Privacy Policy
How {{LEGAL_ENTITY}} collects, uses, and protects your personal data.
This Privacy Policy explains what personal data we collect when you use FOMA, why we collect it, and the rights you have over it. FOMA sends you notifications about events you choose to follow — game releases, TV and film, sports, rocket launches, and more — so most of what we hold is the account and the preferences needed to do exactly that.
We are based in the European Union and follow the General Data Protection Regulation (GDPR). If any term here conflicts with a mandatory right the GDPR gives you, the GDPR wins.
1. Who we are In short {{LEGAL_ENTITY}}, based in {{CONTROLLER_COUNTRY}}, is the data controller. Email [email protected] with any privacy question.
The controller responsible for your personal data is {{LEGAL_ENTITY}} (company no. {{COMPANY_REG_NUMBER}}), {{REGISTERED_ADDRESS}}, {{CONTROLLER_COUNTRY}}.
For anything in this policy, contact us at [email protected].
2. What we collect In short Your email and password, the event filters you save, your notification and device settings, payment status (via Stripe — we never see your card number), and masked product-usage analytics.
Data you give us
- Account: your email address and a password (stored only as a secure hash — we can never read it).
- Preferences: your timezone, country, language, and notification settings, so alerts arrive at a sensible local time.
- Event-type interests: optional account or local choices used to order discovery surfaces. Local choices stay in that browser; signed-in choices sync to your account and across devices. These interests are not alerts and do not create notifications.
- Your subscriptions: the event filters and follows you create. These describe your interests (for example, a game franchise or a sports team) and are the core of the service.
- Payments: if you subscribe to Pro, our payment processor Stripe collects your payment details. We never receive or store your full card number — only your subscription status and a Stripe customer reference.
- Support: anything you send us by email.
Data we collect automatically
- Device & push: if you enable notifications, a push subscription identifier from our delivery provider (OneSignal), your device platform, and a short automatic label so you can tell your devices apart in Settings (for example "Chrome on macOS" or "iPhone"). We also store your device model, OS version and app version to diagnose crashes and verify staged releases. We never collect the name you gave the device yourself.
- Usage analytics: how you move through the app — pages viewed, features used, and session recordings in which all form inputs are masked so we never capture what you type. Analytics runs on our own self-hosted PostHog server; this data is not sent to an advertising network.
- Searches: the search terms you enter in the app, so we can improve results.
- Technical: your IP address and browser/device type, processed transiently for security and to deliver the service (via our CDN, Cloudflare, and our server logs).
3. How we use your data In short To run your account, send the notifications you asked for, take payment for Pro, keep the service secure, and improve it.
- Create and manage your account and sign you in.
- Match incoming events against your saved filters and send you the notifications you requested.
- Process Pro subscriptions and handle billing.
- Keep FOMA secure and prevent abuse and fraud.
- Understand how the product is used so we can improve it.
- Respond to your questions and legal requests.
4. Our legal bases In short Contract (to run the service), legitimate interests (security and improving the product), consent (analytics cookies and any marketing), and legal obligation (tax records).
Under the GDPR we rely on:
- Performance of a contract — creating your account, delivering your notifications, and billing you for Pro.
- Legitimate interests — keeping the service secure, preventing fraud, and improving the product, balanced against your rights.
- Consent — non-essential analytics cookies and session recording, and any marketing email. You can withdraw consent at any time.
- Legal obligation — retaining payment and tax records where the law requires it.
5. Analytics and session recording In short We use our own self-hosted PostHog — not a third-party ad tool. Session recordings mask every input, so we never see what you type. In the EU these run only with your consent.
We run PostHog on our own servers, so product-usage data stays within our infrastructure and is never sold or shared with advertisers. Session recordings are configured with all inputs masked and sensitive elements excluded, so passwords, messages, and similar content are never captured.
Because analytics and recording are not strictly necessary to provide the service, in the EU/EEA we use them only where you have given consent. See our Cookie Policy for the specifics and how to change your choice.
7. International transfers In short Our servers are in the EU. A few providers (like Stripe and OneSignal) may process data outside the EEA under Standard Contractual Clauses.
Your data is stored on servers in {{HOSTING_REGION}}. Some processors named above may process data outside the European Economic Area. Where they do, the transfer is protected by an approved mechanism such as the European Commission's Standard Contractual Clauses or an adequacy decision.
8. How long we keep it In short Account data until you delete your account; payment records for the legally required period; analytics is anonymised when you delete your account.
- Account and preferences — kept while your account is open. When you delete your account we delete or anonymise your personal data.
- Analytics — when you delete your account, records tied to you are anonymised so they can no longer identify you.
- Payment and tax records — retained for the period required by accounting and tax law in {{CONTROLLER_COUNTRY}}.
- Backups — deleted data may persist in encrypted backups for a short rolling window before being overwritten.
9. How we protect your data In short Encryption in transit, hashed passwords, secrets kept in a dedicated vault, and access limited to what's necessary.
We use technical and organisational measures appropriate to the risk: TLS encryption for all traffic, passwords stored only as secure hashes, secrets held in a dedicated secrets manager, network isolation for our databases, and access limited to those who need it. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.
10. Your rights In short Access, correct, delete, restrict, port, or object to the use of your data, and withdraw consent — all free of charge. See our GDPR page for how.
You can access, correct, delete, restrict, or port your data, object to certain processing, and withdraw consent at any time. You can delete your account and its personal data directly in the app. For anything else, email [email protected]. Full detail and timelines are on our GDPR & Your Rights page.
11. Children In short FOMA isn't intended for children under 16. We don't knowingly collect their data.
FOMA is not directed at children under 16 (or the minimum age of digital consent in your country). We do not knowingly collect data from children; if you believe a child has given us data, contact us and we will delete it.
12. Changes to this policy In short We'll post changes here and update the date; significant changes get a heads-up.
We may update this policy as the product evolves. We will post the new version here with a revised date, and for significant changes we will notify you in the app or by email.
13. Contact us In short Email [email protected], or your local data-protection authority if you're unhappy.
Questions or requests: [email protected]. You also have the right to complain to a supervisory authority — in our case {{SUPERVISORY_AUTHORITY}}, or the authority where you live.
Last updated 2026年7月19日. See all our legal pages.