Privacy Policy for Replay Sports App
Introduction
Replay Sports App ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application.
Information We Collect
Personal Information
We collect the following personal information:
- Account Information: Name, email address, password (encrypted), phone number.
- Profile Information: User role (coach, player, parent), team affiliations, profile picture.
- Authentication Data: Google OAuth credentials (if you sign in with Google).
Content You Create
- Videos: Training videos, game footage you upload or record.
- Notes: Timestamped notes and comments on videos.
- Drawings: Annotations and drawings on videos.
- Messages: Direct messages, team chats, and group conversations.
- Events: Calendar events, schedules, and workout plans.
- Achievements: Performance tracking and accomplishments.
Automatically Collected Information
- Device Information: Device type, operating system, app version.
- Usage Data: Features used, videos watched, time spent in app.
- Push Notification Tokens: For sending notifications (only when permission granted).
How We Use Your Information
We use your information to:
- Provide Services: Enable video playback, team management, messaging, and scheduling.
- Improve Performance: Optimize video streaming, fix bugs, enhance user experience.
- Send Notifications: Alert you about messages, events, and team activities.
- Team Management: Connect coaches, players, and parents within teams.
- Analytics: Understand how users interact with the app to improve features.
- Support: Respond to your questions and technical issues.
- Safety & Moderation: Monitor content to enforce our Terms of Service and protect users.
- Legal Compliance: Respond to legal requests and prevent illegal activity.
Third-Party Services
We use the following third-party services that may collect your data:
- Firebase (Google)
- Mux
- Google OAuth
- Expo
- Sentry
- Twilio
Purposes and data shared:
- Firebase: Authentication, database, cloud storage, analytics. Data shared: email, name, user ID, app usage data.
- Mux: Video hosting, streaming, and playback. Data shared: videos you upload, viewing statistics.
- Google OAuth: Sign in with Google account. Data shared: email, name, profile picture (only with your permission).
- Expo: App development platform, push notifications. Data shared: push notification tokens.
- Sentry: Crash reporting and error monitoring. Data shared: error logs, device info, user ID (if available).
- Twilio: Phone number verification. Data shared: phone number, verification status.
Privacy policies:
- Firebase: https://firebase.google.com/support/privacy
- Mux: https://www.mux.com/privacy
- Google: https://policies.google.com/privacy
- Expo: https://expo.dev/privacy
- Sentry: https://sentry.io/privacy/
- Twilio: https://www.twilio.com/legal/privacy
Data Storage and Security
Where Your Data is Stored
- Videos: Stored securely on Mux servers (US-based).
- User Data: Stored on Firebase Cloud Firestore (US-based).
- Files: Stored on Firebase Cloud Storage (US-based).
Security Measures
- Encryption: All data transmitted using HTTPS/TLS encryption.
- Authentication: Secure Firebase authentication with encrypted passwords.
- Access Control: Role-based permissions (coaches, players, parents have different access levels).
- Rate Limiting: Protection against abuse and spam.
- Regular Updates: Security patches and updates applied regularly.
Our Access to Your Data
What We Can Access
To provide, maintain, and improve our services, we have technical access to:
- All Videos: Videos you upload, record, or share, including training footage and game recordings.
- All Messages: Direct messages, team chats, and group conversations.
- Notes & Drawings: Timestamped notes, comments, and annotations on videos.
- Events & Schedules: Calendar events, workout plans, and team schedules.
- Account Information: Profile details, team memberships, and usage data.
When We Access Your Data
We access your data only when necessary for:
- Technical Support: Troubleshooting issues you report or investigating bugs.
- Content Moderation: Reviewing reported content for Terms of Service violations.
- Safety & Trust: Preventing harassment, abuse, or illegal activity.
- Legal Obligations: Complying with valid legal requests, subpoenas, or court orders.
- Service Operations: Maintaining servers, performing backups, and ensuring system reliability.
- Security: Detecting and preventing fraud, spam, or security threats.
How We Protect Your Privacy
- No Routine Monitoring: We do not routinely read your messages or watch your videos.
- Manual Review: Content is reviewed manually only when reported or when a violation is suspected; we do not perform automated scanning of your content.
- Limited Access: Only authorized personnel can access user data, and only when necessary.
- Employee Training: Our team is trained on privacy best practices and data handling.
- Anonymization: When possible, we use anonymized or aggregated data for analysis.
Your Content Rights
- You retain ownership of all content you create and upload.
- We do not use your videos or messages for marketing or advertising.
- We do not share your private content with third parties except as required by law.
- You can delete your content at any time through the app.
Data Retention
How Long We Keep Your Data
- Account Data: Retained while your account is active.
- Videos: Retained while your account is active or until you delete them.
- Messages: Retained while your account is active or until deleted by users.
- Events/Schedules: Retained while relevant to your team.
- Logs: Technical logs retained for 90 days for debugging.
- Anonymized Data: After account deletion, anonymized content (e.g., team videos, shared messages) may be retained for the continued functioning of team features.
Account Deletion
When you delete your account:
- Your profile is anonymized (name changed to "Deleted User").
- Your email and phone number are permanently removed.
- Your profile picture is deleted from our servers.
- Videos you uploaded remain with your team but show "Deleted User" as uploader.
- Your messages remain visible to other participants but are anonymized.
- You cannot recover your account after deletion.
- Your Firebase authentication is permanently removed.
- For users under 18, parent/guardian or head coach approval is required.
- Cached data in backups may take up to 30 days to be fully removed.
Your Rights
You have the right to:
- Access: Request a copy of your personal data.
- Correction: Update or correct your information in the app.
- Deletion: Delete your account and associated data.
- Export: Request an export of your data by contacting support. We will provide your data within 30 days.
- Opt-Out: Disable push notifications in device settings.
- Withdraw Consent: Revoke permissions at any time.
Children's Privacy
Our app is not directed to children under 13 years of age. Children under 13 may only use the app through a parent or guardian-managed profile.
For Children Under 13:
- A parent or guardian must create and manage the child's profile.
- We collect limited information (name, age, position, jersey number) to provide team features.
- We record parental consent before creating a child profile.
- Parents can request deletion of their child's data at any time.
- We comply with COPPA (Children's Online Privacy Protection Act) for children under 13.
For Users 13-17:
- We require parental consent for account creation.
- Parents/guardians are responsible for monitoring their child's use of the App.
- Parents: If you believe your child has provided personal information without your consent, please contact us immediately at replaysportsapp@gmail.com.
Sharing Your Information
We DO NOT sell your personal information.
We may share your information:
- With Your Team: Other team members can see your name, role, and shared content.
- With Service Providers: Third parties helping us operate the app (Firebase, Mux, Sentry, Twilio).
- For Legal Reasons: If required by law, court order, or government request.
- Business Transfer: If we merge with or are acquired by another company.
We will NEVER:
- Sell your data to third parties.
- Share your videos without your permission.
- Use your data for advertising purposes.
Cookies and Tracking
We do not use cookies in our mobile app. However, third-party services (Firebase Analytics, Mux, Sentry) may use tracking technologies for analytics and performance monitoring.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of significant changes by:
- Posting the new policy in the app.
- Sending a notification through the app.
- Updating the "Last Updated" date.
Your continued use of the app after changes constitutes acceptance of the updated policy.
International Users
Our services are operated from the United States. If you access the app from outside the U.S., your data will be transferred to and processed in the United States. By using the App, you consent to the transfer of your data to the United States, which may have different data protection laws than your country. We take steps to ensure your data receives an adequate level of protection in accordance with applicable data protection laws, including the use of Standard Contractual Clauses where required.
Contact Us
If you have questions about this Privacy Policy or your data, contact us:
- Email: replaysportsapp@gmail.com
- App: Use the "Contact Support" link in Profile settings
California Privacy Rights
If you are a California resident, you have additional rights under CCPA:
- Right to know what personal information is collected.
- Right to know if personal information is sold or disclosed.
- Right to opt-out of sale (we don't sell data).
- Right to deletion.
- Right to non-discrimination for exercising your rights.
To exercise these rights, contact us at replaysportsapp@gmail.com.
GDPR (European Users)
Legal Basis for Processing
We process your personal data based on the following legal grounds:
- Contractual Necessity: To provide the services you signed up for (account management, video hosting, messaging, team features).
- Consent: For optional features such as push notifications, analytics, and processing children's data under COPPA.
- Legitimate Interest: For service improvement, security, fraud prevention, and bug fixing — balanced against your privacy rights.
- Legal Obligation: To comply with applicable laws, court orders, or government requests.
Your Rights Under GDPR
- Right to access your personal data.
- Right to rectification of inaccurate data.
- Right to erasure ("right to be forgotten").
- Right to restrict processing.
- Right to data portability.
- Right to object to processing.
- Right to withdraw consent.
Right to Erasure
If you exercise your right to erasure, we will delete your personal data. Content you have shared with teams (such as videos) may be retained in anonymized form where necessary for the functioning of team features, but all personally identifiable information will be removed.
Data Transfers
Your data is transferred to and processed in the United States. We rely on Standard Contractual Clauses approved by the European Commission to safeguard your data during international transfers.
To exercise these rights, contact us at replaysportsapp@gmail.com.
Effective Date
Effective Date: February 6, 2026
By using Replay Sports App, you acknowledge that you have read and understood this Privacy Policy.