PRIVACY POLICY
Short version: We collect only what we need to run the site. We do not sell your data. We do not track you across the internet. We do not store your IP address or your precise location, and we never ask your device where it is. We run no analytics: no page of this site or either app loads an analytics script, and we do not count page views. Google Sign In is provided by Google and their privacy policy also applies to that authentication step. The microphone is used only if you record a voicemail for the show, only after you tap Record, and what you send is heard by show staff and may be played on the show. Beyond that, the iOS and Android apps collect nothing extra except a push token, and only if you switch notifications on.
01 — WHO WE ARE
Doomer Friday is operated as a hobby project by an individual based in Colorado, United States. We are not a registered business entity at this time. For all privacy matters, contact: legal@doomerfriday.com
02 — AGE REQUIREMENT
This website and our iOS and Android apps are intended for users aged 18 and older. We do not knowingly collect personal information from anyone under 13. If we learn we have collected information from a child under 13, we will delete it promptly. Contact legal@doomerfriday.com if you believe this has occurred.
03 — INFORMATION WE COLLECT
Account Information (Google or Apple Sign In): When you sign in with Google, we receive your Google UID, display name, email address, and profile photo URL to identify your account. The apps also offer Sign in with Apple. If you choose Apple's Hide My Email option, we receive a relay address that forwards to you and never your real one, and that relay address is the only address we hold — we cannot see through it, and if you switch it off at Apple we lose the ability to reach you. We do not store your Google or Apple password.
Anonymous Account (apps only): When you first use one of the apps without signing in, it creates an anonymous account so you can browse, play the game and keep your settings without handing over a name or an email. It is a random account ID issued by Firebase and nothing else attached to it — no name, no email address, no device identifier, no advertising ID. If you later sign in with Google or Apple, that same ID is upgraded in place rather than swapped for a new one; that is how your scores, history and settings survive signing in, and it means we never hold two records for you. If you never sign in, the ID exists only on that installation of the app — delete the app and it is unreachable.
Callsign: Your chosen display name is stored linked to your Google UID.
Votes and Game Data: Your Doom Meter votes and Operation: Signal Lost game scores are stored linked to your Google UID to maintain history and leaderboard position.
Game Run Records (leaderboard integrity): When you start a game we record a run ticket against your account — a random ID, the time it was issued, and whether it has been used. When the run ends we also store how long it lasted alongside the score. This exists for one reason: without it, anyone could post any score to the leaderboard without playing, and we would have no way to tell. It is not analytics and we do not use it to study how you play — it holds no information about what happened during the game, no inputs, and nothing about your device. These records are not public: they are readable only by the server, never by other players, never by your own browser, and not by you either. They are not deleted with your account. That same closure is why: nothing running in the app or the website can read or write them, so the Delete Account button cannot reach them, and they stay until a staff member removes them. Email legal@doomerfriday.com and yours will be erased. Section 09 says how long they otherwise last.
Visitor Region (Anonymous): Once per browsing session we add 1 to a public counter for the nearest major city, so the homepage map can show roughly where the audience is. Here is exactly how that works. Our host (Netlify) already sees the IP address of every request — it has to, in order to send the page back. At the moment the request arrives, an edge function of ours reads the approximate position Netlify derives from it, rounds it to roughly 11 kilometres, and passes that back to your browser. Your browser picks the nearest city on the map and increments that city's tally. The only thing that is ever written down is that tally. Your IP address is never read by us, never returned, never logged and never stored. The rounded coordinates are never stored either — they exist only for the instant it takes to choose a city. Nothing is attached to the count: no identifier, no account link, no session ID, no timestamp. The finished number is simply "N visitors near Denver", which cannot be traced back to any person. We never call your browser's geolocation API, so you are never prompted to share your location — the site blocks that API outright with a Permissions-Policy header. If you block the lookup, we fall back to your browser's timezone, which is coarser still.
Site Analytics: none. No page of this website and no screen of either app loads an analytics script, and we do not count page views. There is no Google Analytics, no Meta Pixel, no product-analytics or attribution SDK, and no replacement for the one we used to run: most pages loaded Cloudflare Web Analytics until 16 September 2026, when the beacon was removed. Nothing took its place. The only counting described anywhere in this policy is the aggregate visitor-city tally above — a city name and a number — and the diagnostic logger below, which is switched off unless an admin turns it on to chase a specific bug. One caveat we used to state here has gone, and it is worth saying what it was rather than deleting it quietly: until 24 September 2026 a Cloudflare edge sat in front of our host and was able to inject its own Web Analytics beacon without any change to our pages. We never asked for it and never read a report from it, but we could not switch it off from our side, so we disclosed it. On that date the Cloudflare proxy was turned off and requests now reach our host directly — there is no edge in front of us and nothing can be injected into a page on the way to you. Cloudflare still answers DNS for this domain, which means it is told that somebody looked up doomerfriday.com, and nothing about what they then did. If the proxy is ever switched back on, this paragraph goes back to what it said before. If we ever adopt analytics of our own, this section will say so before it starts.
Diagnostic Logs (off by default): The site carries a technical logger that is switched off unless an admin turns it on to chase a specific bug, and is switched back off afterwards. While it is on, it records page load times, JavaScript errors (message, file, line, stack), the page name, your device class (Desktop / Mobile / Tablet) and your browser name. It also tags each entry with a random six-character string generated fresh on every page load — it lets us group one page view's entries together and is not linked to you, your account, or your next page view. These logs contain no account link, no callsign, no email address and no IP address, and they are readable only by site admins.
Voicemail Recordings (only if you send one): The site and apps have a voicemail line where you can record a message for the show. Nothing is recorded until you tap Record — that tap is also when your device asks for microphone permission, and the microphone is open only while the tape rolls, for at most 75 seconds. You hear your take back and choose to send it or discard it; a discarded take never leaves your device. If you send it, we store the audio itself (up to 4 MB), its length, size and format, any note you typed with it, your account ID and the time, plus its review state. Be clear about what sending means: you are submitting a recording of your voice to be considered for broadcast. It is readable only by you and by show staff, who may download a copy to produce the show and may re-encode it through the show's radio effect — but if the hosts pick it, it is played on the show, which is public. Recordings are held in an area only staff can delete from, and deleting your account does not delete recordings you have already sent in — section 09 says why and what to do about it. You are told what happened either way: if you have that notification switched on, a decision on your message is one of the things we notify you about.
Feedback Reports (only if you send one): If you use the feedback widget, we store what you typed — the report type, urgency, area, title and description — together with technical context that helps us reproduce the problem: the page you were on, your device, operating system, browser, window size, pixel ratio and whether the device is touch-enabled. If you attach a screenshot, we store the image you attached — and only that image, chosen by you from your device's own picker; nothing else in your library is read, listed or uploaded. If you provide an email address so we can reply, we store it with the report. If you are signed in, your callsign is attached so we know who to thank. Nothing is sent unless you press submit.
App Beta Sign-Up (only if you ask to join): If you put your name down to test the Doomer Friday app, we store the first name, email address, platform (iOS or Android), device and — if you give it — OS version that you enter. We need the email to send you an invite and the device details to know what to build and test against. If you pick Android, the address we ask for is the Google account signed in on the phone you will test on, and the form says so before you type it: Android testing runs as a Google Play closed test, and Google only lets a named Google account opt in — any other address cannot be admitted, however good it is for email. We ask for one address, not two, so that is the address we hold and the address we write to. Nothing is sent until you press the sign-up button, and we never take any of it from your browser automatically — every field is one you typed. This list is not public: unlike the visitor counters described above, it can only be read by site administrators. We do not share it, sell it, or use it to email you about anything other than the beta. One sign-up per email address; a second attempt with the same address is refused. When we invite you, your name and email address are passed to the relevant app store so the invitation can reach you: for iOS testers to Apple (App Store Connect / TestFlight), which is what sends you the TestFlight invitation and adds you to the tester list for that build; for Android testers to Google (Google Play Console), where your Google account address is added to the closed test’s tester list — that list is what lets you in — and the invitation itself is an email from us, via Resend, containing the track’s opt-in link. Android testing used to run through Firebase App Distribution and no longer does; if you signed up before that change, we will ask you for your Google account address before adding you. Both Apple's and Google's own privacy policies apply to the tester records they hold. We pass nothing else — not your device details, not anything from your account. To be taken off the list, or to correct something, email legal@doomerfriday.com and we will delete your entry; tell us if you also want removing from the TestFlight or Play tester list and we will do that too.
Push Notification Tokens (only if you switch notifications on): If you allow notifications in one of the apps, Firebase Cloud Messaging issues that installation a push token — a long random string that identifies one app on one device, so a message can be routed to it. We store it against your account, because some of the notifications we send are personal ("your vote is available again", "the hosts decided on your voicemail") and have to reach you rather than everybody. We treat that token as personal data. It is not public: it is stored under your own account ID, readable only by you and by the server function that sends the message, and it is used for nothing but the five notification types listed below. It is not your device's serial number or advertising ID, it does not follow you into other apps, and it tells us nothing about the device except which platform issued it — iOS or Android. Firebase reissues it from time to time and we replace our copy when that happens. Nothing is stored until you accept your operating system's permission prompt. We delete the token when you sign out and when you delete your account. If you revoke the permission at the operating-system level, or delete the app, the token stops working, and we delete it the next time we try to send to it and Firebase tells us it is dead.
That We Asked You About Notifications: The first time you sign in we show a sheet offering the notifications below, and we store the date you answered it so we do not ask again on your next device. That is one timestamp; it does not record what you chose (the switches below do that) and it exists only to stop us nagging.
Notification Preferences: There are five notification switches, each its own choice: voting opening on a new show; your own vote cooldown expiring; a decision on a voicemail you sent (sent only to you, and it never quotes your recording); your role on the site changing (sent only to you); and a message from the hosts to everyone. They are stored in your account profile so they hold on every device you sign in on, and a copy is kept alongside each of your push tokens so the sender knows in one read whether to send to that device. They are five on/off values and nothing else; we do not record which notifications were delivered, opened or ignored. Switching one off stops us sending that kind of message, but does not by itself delete the token — signing out or deleting your account does that, and so does revoking the permission, once the next send tells us the token is dead. They are separate from your operating system's notification permission, and both have to allow it for anything to arrive.
Offline Scores (held on your device until they sync): The game is playable with no connection. A score you set offline is written to storage on your own device — a small queue under df_score_bank, holding the score, when it was set and your account ID — and stays there until the app next has a connection, at which point it is posted like any other score and removed from the queue. While it is waiting it has not been sent anywhere and we cannot see it. If you never reconnect, or delete the app first, it goes with the app and never reaches us. Nothing else is queued this way — no votes, no analytics, no diagnostic logs.
Last-Used Date (one number, no times): Your account records the date it was last used — a date only, truncated to UTC midnight before it is sent, so the time of day, the page you were on, the session and the order you did things in are never transmitted and cannot be recovered from what is stored. It exists for one administrative question: whether an account is still in use, which is what we need to know before adding someone as a host or handing out an admin seat. It is written by your own browser, at most once per day, and it is readable only by you and by site administrators — never publicly. It is not analytics, it is not a behavioural log, and it is deleted with your account.
Blocked Accounts (only if you block someone): If you block another agent on THE INDEX, we store their account ID and the date you blocked them on your own account record, so the block follows you to every device you sign in on. It is readable only by you and by site administrators — the person you blocked is never told, and cannot see the list. Nothing else is stored: not why, not what was said. Unblocking deletes the entry outright, and the whole list goes with your account if you delete it.
Reports You File (only if you report a comment): If you report a comment, we store your account ID, the comment and post it was about, the reason you picked and the time, plus a running count of how many reports you have filed recently so one account cannot bury the queue. This lives in a moderation area that only site staff can read — the person you reported is never shown who reported them, and it is not public even when THE INDEX is. A snapshot of the reported comment's text is kept with the report so the record survives the author editing or deleting it.
That You Agreed to the Content Rules: Before your first comment we store the date you agreed and a version number for the rules you agreed to. That is two values; it records that you agreed, not anything about you.
Host Profile Media and Host Broadcasts (hosts and staff only): If you are one of the show's hosts, the profile card tools let you upload a profile photo and a show logo. Both are converted to WebP on your own device before upload, stored under your own account's folder, and published on the public hosts page — uploading one is publishing it. A host can also record a voice message to the whole community from the admin panel; the confirmation says so before it goes, because that recording becomes public and permanent: it is playable by anyone at a public address, and hiding the post later does not erase the audio. The answering-machine greeting an admin records for the voicemail line is likewise played to everyone who calls. These are staff tools — nothing in this paragraph applies to a regular account, which cannot upload images or post broadcasts.
Merch Waitlist Email: If you submit your email for merch notifications, we store it only for that purpose and do not share it with third parties.
Preferences: Audio, control, and UI settings are stored in browser local storage and optionally in your account profile.
04 — INFORMATION WE DO NOT COLLECT
- Precise GPS or device geolocation data (we never ask your browser for it)
- Your IP address — we never log or store it ourselves. Our host and CDN necessarily see it in order to deliver the page; see section 06
- Payment information of any kind
- Your device's advertising identifier — the apps never request IDFA or the Android advertising ID, never show Apple's App Tracking Transparency prompt, and contain no advertising or attribution SDK
- Your contacts or your files — the apps request neither and contain no code that reaches them
- Your microphone, except while you are recording. The apps and the site declare microphone access for exactly one feature: recording a voicemail for the show (and, for hosts, the staff recording tools). The permission prompt appears only when you tap Record, the microphone is open only while the tape visibly rolls, and nothing is kept unless you press send — see “Voicemail Recordings” in section 03. There is no always-on listening, no wake word, and no audio processing outside the recorder you started
- Your photo library, except at the one moment you open it yourself. The apps never scan it and never read it in the background. If you choose to attach a screenshot to a feedback report, the iOS app shows your device's own picker and — because that picker offers “Take Photo” as well — iOS asks for camera and photo permission at that moment. That is the only reason those two permissions are declared, and the only time either is used. Decline and the report still sends, without an image. The Android app declares neither camera nor photo permission — its picker needs none; its manifest permissions are internet access and the microphone pair used by the voicemail recorder (record audio, and adjust audio routing while recording), with the microphone marked as hardware the app does not require
- Notifications, unless you switch them on. That is the only permission the apps ask for on their own initiative
- Advertising tracking pixels or third-party ad network data
- Cross-site tracking data
- Google Analytics, Meta Pixel, or analytics of any kind. We ran one cookieless page-view tool (Cloudflare Web Analytics) until 16 September 2026 and removed it without replacing it — section 03 says so in full
- Behavioural profiles, interest categories, or any data used to target you
We do not sell, rent, or trade your personal information.
05 — HOW WE USE YOUR INFORMATION
- Authenticating your account and maintaining your session
- Displaying your callsign and scores on leaderboards
- Recording your votes in Doom Meter rounds
- Saving your game preferences across devices
- Notifying you about merch availability if you opted in
- Displaying the anonymized visitor city map on our homepage
- Reviewing callsigns flagged by our automated content filter
- Counting page views so we know which parts of the site are worth keeping
- Diagnosing errors and slow pages when diagnostic logging is switched on
- Reading, reproducing and fixing what you report through the feedback widget
- Inviting you to test the app, and tracking who has been invited, if you signed up for the beta
- Holding voicemail recordings you send in, reviewing them, and playing the ones the hosts pick on the show
- Telling you what happened to a voicemail you sent, if you switched that notification on
- Sending only the notifications you switched on — voting opening, your vote becoming available again, a decision on your voicemail, a change to your role, or a message from the hosts — and nothing else
- Remembering which of those you want, on every device you sign in on
- Letting you play and bank a score with no connection, then filing that score when a connection returns
- Keeping your scores, history and settings attached to you when an anonymous app account becomes a signed-in one
06 — DATA STORAGE AND PROCESSORS
Our site is hosted on Netlify (Netlify, Inc., San Francisco, CA). Netlify receives the IP address of every request as a normal part of serving the site, and is the source of the approximate region used by the visitor map described above; we do not receive or retain that IP address. Our database, authentication and file storage — including voicemail recordings and host images — are provided by Firebase (Google LLC, Mountain View, CA). Data stored in Firebase may be processed on Google's servers in the United States or other countries. By using this site you acknowledge that your data may be processed in the United States.
There is no analytics processor. Cloudflare (Cloudflare, Inc., San Francisco, CA) provided cookieless page-view analytics until 16 September 2026; the beacon was removed and nothing replaced it, so we send no record of the pages you view to anyone, and we receive no such record from anyone. The Cloudflare edge that section 03 used to carry a caveat about was taken out of the request path on 24 September 2026; Cloudflare still answers DNS for the domain and no longer sees the requests themselves. Netlify necessarily receives and logs each request in order to serve it, as the paragraph above says, and we do not turn those logs into analytics about you.
If you join the app beta, Apple Inc. (App Store Connect, for iOS testers) and Google LLC (Google Play Console, for Android testers) receive the name and email address you gave us, so they can hold you on the tester list for that build and deliver the invitation. For Android that address is your Google account address, because a Play closed test admits named Google accounts and nothing else. Android invitation emails are sent through Resend, the same provider used for the site's other mail. None of them receive anything else about you.
Push notifications are delivered by Firebase Cloud Messaging (Google LLC), which holds the push token and hands our message to the platform. On iOS the final delivery is made by Apple Push Notification service (Apple Inc., Cupertino, CA); on Android it is Google throughout. Apple or Google therefore necessarily sees that a message went to your device, and sees its text, as any notification service must — so we put nothing in a notification that we would not put on the public site. We send only the five notification types described in section 03, each behind its own switch — and the personal ones never quote your recording or your data, they only say a decision or a change happened.
The iOS and Android apps are distributed through the Apple App Store and Google Play, which are run by Apple and Google under their own privacy policies and account terms. They know you downloaded the app, they handle anything to do with your store account, and they give us aggregate install and crash counts that do not identify anyone. The apps are the same web pages this site is built from, wrapped for each platform: neither build bundles a crash reporter, an advertising SDK or a mobile analytics SDK.
Google Fonts are loaded from Google's CDN, which may allow Google to log your IP address when fonts are requested. This is standard practice for CDN font delivery.
07 — COOKIES AND LOCAL STORAGE
This site uses browser local storage and Firebase session cookies to maintain your login and save preferences. These are strictly necessary for site operation and do not require consent under applicable law. We do not use advertising cookies, analytics cookies, or third-party tracking cookies — since 16 September 2026 we run no page-view analytics at all, cookieless or otherwise, so there is nothing of that kind to set a cookie. A disclosure banner is shown on your first visit.
The visitor map sets no cookie. It stores a single flag in your browser's session storage (df_visit_logged_v1) so that one browsing session is counted once instead of on every page you open. That flag never leaves your browser and is discarded when you close the tab.
The website and the apps both keep an offline copy of pages, images and audio in your browser's cache storage, so the game still works when the connection does not. That copy is our site content, not information about you, it never leaves your device, and clearing your browser's site data — or deleting the app — removes it. The apps use that same device storage for the offline score queue described in section 03.
08 — YOUR RIGHTS
Regardless of where you live, you may:
- Access the data we hold about you by contacting us
- Delete your account and associated data via the Delete Account option on your Settings page — this removes your profile and the vote history shown on it, your callsign, your leaderboard row, your push tokens, your notification preferences and your host page if you have one. It does not reach everything. What it leaves: voicemail recordings you already sent in, your game scores on the public leaderboard, each show's vote tally, your game run records, and your comments and votes on THE INDEX. The next right covers all of them, and the Settings page lists them before you delete rather than after
- Have voicemail recordings erased — and with them anything else account deletion cannot reach — by emailing legal@doomerfriday.com. Recordings live where only staff can delete them, so account deletion cannot reach them — the Settings page says the same thing before you delete. Ask, and a staff member erases the audio and its record. The same request covers your leaderboard score rows, your entries in each show's vote tally, your game run records and your comments and votes on THE INDEX, all of which deletion leaves behind for the reasons section 09 gives
- Update your callsign at any time (subject to the 30-day cooldown)
- Unsubscribe from the merch waitlist by emailing legal@doomerfriday.com
- Withdraw a feedback report you sent, including any screenshot attached to it, by emailing legal@doomerfriday.com
- Leave the app beta list at any time by emailing legal@doomerfriday.com — your entry is deleted outright, not just marked inactive
- Turn off any of the five notifications in the app's Settings at any time, which stops us sending it; sign out to delete that device's push token outright, and revoke the notification permission in your operating system to stop delivery whatever we do
- Stay anonymous in the apps and never sign in; delete the app to walk away from that account, since nothing in it is linked to your name or email
California Residents (CCPA): You have the right to know what personal information we collect, the right to delete it, and the right not to be discriminated against for exercising these rights. We do not sell personal information.
EU/EEA Residents (GDPR): Our lawful basis for processing is contract performance (providing the service you signed up for) and legitimate interests (operating a fan community). For push notifications the lawful basis is consent — given when you accept the permission prompt, withdrawn the moment you switch them off, with no effect on anything else. You may request data portability, restriction, or erasure by contacting us at legal@doomerfriday.com.
09 — DATA RETENTION
Account data is retained while your account is active. Deleted accounts are purged within 30 days. Game scores already displayed on the public leaderboard may remain as historical record, and each row carries your account ID alongside your callsign, the score, the time it was set and how long the run lasted. The account ID is not decoration: it is what ties a score to a real run and stops anyone posting one without playing, and it is on a part of the database anyone can read. Deleting your account does not remove those rows — email legal@doomerfriday.com to have yours taken down. Each show also keeps a vote tally recording your callsign and which way you voted, on the same publicly readable footing and equally untouched by deletion; the same email removes it. The vote history drawn on your own profile page is a different record, stored with your account, and that one does go when the account does. Comments you posted on THE INDEX, and the post and comment votes you cast there, are stored against your account ID and are likewise not removed by deleting the account; the same email takes them down. Merch waitlist emails are retained until notification is sent or you unsubscribe. Anonymized visitor city counts are retained indefinitely as aggregate statistics — a city name and a number, with no personal data attached and nothing to identify or delete. Diagnostic logs are kept in daily buckets, are only written while logging is switched on, and are cleared by hand once the bug they were gathered for is fixed. Feedback reports and any screenshot attached to them are kept until the report is resolved and for a reasonable period afterwards as a record of what was fixed; ask us at the address below and we will delete yours. We retain no analytics data, because since 16 September 2026 we collect none. App beta sign-ups are kept for as long as the beta programme runs, so we know who has already been invited and who has tested; when the programme ends the list is deleted, and you can ask to be removed before then at any time. Game run tickets are kept indefinitely. An unused one stops working after 14 days — the window that lets a game played offline still reach the leaderboard when you reconnect — but expiring is not deleting: the server refuses the expired ticket and the row stays. A used one keeps the time it was issued, the time it was spent and the score it produced. Deleting your account does not remove them, because they sit on a part of the database no client can read or write at all, only the server; email legal@doomerfriday.com and yours will be erased. Voicemail recordings are kept until a staff member deletes them, and are not removed by account deletion — they live in a storage area that only staff can delete from, precisely so that a recording cannot be silently altered or removed once it is in the review queue; email legal@doomerfriday.com to have yours erased, and a staff member will do it. Where a reviewer has re-encoded a recording through the show's radio effect, the original is erased once a copy is safely on file, or kept alongside the processed copy until the recording is deleted — either way an erase request covers every copy we hold. A host's voice broadcast is public and permanent once posted: hiding the post stops it being listed, but the audio stays at its public address until an administrator erases it. Host photos and logos stay published until the host replaces or removes them. Push tokens are kept while that installation is registered: signing out or deleting your account removes the token at once, and a token Firebase reports as dead is deleted the next time we try to send to it. Notification preferences live with your account and are purged with it. Queued offline scores are not retained by us at all while they are queued — they sit on your device until they sync, and are discarded with the app if you delete it first. An anonymous app account that is never signed in leaves behind only its random ID and whatever scores or settings were made under it; once the app is deleted that record is orphaned and we have no way to connect it to any person.
10 — DMCA / COPYRIGHT
To submit a DMCA takedown notice, contact our designated agent:
- Designated Agent: Justin Costa, Doomer Friday
- Email: legal@doomerfriday.com
- Subject: DMCA Notice
The complete designation, including the agent's mailing address and our U.S. Copyright Office registration number, is published in section 07 of our Terms of Service.
Your notice must include: identification of the copyrighted work and infringing material, your contact information, a good-faith belief statement, and a statement under penalty of perjury that you are authorized to act.
11 — POLICY CHANGES
Material changes to this policy will be announced via the site's version update notification system on your next visit. The effective date above always reflects the latest revision.
CONTACT // LEGAL CHANNEL
DOOMER FRIDAY
Colorado, United States
legal@doomerfriday.com
For data requests, DMCA notices and privacy inquiries. You do not need to write to us to delete your account — the control is in the app and on the website, under Settings, and it works without asking anyone.