Ana içeriğe atla
IFSCORES logosu
Legal

Privacy Policy

Effective date: 2026-05-27 · Version: 2026-05-27

This Privacy Policy describes how IFSCORES ("we", "us", "our") collects, uses, shares, and safeguards information when you use the IFSCORES mobile application (iOS and Android), the IFSCORES website at https://ifscores.com (the "Landing Page"), and any related services (collectively, the "Service").

By using the Service you acknowledge that you have read and understood this Policy. If you do not agree with any part of it, do not use the Service.

1. Information We Collect

1.1 Information you provide directly

CategoryWhat it containsWhen we collect it
Account credentialsEmail address, password (stored only as a bcrypt hash; we never see your plaintext password), or third-party identifier (Google or Apple subject ID, email returned by the provider)When you register or sign in
Two-factor authenticationOne-time password (TOTP) seed, hashed recovery codesWhen you enable 2FA on your account
Username (public handle)The name you choose to display publicly when you publish content to the in-app marketplace, and to identify you on your profile screen. Optional — you can use most of the Service without a usernameWhen you set one in Settings → Username, or when you first publish a preset publicly
Profile mediaAvatar image you uploadWhen you upload one
Preset contentPreset names, descriptions, condition rules you createWhen you create, clone, or edit presets
AI Preset Draft inputsNatural-language text you type into the AI Preset Draft toolWhen you use the AI Preset Draft feature
FeedbackFree-form messages, star rating, category tagWhen you submit feedback in-app
Verification codes6-digit codes you receive via email to confirm signups, change your email, or reset your passwordWhen you initiate one of those flows

1.2 Information collected automatically

CategoryWhat it containsPurpose
Device dataDevice model, operating system version, app version, locale (language and region), timezone, platform (iOS / Android / Web)Render the correct UI, target push channels, debug crash reports
Push notification tokensFirebase Cloud Messaging or Apple Push Notification Service tokens (per device, up to three active per account)Deliver match-event and system notifications
IP addressCaptured at session creation and stored on your session record; also used by our rate-limit system for short-lived counters in cacheSecurity audit, fraud detection, rate limiting
Approximate geographic regionDerived by Firebase from your device's IP address (we do not request or access GPS or precise location data)Push delivery routing
Usage signalsMatch favorites, preset triggers, notification preferences, quiet hours window, theme, sound toggle, last activity timestampOperate the Service and personalize the experience to your account
Subscription statePlan tier (free / trial / pro), trial start and end dates, RevenueCat customer ID, store-issued transaction IDs (Apple original_transaction_id, Google purchase_token), product ID, billing period dates, currency and amount, refund timestamps, environment (sandbox / production), Family Sharing flagProvide and audit your Pro entitlement; reconcile billing events from the stores
Referral dataYour invite code, redemptions of your code by others, the code you redeemed (if any), redemption timestamps, a SHA-256 hash of your primary device push token at the moment of redemption (used to block self-farming)Operate the referral program
Username moderation recordsInitial username submissions and change requests (current and previous username, requested username, timestamps, reviewing admin, admin notes, decision)Operate the moderation review pipeline and audit decisions

1.3 Information from third-party sign-in providers

When you use Sign in with Google or Sign in with Apple, the provider returns a signed identity token that we verify on our backend. The token contains your provider-issued subject identifier and your email address (Apple users may choose to share a private relay email, which we accept).

We do not receive your Google or Apple account password and we do not gain ongoing access to your provider account.

1.4 Information we do NOT collect

We do not collect:

  • GPS coordinates or precise device location
  • Your contacts, calendar, photos, microphone, or camera content
  • Health, fitness, or biometric data
  • Information about your race, ethnicity, religion, political beliefs, union membership, sexual orientation, or criminal record
  • Browsing history outside the IFSCORES app and Landing Page
  • The contents of your in-app searches (we removed search query logging on 2026-05-27 as a data-minimization measure)
  • Your date of birth (the Service has no in-app age gate; the App Store and Google Play handle age rating at the store level)

2. How We Use Information

We process your information for the following purposes and on the following legal bases under the EU General Data Protection Regulation (GDPR) and the Turkish Personal Data Protection Law (KVKK):

PurposeLegal basis (GDPR Art. 6 / KVKK Art. 5)
Create and operate your accountPerformance of contract
Send transactional emails (verification, password reset, email-change confirmation)Performance of contract
Deliver push notifications you have enabled (match events, preset triggers, kickoff reminders, full-time, half-time)Performance of contract; consent (you can disable any category at any time in Settings)
Process subscription payments through Apple App Store and Google PlayPerformance of contract
Detect and prevent fraud, abuse, and self-farming in the referral and username systemsLegitimate interests (protecting users and our business)
Maintain security, troubleshoot bugs, and review crash reportsLegitimate interests
Comply with legal obligations (tax, KVKK requests, court orders)Legal obligation
Display advertising to non-Pro users via Google AdSenseLegitimate interests, with the ability to opt out of personalized advertising via your device or Google account settings
Run conversion-tracking and marketing analytics on the Landing Page via Facebook Pixel and TikTok PixelConsent (collected via the Landing Page cookie banner)
Process your natural-language input for the AI Preset Draft featurePerformance of contract (you initiate each request); the feature is optional

You may withdraw any consent at any time. Withdrawal does not affect the lawfulness of processing carried out before the withdrawal.

3. Advertising and Cookies

3.1 In-app advertising (mobile)

We display advertisements to free-tier users only through Google AdSense for Mobile. Pro subscribers see no advertising.

AdSense may collect a resettable advertising identifier (Google Advertising ID on Android, IDFA on iOS), interact with your device's "Limit Ad Tracking" / "App Tracking Transparency" settings, and serve personalized or non-personalized ads accordingly.

To opt out of personalized advertising:

  • iOS: Settings → Privacy & Security → Tracking → disable "Allow Apps to Request to Track", or decline the in-app tracking permission prompt
  • Android: Settings → Privacy → Ads → "Delete advertising ID"
  • Google account-wide: https://adssettings.google.com

3.2 Landing Page cookies and tracking pixels

The Landing Page at https://ifscores.com uses cookies for analytics and marketing purposes. See our separate Cookie Policy at https://ifscores.com/cookies for the full list of cookies and their purposes.

Notably, the Landing Page may set:

ProviderPurposeType
Google AdSenseAd serving and personalizationAdvertising / functional
Facebook Pixel (Meta)Conversion tracking, ad attribution, custom audience creationMarketing
TikTok PixelConversion tracking, ad attributionMarketing

A cookie consent banner on the Landing Page allows you to accept or reject non-essential cookies. The mobile app itself does not use cookies; auth tokens are stored in your device's secure keystore (Apple Keychain on iOS, Android Keystore on Android).

4. How We Share Information

We do not sell or rent your personal information. We share it only in the ways described below.

4.1 Sub-processors (service providers that process data on our behalf)

ProviderPurposeRegionData shared
RevenueCat, Inc.Subscription and in-app purchase mediationUnited StatesYour account ID, email, subscription events, transaction IDs, refund events
Google LLC (Firebase Cloud Messaging)Push notification deliveryUnited StatesDevice push tokens, notification payloads (match IDs, preset IDs, event types)
Functional Software, Inc. (Sentry)Crash and error reportingUnited StatesException traces, breadcrumb events, your account ID, app version (PII filtering is enabled by default; 10% of transactions are sampled)
Resend, Inc.Transactional email deliveryUnited StatesRecipient email address, message subject and body
Anthropic PBCAI Preset Draft (Claude API)United StatesThe natural-language prompt you type into the AI Preset Draft tool. Anthropic processes this input under its API terms; by default, Anthropic does not use API inputs to train its models. We do not send your other personal data to Anthropic
Google LLC (AdSense)Mobile advertisingUnited StatesAdvertising identifier, app interaction signals, ad request context
Meta Platforms, Inc. (Facebook Pixel)Landing-page conversion trackingUnited StatesPixel events (page view, sign-up, subscription) as triggered by your interaction with the Landing Page
TikTok Pte. Ltd. (TikTok Pixel)Landing-page conversion trackingUnited States / SingaporePixel events (page view, sign-up) as triggered by your interaction with the Landing Page
Hetzner Online GmbHDatabase, cache, and application hostingGermanyAll personal data stored by the Service (full database)
Cloudflare, Inc.Encrypted database backups (Cloudflare R2)United States / global edgeEncrypted backups containing all stored personal data; 30-day rolling retention

4.2 Third-party identity providers

If you sign in with Google or Apple, those providers operate independently as data controllers for your interaction with their sign-in service. Their policies apply alongside ours:

  • Google: https://policies.google.com/privacy
  • Apple: https://www.apple.com/legal/privacy/

4.3 Sports data provider

The Service uses Live-Score-API.com as the source of all sports, league, and match data. We do not share any personal data with Live-Score-API. Match and team data flows one way: from the provider to us.

4.4 Marketplace and public surfaces

If you choose to publish a preset to the in-app community marketplace, the following information becomes visible to other IFSCORES users:

  • Your username
  • The preset name and description
  • The preset's condition rules

If you do not want this content to be public, do not publish presets to the marketplace. You may withdraw a marketplace submission at any time from the in-app Settings.

4.5 Legal disclosures

We may disclose information when required by law, court order, or governmental request, or when necessary to protect our rights, the rights of users, or the safety of the public.

5. International Data Transfers

Some of our sub-processors are located in the United States. When personal data is transferred outside the European Economic Area or Turkey, we rely on safeguards such as the European Commission's Standard Contractual Clauses (SCCs) and, where applicable, the EU–U.S. Data Privacy Framework.

You may request a copy of these safeguards by contacting us (see Section 12).

6. Retention

We keep personal data only as long as needed for the purposes described in this Policy. Specifically:

Data categoryRetention
Active user accountUntil you request deletion
Account marked for deletion30-day grace period, then permanent deletion. During this grace period your account is hidden but recoverable on sign-in — this protects you from accidental deletion. After 30 days the row is hard-deleted from our database.
Session and refresh tokensUntil expiry or manual revocation; refresh tokens expire 30 days after issue
Push tokensDeactivated automatically when Firebase reports the token as unregistered, or after 90 days of inactivity
Subscription events and webhook logsIndefinite, for billing audit purposes
Database backups (encrypted)30-day rolling window in Cloudflare R2; data from deleted accounts naturally expires from backups within 30 days of deletion
Push notification inboxUp to 90 days (oldest items are cleaned up automatically)
Username moderation recordsIndefinite, for audit purposes
Referral redemption recordsIndefinite, for audit and abuse-prevention purposes
Sentry crash reportsSentry's default retention (typically 90 days)
Resend email logsResend's default retention

After deletion, residual copies may persist in backup snapshots for up to 30 days before they are overwritten.

7. Your Rights

Depending on your jurisdiction, you have some or all of the following rights:

  • Access the personal data we hold about you
  • Correct inaccurate or incomplete data
  • Delete your account and associated data
  • Restrict or object to specific processing
  • Port your data to another service in a structured, machine-readable format
  • Withdraw consent at any time
  • Lodge a complaint with your local supervisory authority (in Turkey, the KVKK Kurulu; in the EU, your national Data Protection Authority)

7.1 How to delete your account

You may delete your account at any time from within the mobile app: Settings → Account → Delete Account. You may also delete from the web at https://ifscores.com/delete-account.

Deletion triggers a 30-day soft-delete grace period (see Section 6). During this window your data is hidden and inaccessible but recoverable if you sign in again. After 30 days, your data is permanently erased from our active database. Backup snapshots containing your data are overwritten within an additional 30 days.

7.2 How to exercise other rights

Contact us at the address in Section 12. We will respond within 30 days (or sooner where required by law).

7.3 Users in Türkiye (KVKK)

If you are located in Türkiye, you have all of the rights enumerated in Article 11 of the Turkish Personal Data Protection Law (Kanun No. 6698). You may exercise these rights by contacting our data controller representative at the address in Section 12.

7.4 Users in the European Economic Area (GDPR)

If you are located in the EEA, the United Kingdom, or Switzerland, you have the rights enumerated in Articles 15 through 22 of the GDPR. You may also lodge a complaint with your national supervisory authority.

7.5 Users in California (CCPA / CPRA)

If you are a California resident, you have the rights enumerated under the California Consumer Privacy Act and the California Privacy Rights Act. We do not sell or share personal information in the sense defined by the CCPA. To exercise CCPA rights, contact us at the address in Section 12.

8. Children

The Service is not directed to children under 13, and we do not knowingly collect personal data from anyone under 13. The mobile app store age rating (set by Apple and Google) reflects the recommended minimum age.

If you believe a child under 13 has provided us with personal data, please contact us at privacy@ifscores.com and we will delete the account promptly.

9. Security

We implement industry-standard administrative, technical, and physical safeguards including:

  • TLS 1.2+ encryption for all data in transit
  • Encryption at rest for database backups
  • bcrypt password hashing
  • Optional two-factor authentication for accounts
  • Atomic claim and rate-limit primitives in the database to prevent race conditions and abuse
  • A 24-hour Redis dedup layer plus a persistent per-favorite database claim to prevent duplicate notifications
  • Separate moderation queue for user-submitted content (presets, usernames) before public exposure
  • Regular dependency security audits

No method of transmission or storage is 100% secure. If we become aware of a personal data breach affecting your account, we will notify you and the relevant supervisory authority as required by applicable law.

10. AI Processing

The Service includes an AI Preset Draft feature that converts a natural-language description (typed by you) into a structured preset rule. The text you submit is sent to Anthropic's Claude API for processing.

  • The AI feature is optional. You can use the rest of the Service without ever invoking it.
  • Anthropic processes your input under its API terms. As of the effective date of this Policy, Anthropic states that it does not use API inputs to train its public models by default. See Anthropic's privacy policy at https://www.anthropic.com/legal/privacy.
  • We do not send your account ID, email, subscription state, or other personal identifiers to Anthropic — only the natural-language string you typed.
  • The AI generates a structured preset suggestion. You can accept, edit, or reject the suggestion. No decision with legal or similarly significant effects on you is made by the AI; you remain in full control of whether to save the resulting preset.

11. Changes to This Policy

We may update this Policy from time to time. When we do, we will:

  • Update the version date at the top of this document
  • Notify active users via an in-app screen on next launch (the "Legal Acceptance" modal) that prompts for fresh acceptance before continuing to use the Service
  • Keep the version-acceptance log per user so we have a record of which policy version each user agreed to and when

Material changes (such as new categories of data, new sub-processors, or new sharing purposes) will be highlighted in the in-app notification.

12. Contact

Data Controller: IFSCORES

Contact email: privacy@ifscores.com

Support: support@ifscores.com

For users in Türkiye, this address also serves as the contact for KVKK requests.

For users in the EEA, please use the same address for GDPR requests.

We will respond to all rights requests within 30 days, except in cases where applicable law sets a different deadline.