Privacy Policy
Last updated: September 18, 2026
BilliHub ("the App") is an app for keeping your billiards records and sharing them with the people you play with. The App is designed around one principle: do not collect what is not needed.
1. Your account
- The App creates an anonymous account automatically the first time you open it, so your records belong to you and can be deleted later.
- When you do something other people can see โ posting, following โ we ask you to verify yourself with one of: email and password, Sign in with Apple, or Sign in with Google.
- With Sign in with Apple, you can keep your email address hidden from us.
- Your account holds an internal identifier (a random ID), the display name you choose, and a profile photo if you set one.
- Your display name is shown to other users. Do not use your real name.
2. What is stored on the server
To share them with other people, the following are stored on the server:
| Stored | Contents |
|---|---|
| Posts | Text, photos, time posted, and a copy of a match result if you attached one |
| Profile | Display name, profile photo |
| Follows | Who you follow |
| Check-ins | The shop name and time of "I'm playing here right now" |
| Shops | The name and location (latitude and longitude) of a shop. This is a shared list |
| Blocks | Who you blocked |
| Reports | The content and reason of a report |
| Notification address | Your device's notification token, language and platform (see ยง9) |
๐ด The shop list itself does not say who added an entry. It holds only the name and the location, and other users cannot tell who added a shop.
However, so that the person who added a shop can correct it, we do keep a record of which shop was added by whom, stored separately. That record is readable only by that person and by us โ never by other users.
The following stay only on your device and are never sent to the server:
| On your device only | Contents |
|---|---|
| Match records | Opponent, game, score, date |
| 5-9 | Match in progress, point-game records, saved rules |
| My cues | Name, maker, photo, notes, parts |
| Favourite shops | Shop names and notes |
| App settings | Whether to share check-ins as posts, and similar |
| Mutes and hidden posts | Records of posts you hid |
Storage is provided by Firebase (Google; database and authentication, Tokyo region) and Cloudflare R2 (photos). Data may be stored on servers outside your country.
3. Location
Your location is read once, when you open the check-in screen. It is used for two things:
- To put nearby shops at the top of the list. For this purpose your location is used for sorting only โ it is neither stored nor sent anywhere.
- To add a shop that is not on the list yet. When you add one, the location at that moment is saved on the server as that shop's location (the "Shops" row in section 2). From then on, the shop appears automatically for anyone who goes there.
๐ด What is saved is the shop's location, not a record of your movements. No location history is kept. The link between you and a shop you added is stored as described in section 2 โ readable only by you and by us, so that you can correct your own entries.
๐ด It never tracks you continuously and never reads your location in the background. We do not look up where you are while the App is closed.
๐ด Granting location permission is optional. Check-in works without it โ you pick a shop by name or type one in; the list simply is not sorted by distance.
โ ๏ธ When you add a shop, its location is shared with other users. Do not add your home, or anywhere else you do not want other people to know about, as a shop.
โ ๏ธ A check-in itself tells your followers that you are at a shop (see section 5). That is not location data โ it is the shop name you chose.
4. Photos
- When you pick a photo, the App re-encodes it as JPEG on your device before uploading. Capture metadata (Exif, which can include the latitude and longitude of where the photo was taken) is not carried over by that re-encoding.
- The upload path also strips the Exif and comment segments (a second layer).
- Post photos and profile photos are visible to other users, including your followers.
- My cue photos stay on your device only.
5. Who can see what
- Posts and profiles are visible to signed-in users.
- Check-ins are visible only to people who follow you.
- However, if you turn on the setting "Also share check-ins as posts", every check-in also creates a post containing the venue name (for example, "Came to ___"). Posts are visible to everyone who is signed in โ a wider audience than check-ins.
- This setting is off by default. While it is off, no check-in ever becomes a post.
- The setting lives under Settings on the "Me" tab and can be turned off at any time. Posts that were already created can be deleted by you from the timeline (and if you undo a check-in right away, its post is deleted with it).
- Match records themselves stay on your device and are not visible to others. Only when you attach one to a post does a copy become part of that post.
6. Reports and blocks
- The content of a report is readable only by us. Other users never see it.
- ๐ด Nobody can delete a report โ not even the person who filed it. This prevents abuse (reporting someone and then erasing the trail). Reports survive account deletion.
- You can undo a block yourself.
7. Deleting your account
You can delete your account at any time from "Delete account" on the Me tab.
Removed from the server: posts, photos, follows, check-ins, profile.
What remains, and why it cannot be removed:
- Reports we have received (see section 6)
- Suspension records applied by us
- Other people's records of following you (only they can delete those)
- Photos attached to posts created before September 11, 2026 (an older format that the deletion path cannot reach)
- If you delete an account while still anonymous, an internal identifier with nothing in it. It is empty, and that account can never be signed into again.
- ๐ด Shops you added (name and location). The shop list is shared: other people have bookmarked those shops and check in at them. Deleting one would leave their screens pointing at a shop that no longer exists, so shops stay. โ ๏ธ The record of which shops you added (section 2) is deleted.
Things stored on your device (match records, 5-9, my cues, favourite shops, display settings) remain. We do not think a record of the games you played should disappear merely because you closed your account.
8. BilliHub Pro
- Purchases and cancellations are handled through the Apple App Store.
- We never receive your payment details, such as credit card numbers.
- All we keep is whether an active plan exists.
9. Notifications
When someone you follow checks in at a venue, we send a notification to your device.
- To do that we keep your device's notification token (the address issued by Apple), your language and your platform. They are stored in Cloudflare KV and can be read only by the program that sends the notifications. Other users cannot see them.
- Notifications are written in the language of the person receiving them. That is why we keep the language.
- Turning off "Receive notifications" in Settings deletes this device's registration. We do not keep a "may we send" flag - we delete the registration itself (with no registration there is nothing to send to).
- Deleting your account also deletes the registration.
- We delete it as well when Apple tells us the address no longer exists.
- โ ๏ธ Notifications require the OS permission. If you declined it, nothing is delivered. The rest of the App (check-ins and so on) works with notifications turned off.
10. Advertising
๐ด The free version shows ads (Google AdMob native ads) in the timeline.
- ๐ด Ads are fixed to "non-personalised". They are not chosen from your behaviour or history. The only signals used are what is on the screen and your approximate area.
- Because of that we do not show the App Tracking Transparency prompt. We do not use the advertising identifier to link your data with other companies' apps or sites. (Google states that for non-personalised ads the advertising identifier is still used for frequency capping and aggregate reporting. Reference)
- You can report an ad. Tap the ad card's "..." and choose to report it: a draft email opens, and you can read and edit it before sending. The body contains only information identifying the ad and the app version - nothing that identifies you.
- There is no analytics. We have not built in anything that tracks how you use the App.
11. Contact
nanana03info@gmail.com