Kicko

Privacy Policy

Effective date: 2 October 2026

This Privacy Policy explains how the Kicko mobile app (“Kicko”, “we”, “us”) and this website handle personal data. Kicko is published by Gökhan Tuncer, an independent developer, who is responsible for the processing described here. Questions can be sent to [email protected].

1. Information we collect

We collect only what is needed to run the app. You can use Kicko without signing in; some data below applies only if you sign in, enable notifications or make a purchase.

Account data (only if you sign in)

You can sign in with Apple or Google. We receive the email address, name and profile picture URL that the sign-in provider shares with us (Apple’s “Hide My Email” is supported), the provider you used, and your last sign-in time. You can also enter a first and last name in the app. This is stored in your Kicko profile together with your subscription status.

Device and app-usage data

  • Installation identifiers. To keep the free-token system fair, the app creates a device key (on Android the app-specific Android ID; on iOS a random identifier kept in the device Keychain). We store only a one-way hash of this key, together with a random installation ID and a hashed installation token.
  • Token wallet and unlocks. Your in-app token balance, daily bonus and lucky-wheel usage, the matches you unlocked, and records of rewarded ads you completed (to credit the reward and prevent duplicates).
  • App integrity. Firebase App Check (Apple App Attest / DeviceCheck, Google Play Integrity) is used to confirm that requests come from the genuine app. We store the result of this check with the installation.
  • Analytics. Firebase Analytics records app usage such as screens viewed and in-app events, plus device model, operating system, app version, language and approximate country. If you are signed in, your pseudonymous Kicko account ID is attached so we can count users correctly. We do not attach your name or email to analytics.

Purchase data

Subscriptions are sold and charged by Apple (App Store) or Google (Google Play). We never see your card details. RevenueCat validates receipts and tells us whether a subscription is active; it stores your purchase history linked to your Kicko account ID (or, if you are not signed in, to an anonymous ID created for your installation).

Push notification data (only if you allow notifications)

Notifications are delivered by our own push service, which stores your device’s push token, platform, app and operating-system version, language, time zone, the leagues you marked as favourites (so we can notify you about them) and, if you are signed in, your Kicko account ID. Messages are delivered through Apple Push Notification service and Firebase Cloud Messaging.

Advertising data

If you do not have a subscription, Kicko may show ads, including optional rewarded ads that earn tokens, served by Google AdMob. AdMob may collect your device’s advertising identifier (IDFA on iOS, Advertising ID on Android), IP address and ad interaction data to serve, measure and limit ads. In the EEA, the UK and Switzerland we ask for your consent through Google’s consent form before personalised ads are shown. On iOS, we only access the IDFA if you allow tracking in Apple’s App Tracking Transparency prompt. You can reset or limit the advertising identifier in your device settings at any time.

What we do not collect

Kicko does not access your GPS location, contacts, photos or microphone. Our ad and analytics partners may infer an approximate region from your IP address.

2. How we use information

  • Provide the app: match lists, AI analysis and the features you request
  • Create and maintain your account and sync your subscription across devices
  • Run the token wallet, daily bonuses and rewarded ads, and prevent abuse of them
  • Process and verify subscriptions and unlock subscriber features
  • Send the notifications you enabled, in your language and time zone
  • Show and measure ads for non-subscribers
  • Understand how the app is used, fix problems and keep the service secure

Where the GDPR or similar laws apply, we rely on performance of our contract with you (providing the app and your account), our legitimate interests (security, fraud prevention, basic analytics and improving the app) and your consent (personalised advertising and notifications). You can withdraw consent at any time in the app or your device settings.

3. Service providers

We use the following providers to run Kicko. They process data on our behalf or under their own privacy policies.

ProviderPurpose
SupabaseSign-in, account database and app backend
Sign in with AppleSign-in
Google Sign-InSign-in
RevenueCatSubscription management and receipt validation
Google AdMobAds and rewarded ads for non-subscribers; consent management (Google UMP)
Google FirebaseAnalytics, App Check and Cloud Messaging (Android push delivery)
Apple Push Notification serviceiOS push delivery
Our own push serviceStores push registrations and sends notifications; runs on our server in Germany

We do not sell your personal data and we do not share it with data brokers.

4. Account and data deletion

You can delete your account at any time in the app: open the menu (☰) on the home screen, tap Account Details, then Actions › Delete Account. This permanently deletes your account and profile, removes your purchase history from RevenueCat and unlinks your account from our push service. You can also request deletion by email. See Delete your account for details.

Deleting your account does not cancel an App Store or Google Play subscription. Cancel it in your store settings to avoid future charges.

5. Data retention

  • Account and profile data: until you delete your account.
  • Installation, token wallet and unlock data: tied to the installation rather than to your account, kept while the app is in use so the free-token limits keep working, and deleted on request.
  • Push registrations: until the push token becomes invalid, you uninstall the app or you ask us to delete them.
  • Analytics data: kept by Google Analytics for Firebase for the retention period set in our analytics settings, at most 14 months.
  • Records we must keep for legal, tax or fraud-prevention reasons: only as long as required.

6. Children

Kicko is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from children. If you believe a child has given us personal data, contact us and we will delete it.

7. Your rights

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict certain processing, and to withdraw consent. To exercise these rights, email [email protected]. We reply within the time required by law (usually within 30 days). You may also complain to your local data protection authority.

8. Security

Data is sent over encrypted connections (HTTPS). Device keys and installation tokens are stored only as one-way hashes, and access to our databases is restricted. No system is completely secure, but we work to protect your data.

9. International transfers

Our providers may process data outside your country, including in the United States. Where required, these transfers rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

10. Changes to this policy

We may update this policy. We will change the effective date at the top of this page and, for significant changes, tell you in the app.

11. Contact

Gökhan Tuncer (publisher of Kicko)
Email: [email protected]