OpenHoops Privacy Policy

Effective date: September 6, 2026 · Contact: support@timbuilds.dev

OpenHoops ("the app") helps basketball players find gyms and outdoor courts, and see activity at nearby courts. This policy explains what information the app handles and why. The short version: we collect the information the app needs to work, plus optional profile details you choose to add; we don't sell your personal information; your location is never read in the background; and the parts of the app that show you to other players are described plainly below.

Using OpenHoops also means agreeing to our Terms of Service. You must be at least 13 years old to use OpenHoops.

What other players can see about you

This is the part worth reading twice, because it is the point of the app.

They can seeDetail
Your usernameOn rosters and player cards when the visibility and block rules below allow it. Accepted friends also see it in their Friends list, and a signed-in player who already knows your exact username can use it to send a friend request or block.
Your profile pictureAny signed-in player the visibility and block rules allow can fetch it. That check is only those rules — it does not also require that you share a court or appear on a roster with them. The photo is delivered through a link that expires after one hour, and anyone holding an unexpired link can open it.
That the app still treats you as checked in at a courtWhile your check-in is active. Without a new nearby verification it ends after your auto check-out window, which starts at 2 hours and can be set anywhere from 1 to 3. A check-in the open app keeps verifying can last longer, but is capped at about 12 hours. A scheduled server check can add a few minutes.
Roughly how long ago you arrivedRounded down to 15-minute steps ("just now", "~30 min ago"). Your exact arrival time is shown only to you.
Your current venue in FriendsAccepted friends can see the venue and rounded arrival age while your check-in is active and was confirmed nearby within the previous three hours, but only when both players' roster-visibility settings and the block rules allow it.
Your "heading there" planVenue and estimated arrival, with your username, until that time passes, under the same visibility and block rules. Other players see the arrival time rounded up to the next 15 minutes; you see the exact time.
Your Reps and streakTotals only — never who gave you a Rep, or where.
The date you joined OpenHoopsShown as "Member since" on your player card, and returned alongside your name wherever a roster is shown to a player permitted to see you.
Your real nameOnly if you turn it on. Hidden by default; never more than a first name plus last initial.

Other players cannot see your email address, your historical Activity list, which courts you visit most, your favourite courts, expired plans, your settings, or the list of people you have blocked. Other players cannot directly read your complete account profile. The app gives them only the roster, player-card, plan, Friends-presence and photo details described above, through specific lookups that apply the visibility and block rules. The two court numbers are the one deliberate exception. The count of players at a court, and the count of players heading to it, both still count everyone — including players whose names are hidden from you and players either of you has blocked. You see the number; you do not see the name.

Friends, visibility and blocks

You can add another player as a friend by exact username or their in-app QR code, which contains the player's current username in an add-friend link. Hidden mode does not prevent a request from an exact username or QR code, but a block in either direction makes that request unavailable. We store pending and accepted friend relationships. Accepted friends see each other's usernames in Friends. When both players' settings allow it, Friends also shows a friend's current venue and rounded arrival age for an active check-in confirmed nearby within the previous three hours.

The "Show me on rosters" setting starts at Visible for a new account. Visible shows your username, photo and rounded arrival time to other visible players at the court. Friends only shows those details to accepted friends whose own setting also permits it. Hidden leaves you in the court's headcount but removes your name from these presence views. It also hides other players' roster names and removes friends' live venues from your Friends list. The same two-sided rules apply to "heading there" plans. New accounts also start with Check-in mode set to Instant, so after you allow precise location, opening the app at a venue can start a named check-in without a separate tap unless you change one of these settings.

Blocking ends any friendship and removes both players from each other's rosters, plans and Friends presence. A narrow player-card exception remains only for the person who set the block: they can open a limited card when the other player's own visibility setting allows it, so Unblock remains available. A player who blocked you is not revealed to you through that exception.

What we collect

Account information. When you sign up we collect your email address and a username you choose. If you sign in with Google, we receive your email address and the name on your Google account (which pre-fills the optional name fields — you can clear them). Your email is used for signing in, account recovery, and verifying an email deletion request. Other players never see it.

Optional profile details. You may add your first and last name and a profile picture. These are entirely optional and leaving them blank changes nothing about how the app works. Your name is hidden by default: other players see it only if you choose a display option in settings (initials, first name only, or first name plus last initial; your full last name is never displayed to anyone).

Your profile picture. It is stored with our infrastructure provider in a private bucket, not at a public web address. A signed-in app can request a one-hour signed link only when the visibility and block rules above permit that photo; there is no additional requirement that you be at the same court as the person asking. Anyone who receives an unexpired signed link can still open it until it expires. In-app account deletion removes the photo first and does not continue if that removal fails.

Location (while using the app). The app uses your device's precise location to show venues near you on the map, to place your own marker on it, to tell you how far away a venue is, and to manage check-ins: confirming that you are close enough to a venue to arrive or check in, renewing an active check-in while you remain nearby, and detecting when you leave for automatic check-out. The check-in ring is about 50 metres for an outdoor court and 200 metres for a gym; gyms use a wider ring because GPS is less accurate inside large buildings. Location is read only while the app is open, never in the background. To load nearby venues, the app queries our server with the latitude and longitude edges of a search box centred on your location or the part of the map you are viewing. It sends a foreground position for manual and automatic check-in or arrival attempts. While the app is open and you have an active check-in, it can also send a fresh position that confirms you are within the check-in ring to renew that check-in; regular renewals are spaced at least ten minutes apart after a successful nearby check, and a separate fresh check may happen before timed check-out. The server uses the coordinates to measure distance, but the current check-in and arrival database records contain account and venue IDs, relevant times, active or pending status and an internal request number — not the coordinates. The departure test runs on the device, and its check-out request does not send your position. This describes what the current database records store, not how long temporary network handling may last.

Check-in mode defaults to Instant. While the app is open, Instant can use your precise location to check you in when it places you at a venue. Ask first waits for your tap. Off disables automatic location use for check-in; a manual check-in still uses location to verify that you are near the venue. Change this at Profile → gear icon → Check-in mode.

The auto check-out window starts at 2 hours and can be set anywhere from 1 to 3 hours at Profile → gear icon → Advanced → Auto check-out timer.

Check-ins and your activity history. When you check in we store which venue and when. While it is live, permitted players can see the venue and rounded arrival age as described above. Only you can read the historical Activity list and the "gyms you frequent" list on your profile. A nightly job creates personal day and week summaries before deleting detailed check-in records that are no longer active and started more than 90 days earlier. Those summaries record only the day or week, not the venue or exact time; they remain while your account exists and are deleted with it. The same job separately creates venue-level busy-time statistics. Those statistics combine check-ins by venue and time block, contain no account ID, are kept on a rolling 52-week basis, and are not deleted when an individual account is deleted. Any signed-in player can ask our server for a venue's busy-time statistics, although no screen in the app shows them today.

Reps. When you give another player a Rep, it is stored. The recipient's Activity list can show when and where the Rep was received, but not who gave it. Other players see the recipient's Rep total only, subject to the visibility rules above.

"Heading there" plans. If you announce you're heading to a court at a certain time, we store that plan (venue and estimated arrival) and show it, with your username, to permitted players looking at that court. Other players receive an arrival time rounded up to the next 15 minutes. Once the time passes the plan stops being shown, and you can cancel it at any time. A nightly job deletes the underlying record seven days after its estimated arrival time.

Favourite courts. Courts you star are stored so the app can alert you when players show up there. Your favourites list is visible only to you.

Notification token and court-alert log. If you allow notifications in the store version of the app, your device's push-notification token (a random address for delivering notifications — not your phone number or any hardware ID) is stored so server alerts can reach your device with the app closed. The registration stays active only if renewed within 24 hours. A confirmed online sign-out closes that sign-in's registration and removes its tokens. If you choose the local sign-out fallback after the server cannot confirm closure, alerts can continue until the 24 hours expires; an alert already selected for sending can still arrive. Account deletion removes the registration.

Court-alert text can name the venue. Crowd-size alerts can include the active-player count; a plan alert can say anonymously that someone is heading there with an approximate arrival time. These alerts do not name the player who checked in or announced the plan. To avoid duplicate alerts, we store your account, the venue, alert type and the time the alert was selected for sending. This log does not prove that delivery succeeded. A nightly job removes entries older than seven days, and account deletion removes entries linked to that account.

Sign-in identifiers. Each time you sign in, that sign-in gets an internal identifier. It is stored alongside your notification registration and your presence bookkeeping so that signing out closes exactly that sign-in and no other, and so a stale device cannot keep a check-in alive. It is an internal number, not anything about your device or you. These identifiers are deleted with your account.

Abuse-prevention counters. For actions with limits, we store your account, the action, its time window and a count. Each time a limited action runs, it removes that account's counter rows whose windows began more than two days earlier. Account deletion removes the account's counters too.

Reports and blocks. If you report a player, we store your account as the reporter, who you reported, the category — including a child-safety option — the venue if supplied, and the time. Reports are not shown to the reported player. Filing a report can send a notification to an account marked as a moderator; that notification carries only the report category, never your username or the reported player's. A report is available for possible review, but this policy does not promise that it will be reviewed or acted on. Blocking works as described in the first section.

Crash reports and analytics. Google Play builds with Sentry enabled send crash logs and diagnostics used to monitor app health and find bugs. These can include device model, operating system and app versions, the app update that was running, and technical details about where a failure happened. A report can also carry a short trail of the app events that led up to the failure, which the crash-reporting library records by default. Sentry's default personal-information option is off, and the app does not identify you to Sentry as a user or add an account ID, email address or username. The app does not turn on session recording, screenshots or performance profiling. This crash analytics is not used for advertising or player profiling.

What we don't collect

No contacts, payment information, health data, advertising identifiers or background location. We do not browse your files or photo library: when you set a profile picture, your phone's picker gives the app only the image you chose. The app's declared dependencies contain no advertising, attribution or product-analytics SDK. Sentry crash analytics is described above.

Where your data lives, and who else touches it

OpenHoops account and database data is stored with Supabase (our database and authentication provider), hosted in the United States (AWS us-east-2). The app sends its service requests over encrypted HTTPS connections. The database access boundaries for player-visible data are described in the first section.

We do not sell, rent, or trade your personal information. A small number of service providers necessarily handle some data to make the app work:

Data retention and deletion

Except for the shorter retention periods described above, and the three things named below that outlive your account, account data is kept while your account exists. You can delete in the app or request deletion by email:

  1. In the app: Profile → gear icon → Delete account, then confirm twice. This removes your profile, detailed check-in records, personal check-in day and week summaries, Reps you received and Reps you gave (so other players' totals go down), plans, favourites, pending friend requests and accepted friendships, reports you filed, blocks you set and blocks set against you, notification registrations and court-alert log, sign-in identifiers, abuse-prevention counters, internal presence bookkeeping records, and your profile picture. In the live database this happens immediately.
  2. By email: write to support@timbuilds.dev from the address you signed up with to request deletion. Our account-deletion page gives these email instructions if you do not have the app.

Three things outlive your account.

Children

You must be at least 13 years old to use OpenHoops. The app is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has an account, email us and we will remove it. If you are under 18, please use the app only with a parent's or guardian's permission — and read the safety section of our Terms of Service together.

Changes

If this policy changes in a meaningful way, we will update this page and the effective date above. Continued use of the app after a change means the new policy applies.