Privacy Policy

Flow with Hockey

Effective date: 2026-09-22

This policy explains how this application handles information and how to contact us about privacy.

Information we process

Flow with Hockey is a coaching journal for adult coaches. The app stores your local coach name, language and sync preference, team names, player names and jersey numbers, positions, strengths, growth areas, coaching notes and ratings, line combinations, practice blocks, event dates and attendance, travel schedules, addresses and staff tasks, and game scores and contributions on your iPhone. Records may describe players, including young players, if a coach chooses to enter them. Synchronization is optional and initially off. When enabled, team records and their update timestamps are sent to the backend, stored in PostgreSQL, and used to derive cached statistics in Redis. Your local coach name and language setting are not sent in the synchronization payload. The backend creates a random installation identifier and secret; the secret is stored in this iPhone’s Keychain and only its hash is stored on the server. No user account, password, email registration, location tracking, advertising identifier or contact-book access is used. Visiting the public website or calling the API sends normal network request information, including an IP address, to the hosting infrastructure.

How we use information

Local records support team planning, player development, attendance, travel preparation and post-game reflection without a network connection. Optional synchronization keeps authorized installations’ team records aligned and applies timestamp-based conflict resolution. Installation credentials and membership records authorize access to private teams. Statistics and focus suggestions are calculated from entered records, not from a third-party artificial-intelligence service. Optional local notifications remind you about selected events. Request status and error metadata support service operation, abuse limits and troubleshooting.

Service providers and sharing

The API, PostgreSQL database and Redis cache are hosted on Railway, which processes stored information and network traffic to operate the service. Railway and its infrastructure providers receive operational request information and may maintain infrastructure logs. The application backend logs request identifiers, HTTP methods, route templates, status codes and safe error codes; it does not deliberately log authentication secrets or coaching payloads. A team owner can grant another installation access to the team; authorized staff can read and edit its records. Sharing an installation identifier through the iOS share sheet passes that identifier to the destination you choose, but does not include the secret. There are no advertising, third-party behavioral analytics, mail delivery or map SDK integrations. Data is not sold. A privacy inquiry sent separately to the published contact email is handled through that email provider, not through an in-app messaging system.

Data retention

Local journal data remains on the device until you delete it or remove the app, subject to your device and backup settings. Keychain storage is managed by iOS and may outlast app removal; use the in-app deletion action before uninstalling when you want to erase server data. Synchronized records remain in PostgreSQL until deleted. Ordinary record deletion removes the stored payload and retains an identifier, type and timestamp tombstone so other devices can apply deletion. Permanently erased shared records retain only the metadata needed to prevent stale copies from restoring them. Derived Redis entries expire after 60 seconds. A successful installation deletion retains the installation identifier and secret hash in a deletion receipt, accepted only for retrying that deletion for 24 hours; expired receipts are purged on a later installation creation or deletion request, so physical removal may occur later. The application does not set a fixed retention period for Railway infrastructure logs or provider backups and does not promise one. Device backups are governed by your Apple and device settings.

Deleting your information

Use Settings, Delete my installation data to request deletion. If a server credential exists, the app first requires successful server deletion, then removes its local journal, credential and scheduled reminders. Server deletion removes the installation, its owned teams and access grants, and erases its originally authored records in shared teams, even if another coach later edited them. Shared records become permanent empty tombstones. A deleted credential cannot access other API operations. Ordinary records can also be deleted from their detail screen. Disabling synchronization does not erase existing server data. Staff devices may retain downloaded copies while offline; those copies are removed or updated at a later authorized sync. Revoking a staff grant immediately prevents future server access but cannot remotely wipe that person’s device. Deletion affects active application storage, not an independently retained device or infrastructure backup; backup copies, if present, follow the provider’s lifecycle and are not edited individually by the app. If a credential is lost, remote recovery is not offered; contact the privacy address to discuss what can be identified without disclosing private records to an unauthorized person.

Permissions and your choices

The only optional device permission requested is notification authorization, when you ask for an event reminder. Reminders are scheduled locally through iOS; no push-token or remote messaging service is used. You can withdraw permission in iPhone Settings at any time and continue using the journal. Turning off synchronization stops automatic uploads and downloads; it does not delete earlier uploads. No camera, microphone, photos, contacts or geographic location permission is requested. Addresses are text entered by the coach. The privacy-policy link opens a public HTTPS web page and needs no login or cookies.

Your privacy rights

For questions about personal information or requests for access, correction or deletion, contact clem1.blenkin.sop@icloud.com. You can view, edit and delete journal records within the app. Depending on where you live, you may have additional rights to restrict or object to processing, receive your information, or complain to a relevant data-protection authority. The available response may depend on which records can be identified and whether you are authorized to request them. Do not send your installation secret by email. Coaches who enter another person’s information should have an appropriate basis to do so, minimize unnecessary personal details and handle player requests responsibly.

Security

The deployed app communicates with the public API over HTTPS. The installation secret is random and held in device-only Keychain storage; the server stores a hash and checks credentials and team membership for every private operation. Only owners can change staff grants. Local journal writes use atomic replacement and iOS file protection. Database credentials remain server-side. Request limits, typed validation, transactions and deletion tombstones protect integrity and reduce accidental disclosure. These controls do not guarantee absolute security. Access to an unlocked device, a disclosed installation secret or a staff member’s retained copy can expose records.

Children’s privacy

The app is intended for adult hockey coaches and staff, not for children to use independently. A coach may record information about youth players as part of legitimate team management. The app does not ask children to create accounts or submit information directly. Coaches should avoid unnecessary sensitive information and obtain any permissions required for their team and players. A parent or guardian concerned about a player’s records may contact the coach and the privacy address.

Changes to this policy

This policy describes the current app and backend practices as of the effective date shown on this page. If the processing changes, the policy and its effective date will be updated at this public address. Review this page when enabling synchronization or after an app update. The in-app Privacy Policy link provides access to the current policy.