ScoreGlance privacy
What the board keeps, and what it does not.
Effective date: July 26, 2026
Plain-English summary
ScoreGlance is a short-lived shared scoreboard. A public watch link is meant to be shareable, while a private keeper capability controls the official record. We collect only the product data needed to run the board, prevent abuse, improve the service with bounded first-party telemetry, and respond to feedback.
We do not require accounts or player names. We do not put raw game routes, game codes, keeper keys, scores, rosters, feedback content, IP addresses, or user agents into first-party telemetry.
No account required
ScoreGlance does not require an account, login, payment profile, or player name to start or follow a board. This means there is no account record to recover a deleted game or private keeper capability from later.
Game data and discovery
A game stores the teams, game settings, score, inning, count, bases, game events, game-scoped observations, keeper-capability hash, and any push subscriptions needed to run that board. Anyone with a public watch link or code can see the public game state.
If a keeper enables discovery, ScoreGlance keeps the game code, team names, optional region, discoverability flag, and optional snapped field coordinates in a separate discovery index. The field coordinate is coarse/snapped, not a precise device-location history. Discovery can be disabled.
What stays in the browser
Player names and roster caches stay in browser storage by default. Keeper keys, recent-game shortcuts, tracking and crew preferences, local device helpers, bounded sync diagnostics, push-enrollment state, and per-tab attribution/retry state may also stay on the device for the product to work.
A person can deliberately share a private roster payload in a URL fragment. Fragments are not sent to ScoreGlance servers, but anyone who receives that private link may be able to open it. Clear browser/site data to remove browser-local data.
Optional location
ScoreGlance asks for browser location only when someone chooses a nearby-game or discoverability feature. Browser permission controls access. We use snapped coordinates for field discovery and Cloudflare region for ranking.
Push notifications
If a person enrolls in notifications, a browser push subscription endpoint and keys are stored with the game. They are removed on unsubscribe, dead-endpoint handling, or game expiration. Browser push providers process push delivery under their own policies.
Retention at a glance
| Category | What it covers | Retention/control |
|---|---|---|
| Game state | Team names, settings, score, inning/count/bases, events, observation/crew state, keeper capability hash, and push subscriptions in a game Durable Object. | Deleted after 48 hours of inactivity. |
| Discovery | Game code, team names, region, discoverability, and optional snapped field coordinates in the discovery Durable Object. | Entries age out after 12 hours; discoverability can be turned off. |
| Roster and browser data | Roster names, keeper keys, recent games, preferences, device and sync helpers, push enrollment, attribution, and retry state in browser storage. | Local until browser or site data is cleared; per-tab state ends when the tab session ends. |
| Raw first-party telemetry | Bounded event names, time, random tab session ID, UTM dimensions, public surface/action, and Reddit delivery flags in D1. | 90 days, then scheduled deletion. |
| Aggregate telemetry | Daily totals by bounded dimensions. It excludes feedback content, scores, rosters, codes, raw URLs, IP addresses, and user agents. | 25 months, then scheduled deletion. |
| Feedback | Category, message, optional reply email, safe surface, and optional safe diagnostics in a separate D1 table. | 12 months, then scheduled deletion; earlier manual deletion may be appropriate. |
First-party product telemetry
First-party telemetry uses bounded event, surface, and action names rather than arbitrary paths. It records a random per-tab session ID, time, permitted campaign dimensions, and Reddit click-presence/request/delivery flags. It does not store raw URLs, game codes, names, scores, roster data, feedback content, IP addresses, user agents, or raw Reddit click IDs in our D1 database.
Reddit conversion measurement
For eligible Reddit-attributed conversion events only, ScoreGlance may send an event, time, random session UUID, request IP address, user agent, and Reddit click ID to Reddit server-to-server. Those raw click, IP, and user-agent values are not written to first-party D1. Reddit controls its own processing and retention.
Feedback and contact data
A feedback submission can include a category, message, optional reply email, a safe source surface, and optional safe technical diagnostics when the sender chooses them. Diagnostics are limited to bounded product surface, app/build version, derived browser and operating-system labels, viewport, display mode, timestamp, and timezone.
The feedback system does not attach live game context, telemetry session IDs, acquisition IDs, push endpoints, raw URLs, request headers, IP address, Cloudflare country, Turnstile token/result payload, team names, player names, scores, game codes, roster links, or keeper keys.
Service providers and outbound links
Cloudflare provides hosting, Durable Objects, D1 storage, security controls, rate limiting, Turnstile verification, and infrastructure logging. Reddit receives eligible conversion events as described above. Browser push providers handle enrolled push delivery. Sponsor and other outbound destinations receive information under their own policies only after a visitor chooses to leave ScoreGlance.
Cloudflare infrastructure may handle normal request and security metadata under the configured service and logging settings. This is different from saying ScoreGlance writes that information to the product database.
Public links and private capabilities
A public watch link is meant to be shared. A private keeper capability controls scoring and should be treated like a private key. A deliberately shared private roster artifact can expose the names it contains to people who receive it.
Children and youth sports
ScoreGlance is designed for adult volunteers and spectators around youth sports. It does not require child accounts or player names. Do not enter or share personal information that you do not have permission to share.
Your choices and deletion requests
You can disable discovery, decline location or notifications, clear browser/site data, and avoid sharing private capabilities. While a game exists, it can be identified by its game code for a practical deletion request. Feedback can be identified by its reference ID or reply email. Aggregate telemetry cannot be tied back to a named person.
Security limitations
No web service can promise perfect security or uninterrupted availability. We use reasonable controls, but you should not treat the service as an official record, emergency channel, or permanent archive.
Changes to this notice
We may update this notice when product practices change. The effective date at the top of the page changes when a revised notice is published.
Contact
For privacy, deletion, or security concerns, email dave@lelandbluesdigital.com or use the feedback form. Include a feedback reference ID or reply email for a feedback request, or a game code only while a game still exists. Do not send private keeper or roster links.