NextPlay
Sign In
Back to Home

Privacy Policy

Effective Date: September 8, 2026

Xphere LLC, a Maryland limited liability company (xphere.org), operates NextPlay ("NextPlay," "we," "us," or "our") and is the controller responsible for the information described here. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information when you use the NextPlay website, native iOS and Android applications, and sports-statistics services (collectively, the "Service").

Where consent is required, we request it separately, including through device permission prompts.

Privacy questions, requests, and complaints go to the NextPlay privacy contact at support@nextplay.team, which reaches the Xphere LLC personnel responsible for privacy, account deletion, and safety matters.

1. Information We Collect

A. Account, Identity, and Subscription Information

  • Account and Authentication: We collect your name, email address (including an Apple private-relay address if selected), internal user identifier, authentication-provider identifier, login and security information such as session tokens, profile type, administrator status, and age-verification status. We do not store the profile photo from Google or Apple Sign In. Player-profile avatars and generated avatar images are collected only if you create or upload them. During age verification we ask you to enter your date of birth in the website or mobile app; we use it only to confirm you are at least 13 and do not store the date of birth. We store an age-verification timestamp. Production sign-in uses Google on the website, Google or Apple in the iOS app, and Google in the Android app.
  • Profiles and Relationships: We collect profile type and preferences, guardian and player-profile relationships, team membership, claim and follow requests, blocks, and visibility settings.
  • Subscriptions and Payments: Paid subscriptions are purchased on the NextPlay website, not in the iOS or Android apps. Stripe processes payment-card details; NextPlay does not store full card numbers. We store Stripe customer identifiers, plan, subscription status, billing period, and cancellation status to provide the correct account access.
  • Communications: If you contact us, we collect your contact details and the contents of the communication.

B. Sports Data and User Content

  • Sports and Youth Data: We collect player names or pseudonyms, under-13 profile status, teams, rosters, seasons, games, schedules, positions, statistics, events, coaching focus items, and related sports information that users enter or ask us to extract.
  • Photos and Video: We collect scorebook and roster images, avatar source and generated images, chat images, game photos, game video, captions, tags, reactions, and associated editing or deletion activity.
  • Audio, Transcripts, Notes, and Chat: If you use voice or live-reporting features, we collect raw audio, transcripts, extracted game actions, notes, and player names plus related sports vocabulary sent as transcription hints so the speech-to-text provider can recognize what you said. We also collect text notes, team chat messages, replies, reactions, and attachments.
  • Automated Safety Screening: Before certain user-generated text or media is saved or published, we process the submitted content and limited context about the type of submission to identify prohibited or unsafe material. Covered text includes team names, player display names, media descriptions, and chat messages. Screening may allow or reject a submission, or ask you to try again if the check cannot be completed.
  • Sharing Information: We collect share codes, links, and visibility settings. Games may be Private, Unlisted, or Public. Player profiles may be Private, Code, or Team. Teams and some games and player profiles can be opened with a share code or link. Game photos and videos inherit the visibility of the game they belong to; they do not have a separate public/private control.
  • Safety Reports and Appeals: We collect report categories, optional descriptions, references to reported content, controlled evidence metadata, reporter and reported-account identifiers, moderation actions, restriction and block information, appeal statements and decisions, and an audit history.

C. Device, Usage, and Technical Information

  • Device and Network Information: We collect IP address, browser type, operating system, device platform and model or device name, and request and security logs.
  • Push Notifications: If allowed, we collect an Expo push token, device platform (iOS or Android), device name, registration time, and delivery-failure status. You may turn notifications off in iOS Settings or Android system settings, which stops system delivery to that device. Signing out of the mobile app unregisters the token with NextPlay. There is no in-app notification-off toggle.
  • Product Usage: On the website, Amplitude receives a pseudonymous analytics identifier, page and feature interactions, paths and search parameters, profile area, and account attributes such as name, email, age-verification status, profile type, and subscription status. The iOS and Android apps do not currently include the Amplitude analytics SDK.
  • Diagnostics: Sentry receives production server error and diagnostic information, which may include identifiers, IP address, request headers and context, log breadcrumbs, and details associated with a failed request. The iOS and Android apps do not currently include a Sentry mobile SDK.
  • Cookies and Similar Technologies: The website uses authentication cookies, local browser storage, and similar technologies needed to sign you in, remember settings, secure the Service, and support web analytics.
  • Unauthenticated Usage: If you participate in live game reporting using a shared code, we collect submitted reports, audio, and related information even without a registered account. That session also receives the game's roster names so you can attribute plays, and those names are sent as transcription hints.

D. Device Permissions

Camera, photo-library, microphone, and notification access are optional and requested only when you use a feature that needs them. You can revoke these permissions in iOS Settings or Android system settings, although affected features may stop working.

E. Why We Collect Each Category, and What Is Optional

This table lists every category of personal information the native iOS and Android apps and the Service collect, why we collect it, and whether you can use NextPlay without providing it. "Required" means the Service cannot function without it. "Optional" means the feature that collects it is one you choose to use, and declining it leaves the rest of the Service working.

CategoryWhy we collect itRequired or optional
Authentication identity (email, provider identifier, Apple private-relay address)To create your account, sign you in, and keep sessions secureRequired to have an account
Account details (name, avatar, preferences)To identify you to your teams and apply the right permissionsName required; avatars optional
Declared age and age-verification statusTo apply under-13 Guardian Profile rules and meet children's-privacy obligations. Date of birth is requested only to confirm you are at least 13 and is not storedRequired
Sports and youth data (players, rosters, games, statistics, events)To provide the core statistics-tracking product and screen submitted names for prohibited contentRequired for the core product; you choose what you enter
Photos and images (scorebooks, rosters, chat images, game photos, avatar sources)To extract statistics, build rosters, share game-day media, and screen uploads and descriptions for prohibited contentOptional to upload; screened when submitted — camera and photo permission requested only when used
Video (game video, samples)To extract statistics and generate highlights from footage you uploadOptional
Audio (voice notes, live-reporting recordings)To transcribe what you say into game events and notesOptional — microphone permission requested only when used
Transcripts and extracted actionsTo turn recordings into reviewable, correctable game dataCollected only when you use audio features
Chat messages, replies, and attachmentsTo provide team chat and screen submissions for prohibited contentOptional to submit; screened when submitted
ReactionsTo provide lightweight responses to media and messagesOptional
Coaching notes and focus itemsTo store and generate the coaching material you ask forOptional
Device model and platformTo deliver notifications correctly and diagnose device-specific faultsCollected with push registration and request logs
IP addressTo secure the Service, rate-limit abuse, and investigate security incidentsRequired — generated by the network connection itself
Expo push tokenTo deliver notifications to your deviceOptional — only if you allow notifications
Usage and security logsTo operate, troubleshoot, and protect the ServiceRequired for server logs; web analytics described above
Subscription statusTo grant the account access your plan includesRequired if you subscribe; the mobile apps only read this status
Safety reports, appeals, and support messagesTo review reports, protect users, and answer youOptional — collected when you contact us or use safety tools

Declining an optional category disables only the feature that needs it. You can revoke camera, photo-library, microphone, and notification permission at any time in iOS Settings or Android system settings, and Section 9 explains how to withdraw consent and delete information you already provided.

F. Sources of Information

We receive information directly from you; from coaches, team administrators, guardians, players, and other users who create teams, rosters, games, reports, or shared content; automatically from your browser, device, and use of the Service; from Apple and Google when you sign in; from Stripe for subscription and transaction status; and from the service providers in Section 3 when they return processing, delivery, security, analytics, or diagnostic results. If you provide information about another person, you are responsible for having authority to do so and for giving them any notice required by law.

2. How We Use Information

  • To create and secure accounts, authenticate users, maintain sessions, and enforce account and team permissions.
  • To provide teams, games, statistics, media, chat, notes, sharing, notifications, support, and subscription-based access.
  • To process images, video, and audio; produce transcripts and structured sports data; generate coaching insights, highlights, and avatars; and return results to users.
  • To screen covered user-generated text and media for prohibited or unsafe content before it is saved or published, and temporarily prevent submission when screening cannot be completed.
  • To operate, troubleshoot, measure, and improve the Service and communicate about accounts, support requests, and material changes.
  • To detect fraud, abuse, security incidents, repeated violations, and ban evasion, and comply with legal obligations.
  • To review reports, protect minors and other users, restrict or remove prohibited content, enforce restrictions or bans, review appeals, and document moderator decisions.

We do not sell personal information or use it for third-party targeted advertising.

3. Service Providers and Other Disclosures

  • Hosting and Storage: Amazon Web Services stores and processes application content and generated results — S3 holds uploaded and generated media and raw processing files, and Lambda runs image, video, and transcript processing steps. Heroku (Salesforce) hosts the application server, its database, and its backups. Google Firebase hosts the website. A managed Redis instance holds cached values, background-job payloads, and real-time chat delivery in transit; it is working storage, not a system of record, and its contents are transient.
  • Authentication and Platform Services: Apple and Google provide sign-in services. Apple also provides iOS platform and push-delivery services, and Google provides Android platform services and Firebase Cloud Messaging push delivery.
  • Payments: Stripe processes website subscriptions and payment information.
  • AI, Safety Screening, and Transcription: Contracted service providers receive the user content and limited contextual data needed to perform automated safety screening, transcription, extraction, generation, and other supported AI features. Today those providers are OpenRouter (an AI gateway that may route a request to model providers such as OpenAI, Google, and MiniMax) and ElevenLabs (speech-to-text). OpenRouter chat-completions requests from NextPlay, including AWS Lambda processing, are sent with a setting that asks providers not to collect the content for training or storage, where that setting is available. These providers may use subprocessors to deliver their services. Vendors in this category may change; we update this policy when our processing practices materially change. Section 4 explains our automated processing and training practices.
  • Notifications: Expo, Apple Push Notification service on iOS, and Google Firebase Cloud Messaging on Android process push tokens, notification payloads, and delivery results.
  • Analytics and Diagnostics: Amplitude processes the web analytics and account attributes described above. Sentry processes production server diagnostics and request context.
  • Public or User-Directed Sharing: Content set to public, unlisted, team, code, or link visibility is disclosed according to the selected setting. Public and unlisted team and game pages show a site-generated pseudonym instead of a player's real name by default. If a player profile is set to Team visibility, the profile display name and avatar may appear in team contexts, including public team pages.
  • Legal and Safety: We may disclose information in response to valid legal process or when reasonably necessary to protect rights and safety, address child exploitation or credible imminent harm, or comply with law. We do not disclose a reporter's identity to the reported user.
  • Business Transfers: Information may be disclosed as part of a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets, subject to this policy and applicable law.

The categories above describe the production service providers that may receive personal information from NextPlay. We require service providers that receive personal information to use it only to deliver their services and to maintain privacy and security protections consistent with this policy and applicable law. Processing may occur in the United States or other countries where a provider or its subprocessors operate. Vendors within a category may change as our Service evolves; we update this policy when our processing practices materially change.

4. AI and Automated Processing

NextPlay uses automated systems to screen user-generated content for prohibited or unsafe material, transcribe audio, extract sports information, validate or generate images, and create insights and highlights. These systems may send the content and limited context needed for the applicable function to the service providers described in Section 3. Automated results can be inaccurate; review generated results before relying on or publishing them.

Automated safety screening. Covered user-generated text — team names, player display names, media descriptions, and chat messages — is checked before it is saved. A check may reject content that appears to violate our rules, permit it, or temporarily prevent submission and ask you to try again when screening is unavailable. Text screening is required for those fields and cannot be disabled. Photos and videos are processed after upload: descriptions are screened as text; video may be sampled for automated review; image-file screening depends on a configured media provider and may quarantine, allow, or fail closed depending on configuration.

Training. Xphere LLC does not train or fine-tune any AI model on your content, and we do not sell, license, or otherwise supply your content to anyone as training data. Service providers that assist with automated processing handle content under their terms and our account configuration or agreement with them, and may use subprocessors to deliver their services.

Choices. You can avoid optional AI and voice processing by not using those features. Safety screening is part of submitting covered user-generated content; if you do not want that content processed for safety, do not submit it. You may continue using portions of the Service that do not require that content.

5. Privacy Features and Player Protection

  • Pseudonymization: Unlisted and public games and team pages show site-generated pseudonyms instead of real player names by default. A player profile set to Team visibility may disclose that profile's display name and avatar in team contexts, including public team pages.
  • Visibility Controls: Users can choose available game visibility (Private, Unlisted, or Public) and player-profile visibility (Private, Code, or Team). Game media follows the game's visibility. Teams are shared with a share code or link rather than a separate Private/Unlisted/Public control.
  • Mapping Access: Coaches and authorized team administrators can see roster names alongside pseudonyms for teams they manage. A player (or a guardian viewing a Guardian Profile they manage) can see that profile's display name. Public visitors see a pseudonym unless the profile is set to Team visibility.
  • Guardian Profiles: Guardian-managed player profiles are constrained to private visibility.

6. Children's Privacy

Children under 13 may not create NextPlay accounts. The age gate deletes an account that self-reports as under 13. A parent or authorized guardian who is 13 or older may create their own account and manage a Guardian Profile containing a child's sports information (a private player identity on the guardian's account, not a login for the child). The person creating the Guardian Profile represents that they are the child's parent or are otherwise authorized to provide the child's information and directs us to collect and use it as described in this policy.

Roster entries without a Guardian Profile. Coaches and team administrators can create under-13 roster entries without a Guardian Profile. New roster players default to under-13 unless the coach or administrator marks otherwise, including when a roster is entered manually or imported from an image. That default roster path is how most child sports information is collected. Authorized team users who submit that information represent they have the consent described in the Terms of Service. We do not treat authorized team-submitted child data as unauthorized collection, and we do not delete it solely because it is not attached to a Guardian Profile.

Information about children. Depending on what the guardian, coach, or other authorized team user provides, child information may include the child's name or pseudonym, under-13 status, avatar or photo, team and roster relationships, games, schedules, positions, statistics, events, notes, media, reactions, and the safety information described in Section 1. A Guardian Profile stays private and cannot use the Private, Code, or Team player-profile sharing settings in Section 1. Games and teams the child is on can still be Private, Unlisted, or Public. Public and unlisted team and game pages may show a site-generated pseudonym, under-13 status, statistics, media that follows the game, and a parent/guardian claim prompt. Coaches and authorized team administrators can see roster names alongside those pseudonyms. We use this information to provide and protect the sports features requested by the guardian and authorized team users, and disclose it to the providers and authorized users described in Sections 3 and 5. We do not condition participation on providing more child information than is reasonably necessary for the selected feature.

Guardian controls. A parent or authorized guardian may review or correct a child's Guardian Profile in the Service, delete content where controls are available, or contact us to request access to or deletion of the child's information or to stop further collection or use. We verify the requester's identity and authority before granting access or acting on a request. Deletion is subject to the narrow safety, legal, shared-content, provider, and backup limitations in Section 7.

If we learn that a child under 13 independently created an account or otherwise provided personal information without the required authority, we will take reasonable steps to delete it. Authorized coach or team-administrator roster entries are not treated as unauthorized. Contact us immediately if you believe a child submitted information without authority or that a roster entry was created without the required consent.

7. Retention and Account Deletion

We keep each category only as long as the criterion below is met, and we delete, de-identify, or aggregate it once that criterion no longer applies. Where a category has no fixed clock, the stated criterion is the retention rule.

  • Account records: Retained while your account exists. Deleting your account removes the primary user record and in-scope account content from active systems immediately, subject to the exceptions below.
  • Sports data, media, chat, notes, and sharing records: Retained while the account or the related team or game is active, because the data belongs to a shared team history other members still rely on. Removed when you delete it, when the owning team or game is deleted, or when it falls within a deleted account's deletion graph. That graph includes teams and games you created, even if other people were members.
  • Raw voice and live-reporting audio: Retained after transcription while the related team, game, or account is active, so a transcript can be re-derived or corrected. Raw processing files sit in object storage separately from account records, so deleting them can require a separate cleanup — contact us if you need a specific raw file removed.
  • Transcripts and extracted actions: Retained on the same basis as the game or note they belong to, because they are the reviewable record of that game.
  • Server, request, and security logs: Retained for the period our hosting platform's log retention provides, and beyond that only where a specific security incident, abuse investigation, or legal obligation requires it. These logs are not used to build user profiles.
  • Diagnostics (Sentry): Retained for the retention window configured in our Sentry account and deleted on that schedule. We keep error data only long enough to diagnose and fix the fault it records.
  • Web product analytics (Amplitude): Retained for the retention window configured in our Amplitude account. Analytics apply to the website only; the mobile apps do not include the Amplitude SDK.
  • Push tokens: Retained while the device stays registered. Signing out of the mobile app unregisters the token. A token that Expo reports as permanently unregistered is marked failed and is no longer used for delivery. Tokens are deleted when the account is deleted. Turning notifications off in iOS Settings or Android system settings stops system delivery; the stored token may remain until the app unregisters it, a later delivery fails, or the account is deleted.
  • Payment and subscription records: Retained as long as tax, accounting, billing, chargeback, and fraud-prevention obligations require — a period set by law rather than by us, and typically measured in years after the transaction. Stripe retains its own records under its own policy.
  • Safety reports, evidence metadata, enforcement actions, appeals, and audit events: Retained after content or account deletion while reasonably needed for safety, appeal review, fraud and ban-evasion prevention, disputes, or legal compliance. Records establishing a permanent ban or relating to child-safety matters are kept as long as the safety purpose lasts, because deleting them would let the banned conduct resume. Access is limited to authorized moderation personnel.
  • Deletion and cleanup records: A restricted retry record is kept until provider and attachment cleanup succeeds, then removed. It contains only what the cleanup needs and no user foreign key.
  • Backups: Disaster-recovery backups follow our hosting provider's backup lifecycle and are overwritten or expire on that rolling schedule. Deleted information may persist in a backup until it expires, and backups are restored only for disaster recovery, never to reinstate individually deleted data.

If a legal hold, an open dispute, or an active safety investigation applies, we retain the affected information until that matter closes, and then apply the criteria above.

What account deletion actually does

You can permanently delete your account from the iOS or Android app. The website does not currently include a self-serve delete control; email support@nextplay.team and we will delete the account after we verify your identity. Deletion is immediate and cannot be undone. Specifically:

  • Your account and content: The primary user record and the account content within its deletion graph are removed from active systems in a single transaction. The Service confirms deletion only after that removal completes.
  • Registered devices: Push device registrations are deleted, and your device stops receiving notifications.
  • Stored files: Owned avatar, chat-image, and game-media objects are detached, and their original and generated variants are staged for removal from object storage. Because that cleanup runs against an external storage provider, it may continue through a restricted retry record until it succeeds.
  • Public and shared content: Content you own that was shared publicly, by link, by code, or with a team is removed when it falls within your account's deletion graph. Share links to it stop resolving.
  • Content involving other users: Content owned by another user does not disappear because you deleted your account. A top-level chat message of yours may remain as an identity-free thread tombstone where deleting it would destroy other people's replies; the tombstone carries no name, no identifier, and none of your original text. Teams and games you created are removed, including for other members. Copies other users independently saved or exported are outside our control.
  • Apple and Stripe: Where applicable, we revoke the Apple sign-in token and de-link or delete the connected Stripe customer record. Stripe still retains its own transaction history under the payment-record criterion above, because tax and accounting law requires it.
  • Provider copies: Content already sent to an AI or transcription provider to fulfill a request you made is handled under that provider's retention terms. We do not hold a copy on your behalf after deletion, and we cannot compel a third-party provider's independent retention schedule.
  • Backups: Deleted information may remain in disaster-recovery backups until those backups expire on the rolling schedule described above. We do not restore a backup to reinstate deleted data.
  • Safety and legal records: The limited safety, audit, payment, backup, legal-hold, and cleanup-retry records described above may remain, for the reasons and durations stated.

Contact us at the address below if you need help deleting a specific item, a raw processing file, or information held under a Guardian Profile.

8. Security

We use reasonable administrative, technical, and organizational safeguards, including encrypted network transport, storage-provider encryption at rest, access controls, and authentication safeguards. No method of storage or transmission is completely secure.

9. Your Rights and Choices

Depending on where you live, you may have rights to access, know about, correct, delete, or receive a copy of personal information; object to or restrict certain processing; withdraw consent; or appeal a privacy-request decision. We do not discriminate for exercising applicable privacy rights.

Withdrawing consent and revoking permissions. In short: you can update account and visibility settings in the Service, permanently delete your account from the mobile app or by contacting us, revoke camera/photo/microphone/notification permissions in iOS Settings or Android system settings, and manage website cookies or local storage through your browser. Every optional collection in Section 1.E can be switched off, and each one is switched off in a specific place:

  • Camera, photo library, and microphone: revoke in iOS Settings → NextPlay, or in Android Settings → Apps → NextPlay → Permissions. The app can no longer capture or upload new media or audio. Revoking permission does not delete media you already uploaded — delete that content in the Service, or delete your account.
  • Notifications: turn off in iOS Settings → NextPlay → Notifications, or in Android Settings → Apps → NextPlay → Notifications, to stop system delivery to that device. Signing out of the mobile app unregisters the push token with NextPlay. There is no in-app notification-off control.
  • AI, voice, and safety-screened features: stop using optional AI or voice features to avoid new processing for those features. Safety screening is required when you submit covered user-generated content as described in Section 4; to avoid that processing, do not submit the covered content.
  • Sharing and visibility: change a game or player-profile visibility setting at any time. Game media follows the game. Making something private stops new access; it cannot retrieve what someone already saw or saved.
  • Website cookies and local storage: manage or clear them through your browser. Website analytics apply only to the website.
  • Your whole account: delete it in the iOS or Android app, or email support@nextplay.team from the website, as described in Section 7.

Withdrawing consent applies going forward and does not undo processing that already, lawfully, occurred. Withdrawing a permission the Service needs for a feature disables that feature, not the rest of the Service.

Making a request. You can update available account and visibility settings yourself. For any other privacy request — access, correction, deletion, a copy of your information, objection or restriction, or an appeal of a privacy decision — contact us at the address below. We may need to verify your identity, or your authority over a child's Guardian Profile, before completing a request, and we will say so if we do.

U.S. state privacy rights. Where applicable, you may ask us to confirm whether we process your personal information; access, correct, delete, or obtain a portable copy of it; and appeal our response. You may use an authorized agent where applicable, but we may ask for proof of the agent's authority and may verify your identity directly. We do not sell personal information for money, share it for cross-context behavioral advertising, use it for targeted advertising, or profile users to make decisions that produce legal or similarly significant effects. We therefore do not offer opt-outs for activities we do not perform. We use sensitive information, including account credentials and information concerning children, only to provide, secure, and protect the Service and for other purposes permitted without a right to limit under applicable law.

Browser signals. Because we do not sell or share personal information for targeted advertising, Global Privacy Control and Do Not Track signals do not change how we process information. We do not track users across unaffiliated services for targeted advertising.

How we respond. Describe the right you want to exercise and the account or child profile involved. We will confirm receipt and respond within the period required by applicable law. If we deny a request, we will explain why and, where applicable, how to appeal or contact the relevant regulator. We may deny or limit a request where an exception applies, including where we cannot verify the requester, must protect another person's rights, or must retain information for security or legal compliance.

10. Legal Bases and International Transfers

If privacy law in your location requires a legal basis, we process information as necessary to perform our contract with you and provide requested features; for our legitimate interests in operating, securing, improving, and enforcing the Service, balanced against your rights; to comply with law and protect vital interests; and with consent where required, such as for optional device permissions. Where we rely on consent, you may withdraw it as described in Section 9. Where we rely on legitimate interests, you may object by contacting us.

Information may be processed and maintained outside your state, province, or country, primarily in the United States. Where required, we use legally recognized transfer mechanisms and safeguards. Contact us to ask about the safeguard applicable to a transfer or to request a copy where the law provides that right.

If you are in the European Economic Area or United Kingdom, you may lodge a complaint with the data-protection authority where you live or work, although we encourage you to contact us first so we can try to resolve the concern.

11. Changes to This Policy

We may update this Privacy Policy to reflect changes to the Service, our practices, or law. We will post the revised policy, update the Effective Date, and provide additional notice when required for material changes.

NextPlay is operated by Xphere LLC, a Maryland limited liability company, xphere.org.

For privacy questions or requests, account deletion help, or moderation privacy concerns, contact the NextPlay privacy contact:

support@nextplay.team

This address is monitored by the Xphere LLC personnel responsible for privacy requests, account deletion, and safety reports, and is the contact of last resort for a user who cannot use the in-product appeal flow. We acknowledge privacy requests and respond within the time applicable law allows, and we will tell you if we need to verify your identity or your authority over a child's profile before acting.

Read the Community Standards