Privacy Policy
GTA 6 Hub, operated by Meenflow, is committed to protecting its users' privacy in accordance with the General Data Protection Regulation (GDPR) and the French Data Protection Act (loi Informatique et Libertés).
This policy applies to the GTA 6 Hub website and to the VI Hub mobile app, available on iOS and Android.
Data controller
Company: Meenflow
Country: France
Email: contact@gta6hub.fr
Data we collect
Data you provide:
- Username
- Email address
- Encrypted password
- Profile photo, if you add one
- Published content: posts, comments, images, contributions
Data collected automatically:
- IP address
- Browser type and device used
- Pages visited and time spent
- Date and time of sign-in
- Technical data required for site security
Data received through third-party services:
- Discord OAuth: Discord ID, username, email if authorised
- Google OAuth: Google ID, name, email
- Sign in with Apple: Apple ID, name and email if you choose to share them
- X OAuth: X ID, username, display name, email if authorised
- Twitch OAuth: Twitch ID, username, email if authorised
- Apple (Apple Push Notification service): the device's notification identifier, when notifications are enabled in the iOS app
- Google (Firebase Cloud Messaging): the device's notification identifier, when notifications are enabled in the Android app
- xAI: questions asked to the Cal assistant are sent to xAI to produce an answer
- Google Analytics: audience measurement data, only if this service is enabled and subject to your consent where required
Mobile app
In addition to the data above, the VI Hub app collects and stores:
- A notification identifier issued by the operating system (Apple on iOS, Google Firebase on Android), linked to your account or, for a signed-out visitor who accepted announcements, to the device only, in order to deliver notifications. It is withdrawn when notifications are turned off, when you sign out or when the app is uninstalled, and erased from our servers within seven days at most.
- An installation identifier, specific to the app on this device and unrelated to your identity (vendor identifier on iOS, Firebase installation ID on Android). It is used to recognise the device, replace an older notification registration and troubleshoot delivery issues with support. It is shown in the app settings.
- The app version and display language, so that content and notifications are delivered in the right language.
- Session credentials, kept in the operating system's secure storage and never shared with third parties.
- Local preferences, such as the chosen theme, the language, accepted announcements or the list of hidden members, stored on the device only.
- A cache of images and of public content you have already viewed (home, articles, topics, wiki pages), used to speed up display and allow offline reading. It is kept on the device for at most seven days and cleared on uninstall. Private content, such as messaging, is never cached.
Event reminders are scheduled locally on the device and do not go through our servers. Adding an event to your calendar happens in the phone's Calendar app, with your approval at that moment.
Questions asked to the Cal assistant are sent to xAI, a provider located in the United States, for the sole purpose of producing an answer. They are not used to identify you. This transfer is covered by the safeguards described in the "Data transfers" section.
The app does not use browsing cookies. When a full page of the website is opened from the app, the website's cookie rules apply to that browsing.
Purposes
Your data is used to:
- Create and manage your user account
- Let you take part in the community
- Send you the notifications you have enabled: private messages, replies, mentions, announcements
- Keep the site secure and prevent abuse
- Improve our services and the user experience
- Contact you when needed: support, important notices, account security
Legal basis
- Performance of a contract: managing your account and giving access to the services
- Legitimate interest: site security, abuse prevention, service improvement
- Consent: notifications, non-essential cookies, audience measurement, newsletter where applicable
- Legal obligation: retaining certain information where the law requires it
Retention
Active account: for as long as the account is active
Inactive account: up to 3 years after the last sign-in
Notification identifiers: while notifications are enabled, then at most 7 days after they are turned off, after sign-out or after uninstall
Security logs: up to 12 months
Website audience measurement with Google Analytics 4: detailed event data is retained for 2 months; user data is retained for 14 months, reset on new activity. These periods do not apply to aggregated statistical reports. Newly created analytics cookies are configured to expire after at most 13 months, without automatic renewal on each visit. Older cookies may retain their previous expiry until they expire or are removed.
GDPR requests: as long as needed to handle the request and evidence its handling
Data sharing
Your data is never sold. It may be shared only with the providers needed to run the service:
- Hostinger: hosting and data storage
- Discord, Google, Apple, X and Twitch: authentication when you use these services
- Apple: delivery of notifications to iOS devices
- Google (Firebase Cloud Messaging): delivery of notifications to Android devices
- xAI: processing of questions sent to the Cal assistant, in the United States
- Google Analytics: audience measurement, only if the service is enabled and subject to the required consent
- Competent authorities: only where the law requires it
Your rights
Under the GDPR you have the following rights:
- Right of access: obtain a copy of your data
- Right to rectification: correct inaccurate data
- Right to erasure: request deletion of your data
- Right to portability: receive your data in a readable format
- Right to object: object to certain processing
- Right to restriction: restrict the processing of your data
- Right to withdraw your consent to notifications at any time, from the app or phone settings
To exercise your rights, contact us at: contact@gta6hub.fr
You may also lodge a complaint with the CNIL, the French data protection authority: www.cnil.fr
Data security
We implement technical and organisational measures to protect your data:
- Password encryption
- Secure HTTPS connection
- Restricted access to personal data
- Regular backups
- Measures against abuse and unauthorised access
- In the app, a notification is only displayed if the device is confirmed as belonging to the recipient account; an account's notifications are removed on sign-out
Data transfers
Some data may be processed by providers located outside the European Union, in particular through third-party services or technical tools. Where necessary, these transfers are covered by appropriate safeguards, notably the European Commission's standard contractual clauses or any other mechanism recognised by applicable law.
Last updated: September 2026
Third Parties
Spam Defense
The IPS Spam Defense Service passes the email address and IP address of the registering member to the service to determine the likelihood a registering account is a spam source.