ZUKII Football — Privacy Policy

Effective date: 2026-05-31
Last updated: 2026-05-31

This Privacy Policy explains what information ZUKII Football (“the App”, “we”, “us”) collects, how we use it, and the rights you have over it. ZUKII Football is operated by Mikaël Tokotuu (“Operator”, contact: mikael.tokotuu@gmail.com).

By using the App you agree to this Policy.

1. Information we collect

We collect only what's needed to operate the App.

1.1 Information you provide

DataWhenPurpose
Email addressSign-up (email, Sign in with Apple, or Sign in with Google)Account identification, password recovery, transactional emails (verification codes)
UsernameSign-upPublic display on leaderboards and pool member lists
First name, last nameProfile setup or auto-filled from Apple / Google on first sign-inDisplay name
Country of nationalityOptional, profile setupCountry flag display next to your name
Date of birthOptional, profile setupValidating you meet the minimum age (13+); never displayed publicly
Profile pictureOptional, you uploadDisplay as avatar
Match predictionsWhen you predictCore function — scoring against actual results, ranking on leaderboards
Pool membershipsWhen you join a poolShowing you in pool leaderboards and member lists
Notification preferencesWhen you toggle settingsHonouring your preferences

1.2 Information collected automatically

DataPurpose
Device push token (Firebase Cloud Messaging)Sending push notifications you have opted into (match reminders, results, pool activity)
Device platform (ios or android)Routing the push token to the correct push service
Server logs (request times, HTTP status, error stack traces)Detecting bugs and abuse; stored in AWS CloudWatch for 30 days, then auto-deleted
Client IP address (in server logs only)Abuse prevention — e.g. detecting brute-force attempts on the sign-in endpoint

The App does not collect: precise location (GPS), coarse location, app version, OS version, contacts, photos beyond what you explicitly upload as your avatar, microphone, health data, financial data, advertising identifiers (IDFA), or browsing history. We have no analytics SDK and no advertising SDK.

2. Third parties

The App uses these third-party services. Each has its own privacy policy linked below.

ServicePurposeData shared with them
Apple — Sign in with AppleAuthenticationYour Apple ID identifier, full name (sent only on first sign-in, per Apple's design), and email (real or private relay — your choice in the Apple sheet). If you choose Hide My Email, we only see a @privaterelay.appleid.com address that forwards to your real email; we never see the real address.
Google — Sign in with GoogleAuthenticationYour Google account identifier, name, and email
Firebase Cloud Messaging (Google)Push notificationsDevice token, message payload (e.g. “Match XYZ has finished — see your score”)
Amazon Web Services (AWS)Backend hosting — servers, database, image storageAll data above is hosted here, in the Sydney region
Amazon SES (within AWS)Sending transactional emails (verification codes, password resets)Your email address, subject, and email body
api-sports.ioFootball data provider (fixtures, results, odds)Nothing about you. They send data to us; we send them nothing except our API key.

Native device sharing

The App offers a Share button that uses your device's built-in share sheet (Messages, Mail, third-party apps you have installed). When you tap Share, the data you choose to share is handed to the operating system (iOS / Android), not to us or our third parties. Apple's and Google's privacy policies apply to that operation.

Privacy policies of the services above

3. How we use your information

We do not sell your data, share it with advertisers, or use it for behavioural advertising.

4. Where your data lives

All your data is stored on AWS infrastructure in the Asia Pacific (Sydney) region (ap-southeast-2):

Images are delivered to the App through Amazon CloudFront — a global content-delivery network that caches images at edge locations close to you for speed. The original files always live in Sydney.

5. Data retention

DataRetention
Profile, predictions, pool memberships, leaderboard historyUntil you delete your account
Notifications history (in-app)30 days, then auto-deleted
Device push tokens90 days from last registration (which is refreshed every time you open the App), then auto-deleted
Server logs (CloudWatch)30 days
Account deletion: residual backupsUp to 7 days (AWS RDS automated daily backups roll off naturally; we cannot delete from individual snapshots)

6. Account deletion

You can delete your account at any time from inside the App:

Profile → Edit Profile → Delete Account → slide to confirm

This permanently deletes:

If you signed up with Sign in with Apple, we call Apple's revocation API so Apple removes the link between your Apple ID and Zukii Football. We do not call Google's equivalent revocation API; if you signed up with Google, you can manually disconnect Zukii Football at any time from your Google account at https://myaccount.google.com/permissions.

Your avatar is removed from S3 storage as part of deletion.

Account deletion is irreversible. There is no recovery period. Residual copies may exist in encrypted daily backups for up to 7 days before they roll off; these are never restored except in a database disaster-recovery scenario.

If you cannot access the App but wish to delete your account, email mikael.tokotuu@gmail.com with your username and we will action it within 14 days.

7. Your rights

Depending on your jurisdiction (GDPR in EU/UK, CCPA in California, the Privacy Act in Australia, etc.) you may have rights to:

To exercise any right, email mikael.tokotuu@gmail.com. We respond within 30 days.

8. Children

The App is intended for users 13 and older. We do not knowingly collect data from children under 13. If you believe a child has signed up, email us and we will delete the account.

9. Security

No system is perfectly secure. In the event of a breach affecting your personal data, we will notify you and your local authority as required by law.

10. Changes to this policy

We may update this Policy. Material changes will be announced in the App and via push notification (where you have opted in). The “Last updated” date at the top reflects the most recent change.

11. Contact

Operator: Mikaël Tokotuu
Email: mikael.tokotuu@gmail.com
App: ZUKII Football

For data-protection-specific requests, use the same email with subject line “Privacy Request”.