F
FPL Pro
Legal

Privacy Policy

Last updated: March 2026

This Privacy Policy explains how Keanu Pense ("we", "us", "our"), operating as the developer of FPL Pro ("the App"), collects, uses, stores, and protects your personal data when you use FPL Pro on iOS. We are committed to handling your data responsibly. This policy is written to be clear and complete. If something is unclear, contact us at keanudevlabs@gmail.com.

By downloading or using FPL Pro, you acknowledge that you have read and understood this policy.

1. Who We Are (Data Controller)

The data controller responsible for your personal data is:

Keanu Pense
Berlin, Germany
keanudevlabs@gmail.com

As a sole developer based in Germany, we are subject to the EU General Data Protection Regulation (GDPR) and the German Bundesdatenschutzgesetz (BDSG).

2. What Data We Collect

2.1 Account Data

When you create an FPL Pro account, we collect:

  • Your email address (via email/password signup, Sign In with Apple, or Google Sign In)
  • A unique user identifier (UUID) assigned by our authentication provider (Supabase)
  • Your display name (optional, if set)
  • Your avatar URL (optional, if provided by Apple or Google profile)
  • Your device locale

2.2 FPL Account Data

When you connect your Fantasy Premier League team, we collect and store:

  • FPL Entry ID β€” your FPL team number, stored locally on your device and synced to our cloud database
  • FPL squad data β€” players, positions, selling prices, and purchase prices, fetched from the FPL API to generate advice; not stored permanently on our servers
  • FPL transfer history and season history β€” fetched on demand from the FPL API; not stored permanently on our servers
  • FPL session cookies β€” stored in your device's secure Keychain to avoid repeated logins; not transmitted to or stored on our servers

2.3 App Preferences and Settings

  • Dark mode preference
  • Selected gameweek
  • Advice date range settings
  • These are stored locally on your device and synced to our cloud database under your account

2.4 Watchlist Data

  • Player IDs you have saved to your watchlist
  • Team IDs you have saved to your watchlist
  • Stored in our cloud database and synced across your devices

2.5 Sell Value Overrides

  • Custom selling price adjustments you enter for individual players
  • Stored in our cloud database per user

2.6 Premium and Subscription Status

  • Whether your account has premium access
  • The source of premium access (e.g. in-app purchase)
  • Expiry date of premium access if applicable

2.7 Newsletter Email (Optional)

If you choose to sign up for our gameweek tips newsletter:

  • Your email address
  • Your user ID if you are signed in at the time
  • Signup is entirely optional and can be requested for deletion at any time

2.8 Sync Metadata

  • Timestamp of last cloud sync, reason for sync, current gameweek at time of sync, and app snapshot version
  • Used solely to manage cross-device sync reliability

2.9 What We Do NOT Collect

  • We do not collect your location
  • We do not access your contacts, calendar, camera, or microphone
  • We do not collect your FPL password β€” it is entered directly on the official FPL website inside a WebView; we never see or store it
  • We do not use any third-party behavioural analytics SDK (no PostHog, no Firebase Analytics, no Mixpanel)
  • We do not build advertising profiles or engage in cross-app tracking

3. How We Collect Your Data

  • Directly from you β€” when you register, connect your FPL team, set preferences, or sign up for the newsletter
  • From the FPL API β€” when you load your team, the App fetches data from fantasy.premierleague.com on your behalf using your stored session
  • From Apple or Google β€” when you use Sign In with Apple or Google Sign In, we receive your email address and a unique identifier from those providers
  • Automatically during use β€” app preferences and sync metadata are captured as you use the App

4. Legal Basis for Processing (GDPR)

Under GDPR, we rely on the following legal bases for processing your personal data:

DataLegal Basis
Account data, FPL Entry IDContract β€” necessary to provide the service
Preferences, watchlist, sync metadataContract β€” necessary to provide the service
Newsletter emailConsent β€” you opted in voluntarily
Premium and subscription statusContract β€” necessary to manage your subscription
AdMob advertising data (when active)Legitimate interests / Consent as required by applicable law

You may withdraw consent for newsletter communications at any time by contacting us or using any unsubscribe link in our emails.

5. How We Use Your Data

We use your data exclusively to:

  • Create and manage your FPL Pro account
  • Load your FPL team data and generate personalised transfer and selection advice
  • Sync your preferences, watchlist, and settings across your devices
  • Manage your premium subscription status
  • Send you the gameweek tips newsletter (only if you opted in)
  • Display advertisements via Google AdMob (not yet active β€” see Section 8)
  • Maintain and improve the reliability of the App

We do not use your data for automated decision-making or profiling beyond generating FPL advice from your own team data.

6. Third-Party Services

6.1 Supabase

We use Supabase for user authentication and cloud data storage. Supabase stores your account data, preferences, watchlist, FPL Entry ID, premium status, and newsletter signups. Data is hosted in the EU. Supabase is a US company operating with EU data residency and Standard Contractual Clauses. Supabase Privacy Policy

6.2 Apple

Sign In with Apple provides your email and Apple user identifier when you choose this login method. Apple also processes all in-app subscription payments via StoreKit β€” we receive only confirmation of subscription status, not your payment details. Apple Privacy Policy

6.3 Google

Google Sign In (via OAuth) provides your email and Google user identifier if you choose to sign in with Google. Google Privacy Policy

6.4 Google AdMob

FPL Pro is integrated with Google AdMob for future advertising. Advertising is not yet active and will be introduced in a future update. When active, AdMob may collect a device advertising identifier (IDFA on iOS, if permitted), IP address, and app usage context for ad targeting. You can limit ad tracking at any time in iOS Settings β†’ Privacy & Security β†’ Tracking. Google AdMob Privacy Policy

6.5 Fantasy Premier League API

FPL Pro reads data from the official FPL API (fantasy.premierleague.com), operated by the Premier League. This includes public data (player statistics, fixtures, gameweek data) and your private team data (squad, picks, transfers, history) accessed using your FPL session. We are not affiliated with the Premier League. Premier League Privacy Policy

We do not sell, rent, or share your personal data with any third party beyond the services listed above.

7. Local Storage on Your Device

iOS Keychain (encrypted, secure)

  • Your FPL session cookies β€” used to re-authenticate without requiring a new login
  • Your FPL Entry ID
  • Your Supabase authentication context

Keychain data is protected by iOS encryption with AfterFirstUnlock accessibility β€” it is accessible only after the device has been unlocked at least once after a restart.

UserDefaults

  • Your Supabase user ID (a non-sensitive identifier)
  • Your email address (for display purposes)
  • App preferences such as dark mode setting
  • A local mirror of your FPL Entry ID for fast access

8. Cookies and Web Tracking

FPL Pro does not use browser cookies in the traditional sense. However, when you log in to FPL through the in-app WebView, cookies set by fantasy.premierleague.com are captured and stored in your device Keychain. These cookies are used solely to authenticate subsequent FPL API requests on your behalf.

We do not use tracking pixels, fingerprinting, or any cross-site tracking technologies. Google AdMob may use a device advertising identifier (IDFA) once advertising is active and if you have granted tracking permission via iOS App Tracking Transparency. You can revoke this in iOS Settings at any time.

9. Analytics

FPL Pro does not use any third-party analytics SDK. App performance data is available to us through Apple's built-in App Store Connect Analytics, which provides aggregated, non-identifiable statistics such as install counts, session counts, and crash reports. We do not receive personal data through Apple Analytics.

10. Data Storage and Security

  • All cloud data is stored on Supabase servers in the EU
  • All network communication uses HTTPS/TLS encryption
  • Sensitive credentials (FPL session cookies, authentication tokens) are stored in the iOS Keychain, which is hardware-encrypted on modern iPhones
  • We do not log or store your FPL username or password at any point
  • We take reasonable technical and organisational measures to protect your data

No system is 100% secure. In the unlikely event of a data breach affecting your personal data, we will notify you as required by applicable law.

11. Data Retention

  • Account data is retained as long as your account is active. If you delete your account, we will delete your personal data within 30 days.
  • Newsletter signups are retained until you request removal.
  • Local device data (Keychain, UserDefaults) is cleared when you sign out or delete the App.
  • FPL API data (squad, transfers, history) is fetched on demand and not stored permanently on our servers.

12. International Data Transfers

Your data may be transferred outside your country of residence:

  • Supabase stores data in the EU. As a US company using EU data residency, transfers are covered by Standard Contractual Clauses (SCCs).
  • Google (AdMob, Google Sign In) is based in the USA. Transfers are subject to Google's GDPR data transfer mechanisms.
  • Apple is based in the USA. Transfers are subject to Apple's GDPR transfer mechanisms.

By using FPL Pro, you acknowledge these transfers. We only use providers with adequate data protection frameworks under GDPR.

13. Your Rights Under GDPR

If you are in the EU or EEA, you have the following rights regarding your personal data:

  • Right of access β€” request a copy of the personal data we hold about you
  • Right to rectification β€” request correction of inaccurate or incomplete data
  • Right to erasure ("right to be forgotten") β€” request deletion of your account and all associated personal data
  • Right to restriction β€” request that we limit how we process your data in certain circumstances
  • Right to data portability β€” receive your data in a structured, machine-readable format
  • Right to object β€” object to processing based on legitimate interests
  • Right to withdraw consent β€” for any processing based on consent, such as newsletter subscription, at any time
  • Right to lodge a complaint β€” with your national data protection authority. In Germany: Berliner Beauftragte fΓΌr Datenschutz und Informationsfreiheit (datenschutz-berlin.de)

To exercise any of these rights, email keanudevlabs@gmail.com. We will respond within 30 days.

14. Children's Privacy

FPL Pro is not directed at children under 13 years of age (COPPA) or children under 16 in EU member states where a higher age of digital consent applies (GDPR Article 8). We do not knowingly collect personal data from children below the applicable minimum age.

If you believe we have inadvertently collected data from a child under the applicable minimum age, please contact us immediately at keanudevlabs@gmail.com and we will delete it promptly.

15. Changes to This Policy

We may update this policy as the App evolves. The "Last updated" date at the top of this page will always reflect the most recent version. For material changes, we will notify you via the App or by email. Continued use of FPL Pro after changes constitutes acceptance of the updated policy.

16. Contact and Data Deletion

For privacy questions, data access requests, or account deletion:

Email: keanudevlabs@gmail.com
Subject for deletion requests: "Delete my account"

Data controller:
Keanu Pense, Berlin, Germany

We will respond within 30 days of receiving your request.

← Back to FPL Pro Terms of Service
Β© 2026 FPL Pro