BeefedUp
Privacy Policy
Version: July 30, 2026
This policy explains what BeefedUp collects, why it is used, which providers process it, how long it is kept, and the choices available to you. It applies to the BeefedUp mobile and web app, support, and related services.
1. Data We Collect
Account and profile
- Email address, optional phone number, authentication provider, and provider identifiers.
- Display name, handle, profile and banner images, biography, favorite team, and other profile choices.
- During signup, your birthday is checked on your device to determine account eligibility and apply age-appropriate protections. BeefedUp receives and stores only the resulting category (13–17 or 18+), confirmation that you meet the minimum age, and the versions of the Terms, Privacy Policy, and Community Guidelines you accepted. Your exact birthday is not transmitted to or stored by BeefedUp for this purpose.
If you choose Sign in with Apple, Apple provides an account identifier and may provide your name and email the first time. If you choose Hide My Email, BeefedUp receives and uses Apple's private relay email address instead of your personal address.
Fantasy gameplay and purchases
- League membership, teams, rosters, drafts, waivers, trades, matchups, scoring, standings, commissioner actions, Beef challenges, Power features, and related history.
- Purchase, receipt, restore, renewal, and entitlement status for Ad-Free, Commissioner Pro, and BeefedUp+ League Pass products.
Apple App Store and Google Play process supported mobile purchases. Xsolla processes supported web purchases as the merchant of record. BeefedUp does not receive payment-card numbers. Money collection for league entry fees, cash wagers, pots, or escrow is disabled in public releases.
Messages, social content, and media
- Direct, group, league, and locker-room messages.
- Social posts, comments, reactions, follows, bookmarks, polls, reports, blocks, and moderation records.
- Photos, GIF selections, and other media you choose to upload or share.
- Approximate city, region, and country labels when you choose to add a location to a post. Device coordinates may be used temporarily for reverse geocoding; BeefedUp is designed to store and publish the approximate label rather than exact coordinates.
BEEF AI
When you choose BEEF AI, the question and bounded fantasy context needed to answer it are sent for the current request. Context can include rosters, player results, scoring settings, week, projections, injuries, and matchups. BeefedUp does not save BEEF AI question text or response history to your account during ordinary use. If you explicitly report an AI response, the reported question, answer, reason, request identifier, and limited request context are saved in the moderation report so authorized reviewers can investigate it. Operational records can otherwise include user ID, feature context, provider/model, timing, status, and token totals without the question or answer text.
Support
Support requests can include category, subject, description, reply email, selected league, and bounded diagnostics such as app version, build, platform, OS version, device model/type, locale, time zone, and relevant purchase identifiers or status. We hash network-address information for abuse rate-limiting. Do not send passwords, sign-in codes, unrelated private messages, or payment-card information.
App activity, advertising, and diagnostics
- App opens, screen or feature interactions, journey timing, session identifiers, platform, OS, app/build/release identifiers, and performance events.
- Fatal and nonfatal error message, stack, screen/placement, session, app/build, and platform data. Diagnostic fields are allowlisted before transmission: user-message and purchase-identifier fields are dropped, while credentials, contact details, URL query strings, and any recognizable copies of those values in the remaining error text or stack are redacted.
- Push token, notification preferences, delivery state, and interaction state.
- When advertising is active: IP-derived approximate location, device or advertising identifiers, app/ad interactions, diagnostics, performance, and advertising-event data.
The app keeps bounded device caches so recently viewed pages can open quickly. Account-bound roster, league, feed, draft, outbox, and message state is scoped to the signed-in account, encrypted at rest in the native app, and purged on sign-out or account deletion. Browser copies expire after no more than 24 hours and use the same account purge. Public player, projection, score, and schedule caches are not account data and can remain after sign-out.
2. How We Use Data
- Provide accounts, fantasy leagues, social features, messages, media, AI requests, purchases, notifications, and support.
- Personalize league and app experiences.
- Measure reliability, diagnose errors, secure accounts, prevent abuse and fraud, and enforce our rules.
- Display and measure advertising for eligible free-tier users.
- Meet legal obligations, protect users and the service, resolve disputes, and respond to valid requests.
BeefedUp does not sell personal information for money.
3. Providers and Disclosures
Data is disclosed to providers only as needed for the functions described here, subject to provider terms and configuration:
- Supabase — authentication, database, file storage, Realtime, and server functions.
- Expo and EAS — builds, updates, and push routing. Push content and tokens pass through Expo and then Apple Push Notification service or Firebase Cloud Messaging.
- Apple and Google — app distribution, authentication where selected, purchases, device services, and push delivery.
- Google AdMob and Google AdSense — mobile-app and browser advertising, consent controls, measurement, diagnostics, and fraud prevention for eligible free-tier users. Depending on platform, configuration, and consent, this can include cookies or local storage, IP-derived approximate location, app or website interactions, diagnostics, and device or advertising identifiers.
- RevenueCat — linked customer ID, purchase history, receipts/transactions, products, restores, and entitlement state.
- Xsolla — linked user ID, email and country where provided, web checkout, payment and transaction records, subscription management, fraud prevention, receipts, refunds, and entitlement events.
- OpenRouter — BEEF AI processing. Requests ask for zero-data-retention and denial of provider data collection. Groq may be used only as a configured fallback after equivalent controls are verified.
- Resend and our support mailbox — authentication, security, support-ticket delivery, replies, and attached support diagnostics.
- Football and media providers — schedules, scores, projections, injuries, player information, and related fantasy data.
- KLIPY — optional GIF search receives search terms, viewed/selected results, IP address, and device/network information after the user completes the feature's first-use disclosure. KLIPY states that it may use this data for analytics, advertising, ad measurement, and interest targeting. BeefedUp does not send a BeefedUp account ID to KLIPY. When you select a GIF, BeefedUp copies it to BeefedUp storage before publication so other users do not contact KLIPY merely by viewing your post, pin, or message.
Some public or league-scoped content is disclosed to the other users you choose to interact with. Reports can be disclosed to authorized moderators.
4. Advertising and Tracking Choices
Where required, BeefedUp gathers advertising consent before initializing ads and provides advertising privacy choices. Public iOS store builds keep AdMob ads disabled and delay native app measurement unless and until the applicable consent and disclosure requirements are met. On Android, AdMob does not initialize until an eligible account age category is available. Accounts in the 13–17 category receive Google's teen age-restricted and under-age-of-consent treatment; Android ad requests remain non-personalized. Eligible browser users may receive AdSense ads according to their consent and Google advertising settings. Personalized, non-personalized, and limited advertising can still involve cookies or local storage, identifiers, measurement, fraud prevention, and contextual advertising.
KLIPY GIF search is optional and off for each account until the user confirms they are 18 or older and accepts an in-app disclosure. That choice is saved to the BeefedUp account and remains active across sign-out, reinstall, and devices until the user turns it off. On iOS, BeefedUp also requests App Tracking Transparency permission before contacting KLIPY; if permission is denied, KLIPY remains off. On other platforms, the in-app disclosure remains required. You can stop future KLIPY requests at any time in Profile, Settings, Account actions, KLIPY GIF search. BeefedUp remains usable without KLIPY.
5. Retention
Retention depends on the record and the reason it is needed:
- Account, profile, messages, social, and league data: while the account or relevant league is active, until you delete supported content, or until account deletion, subject to the exceptions below.
- Performance telemetry: exact PostgreSQL performance and product-denominator rows are generally retained for 7 days. Sampled, allowlisted performance measurements sent without an account or session identifier to Cloudflare Analytics Engine can remain for up to 3 months under that service's fixed retention.
- Application error logs: redacted raw R2 archives and deduplicated PostgreSQL error summaries are retained for 30 days.
- Push provider message identifiers: scrubbed after approximately 7 days.
- Notification delivery records: generally 45 days; noncritical notifications generally 120 days; critical notifications no longer than 365 days.
- Inactive push tokens: generally 90 days.
- Closed support tickets: generally 2 years after closure. Open requests remain until resolved and are then placed on the closed-ticket schedule.
- Mock drafts: generally the most recent 10 and no more than approximately 90 days.
- Locker-room content: generally the current season plus approximately 90 days after rollover, subject to shorter content expiration.
- BEEF AI question and answer text: not stored by BeefedUp as account history during ordinary use. When you explicitly report an AI response, a bounded question-and-answer snapshot is retained with the moderation record as reasonably needed for safety review, enforcement, appeals, disputes, fraud prevention, or legal obligations. Limited operational metadata follows reliability and abuse-prevention needs.
- Provider copies: app stores, RevenueCat, Xsolla, Resend/support mailboxes, Expo/APNs/FCM, AdMob, AdSense, KLIPY, AI processors, and other providers may retain records under their contracts, security practices, or legal duties. Payment providers may retain transaction records for tax, accounting, fraud, chargeback, and legal requirements. KLIPY states that it retains information while needed to provide its services and may keep it longer for legal, dispute, or other permitted reasons, followed by de-identified or aggregated retention.
We may retain limited security, fraud, moderation, transaction, legal, or dispute records longer where reasonably required. Retention rules may pause for a legal hold.
6. Account and Data Deletion
Delete your account in Profile, Settings, Delete Account or follow the web process at Delete Account. Valid verified requests are actioned within 30 days.
Deletion removes or overwrites profile data, authored messages and social content, memberships, push data, support records in the application database, covered uploaded files, and the account link on retained Xsolla event or subscription records. It requests deletion of the identified RevenueCat customer. It does not cancel an App Store, Google Play, or Xsolla subscription; cancel recurring billing before deleting your account.
Some gameplay, scoring, draft, transaction, security, and audit history can remain in de-identified form as “Deleted User” to preserve league integrity, prevent fraud, resolve disputes, or meet legal obligations. Account deletion erases the account's keyed, pseudonymous raw-error archive prefix; deduplicated diagnostic summaries can remain unlinked until their 30-day expiration. Provider and support-mailbox copies can follow separate retention schedules. BeefedUp does not give KLIPY an account ID, so BeefedUp account deletion cannot identify or automatically erase KLIPY records associated only with network or device information; use KLIPY's privacy-request process or ask BeefedUp support for help. Cleanup steps are retried during deletion; if a storage or Apple revocation step still fails after the account is disabled, the deletion result includes a cleanup warning so you can request support follow-up.
7. Access, Correction, Export, and Specific Deletion
Use Profile, Settings, Privacy & data choices or visit Privacy & Data Requests to request:
- access to the personal data associated with your account;
- correction of inaccurate account data;
- a portable export, generally delivered as JSON/CSV with separate media links where appropriate;
- deletion of specific data without closing the full account.
We may verify account control and redact another person's data, security-sensitive material, provider-only records, or information we must retain. We generally respond to valid requests within 30 days, subject to applicable law.
8. Email and Push Choices
BeefedUp currently sends authentication, security, purchase-support, and support-reply email rather than marketing newsletters. Transactional messages do not include a marketing unsubscribe. If marketing email is introduced, BeefedUp will add the required consent and unsubscribe controls first.
Push notifications can be disabled globally, by category, and for supported league events in Settings. Disabling push suppresses delivery but may not immediately delete the token; tokens are removed or deactivated on sign-out, invalidation, inactivity cleanup, or account deletion.
9. Age Eligibility
BeefedUp is intended for people age 13 and older. Account creation uses a neutral, blank birthday entry. The app checks that entry on the device and does not transmit or retain the exact birthday. People who are not eligible cannot create or continue with a BeefedUp account. Only the resulting 13–17 or 18+ category is stored so BeefedUp can enforce age eligibility and apply age-appropriate privacy and advertising treatment. If we learn that an account belongs to a child under 13, contact us so we can investigate and delete the account as appropriate.
KLIPY GIF search is separately limited to people who confirm they are 18 or older because KLIPY states that users under 18 may use its service only with parent or guardian involvement. Users who do not complete that confirmation can continue using the rest of BeefedUp.
10. Security and International Processing
We use access controls, encryption in transit, native encryption for account-bound device caches, row-level authorization, rate limits, audit records, and account-security measures designed to protect data. No system is completely secure. Providers may process data in the United States or other countries where they operate, subject to applicable safeguards.
11. Changes
We may update this policy. Material changes will be identified by a new version date and, where appropriate, an in-app notice or renewed acknowledgment.
12. Contact
Privacy requests: privacy@beefedup.app
General support: support@beefedup.app