Privacy policy

Last updated: September 16, 2026

Core card storage and normal gameplay stay on your device. Every Scan begins with local processing. A sanitized card crop leaves your device for Cloud validation only with your separate standing Cloud permission and verified subscription or rewarded-ad funding, when you separately select an attachment for a support report, or when you affirmatively opt in to optional Help improve scanning sharing after that program is fully enabled. Ads and subscriptions use the third-party services described below.

Local scanning and optional Cloud assistance

Every Scan starts locally. Before the first eligible Cloud check, the privacy prompt offers “No thanks” and “Allow Cloud Help”. Allow Cloud Help permits validation of all 24 numbers for this scan and future scans, including numbers the local scanner considers confident. It does not select a scanner mode. No thanks keeps Cloud Help off and suppresses this disclosure version until you change the permission in Settings. A changed disclosure requires a fresh decision. Permission is not requested merely for opening the scanner.

After permission, server-verified BingoFlow Pro bypasses the ad. Free users may choose a rewarded ad for each Cloud check. Cloud assistance requires a fresh server subscription check or a signed, single-scan AdMob reward verification. Advertising consent, a client ad-completion callback, camera permission, and cached Pro status never grant Cloud permission or funded access by themselves. If permission is declined, the device is offline, an ad is unavailable, proof is pending, or the service fails, BingoFlow preserves the local result with uncertain or incomplete cells marked for review and correction.

Cloud assistance sends a bounded, metadata-stripped crop of the frozen scan frame through a BingoFlow Cloudflare Worker to the OpenAI API. It includes the card’s five number rows and printed BINGO header, and may include background visible inside the scan frame. Keep only one card in the frame and avoid personal information. Cloud reads the captured card independently of local perspective rectification. The original full-scene camera image outside the scan frame is not sent. At most one server-authorized orientation retry is allowed.

BingoFlow keeps an anonymous installation credential in protected native storage. Its Cloudflare service assigns and binds a RevenueCat customer identifier and verifies app integrity, subscription state, signed rewarded-ad transactions, and one-scan grants. An opaque, single-scan nonce connects AdMob reward verification to the grant. Funding, request hashes, and security records contain no card values; the credential, RevenueCat identity, reward transaction, and integrity proof are never sent to OpenAI or included in model contributions. Scan-operation records are scheduled for deletion 30 days after grant expiry. Verified reward credits and replay records last 365 days from verification; unused credit can fund a later scan. The anonymous billing identity is removed after 365 days without funding activity once no grants or credits remain. An existing purchaser may need to use Restore Purchases to connect store ownership to this installation; the app does not silently transfer an existing purchase identity. A random opaque installation token is also sent only to BingoFlow/Cloudflare, never OpenAI; it is not a hardware, advertising, or cross-app tracking identifier.

BingoFlow does not persist Cloud-assistance images or result card values. OpenAI states that API data is not used to train its models by default. Default abuse-monitoring logs may retain content for up to 30 days, or longer when required by law or needed to prevent harm. Image inputs flagged as possible child sexual abuse material may be retained for manual review even when stricter retention controls are enabled. See OpenAI's API data controls.

Cloud permission authorizes only this optional scanner validation. It never enables model contribution or training.

Help improve scanning

Reviewed-scan sharing is optional, has a separate versioned disclosure, and is off by default. When the private service and signed app configuration make it fully available, BingoFlow shows the one-time “Help improve scanning?” question after camera access succeeds and before the scanner opens. Contribution starts only if you affirmatively choose “Share reviewed scans.” The equal “No thanks” choice never affects scanning, local review, Cloud assistance, or manual entry, and BingoFlow does not ask again for the current disclosure after you decline. You can later opt in or withdraw in Settings.

Cloud permission alone never enables contribution or training. After separate contribution consent, an eligible reviewed and saved scan may enter private quarantine whether it was completed locally or used Cloud assistance. For a Cloud-assisted outcome, every OpenAI fallback prediction is stripped before contribution; only available local predictions and the reviewed final labels remain. That sample can never use deterministic or single-review admission: two independent adjudications must agree, otherwise it remains quarantined. Availability is fail-closed: without complete signed configuration for your platform with capture enabled, no contribution prompt appears and no model-contribution sample is collected or shared. A complete cleanup-only configuration also keeps consent and new capture disabled while preserving status/deletion cleanup for existing work. A matching provisioned private service and version-pinned server policy are operator prerequisites before signed configuration enables capture; Android sharing additionally requires a hardware-backed key and successful Google Play app, device, and licensing checks; unavailable checks cannot authorize an upload.

The fail-closed contribution path is limited to exactly 24 metadata-free 112x112 grayscale number-cell PNG crops; available cell-recognition predictions and confidence; recognizer, model, runtime, preprocessing, and pipeline versions; on-device capture and engine status; rectified grid geometry and image-quality measurements; the disclosure version; reviewed labels and correction diff; and bounded integrity and retry state. It excludes the original camera scene, EXIF/location data, device private keys and raw installation key IDs in training data, and account/advertising identifiers. During upload, the private service receives the Cloudflare-provided IP address, keyed-hashes it for abuse prevention, security, deletion, status, and audit, and does not retain the raw IP address.

Automated OpenAI review has two independently gated lanes. Ordinary disagreement or verification may send 1–24 selected 112x112 grayscale cell crops; each crop's row and column and local and corrected candidate values; the review kind and prompt version; and an opaque review ID. The separate verified-unreadable lane sends each reviewer exactly one candidate-free crop, the prompt version, and an opaque review ID. It sends no coordinates or number candidates and asks only whether that crop is visually readable. Neither lane sends the full card, unselected crops, raw identifiers, or pseudonymous hashes. OpenAI states that API data is not used to train its models by default. Default abuse-monitoring logs may retain this API data for up to 30 days, or longer when required by law or needed to prevent harm. Flagged image inputs may be retained for manual child-safety review even under stricter retention controls.

The app includes protected iOS and Android upload, recovery, status, deletion, and automatic retry controls. The app does not use an online service-health check to enable contribution. If the service is unavailable, upload acceptance fails closed while queued samples remain protected locally within the retention limits. Known-unsent local samples and POST replay expire after 7 days. An exact request with an uncertain network outcome may remain in protected local storage for no more than 38 days total, even without cleanup networking. Accepted contribution crop/label data is retained for no more than 30 days and online deletion/status access for no more than 365 additional days. The service retains pseudonymous security, provenance, audit, replay, quota, abuse-control, and withdrawal-fence hashes and records indefinitely, including keyed installation, consent-receipt, Cloudflare-provided-IP-address, grant-token, idempotency-key, and request hashes plus bounded attributes, timestamps, and byte counts. Those records contain no crops, labels, card values, or raw identifiers and are not training data. Device private keys remain on device. On iOS, the shared broker may retain the public verification key and bounded app/environment, counter, and timestamp state for no more than 1,095 days after inactivity. Android public verification keys and limited app, counter, and security records support ownership, replay prevention, and audit; records linked to retained evidence may remain indefinitely. Google Play security checks do not receive the contribution crops. Deletion cannot retroactively remove a sample's influence from a model already trained and released.

Beta signup data

iOS beta signup opens the TestFlight public link. Android beta signup opens the Google Groups tester link and Google Play testing link. BingoFlow does not collect an email address for either beta signup path on the website.

Support report data

Ads and subscriptions

BingoFlow uses Google Mobile Ads / AdMob to show ads and Google User Messaging Platform to request ad consent choices where required. Google Mobile Ads may collect or share ad-related data such as IP address, device or advertising identifiers, product interactions, ad interaction data, diagnostics, and performance data for advertising, analytics, and fraud prevention. Depending on consent and regional requirements, ads may be personalized, non-personalized, or limited/contextual.

Impression-level ad revenue is enabled so the app can receive per-impression ad revenue metadata from AdMob. BingoFlow forwards ad revenue metadata to RevenueCat for revenue reporting, including ad format, ad unit ID, impression or response ID, revenue amount, currency, and precision. This does not include bingo card content, camera frames, support attachments, or manually entered card data.

BingoFlow Pro subscriptions are processed through the App Store or Google Play and managed in the app with RevenueCat. RevenueCat receives subscription entitlement and purchase status needed to unlock Pro features. BingoFlow does not receive full payment card details.

BingoFlow does not currently enable AdMob's optional full IP address sharing control. If that setting changes, this policy and store privacy disclosures should be reviewed before release.

Storage and retention

User-selected support attachments are stored in Cloudflare R2 under non-guessable object keys and linked in private support issues using tokenized Worker URLs. Their default retention target is 30 days unless manually retained for investigation. The support-report flow never uploads camera frames, card content, photos, or videos unless the user selects and submits them. Cloud-assistance data handling is separate and described above; BingoFlow does not persist Cloud-assistance images or result card values.

Processors