Legal

Privacy Policy

Last updated: April 9, 2026

This policy explains what personal data FichaFlow collects, how we use it, when it is shared, and which controls are available in the product today.

Policy summary

FichaFlow uses account, gameplay, device, and service data to run sign-in, secure sessions, clubs, rankings, online play, puzzles, streaks, challenges, notifications, and support workflows.

At a glance

  • FichaFlow supports email/password accounts and Google sign-in.

  • Authentication relies on Better Auth session cookies instead of browser-stored auth tokens.

  • Google Analytics and Meta Pixel are active in the current US-facing product configuration, and the app does not present a separate analytics or advertising consent prompt today.

  • Privacy settings let you control profile, search, leaderboard, stats, email, and browser push visibility.

  • Users can export account data, review active sessions, revoke other sessions, and request deletion with a 30-day grace period.

1. Information We Collect

Account, gameplay, community, device, and support information.

FichaFlow collects information you provide when you create an account, sign in, edit your profile, join clubs, participate in sessions or tournaments, contact support, or use community features.

Account information may include your email address, username, display name, profile image, authentication method, and session records. If you sign in with Google, we receive the profile information needed to complete that flow.

Gameplay information may include session history, match results, tournament records, club activity, follows and rivalry surfaces, leaderboard participation, online game activity, daily puzzle progress, daily challenge progress, streak progress, and related rewards or unlocks tied to your account.

We also collect technical and service information such as browser type, device details, service-worker or push capability state, IP-based security metadata, logs, and error or diagnostic signals that help us operate the service and investigate abuse.

  • Account data: email, username, profile fields, login method, connected account provider details, and active or historical session records.

  • Gameplay data: sessions, matches, scores, tournament records, clubs, rankings, puzzle progress, challenge progress, streak data, and online play records.

  • Community data: public profile details, club invites and memberships, follow relationships, rivalry views, and visibility settings.

  • Technical data: browser, device, service-worker state, approximate IP-based location metadata, logs, and abuse-prevention signals.

2. How We Use Information

To operate, secure, improve, and support FichaFlow.

FichaFlow uses personal data to provide the features you request, including account creation, email verification, password reset, secure sign-in, session management, profile settings, clubs, leaderboards, match history, tournament tools, online play, daily puzzle delivery, challenge tracking, streak rewards, and notification delivery.

We also use information to maintain product performance, detect and investigate fraud or abuse, measure how features are used, improve reliability, communicate security or service notices, and comply with legal obligations.

  • Authenticate users and maintain secure session-based access.

  • Power gameplay, rankings, clubs, tournaments, online sessions, puzzles, streaks, and challenge systems.

  • Send transactional messages such as verification, password reset, security, and account lifecycle notices.

  • Measure product usage, diagnose failures, and improve quality through analytics and operational monitoring.

3. Public Features, Profiles, and Sharing

Some FichaFlow surfaces are intentionally social and public-facing.

Depending on your settings and the feature involved, other users or visitors may be able to see your username, public profile details, club membership, leaderboard placement, public stats, and certain match or tournament history.

FichaFlow currently lets users manage profile visibility, player-search visibility, leaderboard visibility, detailed stats visibility, email notification preferences, and browser push preferences from account settings.

Some records may remain visible, or may be retained in anonymized form, when necessary to preserve match history, tournament integrity, club history, or other records that affect other players.

FichaFlow also uses service providers that help us operate the service, including hosting, infrastructure, authentication support, email delivery, analytics, advertising measurement, and browser push infrastructure. We may also disclose information when required by law or when reasonably necessary to protect FichaFlow, our users, or the public.

4. Cookies, Analytics, and Browser Technologies

Session cookies, local storage, analytics identifiers, advertising measurement identifiers, and push-related browser storage are used today.

FichaFlow uses Better Auth session cookies and related browser storage to keep signed-in sessions secure and working. In production on approved FichaFlow domains, some authentication cookies may be configured for cross-subdomain use on fichaflow.com so supported surfaces can share sign-in state.

FichaFlow also uses local storage, service-worker related storage, and cached browser data to remember product preferences, keep parts of the web app responsive, and support browser-based capabilities.

Google Analytics is currently active in the shipped product. FichaFlow uses it for page views, authentication events, session or match creation flows, club lifecycle events, and feature or CTA usage measurement.

Meta Pixel is also currently active in the shipped product. FichaFlow uses it for page-view measurement, campaign attribution, selected registration and other bounded in-product activation events, and related ad-performance analysis on Meta platforms. Depending on the browser and Meta's implementation, Meta Pixel may rely on cookies or similar browser-side identifiers and may receive browser, device, referrer, page-view, and other bounded event information in connection with those measurements.

FichaFlow does not currently present a separate in-product analytics or advertising consent prompt in the current US-facing launch configuration, and this policy reflects that live behavior.

If you enable browser push notifications, FichaFlow stores a push subscription and related browser-side data so supported browsers can receive messages even when the site is not open.

  • Essential cookies support secure sign-in, session continuity, and account security.

  • Local storage or cached browser data may store preferences, prompts, and recent app state.

  • Analytics or advertising-related identifiers may use cookies or similar browser storage.

  • Read the Cookie Policy at /cookies for more detail, or contact support@fichaflow.com.

5. Your Controls and Rights

Practical account controls are available inside the product today.

Users can update profile information, adjust privacy settings, manage email and browser push preferences, review active sessions, revoke other sessions, export account data, and request account deletion from the settings area.

Account deletion currently starts a 30-day grace period. During that window, the account is scheduled for deletion, all active sessions are revoked, and the user can cancel deletion by logging back in during the grace period or by using the cancellation link sent by email.

After the grace period, account data is deleted according to the deletion flow, but some match or community records may be anonymized rather than fully erased when that is necessary to preserve records affecting other players.

6. Data Retention and Security

We retain data for legitimate service, compliance, and record-keeping needs.

FichaFlow keeps personal data for as long as needed to operate the service, comply with legal obligations, resolve disputes, enforce platform rules, maintain rankings or historical records, and support security or fraud investigations.

We use technical and organizational safeguards intended to protect user data, including access controls, secure transport, session management, logging, and abuse-prevention systems. No system can guarantee absolute security, so users should also protect their credentials and devices.

7. Children, Policy Changes, and Contact

We do not knowingly direct the service to children under 13.

FichaFlow is not directed to children under 13, and we do not knowingly collect personal information from children under 13 through the service. If you believe a child has submitted personal information, contact us so we can investigate and take appropriate action.

FichaFlow may update this Privacy Policy when the product, service providers, or legal requirements change. Material updates will be reflected by a revised effective date and, where appropriate, by in-product or email notice.

Questions about this Privacy Policy can be sent to support@fichaflow.com.

Clear rules for a real product.

FichaFlow is built to keep Dominican domino moving with practical controls, secure account handling, and straightforward disclosure about how the service works today.