LEGAL
Privacy Policy
Last updated: 2 July 2026 · Applies to app.nullcorp.eu and every tool hosted under it
1. Overview
NULL TOOLS (app.nullcorp.eu) is operated by NULL Corporation ("NULL Corp", "we", "us"). This Privacy Policy explains what personal data we collect across the main site and every individual tool hosted on the platform, why we collect it, and what rights you have over it.
Each tool on NULL TOOLS can collect and process data differently. Section 4 ("Per-tool data handling") describes exactly what each tool does. Where a tool's behavior is identical to the main site, it is covered by the general sections below and not repeated.
2. What we collect
Account data
- Username and email address, provided at registration.
- Password, stored only as a bcrypt hash — we never store or can read your plaintext password.
- If you sign in with Google, your Google account ID and the profile info Google shares with us (name, email).
- A session token issued after login, used to keep you signed in.
Technical data
- IP address, recorded briefly for rate-limiting on registration/login to prevent abuse (kept 1 hour).
- A security log of login/registration attempts (IP address, timestamp, email), kept for 1 year, for detecting abuse and account-security investigations.
- Standard server request logs (URL, timestamp, status code) for security and debugging.
Tool-specific data
Some tools collect additional data unique to their function — connected social media tokens, direct messages, time-tracking entries, uploaded game assets, prediction picks. Full detail is in Section 4.
3. Legal basis for processing (GDPR)
| Data | Legal basis |
|---|---|
| Account credentials, session tokens | Contract — necessary to provide the service you signed up for (Art. 6(1)(b) GDPR) |
| IP address for rate-limiting, security logs | Legitimate interest — protecting the platform from abuse (Art. 6(1)(f) GDPR) |
| Connected social media accounts (Overlay Maker) | Consent — you explicitly authorize each connection via OAuth (Art. 6(1)(a) GDPR) |
| Cookies/local storage beyond essential | Consent — see our Cookie Policy |
4. Per-tool data handling
Main site / account system
Handles registration, login, Google OAuth, session management, and the code-redemption system used to unlock certain tools. Data: username, email, password hash, Google ID (if used), session token, IP (rate-limiting only). No file uploads. No analytics or advertising trackers.
Overlay Maker
This tool holds real credentials to your connected social media accounts. When a team owner connects Instagram, Facebook, TikTok, YouTube, LinkedIn, or X, we store the OAuth access token and refresh token issued by that platform, so we can display follower counts, posts, and engagement metrics inside the dashboard. These tokens can act on your account within the permissions ("scopes") you grant during the connection — we only request read-level scopes needed to display analytics.
- Retention: connected-account tokens are kept until you or a team owner disconnects the platform, at which point they are deleted immediately.
- Revocation: you can also revoke access at any time directly from the connected platform's own security/app-permissions settings — this is the fastest way to cut access if you don't have access to disconnect it in-app.
- Team membership and roles (owner/admin/member) are stored to control who can connect or disconnect accounts.
Timekeeping
Time entries and subjects are stored in your browser's local storage for offline use, and synced to our server under your account so they're available across devices. No data is shared with third parties.
NULL Predictions / WC2026
Stores your predictions/picks, group memberships, and (if you started with a guest link) a claim token used to link that guest activity to a full account. Match schedules and results are fetched from a public football-data API — no personal data is sent to that API. The "AI Leaderboard" feature shows genuine World Cup predictions from several public AI chatbots (ChatGPT, Claude, Gemini, Grok, Copilot, Perplexity) — we ask each one directly and manually record what it said; this tool does not call any AI provider's API itself, and no NULL TOOLS user data is ever sent to any AI company through this feature. See our Data & Compliance page for the full AI disclaimer.
eSports Dashboard
Direct messages: messages you send to other team members are stored on our server in readable form so the recipient can read them. The sender can permanently delete a message they sent — this removes it entirely, for both parties, not just from the sender's own view; to request deletion of a message you received (that the sender hasn't deleted), contact us using the details in Section 9.
Real-time messaging: we use Pusher (a third-party real-time messaging provider) to deliver strat-discussion channels and notifications live. Pusher acts as our data processor for message delivery — see Section 5.
Uploads: team admins can upload game-asset images (operator icons, map blueprints). These are game reference images, not personal files, and are retained while in active use by the team.
Availability, schedules, and match history are stored to run the team-scheduling features.
SponsorDeck
A standalone deck-generation tool with no server-side backend and no account requirement identified at the time of writing. It does not collect or store personal data on our servers. If this changes, this section will be updated.
Verdict¡
A 1v1 courtroom battle game. Stores match data (invite code, which case was assigned, which role — Prosecutor or Defense — each player picked, each side's evidence/witness/opening-statement choices, and the full turn-by-turn event log of what was asked, presented, or objected to during a match), plus a running career record (XP, in-game currency, reputation, win/loss totals). No file uploads. No third-party services. Uses the same site session/account as every other tool — no separate Verdict-specific login.
- Retention: your career stats (XP/currency/reputation/win-loss record) are deleted when your account is deleted. Match and event history is not deleted, for the same reason as eSports' team content above — a match involves another player who is still entitled to their own match history — but those rows only ever store a numeric account id, never a name, so once your account is gone that id simply stops resolving to you rather than leaving identifying data behind.
5. Third parties
| Service | Purpose | Data shared |
|---|---|---|
| Google (OAuth) | Sign-in / account claiming | Email, name, Google account ID |
| Cloudflare Turnstile | Bot protection on registration | Browser/device signals, no personal identifiers we store |
| Hostinger (SMTP) | Sending verification/reset emails | Your email address, email content |
| Pusher | Real-time messaging (eSports) | Team channel membership, message delivery metadata |
| Public football-data API | Match schedules/results (Predictions) | None — public sports data only, no personal data sent |
| Instagram / Facebook / TikTok / YouTube / LinkedIn / X | Social analytics (Overlay Maker, opt-in per connection) | OAuth tokens you authorize; we read your public/owned account metrics |
We do not sell personal data, and we do not run advertising or third-party analytics trackers anywhere on NULL TOOLS.
6. International data transfers
Some of the providers above (Google, Pusher, Cloudflare, and the social platforms) may process data outside the European Economic Area. Where this happens, we rely on the provider's own GDPR-compliant safeguards, including Standard Contractual Clauses, as their standard basis for international transfer.
7. Data retention
| Data type | Retention |
|---|---|
| Account data (username, email, password hash) | Kept while your account is active. After a deletion request, deactivated for a 14-day grace period (during which you can cancel), then permanently deleted automatically |
| Session tokens | Expire automatically after 30 days |
| Email verification / password reset tokens | Single-use, expire after 24 hours |
| Data export file & download link (your "Request My Data" copy) | Expires and is deleted automatically 48 hours after generation, or immediately if you delete your account before it expires |
| Connected social media tokens (Overlay Maker) | Deleted immediately on disconnect |
| Direct messages (eSports) | Kept until deleted by the sender or removed on request — see Section 4 |
| Uploaded game-asset images (eSports) | Kept while in active use by the team; removed within 30 days of a deletion request |
| Career stats — XP/currency/reputation/win-loss record (Verdict¡) | Deleted automatically when your account is deleted |
| Match & event history (Verdict¡) | Kept indefinitely (a match involves another player with their own claim to that history) — see Section 4 for why this doesn't leave identifying data behind |
| IP rate-limiting counter (blocks abusive login/registration attempts) | 1 hour — purged automatically on every attempt |
| Security/audit log (login and registration attempts, IP address, timestamp) | 1 year, purged automatically by a daily maintenance job |
| Backups | Target retention: 30 days rolling. Automated backup-expiry is not yet implemented — tracked as a technical follow-up. |
For a more detailed operational breakdown, including how to actually submit a deletion or export request, see the Data & Compliance page.
8. Security measures
We use bcrypt password hashing, random single-use tokens for email verification and password resets, and role/membership checks to gate access to team data. HTTPS is enforced sitewide. Backend service credentials (database, third-party API keys, admin access key) are stored in server-side configuration rather than the application source, and blocked from direct web access — see our Security page for full detail.
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security, but we work to use practices appropriate to the risk.
9. Your rights
If you are in the EEA/UK, GDPR gives you the right to:
- Access the personal data we hold about you.
- Correct inaccurate data.
- Delete your data ("right to be forgotten").
- Export your data in a portable format.
- Restrict or object to certain processing.
- Withdraw consent at any time, where processing is based on consent.
To exercise these rights, use the Privacy & Data section under Account Settings → Account Details to request an export or account deletion directly, or contact us — see below. We aim to respond within 30 days. See Data & Compliance for step-by-step instructions.
10. Contact
For any privacy request or question, contact contact@nullcorp.eu. NULL Corporation is based in Belgium and this policy is governed by Belgian law and GDPR.