Privacy Policy

Last updated: September 30, 2026 · Version 1.2

The Spanish version (Aviso de privacidad) is the governing text for purposes of Mexican law.

Summary

  • Without an account, your bowling data stays on your phone: your games, balls and sessions never leave it.
  • With Google (optional), we store your email, name, profile picture and a copy of your bowling data on our server (Supabase), to sync it and restore it on another phone.
  • Scoreboard photos (account required): the photo is downscaled, its metadata (EXIF, including location) is removed, it is read with the Anthropic API, and it is not stored on our server.
  • Error reports: if the app fails, it sends Sentry a technical report without your bowling data, your name or your account. You can turn it off in Settings → Privacy.
  • No ads, no third-party analytics, no cookies, and we never sell your data.
  • You can delete everything from the app: Settings → Your data → Delete all my data.

1. Who is responsible

The party responsible for your personal data is Mario Carrillo (CarMaDev), the independent developer of BolichApp (“we”), with an address for notices at De la Plaza 5401, Col. Guadalupe Jardín, 45030 Zapopan, Jalisco, Mexico. Contact: carma.dev.app@gmail.com.

This policy follows Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (published in the Official Gazette on March 20, 2025) and the Google Play User Data policy.

2. What data we handle and why

2.1 Using the app without an account

Everything you enter is stored in a database on your phone. In this mode the app does not send your data to our server and we have no access to it. The only thing that leaves the phone, if the app fails, is a technical error report without your data (see section 2.7).

Backups. When you export a backup, the app creates a file and opens the Android share menu; you choose where it goes (for example, WhatsApp or Google Drive). That file never goes through our servers and is subject to the privacy terms of the service you choose. Photos are not included in backups.

Android backup. If your phone’s Google account backup is turned on, Android may include the app’s data in it. That backup is managed by Google, not by us.

2.2 Signing in with Google (optional)

Signing in with Google is optional. It lets you back up and sync your data across phones, restore it when you switch phones, and use “From photo”.

2.3 Data we receive from your Google account

This section applies only if you sign in with Google.

Access

The app asks Google only for the basic sign-in scopes: openid, email and profile. Through them we receive only these data from your Google account: your account identifier, your email address (and whether it is verified), your name and your profile picture.

We do not access Gmail, Google Drive, Contacts or any other service or data in your Google account, and we never receive your password.

Use

We use these data only to:

Your Google name and profile picture are stored as part of the account, but the app does not use or display them. Your BolichApp profile name is the one you type.

Sharing

These data are stored only in Supabase, which processes them as our processor (see section 4). Your Google email, name and picture are not sent to Anthropic or to any other third party. The only things sent to Anthropic, when you use “From photo”, are the scoreboard photo and your aliases (see section 2.5).

Protection

Retention and deletion

They are kept until you delete your account. Signing out does not delete them. Using Settings → Your data → Delete all my data deletes your account with these data and your synced copy, and the app revokes BolichApp’s access to your Google account. See section 7 and Delete your account.

2.4 Limited Use of Google data

BolichApp’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

This is a different policy from the Google Play User Data policy, which we also follow (see section 1).

2.5 Scoreboard photo reading (“From photo”)

This feature requires signing in with Google. When you read a photo:

  1. The app downscales the photo (1,568 px maximum on its longest side) and re-encodes it as JPEG, which removes EXIF metadata, including location.
  2. The photo and your aliases (up to 10) are sent to our server; the aliases are used to find your row on the scoreboard.
  3. The server sends the photo and aliases to the Anthropic API (Claude model), which returns the reading: rolls per frame, totals, speed, handicap and the names visible on the scoreboard (so you can pick your row if your alias was not found).
  4. The photo is not stored on our server or in its logs: it only exists in memory while it is processed. The reading is not stored on the server either: it is sent back to your phone, and nothing is saved in the app until you review and confirm it.

Anthropic processes the photo as our provider under its commercial terms: it does not use it to train its models and keeps it only for a limited period before deleting it, under its API data retention policy.

The photo may show other players’ names as they appear on the bowling center screen. They are used only to locate your row and are not stored on the server. We recommend photographing only the scoreboard.

Photo usage log. To apply your account’s monthly limit and control the cost of the service, for each photo we store: your account identifier, date and time, outcome (read, unreadable or failed), model used, tokens consumed, estimated cost, image size and an error code if any. It contains no images, names, aliases or readings. The server also writes technical logs with the same data plus the request duration, likewise without images or names.

2.6 Technical connection data

When the app connects (sign-in, sync, photo reading, account deletion or sending an error report), our providers receive, like any internet service, your IP address and technical request data, which may be kept in their security logs for a limited time. We do not use them to track you.

2.7 Error reports

If the app fails, it sends a technical error report to Sentry, our error monitoring provider, so we can find and fix the problem. This applies with or without an account and is on by default; you can turn it off at any time (see below).

What is sent:

What is not sent: your bowling data (games, rolls, balls, sessions and bowling centers), your name, your aliases, your email, your account identifier, photos, screenshots or screen recordings, or your location. Before sending each report, the app removes any personal data that could be inside the error message (for example, emails or stored values). Reports are not linked to your Google account. We do not measure app performance or record what you do in it.

Provider and region: Sentry (Functional Software, Inc.), which processes the reports on our behalf, with servers in the United States. Like any internet service, it receives your IP address when the app connects (see section 2.6), but it is not stored with the report.

Retention: Sentry deletes reports automatically within 90 days at most. Because they are not linked to your account, “Delete all my data” cannot find them; they are deleted on their own within that period.

How to turn it off: Settings → Privacy → Send error reports. From then on the app stops sending reports, including for later failures. The setting is saved in your profile and, if you use a Google account, synced to your other phones.

2.8 What we don’t do

This applies to the data we receive from Google and to any other data of yours:

2.9 Purposes

We use your data only to provide the service you ask for:

There are no secondary purposes: no marketing, advertising or commercial profiling.

3. Phone permissions

4. Providers and transfers

We use these providers, which process data on our behalf and only to provide the service (processors):

These providers operate outside Mexico, in Canada and the United States, so your data may be processed in other countries. Sharing data with processors does not require your consent; we require them to use it only to provide their service to us. We make no transfers to third parties that would require your consent. We would only disclose data if a competent authority legally requires it.

5. Security

No system is infallible. If a security breach affects your rights, we will notify you as required by law.

6. How long we keep data

7. How to delete your data

In the app: Settings → Your data → Delete all my data. It deletes what is on your phone and, if you signed in, your account and your copy on our server. If you no longer have the app, you can ask by email. Details (what is deleted, what is not, and how long it takes) are on Delete your account.

8. Your rights

You have the right to access, rectify and cancel (delete) your data and to object to its processing (known in Mexico as ARCO rights), and to withdraw your consent or limit how your data is used or disclosed.

9. Children

BolichApp is for bowlers aged 13 and over. It is not directed to children under 13 and we do not knowingly collect their data. If you are under 18, use the app with permission from a parent or guardian. If you believe a child has sent us data, contact us and we will delete it.

10. Changes to this policy

If we change this policy, we will publish the new version on this page with its update date. If the change is significant (for example, new data or new providers), we will also tell you in the app before it takes effect.

11. Contact

For any question about this policy or your data: carma.dev.app@gmail.com.