Legal
Privacy Policy
- Core league data views work without an account.
- Sign-in is optional - used for watchlist, linked squad, leagues and personal features.
- Optional FPL Weekly Pro subscriptions are available in our mobile apps and billed by Google Play or the App Store.
- You can delete your account and cloud data in-app (Settings → Delete account).
- We do not sell your personal information.
- We use privacy-focused product analytics (PostHog, EU-hosted) to understand how the app and website are used - not to sell ads.
This Privacy Policy explains what information FPL Weekly ("we", "us") collects when you use the FPL Weekly app at app.fplweekly.com, native mobile apps when available, and this website at fplweekly.com (together, the "Service"), how we use it, and the choices available to you.
Information we collect
- Public FPL data. We ingest and mirror publicly available Fantasy Premier League data (fixtures, players, prices, live gameweek statistics). This data describes players, teams and matches - not you personally.
- Optional account. If you choose to sign in with Google (Apple where supported in a future release), we receive an account identifier and basic profile fields from your auth provider (for example name and email). Authentication is handled by Firebase Auth.
- Linked FPL entry. If you link a Fantasy Premier League manager entry, we store your entry ID and related metadata (such as team name and verification state) in Firestore under your account, and may cache the same public API responses the official FPL service exposes for that entry (picks, points, leagues). A copy of your linked entry ID may also be kept locally on your device for convenience.
- Personal app data. When signed in, we may store watchlist items, team-assistant conversation state, and Stock Exchange game progress in Firestore paths scoped to your user ID. These features are optional.
- Team-change assistant (AI). If you use the optional AI assistant when editing your squad, we send relevant squad context to our backend AI service (Firebase AI / Google Gemini) to generate a response. Do not include sensitive personal information in free-text prompts.
- Device and technical data. When the Service contacts our servers we receive standard technical information (IP address, app/browser version, timestamps, crash or error logs). We use this to operate, secure and debug the Service.
- Local preferences. Theme choice, intro flags and similar settings may be stored on your device (for example via browser or app local storage).
- Product analytics. We use PostHog (hosted in the European Union) to understand how the Service is used - for example which platform you use (web, Android or iOS), which screens you open, whether you sign in, whether you link an FPL entry, and subscription funnel events on mobile (for example paywall opened, purchase started or completed - plan type and outcome only, not payment card details). PostHog assigns an anonymous identifier to your browser or app; if you sign in, we associate events with your Firebase user ID (not your email or FPL entry ID). We do not send names, emails, FPL entry IDs, or player names in analytics events. Session replay, advertising trackers and cross-site profiling are not enabled.
- Marketing website. This site uses the same PostHog analytics described above (tagged as marketing traffic, separate from the web app at app.fplweekly.com). We do not use advertising cookies.
- Subscriptions (mobile). If you purchase FPL Weekly Pro in our Android or iOS app, payment and subscription management are handled by Google Play or the Apple App Store. We use RevenueCat to verify your entitlement and associate it with your signed-in Firebase account. We receive subscription status (for example active, expired, or renewal date) and product identifiers - not your full payment card details. See our Terms for billing and cancellation.
How we use information
- To provide and improve Service features you request.
- To sync linked entries, watchlists and personal game state across your devices when signed in.
- To generate optional AI assistant responses when you invoke that feature.
- To maintain security, prevent abuse and investigate reliability issues.
- To measure product usage and improve features (via PostHog analytics).
- To verify and deliver FPL Weekly Pro subscription features when you subscribe on mobile.
- To comply with legal obligations.
Legal bases (EEA / UK)
Where applicable, we process personal data on the basis of: (a) performance of a contract - providing the Service you request; (b) legitimate interests - securing and improving the Service; and (c) consent - where required for optional features such as marketing emails (we do not currently send promotional email by default).
Sharing
We do not sell or rent your personal information. We use infrastructure providers to host the Service, including Google Firebase / Google Cloud (authentication, database, functions, storage and AI), PostHog (EU-hosted product analytics), and RevenueCat (subscription entitlement management on mobile). Those providers process data on our behalf under their security and privacy commitments. Auth providers (Google, Apple) process sign-in according to their own policies.
International transfers
Our infrastructure may process data in the United Kingdom, European Economic Area, United States or other regions where our providers operate. PostHog analytics data is stored in the EU. We rely on appropriate safeguards offered by those providers where required by law.
Retention
Server logs are kept for a limited period for security and debugging, then deleted or aggregated. PostHog retains analytics events according to our PostHog project settings (typically up to one year; we may adjust retention as the product matures). Account-linked data in Firestore remains while your account is active. You can remove individual linked FPL entries and watchlist items in the app without deleting your whole account. See Account deletion below to remove your account entirely. Deleting your account removes your Firebase profile and Firestore data; PostHog may retain prior anonymous or identified analytics events until they expire under PostHog retention.
Account deletion
You can permanently delete your FPL Weekly account and all personal data we store for you from within the app: open Settings → Delete account, review the warning, type DELETE, and confirm. This removes your Firebase Authentication profile and Firestore data tied to your user ID, including linked FPL entries, watchlist, Stock Exchange progress, team assistant history, and verification state.
Deleting your account does not cancel an active FPL Weekly Pro subscription billed through Google Play or the App Store. Cancel the subscription in your store account settings to stop future charges. See our Terms.
Deletion takes effect on our active systems without undue delay. Backup copies held by our infrastructure providers may persist for a short period before automatic purging.
If you cannot access the app, email hello@fplweekly.com from the address on your account and we will help verify and complete deletion.
Your rights
Depending on where you live, you may have rights to access, correct, delete or restrict processing of your personal data, and to object or port data. You may delete your account in the app as described above. For other requests, contact us below and we will respond within a reasonable time. You may also lodge a complaint with your local data protection authority.
Children
The Service is not directed to children under 13 and we do not knowingly collect personal information from children. If you believe a child has provided us personal data, contact us and we will delete it.
Changes
We may update this policy as the Service evolves. We will change the effective date at the top and, for material changes, provide notice in the app or on this page.
Contact
Privacy questions: hello@fplweekly.com.