Last updated: 18 August 2026(version 2026-08-18)
Longroom is a cricket statistics service for clubs. Your club holds a Longroom account and invites its members to use it.
This policy covers the account and usage data Longroom collects about you as a signed-in user, and the little we collect if you try the public demo without an account. The cricket statistics themselves, meaning matches, scorecards and player records, come from your club's Play-Cricket records, which your club provides and controls. Longroom handles those on your club's behalf, and the terms are in the Data Processing Addendum.
Longroom is operated by Tim Hoare, a sole trader trading as Longroom, of 9 Ingram Road, London N2 9QA.
For the account and usage data described in this policy, Longroom is the data controller. If you have questions about your data, email hello@longroom.app or contact your club's administrators.
Where the two meet. When you ask the assistant a question, your question is ours and the answer is built out of your club's records, so a conversation contains both. We treat the club-derived content inside a conversation as your club's data, which means your club can require us to delete it, for example when it ends its agreement with us. That does not give your club a way to read or remove one conversation at a time; it means your conversation history does not survive your club's data being deleted. The Data Processing Addendum sets this out in full at clause 2.3.
When you sign in, we receive and store:
When you use the app, we also store:
If you are the person who subscribes on your club's behalf, we also hold billing contact details and a record of your club's subscription and invoices. Card details are held by Stripe, not by us, and we never see or store them.
If your club suspends you, or removes you and bars your address, the administrator who does it can record a short note of the reason. We hold that note with the suspension or the bar. Your club's administrators can see it; you are not shown it in the app, but it is personal data about you and you can ask us for it, in the same way as anything else we hold (see Your rights). We tell administrators to keep it factual and about you.
The demo. The login page offers a demo of Longroom on a made-up club, without an account. Trying it signs you into a shared visitor account: we record a sign-in event with its time, IP address and browser identifier, kept for 90 days like any other sign-in event, and count which sections of the demo are visited. Nothing you do in the demo is attributed to you by name. The demo's chat replays pre-written questions and answers in your browser, with no free text; nothing from it is sent to us or to Anthropic.
| What | Why | Lawful basis |
|---|---|---|
| Account, sign-in, conversations, games | To provide the service to you as a member of your club | Legitimate interests (Article 6(1)(f)): running the service your club has asked us to provide to you |
| Usage information, error logs | To see which features are used and to fix problems | Legitimate interests: keeping the service working and worth using |
| Sign-in and security events | To detect and investigate unauthorised access | Legitimate interests: keeping your account and your club's data secure |
| Push tokens | To send the notifications you have chosen to receive | Legitimate interests, and your in-app choice controls it |
| Club billing and subscription records | To take payment and keep proper records | Contract (Article 6(1)(b)) with the club, and legal obligation (Article 6(1)(c)) for tax records |
We do not use your data for marketing or advertising, and we do not sell it. We do not use it to train AI models, and neither does our AI provider.
Administrators at your club manage who belongs to the club and see how it uses the app only as aggregate counts (such as how many members were active this week) — never as an individual member's browsing activity, and never as the text of your conversations with the assistant. Longroom's own operator may read conversations to keep an eye on answer quality and troubleshoot problems, and may access data where needed to operate the service or meet a legal obligation, and for no other purpose.
We use a small number of external services to run Longroom. Most of them are based in the United States, so using them involves transferring personal data outside the UK. Where that happens we rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or on the UK extension to the EU-US Data Privacy Framework where the provider is certified under it. Both are recognised safeguards under Article 46 of the UK GDPR. Each one, what it does, and where it is:
| Service | What it does | Where |
|---|---|---|
| Anthropic | The AI that answers questions | United States |
| Stripe | Subscription payments | United States / Ireland |
| Resend | Sends sign-in links and our emails | United States |
| Google (Sign-In, Firebase) | Sign-in, push notifications | United States |
| Apple (Sign in with Apple, APNs) | Sign-in, push notifications | United States |
| Porkbun | Forwards email to our published addresses | United States |
| Hetzner | Servers and backups | European Economic Area |
In more detail:
Google Sign-In and Sign in with Apple. If you choose one of these, we use Google or Apple to verify your identity. They know you have signed in to an application called Longroom, but we do not send any of your data to them beyond the standard sign-in flow. Your name and email come from them to us, not the other way around.
Nothing reaches Google unless you choose it. Our pages load no code from Google at all: pressing the Google button takes you to Google's own website to sign in, and you come back to us afterwards. If you sign in by email, or simply look at the page and leave, Google is not contacted, learns nothing about your visit, and stores nothing in your browser.
Resend (email). If you choose to sign in by email, we use Resend to deliver your login link. Your email address is shared with Resend solely for this purpose. No other personal data is sent. Resend's privacy policy.
Anthropic (Claude AI). When you ask a question, the text of your question and the data needed to answer it are sent to Anthropic's API to generate a response. Your name, email and other account details are not sent. Anthropic does not use API inputs to train their models. This is a transfer to the United States, covered by standard contractual clauses with the UK addendum.
Stripe (payments). Handles your club's subscription. If you are the person who pays on your club's behalf, your billing contact details and card details go to Stripe. Stripe holds the card; we never see it. Other members' data is not sent to Stripe. Stripe's privacy policy.
Firebase Cloud Messaging (Google), and Apple's Push Notification service. These deliver push notifications to the mobile apps. Your device token and the text of the notification pass through them, and that text can name a player: "Debut for J Smith", or that you have passed 1,000 runs. Notifications on an iPhone go through Apple as well as Google. You choose which notifications you get, if any, in the app.
Hetzner. Hosts the servers and the off-site backups, in the European Economic Area.
Porkbun. Forwards email sent to our published addresses, including
hello@longroom.app, to us. If you email us about your data, that email passes through
them.
Apart from the services listed above, we do not pass your personal data to anyone.
We use two authentication cookies to keep you signed in: one identifies you on each request, the other renews your session. A third, short-lived cookie is set only while you are signing in with Google or Apple, to check that the sign-in coming back is the one you started. These are strictly necessary cookies and do not require consent under UK PECR.
We use no analytics, tracking or advertising cookies, and no third-party analytics service of any kind. The usage information described above is measured through your existing signed-in session on our own server. Our web fonts are served from our own servers, not from Google.
Nothing in the app loads code or images from anyone but us.
Your browser also stores a few preferences and working state for us, on your device and not sent to us: which sidebar sections you have open, how you last viewed the milestones page, a game in progress so you can resume it, the room code and settings of a 501 game, where you had scrolled to in a long list, a message you were composing when the page reloaded, that you dismissed the "install the app" banner, and, in the mobile app, the notification token registered for your device. Storing settings like these is exempt from consent under UK PECR because they exist only to do what you asked. You can clear all of them at any time by clearing this site's data in your browser settings; the app then starts from its defaults.
Your account data and conversation history are kept for as long as you have an account. You can delete individual conversations at any time, or delete your entire account (see below).
Your account does not outlive your club's agreement with us. If your club ends that agreement, we delete member accounts and their conversation history 30 days afterwards. A club that has missed a payment has not ended anything, and nothing here applies to it. That is our decision rather than your club's, as the Member Terms of Use explain, and 30 days is your window to export anything you want to keep.
Error logs, game results and push notification tokens are kept for as long as you have an account and are deleted with it. A push token is also replaced whenever your device gets a new one, and deleted when you turn notifications off.
Sign-in and security events are deleted 90 days after they happen. Deleting your account immediately removes you from any that remain: the record that a sign-in happened is kept, with the link to you, the IP address and the browser identifier all removed.
Usage records are reduced to anonymous daily counts, no longer linked to you, once they are 90 days old. That tidying runs when the app is being used, so on a quiet club it can run later than 90 days. Deleting your account removes any usage records that have not yet been anonymised, along with everything else, immediately.
If your club removes you and bars your address from re-joining, we keep your email address, and any note the administrator recorded with the bar, for as long as that bar is in place, and nothing else about you. It is the only way to recognise the same address arriving at the join screen again, which is what the bar means. We keep it because your club is entitled to decide who is in it, and because a bar that quietly stopped working would be worse for everyone, including in a safeguarding case. Your club's administrators can see the address on the list and can lift a bar at any time; when they do, the record goes with it. You can also object: email us and a person will look at it.
Billing records are kept for six years after the end of your club's subscription, because tax law requires it.
Deleted data leaves our backups within 13 months. It is not restored to the service and is not used for anything in the meantime.
Under UK data protection law, you have the right to:
We respond to requests within one month.
You have the right to complain to us directly about anything to do with how we use your personal data, and we have a duty to deal with it properly.
How. Email hello@longroom.app and say that you are making a data protection complaint. Putting those words in makes sure it is treated as one rather than as a support question, but if you describe the problem in your own words we will recognise it either way.
What we will do.
If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk. You can go to the ICO at any point and you do not have to come to us first. The ICO will usually ask whether you have raised it with us first, which is why the order is mentioned here.
Longroom is for members of a cricket club, and clubs have junior sections.
Junior players appear in the cricket records. Scorecards for junior matches are part of a club's Play-Cricket history and are synced like any others. They contain a player's name and what they did in a match, and nothing else: no date of birth, no contact details, no photograph. Those records belong to the club, and a parent with a question about them should ask the club.
Accounts are for ages 13 and over. If you are under 18 we would like a parent or guardian to know you are using it. We do not ask for your age and we do not verify it.
If you are a parent or guardian and you want your child's account removed, or you have any concern about their records, email hello@longroom.app and we will deal with it.
Access is invite-only. Authentication uses Google or Apple sign-in or email magic links, with secure, HTTP-only cookies. Sign-ins, failed sign-ins and administrator actions are logged, and the operator is alerted to the patterns that suggest a break-in, such as a stolen session token being reused or a burst of failed sign-ins. Each club's cricket data is held in a separate database, and that database is read-only on the serving path. API tokens and keys are encrypted at rest. All communication is encrypted via HTTPS in production. Backups are taken nightly, encrypted before they leave the server, and held off-site.
A fuller description of the measures in place, including what we do not have, is in Annex 2 of the Data Processing Addendum.
We update this policy when what we do changes, and every version carries a date.
We do not currently show you a notice inside the app when it changes. If a change is significant we will email you where we have your address, and the dated version here is always the current one.