PronoGo Legal

Privacy Policy & Terms of Service — PronoGo

View the Project on GitHub MehdiBou7a/pronogo-legal

Privacy Policy — PronoGo

Last updated: August 29, 2026 Version: 1.4

← Back to home · Version française


1. Introduction

This privacy policy (“Policy”) explains how PronoGo (“we”, “our application”) collects, uses, and protects your personal data when you use the PronoGo mobile application (“the Application”).

PronoGo is published by Mehdi Bouhaouala, a sole proprietor (auto-entrepreneur) registered in France, whose contact details are available at the end of this Policy.

PronoGo is a mobile sports prediction game based on virtual currencies (tokens, pronocoins). No real money is wagered, no monetary winnings are paid out. The Application is free to use and is funded through optional in-app purchases (via Google Play and the App Store) and advertising (Google AdMob). See our Terms of Service for more details.

By using the Application, you acknowledge having read and accepted this Policy.


2. Data we collect

2.1 Data provided upon account creation

You can create your account in three ways:

In all cases:

2.2 Data generated by your activity

2.3 Technical data

2.4 Transaction data (in-app purchases)

If you make an in-app purchase (virtual currency, card pack, welcome bundle), the transaction is entirely processed by Google Play or the App Store. We never see and never store your card number or payment details.

We receive and keep only: the identifier of the purchased product, a transaction token/identifier provided by the platform (to verify the purchase and credit your account), the date, and the transaction state.

2.5 Data we do NOT collect


3. How we use your data

Your data is used exclusively to:

  1. Provide the service: login, save your progression, calculate scores, resolve predictions via the api-football.com API.
  2. Personalize the experience: rankings, recommendations, match and result notifications.
  3. Social system: display your nickname in leagues, manage friend list, friend rankings, and referrals.
  4. Process your in-app purchases: verify transactions with Google Play / App Store, credit purchased items, prevent fraud, and meet our accounting and tax obligations.
  5. Secure the service: abuse detection, anti-cheat, rate limiting.
  6. Improve the application: audience measurement (Firebase Analytics), crash reports (Crashlytics) and performance traces (Performance Monitoring). These three measurements are tied to your account identifier — so we do not present them as anonymous. Crash reports carry only a prefix of that identifier: enough to piece an incident back together, not enough to identify you.
  7. Advertising monetization: display ads via Google AdMob (native ads and optional rewarded videos). See section 4 regarding consent.

We ask for your agreement first, and you can take it back. These three measurement tools start switched off and send nothing until you have accepted. You can withdraw that agreement at any time: Settings → “Analytics and diagnostics”. The withdrawal takes effect immediately on the device and applies to every subsequent launch; it requires neither writing to us nor deleting your account.

We never sell your data to third parties. Ads served via AdMob are filtered: we block sensitive categories (real-money competitor gambling, adult content, dating, politics, religion, etc.).


The Application displays ads via Google AdMob: native ads integrated into the interface, and “rewarded” videos that you voluntarily choose to watch in exchange for virtual rewards.

Consent (EEA / United Kingdom / Switzerland): before any personalized advertising, a Google UMP consent form (User Messaging Platform) is presented to you. You may accept or refuse personalized advertising; if you refuse, non-personalized (contextual) ads are served instead. You can change your choice at any time from the Application Settings.

If you consent, AdMob may use your advertising identifier (Android Advertising ID / Apple IDFA) to personalize ads. You can also reset this identifier or disable personalization from your device Settings → Privacy → Ads.

Rewarded videos: when you watch a video in exchange for a reward, your account identifier is passed to Google’s advertising network, which sends it back to us signed. It serves one purpose only: to verify server-side that the reward goes to the right person, and to prevent it from being claimed twice. It is not used for ad targeting.

Approximate location: we request no location permission, and the Application contains no geolocation component. Google’s advertising module nevertheless estimates a region from your IP address in order to choose ads. This is the only form of location involved, and it is why our privacy labels declare it.

On iPhone and iPad — tracking permission: Apple requires a permission separate from ours (App Tracking Transparency). If you grant it, your device’s advertising identifier (IDFA) may be used to track you from one app or site to another, including those of other companies. If you refuse it, it is not. This choice can be changed at any time in iOS Settings → Privacy & Security → Tracking. This permission is what explains the “Data Used to Track You” mention on our App Store listing.

The Application currently offers no subscription: all in-app purchases are one-time purchases.


5. Sharing data with third parties

5.1 Technical subcontractors

5.2 Limits on commercial sharing

We do not share any data with:


6. Retention period

Data Duration
User account (users, user_scores, cards, predictions, lineups) As long as the account is active
Notifications inbox 7 days (automatic TTL)
Daily claims logs 15 days (automatic TTL)
XP logs (xp_log) 30 days (automatic TTL)
Technical and security logs (server) Up to 90 days
In-app purchase records (IAP transactions) Legally required duration (accounting, tax and anti-fraud obligations), including after account deletion
League chat messages 30 days at most, and only the last 200 messages of each league are kept (automatic daily purge)
Your list of blocked players As long as your account exists, or until you lift the block
Report files 90 days, by automatic purge. This duration is not arbitrary: the file acts as a lock against repeated reports, and the message it targets lives at most 30 days — three times that duration leaves room for review without keeping a trace that has become unverifiable. A file you submitted is also deleted when you delete your account, and a report targeting your profile is deleted when you delete yours
Card image you publish Overwritten on each new share, purged automatically after 30 days, and deleted together with your account
Support requests Kept for as long as needed to handle the request and to retain a record in case of dispute

Upon account deletion (via Settings → Delete my account), your personal data is irreversibly erased on the Firebase side, in compliance with Article 17 of the GDPR: account, cards, predictions, line-ups, friends, private messages, progress and history.

Six exceptions, and we would rather tell you about them:

What remains Why For how long
Purchase records Accounting and tax obligation — Article 17.3(b) of the GDPR expressly covers this case Statutory retention period
Messages you already posted in a league that carries on without you Erasing them would leave holes in other members’ conversation Automatically purged after 30 days
Your standings row in a league still in progress Removing it would distort the result for the other participants. It is anonymized as “Deleted account” Until that league ends
Your place in a finished season’s hall of fame It is the shared history of the game; rewriting it would change other players’ standings. Only already public information appears there (display name, height reached, tier) Kept
Aggregated, anonymized statistics They are no longer linkable to you Kept
Report files concerning a message you had posted They document the handling of a report filed by another player. The message itself is already gone (30-day purge); only the moderation record remains Kept as a moderation record

Everything else goes. See our dedicated page: Account Deletion.


7. Your rights (GDPR)

In accordance with Regulation (EU) 2016/679, you have the following rights:

To exercise these rights, contact us at pronogo.dev@gmail.com.


8. Security

Your data is protected by:

No system is infallible; we cannot guarantee absolute security, but we implement industry best practices.


9. Minors

PronoGo is intended for persons at least 16 years old. This restriction applies worldwide (GDPR Europe: article 8; in the United States and the United Kingdom: COPPA and UK-GDPR compliance through alignment).

Upon account creation, you explicitly declare being at least 16 years old by validating the consent checkbox.

If you become aware that a minor under 16 is using PronoGo, contact us at pronogo.dev@gmail.com — we will delete the account without delay.


10. Cookies / local storage

PronoGo stores locally on your device:

The Google Mobile Ads SDK (AdMob) may use technical identifiers for ad targeting, subject to your consent (see section 4). You can reset your advertising identifier or disable personalization from your device Settings → Privacy → Ads.


11. Changes to this Policy

We reserve the right to modify this Policy. The “Last updated” date will be updated at the top of the document.

In case of substantial changes, we will inform you via in-app notification or email before the changes take effect.


12. Contact

For any questions or requests:


PronoGo is published by Mehdi Bouhaouala, sole proprietor (auto-entrepreneur), resident in Courbevoie, France. The application is free to use, with optional in-app purchases (virtual currencies and game bundles via Google Play / App Store, all consumable — no subscription) and advertising (Google AdMob — native ads and optional rewarded videos). This Policy will be updated if the publisher status evolves (company) or if new paid features are introduced.