PlayerVault
← Back to site

Privacy Policy

How PlayerVault collects, uses, and protects your family’s information.

Effective date
1 July 2026
Last updated
25 August 2026
Data controller
PlayerVault Ltd, registered in England & Wales (company number 13160985), 61 Bridge Street, Kington, England, HR5 3DJ. ICO registration reference: ZC204020.
Contact
privacy@playervaultapp.com
Applies to
United Kingdom users

On this page

  1. Who we are
  2. Our privacy-first approach
  3. Information we collect
  4. Children’s data & the Children’s Code
  5. Why we use your information
  6. Lawful bases
  7. Sharing & disclosure
  8. Location & photo metadata
  9. Analytics & tracking
  10. Payments & subscriptions
  11. Data retention
  12. Where your data is stored
  13. How we protect your data
  14. Your rights
  15. Early access waitlist
  16. Changes to this policy
  17. Contact & complaints

1Who we are

PlayerVault is a mobile app that helps families capture and keep the moments of a young footballer’s journey — goals, milestones, photos, videos and memories — in one private, secure place.

The data controller responsible for your information is PlayerVault Ltd, a company registered in England & Wales (company number 13160985), with its registered office at 61 Bridge Street, Kington, England, HR5 3DJ, and registered with the Information Commissioner’s Office (ICO registration reference ZC204020). For any privacy matter you can reach us at privacy@playervaultapp.com.

PlayerVault Ltd is the data controller for everything the app holds about your child — their photographs, videos, name, age band and club history — which means we are the ones answerable for how it is stored, protected and otherwise processed. You are the account holder, and the vault is yours to run: you choose what goes into your child’s vault, you can change or remove any of it at any time, and you can take a full copy or delete the account outright. Nothing is added without you putting it there.

PlayerVault is available only to users in the United Kingdom. This policy is written to UK law. If we expand to other countries, we will update this policy and our practices accordingly.

2Our privacy-first approach

PlayerVault is built around a simple principle: your child’s memories belong to your family, and no one else. We designed the app to collect as little as possible, and to leave every decision about what goes in and what comes out with you.

In plain terms: No ads, ever. No third-party tracking or fingerprinting. We don’t track your location. Your child’s memories are never shared with clubs, coaches, or anyone else — today they are visible to you alone.

3Information we collect

The parent or guardian is always the account holder, and always the one who enters information — the child never has an account or enters data themselves.

Account information

You sign up with an email address and a password. We store the minimum needed to operate your account: an account identifier and the email address you signed up with. We never see your password — it is hashed by our authentication provider and we cannot read it.

Information about your child

So you can build your child’s journey, the app stores the information you choose to enter about them:

These privacy-minimising choices — age band instead of date of birth, month/year-only club dates — are deliberate, to hold as little identifying information about a child as possible. We do not ask for or store a child’s date of birth, playing position, squad number, school, or address.

Photos and videos

Photos and videos you upload are stored in cloud storage in the United Kingdom — see section 12. They are held for your account only, and no one else’s account can reach them.

Location data is removed from every photo and video before it leaves your phone. Phones routinely record GPS co-ordinates inside a photo file. PlayerVault strips those out on your device, before the file is uploaded, and checks the result before sending. We never store where a photo or video was taken. There is more detail in section 8.

4Children’s data & the Children’s Code

PlayerVault stores information about children, entered and controlled by their parent or guardian. We take this responsibility seriously and have designed the app to align with the ICO’s Age Appropriate Design Code (Children’s Code).

5Why we use your information

We use the information in your account to:

If you joined our early-access list, we also use that email address to send launch updates — see section 15.

The table below sets out the lawful basis we rely on for each purpose:

PurposeLawful basis
Creating your account & providing the app’s core featuresPerformance of a contract
Storing photos, videos and memories of your childLegitimate interests
Securing the app & preventing misuseLegitimate interests
Marketing emails / early access listConsent
Meeting legal & regulatory dutiesLegal obligation

For your child’s memories we rely on legitimate interests rather than consent, so the right that applies is the right to object, not the right to withdraw consent. You can act on it yourself at any time — delete the memories in question, or delete your account — see section 14. Where we do rely on consent, such as our early-access emails, you can withdraw it at any time.

7Sharing & disclosure

We do not sell your data, and we never will. We do not share your child’s memories with clubs, coaches, academies, scouts, or anyone else.

Club names you enter are simply free text you type — there is no integration with real clubs, no club-verified badges, and no public club directory.

Today, the only person who can see your account is you. Family sharing — inviting a small number of relatives to view a child’s vault — is not available yet. Everything you add is private to your account, and because there is no sharing yet there is no privacy setting to configure and nothing you need to switch on: private is the only state there is. When family sharing arrives it will be sharing you choose and can withdraw, and we will update this policy before it does.

We use a small number of processors to run PlayerVault. They handle data on our behalf under contract, only on our instructions, and cannot use it for their own purposes. The table below covers those processors, and only those — it is not a list of every company your browser might contact. The early-access form on our website is embedded from another company and brings its own connections with it: section 15 sets out exactly what loading it involves. Our processors are:

ProviderWhat they do & where
SupabaseDatabase, media storage and sign-in — London, United Kingdom (eu-west-2)
SentryCrash and error reporting — European Union
ResendTransactional email: address confirmations and password resets — EU / US
ApplePayments, subscriptions and sign-in, if and when you use them — handled under Apple’s own terms
EmailOctopusOur early-access mailing list only — never your account or your child’s memories — United Kingdom and EU (Ireland)

We may also disclose information if the law requires it. If that ever happens, we will tell you unless we are legally prevented from doing so.


8Location & photo metadata

We don’t track your location. The app has no GPS tracking, no maps, and no check-in feature, and we never ask for location permission.

The only location-adjacent data involved is the metadata your phone stores inside a photo or video — which can include the exact co-ordinates where it was taken. PlayerVault removes that before the file is uploaded. Stripping happens on your device; the app reads only the date the photo was taken, so it can file the memory in the right season, and the upload is checked to confirm the location data is gone before it is sent.

The result: your photo metadata stays with you, and we never hold a record of where your child played.

9Analytics & tracking

There is no product analytics in PlayerVault. We do not measure which screens you visit, we use no advertising SDKs, no cross-app tracking, and no fingerprinting, and we do not allow third parties to track you across other apps and websites. We do not build profiles of you or your child.

The one thing we do collect is crash diagnostics, through Sentry, so that a crash can be found and fixed. These reports are deliberately stripped back: no screenshots, no view of your screen, no network logs, no user identifier, no email address, and nothing identifying a memory or a file. What is sent is the technical detail of the crash itself — where in the code it happened, the device model and the iOS version.

One thing we cannot remove, and would rather tell you about. When a crash report reaches Sentry, Sentry derives an approximate town or region from the internet address the report arrived from. The app does not send your location, and we do not send your IP address; this happens on Sentry’s systems as the report is received, and we have not found a setting that switches it off. It is not used to build a profile, it is not linked to your account, and it is not shared with anyone. We record it here because you should know it exists.

10Payments & subscriptions

PlayerVault does not charge for anything today, and no payment information is collected.

When paid subscriptions are introduced, purchases will be processed by Apple through the App Store using Apple’s in-app purchase system. We never see or store your card details — Apple handles all payment information under its own privacy policy, and we receive only what we need to activate and manage your subscription.

11Data retention

We keep your information for as long as your account is active. Your memories stay on our systems until you remove them or delete your account.

If you delete your account, we delete your personal data and your child’s memories from our systems — the database records, the photo and video files, and the smaller copies described in section 13 — except where the law requires us to keep certain records, such as basic transaction records for tax purposes. Deletion begins as soon as you confirm it and it is not reversible, so export anything you want to keep first. One thing we would rather state plainly than gloss over: if your phone had already been authorised to finish an upload before you deleted, that upload can still complete afterwards. Anything that arrives that way is removed by a later clean-up, and it is not visible to anyone in the meantime.

Deleting your account clears our systems, not your phone. That is the honest position, and it is worth knowing exactly what stays behind. If you have run an export, that folder is yours and we leave it alone — delete it in the Files app, under On My iPhone → PlayerVault, whenever you want it gone. The app also keeps working files on your device: anything still part-way through uploading, and its record of what it was doing. Deleting the app removes all of that. None of it is sent anywhere, and none of it is visible to us.

Crash diagnostics are held by Sentry under Sentry’s own retention schedule and are deleted automatically when it expires.

Early-access list emails are kept as described in section 15.

12Where your data is stored

Your account, your child’s profile and every photo and video you upload are stored in the United Kingdom, in our provider’s London region (eu-west-2). That is where the database and the media files live.

A few supporting services sit outside that: crash diagnostics are stored in the European Union; the service that sends your account emails may process an email address in the EU or the United States; and the early-access mailing list is run by a UK company, storing in Ireland. None of them receives your child’s memories. The providers are named in section 7.

What this means in practice: your child’s photographs and videos never leave the UK. That is not simply a setting we picked and could quietly change — our contract with the company that stores them commits them to keeping your data in the region we specify, and we specify London. The supporting services, which only ever see an email address or a crash report, are each covered by safeguards UK data protection law recognises — and every one is already in place rather than still being arranged:

Where a framework is relied on, fallback clauses sit behind it, so if one were ever withdrawn your data stays protected rather than lapsing while paperwork is redone.

13How we protect your data

We use appropriate technical and organisational measures to keep your information secure. In practical terms:

One thing worth knowing about what we store. When you add a photo or video, we also make a smaller copy of it — a thumbnail — so grids and lists load quickly without pulling down the full-size file every time. It lives alongside the original, is treated exactly the same way, and is deleted with everything else when you delete your account. Your export contains the originals only, so you will not see thumbnails in your own copy; there is nothing missing when you don’t.

No system is ever completely risk-free, but protecting your family’s memories is central to how we’ve built PlayerVault.

14Your rights

Under UK data protection law you have the right to:

Two of these you can exercise yourself, in the app, without asking us. Both are under Profile.

Export your data writes a copy of your memories and their details to your phone, in open formats you can keep — the original photos and videos, a spreadsheet, and a full record in JSON. It is assembled on your device and no copy is made on our servers. Because it is genuinely your copy, it lands somewhere you can reach it: the Files app, under On My iPhone → PlayerVault. That also means it sits on your phone as ordinary files, unencrypted by us, for you to move, back up or delete as you see fit. Keep it somewhere you are happy to keep photographs of your child.

Delete account erases your account and everything in it from our systems, permanently. It begins as soon as you confirm and cannot be undone, though an upload your phone was already authorised to make can still complete afterwards, and anything it writes is cleared by a later clean-up. It does not reach your phone: see section 11 for what stays behind and how to remove it.

For anything else, email privacy@playervaultapp.com. You also have the right to complain to the UK’s Information Commissioner’s Office (ICO) at ico.org.uk.


15Early access waitlist

This section covers the early-access email list on our website, which is separate from the app and from your account.

If you join the list, we collect only your email address (and your name, if the form asks for it), and only with your consent. We use it for one purpose: to let you know about PlayerVault’s launch and early access. We will never sell it or share it, and you can unsubscribe at any time using the link in any email we send, or by emailing privacy@playervaultapp.com.

The early-access sign-up form on our home page is provided by EmailOctopus. We do not load it during an ordinary visit. It loads only when you select an early-access link or button, or open the page directly at the early-access section. The consent checkbox is unticked when the form loads, we never pre-tick it, and the form will not submit until you tick it.

When the form loads, your browser connects to EmailOctopus, which serves the form, and to Google, which supplies a typeface used in EmailOctopus’s own attribution line. These connections automatically disclose your IP address and standard technical request information, such as browser details and the referring page, to those providers. Neither sets a cookie, and neither stores anything on your device. Before the form is loaded, everything our pages request — including our fonts — comes from our own domain, and no third-party request is made.

If you submit the form, EmailOctopus also receives the email address you enter and your consent choice, and sends you a confirmation email. You are not added to the list until you confirm.

16Changes to this policy

We may update this policy from time to time. If we make a significant change, we will update the “last updated” date and, where appropriate, notify you in the app or by email.

17Contact & complaints

For any privacy question, request, or concern, contact us at privacy@playervaultapp.com. If you are not satisfied with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO), the UK’s data protection regulator, at ico.org.uk.