Privacy Policy
Last updated: September 2026
Data controller: H2N Ventures LLC · Florida, USA
Privacy contact (data protection channel): henrique@swimlytic.com
SwimLytic ("we", "us", "our", or "the App") is an AI-powered swimming technique analysis application developed by H2N Ventures LLC, a company registered in the State of Florida, United States. This Privacy Policy explains in detail what data we collect, what we deliberately do not collect, how we use, store, share, and protect personal data, and the rights you have over it.
This Policy is written for an international audience. It is designed to comply with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), the U.S. Children's Online Privacy Protection Act (COPPA), and the Brazilian General Data Protection Law (LGPD, Law No. 13,709/2018), which continues to apply to our users in Brazil.
1. The Core Promise: Your Video Never Leaves Your Phone
Before anything else, understand the single most important fact about how SwimLytic works:
- All video analysis runs 100% on your device. The artificial intelligence that reads your stroke executes locally, on your phone's own processor.
- Your video is NEVER uploaded. There is no video upload feature, no server that receives footage, and no code path through which video content could leave your device.
- We never capture, copy, or retain frames. Not a single image, frame, thumbnail, or clip from your video is transmitted, stored, or retained by SwimLytic: not temporarily, not "for processing", not at all.
- This is guaranteed by architecture, not by policy. It is not a promise we choose to keep; it is how the product is built. There is no server-side video pipeline to misuse, breach, or change quietly.
What leaves the analysis is only the result: numerical body landmark angles, the scores of the 8 technique metrics, the stroke style you selected, and your tier classification. Numbers and labels. Never images, never footage.
This point is repeated throughout this Policy because it is the foundation of everything else in it.
2. Data We Collect
2.1 Account and authentication data
- Email address: required; used for passwordless sign-in (magic link / one-time code) and account identification.
- Full name: only when provided by Sign in with Apple or Sign in with Google.
- Authentication provider identifier: the account ID issued by Google or Apple when you use their sign-in.
- We use passwordless authentication only. No password is ever created, transmitted, or stored.
2.2 Analysis results (the output of on-device processing)
For each analysis you run, we store only the derived output: the 8 metric scores, stroke style, tier, and report text.
- Scores of the 8 technique metrics: numerical scores for entry, catch, pull, recovery, rotation, kick, head position, and breathing.
- Stroke style: the stroke style you selected.
- Tier classification: your performance tier.
- Report text: the written report generated for your analysis.
These values describe swimming movement only. They contain no images and cannot be used to reconstruct video, identify a face, or recognize any person.
2.3 Anonymous technical data used to train and improve our models
The App sends anonymous, aggregate technical metrics from each analysis: metric scores, median body angle values, roll amplitude, processed frame counts, and the App version. We use this data to calibrate, train, and improve SwimLytic's analysis models, so scoring gets more accurate for every swimmer over time.
These metrics contain no personal identifiers whatsoever: no email, no name, no account ID, no device ID that identifies you, and, as always, no video content, frames, or images. The data is derived numbers only, and it cannot be traced back to you or reconstructed into footage.
2.4 Preferences
- Language preference (stored to display the App in your language).
2.5 Payment data (future paid plans)
When paid subscriptions launch, payments will be processed exclusively by the Apple App Store or Google Play, with subscription state managed by RevenueCat. SwimLytic never receives, sees, or stores your card number, billing credentials, or any payment instrument. We receive only subscription status (e.g., active, expired) via store receipts.
3. What We NEVER Collect
The following data is never collected, transmitted, or stored by SwimLytic, by architecture, not merely by policy:
- Video content or video frames: footage is analyzed on-device and never leaves your phone; no frame is ever captured or transmitted.
- Images or photos: we do not upload, copy, or retain any image from your device.
- Audio: no audio is recorded, extracted, or transmitted by the App's analysis.
- Precise location (GPS): the App does not request or use location data.
- Contacts: the App never reads or accesses your contact list.
- Behavioral advertising profiles: we do not build profiles for advertising and we do not use third-party advertising trackers in the App.
- Health data beyond swimming technique metrics: no heart rate, no medical information, no fitness records.
We do not sell personal data, we do not rent it, and we do not share it for marketing or advertising purposes. Under the CCPA/CPRA: we do not "sell" or "share" personal information as those terms are defined by that law.
4. Purposes and Legal Bases
| Data | Purpose | Legal basis (GDPR / LGPD) |
|---|---|---|
| Email, provider ID, name | Create and secure your account; sign-in | Contract performance (GDPR Art. 6(1)(b); LGPD Art. 7, V) |
| Analysis results | Deliver your technique history, scores, and progress | Contract performance (GDPR Art. 6(1)(b); LGPD Art. 7, V) |
| On-device video analysis | Generate the analysis you request | Your action/consent: you choose each video; processing never leaves your device (GDPR Art. 6(1)(a)/(b); LGPD Art. 7, I) |
| Anonymous technical metrics | Calibrate, train, and improve the analysis models | Legitimate interest (GDPR Art. 6(1)(f); LGPD Art. 7, IX); no personal data involved |
| Subscription status (future) | Provide paid features you purchased | Contract performance |
| Parental consent records (users 13 to 15) | Legal compliance for minors | Legal obligation (GDPR Art. 6(1)(c); LGPD Art. 14) |
5. Where Data Is Stored and How It Is Protected
- Account data and analysis results are stored with Supabase (our backend provider), on cloud infrastructure in the United States. All communication is encrypted in transit (HTTPS / TLS 1.2+), and data is encrypted at rest by the provider.
- Videos are not stored anywhere by SwimLytic. They exist only in your device's own camera roll or storage, under your control, exactly where they were before the analysis.
- Language preference is stored locally on your device.
- No passwords exist to be stolen: authentication uses one-time codes, magic links, or your Google/Apple account with secure tokens (JWT, with cryptographic nonce for Sign in with Apple).
International data transfers
Account data and analysis results are processed on servers in the United States. For users in the EU/UK, transfers rely on appropriate safeguards (including provider standard contractual clauses). For users in Brazil, transfers are made under LGPD Art. 33, with the controller ensuring the operator adopts adequate security measures, including encryption in transit and at rest.
6. Data Sharing (Processors / Service Providers)
We share personal data only with the service providers strictly necessary to run the service, acting as processors (GDPR) / operators (LGPD) under our instructions:
| Provider | Role | Data involved |
|---|---|---|
| Supabase Inc. | Authentication, database, backend | Email, provider ID, analysis results |
| Google LLC | Sign in with Google (only if you use it); Google Play billing (future) | Authentication data; purchase receipts |
| Apple Inc. | Sign in with Apple (only if you use it); App Store billing (future) | Authentication data; purchase receipts |
| RevenueCat, Inc. | Subscription management (future paid plans) | Store receipts and subscription status; never videos, never analysis data |
No provider on this list receives video content, because video content never exists on any server. We never share personal data with data brokers, advertisers, or any third party for marketing.
7. Data Retention by Data Type
| Data | Retained for |
|---|---|
| Video content | Zero retention. Never collected. Your video stays on your device, untouched |
| Account data (email, name, provider ID) | While your account is active; deleted within 30 days after account deletion |
| Analysis results (scores, tier, report text) | While your account is active; deleted with your account |
| Anonymous calibration metrics | Indefinitely; they contain no personal data and cannot be linked to you |
| Parental consent records (users 13 to 15) | While the account is active, as legal proof of consent; deleted with the account |
| Subscription status (future) | While your account is active; store receipts follow Apple/Google retention rules |
| Language preference | On your device until you change it or uninstall the App |
8. Your Rights
Wherever you live, you can exercise the following rights directly in the App (account deletion is built in) or by emailing henrique@swimlytic.com:
- Access: obtain a copy of the data we hold about you.
- Correction: fix incomplete or outdated data.
- Deletion: delete your account and all associated data directly in the App, at any time, no email required.
- Portability / export: request it at henrique@swimlytic.com and we will send your data in a structured, machine readable format within 15 business days.
- Withdraw consent: at any time, without affecting prior lawful processing.
- Information about sharing: know which providers process your data (see Section 6).
EU/UK (GDPR): you additionally have the rights to restriction of processing, objection, and to lodge a complaint with your local supervisory authority.
California (CCPA/CPRA): you have the rights to know, delete, correct, and opt out of sale/sharing, noting again that we do not sell or share personal information. We do not discriminate against you for exercising your rights.
Brazil (LGPD Art. 18): you have the full set of LGPD rights: confirmation of processing, access, correction, anonymization/blocking/deletion, portability, deletion of consent-based data, information about sharing, and revocation of consent. Complaints may be filed with the ANPD (https://www.gov.br/anpd).
We respond to rights requests within 15 business days.
9. Children and Teens
- Minimum age: 13. SwimLytic is not directed to children under 13, and we do not knowingly collect data from anyone under 13. This minimum age is aligned with COPPA requirements in the United States.
- Users aged 13 to 15: consent from at least one parent or legal guardian is required and is collected in-App during sign-up, including the guardian's email address (this also satisfies LGPD Art. 14 for Brazilian users). The guardian may revoke consent at any time through the privacy channel (henrique@swimlytic.com); revocation results in closure of the minor's account and deletion of their data.
- Users aged 16 to 17: may use the App under the supervision of a parent or legal guardian.
- If we learn that data was collected from a child under 13, or from a user aged 13 to 15 without valid guardian consent, we will delete it promptly.
It is worth repeating in this context: even for minors, no video is ever uploaded or retained. Analysis happens entirely on the device, and only numerical results are stored.
10. Website Cookies and Analytics
This section applies to the swimlytic.com website (not the App):
- The website may use Google Analytics 4 (GA4) to measure aggregate traffic (pages visited, approximate region, device type). GA4 uses cookies or similar identifiers for this purpose.
- You can opt out of Google Analytics at any time via the Google Analytics Opt-out Browser Add-on (https://tools.google.com/dlpage/gaoptout), by blocking cookies in your browser, or by using your browser's tracking protection.
- The website does not use advertising cookies or third-party ad trackers.
The App itself uses no cookies and no third-party analytics or tracking SDKs. The only telemetry the App sends is the anonymous calibration metrics described in Section 2.3, which contain no personal data.
11. Security
- All network communication uses HTTPS (TLS 1.2+); data is always encrypted in transit.
- Data at rest is encrypted by our backend provider.
- Authentication uses secure tokens (JWT), with cryptographic nonce for Sign in with Apple; no passwords are ever stored.
- The single largest security guarantee is architectural: your video cannot be breached from our servers, because it is never on our servers.
12. Changes to This Policy
We may update this Policy periodically. Significant changes will be communicated through the App and/or the website before taking effect. The "Last updated" date at the top always reflects the current version.
13. Contact
H2N Ventures LLC · Florida, USA
Privacy and data protection channel: henrique@swimlytic.com
For any question, request, complaint, or exercise of rights regarding this Policy, write to the address above with a subject line describing your request. We respond within 15 business days.
© 2026 SwimLytic · H2N Ventures LLC. All rights reserved.