Skip to main content
Ridgewood YMCA Breakers Training

Privacy Policy

For the Breakers mobile app and Breakers Training website · Last updated August 26, 2026

What this covers

This policy covers the Ridgewood YMCA Breakers mobile app and the rybreakers.com website (together, “Breakers Training”). The operator is Ridgewood YMCA, 112 Oak Street, Ridgewood, NJ 07450, (201) 444-5600 ext. 319, swimteam@ridgewoodymca.org.

Registration, billing, meet commitments, and meet entries are handled by GoMotion / Team Unify under their own privacy policy. Breakers Training links to GoMotion but does not store those records.

Accounts

Coach and admin accounts: staff sign in with a name, email, and a password or one-time email code. New staff accounts must be approved by a team admin before they can see anything.

Parent accounts: parents sign in with an email and password. A parent account can see only the swimmers explicitly linked to that family — links are created by team staff or matched from the team's member directory, are auditable, and can be revoked.

Swimmers do not have email-based accounts. A claimed swimmer device receives an anonymous technical account with no email or password, scoped to one roster swimmer and revocable by the family. A device can also keep a local display name and practice group for training features.

What we collect

Roster and results: the team roster (names, practice groups) is managed by staff, and official meet results (published names, ages, teams, and times) are imported from public result files.

Practice feedback: if a swimmer chooses to submit feedback, we store the name they enter, their practice group, their ratings, and any comments. Feedback is visible to Breakers coaching staff only.

Training log: if a swimmer uses Train, their logged sessions, points, and badges are stored under their device profile.

Photos: optional swimmer headshots (taken by a coach, or self-uploaded and coach-approved) and photos a parent adds to their own swimmer's profile are stored in private storage and shown only to team staff and that swimmer's family through time-limited links. Heat sheets photographed by coaches on meet day are private to staff.

Attendance and coaching records: staff record attendance and development information; coaches' private notes are visible to staff only.

Safety and health records: staff may record an injury, body area, severity, return-to-swim status, and safety notes when needed to protect the swimmer.

Health data (Apple Health)

On iOS, with your permission, the app can import recent workouts from Apple Health — activity type, time, distance, stroke count, and active calories — into the swimmer's training log.

Heart-rate samples read during a practice session stay on the phone and are never uploaded to our servers.

Health data is never sold, never used for advertising, and never shared outside the team systems described below. You can revoke Health access at any time in iOS Settings.

Notifications and alerts

If you enable push notifications, we store a device token for system alerts. A token can be linked to your parent account (for meet sign-up alerts) or to the swimmer selected in My Journey (for personal-best alerts) so you only get alerts that concern your family. Coach announcements are private staff notes and are not delivered to families.

Meet-alert choices are optional. Email and iPhone notifications can be turned off independently. Text-message alerts appear only after the team enables them, and they require separate consent and a verified mobile number.

How long we keep it, and why

We keep personal information only as long as there is a reason to, and never indefinitely. Each category below states what we keep, why we need it, and for how long. A period is a ceiling, not a target — if a record's purpose is served sooner, it goes sooner. “Season” means the swim season the record was created in; the clock starts when that season ends.

Roster identity (name, practice group, team ID, headshot) — needed to run practices, attendance and meet entries. Kept while the swimmer is registered plus one full season, so a swimmer returning after a year off does not have to be re-entered. Then deleted or de-identified.

Photographs of swimmers — needed so coaches can identify athletes on deck and families can see their own swimmer. Kept while registered plus one season, and deleted straight away if a parent withdraws photo consent.

Attendance and participation records — needed for coaching decisions and for answering “was my swimmer at practice”. Kept three seasons, then reduced to anonymous totals.

Performance data (test sets, skills, rankings, lane assignments, practice feedback) — needed to track development across seasons. Kept three seasons, then the per-swimmer rows are deleted; the value is in the trend, which survives without names.

Training-log points, streaks and badges — needed only for the current season's motivation features. Kept the current season plus one, then deleted.

Injury and health records — needed for athlete safety and return-to-swim decisions. Kept the active season plus seven years, or until the swimmer turns 21 if that is later.

Parent and staff accounts — needed to control who can see a swimmer's information. Kept while the relationship is active plus one season, then deactivated and deleted.

Device setup codes and push tokens — needed to link a device and deliver alerts. Setup codes are purged within 24 hours of use or expiry; failed claim attempts are kept 90 days; a device link lasts only while the swimmer is registered; push tokens are deleted when a device is unlinked, signed out, or inactive for 12 months.

Database backups — needed for disaster recovery. Breakers uses a Supabase Pro project with daily database backups retained for seven days. Deleted database records can remain in those encrypted backups until that seven-day window expires. Storage photos are not included in those database backups and are removed from live storage when deleted.

The Ridgewood YMCA's own records schedule governs wherever it is stricter than the periods above.

What deletion does not reach

Published meet results. Official results — names, ages, teams and times — are a public competition record, published by meet hosts and by USA Swimming, and the team keeps them as its historical record. They are not removed by a deletion request. Everything else described above is.

Safeguarding records. Any report or investigation involving athlete safety is kept through the investigation and any claim, legal hold, limitation period, and insurer-required retention window. It is deleted only after the YMCA's designated safeguarding officer, counsel, and insurer confirm those obligations have ended. This period is not set by a coach or by an automated deletion job.

Access logs. When a family's information is viewed, we log that it was viewed. Those log entries are kept seven years and are never edited or deleted — deleting the record of an access would defeat the point of keeping it. When a swimmer's data is deleted, the log entry survives but no longer identifies them.

Backups. Deletion applies to live systems immediately; a deleted database record ages out of the seven-day backup window without being restored to the live service.

Children

Most Breakers swimmers are minors, and the app is built around that: swimmer features need no email address or named login, family access requires an approved, explicitly linked parent account, photos live in private staff-controlled storage, there are no ads, no public leaderboards for 12-and-under groups, and no in-app messaging of any kind.

Parents can review what the app holds about their swimmer through Parent Account and can ask us to correct or delete any of it at any time.

A parent or team staff member can issue a short-lived setup code that activates a roster-linked swimmer device, and the parent can revoke that device later. The team is confirming with the Ridgewood YMCA whether its registration consent covers the older, unlinked cloud training profile. Until that is confirmed or the profile is moved behind the setup-code flow, swimmers under 13 should not use optional cloud training, feedback, or self-photo features without their parent's direction.

A parent may also refuse any further collection about their child while the child keeps swimming. We will revoke the swimmer's device, delete their photos, and stop feedback and training-log collection, and the swimmer stays on the roster and at practice. Taking part in the team is never conditioned on agreeing to collection the team does not need to run practices and meets.

To make any request — see, correct, delete, or stop collection — contact the team at the address at the foot of this page. We will acknowledge within 5 business days and complete it within 30.

Where data lives

Data is stored with Supabase (database and private file storage, protected by row-level security), the website is hosted on Vercel, push notifications are delivered through Expo, emails are sent through Resend, and text messages (when enabled) are sent through Twilio. These providers process data on our behalf and do not use it for their own purposes.

We do not collect location, contacts, or advertising identifiers, we do not run ads or third-party analytics, and we never sell personal information.

Your choices

Notifications can be turned off in your phone's settings at any time, and email/text alerts each have their own switch in Parent Account.

To ask about, correct, or request deletion of any data — feedback, photos, training logs, or a whole account — contact the team; parents can make any request on behalf of their swimmer.

Questions or requests: swimteam@ridgewoodymca.org · see also Terms of Use and Support.