Privacy Policy
1. Who We Are
Boolip is operated by Boolip Ltd, a company registered in Israel (company no. 517350443), David Saharov 3, Rishon LeZion, Israel (“Boolip”, “we”, “us”). Boolip is a social arcade: a curated feed of quick mobile games, friend-to-friend duels, and daily leaderboards. This Policy explains what we collect, why, and your rights.
2. What We Collect
Account data
Your email address, display name, avatar, and any profile information you provide. When you sign in with a third party (Apple or Google), we receive the basic profile fields that provider returns — typically your name, email, and avatar.
Date of birth
We ask for your date of birth when you create an account. We use it to confirm you meet our minimum age of 13 and to apply the protections required for younger teens: if you are under 18, you can send a game only to accounts you follow. We store the date on your account and never show it to other users.
Activity & content data
The comments you post, the likes and saves you give, the people you follow, the messages you send to other users, and any gameplay clips you choose to record and share.
Gameplay data
Scores, play durations, completion status, duel results, and leaderboard/coliseum progress. We collect this to power leaderboards, challenges, duels, and your own statistics. We generate a random identifier on your device and send it only to Boolip’s servers with gameplay records, including when you play without an account, to understand repeat play and improve games; we do not send this identifier to PostHog or advertising partners. In the Android app — and in the iOS app, only if you allow tracking (section 4) — we also record whether the app was installed from an ad and, if it was, which campaign and ad, next to that same random identifier on Boolip’s own servers, so we can see which campaigns bring players who keep playing. That record holds campaign and ad names and identifiers only — no name, email or account — and we do not share it, or the random identifier in it, with PostHog or advertising partners.
Safety & moderation data
We log reports you file and reports filed against your content or profile, along with the moderation decision and reasoning. This data is used for safety, audit, and to improve our filters.
Technical data
IP address, user agent, device type, approximate location (country and city, derived from IP), referrer, and usage telemetry (screens viewed, games shown, opened and played, load and start-up times, crashes and memory warnings). We use this for security, abuse prevention, and product analytics.
Notifications
If you enable push notifications, we store a device push token, plus the app version of that device (so an invite is only sent to a device that can open it), so we can send you duel invites, leaderboard updates, and important account notices. You can turn notifications off at any time in your device settings.
Guest notifications.
If you enable notifications without creating an account, we store your device’s push token, language, app version, registration and last-seen times, and whether we attempted a one-time score reminder. We use this information to send a score-to-beat reminder about a Boolip game around 24 hours after registration. This guest record is not linked to a Boolip account or our gameplay installation identifier. You can stop notifications in your device settings.
3. How We Use Your Data
- To provide and operate the Service (create your account, serve games, host your content);
- To power social features — leaderboards, duels, follows, and messages;
- To moderate content and enforce our Terms (reports, review, enforcement actions);
- To prevent fraud, abuse, and unauthorized access (rate limits, anomaly detection);
- To communicate with you about your account, safety reports, or material policy changes;
- To improve the Service (which games people enjoy, where the app can be faster or clearer).
4. Third-Party Processors
We share specific data with the following processors strictly to operate the Service. Each is bound by its own data-processing agreement. We do not sell your personal data and we do not share it with advertisers, and we do not track you across other companies’ apps or websites, with one exception: install attribution in the Boolip apps, to know which ad brought a new player. The Android app shares the Android advertising ID and install details with AppsFlyer and, for installs that came from a Meta ad, with Meta Platforms. The iOS app includes the same AppsFlyer SDK, which starts only if you tap “Allow” when iOS asks, through App Tracking Transparency, whether Boolip may track you: until you answer, and if you choose “Ask App Not to Track”, the iOS app sends nothing to AppsFlyer. Apple’s own SKAdNetwork can still report an install to the ad network that showed the ad, in aggregate and without any identifier, and send AppsFlyer a copy of that report. Both are described in the table below; our marketing website, boolip.com, is described in section 8.
| Processor | Purpose | Data shared |
|---|---|---|
| Vercel | Hosting, CDN & asset storage | Application traffic, request logs, uploaded clips/assets |
| Neon | PostgreSQL database | All persistent account & gameplay data |
| Upstash (Redis) | Rate limiting & caching | User IDs, transient counters |
| Apple | Sign in with Apple | OAuth profile (name, email) |
| Sign-in | OAuth profile (email, name, avatar) | |
| Google Firebase (Cloud Messaging) | Push-notification delivery (Android) | Device push token, device identifiers |
| Sentry | Error and performance monitoring | Crash reports and stack traces, request metadata, device, browser and app version, the screen address with secrets removed, and a trail of recent app activity (screens visited, network requests, console messages, and in-app events with their Boolip identifiers, including your pseudonymous user ID once you sign in), from every user including before sign-in; and page-load and navigation timings for a sample of sessions. |
| PostHog (EU) | Product, performance and usage analytics. Outside the European Economic Area, the United Kingdom and Switzerland, the app sends usage events about how it and its games work and are used, including before you create an account: app opens and sessions, which games were shown, opened, started, finished or skipped, how long games and the app took to load, crashes and memory warnings, the outcome of in-app prompts (sign-up, notifications, guest score claims) and why a sign-in failed. Before you create an account and agree to this Policy, these events carry the identifier of the game, challenge, comment or notification involved and a random analytics identifier, and never include your name, email address, username, game scores, other users’ identifiers or the address of the page you were on. Once you have an account and have agreed to this Policy, events are linked to your pseudonymous user ID and can include your game scores. In the European Economic Area, the United Kingdom and Switzerland, whether or not you have agreed to this Policy, we send only install and attribution results, app opens, first play, campaign deep-link routing, the outcome of in-app prompts, opening the app from a notification, why the previous session ended and the outcome of a resumed sign-in, until you turn on usage analytics in Settings → Account → Privacy. In those countries you can turn usage analytics on or off at any time in Settings → Account → Privacy; users below the age of digital consent in their country (between 13 and 16) cannot turn it on. Wherever you are, if you have an account you can turn usage analytics off at any time in Settings → Account → Privacy; outside the European Economic Area, the United Kingdom and Switzerland, a guest can do the same from the sign-in screen. A device on which someone was refused an account for being under 13 sends no analytics at all. | Pseudonymous user ID (after sign-in and agreement), a random analytics identifier, in-app events, device and app details (model, OS and app version), and IP address, used to derive approximate location (country and city). No advertising identifiers. |
| AppsFlyer (Android app; iOS app only if you allow tracking) | Install attribution — measuring which ad led to an install | Android: advertising ID, Google Play install referrer, IP-derived country, and app-open events. iOS, only after you tap “Allow” in Apple’s App Tracking Transparency prompt: Apple’s advertising identifier (IDFA), the app’s vendor identifier, IP-derived country, and app-open events. On both: device and app details (model, OS and app version) and the links that open the app. For installs that came from a Meta ad, AppsFlyer passes the install and that identifier to Meta Platforms as the ad network. Not used to build profiles or to show you ads inside Boolip; no email, name or account identifier is sent. Opt out any time: Android Settings → Privacy → Ads (“Delete advertising ID”, or reset it); iOS Settings → Privacy & Security → Tracking (turn Boolip off). |
| Meta Platforms (Meta Pixel) | Advertising measurement on the boolip.com website only (never inside the app) — tells Meta that an ad click reached our store link | Page view of a boolip.com landing page, the game and campaign the link named, browser/device metadata, and Meta’s own cookie if you are logged in to Facebook or Instagram |
5. Where Your Data Lives
Our primary database (Neon) is hosted in EU regions. Media and assets are stored on Vercel (multi-region with EU presence). Some processors may process limited data outside the EEA; where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
6. Retention
- Account data: while your account is active, plus up to 30 days after a deletion request.
- When you delete your account, we remove installation identifiers from gameplay records linked to that account or the same installations; gameplay statistics remain without that installation link.
- Content you publish (comments, clips): retained while published; removed on takedown and hard-deleted within 30 days.
- Safety & moderation logs and reports: retained 24 months for safety and audit.
- Guest notifications: we retain the token record to prevent repeated score reminders. We remove it when the same token is registered to an account or the platform’s push service (Firebase on Android, Apple on iOS) reports that it is invalid during a delivery attempt. Turning notifications off does not automatically delete this record. You may request deletion using the contact details below.
- Server logs: retained up to 90 days for security and debugging.
7. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, or to lodge a complaint with a supervisory authority. EU residents may exercise rights under the GDPR; California residents may exercise rights under the CCPA. To exercise any right, email support@boolip.com. We respond within 30 days.
Deleting your account
You can delete your Boolip account and its associated personal data at any time from within the app (Profile → Settings → Account → Delete my account), or by emailing support@boolip.com from your registered address. When you delete your account, we erase your personal data within 30 days, except limited records we are legally required to retain (such as safety logs or fraud-prevention data) as described in Retention above.
8. Cookies & Local Storage
We use a session cookie to keep you signed in, and local-storage entries on your device to remember preferences and app state (for example theme and last-viewed feed position), to keep the random gameplay identifier described in section 2, to count your visits and play days for analytics, and to hold install-measurement events until our analytics service confirms receipt. Once you agree to this Policy (and, in the European Economic Area, the United Kingdom and Switzerland, once you turn usage analytics on), our analytics service (PostHog) also keeps an analytics identifier in a first-party cookie and in local storage on your device. We do not use third-party advertising cookies. Our analytics are first-party and do not identify you across other companies’ sites or apps. In the European Economic Area, the United Kingdom and Switzerland, the visit and play-day counts and install-measurement events are not stored on your device, and our analytics service keeps no identifier there, until you turn on usage analytics in Settings → Account → Privacy.
Marketing website only. When you arrive at a boolip.com landing page from one of our ads, that page loads the Meta Pixel, a script from Meta Platforms that sets or reads Meta’s advertising cookie so Meta can measure whether its ads brought you to our store link. It records the page view, the game and campaign named in the link, and browser metadata. It runs on boolip.com only — the Boolip app itself never loads it and uses no advertising cookies; the apps’ only attribution SDK is described in section 4. You can control Meta’s use of this data in your Facebook or Instagram ad settings, or block the script with a browser content blocker.
9. Children’s Privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from children. In the European Economic Area, the United Kingdom and Switzerland, usage analytics beyond the limited list in section 4 run only with the account holder’s separate consent, which users below the age of digital consent in their country (between 13 and 16) cannot give. If you believe a child has provided us with personal information, contact support@boolip.com and we will delete it.
10. Security
We use industry-standard safeguards: encryption in transit (HTTPS/TLS), encryption at rest for our database, strong password hashing, least-privilege internal access, automated security monitoring, and regular review of our infrastructure. No method of transmission or storage is 100% secure; we work to continuously improve.
11. Changes to This Policy
We may update this Policy. When we make material changes, we will revise the version string above and notify active users so you can review and re-accept where required.
12. Contact
Privacy questions, data-rights requests, or general support: support@boolip.com.