AppStateFans.com

Legal

Privacy Policy.

Last updated September 14, 2026

AppStateFans.com is run by dotSimple LLC. This page describes what we collect, why we collect it, who processes it on our behalf, and how to get it removed. We have tried to describe what the site actually does rather than everything a site could conceivably do.

What you give us

  • Account: email address, username, and whatever you choose to add — display name, bio, avatar, fan affiliation and fan types.
  • Social sign-in: if you sign in with Google, Facebook or X, we receive your email address and basic profile from that provider. We never receive your password. The provider name is shown on your public profile when it is used for verification.
  • What you post: posts, comments, replies, reactions, upvotes, direct messages, game-day chat, and the photos you upload.
  • Verification evidence: if you apply for Yosef Club verification, the screenshot you upload. It is stored privately, viewable only by administrators reviewing your request, and deleted as soon as that request is decided or you withdraw it.
  • Store orders: your shipping address, collected by Stripe at checkout and passed to our fulfilment partner. We never see or store your card number.
  • Group donations: if you give to a private group’s donation box, the amount, the message you leave, and whether you asked to be anonymous. By card, Stripe collects your card and the email for your receipt. A Venmo or Cash App payment never passes through us and we record nothing about it: the page opens the app with the organiser’s account and a memo, and that is all. If you give without an account, we keep the name you type and a one-way hash of your email.
  • Buying from a group’s store without an account: when a private group opens its store to anyone on its own web address, you can buy with a name and an email. The name is for whoever hands the item over; Stripe collects your card and emails the receipt to that address, and we keep a one-way hash of the email, not the address. There is no account to log into, so the receipt is your record.
  • Tailgate sign-ups: if you put your name down for something on a private group’s tailgate list — from the sign-up link, without an account — we keep the name you type, how many you are bringing, any note you add, and a one-way hash of your email. The name and the note are shown to the group; the address is not, to them or to anyone. We email you once, with the link back to your own sign-up, and never again.

What we record as you use the site

  • Activity: APP Points and Mountain Money earned, titles, and a log of the actions that earned them.
  • Presence: whether you are currently online, and a “last seen” timestamp.
  • Game-day check-ins: the event and the type of check-in (stadium, tailgate, watch party, road trip). Checking in at the stadium or a tailgate asks your browser for your location once, to confirm you are near the venue. It is compared with the venue’s location and discarded: we store only that the check-in was confirmed, never where you were.
  • Travel map pins: if you add one, we store your coordinates rounded to two decimal places — roughly a one-kilometre square, not your address. Pins expire automatically, and the API never returns the user ID attached to a pin, so a pin cannot be traced back to you through the site.
  • Read state and preferences: which threads you have read, your view-style choices, and your notification settings.

Guests who comment

You can comment without an account using a name and email. We store the name as you typed it, and we store your email address and IP address as one-way SHA-256 hashes — used only for rate limiting, abuse prevention, and remembering whether an address has been confirmed and how many of its comments moderators have approved. We cannot read them back.

The one email we send: the first time you comment from an address, we send it a single link to confirm it is yours. The address is used to send that message and is not stored — you get no other email from us, no account is created, and there is no newsletter and no notifications. We also check that the address’s domain can receive mail and is not a throwaway-mail service; that is a DNS lookup of the domain, not of you.

Every guest comment is checked for spam before it appears — by Cloudflare Turnstile, which checks that a browser rather than a script is sending the form; by automated rules; and by a model from Anthropic that reads the comment and what it replies to. Comments from an address that has not been confirmed always wait for a moderator, as do a confirmed address’s comments until a few have been approved. A moderator can remove a guest comment or pause guest comments from an address.

Who processes data for us

These are service providers, not audiences. We do not sell your data to anyone.

  • Supabase — database and authentication.
  • Cloudflare — image, file and video storage and delivery, and the Turnstile bot check on guest comment forms.
  • Resend — sends the guest comment confirmation email and a guest’s pledge link; it receives the address that message goes to.
  • Ably — real-time chat, presence and live game updates.
  • Stripe — payment processing for the Fan Store and card donations to private groups. Stripe handles card data directly.
  • Printful — printing and shipping store orders; receives your shipping address.
  • Printify — printing and shipping store orders; receives your shipping address and, because their order form requires one, your email address. We switch their shipping emails off; the site tells you when an order ships.
  • Anthropic (Claude) — powers the mounAIneer assistant, the rewritten summaries in Around the Internet, and automated screening of guest comments and reports. Message content sent to the assistant is processed by Anthropic to generate a reply.
  • Giphy — GIF search, proxied through our server so Giphy does not see your browser.
  • Google Cloud Vision — checks each photo you upload for explicit or violent content before it is published. The photo is sent to Google for that check.
  • Google Tag Manager and analytics — aggregate usage measurement, where enabled.
  • Sentry — error reports when something breaks, so we can fix it.

What other people can see

Your username, display name, avatar, bio, fan affiliation, verification badges, APP Points rank and everything you post publicly are visible to anyone — including people who are not logged in, and search engines. Direct messages are visible to the people in the conversation and to administrators investigating a report. Reports you file are anonymous to the person reported.

Private groups are the exception. What you post inside one is visible to that group’s members, and to site moderators acting on a report. It is kept out of the public feeds, the boards, search engines and everyone else’s view. A hidden group is not listed anywhere on the site at all. If a group has its own web address, that address serves the same group — it does not make anything in it public. Leaving a group, or being removed from it, stops your access; what you already posted stays for the people still in it, so their replies still make sense. A group with house rules, such as Politics, keeps the rules as you agreed to them with your request to join, so its moderators can see what you signed up to.

Ranks and coupons inside a private group. A group’s admins can give members a rank of the group’s own, shown only inside that group and never on your profile, and can give you a code for the group’s store items. The group’s admins see who holds a code, not who used it or what anyone bought; the site’s own administrators see orders, as they do for the Fan Store. If your rank’s posts wait for approval, the group’s moderators read them before anyone else does.

A tailgate list can be shared by link. Whoever opened the list can hand round a link so people outside the group can bring something without making an account. Anyone holding it sees that list — what is needed, and the first names of whoever is bringing what — and nothing else of the group. A name and an email are asked for once: the name goes on the list, the email only sends you the link back to your own sign-up, and we keep only a hash of it. The address is the game’s name, so anyone who knows the group and the game can open it while the link is open; whoever opened the list can close it at any time.

A group can be served on its own web address. When it is, the page shows the group and a small line saying AppStateFans.com provides it. It is still this site, these terms and this policy, and the account you sign in with there is your AppStateFans.com account.

A donation box is shared by link. Anyone holding the link sees the box: its total, the names of people who gave (or “Anonymous”, if you asked), their messages, and the Venmo or Cash App account the organiser chose to share. It shows nothing else from the group. The group’s admins and moderators always see who gave, even when the box shows you as anonymous.

Cookies and similar technology

We use cookies to keep you signed in. If you do not tick “remember me”, your session is kept only for the current browser session. We also use your browser’s local storage for preferences such as theme and view style — that never leaves your device. Analytics, where enabled, sets its own cookies to measure aggregate usage.

How long we keep things

Account data is kept while your account exists. Public posts remain unless you delete them or we remove them. Travel-map pins expire on a timer. Verification screenshots are deleted the moment your request is decided or withdrawn — the decision and the reviewer's note stay on your record, the image does not. A photo that does not pass review is deleted. Moderation records are kept longer, because they are what makes repeat behaviour visible.

Your choices

  • Edit or remove most profile information yourself in settings.
  • Turn off individual notification types in notification settings.
  • Edit or delete your own comments at any time; a deleted comment stays in its thread as a placeholder so the replies under it still make sense. Posts and threads stay up — you can lock the comments on yours, and a moderator can remove one.
  • Leave a private group whenever you like, from its page. If you own one, hand it to another admin first.
  • Ask us to delete your account and personal data, or to send you a copy of it, via the contact page. Public posts may remain where removing them would break other people’s conversations, but they will be detached from your identity.

Depending on where you live you may have additional rights — to access, correct, export, restrict or object to processing. Ask and we will honour them.

Children

The site is not intended for children under 13 and we do not knowingly collect their data. If you believe a child under 13 has an account here, contact us and we will remove it.

Changes

We will update the date above when this policy changes, and say what changed if the change is material.

Privacy Policy | AppStateFans.com