Back to site

Legal

Privacy Policy

Scorebug is a log of the games you watch. This page says exactly what that means for your data: what we store, who processes it, and how to get it back or get rid of it.

Last updated

Who we are

Scorebug is built and operated by Cadenic Studios, Calgary, Alberta, Canada. In this policy, “we” and “us” mean Cadenic Studios; “Scorebug” means Scorebug Online at app.getscorebug.app and the Scorebug Android app.

We are the controller of the personal information described here. You can reach a human at hello@getscorebug.app about anything on this page.

Accounts and sign-in

Accounts are handled by Supabase, which stores your credentials and issues your session. You can sign in three ways: an email address and password, a Google account, or a Discord account.

When you use Google or Discord, that provider tells us your email address and, if you have one set with them, a display name and avatar image. We never see your Google or Discord password. When you use email and password, Supabase stores the password as a salted hash — we cannot read it, and neither can support.

The account record itself holds your email address, your display name and your avatar.

What you create in Scorebug

Almost everything else we store is something you deliberately made. That includes:

  • Game logs — the game, your rating out of 5, your written notes, and the perspective you logged it from.
  • Your on-deck list — games you have lined up to watch.
  • Clippings — news items and pages you saved.
  • Cheers and comments — the reactions and replies you leave on entries.
  • Follows — the teams and the fans you follow.
  • Accolades — the milestones your logging history has earned.

Where an entry is visible depends on where you put it. Anything you post into a community area of the app — a comment, a cheer — is visible to other fans by design. Your photos are never part of that; see the next section.

Photos

Photos you attach to a game log are stored in Supabase Storage in a private bucket. They are not public files with hard-to-guess names — the bucket refuses anonymous reads outright.

When the app needs to show you one of your photos, it asks the server for a short-lived signed URL that expires shortly after it is issued. Your photos are never posted publicly, never attached to community entries, and never used in marketing.

Push notifications

Push is opt-in. If you turn it on, Firebase Cloud Messaging issues a token that identifies that one device, and we store the token against your account so we know where to deliver. One token per device you enable.

Turning notifications off in your device settings, or deleting your account, ends this. Device tokens are deleted with the account.

Advertising

Free accounts see ads. On Android they are served by Google AdMob, and on the web by Google AdSense. Members of The Front Office, our paid tier, do not see ads.

Those ad services may use an advertising identifier — a resettable ID held by your device or browser, not by us — to limit repeats and to measure whether an ad worked. We do not send your email address, your logs, your notes or your photos to any ad network.

We do not sell your personal information for money. Serving ads through AdMob and AdSense can count as “sharing” for cross-context behavioural advertising under California law. You can limit it at the source: reset or delete the advertising ID in your Android settings under Privacy → Ads, or use Google's ad settings on the web. Subscribing removes the ads entirely.

Subscriptions and payments

The Front Office is billed through Google Play Billing and managed with RevenueCat. Google takes the payment and holds the payment instrument — we never see your card number. What comes back to us is whether an account has an active entitlement, and the receipt behind it.

RevenueCat receives an app user ID and the store receipt so it can tell the app whether your subscription is live. Refunds, cancellations and billing history stay with Google Play.

Analytics

Our analytics are minimal and first-party: counts of what got used, so we know which parts of the app are worth improving. We do not embed a third-party analytics vendor. The one third-party request we do make is CJ's advertising impression pixel, described under Affiliate links above — it measures that an ad was delivered, not what you do, and nothing else on any page reports back to anyone.

Who else touches your data

We use a small number of service providers, each for one job, and each bound to use the data only to do that job:

  • Supabase — the database, authentication and photo storage.
  • Google Firebase — push notification delivery.
  • Google AdMob and AdSense — ads for free accounts.
  • Paddle — web subscription payments. Paddle is the merchant of record for a purchase made on the web and handles your payment details directly; we never see your card.
  • Google Play Billing — subscription payments made inside the Android app.
  • RevenueCat — matching a subscription from either storefront to your account.
  • Vercel — hosting for Scorebug Online and this site, and cookieless page analytics on this site. It counts page views and where they came from. It sets no cookie, stores no identifier that follows you between sites, and cannot be used to recognise you on a later visit.
  • Sports scores, schedules and news come from third-party data providers. Those are requests for public sports data — no account information travels with them.

Beyond that, we disclose personal information only when the law requires it, or where it is necessary to investigate abuse or protect someone's safety.

Your rights and choices

Depending on where you live, PIPEDA (Canada), the GDPR (UK/EU) or the CCPA/CPRA (California) give you rights over this data. We extend the same handling to everyone rather than checking your address first:

  • Access — ask what we hold about you and get a copy.
  • Correction — fix anything inaccurate. Most of it you can edit in the app directly.
  • Deletion — remove your account and its data. See below.
  • Portability — receive your logs in a machine-readable format.
  • Objection and restriction — object to a particular use, or ask us to pause it.
  • Withdraw consent — turn off notifications, or reset your advertising ID.
  • Opt out of “sharing” for cross-context behavioural advertising, as described above.
  • Non-discrimination — exercising any of these never costs you access or features.

Email hello@getscorebug.app from the address on your account and we will answer within 30 days. If you are not satisfied, you can complain to your data protection authority — in Canada, the Office of the Privacy Commissioner; in the EU or UK, your local supervisory authority.

Deleting your account

You can delete your account yourself, from inside the app or from the web, without asking us. The full list of what goes, what is kept and how long it takes has its own page:

How to delete your Scorebug account →

How long we keep things

We keep your account and everything in it for as long as your account exists — that is the point of a lifetime archive.

  • When you delete your account, your data is purged from our live systems within 30 days.
  • Encrypted backups roll off on their own cycle and are overwritten within 90 days. They are never used to restore a deleted account.
  • Purchase and tax records are retained as long as Canadian law requires, and are held by Google Play and RevenueCat as much as by us.

Security

  • Everything moves over TLS. There is no unencrypted endpoint.
  • The database enforces row-level security: the rules that decide who can read a row live in the database itself, not in app code, so one account cannot read another's rows even if a client is tampered with.
  • Keys are scoped. The key the browser and the app carry can only do what a signed-in user is allowed to do; privileged keys stay server-side and are never shipped to a client.
  • Photo buckets are private, and are read only through expiring signed URLs.

No system is perfect. If we ever discover a breach affecting your personal information, we will notify you and the relevant regulator as the law requires.

Children's privacy

Scorebug is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, write to hello@getscorebug.app and we will remove the account and its data.

Where your data is processed

We are based in Canada. Our providers — Supabase, Google, RevenueCat and Vercel — operate infrastructure in the United States and other countries, so your data may be processed outside the country you live in, and may be accessible to courts and authorities there under local law.

For transfers out of the UK, EU or Switzerland we rely on the European Commission's Standard Contractual Clauses in our agreements with those providers.

Changes to this policy

If we change this policy we update the date at the top of the page. If the change is material — a new category of data, a new processor, a new purpose — we will say so in the app before it takes effect, and we will not apply it retroactively to data you gave us under an older version.

Contact

Cadenic Studios
Calgary, Alberta, Canada
hello@getscorebug.app

See also our Terms of Service and account deletion instructions.