Privacy Policy
This policy explains which personal data FootIQ processes, why, and what rights you have. It describes how the service actually works today.
Last updated:
1. Who is responsible
The controller for the processing described here is Footiqai, (not yet provided) ("FootIQ", "we"). Privacy contact: (not yet provided). We have not appointed a data protection officer; please use this contact for all privacy questions.
2. Summary
| Data | Purpose | Legal basis (GDPR) | Kept for |
|---|---|---|---|
| Account: name, email, password hash, preferences | Providing your account and the service | Art. 6(1)(b) contract | Until you delete your account |
| Sessions: session identifier (hashed), IP address, browser type | Keeping you signed in; security | Art. 6(1)(b); Art. 6(1)(f) security | 30 days, deleted 7 days after expiry |
| Security records: sign-in failures, blocks, email domain checks, IP addresses | Preventing password guessing, bot sign-ups and fraud | Art. 6(1)(f) legitimate interest in security | Counters: up to 2 days; log entries: 12 months |
| Subscription and payments: plan, status, periods, amounts, Whop reference IDs | Selling and managing Premium; accounting | Art. 6(1)(b); Art. 6(1)(c) tax law | As long as tax and commercial law requires |
| Emails and email log: address, subject, type, delivery status | Verification, password reset, account and service messages | Art. 6(1)(b); Art. 6(1)(f) | Log: 12 months |
| Announcements (broadcasts) | News about FootIQ; promotional emails only with consent | Art. 6(1)(f) for service news; Art. 6(1)(a) consent for promotions | Delivery records: 12 months |
| Support messages | Answering your request | Art. 6(1)(b) or (f) | 24 months after answering |
3. Data we process
Account
When you create an account: your name, email address, password (stored only as a salted bcrypt hash, never in plain text), interface language, theme, favourite leagues and notification choices, plus technical account fields (role, status, creation date, date of email verification). You must verify your email address before you can use the dashboard.
Sign-in and security
Each sign-in creates a session: a random identifier stored in a cookie on your device and, on our side, only as a hash, together with the IP address and browser description (user agent) of that session and the time it was last used. We record the time and IP address of your last sign-in.
To protect accounts and the service we count failed sign-ins per email address and per IP address, count sign-up attempts per IP address and per email domain, and may block an account or IP address temporarily (from minutes up to 24 hours; never permanently by this mechanism). At sign-up we check whether the email domain belongs to a disposable (temporary) email service. We keep a security log of sign-in failures, blocks and similar events with the email address typed and the IP address.
If a bot check is enabled on the sign-up form, it is provided by Cloudflare Turnstile, which processes your IP address and technical browser signals to tell humans from bots; only the resulting pass/fail token is checked by our server.
Subscriptions and payments
Premium is sold through Whop. You pay on Whop's checkout; FootIQ never receives your card or bank details. We receive and store the Whop membership and payment reference, plan, status, billing period, amount and currency, and whether the subscription is set to end.
Emails
We send transactional emails (verification, password reset, notices about your account or security) and, where permitted, announcements. For each email we log the recipient address, subject, type, time and delivery status, but not the content or any links or codes it contained.
Support and contact
If you contact us, we store your name, email address, subject, message and our reply.
What we do not do
- No analytics, advertising or tracking tools and no tracking cookies on FootIQ.
- We do not sell personal data or share it for targeted advertising.
- We do not track which predictions you look at for profiling.
- The AI model that reviews predictions receives football data only, never data about you.
4. Purposes and legal bases
- Contract (Art. 6(1)(b) GDPR): creating and running your account, signing you in, providing Free and Premium features, processing your subscription, answering support requests about your account.
- Legal obligation (Art. 6(1)(c)): keeping payment and accounting records as required by tax and commercial law; responding to lawful requests from authorities.
- Legitimate interests (Art. 6(1)(f)): protecting the service and its users against abuse, fraud and attacks (rate limits, blocks, disposable-email checks, security logs); sending you news about FootIQ's own service, which you can unsubscribe from at any time in each email or in Account → Notifications; improving the reliability of the service.
- Consent (Art. 6(1)(a)): promotional emails, only if you switched on "Promotions & news" in your account. You can withdraw consent at any time; this does not affect earlier processing.
Automatic temporary blocks after repeated failed sign-ins or excessive sign-up attempts are security measures. They do not produce legal effects for you, and you can always reset your password or contact us.
5. Recipients and service providers
We use the following providers. Processors act only on our instructions under a data processing agreement.
| Provider | What for | Data | Location |
|---|---|---|---|
| Neon (database hosting) | Storing all FootIQ data | All data described above | AWS data centre in Frankfurt, Germany (EU) |
| Our web hosting provider | Running the FootIQ server | Requests to our server, including IP addresses | Depends on the hosting location |
| Resend | Delivering emails | Email address, email content | USA |
| Whop | Checkout, payments, subscriptions | Payment and billing data you enter at Whop; membership status | USA. For its checkout and your Whop account Whop is responsible under its own privacy policy. |
| Cloudflare (only if the sign-up bot check is enabled) | Bot protection | IP address, technical browser signals | USA / global |
| API-Sports (football data) | Team and competition logos shown in the app are loaded from its image servers | Your IP address and browser details, when your browser loads a logo | Global content delivery |
Football data (fixtures, statistics, odds) is obtained from API-Sports, and match data is sent to an AI model provider for review; neither receives personal data about you in these requests. We may disclose data to authorities or courts where the law requires it.
6. International transfers
Our database is in the EU. Resend, Whop and Cloudflare are based in the USA. Where personal data is transferred outside the EU/EEA, this is based on an adequacy decision (for example the EU-U.S. Data Privacy Framework, where the recipient is certified) or on the European Commission's Standard Contractual Clauses. You can ask us for a copy of the relevant safeguards.
7. How long we keep data
- Account data: until you delete your account (or we close it).
- Sessions: 30 days of validity; expired sessions are deleted after 7 days.
- Verification and password-reset tokens (stored as hashes): deleted 30 days after use or expiry.
- Sign-in and sign-up rate-limit counters: deleted after about 2 days unless a block is active.
- Security log entries (sign-in failures, blocks): 12 months.
- Administrative audit log: 3 years.
- Email log: 12 months; broadcast delivery records: 12 months.
- Support messages: 24 months after they were answered or closed.
- Payment and subscription records: as long as tax and commercial law requires (up to 10 years in some countries).
When you delete your account, your profile, sessions, tokens, preferences and subscription records are deleted immediately. Records we must or may keep for longer (payment records, support messages, email and security logs) are kept only for the periods above and are then deleted automatically.
8. Your rights
- Access to your data and a copy of it (Art. 15).
- Correction of inaccurate data (Art. 16); you can edit your name and preferences yourself in Account.
- Deletion (Art. 17): delete your account yourself in Account → Delete account, or ask us.
- Restriction of processing (Art. 18) and data portability (Art. 20).
- Objection (Art. 21) to processing based on legitimate interests, and at any time to direct marketing.
- Withdrawal of consent at any time (Art. 7(3)).
- Complaint to a data protection supervisory authority, in particular in the EU country where you live or work (Art. 77).
To exercise your rights, contact (not yet provided). We may ask you to confirm your identity (for example from the email address of your account) and will answer within one month.
9. Deleting your account
Account → Delete account (with your password) deletes your account at once. If you have an active Premium subscription, we ask Whop to stop its renewal first; you keep no Premium access after deletion. The owner account of the service cannot be deleted this way.
10. Security
Passwords are hashed with bcrypt; sessions, verification and reset tokens are stored only as hashes; connections use HTTPS; secret keys of providers are encrypted; access to administrative functions is limited by role. No system is perfectly secure, but we work to protect your data appropriately.
11. Age
FootIQ is intended for adults. You must be at least 18 years old to create an account.
12. Information for residents of the United States
Several US states (for example California, Colorado, Connecticut, Virginia and others) give residents privacy rights when a business meets the thresholds of their laws. Where such a law applies to FootIQ, you can request to know, access, correct and delete your personal information, obtain a copy, and appeal a decision about your request by replying to our answer. We do not sell personal information, do not share it for cross-context behavioural advertising, do not use sensitive personal information to infer characteristics about you, and do not engage in profiling that produces legal or similarly significant effects. We will not discriminate against you for exercising your rights. Categories collected: identifiers (name, email, IP address), commercial information (subscription and payment records), internet activity limited to sign-in and security records, and communications you send us. Sources, purposes, recipients and retention are described above.
Requests: (not yet provided). An authorised agent may submit a request on your behalf where the applicable law allows it; we may verify the request with you.
13. Cookies
FootIQ uses one essential cookie for signing in and stores a few preferences in your browser. Details: cookie policy.
14. Changes
We update this policy when the service or the law changes. The date at the top shows the latest version. We will inform account holders by email about material changes.