Scope
Grappler LLC ("Grappler," "we," "us," or "our") operates the Grappler apps, website, and connected services described in this policy.
Grappler is a wrestling scoring, timing, meet-management, evaluation, and reference application. This policy applies to Grappler on Android phones and tablets, iPhone and iPad, Wear OS, Apple Watch, and Apple TV. Features differ by platform, but this policy describes the combined data practices of all supported versions.
Information you provide
Accounts. Core local tools can be used without creating a permanent account. On supported mobile platforms, you may choose Sign in with Apple, Google Sign-In, or a verified email/password account. Grappler and Firebase then process an account identifier and may process your name, email address, authentication provider, and verification state. For email/password accounts, Firebase processes the password credential and sends verification and password-reset messages; Grappler does not store a readable copy of the password.
Wear OS, Apple Watch, and Apple TV do not create permanent Grappler accounts when joining a timer session. They use a temporary anonymous Firebase service identity to redeem a role invitation and access only the authorized session.
Records, evaluations, and preferences. Information you enter can include evaluator and official information, professional officiating-performance ratings, state or association affiliation, school affiliation, event and violation details, observations, dual-meet information, team and wrestler names, match scorebooks, choices, penalties, results, and other bout records. Cloud-enabled features can associate this content with an authenticated account so it can be synchronized, recovered, reviewed, or submitted.
The evaluation's movement and positioning criteria assess how effectively an official performs officiating duties. They are not used as personal exercise, workout, wellness, or biometric tracking. When signed in, eligible preferences can also be synchronized to the account, including preferred weight classification, period format, dashboard order, pre-meet group, and tutorial completion state.
Timer and scoring sessions. Timer sessions process invitation codes, session and device roles, membership, clocks, scores, periods, positions, commands, teams, wrestler names, scorebooks, and related match state so authorized devices remain synchronized. Special-timer state can include rule-based injury, blood, recovery, and head-and-neck countdown selections and remaining time. When Internet Sync is used, this state can be transmitted together with wrestler, corner, or team labels. Grappler uses it to administer wrestling rules and connected displays, not to diagnose, treat, or monitor a medical condition.
Temporary invitation codes are credentials. Share them only with people who should be able to view or control the match in the assigned role.
Platform-specific behavior
Android, iPhone, and iPad. The mobile apps provide the full local and cloud-enabled feature set. Depending on the feature, they can use Firebase Authentication, Cloud Firestore, Realtime Database, Cloud Functions, App Check, Local Wi-Fi, camera or photo access, on-device text recognition, and Sentry diagnostics.
Wear OS and Apple Watch. The watch apps provide local timer functionality and can join Internet Sync sessions. Each watch can store local timer settings, active deadlines, alerts, an anonymous Firebase credential, and temporary reconnection information on the device. A connected watch reads authorized session state and can send timer commands only when its assigned role permits control.
Wear OS uses Google Play Integrity for production App Check attestation. Apple Watch uses Apple App Attest for production App Check attestation. Debug builds use platform-specific debug attestation instead. The watch apps do not use Grappler's direct Local Wi-Fi session transport. Local notifications, alarms, vibration, and wrist haptics can alert when supported timers expire. Grappler does not receive or store Siri audio; Apple processes supported App Shortcut speech through its operating-system services.
Apple TV. Apple TV is a view-only scoreboard. It first looks for a matching encrypted Local Wi-Fi Observer session and can fall back to Internet Sync. For Internet Sync, it uses an anonymous Firebase identity and Apple App Attest to redeem an Observer invitation and read authorized session state. It can store a temporary session identifier locally to reconnect, but it cannot change match scoring or timer state.
Local Wi‑Fi and Internet Sync
Supported Android, iPhone, iPad, and Apple TV devices can discover a timer host through platform local-network discovery services, including Bonjour on Apple platforms. Local Wi-Fi session traffic is authenticated and encrypted between participating devices and is not stored in Firebase unless the connection uses or falls back to Internet Sync. Devices on the local network can necessarily observe ordinary network addressing and service-discovery traffic.
Internet Sync uses Firebase Cloud Functions and Realtime Database, with Cloud Firestore retained for features and older app versions that use it. Firebase processes the temporary session records and authorization grants required to synchronize devices. Internet Sync connections require an invitation and expire or become unavailable when the host ends the session.
Information processed automatically
Firebase processes technical information needed for authentication, cloud storage, requests, abuse prevention, and Internet Sync. Depending on the platform and feature, this can include IP address, user-agent information, Firebase user or installation identifiers, app version, request metadata, and service diagnostics.
Firebase App Check processes app or device attestation material and short-lived integrity tokens to help determine whether protected requests come from an authentic Grappler app or device. Android and Wear OS use Google Play Integrity in production; iOS, watchOS, and tvOS use Apple App Attest in production.
The Android and iOS mobile apps use Sentry for crash, performance, log, and technical diagnostics when a Sentry connection is configured. Diagnostic events can include device and operating-system details, app version, stack traces, network or timing information, recent screen and control breadcrumbs, and error messages. Because current application logs can include account or user-entered values when an error occurs, a diagnostic event may include a name, email address, or limited content context.
On supported mobile devices, on-device text-recognition libraries can process device, app, installation, and technical performance information. The source weigh-in image remains on the device as described below.
The Google Sign-In SDK embedded in the Apple mobile build declares that it may process account/profile and technical categories including name, email address, phone number, coarse location, user ID, device ID, other usage data, and other data for app functionality or analytics. Grappler requests only the sign-in information needed for authentication and does not use this information for advertising or cross-app tracking.
Camera, photos, location, and sensors
On supported mobile devices, camera access is used to scan QR invitations or capture a weigh-in sheet. Photo-library access can be used to select a weigh-in sheet for on-device text recognition. Grappler does not intentionally upload or retain the source camera image or selected photo as a cloud image after the local task is completed.
Grappler does not request GPS or device-location permission and does not intentionally derive or store precise physical location. Network and identity providers necessarily receive IP addresses, which can inherently reveal an approximate region, but Grappler does not use those addresses to determine physical location. Local-network access is used to find participating devices, not to determine physical location.
Grappler does not access HealthKit, Health Connect, workout history, heart rate, motion-and-fitness sensors, or other health sensors. Rule-based special-timer state may nevertheless indicate that an injury, blood, recovery, or head-and-neck stoppage was selected during a match, as explained above.
The watch and TV apps do not access the camera, photo library, contacts, microphone recordings, or precise location for Grappler features.
How information is used
Information is used to:
- provide timing, scoring, dual-meet, evaluation, recovery, reference, and synchronization features;
- authenticate accounts, verify email addresses, support password resets, and associate authorized content with the correct account;
- connect role-based mobile, Wear OS, Apple Watch, and Apple TV devices;
- remember eligible preferences and restore authorized records;
- submit an official final-dual result when the user explicitly requests it;
- maintain service integrity, reliability, security, and abuse prevention;
- diagnose crashes, performance issues, and technical failures; and
- respond to support, privacy, correction, and deletion requests.
Service providers and result recipients
Grappler relies on Apple and Google for supported sign-in and platform services, Google Firebase for authentication and cloud services, Apple App Attest and Google Play Integrity for app-attestation checks, on-device recognition libraries for weigh-in scanning, and Sentry for mobile application diagnostics. These providers process information under their own terms and privacy policies and may process information in countries other than your own.
When you explicitly submit an official final-dual result, Grappler can deliver the event record to the state association or other governing organization identified in the submission flow. That recipient may retain and use the delivered record under its own rules and privacy practices.
Retention
Local app information remains on a device until it is deleted in the app, reset, or removed with the app, subject to operating-system backups and platform credential-storage behavior. Watches and Apple TV can retain an anonymous credential or temporary session information so they can reconnect. Disconnecting or leaving a session clears the active reconnection state where supported; local timer preferences can remain until reset or app removal.
Cloud records remain while needed to provide the selected feature, complete a deletion request, maintain security, or meet legal obligations. Temporary invitations expire, and Internet Sync session records are intended to be short lived. Diagnostic providers retain technical data according to their configured retention periods.
Final-dual results submitted for a state association or other organization may be retained as official event records after the reporting official deletes a Grappler account. Grappler removes the reporting official's name, account identifier, and email address from the retained copy it controls. Event information such as the meet date, teams, scores, receiving organization, confirmation identifier, and delivery status may remain. A receiving organization may separately retain a result already delivered to it.
Your choices and deletion
You can use core mobile tools without a permanent account, decline optional camera or photo access, use Local Wi-Fi instead of Internet Sync where supported, disconnect connected devices, sign out, remove local records, and request deletion of an account and personal cloud data. Some automatic security and diagnostic processing cannot currently be disabled while using the affected online service or mobile app.
While signed in on Android, iPhone, or iPad, open Account and choose Delete Grappler Account to delete the authentication account and personal cloud data, subject to the official-result retention described above. Grappler also removes account-specific recovery copies from that mobile device. Deleting an app from a device does not by itself delete cloud records.
You may alternatively use the account-deletion page or email admin@grappler.social from the address associated with the account and request “Grappler account deletion.” Grappler may ask you to verify account ownership and will explain any required retention. Sign in with Apple credentials are reverified and revoked as part of the in-app deletion process; Apple-linked accounts must be deleted from Grappler on an iPhone or iPad.
Wear OS, Apple Watch, and Apple TV session identities are temporary service identities rather than permanent Grappler accounts. Disconnecting and removing the app clears locally held session information, subject to platform backup and credential-storage behavior.
Children
Grappler is a general-audience sports utility intended for officials, coaches, event personnel, and other adult users. It is not directed to children under 13 and does not knowingly invite children under 13 to create accounts. Adults should avoid entering more information about youth athletes than is necessary to administer a match. A parent or guardian who believes information about a child was provided inappropriately may contact Grappler to request review or deletion.
Security
Grappler uses platform security controls and encrypted transport for cloud connections. Local Wi-Fi timer traffic uses an authenticated encrypted session intended to remain within the participating local network. Access to synchronized sessions is role-based and invitation-controlled. No method of storage or transmission can be guaranteed to be completely secure, so users should protect invitation codes and avoid placing unnecessary sensitive information in free-text fields.
Changes
This policy may be updated as Grappler, its supported platforms, or its service providers change. The effective date will be revised when material changes are published.
Contact
For privacy questions, access requests, corrections, or deletion requests, contact Grappler LLC at admin@grappler.social.