1. Who we are
My Jersey ("My Jersey", "the app", "we", "us") is a football kit design app published by Tapmax Apps. This policy explains what happens to information when you use the app or this website.
If you have a question about anything here, or want to exercise any of the rights in section 13, email hello@tapmaxapps.com.
2. What we don't collect
It's worth being clear about this first, because it covers most of what people worry about:
- No passwords, ever. Signing in uses Sign in with Apple or Google, so authentication happens with them, not us. We never receive, store or transmit your password, and there is no password for us to lose.
- An account is optional. Every feature works signed out. Sign in only if you want your designs backed up.
- No contacts, microphone, location or health data. The app doesn't ask for these and doesn't use them.
- We don't sell your data. Not to anyone, for any purpose.
If you never sign in, your designs live only on your device, and uninstalling the app deletes them — there is nothing on our side to restore from.
3. Accounts and cloud backup (optional)
The app offers an optional account so your designs survive losing or replacing your phone. It is entirely opt-in — you have to go to the More tab and choose to sign in, and nothing is uploaded before you do.
How signing in works
We support Sign in with Apple and Google Sign-In only. There is no email-and-password option, deliberately: it means we never handle a password, and you can't be locked out of your designs by forgetting one. Apple and Google confirm who you are and pass us a secure token — never your password.
From that we receive an account identifier and, if the provider supplies it, your name and email address. Apple's Hide My Email gives us a relay address rather than your real one, and that works fine here — we identify your account by its identifier, not your email.
What gets backed up
Once signed in, we store:
- Your kits — as the design data itself (colours, patterns, layer positions, text), not as images.
- Your badges — likewise, as the shapes and text they're made from.
- Your account record — the identifier above, a display name if one was provided, and when the account was created.
We do not upload the exported picture of your jersey. Your designs are re-drawn from the design data on whichever device you sign in to, which means far less of your information leaves your phone.
This data is held in our database, provided by Supabase and hosted in the European Union (Ireland). Access is restricted at the database level so that an account can only ever read its own designs.
Deleting your account
In the app, go to More › Delete account. This permanently deletes your account and everything backed up to it, immediately — there's no waiting period, and you don't need to email us. Designs already saved on your phone stay on your phone; we don't reach into your device and remove your work.
Signing out simply stops backing up. It deletes nothing.
4. Information collected when you use the app
Usage analytics
We use Google Firebase Analytics to understand how the app is used — which features people reach for, and where they get stuck. This is tied to a randomly generated app instance identifier, not to your identity. It typically includes:
- Device model, operating system version, language and approximate country
- App version and session information (when the app was opened, how long for)
- In-app actions, such as saving a design, unlocking an item, or selecting a favourite team
Where you pick a favourite team, that choice is recorded as a preference so we can see which clubs are popular. It isn't linked to a named person.
Crash reports
We use Firebase Crashlytics to find and fix crashes. If the app fails, it sends a diagnostic report containing the technical error, the device model and OS version, and the state of the app at the time. These reports are sent from published (release) builds of the app.
Advertising
My Jersey is free and is funded by ads, served by Google AdMob. To do that, Google may process your device's advertising identifier, IP address, and how you interact with an ad. Depending on your consent choices (section 7), ads are either personalised — selected using that identifier — or non-personalised, which still requires basic data to serve and measure the ad but does not build an advertising profile.
Some content in the app can be unlocked by watching a rewarded ad. Choosing to watch one is optional.
Remote configuration and content
The app uses Firebase Remote Config to update settings and to point at up-to-date catalogues of kits, patterns, textures, brands and sponsors. Artwork is then downloaded from our content delivery network, Bunny.net. As with any request over the internet, the servers involved receive your IP address in order to send the files back.
Reviews and updates
The app may show the operating system's own "rate this app" prompt, and may check whether a newer version is available. Any review you write goes to Apple or Google, not to us, and is governed by their policies.
5. Photos and images
Two separate permissions are involved, and both are asked for only at the moment you use the feature:
- Choosing an image. If you add your own image to a design, the app reads the single file you select. It is used to render your kit on your device and is not uploaded to us.
- Saving an image. When you export a design, the app writes the finished PNG to your device's photo library so you can keep or share it.
If you share a design using your device's share sheet, where it goes is entirely your choice and is handled by the app you send it to.
6. AI photo generation
The app includes an optional feature that turns one of your saved designs into a photorealistic image. It runs only when you choose to use it, and never in the background.
What is sent, and where
- A picture of your design. The app draws your saved kit and sends that image. It is generated from your design on your device — it is never a photo of you, and nothing is read from your camera roll.
- The options you pick. Whether the kit is shown on a mannequin or on a person, and, if a person, the general characteristics you select from a fixed list. You cannot type free text, so no personal description is ever sent.
That image is sent to our server in the European Union (Ireland) and passed to OpenAI, which generates the photograph and returns it. OpenAI processes it on servers in the United States. OpenAI states that content submitted through its API is not used to train its models, and is retained only briefly for abuse monitoring — see the OpenAI API data usage policies.
What we keep
We do not store the generated photo anywhere. It is returned to your device, saved inside the app, and copied to your photo library. It exists on your phone and nowhere else, which also means it is not backed up to your account and will not survive reinstalling the app unless you have saved it elsewhere yourself.
Our server keeps only a record of the request itself: which model ran, how much processing it used, what it cost us, and when. No images are kept, and those records are not used to identify you beyond linking the request to your account so your balance is correct.
Paying for it
Generating a photo spends a token, bought through the App Store or Google Play. Your balance and the history of tokens added and spent are stored with your account. Purchases themselves are handled by Apple or Google — we never see your payment details — and are reported to us through RevenueCat so the right number of tokens is credited.
7. Your consent choices
You are in control of how your data is used for advertising:
- On iOS, the system App Tracking Transparency prompt asks whether the app may track you across other companies' apps and websites. If you decline, no advertising identifier is used for personalised ads. You can change this at any time in Settings › Privacy & Security › Tracking, or in Settings › My Jersey.
- In the EEA and UK, Google's consent form appears before personalised ads are enabled, and records whatever choice you make.
- On Android, you can reset or delete your advertising ID in Settings › Google › Ads.
Declining personalised ads does not restrict any feature of the app — you'll simply see less relevant ads.
8. Legal bases for processing
If you are in the UK or the European Economic Area, we rely on the following legal bases under the UK GDPR and EU GDPR:
- Consent — for personalised advertising, and for the use of advertising identifiers.
- Legitimate interests — for anonymous usage analytics and crash diagnostics, so the app can be kept working and improved. We consider this proportionate because the data is not linked to your identity.
- Performance of a contract — to deliver the app's functionality to you under our Terms of Use.
9. Who your data is shared with
We do not sell or rent data. It is shared only with the service providers that make the app work:
- Google (Firebase Analytics, Crashlytics, Remote Config, AdMob) — see the Google Privacy Policy and how Google uses data from partner apps.
- Bunny.net — content delivery for app artwork. See the Bunny.net Privacy Policy.
- Supabase — the database holding accounts and backed-up designs, for signed-in users only. Hosted in the EU (Ireland). See the Supabase Privacy Policy.
- OpenAI — generates AI photos from the design image you submit, for that feature only. See the OpenAI Privacy Policy.
- RevenueCat — processes purchase and subscription events so entitlements and token balances are applied to your account. See the RevenueCat Privacy Policy.
- Apple and Google — as the app stores that distribute the app and handle any purchases or reviews.
We may also disclose information if we are legally required to do so.
10. International transfers
Your account and backed-up designs are stored in the European Union (Ireland) and are not moved elsewhere by us.
Images submitted for AI photo generation are processed by OpenAI in the United States. The other providers above operate globally, so analytics, crash and advertising data may be processed outside the UK or EEA, including in the United States. Where that happens, those transfers rely on the safeguards those providers put in place, such as the European Commission's standard contractual clauses.
11. How long data is kept
Designs and settings remain on your device until you delete them or uninstall the app.
If you have an account, your account record and backed-up designs are kept until you delete the account. Deleting it removes them immediately — see section 3. We don't keep a shadow copy afterwards, and we don't delete accounts for inactivity, so your designs stay recoverable however long you leave them.
AI photos are never stored on our servers at all. The record of each generation request, and your token balance, are kept with your account and removed when you delete it.
Analytics and crash data are retained by Google according to the retention periods set for our Firebase project, after which they are deleted or aggregated. Advertising data is governed by Google's own retention policies.
12. Security
We hold no passwords, because sign-in is handled entirely by Apple or Google. That removes the single most damaging thing an app can leak.
For signed-in users, access to backed-up designs is enforced in the database itself: each account can only read and write its own rows, rather than relying on the app to ask the right question. Data in transit is encrypted using HTTPS.
No method of transmission or storage is completely secure, but the amount of information involved here is deliberately small — no passwords, no payment details, no contact list, and no exported images.
13. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal data, to object to or restrict processing, and to withdraw consent at any time.
In practice the most direct controls are in the app itself: the consent choices in section 7, and More › Delete account, which erases your account and everything backed up to it at once.
For a formal request, email hello@tapmaxapps.com. If you have an account, tell us the email or Apple/Google identity you signed in with so we can find it. If you've never signed in, we hold no record tied to you, and we may not be able to link any data to you at all — a consequence of collecting so little.
If you are in the UK you may complain to the Information Commissioner's Office; in the EEA, to your local data protection authority.
California residents. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we do not knowingly process sensitive personal information. You may exercise your rights using the contact address above.
14. Children
My Jersey is a general-audience app and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided personal information to us, contact hello@tapmaxapps.com and we will delete what we can identify.
15. Changes to this policy
If this policy changes, the updated version will be posted on this page with a new "last updated" date. Significant changes affecting how your data is used will be highlighted in the app where practical.
16. Contact
Questions, requests or complaints: hello@tapmaxapps.com.