Privacy

There are no accounts on this site, so there is very little about you to store. This page lists what is measured anyway, who else sees a request from your browser, and how to reach us about it.

Last updated 12 September 2026. The first half is about the website, which exists today. The second half is about the iOS and Android apps, which do not exist yet — those sections are written in the future tense on purpose, and they will be rewritten in the present tense on the day the apps ship. The rules for using the site are on the terms of use page.

Analytics

We use Yandex.Metrica (counter 112465743) to see how many people open which pages, from which country, and on what kind of device. Metrica currently also records anonymous session replays (Webvisor) and click maps, which show where visitors click and how far they scroll.

That data is processed on Yandex servers under the Yandex privacy policy. We look at it in aggregate and we do not use it to identify anyone.

Cookies and local storage

Your light or dark theme choice is kept in your browser's local storage under the key tsl-theme. It never leaves your device and it is not sent to us.

Yandex.Metrica sets its own cookies to tell repeat visits from new ones. There are no advertising cookies, no ad networks, no social buttons, and no cross-site profiling.

Server logs

Our web server writes standard request logs — IP address, requested page, referrer, browser user agent — which we use to keep the site up and to stop abuse. They are not combined with analytics data and are not shared.

Content loaded from other services

Player photos and tournament logos are served from our data provider's image host. Live-score pages load the SignalR client from a public code CDN, and venue pages with coordinates load map tiles from OpenStreetMap or Apple Maps. Because your browser fetches those files directly, those services see your IP address; we send them nothing else.

What we do not collect

  • No registration, no accounts, no passwords
  • No email lists and no newsletters
  • No payment data — nothing on the site is for sale
  • No selling or sharing of visitor data beyond the analytics service above

This list describes the website. The apps are covered further down, and the difference is honest: an app that shows ads sees more about a device than this website does.

Your choices

You can block or delete analytics cookies in your browser settings, or opt out of Metrica entirely with the Yandex opt-out tool. The site works the same either way.

To ask what we hold about you, or to ask us to delete it, use the contact form. In practice there is no personal account data to return — only aggregated analytics, server logs, and any message you sent us yourself.

The contact form

Sending the form on the contact page stores a row in our database: the topic you picked, the text you wrote, the page address you typed in, the email address if you filled that field, plus your IP address and browser user agent. The last two are kept to recognise spam and abuse, not to identify you.

We use it to check the report and, if you left an address, to answer that one message. It is never added to a mailing list, never sold, and never shared with the analytics service or the data provider.

There is no automatic expiry: a message sits in the database until we delete it, and we clear out handled ones from time to time. Leaving the email field empty makes the message anonymous apart from the IP address stored beside it. To have a message deleted sooner, send another one through the form saying which message it was, and we remove it.

The mobile apps, when they are released

There is no TennisScoreLive app yet. Nothing in this section is running anywhere right now; it describes what the iOS and Android apps will do when they are published, so that nothing in them comes as a surprise. If a plan below changes before release, this page changes with it.

The apps will read the same data as the website through the same public API. There will still be no accounts, no registration, no passwords, and nothing to buy inside them. As with the website, our server will write a log line for each request — address, path, app version, and the client identifier the operating system sends — which we use to keep the service up and to stop abuse.

The apps will not ask for your device location, your contacts, your photos, your files, your calendar, your microphone, or your camera. Venue maps are drawn from coordinates in the data feed, not from where your phone is.

Device and advertising identifiers in the apps

Two kinds of identifier are involved once an app exists. The first is an install identifier generated on your device, which lets us count installs and tie a crash report to the session that produced it; it is reset when you delete and reinstall the app, and it is not your name. The second is the advertising identifier the platform maintains — IDFA on iOS, the Advertising ID on Android — which exists for ads, is device-wide, and can be reset or removed by you at any time.

On iOS, an app may only read the IDFA after you agree to the App Tracking Transparency prompt. If you tap “Ask App Not to Track”, or turn off “Allow Apps to Request to Track” in Settings, the identifier the app receives is all zeros and no cross-app tracking happens; the app works exactly the same either way. Apple explains the prompt here.

On Android, the control is in the system settings rather than in a prompt: Settings → Privacy → Ads lets you reset or delete the Advertising ID, and the ad-privacy switches next to it turn off ad topics, app-suggested ads, and ad measurement. Google explains those settings here. A deleted Advertising ID is returned to apps as a string of zeros.

Ads in the apps

The apps are expected to show ads — that is how a free score app without subscriptions pays for a server. The website does not show ads and there is no plan to put any on it. Ads will be filled through an advertising mediation partner and the ad networks it works with; the sellers we authorise are listed publicly in app-ads.txt at the root of this domain, which is the industry file that lets buyers check who is allowed to sell our inventory.

Be clear about what that means: to request and render an ad, those SDKs run inside the app and see technical data directly — your IP address, the advertising identifier if you allowed it, device model, operating system version, language, coarse country, and which ad you were shown and whether you interacted with it. They receive that under their own privacy policies, and we cannot inspect or delete what they hold. We do not send them your contact-form message, and there is nothing else about you in the app for them to receive.

If you decline tracking on iOS or remove the Advertising ID on Android, you will still see ads, but they are picked from context rather than from a profile.

Push notifications

We send no notifications today. The website has no web push at all — no service worker, no notification permission prompt, nothing to subscribe to — and that is deliberate, not an oversight.

If the apps add score alerts, they will work like this. The operating system issues your app install a device token — a long random string that identifies this installation to Apple's or Google's push service, not you — and we store that token so we can ask the platform to deliver a message to it. A token is not an address, not a phone number, and cannot be used to reach you anywhere else. Alerts will be opt-in: you pick a match or a player, and no alerts go out before you do.

Turning them off will be equally plain: switch notifications off for the app in the system settings, or turn the alert off in the app. Either way the token stops being usable and we delete it; deleting the app has the same effect.

Crash reports and app diagnostics

An app that crashes silently never gets fixed, so the apps will most likely carry crash reporting: a stack trace, the app version, the device model and operating system version, and the install identifier that ties one report to one session. That is diagnostic data, not content — no scores you looked at, no message you typed.

We have not picked a crash-reporting provider yet, so we are not naming one here rather than naming the wrong one. When the choice is made, this section will say who it is and where the reports are held. Beyond crashes, we expect only aggregate usage counts — how often a screen is opened, which sections people use — and not a per-person history. Apple's and Google's own store analytics also report installs and crashes to us in aggregate, whatever we do, and you can turn that sharing off in your device settings.

What the App Store and Google Play listings will declare

Both stores make us fill in a form — Apple's privacy labels, Google's Data safety section — and the answers there have to match this page. Here is what we expect to declare, in their words:

  • Identifiers · Device or other IDs — the advertising identifier, only if you allow it, plus the install identifier and the push token if alerts ship. There is no User ID, because there are no accounts.
  • Usage Data · App activity — app interactions, meaning which screens are opened and how often, in aggregate.
  • Diagnostics · App info and performance — crash logs and performance data.
  • Contact Info — only the email address you type into the contact form yourself, and only if you type one. Leaving it empty is supported and normal.
  • Other Data · Other actions — the text of a message you send us through the form.
  • Location — declared as coarse at most, because an IP address implies a country. No permission for device location is requested.
  • Data used to track you — this is the one to watch. With ads on and the ATT prompt accepted, the advertising identifier is used by ad networks for ad selection and measurement, which is exactly what Apple counts as tracking. Decline the prompt and that stops.

Nothing else is collected and nothing else will be declared: no health or fitness data, no financial data, no contacts, no photos or videos, no audio, no files, no calendar, no messages, no search history from other apps, no browsing history.

Your rights over this data

If the GDPR applies to you, you have the right to ask what we hold about you, to have it corrected or deleted, to have its use restricted, to object to it, and to receive it in a portable form. You can also complain to your national data protection authority. Our legal basis is legitimate interest for server logs, aggregate analytics, and abuse prevention; consent for anything that depends on a prompt you accepted, such as tracking on iOS or push alerts.

If you are in California, the CCPA and CPRA give you the right to know, to delete, to correct, and to opt out of the “sale” or “sharing” of personal information, without being treated worse for asking. We do not sell personal information for money. Letting ad networks use the advertising identifier for targeted advertising can count as “sharing” under that law, and the opt-out is the one described above: decline the ATT prompt on iOS, delete the Advertising ID on Android.

The route for any of these is the contact form, since there is no account to log in to. Be honest with yourself about what we can actually find. We can find and delete a message you sent us through the form — say roughly when you sent it or what it was about. We cannot look you up in the analytics, because Metrica reports are aggregated on Yandex's side and there is no per-person record for us to export; the practical remedy there is the Metrica opt-out above. Server logs are not organised by person and are not archived for analysis, so there is no “your file” in them to hand over. If the apps are live and you ask us to stop sending alerts, we delete the token.

Children

The site and the apps are meant for people aged 16 and over. We do not knowingly collect personal data from children: there is no registration, nothing on the site is directed at children, and the apps will not be published in a children's category or use child-directed ad settings.

If you are a parent or guardian and you believe a child has sent us something through the contact form, write to us through the same form and describe the message. We will find it and delete it. We do not need to know who the child is to do that.

Where this data physically goes

Our own servers are rented from a hosting company, and they may be in a different country from you. Contact-form messages and server logs stay there.

Analytics is different and worth stating plainly: Yandex.Metrica processes what it collects on Yandex servers, outside the European Economic Area, under the Yandex privacy policy and not under an arrangement we negotiated. If you are in the EU or the UK, that is a transfer to a third country, and if you would rather it did not happen, the Metrica opt-out removes you from it entirely and the site keeps working. The same logic applies to the ad networks in the apps: they are separate companies, operating their own infrastructure in their own countries, and what they hold is governed by their policies rather than by ours.

Changes to this page

This page was last updated on 12 September 2026, and the date at the top moves whenever the text does. There is no mailing list to notify you with — that is the point of having no accounts — so changes are announced here and nowhere else. The day the apps ship, the future-tense sections above become present tense and name the SDKs that are actually in the build.

What you may and may not do with the site is a separate page: the terms of use.