Privacy Policy
Last updated: August 7, 2026
BowlSheet® is made by Edibu LLC (“BowlSheet,” “we,” “us”). This policy covers two products that handle data very differently, so it is split into two clearly scoped sections:
- BowlSheet for iOS, iPadOS, and macOS — the app on the App Store today. Your data lives on your device.
- BowlSheet Community (beta) — the next-generation platform, currently in closed beta with invited pilot teams. It adds accounts and cloud sync.
If you only use the App Store app, only the first section and the general section at the end apply to you.
BowlSheet for iOS, iPadOS, and macOS (the current App Store app)
Your data stays on your device
The App Store app has no account system. There is nothing to sign up for and no password to create. Your games, frames, stats, equipment, targeting, oil patterns, notes, and bowling-center records are stored in the app’s private storage on your device. We do not run a server that holds your scores.
What leaves the device
Three narrow things can leave your device:
- Crash reports and usage diagnostics. The app uses crash reporting and diagnostics services from Google Firebase (including Crashlytics) so we can find and fix problems. These reports include things like crash traces, device model, OS version, and which features are used. They do not include your scoresheets, notes, or photos — and because the app has no accounts, they are not tied to your name.
- A push token, if you enable notifications. If you allow notifications, Apple’s push service issues your device a token so notifications can be delivered. Decline the permission and no token is created.
- Purchases. The app and the optional Analytics Export subscription are billed by Apple through your App Store account. We never see or store your payment details.
The app shows no advertising, and we do not sell or rent your data.
Location — only at the moment you ask
When you add a bowling center, you can use your device’s location to fill in its coordinates. The app reads your location at that moment only. What gets stored is the bowling center’s coordinates — not a history of where you have been — and the app never reads your location in the background. You can enter coordinates by hand instead, and the app works without ever granting location access.
Photos
Photos you attach — to bowlers, equipment, bowling centers, and events — are saved into the app’s private storage on your device. We do not upload them.
Deleting your data
Because your data lives on your device, deleting the app deletes your BowlSheet data from that device. Copies may persist in your device backups (iCloud or local); those backups belong to you and are managed through your device settings. Any CSV files you have exported are likewise under your control.
BowlSheet Community (beta)
BowlSheet Community is the next generation of BowlSheet, currently in closed beta with invited pilot teams. This section applies only to beta participants. Community adds accounts and sync.
Two facts shape everything below:
- We do not collect dates of birth or ages. There is no such field anywhere in BowlSheet — not on a bowler, not on an account. We therefore hold no information about how old anyone on a roster is.
- We do not import data from anywhere. BowlSheet does not query USBC, a league management system, a school information system, or any other source. Every roster field is typed in by a coach or admin who decides what to enter.
Data the beta collects
- Identity and contact — coach, assistant, analyst, and admin accounts, and the email address used to sign in. Sign-in is passwordless: a magic link sent to your email, or Sign in with Google or Apple (each returns only your email address to us). We never store a password. An optional display name may be shown.
- Roster and athlete data — bowler display names and profiles, and team and season membership. Optional fields a coach may fill in include a USBC membership number, a contact detail, sex, handedness, and bowling style. All of these are entered by the coach or admin, not by the bowler.
- Performance data — scores, frames, ball throws, leaves, splits, equipment, targeting, notes, and event, location, and oil-pattern context.
- Operational data — audit logs, and device and sync metadata used to keep offline scoring in sync and to diagnose errors. Your account email may appear in error-monitoring reports.
- Location — read only at the moment you use it to auto-fill a bowling center’s coordinates; never in the background. You can type coordinates by hand instead.
- Photos — photos you attach in the mobile app are stored on your device; the app does not upload them. The Community platform also supports image storage used through the web dashboard — images uploaded there are kept in object storage we operate ourselves in the United States, and served over short-lived signed links.
Where beta data is stored
Community’s backend, database, and file storage run on infrastructure Edibu LLC operates directly in the United States — not on a third-party cloud provider. Disks are encrypted at rest, and all traffic between your device and our servers is encrypted in transit (HTTPS/TLS). Scores you enter are stored locally on your device so scoring works offline, and sync to our servers when a connection is available.
Service providers
We share beta data only with the providers needed to run the service, each limited to that purpose:
- Our own infrastructure (United States) — the application, database, and object storage run on servers Edibu LLC operates and administers directly. No third-party cloud provider holds your roster or performance data.
- Cloudflare — DNS, TLS termination, and content delivery for our website and API, and routing of inbound email sent to our published addresses.
- Resend — delivery of transactional email, including magic-link sign-in and invitation messages.
- Google and Apple — identity verification if you choose Sign in with Google or Apple; they return your email address to us.
- Sentry — application error and crash monitoring. This integration is not currently enabled on the Community backend, so no Community data is being sent to it today. If we enable it, reports can include your account email and device and technical context, and we will update this policy before doing so.
- Stripe — payment processing, when billing is enabled. Stripe collects your card details and billing address directly; we store only your Stripe customer and subscription identifiers, never card data.
We do not sell data to, or allow advertising use by, any third party.
Student data
- Institutional control. When a school, college, or program is the customer, the institution is the data controller and BowlSheet is a processor acting under its direction. A Data Processing Addendum (DPA) governs that relationship.
- No accounts for athletes, and no ages on file. Athletes do not self-register, do not have logins, and never interact with BowlSheet. Only coaches, assistants, analysts, and admins have accounts. Because we collect no date of birth or age, we do not hold — and cannot infer — whether anyone on a roster is a minor.
- The coach decides what is entered. Every roster field is optional and typed in manually. A coach who prefers to identify bowlers by first name or initials alone can do so and BowlSheet works normally. Obtaining any parental or school consent required before adding a person’s details is the responsibility of the coach or institution entering them.
- State student-data-privacy laws. No advertising use, no sale of student data, and deletion on request.
Access is role-based and enforced on the server. Every record is scoped to its organization, and account activity is audit-logged. Institutions accept our Terms and, where applicable, a Data Processing Addendum at onboarding.
Retention and deletion (beta)
- Active retention — performance and roster data is retained while the team’s account is active.
- Athlete removal — removing a bowler hides them from active views. To fully delete a bowler’s personal data, contact us and we will remove it.
- Account and data deletion — you can request deletion of your account and your team’s data by emailing support@bowlsheet.com; we honor deletion requests within 30 days. Account closure includes a 90-day window to export your data first.
- Backups — where a deleted record also exists in a backup copy, that copy is removed as backups age out on their retention schedule. We are actively expanding our backup coverage for the Community beta; this line will be updated with the specific retention window once that work is complete.
Both products
Children
Neither product shows advertising, and neither sells personal data. The App Store app collects no identity at all — it has no accounts. In the Community beta, student-athlete data is handled under the institutional and consent rules above.
Changes to this policy
We may update this policy as the products evolve. Material changes will be noted here with a new “Last updated” date, and beta participants will be notified directly.
Contact
For privacy questions, data requests, or to report a concern, email support@bowlsheet.com.