Pitch is a planning tool for youth football coaches. This policy explains what personal data the app handles, why, where it is kept and what you can do about it. It is written for coaches and club officials, not for lawyers.
Who is responsible for what
Two different kinds of data live in Pitch, and they have two different owners. This split is the most important thing on this page.
- Your account. Your e-mail address, your own profile details and your app preferences. For these, [FYLL I: företagsnamn, org.nr ÅÅÅÅMM-XXXX] is the data controller — we decide how they are used, and this policy is our promise about it.
- Everything you record about other people. Players, their guardians, your fellow coaches, attendance, assessments, match notes. You — or the club you coach for — decided to write those down. You, or your club, are the data controller for them. Pitch is your data processor: we store and move that data on your instructions and do nothing else with it.
What we hold
Your account
- Your e-mail address, and the times you signed in. Pitch has no passwords — you sign in with a one-time link or code sent to that address.
- Anything you type into your own profile: name, role, phone number.
- Your language choice, stored so that messages sent to you are written in it.
- Which teams and clubs you belong to, and the plan those are on.
What you record about players
Nothing here is required by Pitch — every field is one you choose to fill in. The app can store:
- Players: name, date of birth, shirt number, position, preferred foot, kit size, photo, e-mail and phone, free-text notes (coaches use these for medical and general notes), and an emergency contact name and phone number.
- Guardians: name, e-mail, phone, relationship to the player, and the invitation code that links a guardian to their own Pitch login.
- Coaches and staff: name, role, e-mail, phone, date of birth, qualifications, notes and photo.
- Day to day: attendance, availability answers to training and matches, dated skill assessments with notes, match line-ups, per-player match ratings, scouting notes and match reports.
- Plans and messages: training sessions and drills, notes on each block, session reviews, comments between coaches (with the author name), announcements to parents, and notifications addressed to a parent e-mail address.
- Clubs: facilities and their addresses, pitches, closures, the training allocation grid, and booking and season requests together with the notes written on them.
Photos are stored inside the player or coach record itself, not as a file with its own web address. There is no link that shows a child’s photo to someone who is not allowed to see the record.
Children’s data
Most players in youth football are children. Pitch therefore holds data about minors, including dates of birth and free-text notes that in practice often contain health information. We are not going to pretend otherwise, so here is exactly how it is protected:
- Every table enforces row-level security in the database. A coach can only read rows for the teams they are a member of; a club admin only for their club. This is enforced by the database, not by the app screen.
- Player photos and notes have no public URL and are never shared outside the team.
- We do not advertise, we do not profile, and we do not sell or rent personal data to anyone. Ever.
- There is no analytics, tracking or telemetry in this app at all. No Google Analytics, no ad pixels, no session recording, no third-party SDK watching what you do.
- Player data is stored in the EU. No player’s name is ever taken from a record in Pitch and sent to the Mentor AI — not from the squad list, and not from the labels on the tactics board, which are removed before the board is sent. The one way a name can still reach it is if you type one yourself into a note or a session review; “What the Mentor sends” below says exactly where that happens.
- The community drill library is the only part of Pitch visible to coaches outside your club. It is for drills. Do not put player names in a drill you publish.
Where it is kept
- In the cloud: in a Supabase project hosted in eu-central-1 (Frankfurt, Tyskland). Database, sign-in and the sign-in e-mails all run there.
- On your device: Pitch is offline-first. A full copy of your teams’ data is kept in your browser’s own database (IndexedDB) so the app works on a pitch with no signal, and is synchronised when you are back online. That copy is not encrypted beyond whatever protection your device and browser profile give it — which is a reason to lock your phone.
- The app itself is served by Vercel. Vercel sees the ordinary traffic a web server sees, including IP addresses, in short-lived operational logs.
Who else sees it
We use three suppliers, and no others. All three act on our instructions.
- Supabase — database, accounts and transactional e-mail. Data at rest in the EU (eu-central-1 (Frankfurt, Tyskland)).
- Vercel — hosting and delivery of the app.
- Anthropic — the Mentor AI features only, and only when you use them. See the next section.
One more, worth naming because it is technically a request that leaves your device: if you export a tactics-board animation as a video, your browser downloads the video encoder from the public unpkg CDN. No app data is sent — only the request itself, which reveals your IP address. The conversion runs entirely on your device.
And one you choose. If you turn on notifications on a device, that device registers with the push service belonging to whoever made your browser — Google for Chrome and Android, Apple for Safari and iPhone, Mozilla for Firefox. We are not choosing that supplier; your browser is. The service is given a delivery address for your device and can see that a message was sent, and when. It cannot see what the message says: the text is encrypted to your device before it leaves our server, and only your browser holds the key. Turning notifications off in Settings deletes the delivery address.
What the Mentor sends
The Mentor is powered by Anthropic’s Claude models. It only runs when you press a Mentor button. Here is precisely what is put in the request, feature by feature:
- Plan a session: the theme or focus you typed, the age group, the total minutes, and the number of players available. No names.
- Design a drill / suggest a formation: only the free text you typed.
- Review or revise a session: the whole session plan — block titles, durations, intensity, equipment and any notes and review comments you wrote on it.
- Analyse the tactics board: a snapshot of the board — for each token, its side, its shirt number, whether it is the goalkeeper, and where it stands on the pitch. When the board is animated, those positions are sent for each step of the animation, because a drill is a movement and not a photograph. The labels on the tokens are removed before the request leaves Pitch, so the first names that appear when you add your squad to the board are not sent. Neither is anything else written on the board: text boxes, the name you give a zone, and the name you give a step are left out of the snapshot entirely. What travels of your notation is its geometry — an arrow’s two ends and its type, a zone’s shape and size.
What is never sent: player names — including the first names on your board tokens — dates of birth, medical or general notes on a player, contact details, guardians, photos, attendance, assessments, match records, or your account e-mail. No identifier of you or your team is attached to the request.
Pitch stores nothing from a Mentor request on its servers — the reply goes straight back to your device. Anthropic processes the request in order to answer it and may keep it for a limited period for abuse monitoring; under its commercial API terms it does not use it to train models. Anthropic processes data outside the EU, on the basis of the safeguards in its data processing agreement. [PLACEHOLDER — confirm against Anthropic’s current DPA and sub-processor list before launch.]
Finding an opponent
If your team is looking for a friendly, you can publish a listing for it — and if you are running a cup, you can announce that the same way, for other teams to apply to. Alongside the shared drill library, these are the only parts of Pitch where something you write becomes visible outside your club — so here is exactly what happens to it. Everything below is true of both kinds of advert; where a cup differs, it says so.
The listing is published on a web page of its own that needs no sign-in: anyone holding the link can read it, and other coaches see it in the app. The page shows
- the team’s display name and the club’s name,
- the birth year or age group, whether the team is boys, girls or mixed, and the play form,
- for a friendly: the range of dates you can play within, whether you want to play at home or away, and the area you typed,
- for a cup: what the cup is called, the day it is on, the area, what it costs to enter, and how many places are left,
- the message you wrote in the listing.
Nothing about a player is in it — no names, no squad, no contact details — and none of it is published until you press “Publish” yourself. You can take the listing down whenever you like. It leaves the public page the moment you take it down, when a game has been booked on it or a cup’s last place has gone, when you publish a new one instead, and when its dates — the range for a friendly, the day itself or the closing date for a cup — have passed.
Contact details are exchanged only once you have both said yes. When you do, your account e-mail address is sent to the coach of the other team, and theirs to you; on a cup, the same exchange happens between the organiser and each team they let in. That is a disclosure to a third party — the other club — with one purpose: so that the two of you can arrange the game or the cup day you have just booked. The lawful basis is giving you the service you asked for (performance of a contract) — the exchange is what saying yes means, and it does not happen unless you have. Turning an offer or an application down, taking one back, missing out because a cup filled up, or letting a listing run out discloses no contact details at all, in either direction.
Once you have booked, the two of you can write to each other in the app. Those messages go through Pitch: they are stored in the database and shown to the coach of the other team and their fellow coaches there — to nobody else, and not to us as something we read. So do not write anything about a player in the thread either: no names, no illness, nothing about why somebody cannot play. Kickoff, the pitch, the kit and a cancelled Saturday are what it is for.
After the game you can share the result with the opponent. When you do, only the goals, as numbers, are written into their fixture, turned round to their side — no scorers, no assists, no cards, no names and nothing else out of your match report. If you run a cup you can publish how the day went in the same way: a table of team names and numbers, which goes on the cup’s public page and to the teams that were there. No player is named there either. For the youngest age groups no table is published at all, only how many games each team played — Swedish children’s football keeps no tables, and the app will not let you publish one. If you switch the cup page to live on the day, the same page also shows, game by game, which games have been played and — for the age groups that keep a table — the score, as it is entered; the tables and the bracket it draws from those are the same team names and numbers. Who refereed a game stays on your own phone and on the sheet you print.
Listings, and the offers and applications made on them, are deleted no later than six months after the listing’s dates have passed — the end of the range for a friendly, the day of the cup for a cup. That is a deletion and not an unpublishing: the row and everything you wrote in it goes from the database, and the messages between you and the published table go in the same sweep, because they hang off the listing. The game booked when an offer is accepted, and the cup day put in your calendar when your application is accepted, are each team’s own — they sit in that team’s calendar and follow the ordinary account rules above.
Cookies and what sits in your browser
Pitch sets one cookie: your language choice, so the right language can be picked before the app loads. It contains no personal data and there is nothing to consent to, which is why the app has no cookie banner.
Everything else is ordinary browser storage on your own device, not sent to anyone: your sign-in token, your theme and language, the current team, an autosaved tactics board, live match clocks, onboarding flags, and — for a guardian using the parent view — the name and e-mail that guardian signed in with.
Why we are allowed to hold it
- To give you the service you asked for — this covers your account, your teams and the sync that makes the app work (performance of a contract).
- To keep the service safe and working — abuse prevention, rate limiting, error diagnosis (legitimate interests). This is why an IP address is briefly held in memory when the Mentor is called; it is used to count requests for sixty seconds and is never written to disk.
- Because the law says so — accounting records once paid plans are in use (legal obligation).
For player and guardian data, the lawful basis is not ours to choose: the club or the coach who records it decides it, and must be able to point to it.
How long
- Data you record stays until you delete it. Deleting a player, a session or a team removes it from the cloud and from every device you have signed in on.
- Delete your account and the account, and everything owned solely by it, is removed. See Deleting your account below.
- A small internal record of deletions is kept so that other devices know to delete their copies too. It holds an identifier and a timestamp, not the deleted content.
- The offline copy on a device stays on that device until you delete your account from within the app, sign out and clear the app data, or uninstall it.
Your rights
You can, at any time and without giving a reason:
- Get a copy. Settings → Data writes a JSON file holding every table Pitch keeps on your device — which, because the app keeps a full copy of everything your account is allowed to read, is the same content as the cloud’s. Export while signed in and online and the file also carries what exists only in the cloud: what you have published to the shared drill library and the comments, ratings and favourites you left there, the exercises you submitted to your club’s playbook, the requests you filed for training time, and your account’s own details. Export offline and those parts are missing — the file says so at the top rather than leaving you to assume they were empty. The one thing left out on purpose is the sync engine’s note of records already deleted, which holds ids and no content. If you want something the export does not cover, write to us.
- Correct it. Every record in Pitch is editable in the screen it belongs to.
- Delete it. Individual records anywhere in the app; the whole account under Settings → Delete account.
- Object, or ask us to restrict processing, and take your data elsewhere — the export above is a machine-readable file made for exactly that.
Write to [FYLL I: din e-postadress] and we will answer within one month. If you are a player or a guardian and your question is about what a club has recorded, ask the club — but write to us too if they do not answer, and we will make sure they can.
If you think we have got this wrong you can complain to the Swedish Authority for Privacy Protection, IMY, or to the supervisory authority where you live.
Deleting your account
Settings → Delete account removes your account for good. It is immediate and cannot be undone, so export your data first. What happens to shared data:
- Everything only you own — your teams, their players, your sessions and drills — is deleted with the account.
- Teams that belong to a club are handed to another club admin, so the club does not lose a squad because one coach left.
- If you created a club and other admins have been appointed, the club and its facilities pass to the longest-serving of them.
- If you created a club and you are its only admin, the club is deleted with you, and its teams and grounds go with it. The app warns you by name before this happens. Appoint a second admin first if that is not what you want.
Security
- Everything travels over HTTPS.
- Access is enforced in the database itself with row-level security, so a bug in a screen cannot show one coach another club’s squad.
- Sign-in is by one-time link or code — there is no password to leak or reuse.
- Sensitive server operations run through audited database functions with fixed permissions rather than open table access.
No system is perfect. If you find a security problem, please write to [FYLL I: din e-postadress] before telling anyone else, and we will fix it.
Changes to this policy
When this policy changes, the date at the top changes and the new version appears here. If a change matters — a new supplier, a new kind of data — we will tell you in the app before it takes effect.
Contact
[FYLL I: företagsnamn, org.nr ÅÅÅÅMM-XXXX]
[FYLL I: gatuadress, postnummer, ort, Sverige]
[FYLL I: din e-postadress]