Who gets your data
Nobody. There's no server of mine, no account with me, and no company here. I can't read your group, join it, change it or shut it down. Nothing is sold or handed to anyone else, because nothing arrives with me in the first place.
Privacy
This page is short because there isn't much to tell you. It's not a summary of a longer document kept somewhere else — this is the document.
Nobody. There's no server of mine, no account with me, and no company here. I can't read your group, join it, change it or shut it down. Nothing is sold or handed to anyone else, because nothing arrives with me in the first place.
Your group's record — the parents, the kids, practice times, pickup addresses, who offered what, and the running count of who's driven — sits on the phones of the people in your group. It moves between them through one parent's own iCloud, using Apple's syncing and notifications. That part is between you and Apple, in your own account, under their terms.
Pickup addresses get turned into map coordinates once so the app can work out routes. That's the most sensitive thing here, and it stays on the phones of the group you chose to join.
The app never asks for live location, never asks for background location, and never asks for the "Always" permission. It has no way to tell where any person or car is at any moment. There's no setting that turns this on.
Children don't have accounts. A kid doesn't install the app, doesn't sign in, and can't be contacted through it. What's held about a child is their name, which practice group they're in, and a pickup address, all entered by their own parent.
There are none. No analytics, no crash reports leaving your phone, no advertising identifiers, no third-party code phoning home. There's no money in this app, so there's nothing that measuring you would be in service of.
No cookies. No analytics. Nothing loaded from anywhere else — not fonts, not scripts, not images. There are no forms and no mailing list. The only trace of your visit is the ordinary server log kept by whatever delivers the files. Open your browser's network tab and check.
Delete the app and the copy on that phone goes with it. Leave a group and your phone stops getting its updates. Entries you already published stay in the copies the other parents hold, the same way a message you sent to the group chat is still in it. There's no central copy for me to delete, because there's no central copy.
Your group's record is encrypted on the way to iCloud and while it sits there, and only the parents invited to the share can open it. The entries themselves are sealed from the service doing the syncing.
A group key is coming that adds end-to-end encryption, so entries are readable only by the phones in your group and closed even to whoever stores them. It ships before launch. Until then that last guarantee rests on the iCloud share's access controls rather than on the math, which I'd rather say here than leave out.
If this page changes in a way that matters, it'll say so on the page rather than quietly updating. The code repository is where to raise something or check any of this against what the app actually does.