MiSportsCareer Your football career, tracked

Privacy Policy

Last updated: 2 October 2026

MiSportsCareer is a football (soccer) career-tracking app: you log your own match stats, get a player card that evolves from real performance, and can join clubs and leagues with other players. This page explains what the app collects, what it's used for, who can see it, and how to get your data deleted.

Who runs this

MiSportsCareer is an independently run app. Questions, requests, or reports about privacy can be sent to [email protected].

What we collect

DataWhy
Username, display name, team name, positionIdentifies your account and player card
PasswordSigning in. Stored only as a salted scrypt hash — never in plain text, and never sent anywhere else
Email addressConfirms you're a real, unique person (one account per address), and lets an admin reach you if you're ever locked out. Optional for accounts created before email confirmation existed
Date of birthChecked once at signup to confirm you're old enough to create an account. Not stored — only the pass/fail result matters
Match stats you submitGoals, assists, minutes, passes and similar — used to calculate your player card and fantasy points
A photo, if you add oneShown faded into the background of your player card
Bio, club motto, profile colour, bannerOptional personalisation, shown on your public profile
Feedback board postsPublic messages you choose to post to the app's feedback board
Reports you file against another playerSent privately to admins for moderation
IP addressUsed only in memory, briefly, to enforce rate limits (e.g. login attempts per hour). Never written to the stored data or kept once the rate-limit window passes
Advertising IDRead by Google's AdMob SDK, not by us, when you choose to watch a rewarded video ad. Google uses it to serve the ad and to confirm the reward before we credit coins. See "Ads and purchases" below
Notification address, if you turn on remindersA push address and encryption keys from your browser or phone, plus your device's time-zone offset. Used only to send the reminders you switch on (logging matches, MiFantasy, MiLeague) and to keep them quiet overnight. Turn them off in Profile and the address is deleted; signing out removes it from that device
Subscription statusIf you subscribe to MiPremier or MiChampion, Google Play Billing tells us whether the subscription is active, in a grace period, or cancelled, so we can turn premium features on or off. We never see your card details — Google handles those

Ads and purchases

Rewarded video ads are shown through Google AdMob. When you choose to watch one, AdMob handles the ad itself and reads your device's advertising ID to do so — MiSportsCareer never sees that ad or your ad ID directly. We only find out an ad was watched through Google's own signed reward callback, which is what triggers your coins; see the fair-play note in the Terms of Service for why it works that way. In a web browser, ads (if enabled for your plan) are served by Google AdSense, which may use cookies or similar identifiers to show and measure them; the same fair-play rules apply. AdMob's and AdSense's own data use is covered by Google's ad policy, not this one.

MiPremier and MiChampion subscriptions are sold and billed entirely through Google Play Billing. Payment details go to Google, never to us. What we receive back is just the subscription's status — active, in a grace period, or cancelled — which we use to turn premium features on or off. Cancelling, refunds, and payment issues are handled through Google Play, not through us; see "Subscriptions" in the Terms of Service.

Who can see what

Visible to other players: your username, display name, team, position, player card and stats, public match summaries, bio, club/league memberships, and anything you post to the feedback board.

Visible to admins only: your full match reports (including the written report text), your email address, and any reports filed about you or by you. The README for this project is public about this, and it's disclosed here too: admins can read any player's match reports as part of moderating the app.

Visible to no one but you: your password (not even in reversible form — it's a one-way hash), and your session.

Blocking and reporting

You can block another player from Profile or their public profile. Blocking removes any follow connection between you, and hides that player's feedback posts, directory listing, and profile from you (and you from them). You can report a player or their content to admins with a reason and an optional note; admins review open reports and can suspend accounts, remove match reports, or take other moderation action.

Deleting your account

You can permanently delete your account and its data yourself, at any time, from Profile → Delete my account — no admin needed. This removes your account, match history, club and league memberships, follows, blocks, feedback posts, and any reports involving you. It's separate from "Reset all data," which only clears your in-app career and keeps your account and username.

You can also request deletion without opening the app at /delete-account on this same site.

The one exception: if you're the only admin on the app, you'll need to promote another admin first, so the app doesn't lose its moderation entirely. Almost no one will hit this — it only affects the person running the app.

How data is stored

Accounts, match history, clubs, leagues, feedback and moderation records are held in a PostgreSQL database run by our hosting provider, Railway, on servers in the region chosen for the app. The app connects to it over an encrypted connection, and the database is not reachable from the public internet — only the app server can read or write it.

Passwords are never stored in a readable form. Each one is put through scrypt with its own random salt, so the stored value can't be turned back into the password. The same is true of session tokens and email confirmation links, which are stored only as hashes.

Database contents are not separately encrypted by us beyond the encryption our hosting provider applies to its storage, so anyone with administrative access to the hosting account could read stored data — though never passwords in plain form. Only the app itself is served over the web; the database, its credentials, and the app's source code are not.

Database credentials are held as environment variables on the server and are never included in the app you download, the website, or anything sent to your device.

Backups are taken by the hosting provider on its own schedule and retained by it. A deleted account is removed from the live database immediately; copies inside those provider backups age out with the backup itself, normally within 30 days.

Children

New accounts are asked for a date of birth when signing up, and account creation is refused if it works out to under 13. This is checked on the server, not just the app on your screen, and the date of birth itself isn't kept afterwards — only whether the check passed. If you believe an underage account has slipped through some other way, contact us at the address above and we'll remove it.

Changes to this policy

If this policy changes in a way that matters, the "Last updated" date above will change and, where practical, an in-app notice will say so.

Contact

For anything on this page — access, correction, deletion, or a general question — email [email protected].

See also: Terms of Service · Community Guidelines · Delete your account

© 2026 MiSportsCareer. All rights reserved.

← Back to MiSportsCareer