Poools

Privacy policy

Last updated 31 August 2026

Poools is where you run football survival pools, predictors and racing pools with your mates. This page explains what we do with your data. It covers the Poools website and the Poools iOS app together, because they are one service behind one account.

Poools is run by Daniel Keeble, who is the data controller for everything described here. Questions, requests and complaints go to privacy@poools.app.

The short version

  • We collect what it takes to run your pools: who you are, and what you picked.
  • Your email address is never shown to the people you play with.
  • There is no advertising, no profiling, and no tracking across other apps or websites.
  • Your pool’s buy-in is settled between you and your organiser, never through the app.
  • Delete your account and everything goes with it.

What we collect

When you sign in. You sign in with Google or Apple, so your password for either of them never reaches us. On iOS the Google flow runs inside Google’s own sign-in library, so your device talks to Google before it talks to us; on the website it happens in the browser. Our authentication provider receives your email address and the name your provider passes on, and creates your account from them.

Your email address is never copied into the game database and is never shown to anyone you play with. It leaves the authentication layer in two places: to our email provider when we send you a notification, and back to your own signed-in app when it asks for your account. If you sign in with Apple and choose Hide My Email, the relay address Apple gives us is all we ever see.

Your profile. A username, which is a public handle you choose, and a display name. These are how you appear to other players, so pick something you are happy for your pools to see. Where your sign-in provider passes on a profile picture, we keep the link to it alongside them. The image itself stays hosted by that provider. Your profile also carries a flag saying whether you are an ordinary player or an operator of the app.

What you do in the app. The pools you belong to and the name you joined each one under; your picks and predictions; your results, eliminations and wins; your notification preferences and the notifications we have sent you.

Technical data, collected automatically. A cookie that keeps you signed in. Your IP address, seen by our rate-limiting service so that one person cannot flood the app. And diagnostic data, described under Sentry below. One part of that is worth saying plainly here, because it does not wait for something to go wrong: about one website session in ten is recorded as a masked replay whether or not anything breaks.

On your device, not on our servers. Your light or dark theme preference, and a half-finished “create a pool” form, are saved in your browser’s own storage. They never reach us, and clearing your browser data removes them.

Who can see what

The other players in a pool you are in can see the name you play under, whether you still owe a pick for the open gameweek, the standings, eliminations and honours board. They cannot see what you picked before the round locks, and they can never see your email address.

Once a round locks, your picks stop being private to you. Your pool sees which team you backed, by name, next to everyone else’s, and it keeps seeing it: the players list carries your pick for every round you have played and the clubs you have already used up. In a predictions pool, a rival can also tell, fixture by fixture, whether you have called one yet, before either of you can see the other’s answer. A pool is meant to be played in the open, so this is the design rather than a leak, but it is worth knowing before you join one: what you pick is between you and everyone you play with, permanently.

The name they see is the display name you joined that pool under. Your @username stands in for it in most places, but not everywhere, so a pool you joined under your real name will show it to that pool.

Your pool’s organiser can additionally keep a private paid-or-not mark against you for the buy-in they collect outside the app. Nobody else sees it, including you, and it changes nothing about how you play.

We can. Operators of the app can view game activity in order to run the service, investigate problems and answer support requests.

Nobody else. We do not sell your data, and we share it only with the services below, which handle it on our instructions.

Services we use

Running the app means handing parts of your data to specialist providers. These are all of them, and what each one gets.

Supabase (database and sign-in)
Holds your account, your profile and everything you do in the app, and issues the session that signs you in. Your email address lives here.
Google (sign-in)
Where you choose Google, Google identifies you and tells us who you are. On iOS this happens in Google’s own library inside the app, so Google sees your device and its network address directly. We send Google nothing about your pools or your picks.
Apple (sign-in)
Where you choose Apple, Apple identifies you and tells us who you are, passing on your name and either your email address or the relay address you get from Hide My Email. On iOS the sign-in sheet belongs to Apple, so your device talks to Apple directly. We send Apple nothing about your pools or your picks.
Vercel (hosting)
Serves the website and the app’s API, so every request you make passes through them. Nothing is measured from your browser for them, and no profile is built.
Sentry (error monitoring)
Receives errors, performance traces and logs from your browser and from our servers. The only account field we attach is your internal ID: no email address, no username. Reports from your browser also show Sentry your network address and browser, the way any site you send data to sees them, and carry a trail of the pages you moved through, which for a pool page identifies the pool. They carry the technical detail of what went wrong, which is the point of them, and that detail can include fragments of whatever the app was handling when it broke: if an email of ours fails to send, the failure we record can quote the address it was going to. Sentry also records about one website session in ten as a replay, whether or not anything goes wrong, plus the session around an error. Replays are masked: the text you see and type is blanked out and images are blocked, leaving the shape of the page and where you clicked.
Upstash (rate limiting)
Counts requests against your IP address and a short-lived fingerprint of your session, so that the app can turn away abuse. The counters expire within minutes and nothing else is kept.
Resend (email delivery)
Sends the notification emails about your pools, and receives your email address and the contents of those emails to do it.
OpenRouter (AI gameweek recaps)
Where written round-ups are switched on, the round’s facts are sent through OpenRouter to a language model, which writes the summary your pool reads. Those facts are the pool’s name and house rules, which round it was and where the pool stood after it, who was still standing, who went out, which clubs they backed and how those matches finished, and the names attached to each. Email addresses are never sent, and the recap is stored with the pool like any other result. Which model writes it is a setting we can change; today it is one of Anthropic’s or Google’s.
Bzzoiro Sports (fixtures, results and club crests)
Supplies the football and racing data the app runs on. The club crests and league badges you see are loaded by your device straight from their servers rather than copied onto ours, so they see your IP address and browser the way any site you visit does. Nothing about your account, your picks or your pools is sent to them.

Notifications

Notifications reach you in two ways today: in the app’s own notification centre, and by email. Both are on when you sign up, because a pool you cannot be reminded about is a pool you drop out of. You can turn off any kind you do not want, by channel, in your settings. Everything we send today can be turned off that way. If we ever have to tell you something about your account or the security of the service, that would reach you whatever your settings say.

Push notifications are not running yet. The iOS app may ask your permission to send them, but nothing is delivered through them and no token identifying your device is stored. When push messages do start, allowing them will give us a token for your device, kept only to deliver those messages, and turning notifications off for Poools in your device settings withdraws it. This page will say so before that happens.

The iOS app

The iOS app is the same service as the website, so everything above applies to it. A few things are specific to it:

  • Camera. The app carries a camera permission for scanning a pool’s join code. It does not open the camera yet, so today you join by following a link. When the scanner arrives, the frames will be read on your device to find the code, and nothing will be recorded, stored or uploaded.
  • Sign in with Google. On iOS this runs through Google’s own sign-in library inside the app, so your device talks to Google directly as well as to us. On the website the same sign-in happens in the browser instead.
  • Sign in with Apple. Handled by Apple. Your signed-in session is kept in the device Keychain, not in ordinary app storage.
  • Push notifications. The app may ask your permission for these. As above, nothing is sent through them yet and no device token is stored.

What we don’t do

  • No advertising, no ad networks and no advertising identifiers.
  • No behavioural profiling, and no analytics product studying what you do, beyond the fault-diagnosis tool named above.
  • No tracking of you across other apps or websites, and nothing sold or passed to data brokers.
  • No handling of your pool’s money. Buy-ins are settled between players, and the app never learns what one is worth; an organiser’s paid marks are only a note to themselves.
  • No location data, and no health, biometric or similar data.

Poools is free to use at the moment, so no payment details reach us at all. If paid plans arrive, this page will say what the payment provider receives before they do. Your pool’s buy-in is a separate matter and stays outside the app either way.

How long we keep it

For as long as your account exists. There is no separate clock: your account is the retention period.

Deleting your account erases it. The account, the profile, and every pick, prediction and pool membership attached to it, everywhere they appear. That includes your entries in pools you played with other people: your rows go from their standings and their past rounds, and if you won a series your name comes off that pool’s honours board. We do not leave an anonymised placeholder behind, so there will be gaps in the history your pool remembers. It cannot be undone.

Two things written about you survive it, because they are not stored as your data. Where a pool has AI round-ups switched on, your name may be written into the copy of a round you played, and that copy belongs to the pool rather than to you. And a notification another player has already received, telling them you joined or that you won, stays in their app. Both keep the name you played under. Email privacy@poools.app if you want them dealt with too, and we will.

Deleting your account also deletes the pools you organise. A pool belongs to whoever set it up, so it goes when their account does, and it takes everyone in it with it: their entries, their picks, the standings and the honours board. There is no way to hand a pool to another player first. If you run a pool that other people are still playing, this is worth knowing before you delete rather than after.

Leaving a single pool is a smaller, different thing, and at the moment you cannot do it yourself: ask the organiser to take you out, and the rest of your account is left alone.

To delete your account, use the account-deletion option in the app, or email privacy@poools.app and we will do it for you. Copies can survive briefly in backups and in the diagnostic records described above, which age out on their own schedule. Your internal ID is the only account field we attach to those, but the report itself can carry your network address, the pages you were moving through, or a fragment of whatever the app was handling when it broke.

Your rights

This service is run from the United Kingdom under the UK GDPR, and those rights apply to you wherever you play from. You can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, ask for it in a portable form, and object to a use we base on our legitimate interests. Email privacy@poools.app and we will answer within one month.

We process your data to provide the pools you joined (our contract with you), and to keep the service working, secure and free of abuse, and to diagnose faults (our legitimate interests). Notification emails go out under that same contract rather than on your consent: they are part of the service you signed up for, not marketing, and you can switch off any of them. We send no marketing email, and if that ever changes it will be on your consent and this page will say so first.

If you think we have got this wrong, you can complain to the UK Information Commissioner’s Office at ico.org.uk.

Where your data goes

The app is available worldwide, and several of the providers listed above are based in or process data in the United States. Where your data leaves the UK, we rely on the standard contractual safeguards those providers publish for exactly that.

Age

Poools is for people aged 13 and over. We do not knowingly collect anything from under-13s. If you believe a child has an account, email privacy@poools.app and we will remove it.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change matters to you, such as a new processor or a new kind of data, we will say so in the app rather than leaving you to spot it.

Contact

Daniel Keeble, data controller for Poools. Email privacy@poools.app for anything on this page, including data requests.