Privacy Policy
Effective date: 2026-05-27 · Version: 2026-05-27
This Privacy Policy describes how IFSCORES ("we", "us", "our") collects, uses, shares, and safeguards information when you use the IFSCORES mobile application (iOS and Android), the IFSCORES website at https://ifscores.com (the "Landing Page"), and any related services (collectively, the "Service").
By using the Service you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, do not use the Service.
1. Information We Collect
1.1 Information you provide directly
| Category | What it contains | When we collect it |
|---|---|---|
| Account credentials | Email address, password (stored only as a bcrypt hash; we never see your plaintext password), or third-party identifier (Google or Apple subject ID, email returned by the provider) | When you register or sign in |
| Two-factor authentication | One-time password (TOTP) seed, hashed recovery codes | When you enable 2FA on your account |
| Username (public handle) | The name you choose to display publicly when you publish content to the in-app marketplace, and to identify you on your profile screen. Optional — you can use most of the Service without a username | When you set one in Settings → Username, or when you first publish a preset publicly |
| Profile media | Avatar image you upload | When you upload one |
| Preset content | Preset names, descriptions, condition rules you create | When you create, clone, or edit presets |
| AI Preset Draft inputs | Natural-language text you type into the AI Preset Draft tool | When you use the AI Preset Draft feature |
| Feedback | Free-form messages, star rating, category tag | When you submit feedback in-app |
| Verification codes | 6-digit codes you receive via email to confirm signups, change your email, or reset your password | When you initiate one of those flows |
1.2 Information collected automatically
| Category | What it contains | Purpose |
|---|---|---|
| Device data | Device model, operating system version, app version, locale (language and region), timezone, platform (iOS / Android / Web) | Render the correct UI, target push channels, debug crash reports |
| Push notification tokens | Firebase Cloud Messaging or Apple Push Notification Service tokens (per device, up to three active per account) | Deliver match-event and system notifications |
| IP address | Captured at session creation and stored on your session record; also used by our rate-limit system for short-lived counters in cache | Security audit, fraud detection, rate limiting |
| Approximate geographic region | Derived by Firebase from your device's IP address (we do not request or access GPS or precise location data) | Push delivery routing |
| Usage signals | Match favorites, preset triggers, notification preferences, quiet hours window, theme, sound toggle, last activity timestamp | Operate the Service and personalize the experience to your account |
| Subscription state | Plan tier (free / trial / pro), trial start and end dates, RevenueCat customer ID, store-issued transaction IDs (Apple original_transaction_id, Google purchase_token), product ID, billing period dates, currency and amount, refund timestamps, environment (sandbox / production), Family Sharing flag | Provide and audit your Pro entitlement; reconcile billing events from the stores |
| Referral data | Your invite code, redemptions of your code by others, the code you redeemed (if any), redemption timestamps, a SHA-256 hash of your primary device push token at the moment of redemption (used to block self-farming) | Operate the referral program |
| Username moderation records | Initial username submissions and change requests (current and previous username, requested username, timestamps, reviewing admin, admin notes, decision) | Operate the moderation review pipeline and audit decisions |
1.3 Information from third-party sign-in providers
When you use Sign in with Google or Sign in with Apple, the provider returns a signed identity token that we verify on our backend. The token contains your provider-issued subject identifier and your email address (Apple users may choose to share a private relay email, which we accept).
We do not receive your Google or Apple account password and we do not gain ongoing access to your provider account.
1.4 Information we do NOT collect
We do not collect:
- GPS coordinates or precise device location
- Your contacts, calendar, photos, microphone, or camera content
- Health, fitness, or biometric data
- Information about your race, ethnicity, religion, political beliefs, union membership, sexual orientation, or criminal record
- Browsing history outside the IFSCORES app and Landing Page
- The contents of your in-app searches (we removed search query logging on 2026-05-27 as a data-minimization measure)
- Your date of birth (the Service has no in-app age gate; the App Store and Google Play handle age rating at the store level)
2. How We Use Information
We process your information for the following purposes and on the following legal bases under the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK):
| Purpose | Legal basis (GDPR Art. 6 / KVKK Art. 5) |
|---|---|
| Create and operate your account | Performance of contract |
| Send transactional emails (verification, password reset, email-change confirmation) | Performance of contract |
| Deliver push notifications you have enabled (match events, preset triggers, kickoff reminders, full-time, half-time) | Performance of contract; consent (you can disable any category at any time in Settings) |
| Process subscription payments through Apple App Store and Google Play | Performance of contract |
| Detect and prevent fraud, abuse, and self-farming in the referral and username systems | Legitimate interests (protecting users and our business) |
| Maintain security, troubleshoot bugs, and review crash reports | Legitimate interests |
| Comply with legal obligations (tax, KVKK requests, court orders) | Legal obligation |
| Display advertising to non-Pro users via Google AdSense | Legitimate interests, with the ability to opt out of personalized advertising via your device or Google account settings |
| Run conversion-tracking and marketing analytics on the Landing Page via Facebook Pixel and TikTok Pixel | Consent (collected via the Landing Page cookie banner) |
| Process your natural-language input for the AI Preset Draft feature | Performance of contract (you initiate each request); the feature is optional |
You may withdraw any consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.
3. Advertising and Cookies
3.1 In-app advertising (mobile)
We display advertisements to free-tier users only through Google AdSense for Mobile. Pro subscribers see no advertising.
AdSense may collect a resettable advertising identifier (Google Advertising ID on Android, IDFA on iOS), interact with your device's "Limit Ad Tracking" / "App Tracking Transparency" settings, and serve personalized or non-personalized ads accordingly.
To opt out of personalized advertising:
- iOS: Settings → Privacy & Security → Tracking → disable "Allow Apps to Request to Track", or decline the in-app tracking permission prompt
- Android: Settings → Privacy → Ads → "Delete advertising ID"
- Google account-wide: https://adssettings.google.com
3.2 Landing Page cookies and tracking pixels
The Landing Page at https://ifscores.com uses cookies for analytics and marketing purposes. See our separate Cookie Policy at https://ifscores.com/cookies for the full list of cookies and their purposes.
Notably, the Landing Page may set:
| Provider | Purpose | Type |
|---|---|---|
| Google AdSense | Ad serving and personalization | Advertising / functional |
| Facebook Pixel (Meta) | Conversion tracking, ad attribution, custom audience creation | Marketing |
| TikTok Pixel | Conversion tracking, ad attribution | Marketing |
A cookie consent banner on the Landing Page allows you to accept or reject non-essential cookies. The mobile app itself does not use cookies; auth tokens are stored in your device's secure keystore (Apple Keychain on iOS, Android Keystore on Android).
4. How We Share Information
We do not sell or rent your personal information. We share it only in the ways described below.
4.1 Sub-processors (service providers that process data on our behalf)
| Provider | Purpose | Region | Data shared |
|---|---|---|---|
| RevenueCat, Inc. | Subscription and in-app purchase mediation | United States | Your account ID, email, subscription events, transaction IDs, refund events |
| Google LLC (Firebase Cloud Messaging) | Push notification delivery | United States | Device push tokens, notification payloads (match IDs, preset IDs, event types) |
| Functional Software, Inc. (Sentry) | Crash and error reporting | United States | Exception traces, breadcrumb events, your account ID, app version (PII filtering is enabled by default; 10% of transactions are sampled) |
| Resend, Inc. | Transactional email delivery | United States | Recipient email address, message subject and body |
| Anthropic PBC | AI Preset Draft (Claude API) | United States | The natural-language prompt you type into the AI Preset Draft tool. Anthropic processes this input under its API terms; by default, Anthropic does not use API inputs to train its models. We do not send your other personal data to Anthropic |
| Google LLC (AdSense) | Mobile advertising | United States | Advertising identifier, app interaction signals, ad request context |
| Meta Platforms, Inc. (Facebook Pixel) | Landing-page conversion tracking | United States | Pixel events (page view, sign-up, subscription) as triggered by your interaction with the Landing Page |
| TikTok Pte. Ltd. (TikTok Pixel) | Landing-page conversion tracking | United States / Singapore | Pixel events (page view, sign-up) as triggered by your interaction with the Landing Page |
| Hetzner Online GmbH | Database, cache, and application hosting | Germany | All personal data stored by the Service (full database) |
| Cloudflare, Inc. | Encrypted database backups (Cloudflare R2) | United States / global edge | Encrypted backups containing all stored personal data; 30-day rolling retention |
4.2 Third-party identity providers
If you sign in with Google or Apple, those providers operate independently as data controllers for your interaction with their sign-in service. Their policies apply alongside ours:
- Google: https://policies.google.com/privacy
- Apple: https://www.apple.com/legal/privacy/
4.3 Sports data provider
The Service uses Live-Score-API.com as the source of all sports, league, and match data. We do not share any personal data with Live-Score-API. Match and team data flows one way: from the provider to us.
4.4 Marketplace and public surfaces
If you choose to publish a preset to the in-app community marketplace, the following information becomes visible to other IFSCORES users:
- Your username
- The preset name and description
- The preset's condition rules
If you do not want this content to be public, do not publish presets to the marketplace. You may withdraw a marketplace submission at any time from the in-app Settings.
4.5 Legal disclosures
We may disclose information when required by law, court order, or governmental request, or when necessary to protect our rights, the rights of users, or the safety of the public.
5. International Data Transfers
Some of our sub-processors are located in the United States. When personal data is transferred outside the European Economic Area or Turkey, we rely on safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–U.S. Data Privacy Framework.
You may request a copy of these safeguards by contacting us (see Section 12).
6. Retention
We keep personal data only as long as needed for the purposes described in this Policy. Specifically:
| Data category | Retention |
|---|---|
| Active user account | Until you request deletion |
| Account marked for deletion | 30-day grace period, then permanent deletion. During this grace period your account is hidden but recoverable on sign-in — this protects you from accidental deletion. After 30 days the row is hard-deleted from our database. |
| Session and refresh tokens | Until expiry or manual revocation; refresh tokens expire 30 days after issue |
| Push tokens | Deactivated automatically when Firebase reports the token as unregistered, or after 90 days of inactivity |
| Subscription events and webhook logs | Indefinite, for billing audit purposes |
| Database backups (encrypted) | 30-day rolling window in Cloudflare R2; data from deleted accounts naturally expires from backups within 30 days of deletion |
| Push notification inbox | Up to 90 days (oldest items are cleaned up automatically) |
| Username moderation records | Indefinite, for audit purposes |
| Referral redemption records | Indefinite, for audit and abuse-prevention purposes |
| Sentry crash reports | Sentry's default retention (typically 90 days) |
| Resend email logs | Resend's default retention |
After deletion, residual copies may persist in backup snapshots for up to 30 days before they are overwritten.
7. Your Rights
Depending on your jurisdiction, you have some or all of the following rights:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Delete your account and associated data
- Restrict or object to specific processing
- Port your data to another service in a structured, machine-readable format
- Withdraw consent at any time
- Lodge a complaint with your local supervisory authority (in Turkey, the KVKK Kurulu; in the EU, your national Data Protection Authority)
7.1 How to delete your account
You may delete your account at any time from within the mobile app: Settings → Account → Delete Account. You may also delete from the web at https://ifscores.com/delete-account.
Deletion triggers a 30-day soft-delete grace period (see Section 6). During this window your data is hidden and inaccessible but recoverable if you sign in again. After 30 days, your data is permanently erased from our active database. Backup snapshots containing your data are overwritten within an additional 30 days.
7.2 How to exercise other rights
Contact us at the address in Section 12. We will respond within 30 days (or sooner where required by law).
7.3 Users in Türkiye (KVKK)
If you are located in Türkiye, you have all of the rights enumerated in Article 11 of the Turkish Personal Data Protection Law (Kanun No. 6698). You may exercise these rights by contacting our data controller representative at the address in Section 12.
7.4 Users in the European Economic Area (GDPR)
If you are located in the EEA, the United Kingdom, or Switzerland, you have the rights enumerated in Articles 15 through 22 of the GDPR. You may also lodge a complaint with your national supervisory authority.
7.5 Users in California (CCPA / CPRA)
If you are a California resident, you have the rights enumerated under the California Consumer Privacy Act and the California Privacy Rights Act. We do not sell or share personal information in the sense defined by the CCPA. To exercise CCPA rights, contact us at the address in Section 12.
8. Children
The Service is not directed to children under 13, and we do not knowingly collect personal data from anyone under 13. The mobile app store age rating (set by Apple and Google) reflects the recommended minimum age.
If you believe a child under 13 has provided us with personal data, please contact us at privacy@ifscores.com and we will delete the account promptly.
9. Security
We implement industry-standard administrative, technical, and physical safeguards including:
- TLS 1.2+ encryption for all data in transit
- Encryption at rest for database backups
- bcrypt password hashing
- Optional two-factor authentication for accounts
- Atomic claim and rate-limit primitives in the database to prevent race conditions and abuse
- A 24-hour Redis dedup layer plus a persistent per-favorite database claim to prevent duplicate notifications
- Separate moderation queue for user-submitted content (presets, usernames) before public exposure
- Regular dependency security audits
No method of transmission or storage is 100% secure. If we become aware of a personal data breach affecting your account, we will notify you and the relevant supervisory authority as required by applicable law.
10. AI Processing
The Service includes an AI Preset Draft feature that converts a natural-language description (typed by you) into a structured preset rule. The text you submit is sent to Anthropic's Claude API for processing.
- The AI feature is optional. You can use the rest of the Service without ever invoking it.
- Anthropic processes your input under its API terms. As of the effective date of this Policy, Anthropic states that it does not use API inputs to train its public models by default. See Anthropic's privacy policy at https://www.anthropic.com/legal/privacy.
- We do not send your account ID, email, subscription state, or other personal identifiers to Anthropic — only the natural-language string you typed.
- The AI generates a structured preset suggestion. You can accept, edit, or reject the suggestion. No decision with legal or similarly significant effects on you is made by the AI; you remain in full control of whether to save the resulting preset.
11. Changes to This Policy
We may update this Policy from time to time. When we do, we will:
- Update the version date at the top of this document
- Notify active users via an in-app screen on next launch (the "Legal Acceptance" modal) that prompts for fresh acceptance before continuing to use the Service
- Keep the version-acceptance log per user so we have a record of which policy version each user agreed to and when
Material changes (such as new categories of data, new sub-processors, or new sharing purposes) will be highlighted in the in-app notification.
12. Contact
Data Controller: IFSCORES
Contact email: privacy@ifscores.com
Support: support@ifscores.com
For users in Türkiye, this address also serves as the contact for KVKK requests.
For users in the EEA, please use the same address for GDPR requests.
We will respond to all rights requests within 30 days, except in cases where applicable law sets a different deadline.