Privacy Policy
Last updated: 3 September 2026
This update names every company that handles your data, describes the coaching assistant and our other AI features in full, and covers our iOS app. It also corrects three things we previously told you — about deleting data, about what our error reports contain, and about international transfers. Those three are the changes worth reading.
Introduction
Matchday Lab ("we", "us", "our") operates the coaching platform available at matchdaylab.ai. This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our service. By using Matchday Lab, you agree to the practices described in this policy.
What we collect
- Account information — your name and email address, collected through Google OAuth or Sign in with Apple when you sign in. We do not store your Google or Apple password. If you choose to hide your email address when signing in with Apple, the address we store and email you at is the Apple Private Relay forwarding address Apple gives us. If someone in your organization invites a colleague, we store the email address they enter for that person before that person has an account with us, so the invitation can be matched when they first sign in.
- Team and coaching data — team profiles, season structures, training sessions, debrief notes, coach notes, match summaries, your conversations with the coaching assistant, and coaching preferences you create within the app.
- Player and roster data — player names, jersey numbers, positions, age group, graduation year, and status information entered by authorized adult coaches on behalf of their players, who may include minors, together with any free text a coach writes about a player, such as a development goal or a note. Where a coach supplies one, we also store a player's own email address — for a player who is a minor, that is a child's contact detail. Coaches do not have to provide it, and you can ask us to remove it at any time.
- Player availability and restrictions — coaches can record whether a player is available to train and a free-text restriction explaining why, for example an injury or a limit on participation. Depending on what a coach writes, this can amount to health information about a player who is a minor. We ask coaches to record only what they need in order to plan training, not clinical detail.
- Trial and tryout data — for teams that run trials, the names, ages, graduation years, evaluations, and scouting notes of the candidates a coach enters or pastes in. These candidates are frequently minors who do not hold an account with us.
- Match and performance data — match scores, attendance records, player appearance information, and per-match event statistics (such as passes, receptions, ball recoveries, and shots) from match analysis files you choose to upload. We do not collect physical or biometric measurements such as distance covered, speed, heart rate, or location tracking.
- Dictated notes — in our iOS app you can speak a session or match note instead of typing it. The app requires your device's own on-device speech recognition and sets the recording to be transcribed locally, so the recorded audio never leaves your phone and is never sent to Apple or to us. On a device that cannot transcribe locally, dictation is unavailable rather than sent away, and you type the note instead. The text the recognizer produces is not local: the app sends it to us, it becomes part of your coaching notes, and it feeds the coaching memory described below. You can always type instead.
- Feedback and bug reports — if you send us feedback from inside the app, we receive what you wrote, your name and email address, and, unless you switch it off, the page you were on and your organization, team, browser, and screen size. You can also attach a screenshot. A screenshot is stored exactly as you sent it, so if it shows a roster, a player record, or a trial list, it shows those names. Our support and engineering staff can open feedback from any organization in order to act on it. Please avoid attaching a screenshot showing a player's name or health information unless it is necessary to explain the problem, and tell us if you want an attachment deleted.
- Usage analytics — page views and feature usage collected through PostHog and Vercel Web Analytics to help us understand how the product is used. Analytics events are tied to an internal account identifier rather than your name or email address, but the page addresses they record include organization, team, and player record identifiers. We configure PostHog not to record browsing sessions, not to capture what you type, and to respect your browser's Do Not Track setting.
- Cookies and browser storage — to keep you signed in we set a session cookie, which is necessary for the service to work. Our analytics does not use cookies, but PostHog is configured to store a pseudonymous identifier in your browser's local storage so repeat visits can be counted once. We also keep small things there: your theme, your dashboard layout, notes you are part-way through writing, and trial evaluations captured while your connection is down. That storage is not encrypted by us, so on a shared or club-owned computer any player or candidate name in an unsent draft can remain readable to the next person who uses that browser profile. Signing out and clearing your browser's site data for Matchday Lab removes all of it.
- Error and diagnostic data — technical error reports collected through Sentry when something goes wrong. An error report can include the details of the request that failed, which may contain data you or your coaches entered, including player names, and the email address of the signed-in coach. We remove email addresses and US-format phone numbers from error messages and diagnostic traces in both the app and the API, and the API also strips the authorization header from the reports it sends — but we do not filter the request contents themselves, so you should assume an error report can contain the data that was being saved at the time. Access to error reports is limited to our engineering team.
Player and minor data
Matchday Lab is a professional tool designed for adult coaches aged 18 and older. It is not a product directed at children or intended to be used by minors.
Coaches and team administrators enter player information, including the names of players who may be minors, in their professional capacity as authorized adults responsible for those players. We do not collect data directly from minors at any point.
Before we send coaching content to our AI providers, we replace player names with anonymous identifiers such as "Player 1" and "Player 2", and we remove email addresses and phone numbers. This replacement works by matching the names on your team's current roster, so a nickname, a first name on its own, a possessive, or a misspelling may not be caught. It also cannot work before a roster exists — if you write coaching principles or season goals while setting up a team, there are no names to match against yet, so that text is sent as written.
Three features are exceptions. In two of them — importing a roster and reading a trial or tryout registration list — the AI's job is to find the names in the text you paste, so the text is sent as you pasted it. In the third, we send the name you give each block of a season periodization plan and the notes you write on it, both as you wrote them, together with your team's name, age group, and level. All three are described under AI processing below.
Where a coach records a player's availability or a restriction such as an injury, that text can be included in what we send to our AI providers. Names inside it are replaced as described above, but the rest of what the coach wrote is sent as written.
If you are a parent or guardian and you want to know what a coach has recorded about your child, or you want it corrected or deleted, email us at hello@matchdaylab.ai. Children's privacy below explains how we handle those requests.
How we use your data
- To provide and operate the Matchday Lab coaching service.
- To build training session plans from your team's schedule, themes, and drill library. Assembling the plan happens entirely on our own servers, with no AI model involved. If you describe the session you want in your own words first, that description is sent to an AI model to be turned into planning settings — with player names replaced, as described below.
- To power the AI features described below, including the coaching assistant, coaching memory summaries, season intelligence, drill generation, and the reading of text you paste in.
- To process roster, schedule, and trial registration imports you submit.
- To send product updates and notifications. You can opt out of non-essential communications at any time.
- To improve the service through anonymized, aggregated analytics, and to produce the aggregate cross-team comparisons described under Data storage and security.
We do not sell your data. We do not share it with anyone beyond the service providers listed below and the aggregate, de-identified benchmarking described under Data storage and security.
AI processing
We use OpenAI's models to power a number of features. Session plans themselves are built by our own software and involve no AI model. The features that do send data to an AI provider are:
- The coaching assistant — the chat where you ask questions about your team.
- Coaching memory summaries and season intelligence built from your sessions, debriefs, pulses, and match results.
- Answering questions grounded in your team's season intelligence.
- Turning the free-text brief you write for a session into planning settings.
- Generating and improving drills.
- Reading rosters, schedules, and trial registration lists you paste in.
- Reading the coaching principles and season goals you type into your team profile.
- Interpreting the notes on your season periodization plan.
When you send a message to the coaching assistant, we send the model your message, the recent messages in that conversation, a summary of the earlier ones, your team's memory summary, the context you have approved for that team, and your team's current intelligence document. The assistant can also call tools that return your roster, individual player records — including availability, restrictions, development goals, and notes — recent sessions, upcoming schedule, recent matches, and drills, and those results are sent to the model too. Player names are replaced with anonymous identifiers throughout. Player record identifiers, jersey numbers, and positions are not.
Some of the assistant's tools go further than reading: it can draft a session, or write up an observation about the team or about an individual player. Anything the assistant writes is held as a proposal and is added to your records only when you approve it, but the proposal itself is stored on our servers in the meantime. This means part of what is recorded about a player may have been drafted by an AI model and accepted by a coach, rather than written by the coach from scratch.
We store your side of each conversation as you typed it, with real names. The assistant's replies are stored in the anonymized form the model produced and are expanded back to real names when you read them. The mapping between the anonymous labels and your players is held on our servers. We do not send you the mapping as a whole; where the assistant asks you to approve a note about a named player, that one card carries the pairing it needs so you can see who it is about.
The coaching assistant can also run a web search through OpenAI's hosted search tool, restricted to a fixed list of coaching and sports science sites. The search is carried out by OpenAI, not by us, and the query is sent with player names replaced.
For roster imports and trial or tryout registration parsing, player names are sent to OpenAI as you pasted them, because the AI must extract names from the raw text you provide. These lists frequently contain the names of minors. We narrow that exposure as far as each feature allows. The trial parser calls the AI only when our own non-AI parser cannot read the list, and email addresses and phone numbers are removed from the trial text before it is sent and again from the results. The roster import has no equivalent redaction: it is built to capture a player's email address where you have supplied one, so a student's email address is sent to the AI provider along with their name. Both flows send nothing else about your team and are rate-limited. The name you give each block of a season periodization plan and the notes you write on it are also sent as you wrote them, together with your team's name, age group, and level.
On every AI call that carries your coaching data, we tell OpenAI not to keep a stored copy of the request on their side. (In OpenAI's own terms: we disable Responses API application-state storage.) That is a separate thing from OpenAI's abuse-monitoring logs — the records OpenAI keeps to catch misuse of their service — which may hold content for up to 30 days under OpenAI's standard settings. OpenAI offers two stricter settings, called Modified Abuse Monitoring and Zero Data Retention, which have to be applied for and approved. We will not tell you either one is switched on for our account unless we have confirmed it in our OpenAI configuration, and today we have not.
Requests made by the coaching assistant also carry a scrambled version of your account identifier — a fixed string of characters produced by a one-way calculation, which cannot be reversed to get back to your account, your name, or your email address. OpenAI uses it to spot abuse of their service.
As of the date of this policy, OpenAI states that data submitted through their API is not used to train their models.
Some of our AI requests — including every request the coaching assistant makes — pass through Cloudflare's AI Gateway on their way to OpenAI. Cloudflare stores our OpenAI key and adds it to each request as it goes past, which means the request is unwrapped on Cloudflare's servers rather than travelling sealed all the way to OpenAI. So Cloudflare is technically able to read what is in the request, and what comes back. We send each of these requests with instructions to Cloudflare not to log the request or response body and not to cache anything. Cloudflare does keep usage records — the model used, token counts, cost, latency, and status — along with the metadata we attach to each request: a scrambled version of your organization identifier, a scrambled version of your team identifier, the name of the operation, and which environment it came from. No names and no free text are in that metadata. AI requests that are not routed through the gateway go to OpenAI directly.
Cloudflare's gateway runs on a global network and we do not select a processing region for it, so an AI request may be handled outside the United States even though your data is stored here.
Service providers we use
These companies handle your data on our behalf so that we can run Matchday Lab. We do not sell your data to them or to anyone else.
Scroll the table sideways to see every column.
| Provider | What it does for us | What it receives | Where it is processed |
|---|---|---|---|
| Render | Application hosting, background workers, and our production database. | All of the data described in this policy. | United States. |
| Vercel | Hosting and delivery of our web app and this marketing site, and page-level web analytics. | Every request you make to our web app, including the page addresses you visit and the contents of what you submit. | Vercel's global network. |
| OpenAI | The AI models behind the features listed under AI processing. | The prompt content described under AI processing, and — for the coaching assistant — a scrambled version of your account identifier. | OpenAI's infrastructure; we do not select a region. |
| Cloudflare (AI gateway) | An AI gateway that routes some of our AI requests to OpenAI and holds our OpenAI credential on our behalf. | The content of those AI requests and replies as they pass through. We configure these requests so that bodies are not logged and nothing is cached; Cloudflare keeps usage records plus scrambled versions of your organization and team identifiers. | Cloudflare's global network; we do not select a region. |
| Cloudflare (domains and DNS) | Domain registration and DNS for matchdaylab.ai. | The network requests needed to resolve and reach our sites. | Cloudflare's global network. |
| Authentication via Google OAuth, and web fonts on this marketing site. | Your Google account identifier, name, and email address when you sign in; your IP address when a marketing page loads a font. | Google's global network. | |
| Apple | Sign in with Apple. (Dictation uses Apple's on-device speech recognition on your own device; no audio or transcript is sent to Apple.) | Your Apple account identifier, name, and email address (which may be a Private Relay forwarding address). | Apple's infrastructure; we do not select a region. |
| PostHog | Product analytics. | Page views and feature-usage events tied to an internal account identifier. Page addresses include organization, team, and player record identifiers. | United States. |
| Sentry | Error monitoring and diagnostics. | Error reports as described under What we collect, which can include the contents of the request that failed. | United States. |
| Resend | Delivery of product and notification emails, where email notifications are switched on. | Your email address and the contents of the emails we send you. | Resend's infrastructure. |
Several of these providers run global networks, so a request may be handled outside the country named. See Your rights under GDPR below for how we treat transfers.
The Matchday Lab iOS app
You can sign in to the iOS app with Sign in with Apple or with Google. Your signed-in session — the access token, your account identifier, email address, display name, and the organization and team you are working in — is stored in your device's keychain. It stays on that one device and is not synced to iCloud.
Apart from signing you in, the app sends your data only to Matchday Lab's own servers. Signing in uses Google's and Apple's own sign-in software, which contacts them directly from your device. The app contains no analytics, advertising, or crash-reporting software. Reminders are scheduled locally on your device; we do not operate a push service and we never receive a device push token.
Where you dictate a note instead of typing it, the app uses your device's on-device speech recognition, and requires it: it asks the recognizer to transcribe locally and will only open the microphone when that device can. If your device has no on-device speech model, dictation is unavailable rather than sent away — the app tells you so and you type instead. The recorded audio therefore never leaves your device and is never sent to Apple or to us. What does reach us is the text the recognizer produces, which you can edit before saving; once saved it is treated like any other coaching note. One thing that confuses people: when iOS asks for speech-recognition permission it shows its own standard notice saying speech data will be sent to Apple. That notice is the same for every app and iOS shows it before it knows we have restricted ourselves to on-device transcription. It does not describe what this app does.
When you are offline, work you save is queued on the device until it can sync. That queue holds the full contents of what you saved, including dictated notes, the players a note refers to, and trial candidate names. It is stored in the app's own storage area, and it can be included in your device backups until it syncs and clears.
Data storage and security
Your Matchday Lab database is hosted by Render in the United States. Our web app and this marketing site are delivered by Vercel, and some of our AI requests are routed through Cloudflare — both of which run global networks, so a request may be processed outside the United States even though your data is stored here. Data is encrypted in transit (TLS), and our hosting provider encrypts the database at rest.
That encryption protects the stored data against access to the underlying disks; it is not a per-field encryption of your records. Everything a coach enters is stored under the real name — a player's name, email address, availability and restriction notes, development goals, coaching notes, and every debrief or conversation that mentions them are held in readable form in our database. The name replacement described under Player and minor data applies to what we send to our AI providers. It is not how your data is stored.
Access controls and multi-tenancy isolation keep each organization's data separate: before returning data, each endpoint checks your organization and team membership through a shared set of authorization checks. There are two deliberate exceptions. Our platform administrators can reach data across organizations in order to operate and support the service. And a shared demonstration organization, which contains only fictional teams and invented player names, is readable by everyone who signs in.
A third exception is anonymized benchmarking: to show how a team compares to similar teams, we compute aggregate, de-identified signals across teams that share an age group and competitive level, excluding your own organization's teams. What crosses between organizations is the training-theme label and how many sessions teams took to pass it — never player names, scores, match details, or team or organization identifiers. These comparisons are released only in aggregate and only when enough teams are in the group that no individual team's data can be inferred. Theme labels are free text a coach types, so a label another coach wrote can appear in your comparison and one you wrote can appear in theirs; please do not put a player's name in a theme label.
Within a team, everyone with access to that team can see each player's record, including availability and restriction notes, and can export the roster — with the restriction and note columns — as a spreadsheet or a printable document. Once a coach has exported a file it is outside our systems and we cannot retrieve or delete it.
We follow industry-standard security practices to safeguard your information. However, no method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security.
Calendar sharing links
Anyone who has a team's calendar subscription link can read that team's schedule without signing in. Treat the link like a password: share it with the people who need it, and generate a new one if it gets out.
The feed carries event types, opponents, venues, times, and the focus text you wrote for each event. It does not include your roster — but if you have typed a player's name into an event's focus text, that name will appear in the feed.
Data retention and deletion
- We keep your data until you ask us to delete it. Coaching data does not expire or age out on its own.
- You can ask us to delete your account and its data at any time by emailing us. There is no self-service delete button in the app today, so we carry these requests out manually — email us and we will confirm when it is done.
- Deleting an organization removes its teams, players, schedule, sessions, debriefs, coach notes, match records, trials, and the AI-generated summaries, coaching memory, and season intelligence built from them.
- An individual team cannot currently be deleted on its own. A team can be archived, which takes it out of day-to-day use but does not delete anything. A team's data is removed when the organization it belongs to is deleted.
- Removing a player from a roster deletes that player's record and attendance history and detaches them from their match appearances. It does not rewrite coaching text written before that point: debriefs, event reviews, session and coach notes, match summaries, assistant conversations, the patterns we detect from repeated debrief wording, and the record of any roster you imported can still mention that player by name, and their name stays attached to the match statistics already recorded. A screenshot attached to a feedback report is also kept as sent. If you want a specific player's name removed from all of that as well, email us and we will do it manually and confirm when it is done.
- A trial or tryout candidate can be deleted while the tryout is still open. That removes the candidate's name, age, graduation year, evaluations, and notes, and leaves only a record that a deletion happened. Once a tryout has been closed, candidates can no longer be deleted from within the app — email us and we will handle it.
- We keep audit records of administrative changes — who changed or deleted what, and when — and these outlive the data they describe. Most hold only identifiers, but some entries include a snapshot of the record that changed, for example a team profile with the coaching principles written on it, or a member's name and email address when their role changed. None of them contain the text of an AI request or reply. If you want an audit snapshot removed as part of a deletion request, tell us and we will handle it manually.
- Deleted data can remain in our hosting provider's database backups until those backups age out on their normal schedule. We do not restore deleted data from a backup except to recover from a failure.
- Analytics events and error reports are held by the providers listed above under their own retention settings, separately from your account data.
Your rights under CCPA/CPRA (California)
If you are a California resident, you have the following rights under the California Consumer Privacy Act and the California Privacy Rights Act:
- Right to know — you may request details about what personal information we collect and how it is used.
- Right to delete — you may request that we delete the personal information we hold about you. See Data retention and deletion above for what deletion covers today and which parts we carry out manually.
- Right to opt out of sale — we do not sell personal information to third parties.
- Right to non-discrimination — we will not discriminate against you for exercising any of these rights.
Coaches can record a player's availability and the reason for it, which may be sensitive personal information about that player's health. We use it only to plan training and to produce the coaching outputs described in this policy. We do not use it for any other purpose, and we do not sell or share it. Within a team, everyone with access to that team can see it and can export it, as described under Data storage and security. We ask coaches to record only what they need in order to plan training.
To exercise your rights, contact us at the address listed below. If you are a player, or the parent or guardian of a player whose information a coach has entered, you can write to us at the same address.
Your rights under GDPR (EEA/UK)
Matchday Lab is the data controller — the organisation that decides why and how the data is handled — for coach account information and for the team, player, and coaching data that coaches enter into the service. Most of the providers listed above act as our processors: they handle that data only on our instructions, and not for their own purposes. The sign-in providers are the exception. When you choose to sign in with Google or Apple, that provider is an independent controller of the sign-in itself and handles it under its own privacy policy; what it passes back to us we then handle as controller.
If you are located in the European Economic Area or the United Kingdom, the General Data Protection Regulation provides you with the following rights:
- Right of access — you may request a copy of the personal data we hold about you.
- Right to rectification — you may request correction of inaccurate personal data.
- Right to erasure — you may request deletion of your personal data ("right to be forgotten").
- Right to data portability — you may request your data in a structured, commonly used format.
- Right to restrict processing — you may request that we limit how we process your data.
- Right to object — you may object to certain types of data processing.
An organization owner can export a JSON archive of the organization's teams, rosters, schedule, sessions, match results, session check-ins, coach notes, event reviews, and trials from the app's settings. That export does not include your conversations with the coaching assistant, coaching memory summaries, season intelligence documents, or the theme and pattern records built from them. If you want a complete copy, email us and we will produce one.
Our lawful basis depends on what we are processing:
Scroll the table sideways to see every column.
| What we process | Why | Lawful basis |
|---|---|---|
| Your account and sign-in data | To create your account and sign you in | Performance of a contract, Art. 6(1)(b) |
| Team and coaching data you create | To provide the coaching features you ask for | Performance of a contract, Art. 6(1)(b) |
| Player and roster data, including data about minors | To provide the coaching service to the coach or club responsible for those players | Legitimate interests, Art. 6(1)(f) — weighed against the player's interests, which is why we replace names before AI processing and keep the data inside the organization that entered it |
| Player availability and restriction notes, where these amount to health data | To plan training around a player's availability | Explicit consent, Art. 9(2)(a) — our terms require you to be authorized by the club or school responsible for the player and to have whatever consent or authority your organization requires before you record it. That consent is obtained and held by the club or coach rather than by us, and we will ask them to produce it if a player, parent, or regulator questions the processing. |
| Analytics and error diagnostics | To understand how the product is used and to fix faults | Legitimate interests, Art. 6(1)(f) |
If you use Matchday Lab to record health information about a player, you must have that person's explicit consent, or that of their parent or guardian. We ask coaches to record only what they need in order to plan training.
Matchday Lab is based in the United States and stores your data in the United States. Several of the providers listed above operate global networks, so a request may be processed outside the United States even though the underlying data is stored here.
Where personal data of individuals in the EEA or UK reaches one of those providers, we rely on the transfer terms that provider makes available — generally its data processing addendum incorporating the European Commission's Standard Contractual Clauses, and, for certified providers, the EU–US Data Privacy Framework. If you need to know which mechanism applies to a specific provider before using Matchday Lab, email us and we will tell you.
If you are a player, or the parent or guardian of a player whose data a coach has entered into Matchday Lab, you can exercise these rights by contacting us. We will work with the coach or club that entered the data in order to confirm your relationship to it.
To exercise your rights, contact us at the address below. You also have the right to lodge a complaint with your local data protection supervisory authority.
Children's privacy
Matchday Lab is not directed at children under the age of 13, or under the age of 16 in jurisdictions where a higher age threshold applies. We do not knowingly collect personal information directly from children.
Player data entered by coaches may include information about minors, but this data is collected from and controlled by the adult coach or team administrator, not from the minors themselves.
You should know that two features send that text to our AI provider with the names left in place: importing a roster, and reading a trial or tryout registration list. These lists frequently contain the names of minors. We narrow that exposure as far as each feature allows. The trial parser calls the AI only when our own non-AI parser cannot read the list, and email addresses and phone numbers are removed from the trial text before it is sent and again from the results. The roster import has no equivalent redaction: it is built to capture a player's email address where you have supplied one, so a student's email address is sent to the AI provider along with their name. Both flows send nothing else about your team, are rate-limited, and run with the provider's stored copy of the request switched off — but the names themselves are sent as you pasted them.
There is one further exception, which does not involve a roster: the notes a coach writes on a season periodization plan are sent as the coach wrote them, so a player's name written into those notes would go with them. Everything else we send to an AI provider has player names replaced first — matched against your current roster, so a nickname, a first name on its own, a possessive, or a misspelling can still get through. All of this is set out in full under AI processing above.
If you are a parent or guardian and you want to know what a coach has recorded about your child, or you want it corrected or deleted, contact us at the address below. We will work with the coach or club responsible for that team.
If you believe that a child has directly provided us with personal information without appropriate authorization, please contact us at the address below and we will promptly delete that information.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. When we make material changes, we will notify registered users by email. Your continued use of Matchday Lab after such changes constitutes your acceptance of the updated policy.
Contact
If you have questions about this policy or wish to make a data request, reach us at hello@matchdaylab.ai.
For data access, deletion, or portability requests, please include "Privacy Request" in the subject line so we can route your inquiry promptly.
You do not need a Matchday Lab account to write to us. If you are a player, or the parent or guardian of a player or trial candidate whose information a coach has entered, use the same address and tell us the team or club involved so we can find the record and work with the coach responsible for it.