Your privacy

Beta privacy notice · Updated September 21, 2026

What we store

XtraBases stores your account email, sign-in records, player profile, birth date for adult eligibility and age, photos, highlights, self assessments, teammate ratings, connections, reports, and support requests. Team features store memberships, messages, media, events, attendance, and lineups.

Who can see it

Your birth date and account email are not included in player cards. Cards show your age. Connected teammates can view your card. If you enable your public player-card link, anyone who knows that link can see the card and its media. Search discovery is a separate opt-in in Edit Bio. Team content is restricted by team membership and roles.

Individual teammate rating records are not shown on cards. Teammate averages appear only after three eligible ratings; position defense is aggregated separately at each position.

Your controls

In Account, disable your public link to stop new public card requests and revoke older share links. This does not remove teammate access. Already-issued media links expire within one minute, but downloaded copies and screenshots cannot be recalled. Remove photos and highlights from your card, change search visibility, or block a player in the app.

Hosting and retention

The app uses OpenAI Sites for hosting and Supabase for account, database, and file services. Those services process information needed to run the app. Data remains while your account and content are active. Removed uploads are hidden immediately and queued for file cleanup if immediate deletion fails. Operational backups may retain earlier copies until their retention period ends.

Privacy and deletion requests

Use Account → Help & privacy requests to request a copy, correction, or deletion of your information. Requests are reviewed by the XtraBases operator. An account-deletion request is not immediate deletion; its status appears in Account. You can disable your public link immediately while a request is reviewed.