Baseline

Baseline mobile application

Privacy policy

What the Baseline app collects, why, where it goes, and how to make us delete it.

Version 1.0 17 September 2026 UK & EU GDPR

Draft — needs legal review before publication

This policy was written from what the application code actually does, and it is accurate to that. It has not been reviewed by a solicitor. Baseline processes health data — special category data under Article 9 of the UK GDPR — and, where officials record fixtures involving under-18s, children’s data. Both attract obligations beyond the scope of a policy drafted from source code. Have it reviewed before you submit it to Google Play or publish it as binding.

01 · Who we are

The controller

Application
Baseline, for Android, iOS and their companion watch apps.
Controller
[Registered company name and number — complete before publishing]
Registered address
[Complete before publishing]
Contact
privacy@baselineapp.co.uk
ICO registration
[Required: an organisation processing health data must register with the Information Commissioner’s Office]

02 · What we collect

Every category, and why

Baseline asks for a narrow set of data and refuses several things it could plausibly have asked for. Both are listed.

Data Why Lawful basis
Account Name, email address, date of birth, phone number and address. Identifies you, and proves you are old enough to hold an account. Contract
Licence For official accounts: licence number, grade and issuing body, verified against that body’s registry. Without it an account cannot write to a competitive record. Contract; legitimate interests (integrity of the match record)
Health & fitness Steps, heart rate, distance, active calories, exercise sessions and elevation gained, read from Health Connect on Android or HealthKit on iOS, and from a paired watch or Bluetooth chest strap. Explicit consent (Art. 9(2)(a))
Motion Step counting from the phone’s own sensor when no watch is connected. Explicit consent
Match record Fixtures, scores, events, sanctions, stoppages and their reason codes, with the timestamp, licence and device of whoever recorded them. Contract; legitimate interests
Profile photo One image you choose. Location metadata is stripped from it before it is stored. Consent
Messages Messages and match proposals you send to other users. Contract

What the app deliberately does not take

No camera. The app cannot capture a photo or video. It can only read one image you pick.

No microphone. The app cannot record audio.

No location. No GPS permission is requested, and exercise routes are deliberately not read from Health Connect — a session tells us how far you went, not where.

No advertising identifier, no analytics SDK, no third-party trackers.

Photo access, specifically

On Android 13 and later, choosing a profile photo goes through the system photo picker. The app receives only the single image you select and never gains access to your photo library. On Android 12 and earlier, where no system picker exists, storage access is used as a fallback.

On iOS, the photo library permission is limited to the images you choose.

03 · Where it goes

Storage, transfer and retention

On your device
Authentication tokens are held in the platform keystore (Android Keystore / iOS Keychain). Automatic cloud backup is switched off, so no copy of app storage reaches your Google or Apple account. Uninstalling the app destroys everything held locally.
On our servers
Account, licence, match and messaging data is held in a managed Postgres database with row-level security, so one account cannot read another’s rows. Encrypted in transit (TLS) and at rest.
Health data
Read from Health Connect or HealthKit with your explicit consent, and used to show your own fitness beside your own results. It is never sold, never used for advertising, and never shared with a league, federation or club.
Match records
Where an official signs off a fixture, that record is shared with the competition’s governing body, which becomes a controller of it in its own right under its own rules. This is the purpose of the app and cannot be opted out of for official accounts.
Casual results
Results recorded on a general account are never written to a league or federation record.
Retention
Account data for as long as the account exists, then deleted within 30 days. Health data [complete: retention period]. Signed match records are retained by the governing body under its own rules and cannot be deleted by us — the record is append-only by design, which is what makes it usable as evidence.
International transfer
[Complete: name the hosting region. If data leaves the UK/EEA, state the transfer mechanism.]

04 · Your rights

What you can make us do

Access

Ask for a copy of everything we hold about you. We respond within one month.

Rectification

Ask us to correct anything wrong. In the match record a correction is added as a new signed entry rather than overwriting the original — both remain visible, which is what an auditable record requires.

Erasure

Ask us to delete your account and data. Signed match records already transferred to a governing body are outside our control; we will tell you which body to approach.

Withdraw consent

Revoke health and motion access at any time in Health Connect, iOS Settings, or Baseline’s own settings. The rest of the app keeps working.

Portability

Receive your data in a machine-readable format, or have it sent directly to another controller where technically feasible.

Complain

Complain to the Information Commissioner’s Office at ico.org.uk, or to your own supervisory authority in the EEA. You can do this without contacting us first.

To exercise any of these, email privacy@baselineapp.co.uk. We may ask you to confirm your identity before we act, so that someone else cannot use these rights against you.

05 · Children

Under-18s

This section must be completed before publication. Officials using Baseline in school, academy and youth competition will record data about players under 18. That engages the UK Age Appropriate Design Code, the Article 8 rules on a child’s consent, and Google Play’s Families policy. Decide and state: the minimum age to hold an account; how a club or federation’s lawful basis for youth player data is established; and what a parent or guardian can ask for. This is the single most likely reason a reviewer rejects an app of this kind.

06 · Changes

If this policy changes

We will post the new version here and update the date at the top. Where a change materially affects how your data is used, we will tell you in the app before it takes effect, and ask again for consent where consent is the basis we rely on.

Version 1.0 · 17 September 2026 · baselineapp.co.uk/privacy