Legal Document
Privacy Policy
Effective: July 1, 2026 · Last updated: June 28, 2026 · Version 1.0
Important — Biometric & Video Data
SwingAI processes body-pose video data, classified as sensitive personal data under LGPD (Brazil), GDPR (EU/EEA), and CCPA (California). Processing begins only after explicit, informed in-app consent. You may withdraw consent at any time.
1. Who We Are
SwingAI is operated by Marcio Meio (CPF: 071.591.707-96), an individual developer based in Rio de Janeiro, Brazil (we, us, or our). The product is distributed through the Apple App Store under the name SwingAI. Our backend service is hosted at api.swingaitennis.com. Contact us at hello@swingaitennis.com.
2. Scope
This policy applies to:
- The SwingAI iOS app
- The backend API at swingaitennis.com
- Any waitlist or marketing pages at swingaitennis.com
3. Data We Collect
3.1 Account & Identity Data
| Data | Purpose | Legal Basis |
|---|---|---|
| Email address | Account creation, login, receipts | Contract performance |
| Display name (optional) | Personalising in-app experience | Consent |
| Apple Sign In subject ID | Authentication | Contract performance |
| Skill level (self-reported) | Calibrating benchmark scores | Contract performance |
3.2 Video & Biometric-Derived Data (Sensitive)
When you upload or record a tennis video, the following data is processed:
| Data | Purpose | Retention |
|---|---|---|
| Raw video file (MP4/MOV) | Input to analysis pipeline | Deleted within 24 h of analysis completion |
| 2D pose keypoints (33 landmarks/frame) | Intermediate ML step | Never persisted — discarded in-process |
| 3D pose coordinates (17-joint skeleton/frame) | Biomechanical metric computation | Stored per session; deleted on account deletion |
| Biomechanical metrics (angles, velocities, scores) | Results display + progress tracking | Stored for account lifetime; deleted on account deletion |
| Annotated output video (skeleton overlay) | In-app review playback | Stored in Supabase Storage; deleted with session or account |
Under LGPD Art. 5(II), GDPR Art. 9, and equivalent laws, body-pose data derived from video is biometric data requiring heightened protection. We will not process your video until you provide explicit, affirmative consent inside the app.
3.3 AI Coaching Data
Biomechanical metrics (not your video or identity) are sent to Anthropic's Claude API to generate personalised coaching tips. No video, name, or email is shared with Anthropic. See anthropic.com/privacy for Anthropic's data handling practices.
3.4 Payment Data
All payment processing is handled by Apple StoreKit and RevenueCat. We never see, store, or have access to your credit card details. RevenueCat may store your Apple App Account Token and purchase history to manage subscription entitlement.
3.5 Usage & Diagnostic Data
| Data | Purpose |
|---|---|
| Job IDs, session IDs, status transitions | Job queue monitoring and error recovery |
| Error messages and stack traces (anonymised) | Bug fixing and service reliability |
| iOS device model, OS version | Compatibility and crash debugging |
We do not currently use third-party analytics SDKs that track you across apps.
4. How We Use Your Data
| Purpose | Legal Basis (LGPD) | Legal Basis (GDPR) |
|---|---|---|
| Creating and managing your account | Contract performance (Art. 7, V) | Art. 6(1)(b) |
| Processing video & generating analysis | Explicit consent (Art. 11, I) | Art. 9(2)(a) |
| Generating AI coaching tips | Contract performance (Art. 7, V) | Art. 6(1)(b) |
| Progress tracking over sessions | Contract performance (Art. 7, V) | Art. 6(1)(b) |
| Subscription management & billing | Contract performance (Art. 7, V) | Art. 6(1)(b) |
| Bug fixing & service reliability | Legitimate interests (Art. 7, IX) | Art. 6(1)(f) |
| Compliance with legal obligations | Legal obligation (Art. 7, II) | Art. 6(1)(c) |
We do NOT use your data to train AI models, sell to advertisers, build ad profiles, or share with data brokers.
5. Third-Party Data Processors
| Processor | Data Shared | Purpose | Location |
|---|---|---|---|
| Supabase | Account data, session results, output videos | Database & file storage | USA / EU |
| Anthropic | Structured metrics only (no video, no PII) | AI coaching text generation | USA |
| RevenueCat | Apple App Account Token, purchase history | Subscription entitlement | USA |
| Cloudflare | IP address, request metadata | Tunnel, DNS, DDoS protection | Global CDN |
| Apple | App usage, crash reports | App Store distribution | USA |
We do not sell, rent, or trade your personal data. International transfers to the USA are covered by Standard Contractual Clauses (EU SCCs 2021) and LGPD Resolution CD/ANPD No. 19.
6. Data Retention
| Data Category | Retention Period |
|---|---|
| Raw video files | Auto-deleted within 24 hours of analysis completion |
| 2D pose keypoints | Never persisted — discarded during processing |
| 3D pose coordinates & metrics | Account lifetime; deleted within 30 days of account deletion |
| Account data (email, name) | Until account deletion, then within 30 days |
| Payment records | As required by Brazilian tax law (~5 years) |
| Error & diagnostic logs | Auto-purged after 90 days |
7. Your Rights
| Access | Request a copy of all personal data we hold about you. |
| Correction | Request correction of inaccurate or incomplete data. |
| Deletion | Request deletion of your account and all data. Via Settings → Delete Account. |
| Withdraw Consent | Withdraw biometric processing consent at any time in Settings → Privacy. |
| Data Portability | Request your analysis results in structured JSON format. |
| Object | Object to processing based on legitimate interests. |
| Restriction | Request restriction of processing while a dispute is pending. |
| No Automated Decisions | Request human review of any solely automated decision affecting you. |
To exercise any right, email hello@swingaitennis.com with subject “Privacy Request”. We respond within 15 business days (LGPD) or 30 days (GDPR), whichever is shorter. Brazil complaints: ANPD at gov.br/anpd.
8. Children’s Privacy
SwingAI is not directed at children under 13. Users aged 13–17 require parental or guardian consent before any biometric data is processed. If we learn we have collected data from a child under 13 without verifiable consent, we delete it immediately. Contact hello@swingaitennis.com if you believe this has occurred.
9. Security
- All data in transit encrypted with TLS 1.2 or higher
- Supabase database and file storage encrypted at rest (AES-256)
- API keys stored in environment variables, never in source code
- Row-Level Security (RLS) on Supabase — you can only access your own data
- Cloudflare Tunnel — no public server ports exposed
In the event of a breach, we will notify you and the relevant authority within 72 hours (LGPD Resolution CD/ANPD No. 15 / GDPR Article 33).
10. Changes to This Policy
We will notify you of material changes via in-app notification and email at least 30 days before they take effect. If a change affects how we process biometric data, we will request your explicit consent again.
11. Contact
- Data Controller:
- Marcio Meio — SwingAI, Rio de Janeiro, Brazil
- Privacy requests:
- hello@swingaitennis.com
- Website:
- swingaitennis.com/privacy
- Response time:
- Within 15 business days