Privacy Notice

Last updated: October 2026 (v2.10.89)


Who We Are

Atmos Football is a web app (with a companion Android app on Google Play) for tracking match results, player ratings, and generating balanced teams for casual football and other recreational sports groups. It is developed and operated by James Boucher — an individual, not a company.

For any data protection queries, contact Atmos.football@gmail.com.


What Data We Collect

Player Data

When you play in a group that uses Atmos Football, the following is recorded by your group organiser:

If you add yourself as a guest via the "Not on the list?" link on a sign-up page, your name is stored for that game week only. By entering your name, you are voluntarily providing personal data.

Other Sports Sessions

Groups can also record sessions for sports other than football — for example badminton. For a badminton session, each round is stored as a separate record containing the player names on each side, the score, the winner, and the time it was recorded. This is the same kind of data as a football result and is treated the same way throughout this notice.

New Group Requests (Optional)

If you ask for a new group to be set up from within the app, we store your account identifier, your email address, your display name, the group name and organiser name you propose, an optional description, and the request status (pending, approved, or rejected). It is visible to site administrators and to you, and is used solely to review and create the group. The request record is deleted if you delete your account.

Organiser Invitations

When an admin or organiser invites someone to organise a group, an invitation record is created containing the invited email address, the group, and the role being granted. It exists so the invitation can be matched to the right account at sign-in. Invitation records can be read only by site administrators and by the signed-in holder of the invited email address, once that address has been verified. An invitation is only accepted for an account whose email address is verified. If you register with an email and password, we send you a verification link for this reason. Google sign-in addresses are already verified.

Using the App Without an Account (Anonymous Identity)

You do not need an account to sign up for games. When you open a group's sign-up link, or enter its share code, without being signed in, the app creates an anonymous identifier for your device using Google Firebase Authentication. It is a random code. It contains no name, email address or phone number, and it is never linked to Google Analytics.

The identifier is used to record which groups you belong to, as a group membership record: the anonymous identifier, the group, your role in it (member), how you joined (for example by share code), and when. Simply browsing the public example group does not create one.

Player Accounts (Optional)

Creating a player account is entirely optional — the app works without one. If you choose to register, we store:

Peer Attribute Ratings (Optional — Group Feature)

If a group organiser enables peer attribute ratings, linked players may rate each other on nine attributes: seven FIFA-style skills (Pace, Shooting, Passing, Dribbling, Defending, Physicality and Goalkeeping) and two sliding scales (Play Style — defensive to attacking — and Elo Accuracy — over-rated to under-rated). This feature is off by default and must be explicitly enabled by the group organiser.

When this feature is enabled:

Minimum Players / Conditional Sign-Up (Optional)

If you have a linked player account you can set a minimum number of players for yourself in My Account: "I'll play, but only if at least this many people are playing, including me." The setting is off unless you choose to use it.

When you use this feature:

Team Suggestions (Optional — Group Feature)

If your organiser turns on team submissions, any player who has linked their account to their name can build a line-up in the Team Generator or Game Analysis and send it to the organiser as a suggestion for that week's vote.

Fantasy Premier League (Optional — Group Feature)

If we enable the Fantasy League feature for a group, the app displays that group's Fantasy Premier League classic mini-league table. This feature is off by default and can only be switched on by an Atmos Football administrator — group organisers cannot enable it themselves.

Atmos Football is not affiliated with, endorsed by, or associated with the Premier League or Fantasy Premier League. The data is read from the Premier League's own publicly accessible service, which anyone can view without signing in.

When this feature is enabled:

Group Discovery (Optional — Organiser-Controlled)

If a group organiser chooses to make their group discoverable, the following information is published in a public listing visible to anyone using the Find a Group feature:

Organisers can remove or modify the listing at any time from Admin → Settings → Group Management → Discovery. Removing the listing removes the group from search results immediately.

Find a Group — Location Access (Optional)

When you use the Find a Group feature, you may be asked to share your device location. This is entirely optional — you can browse listings without granting location access, but distance labels ("1.2 km away") and proximity sorting will not be available.

If you grant location access, your coordinates are used in the browser only to calculate distances from group pitch locations. Your location is not sent to our servers and is not stored. Location access is requested only when you explicitly click "Use my location".

If you type an address in the location search box, it is sent to the Nominatim geocoding API (OpenStreetMap) to convert it to coordinates. Your IP address is shared with Nominatim for this request. See the Third-Party Services table for details.

Join Requests (Optional)

If you send a join request to a group via Find a Group, we store:

Your email address is not shared with the organiser. Only your display name and optional message are visible to them.

When your request is approved, a server-side process automatically adds you to the group. No share code entry is required.

Join request documents are retained until they are superseded by a new request to the same group or your account is deleted.

Public Player Profile (Optional)

You may optionally create a public player profile from My Account → Public Profile. If you choose to do so, the following information may be stored and shared:

None of this information is shared until you explicitly save it. The profile is stored in a public subcollection (users/{uid}/publicProfile) and can be read by anyone — it is not restricted to signed-in users.

You can delete your public profile at any time by clearing the fields and saving, or by deleting your account.

Fitness and Health Data (Optional)

If you enable the Match Fitness Sync feature and link your account to a player name, we collect fitness data for games you participate in. This data comes from three possible sources:

Android Health Connect: Summary workout data including distance covered (metres), average heart rate (bpm), peak heart rate (bpm), workout duration (seconds), and heart rate recovery (bpm drop at 1 minute post-exercise). We only collect this data when you explicitly initiate a "Sync" for a specific match.

The Android app requests exactly three Health Connect permissions, all read-only: Exercise (workout sessions), Distance, and Heart rate. It requests no other health data types, and it never writes anything back to Health Connect. In particular, it does not request access to your exercise routes, so no GPS or location data is read from Health Connect and Atmos Football has no access to your location history. You can review or revoke these permissions at any time in Android Settings → Health Connect → App permissions.

TCX file import (all platforms): You may import a Training Center XML (TCX) file exported from your fitness device or app (e.g. Fitbit, Garmin Connect). TCX files typically contain 1-second resolution data including timestamps, cumulative distance, heart rate, and GPS coordinates (latitude/longitude). The file is parsed entirely on your device — the file itself is never uploaded to our servers. See "Where Fitness Data Is Stored" below for details on what is retained.

Manual entry: You may manually enter distance, calories, duration, heart rate, and peak heart rate for any game.

We do not track your live location in the background. GPS data reaches the app only through a TCX file that you choose to import. If that file contains recorded location data (latitude/longitude), it is processed locally on your device to calculate sprint velocity, map your route, and verify distance accuracy. GPS coordinates from imported files are stored only on your device and are never sent to our servers.

High-Resolution Fitness Analysis

When you import a TCX file — the only source of second-by-second data, since Health Connect provides summary figures only — the app computes the following analytics locally on your device:

Sprint and intensity detection: Using 1-second velocity data, the app detects sprint and high-intensity running (HIR) events that are invisible in standard 60-second health data. Adaptive speed thresholds are computed relative to your session's average moving speed.

Post-event heart rate recovery: After each sprint or HIR effort, the app analyses your heart rate for up to 60 seconds to find the true peak (heart rate often continues rising 15–40 seconds after an effort ends) and measures your recovery rate. This delayed HR analysis is necessary because standard instantaneous readings underestimate cardiovascular strain.

Mechanical load: The app detects explosive accelerations (> 2.5 m/s²) and hard decelerations (< −3.0 m/s²) from the velocity data. A 3-second smoothing filter is applied first to remove GPS sensor noise. This measures muscular fatigue from changes in speed that total distance alone does not capture.

Aerobic efficiency: The app compares your heart rate relative to your work rate (metres per minute) between the first and last 15 minutes of active play to assess aerobic decoupling — how much harder your heart works to maintain the same pace as you fatigue.

Speed distribution and percentiles: Time spent in each speed band (walk, jog, run, HIR, sprint) and percentile benchmarks (P50, P75, P90, P95, P99, peak) are computed from the full velocity series.

All of these analyses are performed entirely on your device. The raw 1-second data (velocities, GPS coordinates, heart rate timeline, stride data, acceleration series) is stored only in your browser's local database — it is never sent to our servers. Only summary metrics are stored in the cloud (see below).

Where Fitness Data Is Stored

Fitness data is split between two storage locations:

Data Storage Who can access
Summary metrics — distance, heart rate averages, peak work rate, HIR count, zone breakdown, sprint seconds, peak speed, aerobic efficiency index, mechanical load count, decoupling percentage Cloud (Firebase Firestore, EU region) Only you (authenticated, private subcollection)
Raw high-resolution data — 1-second velocity series, GPS coordinates, heart rate timeline, stride length estimates, acceleration series, individual sprint/HIR event details, recovery curve data Local device only (IndexedDB in your browser) Only you, on the device where you imported the data

This separation is by design. Raw high-resolution data stays on your device because it is large (200–400 KB per game) and contains detailed location and biometric information. Summary metrics are stored in the cloud so your averages and trend charts work across devices.

If you clear your browser data or switch devices, the raw high-resolution data is lost — you would need to re-import the TCX file to restore it. Summary metrics in the cloud are unaffected.

Organiser and Admin Data

If you sign in as an organiser or admin, we also store:

Organisers may also create a player account and link themselves to a player name, in which case the Player Accounts section above also applies.

Analytics Data

If you accept the cookie consent banner, we collect usage data through Google Analytics 4 (GA4). This includes which pages you visit, which features you use (including the Blog tab), and whether you installed the app. For signed-in organisers, your Firebase User ID is sent to GA4 to link your sessions together — this only happens when you have accepted analytics cookies.

If you decline cookies, no analytics data is collected.

Error Reporting (Optional — Consent Required)

If you accept the cookie consent banner, the app automatically sends anonymous error reports when it encounters an unexpected crash or problem. This helps identify and fix issues that would otherwise go unnoticed. Error reporting uses the same consent flag as analytics — accepting cookies enables both; declining disables both.

What is sent in an error report:

What is never sent:

Retention: Error reports are retained until an administrator removes them. There is no automatic deletion.

Opt-out: Decline cookies via the cookie banner or click "Reset preferences" on the Privacy page. Clearing your stored cookie preference also stops error reporting until you make a new choice.

User Feedback (Signed-in — No Analytics Consent Required)

Signed-in users may send feedback — bug reports and feature requests — using the "Send feedback" link at the bottom of every page. This feature does not require analytics cookie consent. Submitting feedback counts as implied consent to store the data described below.

What is stored when you submit feedback:

What is never stored:

Optional technical attachment: On bug reports, you may optionally check "Attach technical details from the last error." This only sends if you have accepted analytics cookies, and attaches the most recent error's stack trace and fingerprint as a separate automated report (same format as the automatic error reporting above).

Who can see feedback: Only site administrators. Feedback is never visible to group organisers, other players, or share-code viewers.

Retention: Feedback is retained until an administrator removes it. You may request deletion by contacting Atmos.football@gmail.com.

Lawful basis: The act of deliberately submitting feedback constitutes implied consent (Article 6(1)(a) UK/EU GDPR). Your email and message are stored solely to investigate the report and respond to you. Text is run through automated PII redaction before storage to remove any incidentally included email addresses or account identifiers.

We do not collect your address, phone number, date of birth, bank account numbers, sort codes, or payment card details.


How We Use Your Data

Your data is used to:

All processing serves the purpose of running your football group's stats, team generation, weekly organisation, personal fitness tracking, and (where opted into) group discovery.


Who Can See Your Data

Your name and match data are visible to anyone who has your group's share code — a private 8-character code distributed by the group organiser. Share codes are not published or searchable. No group data is visible on the internet without the code. This includes your sign-up responses, team votes, match closeness votes, any other-sport session results, your peer attribute rating averages, and your group's Fantasy League table and linked fantasy squads — all visible on the same basis as match results. Team suggestions are the exception — a line-up you send in is readable only by you and your group's organisers, not by other players and not by someone holding the share code.

Group discovery listings — if an organiser opts their group into discovery, the listing (group name, pitch address, typical day/time, format, description, and active player count) is publicly visible to anyone using the Find a Group feature. The listing does not include individual player names, email addresses, or any personal data about group members.

Public player profiles — if you create a public profile, your display name, bio, position, availability, and any per-group rating data you have enabled are visible to anyone — no login required. You control exactly what is shared and can remove or change it at any time.

World Cup sweepstake share page — if your organiser runs a sweepstake and shares its public link, your display name and the team you drew are visible to anyone who has that link — no login required. Nothing else from the group (match data, ratings, contact details) is included on that page. If you would rather not appear, ask your organiser not to enter you in the sweepstake.

Cohorts — if your organiser puts you in a cohort, its name and the names of everyone in it are stored on the group's record. That record can be read without a share code. Treat membership as visible to anyone, and its name as public, even though the app only shows the filter to people viewing the group. Only organisers and admins can change who is in a cohort.

Minimum players (conditional sign-up) — the number you set is visible only to you and to your group's organisers and admins; no other player and no share-code viewer can see it. A count of how many people are waiting on numbers is shown on the sign-up page to anyone who can view it, including visitors who are not signed in — that count never names anyone and never reveals any individual's number.

Group membership records — whether you have an account or an anonymous identifier, your membership record in a group (your role, how you joined, and any linked player name) can be read only by you and that group's organisers and admins. Other players and share-code viewers cannot see who is a member.

Join requests — when you submit a join request to a group, your display name and optional message are visible to the organisers and admins of that group. Your email address is not shared. Your request status is visible only to you and the group's organisers/admins.

Organiser email addresses are visible only to other organisers and admins within the same group.

Payment data — including payment status per game, credit balances, and bank name aliases — is visible only to group organisers and admins. Other players and share-code viewers cannot see payment information, with one exception: if your organiser has set a sign-up debt reminder amount for everyone to see and you owe at least that much, other signed-in members of your group can see on the sign-up page that you owe money and how much. Share-code viewers never see it.

Player account email addresses are not visible to other players. They are visible to site admins, and to a group's organisers and admins in one place only: the link request you send when you ask to link your account to a player name in that group (see Link requests above).

Push notification tokens are stored in your account record and are not visible to organisers or other players.

Fitness Data Privacy: Unlike match results and Elo ratings, your fitness data (distance, heart rate, sprint analysis, recovery metrics, GPS coordinates) is strictly private. Summary metrics are stored in a secured area of the database that only you can access. Raw high-resolution data is stored only on your device and never leaves it. No fitness data — whether summary or raw — is visible to group organisers, admins, other players, or anyone using a group share code.

We do not sell or share your personal data with third parties for marketing purposes.


Data Accuracy Disclaimer

The fitness analysis features in Atmos Football depend on the accuracy of data from your tracking device (e.g. Fitbit, Garmin, Apple Watch). Consumer fitness trackers have inherent limitations:

All metrics should be treated as relative indicators across your own games over time, not as absolute physiological measurements. Trends over 5 or more games are significantly more reliable than single-game numbers.


Cookies, Analytics, and Advertising

Google Analytics 4

We use GA4 to understand how the app is used — which pages are popular, how many people install the app, and how features are adopted. GA4 is only activated if you accept cookies via the consent banner shown on your first visit.

You can change your cookie preference at any time using the Reset preferences link on the Privacy page.

Google AdSense (Blog Pages Only)

We use Google AdSense to display advertisements on the public blog pages at /blog/. Since September 2026 (v2.10.38) AdSense is no longer loaded anywhere inside the app itself — there are no ads on the leaderboard, the sign-up flow, the stats tabs or any other signed-in screen, and the ad script is not requested on those pages at all. Ad-related cookies are gated behind the consent banner on the blog pages — they are only set if you accept. AdSense is not used on the Android app.

Google AdMob (Android App Only)

The Android app uses Google AdMob to display ads. AdMob is Google's mobile advertising platform and is separate from AdSense. The type and frequency of ads you see depends on your subscription tier:

AdMob uses a device advertising identifier (Google Advertising ID) and may use it for ad personalisation if you have accepted cookies. If you decline cookies, only non-personalised ads are shown. You can reset or opt out of ad personalisation in your device settings under Google → Ads.

Google's own consent form, and how to change your answer

If you are in the UK, the EEA or Switzerland, Google shows its own consent message when you first open the Android app — before any ad is requested. This is separate from our cookie banner: ours covers analytics, error reporting and ad personalisation within the app; Google's covers what Google and its advertising partners may do.

You can reopen Google's form and change that answer at any time using the "Ad privacy settings" control, which appears in two places in the Android app:

The control appears only where Google requires it, so you will not see it on the web version or on devices outside the regions where it applies.

Choosing Reset preferences on the About page clears both records together — our cookie choice and Google's stored consent — so the app's banner and Google's form both appear again next time you open the app.

The AdMob SDK is provided by Google LLC. Their privacy policy applies: policies.google.com/privacy.

What Happens When You Decline

If you decline cookies, the app works identically. No analytics are collected, no error reports are sent, only non-personalised ads are shown (web and Android), and no usage data is sent to Google beyond what is strictly necessary.

Declining does not stop the app storing a small amount of information in your browser's own storage, because that never leaves your device. This covers your cookie choice itself and your own display preferences — for example which tab opens by default, which leaderboard columns you have chosen to show, your team-generator and prediction settings for a group, your maximum heart rate if you have entered one, whether you have dismissed a setup prompt, and when a rewarded ad-free period expires. None of this is transmitted to us, and you can clear all of it by clearing your browser data (or the app's storage on Android).


Data Storage and Security

All cloud data is stored in Google Firebase (Firestore), located in the EU region (europe-west2, London). Firebase is operated by Google LLC under standard data protection terms, including appropriate safeguards for international data transfers.

Google acts as a data processor on our behalf. Their Data Processing Agreement is part of the Firebase Terms of Service.

High-resolution fitness data (1-second velocity, GPS coordinates, heart rate timeline, acceleration series) is stored locally on your device using IndexedDB — a browser-based database. This data does not leave your device and is not accessible by us or any third party. It persists until you clear your browser data or uninstall the app.

The app uses HTTPS for all connections, and access to group data is controlled by share codes (for viewers) and Firebase Authentication (for organisers). Firestore Security Rules restrict who can read and write data at the database level. Subscription tier fields on your account can only be modified by the system after payment confirmation — they cannot be changed by any client-side code.


How Long We Keep Your Data


Your Rights

Under UK data protection law (UK GDPR / Data Protection Act 2018) and EU GDPR, you have the right to:

To exercise any of these rights, email Atmos.football@gmail.com with your name and the group you belong to. We will acknowledge your request within 72 hours and complete it within 30 days.

Erasure works along two separate tracks, and it is important to understand the difference:

How Erasure Works — Match Records

Match records cannot simply be deleted. Every result contains the line-ups for both teams, and the group's Elo ratings, chemistry figures, and head-to-head records for every other player are calculated from those line-ups. Removing a player's games outright would silently corrupt the statistics of everyone they ever played with or against.

So instead of deleting, we anonymise. If you want your personal information taken out of a group's records, email Atmos.football@gmail.com and we will replace your name with a numbered placeholder (e.g. "Removed Player #1", "Removed Player #2") everywhere it appears. Your results stay in the group's history, but nothing in them identifies you. If you would prefer a different placeholder, say so in your email and we can use one.

This is a manual process handled by the site administrator, because it rewrites shared group data rather than your own account and cannot be undone once done.

When a player is anonymised, their name is replaced with that identifier across all game records. This preserves the integrity of the group's statistics — win/loss records, Elo calculations, and chemistry data for the remaining players stay correct — without retaining any personal data about the removed player. The replacement is permanent and cannot be reversed.

The same replacement is applied to the other places your name appears in the group: sign-up responses, team votes, team suggestions, payment records, match closeness votes, peer attribute ratings, sealed season standings, and the stored ratings snapshot. Any associated data (tier assignments, active player list entries, cohort membership, sign-up debt reminder exemptions) is also cleared.

Records of sessions in other sports (e.g. badminton rounds) are not covered by the automated tool and are handled manually as part of the same request — tell us if your group has used that feature so we can include them.

How Erasure Works — Player Accounts

If you have a player account, you can delete it yourself at any time from My Account → Delete account. Deleting your account immediately and permanently:

High-resolution fitness data stored locally on your device (IndexedDB) is not affected by account deletion — it exists only in your browser and can be removed by clearing your browser data.

What account deletion deliberately does not do: it does not touch your match history (results entered by your organiser). Those records stay in the group's statistics under your player name, because deleting them would break the ratings and chemistry figures of everyone you played with — see "Match Records" above for why.

Deleting your account is instant and self-service precisely because it only affects data that is yours alone. If you want your name removed from the match history as well, email Atmos.football@gmail.com. The two are independent — you can do either without the other, in any order.

Data Removal for Organisers

Group organisers can request removal of any player from their group's records by emailing Atmos.football@gmail.com. Organisers are responsible for ensuring they have a reasonable basis for adding a player's results to the app in the first place.


Lawful Basis

Data Lawful Basis
Player match data (name, results, sign-up responses, team votes, match closeness votes, other-sport session results) Legitimate interest (Article 6(1)(f)) — operating a recreational leaderboard and team generator. Players in a casual group reasonably expect their results and their organising responses to be tracked as part of the group's activity.
Team suggestions (proposed line-ups, submitter name and account ID) Legitimate interest (Article 6(1)(f)) — letting players take part in how the sides are picked. Submitted voluntarily, only while the organiser has the window open, readable only by the submitter and the group's organisers, and deleted with the event.
New group requests (account identifier, email, display name, proposed group and organiser name, description) Consent (Article 6(1)(a)) — you submit the request voluntarily so that a group can be created for you. Deleted if you delete your account.
Organiser invitations (invited email address, group, role) Legitimate interest (Article 6(1)(f)) — necessary to grant an agreed organiser the correct access to the group they will run.
Season archives (final standings and podium player names) Legitimate interest (Article 6(1)(f)) — preserving the group's own competitive record, the same basis as match results.
Player accounts (email, display name, subscribed groups, notification preferences, push tokens, identity links, link requests) Consent (Article 6(1)(a)) — creating an account is entirely voluntary. By registering, you consent to storage and use of this data to deliver account features. You may withdraw consent at any time by deleting your account.
Subscription tier and expiry Consent (Article 6(1)(a)) — stored as part of your player account to deliver the features included in your subscription.
Organiser accounts (email, Firebase UID, assigned groups) Legitimate interest (Article 6(1)(f)) — necessary to authenticate organisers and track who made changes to group data.
Analytics and advertising cookies (web) Consent (Article 6(1)(a)) — managed by the cookie consent banner.
Automated error reports (crash type, stack trace, breadcrumbs, group ID, Firebase UID) Consent (Article 6(1)(a)) — gated behind the same cookie consent banner as analytics. Only collected if you accept.
User feedback (message, title, email, Firebase UID, technical context) Consent (Article 6(1)(a)) — implied by the deliberate act of submitting. Requires sign-in; no analytics cookie needed.
AdMob ads and advertising identifier (Android) Consent (Article 6(1)(a)) — personalised ads require cookie consent. Non-personalised ads are shown without consent.
Payment data (payment status, bank name aliases, credit balances) Legitimate interest (Article 6(1)(f)) — necessary for organisers to manage group finances. Payment tracking is a natural extension of organising a recurring sports group and replaces informal manual record-keeping.
Fitness summary metrics (distance, average and peak heart rate, peak work rate, HIR effort count, Zone 5 time, full zone breakdown, sprint seconds, HIR seconds, peak speed, aerobic efficiency index, mechanical load count, aerobic decoupling percentage, heart rate recovery drop, work:rest ratio, speed percentiles) Explicit Consent (Article 9(2)(a)) — health data is special category data under GDPR. You must explicitly opt in to fitness tracking in account settings, separate from OS-level permissions. You can withdraw consent at any time by disabling the feature or deleting your data.
High-resolution velocity data (1-second speed, distance, heart rate) Explicit Consent (Article 9(2)(a)) — processed locally on your device to detect sprints and high-intensity events that are invisible in standard 60-second health data. Stored on-device only (IndexedDB).
GPS coordinates (latitude/longitude, from an imported TCX file only) Explicit Consent (Article 9(2)(a)) — processed locally on your device to calculate velocity, verify distance accuracy, and optionally map your route. Stored on-device only. Never sent to our servers. No location data is read from Health Connect.
Post-event heart rate recovery data Explicit Consent (Article 9(2)(a)) — the app analyses heart rate for up to 60 seconds after each sprint or high-intensity effort to measure true peak HR and recovery rate. This delayed analysis is necessary because heart rate sensors lag behind actual exertion and standard instantaneous readings underestimate cardiovascular strain. Summary metrics (average recovery drop, average HR lag) are stored in the cloud; raw per-second HR data remains on-device only.
Group discovery listing (group name, pitch address, GPS coordinates, format, description) Legitimate interest (Article 6(1)(f)) — organiser-controlled opt-in to make the group findable by prospective players. No personal data about individual players is published. Organisers can remove the listing at any time.
Join request data (display name, message, request status) Legitimate interest (Article 6(1)(f)) — necessary to allow prospective players to contact a group organiser and for organisers to manage admission. The requesting player's email is not shared with the organiser.
Public player profile (display name, bio, position, availability, per-group rating visibility) Consent (Article 6(1)(a)) — entirely optional. Nothing is published until you explicitly save your profile. You can remove it at any time.
Achievements (season podium finishes, teammate commendations) Legitimate interest (Article 6(1)(f)) — recognising recreational sporting achievements within the player's own group context. Achievements only attach to accounts that have voluntarily linked themselves to a player name; recipients can remove all achievements by deleting their account.
Peer attribute ratings (rater UID, player names, attribute scores) Legitimate interest (Article 6(1)(f)) — supplementary skill profiling within a closed football group, opted into by the organiser and by each individual rater. Off by default; only available to groups at tier 4 or above. Raters' submitted documents are deleted on account deletion.
Device location (Find a Group proximity search) Consent (Article 6(1)(a)) — requested only when you explicitly click "Use my location". Used in the browser only to calculate distances; not sent to our servers or stored.

Third-Party Services

We use the following third-party services, each of which acts as a data processor:

Service Provider Purpose Data Shared
Firebase / Firestore Google LLC App data storage and authentication Player names, match data, organiser emails, player account data, fitness summary metrics
Firebase Cloud Messaging Google LLC Push notifications (account holders only) Push notification device tokens (FCM tokens)
Google Analytics 4 Google LLC Usage analytics (consent required) Page views, feature usage, Firebase UID (organisers only)
Google AdSense Google LLC Advertising on the public blog pages only — not inside the app (consent required) Ad interaction data via cookies
Google AdMob Google LLC Advertising on the Android app Device advertising identifier (Google Advertising ID); personalisation requires consent
Android Health Connect Google LLC Reading fitness data (Android) Read-only access to exactly three data types from the on-device health store: ExerciseSession (workout duration and type), Distance (metres covered), and HeartRate (average and peak bpm). No exercise route/GPS access is requested, and nothing is written back.
OpenStreetMap tile servers OpenStreetMap Foundation Map tile rendering for the GPS heat map (street view) Your IP address is sent to OSM tile servers when you open the heat map. No personal account data is shared. Tiles are © OpenStreetMap contributors (ODbL).
Esri World Imagery tile servers Esri Map tile rendering for the GPS heat map (satellite view) Your IP address is sent to Esri tile servers when you select satellite view. No personal account data is shared. Tiles © Esri, Maxar, Earthstar Geographics.
Open-Meteo API open-meteo.com Game-day weather forecast on the sign-up screen Your IP address is used to fetch forecasts. No account data is shared. Weather data is provided under CC BY 4.0; see open-meteo.com.
football-data.org football-data.org Fetching public tournament fixtures and results for the World Cup sweepstake Nothing. Requests are made by our server on a schedule, never by your device, and contain no user or group data.
Nominatim (OpenStreetMap) OpenStreetMap Foundation Address-to-GPS geocoding in Find a Group setup When an organiser or user types an address and clicks "Set GPS from address", that address string and your IP address are sent to the public Nominatim API to convert the address to GPS coordinates. No account data is shared. Usage is subject to the Nominatim usage policy.

No data is shared with any other third parties.


Children's Data

Atmos Football is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child's data has been added to the app, contact us and we will remove it.


Changes to This Notice

We may update this notice from time to time. The "Last updated" date at the top will always reflect the most recent revision. Significant changes will be noted in the app's Change Log.


Contact

For any questions about your data, this privacy notice, or to exercise your data rights:

Email: Atmos.football@gmail.com


Home · Blog · About · Contact · Privacy