Good Rally Privacy Notice (Early Access Program)

Effective date: August 12, 2026 Version: PN-EA-1.0 Applies to: the invite-only Early Access Program (U.S. residents, 18+)

Crosscourt Labs, LLC ("Good Rally," "we"), doing business as UpRally and as Good Rally, operates the Good Rally service (previously offered as UpRally). This notice describes what we actually collect and do during the Early Access Program. It is written to be read; a summary comes first, details follow. We will replace this notice with a full Privacy Policy at commercial launch.

The short version

  • We collect what the product visibly needs: your account, profile, matches (including who you played), and first-party records of how you use the app.
  • We do not sell personal information, do not share it for targeted advertising, and run no advertising or analytics trackers.
  • Beta data may be wiped at any time and is not backed up. Export what you want to keep.
  • Coach recommendations are generated by our own deterministic logic — no AI service processes your data today. If that ever changes, this notice changes first (Section 12), and you can turn Coach off.
  • You can export or delete your data yourself, any time, in settings.
  • Questions: use the in-app feedback tool, or write to us at the address at the end of this notice.

1. What we collect

  • You provide: account details (name, email, sign-in provider identifier, optional avatar); birth month and year (age verification only); profile details you choose (skill self-assessment, goals selected from options, play style, home courts, optional DUPR ID); match records you log (scores, participants, time, optional venue or game location); group posts and other content; settings and notification preferences; support messages.
  • Recorded about you by others: match records naming you as an opponent, subject to the confirmation flow; if you are recorded as a guest before you have an account, only a first name should be recorded (see Section 8).
  • Collected automatically: ordinary technical records inherent to operating a web service (server and hosting logs held by our infrastructure provider, Google); integrity signals derived from ordinary use and used only to prevent cheating and abuse (submission patterns and velocity); first-party usage records generated by using the app (e.g., quiz progress, feature usage). We use no third-party analytics, error-tracking, or advertising SDKs in the Program — if we add one, this notice is updated first (Section 12).
  • Computed about you: Rally Rating and skill ratings, standings, badges, and streaks — deterministic calculations from confirmed matches, not AI. You cannot edit them; the integrity system can adjust them with in-app explanations and an appeal path.

2. What we deliberately do not collect

No phone numbers (there is no SMS login). No background or continuous location — a game location is stored only when you choose to attach one to a match, via your device's permission prompt, and you can remove it later. No biometric data of any kind: avatars are stored as images and are screened at upload for policy compliance, not analyzed to identify anyone. No payment data: no charges occur during the Program and no payment method is ever collected — the subscription screens you may see are previews, and your trial and plan-preference settings are stored as ordinary account settings. No advertising identifiers.

3. How we use information

To run the service you see: accounts, profiles, matches, groups, competitions, ratings math, and in-app notifications. To keep it fair and safe: integrity signals, moderation under the Community Guidelines, and enforcement records. To communicate: the only emails we send today are account emails (sign-in links and password resets, delivered by Firebase Authentication); everything else reaches you as in-app notifications. If we add other email streams or web push, each email stream will be individually unsubscribable, push will be opt-in, and this notice will be updated first (Section 12). To improve the pre-release product: fixing bugs and analyzing first-party usage. To meet legal obligations and protect users, the public, and Good Rally. We do not use your personal information for third-party advertising, and we do not sell it.

4. Coach and AI processing

Coach recommendations (check-ins, drill suggestions, rules-module picks) are generated by deterministic logic on our own servers from your activity. No artificial-intelligence service processes your personal information in the current build. If we introduce AI processing (planned: Google's Gemini models), we will update this notice before it begins (Section 12); it will use a compact, server-maintained summary of your own activity — never free text you type — under configurations that do not permit the provider to train its models on your data; and turning Coach off in settings will stop all such processing. We do not use your personal information to train our own or anyone else's models, and will not without asking you separately.

5. Who receives data (processors and integrations)

RecipientWhat and whyNotes
Google (Firebase / Google Cloud)Hosting, database, authentication (including sign-in and password-reset email delivery), file storage, server logsData hosted in the United States; processor terms
DUPRMatch export, only if you link a DUPR ID and mark a match for exportPer-event, per-player consent; no export happens without your explicit flag, and you download the export file yourself

That is the whole list today. When a new service that receives personal information is added — an error-tracking service, an email provider, AI processing, a payment processor — this table is updated and the notice re-issued before the service activates (Section 12). We may also disclose information if required by law or legal process, to protect the safety of users or the public, to enforce our agreements, or as part of a business transfer (in which case this notice's promises follow the data). No other third parties receive personal information during the Program.

6. Visibility of your information to other users

Per-surface privacy controls (public / groups-only / private) govern what other users see, with a live preview; defaults are groups-only. Match records are inherently shared with the people in them: your opponents see the matches you played together. During the Program, the only pages visible without an account are: profile share cards behind unguessable links that only their owner can create (and can revoke at any time), group and competition invite pages behind their join codes, and these legal pages. Nothing else is public, and nothing is indexed for search engines.

7. Your choices and rights

  • Export: self-service JSON export of your profile and matches, any time, in settings.
  • Deletion: self-service account deletion in settings. Your own data is deleted from active systems promptly. Your appearances in other people's match histories are anonymized to "deleted player" rather than erased, so their records stay intact without naming you. Moderation and enforcement evidence may be retained as described in Section 9.
  • Correction: edit your profile and settings directly; disputes about match records go through the confirmation and appeal flows.
  • Communications: the only emails today are account emails (sign-in and password resets); in-app notifications sit quietly until you read them. Any future email stream will carry its own unsubscribe, and push — when it exists — will be opt-in with configurable quiet hours.
  • Coach: can be disabled entirely in settings.
  • No discrimination: we will not degrade the core service because you exercised a privacy choice.
  • Signals: we do not sell or share personal information for cross-context behavioral advertising, so opt-out signals such as Global Privacy Control currently have nothing to opt you out of; we honor the intent of such signals.
  • Requests and questions: use the in-app feedback tool or write to us at the address at the end of this notice. If you are not satisfied with our response, tell us and we will take another look.

8. Data about people who are not users (guests)

Users can record a match against a guest identified by first name only. Guest entries never affect ratings unless the guest later creates an account and claims and confirms them. We instruct users to record first names only and only for people who actually played. If you believe someone has recorded information about you and you want it removed, tell us through the in-app feedback tool or by mail. During the Program, guest history claiming is disabled.

9. Retention

The Program is short-lived and data may be wiped at any time (see the Early Access Program Agreement). Otherwise: account and activity data are kept while your account exists and deleted or anonymized when you delete it; moderation and enforcement evidence for [1 year — placeholder pending counsel]; acceptance and consent records for [5 years — placeholder pending counsel], kept even after deletion as our record that consent existed. There are currently no backups; when backups are introduced at launch, deleted data will additionally age out of backups within a stated window and this notice will be updated first.

10. Security

We use reasonable technical and organizational safeguards: Google Cloud infrastructure, Firebase security rules, access restricted to the founder, audit logging of administrative actions, and TLS in transit. No internet service can promise perfect security, and we do not. Suspected vulnerabilities: report them through the in-app feedback tool or by mail.

11. Age, location, and scope

The Program is limited to U.S. residents 18 or older; the service is hosted in the United States. We do not knowingly collect data from anyone under 18 during the Program, and if we learn we have, we will delete it. At commercial launch the service will open at 13+ with teen protections, under a revised policy published before that change.

12. How this notice changes

This notice is versioned: every published version carries a version ID and effective date, and every historical version stays readable at this page — you can always answer "what did the notice say when I agreed."

  • When a new service or processor that receives personal information is added — an error-tracking service, an email provider, AI processing, a payment processor — this notice is updated and takes effect before the service activates. The change is what makes the service permissible, so the change always comes first.
  • Material changes (new data collected, a new use, a new recipient, a changed retention promise) are announced in-app with a summary of what changed, and where your agreement is required, the app pauses on a re-acceptance screen before you continue.
  • Non-material changes (typos, clarifications, contact details) bump the version and are noted at this page without an interruption.
  • The version and date at the top of this notice always identify exactly what you are reading.

13. Contact

Crosscourt Labs, LLC · 390 North Orange Ave., STE 2300-N, Orlando, FL 32801