Privacy Policy
1. Introduction
Welcome to Fanbooya ("we," "us," "our," or the "App"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application available on the Apple App Store and Google Play Store.
Fanbooya operates as a commercial news and sports aggregator app (ad-supported) across the USA, United Kingdom, European Union, and India. Please read this Privacy Policy carefully. By using Fanbooya, you agree to the collection and use of information in accordance with this policy. If you do not agree with the terms of this Privacy Policy, please do not access the application.
Governing Law: This Privacy Policy is governed by the laws of the State of Wyoming, USA, without regard to its conflict of law provisions. Users in the EU, UK, and India have additional rights under their respective local laws as described in Section 10.
2. Information We Collect
2.1 Information You Provide to Us
We collect information you directly provide when using our App, including:
- Account Information: Username and email address when you create an account. Authentication is managed exclusively through Firebase Authentication (Google LLC), Google Sign-In, or Sign in with Apple — we do not collect or store passwords directly.
- Profile Information: Any additional information you choose to add to your profile (display name, bio, profile image, date of birth, location, etc.).
- User Content: Content you create, upload, or share through the App, including events and community posts.
- Communications: Information when you contact us for support, feedback, or to report intellectual property concerns.
2.2 Information Automatically Collected
When you use Fanbooya, we automatically collect certain information, including:
- Device Information: Device type, operating system version, unique device identifiers (such as advertising identifiers), and mobile network information.
- Usage Data: App features used, time spent in the App, click data, interaction information, and content viewing patterns (collected via Firebase Analytics).
- Log Data: IP address, app version, error logs, diagnostic data, and crash reports.
- Location Information: General location based on IP address for content localization. We do not collect precise GPS location without your explicit permission.
- API Interaction Data: Metadata related to your interaction with third-party content feeds.
2.3 Information from Third Parties
We receive information about you from:
- Content Providers: NewsAPI.org, NewsData.io, and API-Sports (api-sports.io) for news and sports data feeds.
- Analytics Providers: Firebase Analytics (Google LLC) for app usage patterns and performance data.
- Advertising Partners: Google AdMob for non-personally identifiable information for ad targeting.
2.4 Third-Party Authentication Services
When you sign in using a third-party authentication service, we receive certain information from that provider:
- Google Sign-In: Your name, email address, and profile picture as associated with your Google account. We receive a Google ID token and access token to authenticate you via Firebase Authentication (Google LLC).
- Sign in with Apple: Your name and email address (or an Apple Private Relay email address if you choose to hide your email). Apple only shares your name on the first sign-in; we store it at that time. If you use Apple's "Hide My Email" feature, we receive a unique private relay address and will never see your real email address.
We do not receive, collect, or store passwords. All authentication is managed entirely through Firebase Authentication (Google LLC), Google Sign-In, or Sign in with Apple.
2.5 Device Fingerprint
On first launch, we collect a one-time device fingerprint (device model, OS version, timezone, language) solely to match referral links for our invite-a-friend program. This data is not used for ongoing tracking or advertising purposes.
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Delivery: To provide, maintain, and improve the App's functionality, including aggregating news and sports content.
- Account Management: To create and manage your account.
- Communications: To send you updates, security alerts, support messages, and respond to takedown notifications.
- Content Personalization: To customize news feeds and sports content based on your preferences and location.
- Analytics: To understand how users interact with our App and improve user experience via Firebase Analytics.
- Advertising: To serve relevant advertisements via Google AdMob (using anonymized and aggregated data only).
- Legal Compliance: To comply with legal obligations, including regional copyright and data protection laws.
- Intellectual Property Protection: To process and respond to copyright and trademark claims.
- Gamification: To operate daily tasks, quizzes, surveys, leaderboards, and the Spin & Win mystery wheel, and to track virtual currency balances (XP, Boo's, Yah's, FAN Coins).
- Community Safety: To moderate user-generated content, process content reports, enforce community guidelines, and manage user blocks.
- Push Notifications: To send push notifications about updates, events, rewards, and promotions via Firebase Cloud Messaging (with your consent).
4. Third-Party Data & API Integration
4.1 Content Sources
Fanbooya aggregates data via professional APIs including:
- NewsAPI.org: For global news headlines and snippets.
- NewsData.io: For AI summaries and full-text news content where available.
- API-Sports (api-sports.io): For live scores, match statistics, and team information.
4.2 API Compliance
- Server-Side Protection: API keys are stored securely on our backend servers and never exposed in the app's frontend code.
- Caching Policy: We refresh data according to provider requirements (typically every 24 hours) and respect Cache-Control headers.
- No Permanent Storage: We do not permanently archive third-party news or sports data.
- Rate Limiting: We implement appropriate rate limiting to comply with API usage terms.
4.3 Usage Restrictions
The data provided within this App is licensed for your personal, non-commercial use only:
- No Redistribution: You are prohibited from scraping, redistributing, or syndicating any content from the App.
- No Automated Access: Use of robots, spiders, or automated means to access content is strictly forbidden.
- No Reverse Engineering: Attempting to reverse-engineer data structures or bypass attribution links violates these terms.
5. Gamification, Virtual Currencies & Contests
The App includes gamification features such as daily tasks, quizzes, surveys, leaderboards, and a Spin & Win mystery wheel. Through these features, users may earn virtual currencies including XP (Experience Points), Boo's, Yah's, and FAN Coins.
We collect data related to your participation in these features, including:
- Tasks completed, quizzes taken, and survey responses.
- Spin & Win mystery wheel participation, results, and virtual rewards earned.
- Leaderboard rankings and achievement progress.
- Virtual currency balances and transaction history.
All currencies and rewards within the App are virtual and have no real-world monetary value. They cannot be exchanged for cash, gift cards, or any tangible goods, and cannot be transferred outside the App.
5.1 Spin & Win — Official Rules
Apple is not a sponsor of, nor involved in any way with, the Spin & Win feature or any contest, sweepstakes, or promotional activity within Fanbooya. This feature is operated solely by Fanbooya.
- Eligibility: Open to registered Fanbooya users aged 13 or older (16 or older in certain jurisdictions). Void where prohibited by law.
- How to Enter: Users may spin the Spin & Win mystery wheel once per qualifying period as determined by the App. No purchase necessary to participate.
- Prizes: All prizes are virtual rewards (XP, Boo's, Yah's, FAN Coins, or in-app bonuses). Prizes have no real-world monetary value and cannot be redeemed for cash or transferred outside the App.
- Odds: Odds of winning each prize tier depend on the number of available prize slots at the time of each spin, as configured within the App.
- Winner Notification: Winners are notified immediately within the App upon a successful spin result.
- Disqualification: Fanbooya reserves the right to disqualify any user found to be tampering with the spin mechanism, using automated tools, or otherwise violating these rules or the App's Terms of Service.
- Sponsor: The Spin & Win feature is operated solely by Fanbooya. Apple Inc. is not a sponsor and has no involvement in the administration, operation, or fulfillment of this feature.
- Governing Law: These rules are governed by the laws of the State of Wyoming, USA. Any disputes shall be resolved in accordance with the App's Terms of Service.
- Availability: These official rules are available at all times within the App and at support@fanbooyah.com upon request.
6. User-Generated Content & Community Safety
The App includes community features where users may create and share content, including events. To ensure a safe community, the following precautions are in place:
6.1 Terms Agreement & Zero-Tolerance Policy
Users must agree to our Terms of Service (which includes an End User License Agreement) before creating an account. The EULA explicitly states a zero-tolerance policy for objectionable content and abusive behavior. Users who violate these terms are subject to immediate content removal and account suspension or permanent termination.
6.2 Content Filtering
We employ automated and manual content filtering methods to detect and prevent objectionable content from being published within the App, including profanity filters and image moderation checks applied to user-submitted content.
6.3 Reporting Objectionable Content
Every piece of user-generated content includes an in-app Report button allowing any user to flag content they consider objectionable, inappropriate, or in violation of our guidelines. Reports are immediately queued for moderation review.
6.4 Blocking Abusive Users
Users may block any other user directly within the App. When a block is initiated:
- The blocked user's content is immediately removed from the blocking user's feed.
- Our moderation team is automatically notified of the block action for review.
- The blocked user cannot interact with or view the blocking user's content.
6.5 Moderation Response
Our moderation team reviews all reported content and block notifications within 24 hours. Upon review:
- Objectionable content is removed from the App.
- The user who provided the offending content is ejected (suspended or permanently banned) depending on severity.
- Repeat offenders are permanently banned from the platform.
- Moderation records (reports, block actions, enforcement decisions) are retained for up to 12 months for safety and compliance purposes.
7. Third-Party Services & SDK Integrations
We integrate the following third-party services to operate the App. Each service may collect data as described below and in accordance with their own privacy policies:
- Firebase Authentication (Google LLC): User sign-in and account management. Data involved: email, name, authentication tokens. Privacy Policy
- Firebase Analytics (Google LLC): App usage analytics, user engagement tracking, and performance monitoring. Data involved: device identifiers, usage events, session data, in-app actions. Privacy Policy
- Firebase Cloud Storage (Google LLC): Profile image and event thumbnail hosting. Data involved: uploaded photos. Privacy Policy
- Firebase Cloud Messaging (Google LLC): Push notifications delivery. Data involved: device push token. Privacy Policy
- MailerSend (MailerSend Ltd): Transactional email delivery for account-related communications including OTP verification codes and password reset emails. Data involved: email address, email delivery metadata. MailerSend acts as a data processor and does not use your email address for any purpose other than delivering emails on our behalf. Privacy Policy
- Google Sign-In (Google LLC): Social login via Google account. Data involved: Google profile information (name, email, profile picture). Privacy Policy
- Google AdMob (Google LLC): Banner, interstitial, and rewarded video advertisements. Data involved: device identifiers, ad interaction data. Privacy Policy
- Sign in with Apple (Apple Inc.): Social login via Apple ID. Data involved: name, email address (or Apple Private Relay email). Privacy Policy
- SKAdNetwork (Apple Inc.): Anonymized ad attribution and conversion tracking via Apple's privacy-preserving framework. Data involved: anonymized attribution data only (does not track individual users). Privacy Policy
All Google/Firebase services process data on Google's infrastructure, which may include servers in the United States. For EU/UK users, please see Section 11 (International Data Transfers) for details on applicable safeguards.
8. Information Sharing and Disclosure
8.1 Sharing with Advertisers
We share anonymized and aggregated information with advertisers and advertising networks. This includes:
- Demographic information (age range, general location based on country/region).
- App usage patterns and content preferences.
- Device type and operating system.
- Advertising identifiers (when permitted by your device settings).
Important: We do NOT share your personal identifying information (name, email address, specific user ID, or precise location) with advertisers.
8.2 Other Disclosures
We may share your information in the following situations:
- Service Providers: With third-party vendors who assist in app operation (under strict confidentiality agreements).
- Content Providers: Aggregated usage statistics with our API partners as required by commercial licenses.
- Legal Requirements: When required by law, court order, or to respond to legal processes.
- Protection of Rights: To protect the rights, property, or safety of Fanbooya, our users, or others.
- Business Transfers: In connection with a merger, sale, or acquisition of all or a portion of our business.
- With Your Consent: When you explicitly agree to share your information.
9. Intellectual Property & Copyright
9.1 Content Ownership
All news articles, headlines, summaries, sports data, team logos, and associated metadata displayed within Fanbooya are the intellectual property of their respective owners and publishers. Fanbooya does not claim ownership over any third-party content.
9.2 Fair Use & Attribution
Content is used in accordance with:
- USA: Section 107 of the Copyright Act (Fair Use) for news reporting and commentary.
- UK/EU: Fair Dealing for reporting current events, providing only "very short extracts" (under 160 characters) in compliance with Article 15 of the EU Digital Single Market Directive.
- India: Fair Dealing with "Sufficient Acknowledgement" — source names are prominently displayed.
All content includes mandatory direct links to original publishers. Every article and sports update displays clear attribution to the source.
9.3 Images and Logos
- News Images: Served via third-party APIs; we do not claim rights to news photography.
- Sports Logos: Team crests and player images are property of respective leagues and clubs, used for nominative identification purposes only.
- UK/EU Special Notice: The "Reporting Current Events" exception does not apply to photographs. Images are displayed via API links only.
9.4 Notice & Takedown Policy
Designated Agent for IP Claims:
Email: legal@fanbooyah.com
Subject Line: IP Takedown Request - Fanbooya
To report alleged infringement, provide:
- Description of the copyrighted work or trademark.
- Specific location within the App where material appears.
- Your contact information (name, address, phone, email).
- Good faith statement that use is unauthorized.
- Statement of accuracy under penalty of perjury.
- Physical or electronic signature.
Upon receiving valid notice, we will expeditiously remove or disable access to the material, replace sports logos with generic placeholders if necessary, notify the content provider of the removal, and process counter-notifications according to DMCA procedures.
10. Your Privacy Rights & Regional Compliance
10.1 United States — California (CCPA / CPRA)
California residents have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to Know: Request disclosure of the personal information we collect, use, share, or sell about you.
- Right to Delete: Request deletion of your personal information, subject to certain exceptions.
- Right to Correct: Request correction of inaccurate personal information we hold about you.
- Right to Opt-Out of Sale/Sharing: We do not sell your personal information. However, sharing of data with advertising partners for cross-context behavioral advertising may constitute "sharing" under CPRA. You may opt out as described below.
- Right to Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information (such as device fingerprints) to necessary purposes only.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of these rights.
Do Not Sell or Share My Personal Information
To opt out of the sharing of your personal information for advertising purposes, or to exercise any of your California privacy rights, email us at privacy@fanbooyah.com with the subject line "California Privacy Request". We will respond within 45 days.
10.2 European Union (GDPR)
Users in the European Economic Area have rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of your personal data and how it is used.
- Right to Rectification: Request correction of inaccurate personal data.
- Right to Erasure ("Right to be Forgotten"): Request deletion of your personal data where there is no compelling reason for continued processing.
- Right to Data Portability: Receive your personal data in a structured, machine-readable format (JSON or CSV) for transfer to another controller.
- Right to Restrict Processing: Request restriction of processing of your personal data in certain circumstances.
- Right to Object: Object to processing based on legitimate interests or for direct marketing purposes.
- Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent.
- Right to Lodge a Complaint: Lodge a complaint with your local supervisory authority (e.g., ICO in the UK, CNIL in France).
Legal Basis for Processing:
- Consent: When you have given explicit consent (e.g., push notifications, location).
- Contract: When processing is necessary to perform our services for you.
- Legal Obligations: When processing is required by law.
- Legitimate Interests: For analytics, security, fraud prevention, and service improvement, where our interests are not overridden by your rights.
To exercise your GDPR rights, email dpo@fanbooyah.com. We will respond within 30 days as required by GDPR Article 12.
10.3 United Kingdom (UK GDPR)
UK users have the same rights as EU users under UK GDPR (retained from EU law post-Brexit). Additionally, we comply with NLA Media Access licensing requirements for UK news sources. To exercise your rights, contact our UK representative at dpo@fanbooyah.com. You may also lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.
10.4 India (DPDP Act)
We ensure "Sufficient Acknowledgement" under Indian Fair Dealing laws with prominent source attribution. Indian users have rights under the Digital Personal Data Protection Act 2023 (DPDP Act) and the Information Technology Act. To exercise your rights, contact privacy@fanbooyah.com.
10.5 How to Submit a Privacy Request
For all privacy rights requests (access, deletion, correction, portability, opt-out):
- Email: privacy@fanbooyah.com
- Subject line: "Privacy Rights Request — [Your Request Type]"
- Include your registered email address and a description of your request.
- We will verify your identity before processing and respond within 30 days (45 days for CCPA).
10.6 Account Deletion
You can permanently delete your account and all associated data directly from within the App by navigating to Profile > Delete Account. Account deletion is permanent and cannot be undone. Upon deletion:
- Your profile, personal information, and preferences are permanently removed from our systems.
- All virtual currencies (XP, Boo's, Yah's, FAN Coins) and progress are permanently lost.
- Content you created (such as events) will be removed.
- Your Firebase authentication account (including any linked Google or Apple sign-in) is deleted.
- All backend data associated with your account is purged within 30 days.
You may also request account deletion by emailing privacy@fanbooyah.com. We will process your request within 30 days.
11. International Data Transfers
Fanbooya is operated from the United States. If you are located in the European Union, United Kingdom, or other regions with laws governing data collection and use that may differ from US law, please be aware that your personal data may be transferred to and processed in the United States.
11.1 Transfers to the United States
We use Google LLC services (Firebase Authentication, Firebase Analytics, Firebase Cloud Storage, Firebase Cloud Messaging, Google AdMob) which process data on Google's infrastructure, including servers in the United States. Google LLC participates in and complies with the EU-US Data Privacy Framework and implements Standard Contractual Clauses (SCCs) as approved by the European Commission for transfers of personal data from the EEA and UK to the US.
For more information on Google's data transfer safeguards, see Google's Privacy Framework.
11.2 Safeguards
Where we transfer personal data outside the EEA or UK, we ensure appropriate safeguards are in place, including:
- Standard Contractual Clauses (SCCs): European Commission-approved contractual clauses with our data processors.
- Adequacy Decisions: Transfers to countries recognized by the European Commission as providing adequate data protection.
- Supplementary Measures: Technical and organizational measures to protect data in transit and at rest.
To request a copy of the relevant transfer safeguards, contact dpo@fanbooyah.com.
11.3 GDPR Representative
As a company established outside the EU/UK that offers services to EU/UK residents, we have designated a Data Protection contact as our GDPR Article 27 representative:
- Contact: Data Protection Officer, Fanbooya
- Email: dpo@fanbooyah.com
- Address: 30 N. Gould St, Ste R, Sheridan, WY USA 82801
EU and UK users may contact our DPO directly with any data protection concerns, rights requests, or complaints.
12. Data Retention & Security
12.1 Retention Periods
- Account & Profile Data: Retained for the duration of your account. Permanently deleted within 30 days of account deletion request.
- Usage & Analytics Data (Firebase Analytics): Retained for up to 14 months per Google's default retention policy, then anonymized.
- Content Cache: News and sports data refreshed every 24 hours per API requirements. Not permanently stored.
- Advertising Data: Anonymized and aggregated data retained for up to 12 months for analytics.
- Device Fingerprints: Collected once at first launch for referral matching only. Not retained for ongoing tracking.
- Virtual Currency & Engagement Data: Retained for the duration of your account to maintain your progress, levels, and currency balances.
- Moderation Records: Content reports and enforcement actions retained for up to 12 months after resolution for safety and compliance purposes.
- Communication Records: Support and legal correspondence retained for up to 3 years.
12.2 Security Measures
We implement industry-standard security measures:
- Encryption of data in transit (HTTPS/TLS 1.2+) and at rest (AES-256).
- Secure API key storage on backend servers only — never in client-side code.
- Regular security assessments and dependency updates.
- Access controls, role-based permissions, and authentication measures.
- Protection against automated scraping and data extraction.
However, no method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
12.3 Data Breach Notification
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the relevant supervisory authority (e.g., ICO for UK, lead DPA for EU) within 72 hours of becoming aware of the breach, as required by GDPR Article 33.
- Notify affected users without undue delay where the breach is likely to result in a high risk to their rights and freedoms, as required by GDPR Article 34.
- Breach notifications to users will be sent via the email address associated with your account and/or via in-app notification.
- Notifications will include the nature of the breach, categories of data affected, likely consequences, and measures taken to address it.
13. Children's Privacy
Fanbooya is not intended for children under 13 years of age (or 16 in the EU/UK). We do not knowingly collect personal information from children under these ages. If you become aware that a child has provided us with personal information, please contact us immediately at privacy@fanbooyah.com. We will take prompt steps to delete such information from our systems.
14. Advertising & Analytics
14.1 Advertising
We work with Google AdMob to serve advertisements within the App. AdMob and its partners may use device identifiers, cookies, and tracking technologies to provide targeted advertising based on anonymized interests. Advertisements are independent of news content and do not imply endorsement.
On iOS, we display an App Tracking Transparency (ATT) prompt before accessing your device's advertising identifier (IDFA). You may allow or deny this request. If denied, you will receive non-personalized ads only.
14.2 Analytics
We use Firebase Analytics (Google LLC) to collect anonymized usage data including screen views, feature interactions, session length, and in-app events. This data is used solely to improve App performance and user experience. Firebase Analytics data is retained for up to 14 months. You can opt out of Firebase Analytics data collection via your device settings.
14.3 Your Ad Choices
- iOS Users: Go to Settings > Privacy & Security > Tracking to manage app tracking permissions.
- Android Users: Go to Settings > Google > Ads > Opt out of Ads Personalization.
- Analytics Opt-Out (iOS): Go to Settings > Privacy & Security > Analytics & Improvements and disable "Share iPhone Analytics."
- Analytics Opt-Out (Android): Go to Settings > Google > Ads > Delete advertising ID.
15. Camera and Photo Library Access
The App may request access to your device's camera and photo library for the following purposes:
- Taking or selecting a profile picture.
- Selecting thumbnail images for events you create.
Photos are uploaded to our secure servers (Firebase Cloud Storage) for display within the App. Camera and photo library access is optional and can be revoked at any time through your device's Settings > Privacy & Security. We do not access, scan, or use your photos for any purpose other than what you explicitly upload.
16. Push Notifications
With your permission, we may send push notifications about updates, events, rewards, and promotions using Firebase Cloud Messaging (Google LLC). You can manage notification preferences:
- In-App: Profile > My Preferences > Push Notifications toggle.
- Device Settings (iOS): Settings > Notifications > Fanbooya.
- Device Settings (Android): Settings > Apps > Fanbooya > Notifications.
Disabling push notifications will not affect the core functionality of the App.
17. Platform-Specific Requirements
17.1 Apple App Store Compliance
This App complies with Apple's App Store Review Guidelines:
- Clear disclosure of all data collection practices in this Privacy Policy and in the App Store Privacy Nutrition Label.
- Purpose strings (NSUsageDescription) declared for all APIs that access user data (camera, photo library, notifications).
- App Tracking Transparency (ATT) prompt displayed before accessing the IDFA per iOS 14.5+ requirements.
- Sign in with Apple offered as an equivalent login option per Guideline 4.8.
- Official Spin & Win contest rules with explicit Apple non-sponsorship disclaimer per Guideline 5.3.2.
- Terms of Service (EULA) with zero-tolerance policy for objectionable content per Guideline 1.2.
- In-app content filtering, reporting, blocking, and 24-hour moderation per Guideline 1.2.
- No permanent storage of third-party content per API provider terms.
- In-app account deletion available per Guideline 5.1.1(v).
17.2 Google Play Store Compliance
This App complies with Google Play's Developer Program Policies:
- Transparent disclosure in the Data Safety section of the Play Store listing.
- Adherence to Google's advertising ID policies and AdMob guidelines.
- Compliance with Families Policy where applicable.
- User data handling consistent with Google Play's User Data policy.
18. Accuracy Disclaimer
While we utilize industry-standard commercial APIs (NewsAPI.org, NewsData.io, and API-Sports (api-sports.io)), we do not guarantee the real-time accuracy, completeness, or reliability of news and sports data. We are not liable for any errors, omissions, delays, or damages arising from the use of third-party content.
19. Updates to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of material changes by:
- Posting the updated Privacy Policy within the App.
- Sending a push notification or in-app alert for material changes.
We encourage you to review this policy periodically. Continued use of the App after changes are posted constitutes acceptance of the updated Privacy Policy.
20. Contact Information
For privacy inquiries, data subject requests, or intellectual property concerns, please contact us:
We aim to respond to all privacy inquiries within 30 days. For urgent data breach concerns, we will respond within 72 hours.
BY USING FANBOOYA, YOU ACKNOWLEDGE THAT YOU HAVE READ AND UNDERSTOOD THIS PRIVACY POLICY AND AGREE TO ITS TERMS.