Privacy

What we keep,
and what is public

Written from the database schema rather than from a template, so every line below describes something the software actually does. The uncomfortable parts are here too.

Last updated 19 August 2026. This covers the Open Innings Android app and this website, run at openinnings.com. Open Innings is AGPL-3.0 open source and anyone may run their own copy — this policy speaks only for the copy we operate.

Read this part first

Scorecards are public, and they are meant to be

When you score a match, its scorecard is readable by anyone with the link, with no account and no app. That is the point of the product: a career that follows a player between clubs only works if the record is open. It also means a player’s name, their runs, their wickets and every ball they faced are public from the moment you record them.

Two consequences worth being blunt about. You are publishing other people. The players in your squad did not sign up here, and adding somebody puts their name and their figures on a public page. Only add people who would be comfortable with that, the way a club scorebook or a league website already works.

And anyone can add a player, including someone you have never met, because a cricketer who turns out for two clubs is one person and both clubs need to be able to score them. If figures appear against your name that you did not agree to, write to us and we will deal with it.

Not public

Your email address, your display name, your password, your sessions and your IP address never appear on any public page and are never shown to another user.

Also not public

Which account created a player or a team. A public career page shows the cricket and nothing about whoever typed it in.

What is collected

Eight things, and that is the whole list

Collected dataFrom the schemaSheet 01
01Email addressIt is how you sign in, and the only way to reach you about your account.Until the account is deleted.
02PasswordStored only as an Argon2 hash with a per-account salt. Nobody, including us, can read it back.Until the account is deleted.
03Display name, optionalShown to you. Not shown on public pages.Until the account is deleted.
04Session records — a hash of your sign-in token, your IP address and your browser or device descriptionTo keep you signed in, and so a session can be ended. The IP and device are what let you tell your own sessions apart from one you do not recognise.Until the session expires or you sign out.
05Players you add — name, short name, date of birth if you enter one, batting and bowling style, roleThey are the squad you score. A date of birth is optional and used only to separate players with the same name.Indefinitely — see “What is public”.
06Teams, matches, and every ball you recordThis is the product. Every figure in the app is derived from the ball log rather than stored separately.Indefinitely — see “What is public”.
07An anonymous viewer key, if you watch a live matchTo count how many people are watching, so the scorer sees it. It identifies a browser or a device, never a person, and is never joined to any account.Until the match is deleted.
08Your email, if you ask to be notified about a releaseTo tell you when the thing you asked about is ready. Nothing else is ever sent to it.Until you ask for it to be removed.
09A short-lived code or link, when you confirm your address or reset your passwordStored hashed, never in a form we could read back, alongside the address it was sent to and the time it expires. It proves the person holding it can read that inbox, and nothing else.Minutes to a day, then deleted.

You can read the table definitions these rows describe — the schema is in the public repository, and a claim here that the code contradicted would be visible to anyone.

What is never collected

The list most apps cannot write

01
No analytics of any kind. There is no Google Analytics, no Firebase Analytics, no PostHog, Mixpanel, Amplitude, Segment or Plausible in either the website or the app. Nothing records which screens you open or how long you stay.
02
No location. The app never asks for it and could not use it.
03
No contacts, photos, microphone, camera or calendar. None of these permissions is requested.
04
No advertising or tracking cookies on this website, and no third-party fonts or scripts — the two typefaces are served from this domain, so loading a page here tells nobody else that you did.
05
No selling of anything to anybody, and no sharing with data brokers. There is no version of this where your club’s scorebook becomes somebody’s dataset.
Who else is involved

Four companies, and what each one sees

Heroku and Amazon Web Services host the servers and the database, in Europe. They store what is listed above on our behalf and do nothing else with it.

Resend delivers the two emails this app sends — confirm your address, and reset your password — from servers in Ireland. It sees the address the message goes to and the message itself. Click and open tracking are switched off, which is not the default: with them on, every link in a message is rewritten to run through a third party first, and an invisible pixel reports when you opened it. Neither belongs in a mail you did not ask for, and the promise above that nothing here tracks you would not survive either of them.

Google AdMob serves the banner on the scorecard and share screens. It uses your device’s advertising identifier and may personalise what it shows. Android lets you reset or delete that identifier at any time, in Settings → Privacy → Ads. No ad ever appears on the scoring screen, and paying supporters see none at all. AdMob’s own policy governs what it collects.

RevenueCat and Google Play Billing handle the optional supporter subscription. They see the purchase; we never see your card. If you never subscribe, neither is contacted.

Your data, your call

Getting a copy, and getting rid of it

Export. Any match you scored can be exported as CSV or JSON from the app, ball by ball. Nothing is held back and no plan is required.

Deletion. From inside the app: More → Delete account, and your password to confirm. It takes effect immediately, with no waiting period. Your email address and display name are erased, your password and sessions are destroyed, any confirmation or reset link in flight is killed, and the account can never be signed in to again. If you cannot reach the app, this page explains how to ask us instead.

Matches and ball events survive, with no trace of who recorded them. That is deliberate: a match is other people’s cricket too, and deleting it would remove innings from the careers of everyone else who played. If you want a specific match removed rather than your account, ask for that instead and we will do it.

Correction and access. Ask, and we will tell you everything held about you and fix anything wrong. You do not need to give a reason.

Two more things

Children. The app is not directed at children under 13 and we do not knowingly create accounts for them. Junior cricketers are often scored — if you are a parent and want a child’s name removed from public pages, write to us and it will be done without argument.

Changes

This page changes when the software does, and the date at the top moves with it. Because the source is public, you can see the change itself rather than take our word for it.

Contact

support@openinnings.com
Anything about your data, at that address. Bugs are better in the issue tracker.

In one paragraph

We keep your email, a hash of your password, your sessions, and the cricket you record. The cricket is public because that is the product; everything about you is not. There is no analytics, no tracking and nothing sold. Ads appear on the reading screens only, never while you score. Ask us and it goes away. More questions.