Privacy Policy
Version: 2026-09-25-draft
⚠️ DRAFT — NOT LEGAL TEXT. This is placeholder structure. Final copy
will be authored by qualified legal counsel.
1. Data We Collect
- Account data: email, name, hashed password.
- Performance data (PRQ): self-reported or drill-derived fitness
- Game session data: mode, score, duration, win/loss.
- Coach chat inputs: messages sent to the AI coach.
- To operate and improve the Service.
- To compute your Player Readiness Quotient (PRQ).
- Coach chat inputs are processed by AI models to generate responses.
attributes (e.g. vertical jump, reaction time). Source and timestamp
are stored with every value.
2. How We Use Your Data
3. AI-Generated Content
The Coach and Studio features use AI models. Outputs are generated
guidance, not professional advice. See our AI Disclosure.
4. Data Retention & Deletion
You may export or delete your PRQ data at any time from your Profile
settings. Account deletion removes all personal data.
5. Health-Adjacent Data
PRQ attributes (e.g. vertical, balance, recovery) are fitness metrics.
We do not collect medical data. These values are stored with their source
and measurement date for full traceability.
6. Camera and Body Tracking
Some features use your camera: playing with your body as the controller, the Mirror, Prove It and face scan. The camera picture is processed on your device, in your browser. It never leaves your browser and is never stored. Face scan can also read a photo you choose; that photo is handled the same way.
When you play, only numbers worked out from the camera (for example jump height, rep counts or form reads) may be saved to your history. Face scan keeps only the face settings it picks, never the picture.
Before body play, a space check makes sure the camera can see all of you and the floor. It also checks how bright the picture is. Both happen on your device, and nothing from them is sent or saved. Your choice to play a game with your body is remembered on this device only. The small self-view of you is shown only on your screen.
The tracking model files are downloaded to your device when a camera feature first needs them, so the tracking can run there. The body-tracking files come from our own servers. Face scan's model file comes from Google's servers (storage.googleapis.com), and if our copy of the body-tracking files is ever missing they come from jsDelivr and Google instead. These downloads never include your picture.
7. Third Parties
We do not sell personal data. Payment processing (when enabled) uses
Stripe, governed by Stripe’s privacy policy.
8. Your Rights
You may request data export (JSON) or deletion via your Profile settings.
9. Changes
We may update this Policy. Material changes will be communicated in-app.