Privacy Policy
Effective date: August 15, 2026
Contact: support@bleacherbrag.com
Operator: DALiApps, LLC (Arkansas) — the data controller. It is run by one person, so “I” below means that person.
BleacherBrag makes game-day graphics from photos you choose. This policy explains what I collect, why, and the controls you have. The short version: I collect only what the app needs to work, I never sell data or run ads, the analytics are aggregate-only with no per-user tracking, and you can export or delete everything from inside the app.
What I collect
- Account. Your email address and the sign-in identifier from Apple, Google, or your email/password account (managed by Google Firebase Authentication), plus an optional display name. If you try the app before creating an account, sign-in still happens — anonymously, so no email address is involved and there is nothing to sign back in with.
- Your content. The photos, team logos, and details (names, jersey numbers, schedules, scores, stats) you add to make graphics, and the team/player profiles you choose to save. Photos are often of your kids — see "Children" below.
- Purchases. When you buy a subscription or a watermark unlock, Apple or Google processes the payment. I receive and store the store's transaction record (transaction ID, product, expiry) to grant your entitlement — never your card details.
- Push token. If you enable notifications, a device push token so the app can tell you a graphic is ready. It is removed when you sign out.
- Aggregate usage metrics. I count events like "a graphic was created" or "a render failed" to operate the service. These counts contain no user identifiers — I cannot look up any person's activity in them. There is no advertising SDK in the app and nothing that tracks you across other apps or websites, and I run no analytics product of my own. The app does embed Google's sign-in and push SDKs — see "Third-party code in the app" below for exactly what those collect.
How I use it
To make and deliver your graphics (photos are processed on my servers to extract colors and composite the design), to store what you save (Album, teams, players), to notify you when a render finishes, to grant purchases, to protect the service (rate limits), and to understand usage in aggregate.
Children
BleacherBrag accounts are for adults — parents, guardians, and family members. I do not knowingly let children under 13 create accounts. Photos of minors are uploaded by the adults who control the account, and those adults control them: saved content can be deleted at any time, and deleting your account removes everything.
Sharing
I do not sell personal information, and I do not share it for advertising. Data is handled by service providers only as needed to run BleacherBrag:
- Amazon Web Services — hosting, storage, and delivery.
- Photoroom — when a graphic uses background removal, the photo is sent to Photoroom's API to produce the cutout.
- Google — Firebase Authentication operates sign-in, and Firebase Cloud Messaging routes push notifications. See "Third-party code in the app" for what Google keeps.
- Apple / Google — payments, and platform sign-in when you use the Apple or Google button.
When you share a graphic, free shares include a "Made with BleacherBrag" caption with a link. If someone taps that link, my own redirector counts the tap with a coarse platform label (iPhone/Android/other) — no cookies, no fingerprinting, and no IP address or advertising identifiers are kept.
Storage and retention
- Uploaded source photos are held briefly for rendering and expire within about a week (at most 8 days) (a purchased graphic's source is kept so it can be re-rendered cleanly).
- Rendered graphics expire after about 7 days unless you save them to your Album or purchase them — then they are kept until you delete them.
- Team and player profiles are kept until you delete them.
- If you try the app without creating an account, that trial runs on its own anonymous account, and everything it makes — the graphics, and the anonymous account itself — is deleted after about a day unless you create a free account to keep it. Creating one keeps everything the trial made, because it is the same account either way.
- Deleting your account (Account → Delete Account) permanently removes your account, profiles, graphics, and purchase records from my systems.
- One exception: if a graphic uses background removal, the cut-out subject is cached for up to 30 days so the same photo is not sent to Photoroom twice. That cache is keyed by a fingerprint of the image itself and is not linked to your account, so deleting your account does not clear it — every entry expires on its own within 30 days.
Third-party code in the app
The app embeds these Google SDKs. None is an advertising SDK, and each ships an Apple privacy manifest declaring no tracking.
- Firebase Authentication (both platforms) — signs you in and keeps you signed in.
- Firebase Cloud Messaging (Android) — delivers the "your graphic is ready" notification.
- Google Sign-In (iOS) — the Google button. Its own privacy manifest declares that it may collect a coarse location, a device identifier and usage data, some of it for Google's own analytics. None of that reaches me — it is collected by Google, under Google's privacy policy. Apple aggregates every embedded SDK's manifest into the app's App Store privacy report, so it is listed there whether or not you ever tap that button.
- Google Play Billing (Android) — runs the purchase itself. Payment details go to Google Play; I never see a card number.
- Google Play In-App Review (Android) — shows the "rate this app" sheet, at most three times ever and no more often than once every 90 days, and only after you save or share a finished graphic. It reports nothing back to me — not whether the sheet appeared, and not what you rated.
What Google keeps for sign-in
Firebase Authentication is a Google service, so some sign-in data is held by Google rather than by me. Per Google's Privacy and Security in Firebase:
- IP addresses. Firebase Authentication logs the IP address of sign-in requests and retains it for a few weeks, to detect and block abuse. I do not receive or store IP addresses anywhere in this product.
- Where it is processed. Firebase Authentication processes this data exclusively in data centers in the United States.
- After you delete your account. Deleting your account removes your data from my systems right away (above). Google clears the remaining authentication data from its live and backup systems within 180 days.
Security
Data is encrypted in transit. I never see or store your password — Firebase Authentication handles it — and your signed-in session is kept by Firebase's SDK in your device's own app-private storage (the iOS Keychain; app-private files on Android). Access to your images uses short-lived, signed links.
Your controls
Inside the app you can export your data (Account → Export my data), delete individual items, or delete your account entirely. Delete your account and data is the step-by-step page — including how to ask for a deletion if you no longer have the app installed. For anything else, write to support@bleacherbrag.com and I will honor it.
Changes
If this policy changes, I will update the effective date above and, for material changes, note it in the app or on this page.