App Privacy Policy

This Privacy Policy explains how STREIQ collects, uses, stores, discloses, and protects personal data when you use the STREIQ mobile application, website, and related services.

In this Privacy Policy, "STREIQ," "we," "us," and "our" refer to the joint data controllers identified below.

1. Data controllers

STREIQ is operated by two joint controllers:

STREIQ is currently operated as a personal project by the two individuals named above. There is no separate company or Business ID.

Contact for all privacy and support matters — you may use either address, and either controller will respond:

Joint-controller arrangement. The two controllers jointly determine the purposes and means of processing described in this Privacy Policy. Between themselves they have agreed that either of them may receive and handle any request concerning your personal data, and that they are jointly responsible for meeting the obligations in this policy. Regardless of that internal arrangement, you may exercise your rights under the GDPR against either controller, and you may contact either address above for any matter. You may also contact the supervisory authority named in Section 17.

2. Scope of this Privacy Policy

This Privacy Policy applies when you:

Third-party services, including Apple, may process information independently under their own terms and privacy policies.

3. Summary of how STREIQ handles your swing videos

This section is a plain-language summary. The detail is in Sections 4, 8, 9 and 12.

Your swing video never leaves your phone. When you record a swing in STREIQ, or import one from your photo library, the video file stays on your device. It is not uploaded to STREIQ, to our cloud storage, or to anyone else. No video, no video frame, no still image and no audio is transmitted off your device at any point. The video is read only by the app itself, on your phone, for as long as you keep it there.

All swing analysis runs on your device. STREIQ uses machine-learning models, and inference is purely local: the models are bundled inside the app and run on your phone's own processor. Body-pose detection, 3D body reconstruction, club and club-head detection, swing-phase detection and impact detection all happen on-device. Nothing about this stage involves a server, a GPU cloud, or any third-party AI service.

Only compact numeric results are saved to your account. After your phone has finished analysing a swing, STREIQ saves a small JSON record of the result to your account so your history survives a reinstall or a new phone: joint positions per frame, joint angles, swing-phase markers, club-path coordinates, and the club label. This is measurement data, not imagery. It contains no pixels and no sound.

The swing-trace picture stays on your phone. The rendered swing-trace image — the still frame with the club path drawn on it — is generated on your device and stored only on your device. STREIQ does not save that image to the cloud, and it is not part of what syncs to your account. If you delete and reinstall the app, previously generated trace images are not restored, because we never had a copy.

Only text reaches the AI coach. Coaching text is generated by a third-party large-language-model API (Section 8). That service receives text only: numeric swing measurements, joint angles, phase markers, your typed messages, your display name, handicap, skill category and bio, and internal record identifiers. It never receives your video, any video frame, any image, any audio, your photo library, your email address, your IP address or your location.

Photo-library access does not upload your library. STREIQ never scans, indexes or uploads your photo library. Only the specific videos you pick in Apple's photo picker are imported — and those are not sent anywhere either. They are processed locally on the device, exactly like a swing you record in the app.

STREIQ does not offer cloud video storage. Because we never receive your videos, there is no cloud library of them to offer, delete or leak. If cloud video storage is ever introduced as an optional feature in future, this policy will be updated and you will be told before it applies to you.

4. Personal data we collect and process

The data we process depends on the features you use and the permissions you grant.

4.1 Account and authentication information

STREIQ accounts are provided by Supabase Auth. Two sign-in methods exist:

Through Supabase Auth we process:

Separately, in your profile record, we process what you enter yourself: display name, bio, handicap, skill category, gender, height, home course, preferred units, your club bag composition, and your recording-storage preference (Section 4.3). Your profile record also holds three short AI-written "coach comments" about your game (Section 4.4) and the timestamps and internal fingerprint used to decide when to regenerate them.

We use this to create and administer your account, authenticate you, recover and secure your account, associate your sessions and coaching history with your account, manage subscription access, communicate with you, respond to support requests, and prevent unauthorised access and misuse.

Your session token is stored on your device in the iOS Keychain.

4.2 Photo-library access

STREIQ touches your photo library in three distinct ways, with distinct permission models:

Importing a video for analysis — no library permission is requested. The "analyse from gallery" feature uses Apple's system photo picker, which runs outside the app in its own process. STREIQ never gains access to your library; it receives only the specific video files you select. No permission prompt appears, and STREIQ cannot see, list or read anything you did not pick. If a selected video lives in iCloud rather than on the device, iOS downloads the original so it can be imported. These videos are not sent anywhere — they are processed locally on the device, and the imported copy stays in the app.

Saving recordings to your photo library — full photo-library access is requested. This applies only if you turn on the optional "save recordings to my gallery" setting, which is off by default. When you turn it on, STREIQ requests full read-and-write photo-library access: write access to save recordings into an album (named STREIQ by default), read access to play a previously saved recording back inside the app and to restore an original into the app if a re-analysis needs it. STREIQ never reads, scans or indexes anything in your library other than assets it saved itself.

Downloading a single recording to your photo library — add-only access is requested. The per-shot "save video to my gallery" action asks only for permission to add to Photos, not to read your library.

Metadata. STREIQ does not read your photo library's location metadata — the "access media location" capability is explicitly disabled in the app's configuration. Because no video is uploaded, no file-level or camera-level metadata about a recording is transmitted either: file name, size, dimensions, frame rate, codec, exposure, ISO, lens position, white balance, zoom, stabilisation and lens-derived camera calibration are computed and used on your device only. A video you import from your library may itself contain metadata embedded by the device that originally recorded it; that metadata also stays on your device, because the file stays on your device.

What does reach your account for a shot is described in Section 4.5: the numeric analysis result, the club label, any launch-monitor values you typed in yourself, and — if you saved the recording to your gallery — a device-local reference to that photo-library asset (Section 4.11).

You can withdraw photo-library permission at any time in iOS Settings. Doing so may stop STREIQ saving new recordings to your gallery or playing back previously saved ones. It does not delete anything already processed.

4.3 Videos and data stored on your device

STREIQ stores data locally in these places:

Saving to your photo library is OFF by default. Recordings reach your library only if you explicitly enable that setting or explicitly download a shot.

Automatic deletion of the temporary app copy. When a recorded swing reaches a final state — analysis completed, or permanently failed — STREIQ deletes the app's temporary copy of that video from its Documents directory. If you enabled gallery saving, your copy in the photo library is untouched and remains entirely yours. If you did not, the original recording is gone at that point, by design. Videos you imported from your photo library are the exception: the imported copy is kept in the app so the shot stays playable, and your original in the photo library is never modified or deleted by STREIQ.

The analysis results generated on your device — the motion skeleton, the club-trace data and the swing-trace image — remain in the app's own storage until you delete the shot, delete the session, delete your account, or delete the app.

Device backups. STREIQ does not mark its Documents directory as excluded from backup. If you have iCloud Backup or encrypted local backups enabled, the app's local database, its analysis results, and any swing videos still present in its Documents directory are included in those backups. Those backups are governed by Apple's terms and privacy policy, not by this one.

You can delete local data at any time by deleting individual shots or sessions in the app, by deleting your account, or by deleting the app.

4.4 Data sent to the AI coach

STREIQ's AI coach, "Shimmy," is built on a third-party large-language-model API (the provider is named in Section 8). Text is sent to that provider in four situations:

Web search. The coach is offered a web-search tool that runs inside the provider's API, and it is enabled by default. If the coach uses it, a search query it composes from the conversation is processed by that provider's search integration. The coach is instructed to treat search as an absolute last resort, behind its knowledge base and your own data, and any links or citations are stripped before the reply reaches you.

What is never sent to the AI provider:

Internal record identifiers — session, shot and conversation UUIDs — appear in the text sent to the provider, because the coach uses them to look your data up. Your STREIQ user ID (a UUID) is also included in the result of the coach's profile lookup. These are random values that carry no meaning outside STREIQ's own database and are not linked to your email address or any other identifier at the provider.

Because no media of any kind exists off your device, the audio track of a recording never reaches the AI provider, and faces or bystanders visible in a recording are never exposed to it — or to us. See Section 19.

The coach does not identify itself as a third-party AI product inside the app, and is presented simply as Shimmy, STREIQ's coach. This Privacy Policy is where the underlying processor is disclosed to you, and Section 9.4 sets out what it does and does not receive.

4.5 Swing-analysis and movement data

From each swing video, the models running on your phone derive:

Of these, what is saved to your STREIQ account is the compact numeric result: the motion skeleton, the phase markers, the impact frame and time, the club-path coordinate data, and the derived per-position measurements, stored as JSON in the Supabase Postgres database and linked to your user ID. Alongside it we store the club label, any launch-monitor values you typed in yourself (ball speed, launch angle, spin, carry and similar), and the coaching texts generated from the above.

The rendered swing-trace image is NOT saved to your account. It exists only on the device that produced it.

Ball-flight metric fields exist on each shot record but, in the current release, are populated only from values you enter yourself — there is no automatic ball-flight measurement.

Analysis is performed on your device. STREIQ uses machine-learning models, and inference is purely local. The models are bundled into the app: Apple's Vision human-body-pose detection, a Core ML 3D pose-lifting model, and a Core ML club-head detector. There is no server-side analysis of your swings, and no third-party AI service is involved in producing the measurements. Audio impact detection also runs on your device, from the recorded file's own audio track.

This data is linked to your account and is retained until you delete the shot, delete the session, or delete your account (Section 12).

4.6 Camera, spatial and environment data

STREIQ uses your camera, and computer-vision models applied to it, to locate you and your club and to reconstruct your swing in three dimensions. This involves:

All of the above — including the 3D reconstruction — runs on your device. STREIQ does not use ARKit, LiDAR, hardware depth sensors, or your device's motion sensors. All spatial understanding is inferred from ordinary video frames by software running locally.

What leaves your device from this stage is only the numeric result described in Section 4.5. The video frames the reconstruction was derived from never leave your device.

STREIQ does not use body, face or movement data to recognise, identify or authenticate anyone. No facial recognition is performed at any point, and no biometric template is created or stored.

4.7 Coach messages, prompts, and responses

When you use the AI coach, we store in the Supabase database:

Conversations created by automatic features — per-shot feedback, session summaries and profile comments — are stored as hidden system threads that never appear in the app's chat list.

Voice is not supported. There are no voice transcripts and no spoken responses; the coach is text-only in this release, and STREIQ performs no speech recognition or voice synthesis.

You can delete conversations. Any chat thread can be deleted in the app, which permanently deletes that thread and all of its messages from the database.

Human review. STREIQ operates no tooling for routine human review of coach conversations, and we do not read them as a matter of course. As the operators we hold administrative database credentials and can technically access stored conversations; we do so only where necessary to investigate a specific fault, an abuse report, or a legal obligation.

4.8 Audio data

STREIQ requests microphone permission and records an audio track as part of every swing video.

4.9 Location

STREIQ collects location. When you start a new recording session, STREIQ requests foreground ("while using the app") location permission. If you grant it, STREIQ records where the session is taking place, so each practice session can be labelled with its location in your history.

We process:

Location is captured only once, at the start of a session. It is never collected continuously and never in the background. If you refuse permission, or the lookup fails, sessions simply have no location and everything else works normally.

Because the stored coordinates are full-resolution, STREIQ declares Precise Location, linked to your identity in its App Store privacy disclosure, which is the conservative classification.

Session location is never sent to the AI coach provider.

You can withdraw location permission at any time in iOS Settings. Locations already recorded remain on their sessions until you delete the session or your account.

4.10 Subscription and purchase information

STREIQ uses Apple's in-app purchase system with RevenueCat for subscription management.

The app sets your RevenueCat app-user ID to your STREIQ user ID, so purchases and entitlements map to your account. Purchases made anonymously before you sign in are merged into your account by RevenueCat's aliasing.

The app sets no RevenueCat customer attributes. It does not send your email address, display name, push token, advertising identifier or any attribution data. RevenueCat's own SDK collects the app and device information it needs to operate, under RevenueCat's privacy policy.

Through RevenueCat and Apple we process:

STREIQ's backend keeps an entitlements record with your tier, entitlement identifiers, product identifier, expiry, environment and last event, and a usage ledger recording the timestamp of each analysed shot so the weekly allowance can be enforced. Ledger entries are deliberately kept independent of the shots themselves, so deleting a shot does not return quota; they record only a shot identifier, your user ID and a timestamp.

STREIQ never receives your payment-card details. Payments are processed entirely by Apple.

We use this to validate subscriptions, provide paid features, restore purchases, manage trials and entitlements, prevent purchase fraud, answer subscription support requests, and keep legally required transaction records.

4.11 Device, technical, usage, and diagnostic data

STREIQ contains no analytics SDK, no crash-reporting SDK, and no advertising or attribution SDK. There is no Sentry, Firebase, Crashlytics, Google Analytics, PostHog, Amplitude, Mixpanel, AppsFlyer, Adjust or Branch integration, and no over-the-air update service that reports device information. Diagnostic messages the app writes go to the device console only and are never transmitted.

The technical information actually processed is:

The app does not register for push notifications and holds no push token. The practice-session Live Activity shown on the Lock Screen and Dynamic Island is updated entirely on your device and involves no server and no push service.

Device model, iOS version and app version are used on your device and are no longer transmitted with swing data, because swing videos and their metadata are not uploaded.

We use this to operate the application, diagnose technical problems, maintain availability, secure accounts and infrastructure, prevent fraud and abuse, and improve reliability.

4.12 Customer-support information

Support is handled by email at tuomas.haapasalo@aalto.fi and onni.peltola@aalto.fi. There is no in-app ticketing system, chat widget, or third-party helpdesk product.

These mailboxes are hosted on Microsoft 365, so Microsoft processes support correspondence as a service provider.

When you contact us we process your name, your email address, your account identifier if you supply it, the content of your request, any screenshots or files you attach, relevant device and app information, and our responses and support history.

We use this to respond to your request, investigate problems, protect accounts and improve support.

5. How we collect personal data

We collect personal data:

Access to your photo library does not mean STREIQ uploads or reads your library. Unselected photos and videos stay on your device, untouched — and selected ones stay on your device too.

6. Purposes of processing

Providing the STREIQ service. Creating accounts, authenticating users, analysing swings on your device, generating coaching feedback, maintaining your practice history, restoring your data after a reinstall, and enabling paid features.

Personalising coaching. Using your swing measurements, session history, profile and previous coaching context to make the coaching relevant to you specifically.

Managing subscriptions. Verifying entitlements, restoring purchases, enforcing the weekly shot allowance, resolving subscription issues.

Security and fraud prevention. Processing account, network, authentication, purchase and technical information to prevent misuse, secure accounts and investigate incidents.

Customer support. Answering questions and investigating reported issues.

Maintaining and improving STREIQ. Using technical and diagnostic information to improve reliability and performance, and using analysis output to diagnose faults in the analysis pipeline itself.

Model training — what we do and do not do. STREIQ does not train machine-learning models on your videos, your coach conversations, or your swing data. The models bundled in the app are pre-trained models that STREIQ deploys; they do not learn from your data. Because your videos never leave your device, they could not be used for training even in principle.

One narrow exception is disclosed for completeness. STREIQ supports a "data gathering" session type in which a user deliberately records swings alongside launch-monitor readings they type in themselves. Those sessions are flagged so STREIQ can compare its own computed results against the reference readings and check the accuracy of its analysis. This is measurement validation, not model training, and only sessions you explicitly start in that mode are ever marked.

If STREIQ ever intends to use identifiable user recordings or swing data to train or fine-tune its own models, this policy will be updated and a separate, optional consent will be obtained first.

Compliance and legal claims. Where necessary to comply with legal obligations, respond to lawful requests, keep accounting records, or establish, exercise or defend legal claims.

7. Legal bases for processing

Where the EU General Data Protection Regulation applies, we rely on the following.

Performance of a contract

Most of what STREIQ does with your data is necessary to deliver the service you asked for, and rests on this basis:

Because these activities are necessary to perform the contract, they are not offered as separately switchable options. If you do not want your swing measurements processed to produce coaching, do not submit swings for analysis — the recording, viewing and history features described in Section 8 remain available without it.

Consent

We rely on consent where the law requires it, specifically for access to protected resources on your device: camera, microphone, photo library and location. iOS asks you for each of these, and you can withdraw any of them at any time in iOS Settings. Withdrawing a permission disables the feature that depends on it but does not delete data already processed, and does not affect the lawfulness of processing carried out before withdrawal.

Legitimate interests

We rely on legitimate interests, having weighed them against your rights and interests, for:

You may object to processing based on legitimate interests — see Section 16.

Legal obligations

Tax, accounting, consumer-protection, regulatory and law-enforcement obligations.

8. AI coaching and the AI provider

STREIQ uses a third-party large-language-model API to generate coaching text. The active provider is OpenAI, and the model used is gpt-5.4-mini. STREIQ's backend is built so the provider can be switched by configuration; if the active provider changes, this policy will be updated to name the new one.

What is sent to the AI provider

Depending on the feature, a request may include:

Not sent: video, video frames, images, audio, your photo library, your email address, your password, your Apple identifier, your IP address, device identifiers, or your location.

What works without AI coaching

If you would rather not have swing measurements processed by our AI provider, the following features involve it in no way at all: recording swings, hands-free auto-capture, the on-device swing analysis itself, the 3D body-motion viewer and skeleton playback, the swing-trace image, session and shot history, statistics, dispersion and consistency views, club distances, saving recordings to your gallery, and subscription management. What you would not receive is the written swing overview, the per-position texts in the 3D viewer, session summaries, profile coach comments, and coach chat.

API configuration

STREIQ calls the provider through a developer API account, using an API key held server-side and injected into the backend at runtime. It does not automate a personal consumer chat account. The integration uses gpt-5.4-mini, a small, fast model chosen for conversational latency; STREIQ persists conversation history in its own database rather than relying on provider-side conversation state; the provider's built-in web-search tool is enabled, capped where the provider supports a cap and constrained by the system prompt as a last resort in all cases; and structured schema-constrained outputs are used for the automatic per-shot, session-summary and profile-comment calls.

Retention at the AI provider

STREIQ does not enable provider-side storage of conversations as persistent application state, so there is nothing stored there for STREIQ to list or delete later. Under OpenAI's standard API terms, API inputs and outputs may nonetheless be retained by OpenAI for a limited period — up to 30 days — for abuse and misuse monitoring, and then deleted, unless a longer period is required by law. Zero Data Retention and Modified Abuse Monitoring are not enabled on STREIQ's OpenAI project.

Model training

Our AI provider does not use content submitted through STREIQ's API account to train or improve its models. STREIQ uses the provider's API under commercial terms, and the account has not opted in to sharing API data for model improvement.

AI limitations

AI-generated coaching may be incomplete, inaccurate, or unsuitable for a particular golfer. Treat it as practice guidance — not a guaranteed assessment, and not medical, physiotherapeutic or injury advice.

STREIQ's AI systems are not used to make decisions producing legal, employment, credit, insurance, healthcare or similarly significant effects.

9. Service providers and recipients

9.1 Supabase

STREIQ uses Supabase Auth, Supabase Postgres and Supabase Realtime. It does not use Supabase Storage or Supabase Edge Functions.

Supabase processes:

No videos, video frames, thumbnails, extracted images, rendered swing-trace images or audio are stored in Supabase. No Supabase storage bucket is used by this application at all.

Realtime is used so the app learns of status changes immediately; it carries the same row data described above.

The Supabase project is hosted in Supabase's North EU (Ireland) region, within the European Economic Area, and is on the Free plan — which is relevant to log retention and backups, described in Sections 12.8 and 12.10.

9.2 RevenueCat

RevenueCat manages subscriptions, verifies App Store purchases, synchronises entitlements and controls access to paid features.

RevenueCat receives:

STREIQ sets no custom customer attributes. RevenueCat receives no email address, display name, push token, advertising identifier or attribution data from STREIQ, and no RevenueCat attribution integration is configured.

STREIQ's backend calls RevenueCat's REST API server-side to re-read a subscriber's current entitlements when a subscription event fires.

RevenueCat is established in the United States.

9.3 Google Cloud

STREIQ uses these Google Cloud products:

Google Cloud therefore receives account and record identifiers, the numeric analysis results as they pass through the backend API, legacy result files for older shots, and — through Cloud Run's request logging — IP addresses. It does not receive swing videos, video frames, images or audio.

The Cloud Run service and the Cloud Storage bucket are located in europe-north1 (Hamina, Finland), within the European Economic Area.

9.4 The AI provider

Our AI provider, OpenAI, processes the text described in Section 8 to generate coaching responses.

It receives no videos, video frames, images, audio, photo-library content, email addresses, IP addresses or location data.

STREIQ's contracting entity is OpenAI Ireland Ltd, and OpenAI's Data Processing Addendum applies to the account.

9.5 Apple

Apple processes information independently when you download STREIQ, use Sign in with Apple, make an in-app purchase, manage a subscription, or send diagnostics to Apple.

The Apple services this app uses are:

STREIQ does not use CloudKit, Apple's app analytics SDK, App Store attribution (AdServices), or App Tracking Transparency — the last because it performs no tracking.

STREIQ never receives your payment-card details from Apple.

9.6 Microsoft

Support correspondence is hosted on Microsoft 365 mailboxes. Microsoft processes the content of your support emails and their metadata as a service provider.

9.7 Legal and professional recipients

We may disclose information to legal advisers, accountants, insurers, courts, regulators, law-enforcement bodies or other competent authorities where reasonably necessary to comply with law, respond to a lawful request, investigate fraud or misuse, protect users or the service, or establish, exercise or defend legal claims.

9.8 Business transfers

If the business operating STREIQ is involved in a merger, acquisition, restructuring, financing or asset transfer, personal data may be disclosed as part of that transaction, subject to applicable legal safeguards.

10. Sale, advertising, and tracking

The released application contains no advertising SDK, no attribution SDK, no analytics SDK, no data-broker integration and no cross-app tracking technology. There is no Meta SDK, no Google Ads, no AppsFlyer, no Adjust, no Branch, and no Apple AdServices integration. No RevenueCat attribution integration is configured. The app requests no advertising identifier and never shows an App Tracking Transparency prompt, because it has nothing to ask permission for.

Data sent to our AI provider is used to produce the coaching you asked for, never for advertising.

11. International data transfers

STREIQ is operated from Finland. Most processing stays inside the European Economic Area: the Supabase project is hosted in Ireland, and the Google Cloud backend and storage bucket are in Finland. Your swing videos do not travel at all — they stay on your phone.

Some providers or their subprocessors may nonetheless process personal data outside the EEA:

Where personal data is transferred outside the EEA, the transfer is protected by an applicable legal mechanism — a European Commission adequacy decision, European Commission Standard Contractual Clauses, contractual data-protection obligations, supplementary technical and organisational measures, or another lawful mechanism. Data Processing Addendums are in place with our processors.

You can ask us for information about the safeguards applying to a specific transfer using the contact details in Section 1.

12. Data retention

We retain personal data only as long as necessary for the purposes in this Privacy Policy, including providing the service, maintaining security, resolving disputes and complying with legal obligations.

12.1 Account information

Account information is retained while your account exists. When you delete your account, your authentication record and the database records that depend on it are deleted (Section 15).

Residual copies — in server logs and any provider backups — are purged within 90 days, except where law requires a longer period.

12.2 Swing videos

Swing videos are never uploaded, so there is nothing to retain in the cloud and no cloud retention period to state. Videos exist only where Section 4.3 describes: in the app's own storage until the shot reaches a final state, in the app's storage indefinitely for videos you imported from your library, in your photo library if you chose to save them there, and in your device backups if you have them enabled. STREIQ does not control how long content remains in your photo library or in your device backups.

12.3 Swing measurements, session history and analysis results

The numeric analysis results saved to your account, session records including location, and coaching texts are retained until you delete the shot, delete the session, or delete your account. There is no automatic expiry.

The rendered swing-trace image and the local copies of the analysis files live on your device and are removed when you delete the shot, the session, your account, or the app.

Legacy result files in Google Cloud Storage, produced by the retired server-side pipeline, are deleted when the corresponding shot or session is deleted.

12.4 Coach conversations and AI outputs

Coach conversations, messages, tool results, summaries and generated texts are retained until you delete the conversation or your account. There is no automatic expiry. Per-turn telemetry — token counts, tool names, cue counts, latency, mode, model and error code, with no message content — and daily usage counters are retained on the same basis, for operational and budget purposes.

Text sent to the AI provider is subject to the retention described in Section 8: no persistent application state, and up to 30 days of abuse-monitoring retention.

12.5 Audio

Raw audio is not stored separately and is never uploaded. It exists only as the audio track inside a recorded video on your device, and is removed with that video as described in Section 4.3. There are no voice transcripts, because STREIQ performs no speech recognition.

12.6 Location

Session location — latitude, longitude and place name — is retained on the session record until you delete that session or your account. It is not stored separately anywhere else. Coordinates sent to Apple for reverse geocoding are subject to Apple's own retention.

12.7 Subscription and transaction records

Subscription and entitlement records held by STREIQ are retained while your account exists and are deleted with it. The weekly shot-usage ledger records a shot identifier, your user ID and a timestamp; ledger rows deliberately outlive the shots they refer to, so that deleting a shot does not return weekly quota, and are deleted when your account is deleted. RevenueCat and Apple retain their own transaction records under their own policies and legal obligations.

Where Finnish accounting law requires it, transaction records are retained for the statutory periods — generally six years from the end of the financial year for accounting material, and ten years for accounting books and the chart of accounts.

12.8 Technical, security and diagnostic logs

12.9 Customer-support communications

Support email is retained for 24 months after the issue is closed, unless a longer period is needed to defend a legal claim.

12.10 Backups

The Supabase project is on the Free plan, which does not include automated database backups; there is therefore no separate backup copy of the database beyond the live data. No object versioning, lifecycle retention or backup is configured on the Google Cloud Storage bucket, so deleted objects are not held in a backup copy.

In practice this means deletion is effectively immediate, with no backup-restoration window in which deleted data persists. If the project moves to a plan with automated backups, this section will be updated.

When information is no longer required, we delete or anonymise it, subject to legal obligations.

13. Security

We use technical and organisational measures intended to protect personal data against unauthorised access, disclosure, alteration, loss, misuse and destruction. The measures in place are:

No storage or transmission system is completely secure, and absolute security cannot be guaranteed.

14. Device permissions and your choices

STREIQ requests these iOS permissions:

Importing a video for analysis needs no permission — it uses Apple's out-of-process photo picker.

STREIQ does not request notification, contacts, calendar, health, or tracking permission.

You can manage every permission in iOS Settings. Disabling one disables the feature that depends on it.

Privacy controls inside the app:

A control that does not exist: there is no setting to disable AI processing of your swing measurements while continuing to receive coaching. As explained in Section 7, coaching is the service rather than an optional layer on top of it, so the two are not separable. If you do not want your swing measurements processed to produce coaching, do not submit swings for analysis; Section 8 lists what remains available.

15. Account and data deletion

Deleting individual items. You can delete an individual shot or an entire session from the app. Either action removes the local copy and its files, removes the database records, and deletes any legacy result files held in Google Cloud Storage for that item. If the remote deletion fails — because you are offline, for example — STREIQ records the deletion locally and retries on the next sync, so a deleted item can never reappear. You can delete an individual coach conversation from the coach screen, which permanently deletes that thread and all of its messages.

Deleting your account. In the app: My Profile → tap your profile card → Settings → "Delete my account", then confirm. You may also request deletion by email at either address in Section 1.

Deletion runs immediately. Your authentication record is deleted, and the records that depend on it are removed with it: your profile, sessions, shots, analysis results, entitlements, usage ledger, coach conversations, coach messages, coach usage and coach telemetry. The app then clears its local database and files and signs you out.

If the deletion request fails for any reason, nothing is deleted, the app tells you so plainly, and your data is left intact — you are never told your account is gone when it is not.

What survives deletion, and why:

16. Your data-protection rights

Subject to applicable law, you may:

To exercise any right, contact either controller at tuomas.haapasalo@aalto.fi or onni.peltola@aalto.fi. As joint controllers, Tuomas Haapasalo and Onni Peltola are both responsible for handling your request, and we will respond within one month, as the GDPR requires. If a request is complex we may extend that by up to two further months and will tell you why within the first month.

Access and portability. STREIQ does not currently have a self-service export button. On request we will produce a copy of your account, profile, session, shot, measurement and coaching data manually and supply it in a machine-readable format (JSON), within the same one-month deadline. Data that exists only on your device — your videos and the swing-trace images — is already in your possession and is not something we can export, because we do not hold it.

Correction. Much of your data is directly editable in the app: your profile, session titles, notes and locations, shot labels and club selections.

We may ask for information reasonably necessary to verify your identity before acting on a request, so that we do not disclose your data to someone else. These rights are not absolute; applicable law may permit or require us to refuse or limit a request, and we will explain our reasons if that happens.

17. Complaints

You may lodge a complaint with the data-protection authority in the country where you live, work, or believe an infringement occurred.

In Finland, the supervisory authority is:

We would appreciate the chance to resolve your concern first — contact either address in Section 1.

18. Children's privacy

STREIQ is not intended for anyone under 16, and the App Store age rating and availability are set accordingly. We do not knowingly collect personal data from a child under 16 without any consent or authorisation required by law.

STREIQ does not currently ask for a date of birth or operate an age gate; the minimum age is enforced through this policy and the App Store age rating.

If you believe a child has used STREIQ without appropriate authorisation, contact either address in Section 1. We will investigate and take appropriate action, including deletion where required.

19. Data relating to other people

A swing video may show other people in the background, and its audio track may capture their voices.

That video is never uploaded. It is analysed on your phone and stays there. Nobody at STREIQ sees it, no server processes it, and no AI provider receives it. Anyone captured in your recording is therefore never exposed to us or to any third party by STREIQ — the recording is yours alone, in the same way any other video on your phone is.

You should still avoid recording or importing content containing another identifiable person unless you have the right or permission to do so, and you remain responsible for what you choose to keep in your own photo library. Where possible, position the camera so only the intended golfer is in frame.

STREIQ provides no cropping, trimming, muting, blurring or redaction tools, and performs no automatic face detection or blurring. None is needed to protect a bystander from us, because we never receive the footage.

20. Changes to this Privacy Policy

We may update this Privacy Policy when STREIQ's functionality changes, our service providers change, our data-processing practices change, or legal requirements change.

The updated policy is published with a revised "Last updated" date at the address above. For minor changes, that revised date is the notice.

For material changes — a new category of data, a new purpose, a new recipient, or a change such as introducing cloud video storage or a change of AI provider — we will give you additional notice in the app or by email before the change takes effect, and will obtain fresh consent where the law requires it.

This Privacy Policy is linked from within the STREIQ app and from the STREIQ website.

21. Contact us

Questions, requests or complaints about this Privacy Policy or STREIQ's processing of personal data may be sent to either joint controller:

Website: https://www.streiq.golf