Privacy Policy

How Otto & Best Limited collects, uses, and protects your personal data.

Effective: 2026年8月29日 Last updated: 2026年9月13日
This policy isn't available in your language yet. The authoritative English version is shown below.

This Privacy Policy explains what personal data we collect when you use FOMA, why we collect it, and the rights you have over it. FOMA sends you notifications about events you choose to follow (game releases, TV and film, sports, rocket launches, and more) so most of what we hold is the account and the preferences needed to do exactly that.

We are based in the European Union and follow the General Data Protection Regulation (GDPR). If any term here conflicts with a mandatory right the GDPR gives you, the GDPR wins.

1. Who we are In short Otto & Best Limited, based in Ireland, is the data controller. Email [email protected] with any privacy question.

The controller responsible for your personal data is Otto & Best Limited, a company registered in Ireland under company number 680594. Our registered office address is on the public register of the Irish Companies Registration Office. Write to us at [email protected] and we will give it to you on request.

For anything in this policy, contact us at [email protected].

2. What we collect In short Your email and password, the event filters you save, your notification and device settings, payment status processed by Stripe without us seeing your card number, and masked product-usage analytics.

Data you give us

  • Account: your email address and a password stored only as a secure hash that we can never read.
  • Preferences: your timezone, country, language, and notification settings, so alerts arrive at a sensible local time.
  • Event-type interests: optional account or local choices used to order discovery surfaces. Local choices stay in that browser. Signed-in choices sync to your account and across devices. These interests are not alerts and do not create notifications.
  • Your subscriptions: the event filters and follows you create. These describe your interests (for example, a game franchise or a sports team) and are the core of the service.
  • Shared alerts: when you choose Share, the filter criteria become available to anyone with the link and remain available without an expiry until we remove the link. Delivery channels, reminder timing and your unfinished draft are not shared. We keep an internal reference to the original creator, but the creator's identity is not shown to people opening the link.
  • Payments: if you subscribe to Pro, our payment processor Stripe collects your payment details. We receive only your subscription status and a Stripe customer reference, never your full card number.
  • Support: anything you send us by email.

Data we collect automatically

  • Device & push: if you enable notifications, the push address your own browser or device issues (a Web Push subscription from your browser's push service, or a Firebase Cloud Messaging registration token on a mobile app) together with your device platform and a short automatic label so you can tell your devices apart in Settings (for example "Chrome on macOS" or "iPhone"). We also store your device model, OS version and app version to diagnose crashes and verify staged releases. We never collect the name you gave the device yourself.
  • Usage analytics: how you move through the app: pages viewed, features used, and session recordings in which all form inputs are masked so we never capture what you type. Those recordings also include the app's network requests and their content, excluding anything to do with signing in. See *Analytics and session recording* for what that means in practice. We use PostHog for this. It is a product-analytics tool, not an advertising network, and this data is never sold or used to target ads.
  • Searches: the search terms you enter in the app, so we can improve results.
  • Shared-link views: every successful shared-alert open increases its public view count. Separately, we keep a record of the request under our legitimate interest in understanding how shared alerts are used, even if you decline optional analytics. A request with a usable signed-in session can carry your internal account reference, while a genuinely anonymous request can carry FOMA's browser and session identifiers. We do not attach those identifiers when a session has been rejected, and we sever them if you delete your account.
  • Technical: your IP address and browser/device type, used to deliver the service and keep it secure (via our CDN, Cloudflare, and our server logs). We record your IP address against security-relevant account actions (signing in, changing a password, deleting your account) and delete those records after 90 days.
3. How we use your data In short To run your account, send the notifications you asked for, take payment for Pro, keep the service secure, and improve it.
  • Create and manage your account and sign you in.
  • Match incoming events against your saved filters and send you the notifications you requested.
  • Create permanent shared-alert links, show their public view counts, and let another person reuse the shared criteria.
  • Process Pro subscriptions and handle billing.
  • Keep FOMA secure and prevent abuse and fraud.
  • Understand how the product is used so we can improve it.
  • Respond to your questions and legal requests.
5. Analytics and session recording In short We use PostHog, a product-analytics and error-tracking tool rather than an ad tool. Session recordings mask every input and exclude sign-in and password requests entirely. They do capture the app's other network traffic, which can include data the app was showing you. Feedback you send us goes there too, without your account id or email attached. In the EU client analytics and recording run only with your consent. Essential service and error reports do not.

We use PostHog for product analytics and session recording. It is a product-analytics tool rather than an advertising network: your usage data is never sold, and never shared with advertisers. It is processed in the European Economic Area or the United Kingdom, as described under *International transfers* below. Session recordings are configured with all inputs masked and sensitive elements excluded, so passwords, messages, and similar content are never captured.

Session recordings also capture the network requests the app makes while you use it, including their headers and their content. This is how we can see what actually happened when something goes wrong, rather than guessing from a screenshot. It is the difference between fixing a bug in an hour and fixing it in a week. It does mean a recording can contain data the app was displaying to you at the time, such as your email address or the alerts you have saved. Requests to our sign-in and password endpoints are excluded from this, so passwords, sign-in codes and password-reset links are never captured. Recordings follow the same consent rule and the same retention as the rest of this section.

When you send us feedback from inside the app, your message is also sent to PostHog's support tool, so that we can read it and act on it. We do not attach your account id or your email address to it: it carries only a reference number, which means nothing outside our own records. If you delete your account we sever that reference, so nothing in our own records connects the message back to your account. Keep in mind that the message itself is whatever you write. If you put your email address or other personal details in the text, those travel with it.

Because analytics and recording are not strictly necessary to provide the service, in the EU/EEA we use them only where you have given consent. See our Cookie Policy for the specifics and how to change your choice.

Separately, under our legitimate interest in operating and improving the service, we send limited service events and operational error reports to PostHog even if you decline client analytics. Service events include notification delivery, subscription changes, feedback submission, and native update health. Service events and error reports can carry the internal account, subscription, or device reference needed to join the operational flow. An error report can also include the message and stack, a URL with sensitive query values removed, and browser or app details. These reports never enable client tracking or session recording.

6. Who we share data with In short Only the processors needed to run FOMA: PostHog (analytics, error tracking and support), Stripe (payments), Cloudflare (security/CDN and the mail relay), the push service your own browser or phone uses, and our host. We send notifications ourselves. We never sell your data. Event data sources receive nothing about you.

We do not sell your personal data. We share it only with service providers who process it on our behalf under contract:

  • PostHog: product analytics, session recording, operational error tracking, and the support tool that receives the feedback you send us. See *Analytics and session recording* above for what is captured, what is masked, and what is left out of a feedback message.
  • Stripe: payment processing for Pro subscriptions.
  • Push services: a notification you asked for is handed to the push service your own browser or device already uses: Mozilla for Firefox, Google (Firebase Cloud Messaging) for Chrome and for the Android and iOS apps, Apple for Safari. They receive the address your device issued and the notification itself. We do not choose them and cannot substitute one. Your browser or operating system does.
  • Cloudflare: content delivery, DNS, protection against attacks, an invisible bot check when you sign in or create an account, and the mail relay that carries our transactional email. See Cloudflare's Turnstile Privacy Addendum for how that check is handled.
  • Discord: only if you choose to add a Discord webhook as a notification channel. The webhook is yours. We post your notification to the address you gave us, and nothing reaches Discord until you set one up.
  • Our hosting provider: servers located in the United Kingdom, where the application and database run.

The event catalogues we draw on (such as TMDB, IGDB, and launch and sports data providers) are sources we read from: we send them nothing about you. We may also disclose data if required by law or to protect our rights, users, or the public.

7. International transfers In short Our servers are in the United Kingdom: outside the EEA, under the UK adequacy decision. Analytics is processed in the EEA. A few providers (like Stripe, and the push service your browser or phone uses) may process data elsewhere under Standard Contractual Clauses.

Your account, subscription and saved-filter data is stored on servers in the United Kingdom. Product analytics and session recordings are processed in the European Economic Area. Because we are established in Ireland, storage in the United Kingdom is a transfer outside the European Economic Area. It is covered by the European Commission's adequacy decision for the United Kingdom, which recognises UK data-protection law as providing an equivalent level of protection. Some processors named above may also process data outside the EEA. Where they do, the transfer is protected by an approved mechanism such as the European Commission's Standard Contractual Clauses or an adequacy decision.

8. How long we keep it In short Account data until you delete your account, then a 30-day grace period you can cancel from before erasure. Payment records for the legally required period. Analytics is anonymised as soon as you ask to delete.
  • Account and preferences: kept while your account is open. When you ask to delete your account we sign you out, stop your notifications, disable your alerts and unlink your analytics records straight away. The account record itself is held for 30 days and then permanently erased, along with your sign-in.
  • Changed your mind: sign back in during those 30 days and the app shows the date your account will be erased, with a button to cancel. Cancelling stops the erasure and brings your alerts and devices back as they were. The analytics unlinking above is not reversed. Those records can no longer be traced back to you, which is the point of it.
  • Notification records: your notification history is kept for 90 days. A minimal technical duplicate-prevention key (alert, event, channel and notification kind, not the message content) is kept while that alert is active so a removed event cannot notify you again if it returns. It is deleted 90 days after you delete the alert or ask to delete your account.
  • Analytics: the link between you and our product-usage records is severed as soon as you ask to delete your account, so they can no longer identify you.
  • Shared alerts: the public filter criteria and view count remain available without an expiry. If you delete your account, we remove the internal creator reference and any account or browser identifiers attached to its view records.
  • Payment and tax records: retained for the period required by accounting and tax law in Ireland.
  • Backups: deleted data may persist in encrypted backups for a short rolling window before being overwritten.
9. How we protect your data In short Encryption in transit, hashed passwords, secrets kept in a dedicated vault, and access limited to what's necessary.

We use technical and organisational measures appropriate to the risk: TLS encryption for all traffic, passwords stored only as secure hashes, secrets held in a dedicated secrets manager, network isolation for our databases, and access limited to those who need it. No system is perfectly secure, but we work to protect your data and will notify you and the authorities of a breach where the law requires.

10. Your rights In short Access, correct, delete, restrict, port, or object to the use of your data, and withdraw consent. These rights are free of charge. See our GDPR page for how.

You can access, correct, delete, restrict, or port your data, object to certain processing, and withdraw consent at any time. From Settings you can download your account data (your profile, your alerts and their history, the shared alerts you originally created, your notification history, your devices, your searches, your feedback and your account activity) and delete your account. For anything that download does not cover, or any other request, email [email protected]. Full detail and timelines are on our GDPR & Your Rights page.

11. Children In short FOMA isn't intended for children under 16. We don't knowingly collect their data.

FOMA is not directed at children under 16 (or the minimum age of digital consent in your country). We do not knowingly collect data from children. If you believe a child has given us data, contact us and we will delete it.

12. Changes to this policy In short We'll post changes here and update the date. Significant changes get a heads-up.

We may update this policy as the product evolves. We will post the new version here with a revised date, and for significant changes we will notify you in the app or by email.

13. Contact us In short Email [email protected], or your local data-protection authority if you're unhappy.

Questions or requests: [email protected]. You also have the right to complain to a supervisory authority, in our case Ireland's Data Protection Commission (DPC), or the authority where you live.

Last updated 2026年9月13日. See all our legal pages.