REP11 Privacy Policy
Applies to: the REP11 app (iOS, Android) and the REP11 website. Publisher: Bolly Labs Pty Ltd (ACN 701 365 246), South Australia, Australia. Contact: support@rep11football.com (If you already have hello@rep11football.com, that reaches us too — it is the same inbox, and you never need to re-send anything to the address above.) Postal address: Reception, 16 Matthew Street, Stanthorpe QLD 4380, Australia Telephone: +61 420 100 690
Version: v1.0 · effective 2026-08-25 · published before legal review — see the note below.
About this version — please read this first. This policy accurately describes what the REP11 app does today, and every factual claim in it is checked automatically against our own source code each time we build the app. It has not yet been reviewed by a lawyer. That review is booked to happen before REP11 is released publicly, and if it changes anything here we will publish the new version and say what changed. We would rather tell you that plainly than let a polished page imply a sign-off it has not had.
The short version
REP11 is a football training app used mostly by children. We built it so that using it well requires almost nothing about you.
- Kids never hold accounts here — a parent's account, a parent's card, always. One adult signs up and owns the account. Everyone under 18 in the household is a profile inside it: no login of their own, no email address, nothing to sign up for and nothing to wait for.
- You can train without an account at all. A guest profile lives on the device and is never sent to us.
- We do not show advertising to children. Not on any profile, not in any family account, not at any age band. No exceptions and no "tasteful" ones.
- We do not sell personal information, and we do not share it with advertisers or data brokers. There is no advertising SDK in the app.
- No photographs. Players are represented by illustrated avatars. There is no photo upload, no camera access, and no video upload.
- No messaging between people. No player can message another player, and nobody can contact a child through this app. The one thing anyone in the household can send is feedback to us — see §2.3, and note that a child can use it.
- We never see your card. Subscriptions are billed by Apple or Google.
The rest of this document is the detail behind those sentences.
1. Who this policy is for
People use REP11 in four different ways, and the answer to "what do you hold about me" is different for each:
| What exists | Where it lives | |
|---|---|---|
| A Little Baller (under 5) | The grown-up runs the session from their own device. The app does not currently create a profile or keep progress for this mode | Nowhere |
| A guest player (any age) | A local profile: chosen name, age band, avatar, training history | The device only |
|---|---|---|
| Anyone under 18 in a household | A profile inside an adult's account. No login, no email address, no separate sign-up | Our server, under that adult's account |
| The adult who owns the account | An account: sign-in identity + subscription state | Our server |
The rule underneath the table: an account belongs to an adult, and only to an adult. One grown-up signs up and pays; everyone under 18 plays as a profile inside that account. There is no child login, no child email address, and no way for a child to be contacted through this app.
We treat every player as a child. Rather than sorting people into stricter and looser regimes by age, we apply the protections designed for children to everyone who uses REP11 — including the adults. It is simpler, it is safer, and it means we never have to guess someone's age to know how to treat their information.
An account is the main thing that creates a record with us, but it is not the only one — feedback you send us (§2.3) and a club application (§2.5) are also records we hold, and both can exist without an account.
2. What we collect
2.1 A player profile (child or adult)
- A display name. A first name or a nickname — the app asks for what a player wants to be called, not for a legal name, and we ask parents not to use surnames.
- An age band (5–8, 9–12, 13+). Bands set the difficulty and reading level of content.
- A birth year, if a parent enters one — the year only, never a full date of birth, and it can be left blank. It exists so a profile ages up on its own rather than being stuck at the band it started in.
- An avatar choice from our illustrated set, and a chosen coach character. Both are picks from a fixed list, not uploads.
- Card-style picks: a country (a two-letter code, shown as the flag on the player card), a favourite position, and kit colours. Each is a pick from a fixed list, each is optional, and none is typed text.
- An optional club or team affiliation. A parent can add the name of the club a player trains with from the grown-up settings, or a player can join a REP11-affiliated club by opening that club's own join link, which attaches the club's verified name. The affiliation appears on the player's own card. It does not put the player on the club's board: that is a separate, off-by-default parent choice (§7).
- Training history: which drills were completed and when, stars earned, streak days, experience points, personal bests (and which foot a best was set with, on the drills that are tracked per foot), time spent running a drill timer, quiz attempts and scores, achievements earned, any custom session built, and an optional one-tap "how did that feel" answer.
- Which drills were opened and worked on, even when nothing was scored — one record a day per drill, with the date, and whether a completion followed. Added 2026-08-25. Until now this app only ever recorded what went WELL, which meant it could not tell that a child was struggling with something; a record of "worked on it, nothing came of it" is what makes that possible. It is stored, it goes with an export and it goes with a delete like the rest of the training history. Two things it is deliberately not: it is not a judgement — no completion does not mean a child gave up, and nothing in the app says or shows that it does — and it is not shown to anybody today. Nothing in REP11 reads these records yet.
- An optional four-digit PIN, if the player chooses to lock their own profile on a shared device, and one optional parent PIN for the household. We never store the digits themselves — only a salted scrypt hash — but that hash is held on our server, because the profile it locks is held there too. A four-digit PIN has only 10,000 possible values, so treat it as a lock that stops a sibling opening the wrong profile on a shared tablet, and not as protection for anything that matters. A PIN is a convenience for sharing a tablet between siblings — it is not an account and not a password, and it protects no data from anyone with access to the device itself. A parent PIN opens any player's lock and can remove it, so no child can be locked out of their own profile. Because there is no account, there is nothing for us to reset: a forgotten parent PIN is re-set in the app by the press-and-hold check it replaced. An export tells you WHETHER a PIN is set; it never contains the PIN or its hash.
2.2 An account — always held by an adult
An account is created by an adult, who confirms they are 18 or over and adds a payment method. That card is also the age check that matters: at the moment anyone pays, an adult is present. Everyone under 18 in the household is a profile inside that account (§2.1), never an account holder.
- A sign-in identity. At launch on Android this is Sign in with Google, and we receive the identifier Google gives us for your account plus the email address on it. Sign in with Apple and a one-time code sent to your email address are the next two we are adding; when REP11 reaches iOS, Sign in with Apple will be offered alongside Google. If you sign in with Apple you may give us a private relay address instead of your real one, and that works perfectly well for us. We never set or store a password, so there is no password for us to lose.
- Subscription state — whether the account has an active plan, and which one. Managed for us by RevenueCat (§4).
- Family membership — which profiles belong to the account, and any join code issued.
2.3 Feedback you choose to send
If you use the in-app feedback control we store what you wrote, what screen it was about, and the app version. Please don't put personal details in it; we don't need them, and we'd rather not hold them.
2.4 The website
Reading rep11football.com collects nothing about you. The pages — this one included — carry no analytics, no tracking pixels, no advertising code, no embedded third-party content, and no cookies of any kind. Nothing on the site needs to remember you, so nothing does.
The one page that can receive anything is the feedback page (/feedback), and it only holds what you choose to put in it:
- What you write is stored and shown publicly on that page, without any name attached — the form has no name field at all. The page says this before you send.
- An email address is optional, for people who want a reply. It is never shown publicly, never shared, and is used to reply to you — plus, only if you tick the box, to send occasional REP11 updates you can stop at any time.
- Photos you attach come only to us and are never displayed on the site.
- To stop one visitor flooding the wall, the page keeps a scrambled (hashed) form of the sending address for rate-limiting — it cannot be turned back into your address and is used for nothing else.
- Delete any of it — your note, your email, a photo — by asking at the address in the header; the same works if you change your mind about updates.
That page uses JavaScript to work (the rest of the site runs none), and what you submit is stored with our hosting provider (§4, Cloudflare) in a database in their Oceania region. The admin view of that page, which only we use, remembers our own access key in our own browser — it stores nothing in yours.
As with any website, our hosting provider handles each request and sees the IP address it came from, in the ordinary course of serving the page. We do not receive that as a report and build no profile from it.
If we ever add analytics to the website, this section changes first, and so do our store declarations.
2.5 A club application (adults only)
A club official can apply, from the app's club page, to affiliate their club with REP11. The form collects what it shows: the club's name, website, suburb and state, and the applicant's own name, role and email address. This is business contact information about an adult, used to assess the application, manage the affiliation and reply to the applicant. It is stored with our club records, not on any player's profile, and players never see it — if the club is approved, the only club identity that ever reaches a player's screen is the club's name and badge. Ask us at the contact address above to correct or delete an application's details.
2.6 App updates — the one thing the app itself sends
The REP11 app checks whether a newer version of itself is available, and downloads it if there is one. That check goes to Expo (§4), the company whose build tools REP11 is made with — not to us.
What the check carries:
- which version of the app is installed, and what kind of phone it is on;
- a random ID that Expo's update tool creates for this installation the first time the app opens, and then reuses. It is a string of random characters. It is not a name, an email address, an account or an advertising ID; it is not connected to a player, a profile or anything a player does; and we never see it. We name it here because it stays the same for that installation, and an identifier that persists deserves saying out loud even when it means nothing to us.
What the check does not carry: no profile, no name, no age band, no avatar, no scores, no training history, no quiz answers. None of what the app records is any part of it.
In our store privacy declarations this is the reason the app answers yes to "Device or other IDs", for app functionality, not shared with anyone. It is the only data type the app declares.
Uninstalling the app discards the ID. With the phone offline the check finds nothing and everything else works normally.
3. What we deliberately do not collect
This list is the product decision, not a courtesy:
- No child email addresses, phone numbers or postal addresses.
- No photographs or video of players. No camera or photo-library access is requested.
- No contacts, no microphone, no device advertising identifier.
- No sensors, and no location permission. We do not ask for GPS and we do not read heart rate, steps, motion, calories or anything from Apple Health or Google Fit. A server does see the IP address a request arrives from, which is roughly a city — that is how the internet works, not a location feature.
- But we DO hold fitness information, and we say so on both stores. Your training record — which drills, for how long, personal bests, which foot — is information about physical activity, so it is declared to Google as Fitness info and to Apple as Health & Fitness → Fitness. We have no sensors; that does not make training records something other than what they are, and we would rather declare them than argue the point.
- No health information. Nothing in the app records injury, pain, symptoms, medication, mood or diagnosis. The one "how did that feel" question offers exactly three answers — easy, getting there, tricky — which is about the drill, not about the player.
- No full date of birth (see the band note in §2.1).
- No school name and no coach's name attached to a child's profile in the consumer app. A club or team name is the one exception: it is optional and parent-controlled, and §2.1 and §7 describe exactly what it is and where it shows.
- No behavioural profile for advertising. We do not build one, and there is no third-party SDK in the app that could.
4. Who else is involved
We keep this list short on purpose, and every addition to it is a decision reviewed against this policy — not a technical detail.
- Apple and Google process every subscription payment. They tell us that a purchase is valid; they do not give us your payment details, and we never handle them.
- RevenueCat validates purchase receipts and records which anonymous app user ID is entitled to which plan, on our behalf. We do not send RevenueCat an account ID, profile ID, email address or device identifier. We do not enable attribution integrations, and its Integrations dashboard must remain empty; we verify that before every store submission.
- Expo provides the tool that delivers app updates. Each time the app checks for one, Expo receives the app version, the kind of phone, and the random per-installation ID described in §2.6, together with the IP address that any internet request carries. Expo acts as our processor and receives nothing about a player. This happens in the app whether or not anyone has an account.
- Crazytel runs the telephone number printed at the top of this policy. If you ring and leave a message, Crazytel records it and emails us the recording, so a message you leave is held by them as well as by us until we delete it (§8 — we keep it as long as the rest of our support correspondence). We deliberately do not have your message transcribed. The option was there, it is cheap, and we turned it off: it would have sent whatever you said — your child's name included, if you used it — through an automatic transcription service, and that is a third company hearing a child's name to save us listening to twenty seconds of audio. It was not worth it. We listen to the message ourselves. Nothing about a call is connected to a player's profile.
- Cloudflare is our hosting provider. Our website, our API and our database all run on Cloudflare's network, so the account and profile data described above is stored and served by Cloudflare on our behalf, and Cloudflare handles every request that reaches us. Cloudflare, Inc. is a United States company operating a global network; §8 says what that means for where your information physically sits. Cloudflare acts on our instructions as our processor — it is not permitted to use your information for its own purposes.
We do not use advertising networks, data brokers, behavioural analytics SDKs, or any crash-reporting service that profiles users or follows them between apps.
One correction, made 2026-08-31, because the sentence above used to say "or crash-reporting services" without qualification and that was not accurate about the Android app. The app-update service described under App updates above (Expo) does two things we had not spelled out. It sends a random installation identifier with every update check, so it knows which installation to send an update to. And if the app has failed to start, the next update check carries the error message from that failure, so the service can decide whether to undo the update that broke it.
That second one is crash information leaving the device, and we now say so rather than implying otherwise. It is a recovery mechanism, not a monitoring one: it is sent once after a failure, it is not a profile, nobody at REP11 reads a dashboard of it, and neither the identifier nor the error message is connected to a player, a family or an account. Both are declared on our Google Play Data safety listing as Device or other IDs and Crash logs, collected for app functionality and shared with nobody.
RevenueCat processes purchase history for subscription functionality. If we use its dashboard features to inspect that purchase history, the store privacy labels also declare Analytics as a Purchases purpose; that does not enable behavioural tracking, attribution or device-identifier collection. We do not sell personal information, and we do not disclose it for anyone else's advertising.
If that ever changes, it changes here first, and — because the app is used by children — it is a decision made in the open, not a quiet dependency bump.
5. Advertising
- Nobody is shown advertising in REP11 — and because we treat every player as a child (§1), that promise does not depend on anyone's age. Not on any profile, not on any plan, not anywhere.
- Paid plans never show advertising of any kind, to anyone.
- We do promote REP11 itself — for example, telling a parent about a paid plan. These promotions appear on grown-up screens behind a parent gate, never as pressure aimed at a child.
- There is no third-party advertising in REP11, and none is planned. If that ever changed it would be a change to the promises above, and this policy — and the store declarations it feeds — would have to change first, in public, before it launched.
6. Notifications
Reminders are generated on your device and are switched off until a player has a streak worth protecting. They are limited to one a day, a parent can turn them off, and there is no message from us hiding inside them. Because they are local, we do not collect a push token and cannot target them.
7. Children
REP11 is designed for children and used by children, and that shapes everything above rather than adding a paragraph at the end.
- No under-18 can create an account, at any age. There is one account type and it belongs to an adult, so this is not an age gate we have to police — there is simply no signup path for anyone else to take. The adult confirms they are 18 or over and adds a payment method, and the card is the check that matters: at the paying moment, an adult is there.
- Every player is treated as a child, including the adults (§1). We do not sort people into stricter and looser regimes, so nobody's protection depends on us correctly guessing their age.
- A parent or guardian controls a child's profile — creating it, correcting it, and deleting it — from their own account.
- Nothing a child does in REP11 is visible on the open internet, and nothing is visible outside the household unless a parent switches on the club board below. The leaderboard is the household's own profiles by default. There is no friend search, no public profile, no feed, and no way for anyone to message or contact a child through the app.
- The club board is the one sharing feature, and it is off until a parent turns it on. A player whose profile carries a verified club can appear on that club's own board, visible only to other REP11 families at the same club. The board shows exactly four things: first name only (we cut the stored name at the first word — never a surname), avatar, points for showing up this week, and streak. Never a full name, never a photo, and there is no way to reply, react or message from it. The switch lives in the grown-up settings behind the parent gate; a child can ask to be on the board, but the ask is a request and never a grant; and switching it off removes the player from the board immediately.
- We ask parents not to use a child's surname as a display name, and nothing in the app requires one.
- United States (COPPA): REP11 is directed to children, and a child's profile inside a parent's account does reach our server. Putting that record under a parent's account does not stop it being information about a child. What is held is set out in §2.1 in full — it is not only a name, an age band and progress, and any shorter summary of it is wrong.
How a parent consents. Only an adult can create an account, and only the adult who owns it can create a child's profile inside it — there is no path by which a child's record reaches us without an adult signing in and making it. Before that profile is created, the parent is shown, on that screen, the notice set out immediately below. The club board — the only feature that shows anything about a child to anyone outside the household — is separate, off by default, behind the parent gate, and switching it off removes the player immediately.
What a parent is told, and when (the COPPA direct notice — drafted here so the lawyer edits rather than writes it). Before a child profile is created, the parent sees, on that screen and not buried in this page:
- That we have collected their contact details to get their consent.
- That they must consent before their child's profile is created, and what happens if they do not (the child can still train as a local guest, and nothing is sent to us).
- Exactly what we will hold about the child — the list in §2.1, in full, not a summary.
- What we use it for: running their training and showing their progress.
- Who else sees it: nobody, unless the parent later switches on the club board, which is a separate, off-by-default choice.
- That we never use it for advertising, and never sell it.
- That the parent can review it, correct it, export it, refuse any further collection, and delete it at any time — and how.
- A link to this policy.
- Bolly Labs Pty Ltd's name, physical address, telephone number and email — COPPA requires all four, and two email addresses is not enough.
- Australia: we follow the Australian Privacy Principles as our standard. In practice that means: we collect only what the app needs to work (§2 and §3); if you send us something we did not ask for — in a name field, a club name or a feedback note — we will destroy or de-identify it once we notice, unless we could lawfully have collected it; we hold it securely (§8); you can see and correct it (§9); and you can complain, with a process and a timeframe (§10).
We follow the Australian Privacy Principles as our standard, by choice, rather than waiting to be told whether a company our size is legally required to. Australia's Children's Online Privacy Code is due to be registered by 10 December 2026; we intend to meet it, and we will re-read this policy against it when it lands.
- UK / EU (GDPR and UK GDPR). REP11 is available worldwide, so this applies. Controller: Bolly Labs Pty Ltd (ACN 701 365 246), South Australia, Australia. Contact: support@rep11football.com.
- Why we are allowed to hold what we hold. Running the app for you — your profile, your training history, your subscription — is on the basis that it is necessary to perform the agreement you made with us when you created an account. Keeping the service secure and working is on the basis of our legitimate interests, and we have weighed those against your privacy. Two things are consent-only, off by default, and withdrawable at any time: the club board, and reminders.
- Your rights. You can ask us for a copy of what we hold, correct it, delete it, restrict or object to what we do with it, take it elsewhere in a portable form, and withdraw any consent you gave — and withdrawing is as easy as giving it, by turning the same switch off. A child's rights are the child's, even where the record sits inside a parent's account; where the child is old enough to exercise them, we deal with the child.
- Complaining. You can complain to your own country's data protection authority. In the UK that is the ICO; in Ireland the DPC; elsewhere in the EU, your national authority.
- Where your data goes. To Australia, where we are. Australia does not have an EU adequacy decision, so a transfer out of the EU/UK to us relies on Standard Contractual Clauses, which we put in place with our hosting provider.
- Children's consent age in the EU. The age at which a child can consent for themselves ranges from 13 to 16 depending on the country. This does not change what we do, because REP11 never relies on a child's own consent for anything: an adult creates the account, an adult creates each profile, and the two consent-based features — the club board and reminders — are both switched by an adult behind the parent gate.
- Automated decisions. We do not make decisions about you by automated means that produce legal or similarly significant effects. Choosing which drill to suggest is not one of those.
8. Where your information is held, and for how long
- Guest play: on the device. Uninstalling the app removes it. We never receive it.
- Accounts and profiles: on Cloudflare's network (§4), in a database we ask Cloudflare to keep as close to Australia and New Zealand as it can. We should be straight with you about the limit of that promise: Cloudflare's database service takes our region preference as a hint and does not contractually guarantee the data never leaves it, and its network is global by design. So the honest sentence is: we have asked for this region, we expect it, and we cannot guarantee it. If contractual residency in Australia ever becomes something we must promise, we would have to move to a different provider to promise it, and we would tell you before we did. Bolly Labs Pty Ltd is an Australian company, so we are in Australia whatever the servers are doing.
- How long — by category. "Until you delete it" is not a real answer for a child's record, so here is the actual schedule.
| What | How long we keep it | |---|---| | A child's profile and training history | While the account is live. If nobody signs in for 24 months we tell you, and if nothing happens by 36 months we delete it | | Feedback you send us | 12 months | | A club application we approved | The life of the club relationship, then 24 months | | A club application we rejected or you abandoned | 90 days | | Club-board publication records | Removed when you switch it off; the record that you switched it on or off is kept 12 months | | Purchase and subscription records | 7 years — Australian tax law requires it | | Support and privacy correspondence | 24 months | | The log proving we deleted something | 7 years, minimised |
- Deleting. Delete a profile and its training history goes with it. Delete the account and everything under it goes. Deletion from our live systems is immediate. Two honest exceptions:
- Backups. Our database keeps a rolling recovery window of 30 days, so a copy of a deleted record can survive in that window before it ages out. It is never restored to serve anyone; it exists so that a mistake or a failure on our side does not lose your family's training history. So the full sentence is: immediately from live systems, and within 30 days from backups.
- Purchase and deletion records, which we keep for the periods in the table above because Australian law requires it.
- Security. In plain terms: everything travels over an encrypted connection; access to the live database is limited to the people who run the service, which today is a very small number of people; profile PINs are stored only as salted scrypt hashes, never as digits; and there is no advertising, tracking or analytics code in the app at all — which is checked automatically every time we build it, across every source file, and the build fails if that stops being true.
One deliberate exception you should know about, because it is a choice and not an oversight: a profile PIN is never locked out. There is no attempt limit, no timer and no cooling-off period, and we will not add one. A four-digit PIN can therefore be guessed by someone holding the tablet, and we would rather tell you that than imply a strength it does not have. We chose it that way because a child locked out of their own football app by their own PIN is a worse outcome than a sibling guessing 1234, and because the PIN is not protecting anything a person holding the unlocked tablet could not already reach. Treat it as the lock on a bedroom door between siblings, not as the lock on a safe. If you need real protection for a device, use the device's own passcode — that is the one doing the work.
If something does go wrong, we will investigate it, fix it, and tell the people affected and the regulators we have to tell, as quickly as we can establish what happened.
9. Your choices and rights
- See it: ask us for a copy of what we hold about your account.
- Fix it: ask us to correct a name, band or avatar. Age band corrections never remove anything a player already earned.
- Delete it: ask us and we will delete a single player, or your whole account. Deleting a player deletes that player's training history with them.
- Take it with you: ask and we will export your family's training history in a readable format.
- Withdraw: stop using the app; a guest profile never involved us at all.
- Feedback you send us: the notes typed into the in-app feedback box belong to the household, not to any one player, so deleting a player does not delete them. They are included in your export and have their own Delete my notes control, which stays behind the parent gate.
- Who can type it: anyone in the household, including a child. The box takes free text, so the app asks — in the box, in words a child can read — for no names, addresses or phone numbers. Nothing typed there is shown to any other user, and it does not leave the household's own server.
To ask for any of these, contact support@rep11football.com.
10. Complaints
Tell us first — we would rather fix it than be reported for it. Email support@rep11football.com with "Privacy" in the subject and tell us what happened. You can also ring the number at the top of this page, though email is better for this: it gives you a written record of what you asked and when, and the clock below runs from the moment it arrives. If you do ring and we miss you, please leave a message — an unanswered call with no message tells us nothing about who to call back or why (and see §4 for what happens to a message you leave).
What we will do, and when. We will confirm we have your complaint within 5 business days, and give you a substantive answer within 30 days. If we need longer we will tell you why and when. If we got it wrong we will say so, fix it, and tell you what we changed.
If you are not satisfied with our answer, you can escalate — you do not need our permission and you do not have to come to us first:
- Australia: the Office of the Australian Information Commissioner, oaic.gov.au
- UK: the Information Commissioner's Office, ico.org.uk
- EU: your national data protection authority
- Anywhere else: your local privacy or consumer regulator
11. Changes
If we change this policy we will update the version and date above, and for any change that affects children or introduces a new third party we will say so in the app before it takes effect.
If something here is unclear, or you think we have got something wrong, we would genuinely like to know: support@rep11football.com.