SwingShadow

Privacy Policy

Effective September 8, 2026

SwingShadow ("the app") is a tennis swing analysis app by Matthew Lee ("we", "us"). This policy covers the Android version distributed through Google Play and the iOS version distributed through the App Store: what the app does with data, and the choices you have. The two versions behave the same except where a paragraph names one of them. Write to matthewlee0725@gmail.com with any questions.

The short version

Data processed on your device

On Android, the app asks the system for read-only access to each video you import. It does not copy, modify, move, or delete your video files; they stay where they are in your gallery or storage. On iOS, you pick a video with the system photo picker and the app keeps its own copy in the app's private storage; the original in your photo library is never modified or deleted, and deleting the video inside the app deletes the app's copy.

From the video, the app computes and stores the following in its private storage on your device:

This data stays on your device unless you share a clip (next section). Delete a video inside the app and the app deletes its analysis; uninstall the app (or, on Android, clear its data) and the system removes all of it. On iOS, the app's private storage is part of your device backup (iCloud or computer) like any other app's data.

Optional sharing of swing clips

Correct a misdetected swing and the app offers a checkbox: "Upload a video clip of this swing to help improve detection." The app uploads nothing unless you tick that box, and the tick covers that one swing only.

Tick it, and the app uploads the following over an encrypted (HTTPS) connection:

A shared clip is ordinary video: it may show you, and it may show other people on court. Share only clips you are comfortable sharing and have the right to share.

What shared clips are used for

We use shared clips for one purpose: improving SwingShadow's swing detection. We review them and use them as training and evaluation data for the detection models. We do not use them for advertising or profiling, do not publish them, and do not sell or pass them to anyone for their own use.

Where shared clips are stored

The app uploads to our API at api.swingshadow.app. Cloudflare, Inc. (Workers and R2 storage) hosts the data and processes it only on our behalf. Cloudflare operates a global network, so your uploads may pass through data centers outside your country. No one can read a stored clip from the internet: the storage has no public read access.

We keep standard server logs (request metadata, including the install identifier) for a limited period, for debugging and abuse prevention.

Retention and deletion

Uploads carry no identity, so we cannot match a clip to an email request. The in-app control is the way to delete your data, and it needs no proof of identity: only your installation holds its identifier.

Crash reports (Android only)

On Android, if the app stops unexpectedly, it sends us a crash report. It also counts each ordinary run as one session. The app sends these without asking you first, and they are on by default. Turn them off under Settings → Privacy → Send crash reports; from then on it sends neither, not even for a crash it already recorded.

The iOS version contains no crash reporter and sends us nothing when it stops unexpectedly. If you have chosen in iOS Settings to share diagnostics with app developers, Apple may pass anonymized crash logs to us under Apple's own privacy terms; that choice is Apple's setting, not the app's.

A crash report contains:

A crash report carries no imagery, no pose data, no file names, and nothing that identifies you.

Counting sessions

A session carries no content of its own. The app reports that a run happened and whether it ended in a crash, and nothing else: no timing, no screen you opened, no record of what you did. The count is what turns a pile of crash reports into a rate we can act on, and it is why the app sends something on a day it never crashes. One switch governs both.

Where crash reports go, and for how long

Firebase Crashlytics, a service of Google LLC, processes crash reports and session counts on our behalf and stores them on Google's infrastructure, which may be outside your country. Google states that Crashlytics keeps crash traces and their associated identifiers for 90 days before it begins removing them from live and backup systems. We read crash reports to diagnose and fix faults in the app. We do not sell them, we do not use them to advertise to you or profile you, and we pass them to no one for their own use.

A crash report carries no identity, so we cannot match one to an email request. The setting is the control: switch it off and your installation sends no more, and anything already sent ages out under the 90-day rule.

App permissions

Android

iOS

On either platform the app uses no camera, microphone, location, or contacts, and reads no files beyond the videos you pick.

Children

SwingShadow is not directed at children under 13, and we do not knowingly collect personal information from children. What the app does collect is described above, and it builds no profile of anyone, child or adult.

Changes to this policy

If we change this policy, we will post the new version at this address with a new effective date. For changes that affect what the app shares or how long we keep it, we will update the app's consent text before the change applies to new uploads.