Privacy
Privacy Policy
Last updated August 12, 2026
This Privacy Policy describes how JM Photography LLC (“we,” “us,” or “our”) collects, uses, discloses, and protects information in connection with Lineup, our desktop application for youth sports photography businesses, including its optional Coordinator Portal, Parent Verification, and other relay features.
Lineup is a product of JM Photography LLC, which also operates The Picture Day Rig, a separate photography business at thepicturedayrig.com. That business has its own privacy policy for its own website and photography services. If you’re a family whose picture day was run by a business using Lineup, this is the policy that applies to you.
If you are a parent, guardian, league coordinator, or athlete interacting with a Lineup-operated relay link, this policy explains what happens to your information. If you are a photography business that purchases or uses Lineup, this policy also explains what we collect about you as our direct customer.
One important distinction that runs through this whole policy: Lineup is a locally installed application. For photography businesses using Lineup, most production data — athlete rosters, photos, local databases — stays on the business’s own computer and is never received by us. The business (the “Operator”) controls that data and is responsible, as the data controller, for its own notices and consents to the families it serves. Sections below are marked where this local-first design applies.
Information We Collect
- Account, license, and subscription information collected when you purchase or activate Lineup — name, business name, billing email, License Key, subscription and renewal status, purchase date, payment status, and a basic machine fingerprint used to enforce activation limits.
- Support communications you voluntarily send us — name, email, business name, License Key, issue description, and any files or screenshots you choose to share.
- Only if you connect Google: a Google refresh token, stored only in your Mac’s Keychain and never transmitted to or stored on our servers. See the Google API Services section below for full detail.
- Athlete and roster data — names, jersey numbers, team assignments, roster files, parent/guardian contact details, order and delivery records — which by default stays on the Operator’s own computer and is not received by us. A narrow slice of this data may transit our optional relay service if the Operator enables it; see Data Retention below for exactly what and for how long.
Google API Services Data Use Disclosure
Lineup optionally connects to a Google account, at the operator’s initiation, to draft email replies and deliver finished photos to the operator’s own Google Drive. This section discloses exactly what we access and why, in compliance with the Google API Services User Data Policy.
Scopes requested
drive.file
- What it’s for
- Uploading finished photo deliveries to a folder Lineup creates in the operator’s Drive (“Lineup Delivery”).
- What happens to the data
- Lineup can only see and write files it created itself — never the operator’s existing Drive contents. Files are uploaded directly from the operator’s device to the operator’s own Drive; we do not receive or store them.
gmail.send
- What it’s for
- Sending transactional emails (access codes, delivery notifications, roster reminders) from the operator’s own Gmail account, when the operator selects Gmail as their email provider in Settings.
- What happens to the data
- Sent directly from the operator’s Gmail account to the recipient; we do not receive or store the message content on our servers.
gmail.compose
- What it’s for
- Creating draft replies to parent emails in the Parent Inbox Responder feature.
- What happens to the data
- Drafts are created in the operator’s own Gmail account for the operator to review and send themselves; Lineup does not send on the operator’s behalf via this scope.
gmail.readonly
- What it’s for
- Reading parent emails so the Parent Inbox Responder can track conversation state and, if AI-assisted classification is enabled, suggest what an email is about.
- What happens to the data
- Read-only — Lineup never modifies, labels, archives, or deletes mail. See “AI-Assisted Features” below for the one case where message content leaves the operator’s device.
Storage. The Google authorization token is stored only in the operator’s macOS Keychain, on the operator’s own computer. It is never transmitted to or stored on our servers.
Sharing. Data obtained via these scopes generally flows only between the operator’s device and the operator’s own Google account, with one opt-in exception, described in full in the next section: if the operator turns on AI-assisted reply classification, the subject and body of unread parent emails are sent to Anthropic to classify intent. That is the only third party that ever receives Google-scoped data, and only for operators who opt in.
Revocation and deletion. Operators can revoke Lineup’s access at any time from their Google Account permissions (myaccount.google.com/permissions) or by disconnecting Google within Lineup’s Settings. Revoking access deletes the local token from Keychain; it does not delete anything from the operator’s own Gmail or Drive, since Lineup never held a separate copy of that data.
Compliance note. Lineup’s access to and use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Restricted scope.
gmail.readonly is classified by Google as a
restricted scope, not merely sensitive. Google’s published
guidance is that its annual CASA (Cloud Application Security Assessment) requirement applies to
applications that access restricted data “from or through a third-party server” —
which describes the AI-classification flow in the next section, for operators who enable it.
AI-Assisted Features (Anthropic)
If a Lineup operator chooses to enable AI-assisted features (Settings → AI Features, using the operator’s own Anthropic API key, stored in the operator’s macOS Keychain — never on our servers), Lineup sends limited data to Anthropic (anthropic.com) for three specific purposes. Every feature below is off unless the operator turns it on, and each is independently optional.
1. Parent Inbox Responder — reply classification. When
enabled, the subject and body of each unread parent email (read via the
gmail.readonly scope above) is sent to
Anthropic solely to classify what the message is likely about (for example, a schedule question vs.
an order question). Lineup never asks Anthropic to draft or send a reply through this feature, and
the classification never causes mail to be modified, labeled, archived, or deleted. If classification
fails or is disabled, the message is simply flagged for the operator to handle manually.
2. Zoe, the voice assistant. When the operator talks to Zoe, what they say (converted to text) and related job/roster information from the operator’s own Lineup database are sent to Anthropic so Zoe can respond and, only after the operator confirms out loud, carry out an action — such as sending an access-code email, sending a delivery notification, or sending a roster reminder, through whichever email provider the operator has configured. If the action involves a Google Drive delivery, a confirmation (such as a delivery link) may be included in what’s sent back to Anthropic as part of the conversation. Zoe cannot change a picture day’s date on its own — that always requires a manual, on-screen confirmation.
3. Field-corrections extraction. Free-text or transcribed correction notes the operator types or dictates (for example, “his jersey number is actually 23”) are sent to Anthropic to turn them into structured, operator-reviewable roster corrections. This feature only ever sees text the operator directly entered — it does not read Gmail or Google Drive data.
Model training. By default, Anthropic does not use API inputs or outputs to train its models. Lineup’s use of the Anthropic API does not opt in to any exception to this.
Retention. Anthropic automatically deletes API inputs and outputs within 30 days under standard operation. If content is flagged by Anthropic’s own automated trust-and-safety systems as violating its Usage Policy, that content may be retained longer — up to 2 years for the input/output itself, and up to 7 years for the safety classification score. We do not separately store the content of these requests on our servers beyond what is needed to display the result to the operator in the moment.
Payments
Payment for Lineup software purchases is handled by our Merchant of Record, Lemon Squeezy. Lemon Squeezy processes billing information necessary for your subscription and license — payment card information is processed by Lemon Squeezy and is not received or stored by us.
How We Use Information
- To provide your software license, subscription, and customer support.
- To provide the optional features described in the Google API Services and AI-Assisted Features sections above, only when you turn them on.
- To operate, secure, and improve the Software and its optional relay features.
- To communicate with you about your license, subscription, support requests, and material changes to this policy.
You choose your own transactional email provider for parent- and coordinator-facing mail — Gmail, Postmark, or Resend — in Settings. This determines which provider handles access-code emails, delivery notifications, and roster reminders on your behalf, as described in How Information Is Shared above.
You can contact us to update an email address on your own account or support communications with us.
Children And Athlete Information
Lineup is software used by youth sports photography businesses. Athlete information may be submitted by a parent, guardian, league, coach, or authorized organizer — or entered directly by the photography business using Lineup — so that the business can run picture day, identify galleries, fulfill orders, and support families.
The photography business using the software is the data controller for athlete, parent, and guardian information, and is responsible for the privacy notices, consents, and legal basis (including COPPA) for processing that information with the families it serves.
Our design and practices with respect to minors’ information follow these principles:
Local-first, by default. Athlete and roster data entered into Lineup stays on the operator’s own computer unless the operator turns on an optional relay feature.
Data minimization on the relay. Only the narrow contact/roster data needed to route a coordinator or parent submission ever transits our relay, and only when the operator enables it. Emails inviting parents to verify their child’s information contain no athlete details; athlete information is shown only within the secure relay portal behind a unique token-protected link.
Minimal retention on the relay. Relay data is deleted immediately on retrieval or pickup by the operator. Data that is never retrieved is excluded from active use once it expires, and is cleared by a daily automated deletion sweep; see the Data Retention table below for specifics by data type.
No profiling, no AI training. We do not analyze or profile athlete, parent, or guardian information beyond transiently transmitting it to the operator’s installation, and we do not use it to train AI or machine-learning models. (The AI-assisted features described above are about an operator’s own inbox, voice, and correction-entry content, not about analyzing athletes.)
No direct collection. We do not collect information directly from athletes, parents, or guardians.
Parents, guardians, and league organizers with questions about athlete information, opt-outs, corrections, or deletion requests should contact the photography business running their picture day, or reach us directly at support@lineupcentral.com.
Data Retention, Correction, And Deletion
| Information | Retention |
|---|---|
| License and subscription records | In accordance with Lemon Squeezy’s business and legal retention requirements |
| Google authorization token | Stored only in the operator’s macOS Keychain; never on our servers; removed on disconnect |
| Postmark / Resend API keys (if configured) | Stored only in the operator’s macOS Keychain; never on our servers |
| Coordinator roster files (relay) | Deleted immediately on retrieval; swept within 24 hours at most |
| Coordinator corrections (relay) | Deleted immediately on pickup; unretrieved corrections cleared by expiry sweep |
| Parent verification submissions (relay) | Deleted immediately upon pickup by the operator. Submissions that are never picked up are excluded from active use once expired, and are cleared by an automated deletion sweep that runs daily. |
| Fly.io encrypted backups (relay) | Up to 5 days, encrypted at rest with Linux LUKS, inaccessible without Fly.io’s cryptographic keys |
| Customer support communications | Three (3) years |
| Legal compliance records | As required by applicable law |
We have no ability to retain production databases, athlete information, photographs, or other data stored solely on an Operator’s computer.
To request correction, deletion, or a copy of information connected to you, email support@lineupcentral.com. Requests concerning athlete/parent data collected through Lineup should be directed to the photography business operating it, as the data controller.
Security
For Lineup and its optional relay, we use TLS encryption for data in transit, Keychain storage for tokens and API keys (never plaintext on our servers), AES-256 encryption at rest for the brief window a relay file is held pending retrieval, Linux LUKS encryption for Fly.io backup snapshots, non-root hardened container deployment, authenticated internal endpoints gated by an operator-held shared secret, and personal-information scrubbing from relay logs.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If you believe information has been exposed or used incorrectly, contact us promptly. Operators are responsible for protecting their own computers, backups, databases, passwords, and local storage.
Your Privacy Rights
Depending on your state of residence, you may have rights under state privacy laws, which may include the right to know, access, correct, delete, and obtain a portable copy of personal information, and to opt out of sale/sharing or targeted advertising (we do not sell, share for targeted advertising, or engage in such activities). These laws include, among others:
California’s Consumer Privacy Act (CCPA), as amended by the CPRA; Virginia’s Consumer Data Protection Act (VCDPA); Colorado’s Privacy Act (CPA); Connecticut’s Data Privacy Act (CTDPA); and Texas’s Data Privacy and Security Act (TDPSA).
To exercise any available right, contact support@lineupcentral.com. We will not discriminate against you for exercising your rights.
International Users
Lineup is operated from the United States. If you access our services from another country, your information may be transferred to and processed in the United States where permitted by applicable law. Because production data generally remains on the Operator’s own computer, international transfers by us are limited primarily to licensing, billing, and support information an Operator voluntarily provides.
Changes To This Policy
We may update this Policy from time to time. When we make material changes, we will update the “Last updated” date at the top of this page. Continued use after the effective date constitutes acceptance where permitted by applicable law.
Questions about this policy? Email support@lineupcentral.com.