Data Controller
Controller for the purposes of the General Data Protection Regulation (GDPR) is:
Nicholas Kruempelmann
c/o Impressumservice Dein-Impressum
Stettiner Straße 41
35410 Hungen, Deutschland
Email: info@scoregpt.app
For further details, please see our Impressum.
1. Information We Collect
1.1 Device Identifier (No Account Required)
ScoreGPT does not require you to create an account, and we do not ask for your name or any sign-in credentials. We collect an email address only if you choose to provide one — for example, when you include it with in-app feedback so that we can reply to you (see Section 1.5). To provide core functionality such as your free weekly prediction allowance, the app generates a random, anonymous device identifier (a UUID) the first time you open it:
- This identifier is anonymous and is not linked to your real-world identity.
- It is stored in your device's secure storage (Apple Keychain / Android Keystore) and, by design, persists across app reinstalls — so your free allowance cannot be reset simply by reinstalling.
1.2 Purchase and Subscription Data
We collect information related to your purchases and subscriptions:
- Purchase history, subscription status, and renewal dates
- An anonymous purchase identifier provided by RevenueCat
We never receive or store your payment card details. All payments are processed directly by the Apple App Store or Google Play; RevenueCat manages subscription status on our behalf.
1.3 Usage Data
To improve our service, we collect:
- App usage statistics, feature interactions, and prediction views
- Device information (model, operating system version, app version)
- Crash reports, error logs, and the IP address associated with them
- A mobile advertising identifier (Apple IDFA / Google Advertising ID), used only to measure the effectiveness of our app-install advertising
1.4 Third-Party Services
We use the following third-party services that may collect data:
- RevenueCat: Subscription management and purchase attribution
- Apple App Store & Google Play: Payment processing and app distribution
- PostHog: Product analytics, keyed to the anonymous device identifier
- Sentry: Crash and error reporting
- Meta (Facebook): Measurement and attribution of our advertising (we do not display ads inside the app)
- Supabase: Hosting of match data and predictions
- Sports data providers: Football fixtures, results, and statistics
1.5 Information You Provide (Feedback)
When you send feedback through the app, we collect the message you write and, if you choose to add it, your email address. Providing an email is entirely optional — you can send feedback without one. We use this information solely to understand your feedback and, where you have given an email, to reply to you. Feedback is processed through our analytics provider (PostHog).
2. How We Use Your Information
We use the collected information for the following purposes, along with the legal basis under the GDPR:
- Provide and maintain our prediction services — Performance of a contract (Art. 6(1)(b) GDPR)
- Process and validate your subscriptions — Performance of a contract (Art. 6(1)(b) GDPR)
- Improve app performance and user experience — Legitimate interest (Art. 6(1)(f) GDPR)
- Measure the effectiveness of our advertising — Legitimate interest, or consent where required (Art. 6(1)(f)/(a) GDPR)
- Respond to support requests and inquiries — Legitimate interest (Art. 6(1)(f) GDPR)
- Detect and prevent fraud or abuse — Legitimate interest (Art. 6(1)(f) GDPR)
- Comply with legal obligations — Legal obligation (Art. 6(1)(c) GDPR)
3. Data Sharing and Disclosure
We do not sell your personal information. We may share your data only in the following circumstances:
- Service Providers: With trusted third-party services (RevenueCat, analytics providers) that help us operate our app
- Legal Requirements: When required by law or to protect our rights
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
- With Your Consent: When you explicitly authorize us to share your information
4. Data Retention
We retain your information for as long as necessary to:
- Provide our services to you
- Comply with legal obligations
- Resolve disputes and enforce agreements
You can request deletion of the data associated with your device identifier at any time by emailing info@scoregpt.app. We will delete or anonymize that data within 30 days, except where we are required to retain it for legal purposes. Note that uninstalling the app does not by itself erase the anonymous device identifier, which is held in your device's secure storage.
5. Your Rights
Depending on your location, you may have the following rights:
GDPR (European Users)
- Right to access your personal data
- Right to rectify inaccurate data
- Right to erasure (“right to be forgotten”)
- Right to restrict processing
- Right to data portability
- Right to object to processing
CCPA (California Users)
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your rights
Right to Lodge a Complaint
You have the right to lodge a complaint with a data protection supervisory authority, in particular in the EU Member State of your habitual residence, place of work, or place of the alleged infringement, if you believe that the processing of your personal data infringes the GDPR (Art. 77 GDPR).
To exercise your rights, please contact us at info@scoregpt.app.
6. Security Measures
We implement industry-standard security measures to protect your data:
- Encryption of data in transit (HTTPS/TLS)
- Storage of the anonymous device identifier in the device's secure storage (Apple Keychain / Android Keystore)
- Regular security audits and updates
- Limited access to personal data on a need-to-know basis
- Secure payment processing through Apple and RevenueCat
However, no method of transmission over the internet is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
7. Children's Privacy
ScoreGPT is intended for a general adult audience and is not directed at children. We do not knowingly collect personal information from children under 13, in accordance with COPPA. If you believe we have inadvertently collected information from a child under 13, please contact us immediately at info@scoregpt.app.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. We ensure appropriate safeguards are in place to protect your data in accordance with this Privacy Policy — for transfers to the United States, this is primarily the EU-US Data Privacy Framework (for certified providers such as Meta) or the EU Standard Contractual Clauses (Art. 46 GDPR).
9. Cookies and Tracking on Our Website (scoregpt.app)
This section applies to our website at scoregpt.app. Beyond what is strictly necessary to operate the site, we only use cookies and similar technologies (such as browser storage and tracking pixels) with your consent (Art. 6(1)(a) GDPR, §25(1) TTDSG).
9.1 Consent Management
When you first visit our website, a cookie banner asks whether you agree to the use of analytics and marketing technologies. Nothing in those categories loads before you make a choice, and no choice is pre-selected. You can accept all, reject all, or enable individual categories — rejecting is just as easy as accepting, and the website works identically either way.
- Your choice is stored in your browser's local storage (key
scoregpt-consent) together with a timestamp and the version of the consent notice you responded to. This storage is strictly necessary to remember your decision (§25(2) TTDSG) and is kept until you delete it or a new consent version requires asking again. - You can change or withdraw your consent at any time — with effect for the future — via the “Cookie settings” link in the website footer (Art. 7(3) GDPR). Withdrawing a category stops the associated processing and deletes the cookies it set.
- The consent tool is built and hosted by us; no third-party consent provider receives your data.
9.2 PostHog (Website Analytics) — with Your Consent
If you consent to the “Analytics” category, we use PostHog (PostHog, Inc.), hosted on PostHog's EU cloud in the European Union, to understand how our website is used.
- Data categories: pages viewed, clicks on app-download buttons, referrer, approximate location derived from your IP address, device and browser information, web performance metrics, and a random visitor identifier stored in a first-party cookie / local storage (prefix
ph_, retained for up to 12 months). - Purpose: aggregate usage statistics and improving the website and its conversion funnel.
- Legal basis: your consent (Art. 6(1)(a) GDPR, §25(1) TTDSG).
- Retention: event data is retained in PostHog for as long as needed for the purposes above; you can request deletion at any time (see Section 5).
- Withdrawal: via “Cookie settings” in the footer. Collection stops immediately and PostHog's cookies and local storage are deleted.
9.3 Meta Pixel (Marketing) — with Your Consent
If you consent to the “Marketing” category, we use the Meta Pixel, a service of Meta Platforms Ireland Limited, Merrion Road, Dublin 4, Ireland (“Meta”), to measure the effectiveness of our advertising on Meta platforms (Facebook, Instagram) and to build advertising audiences (including lookalike audiences) from website visitors.
- Data categories: pages viewed, clicks on app-download buttons (sent as a “Lead” event with the page surface and target store), IP address, browser and device information, and cookie identifiers (in particular the
_fbpcookie, retained for 3 months). If you have a Meta account, Meta may link this data to it. - Purpose: ad measurement and attribution, retargeting, and creation of custom and lookalike audiences for our app-install advertising.
- Legal basis: your consent (Art. 6(1)(a) GDPR, §25(1) TTDSG).
- Joint controllership: for the collection of data via the pixel and its transmission to Meta, we and Meta Platforms Ireland are joint controllers (Art. 26 GDPR). The essence of this arrangement is set out in Meta's Controller Addendum. For the subsequent processing of the data, Meta is the sole controller; details are in Meta's Privacy Policy.
- US transfer: data may be transferred to Meta Platforms, Inc. in the United States. Meta is certified under the EU-US Data Privacy Framework, which the European Commission has recognized as providing an adequate level of data protection (Art. 45 GDPR).
- Withdrawal: via “Cookie settings” in the footer. The pixel stops sending data immediately and its cookies are deleted.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the updated policy on this page
- Updating the “Last updated” date
- Sending you an email notification (for significant changes)
Your continued use of the app after changes become effective constitutes acceptance of the updated policy.
11. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: