This Privacy Policy describes how FootyDeck (hereinafter "the Service") handles user personal information and data. Users must agree to this policy before using the Service.
The Service collects the following personal information for account registration and authentication:
The Service collects the following technical information for security, fraud prevention, and advertising purposes:
When using in-app purchases, the following purchase information is stored on our servers:
The Service uses the following third-party services, and data is handled in accordance with each service's privacy policy:
Firebase Authentication (Google LLC)
User authentication (Apple Sign-In / Google Sign-In)
Email address, display name, authentication provider information
https://firebase.google.com/support/privacyRevenueCat, Inc.
In-app purchase processing and management
User identifier, purchase transaction information
https://www.revenuecat.com/privacy/OpenAI, Inc.
AI card creation (player and manager), squad analysis, and generation of explanations
For AI card creation (player and manager), the entered name is included in the message sent. The name is used to determine whether it identifies a widely known football-related person. If it does, the Service creates an entertainment analysis based on public information; otherwise, it creates a fictional profile from a server-owned creative seed. Accuracy is not guaranteed. For squad analysis, we send server-issued opaque subject/entity tokens, creative seeds, entity IDs, positions, abilities, ratings, language, formation, and non-identifying tactical context needed for analysis, and squad and card names are not sent (email addresses, authentication IDs, and purchase information are not sent for either feature)
https://openai.com/policies/privacy-policy/Google AdMob (Google LLC)
In-app advertising (banner ads; ad-based credit rewards are not currently offered)
Advertising identifier (IDFA), ad display and interaction data, device information
https://policies.google.com/privacyApple Inc.
App distribution and in-app purchase processing
Purchase transaction information
https://www.apple.com/legal/privacy/Collected information is used for the following purposes:
Player cards, manager cards, and squad data generated by users are stored in the device's local storage. Account information, credit balances, transaction history, and the following AI-processing data are stored in the Service's PostgreSQL database. All communications are encrypted via HTTPS, and API access requires authentication via Firebase ID Token. For troubleshooting purposes, diagnostic information such as error logs, device platform, and app version may be stored in the device's local storage (retained for 30 days, not transmitted externally).
The content of AI requests, upstream responses, and narratives, together with detailed error messages, is retained for 30 days by default after processing is completed or failed, and is then deleted or redacted. Pending records are retained until they reach a completed or failed state. Metadata such as request IDs, operation IDs, payload hashes, status, model, token usage, and cost is retained as needed for billing integrity, fraud prevention, usage-limit enforcement, and auditing. When account deletion completes, user-identifying in-app data, including these AI records, is deleted. Some records are retained in anonymized or pseudonymized form for purchase integrity, fraud prevention, security, and legal compliance. The operational setting may shorten the default 30-day AI-content period; we will update this Policy before extending it.
Data deleted:
Data retained:
Users can request account deletion at any time from the in-app Settings screen. The request is persisted in a server-side processing queue and retried in the background if deletion from RevenueCat or Firebase Authentication cannot complete immediately. Billing and AI use are blocked while processing, and users are instructed not to sign in again or make purchases until deletion completes. After completion, server data is deleted or pseudonymized as described in Article 8, and cards, squads, analysis results, and images stored locally on the device are also deleted. If a network or provider error prevents completion, the app reports that deletion is still processing rather than reporting it as complete.
This Service is not intended for children under 13. Users who are 13 or older but have not reached the legal age to consent to personal-data processing in their region may not use the Service. The Service does not currently provide a mechanism to obtain or verify parental consent. If we learn that personal information was provided by a child who does not meet these requirements, we will promptly delete it.
Under applicable data protection laws (including APPI and GDPR), you have the following rights regarding your personal data. To exercise these rights, please contact us at info@tkgshoyu.jp.
Your data may be transferred to and processed in countries outside of Japan, including the United States. The third-party services listed in Article 5 process data at their respective server locations. The Service ensures that appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
The Service may update this Privacy Policy as necessary. For material changes, we will notify users via in-app notification at least 14 days before the effective date of the changes.
For questions or requests regarding this policy, please contact us at info@tkgshoyu.jp.
Effective Date: February 16, 2026
Last Updated: July 22, 2026