Matchbox — Privacy Policy

Rewritten 2026-09-07 (docs/product-review-2026-09-07.md §6: the 8/30 draft said "no accounts" the day after accounts shipped). This is the repo's canonical text; the App Store requires it hosted at a public URL (an owner ceremony — see docs/app-store-checklist.md). If any lane described below changes what it carries, this document changes FIRST — it is the contract the fleet's telemetry was designed against (the Health struct in internal/protocol/health.go cites it). Amended 2026-09-28 for the website and its waitlist, before either collected anything.

Matchbox is a wall-mounted LED display that shows live football as ambient decor, and the companion app of the same name. The short version: an optional account made of an email address and a password, no ads, no analytics, no tracking, no location. The app exists to carry your preferences to your Matchbox, to mirror what the Matchbox is showing, and to make sure only you can change it.

The account

You can create an account in the app (during setup, or later from the Matchbox tab) with an email address and a password. The account does one thing: it ties your Matchbox to you, so only phones signed in as you can change what the Matchbox shows, and a second phone signed in as you shares it. You can use the app without one — your settings then stay on your phone and the Matchbox plays on its own — and you can sign in later.

What we keep for an account:

We do not keep a name, a phone number, a postal address, a payment method, or anything about who you are beyond the email you chose.

Password recovery works two ways. Where the service can send email, a code goes to your address. Everywhere — and on day one — the Matchbox you own is the other proof: pairing reads a short code the Matchbox keeps, and that code (proof you are standing at the wall) resets the password of the account that owns it. No email is needed for that path.

Deleting the account is in the app (Matchbox → Account → Delete account, with your password). It removes the account, its sessions and its reset codes, releases every Matchbox it owned, and withdraws the settings the service held for those Matchboxes. The Matchbox itself keeps playing on the settings it already has until someone pairs it again; your email is free to reuse.

What the app touches, and why

Bluetooth, during setup. The app uses Bluetooth for one job: finding your Matchbox the first time and handing it your Wi-Fi network name and password so it can get online. That transfer goes directly from your phone to the Matchbox over Bluetooth; your Wi-Fi credentials are never sent to us or to any server. The same connection reads the Matchbox's pairing code (the proof of possession above). After setup the Matchbox is on its own and the app does not use Bluetooth again unless you re-pair. Bluetooth is never used to infer your location (the app declares this to the operating system).

Your display preferences. What you configure in the app — the club and teams you follow, which competitions play as ambience, display style, attention preset, brightness, spoiler delay, quiet hours, a pinned match, the matches you keep as great days, and your Matchbox's time zone (a rule such as EST5EDT,M3.2.0,M11.1.0, so the Matchbox's clock follows daylight saving) — is sent to our message service, stored there against your Matchbox's device identifier, and echoed back to any phone signed in as you. This is the app's entire purpose. It says what football you like and roughly which part of the world your clock is in; it carries no name and no address.

What the Matchbox reports. The Matchbox (not the phone) publishes two small operational records to the same service, keyed by the same device identifier:

Both records hold only the most recent value — the service keeps the last message per topic, not a history.

Software updates. The Matchbox checks for firmware updates through the same service and installs them itself, never during a match you follow. Updates are signed; the Matchbox refuses an unsigned image.

The football data, and the memory register

Match data flows to the app and the Matchbox from a licensed sports data provider. Our service records the raw feed for the matches it follows (scores, events, ball positions — data about football, not about you) and keeps a finished match's recording for a while so that, if you choose, your Matchbox can re-air your club's day in miniature that evening and on its anniversaries ("great days"). Which matches are kept longer is decided by what the Matchboxes following that club asked for; the recordings themselves contain nothing about any person.

The website and its waitlist

The Matchbox website (matchbox.staytethered.app) has no analytics, no advertising, no tracking pixels and no third-party scripts; its fonts and pictures come from our own server. It sets one cookie, lex, and only if you choose "football" or "soccer" yourself: it remembers that word and nothing else.

If you join the waitlist, we keep three things: your email address, the word the page used for the game, and when you joined — not your IP address, not your browser. We use the address for one thing: to email you when Matchbox can be ordered. It is stored on our own server (Amazon Web Services, in the United States), backed up nightly with the account records, and never shared, sold or added to anyone else's list. To be taken off it, write to the address under Contact and we will delete it and confirm. Joining twice changes nothing, and the form never says whether an address was already on it.

The server uses the address a request comes from, in memory and briefly, to limit how fast anyone can submit the form; it is not kept.

What we do not do

Identifiers, logs and retention

The Matchbox's device identifier is assigned to the hardware, not to you; an account links it to your email for as long as you own it, and unclaiming, deleting the account or a factory reset breaks the link. Retained messages are overwritten in place by the next message and are not archived.

Operational server logs are kept briefly for debugging. They contain the device-scoped records described above and, for the account service, the IP address a request came from — used only to limit how fast anyone can try passwords or claim Matchboxes, and never joined to anything else.

Account records are backed up nightly so a server failure does not lose your account; backups hold the same hashed data described above.

A factory reset on the Matchbox (hold both buttons through a power-on) forgets your Wi-Fi credentials, the phones it was paired with, its cached season and its pairing code, and rotates to a new code. Do that, and delete the account or unclaim the Matchbox in the app, before giving a Matchbox away.

Children

Matchbox is not directed at children and collects no personal data from anyone beyond the optional email addresses above. Do not create an account for a child.

Changes

If the app, the Matchbox or the service ever starts carrying more than what is listed here, this policy will say so before that version ships.

Contact

Questions about this policy, or about what we hold for your account: malik@staytethered.app. Ask for your account to be deleted there if you would rather not do it in the app, and we will confirm when it is done.