Privacy Policy
Overview
This Privacy Policy explains what data WeMillion (“the App”) collects, how it is used, and your rights as a user. We are committed to collecting the minimum data necessary to operate the App.
Data Controller
Félix Thiollier
38 avenue des Ternes, 75017 Paris, France
felixthiollier63@gmail.com
Data We Collect
3.1 — Data you provide
- None by default. Neither the App nor the Website has a sign-in step, and neither asks you for anything in order to join. A silent anonymous Firebase Authentication session is created on your device or in your browser, which yields a random identifier with no link to your identity. We never receive your name, email address, or Apple identifier.
- One exception, only if you choose it. On the Website you may optionally link your anonymous session to a Google account (Settings → “Save my account”) so that you can recover your number on another device. If — and only if — you do this, we receive the email address of that Google account and store it against your record. Joining and paying never require it.
3.2 — Approximate location (derived, not provided)To place you on the world map and in the country ranking, a third-party geolocation service converts your IP address into an approximate country and city. In the App this happens on your device. On the Website it happens on our server at the moment you start a payment, because a browser cannot perform that lookup itself; your IP address is sent to the service at that moment. Either way we do not store your IP address — only the resulting country and city name are saved. Neither the App nor the Website ever requests your device's GPS location.
3.3 — Data we store (Firestore database)For each participant we store only:
- userNumber: your unique numbered position (e.g. 4,726,319)
- amountUSD: the total you have contributed, in whole dollars
- paidAt: timestamp of your payment
- countryCode: ISO 3166-1 alpha-2 code (e.g. “FR”), derived as described in 3.2
- cityName: the name of the nearest city, derived as described in 3.2. You can change or clear it at any time from the profile screen.
We do NOT store your name, email address, phone number, Apple ID, payment card details, IP address, or device identifiers.
3.4 — Data shown publiclyTwo screens display participation publicly, and both are visible only to participants who have joined:
- Live feed: recent events, each showing a registry number, a country flag and, for an additional contribution, its amount.
- Top Users: a ranking of the largest contributors, showing registry number, country and total amount.
Neither display includes your name, email address, city, or any identifier. Your registry number is already public by design — it is the whole point of the App — but be aware that a large contribution makes that number visible alongside its amount. If you do not want this, do not make additional contributions.
3.5 — Aggregate data
- A global counter (totalPaid, todayCount) and per-country and per-city counters are maintained. These count dollars, not people, and contain no personal data.
3.6 — Transaction data
- Apple's StoreKit 2 transaction ID is stored server-side for idempotency (to prevent double-counting). It is not linked to your identity beyond your Firebase UID.
3.7 — Authentication tokens
- Firebase Auth ID tokens are used to authenticate requests between the App and the backend. They are stored in the iOS Keychain and are never written to UserDefaults or any unprotected storage.
3.8 — Website audience measurementThe Website uses Cloudflare Web Analytics to count how many people visit it. It sets no cookies, stores nothing on your device, and uses no fingerprinting or any other identifier that would let us recognise you between visits or follow you across other websites. It records only aggregate, non-identifying signals about each page load: the page viewed, the referring site, an approximate country, and browser and device type. No individual can be identified from it, and it is never combined with your registry record. The App does not use it.
Data We Do Not Collect
- We do not use advertising SDKs, and the App uses no analytics at all. The Website uses one privacy-preserving audience measurement tool, described in 3.8, which sets no cookies and builds no profile of you.
- We do not use advertising, analytics or tracking cookies, and we do not track you across other websites.
- The Website does use strictly necessary browser storage: Firebase Authentication keeps your anonymous session so your number stays attached to you, and Stripe sets its own cookies on the payment step for fraud prevention. Neither is used for advertising or profiling.
- We do not collect device identifiers (IDFA, IDFV).
- We do not access your contacts, photos, camera, microphone, or location.
How We Use Your Data
| Purpose | Legal basis (GDPR) |
|---|---|
| Assigning your unique numbered position | Performance of contract (Art. 6(1)(b)) |
| Preventing double-counting (idempotency) | Legitimate interest (Art. 6(1)(f)) |
| Displaying real-time global and country counters | Legitimate interest (Art. 6(1)(f)) |
Data Sharing
We do not sell, rent, or share your personal data with third parties for marketing or advertising purposes.
We use the following sub-processors solely to operate the App and the Website:
- Apple Inc. — App Store payment processing and receipt validation. Apple's Privacy Policy: apple.com/legal/privacy
- Google LLC / Firebase — Cloud database (Firestore), anonymous Authentication and Cloud Functions. Firebase's Privacy Policy: firebase.google.com/support/privacy
- Stripe Payments Europe, Ltd. — payment processing for purchases made on the website (wemillion.world), including card, Apple Pay and Google Pay. Stripe receives your payment details directly; we never see or store your card number. Stripe also receives the country your payment is associated with. Stripe's Privacy Policy: stripe.com/privacy
- ip-api.com — IP-to-location lookup used to derive the approximate country and city described in 3.2. Your IP address is sent to this service by your device at the moment of the lookup and is not stored by us. Their Privacy Policy: ip-api.com/docs/legal
- Cloudflare, Inc. — privacy-preserving audience measurement on the Website, as described in 3.8. Cloudflare Web Analytics is cookieless and does not build cross-site profiles. Their Privacy Policy: cloudflare.com/privacypolicy
These sub-processors are subject to Standard Contractual Clauses (SCCs) for any data transfers outside the European Economic Area.
Data Retention
Your user record (userNumber, amountUSD, paidAt, countryCode, cityName) is retained indefinitely as it forms the permanent historical registry of participants. If you request deletion (see Section 9), we will delete your record and you will disappear from the public contributors list, but note that the totalPaid counter will not be decremented — your numbered position will simply become unoccupied.
Transaction IDs (idempotency records) are retained for 5 years for fraud-prevention purposes.
Security
- All communication between the App and backend uses HTTPS/TLS.
- Payment verification is performed server-side using cryptographic JWS signature verification against Apple's Root CA G3. The client never decides the outcome of a payment.
- Firestore Security Rules prevent clients from writing to sensitive collections (/stats/global, /countries/*, /users/*).
- Authentication tokens are stored in the iOS Keychain.
Your Rights (GDPR / French Law)
If you are located in the European Economic Area, you have the following rights:
- Right of access: request a copy of the data we hold about you.
- Right to rectification: request correction of inaccurate data.
- Right to erasure (“right to be forgotten”): request deletion of your data.
- Right to restriction of processing.
- Right to data portability.
- Right to object to processing based on legitimate interest.
To exercise any of these rights, contact us at felixthiollier63@gmail.com. We will respond within 30 days.
You also have the right to lodge a complaint with the French data protection authority: Commission Nationale de l'Informatique et des Libertés (CNIL) — cnil.fr
Children's Privacy
The App is not directed at children under 13. We do not knowingly collect data from children under 13. If you believe a child has used the App, contact us and we will delete the relevant data.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes through the App. The date at the top of this document indicates when it was last revised.
Contact
Félix Thiollier
38 avenue des Ternes, 75017 Paris, France
felixthiollier63@gmail.com
