PRIVACY
Privacy Policy
Explains how personal data is handled in the CrossRoster application and website and the choices available to users.
Scope and data controller
This policy covers the CrossRoster iOS and Android applications, the marketing site at crossroster.app, and account action links at account.crossroster.app.
CrossRoster is provided by Adem Özsayın, an independent developer and the data controller. Privacy requests may be sent to support@crossroster.app.
Information handled
Play can begin with a stable, opaque player identity. Short-lived access and resume credentials are handled to operate the session. When an account is created, CrossRoster handles a username and a one-way password-verification hash; if the player adds one, it also handles a private recovery email, verification state, and language preference.
When game and social features are used, CrossRoster may handle room membership, picks, typed answers, scores, match results and history, friendships, requests, invitations, notification records, and notification preferences.
- Recovery email never appears in public player, friend, invitation, leaderboard, room, or match data.
- Passwords are not stored in plain text; access and resume credentials are secret values belonging to the user.
- The marketing site uses no analytics, ads, session replay, tracking pixels, or tracking cookies and does not call the CrossRoster API from the browser.
- No user account, answer, or personal data is sent to the football catalog provider during a match.
Purchases and CrossRoster Plus
In builds that offer purchases, purchases and billing are processed by the Apple App Store on iOS and Google Play on Android. CrossRoster does not directly receive payment-card details. Only the stable, opaque CrossRoster player ID is supplied to RevenueCat as the App User ID; usernames, email addresses, passwords, and access or resume tokens are not used as that identity.
Product, entitlement, and transaction status may be handled for subscription verification, purchase restoration, support, fraud prevention, and Plus access management. The server stores entitlement status and any expiration time matched to the relevant player identity.
Commercial transaction status supplied by Apple, Google Play, or RevenueCat may be used for payment disputes and refunds; CrossRoster does not receive or store a full payment-card number.
Notifications and device information
On iOS, when the user enables notifications, an installation ID, opaque APNs device token, app environment, language, and notification preferences are associated with the player identity. Apple Push Notification service is used only to deliver notifications. In Android builds supporting remote notifications, Firebase Cloud Messaging (FCM) handles an installation ID, device registration token, language, and notification preferences for delivery. This does not mean remote notifications are enabled in every Android test build.
Push content is a limited routing hint that an item changed; it does not carry a password, access credential, email address, invite code, or room capability. Notifications can be managed in system settings and within CrossRoster.
Optional measurement and error reports
In versions offering measurement preferences, usage analytics, technical error reports, and advertising attribution are separate and optional. You can continue playing without granting permission. You can change these choices in the app’s privacy and measurement settings; available data categories depend on the version you use.
If you allow usage analytics, PostHog processes limited events such as screens visited, button and operation types, success or error codes, times and durations, and app version. Events may be associated with your opaque player ID. Purchase and subscription outcomes within your permission may be added from RevenueCat and the CrossRoster server. Email, passwords, access tokens, payment-card information, and entered gameplay answers are not added to analytics events.
If you allow technical error reports, limited operation and error codes may be shared with Sentry and associated with your opaque player ID. Native crash reports have a separate device preference. In versions with the updated explicit-consent flow, collection does not start until you enable it; some earlier test builds may enable it by default. They contain technical stack information, app version, build, time, and operating information, but not your player ID, email, or entered text. The provider can see the network source IP during transmission; omitting identity fields does not make reports completely anonymous.
If you allow measurement of how you found us, AppsFlyer processes installation, app-opening, advertising or campaign source, and permitted conversion data. Device and advertising identifiers may be used depending on your permissions and platform. Approximate region/city information may be derived from the IP address; technical performance information such as app launch timing may be processed for measurement and fraud detection. Precise location is not collected. On iOS, tracking that links activity with other companies’ apps or websites additionally requires Apple’s tracking permission. This choice does not enable personalized advertising or retargeting. Measurement identifiers may be shared with RevenueCat for purchase attribution.
Turning permission off stops new optional transmissions; it does not by itself delete data already sent. Pending local crash reports are cleared when you turn reporting off, and reports older than seven days are not sent. Crash records without an account identity may not be locatable or deletable using your account ID alone. Contact support@crossroster.app for data and deletion requests.
Older Android versions containing Firebase Crashlytics may collect diagnostics automatically without an in-app opt-out. New versions with measurement controls disable automatic Crashlytics collection and use the Sentry permissions described above. Updating the app does not automatically delete older provider records.
On-device speech input
On iOS, speech input is optional and works only after the user grants microphone and speech-recognition permissions. Recognition is required to run on the device; CrossRoster does not retain raw audio or upload it to its servers. If the user submits the resulting editable text as an answer, it is handled like any other game answer.
Purposes and legal grounds
Information is used to operate the game and account, run private rooms and matches, fulfill friendship and notification preferences, verify subscriptions, provide support, preserve score and history integrity, secure the service, and prevent abuse and fraud.
For users in Türkiye, processing may rely as applicable on necessity to enter into or perform the service contract, compliance with legal obligations, establishment, exercise, or protection of a right, and legitimate interests that do not harm fundamental rights. Where explicit consent is required for an optional feature, it is requested separately and can be withdrawn.
Service providers and international transfers
CrossRoster uses DigitalOcean for hosting, Resend for account-recovery email, RevenueCat for subscription management, and Apple for iOS payments and push delivery. Google Play is used for supported Android purchases. CrossRoster uses PostHog for optional analytics, Sentry for technical error and crash reports, AppsFlyer for attribution, and FCM where remote notifications are supported. Older Android versions may use Firebase Crashlytics. Each provider receives only the limited data needed for its function.
These providers and their subprocessors may process data outside Türkiye. International transfers are handled under applicable data-protection requirements and contractual safeguards with the providers. User data is not sold for advertising.
Retention and deletion
Access credentials are valid for approximately 15 minutes and resume credentials for approximately 30 days; previous values become invalid when rotated. Email-verification links are valid for 24 hours and password-reset links for 15 minutes.
Account and social data is kept while the account remains open. The notification inbox is limited to the newest 100 records; a push-device record is removed on logout, account change, device deregistration, or account deletion and is disabled when the provider invalidates its token.
Account deletion removes the username, password-verification data, recovery email, friendships, pending social actions, notifications, preferences, and push devices. Anonymous match summaries and limited subscription events associated with the opaque player ID may be retained as necessary for completed-match integrity and subscription disputes; data that is no longer necessary is deleted or anonymized.
Choices, rights, and contact
Account deletion is available in the app. Notification preferences can be managed in the app, system notification permission in device settings, and subscriptions in the Apple Account or Google Play subscription settings used for the purchase.
Users may ask whether their data is processed, request information or a copy, correction, deletion or anonymization, object to unlawful processing, and exercise other applicable rights by contacting support@crossroster.app. CrossRoster applies technical and organizational measures intended to reduce unauthorized access.