XO Gridmaker

Faster on the app — free on the App Store

Get the app

Privacy Policy

Last updated: September 3, 2026

The AI-native playbook for flag & youth football coaches

Design plays, get instant coaching from Cal, and print wristbands — free to start.

Try the free play designer →

Kerry Software, LLC ("XO Gridmaker," "we," "us") cares about your privacy. This policy explains what we collect, why, and how it's protected.

What we collect

  • Account info: email address and (optionally) a display name, used to sign you in and identify your playbooks.
  • Administrator-connected Reddit account:if a site administrator enables Social Radar, Reddit shares the connected account's username, account identifier, granted OAuth permissions, and a revocable refresh token. The app secret and refresh token are encrypted with a server-only key. The administrator can disconnect the account at any time.
  • Short-lived public Reddit content: Social Radar may temporarily copy the title, author, excerpt, community, public engagement counts, and link for relevant public posts so an administrator can review a possible response. Those post copies expire from our database within 48 hours, including deleted or removed content found during routine sync. We retain a limited action log containing the Reddit post ID and the admin action for auditing. Nothing is posted automatically.
  • Age range and adult attestations: when you first authenticate a new account, age range is the first account question before app access. On supported iOS or Android devices, you may choose to share a privacy-preserving range from Apple or Google Play; otherwise you can select a broad range yourself. We store the range, its source, and when it was recorded so we can keep children out of private communication and require a parent or guardian in youth messaging. Signing in with Apple or Google alone does not provide us an age. We do not ask for or store a full date of birth in this workflow.
  • Team roster and contact details:coaches may store player names, jersey numbers, positions, minor status, and links to parents or guardians. A linked adult or a team coach may add or correct team-specific player and guardian display names, contact email, or phone number. The adult chooses whether contact details are visible only to that team's coaches (the default) or to the entire team, and a coach's correction does not change that choice. Team-specific corrections do not overwrite account names or sign-in email, and we do not automatically publish the email address used to sign in.
  • League registration imports and team requests: a league organizer may import registration data collected by a service such as SportsEngine, including player and coach names, contact email, requested teammates or coaches, and an address or ZIP/postal code supplied for geographic team planning. The organizer reviews the normalized data and proposed assignments before anything is applied or emailed. Full street addresses are used only in that review draft and are removed from the saved import after approval. The lasting registration and team-roster records keep the submitted name and contact details, at most a ZIP/postal location hint, requests, source key, and assignment so later re-imports can avoid duplicates.
  • Time zone:when you're signed in, your browser or device reports its time zone name (for example “America/Chicago”) so scheduled email like the team digest arrives in your morning rather than someone else's. Where we have no report, we estimate the zone from the approximate region already derived from your IP address for analytics. It is stored on your account, you can change it in the team digest settings, and it is used only to time messages you have asked to receive.
  • Content you create: formations, plays, playbooks, practice plans, notes, saved external-resource links, and related metadata.
  • Private team video: an account with the Film Room add-on may upload game or practice footage into a private library, preview it, and later assign it to an eligible team. We store the video, title, optional team and event context, uploader, file and duration metadata, processing status, viewing authorizations, timestamped comments, clips, and links to plays. Footage may depict players, spectators, voices, jersey numbers, and other information visible or audible at the event. When the original file contains it, we also extract its capture date and time and embedded GPS coordinates to help the account owner organize film. We do not infer a location from an IP address or an upload time. Exact coordinates are shown only to the account owner by default and can be edited or removed. A team owner may separately allow players and coaches who can view a video to create an external link. Anyone who receives that link can stream the video until the team owner disables external sharing; comments, annotations, exact source coordinates, and roster information are not included on the external page. We also measure stored video duration, upload reservations, processing, and delivery usage to show capacity and enforce the limits attached to a coach or league Film Room subscription.
  • Practice-plan images:coaches may upload photos or diagrams to a practice-plan block or activity. The image is stored privately with Supabase and is available only after the viewer signs in and passes the same team-sharing check as the practice plan. Coaches can remove an image from the current plan; prior version snapshots retain it so edit history remains accurate. Saved YouTube links may show a video thumbnail fetched through our server; opening the link takes you to the external site and subjects you to that site's privacy practices.
  • Team links: coaches may save the title, secure external URL, resource type, optional description, due date, and return instructions for league websites, schedules, blank forms, downloads, and other team resources. These details are visible to people with access to the team. We do not fetch or copy the linked file, accept completed forms through this feature, or track what a family submits at the destination; the external site handles that activity under its own privacy practices.
  • Technical data: standard server logs (IP, user agent, timestamps) generated when you use the Service.
  • Product usage (first-party): the pages you visit, your session ID, device class (mobile/tablet/desktop), referring URL, the landing page you arrived on, and the standard UTM parameters (source, medium, campaign, content, term) on first visit, plus foreground time-on-page and selected product actions such as opening the builder, installing a library concept, sharing, and viewing or opening Film Room from a sidebar, pricing card, product page, FAQ, or tutorial. A Film Room promotion view is counted only after the link is substantially visible. We also record content-safe workflow milestones (such as upload, asset readiness, playback, coaching, and recipient engagement) and coded failure categories, but not filenames, titles, note text, share tokens, or playback URLs. When you are signed in, those action records may be associated with your account so we can see which coaches are interested in a feature and whether they go on to use it. Designated product evaluators are reported separately from organic interest. We also collect sampled performance timings for a small set of named product flows. Performance records use normalized feature and route labels and do not contain team IDs, message text, or content you create. We also attach the app build, interface version, broad platform (web/iOS/Android), and rollout cohort so we can tell whether a product change helped or hurt. We use this to understand which features get used, to size the product to actual usage, and to measure which marketing campaigns brought you here. It is collected by us, stored in our own database, and never shared with an analytics vendor.
  • Ad-platform click IDs:if you arrive from an advertisement, the click identifier the platform attaches to the link (Meta's fbclid, Google's gclid, TikTok's ttclid, and the equivalents for Bing, LinkedIn, and X). We use these to attribute signups back to the specific ad and market that drove them.
  • Approximate location: we look up your IP address against a local copy of the MaxMind GeoLite2 database to derive country, region (state/province), and city. The IP itself is not stored. We use approximate location to understand which markets respond to which campaigns.
  • Error reports: when something goes wrong in your browser, we send the error stack and the page URL to Sentry to help us fix it. Errors include the same technical data above but no playbook content.
  • Billing: if you subscribe to a paid plan, your payment details are collected by Stripe — we never see your card number. Stripe shares your customer ID, email, and subscription status with us so we can grant access to paid features. If you subscribe inside the iOS app, Apple processes the payment and shares signed transaction details with us, including subscription status, product, purchase/renewal time, price, currency, and refund or revocation status. We retain those details to grant access and reconcile revenue; we never see your card number.
  • Contact form: messages you send us through the contact form, which are delivered to our inbox via an email provider (Resend).
  • Tutorial progress:if you start a guided tour in the Learning Center, we save which tutorial you're on, the current step, the sport variant active when you started, and whether you completed or dismissed it. This is so the tour can resume where you left off and never auto-prompt you twice. It's stored only on our own servers, scoped to your account.
  • Embedded tutorial videos: the Product Tour, complete play-editor lesson, team-logistics lesson, and printing lesson initially show thumbnails hosted by XO Gridmaker, so YouTube receives no request until you choose Play. At that point Google may receive your IP address, device and browser details, and playback interactions. Privacy-enhanced views are not used to personalize your YouTube browsing experience or ads outside XO Gridmaker. We record first-party lesson and CTA events, but do not receive your YouTube account or viewing history.
  • Edit history:when a play or playbook is edited, we save a snapshot along with the editor's name, the time of the edit, and (optionally) a note left by the editor. Team coaches can review this history and restore prior versions. Deleted plays are kept in a 30-day trash before being permanently removed.
  • Play review receipts:when automatic play review tracking is enabled and a signed-in team member keeps a shared play open, we store the play, the account that viewed it, the first and most recent view times, and the version viewed. Team coaches can see which roster players have and have not reviewed each shared play. A view from the player or any linked parent or guardian satisfies that player's roster spot; the coach can see which linked account recorded the view. Views made in an offline copy are kept on that device and sent when it reconnects. Routine play edits do not reset progress; a coach may explicitly start a new review round, while prior receipts remain preserved.
  • Referral records:when a new coach signs up through your referral link, a copy of your playbook, or a team invite, we record the link between your account and theirs. If a referral reward is offered, we also record whether the referred coach completed an eligible paid coaching subscription, the billing provider, and its invoice or transaction identifier so we can issue and reconcile the reward, including reversing rewards tied to canceled, refunded, disputed, or revoked payments. We do not store payment-card details in the referral record. Each new coach can generate only one reward. We don't share the record with anyone outside our system, and you can ask us to delete it at any time.
  • Coach AI chat history:when you chat with Coach Cal we store your messages and Cal's replies on our servers, organized per playbook. This is what lets Cal keep working on a long answer if you close the chat window and pick up the result when you return, and it lets the same conversation appear when you sign in on another device. Only you (and our database administrators acting for support / debugging) can read your conversation. You can wipe the history for a given playbook at any time with the trash icon at the top of the chat panel — that deletes the rows on our servers, not just on your device.
  • Coach AI image attachments:Coach Cal accepts photo attachments (e.g. a snapshot of a play sheet, wristcoach, or whiteboard) so Cal can read what's drawn and help you import plays. Images you attach are sent in-flight to Anthropic (see the sub-processors list below) to interpret their content and are notstored on our servers. Cal sees each image only on the turn it was attached; we don't retain a copy afterward. The chat history row keeps your typed text plus a “[image attached]” placeholder but no image bytes. Image uploads are capped at 10 per coach per calendar month.
  • Photo play imports and quality reports:when you import a play from a picture, the full photo is processed in-flight and is not stored. The cropped play panel selected for import is kept privately on our servers for up to 14 days so the read can finish in the background and you can resume it. If you explicitly choose “Report this import,” we retain that cropped panel together with the original generated output, your current corrections, the issue category you select, and any note you add. Site administrators use that report to diagnose and improve photo importing. Nothing is retained for improvement unless you send the report; reported material remains linked to your account until an administrator deletes it or your account is deleted.
  • Cancellation feedback (optional):when a paid subscriber clicks “Manage billing”, we show an optional text box where they can tell us why they’re leaving (or what isn’t working). Anything typed there is stored on our servers and read by the site admin so we can improve the product. Skipping it stores nothing. We also record whatever cancellation reason Stripe’s billing portal captures (a category and any comment you choose to leave there) so we have one place to read both.
  • Coach AI feedback (opt-in): if you accept the one-time prompt the first time you use Coach AI, we log the topicof any question Coach AI had to answer from general football knowledge instead of our seeded playbook (e.g. “Tampa 2 defense”), along with your question text and the playbook context (sport variant, sanctioning body, age division). We use this to decide which topics to add to the knowledge base next. You can opt out at any time by asking Coach AI to update your preference.
  • Event volunteer commitments: coaches may create event jobs with instructions, staffing counts, report times, and meeting locations. When you sign up, join a backup list, accept, decline, or withdraw — or when a coach assigns or removes you — we store that commitment and its activity history. Current volunteer names and availability are visible to people with access to the team; coaches can also review the history from the relevant player and family details. We use the assignment to send event reminders by push notification and email.
  • Practice availability polls:coaches may share proposed practice dates and times with a team. When a parent, guardian, or player responds, we store which roster player the response represents, every workable option, an optional preferred option, who submitted it, and the response timestamp. Multiple guardians linked to the same player update one shared player response instead of creating duplicate votes. Team members see aggregate counts; the responding family and the team's coaches can see the player-level answer. If a coach schedules the selected option, it is also stored as a normal team calendar event.
  • Team chat:if your playbook has team messaging turned on, every message you post (text, sender, and timestamp) is stored so other members can read it. The owner of a playbook can disable messaging or clear all history at any time. While you're typing, a brief “is typing…” signal is broadcast to other members in the same chat — that signal is not stored. You can edit or delete your own message within 15 minutes of posting; after that, only the playbook's coaches can remove it. Deleted messages leave a tombstone (“this message has been deleted”) so the chronology stays intact.
  • Team Board: coaches may publish announcements, discussion posts, practice polls, and external links for an age-eligible team audience. We store the post, its author and timestamps, comments, reactions, pin status, and the time each member viewed it. Confirmed adult coaches can see the names of members who viewed a post; other members do not receive that reader list. Posts and comments may be reported and removed. Board access and participation use the same guardian-supervision rules as the entire-team chat.
  • Protected player and unit conversations:a coach may select one or more roster players or a roster unit as the subject of a conversation. We store the selected roster subjects, the users included in the audience, why each user is included (coach, player, or guardian of a named roster player), message history, and each participant's read time. When a teen or an unlinked child roster slot is selected, active adult guardians are automatically included and cannot be removed from that conversation. We recheck the current guardian relationship before new communication; if the final required relationship changes, history remains available but new messages are locked. An unsupervised teen may create a one-use guardian invitation. We store the intended adult's email address, the invitation token, expiration, and the roster player it is meant to protect. The teen chooses how to share that link, and a coach must approve the adult membership and guardian claim before communication unlocks.
  • Content reports: when you report objectionable content or an abusive user, we store your report — the reason, any details you add, a snapshot of the reported content, and who filed it — so our team can review and act on it. Reports are visible only to administrators.

Inside the iOS / Android app:selected first-party product actions and the sampled, first-party performance timings described above are recorded in our own database with the broad platform and app build so web and app experiences can be compared. These records are associated with the current session and, when you are signed in, your account. They contain a normalized flow and route label, timing phase and duration, outcome, navigation source, sample rate, platform, interface/build identifiers, and rollout cohort — never a team ID, message text, or content you create. They are discarded for EU/EEA/UK native requests unless the request carries a previously accepted consent choice. Advertising-conversion pixels (Reddit, Meta) do not load, and this first-party usage data is not used to track you across other companies' apps or sites. The native app also collects the account info, content, and standard server logs above, plus: a per-install identifier together with your device platform, app version, and the dates the app was installed and last opened — linked to your account — so we can measure how many people install and actively use the apps; and, if you allow notifications, a per-device push token used only to deliver the notifications you'd expect (practice and game reminders, play updates, and team messages). You can turn notifications off at any time in your device settings, and the token is removed when you sign out.

What we don't do

We don't sell your data, and we don't share your content with anyone except the people you explicitly share it with. When we run ads on Reddit or Meta, their conversion pixels count ad-driven page visits and signups so we can tell which ads work (see Sub-processors) — they're consent-gated for EU/UK visitors and we don't use them to build cross-site behavioral profiles or to upload personally identifying information.

How it's stored

Your data is stored in Supabase, which encrypts data at rest (AES-256) and in transit (TLS). Passwords are hashed — we never see or store them in plain text. Access is limited to what's required to operate the Service.

Film Room video is stored separately with our managed video providers. New web uploads may be sent directly to Bunny Stream for transcoding, private storage, and delivery; legacy and mobile-app uploads may continue to use private Google Cloud Storage and our isolated Google Cloud video processor during the migration. When Film Room 4K routing is enabled for a paid 4K plan, eligible 4K uploads may instead be sent directly to Mux Video for transcoding, private storage, thumbnails, and signed streaming delivery. Uploads go directly from your device to the selected private video environment; video bytes do not pass through the main application server. Access is authorized for a few minutes at a time after the Service checks private-library ownership, current team membership, or a valid owner-enabled external share link. Unassigned uploads are visible only to their account owner or uploader; team members gain access only after an authorized assignment. Team owners manage whether athletes can view and comment, whether downloads are allowed, and whether external sharing is enabled. Google Cloud original uploads are scheduled for deletion 48 hours after processing succeeds or reaches a final failure; Bunny is configured not to retain the original after encoding. Embedded source metadata, including GPS data, is stripped from processed playback and thumbnail files.

Film stored under a personal Film Room trial or subscription started through checkout stays in place while that access is active. If you cancel it, we schedule that film for permanent deletion 30days after access actually ends, not when a future cancellation is first requested. Restarting Film Room before the deadline cancels the scheduled deletion. Failed-payment and disputed-payment cancellations do not use this automatic cancellation policy. Film paid for by a league follows the league’s Film Room subscription instead. After the deadline, we permanently delete the stored video and its processed playback and thumbnail files. An owner can delete film sooner, and deleting the related account or team may also remove it sooner.

Sub-processors

We rely on the following service providers to run the Service:

  • Supabase — database, authentication, and storage
  • Google Cloud Platform — application hosting (our Next.js server runs on Cloud Run in the us-central1 region, where all user requests are processed); for Film Room, private object storage, asynchronous video processing, thumbnails, and secure delivery in a separately isolated Google Cloud project
  • Bunny.net — Film Room video ingest, transcoding, private video storage, thumbnails, and token-protected streaming delivery for assets routed to Bunny Stream
  • Mux — optional Film Room 4K video ingest, transcoding, private video storage, thumbnails, and signed streaming delivery for assets routed to Mux Video after 4K routing is enabled
  • Resend — transactional email (contact form, team notifications, daily digest of playbook activity)
  • GIPHY — powers the optional GIF picker in team messages. When you search for or send a GIF, your search terms are sent to GIPHY to return results; GIF images are served from GIPHY’s content network. We don’t share your identity with GIPHY.
  • Stripe — payment processing for paid plans (web)
  • Apple App Store — processes in-app subscription purchases made on iPhone/iPad. When you subscribe inside the iOS app, Apple handles the payment and shares your purchase and renewal status with us; we never see your card details.
  • Firebase Cloud Messaging (Google) — delivers push notifications to the Android app. We send Google a per-device messaging token and the notification text; Google does not retain the message beyond delivering it
  • Apple Push Notification service (APNs) — delivers push notifications to the iOS app. We send Apple a per-device token and the notification text; Apple does not retain the message beyond delivering it
  • Twilio — stores the configuration for a future SMS notification integration. User SMS notifications are currently disabled; only a site administrator can send a one-time test to a number they confirm they control, in which case Twilio receives that number and the test message for delivery.
  • Sentry — browser and server error reporting (web only)
  • Reddit — when we run ads on Reddit, the Reddit Ads pixel loads on our site to count page visits and signups from ad clicks. This lets us see which ads work without uploading any personally identifying information. The pixel is suppressed for EU/UK visitors who have not accepted tracking, and it does not load inside the iOS / Android app. Separately, an administrator may connect a Reddit account through OAuth for Social Radar. Reddit then provides the account identity and access needed to read public posts and to publish a reply only after the administrator confirms it.
  • Meta (Facebook/Instagram) — when we run ads on Meta, the Meta Ads pixel loads on our site to count page visits and signups from ad clicks, so we can measure which ads work and reach similar coaches. It reports a page-view and a signup-completion event; we don't upload personally identifying information through it. The pixel is suppressed for EU/UK visitors who have not accepted tracking, and it does not load inside the iOS / Android app.
  • Apple — if you choose “Sign in with Apple,” Apple authenticates you and shares your email and name with us
  • Google — if you choose “Sign in with Google,” Google authenticates you and shares your email, name, and profile photo with us
  • Google Maps Platform — if your team uses the calendar venue autocomplete, the address text you type is sent to Google to return matching places
  • YouTube (Google) — hosts the optional Product Tour overview, complete play-editor tutorial, team-logistics tutorial, and printing tutorial. Each player loads only after you press Play. YouTube then receives the technical and playback data needed to serve the selected video, but privacy-enhanced views are not used to personalize the viewer's YouTube experience or ads outside XO Gridmaker.
  • Google Gemini API — when the site administrator evaluates Gemini for photo play import, or selects it as the production importer, the cropped play panel is sent to Google's Gemini API to read player positions and assignments. Our own photo retention remains limited as described in “What we collect” above.
  • OpenAI — only if you opt into the Coach AI tier, in which case the play descriptions you submit are sent to OpenAI to generate suggestions and to produce search embeddings for the Coach AI knowledge base. If OpenAI is the administrator-selected AI provider, short excerpts from public Reddit posts may also be sent to rank Social Radar opportunities and draft a reviewable response.
  • Anthropic — when you use photo play import, the photo and cropped panel are sent to Anthropic's Claude API to identify panels and, unless Gemini alone is selected, read the selected play. If you opt into the Coach AI tier and the site administrator has selected Claude as the active provider, your Coach AI chat messages (and any images you attach) are also sent to Anthropic to generate responses. If Claude is selected, short excerpts from public Reddit posts may also be sent to rank Social Radar opportunities and draft a reviewable response. Images are processed under Anthropic's API terms; our own retention is described in “What we collect” above.
  • MaxMind — we download a copy of their free GeoLite2 IP-to-city database to our server and look up your IP locally. Your IP is never sent to MaxMind.

EU/UK visitors

XO Gridmaker is offered to coaches in the United States. If you visit from the European Union, the European Economic Area, or the United Kingdom, we ask for your consent before collecting any of the campaign-attribution data above (UTM parameters, referrer, ad click IDs, region, city, and landing page). Until you choose “Accept all,” we record only what is strictly necessary to operate the Service: your session ID, the page path, device class, and country. Your choice is remembered for one year and can be changed by clearing your cookies for our domain.

Your rights

You can access, export, or delete your account and content at any time. To delete your account, sign in and use the “Delete account” option on your account page — this immediately removes your auth record and cascades to your playbooks, plays, formations, and usage data. For anything else, reach us through the contact page.

Children's privacy

XO Gridmaker is intended to be created and managed by coaches and other adults, not used independently by children under 13. A team owner who enables Film Room is responsible for having authority to upload and share the footage with approved team members or through an external link, including any consent required from a parent, guardian, league, facility, or event organizer when minors are depicted. External Film Room links are off by default and can be disabled by the team owner; recipients may forward a link while it is active. A parent or guardian can use the contact page to request access to or deletion of footage involving their child.

Changes

If this policy changes materially, we'll announce it in-product or by email before the change takes effect.

Contact

Questions? Use the contact page.