REP11 Privacy Policy

Applies to: the REP11 app on Android and iOS (on iPhone and iPad it is in Apple's TestFlight beta testing for now), the household web version of REP11, and the REP11 website. Publisher: Bolly Labs Pty Ltd (ACN 701 365 246), South Australia, Australia. Contact: support@rep11football.com (If you already have hello@rep11football.com, that reaches us too, it is the same inbox, and you never need to re-send anything to the address above.) Postal address: Reception, 16 Matthew Street, Stanthorpe QLD 4380, Australia Telephone: +61 420 100 690

Version: v1.12 · first published 2026-08-24, effective 2026-08-25 · v1.12 effective 2026-10-08 (§11 lists what changed) · published before legal review, see the note below.

About this version: please read this first. This policy describes what REP11 does today. The claims it makes about the code in the app (that there is no advertising or behavioural tracking code, that it never asks for the camera, microphone or location, and that deleting a player removes everything held about them) are checked automatically against our own source code each time we build the app. It has not yet been reviewed by a lawyer. That review will happen before REP11 is released publicly, and if it changes anything here we will publish the new version and say what changed. We would rather tell you that plainly than let a polished page imply a sign-off it has not had.

The short version

REP11 is a football training app used mostly by children. We built it so that using it well requires almost nothing about you.

The rest of this document is the detail behind those sentences.

Which REP11 each section describes. Parent sign-in and family account records are available in the store app. When a grown-up signs in, the app backs up the family's players and training to REP11's family service so it can be restored on another phone. Signing in is the consent; a grown-up can stop backup by signing out of the phone, or delete the account, in Account settings. The screen shows the last completed backup; do not assume data is recoverable until that completes. The designated purchase rehearsal uses a separate test service and disposable test families. It does not replace a U12 household's lasting account or complimentary access. Club features described below remain specific to the private household web version unless the app explicitly offers them.

Family backup. After the account holder signs in, REP11 stores players' nicknames, age bands, appearance, plans, player choices, drill and quiz history, scores, rep totals, streak protection, trophies and family cheers in its family service on Cloudflare (§4 and §8 say where that is). Consent covers players later added on that phone. Because the store app now asks a grown-up to sign in before anyone trains, every family using the store app has this backup; the only way to stop it is to sign out of that phone (§9). Backup runs while the app is open and online; offline changes remain local until a later successful backup. Signing in to the same account on a replacement phone can restore the saved family. Matching nicknames never merge players. Device preferences, downloaded media and profile PINs are not backed up. Child training is not sent to RevenueCat, advertising or behavioural tracking services.

A grown-up can sign out of a phone, which stops its backup, without deleting local practice or the existing cloud copy. Account deletion removes the account and a family solely owned by it from the live service; a family with another adult remains. Deleted data can remain in Cloudflare backups for up to 30 days. Uninstalling a phone's app removes its local practice, including changes that have not completed backup. Rehearsal data on the separate test service is not migrated into a lasting family account.


1. Who this policy is for

People use REP11 in four different ways, and the answer to "what do you hold about me" is different for each:

What existsWhere it lives
A Little Baller (under 5)The grown-up runs the session from their own device. No score, streak, star or reward is kept. In the household web version a grown-up can save a Little Baller's first name so they can be picked from the list, the child can pick an animal picture, and each time the grown-up taps "We played!" on a game the app saves which game it was and how long it was open, so the grown-up can see it under View progress. The app on Google Play has no under-5 mode at allIn the web version: the name, the animal and that play log, under the adult's account, included in an export and removed when the Little Baller is removed. Nothing in the store app
A guest player (any age), only on a phone that was already playing as a guest before the store app stopped offering itA new install of the store app has no guest option: a grown-up signs in first. A phone that was already playing as a guest keeps working: its local profiles (chosen name, age band, avatar, training history) stay where they are, and nothing is deletedThe device only, until a grown-up chooses "Save my progress" and signs in, then those players join the family and are backed up like any other
Anyone under 18 in a householdA profile inside an adult's account. A player in the 13+ age band may also be given their own Google or Apple sign-in by a grown-up of the household. We keep only the sign-in identifier, never their email addressOur server, under that adult's account
The adult who owns the accountAn account: sign-in identity, email address, subscription state, and the list of phones signed in to it (§2.2)Our server

The rule underneath the table: an account belongs to an adult, and only to an adult. One grown-up signs up and pays; everyone under 18 plays as a profile inside that account. A grown-up may give a player in the 13+ age band their own sign-in for their own phone; it shows only that player's own training, never the account, plans or other players. There is no child email address, and no way for a child to be contacted through this app.

We treat every player as a child. Rather than sorting people into stricter and looser regimes by age, we apply the protections designed for children to everyone who uses REP11, including the adults. It is simpler, it is safer, and it means we never have to guess someone's age to know how to treat their information.

An account is the main thing that creates a record with us, but it is not the only one: feedback you send us (§2.3) and a club application (§2.5) are also records we hold, and both can exist without an account.


2. What we collect

2.1 A player profile (child or adult)

2.2 An account, always held by an adult

An account is created by an adult, who confirms they are 18 or over. The account holder. That adult may be a parent, a guardian, or an adult who plays REP11 themselves; being a parent is not required. Where the account is paid for, the payment goes through Apple or Google, so an adult is necessarily present at that moment; a free account rests on that confirmation alone. Everyone under 18 in the household is a profile inside that account (§2.1), never an account holder. The app on Google Play and the App Store asks for this sign-in first. See the note under the short version.

We never set or store a password, so there is no password for us to lose.

2.3 Feedback you choose to send

If you use the in-app feedback control we store what you wrote, what screen it was about, and the app version. Please don't put personal details in it; we don't need them, and we'd rather not hold them. The app has a "GIVE FEEDBACK" button on most screens; it sends only the words you type, the reason you pick and which screen it was about, never which player wrote it.

A picture of the screen, for grown-ups and players aged 13 or older. When a grown-up, or a player aged 13 or older, sends feedback from the app, a picture of the screen they were on goes with the note, so we can see what they mean. It is shown before it is sent and can be taken off by tapping Remove. That picture can show what was on the screen at the time, such as a player's first name or avatar, so we treat it like the note itself: it comes only to us, nobody else can see it, and it is deleted with the note (12 months, §8). A child's feedback never carries a picture.

My feedback. The phone remembers the notes it sent, so a grown-up can see in Account settings what happened to each one. To ask, the phone sends us the note's number and a code made from the note's own words. Nothing else, and no account or player is attached.

When something goes wrong. If signing in, backing up or syncing fails, the app sends us a short note of which step failed and its error code, with the app version and the kind of phone. It never includes a name, an email address, an account, anything about your child or anything typed, and we keep these notes for 14 days. We only count them, so we can see when something is broken for families and fix it.

2.4 The website

Reading the public pages at rep11football.com collects nothing about you. The pages, this one included, carry no analytics, no tracking pixels, no advertising code, no embedded third-party content, and no cookies of any kind. Nothing on the site needs to remember you, so nothing does. (app.rep11football.com is different: it is the household web version of the REP11 app itself, not a page about it. It runs the app's own code, holds the household's profiles as described in §2.1 and §8, and is reachable only from inside our private network, so a stranger cannot open it.)

The one page that can receive anything is the feedback page (/feedback), and it only holds what you choose to put in it:

That page uses JavaScript to work (the rest of the site runs none), and what you submit is stored with our hosting provider (§4, Cloudflare) in a database in their Oceania region. The admin view of that page, which only we use, remembers our own access key in our own browser. It stores nothing in yours.

As with any website, our hosting provider handles each request and sees the IP address it came from, in the ordinary course of serving the page. We do not receive that as a report and build no profile from it.

If we ever add analytics to the website, this section changes first, and so do our store declarations.

2.5 A club application (adults only)

A club official can apply, from the club page of the household web version (the app on Google Play has no club page today), to affiliate their club with REP11. The form collects what it shows: the club's name, website, suburb and state, and the applicant's own name, role and email address. This is business contact information about an adult, used to assess the application, manage the affiliation and reply to the applicant. It is stored with our club records, not on any player's profile, and players never see it. If the club is approved, the only club identity that ever reaches a player's screen is the club's name and badge. Ask us at the contact address above to correct or delete an application's details.


2.6 Everything the app on Google Play and the App Store sends

This is the whole list. Each item says where it goes and points to the section with the detail.

Nothing about a player goes to an advertiser, a data broker or an analytics company, and the app contains no advertising or tracking code.

App updates. The REP11 app checks whether a newer version of itself is available, and downloads it if there is one. That check goes to Expo (§4), the company whose build tools REP11 is made with, not to us.

What the check carries:

What the update check does not carry: no profile, no name, no age band, no avatar, no scores, no training history, no quiz answers. None of what the app records is any part of it. That goes only to REP11's own family service, as listed above.

In our Google Play Data safety declaration this ID is why the app answers yes to Device or other IDs: collected for app functionality, not shared with anyone, and not linked to any person. We collect it only so the app can be updated, which is an internal operation of the app; it is never used to contact anyone or to build a profile of anyone, and we could not do either because we never receive it. Expo's crash information is explained under Expo in §4. The rest of the list above is what our store declarations describe as the account, the training record, app activity, feedback and diagnostics.

Uninstalling the app discards the ID. With the phone offline the check finds nothing and everything else works normally.

2.7 How we check REP11 is working for families

About once a week we read, from REP11's own family service, which days each family trained, plus a few yes-or-no facts we already hold to run the app: which day the family first signed in, whether it has a plan, whether it joined a coach's team and whether a second grown-up joined. We use it to see whether families keep coming back, and to fix what makes them stop.

What we keep from that reading is one row per family with no family id, account, email, name, child, drill, score or time of day in it, and the rows are shuffled so they cannot be matched back to a family. Our own family is left out. Nothing new is collected for it: it is read from the backup the app already makes, and it is never shared, sold or used for advertising. No analytics company is involved. It is a reading we take ourselves.

3. What we deliberately do not collect

This list is the product decision, not a courtesy:


4. Who else is involved

We keep this list short on purpose, and every addition to it is a decision reviewed against this policy, not a technical detail.

We do not use advertising networks, data brokers, behavioural analytics SDKs, or any crash-reporting service that profiles users or follows them between apps.

One correction, made 2026-08-31, because the sentence above used to say "or crash-reporting services" without qualification and that was not accurate about the Android app. The app-update service described under App updates above (Expo) does two things we had not spelled out. It sends a random installation identifier with every update check, so it knows which installation to send an update to. And if the app has failed to start, the next update check carries the error message from that failure, so the service can decide whether to undo the update that broke it.

That second one is crash information leaving the device, and we now say so rather than implying otherwise. It is a recovery mechanism, not a monitoring one: it is sent once after a failure, it is not a profile, nobody at REP11 reads a dashboard of it, and neither the identifier nor the error message is connected to a player, a family or an account. Both are declared on our Google Play Data safety listing as Device or other IDs and Crash logs, collected for app functionality and shared with nobody.

RevenueCat processes purchase history for subscription functionality and purchase analytics, so the store privacy labels declare App functionality and Analytics for purchase history. This does not enable behavioural tracking of practice, advertising attribution or automatic device-identifier collection. We do not sell personal information, and we do not disclose it for anyone else's advertising.

If that ever changes, it changes here first, and, because the app is used by children, it is a decision made in the open, not a quiet dependency bump.


5. Advertising


6. Notifications

Reminders are generated on your device. The device shows them, and there is no message from us hiding inside them. Because they are local, we do not collect a push token and cannot target them.

Two honest details. The phone app's practice reminder is also local: the phone schedules it, it asks permission once, and it can be switched off in Settings. In the household web version a reminder is on by default: it stays silent until a player has a streak worth protecting, is limited to one a day, never fires in the quiet hours, and a grown-up can switch it off permanently. An explicit off is remembered forever. Whether one is due is decided by the REP11 server that holds the profile, so the one-a-day rule cannot be argued with by a device; that check tells the server the hour of the day where the device is, and nothing else.


7. Children

REP11 is designed for children and used by children, and that shapes everything above rather than adding a paragraph at the end.

How a parent consents. Only an adult can create an account, and only the adult who owns it can create a child's profile inside it. There is no path by which a child's record reaches us without an adult signing in and making it. Before we open REP11 beyond closed testing, the parent will be shown, on that screen and before the profile is created, the notice set out immediately below. In the store app today, a child's profile and training record reach us as part of the family backup, and only after the grown-up has signed in, ticked that they are 18 or over and agreed to this policy (§1, §2.6). The club board, a coach's view and the team wall (the only features that show anything about a child to anyone outside the household) are each separate, off by default, switched on only by a grown-up of the household, and switching either off removes the player immediately.

What a parent is told, and when (the COPPA direct notice: drafted here so the lawyer edits rather than writes it). Before a child profile is created, the parent will see, on that screen and not buried in this page:

What the store app sends is listed in full in §2.6: the family backup of the child's profile and training (under the grown-up's account and consent), the team features a grown-up switches on, feedback, the failure notes, and the update check. Two persistent identifiers are involved, and both exist only to support the app's own internal operations: the update-check identifier (delivering updates. We never receive it), and the grown-up's sign-in record for each phone (keeping the account signed in and secure, §2.2). Neither is used to contact a child, to build a profile of anyone, or for advertising.

We follow the Australian Privacy Principles as our standard, by choice, rather than waiting to be told whether a company our size is legally required to. Australia's Children's Online Privacy Code is due to be registered by 10 December 2026; we intend to meet it, and we will re-read this policy against it when it lands.


8. Where your information is held, and for how long

| What | How long we keep it | |---|---| | A child's profile and training history | While the account is live. If nobody signs in for 24 months we tell you, and if nothing happens by 36 months we delete it | | The account itself: sign-in identity, email address, join codes | The same rule as the profiles under it: deleted with everything under it at 36 months of silence, or immediately when you delete the account | | A player's own sign-in (13 and over). The sign-in identifier and its session records | Until a grown-up takes it away, the player or the family is deleted, or the player deletes it in the app | | Sign-in records: when each sign-in started and was last used, how it signed in, and the kind of phone (§2.2) | While the account exists, including phones that have been signed out; deleted with the account | | A one-time sign-in code | Kept only as a scrambled (hashed) form; works for 10 minutes; deleted once used, or cleared out after it expires | | The weekly reading of which days families trained (§2.7) | Kept by us with no family id in it, for as long as it helps us improve REP11; it cannot be matched back to a family | | A coach's team, the families that joined it and each player's switch | Until you leave the team or delete your account; a head coach deleting their account removes the team | | The team wall. Each player's switch, the cheers, handshakes, shout-outs and goals | Until you leave the team, or delete the player or your account | | A REP11 Arena link, which players it may show | Until you remove Arena at REP11 › Arena devices, or delete your account | | Feedback you send us | 12 months | | A note that signing in, backing up or syncing failed (§2.3) | 14 days, as daily counts | | A club application we approved | The life of the club relationship, then 24 months | | A club application we rejected or you abandoned | 90 days | | Club-board publication records | Removed when you switch it off; the record that you switched it on or off is kept 12 months | | Purchase and subscription records | 7 years: Australian tax law requires it | | Support and privacy correspondence | 24 months | | The log proving we deleted something | 7 years, minimised |

One deliberate exception you should know about, because it is a choice and not an oversight: a profile PIN is never locked out. There is no attempt limit, no timer and no cooling-off period, and we will not add one. A four-digit PIN can therefore be guessed by someone holding the tablet, and we would rather tell you that than imply a strength it does not have. We chose it that way because a child locked out of their own football app by their own PIN is a worse outcome than a sibling guessing 1234, and because the PIN is not protecting anything a person holding the unlocked tablet could not already reach. Treat it as the lock on a bedroom door between siblings, not as the lock on a safe. If you need real protection for a device, use the device's own passcode. That is the one doing the work.

If something does go wrong, we will investigate it, fix it, and tell the people affected and the regulators we have to tell, as quickly as we can establish what happened.


9. Your choices and rights

To ask for any of these, contact support@rep11football.com.


10. Complaints

Tell us first. We would rather fix it than be reported for it. Email support@rep11football.com with "Privacy" in the subject and tell us what happened. You can also ring the number at the top of this page, though email is better for this: it gives you a written record of what you asked and when, and the clock below runs from the moment it arrives. If you do ring and we miss you, please leave a message. An unanswered call with no message tells us nothing about who to call back or why (and see §4 for what happens to a message you leave).

What we will do, and when. We will confirm we have your complaint within 5 business days, and give you a substantive answer within 30 days. If we need longer we will tell you why and when. If we got it wrong we will say so, fix it, and tell you what we changed.

If you are not satisfied with our answer, you can escalate. You do not need our permission and you do not have to come to us first:


11. Changes

If we change this policy we will update the version and date above, and for any change that affects children or introduces a new third party we will say so in the app before it takes effect.

What changed in v1.12 (2026-10-08). We brought this policy into line with the app as it is now and with what our store forms say. A new install of the store app has no guest option. A grown-up signs in first; phones already playing as guests keep their players and can save them (§1, §8). §2.6 now lists everything the store app sends (sign-in, the family backup of players and training, team features, feedback, failure notes, drill videos and update checks), instead of saying nothing else leaves the phone, and §4 and §8 say where it is held: REP11's family service on Cloudflare, with its databases placed in Cloudflare's Oceania region. Sign in with Apple is live on iPhone and iPad, and a one-time email code is the third way in (§2.2). We describe the PINs and grown-up check in the phone app (§2.1), the kind of phone kept with each sign-in and the Signed-in devices list (§2.2), and the security email to the account holder when a phone signs in (§2.2). One new company is involved: Resend, which sends the sign-in codes and those security emails from Japan (§4). And we describe the weekly reading of which days families trained, kept with no family id, that tells us whether REP11 is working (§2.7). The header now says the app is on iOS too (in Apple's TestFlight beta testing for now). The coach's view, shirt numbers, the failure notes and "no advertising from any other company" are unchanged. Corrected later the same day, still v1.12: §4 describes the two emails as they now look (a simple REP11 email with our logo and a plain-text copy, still with no tracking of any kind), and the policy's wording no longer uses dashes. Nothing about what we collect, why, or who we share it with changed.

What changed in v1.11 (2026-10-08). Three things. We now say what a coach sees in the plainest words: the player's first name and in-game avatar (a cartoon player built from preset parts, not a photo), and a shirt number the coach can give each player for the team (§7). If signing in, backing up or syncing fails, the app now sends us a short note of which step failed and its error code, with the app version and the kind of phone (never a name, an email, an account or anything about your child) kept for 14 days (§2.3, §8). No new company is involved.

What changed in v1.10 (2026-10-08). Three things. A coach now sees the avatar a player built in REP11 beside their first name (the cartoon figure, never a photo), so two players with the same name can be told apart; nothing else about the player reaches the coach (§7). The team wall paragraph now says exactly what the wall shows about training: how many players on the team trained today, never who. The wall already worked that way, and the old words said more than it shows (§7). And §5 now says plainly that no plan, free or paid, ever shows advertising from another company, and that the only things REP11 may tell grown-ups about are its own paid plan and other Bolly Labs apps. Nothing new is collected and no new company is involved.

What changed in v1.9 (2026-10-07). A coach now sees less. If you switch a player on for a coach's team, the coach sees that player's first name and nothing else: not which skills they practised, not when or whether they trained, and no scores, stars, streaks or personal bests (§7). Nothing new is collected and no new company is involved.

What changed in v1.8 (2026-10-06). When a grown-up, or a player aged 13 or older, sends feedback from the app, a picture of the screen they were on now goes with it unless they tap Remove; a child's feedback never does. We also describe how the app shows what happened to the feedback you sent (§2.3). Nothing else is collected and no new company is involved.

What changed in v1.7 (2026-10-05). Two things. The team wall is now available: a family that joins a coach's team can switch a player on, and teammates then see that player's first name, whether they trained today and REP11's own shout-outs about them, and can send a preset cheer or a football handshake, never a message; without a team, the wall shows only your own family (§7). And we now describe REP11 Arena, our football game: when a grown-up connects it, it reads each approved player's name, shirt number, kit, look and which Arena skills they have collected in REP11, nothing more, and it can never change anything in REP11 (§7). No new company is involved.

What changed in v1.6 (2026-10-03). We brought four statements about the phone app up to date with the app as it is now. The app on Google Play and the App Store asks a grown-up to sign in first (the household web version still works without an account). Signing in backs up the family's players and training so they can be restored on another phone; signing out stops it (§1, §2.2). The app has a "GIVE FEEDBACK" button (§2.3). And the phone's practice reminder is local to the phone (§6). Nothing new is collected and no new company is involved.

What changed in v1.5 (2026-10-03). Three things became available, each off until a grown-up of the household chooses it. A second grown-up can join a family in person, and we now record your 18-or-over confirmation on your account (§2.2). A player in the 13+ age band can be given their own sign-in by a grown-up of the household; we keep only the sign-in identifier, never their email address (§1, §2.2). And a grown-up whose family has Premium can coach a team: if you switch it on for a player, the coach sees their first name and which skills they practised in the last 7 days, nothing more (§7).

What changed in v1.4 (2026-10-02). We describe who holds an account more accurately: an account holder is any adult aged 18 or over who signs in (a parent, a guardian, or an adult who plays themselves), rather than only a parent or guardian. Nothing about what we collect, who receives it or how children are protected has changed.

What changed in v1.3 (2026-09-27). We described optional parent-consented cloud backup in designated test builds, what it saves, recovery and offline limits, and the separation between test families and lasting U12 accounts. We corrected the older statement that parent sign-in was unavailable.

What changed in v1.2 (2026-09-27). We described the restricted Google purchase rehearsal separately from complimentary family access. We corrected the RevenueCat identity to the adult account identifier, named purchase analytics and our own purchase webhook, and kept child training out of that data flow. At that version, optional family training backup remained off in the store app.

What changed in v1.1 (2026-09-02). We said which version of REP11 each section describes, because the app on Google Play keeps everything on the phone while this policy also covers the household web version. We corrected where the training database lives (not on Cloudflare). We stopped describing a birth year we do not collect. We said reminders are on by default in the web version, and where the decision is made. We corrected the Standard Contractual Clauses sentence: they are being put in place, not in place. We named Crash logs alongside the update-check identifier the store app sends. We added the account itself to the retention table. And we removed a claim that a parent can correct or delete a profile from inside the store app: today that is done by asking us (§9). Since v1.0 we had also added the telephone number and named Expo and Crazytel in §4.


If something here is unclear, or you think we have got something wrong, we would genuinely like to know: support@rep11football.com.