). You can withdraw it at any time with the "Cookie settings" button at the bottom of each of those pages — see section 8

We do not knowingly process special-category data (Article 9 GDPR — e.g. health, ethnicity, religion, political opinion). Please do not put such data in your bio or messages.

4. How location and addresses work

This is the most privacy-sensitive part of 8nOut, so it is enforced in the database itself, not just hidden in the app:

5. Connections, contact info and messages

Chat — how your messages are handled

Read receipts

Shout-out and Broadcast — local availability calls

Moderator access

To keep the community safe and act on reports, the operator and a small number of senior moderators can open an internal review view of one member at a time. That view shows:

The view does not give a moderator your precise home-table address, the names of your connections, or your individual match history. The view tells a moderator only whether you have added a phone contact (yes/no) — never the number itself, which stays visible only to connections you have accepted. Your precise home-table address stays behind the separate, time-limited grant you control and can revoke at any time (see section 4) — accepting a connection does not reveal it, and neither does this view. Your sign-in email address is not shown either — with one narrow exception: if your account was created but never finished signing up, the view tells a moderator the email address used to attempt the sign-up, so incomplete or abandoned accounts can be identified and administered. The moment your account finishes signing up, this exception no longer applies, and your email is not shown to any moderator through this view again.

Your messages are not part of this view either — they are reachable only through a separate, narrower route, and only when a message is reported. When someone reports a specific message, a moderator with a separately granted message-review permission can read the reported message and a bounded window of the same conversation around it: at most 5 messages before and 5 after, and no more than 24 hours either side of the reported message. Nothing outside that conversation can be read, there is no browsing, no search over messages, and no way to open anyone's messages without an open report naming one. A message that was deleted for everyone appears in that window (marked as deleted) while we still hold it — that is what makes a deleted message still reportable. Every such read is recorded, including exactly which messages were shown, in the same access record described below.

A moderator must give a reason, or link the report they are acting on, before the review view will open — and for messages, only a linked report will do — and every opening is recorded: who opened it, about whom, when, why, and (for messages) which messages were returned. We keep that access record for 18 months and then delete it; it cannot be read from the app by any member. This is what keeps the access accountable and reviewable.

If you submit a venue for review, a moderator holding a separate verification permission can also open a real two-way conversation with you about that specific submission — even if you are not connected. This is narrower than it sounds: the moderator can only reach you about the venue you submitted, never any other member; the conversation is only available while your submission is pending review, plus 14 days afterward; and every message you receive this way carries an on-screen notice telling you a moderator sent it, which submission it concerns, and that Report and Block work exactly as they do anywhere else in the app. This access ends automatically once the 14 days pass, if the venue is removed, or if either account is deleted — whichever happens first. Every opening and every message sent through this route is recorded in the same access record described above.

Legal basis: our legitimate interest in a safe, abuse-free community (Art. 6(1)(f)). You can object to this processing under Article 21 (see section 11); because it exists to protect other members, we may continue where we have compelling legitimate grounds, but we consider every objection on its facts.

Account merges

Occasionally, two accounts on 8nOut turn out to belong to the same real person — most often a duplicate sign-up, for example one made with Apple and one with Google. When we spot this, the operator can combine the two into one surviving account, using an internal tool built for exactly that. This is not something a moderator can do: it is a manual, owner-only action, used only once we've checked the two accounts really are the same person, never automatic and never based on how alike two profiles look.

For almost everything, nothing you already have there is lost. Your profile details, match history, City Ladder standing, Activity points, badges and status tier, and your sent messages, are all combined onto the account that survives. The two exceptions are your City Ladder standing and a home table pin: whichever of the two accounts has played more ladder matches keeps its own standing, and whichever pinned its home table more recently keeps that pin — even if that means the other account's version is the one that's replaced.

The account that doesn't survive is switched off, not deleted. It can no longer be found on the map or challenged to a new match. Existing conversations it's already part of are not affected by the merge — they carry on exactly as before, through the connections that were already accepted.

Your own connections, challenges and conversations with other members are never moved onto a different account by this process. If someone you're connected with later has one of their accounts merged into another, nothing about your side of that connection, challenge or conversation changes — so we don't need to tell you it happened. Both accounts involved in a merge are told directly, every time.

Legal basis: our legitimate interest in accurate, non-duplicated records for the community (Art. 6(1)(f)). You can object under Article 21 (see section 11); we consider every objection on its facts.

Push notifications

Most notifications tell you about something that already happened to you directly — a message, a connection request, a challenge. The one below is different: it's an extra you turn on yourself, and you can turn it off again at any time.

Legal basis: our legitimate interest (Art. 6(1)(f)) in helping members notice and engage with a growing community — not your consent: turning this on is a product preference, not a consent flow, and turning it off is as simple as flipping the toggle back. You can object to this processing under Article 21 (see section 11).

6. CueScore integration

8nOut can read your public CueScore profile and public CueScore match results (from CueScore's public read API) so you can:

  1. Link your CueScore profile — we then store your CueScore player ID and use your CueScore name and photo on your 8nOut profile.
  2. Import a finished match — we read the public match record and store the result (winner, score, discipline, date) against your 8nOut win/loss record.

Two things you should know:

Venue data for the public map (from CueScore). Any signed-in member can add a public pool venue to the 8nOut map by pasting a public CueScore venue link, and our moderators can do the same. When this happens, 8nOut reads that venue's public CueScore details — the venue name, address, city, and country — and stores only those facts, together with the venue's CueScore organisation/venue ID as a record of where the entry came from (its provenance). We do not copy CueScore's page, and we do not store the venue's table list, logo file, or any player, owner, or match data from it. Every submission is reviewed by a moderator before it appears on the public map. A moderator-controlled switch can turn all CueScore reads — venue reads and match imports — off at any time.

Publicly aggregated win/loss counts (like a Fargo rating) may be shown on a member's profile. These are numbers, not a list of named opponents.

7. Who receives your data, and in what role

We do not sell, rent, or trade your personal data, and we do not share it for anyone else's marketing.

Two different kinds of company appear below, and the difference decides who is answerable to you for what happens next:

7.1 Processors — they handle data on our behalf

WhoWhat they do for 8nOutWhat they holdWhere
SupabaseDatabase, sign-in, file storage and server functions — the whole 8nOut backendEverything in your accountDatabase in the EU (Ireland). The Supabase contracting company is outside the EU — see "International transfers" below
CloudflareHosts and delivers our website and web app, and runs a quick, automated check that a sign-up is a real person and not a script (Cloudflare Turnstile), during sign-up on both the website and the iPhone appRequest data only — your IP address, your browser type, and the page you asked for; during sign-up, the same kind of request-level signals (your device/environment), needed to generate that check. Not the contents of your accountGlobal network; a page can be served from outside the EEA — see "International transfers" below
Google (Google Analytics) — only if you accept website statisticsMeasures visits to our public website pages for us, so we can see which pages are used (section 3, "Website statistics"). Google acts only on our instructions: we have switched off its data-sharing settings, Google signals and every advertising feature, so it may not use this data for its own purposes or for adsThe website statistics only — pages viewed, approximate location, device and browser details, and the random identifier from the _ga cookies. Never your 8nOut account or anything in it. Kept for 14 months (section 10)Google Ireland Limited is our contracting party; Google may process the data in the United States — see "International transfers" below
ResendSends the email that carries your one-time sign-in code, on our behalf, when you sign in or sign up by email; and sends us a short internal notification, on our behalf, when you use the in-app feedback form — that notification never contains the text you wrote, only that feedback of a certain category arrived; and, if your account is deleted at your emailed request or removed for a breach of our Terms, sends you one email confirming this or giving the reasonsYour email address, and the content of that one email — the sign-in code itself, generated fresh each time and expiring within minutes. For the feedback notification: the only reference to you in that email is your internal member ID — used only so a moderator can look you up in our own systems if needed; never your name, your email address, or the text you wrote. For a deletion or removal email: only your email address, the dates, and, for a removal, the category of the reason — never an internal note or who reported youProcesses in the United States. Resend's Data Processing Addendum — Standard Contractual Clauses, a UK Addendum, and its own EU–U.S. Data Privacy Framework certification — covers the transfer; see "International transfers" below
GeoapifyLooks up the map coordinates of a pool club's address when someone adds a club, on our behalfOnly the address text typed for the club, sent from our server. Never your IP address, your name, your account, or the club's nameEU. Geoapify is an EU company, based in Cyprus, and handles these lookups in the EU, so this data does not leave the EEA
AnthropicPowers the AI coding-agent sessions we use to build and maintain 8nOutNo access to your data. These sessions read and write our source code and project documentation (tickets, migration files, and similar) — never a live copy of the database, and never member dataWe have not yet confirmed where Anthropic's processing takes place or what transfer safeguard applies — see "International transfers" below

7.2 Independent controllers — they receive data and decide their own use of it

WhoWhat they receive, and when
Apple — Sign in with AppleSigns you in, and gives us an account identifier and an email address (often an Apple private-relay address)
Apple — push notifications (APNs)Carries a notification to your iPhone when we send you one
Apple — App Store and TestFlightDistributes the app, and holds its own relationship with you as a customer or tester
Apple — Apple Maps (MapKit)Draws the map inside the iOS app
Google — Sign in with GoogleSigns you in, and gives us an account identifier and an email address
Google — Google PlayDistributes the Android app, and holds its own relationship with you as a customer or tester
OpenStreetMap Foundation — map tiles (web and Android app)Draws the map on the website, in the web app and in the Android app. Your browser, or the Android app, fetches the map images directly from OSM's servers, so OSM sees your IP address and which part of the map you are looking at. We are not in the middle of that request
GitHub — MapLibre demonstration map (older Android app builds)Builds of the Android app that don't yet use OpenStreetMap map tiles draw a basic map (borders and place names only) from a free demonstration map server that the MapLibre open-source project runs on GitHub's hosting. The app fetches that map data directly, so GitHub sees your IP address and which part of the map you are looking at. We are not in the middle of that request. Updating to a build that uses OpenStreetMap map tiles stops this
OpenStreetMap Foundation — Nominatim (location lookup)For Shout-out on the website only: if you use a browser (not the iPhone app) to compose a Shout-out from your current location, we send your already-rounded, approximate position to Nominatim once, to resolve which city you're in, and nothing else. On iPhone your position is resolved to a city on your own device, and Nominatim never sees it. Only the rounded position is sent — never your IP address, your name, or your account. Club addresses are looked up by Geoapify (section 7.1), not by Nominatim. If Geoapify's lookup is unavailable for a longer period, we may temporarily send club address lookups to Nominatim instead, under the same rule: only the address text, nothing about you.
Google, Mozilla, or Apple — Web Push relayIf you enable notifications on our website or web app, your notification is relayed by whichever company operates push infrastructure for your browser — Google if you use a Chromium-based browser (Chrome, Edge, Brave, Opera, and others), Mozilla if you use Firefox, or Apple if you use Safari with 8nOut installed to your Home Screen. Only one of the three ever receives a given notification — whichever matches your browser. What it receives is the same minimum content already described above for iPhone notifications: who a message or event is from, never its content
Search engines (for example Google)Only if you claim a profile name and leave "Let search engines find my profile" on: the public page at your name's address, as anyone can see it, and the address is listed in our public sitemap

About Apple push notifications specifically. Apple carries our notifications under the Apple Developer Program agreement rather than as a company we could bind with a data-processing agreement. That is exactly why we keep the contents of a notification to the minimum needed to tell you what happened.

A name we removed, and why it's back. Earlier versions of this section listed Google Firebase Cloud Messaging as a push provider "if used", then removed it because nothing in the product used it. That has changed for a specific, disclosed reason: if you enable notifications on our website using a Chromium-based browser, your notification is now relayed through Google's push infrastructure, exactly as the Web Push relay row above describes — so Google is a genuine recipient again, for real data, this time. We use no advertising or attribution service of any kind, and the 8nOut apps use no analytics service (section 8). The one analytics service we use is Google Analytics on our public website pages, only if you accept it, with Google as our processor (section 7.1) — it is separate from this relay, which carries only the minimal notification content described above and nothing else. Receiving a notification does not give Google, Mozilla, or Apple any broader relationship with 8nOut or with you.

International transfers. Where data goes outside the European Economic Area, this is the position, provider by provider:

You can ask us about any of this at privacy@8nout.com.

Law enforcement and competent authorities. If a competent authority requires it under a binding legal instrument, we may have to give them data we hold — including the content of messages that are still within their retention period. We do not act on informal requests: we require a valid order or request from an authority competent over us, and we route requests from outside the Netherlands through the proper legal channels. If an authority makes a valid request to preserve data, we will place it on hold — preserving is not disclosing. We will tell you if your data has been disclosed, unless the law or the order forbids us from telling you, in which case we will tell you as soon as we are allowed to. We may also disclose data to establish, exercise, or defend a legal claim.

8. No ads, no cross-site tracking — and statistics on our website

Website statistics (Google Analytics) — only if you accept.

Storage that needs no consent. The website and web app also keep a few things on your device that are strictly necessary or that you chose yourself: your sign-in session, your theme and language, which notices you have already dismissed, an invite you are in the middle of accepting, an agreement you are in the middle of giving, and your cookie choice itself. They are never used for statistics or shared with Google, and the Dutch Telecommunicatiewet does not require consent for them.

9. The IP address in your agreement record — the specifics

When you agree to the Terms and this Policy at sign-in, we record the agreement (your account ID, the documents and their versions, the timestamp, and the IP address the request came from). We treat an IP address as personal data.

10. Retention — how long we keep things

11. Your rights

Under the GDPR and UAVG you have the right to:

To exercise any right, email privacy@8nout.com. We will respond within one month (extendable by two further months for complex requests, and we will tell you if we need that). We do not charge for this unless a request is manifestly unfounded or excessive.

Complaints. If you think we have mishandled your data you can complain to the Dutch Data Protection Authority:

Autoriteit Persoonsgegevens, Postbus 93374, 2509 AJ Den Haag, the Netherlands — autoriteitpersoonsgegevens.nl

You may also complain to the supervisory authority in your own EU country of residence.

12. Children

8nOut is not intended for children under 16. The Service helps adults arrange in-person games, sometimes at private home addresses, so we set a minimum age of 16. If we learn that someone under 16 has created an account, we will delete it. If you believe a child is using 8nOut, contact privacy@8nout.com.

Our public website can be read by anyone. If you are under 16, please choose Reject in its cookie banner (section 8).

(Netherlands: the UAVG sets 16 as the age of valid consent for information society services. 8nOut adopts 16 as its minimum age regardless of the legal basis used.)

13. Security

Access to sensitive data (precise home addresses, contact info) is enforced at the database layer by row-level security and by server-side functions, so it cannot be bypassed from a client app. Data is hosted in the EU and encrypted at rest at the storage layer. We also keep an encrypted backup of the database so that member data can be restored after a technical failure. Backups are encrypted before they leave the operator's computer, are held only by us, are never used for anything but restoring the Service, and are deleted automatically after at most 30 days (see section 10). No system is perfectly secure, but we design 8nOut so that private data is private by default.

14. Changes to this policy

If we change this policy in a way that materially affects you, we will update the version number and the date, and — because agreement is recorded and versioned — we will ask you to review and agree again the next time you open the app or web app. Minor clarifications may be made without re-consent, but the date will always reflect the latest version.

15. Contact

privacy@8nout.com — Espen Falkenhaug, trading as Digital Commerce Guild, operator of 8nOut, established in the Netherlands (KvK 94972036). Letters: Digital Commerce Guild, Postbus 79055, 1070 NC Amsterdam, the Netherlands (see section 1).