Legal
Privacy Policy
This policy explains what information CFB APP handles, why it is used, and the choices available to you.
Effective
Scope
CFB APP is an independent college football information service operated. This policy applies to cfb.app and its authentication, preview, and supporting services.
Information we collect
- Account and authentication data. When you create an account, we store your email address, name, provider account identifier, account verification status, and session information. A social provider may also return a profile image and OAuth tokens; stored OAuth tokens are encrypted.
- Email-code data. When you request an email sign-in code, we process your email address and a one-time code so Cloudflare Email Service can deliver the message. Codes are stored only in hashed form and expire after five minutes.
- Usage and device data. We collect page URLs and paths, referring pages, campaign parameters, IP address, browser and device information, language, request headers, and timestamps to understand usage, maintain security, and diagnose failures.
- Cookies. We use secure authentication cookies to protect accounts, enforce rate limits, prevent abuse, and support login.
- Communications. If you contact the operator, we receive the information you choose to provide in that message.
How we use information
- Authenticate users, maintain sessions, and deliver sign-in codes.
- Protect accounts, enforce rate limits, and prevent abuse.
- Operate, troubleshoot, measure, and improve CFB APP.
- Respond to support, privacy, and security requests.
- Comply with applicable law and protect users and the service.
How information is shared
We do not sell personal information or use it for targeted advertising.
- PostHog receives pageview and technical analytics under anonymous identifiers; CFB APP does not ask PostHog to create person profiles from these events.
- Google, X, Reddit, or Facebook processes information when you choose that provider for sign-in and returns the profile information needed to create or access your CFB APP account.
- Information may be disclosed when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or complete a service transfer subject to appropriate safeguards.
Retention and security
One-time codes expire after five minutes. Account, provider, session, verification, rate-limit, operational log, and analytics data is kept only for as long as reasonably needed for the purposes described here, legal obligations, security, and dispute resolution.
We use safeguards including encrypted transport, secure cookies, hashed one-time codes, encrypted OAuth tokens, and access controls. No system can guarantee absolute security.
Your choices and rights
- Use email-code sign-in instead of an enabled social provider.
- Sign out and revoke CFB APP access in your provider account.
- Delete or restrict cookies using browser controls.
- Ask to access, correct, or delete account information, subject to legal and security limitations.
To make a privacy request, contact contact@cfb.app. Do not include one-time codes or provider credentials. We may need to verify that you control the relevant account.
Children's privacy
CFB APP is a general-audience service and is not directed to children under 13. If you believe a child provided personal information without appropriate permission, contact contact@cfb.app so it can be reviewed and deleted where required.
Changes and contact
This policy may be updated as the service or legal requirements change. Material changes will be reflected by a new effective date on this page. Questions may be directed to contact@cfb.app.