FanFini

Gizlilik Politikası

Son güncelleme: 18 Ağustos 2026  ·  Yürürlük tarihi: 18 Ağustos 2026  ·  Sürüm 1.0

ÖZET Kısaca ne oluyor?

  • Oyunu oynamak için hesap açmak zorunda değilsin. Uygulama ilk açıldığında cihazına rastgele bir kimlik üretilir; bu kimlik adını, telefon numaranı veya e-postanı içermez.
  • Oyunda verdiğin cevaplar bize ulaşmaz. Cevaplar karşındakine sesli söylenir; uygulamaya yazılmaz, kaydedilmez, sunucuya gönderilmez.
  • Mikrofona, kameraya, konuma, rehbere ve fotoğraflara erişmiyoruz.
  • Ödeme bilgilerini hiç görmüyoruz. Satın alma tamamen App Store / Google Play üzerinden yürür.
  • Verilerinin silinmesi için tek bir e-posta yeterli: utku.ayan@outlook.com

Bu özet bilgilendirme amaçlıdır; bağlayıcı olan aşağıdaki tam metindir.

01 Veri sorumlusu ve iletişim

FanFini (“FanFini”, “biz”), bu politikada açıklanan kişisel verilerin veri sorumlusudur (6698 sayılı KVKK m.3 ve GDPR m.4/7 anlamında).

Veri sorumlusuFanFini
UygulamaFanFini — çiftler ve arkadaşlar için soru-cevap oyunu (iOS & Android)

02 Bu politika neyi kapsar

Bu politika; FanFini mobil uygulamasını, api.fanfini.app adresindeki arka uç servisini ve bu web sitesini kapsar.

Uygulamanın ilk açılışında gösterilen Açık Rıza Metni, oyunun kuralları, 18 yaş sınırı ve oyuncuların birbirine karşı sorumluluğu hakkındadır. Elinizdeki Gizlilik Politikası ise kişisel verilerinizin nasıl işlendiğini anlatır. İkisi birbirini tamamlar; ikisini de okumanızı öneririz.

03 İşlediğimiz veriler

FanFini’de kişisel veri toplama ilkesi basittir: oyunun çalışması için gerekli olan en az veri. Aşağıdaki tablo işlenen tüm veri kategorilerini gösterir.

VeriNe zamanNeden
Cihaz kaydı Uygulamanın ilk açılışında Cihaz için üretilen rastgele kimlik (Cihaz Kimliği), platform (iOS/Android), uygulama sürümü, seçtiğin dil, kayıt ve son görülme zamanı. Hesap açmadan oynayabilmen, yarım kalan oyununa geri dönebilmen ve kötüye kullanımın engellenmesi için gereklidir.
Oturum anahtarı Her girişte Cihazını doğrulayan anahtar sunucuda yalnızca şifrelenmiş özeti (hash) ile tutulur; anahtarın kendisi saklanmaz. Geçerlilik süresi dolduğunda veya çıkış yapıldığında iptal edilir.
Hesap bilgileri (isteğe bağlı) Google veya Apple ile giriş yaparsan Firebase kullanıcı kimliği, e-posta adresin ve görünen adın. Yalnızca coin bakiyenin, hediye coinlerin, Premium üyeliğinin ve satın alımlarının yeni bir telefonda geri gelmesi için kullanılır. Apple ile girişte “e-postamı gizle” seçeneğini kullanırsan bize yalnızca Apple’ın ürettiği yönlendirme adresi ulaşır.
Oyun verisi Oda kurarken ve oynarken Oda kodu, o oyunda kullandığın takma ad, oyun türü ve dili, zar sonuçları, sana gösterilen ve seçilen/atlanan soruların kimlikleri, joker kullanımların, tur sayıları ve zaman damgaları. Oyunun iki oyuncuda da senkron ilerlemesi ve aynı sorunun tekrar gelmemesi için gereklidir.
Favoriler Bir soruyu favorilere eklediğinde Sorunun o anki metni, kategorisi ve cevabı veren oyuncunun takma adı. Favoriler ekranında sana gösterilir.
Soru önerileri “Soru Öner” ekranından gönderdiğinde Yazdığın soru metni, seçtiğin oyun türü ve kategori, öneriyi gönderen hesap. Önerinin değerlendirilmesi ve tekrar/kötüye kullanımın önlenmesi için hesabınla ilişkilendirilir. Bir öneri oyuna eklenirse adınla ya da hesabınla birlikte yayınlanmaz.
Satın alma ve abonelik Coin veya Premium aldığında Mağazadan gelen satın alma olayları (ürün kodu, tarih, durum), coin bakiyen, Premium üyeliğin ve bitiş tarihi. Kart numarası, IBAN ve fatura adresi bize hiçbir zaman ulaşmaz — ödemeyi Apple ve Google alır.
Reklam olayları Ücretsiz oyunlarda Reklamın istendiği, gösterildiği ve tamamlandığı bilgisi — ücretsiz oyun hakkının doğru işlemesi için. Reklamın kendisi Google AdMob tarafından sunulur ve Google kendi tanımlayıcılarını kullanır (bkz. bölüm 7).
Analitik ve hata kayıtları Uygulamayı kullanırken Firebase Analytics olayları (ör. “oyun başladı”, “oda kuruldu”) ve Crashlytics çökme raporları (cihaz modeli, işletim sistemi sürümü, hata yığını). Hataları görmek ve oyunu iyileştirmek için.
Teknik sunucu kayıtları Her istekte IP adresi ve istek yolu. IP adresi yalnızca istek sınırlama (rate limiting) ve kötüye kullanım engelleme amacıyla, kısa ömürlü bir önbellekte tutulur; oyun kayıtlarınla birleştirilmez ve profil oluşturmak için kullanılmaz.

Cihaz Kimliğini uygulama içinde Hesap ekranından görebilir ve kopyalayabilirsin. Bir talep gönderirken bu kimliği eklemen, kayıtlarını bulmamızı kolaylaştırır.

04 İşlemediğimiz veriler

🎙️

Oyun sırasında verdiğin cevaplar hiçbir şekilde kaydedilmez. FanFini’de cevaplar yazılmaz, karşındaki kişiye sesli söylenir. Uygulama mikrofonu açmaz, ses veya görüntü kaydı almaz, cevabın metnini sunucuya göndermez. Sunucuda tutulan tek şey hangi sorunun seçildiği veya atlandığı bilgisidir — cevabın kendisi değil.

Ayrıca şunları toplamıyoruz:

  • Konum bilgisi (GPS veya benzeri)
  • Rehber, kişiler, çağrı veya mesaj kayıtları
  • Fotoğraf, galeri veya dosya erişimi
  • Sağlık, biyometri veya cinsel yaşam verisi
  • Ödeme kartı bilgileri
  • Kimlik numarası, adres veya telefon numarası

05 İşleme amaçları ve hukuki sebepler

AmaçKVKK m.5GDPR m.6
Oyunun kurulması, odanın açılması ve oyunun yürütülmesiSözleşmenin ifası — m.5/2-c6(1)(b)
Hesap açma, coin bakiyesi, satın alma ve geri yüklemeSözleşmenin ifası — m.5/2-c6(1)(b)
Kötüye kullanım, sahtecilik ve istek sınırlama (güvenlik)Meşru menfaat — m.5/2-f6(1)(f)
Hata kayıtları ve ürünün iyileştirilmesiMeşru menfaat — m.5/2-f6(1)(f)
Kişiselleştirilmiş reklam ve ölçümlemeAçık rıza — m.5/16(1)(a)
Yasal yükümlülüklerin yerine getirilmesi (ör. mali kayıtlar)Hukuki yükümlülük — m.5/2-ç6(1)(c)

Açık rızaya dayanan işlemeleri (kişiselleştirilmiş reklam) dilediğin zaman geri alabilirsin; bunun için bölüm 7’ye bak.

06 Hizmet sağlayıcılar ve veri paylaşımı

Kişisel verilerini satmıyoruz ve reklam amacıyla üçüncü taraflara pazarlamıyoruz. Verilerin yalnızca hizmetin çalışması için gerekli olduğu ölçüde, aşağıdaki sağlayıcılar tarafından ve bizim adımıza işlenir:

SağlayıcıNe içinNerede
Supabase Inc.Veritabanı barındırma (oyun, hesap ve coin kayıtları)Londra, Birleşik Krallık
DigitalOcean LLCUygulama sunucuları ve yük dengeleyiciFrankfurt, Almanya
Google LLC — Firebase AuthenticationGoogle ile giriş, hesap kimliğiAB / ABD
Google LLC — Firebase Analytics & CrashlyticsKullanım istatistikleri ve çökme raporlarıAB / ABD
Google LLC — AdMob & UMPReklam gösterimi ve reklam izni yönetimiAB / ABD
Google Play Billing / Apple App StoreSatın alma ve abonelik tahsilatıAB / ABD
RevenueCat, Inc.Satın alma doğrulama ve abonelik durumuABD

Bunların dışında verilerin yalnızca (a) yasal olarak yetkili bir makamın usulüne uygun talebi üzerine veya (b) hakların tesisi, kullanılması ya da korunması için zorunlu olduğunda paylaşılır.

Google’ın veri uygulamaları: policies.google.com/privacy  ·  Apple: apple.com/legal/privacy  ·  RevenueCat: revenuecat.com/privacy  ·  Supabase: supabase.com/privacy

07 Reklamlar ve reklam izni

FanFini ücretsiz oynanabilir. Ücretsiz oyunlar Google AdMob reklamlarıyla desteklenir. Reklamları tamamen kaldırmak istersen coin satın alabilir veya Premium üye olabilirsin — bu durumda oyun içinde reklam gösterilmez.

Avrupa Ekonomik Alanı, Birleşik Krallık ve İsviçre’deki kullanıcılara, uygulamanın ilk açılışında Google’ın UMP (User Messaging Platform) izin ekranı gösterilir. Kişiselleştirilmiş reklam yalnızca burada onay verirsen gösterilir; onay vermezsen reklamlar kişiselleştirilmemiş olarak sunulur ve oyun aynı şekilde çalışmaya devam eder.

iOS’ta ayrıca Apple’ın App Tracking Transparency izni sorulur. Reklam izin tercihini istediğin zaman cihazının ayarlarından değiştirebilirsin:

  • Android: Ayarlar → Google → Reklamlar
  • iOS: Ayarlar → Gizlilik ve Güvenlik → İzleme

08 Yurt dışına aktarım

Uygulama sunucularımız Almanya’da (Frankfurt), veritabanımız Birleşik Krallık’ta (Londra) barındırılır. Google, Apple ve RevenueCat gibi sağlayıcılar verileri ayrıca Amerika Birleşik Devletleri’nde işleyebilir.

Bu aktarımlar; KVKK m.9 kapsamında açık rızanız ve/veya taahhütname ile, GDPR kapsamında ise Avrupa Komisyonu’nun Standart Sözleşme Hükümleri (SCC) ve sağlayıcıların veri işleme sözleşmeleri temelinde yapılır.

09 Saklama süreleri

  • Oturum anahtarları: geçerlilik süresi dolduğunda veya çıkış yaptığında iptal edilir.
  • Oyun odaları: başlatılmayan odalar birkaç dakika içinde, biten veya terk edilen odalar en geç 4 saat içinde otomatik olarak kapatılır.
  • Oyun ve favori kayıtları: uygulamayı kullandığın sürece; silme talebinde bulunduğunda kaldırılır.
  • Hesap ve coin kayıtları: hesabın açık olduğu sürece; hesap silme talebinden sonra 30 gün içinde silinir.
  • Satın alma kayıtları: mali ve vergisel mevzuat gereği ilgili zamanaşımı süresi boyunca (Türkiye’de 10 yıl) saklanır; bu kayıtlar silme talebinden muaftır.
  • Teknik sunucu kayıtları: IP tabanlı istek sınırlama kayıtları dakikalar içinde kendiliğinden düşer; erişim kayıtları en fazla 30 gün tutulur.
  • Analitik ve çökme verileri: Google’ın Firebase için uyguladığı saklama süreleri geçerlidir.

10 Haklarınız

KVKK m.11 ve GDPR m.15–22 uyarınca aşağıdaki haklara sahipsin:

  • Kişisel verilerinin işlenip işlenmediğini öğrenme ve işlenmişse buna ilişkin bilgi talep etme
  • Verilerine erişme ve bir kopyasını isteme
  • Eksik veya yanlış işlenmiş verilerin düzeltilmesini isteme
  • Verilerinin silinmesini veya yok edilmesini isteme
  • İşlemenin kısıtlanmasını isteme ve işlemeye itiraz etme
  • Verilerini yapılandırılmış ve makine tarafından okunabilir bir biçimde alma (veri taşınabilirliği)
  • Verdiğin açık rızayı dilediğin zaman geri alma
  • İşlemenin hukuka aykırı olduğunu düşünüyorsan denetim otoritesine şikâyette bulunma — Türkiye’de Kişisel Verileri Koruma Kurumu, AB’de bulunduğun ülkedeki veri koruma otoritesi

Taleplerini utku.ayan@outlook.com adresine gönderebilirsin. Talebini bulabilmemiz için uygulamadaki Cihaz Kimliğini (Hesap ekranından kopyalanabilir) ve varsa giriş yaptığın e-posta adresini eklemeni rica ederiz. Talepler en geç 30 gün içinde ücretsiz olarak sonuçlandırılır.

11 Hesabını ve verilerini silme

Hesabının ve verilerinin silinmesi için utku.ayan@outlook.com adresine “Veri silme talebi” konulu bir e-posta gönder. E-postana şunları ekle:

  • Uygulamadaki Cihaz Kimliği (Hesap ekranı → Cihaz Kimliği → kopyala), ve/veya
  • Google/Apple ile giriş yaptıysan hesabının e-posta adresi.

Talebini aldıktan sonra en geç 30 gün içinde hesabını, cihaz kaydını, oyun geçmişini, favorilerini ve soru önerilerini kalıcı olarak sileriz ve seni e-posta ile bilgilendiririz.

Silinenler

  • Hesabın (Firebase kimliği, e-posta, görünen ad) ve hesaba bağlı coin bakiyesi
  • Cihaz kaydın ve tüm oturumların
  • Oyun geçmişin, oda kayıtların ve takma adların
  • Favorilerin ve gönderdiğin soru önerileri

Silinemeyenler

  • Satın alma ve fatura kayıtları: mali mevzuat gereği saklanması zorunludur (kişisel bağlantısı asgariye indirilir).
  • Kimliğinden arındırılmış istatistikler: artık seninle ilişkilendirilemeyen toplu sayılar.
  • Apple ve Google’daki satın alma geçmişin: bu kayıtlar mağazalara aittir; silinmesi için ilgili mağazaya başvurman gerekir.

Not: Uygulamadan çıkış yapmak (Hesap → Çıkış yap) verilerini silmez, yalnızca cihazın hesapla bağlantısını keser. Uygulamayı silmek de sunucudaki kayıtları kaldırmaz — bunun için yukarıdaki talebi göndermelisin.

12 Çocukların gizliliği

FanFini yalnızca 18 yaş ve üzeri kullanıcılar içindir. Uygulamayı ilk açtığında yaş sınırını onaylaman istenir. Bilerek 18 yaşından küçüklerden veri toplamayız. 18 yaşından küçük birine ait veri işlendiğini öğrenirsek kaydı gecikmeksizin sileriz; böyle bir durumu utku.ayan@outlook.com adresine bildirebilirsin.

13 Güvenlik

  • Uygulama ile sunucu arasındaki tüm trafik TLS ile şifrelenir.
  • Oturum anahtarları sunucuda düz metin olarak değil, yalnızca şifrelenmiş özetleriyle (hash) tutulur.
  • Veritabanında satır düzeyi güvenlik (RLS) uygulanır; veriye erişim yalnızca sunucu servisi üzerinden mümkündür.
  • Yönetim paneline erişim rol bazlıdır ve tüm yönetici işlemleri denetim kaydına alınır.
  • İstek sınırlama ve kötüye kullanım tespiti her uç noktada aktiftir.

Hiçbir sistem %100 güvenli değildir; bir güvenlik açığı fark edersen lütfen utku.ayan@outlook.com adresinden bize bildir.

14 Bu politikadaki değişiklikler

Bu politikayı zaman zaman güncelleyebiliriz. Güncel sürüm her zaman privacy.fanfini.app adresinde yayınlanır ve yukarıdaki “son güncelleme” tarihi değişir. Verilerin işlenme biçiminde esaslı bir değişiklik olursa, değişiklik yürürlüğe girmeden önce uygulama içinde bilgilendirilirsin ve gerekiyorsa yeniden onayın istenir.

15 İletişim

Gizlilikle ilgili her türlü soru, talep ve şikâyet için:

Yanıt süresiEn geç 30 gün

© 2026 FanFini · Bu sayfa uygulamanın gizlilik politikasının resmî ve güncel sürümüdür.

Privacy Policy

Last updated: 18 August 2026  ·  Effective: 18 August 2026  ·  Version 1.0

SUMMARY The short version

  • You don’t need an account to play. On first launch the app generates a random identifier for your device. It contains no name, phone number or email address.
  • Your answers never reach us. Answers are spoken out loud to the person you’re playing with — they are never typed into the app, recorded, or sent to a server.
  • We do not access your microphone, camera, location, contacts or photos.
  • We never see your payment details. Purchases run entirely through the App Store / Google Play.
  • Deleting your data takes one email: utku.ayan@outlook.com

This summary is for convenience only; the full text below is what applies.

01 Who we are

FanFini (“FanFini”, “we”, “us”) is the data controller for the personal data described in this policy, within the meaning of the Turkish Personal Data Protection Law No. 6698 (KVKK) art. 3 and the GDPR art. 4(7).

ControllerFanFini
AppFanFini — a question game for couples and friends (iOS & Android)

02 What this policy covers

This policy covers the FanFini mobile app, the backend service at api.fanfini.app, and this website.

The Consent Statement shown when you first open the app is about the rules of the game, the 18+ age limit and how players are expected to treat each other. This Privacy Policy is about how your personal data is handled. The two complement each other and we recommend reading both.

03 Data we process

The principle is simple: the least data the game needs in order to work. The table below lists every category of data we process.

DataWhenWhy
Device registration On first launch A random identifier generated for your device (Device ID), platform (iOS/Android), app version, chosen language, first-seen and last-seen timestamps. Needed so you can play without an account, return to an unfinished game, and so abuse can be blocked.
Session token On every sign-in The token that authenticates your device is stored on the server only as a cryptographic hash — never the token itself. It is revoked when it expires or when you sign out.
Account details (optional) If you sign in with Google or Apple Your Firebase user ID, email address and display name. Used only so your coin balance, gift coins, Premium membership and purchases follow you to a new phone. If you use Apple’s “Hide My Email”, all we receive is the relay address Apple generates.
Game data When creating a room and playing Room code, the nickname you use in that game, game mode and language, dice results, the IDs of the questions shown to you and the one selected or skipped, joker usage, turn counts and timestamps. Needed to keep both players in sync and to avoid repeating questions.
Favourites When you favourite a question The text of the question at that moment, its category, and the nickname of the player who answered it. Shown back to you on the Favourites screen.
Question suggestions When you submit one from “Suggest a question” The question text you wrote, the game mode and category you picked, and the submitting account. Linked to your account so suggestions can be reviewed and abuse prevented. If a suggestion makes it into the game it is never published together with your name or account.
Purchases and subscriptions When you buy coins or Premium Purchase events from the store (product code, date, status), your coin balance, Premium status and expiry date. Card numbers, bank details and billing addresses never reach us — Apple and Google handle the payment.
Ad events In free games Whether an ad was requested, shown and completed — so that free games are counted correctly. The ad itself is served by Google AdMob, which uses its own identifiers (see section 7).
Analytics and crash reports While using the app Firebase Analytics events (e.g. “game started”, “room created”) and Crashlytics crash reports (device model, OS version, stack trace). Used to spot failures and improve the game.
Technical server logs On every request IP address and request path. The IP address is held in a short-lived cache purely for rate limiting and abuse prevention; it is not joined to your game records and is not used for profiling.

You can see and copy your Device ID inside the app on the Account screen. Including it in a request helps us find your records.

04 Data we never collect

🎙️

Answers given during a game are never recorded. In FanFini answers are spoken out loud, not typed. The app does not open the microphone, does not record audio or video, and does not send the text of an answer to any server. All the server keeps is which question was selected or skipped — never the answer itself.

We also do not collect:

  • Location data (GPS or similar)
  • Contacts, call logs or messages
  • Photos, gallery or file access
  • Health, biometric or sexual-life data
  • Payment card details
  • National ID numbers, postal addresses or phone numbers

05 Purposes and legal bases

PurposeKVKK art. 5GDPR art. 6
Creating rooms and running the gamePerformance of a contract — 5/2-c6(1)(b)
Accounts, coin balances, purchases and restoresPerformance of a contract — 5/2-c6(1)(b)
Abuse prevention, fraud prevention, rate limitingLegitimate interest — 5/2-f6(1)(f)
Crash reporting and product improvementLegitimate interest — 5/2-f6(1)(f)
Personalised advertising and measurementExplicit consent — 5/16(1)(a)
Complying with legal obligations (e.g. tax records)Legal obligation — 5/2-ç6(1)(c)

Where we rely on consent (personalised advertising) you may withdraw it at any time — see section 7.

06 Service providers and sharing

We do not sell your personal data and we do not market it to third parties. Data is processed on our behalf, only as far as the service requires, by the following providers:

ProviderPurposeLocation
Supabase Inc.Database hosting (game, account and coin records)London, United Kingdom
DigitalOcean LLCApplication servers and load balancerFrankfurt, Germany
Google LLC — Firebase AuthenticationSign in with Google, account identityEU / USA
Google LLC — Firebase Analytics & CrashlyticsUsage statistics and crash reportsEU / USA
Google LLC — AdMob & UMPServing ads and managing ad consentEU / USA
Google Play Billing / Apple App StorePurchases and subscription billingEU / USA
RevenueCat, Inc.Purchase validation and subscription statusUSA

Beyond these, data is shared only (a) in response to a lawful request from a competent authority, or (b) where strictly necessary to establish, exercise or defend legal claims.

Google’s practices: policies.google.com/privacy  ·  Apple: apple.com/legal/privacy  ·  RevenueCat: revenuecat.com/privacy  ·  Supabase: supabase.com/privacy

07 Advertising and consent

FanFini is free to play. Free games are supported by Google AdMob ads. If you would rather not see them at all, you can buy coins or subscribe to Premium — no ads are shown inside those games.

Users in the European Economic Area, the United Kingdom and Switzerland are shown Google’s UMP (User Messaging Platform) consent form on first launch. Personalised ads are only served if you consent there; if you decline, ads are served non-personalised and the game works exactly the same.

On iOS, Apple’s App Tracking Transparency prompt is shown as well. You can change your advertising preferences at any time in your device settings:

  • Android: Settings → Google → Ads
  • iOS: Settings → Privacy & Security → Tracking

08 International transfers

Our application servers are hosted in Germany (Frankfurt) and our database in the United Kingdom (London). Providers such as Google, Apple and RevenueCat may also process data in the United States.

These transfers take place on the basis of your explicit consent and/or an undertaking under KVKK art. 9, and — for the GDPR — the European Commission’s Standard Contractual Clauses (SCCs) together with our providers’ data processing agreements.

09 Retention periods

  • Session tokens: revoked when they expire or when you sign out.
  • Game rooms: rooms that are never started close within minutes; finished or abandoned rooms are closed automatically within 4 hours.
  • Game and favourite records: for as long as you use the app; removed when you request deletion.
  • Account and coin records: for as long as your account exists; deleted within 30 days of a deletion request.
  • Purchase records: kept for the statutory period required by tax and accounting law (10 years in Türkiye); these are exempt from deletion requests.
  • Technical server logs: IP-based rate-limit records expire within minutes; access logs are kept for at most 30 days.
  • Analytics and crash data: subject to Google’s retention periods for Firebase.

10 Your rights

Under KVKK art. 11 and GDPR art. 15–22 you have the right to:

  • Learn whether your personal data is processed and request information about it
  • Access your data and request a copy
  • Have incomplete or inaccurate data corrected
  • Have your data erased or destroyed
  • Request restriction of processing and object to processing
  • Receive your data in a structured, machine-readable format (data portability)
  • Withdraw your consent at any time
  • Lodge a complaint with a supervisory authority — the Turkish Data Protection Authority (KVKK), or the data protection authority of your country in the EU

Send requests to utku.ayan@outlook.com. To help us find your records, please include your Device ID from the app (copyable on the Account screen) and, if you signed in, the email address of your account. Requests are handled free of charge within 30 days at the latest.

11 Account and data deletion

To have your account and data deleted, send an email titled “Data deletion request” to utku.ayan@outlook.com and include:

  • Your Device ID from the app (Account screen → Device ID → copy), and/or
  • The email address of your account if you signed in with Google or Apple.

We will permanently delete your account, device registration, game history, favourites and question suggestions within 30 days of receiving your request, and confirm by email once it is done.

What gets deleted

  • Your account (Firebase ID, email, display name) and the coin balance attached to it
  • Your device registration and all sessions
  • Your game history, room records and nicknames
  • Your favourites and any question suggestions you submitted

What cannot be deleted

  • Purchase and invoice records: retention is required by financial law (personal links are minimised).
  • De-identified statistics: aggregate counts that can no longer be connected to you.
  • Your purchase history at Apple and Google: those records belong to the stores; you need to contact them directly.

Note: signing out (Account → Sign out) does not delete your data — it only unlinks this device from your account. Uninstalling the app does not remove server-side records either; you need to send the request above.

12 Children’s privacy

FanFini is intended for users aged 18 and over only. You are asked to confirm the age limit the first time you open the app. We do not knowingly collect data from anyone under 18. If we learn that we hold data belonging to someone under 18 we delete it without delay — you can report such a case to utku.ayan@outlook.com.

13 Security

  • All traffic between the app and our servers is encrypted with TLS.
  • Session tokens are stored only as cryptographic hashes, never in plain text.
  • The database enforces row-level security (RLS); data is reachable only through the backend service.
  • Admin panel access is role-based and every administrative action is written to an audit log.
  • Rate limiting and abuse detection are active on every endpoint.

No system is 100% secure. If you find a vulnerability, please report it to utku.ayan@outlook.com.

14 Changes to this policy

We may update this policy from time to time. The current version is always published at privacy.fanfini.app, with the “last updated” date above adjusted accordingly. If we make a material change to how your data is processed, you will be informed inside the app before it takes effect and, where required, asked to consent again.

15 Contact

For any privacy question, request or complaint:

Response timeWithin 30 days