RallyCue: Tennis Scorekeeper Privacy Policy
Last Updated: September 27, 2026
Quick Summary
RallyCue is a standalone Wear OS tennis scorekeeper. Match state and the RallyCue Pro entitlement cache stay on the watch. Voice scoring is explicit and user-started: RallyCue prefers Android's on-device recognizer, but can use the default Android speech service with offline processing requested when the explicit on-device route is unavailable, so some provider processing may not be guaranteed on-device. Optional lifetime Pro is handled by Google Play Billing with no RallyCue backend.
App-Specific Details
Specific data handling practices for RallyCue: Tennis Scorekeeper.
- Stores authoritative active tennis match state, bounded Undo recovery state, preferences, and a small Pro ownership cache locally on the watch.
- Uses microphone access only for an explicit user-started, bounded voice-scoring request; RallyCue does not provide continuous or automatically restarted listening.
- Prefers Android's explicit on-device speech recognizer when available; otherwise it may use the watch's default Android recognition service with offline processing requested, which is not a guarantee that processing stays on-device.
- RallyCue does not persist raw microphone audio or recognized transcript text. Final recognition hypotheses are processed transiently for parsing; Android speech providers may process microphone audio and may use provider-managed networking to prepare an on-device language model when needed.
- Debug/validation diagnostics are bounded local files and are not automatically uploaded; non-debuggable production releases do not record the Gate 0 diagnostic files.
- Optional lifetime RallyCue Pro is purchased through Google Play Billing. RallyCue does not persist purchase tokens, order IDs, Google account identifiers, or purchase metadata in DataStore and has no developer-operated billing backend.
- RallyCue has no account system, cloud sync, ads, developer-operated analytics SDK, custom crash-reporting SDK, or developer speech backend.
- The app source does not request android.permission.INTERNET; Android speech providers and Google Play services operate outside RallyCue's custom network stack and may use provider-managed networking where needed.
- Android backup is disabled, cleartext application traffic is disabled, and the microphone foreground service is non-exported. Local data can be removed through app-data controls or uninstall, while a legitimate Play purchase can be restored.
Detailed Official Policy
Full technical and legal disclosure for RallyCue: Tennis Scorekeeper.
RallyCue Privacy Policy
Last updated: September 27, 2026
Canonical published location: <https://consultant.quinnfavo.com/privacy/rallycue>
This document reflects the current RallyCue source implementation and is the source of truth for the public privacy page above. The hosted copy must match this document before production release and must be re-audited against the final AAB, merged manifest, SDK set, Google Play disclosures, and physical-watch runtime speech behavior.
Summary
RallyCue is a standalone Wear OS tennis scorekeeper. Core match scoring remains local to the watch. Voice scoring uses Android platform speech-recognition services during an explicit, bounded Listen request.
RallyCue currently:
- does not require a RallyCue account;
- does not include advertising;
- does not include third-party analytics or crash-reporting SDKs;
- does not include a RallyCue billing/backend service;
- does not request app-level Internet permission;
- does not store raw microphone audio;
- processes final recognized text hypotheses transiently for parsing and scoring decisions, including up to two bounded lower-ranked alternatives when the top hypothesis does not parse;
- does not persist recognized transcript text or store arbitrary recognized transcript text in Gate 0 diagnostics;
- prefers Android's explicit on-device speech recognizer when it is available;
- may use the watch's default Android speech-recognition service when the explicit on-device API is unavailable or cannot be verified, with Android's offline-preference flag enabled;
- uses Google Play Billing for the optional lifetime RallyCue Pro purchase.
Android documents the offline-preference flag as a preference that a recognition-service implementation may ignore. RallyCue therefore does not claim that every default-service recognition session is guaranteed to remain on-device. The active speech provider is part of the Android/Wear OS platform environment and may perform network processing according to that provider's implementation and policies. RallyCue itself does not implement a speech-upload client or request `android.permission.INTERNET`.
Microphone and speech recognition
RallyCue requests microphone access only when the user chooses to use voice scoring and the requested mode is otherwise available/entitled. Microphone access supports a user-started, bounded listening request used to recognize a constrained tennis score phrase.
Recognizer routing is fail-aware:
- RallyCue prefers Android's explicit on-device recognizer when the runtime reports it available. This is the route RallyCue can identify as on-device-guaranteed.
- When that route is unavailable, RallyCue may use the watch's default Android recognition service with offline preference requested.
- If the default service reports that the required language is installed for on-device recognition, RallyCue records that stronger capability evidence.
- If Android cannot verify support, RallyCue can still use the default service as an unverified route. Offline processing is preferred but not guaranteed by RallyCue.
- Network/server recognizer failures demote the affected default-service route for the current process instead of repeatedly retrying it.
A successful default-service recognition result is not proof, by itself, that processing stayed on-device. Physical-device qualification must therefore verify the actual provider/route and network behavior on supported watches before production claims are finalized.
When Android returns a final recognition result, RallyCue can inspect the top hypothesis plus up to two bounded lower-ranked alternatives if the top hypothesis does not parse. These recognized text hypotheses are used transiently for parser/decision logic and are not persisted by RallyCue or written as arbitrary transcript text to Gate 0 diagnostics.
A RallyCue-owned timeout limits each listening request to a maximum of 15 seconds. The user can also stop listening explicitly.
If the selected Android recognition service reports that the required on-device language model is missing or available for download, RallyCue may ask that platform speech service to obtain the model. That request is provider-managed and may use the provider's own network/service infrastructure. The request carries recognition configuration such as the requested locale and RallyCue package identity, not match score state, recorded microphone audio, or a recognized transcript.
Raw microphone audio is not persisted or uploaded by RallyCue code. A platform speech-recognition provider may receive/process microphone audio as necessary to provide recognition, including possible network processing on routes that are not on-device-guaranteed.
Match data and local settings
RallyCue stores the active deterministic match score, bounded Undo recovery snapshots, and local app preferences/settings on the watch using Android DataStore. Match state is used to restore an active match after app recreation.
Current RallyCue source does not upload match score/history state or local preferences to a developer backend.
Local diagnostics
Debug and validation builds maintain bounded local diagnostic JSONL files to support recognition, lifecycle, battery, and scoring validation. Non-debuggable production releases do not record these Gate 0 diagnostic files. These records may include app-controlled decision categories, random local session/event identifiers, confidence buckets, timing values, device model/OS information, battery/thermal samples, recognizer route, and whether the selected route was on-device-guaranteed.
The diagnostic logger does not persist raw audio or arbitrary recognized transcript text. These files are not automatically uploaded by the current source.
The local diagnostic files are bounded to a current file of approximately 4 MiB plus at most one previous rotated archive.
Google Play Billing and RallyCue Pro
RallyCue offers an optional non-consumable lifetime Google Play purchase named RallyCue Pro. The product ID is `rallycue_pro_lifetime`.
RallyCue uses the Google Play Billing service to:
- display the localized Play price/purchase option;
- launch the Google Play purchase UI;
- query whether the current Play account owns RallyCue Pro;
- acknowledge a purchased, unacknowledged lifetime product.
A pending purchase does not unlock Pro.
Purchase tokens may be present transiently in Google Play Billing `Purchase` objects as required by the BillingClient API. RallyCue does not persist purchase tokens, order IDs, Google account identifiers, or purchase metadata in its local DataStore and does not send them to a RallyCue backend.
Local entitlement cache
The watch stores one local boolean indicating whether RallyCue Pro was last confirmed by a successful Google Play ownership query.
This cache exists only so a previously purchased user is not locked out by a temporary Play/service outage. A successful later Play query is authoritative and can remove cached entitlement after refund, revocation, or Play-account change.
Clearing app data removes this cache. A legitimate lifetime purchase can be restored from Google Play.
Service providers and third parties
Google Play
Google Play processes purchase/payment/transaction information to provide Google Play purchasing, entitlement, refund, and account services requested by the user. RallyCue interacts with that service through Google Play Billing Library 9.1.0.
RallyCue does not operate a separate purchase-verification server and does not send purchase tokens to Supabase or another RallyCue backend.
Android / Wear OS speech recognition
RallyCue delegates speech recognition to Android platform speech services. The explicit on-device recognizer route is preferred when available. Default-service routes are requested with offline preference, but RallyCue cannot guarantee that every provider honors that preference. The platform/provider may process technical information and microphone audio under its own implementation and policies.
Network behavior
Current RallyCue app source does not request `android.permission.INTERNET` and does not implement a custom speech or billing network client.
That app-level restriction does not prove that an Android system speech-recognition service in another process is offline. Default speech providers may have their own network capabilities. Production qualification must verify the actual provider/route behavior on each supported physical-watch family before making device-specific offline claims.
Android speech services may also use provider-managed networking to obtain an on-device language model after RallyCue explicitly asks the platform service to prepare a missing model for a user-requested voice feature.
Google Play Billing communicates through Google's Play billing infrastructure rather than a RallyCue-operated HTTPS endpoint.
Application cleartext traffic remains disabled.
Data deletion and privacy requests
RallyCue creates no developer-hosted user account and maintains no RallyCue billing database containing user purchase records.
Local RallyCue data can be removed through Android/Wear OS app-data controls or by uninstalling the app. Clearing app data removes active local state, preferences/settings, diagnostics, and the local entitlement cache subject to platform behavior.
Google Play transaction/account records are controlled by Google under Google's policies and developer-console transaction controls; clearing RallyCue app data does not delete Google Play order records.
For privacy questions, contact the developer using the address below.
Security
The app disables Android backup and cleartext network traffic. The microphone service is not exported to other apps. Match-state changes are persisted locally before RallyCue reports them as accepted.
Billing product identity is centralized in source. RallyCue grants Pro only for a matching Google Play `PURCHASED` result and never for `PENDING`. Purchased, unacknowledged non-consumables are acknowledged through BillingClient.
Children and sensitive use
RallyCue is a sport scorekeeping utility and is not designed to collect personal information from children. It does not make medical, health, or officiating claims.
Changes
If the production data flow changes, this policy and the Google Play Data Safety declaration must be updated before the changed behavior is released.
Contact
Public privacy policy: https://consultant.quinnfavo.com/privacy/rallycue
For privacy questions, contact Quazmoz@vivaldi.net.
General Privacy Terms
These terms apply across all our applications.
Questions or privacy requests? Contact us at Quazmoz@vivaldi.net