GFL (Ghost Fantasy League Surf) is an unofficial fan-built iOS app for private friend-group fantasy CT surfing leagues. The app is operated by Ghost Fingers, an independent California-based surf-data project. GFL is not affiliated with the World Surf League or any event sponsor.
Contact: [email protected]
GFL is built around the principle that the friend group's data is theirs. We do not collect, transmit, or have visibility into:
GFL does use two privacy-preserving diagnostic tools: anonymous crash reporting and anonymous product analytics. They never see your name, your picks, or any content, and you can turn them off. Full detail in Section 5 (Third-party services).
GFL stores the following on your device only, never transmitted to GFL or any third party:
GFL uses Apple's CloudKit framework to sync league data privately between members of the same league. CloudKit is operated by Apple under Apple's Privacy Policy. GFL has no access to your CloudKit data, no ability to read records on your behalf, and no server-side infrastructure that touches your data.
All CloudKit access uses Apple's "private database" scope, never the "public database." Even Apple cannot read the contents of your private CloudKit container.
GFL integrates with the following external sources:
For event-venue conditions, GFL fetches public surf forecast data from Open-Meteo, a free open-source weather API. Requests include only the venue's latitude/longitude (publicly available CT data). No user-identifying information is sent. Open-Meteo is licensed under CC-BY 4.0.
GFL displays publicly available WSL CT scoring data and event schedules. GFL is not affiliated with, sponsored by, or endorsed by the World Surf League. This is a fan-built unofficial app.
To find and fix crashes and slow screens, GFL sends anonymous crash reports and performance diagnostics to Sentry. These contain the crash call stack, device model, OS version, and a one-way hashed device identifier, and never your name, your iCloud ID, your picks, or any league content. The data is used only for app functionality (diagnosing problems), never for advertising or cross-app tracking. You can turn crash reporting off in Settings.
To understand which features get used (e.g. how many people complete a draft), GFL may send anonymous, aggregate product-analytics events to TelemetryDeck. Events are the action name only (no content, no names, no picks). The only identifier is a salted, one-way hash of your device's vendor ID, which cannot be reversed or linked back to you across apps. This is used for analytics only, never for advertising or tracking, and you can opt out in Settings.
GFL ships an Apple Privacy Manifest (PrivacyInfo.xcprivacy) declaring the anonymous crash, performance, and product-analytics data described in Section 5 (all marked not-linked-to-you and not-used-for-tracking). The manifest also declares the league content that syncs through your own iCloud, as described in Section 4: your CloudKit user ID, your display/team name, and the text you enter (league names, side-bet notes). Those rows are marked linked-to-you because your league members see them attributed to you; they are used only for app functionality, never for tracking, and we cannot read them. The manifest also lists the following Apple "required reason" API uses:
GFL is not directed to children under 13. GFL collects no personal information from anyone, regardless of age.
Because GFL stores everything in your own iCloud account, you have full control:
For California residents under the California Consumer Privacy Act:
If GFL adds features that change this policy (e.g., paid subscriptions, third-party advertising, analytics), we will:
To report a privacy concern, request data removal, file a DMCA notice, or request athlete name removal: [email protected].
For DMCA takedown notices, GFL's registered DMCA agent is on file with the U.S. Copyright Office (copyright.gov/dmca-directory).