Privacy Policy

Article 1 (Scope)

This Privacy Policy describes how FootyDeck (hereinafter "the Service") handles user personal information and data. Users must agree to this policy before using the Service.

Article 2 (Personal Information Collected)

The Service collects the following personal information for account registration and authentication:

  • Email address (obtained from authentication providers via Apple Sign-In or Google Sign-In)
  • Display name (obtained from authentication providers; not collected if the user chooses to hide it via Apple Sign-In)
  • User identifier (a unique ID automatically generated by Firebase Authentication)
  • Anonymous account identifier (before registering via Apple/Google Sign-In, an anonymous account is automatically created with an auto-generated user identifier. This identifier is used for credit management, fraud prevention, and other purposes)

Article 3 (Technical Information Collected)

The Service collects the following technical information for security, fraud prevention, and advertising purposes:

  • IP address (recorded in audit logs during API requests)
  • Device identifier (transmitted to the server for fraud prevention and rate limiting purposes. Only a SHA-256 irreversible hash of the device ID is permanently stored on the server; the original device ID is not stored)
  • Advertising identifier (IDFA) (collected only with user consent via App Tracking Transparency for personalized advertising and ad performance measurement)

Article 4 (Purchase Information Collected)

When using in-app purchases, the following purchase information is stored on our servers:

  • Product ID of the purchased item (type of credit pack)
  • Transaction ID (a transaction identifier issued by the Apple App Store)
  • Credit transaction history (records of purchases, consumption, and refunds)
  • Webhook event data associated with purchase processing (full purchase notification data received via RevenueCat)

Article 5 (Third-Party Services)

The Service uses the following third-party services, and data is handled in accordance with each service's privacy policy:

Firebase Authentication (Google LLC)

User authentication (Apple Sign-In / Google Sign-In)

Email address, display name, authentication provider information

https://firebase.google.com/support/privacy

RevenueCat, Inc.

In-app purchase processing and management

User identifier, purchase transaction information

https://www.revenuecat.com/privacy/

OpenAI, Inc.

AI card creation (player and manager), squad analysis, and generation of explanations

For AI card creation (player and manager), the entered name is included in the message sent. The name is used to determine whether it identifies a widely known football-related person. If it does, the Service creates an entertainment analysis based on public information; otherwise, it creates a fictional profile from a server-owned creative seed. Accuracy is not guaranteed. For squad analysis, we send server-issued opaque subject/entity tokens, creative seeds, entity IDs, positions, abilities, ratings, language, formation, and non-identifying tactical context needed for analysis, and squad and card names are not sent (email addresses, authentication IDs, and purchase information are not sent for either feature)

https://openai.com/policies/privacy-policy/

Google AdMob (Google LLC)

In-app advertising (banner ads; ad-based credit rewards are not currently offered)

Advertising identifier (IDFA), ad display and interaction data, device information

https://policies.google.com/privacy

Apple Inc.

App distribution and in-app purchase processing

Purchase transaction information

https://www.apple.com/legal/privacy/

Article 6 (Purpose of Use)

Collected information is used for the following purposes:

  • User authentication and account management
  • In-app purchase processing and credit balance management
  • Providing AI card creation and squad analysis features (using the entered name to determine whether to create a public-information-based analysis of a widely known football-related person or a fictional profile)
  • Displaying advertisements and measuring ad performance (banner ads via Google AdMob)
  • Fraud detection and prevention (e.g., preventing duplicate promotional-reward grants via device hash)
  • Recording audit logs for service operation, maintenance, and improvement

Article 7 (Data Storage and Security)

Player cards, manager cards, and squad data generated by users are stored in the device's local storage. Account information, credit balances, transaction history, and the following AI-processing data are stored in the Service's PostgreSQL database. All communications are encrypted via HTTPS, and API access requires authentication via Firebase ID Token. For troubleshooting purposes, diagnostic information such as error logs, device platform, and app version may be stored in the device's local storage (retained for 30 days, not transmitted externally).

  • AI request data stored by the Service: Entered person names, player, manager, and squad information, language, pre-transformation data, and request and operation identifiers. For player and manager card creation, the entered person name is included in the message sent to OpenAI. For squad analysis and recommendations, squad and card names are removed and replaced with the necessary non-identifying data, including opaque tokens, creative seeds, entity IDs, positions, abilities, ratings, language, and formation
  • AI upstream response data: Generated content returned by OpenAI, model, processing status, error information, token usage, and estimated or actual cost
  • AI results and narratives: Validated player, manager, and squad analyses, recommendations, and explanatory narratives
  • Purposes: Delivering analysis, safe retries, preventing duplicate charges, issuing credit refunds, quality and fraud investigations, and auditing AI costs and usage limits

Article 8 (Data Retention and Post-Deletion Handling)

The content of AI requests, upstream responses, and narratives, together with detailed error messages, is retained for 30 days by default after processing is completed or failed, and is then deleted or redacted. Pending records are retained until they reach a completed or failed state. Metadata such as request IDs, operation IDs, payload hashes, status, model, token usage, and cost is retained as needed for billing integrity, fraud prevention, usage-limit enforcement, and auditing. When account deletion completes, user-identifying in-app data, including these AI records, is deleted. Some records are retained in anonymized or pseudonymized form for purchase integrity, fraud prevention, security, and legal compliance. The operational setting may shorten the default 30-day AI-content period; we will update this Policy before extending it.

Data deleted:

  • User account information (app_users)
  • Wallet balance (wallet_balances)
  • Credit transaction history (ledger_entries)
  • AI request content, OpenAI response content, AI results and narratives, and user-linked AI processing and cost metadata
  • Firebase Authentication account

Data retained:

  • Purchase transaction records: Account identifiers are pseudonymized and records are retained as needed for transaction integrity, duplicate-grant prevention, and legal compliance
  • Webhook event records: Account identifiers are pseudonymized and payloads are replaced with a deletion marker, then retained as needed for transaction auditing
  • Audit logs (audit_logs): Account identifiers are pseudonymized, IP addresses and details are removed, and records are normally retained for 3 years or up to 10 years when required for legal compliance or security
  • Device hash records for historical promotional rewards (welcome_bonus_grants): Retained indefinitely for fraud prevention purposes
  • Ad-reward duplicate prevention records and external transaction matching records: Account identifiers are pseudonymized and records are retained indefinitely for fraud prevention
  • Account deletion completion records: Account identifiers are pseudonymized and records are retained as needed to prove deletion processing and prevent duplicate processing

Article 9 (Account Deletion)

Users can request account deletion at any time from the in-app Settings screen. The request is persisted in a server-side processing queue and retried in the background if deletion from RevenueCat or Firebase Authentication cannot complete immediately. Billing and AI use are blocked while processing, and users are instructed not to sign in again or make purchases until deletion completes. After completion, server data is deleted or pseudonymized as described in Article 8, and cards, squads, analysis results, and images stored locally on the device are also deleted. If a network or provider error prevents completion, the app reports that deletion is still processing rather than reporting it as complete.

Article 10 (Children's Privacy)

This Service is not intended for children under 13. Users who are 13 or older but have not reached the legal age to consent to personal-data processing in their region may not use the Service. The Service does not currently provide a mechanism to obtain or verify parental consent. If we learn that personal information was provided by a child who does not meet these requirements, we will promptly delete it.

Article 11 (Your Rights)

Under applicable data protection laws (including APPI and GDPR), you have the following rights regarding your personal data. To exercise these rights, please contact us at info@tkgshoyu.jp.

  • Right of access: The right to request disclosure of your personal data held by the Service
  • Right to rectification: The right to request correction of inaccurate personal data
  • Right to erasure: The right to request deletion of your personal data (also available via the in-app account deletion feature)
  • Right to restrict processing: The right to request restriction of processing of your personal data under certain circumstances
  • Right to data portability: The right to receive your personal data in a structured, commonly used, machine-readable format
  • Right to object: The right to object to processing based on legitimate interests
  • Right to withdraw consent: The right to withdraw consent at any time for processing based on consent

Article 12 (International Data Transfers)

Your data may be transferred to and processed in countries outside of Japan, including the United States. The third-party services listed in Article 5 process data at their respective server locations. The Service ensures that appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

Article 13 (Privacy Policy Changes)

The Service may update this Privacy Policy as necessary. For material changes, we will notify users via in-app notification at least 14 days before the effective date of the changes.

Article 14 (Contact Us)

For questions or requests regarding this policy, please contact us at info@tkgshoyu.jp.

Effective Date: February 16, 2026

Last Updated: July 22, 2026