Privacy Policy

Effective August 14, 2026

Who we are

@Batz is an independent app for tracking little league hitting statistics. It is not affiliated with, endorsed by, or connected to any third-party scorekeeping service. This policy explains what information @Batz collects, how it's used, and the choices available to you.

Children's privacy

@Batz accounts require the account holder to be at least 13 years old -- this is confirmed with an age attestation at sign-up, before an account is ever created, and the email address used to sign up must be confirmed with a verification code before the account can be used. Players themselves do not create accounts and do not provide any information directly to @Batz, regardless of age. All information about a player (name, uniform number, stats) is entered by the coach or parent/guardian who registers or imports that player. Whoever registers a player is the accountable party for that player's account-related decisions -- including their visibility setting, display name, and the parental-consent step described below. If you believe a player's information was added without appropriate parental involvement, contact us at atbatz@brain-spell.com and we will investigate and remove it if warranted.

Locked players and parental consent

A player imported from a game file starts in a locked state, owned by the team's Head Coach, until a parent/guardian claims them. While locked, a player's name and uniform number are hidden from everyone except that team's coaching staff -- everyone else sees only a generic identifier such as "Rays Player 17" and their stats show as blank. The player never appears on any leaderboard while locked. A player is unlocked only after an explicit parental-consent step: either a parent/guardian requests to claim the player and the coach approves it, or a coach offers the player to a specific team member who must then agree before anything changes. Either way, the parent/guardian must scroll through and agree to a consent screen -- itemizing what information is collected, how it's used, how long it's kept, and their rights -- before unlocking takes effect, and receives a confirmation email immediately afterward with a window to flag it if the agreement wasn't actually theirs. A parent/guardian can unlink a player at any time afterward, returning them to the locked state; a team's Head Coach can also unlink a player unilaterally. A parent/guardian can also set a player's visibility to "Only Me" from Player Settings: the player's card (name, photo, uniform number) remains visible to other users, but hitting statistics are replaced with a placeholder for everyone except that parent/guardian.

Information we collect

Account information: the email address and password you use to sign in (your password is handled entirely by our authentication provider, Supabase, and is never visible to us in plain text), and an age attestation timestamp confirming you were 13 or older when the account was created. A team's coaching staff can see the email address of that team's own members (fans/followers) on the Team Members screen, for identifying who's requesting to claim a player -- it is not shown to other members, and not shared outside your own team. Coach information: first and last name, entered when registering as a coach. Player information: first and last name (optional -- a player can be identified only by their PlayerTag, see below), uniform number, and hitting statistics imported from a CSV export the coach uploads. Once claimed, a player's parent/guardian may optionally add height, weight, and batting/throwing hand. Team logo: a coach may optionally upload an image to display as their team's logo. Player photo: once a player has been claimed, that player's parent/guardian may optionally upload a photo of the player to display on their player card. Uploading a photo is entirely optional and only the claiming parent/guardian can add, change, or remove it. User-generated content: text you submit through the Block/Report feature or a Customer Care request. We do not collect phone numbers, home addresses, precise location, payment information, or any government-issued ID. We do not use analytics tracking SDKs. We use Google AdMob to display ads -- see "Advertising" below for what that involves.

PlayerTag and stat visibility

Once unlocked (claimed), a player is identified in the app by a PlayerTag (a pseudonym) rather than their real name by default. A player's real name is never shown in search results, leaderboards, or the activity feed, unless that player's parent/guardian explicitly chooses to reveal it in Settings. Before being claimed, see "Locked players and parental consent" above -- the player's real name is hidden entirely, not just pseudonymized. Hitting statistics (current and past season) for a claimed, unlocked player are visible to any signed-in @Batz user by design -- this is intentional and central to the app's purpose of making performance auditable rather than hidden behind a single coach's view. A parent/guardian can additionally set a player's profile to Private, which restricts their Player Profile to that player's own team roster (up to 100 members: coaches, parents, and followers who joined via that team's link). A Private player's row still appears on leaderboards, but their name is not a link there, and they're excluded from search results entirely. Statistics are never accessible outside the app (no public web page) and require signing in to view.

How we use information

To operate the app: storing and displaying stats, search, following, leaderboards, and the activity feed. To communicate with you: password reset emails and responses to Customer Care requests. To maintain safety: reviewing Block/Report submissions. We do not sell personal information, and we do not share it with third parties for their own marketing purposes.

Advertising

@Batz displays banner ads served by Google AdMob to support the app. Every ad request @Batz makes is configured as child-directed (Google's tagForChildDirectedTreatment / tagForUnderAgeOfConsent settings), which disables personalized/behavioral ad targeting -- AdMob does not build a profile from your device's identifiers or activity in other apps, and only serves contextual, general-audience ads. Google may still process limited technical information (such as IP address and device information) as needed to deliver an ad and to detect invalid traffic/fraud. See Google's own Privacy Policy for how AdMob handles this information: https://policies.google.com/privacy.

Third-party service providers

@Batz is built on Supabase (database, authentication, and hosting) and Resend (delivery of account verification, password-recovery, and consent-confirmation emails). These providers process data solely to provide their infrastructure service to @Batz and are not permitted to use it for their own purposes. @Batz does not use analytics tracking SDKs. See "Advertising" above for our use of Google AdMob.

Data retention and deletion

Information is retained as long as the associated account or team is active. An unclaimed (locked) player's identifying information -- name, photo, and uniform number -- is automatically and permanently deleted once the coach marks that team's season complete; only an anonymized, non-attributable team total of that player's statistics is kept afterward, and the player can no longer be claimed. A claimed player's career statistics are retained for as long as their profile remains claimed. You can delete your own account at any time from User Settings, which removes your personal account information. To request deletion of a specific player's information, contact us at atbatz@brain-spell.com.

Your choices

Parents/guardians can, at any time from Player Settings: set a player's visibility to Public or Private, customize or regenerate a player's PlayerTag, and choose whether to reveal the player's real name. Any user can request access to, correction of, or deletion of their own account information by contacting atbatz@brain-spell.com.

Security

Access to data is enforced through database-level row security policies, so that, for example, a Private player's information is only ever returned to users who are permitted to see it -- this is enforced by the database itself, not just by app-side checks. Passwords are managed by Supabase Auth and are never stored or visible to us in plain text.

Changes to this policy

If this policy changes materially, we'll update the effective date below and, where appropriate, notify users in-app.

Contact us

Questions about this policy or your information? Email atbatz@brain-spell.com.