iTala is a basketball scorekeeping app. It records games, rosters and statistics for leagues and casual drop-in games. This policy explains what it stores, who can see it, and how to get information removed. It is published by Hanna Abejo Santos and Harold Abejo, who together run the iTala service and are jointly responsible for the information described here.
1. Two ways the app can run
iTala can be built without any server configuration. In that local-only mode there is no sign-in, nothing is uploaded, and everything stays in the app's storage on that one device. Nothing in this policy about servers, sharing or other users applies to a local-only build.
The synced build, which is intended for distribution through the App Store and Google Play, stores data on a server so several devices can follow the same game. It also stores basketball records locally for offline use. Changes made while offline can remain in an on-device queue and are sent when a connection becomes available. The rest of this policy describes the synced build.
2. What we collect
Your account
- Email address, from Google or Apple sign-in. Used to identify you and to decide what you are allowed to do: own a league, keep score, or administer.
- Name, as supplied by Google or Apple, and a Google profile-image URL when Google supplies one. Shown to you in the app; your name is visible to owners of leagues you have been added to. Apple does not supply a profile photo to iTala.
- A user ID, generated by our authentication provider. Spectators who have not signed in are given an anonymous session, which also has an ID.
If you use Sign in with Apple and choose to hide your email address, we receive the Apple relay address rather than your real one, and that is what we store.
We also store authentication session tokens on the device so you remain signed in. During Google sign-in, a temporary PKCE verifier is stored on the device to complete the secure sign-in flow.
What you enter into the app
- League and season names; league settings and owner or scorekeeper memberships.
- Team names, colours, coach or manager names, and roster membership.
- Player names and jersey numbers, and every statistic recorded against a player: shots, points, rebounds, assists, steals, blocks, turnovers, fouls, lineups, attendance, and the season and career totals derived from them.
- Team logos and sponsor images, if you choose a photo from your device library. These are stored as image data on the server.
- The venue you type onto a game, plus the date and time. This is free text. If you type a private address, that address is stored and is readable by other users of the app. It is not device location: the app never asks for, and cannot read, where your phone is.
Content reports and privacy requests
If you report information through the app, we collect the reported content type and identifiers, league and optional team identifiers, report reason, any explanation you provide, your app-session user ID (including for anonymous spectators), submission time, and an optional contact email. We also store a report reference and a request identifier to prevent duplicate submissions, together with the report's review status, resolution notes, reviewing administrator's ID and review time. For requests sent by email, we receive your email address and the information you send.
Reports are not public league records. Within iTala, reports and review records are visible only to authorised iTala administrators, not other users or league owners merely because they own a league. We use them to investigate concerns, communicate with you where contact information is provided, correct or remove information, prevent abuse and document our response. Service-provider processing and legally required disclosures are described in section 7. Please do not include passwords or unnecessary sensitive information in a report.
Legal acknowledgement
We store your account user ID, the version of the legal documents you accept and a server-generated acceptance time. A copy of the receipt is cached on your device to support offline account restoration. These records document acceptance and determine whether a further acknowledgement is needed. Server receipts are deleted with your account.
Photos, sharing and permissions
If you choose a team logo or sponsor image, iTala asks for photo-library access and processes only the image you select for that purpose. iTala does not request camera, microphone, contacts or device-location access. If you ask iTala to share a score or stat card, it sends the generated image or text to the app or person you select through your device's share function.
Sponsor promo taps
Some builds show sponsor cards. When one is tapped, the app increments a counter on that sponsor card so the operator can see how many taps it received. It is a single number per card. No user ID, device ID, timestamp or any other detail is recorded with it, so a tap cannot be traced back to a person.
If a sponsor card opens a website or another app, that destination may receive ordinary connection information and handles it under its own privacy terms.
What stays on your device
iTala stores its basketball records, unsent synchronization queue and authentication session in local app storage. A synced build can therefore cache records downloaded from Supabase, not only records created on that device. Your favourite and recent leagues and teams, membership hints, tap-feedback preference, first-run status and reminder preference are also stored locally and are not uploaded as preferences. Game reminders and final-score alerts are scheduled by your phone itself: the app has no push notification server and never collects a push token.
Technical information
Connecting to Supabase or an identity provider necessarily sends ordinary network information, such as an IP address and request metadata, to that provider. The iTala app does not include an advertising, third-party analytics, attribution or crash-reporting SDK. Service providers and app stores may create their own operational, security, download or crash records under their terms.
3. Who can see what
Writing is restricted. Only the owner of a league, a scorekeeper they have added, or an administrator can create or change that league teams, players, games and statistics. Community drop-in games can be scored only by the person who created them, or by an administrator.
Your email address is not shown to other users in the normal screens of the app. The owner of a league can see the name and email address of the people they have added to it, so they know who has scorekeeping access.
4. Information about people who are not users
This part deserves plain language. A scorekeeper types in the names of players. Those players usually have not installed the app, have not signed in, and have not agreed to anything. Their names, jersey numbers and performance statistics are stored on our server and are readable by every signed-in user, as described above.
If you are a player, a parent or a guardian and you want a name and its statistics removed, email either hanna@itala.fyi or harold@itala.fyi with the league or team name and the player name. We will remove or anonymise it, and we will tell you when it is done. You do not need an account to ask. If you would rather ask the person running your league, they can do it directly in the app.
If you run a league, you are responsible for the information you enter about other people. Please tell your players that their names and statistics are being recorded and can be seen by anyone using the app, and use first names or initials only if that is what they would prefer.
5. Children
iTala is not directed at children and is not designed for them to use. Youth basketball means the app is nonetheless used to record information about children, entered by an adult scorekeeper. That information is treated exactly as described in the section above, and a parent or guardian can have a child name and statistics removed by emailing hanna@itala.fyi or harold@itala.fyi. If you run a youth league, please obtain consent from parents or otherwise have lawful authority before entering a child's name, provide appropriate notice, and use the least identifying information reasonably needed. Consider recording first names or initials only.
6. Why we hold it
To operate and support the app: to show you the right leagues, keep score, calculate standings and career statistics, and let the right people write to the right games. The promo tap counter exists so a sponsor can be told how many taps their card received. We also handle reports and privacy requests, document our responses and legal acknowledgements, and prevent abuse. We do not profile you, we do not build advertising audiences, and we do not use the data to train anything.
Where applicable law requires a legal basis, processing may be necessary to provide the service requested by you, based on consent where requested, required by law, or carried out for our legitimate interests in operating and securing iTala where those interests are not overridden by an individual's rights. You can decline optional photo-library or notification permission, but the related feature will not work. A synced spectator session requires a Supabase user ID, and features reserved for named users require Google or Apple account details.
7. Who else processes it
We do not sell or rent personal information or disclose it for cross-app advertising. Information is disclosed through the visibility described in section 3, when you choose to share a card or open a sponsor link, when required by law, and to providers that help run or distribute iTala:
| Provider | What it does |
|---|---|
| Supabase | Hosts the database, the authentication service and the live-update connection. All of the app data described above is stored here. |
| Provides optional Google sign-in and supplies the account details described above. | |
| Apple | Provides optional Sign in with Apple on iOS and distributes the iOS app. |
| Expo | Provides build and distribution infrastructure. iTala does not use Expo as a push-notification server or runtime analytics provider. |
| Apple App Store and Google Play | Distribute the app and may provide store-level operational information under their own privacy policies. |
| Cloudflare | Hosts the static iTala website and privacy page and may process ordinary web-request and security metadata. The site contains no analytics or advertising scripts. |
The production Supabase project is hosted in the
East US (North Virginia), United States — us-east-1. Other providers
or their subprocessors may process information in additional countries. Users in Canada, New
Zealand or elsewhere should expect information to be transferred outside their home jurisdiction,
where privacy protections and lawful-access rules may differ.
8. Security
- Everything between the app and the server travels over an encrypted connection.
- Write access is enforced on the server, by the database itself, not merely hidden in the app. An app that has been tampered with still cannot write to a league it has no role in.
- The administrator password is stored only as a one-way hash, never in readable form, and repeated wrong guesses lock the attempt out for a period.
No system is perfectly secure. Because rosters are readable by any signed-in user by design, please treat a roster as public information rather than a confidential record.
9. How long we keep it
League, game and statistics records are kept until someone deletes them, because the point of the app is a season history that lasts. Drop-in game spaces can be cleaned up by their owner, which deletes those games along with the teams and players created for them. Account records are deleted when you delete your account.
Local caches, queued changes, sessions and preferences remain until replaced or deleted through the app, the app's storage is cleared through the operating system, or the app is uninstalled, subject to the device platform's behaviour. We may retain limited information longer where reasonably necessary to comply with law, establish or defend legal claims, prevent abuse, or protect the service. Provider-generated operational logs follow the provider's retention practices.
Content reports, email privacy requests and related resolution records are retained for as long as reasonably necessary to handle the concern, document the action taken, prevent repeated abuse, comply with law or establish or defend legal claims. Our retention procedure calls for a monthly review and deletion of resolved or rejected reports and related correspondence normally within 12 months of the final decision, or sooner when no longer needed. If an unresolved concern or a documented legal or safety need requires longer retention, we review that need monthly and delete the information when it ends. This is a manual process, not an automatic expiry in the app.
10. Deleting your account and your data
In the app, go to Settings, then Delete account. This deletes your Supabase sign-in identity and iTala profile and returns the device to a new anonymous spectator session. It also deletes your server-side legal acceptance receipts.
If you signed in with Sign in with Apple, deleting your account also revokes the authorisation you gave iTala to use your Apple ID. Apple asks you to confirm, iTala then asks Apple to revoke that authorisation, and only if Apple confirms the revocation is the account deleted. After this, iTala no longer appears under your phone's Settings -> your name -> Sign in with Apple on your device. iTala never stores an Apple refresh or access token: the confirmation is used once for the revocation request and discarded. If the revocation cannot be completed, nothing is deleted and you can try again.
Account deletion does not automatically delete content reports or related review records, including the reporter's app-session user ID, any contact email or explanation supplied, and administrator review information. Specifically: if you previously submitted a content report, the report and its app-session identifier may remain after account deletion where needed to document and resolve the concern. The identifier will no longer be connected to an active iTala account. Those records follow the retention procedure in section 9. You can request deletion of report information separately using the contact details below; applicable retention needs and legal exceptions may affect what we can delete.
Leagues you created, and the rosters and statistics in them, are shared records that other people may still be using, so they are not automatically destroyed with your account. If you want a league and everything in it deleted as well, delete it in the app first, or email hanna@itala.fyi or harold@itala.fyi and say so.
Account deletion does not deliberately clear basketball records or preferences already cached on your device. To remove local-only information that has no in-app deletion control, clear iTala's app data in your device settings or uninstall the app. You can withdraw notification or photo- library permission in device settings and stop Google or Apple sign-in by signing out. Withdrawing a choice does not undo processing that was lawful before withdrawal.
11. Your rights
Depending on where you live and the law that applies, you may ask whether we hold personal information about you, request access or a copy, ask for inaccurate information to be corrected, object to certain processing, withdraw consent where processing relies on consent, request deletion or blocking where available, and complain to a privacy regulator. Legal exceptions can apply, including where disclosure would reveal another person's information.
Email either address in section 13 with enough detail to locate the information. We may ask for reasonable proof of identity or authority, including parental or guardian authority. We will respond within the period required by the law that applies to the request.
Philippines
Under the Philippine Data Privacy Act of 2012, data subjects may have rights to be informed, to object, to access, to rectify, to erasure or blocking in qualifying circumstances, to data portability where applicable, to file a complaint, and to claim damages as provided by law. Learn more from the National Privacy Commission.
British Columbia, Canada
Where British Columbia's Personal Information Protection Act applies, you may make a written request for access to personal information under our control and information about its use and disclosure, and may request correction of an error or omission. Applicable exceptions and response periods under that Act apply. Concerns may be raised with the Office of the Information and Privacy Commissioner for British Columbia.
New Zealand
Where New Zealand's Privacy Act 2020 applies, you may request access to and correction of your personal information, subject to the Act. Unresolved concerns may be raised with the Office of the Privacy Commissioner.
12. Changes
If this policy changes we will update the date at the top of this page. If a change materially affects what we collect or who can see it, we will say so in the app as well.
13. Contact
Hanna Abejo Santos and Harold Abejo
hanna@itala.fyi
harold@itala.fyi
Contact us first so we can try to resolve a concern. This does not prevent you from complaining to a regulator with authority over the matter, including the Philippine National Privacy Commission, the Office of the Information and Privacy Commissioner for British Columbia, or the New Zealand Office of the Privacy Commissioner.
14. Cookies, analytics and tracking
The static iTala website does not set application cookies and contains no analytics or advertising scripts. Identity providers may use their own cookies during sign-in. The app does not request AppTrackingTransparency permission because the inspected version does not track users across other companies' apps or websites or use data for targeted advertising. Sponsor cards are promotions, but iTala records only the aggregate counter described above.