Trivia App Football Genius Details How It Handles Player Data

Trivia App Football Genius Details How It Handles Player Data

A football-themed trivia application called Football Genius, known in Arabic as عبقري الكورة, has published a detailed account of how it collects, stores and deletes user information across its Android and iOS versions. The publisher, Osama Hasan, has laid out a privacy framework that distinguishes between data kept locally on a device and information processed through cloud services for online competition, purchases and advertising. The distinction matters because it shapes what a user actually exposes when moving from casual solo play to connected, identity-linked activity.

On-device storage covers fairly mundane preferences: age range, language, nickname, avatar choice, sound and haptic settings, and offline best scores. The game also caches a version of a player's cloud wallet so balances can be displayed without a live connection, though this cached figure cannot be used to authorize spending - a sensible safeguard against manipulation of locally stored values. Nearby multiplayer, which relies on local discovery and unencrypted game messages, is flagged as something that should only be used over a trusted private network, a reminder that casual local connections are not inherently secure. Anyone concerned about exposure on public networks might consider the same caution they would apply to other unencrypted traffic, whether that means avoiding shared Wi-Fi for sensitive sessions or routing a device through a provider with servers in dozens of countries when privacy matters more broadly. a provider with servers in dozens of countries

Identity, Matchmaking and the Cloud Layer

Online features require signing in through Google or, on iOS, through Apple, with Firebase Authentication handling the identity handoff. The game receives a provider user ID, name and email - potentially an Apple private relay address - but never a password. Once authenticated, Cloudflare Workers and Durable Objects take over the operational side: matchmaking, private rooms, daily challenges and the scoring logic itself. This means Cloudflare's infrastructure, not the device, determines outcomes, deadlines and rewards, and it also receives behavioral data such as answers, drawings and in-room actions. Wallets, reputation, ownership records and gift receipts persist on these servers, protected in transit by HTTPS and secure WebSockets.

Predictions, Reminders and Advertising Boundaries

A prediction feature lets players guess outcomes verified later against public-domain football results, feeding leaderboard points rather than currency or reputation - a structural choice that limits the incentive for manipulation. Reminder notifications, by contrast, are scheduled entirely on-device with no remote push service involved. Advertising is gated by age: only players who select an 18-and-older range enter Google AdMob's consent flow, and rewarded ads that grant coins rely on server-side verification rather than trusting the device's own callback, closing an obvious avenue for exploiting in-game currency.

Deletion and Retention in Practice

The retention schedule is unusually specific. Daily history caps at 366 days, gift and operation receipts last up to 90 days, and idle lobbies or ad reward tickets expire within hours. Account deletion, triggered from Settings, removes wallets, rooms, predictions and identifiable receipts before the authentication record itself is erased, though non-reversible hashes of deleted IDs remain as anti-replay protection. Uninstalling the app alone does not achieve this - deletion has to happen through the app or by contacting support directly.