Privacy Policy
Summary
- Without an account, your bowling data stays on your phone: your games, balls and sessions never leave it.
- With Google (optional), we store your email, name, profile picture and a copy of your bowling data on our server (Supabase), to sync it and restore it on another phone.
- Scoreboard photos (account required): the photo is downscaled, its metadata (EXIF, including location) is removed, it is read with the Anthropic API, and it is not stored on our server.
- Error reports: if the app fails, it sends Sentry a technical report without your bowling data, your name or your account. You can turn it off in Settings → Privacy.
- No ads, no third-party analytics, no cookies, and we never sell your data.
- You can delete everything from the app: Settings → Your data → Delete all my data.
1. Who is responsible
The party responsible for your personal data is Mario Carrillo (CarMaDev), the independent developer of BolichApp (“we”), with an address for notices at De la Plaza 5401, Col. Guadalupe Jardín, 45030 Zapopan, Jalisco, Mexico. Contact: carma.dev.app@gmail.com.
This policy follows Mexico’s Federal Law on the Protection of Personal Data Held by Private Parties (published in the Official Gazette on March 20, 2025) and the Google Play User Data policy.
2. What data we handle and why
2.1 Using the app without an account
Everything you enter is stored in a database on your phone. In this mode the app does not send your data to our server and we have no access to it. The only thing that leaves the phone, if the app fails, is a technical error report without your data (see section 2.7).
- Profile: your name, the aliases you appear under on scoreboards, your bowling hand (optional), speed unit, language and app preferences.
- Balls: name, brand, weight, coverstock, layout, purchase date, notes and status.
- Games: bowling centers, sessions (date, lanes, oil pattern, type and notes), games, rolls per frame, pins left standing, speed and handicap.
- Scoreboard photos: only if you turn on “Keep the photo with the game”; they stay in the app’s private storage.
Backups. When you export a backup, the app creates a file and opens the Android share menu; you choose where it goes (for example, WhatsApp or Google Drive). That file never goes through our servers and is subject to the privacy terms of the service you choose. Photos are not included in backups.
Android backup. If your phone’s Google account backup is turned on, Android may include the app’s data in it. That backup is managed by Google, not by us.
2.2 Signing in with Google (optional)
Signing in with Google is optional. It lets you back up and sync your data across phones, restore it when you switch phones, and use “From photo”.
- Your account. We only ask Google for basic permissions (identity, email and profile). When you sign in, our server stores your account identifier, your email address (and whether it is verified), your name and your profile picture as provided by Google. The app only uses your email: it shows it in Settings and during initial setup. Your Google name and picture are stored as part of the account, but the app does not use or display them. Details are in section 2.3.
- A copy of your data. We store a copy of your profile (name, aliases and preferences), balls, centers, sessions, games and rolls to sync them across your phones. It includes markers for items you delete, so deletions reach your other phones, and a random identifier of the installation that made each change.
- Not uploaded: scoreboard photos kept on your phone and the backups you export.
- If your phone already had data when you connect your account, it is uploaded to your copy. If your account already has data from another phone, the app asks you before merging them; if you cancel, nothing is uploaded and you stay without an account.
- Access: only your account can read your copy; it is protected with row-level security.
- Signing out syncs and then deletes the data on that phone; the copy on our server is kept until you delete your account. If some changes could not be uploaded yet (for example, while offline), the app warns you first, because they would be lost.
2.3 Data we receive from your Google account
This section applies only if you sign in with Google.
Access
The app asks Google only for the basic sign-in scopes: openid,
email and profile. Through them we receive only these data from
your Google account: your account identifier, your
email address (and whether it is verified), your
name and your profile picture.
We do not access Gmail, Google Drive, Contacts or any other service or data in your Google account, and we never receive your password.
Use
We use these data only to:
- identify your account and link it to your synced copy of your bowling data;
- show your email in Settings → Account and during initial setup, so you know which account you signed in with.
Your Google name and profile picture are stored as part of the account, but the app does not use or display them. Your BolichApp profile name is the one you type.
Sharing
These data are stored only in Supabase, which processes them as our processor (see section 4). Your Google email, name and picture are not sent to Anthropic or to any other third party. The only things sent to Anthropic, when you use “From photo”, are the scoreboard photo and your aliases (see section 2.5).
Protection
- Connections between the app, our server and Google use HTTPS.
- Our provider Supabase encrypts the database at rest (AES-256) and all connections are encrypted in transit (TLS).
- Account data lives in Supabase’s authentication system, which the app cannot access directly. Your synced copy is protected with row-level security (RLS): only your account can read it.
Retention and deletion
They are kept until you delete your account. Signing out does not delete them. Using Settings → Your data → Delete all my data deletes your account with these data and your synced copy, and the app revokes BolichApp’s access to your Google account. See section 7 and Delete your account.
2.4 Limited Use of Google data
BolichApp’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.
This is a different policy from the Google Play User Data policy, which we also follow (see section 1).
2.5 Scoreboard photo reading (“From photo”)
This feature requires signing in with Google. When you read a photo:
- The app downscales the photo (1,568 px maximum on its longest side) and re-encodes it as JPEG, which removes EXIF metadata, including location.
- The photo and your aliases (up to 10) are sent to our server; the aliases are used to find your row on the scoreboard.
- The server sends the photo and aliases to the Anthropic API (Claude model), which returns the reading: rolls per frame, totals, speed, handicap and the names visible on the scoreboard (so you can pick your row if your alias was not found).
- The photo is not stored on our server or in its logs: it only exists in memory while it is processed. The reading is not stored on the server either: it is sent back to your phone, and nothing is saved in the app until you review and confirm it.
Anthropic processes the photo as our provider under its commercial terms: it does not use it to train its models and keeps it only for a limited period before deleting it, under its API data retention policy.
The photo may show other players’ names as they appear on the bowling center screen. They are used only to locate your row and are not stored on the server. We recommend photographing only the scoreboard.
Photo usage log. To apply your account’s monthly limit and control the cost of the service, for each photo we store: your account identifier, date and time, outcome (read, unreadable or failed), model used, tokens consumed, estimated cost, image size and an error code if any. It contains no images, names, aliases or readings. The server also writes technical logs with the same data plus the request duration, likewise without images or names.
2.6 Technical connection data
When the app connects (sign-in, sync, photo reading, account deletion or sending an error report), our providers receive, like any internet service, your IP address and technical request data, which may be kept in their security logs for a limited time. We do not use them to track you.
2.7 Error reports
If the app fails, it sends a technical error report to Sentry, our error monitoring provider, so we can find and fix the problem. This applies with or without an account and is on by default; you can turn it off at any time (see below).
What is sent:
- the error type and message, and the part of the code where it happened (stack trace);
- the app version and technical details of the phone: manufacturer and model, Android version, language, time zone, available memory and storage, and battery status;
- the technical events leading up to the error, without their content: internal app messages and connections to our server (method, address without parameters and response code);
- when each use of the app starts and ends and whether it ended in a crash, to measure how stable each version is;
- a random installation identifier generated by Sentry, to count how many installations are affected by each error. It is not the Android ID or the advertising ID, and it is not linked to your account.
What is not sent: your bowling data (games, rolls, balls, sessions and bowling centers), your name, your aliases, your email, your account identifier, photos, screenshots or screen recordings, or your location. Before sending each report, the app removes any personal data that could be inside the error message (for example, emails or stored values). Reports are not linked to your Google account. We do not measure app performance or record what you do in it.
Provider and region: Sentry (Functional Software, Inc.), which processes the reports on our behalf, with servers in the United States. Like any internet service, it receives your IP address when the app connects (see section 2.6), but it is not stored with the report.
Retention: Sentry deletes reports automatically within 90 days at most. Because they are not linked to your account, “Delete all my data” cannot find them; they are deleted on their own within that period.
How to turn it off: Settings → Privacy → Send error reports. From then on the app stops sending reports, including for later failures. The setting is saved in your profile and, if you use a Google account, synced to your other phones.
2.8 What we don’t do
This applies to the data we receive from Google and to any other data of yours:
- No ads and no advertising SDKs.
- We don’t use your data for targeted or personalized advertising.
- No third-party analytics and no tracking across other apps or websites.
- No cookies. This website doesn’t use them either: no cookies, no JavaScript and no third-party resources.
- We don’t sell or rent your data, or share it for third parties’ own purposes.
- We don’t give your data to data brokers or information resellers.
- We don’t use your data to determine creditworthiness or for lending purposes.
- We don’t use your data, or allow it to be used, to train artificial intelligence or machine learning models, whether ours or third parties’.
- We don’t ask for your location, contacts or sensitive personal data.
2.9 Purposes
We use your data only to provide the service you ask for:
- storing your data and computing your stats;
- identifying your account, syncing your data across your phones and restoring it, if you sign in with Google;
- reading the scoreboard photos you send and applying the monthly limit;
- handling your requests and fixing bugs in the app (with error reports, unless you turn them off).
There are no secondary purposes: no marketing, advertising or commercial profiling.
3. Phone permissions
- Camera: requested only when you tap “Take photo”, after a screen that explains why. You can use the gallery instead.
- Photos: we use the Android photo picker, which gives the app only the photo you choose. We never ask for permission to read your gallery or storage.
- Microphone and storage: explicitly blocked by the app; never requested.
- Internet: only for sign-in, sync, “From photo”, account deletion and sending error reports.
4. Providers and transfers
We use these providers, which process data on our behalf and only to provide the service (processors):
- Supabase (Supabase, Inc.): accounts, the sync database and server functions. Server region: Canada (ca-central-1).
- Anthropic (Anthropic, PBC): reading photos with its Claude API. United States.
- Sentry (Functional Software, Inc.): app error reports. United States.
- Google (Google LLC): Google sign-in. Google Play also distributes the app and handles its own data under its privacy policy.
These providers operate outside Mexico, in Canada and the United States, so your data may be processed in other countries. Sharing data with processors does not require your consent; we require them to use it only to provide their service to us. We make no transfers to third parties that would require your consent. We would only disclose data if a competent authority legally requires it.
5. Security
- Encrypted connections (HTTPS) between the app, our server and providers.
- Our provider Supabase encrypts the database at rest (AES-256) and all connections are encrypted in transit (TLS).
- Keys for paid services (such as Anthropic’s) live only on the server, never in the app.
- Row-level security: each account can read only its own data, and the server only accepts changes from the account you signed in with.
- Data minimization: downscaled photos without metadata, discarded after processing, logs without images or names, and error reports without personal data.
No system is infallible. If a security breach affects your rights, we will notify you as required by law.
6. How long we keep data
- Data on your phone: until you delete it, sign out, uninstall the app or use “Delete all my data”.
- Account and synced copy: until you delete your account from the app or ask us to delete it. We do not delete accounts for inactivity.
- Scoreboard photo on the server: not kept; it only exists in memory while it is processed.
- Photo usage log: while your account exists. Once it is deleted, those records are kept without any identifier (they can no longer be linked to anyone) for cost accounting and the service’s daily limit. They are kept for up to 24 months.
- Server backups: deleted data may remain for up to 7 days in the database’s automatic backups, if any, until they roll over.
- Server technical logs: deleted automatically within 7 days.
- Error reports: Sentry deletes them automatically within 90 days.
7. How to delete your data
In the app: Settings → Your data → Delete all my data. It deletes what is on your phone and, if you signed in, your account and your copy on our server. If you no longer have the app, you can ask by email. Details (what is deleted, what is not, and how long it takes) are on Delete your account.
8. Your rights
You have the right to access, rectify and cancel (delete) your data and to object to its processing (known in Mexico as ARCO rights), and to withdraw your consent or limit how your data is used or disclosed.
- You can do almost all of this yourself in the app: view and correct your data, export it as a backup, sign out and delete your account.
- For any request, email carma.dev.app@gmail.com with the subject “Data rights – BolichApp” and include your name, how to reply to you, the right you want to exercise and the data it refers to. Write from the Google account email you use with BolichApp so we can verify the account is yours. We may ask for more information to verify your identity or your representative’s.
- We will reply within 20 business days and, where applicable, carry out the request within the following 15 business days.
- If you use the app without an account, we hold no data about you on our server: everything is on your phone and you control it from the app.
- If you believe we did not handle your request properly, you may contact Mexico’s personal data protection authority, currently the Secretaría Anticorrupción y Buen Gobierno (Ministry of Anti-Corruption and Good Governance).
9. Children
BolichApp is for bowlers aged 13 and over. It is not directed to children under 13 and we do not knowingly collect their data. If you are under 18, use the app with permission from a parent or guardian. If you believe a child has sent us data, contact us and we will delete it.
10. Changes to this policy
If we change this policy, we will publish the new version on this page with its update date. If the change is significant (for example, new data or new providers), we will also tell you in the app before it takes effect.
11. Contact
For any question about this policy or your data: carma.dev.app@gmail.com.