Privacy Policy for Fawazeer

Last updated: August 27, 2026

This Privacy Policy explains how IT Consulting and Expertise ("we", "us", "our") collects, uses, stores, shares, and protects information when you use Fawazeer (the "App"), our mobile application, and any related website or support pages that link to this policy.

Localized versions of this policy are available in:

In case of discrepancy between translations, the English version governs.

1. Who We Are

Fawazeer is provided by:

For the purposes of applicable privacy law, including the EU General Data Protection Regulation (GDPR), the UK GDPR, and the California Consumer Privacy Act (CCPA/CPRA), IT Consulting and Expertise is the data controller for the personal data described in this policy.

2. Scope of This Policy

This policy applies to:

  • The Fawazeer mobile app on iOS and Android
  • Any website, landing page, or support page for Fawazeer that links to this policy
  • Communications you send us about Fawazeer

The app and our websites are separate surfaces with different data practices. Where a statement below applies to only one of them, it says so. In particular, the in-app analytics setting controls the app only; our websites are described in Section 4.K.

This policy does not apply to third-party services that have their own privacy policies. Links to those policies are provided in Section 7.

3. Summary — at a glance

  • The core game works offline and without an account. No personal data is required to play.
  • Cloud sync, leaderboards, and product analytics are optional. In the app, product analytics and error reporting are off by default — you choose whether to turn them on (there is a setting when you set up your account, and you can change it anytime in Settings → Privacy).
  • Ads may be personalized, depending on your consent. In the EEA and UK we ask through Google's consent form; on iOS the advertising identifier is additionally governed by Apple's App Tracking Transparency prompt, which we show after you solve your first riddle. See Section 4.E.
  • We measure our own advertising. If you install Fawazeer after seeing one of our ads or links, our measurement partner AppsFlyer attributes that install. See Section 4.F.
  • We derive an approximate location (country, region, city) from your IP address when the app talks to our servers. See Section 4.H.
  • We never store your GPS coordinates. Device location is requested only if you tap "Use my location" during setup, and only the resulting country code is kept.
  • You can delete your account and all associated data at any time from the Profile screen, or at https://fawazeer.app/account-deletion.
  • We do not sell your personal data.
  • We never access your contacts, photos, microphone, camera, calendar, or biometric data.

4. Information We Collect

We only collect information needed to operate, improve, support, and sustain Fawazeer.

A. Information stored locally on your device

Fawazeer stores gameplay and preference data locally (via MMKV on-device storage). This information never leaves your device unless you enable cloud sync:

  • Coin and hint balances
  • Solved and skipped riddle IDs
  • Unlocked packs and progression
  • Streaks, scores, and gameplay statistics
  • Settings (sound, haptics, language)
  • Ad-free flag (from an active subscription, or a legacy "Remove Ads" purchase)
  • Cached consent decisions (your analytics opt-in choice, and the ATT result)

B. Account information (optional — only if you sign in or enable cloud sync)

If you sign in with Apple, Google, or continue as an anonymous cloud user, we collect:

  • Anonymous or OAuth user ID — a random identifier created by Supabase Auth
  • Email address — only if you sign in with Apple or Google and choose to share your email (Apple offers an email relay; Google may provide your account email)
  • Display name — only if you voluntarily set one in the Profile screen (2–20 characters)

C. Gameplay sync data (optional — only if cloud sync is enabled)

If cloud sync is enabled, your game state and scores are synchronized to our backend:

  • Full serialized game state (coins, hints, solved/skipped IDs, streaks, stats)
  • Per-submission scores (total correct, total wrong, total skipped, best streak, total coins earned, packs completed)
  • Daily challenge completion records (one per day)

Cloud sync and the leaderboard include server-side anti-cheat protections that validate submissions against your previous state.

Content you type. Some features let you enter free text — a note when you report a riddle, and the name of a private club you create. That text is stored on our backend so we can act on it. Please do not include personal details in it.

What other players can see. If you appear on a leaderboard or play a duel or a group game, other participants see your display name, your avatar, your score and your rank, and — on the country and regional boards — the country your account is associated with.

D. Product analytics and error reporting (optional — only after you grant consent)

In the app, product analytics and error reporting are off by default. Only if you turn them on — there is a clear opt-in when you set up your account, and you can change it anytime in Settings → Privacy — Fawazeer uses Firebase Analytics (Google LLC) and PostHog (product analytics, hosted in the EU) to collect:

  • Event data — product interactions such as app_opened, riddle_started, riddle_answered, hint_used, pack_opened, pack_completed, iap_started, iap_completed, ad_impression, rewarded_ad_completed, language_changed, sign_in, sign_up
  • User properties — player level, player tier, streak bucket, ad-free flag, first-open date, country (ISO code), locale (BCP-47)
  • User ID — your Supabase ID, only after non-anonymous sign-in
  • App-instance ID — a pseudonymous Firebase identifier tied to this install
  • Device and session metadata — device model, OS version, app version, session duration
  • Error information — when something fails (an ad fails to load, a sync call fails, a screen fails to render), we send the name of the failure and a truncated error message — at most 140 characters, and 80 in most cases — never free-form content you typed. We do not collect stack traces, breadcrumbs, or memory dumps: the app contains no crash-reporting SDK such as Crashlytics, Sentry, or Bugsnag.
  • Product-analytics events (PostHog) — the same kind of in-app interaction events as above, sent to PostHog's EU-hosted Cloud (Frankfurt, Germany) so we can understand feature usage and funnels. Session replay is not enabled. PostHog data is tied only to pseudonymous identifiers, never your name or email.

If you leave analytics off, the events, user properties, and error information listed above are not collected — our Firebase and PostHog calls stay disabled. You can turn analytics on or off at any time from Settings → Privacy in the app; turning it off stops collection immediately. This analytics choice is a single in-app control that applies on all platforms, and is separate from Apple's App Tracking Transparency (which only governs the advertising identifier used for ads) and from your ads-consent choice (Section 4.E).

One exception, on the very first launch after you install the app. Google's Firebase SDK starts as part of app startup, before the app has had a chance to apply your analytics choice. On that first launch only, a small number of Firebase's automatic events (such as first_open, session_start, and screen views) and the device and advertising identifiers attached to them may be recorded even if you have not opted in. Your choice is applied from the second launch onward, and it persists. We are addressing this in a future app update.

Two things are collected regardless of this setting, because they are not product analytics: the crash and performance data that the Google Mobile Ads SDK collects about itself in order to stay stable (Section 4.E), and install-attribution data (Section 4.F).

E. Advertising

We display ads served by Google AdMob (banner, interstitial, and rewarded formats). Whether those ads are personalized depends on your consent, and the rules differ by region and platform:

  • In the EEA, the UK, and Switzerland, we present Google's certified consent form (the User Messaging Platform, "UMP") before ads are served. Your choices are recorded in an industry-standard consent string that AdMob reads on every ad request. If you decline personalization, ads are non-personalized.
  • Elsewhere — including most of the Middle East and North Africa — that consent form is not legally required and is not shown, and ads may be personalized, subject to the advertising-identifier controls below and to your device settings.
  • On iOS, in addition to the above, using the advertising identifier (IDFA) for cross-app tracking requires your permission through Apple's App Tracking Transparency (ATT) prompt. We show that prompt after you have solved your first riddle, so the request has context. If you decline, ads are served without the IDFA.
  • You can change your mind at any time — in the EEA/UK through the privacy options in the app's Settings; on iOS through Settings → Privacy & Security → Tracking → Fawazeer; on Android through Settings → Google → Ads, where you can also delete or reset your advertising ID.

To deliver and measure ads, Google may process:

  • The advertising identifier — IDFA on iOS (only with ATT permission) and the Google Advertising ID on Android
  • Ad interactions (impressions, clicks, reward completions)
  • Approximate location inferred from IP address or device region
  • SKAdNetwork postbacks on iOS (privacy-preserving attribution that cannot be joined to an individual)
  • Technical device information (model, OS, app version, language)
  • Crash and performance data of the ad SDK itself, which Google collects to keep the SDK stable. This follows your ads-consent choice, not the analytics setting in Section 4.D.

An active "Treasure of Riddles" subscription removes all ads — while it is active, no ad requests are made at all. Players who purchased the older one-time "Remove Ads" product keep that benefit on their existing install, and across their devices if they use cloud sync. That product has been retired and can no longer be purchased or restored from the store.

F. Attribution and install measurement

To understand which of our ads, posts, and links actually bring players to Fawazeer — and to avoid paying for advertising that does not work — we measure app installs and a small number of early milestones. This measurement is not controlled by the in-app analytics setting in Section 4.D; it is part of how we operate the app commercially. On iOS, use of the advertising identifier for it is governed by the ATT prompt described in Section 4.E.

We use AppsFlyer Ltd. as our mobile measurement partner. AppsFlyer receives:

  • Advertising and device identifiers — the AppsFlyer ID (generated for this install), the Google Advertising ID on Android, and on iOS the vendor identifier (IDFV) and, only if you allow tracking through the ATT prompt, the IDFA. Because our ATT prompt appears after your first solved riddle rather than at launch, your first session is measured without the IDFA.
  • Install and campaign attribution data — the referring ad network, campaign, ad set, and creative, where a network provides them.
  • The Google Play Install Referrer on Android — a string provided by Google Play that names the campaign or link that led to the install.
  • Six in-app milestone events, each sent at most once per install: completing onboarding (af_complete_registration), your first solved riddle (first_solve), returning the day after installing (d1_return), reaching a 3-day streak (streak_3), a subscription purchase (af_purchase), and a free-trial start (af_start_trial). Purchase events carry the product identifier — never payment details.
  • Purchase and revenue events, sent to AppsFlyer by RevenueCat server-to-server, so that subscription revenue can be attributed to the campaign that produced it.

On iOS we also use Apple's SKAdNetwork, with postbacks routed to AppsFlyer. SKAdNetwork is Apple's privacy-preserving attribution system: it reports aggregated campaign performance and cannot be tied back to you.

Campaign parameters from our links. If you reach Fawazeer through one of our links, the utm_source, utm_campaign, utm_content, utm_medium, and utm_term parameters in that link may be read, and a short campaign label (for example paid_tiktok) may be stored once on your account profile as your signup source. It is written once and never overwritten. Our landing pages also detect whether the link carries an advertising click identifier (for example ttclid, gclid, fbclid, sccid, or twclid), which is how we recognise paid traffic. We record only that one was present — never its value.

Deferred deep links — matching a web visit to an install. When you open a Fawazeer riddle, share, or invite page on a phone, our website stores a one-way, salted hash of your IP address (SHA-256 — the raw IP address is never stored), together with the link you opened and your platform, so that if you go on to install the app we can take you straight to the same riddle. This happens on the page view itself, whether or not you ever install. When the app first launches, it asks whether a match exists. A record is deleted the moment it is claimed, and it can only be matched within a short window — 60 minutes, our current setting. Unclaimed records are removed by a clean-up routine that runs whenever a match is attempted, normally within 48 hours.

Separately, we keep a counter-style log of how often this matching succeeds or fails, so we can tell whether the feature works. Each entry records the step, the outcome, the link type, the platform, how much time elapsed between the web visit and the app launch, and when the entry was written. It contains no identifier of any kind — no IP address, no hash, no token, no account id. These entries are kept for around 90 days.

G. Purchases and subscriptions

In-app purchases (coin packs, hint packs) and the auto-renewable "Treasure of Riddles" subscription are processed end-to-end by Apple and Google's billing systems. We never see your payment card number. We receive and store:

  • Product identifier (SKU)
  • Transaction status
  • Transaction timestamp
  • Receipt token (used to verify and restore purchases)

For subscriptions specifically, we also use RevenueCat Inc. (USA) as our subscription-receipt validation processor. RevenueCat receives the App Store / Google Play receipt at the moment of purchase and on each renewal, validates it with Apple / Google, and returns the entitlement status (active / trial / grace / cancelled / expired), the expiration date, and the auto-renewal flag. We mirror this status to your account profile via a server-to-server webhook so the ad-free entitlement and exclusive cosmetics resolve consistently across devices and reinstalls.

RevenueCat does not receive your name or email address. It receives your anonymous Supabase user ID (used to link entitlements to your account when you sign in), the platform receipt itself, and — so that subscription revenue can be attributed to the campaign that produced it — your advertising and AppsFlyer identifiers, which it forwards to AppsFlyer as described in Section 4.F.

H. Location

Fawazeer does not request device location on launch, and we never store your GPS coordinates. There are two distinct things to separate here.

1. Device location — only if you ask for it. During setup, the region step offers a "Use my location" button. Only if you tap it do we ask your operating system for when-in-use location permission and take a single position reading. What then happens is important, because it involves your operating system's provider:

  • Those coordinates are sent to your device's built-in geocoding service — Apple's on iOS, Google's on Android — which is an online service, in order to turn the position into a country. We receive only the resulting country code, and only that country code is stored or transmitted onward by us. We never receive, store, or transmit the coordinates themselves.
  • Your operating system, not us, decides how precise that reading is. On iOS you can grant location with Precise Location turned off, and on Android you can grant approximate location; the app works the same either way, because all we use is the country.
  • Background location is disabled on both platforms — the app cannot access your location unless it is open in front of you.
  • You can decline this entirely and pick your region from a list instead. Nothing in the game depends on it.

2. Approximate location derived from your IP address — always, and not covered by the analytics setting. When the app talks to our servers, our backend derives an approximate location — country, region, and city — from the IP address of your connection, and stores it on your account profile. We use it for regional content, country and regional leaderboards, fraud prevention, and internal analytics and reporting — understanding which countries and cities our players come from, so we can decide where to focus the game and our advertising. The lookup runs against a MaxMind GeoLite2 service that we operate ourselves (geo.itcexpertise.com, hosted in the EU) — your IP address is not sent to a third-party geolocation vendor for this. City-level accuracy derived from an IP address is coarse and typically identifies only the nearest large city or your network operator's location, not your address.

If your device's operating system does not expose a region setting and you have granted analytics consent, the app may additionally call ipapi.co once to resolve a country code from your IP address. This call is off unless you have opted into analytics.

We do not ask for, and never receive, a street address, a postcode, or your exact position.

I. Push notifications (optional)

If you grant notification permission on your device, we send transactional and engagement notifications (for example: daily-challenge reminders, streak reminders, new pack releases, important service updates). To deliver them we process:

  • Device push token — issued through Expo's push service (Expo / 650 Industries, Inc.), which relays to Apple Push Notification service (APNs) on iOS and Firebase Cloud Messaging (FCM) on Android. The token is stored on our Supabase backend and tied to your user ID, and is deleted when you sign out.
  • Notification preferences — which channels you have enabled or disabled
  • Delivery and open events — used to measure notification effectiveness and to avoid sending to inactive installs

If you enable the optional "quiet during prayer times" setting, the app fetches prayer timings from the public AlAdhan API. That request contains today's date, your country name, and a single representative city chosen from a fixed list built into the app — for example Riyadh for Saudi Arabia, Cairo for Egypt, Dubai for the United Arab Emirates. It carries no identifier of any kind. The city is the same for everyone in a country: it is not your city and cannot be used to locate you.

You can disable notifications at any time in your device Settings or from Profile → Notifications. Revoking the OS permission stops all further notifications immediately.

J. Support correspondence

If you email us, we will collect your name, email address, and the contents of your message.

K. Our websites

fawazeer.app and our marketing and support pages are a separate surface from the app. The in-app analytics setting does not control them.

  • Web analytics. On our marketing, SEO, and landing pages — the language-prefixed pages under fawazeer.app/ar, /en, and /fr — we use Vercel Analytics and Vercel Speed Insights for aggregate page-view and performance metrics. They are not loaded on the group-play, share, or invite pages. Separately, specific actions on those pages send events through a server-proxied PostHog pipeline. This collection currently runs without asking: our websites do not yet present a cookie or analytics consent banner. If you do not want it, you can block it with your browser's tracking protection or an ad blocker.
  • A visitor identifier. We store a random identifier (fz_vid) in your browser's local storage so repeat visits can be counted. It contains no personal data, is never linked to your name or email, and you can remove it by clearing site data for fawazeer.app.
  • Deferred deep-link matching. As described in Section 4.F, a salted one-way hash of your IP address is stored when you view a riddle, share, or invite page on a phone, normally for no more than 48 hours, so that a later app install can be connected to that visit. The raw IP address is never stored.
  • The riddle-contribution form. If you submit a riddle, we send the submission — along with the name and social handle you choose to type, and your IP address and browser user-agent, which we use to rate-limit abuse — to our private review channel on Telegram.
  • Cookies. Where cookies are used, they are limited to essential functionality, preferences, and security. You can manage cookies in your browser settings.

5. Legal Bases for Processing (GDPR / UK GDPR)

Purpose Legal basis
Providing offline gameplay Not applicable — data stays on your device
Creating a cloud account and syncing your game state Performance of a contract (Art. 6(1)(b))
Leaderboards and anti-cheat Legitimate interest in fair play (Art. 6(1)(f))
Product analytics and error reporting (Firebase Analytics, PostHog) Consent (Art. 6(1)(a)) — via the in-app analytics setting, off by default
Personalized advertising in the EEA / UK / Switzerland Consent (Art. 6(1)(a)) — via Google's UMP consent form
Use of the advertising identifier on iOS Consent (Art. 6(1)(a)) — via Apple's App Tracking Transparency prompt
Personalized advertising outside the EEA / UK Legitimate interest in sustaining a free app (Art. 6(1)(f)), subject to local law and to your device's advertising-ID controls
Non-personalized ads Legitimate interest in sustaining a free app (Art. 6(1)(f))
Install attribution and campaign measurement (AppsFlyer) Legitimate interest in measuring the effectiveness of our own advertising (Art. 6(1)(f)); on iOS, consent via ATT for use of the advertising identifier
Approximate location derived from your IP address (country / region / city) Legitimate interest in regional content, regional leaderboards, fraud prevention, and internal analytics and reporting (Art. 6(1)(f))
Push notifications Consent (Art. 6(1)(a)) — obtained via the OS notification permission prompt
Processing purchases Performance of a contract (Art. 6(1)(b))
Handling your support requests Legitimate interest / contract
Security, fraud prevention, anti-cheat Legitimate interest (Art. 6(1)(f))
Website analytics and abuse prevention Legitimate interest (Art. 6(1)(f))
Legal compliance Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, you can object at any time using the contact details in Section 16.

6. How We Use Information

We use information to:

  • Provide and maintain Fawazeer
  • Save and synchronize your progress across devices
  • Operate global, country, and weekly leaderboards
  • Deliver and measure advertising (per your consent choice)
  • Measure which of our own campaigns and links bring players to the app
  • Analyze usage to improve the experience (only per your consent choice)
  • Respond to support requests
  • Process purchases and restore entitlements
  • Protect against cheating, fraud, and abuse
  • Comply with legal obligations

7. Who We Share Information With (Data Recipients)

We do not sell your personal data. We share limited information with the following processors and partners, each acting under their own privacy policy:

Processor Purpose Region Policy
Google LLC — Firebase Analytics Product analytics and error events (consent-gated in-app) USA / global https://firebase.google.com/support/privacy
PostHog Product analytics (consent-gated in the app; always on for our websites) EU Cloud (Frankfurt, Germany) https://posthog.com/privacy
Google LLC — Google AdMob Ad serving, ad measurement, consent management (UMP) USA / global https://policies.google.com/technologies/ads
AppsFlyer Ltd. Mobile install attribution and advertising measurement Israel / EU / USA https://www.appsflyer.com/legal/services-privacy-policy/
Expo / 650 Industries, Inc. Push-notification delivery, over-the-air app updates USA / global https://expo.dev/privacy
Google LLC — Firebase Cloud Messaging Push-notification relay on Android USA / global https://firebase.google.com/support/privacy
Apple Inc. — APNs Push-notification relay on iOS USA / EU https://www.apple.com/legal/privacy/
Supabase Inc. Backend auth, cloud sync, leaderboards, RPC EU (Stockholm, eu-north-1) https://supabase.com/privacy
Apple Inc. Sign in with Apple, iOS App Store billing, ATT framework, SKAdNetwork, and — only if you tap "Use my location" on iOS — the geocoding service that turns a position into a country USA / EU https://www.apple.com/legal/privacy/
Google LLC Sign-In with Google, Google Play billing, Play Install Referrer, and — only if you tap "Use my location" on Android — the geocoding service that turns a position into a country USA / global https://policies.google.com/privacy
RevenueCat Inc. Subscription receipt validation, customer-info webhooks, revenue forwarding to AppsFlyer USA / global https://www.revenuecat.com/privacy
Vercel Inc. Website hosting, Vercel Analytics and Speed Insights USA / global https://vercel.com/legal/privacy-policy
Telegram Private review channel that receives riddle submissions from our website form Global https://telegram.org/privacy
ipapi.co Country lookup from IP address — only when analytics consent is granted and the OS exposes no region EU / global https://ipapi.co/privacy/
AlAdhan API Prayer timings for the optional "quiet hours" feature — receives a date, a country name, and a fixed representative city; no personal data Global No published privacy policy; see https://aladhan.com/credits-and-terms

Operated by us, not a third party: the IP-to-location lookup used in Section 4.H runs on geo.itcexpertise.com, a MaxMind GeoLite2 service running on infrastructure that IT Consulting and Expertise — the same company that publishes Fawazeer — operates in the EU (Finland). Your IP address is not disclosed to a third-party geolocation vendor for that lookup.

We may also share information with legal authorities when required by law, or in connection with a corporate transaction such as a merger, acquisition, or sale of assets (with appropriate safeguards).

8. International Data Transfers

Personal data may be processed in countries outside the European Economic Area, including the United States and Israel. When such transfers occur, we rely on appropriate safeguards such as Standard Contractual Clauses (SCCs) published by the European Commission, on European Commission adequacy decisions where one exists (Israel benefits from an adequacy decision), and on our processors' self-certifications where applicable (for example, the EU–US Data Privacy Framework).

Our primary backend database (Supabase) is hosted in the EU (Stockholm, Sweden), our product-analytics provider (PostHog) is hosted in the EU (Frankfurt, Germany), and our IP-to-location service runs on our own EU infrastructure, to minimize cross-border transfers for EU users.

9. Data Retention

Data Retention
Local on-device data Until you uninstall the app or use Profile → Reset Progress
Cloud account and game state Until you delete the account (Profile → Delete Account) — immediate cascade through profiles, weekly_scores, daily_completions, game_state
Approximate location on your profile (country / region / city) and your signup source Stored on your profile; deleted when you delete your account
Free text you typed (riddle-report notes, club names) Until the report is actioned, or until you delete your account
Weekly leaderboard scores Rolling 12-month window for historical analysis; your row is deleted when you delete your account
Firebase Analytics user-level data 14 months (maximum permitted by Firebase); aggregate reports retained indefinitely and cannot be tied back to an individual
PostHog product-analytics data Retained per our PostHog (EU) configuration; deleted on account deletion or on request
AppsFlyer attribution data Per AppsFlyer's documented retention for our account; deleted on request
Deferred deep-link match records (salted IP hash) Deleted the moment they are claimed; otherwise removed by a clean-up routine that runs whenever a match is attempted, normally within 48 hours
Deferred deep-link funnel counters (no identifiers) Around 90 days, removed by the same clean-up routine
Push-notification tokens Until you sign out, revoke notification permission, delete the app, or delete your cloud account
Advertising ID data at Google AdMob Per Google's AdMob retention policy
Purchase receipts As long as required by Apple / Google platform policies and tax law
Subscription entitlement state at RevenueCat Until you delete your account or until RevenueCat's documented retention period elapses, whichever is sooner
Website visitor identifier (fz_vid) Stored in your browser until you clear site data
Riddle submissions in our Telegram review channel Until reviewed and actioned; deleted on request
Support correspondence Up to 3 years after last interaction

10. Data Security

We use HTTPS/TLS for all data in transit, row-level security (RLS) on the Supabase database, server-side anti-cheat validation on score submissions, salted one-way hashing instead of raw IP storage for deep-link matching, and encrypted on-device storage (MMKV). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

11. Your Rights

Depending on where you live, you may have the right to:

  • Access the personal data we hold about you
  • Correct inaccurate data
  • Delete your personal data
  • Object to or restrict certain processing, including processing based on legitimate interests
  • Withdraw consent for analytics and personalized ads at any time (see below)
  • Data portability — receive a copy of your data in a machine-readable format
  • Lodge a complaint with your data protection authority (in France: CNIL)
  • California residents: rights under the CCPA/CPRA, including the right to opt out of the "sharing" of personal information for cross-context behavioral advertising. We treat the advertising-identifier flows to Google and to AppsFlyer as "sharing" for CCPA purposes; you can opt out by declining App Tracking Transparency on iOS, by resetting or deleting your advertising ID on Android, or by subscribing to the ad-free tier.

How to exercise your rights:

Action How
Turn product analytics & error reporting off (all platforms) In the app: Settings → Privacy → Analytics → toggle off
Withdraw ad-tracking consent (iOS) iOS Settings → Privacy & Security → Tracking → Fawazeer → off
Reset or delete your advertising ID (Android) Settings → Google → Ads
Change ad-personalization consent (EEA / UK) In the app: Settings → Privacy options
Disable push notifications OS Settings → Notifications → Fawazeer, or Profile → Notifications
Sign out (keep your cloud data) Profile → Sign out
Delete your account and all cloud data Profile → Delete Account, or https://fawazeer.app/account-deletion (confirmation required; action is immediate and irreversible)
Reset local progress Profile → Reset Progress
Any other request Email mehdi.jabri@itcexpertise.com, or contact@fawazeer.app

We respond to verified requests within one month (extendable by two months where the request is complex, per GDPR Art. 12(3)).

12. Consent Management

  • Product analytics & error reporting: Off by default in the app. You choose whether to turn them on when you set up your account during onboarding, and you can change your choice at any time in Settings → Privacy inside the app. Turning the setting off stops Firebase and PostHog collection immediately. This is a single in-app control that applies on all platforms and is independent of Apple's App Tracking Transparency and of your ads-consent choice. See the first-launch exception noted in Section 4.D.
  • Advertising (EEA / UK / Switzerland): Before ads are served we present Google's certified UMP consent form. You can reopen it at any time from the app's Settings → Privacy options.
  • Advertising (iOS): We present Apple's App Tracking Transparency (ATT) prompt after you have solved your first riddle, so the request has context. It controls whether the advertising identifier (IDFA) may be used for cross-app tracking by AdMob and AppsFlyer. Declining does not stop ads; it stops the IDFA being used.
  • Advertising (Android): You control your advertising ID from Settings → Google → Ads, where you can reset it or delete it entirely.
  • Attribution: Install measurement (Section 4.F) is not controlled by the in-app analytics setting. On iOS, the identifier it may use is controlled by ATT. On Android, deleting your advertising ID limits it.
  • Push notifications: Delivered only if you grant the OS-level notification permission. You can revoke it at any time in your device Settings, or toggle categories from Profile → Notifications.
  • Our websites: There is currently no consent banner on our websites; see Section 4.K for what we collect there and how to block it.

13. Children's Privacy

Fawazeer is a General Audiences app intended for players of all ages. It is not directed at children under 13 (or the equivalent minimum age in your country), and we do not knowingly collect personal data from such children. During onboarding we ask for your age range; analytics and personalized features are never enabled for anyone who indicates they are under 13. If you believe a child has provided us personal data, contact us and we will delete it.

14. Third-Party Services

Fawazeer relies on the third-party services listed in Section 7. Those services operate under their own terms and privacy policies. We encourage you to review them.

15. Changes to This Privacy Policy

We may update this policy from time to time. Material changes will be announced in the app and/or on our website, and the "Last updated" date above will be revised. Continued use of Fawazeer after such notice means you accept the updated policy.

Version history:

  • August 27, 2026 — Major accuracy update for the 1.5.0 release. Added AppsFlyer Ltd. as a mobile measurement partner and a new Attribution and install measurement section covering install attribution, the Play Install Referrer, SKAdNetwork, campaign parameters, and deferred deep-link matching by salted IP hash. Corrected the advertising section: ads are personalized where consent allows, not universally non-personalized, and personalized advertising outside the EEA/UK now has a stated legal basis. Corrected the App Tracking Transparency timing — the prompt is shown after your first solved riddle, not on first launch. Corrected the location section: an approximate country, region, and city are derived from your IP address and stored on your profile; the service performing that lookup is operated by us; the "Use my location" button lives on the setup region step, not the Profile screen; and the position it reads is resolved to a country by your operating system's geocoding service (Apple or Google), which the previous version did not disclose. Removed Firebase Crashlytics, which is not present in the app, and described the error information that is actually collected. Disclosed the first-launch Firebase exception to the analytics opt-in. Added Expo, Telegram, ipapi.co, AlAdhan, and Vercel Analytics as recipients. Described our websites separately from the app, including the absence of a consent banner and the fz_vid visitor identifier. Replaced the retired "Remove Ads" product with the subscription. Added retention rows for attribution, deep-link, location, and user-typed content.
  • June 3, 2026 — Added PostHog (EU Cloud, Frankfurt) as a product-analytics processor. Clarified that analytics and crash reporting are an in-app opt-in, off by default (controlled in Settings → Privacy), applied on all platforms and separate from Apple's App Tracking Transparency — ATT is now described as governing the advertising identifier only.
  • May 3, 2026 — Added the "Treasure of Riddles" auto-renewable subscription. RevenueCat Inc. added as a subscription-receipt validation processor. Subscription entitlement state retention added.
  • April 21, 2026 — v2.0 release. Added Firebase Analytics, crash and error reporting, push notifications, cloud account and sync, Sign in with Apple / Google, named all data processors and retention periods, expanded GDPR / CCPA rights section, added Arabic and French translations.
  • April 13, 2026 — Previous revision.
  • March 24, 2026 — Initial v1 policy.

16. Contact Us

If you have questions, requests, or complaints about this Privacy Policy or our data practices, contact:

IT Consulting and Expertise 42 Rue de la Py, 75020 Paris, France Email: mehdi.jabri@itcexpertise.com (or contact@fawazeer.app — both reach us) Phone: +33 7 61 53 65 45 Website: https://www.itcexpertise.com

For GDPR matters, you may contact our representative at the same address.