Privacy Policy
Last updated: May 21, 2026
1. Introduction
Rosterlytic LLC ("Rosterlytic," "we," "our," or "us") operates the Rosterlytic mobile application (iOS and Android) and web platform at app.rosterlytic.com (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. By using the Service, you consent to the data practices described in this policy. If you do not agree with the terms of this Privacy Policy, please do not access or use the Service.
2. Information We Collect
Information you provide directly
- Account information: Name, email address, an optional phone number, and profile details you provide during registration or profile updates
- Managed profiles: When you add a managed profile for another individual, including a minor, the name you provide and, on the web app, an optional date of birth. This information is provided by you, the adult account holder — not by the individual it describes.
- Team & league data: Team names, rosters, player names, jersey numbers, positions, league configurations, and settings
- Game & statistical data: Game schedules, scores, player statistics, attendance records, lineup configurations, standings, and bracket data
- Communications: Messages sent within team chat, league chat, direct messages, and poll responses
- Files, links & media: Team photos and profile pictures, and files or web links you attach to a team, league, organization, or group — such as roster PDFs, schedules, spreadsheets, and waivers
- Payment information: Subscription status and purchase history. We do not directly collect or store credit card numbers, bank account details, or other financial account information. All payment processing is handled by the Apple App Store, the Google Play Store, or Stripe (for subscriptions purchased on the web).
Information collected automatically
- Device type, operating system, browser type, and app version
- Usage patterns, feature interactions, and session data
- Crash reports, error logs, and performance diagnostics
- IP address and general geographic location (country/region level only — we do not track precise GPS location)
- Device push notification tokens, if you enable push notifications
3. Cookies & Tracking Technologies
We and our service providers use cookies, local storage, mobile software development kits (SDKs), device identifiers, and similar technologies to operate the Service. These technologies support functions such as keeping you signed in, remembering your preferences, measuring performance and reliability, protecting against fraud and abuse, understanding how the Service is used, and delivering and measuring advertisements in the free tier.
You can manage cookies through your browser settings and can limit ad tracking through your device settings. Disabling some of these technologies may affect how the Service functions. We do not use these technologies to track you across unrelated third-party websites or apps for our own advertising.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Service
- Manage team rosters, schedules, statistics, standings, and league administration
- Enable communication between team and league members
- Process subscriptions and manage your account
- Send service-related notifications, updates, and alerts
- Analyze usage patterns in aggregate to improve the product experience
- Detect, investigate, and prevent fraud, abuse, or technical issues
- Comply with legal obligations
Advertisements displayed in the free tier are served through third-party ad networks, currently Google AdMob. These networks may process device identifiers, IP address, app interactions, and coarse (country or region-level) location to deliver, measure, and limit the frequency of ads. We do not provide your team, game, chat, or statistical data to ad networks for targeting, and we do not use that data for third-party advertising targeting ourselves.
5. Third-Party Services
We use the following third-party services to operate the Service:
- Supabase — Database hosting, authentication, and file storage
- RevenueCat — Subscription management and purchase verification
- Stripe — Payment processing for subscriptions purchased on the web
- Apple App Store / Google Play Store — App distribution, in-app purchases, and payment processing
- Vercel — Web application hosting and delivery
- Google AdMob — Advertising delivery and measurement in the free tier
- Apple Push Notification service & Firebase Cloud Messaging — Delivery of push notifications to your device
Each third-party service maintains its own privacy policy. We encourage you to review those policies. Rosterlytic is not responsible for the privacy practices of third-party services.
6. AI Assistant (Rosty)
Rosterlytic does not currently offer an AI assistant in its released production applications. We are developing an optional, opt-in AI-powered assistant called Rosty. Before Rosty becomes available to users, and before any user or team data is sent to an AI model, we will update this Privacy Policy to describe the opt-in consent, the categories of data processed, the AI provider, data retention, and the controls available to you. Until then, no user or team data is sent to any AI model.
7. Data Sharing & Disclosure
We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following circumstances:
- Within your shared workspaces: Your name, statistics, attendance, messages, and other participation data are visible to other members of the teams, leagues, organizations, and groups you belong to, and to the participants of any direct messages or polls you take part in, as necessary for the Service to function. Visibility may be further limited by settings such as Private Stats.
- Service providers: With the third-party services listed above, solely as necessary to operate and maintain the Service
- Legal requirements: When required by law, subpoena, court order, or governmental regulation
- Protection of rights: To protect the rights, safety, and property of Rosterlytic, our users, or the public, including to enforce our Terms of Service
- Business transfers: In connection with a merger, acquisition, reorganization, or sale of assets, your data may be transferred to the successor entity
8. Data Security
We implement commercially reasonable security measures to protect your data, including encryption in transit (TLS/SSL), encryption at rest, secure authentication protocols, and access controls. However, no method of electronic transmission or storage is 100% secure. While we strive to protect your personal information, we cannot and do not guarantee absolute security, and you acknowledge that you provide information at your own risk. If we become aware of a security incident affecting your personal information, we will notify affected users and any applicable regulators as required by law.
9. Data Retention
We retain your data for as long as your account is active or as needed to provide the Service. If you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law, regulation, or legitimate business purposes (e.g., resolving disputes, enforcing agreements, or complying with legal obligations). Deleting your account removes or anonymizes account-level personal information; however, content and records you contributed to shared teams, leagues, organizations, or groups — such as scores, statistics, schedules, standings, messages, files, and links — may remain as part of those shared records where removing them is not feasible without impairing the Service for other members. Aggregated, anonymized data that cannot reasonably be used to identify you may be retained indefinitely for analytical purposes.
10. Your Rights & Choices
Depending on your jurisdiction, you may have the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data, subject to legal retention requirements
- Restriction: Object to or restrict certain processing of your data
- Portability: Request a machine-readable copy of your data
- Opt-out: Opt out of non-essential communications at any time
To exercise any of these rights, contact us at [email protected]. We will respond to verifiable requests within 30 days, or as required by applicable law.
11. California & U.S. State Privacy Rights
Depending on your state of residence, U.S. state privacy laws — including the California Consumer Privacy Act, as amended by the California Privacy Rights Act (the "CCPA") — may give you additional rights regarding your personal information. These may include the right to know and access the personal information we collect, the right to correct inaccurate information, the right to request deletion, the right to opt out of the "sale" or "sharing" of personal information and of targeted advertising, the right to limit the use of sensitive personal information, and the right not to be discriminated against for exercising these rights.
We do not sell your personal information for money. Our use of third-party advertising partners in the free tier may be considered "sharing" or processing for targeted advertising under some state laws; you can limit this through your device's ad-tracking settings, and you may contact us to opt out. To exercise any of these rights, or to have an authorized agent submit a request on your behalf, contact us at [email protected]. We will not discriminate against you for exercising your privacy rights.
12. International Users
The Service is operated from the United States and is intended for users located in the United States. It is not directed to, or intended for, individuals in the European Economic Area, the United Kingdom, or other regions with comprehensive data protection regimes, and we do not offer or market the Service there. If you access the Service from outside the United States, your information may be transferred to and processed in the United States, where data protection laws may differ from those in your jurisdiction. By using the Service, you consent to such transfer and processing.
13. Children's Privacy
The Service is intended for users aged 13 and older and is not directed to children under 13. You must be at least 13 years of age to create an account or use the Service, and a child under 13 may not create an account or use the Service directly. We do not knowingly permit children under 13 to register for or use the Service, and we do not knowingly collect personal information directly from children under 13.
The Service does allow an adult account holder to create a "managed profile" for another individual, including a minor — for example, a parent managing a child's place on a youth team roster. Where a managed profile represents a minor, the information we hold about that minor through the managed profile is what the managing adult provides — the minor's name and, on the web app, an optional date of birth — together with the team and game data (such as roster spot, statistics, and attendance) associated with that profile. Staff may also attach files or links to a team or league; account holders are responsible for not uploading a document containing a child's personal information without authority to do so. The minor does not access or use the Service. This information is provided and controlled by the adult, who represents that they are the minor's parent or legal guardian, or another adult legally authorized to act on the minor's behalf, and consents, on the minor's behalf, to its collection and use. The managing adult may edit, unlink, or delete a managed profile at any time, and a parent or guardian may request access to, correction of, or deletion of a managed profile's information by contacting us at [email protected].
We do not use a minor's information for advertising, and we do not disclose it except as described in this Policy. If you believe a minor has created an account or used the Service directly, or that a managed profile was created without proper authority, please contact us at [email protected] and we will promptly remove the account or information.
14. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated by posting the updated policy within the app or on our website, with an updated "Last updated" date. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy. We encourage you to review this policy periodically.
15. Contact
This Privacy Policy is issued by Rosterlytic LLC, the entity responsible for your information under this Policy. If you have questions about this Privacy Policy or wish to exercise your data rights, please contact us at:
Rosterlytic LLC
[email protected]
You can also reach us through our contact page.