The short version
RaidPact is run by an individual developer based in the Netherlands. For anything in this policy, including requests about your data, write to privacy@raidpact.app.
Under the GDPR this makes us the data controller for the information described below.
RaidPact only works if trainers can find each other and trust each other, so most of what we keep exists to make that possible.
| Data | What it is | Why | Kept for |
|---|---|---|---|
| Account | An anonymous account ID, or your Google account if you sign in with Google (email address and name, held by Firebase Authentication). | To keep your profile attached to you across sessions and devices. | Until you delete your account. |
| Trainer profile | Nickname, Pokémon GO friend code, team, and — if you verify — your trainer level. | Hosts need your exact in-game name to invite you, and you need theirs to add them. | Until you delete your account. |
| Reputation | Karma, reliability, raids completed, star ratings you gave and received, and a karma ledger of how each change came about. | The pact only means something if breaking it has consequences. The ledger exists so a penalty can be explained rather than just applied. | Indefinitely (see deletion below). |
| Raid activity | Which lobbies you joined, when you marked ready, your attestation of the outcome, and reports that a party member abandoned a raid in-game. | To run the lobby, settle the result by quorum, and resolve disputes fairly. | Indefinitely. |
| Reports & blocks | The reason and, if you write one, the note you add when you report a trainer. Separately, the list of trainers you have blocked and the trainers who have blocked you. | To act on harassment, impersonation and cheating, and to keep blocked trainers out of each other's lobbies and invitations. | Reports are kept as a moderation record. Blocks last until you remove them, or until you delete your account. |
| Co-raid counters | How often you and another trainer raided together in the past seven days. | Anti-abuse: it stops two accounts from farming karma off each other. | Rolling 7-day window. |
| Bench & invites | The bosses you marked yourself as looking for, and invitations sent to you. | So hosts can pull you into a lobby. | Bench entries expire after 2 hours; invitations after 90 seconds; priority tokens after 3 days. |
| Push token | A device token issued by Expo's push service, if you allow notifications. | To tell you a host is inviting you, a lobby opened for a boss you are waiting on, or your lobby is ready to start. | Until you delete your account or turn notifications off. |
| Team check score | A percentage describing how well your battle party matches the boss. | Shared with your party as a heads-up. It never blocks anyone from raiding. | With the lobby. |
We do not collect analytics about how you use the app, and we do not build advertising profiles.
RaidPact is a social app, so some of your profile is visible to others by design: your nickname, team, verified level, reliability, karma, raids completed, average rating, badges, and your friend code. The friend code is the point — adding each other in Pokémon GO is how the raid happens.
Your email address, push token and karma ledger are never shown to other trainers.
Tap any trainer to report or block them. Blocking is silent — the other trainer is never told — and it works in both directions: neither of you can join the other's lobby or send the other an invitation. You can undo a block at any time from your profile.
Reports go to the developer, not to other trainers. If you need to raise something and you are not able to use the app — for example because someone is using your name — email abuse@raidpact.app.
Authentication, database, and server functions run on Google Firebase, in the europe-west1 region (Belgium). If you sign in with Google, Google also processes that sign-in.
Push notifications are delivered through Expo's push service, which receives your device push token and the message text. App updates are distributed through Expo's update service.
RaidPact fetches raid boss data from public community sources (Pokébattler, LeekDuck via ScrapedDuck, PogoAPI). These are outbound requests for public game information — no personal data is sent to them.
Under the GDPR we rely on:
You can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to our use of it. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens).
To exercise any of these, email privacy@raidpact.app.
Profile → Delete account removes your account immediately. Your nickname is released, your friend code is erased, your verification is cleared, and your sign-in is deleted — you cannot log back in.
Two things survive, and we would rather say so plainly than bury it:
Cannot wait, or already uninstalled the app? Email privacy@raidpact.app from any address and tell us your trainer nickname. We will delete the account by hand within 30 days, and usually within a few days. You never have to reinstall anything to ask. The same goes for the residual raid history above — say so in the message and we will erase that too.
All traffic is encrypted in transit. Clients can never write to the database directly — every change goes through a server function that checks it first. Database rules only let you read your own profile; other trainers' profiles are served through a function that returns a limited, safe subset.
RaidPact is for trainers 18 and over. Raiding here means exchanging Pokémon GO friend codes with people you have not met, and adding them in another game where they can contact you. We are not able to make that safe for younger trainers, so we do not offer it to them.
Every trainer is asked for their date of birth once, on a screen that states no age requirement and pre-fills nothing. We keep only whether the answer was 18 or over — the date itself is never stored. If you believe someone under 18 has given us personal data, email privacy@raidpact.app and we will delete it.
If this policy changes in a way that matters, we will say so in the app before the change takes effect. The date at the top always reflects the current version.