- On your device
- Authentication tokens are held in the platform keystore (Android Keystore / iOS Keychain). Automatic cloud backup is switched off, so no copy of app storage reaches your Google or Apple account. Uninstalling the app destroys everything held locally.
- On our servers
- Account, licence, match and messaging data is held in a managed Postgres database with row-level security, so one account cannot read another’s rows. Encrypted in transit (TLS) and at rest.
- Health data
- Read from Health Connect or HealthKit with your explicit consent, and used to show your own fitness beside your own results. It is never sold, never used for advertising, and never shared with a league, federation or club.
- Match records
- Where an official signs off a fixture, that record is shared with the competition’s governing body, which becomes a controller of it in its own right under its own rules. This is the purpose of the app and cannot be opted out of for official accounts.
- Casual results
- Results recorded on a general account are never written to a league or federation record.
- Retention
- Account data for as long as the account exists, then deleted within 30 days. Health data [complete: retention period]. Signed match records are retained by the governing body under its own rules and cannot be deleted by us — the record is append-only by design, which is what makes it usable as evidence.
- International transfer
- [Complete: name the hosting region. If data leaves the UK/EEA, state the transfer mechanism.]