Privacy Policy
Version 2026-09-08 · Effective 8 September 2026
1. Who We Are
Boolip is operated by Boolip Ltd, a company registered in Israel (company no. 517350443), David Saharov 3, Rishon LeZion, Israel (“Boolip”, “we”, “us”). Boolip is a social arcade: a curated feed of quick mobile games, friend-to-friend duels, and daily leaderboards. This Policy explains what we collect, why, and your rights.
2. What We Collect
Account data.
Your email address, display name, avatar, and any profile information you provide. When you sign in with a third party (Apple or Google), we receive the basic profile fields that provider returns — typically your name, email, and avatar.
Date of birth.
We ask for your date of birth when you create an account. We use it to confirm you meet our minimum age of 13 and to apply the protections required for younger teens: if you are under 18, you can send a game only to accounts you follow. We store the date on your account and never show it to other users.
Activity & content data.
The comments you post, the likes and saves you give, the people you follow, the messages you send to other users, and any gameplay clips you choose to record and share.
Gameplay data.
Scores, play durations, completion status, duel results, and leaderboard/coliseum progress. We collect this to power leaderboards, challenges, duels, and your own statistics. We generate a random identifier on your device and send it only to Boolip’s servers with gameplay records, including when you play without an account, to understand repeat play and improve games; we do not send this identifier to PostHog or advertising partners. In the Android app we also record whether the app was installed from an ad and, if it was, which campaign and ad, next to that same random identifier on Boolip’s own servers, so we can see which campaigns bring players who keep playing. That record holds campaign and ad names and identifiers only — no name, email or account — and we do not share it, or the random identifier in it, with PostHog or advertising partners.
Safety & moderation data.
We log reports you file and reports filed against your content or profile, along with the moderation decision and reasoning. This data is used for safety, audit, and to improve our filters.
Technical data.
IP address, user agent, device type, approximate region (derived from IP), referrer, and basic interaction telemetry (screen views, load latency). We use this for security, abuse prevention, and product analytics.
Notifications.
If you enable push notifications, we store a device push token, plus the app version of that device (so an invite is only sent to a device that can open it), so we can send you duel invites, leaderboard updates, and important account notices. You can turn notifications off at any time in your device settings.
Android guest notifications.
If you enable notifications without creating an account, we store your device’s push token, language, app version, registration and last-seen times, and whether we attempted a one-time score reminder. We use this information to send a score-to-beat reminder about a Boolip game around 24 hours after registration. This guest record is not linked to a Boolip account or our gameplay installation identifier. You can stop notifications in Android settings.
3. How We Use Your Data
- To provide and operate the Service (create your account, serve games, host your content);
- To power social features — leaderboards, duels, follows, and messages;
- To moderate content and enforce our Terms (reports, review, enforcement actions);
- To prevent fraud, abuse, and unauthorized access (rate limits, anomaly detection);
- To communicate with you about your account, safety reports, or material policy changes;
- To improve the Service (which games people enjoy, where the app can be faster or clearer).
4. Third-Party Processors
We share specific data with the following processors strictly to operate the Service. Each is bound by its own data-processing agreement. We do not sell your personal data and we do not track you across other companies’ apps or websites. The one exception is install attribution in the Android app: to know which ad brought a new player, we share the Android advertising ID and install details with AppsFlyer and, for installs that came from a Meta ad, with Meta Platforms — see the AppsFlyer row below. The iOS app contains no advertising or attribution SDK.
| Processor | Purpose | Data Shared |
|---|---|---|
| Vercel | Hosting, CDN & asset storage | Application traffic, request logs, uploaded clips/assets |
| Neon | PostgreSQL database | All persistent account & gameplay data |
| Upstash (Redis) | Rate limiting and caching | User IDs, transient counters |
| Apple | Sign in with Apple | OAuth profile (name, email) |
| Sign-in | OAuth profile (email, name, avatar) | |
| Google Firebase (Cloud Messaging) | Push-notification delivery (Android). The library is also linked on iOS, where delivery itself runs over Apple’s APNs | Device push token, device identifiers |
| PostHog (EU) | Detailed product & usage analytics after consent. Before consent, only a limited set of outcome events: install and attribution result, app open, first play, campaign deep-link routing, the outcome of in-app prompts (the guest score-claim prompt, the first-launch sign-up screen on Android, and the notification prompt), opening the app from a notification, and why the previous app session ended on Android. These events do not include your name, email address or game scores | Pseudonymous user ID, in-app events, device/app metadata. No advertising identifiers. |
| AppsFlyer (Android app only) | Install attribution — measuring which ad led to an install | Android advertising ID, Google Play install referrer, IP-derived country, and app-open events. For installs that came from a Meta ad, AppsFlyer passes the install and that identifier to Meta Platforms as the ad network. Not used to build profiles or to show you ads inside Boolip; no email, name or account identifier is sent. You can opt out at any time in Android Settings → Privacy → Ads (“Delete advertising ID”, or reset it). Not present in the iOS app. |
| Sentry | Error monitoring | Stack traces, request metadata |
5. Where Your Data Lives
Our primary database (Neon) is hosted in EU regions. Media and assets are stored on Vercel (multi-region with EU presence). Some processors may process limited data outside the EEA; where required, we rely on Standard Contractual Clauses or other lawful transfer mechanisms.
6. Retention
- Account data: while your account is active, plus up to 30 days after a deletion request.
- When you delete your account, we remove installation identifiers from gameplay records linked to that account or the same installations; gameplay statistics remain without that installation link.
- Content you publish (comments, clips): retained while published; removed on takedown and hard-deleted within 30 days.
- Safety & moderation logs and reports: retained 24 months for safety and audit.
- Android guest notifications: we retain the token record to prevent repeated score reminders. We remove it when the same token is registered to an account or Firebase reports that it is invalid during a delivery attempt. Turning notifications off does not automatically delete this record. You may request deletion using the contact details below.
- Server logs: retained up to 90 days for security and debugging.
7. Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to processing, or to lodge a complaint with a supervisory authority. EU residents may exercise rights under the GDPR; California residents may exercise rights under the CCPA. To exercise any right, email support@boolip.com. We respond within 30 days.
Deleting your account.
You can delete your Boolip account and its associated personal data at any time from within the app (Profile → Settings → Delete Account), or by emailing support@boolip.com from your registered address. When you delete your account, we erase your personal data within 30 days, except limited records we are legally required to retain (such as safety logs or fraud-prevention data) as described in Retention above.
8. Cookies & Local Storage
We use a session cookie to keep you signed in and a small set of local-storage entries to remember preferences (theme, last-viewed feed position). We do not use third-party advertising cookies. We use first-party analytics to measure performance; these do not identify you across other sites.
9. Children’s Privacy
The Service is not directed at children under 13 (or under 16 in the EEA). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact support@boolip.com and we will delete it.
10. Security
We use industry-standard safeguards: encryption in transit (HTTPS/TLS), encryption at rest for our database, strong password hashing, principle-of-least-privilege internal access, automated security monitoring, and regular review of our infrastructure. No method of transmission or storage is 100% secure; we work to continuously improve.
11. Changes to This Policy
We may update this Policy. When we make material changes, we will revise the version string above and notify active users so you can review and re-accept where required.
12. Contact
Privacy questions, data-rights requests, or general support: support@boolip.com.

