GOALIX

Privacy Policy

Last updated: 14 August 2026

This policy explains what Goalix does with data when you use the app. It is written to be read, not to be survived. If anything here is unclear, write to us and we will explain it in plain words.

What changed in this version. Goalix 1.1 introduces advertising measurement: the app now contains Meta's measurement kit, so that we can tell which install adverts work. This is a real change and it gets its own section — section 5. It comes with a choice you make on first launch, and declining costs you nothing in the app.

Goalix 1.0 contained no advertising software at all. The fundamentals are unchanged — no account, no name, no email, no location. Two other statements were corrected in this revision after we checked them against the app itself: where the database physically sits (section 6), and which company receives the device identifier Apple gives this app (section 5 and section 6).

1. Who we are

Goalix is an iOS app published by Gurcan Karaduman, an individual developer. There is no company behind it. For data protection purposes, Gurcan Karaduman is the data controller.

Contact: support@goalix-app.com. This is the only support and privacy channel for the app.

Goalix publishes football match predictions (a pick, its odds and an optional written analysis) and combined coupons, in free and subscription-only categories. Match outcomes are marked as won or lost by hand by us, and category success rates are calculated from those manually entered results. The app contains no betting, no gambling, no real-money play, no links to bookmakers and no affiliate links. Everything in it is for information and entertainment only.

2. The short version

3. What we collect

The first time you open Goalix, the app signs in to anonymous Firebase Authentication. This creates a random, opaque user ID (a UID). That UID is not derived from you or from your device identity, and it contains no name or other information about you. It is, however, a stable identifier for your installation and it is the only thing that links your favourites and your subscription entitlements together — so we treat it as personal data and it gets the full protection of this policy.

DataWhyLegal basisRetention
Anonymous user ID (Firebase UID) To keep your favourites and your VIP access attached to your installation, without an account Performance of a contract (providing the app) Kept while the installation is active; deleted within 7 days of a deletion request
isAnonymous, lastSeenAt in users/{uid} To confirm it is an anonymous session, and to see whether an installation is still in use Legitimate interest (running the service, spotting abuse and stale records) Kept while the installation is active; deleted within 7 days of a deletion request
entitlements: which VIP category is unlocked. Whether a subscription is still in date is decided by the App Store and RevenueCat, not by a date stored here To unlock the VIP categories you are entitled to and to stop unlocking them when access ends. An entitlement comes from an App Store purchase confirmation, or in a support case from us setting it by hand — see section 9 Performance of a contract (delivering the subscription) Kept while the installation is active; deleted within 7 days of a deletion request
Favourites in users/{uid}/favorites/{matchId}: the match identifier, its categoryKey and addedAt To show your saved matches. The match content itself is not copied here, only its identifier Performance of a contract (providing the app) Until you remove the favourite, or within 7 days of a deletion request
App Store purchase confirmation, checked for us by RevenueCat To verify that a subscription is active and unlock the matching category Performance of a contract (delivering the subscription) Processed by Apple; on our side only the resulting entitlement is stored
Only if you turn notifications on: your device push token and your anonymous UID (sent to OneSignal as the external ID), plus whether a notification we sent was delivered and opened So a notification we send can reach your device, so it can be addressed to the right one, and so we can see whether it arrived Consent, which you give by turning notifications on and can withdraw at any time Held by OneSignal until you ask us to delete it. Turning notifications off in iOS Settings stops delivery, but does not by itself erase the record — write to us and we will remove it
From version 1.1: install and app-open events, a few in-app steps (anonymous account created, subscription screen opened, Subscribe pressed), the resulting purchase, session length, device and app details, your IP address, and the installation identifier the kit generates for itself — sent to Meta To measure which install advert brought someone to the app, so we do not keep paying for adverts that do not work Legitimate interest for this pseudonymous part; consent for anything involving your advertising identifier Held by Meta under its own policy, not ours — see section 5
From version 1.1, and only if you allow tracking: your device's advertising identifier (IDFA) So Meta can connect an install to the advert that caused it, and so our subscription provider can attribute a purchase to it Consent, given through the system tracking prompt and withdrawable at any time in iOS Settings Not stored by us; held by the recipients under their own policies
The identifier Apple gives this app for your device (IDFV), your IP address, your device and OS version and your answer to the tracking prompt — sent to RevenueCat, together with the installation identifier the measurement kit in section 5 generates So a subscription can be recognised as belonging to this installation and, from version 1.1, attributed to the advert that led to it Legitimate interest (verifying subscriptions and measuring our own advertising); consent for anything involving your advertising identifier Held by RevenueCat as our processor, under our instructions
Only if you ask us to delete your data: a deletion request in deletionRequests/{uid} — your UID, when you asked, and when we carried it out So the request cannot be lost, so we can hold ourselves to the 7-day promise, and so we can show afterwards that the erasure happened Legal obligation (demonstrating compliance with your erasure request) Kept after the erasure as the record that it took place; it contains nothing but the UID and two dates
revenuecatEntitlements on your Firebase Authentication record: the list of VIP categories you are entitled to So the server can release VIP content to you. RevenueCat's webhook writes it after a purchase; it is not stored in the database described above Performance of a contract (delivering the subscription) Kept while the installation is active; deleted within 7 days of a deletion request

That is the complete list of what we hold about you, in our own database and on the two records kept for us by the processors named above. Like any service reached over the internet, the providers in section 6 also see your IP address when the app connects to them and keep it in their own logs for a while — that is unavoidable, and it is not something we collect or use.

4. What we do not collect

5. Advertising measurement

This section applies to Goalix 1.1 and later. Version 1.0 contained no advertising software of any kind, and if you are running it, none of what follows happens on your device.

To find people who might want the app, we run install adverts on Facebook and Instagram (Meta). To know which of those adverts actually bring someone in — and to stop paying for the ones that do not — the app contains that company's measurement kit, the Meta SDK. It is the only advertising kit in the app, and this is the only part of Goalix where data about you reaches a company that is not working purely on our instructions, so it is written out in full.

What they receive

They do not receive your favourites, which predictions you opened, or how long you spent on any individual prediction.

The choice you are given

On first launch, after the opening animation, the app shows Apple's standard prompt: “Allow Goalix to track your activity across other companies' apps and websites?” It is a real choice, not a formality:

Nothing in the app is locked, degraded or nagged behind this choice, and we do not ask twice. You can change your mind at any time in Settings › Privacy & Security › Tracking; switching it off stops the identifier from being shared from that moment on.

What Meta is, legally

This is where Meta differs from everyone else in this policy. Google (Firebase), OneSignal and RevenueCat are our processors: they hold data on our instructions and may not use it for themselves. Meta is not a processor. Once the data above reaches it, Meta also uses it for its own purposes — running and improving its advertising systems — as an independent controller under its own privacy policy. We cannot look inside that, restrict it, or take it back. That is precisely why the decision above is yours and not ours.

Meta is based outside the European Economic Area, so this data leaves it. The safeguards for that transfer are the ones set out in Meta's own policy, not in ours.

Legal basis, plainly

Anything involving your advertising identifier rests on your consent, given through the tracking prompt and withdrawable at any time. The rest — the events, the device details, the IP address and the per-installation identifier described above — rests on our legitimate interest in not wasting money on advertising that does not work. That part is pseudonymous rather than anonymous: it does not carry your name, but it is tied to identifiers for your installation, and we would rather say so than call it anonymous. You can object to it at any time by writing to us, and deleting the app stops all of it.

6. Where your data is stored

Your data is stored in Google Cloud Firestore, in the nam5 multi-region, which is located in the United States. Google LLC (Firebase) acts as our processor: it stores and serves the data on our instructions and is not allowed to use it for its own purposes. The same applies to Firebase Authentication, which issues and verifies the anonymous UID and which Google also operates from the United States.

This means the data described in section 3 leaves the European Economic Area. That transfer is covered by the European Commission's Standard Contractual Clauses, which Google enters into with us as part of the Firebase terms. We would rather tell you where the data actually sits than describe an arrangement that sounds closer to home than it is.

If — and only if — you turn notifications on, a second processor is involved: OneSignal, which holds your push token and your anonymous UID in order to deliver messages, and which may process them outside the European Economic Area under the same Standard Contractual Clauses. Beyond that it records whether the notifications we send were delivered and opened, plus the session and device information described in section 8, and it receives nothing at all until you consent.

RevenueCat is our third processor. It checks with Apple that a subscription is genuine and still active, and it holds your anonymous UID together with the resulting purchase record. Whenever the app talks to it, RevenueCat also receives the identifier Apple gives this app for your device (IDFV) — this is the one place your IDFV goes; the measurement kit in section 5 does not receive it. From version 1.1 the app additionally asks RevenueCat to record, against your subscriber entry, your IP address, your device and OS version, your answer to the tracking prompt, the installation identifier generated by the measurement kit in section 5, and — only when you have allowed tracking — your advertising identifier, so that a purchase can be attributed to the advert that led to it. RevenueCat processes data in the United States under the European Commission's Standard Contractual Clauses.

Meta also receives data from version 1.1 onwards, but it is not a processor and section 5 explains what that means.

All traffic between the app and our servers is encrypted in transit with TLS.

7. Storage on your device

8. Notifications

Notifications are off until you turn them on. Goalix never asks for notification permission on its own. The app shows a card explaining what notifications are for, and nothing happens unless you tap to enable them.

Until you do, our notification provider receives nothing about you. The OneSignal SDK is present in the app but starts in a consent-required state: no push token is registered, no device or user record is created, and no identifier is sent. We verified this on a fresh install — before consent, the only thing stored is OneSignal's own public configuration, which contains no data about you.

If you turn notifications on, two things are sent to OneSignal, which acts as our processor for delivery: your device push token, and your anonymous UID as the external ID so a message can be addressed to the right device. OneSignal is also told when a notification we sent reached your device — that is the job of the small notification extension bundled with the app — and the app itself reports back when you tap one to open it. Beyond that, their SDK keeps the usual session and device information for the subscriber record it manages on our behalf, and it observes App Store purchases made in the app for its own analytics — we do not send those to them ourselves. Nothing else about your use of the app reaches them: not your favourites, not your entitlements, not which predictions you open.

Every notification is written and sent by hand by us from the OneSignal dashboard. There is no automated messaging, and notifications are never used for advertising.

The permission is entirely optional and withdrawable. You can turn notifications off at any time in Settings › Notifications › Goalix, and doing so does not affect anything else in the app — the picks, your favourites and your subscriptions all keep working exactly as before. If you decline the permission prompt, we drop the consent flag again so that nothing is sent.

9. Subscriptions and payments

Some categories — PRO ANALYSIS, ELITE PICKS, RISK HUNTER and GOALIX SIGNATURE — are VIP categories. Each of them is sold as its own separate auto-renewing subscription through Apple In-App Purchase.

Apple takes the payment. We never see and never store your card number, billing address or any other payment detail. All we receive is the confirmation that a subscription is active, which we turn into an entitlement on your anonymous UID.

That confirmation is checked for us by RevenueCat, our subscription processor: it verifies the receipt with Apple, holds the purchase record against your anonymous UID, and tells the app which categories to unlock. The only thing written to your own record on our side is which category is unlocked; the expiry itself is held by RevenueCat and Apple rather than as a date in our database. In rare support cases — a purchase that did not register, for example — we can still set an entitlement by hand from the admin panel.

Apple's own handling of your purchase is covered by Apple's privacy policy, not by this one. The subscription terms themselves — renewal, cancellation and refunds — are described in our Terms of Use.

10. Your rights under the GDPR

You have the right to:

Deleting your data — the quickest route

Deletion has its own button in the app, so you do not have to write to us at all. Open Goalix, tap the profile icon in the top right of the Home screen, scroll to Your data and tap Delete my data. You will be asked to confirm, and the app then shows that the request has been received.

We delete everything within 7 days of that request — your user record, your favourites and the anonymous identity itself. Nothing is locked or degraded in the meantime; you can keep using the app until the deletion happens, and if you carry on using it afterwards the app simply starts again with a fresh anonymous identity.

Two things a deletion request does not do, because they are not ours to do: it does not cancel a paid subscription (Apple bills that — cancel it in Settings › Apple Account › Subscriptions), and it does not reach into the records that Meta holds independently, described in section 5.

Once the deletion is done we keep one thing: a note that a request was made for that UID and when it was carried out. It contains nothing else, and it exists so that we can show the erasure actually happened.

Everything else

  1. Open Goalix, tap the profile icon in the top right of the Home screen, and tap your user ID to copy it.
  2. Email it to support@goalix-app.com and tell us what you want us to do.
  3. We reply within 30 days at the latest, and usually much sooner.

Because there is no account, we have no way to verify who you are beyond the anonymous UID itself. Anyone who can show us a UID is treated as the person behind it. This is the honest trade-off of an app with no sign-up: it keeps you unidentified, but it also means you should not share your UID with people you do not trust.

Your data is kept for as long as the installation is in use, and is deleted within 7 days of you asking us to delete it.

11. Reinstalling the app or losing your ID

This part is unusual, so please read it before you delete Goalix.

Your anonymous UID lives in your device keychain. When you delete the app, iOS removes that keychain entry. If you install Goalix again, the app creates a brand new UID — it has no way to recognise you, because it never knew anything about you in the first place.

After a reinstall, your favourites and any VIP access stay attached to the old UID, and the fresh installation starts empty. Favourites cannot be moved across. Restore Purchases re-establishes a subscription entitlement on the new UID from your Apple Account, so a paid subscription is not lost — only the favourites are.

If you did not copy your old UID from the profile screen before deleting the app, that old record can no longer be found or reached — not by you and not by us. It becomes orphaned data that nobody can connect to you, which also means we cannot act on a deletion request for it, because we would have no way of telling which record was yours.

This is a deliberate consequence of building an app with no account. It is the price of not asking you for an email address, and we would rather state it plainly than let you discover it after the fact. If keeping your favourites matters to you, open the profile icon in the top right of the Home screen, copy your UID and store it somewhere safe.

12. Children

Goalix is intended for an adult audience, 18 and over. It is not directed at children, it is not designed for them, and we do not knowingly collect data from them. Match predictions are commentary on sport, not advice to gamble.

If you believe a child has been using the app and data relating to them is stored, contact us and we will delete the record.

13. Security

No system is perfectly secure, but because we hold so little — no names, no emails, no payment details — there is very little to lose in the first place.

14. Changes to this policy

If this policy changes, the updated version is published on this page with a new date at the top. Meaningful changes — a new processor, a new type of data, a new purpose — will be spelled out on this page rather than buried in a version bump. Continuing to use Goalix after a change means the updated policy applies to you.

15. Contact

Questions, data requests, corrections or complaints about this policy all go to the same place: support@goalix-app.com. Please include your UID if your message is about your own data — you will find it behind the profile icon in the top right of the Home screen, and the Contact support button on that screen fills it in for you.