Privacy Policy
Version 1.1 · Effective August 12, 2026
This policy explains what personal information BayDraft collects, why we collect it, who we share it with, how long we keep it, and what rights you have over it. It describes what the app and service actually do today. If we add a feature that changes what we collect — analytics, payments, or AI-assisted design, none of which exist today — we will update this policy and note the change before that feature ships.
1. Who we are
BayDraft is developed and operated by Bill Sharar II, an individual developer in the United States ("BayDraft," "we," "us," "our"). For the purposes of the EU and UK General Data Protection Regulation, we are the data controller for the information described here.
You can reach us about anything in this policy at legal@baydraft.app.
This policy covers the BayDraft application, the BayDraft backend service and API, and this website. It is referenced by, and incorporated into, the BayDraft End User License Agreement, which is also readable offline in the app under About → End User License Agreement.
2. What we collect
2.1 Account information
To create an account, you give us an email address, a display name, and a password. We store the email address and display name as you enter them. We never store your password: we store only a one-way bcrypt hash of it, from which the password cannot be recovered. We also record the date your account was created and last updated.
To confirm that the address you gave us is really yours, and to let you reset a forgotten password, we email a short numeric code to that address. We never store the code itself — only a one-way bcrypt hash of it, together with the address it was sent to, when it was sent, and how many incorrect attempts have been made. A code expires 15 minutes after it is sent, and the record is discarded once the code is used or has expired. We also record whether your address has been confirmed and when, and the time your password was last changed, which lets a password reset sign out other sessions.
2.2 Stage designs you create
When you save a stage to your account, we store the content of that design: the scene graph (the bay, the props you placed, and their positions and rotations), the stage name, any notes, tags, and sport you set, the calculated round count, and the thumbnail image the app generates for the stage list. This is your content. We do not use it for any purpose other than providing the service to you.
2.3 Share links
If you use the share feature, we create a link for the specific stage you chose and record which stage it points to and when it was created. Anyone who has that link can view that stage design without signing in — that is the point of the feature — so only share it with people you intend to see the design. You can revoke a link, which stops it from resolving.
2.4 Technical and log data
Our servers write an operational log entry for each API request containing the HTTP method, the request path, the response status, how long the request took, a random request identifier, and, for signed-in requests, the account identifier. These logs let us diagnose errors and detect abuse.
Our hosting and DNS providers may separately record standard network information, including IP addresses, in their own infrastructure logs as part of delivering and protecting the service.
3. What we don't collect
To be explicit about the things apps commonly collect that we do not:
- No analytics or telemetry. The app contains no analytics SDK, usage-tracking library, or session-recording tool.
- No crash reporting. We do not collect automatic crash or diagnostic reports.
- No advertising. There is no advertising in BayDraft, no advertising identifier is collected, and no advertising or data-broker network receives anything from us.
- No location data. We do not request or collect your device's location.
- No contacts, photos, microphone, or camera access.
- No payment information. BayDraft is free today; we do not collect or process card details.
- No cookies or trackers on this website. This site sets no cookies, embeds no third-party fonts, scripts, pixels, or analytics, and makes no requests to any other host.
4. How we use it
- To create and authenticate your account and keep you signed in.
- To store, sync, and return the stage designs you create, across your devices.
- To serve the prop and bay asset library to the app.
- To resolve share links you create, and to revoke them when you ask.
- To operate, secure, and troubleshoot the service — including investigating errors, abuse, and attempted intrusions.
- To confirm that your email address is really yours, and to send you a password-reset code when you ask for one.
- To contact you about your account or about material changes to this policy or the license agreement.
- To comply with the law and to establish, exercise, or defend legal claims.
We do not use your stage designs to train machine-learning models. We do not profile you, and we do not make decisions about you by automated means that produce legal or similarly significant effects.
5. Legal bases (EEA and UK)
If you are in the European Economic Area or the United Kingdom, we rely on the following legal bases under Article 6(1) GDPR:
| Purpose | Legal basis |
|---|---|
| Creating your account, authenticating you, and storing and syncing your stage designs | Performance of a contract — Art. 6(1)(b) |
| Resolving and revoking share links you create | Performance of a contract — Art. 6(1)(b) |
| Operational logs, security monitoring, and abuse prevention | Legitimate interests — Art. 6(1)(f), in keeping the service available and secure |
| Confirming your email address, and sending a password-reset code you asked for | Performance of a contract — Art. 6(1)(b); legitimate interests — Art. 6(1)(f), in keeping accounts secure |
| Service and policy-change notices sent to your account email | Performance of a contract — Art. 6(1)(b) |
| Retaining records to comply with law or defend legal claims | Legal obligation — Art. 6(1)(c); legitimate interests — Art. 6(1)(f) |
We do not collect special-category data under Article 9, and you should not put such data into stage names, notes, or tags.
6. Who we share it with
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We have never done so.
We use a small number of infrastructure providers to run the service. They process data on our behalf, under contract, and only to provide us their service:
| Provider | Role | Location |
|---|---|---|
| Amazon Web Services, Inc. | Application hosting, database, file storage, content delivery, and transactional email | United States (us-east-1) |
| Cloudflare, Inc. | Domain registration and DNS | United States / global network |
Beyond those providers, we disclose personal information only:
- When you direct it — for example, by creating a share link or exporting a stage.
- When the law requires it — in response to a valid subpoena, court order, or other lawful demand. Where we are legally permitted to do so, we will make reasonable efforts to notify you first.
- To protect rights and safety — where we reasonably believe disclosure is necessary to prevent fraud, abuse, or harm.
- In a business transfer — if BayDraft is ever sold or transferred, your information may transfer with it. You will be notified, and the acquirer remains bound by this policy until you are given notice of a replacement.
7. Where it's stored, and international transfers
Your information is stored and processed in the United States, in Amazon Web Services' us-east-1 region in Northern Virginia. We do not operate servers in the EEA, the UK, or Switzerland.
If you use BayDraft from the EEA or the UK, using the service necessarily transfers your information to the United States. The United States has not received an adequacy decision of general application. We rely on Article 49(1)(b) GDPR — the transfer is necessary to perform the contract between you and us, because storing and syncing your stage designs is the service you asked for and our infrastructure is located in the United States. Where a provider offers them, we also rely on the European Commission's Standard Contractual Clauses in our agreements with that provider. U.S. law may permit government authorities to access data held by U.S. providers, and U.S. law may not give you the same remedies as the law where you live.
If you would prefer your data not be transferred to the United States, do not create an account.
8. How long we keep it
| Data | Retention |
|---|---|
| Account record (email, display name, password hash) | Until you ask us to delete your account, then deleted |
| Email verification and password-reset codes (stored only as a one-way hash) | Expire 15 minutes after they are sent; deleted when used, and otherwise shortly after they expire |
| Stage designs and thumbnails | Until you delete the stage, or until your account is deleted |
| Deletion markers (which record that a stage was deleted, so the deletion propagates to your other devices) | Removed once all your devices have synced, and in any case with your account |
| Share links | Until you revoke the link or delete the underlying stage |
| Server operational logs | 90 days, then automatically deleted |
We may retain information longer where we are legally required to, or where it is necessary to establish, exercise, or defend a legal claim. Deleted data may persist briefly in routine encrypted backups before being overwritten.
9. How we protect it
- All traffic between the app and our service is encrypted in transit with TLS.
- Passwords are stored only as bcrypt hashes with a work factor of 12. They are never stored, logged, or transmitted in plain text after the moment you enter them.
- On your device, your sign-in tokens are held in the operating system's secure credential store (Keychain on Apple platforms, Keystore on Android), not in ordinary app storage.
- Stage files and asset storage are private. Files are served through short-lived signed URLs, not public buckets.
- Data at rest is encrypted by our hosting provider, and access to production systems is restricted by scoped credentials.
- Requests are scoped to the signed-in account: our API returns only stages owned by the account making the request.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you and the relevant authorities as required by applicable law.
10. Data on your device
BayDraft stores data locally so it works without a connection: your stages, downloaded prop and bay 3D models, thumbnails, your display-unit and other preferences, and your sign-in tokens. This data stays on your device and is under your control. Uninstalling the app removes it. Local data may also be included in your device's own backups — iCloud, Google, or a machine backup — which are governed by that provider's terms, not ours.
11. Your rights
Wherever you live, you can ask us to do any of the following with the personal information we hold about you:
- Access — get a copy of it, and know what we collect, why, and who receives it.
- Correct it if it is wrong or incomplete.
- Delete it, including deleting your account entirely — see Delete Your Account for exactly what is removed and how long it takes.
- Export it in a portable, machine-readable format.
- Object to or restrict processing we base on legitimate interests.
- Complain to a data protection authority, without being penalized by us for doing so.
How to exercise them
Some of this you can do yourself in the app: edit your display name in your profile, and delete individual stages from the stage list, which removes them from our servers and your other devices.
For everything else — a copy of your data, an export, correcting your email address, or deleting your account and all of its contents — email legal@baydraft.app from the address on your account. We will confirm receipt within 10 days and complete the request within 30 days (extendable once, with notice to you, where the request is complex). We do not charge for this, and we will not treat you differently for asking.
We verify requests by requiring that they come from the email address registered to the account, and we may ask a follow-up question that only the account holder could answer. If we cannot verify you, we must refuse the request — that refusal protects your data. An authorized agent may act for you with written permission that we can verify.
12. U.S. state privacy rights
Residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws have the rights listed in Section 11, exercised the same way. In the vocabulary of those statutes:
- The categories of personal information we have collected in the past 12 months are identifiers (email address, display name, account identifier, and IP address recorded by our infrastructure providers), internet or network activity (the operational request logs in Section 2.4), and the content you create (your stage designs). The sources, purposes, and recipients are described in Sections 2, 4, and 6.
- We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are defined by the California Consumer Privacy Act and equivalent state laws. We have not done so in the preceding 12 months, and we do not sell or share the personal information of consumers under 16.
- We do not collect sensitive personal information and therefore do not use or disclose it for purposes requiring a right to limit.
- We do not use personal information for targeted advertising or for profiling in furtherance of decisions producing legal or similarly significant effects, so there is nothing to opt out of.
- Non-discrimination. We will not deny you service, charge you a different price, or give you a lower quality of service for exercising any privacy right.
- Appeals. If we decline a request, you may appeal by replying to our decision. We will respond to the appeal within 45 days with our reasoning, and tell you how to contact your state attorney general if you disagree.
- Shine the Light. We do not disclose personal information to third parties for their own direct-marketing purposes.
13. EEA and UK rights
In addition to the rights in Section 11, if you are in the EEA or the UK you have the right to data portability under Article 20, the right to withdraw consent at any time where we rely on consent (we currently do not rely on consent for any processing), and the right to lodge a complaint with your local supervisory authority. In the UK, that is the Information Commissioner's Office (ico.org.uk); in the EEA, it is the authority for the member state where you live, work, or where you believe an infringement occurred.
We have not appointed an Article 27 representative in the EU or UK, because our processing of EEA and UK residents' data is occasional, small in scale, limited to what Section 2 describes, and unlikely to result in a risk to rights and freedoms. If that changes, we will appoint one and name them here.
14. Children
BayDraft is not directed to children. You must be at least 13 years old to use the app, and at least 18 to create an account. We do not knowingly collect personal information from a child under 13. If you believe a child under 13 has given us personal information, email legal@baydraft.app and we will delete it promptly.
15. Changes to this policy
We may update this policy as the service changes. When we do, we will change the version and effective date at the top of this page. If a change is material — for example, if we begin collecting a new category of information or share it with a new kind of recipient — we will give you notice by email to the address on your account, or in the app, before it takes effect. Previous versions are available on request.
16. Contact
Questions, requests, or complaints about privacy: legal@baydraft.app.
Postal address for formal notices:
Bill Sharar II
651 N. Highway 183 #335, #4162
Leander, TX 78641
United States