Xphere LLC operates NextPlay ("NextPlay," "we," "us," or "our"). This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you use the NextPlay website, native iOS application, and sports-statistics services (collectively, the "Service").
Where consent is required, we request it separately, including through device permission prompts.
1. Information We Collect
A. Account, Identity, and Subscription Information
- Account and Authentication: We collect your name, email address (including an Apple private-relay address if selected), profile picture, internal user identifier, authentication-provider identifier, login and security information, account role, and declared age or age-verification status. The Service supports Google, Apple, and, in limited contexts, email/password authentication.
- Profiles and Relationships: We collect profile type and preferences, guardian and player-profile relationships, team membership, claim and follow requests, blocks, and visibility settings.
- Subscriptions and Payments: Paid subscriptions are purchased on the NextPlay website, not in the iOS app. Stripe processes payment-card details; NextPlay does not store full card numbers. We store Stripe customer identifiers, plan, subscription status, billing period, and cancellation status to provide the correct account access.
- Communications: If you contact us, we collect your contact details and the contents of the communication.
B. Sports Data and User Content
- Sports and Youth Data: We collect player names or pseudonyms, under-13 profile status, teams, rosters, seasons, games, schedules, positions, statistics, events, coaching focus items, and related sports information that users enter or ask us to extract.
- Photos and Video: We collect scorebook and roster images, avatar source and generated images, chat images, game photos, game video, captions, tags, reactions, and associated editing or deletion activity.
- Audio, Transcripts, Notes, and Chat: If you use voice or live-reporting features, we collect raw audio, transcripts, extracted game actions, notes, and related player or team names used to improve transcription accuracy. We also collect text notes, team chat messages, replies, reactions, and attachments.
- Sharing Information: We collect share codes, links, visibility settings, and records needed to determine who may access content.
- Safety Reports and Appeals: We collect report categories, optional descriptions, references to reported content, controlled evidence metadata, reporter and reported-account identifiers, moderation actions, restriction and block information, appeal statements and decisions, and an audit history.
C. Device, Usage, and Technical Information
- Device and Network Information: We collect IP address, browser type, operating system, device platform and model or device name, and request and security logs.
- Push Notifications: If allowed, we collect an Expo push token, device platform, device name, registration time, and delivery-failure status. You may disable notifications in iOS Settings.
- Product Usage: On the website, Amplitude receives a pseudonymous analytics identifier, page and feature interactions, paths and search parameters, profile area, and account attributes such as name, email, age-verification status, profile type, and subscription status. The iOS app does not currently include the Amplitude analytics SDK.
- Diagnostics: Sentry receives production server error and diagnostic information, which may include identifiers, IP address, request headers and context, log breadcrumbs, and details associated with a failed request. The iOS app does not currently include a Sentry mobile SDK.
- Cookies and Similar Technologies: The website uses authentication cookies, local browser storage, and similar technologies needed to sign you in, remember settings, secure the Service, and support web analytics.
- Unauthenticated Usage: If you participate in live game reporting using a shared code, we collect submitted reports, audio, and related information even without a registered account.
D. Device Permissions
Camera, photo-library, microphone, and notification access are optional and requested only when you use a feature that needs them. You can revoke these permissions in iOS Settings, although affected features may stop working.
2. How We Use Information
- To create and secure accounts, authenticate users, maintain sessions, and enforce account and team permissions.
- To provide teams, games, statistics, media, chat, notes, sharing, notifications, support, and subscription-based access.
- To process images, video, and audio; produce transcripts and structured sports data; generate coaching insights, highlights, and avatars; and return results to users.
- To operate, troubleshoot, measure, and improve the Service and communicate about accounts, support requests, and material changes.
- To detect fraud, abuse, security incidents, repeated violations, and ban evasion, and comply with legal obligations.
- To review reports, protect minors and other users, restrict or remove prohibited content, enforce restrictions or bans, review appeals, and document moderator decisions.
We do not sell personal information or use it for third-party targeted advertising.
3. Service Providers and Other Disclosures
- Hosting and Storage: Amazon Web Services, including S3 and Lambda, stores and processes application content and generated results. Heroku/Salesforce hosts application services. Google Firebase hosts the website.
- Authentication and Platform Services: Apple and Google provide sign-in services. Apple also provides iOS platform and push-delivery services.
- Payments: Stripe processes website subscriptions and payment information.
- AI and Transcription: OpenRouter and model providers selected through OpenRouter process prompts, images, audio, transcripts, and structured sports data for supported features. Fireworks AI supports certain model and transcription operations. ElevenLabs receives short-lived links to audio and relevant key terms, which may include player names, to generate transcripts.
- Notifications: Expo and Apple Push Notification service process push tokens, notification payloads, and delivery results.
- Analytics and Diagnostics: Amplitude processes the web analytics and account attributes described above. Sentry processes production server diagnostics and request context.
- Public or User-Directed Sharing: Content set to public, unlisted, team, code, or link visibility is disclosed according to the selected setting. Public team and game pages use privacy-aware player display values by default.
- Legal and Safety: We may disclose information in response to valid legal process or when reasonably necessary to protect rights and safety, address child exploitation or credible imminent harm, or comply with law. We do not disclose a reporter's identity to the reported user.
- Business Transfers: Information may be disclosed as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this policy and applicable law.
We require service providers that receive personal information to use it only for contracted services and to maintain privacy and security protections consistent with this policy and applicable law.
4. AI and Automated Processing
5. Privacy Features and Player Protection
- Pseudonymization: Unlisted and public games use site-generated pseudonyms instead of real player names where supported.
- Visibility Controls: Users can choose available team, game, media, and player-profile visibility options.
- Mapping Access: Only the game owner and authorized administrators can view the mapping between real player names and pseudonyms.
- Guardian Profiles: Guardian-managed player profiles are constrained to private visibility.
6. Children's Privacy
7. Retention and Account Deletion
- Accounts and Content: Account records, sports data, media, chat, notes, transcripts, subscription status, and sharing records are generally kept while the account or related team/game is active. Raw voice and live-reporting audio may remain after transcription while the related team/game/account is active and for limited operational troubleshooting. Because raw processing files are stored separately from account records, a request to delete them may require additional object-storage cleanup.
- Analytics, Logs, and Diagnostics: These records remain for the period configured in the applicable production system or provider account, then are deleted, de-identified, or aggregated when no longer reasonably needed.
- Payments: Stripe and NextPlay may retain transaction and subscription records for billing, tax, accounting, fraud prevention, disputes, and legal compliance.
- Safety and Moderation: Safety reports, controlled evidence, enforcement actions, ban-prevention records, appeals, and audit events may remain after account deletion while reasonably needed for safety, appeal review, fraud or ban-evasion prevention, disputes, or legal compliance.
- Backups: Deleted information may remain in restricted disaster-recovery backups until the relevant backup is overwritten or expires and is not restored except for disaster recovery.
Deleting an account permanently removes the primary user record and in-scope account content from active systems, removes registered push devices, and starts deletion or de-linking of owned stored attachments and connected Apple or Stripe account data where applicable. Restricted provider or attachment-storage retry records may remain until cleanup succeeds. A top-level chat message may remain as an identity-free thread tombstone when needed to preserve other users' replies. Public/shared content owned by the account is removed when it is within the account deletion graph; independently owned content may remain. Limited safety, audit, payment, backup, legal, and retry records may also remain. Contact us if you need help deleting specific information or a raw processing file.
8. Security
9. Your Rights and Choices
Depending on where you live, you may have rights to access, know about, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a privacy-request decision.
You can update available account and visibility settings, permanently delete your account in the iOS app or through the Service, revoke camera/photo/microphone/notification permissions in iOS Settings, disable push notifications, and manage website cookies or local storage through your browser. Withdrawing permission does not affect processing that already occurred. Contact us to make another privacy request; we may need to verify your identity or authority over a child's profile.
10. International Transfers
11. Changes to This Policy
For privacy questions or requests, account deletion help, or moderation privacy concerns, contact Xphere LLC:
support@bot-trap.@nextplay.spam..team
Read the Community Standards