1. Information We Collect
Maximize Magic is designed to work with minimal data. Sign-in is optional — you may use the app as a guest without providing personal information.
- Account information (optional): if you sign in with Google, Facebook or Apple ("Sign in with Apple", including Apple's private email relay if you choose to hide your email), we receive your name and email address to identify your account. When you sign in, we create an account record in Google Firebase containing your email, your AI credit balance and free-usage allowances, and basic device metadata (device model, OS version, app version, language, approximate country, and a device identifier used to prevent abuse of free allowances). Signing in also grants a one-time courtesy of 500 AI credits (for the first account on each device) and unlimited usage time on the ad-supported plan. Watching an optional rewarded video can add 500 AI credits (up to 3 videos per day).
- Guest mode & courtesy allowances: without signing in, an anonymous identifier is created (Firebase Anonymous Authentication) with free-usage meters tied to your device. No name or email is involved. As a courtesy, every guest receives free allowances: 300 AI credits, 4 free AI questions (plus 1 answer with live web search), 15 GPS navigations, 60 minutes of active use, and 5 attraction detail views. These allowances are granted once per device; when any of them runs out, signing in is required to continue.
- AI assistant (MagicBot): when you use the in-app AI assistant, the text of your question is sent to Google's Gemini API to generate the answer, together with live park context (wait times, schedules, weather). We do not store the text of your questions on our servers; we keep aggregate usage metrics (token counts, credits used) linked to a hashed identifier, for cost control and abuse prevention.
- Usage data: events about how the app is used (screens viewed, features used, language, device type, approximate country, sign-in method, subscription status). When you are signed in, part of this data is associated with your account email; in production we only log a random sample of users.
- Device integrity: to protect free allowances from abuse, the app uses Google Play Integrity (Android) and Apple App Attest (iOS) to verify it is running on a genuine device. These checks do not identify you personally.
- Location (optional): only if you explicitly grant permission. Your parking location is stored on your device only and never leaves it. When you ask MagicBot about places near you, your coordinates are sent with that request so the answer can be about your surroundings, and they are forwarded to the Google Places API for that single query — we do not keep them afterwards. For analytics we only derive a coarse area (for example, "Orlando") to understand where the app is used.
- Purchase information: subscriptions and AI credit packs are processed by Apple (App Store) or Google (Google Play) and managed by RevenueCat. We receive only the purchase/subscription status — we never access your payment card details.
- Advertising identifier: on ad-supported plans, Google AdMob reads your device's advertising identifier (IDFA on iOS, Advertising ID on Android). It is used to serve and measure ads and, only if you allow it (Apple's App Tracking Transparency prompt on iOS, Google's consent form in the EEA and the UK), to personalise them. Our own servers never receive or store this identifier. Subscribers on the ad-free plan see no ads at all.
- Rewarded ads (optional): you may choose to watch a video ad to earn AI credits or unlock features. When you complete a video, Google AdMob notifies our server (server-side verification) with your account or anonymous identifier so the reward can be credited — no personal data is included.
2. How We Use Your Information
Any data collected is used exclusively to:
- Display accurate, real-time wait times for Orlando theme parks.
- Identify your account when you sign in with Google, Facebook or Apple.
- Manage your subscription, AI credits and free-usage allowances.
- Generate MagicBot answers through Google's Gemini API.
- Show advertisements to users on ad-supported plans. Where you have given permission, an advertising identifier may be used to personalise those ads and to measure them; if you decline, ads are still shown but are contextual only.
- Prevent abuse of free allowances (rate limits, device integrity checks, annual usage caps).
- Diagnose and fix technical issues, and improve the app over time.
We do not sell your data, and we do not build advertising profiles of you ourselves. If you allow personalised advertising, Google may use the advertising identifier for that purpose under its own policy; you can withdraw that permission at any time.
3. Third-Party Services
Maximize Magic integrates the following third-party services, each governed by their own privacy policies:
- themeparks API: open-source API used to retrieve real-time wait time data. No personal user data is sent to this service.
- WeatherAPI.com: weather forecasts for the Orlando area. No personal user data is sent to this service.
- Wikipedia: attraction images. No personal user data is sent to this service.
- Google Sign-In / Facebook Login / Sign in with Apple: optional sign-in. We receive your name and email from the provider you choose, in accordance with its privacy policy.
- Google Firebase: our backend — authentication, database (account records, credits, usage allowances), analytics and cloud functions. See Google's Privacy Policy.
- Google Gemini API: generates MagicBot answers. Your questions are processed by Google in accordance with Google's Privacy Policy.
- Google Places API: used for some MagicBot answers about nearby businesses (for example, pharmacies near a park). Only the query and an approximate location are sent.
- Google AdMob: banner, interstitial and rewarded advertisements on ad-supported plans. AdMob uses your device's advertising identifier (IDFA on iOS, Advertising ID on Android) together with basic device signals to serve, cap and measure ads. On iOS we ask for your permission through Apple's App Tracking Transparency prompt before that identifier can be used for personalised advertising; in the EEA and the UK the equivalent choice is offered through Google's consent form. If you decline, ads are still shown but are not personalised. You can change your choice at any time in your device settings. See Google's Privacy Policy.
- RevenueCat: manages in-app subscriptions and credit packs. RevenueCat processes purchase receipts and subscription status on our behalf. See RevenueCat's Privacy Policy.
- Google Play Integrity / Apple App Attest: device integrity verification to prevent abuse. See the respective privacy policies of Google and Apple.
4. Children's Privacy
Maximize Magic does not knowingly collect personal information from children under 13 years of age. The app is designed to be family-friendly and safe. If you believe a child has provided personal information, please contact us immediately so we can remove it.
5. Data Security
Account records are stored in Google Firebase with industry-standard protections, and direct access is restricted to our backend services. We minimize what we store by design: AI questions are not persisted, raw location is never kept, and usage analytics in production cover only a random sample of users.
6. Your Rights
You can delete your account at any time from within the app (see section 7), and you can revoke the app's access from your Google, Facebook or Apple account settings.
If you are in the European Economic Area or the United Kingdom, data protection law gives you the following rights over your personal data:
- Access — ask us for a copy of the data we hold about you.
- Rectification — ask us to correct data that is inaccurate or incomplete.
- Erasure — ask us to delete your data. Note that where we rely on legitimate interest to prevent abuse (see section 6b), we may keep the minimum needed for that purpose, and we will tell you if that is the case and why.
- Restriction — ask us to pause processing while a dispute is resolved.
- Portability — receive the data you gave us in a machine-readable file.
- Objection — object to processing based on legitimate interest, including abuse prevention. We will stop unless we can show compelling grounds that override your interests.
- Withdraw consent — where processing is based on consent (advertising and usage analytics), you can withdraw it at any time, without affecting what was done before. Withdrawing it does not stop you from using the app.
To exercise any of these, contact us using the details at the end of this policy. We will answer within one month, as required by the GDPR. There is no charge.
Right to complain. If you believe we are handling your data unlawfully, you may lodge a complaint with the data protection authority of the EU or EEA country where you live or work. You can do that whether or not you contact us first.
6b. Why We Are Allowed to Process Your Data
Under the GDPR we must have a legal basis for each purpose. Ours are:
- Performance of a contract (Art. 6(1)(b)) — your account, AI credit balance, purchases and subscription status. Without this data the app cannot deliver what you asked for.
- Legitimate interest (Art. 6(1)(f)) — preventing abuse and fraud: the device-level record, the sign-in history described in section 7, usage limits, and the records of suspended accounts described in section 8. Our interest is keeping free allowances and AI costs from being drained by automated or repeated abuse, which would make the app unusable for everyone else. We use the minimum needed for that: the sign-in history holds one row per distinct account-and-device combination rather than a log of your activity, and network addresses are stored only as an irreversible hash. Recital 47 of the GDPR expressly recognises fraud prevention as a legitimate interest. You can object at any time (see section 6).
- Consent (Art. 6(1)(a)) — personalised advertising and usage analytics. Advertising consent is requested through Google's consent form the first time you open the app in the EEA, and you can change it later. Analytics are only collected once you have accepted this policy.
- Legal obligation (Art. 6(1)(c)) — records related to purchases, where tax or accounting law requires us to keep them.
6c. Where Your Data Is Processed
The app runs on Google Cloud and Firebase, and our servers are located in the United States (region us-central1). The third-party services listed in section 3 — including Google Gemini, Google Places, Google AdMob and RevenueCat — also process data in the United States.
This means that if you are in the EEA or the UK, your data is transferred outside your country. These transfers are covered by the European Commission's Standard Contractual Clauses and, where applicable, by our providers' certification under the EU–US Data Privacy Framework. You can ask us for details using the contact information below.
6d. How Long We Keep Your Data
- Device-level record (credit balance, free-usage allowances, sign-in history): kept while the device keeps using the app, and deleted automatically after 2 years without any activity.
- Security and diagnostic logs: deleted automatically between 90 and 180 days after they are written.
- Purchase records: kept as long as tax and accounting law requires.
- Suspension records: kept while the suspension is in force, and afterwards only as long as needed to stop it being trivially circumvented.
You can always ask us to erase your data earlier — see section 6.
7. Account Deletion
You can delete your account at any time directly within the app:
Open the app → Settings → Delete Account.
What is deleted. Your authentication account is removed, you are signed out, and all preferences, saved parks, plans and session data stored on your device are permanently erased. Your account record is deactivated and is no longer used to identify you inside the app.
What we keep, and why. We retain a device-level record holding your credit balance, your remaining free-usage allowances and basic device information, together with your account identifier in a deactivated state. We keep it to prevent abuse: the free allowances we grant are granted once per device, and without this record anyone could delete and recreate an account to reset them indefinitely. The record belongs to the device rather than to a single sign-in method — the same phone may still be in use by another account.
What that means in practice. If you sign in again on the same device, your previous balances and remaining allowances will still be there. They are not granted to you again as new — they never left the device.
Sign-in history. We also keep a separate record of each distinct sign-in combination on a device: the email address (or the Apple private-relay address) used, the date, and basic context such as app version, device model and country. One row is written the first time a given account signs in on a given device — not every time you open the app. We keep it for the same anti-abuse reason: it is what lets us see that a single device has cycled through many different accounts to reset free allowances. Deleting your account does not remove these rows, because doing so would erase exactly the evidence they exist to preserve.
If you would like this device-level record and your sign-in history erased as well, get in touch using the contact details at the end of this policy and we will handle your request individually.
- To revoke the app's access to your Facebook account, go to Facebook → Settings → Apps and Websites and remove Maximize Magic.
- To revoke the app's access to your Google account, go to Google Account → Security → Third-party apps with account access and remove Maximize Magic.
- To stop using Sign in with Apple with the app, go to iPhone Settings → your name → Sign-In & Security → Sign in with Apple and remove Maximize Magic.
8. Fair Use and Account Suspension
The app's features and courtesy allowances are intended for normal, personal use. In the event of any abuse within the app, the owner reserves the right to deny access to the account, device or anonymous identifier involved, temporarily or permanently.
Causes of abuse include, among others:
- Improper use of the GPS navigation features.
- Improper use of the interactive map.
- Improper use of the AI assistant (MagicBot), including attempts to manipulate, automate or exploit it.
- In general, any use of the app outside its normal operation — including tampering with free allowances, automated access, or attempts to bypass usage limits.
In addition, total AI usage per user is capped at the equivalent of USD 60 per calendar year (counting both purchased and courtesy credits). Exceeding this annual limit results in suspension of access to the app for the account and device involved.
9. Changes to This Policy
We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated date at the top. We encourage you to review this page periodically. Continued use of the app after changes constitutes acceptance of the new policy.
✉️ Contact Us
Data controller: Eduardo Nuñez, independent developer of Maximize Magic.
For any question about this Privacy Policy, or to exercise the rights described in section 6 — including access, erasure or objection — contact us here. We answer within one month.
Open an issue on GitHub →