Privacy Policy
Volleyball Code listens to your voice during a match, so you deserve a straight answer about where that audio goes. This page gives you one.
Last updated: 31 July 2026
The short version
We do not keep your audio. Your voice is streamed live to a transcription service, turned into text, and the audio is discarded. We never store a recording of your matches, and we never sell anything about you to anyone.
1. Who is responsible for your data
Volleyball Code is operated by an individual sole trader based in Morocco. For the purposes of the GDPR and similar laws, we are the data controller for your account.
2. What we collect
Information you give us
- Account details — your email address, and a display name if you set one. Your password is handled by our authentication provider and stored only as a cryptographic hash. We never see it.
- Match data — teams, rosters, every action you code, scores, rotations, sets and the statistics generated from them.
- Player information — the jersey numbers and, if you choose to enter them, the names of the players on your teams.
- Anything you send us — the content of emails and support messages.
Information collected automatically
- Usage records — how many seconds of voice transcription you used, and which features you opened. This is how we meter plan limits and understand what coaches actually use.
- Error reports — when something breaks, we record what broke, on which browser, and for which account, so we can fix it.
- Technical details — browser and device type, the app version you are running, the date of your last sign-in, and a two-letter country code derived from your connection.
We do not store your full IP address in our database. We do not collect your precise location, your contacts, or anything from your device beyond the microphone while you are actively coding.
3. What happens to your voice
This is the part worth understanding properly, so here is the whole chain.
- You press the microphone button. Your browser asks your permission first, and nothing is captured until you grant it.
- Your microphone audio is streamed, live, through our server to Deepgram, a speech-recognition service, which converts it to text.
- The resulting text — not the audio — is sent to Groq, which runs an AI model that corrects mis-heard volleyball terms.
- The corrected text is parsed into actions and shown to you for confirmation.
- The audio is gone. It is not written to disk on our server and we keep no copy of it.
What we retain is the structured result: that team A's number 9 served an ace. Not the sound of you saying it.
The microphone is only active while you are coding a match and have started voice input. Closing the match or stopping voice ends the capture.
4. Why we are allowed to use your data
| What | Why | Legal basis (GDPR) |
|---|---|---|
| Account and match data | To provide the service you signed up for | Performance of a contract |
| Voice transcription | The core feature you chose to use | Performance of a contract |
| Payment records | To take payment and meet tax obligations | Contract and legal obligation |
| Usage metering | To enforce plan limits and control costs | Legitimate interests |
| Error reports | To keep the app working | Legitimate interests |
| Analytics and session replay | To understand and improve the product | Consent, where required |
5. Who else processes your data
We use a small number of third parties to run the service. Each one only receives what it needs.
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Accounts and database | Email, password hash, match and team data |
| Deepgram | Live speech-to-text | Your microphone audio, while coding |
| Groq | AI transcript correction | The transcribed text of a rally |
| Creem | Payments, as merchant of record | Your email and payment details, which go to Creem directly and never through us |
| Brevo | Account emails | Your email address |
| Google Analytics | Website analytics | Anonymous usage of our public pages |
| Microsoft Clarity | Usage analytics and session replay | How you move through the pages, as described below |
We do not sell your personal data, and we do not share it for advertising.
These providers operate servers in the European Union and the United States, so your data may be processed outside your own country. Transfers rely on the providers' standard contractual clauses.
6. Cookies, analytics and session replay
Our public pages use Google Analytics and Microsoft Clarity to understand what people find useful. Clarity records session replays — an anonymised playback of mouse movement, scrolling and clicks — which we use to find confusing parts of the interface. Clarity masks text input by default, so what you type is not captured in a replay.
The app itself uses your browser's local storage to keep you signed in and to hold a local copy of your matches so the app keeps working if your connection drops. This is not tracking and it never leaves your device except when syncing to your own account.
7. How long we keep things
- Voice audio — not retained at all.
- Account and match data — for as long as your account exists.
- Usage and error records — up to 24 months, then deleted.
- Payment and tax records — retained by Creem for as long as tax law requires, typically several years. This is a legal obligation and we cannot delete it on request.
- After you delete your account — your data is removed from our live systems within 30 days, and from backups within 90 days.
8. Your rights
Wherever you live, we will honour these. If you are in the European Union, the United Kingdom or another region with equivalent law, they are also your legal rights.
- See your data — ask us for a copy of everything we hold about you.
- Correct it — fix anything wrong, from your profile or by asking us.
- Delete it — ask us to close your account and erase your data.
- Export it — take your matches with you as CSV or PDF.
- Object or restrict — tell us to stop processing your data for a particular purpose, such as analytics.
- Complain — to your local data protection authority if you think we have handled your data badly. We would rather you told us first, at contact@volleyballcode.com, so we can put it right.
Email us and we will respond within 30 days. We do not charge for any of this.
9. Players, and players under 18
Volleyball Code is designed for coaches. If you are a coach recording a roster, you may be entering the names of other people, including minors.
For that player information, you are the controller and we are your processor: we hold it on your behalf, use it only to produce your statistics, and delete it when you delete it. You are responsible for having the right to record it under the rules of your club, school or federation, and under the law where you coach.
Our advice is simple: you only need a jersey number to code a match. If you are unsure about recording a young player's name, use the number alone. The app works exactly the same.
The service is not directed at children, and accounts are for people aged 16 and over.
10. Security
Traffic is encrypted in transit with HTTPS. Passwords are hashed by our authentication provider and are never visible to us. Database access is restricted per account with row-level security, so one coach cannot read another's matches. Administrative keys are held only on the server and never sent to your browser.
No system is perfectly secure. If a breach ever affects your data, we will tell you and the relevant authority without undue delay, and within 72 hours where the law requires it.
11. Changes to this policy
If we change how we handle your data in a way that affects you, we will email you before it takes effect. The date at the top of this page always reflects the current version.
12. Contact
Questions, requests, or a concern about any of this: contact@volleyballcode.com. A real person reads every message, usually within one working day.