FCtools.gg / LEGAL
Privacybeleid
Last updated: 2026-09-15
This policy explains what data the FCtools.gg website and Chrome extension collect, how it is processed and stored, and the parties with which it is shared.
FCtools.gg account and authentication data
Email address
FCtools.gg collects an email address when you register, sign in, reset a password, manage an account, or use Google or Discord sign-in. It is sent only to FCtools.gg over HTTPS/TLS and stored as the account identifier. Our transactional email provider receives the address and verification or security message only when an account email must be delivered.
Wachtwoord
A password entered in the extension is sent only to https://fctools.gg/api/auth/login over HTTPS/TLS. The extension never stores it in Chrome storage, local files, URLs, analytics, or logs. The FCtools.gg server stores only a one-way BCrypt hash. Passwords are never sold or shared with EA, Google, Discord, advertising, analytics, or football-data providers.
FCtools.gg authentication token
After a successful sign-in, the extension stores the token in chrome.storage.session until Chrome closes, or in chrome.storage.local when Keep me signed in is selected. It is sent only in Authorization headers to fixed HTTPS endpoints on fctools.gg. It is never placed in a URL or sent to EA, Google, Discord, FUTBIN, FUT.GG, FUTNEXT, FUT.to, advertisers, or analytics providers. Signing out removes both local copies and requests server-side session revocation.
Google and Discord sign-in
If you choose a third-party sign-in button, that provider authenticates you under its own privacy policy. FCtools.gg receives the provider account ID, verified email status, email address, display name, and avatar URL needed to create or link the FCtools.gg account. FCtools.gg never receives your Google or Discord password.
EA account password and EA session data
The extension does not ask for, receive, read, transmit, store, or clear your EA account password. EA sign-in is performed by EA on EA's own pages under EA's privacy policy.
When you are already signed in to the EA Web App, the extension can use the active EA session ID in current page memory to send the market or Web App request you select directly to EA. The EA session ID is never written to Chrome storage, local files, URLs, analytics, Cloud Settings, or FCtools.gg servers. The underlying EA sign-in session, cookies, account data, expiry, and revocation remain controlled by EA.
Data stored in your browser
The extension stores feature settings, market search history, cached player metadata and prices, locked-player identifiers, SBC completion counts and solution identifiers, Evolution data, and bounded notice acknowledgements in your Chrome profile. Expiry-reminder results and bulk pack-opening results remain in current page memory and are not uploaded or retained as history.
Optional Cloud Settings
Cloud Settings are transferred only after you confirm Upload settings or Download settings. The allowlisted document can contain feature preferences, shortcuts, SBC builder rules, saved trading presets, pack ordering, pinned SBC lists, and persona-scoped locked-player identifiers. Trading activity, statistics, caches, API keys, notification tokens, webhooks, custom service URLs, passwords, authentication tokens, and EA sessions are excluded. Transfers are never automatic.
Feature requests and service records
Smart Solve and Evolution Paths send FCtools.gg the requested calculation input, current EA persona ID and name, a random extension installation ID, extension version, and feature name. FCtools.gg records request time, result status, duration, error category, IP address, and browser user agent for authentication, quota enforcement, troubleshooting, security, and abuse prevention. Official notices send the active EA persona ID and platform; FCtools.gg stores a one-way persona key, notice ID, and acknowledgement time. These records are not used for advertising or cross-service tracking.
Data shared with other services
- EA: the current EA session ID and the market or EA Web App request you initiate. The session ID remains in page memory and is sent directly to EA only; it is never sent to FCtools.gg.
- FUTBIN, FUT.GG, FUTNEXT, and FUT.to: only the player, SBC, pack, price, or Evolution identifiers needed for your requested lookup. They do not receive your FCtools.gg email, password, or token.
- Google or Discord: OAuth authorization data only when you choose that provider. Transactional email and infrastructure providers receive only the minimum account email, message, network, and hosting data required to deliver email and operate FCtools.gg securely.
FCtools.gg does not sell user data, share it with advertising or analytics providers, use it for creditworthiness or lending, or use it for purposes unrelated to the extension's user-facing functionality. Other services process the data they receive under their own privacy policies.
Security
Authentication uses HTTPS/TLS only and a fixed endpoint allowlist. Release builds reject insecure HTTP hosts. Authentication responses are not cached, redirects are rejected, and no referrer is sent. Passwords are never persisted by the extension. Tokens stay out of URLs and third-party requests, and sign-out clears both Chrome storage areas.
Retention and deletion
Clear FCtools.gg account credentials and data
The extension never stores the plaintext FCtools.gg password, so there is no local password copy to clear. Signing out of FCtools.gg removes the FCtools.gg account token from chrome.storage.session and chrome.storage.local and requests server-side session revocation. Session-only FCtools.gg tokens are also removed when Chrome closes. Other local extension data remains until you clear FCtools.gg extension data or uninstall the extension.
To request deletion of your FCtools.gg account and associated server data, email support@fctools.gg from the registered address. Data that must be retained temporarily for security, fraud prevention, legal compliance, or backups is deleted when that purpose expires.
Clear EA account credentials and session data
FCtools.gg never asks for, receives, reads, transmits, stores, or clears your EA account password, so FCtools.gg has no EA password copy to delete. When you are already signed in to the EA Web App, the active EA session ID remains only in current page memory and is sent directly to EA for requests you initiate. It is never stored by the extension or sent to FCtools.gg.
Reloading or closing the EA Web App clears the extension's in-memory reference to the EA session ID. Signing out of FCtools.gg or uninstalling FCtools.gg does not sign you out of EA and does not delete EA cookies or EA account data. To terminate the underlying EA session or manage EA account data, sign out through EA or use EA's account and privacy controls.
Contact
Send privacy, deletion, and support requests to support@fctools.gg。