Privacy Policy
Last updated 31 August 2026
We hold match footage, performance analysis and — if you connect it — health data about you. This page says plainly what we collect, why we are allowed to, who else touches it, how long we keep it and what you can make us do about it. Every section has a plain-English summary; the formal wording is what legally applies.
- 01Who is responsible for your data
- 02What we collect
- 03Why we use it, and what allows us to
- 04AI processing
- 05Health and wearable data
- 06Match footage and clips
- 07Who else sees your data
- 08International transfers
- 09How we protect it
- 10How long we keep it
- 11Your rights
- 12Device permissions and notifications
- 13Cookies and similar technologies
- 14Children
- 15Changes to this policy
- 16Contact
01Who is responsible for your data
First Touch SRL, a company registered in the Republic of Moldova under IDNO 1025600043867, with its registered office at Str. Sfântul Andrei 58, Chișinău, Republic of Moldova, is the data controller for the personal data described here. We trade as 1st Touch, and our Founder and CEO is Andrei Butnaraș.
This policy covers the 1st Touch website at 1sttouch.ai, the web application, the iOS and Android apps, and the analysis service delivered through them. It explains what we collect, why, who else sees it, how long we keep it, and what you can make us do about it.
We are established in Moldova, outside the European Union, but we provide the service to players living in the EEA and the United Kingdom. We therefore apply the UK and EU GDPR to their data as well as Moldovan Law No. 133 of 8 July 2011 on the protection of personal data, and we hold ourselves to the higher of the two wherever they differ.
For anything in this policy, write to andrei@1sttouch.ai.
In simple terms
A real registered company is legally on the hook for your data, and privacy@1sttouch.ai reaches the people who handle it.
02What we collect
Account and profile data. Your name, email address, date of birth, nationality, playing position, strong foot, current club and profile photo. Some of this comes from you at sign-up, some from public football databases about your professional career.
Performance data. The analysis our analysts produce from your matches — tagged events, statistics, heatmaps, formations, written reports and the video clips cut from match footage.
Match footage. Video of matches you play in, obtained from broadcast, club or competition sources, held so we can analyse it and cut your clips.
Health and wearable data, only if you connect a provider such as WHOOP: recovery, sleep and strain metrics. This is special category health data and we treat it accordingly — see section 5.
Your conversations with Touchy. The messages you type, the audio you record when you use voice mode, and the transcripts of it.
Billing data. Your subscription plan, its status and renewal dates, and a customer reference from our payment provider. We never see or store your full card number — that stays with Paddle.
Technical data. Device type, operating system, app version, IP address, crash reports, and logs of errors and video playback problems needed to keep the service working.
In simple terms
Your profile, the match analysis and video we make for you, your Touchy chats, anything you connect from a wearable, your plan status, and basic technical data so the app runs. Card numbers never reach us.
03Why we use it, and what allows us to
Where the UK and EU GDPR apply, we must have a legal basis for every use. Ours are:
- To perform our contract with you — producing and delivering your analysis, reports, clips and notifications; running your account; taking payment and handling refunds.
- With your consent — connecting a wearable, using the microphone for voice chat, sending push notifications, and any optional feature we ask you about. You can withdraw consent at any time, and doing so does not affect what we did before.
- Our legitimate interests — keeping the service secure, preventing fraud and abuse, fixing faults, understanding aggregate usage so we can improve the product, and defending legal claims. We weigh these against your rights and use the least intrusive option that works.
- Legal obligation — keeping tax and accounting records, and responding to lawful requests from authorities.
We do not sell your personal data. We do not use it for third-party advertising, and we do not build advertising profiles.
In simple terms
Mostly we use your data because you asked us for the service. Some things — wearables, the mic, notifications — only happen if you say yes, and you can say no later. We never sell it or use it for ads.
04AI processing
Touchy and parts of your reports are produced by AI models run by the providers listed in section 7. To answer you, we send the model your message or recorded audio and the relevant slice of your own match data. Voice mode additionally sends audio to a speech-to-text and a text-to-speech provider.
These providers act as our processors, under contracts that bind them to use the data only to return a result to us. We do not permit them to use your data to train their models, and we do not use your data to train models of our own.
AI output can be wrong. It is not a decision made about you in any legal sense — no automated system decides your membership, your pricing or anything else with legal effect. Please avoid putting information into Touchy that you would not want processed this way.
In simple terms
Touchy sends your question and your own match data to AI providers so it can answer. They're contractually barred from training on it. No AI makes real decisions about your account.
05Health and wearable data
Connecting a wearable is entirely optional and off by default. If you connect one, we receive recovery, sleep and strain metrics through that provider’s secure authorised connection.
Health data is a special category of personal data. We process it only on your explicit consent, given when you connect the provider, and only to enrich your own reports and show you your own trends. Access tokens are encrypted at rest, and the metrics are visible to you and to the 1st Touch staff working on your account.
You can disconnect at any time from Health settings. Disconnecting stops all further syncing immediately; ask us and we will delete the metrics already synced.
In simple terms
Wearable data is opt-in, encrypted, used only for your own reports, and you can unplug it and have it deleted whenever you want.
06Match footage and clips
Footage of matches you play in is stored securely and made available to you and the 1st Touch staff assigned to your account. It is not shared with other players, not published, and not licensed on to anyone else. Where you share a clip through a share link, that link is token-gated, can carry a PIN, and can be revoked by us or by you.
In simple terms
Your match video is private to you and your analyst. Nobody else gets it unless you share a link, and links can be switched off.
08International transfers
Because we are based in Moldova and use providers in the EU, the United Kingdom and the United States, your data is processed outside the country you live in.
Moldova has ratified Council of Europe Convention 108 on the protection of individuals with regard to automatic processing of personal data, and its national data protection law is modelled on the European framework. Where personal data reaches us from the EEA or the UK, and for onward transfers to providers outside those areas, we rely on Standard Contractual Clauses, the UK International Data Transfer Addendum where applicable, or an adequacy decision where one exists — together with encryption in transit and at rest.
You can ask us at any time which safeguard covers a specific provider, and we will tell you.
In simple terms
Some of our tech runs in the US. When data goes there it travels under approved legal safeguards and stays encrypted.
09How we protect it
Data is held on secured cloud infrastructure with encryption in transit and at rest, row-level database permissions so an account can only ever reach its own data, role-based access controls for staff, and an append-only audit log of administrative actions. Health provider tokens are separately encrypted. No system is perfectly secure, but if a breach ever puts your rights at risk we will notify you and the relevant authority within the deadlines the law sets.
In simple terms
Encrypted, locked down per-account, staff access logged. If something ever went wrong, we'd tell you.
10How long we keep it
- Account, profile and performance data — while your account is active.
- Match footage and clips — while your account is active, or shorter where a footage licence requires it.
- Touchy conversations — while your account is active; you can delete individual chats sooner.
- Health metrics — until you disconnect the provider or ask us to delete them.
- Billing and tax records — up to 7 years after the transaction, because tax law requires it.
- Security and error logs — up to 12 months.
If you delete your account, from Settings in the app or by emailing us, we erase your personal data within 30 days, apart from the billing records we are legally obliged to keep and anything needed for an active legal claim.
In simple terms
We keep it while you're a member. Delete your account and it's gone within 30 days — except invoices, which tax law makes us keep for 7 years.
11Your rights
Wherever the GDPR or a similar law applies, you can ask us to:
- Give you access to a copy of your data.
- Correct anything inaccurate or incomplete.
- Delete your data.
- Restrict or stop a particular use.
- Send you, or another provider, a portable copy of the data you gave us.
- Object to processing we base on legitimate interests.
- Withdraw a consent you gave, such as for a wearable or the microphone.
Email andrei@1sttouch.ai and we will respond within one month. Exercising these rights is free, and we will never treat you differently for it.
You can also complain to a data protection authority. If you live in the EEA or the UK, that is the supervisory authority of your own country — you do not have to bring a complaint to Moldova. Our own national regulator is the National Centre for Personal Data Protection of the Republic of Moldova (NCPDP). We would much rather you came to us first so we can put it right.
In simple terms
See it, fix it, download it, delete it, or tell us to stop. Email privacy@1sttouch.ai and we answer within a month. You can also complain to a regulator.
12Device permissions and notifications
The apps ask for the microphone (voice chat and dictation), photos or camera (profile picture, images in chat), notifications (new analysis, messages and reminders), and — if you use it — calendar access to add your fixtures to your own device calendar. Each is requested only when the feature needs it, each can be refused, and each can be switched off later in your device settings without affecting the rest of the app. Notification preferences can also be changed inside the app.
In simple terms
Mic, photos, notifications and calendar are only asked for when a feature needs them, and you can revoke any of them in your phone settings.
14Children
1st Touch is built for professional players and is not directed at children under 16. We do not knowingly collect data from anyone under 16 without the consent of a parent or guardian. If you believe a child has given us data, email andrei@1sttouch.ai and we will delete it.
In simple terms
This is for pros, not for kids under 16.
15Changes to this policy
We update this policy as the product and the law change. The date at the top of the page shows the current version. For material changes we give notice by email or in the app before they take effect.
In simple terms
If this changes in a way that matters, we'll tell you first.
16Contact
Privacy questions and requests: andrei@1sttouch.ai
Everything else: support@1sttouch.ai
First Touch SRL
Str. Sfântul Andrei 58
Chișinău
Republic of Moldova
IDNO 1025600043867
See also our Terms and Conditions and our Refund Policy, which includes a 14-day money-back guarantee.
In simple terms
privacy@1sttouch.ai for anything about your data.