Privacy Policy

Padero — Padel Scoring & Sessions

Last updated: July 26, 2026

The Short Version: Padero has no accounts, no server of ours, no analytics, no advertising and no tracking. Your players, matches and sessions live in the app on your device. With Pro, they also sync through your own private iCloud, which we cannot read. The one thing that deliberately leaves your device is a live session link, and only when you create one and send it to someone. We never receive any of it.

1. Information We Do Not Collect

Pixel Management does not collect any information from you through Padero. Specifically:

  • No account. Padero has no sign-up, no login, no email address and no user profile on any server. There is nothing to register and nothing for us to attach data to.
  • No usage analytics. We do not measure which screens you open, which formats you run, how many matches you score, or whether you open the app at all. There is no telemetry, anonymized or otherwise.
  • No advertising. Padero contains no ads and no advertising SDKs.
  • No device identifiers. We do not collect your device ID, advertising identifier, IP address, or any fingerprinting information.
  • No crash or diagnostic reports. Padero integrates no third-party crash-reporting service. No diagnostic data is sent from the app to us.
  • No location. Padero never asks for your location and contains no location code. The club name on a session is simply text you type.
  • No data sales, ever. We do not sell, rent or share your data with anyone. This is not a promise we have to police, it is a consequence of never receiving the data.

2. Data Stored on Your Device

Padero stores what you enter locally, inside the app's private sandbox on your device. Depending on what you use, that can include:

  • Players. The name, colour, optional photo, optional skill level and optional gender of each player you add, and whether they are a guest.
  • Matches. Date, format, teams, the point-by-point event log, the final score, duration and any notes you write.
  • Sessions. Date, the club name you type, format, rounds, court assignments, standings, sit-outs, and the rotation solver's state so a session can be resumed exactly.
  • Effort figures. If you use the Apple Watch app with Pro, the average heart rate and active energy for a match are stored alongside that match.
  • Settings. Which player is you, your appearance preference and your share-card defaults.

This data is readable only by Padero on your device. It is covered by your device passcode and iOS file protection, and it is included in your device or iCloud backup if you have backups turned on, exactly like the data of any other app you use.

A note about other people. Padel is a four-player game, so the roster you build contains other people's names and sometimes their photos. You entered that information and it stays under your control on your device. Please add other players considerately, and be aware that sharing a live session link (section 5) shows their names to whoever opens it.

3. Network Connections

Padero has no backend. There is no Pixel Management server for the app to talk to, and the app makes no requests to any domain we operate.

The only outbound connections Padero can make are to Apple's own platform services, and only in these cases:

  • iCloud (CloudKit) — only if you turn on Pro sync, to mirror your history between your own devices. See section 4.
  • iCloud (CloudKit) — when you host or follow a live session. See section 5.
  • App Store (StoreKit) — to show the price, complete a purchase, and check your entitlement. See section 10.
  • Links you tap. Opening a link such as this privacy policy hands off to your browser. Nothing about your data goes with it.

If you use Padero for free and never share a session live, the app makes no network connection at all. Scoring a match, running a club night and reading your stats all work fully offline.

4. iCloud Sync (Pro)

iCloud sync is a Pro feature and it is off by default. Until you turn it on in Settings under Data & Export, your history is stored only on that device and is never mirrored anywhere.

When you turn it on, Padero mirrors your players, matches and sessions into the private database of its iCloud container, under your own Apple Account, using Apple's CloudKit. That is what lets your iPhone and your other devices show the same history.

We cannot see or access this data. Pixel Management operates no server and has no way to read a private CloudKit database. Apple handles the storage and transport, and Apple's privacy policy governs how iCloud stores it.

If sync cannot start, for example because you are not signed in to iCloud, Padero tells you so on that screen and keeps working with your data safely on the device. Sync failing never costs you your history.

5. Live Sharing and Following

Padero can put a running session on a link so people who are not playing, or players waiting between rounds, can follow the standings on their own phone. This is the one feature that deliberately puts data outside your device, so it is worth being precise about it.

Nothing is shared until you tap Share Live on a session. When you do, Padero writes a compact live snapshot into your own private iCloud and asks Apple's CloudKit to produce a share link. That snapshot contains only what a scoreboard needs:

  • the session title, its format and which round it is on;
  • the standings: each participating player's display name, points, wins, losses and movement;
  • the current courts: which names are on which side, and the score;
  • who is sitting out this round.

It does not contain player photos, skill levels, gender, notes, match history, heart-rate data, or anything at all about your device or your identity.

The link is unlisted, but it is not password protected. Anyone who has it can open it and watch, read-only, without signing in to anything. Treat it like a link to an unlisted video: share it with the group it is meant for, and assume anyone it is forwarded to can also see the names and scores in it. Followers can only read. They can never write to your session or reach the rest of your data.

You end it whenever you want. Tapping Stop Sharing deletes the shared record from iCloud, and the link stops working for everyone who has it. Followers refresh through silent iCloud notifications that carry no content and never reach us.

As with sync, this runs entirely between you and Apple. Pixel Management operates no server in this path and never receives the snapshot, the link, or any record of who opened it.

6. Apple Health (Apple Watch)

Padero can record a match as a workout on Apple Watch. This is a Pro feature, it is entirely optional, and permission is requested the first time you actually start a watch workout, never at launch.

  • Reading. With your permission, Padero reads your heart rate and active energy while a match is being played, so it can show your effort and store an average against that match.
  • Writing. With your permission, Padero saves the match to Apple Health as a workout, so your padel shows up in your activity rings and your Health history.
  • Declining is normal. If you deny either permission, scoring continues exactly as before, simply without effort figures. Nothing is blocked.

Health data read from Apple Health is used only inside the app on your device. It is never sent to us, it is never included in a live share, and we never use Health data for advertising or marketing, which Apple's rules prohibit and we have no mechanism to do anyway.

7. Device Permissions

Padero asks for the minimum, and only when it is relevant:

  • Apple Health — optional, on Apple Watch only, for the workout described above.
  • Notifications — optional, on Apple Watch only, so it can tap your wrist when your court is up in a session. These are scheduled locally on the watch. There is no push server of ours, so no notification content ever passes through us. We never send marketing notifications.
  • Add to Photos — requested only if you tap Save image on a share card. This is add-only permission: it lets Padero put one image into your library and gives it no ability to read your photos.

Adding a photo to a player uses the standard iOS photo picker, which runs outside the app and hands Padero only the single image you choose. Padero never gets access to your photo library through it.

Padero requests no access to your location, camera, microphone, contacts or calendar.

8. Apple Watch, Widgets and Live Activities

If you use the Padero Watch app, the score and session state are exchanged directly between your iPhone and your paired Apple Watch using Apple's device-to-device WatchConnectivity. This never routes through a Pixel Management server.

Home Screen widgets and watch complications read a small read-only file that the app writes into its own app group container on your device. Live Activities show the running score on your Lock Screen and Dynamic Island. Both are rendered on your device from data already there, and nothing in either leaves the device.

9. Share Cards, Reports and Exports

Padero can render a share card for a result, and with Pro a PDF stats report or session report. All of them are generated entirely on your device, by the app, without any server involvement.

When you share one, iOS shows you the standard share sheet and you choose where it goes: a message, an email, a file, a print, your photo library. Pixel Management never receives a copy and has no visibility into where you send it. Bear in mind that a share card or report shows player names, so once you post one it is visible to whoever sees it.

10. Purchases

Padero is usable for free. Scoring matches, running Americano and Mexicano sessions up to eight players on one court, and your core stats all stay free. Padero Pro is a paid unlock that adds the remaining formats, larger and multi-court sessions, full analytics, Apple Watch session control with Health effort, iCloud sync and PDF export.

All purchases, restores and, where a subscription is offered, renewals and cancellations are handled by Apple through the App Store. Padero never sees your name, payment details or billing address. The app receives only Apple's signed confirmation that an entitlement is valid, which it verifies on-device to unlock Pro features. Apple's privacy policy applies to the transaction, and you manage a purchase in your Apple Account settings, not through us.

We keep no record of who purchased, because there is no account for us to attach a purchase to.

11. Third-Party Services

Padero integrates no third-party analytics, advertising, crash-reporting, attribution or tracking SDKs. There is no Firebase, no Sentry, no Mixpanel, no AdMob, no Facebook SDK and no equivalent of any of them in the app. The app is built entirely from Apple's own frameworks and our own code, with no external dependencies at all.

The only external services Padero relies on are Apple's own: CloudKit for optional Pro sync and live sharing, HealthKit if you enable it on the watch, the App Store for purchases, and local notifications. None of them receives an account identifier from us, because Padero has no accounts of its own.

12. Children's Privacy

Padero does not collect personal information from anyone, including children. Because no data is collected by us, the app complies with the Children's Online Privacy Protection Act (COPPA) and similar regulations by design. If you add a child to your roster, that name and photo stay on your device under your control, and appear in a live session link only if you choose to create one.

13. Data Deletion

Your data is yours, on your hardware and in your own iCloud, so you control all of it:

  • You can delete individual players, matches and sessions from inside the app.
  • Settings has a Delete All Data action that wipes every player, match, session and setting from the device, and also purges what was stored in iCloud if you ever used sync or live sharing. It tells you honestly if the iCloud part could not be reached, rather than claiming success.
  • You can remove all local data by deleting Padero from your device.
  • If you used Pro sync, you can also remove the synced copy in your device's Settings under your Apple Account, in the iCloud storage list for this app.
  • Workouts Padero saved to Apple Health are managed in the Health app, which lets you review and delete them independently of Padero.

There is no server-side copy for us to delete, and no request you need to send us, because nothing was ever sent to a server we operate.

14. Your Rights and International Users

Padero is made in the Netherlands and sold across the EU and beyond. Pixel Management is not a controller or processor of your Padero data, because we never receive or process it. Where you enable iCloud sync or host a live session, Apple acts as your storage provider under its own terms and privacy policy.

Rights such as access, correction, deletion, portability and objection are, in practice, exercised directly in the app: your data is already in your hands, editable and deletable by you, and exportable as PDF with Pro. There is no cross-border transfer by us, because there is no transfer by us at all.

Because your roster holds other people's names, you are the one deciding what is recorded about them and who sees it. If a fellow player asks you to remove them, you can delete them from your roster yourself, immediately, without involving us.

15. Changes to This Policy

If we update this privacy policy, we will post the revised version at this URL and update the “Last updated” date. Because Padero collects no contact information, we cannot notify you directly, so we recommend reviewing this page periodically. Any change that would affect how data leaves your device would be described here plainly before it ships.

16. Contact

If you have any questions about this privacy policy or Padero's data practices, you can contact us at padero@pixel.management.