What we keep,
and what is public
Written from the database schema rather than from a template, so every line below describes something the software actually does. The uncomfortable parts are here too.
Last updated 19 August 2026. This covers the Open Innings Android app and this website, run at openinnings.com. Open Innings is AGPL-3.0 open source and anyone may run their own copy — this policy speaks only for the copy we operate.
Scorecards are public, and they are meant to be
When you score a match, its scorecard is readable by anyone with the link, with no account and no app. That is the point of the product: a career that follows a player between clubs only works if the record is open. It also means a player’s name, their runs, their wickets and every ball they faced are public from the moment you record them.
Two consequences worth being blunt about. You are publishing other people. The players in your squad did not sign up here, and adding somebody puts their name and their figures on a public page. Only add people who would be comfortable with that, the way a club scorebook or a league website already works.
And anyone can add a player, including someone you have never met, because a cricketer who turns out for two clubs is one person and both clubs need to be able to score them. If figures appear against your name that you did not agree to, write to us and we will deal with it.
Your email address, your display name, your password, your sessions and your IP address never appear on any public page and are never shown to another user.
Also not publicWhich account created a player or a team. A public career page shows the cricket and nothing about whoever typed it in.
Eight things, and that is the whole list
| 01 | Email address | It is how you sign in, and the only way to reach you about your account. | Until the account is deleted. |
| 02 | Password | Stored only as an Argon2 hash with a per-account salt. Nobody, including us, can read it back. | Until the account is deleted. |
| 03 | Display name, optional | Shown to you. Not shown on public pages. | Until the account is deleted. |
| 04 | Session records — a hash of your sign-in token, your IP address and your browser or device description | To keep you signed in, and so a session can be ended. The IP and device are what let you tell your own sessions apart from one you do not recognise. | Until the session expires or you sign out. |
| 05 | Players you add — name, short name, date of birth if you enter one, batting and bowling style, role | They are the squad you score. A date of birth is optional and used only to separate players with the same name. | Indefinitely — see “What is public”. |
| 06 | Teams, matches, and every ball you record | This is the product. Every figure in the app is derived from the ball log rather than stored separately. | Indefinitely — see “What is public”. |
| 07 | An anonymous viewer key, if you watch a live match | To count how many people are watching, so the scorer sees it. It identifies a browser or a device, never a person, and is never joined to any account. | Until the match is deleted. |
| 08 | Your email, if you ask to be notified about a release | To tell you when the thing you asked about is ready. Nothing else is ever sent to it. | Until you ask for it to be removed. |
| 09 | A short-lived code or link, when you confirm your address or reset your password | Stored hashed, never in a form we could read back, alongside the address it was sent to and the time it expires. It proves the person holding it can read that inbox, and nothing else. | Minutes to a day, then deleted. |
You can read the table definitions these rows describe — the schema is in the public repository, and a claim here that the code contradicted would be visible to anyone.
The list most apps cannot write
Four companies, and what each one sees
Heroku and Amazon Web Services host the servers and the database, in Europe. They store what is listed above on our behalf and do nothing else with it.
Resend delivers the two emails this app sends — confirm your address, and reset your password — from servers in Ireland. It sees the address the message goes to and the message itself. Click and open tracking are switched off, which is not the default: with them on, every link in a message is rewritten to run through a third party first, and an invisible pixel reports when you opened it. Neither belongs in a mail you did not ask for, and the promise above that nothing here tracks you would not survive either of them.
Google AdMob serves the banner on the scorecard and share screens. It uses your device’s advertising identifier and may personalise what it shows. Android lets you reset or delete that identifier at any time, in Settings → Privacy → Ads. No ad ever appears on the scoring screen, and paying supporters see none at all. AdMob’s own policy governs what it collects.
RevenueCat and Google Play Billing handle the optional supporter subscription. They see the purchase; we never see your card. If you never subscribe, neither is contacted.
Getting a copy, and getting rid of it
Export. Any match you scored can be exported as CSV or JSON from the app, ball by ball. Nothing is held back and no plan is required.
Deletion. From inside the app: More → Delete account, and your password to confirm. It takes effect immediately, with no waiting period. Your email address and display name are erased, your password and sessions are destroyed, any confirmation or reset link in flight is killed, and the account can never be signed in to again. If you cannot reach the app, this page explains how to ask us instead.
Matches and ball events survive, with no trace of who recorded them. That is deliberate: a match is other people’s cricket too, and deleting it would remove innings from the careers of everyone else who played. If you want a specific match removed rather than your account, ask for that instead and we will do it.
Correction and access. Ask, and we will tell you everything held about you and fix anything wrong. You do not need to give a reason.
Children. The app is not directed at children under 13 and we do not knowingly create accounts for them. Junior cricketers are often scored — if you are a parent and want a child’s name removed from public pages, write to us and it will be done without argument.
ChangesThis page changes when the software does, and the date at the top moves with it. Because the source is public, you can see the change itself rather than take our word for it.
Contactsupport@openinnings.com
Anything about your data, at that address. Bugs are better in the issue tracker.
We keep your email, a hash of your password, your sessions, and the cricket you record. The cricket is public because that is the product; everything about you is not. There is no analytics, no tracking and nothing sold. Ads appear on the reading screens only, never while you score. Ask us and it goes away. More questions.