MiSportsCareer is a football (soccer) career-tracking app: you log your own match stats, get a player card that evolves from real performance, and can join clubs and leagues with other players. This page explains what the app collects, what it's used for, who can see it, and how to get your data deleted.
MiSportsCareer is an independently run app. Questions, requests, or reports about privacy can be sent to [email protected].
| Data | Why |
|---|---|
| Username, display name, team name, position | Identifies your account and player card |
| Password | Signing in. Stored only as a salted scrypt hash — never in plain text, and never sent anywhere else |
| Email address | Confirms you're a real, unique person (one account per address), and lets an admin reach you if you're ever locked out. Optional for accounts created before email confirmation existed |
| Date of birth | Checked once at signup to confirm you're old enough to create an account. Not stored — only the pass/fail result matters |
| Match stats you submit | Goals, assists, minutes, passes and similar — used to calculate your player card and fantasy points |
| A photo, if you add one | Shown faded into the background of your player card |
| Bio, club motto, profile colour, banner | Optional personalisation, shown on your public profile |
| Feedback board posts | Public messages you choose to post to the app's feedback board |
| Reports you file against another player | Sent privately to admins for moderation |
| IP address | Used only in memory, briefly, to enforce rate limits (e.g. login attempts per hour). Never written to the stored data or kept once the rate-limit window passes |
| Advertising ID | Read by Google's AdMob SDK, not by us, when you choose to watch a rewarded video ad. Google uses it to serve the ad and to confirm the reward before we credit coins. See "Ads and purchases" below |
| Notification address, if you turn on reminders | A push address and encryption keys from your browser or phone, plus your device's time-zone offset. Used only to send the reminders you switch on (logging matches, MiFantasy, MiLeague) and to keep them quiet overnight. Turn them off in Profile and the address is deleted; signing out removes it from that device |
| Subscription status | If you subscribe to MiPremier or MiChampion, Google Play Billing tells us whether the subscription is active, in a grace period, or cancelled, so we can turn premium features on or off. We never see your card details — Google handles those |
Rewarded video ads are shown through Google AdMob. When you choose to watch one, AdMob handles the ad itself and reads your device's advertising ID to do so — MiSportsCareer never sees that ad or your ad ID directly. We only find out an ad was watched through Google's own signed reward callback, which is what triggers your coins; see the fair-play note in the Terms of Service for why it works that way. In a web browser, ads (if enabled for your plan) are served by Google AdSense, which may use cookies or similar identifiers to show and measure them; the same fair-play rules apply. AdMob's and AdSense's own data use is covered by Google's ad policy, not this one.
MiPremier and MiChampion subscriptions are sold and billed entirely through Google Play Billing. Payment details go to Google, never to us. What we receive back is just the subscription's status — active, in a grace period, or cancelled — which we use to turn premium features on or off. Cancelling, refunds, and payment issues are handled through Google Play, not through us; see "Subscriptions" in the Terms of Service.
Visible to other players: your username, display name, team, position, player card and stats, public match summaries, bio, club/league memberships, and anything you post to the feedback board.
Visible to admins only: your full match reports (including the written report text), your email address, and any reports filed about you or by you. The README for this project is public about this, and it's disclosed here too: admins can read any player's match reports as part of moderating the app.
Visible to no one but you: your password (not even in reversible form — it's a one-way hash), and your session.
You can block another player from Profile or their public profile. Blocking removes any follow connection between you, and hides that player's feedback posts, directory listing, and profile from you (and you from them). You can report a player or their content to admins with a reason and an optional note; admins review open reports and can suspend accounts, remove match reports, or take other moderation action.
You can permanently delete your account and its data yourself, at any time, from Profile → Delete my account — no admin needed. This removes your account, match history, club and league memberships, follows, blocks, feedback posts, and any reports involving you. It's separate from "Reset all data," which only clears your in-app career and keeps your account and username.
You can also request deletion without opening the app at /delete-account on this same site.
The one exception: if you're the only admin on the app, you'll need to promote another admin first, so the app doesn't lose its moderation entirely. Almost no one will hit this — it only affects the person running the app.
Accounts, match history, clubs, leagues, feedback and moderation records are held in a PostgreSQL database run by our hosting provider, Railway, on servers in the region chosen for the app. The app connects to it over an encrypted connection, and the database is not reachable from the public internet — only the app server can read or write it.
Passwords are never stored in a readable form. Each one is put through scrypt with its own random salt, so the stored value can't be turned back into the password. The same is true of session tokens and email confirmation links, which are stored only as hashes.
Database contents are not separately encrypted by us beyond the encryption our hosting provider applies to its storage, so anyone with administrative access to the hosting account could read stored data — though never passwords in plain form. Only the app itself is served over the web; the database, its credentials, and the app's source code are not.
Database credentials are held as environment variables on the server and are never included in the app you download, the website, or anything sent to your device.
Backups are taken by the hosting provider on its own schedule and retained by it. A deleted account is removed from the live database immediately; copies inside those provider backups age out with the backup itself, normally within 30 days.
New accounts are asked for a date of birth when signing up, and account creation is refused if it works out to under 13. This is checked on the server, not just the app on your screen, and the date of birth itself isn't kept afterwards — only whether the check passed. If you believe an underage account has slipped through some other way, contact us at the address above and we'll remove it.
If this policy changes in a way that matters, the "Last updated" date above will change and, where practical, an in-app notice will say so.
For anything on this page — access, correction, deletion, or a general question — email [email protected].
See also: Terms of Service · Community Guidelines · Delete your account
© 2026 MiSportsCareer. All rights reserved.
← Back to MiSportsCareer