Legal Document

Privacy Policy

Effective: July 1, 2026 · Last updated: June 28, 2026 · Version 1.0

Important — Biometric & Video Data

SwingAI processes body-pose video data, classified as sensitive personal data under LGPD (Brazil), GDPR (EU/EEA), and CCPA (California). Processing begins only after explicit, informed in-app consent. You may withdraw consent at any time.

1. Who We Are

SwingAI is operated by Marcio Meio (CPF: 071.591.707-96), an individual developer based in Rio de Janeiro, Brazil (we, us, or our). The product is distributed through the Apple App Store under the name SwingAI. Our backend service is hosted at api.swingaitennis.com. Contact us at hello@swingaitennis.com.

2. Scope

This policy applies to:

  • The SwingAI iOS app
  • The backend API at swingaitennis.com
  • Any waitlist or marketing pages at swingaitennis.com

3. Data We Collect

3.1 Account & Identity Data

DataPurposeLegal Basis
Email addressAccount creation, login, receiptsContract performance
Display name (optional)Personalising in-app experienceConsent
Apple Sign In subject IDAuthenticationContract performance
Skill level (self-reported)Calibrating benchmark scoresContract performance

3.2 Video & Biometric-Derived Data (Sensitive)

When you upload or record a tennis video, the following data is processed:

DataPurposeRetention
Raw video file (MP4/MOV)Input to analysis pipelineDeleted within 24 h of analysis completion
2D pose keypoints (33 landmarks/frame)Intermediate ML stepNever persisted — discarded in-process
3D pose coordinates (17-joint skeleton/frame)Biomechanical metric computationStored per session; deleted on account deletion
Biomechanical metrics (angles, velocities, scores)Results display + progress trackingStored for account lifetime; deleted on account deletion
Annotated output video (skeleton overlay)In-app review playbackStored in Supabase Storage; deleted with session or account

Under LGPD Art. 5(II), GDPR Art. 9, and equivalent laws, body-pose data derived from video is biometric data requiring heightened protection. We will not process your video until you provide explicit, affirmative consent inside the app.

3.3 AI Coaching Data

Biomechanical metrics (not your video or identity) are sent to Anthropic's Claude API to generate personalised coaching tips. No video, name, or email is shared with Anthropic. See anthropic.com/privacy for Anthropic's data handling practices.

3.4 Payment Data

All payment processing is handled by Apple StoreKit and RevenueCat. We never see, store, or have access to your credit card details. RevenueCat may store your Apple App Account Token and purchase history to manage subscription entitlement.

3.5 Usage & Diagnostic Data

DataPurpose
Job IDs, session IDs, status transitionsJob queue monitoring and error recovery
Error messages and stack traces (anonymised)Bug fixing and service reliability
iOS device model, OS versionCompatibility and crash debugging

We do not currently use third-party analytics SDKs that track you across apps.

4. How We Use Your Data

PurposeLegal Basis (LGPD)Legal Basis (GDPR)
Creating and managing your accountContract performance (Art. 7, V)Art. 6(1)(b)
Processing video & generating analysisExplicit consent (Art. 11, I)Art. 9(2)(a)
Generating AI coaching tipsContract performance (Art. 7, V)Art. 6(1)(b)
Progress tracking over sessionsContract performance (Art. 7, V)Art. 6(1)(b)
Subscription management & billingContract performance (Art. 7, V)Art. 6(1)(b)
Bug fixing & service reliabilityLegitimate interests (Art. 7, IX)Art. 6(1)(f)
Compliance with legal obligationsLegal obligation (Art. 7, II)Art. 6(1)(c)

We do NOT use your data to train AI models, sell to advertisers, build ad profiles, or share with data brokers.

5. Third-Party Data Processors

ProcessorData SharedPurposeLocation
SupabaseAccount data, session results, output videosDatabase & file storageUSA / EU
AnthropicStructured metrics only (no video, no PII)AI coaching text generationUSA
RevenueCatApple App Account Token, purchase historySubscription entitlementUSA
CloudflareIP address, request metadataTunnel, DNS, DDoS protectionGlobal CDN
AppleApp usage, crash reportsApp Store distributionUSA

We do not sell, rent, or trade your personal data. International transfers to the USA are covered by Standard Contractual Clauses (EU SCCs 2021) and LGPD Resolution CD/ANPD No. 19.

6. Data Retention

Data CategoryRetention Period
Raw video filesAuto-deleted within 24 hours of analysis completion
2D pose keypointsNever persisted — discarded during processing
3D pose coordinates & metricsAccount lifetime; deleted within 30 days of account deletion
Account data (email, name)Until account deletion, then within 30 days
Payment recordsAs required by Brazilian tax law (~5 years)
Error & diagnostic logsAuto-purged after 90 days

7. Your Rights

AccessRequest a copy of all personal data we hold about you.
CorrectionRequest correction of inaccurate or incomplete data.
DeletionRequest deletion of your account and all data. Via Settings → Delete Account.
Withdraw ConsentWithdraw biometric processing consent at any time in Settings → Privacy.
Data PortabilityRequest your analysis results in structured JSON format.
ObjectObject to processing based on legitimate interests.
RestrictionRequest restriction of processing while a dispute is pending.
No Automated DecisionsRequest human review of any solely automated decision affecting you.

To exercise any right, email hello@swingaitennis.com with subject “Privacy Request”. We respond within 15 business days (LGPD) or 30 days (GDPR), whichever is shorter. Brazil complaints: ANPD at gov.br/anpd.

8. Children’s Privacy

SwingAI is not directed at children under 13. Users aged 13–17 require parental or guardian consent before any biometric data is processed. If we learn we have collected data from a child under 13 without verifiable consent, we delete it immediately. Contact hello@swingaitennis.com if you believe this has occurred.

9. Security

  • All data in transit encrypted with TLS 1.2 or higher
  • Supabase database and file storage encrypted at rest (AES-256)
  • API keys stored in environment variables, never in source code
  • Row-Level Security (RLS) on Supabase — you can only access your own data
  • Cloudflare Tunnel — no public server ports exposed

In the event of a breach, we will notify you and the relevant authority within 72 hours (LGPD Resolution CD/ANPD No. 15 / GDPR Article 33).

10. Changes to This Policy

We will notify you of material changes via in-app notification and email at least 30 days before they take effect. If a change affects how we process biometric data, we will request your explicit consent again.

11. Contact

Data Controller:
Marcio Meio — SwingAI, Rio de Janeiro, Brazil
Privacy requests:
hello@swingaitennis.com
Website:
swingaitennis.com/privacy
Response time:
Within 15 business days