Privacy Policy
Last updated: July 25, 2026
1. Who We Are
Squadyy is a team management application for sports teams. The data controller for your personal information is:
If you have questions about how we handle your data, please contact us at the email addresses above.
2. Scope
This Privacy Policy applies to:
- The Squadyy Android application downloaded from Google Play
- The Squadyy web application at squadyy.app, including the team dashboard
- Public guest voting pages accessible via shared links
- The account deletion page at squadyy.app/delete-account
This Policy does not apply to third-party websites or services that may be linked from our Service.
3. Data We Collect
3.1 Account and Profile Data
- Email address
- Display name
- Avatar image (optional)
- Password hash (stored using industry-standard hashing)
3.3 Guest and Manual-Member Data
- Display name (provided by you or added by a team administrator)
- Device identifier (ANDROID_ID or a generated UUID stored on your device)
3.4 Team and Membership Data
- Team names, settings and invite codes
- Member lists, roles (admin, moderator, member, guest) and join dates
- Membership status (pending, approved, rejected)
3.5 Poll and Vote Data
- Poll titles, options, deadlines and settings
- Your vote selections and timestamps
- For guest vote links: a SHA-256 hash of the voter's IP address and user-agent string
3.6 Fund, Campaign and Expense Records
- Contribution amounts, statuses (pending, approved, rejected)
- Campaign names, descriptions and targets
- Match expenses, split calculations and participant lists
- Fund balance and deficit/surplus data
3.7 Payment Proof Images
Users may upload images or PDF files as evidence of fund contributions. These files are stored in Cloudflare R2 object storage. Proof images may contain bank account numbers, transaction IDs or other financial information — please crop or redact unrelated details before uploading.
3.8 Chat Messages and User-Generated Content
Team chat messages are stored in Firebase Firestore. This includes text messages and images uploaded to team chats. Chat images are stored in Cloudflare R2.
3.9 Notifications and FCM Token
- In-app notification records (creation, read status, dismissal)
- Firebase Cloud Messaging (FCM) device token for push notifications
3.10 Subscription and Purchase Verification Data
When you subscribe through Google Play, we receive:
- Google Play purchase token
- Product ID and subscription status
- Obfuscated account identifier for fraud prevention
Google Play processes your payment. We do not receive your full card number, CVV or billing address from Google Play.
3.11 AI Request and Response Data
When you use AI features (such as AI team splitting), we may send prompts and relevant team information through our backend to the AI provider (Google Gemini API). We log request metadata for service operation and abuse prevention.
3.12 Technical, Security and Diagnostic Logs
- Device type, model and operating system version
- App version and build identifier
- Crash reports and error logs (via Firebase Crashlytics)
- Usage analytics events (via Firebase Analytics), such as feature usage and screen views
- IP address (used for rate limiting; not stored permanently in our database)
3.13 Advertising and Consent Data
For users on the free plan, we display ads via Google AdMob. AdMob may collect and process data according to its own privacy policy. We do not directly collect the Android advertising identifier (GAID) in our application code. Where required (e.g., EEA, UK, Switzerland), we use Google's User Messaging Platform to obtain your consent before serving personalized ads.
3.14 Data From Other Team Members or Administrators
Team administrators can add members manually by providing a display name. Administrators are responsible for having the authority to submit information about other people. Other team members may also see your name, role and fund status within the team.
4. Payment Clarification
Squadyy does not directly process, hold, transfer or escrow team contribution funds. Here is how payments work:
- Subscriptions: Processed entirely by Google Play. Squadyy receives only a purchase token, product ID and verification data.
- Team contributions: Occur outside of Squadyy (e.g., bank transfer, cash). Squadyy only stores the organizational record and any proof image voluntarily submitted by the user.
- Warning: Payment proof images may contain bank account numbers or transaction details. We recommend cropping or redacting unrelated information before uploading.
5. How Data Is Used
We use the information we collect to:
- Provide account and team management functionality
- Handle authentication and session management (access and refresh tokens)
- Process polls, fund records, expense allocation, chat and notifications
- Verify subscription purchases through Google Play
- Display ads and manage rewarded-ad entitlement (24-hour ad-free period)
- Fulfill AI feature requests (team splitting, text generation)
- Ensure security, prevent abuse, debug issues and improve the service
- Comply with legal obligations
6. Legal Bases for Processing
We process your data based on the following legal grounds:
- Contract necessity: Processing required to provide the Service you signed up for (account, teams, polls, funds).
- Legitimate interests: Security, fraud prevention, service improvement and analytics, where these do not override your rights.
- Consent: Where required, especially for personalized advertising and optional analytics. You may withdraw consent at any time.
- Legal obligations: Where we must retain or disclose data to comply with applicable law.
We do not treat continued use of the Service as consent for all processing activities. Where consent is required, we ask for it separately.
7. Team Visibility and Administrator Responsibilities
Data visible within your team depends on your role and feature settings:
- Your display name, role and fund status are visible to other team members.
- Administrators and moderators can view member lists, payment records and approval requests.
- Administrators can add manual members by providing a display name. By doing so, the administrator confirms they have the authority to submit this information.
- Poll votes may be visible to other members depending on the poll settings (e.g., hidden until voted).
- Team chat messages are visible to all members of that team.
8. AI Features
Squadyy uses AI through the Google Gemini API via our backend to provide features such as balanced team splitting and text generation.
- When you use an AI feature, relevant prompts and team information may be sent through our backend to the AI provider.
- Do not enter passwords, bank details, or other unnecessary sensitive data in AI prompts.
- AI output may be inaccurate, incomplete or unsuitable. It is not professional, legal, financial or medical advice.
We do not make claims about whether the AI provider uses your data for model training, as this depends on the provider's terms and API configuration at the time of use.
9. Third-Party Providers
We use the following third-party services. Each has its own privacy policy.
| Provider | Purpose | Data Shared |
|---|---|---|
| Cloudflare Worker, D1, R2 | Application hosting, database, file storage | All application data |
| Firebase Analytics (Google) | Usage analytics and event logging | User ID, device info, app interactions |
| Firebase Crashlytics (Google) | Crash reporting and diagnostics | Crash logs, device info, app state |
| Firebase Cloud Messaging (Google) | Push notifications | FCM device token |
| Firebase Remote Config (Google) | Feature flags | App version, device properties |
| Firebase Firestore (Google) | Real-time team chat | Chat messages, FCM tokens |
| Firebase Auth (Google) | Chat authentication (custom token) | User ID for Firestore access |
| Google AdMob | Advertising for free-plan users | Ad request data, consent status |
| Google Play Billing | Subscription purchases | Purchase token, product ID, verification data |
| Google Play Integrity | App attestation and fraud prevention | Integrity token, device state |
| Google Sign-In | OAuth authentication | Email, name, profile picture, provider ID |
| Facebook Login | OAuth authentication | Email, name, profile picture, provider ID |
| Resend | Transactional email (verification, password reset, account deletion) | Email address, message content |
| Google Gemini API | AI text generation for team management features | Prompts and team information submitted by user |
We encourage you to review the privacy policies of these providers.
10. Advertising and Consent
For users on the free plan, Squadyy displays ads through Google AdMob.
- Where required by applicable law (e.g., EEA, UK, Switzerland), we use Google's User Messaging Platform (UMP) to obtain your consent before serving personalized ads.
- You may change your ad consent preferences at any time through the app settings where available.
- Our application code does not directly collect the Android advertising identifier (GAID). Ad targeting is managed by AdMob according to its own policies.
- Pro subscribers do not see ads. Users who watch a rewarded ad receive 24 hours of ad-free usage.
11. Data Retention
We retain different categories of data for different periods:
| Category | Retention Period | Notes |
|---|---|---|
| Account data (email, name, password hash) | Until account deletion | Deleted immediately upon confirmed deletion |
| Team and membership records | While team exists | Retained after member leaves; teams persist after creator deletes account |
| Payment proof images (R2) | Until account deletion | Deleted when account is deleted |
| Chat messages (Firestore) | While team exists | Managed by Firebase Firestore lifecycle |
| In-app notifications | 90 days | Not automatically purged |
| FCM tokens | Until push delivery failure | Cleaned up when token becomes invalid |
| Sessions | 30-day refresh token TTL | Expired sessions are logically invalid but rows are not auto-purged |
| Purchase verification data | While account is active | Retained for subscription management |
| Analytics and crash logs | 90 days | Managed by Firebase Analytics and Crashlytics retention settings |
| Backups | 30 days | Cloudflare infrastructure backups |
When a member leaves a team, their membership record is removed but team data (polls, funds, matches) remains for the team's continued operation.
When an account is deleted, financial and vote history may be anonymized rather than fully removed where this is necessary to maintain team record consistency.
We may retain data for longer than stated above where required by applicable law, legal proceedings, or legitimate business purposes permitted by law.
12. Account and Data Deletion
You can request deletion of your account through the following methods:
Web: Visit https://squadyy.app/delete-account, enter your email address, and follow the confirmation link sent to your inbox.
Android: Open the app, go to Profile, then look for the account deletion option.
Deletion process:
- We send a confirmation link to your registered email address.
- Click the link to confirm. The link expires after 24 hours.
- Upon confirmation, your account and associated data are permanently deleted.
- We process deletion requests promptly and in any case within 72 hours of confirmation.
What is deleted:
- Your profile (name, email, avatar, password hash)
- Login sessions and social auth connections (Google, Facebook)
- Fund contributions and payment history
- Uploaded payment proof images (from Cloudflare R2)
- Vote responses and poll votes
- Push notification tokens
- AI credit usage history
- Team membership
What is retained:
- Teams you created continue to exist for other members
- Aggregated vote counts remain (no longer linked to your identity)
- Match records and team financial data remain for team operations
- Data we must retain to comply with legal obligations
13. Security
We take reasonable measures to protect your data:
- Data in transit: All connections use TLS encryption (provided by Cloudflare's edge network).
- Password storage: Passwords are hashed using industry-standard algorithms. We do not store plaintext passwords.
- Token security: Verification codes, deletion tokens and IP addresses are stored using industry-standard one-way hashing.
- Infrastructure security: Our backend runs on Cloudflare's enterprise-grade infrastructure.
- Access controls: Team data is protected by role-based access (admin, moderator, member, guest).
Cloudflare D1 and R2 provide encryption at rest as a platform-level feature. We do not implement application-level encryption at rest for stored data such as email addresses and names.
No method of transmission or storage is 100% secure. While we strive to use commercially reasonable measures, we cannot guarantee absolute security.
13a. Security Incident Notification
In the event of a security incident that significantly affects your personal data, we may notify you and relevant authorities as required by applicable law. Notification may be delivered by email, in-app notice, or other appropriate means.
14. International Data Transfers
Your data may be processed in countries other than your country of residence. Our key service providers operate globally:
- Cloudflare processes data across its global edge network.
- Google (Firebase, AdMob, Play Billing, Gemini) processes data on servers that may be located outside your country.
- Facebook processes data according to its own international transfer mechanisms.
Where required by applicable law, we rely on appropriate safeguards such as standard contractual clauses or equivalent mechanisms provided by our service providers.
14a. Business Transfers
If Squadyy is involved in a merger, acquisition, reorganization, or sale of assets, your personal data may be transferred as part of that transaction. We will notify you of any such change and any choices you may have regarding your data, by email or through the Service.
15. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
- Access: Request a copy of your personal data we hold.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data (see Section 12).
- Data Portability: Request your data in a structured, machine-readable format.
- Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
- Objection and Restriction: Object to or request restriction of certain processing activities.
- Complaint: Lodge a complaint with your local data protection authority.
To exercise these rights, contact us at [email protected]. We may need to verify your identity before processing your request.
Withdrawing consent does not affect the lawfulness of processing carried out before the withdrawal.
16. Children
The Service is not intended for children under 16 years of age. We do not knowingly collect personal information from children under 16. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected] and we will take steps to delete that information.
Users below the applicable minimum age require authorization from a parent or guardian where legally permitted.
17. Policy Updates and Contact
Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by email. We will update the "Last updated" date at the top of this page. We encourage you to review this Policy periodically.
Contact Us
For questions about this Privacy Policy or to exercise your data rights: