Privacy Policy
The short version. Sideline SideKick Tracker stores the account details of the people who sign in and the team information coaches enter, including a player roster. That information is visible only to members of that team, and only to the extent the team's owner allows. It is never sold, never shared with other companies, never used for advertising, and never used to track anyone across other apps or websites. The app contains no usage analytics and no advertising software. The one thing it sends that nobody typed in is a crash and error report when something goes wrong; those contain no names and are not linked to your account.
Sideline SideKick Tracker (shown on your device as "Sideline SideKick") is an iOS app for high school football coaching staffs. Coaches log plays during a game and get live stats and a postgame report. The app is developed and operated by Jeffrey Feely as an individual developer.
This policy explains what the app collects, why, and what you can do about it. The terms you agree to when you use the app are set out separately in the Terms of Service.
This policy covers the tracker only. Sideline Headset is a separate app — a wireless headset that lets a coaching staff talk to each other during a game. You sign in to it with the same account, but it stores different things and records no audio at all, so it has its own policy at sideline-sidekick.com/headset-privacy. Everything below describes the tracker.
Information the app collects
1. Account information
When a coach creates an account, the app stores:
- Email address
- Display name
- A user ID assigned by Firebase Authentication
This is used only to sign you in and to show which staff members belong to a team. Passwords are handled by Firebase Authentication and are never stored by the app or visible to the developer.
2. Team information entered by coaches
Everything else in the app is content that a coach types in:
- Team name and team colors
- A team logo, and optionally an opponent's logo, if a coach chooses to add one
- A roster of players: first and last name, jersey number, position, and grade
- A playbook
- Games, individual plays, and scores
About logos. If a coach adds a team logo, the app asks iOS for that one image through the standard photo picker and stores a copy of it with the team. The app has no access to the rest of your photo library and never reads it. iOS hands over only the picture you pick. Adding a logo is optional and the app works without one.
3. Crash and error reports
When the app crashes, or when something inside it fails quietly — a game that will not open, a save the server refuses, a roster import that comes back empty — the app sends a report so the problem can be found and fixed. Apart from the notification token described in section 4, this is the only information the app collects that nobody typed in.
A report contains:
- what kind of failure it was, and where in the app it happened;
- the version of the app, the device model, and the iOS version;
- the internal database id of the record involved, which is a random string of characters and not a name;
- a random identifier for that installation of the app, which is what lets the service count how many devices a problem affects rather than just how many times it happened.
Nothing that identifies a person goes into a crash report. Never a player's name, jersey number, grade or position. Never an email address, a coach's or anyone else's. Never a team name, because naming a school names a set of children. Never an invite code. This is a rule written into the app's source code, not a matter of care at the time.
Reports are not linked to your account. The app deliberately does not attach your user id to them, so a crash cannot be traced back to a named coach or a named team. The installation identifier above is not your account, not your name, and not a device identifier used for advertising.
Two kinds of report go out, and both are covered by everything said above: an actual crash, and a quiet failure that did not crash the app. Apple counts the second kind as diagnostic information rather than crash data, so it is listed separately on the App Store, but the app treats them identically and neither one carries a name.
Both are handled by Firebase Crashlytics, part of the same Google Firebase service described below. Reporting is on in every released version of the app and there is no setting to turn it off.
4. Game alerts (push notifications)
The app can send game alerts to your phone: that a game has started, the score at the end of a quarter, each scoring play, and the final score. This is optional. iOS asks your permission the first time you open a team, and you can say no; nothing else in the app changes if you do.
If you allow it, the app stores a notification token for that device with your account. A token is a long random string issued by Apple and Google's messaging service that lets a message be delivered to one phone. It is not your phone number, not an advertising identifier, and it identifies a device only for the purpose of delivering these alerts. It is stored with your account and is readable by nobody else on the team.
Alongside it, the app stores which alerts you want from each team — four on/off switches. You can change them on the team's Alerts screen, and you can turn alerts off entirely in iOS Settings at any time.
What an alert says. A scoring-play alert carries the same sentence the app already shows on the play-by-play — for example "SST Touchdown, James Aikey 12-yd pass from Dillon O'Brien" — followed by the score. That sentence names the player who scored, and it is delivered through Apple's notification service to every member of the team who has that alert switched on. It is the same information every member of the team can already see in the app; it is not published anywhere else. A team owner can switch alerts off for the whole team, and a coach can mute them for a single game.
The token is removed when you sign out on that device, and when your account is deleted. The alerts themselves are sent by a server-side function that reads only the game's status and its scores; it never reads the playbook or the individual plays.
The app does not collect location, contacts, health data, device identifiers for advertising, or any usage analytics.
About student athlete information
This is the part that matters most, so it is stated plainly.
The roster in this app contains information about student athletes, who are minors. That information is entered by the school's adult coaching staff as part of their coaching work. Players never enter it themselves.
A player or a parent may be given the team's invite code by the coaching staff so they can follow the game and see statistics. They join in a restricted "Fan" role: read-only, no access to the playbook, and no ability to add or change any information about anyone. Creating an account requires an email address and a password.
Who can see it. Roster information is visible only to people the team's owner has admitted to that team in the app, and to the developer as described under Access by the developer below. That is the coaching staff. If the owner chooses to share the team's invite code more widely, it also includes parents and players, who join in the restricted "Fan" role described above. A Fan can see the score, the play-by-play and player statistics. A Fan cannot change anything, and cannot see the team's formation or play names.
It is the team owner's decision who receives the invite code, and the owner can remove any member at any time from the Coaches screen. Schools should treat the invite code as they would any other roster information.
Roster information:
- is visible only to members of that team in the app, as described above, and to the developer as described under Access by the developer;
- is never sold or rented to anyone;
- is never shared with third parties, other than the cloud hosting provider described below that stores the data on our behalf;
- is never used for advertising, marketing, or profiling;
- is never used to build a profile of a student or to track anyone across apps or websites.
Coaching staff are responsible for entering only the information they need and for following their school or district's own policies about student information. We recommend entering the minimum needed to run the game: a name, number, position, and grade.
Access by the developer
Sideline SideKick is run by one person, and he can see everything in it. That is the plain truth of a service this size, and it is better said outright than buried. He can list every team and every account, open any team's roster, playbook, games and statistics, and export any of it — whether or not anyone has asked him to, and whether or not there is a problem.
He does this to run the service. In practice that means:
- Checking that it works. Looking across teams and accounts to confirm that games are syncing, imports are landing, statistics are adding up and nothing has quietly broken — including on teams that have not reported anything wrong.
- Answering a support request. When a coach asks for help with something specific, and looking — or making the fix himself — is the way to answer it.
- Fixing and maintaining data. Correcting records a bug has damaged, repairing a team's setup, migrating data when the app changes shape.
- Administering accounts and teams. Changing somebody's role, removing a member, closing an account, and deleting teams and accounts that are no longer in use — including deleting old or cancelled customers.
- Subscriptions and billing. Seeing which accounts are subscribed, and putting right anything that has gone wrong with a purchase.
- Security and abuse. Investigating a report, or something that looks wrong.
- Where the law requires it, such as a valid legal order.
What that access is never used for. Advertising, marketing, profiling, selling or sharing with anyone else, training any machine-learning system, or building a picture of a student. Those are not things this service does, and broad access does not change it.
Nobody else has it. There are no other staff, no contractors, and no third party is given access to team information. Where that changes, this page changes with it.
How that access is held
The developer uses administrative tools to do this — to browse accounts and teams, to make the changes described above, and to remove accounts that are no longer in use. Those tools run only on his own computer. There is no admin website, and no address on the internet that reaches your team's data.
That is worth spelling out, because it is the part most services cannot say. There is no administrator login page for somebody to find, guess or attack, and no hosted console that could be breached and hand over every team at once. If that ever changes — if administration moves to something reachable over the internet — this page will say so before it does.
Passwords are never part of this, in any of the situations above. They are handled by the sign-in provider and are not stored by the app or visible to the developer. There is also no way for the developer to sign in as you or to use the app as you — support is done by looking at data directly, not by taking over an account.
If you would rather your team's information were not held on these terms, you can delete your team and your account at any time using the steps under Deleting data.
What the app does not do
- No usage analytics. The app does not record which screens you open, which features you use, or how long you spend in it.
- No advertising, and no ad networks.
- No advertising or tracking SDKs. The app never reads the device's advertising identifier, and no data is ever sent to a data broker.
- No selling or sharing of data with other companies.
- No tracking of users across other apps or websites.
Crash and error reports, and the notification token if you turn game alerts on, are the two things the app sends that nobody typed in, and what each contains is described above.
Where the data is stored
The app uses Google Firebase — specifically Firebase Authentication and Cloud Firestore for account and team data, Firebase Cloud Messaging to deliver game alerts, and Firebase Crashlytics for the crash and error reports described above — so all of it is stored on Google Cloud infrastructure. Google acts as a hosting and processing provider for this data; it is not shared with Google for Google's own advertising or marketing. You can read how Google handles data in that role at policies.google.com/privacy and firebase.google.com/support/privacy.
Access to team data is limited to signed-in users who are members of that team, and what each member can see depends on the role the team owner gave them. These limits are enforced on the server by Cloud Firestore security rules, not only in the app.
Data stored on your device
The app keeps an offline copy of your team's data on your device so it keeps working on a field with poor reception. Changes made offline sync back to the cloud when a connection returns. Deleting the app from your device removes that local copy; it does not delete the data stored in the cloud.
How long data is kept
Team data is kept for as long as the team exists, and there is no automatic expiry. That is deliberate. A coaching staff wants last season's games, and the season before that — a policy that quietly deleted a team's history after some number of months would break the thing the app is for. So nothing is deleted on a timer.
What that means in practice is that you decide how long information is kept, not us:
- Team and roster information is kept until someone deletes it — a player, a game, or the whole team — using the steps in the next section. Inactive teams are not purged; a team nobody has opened in two years is still there when a coach comes back to it.
- Account information is kept until you delete your account. Dormant accounts are not removed automatically.
- Deletion is immediate and permanent. When you delete a player, a game, a team, or your account, the records are removed from the database outright. They are not hidden, flagged or archived, and there is no way for us to restore them afterwards.
- Notification tokens are kept while you stay signed in on that device with alerts allowed. Signing out removes the token for that device; deleting your account removes every token and every alert preference stored with it.
- Crash and error reports are the one exception, and they do expire. Firebase Crashlytics ages them out on its own schedule, typically about 90 days. As described above, they contain no names and are not linked to your account.
Deleted data may persist for a short time in the routine backups kept by our cloud hosting provider before those backups age out. It is not accessible through the app once deleted.
If the app is ever discontinued, notice will be posted on this site and sent to the email addresses on active accounts, with time to export your reports before team data is deleted.
Deleting data
- Delete a player. On the Team tab, open the roster, swipe the player's row and choose Delete. This removes them from the roster.
- Delete a game. On the Games tab, swipe or press and hold a game and choose Delete. Every play and score logged in that game is deleted with it.
- Delete a whole team. On the Team tab, under "Danger zone", choose Delete this team and type the team's name to confirm. This permanently deletes the team for everyone on it, along with its roster, playbook, and every game, play and score. Only the team owner can do this, and it cannot be undone.
- Leave a team. If you are not the owner, the same section offers Leave this team. This removes you from the team and leaves the team's data intact for the rest of the staff.
- Delete your account. On the Team tab, under "Danger zone", choose Delete my account and confirm with your password. This deletes your sign-in and your profile, removes you from every team you are on, and deletes any notification tokens and alert preferences stored with the account. If you are the only owner of a team, the app will ask you to make another coach an owner or to delete that team first. Otherwise the team would be left with nobody able to administer it.
If you would rather not do it yourself, or you cannot sign in, email [email protected] from the address on the account and ask for deletion.
You can also email the same address to ask what information is stored about your account or to have it corrected.
Children
The app is built for high school coaching staffs, and everything in it is entered by adult coaches. It is not directed at children under 13, and we do not knowingly collect information from anyone under 13.
High school players may be invited by their coaching staff to follow their own team in the read-only "Fan" role. A player who does so creates an account with an email address and a password, and — only if they allow game alerts — a notification token for their device, as described in section 4. That is the only information the app collects from them; they cannot enter or change any information about themselves or anyone else. If you believe an account was created by someone under 13, or that roster information was entered that should not have been, email [email protected] and it will be removed.
Changes to this policy
If this policy changes, the updated version will be posted on this page with a new effective date.
Contact
Jeffrey Feely
[email protected]