Data protection declaration for the app “DeepSwing”
Status:
We (Deep Platforms GmbH) are pleased about your interest in our AI-supported golf swing analysis app “DeepSwing”. Data protection and data economy are a high priority for us. This declaration transparently explains what data we process, what it is used for – and what not happens (no app tracking, no advertising SDKs).
1. Responsible person (Art. 4 No. 7 GDPR)
Deep Platforms GmbH
Eschenriederstr. 24, 82194 Gröbenzell, Germany
Managing Director: Blagovest Ouglechov, M.Sc. TUM
Registration court: Munich HRB 246874 • VAT ID: DE 322 408 001
Tel: 0179 / 4508754 • Email: bo@deep-platforms.com
Web: https://deep-platforms.com
2. Basic principles & Special features
- On-device processing: Video, pose & Angle analysis occurs locally on the device.
- Community optional: An account is required for the community area; Core functions can still be used without an account.
- Transparency: Community content is visible to other users; no hidden profiles.
- No app tracking SDKs: No advertising IDs, no fingerprinting in the app.
- Minimization: We only process data that is necessary for functions.
3. Categories of processed data
| Category | Description | Legal basis | Location | Storage period |
|---|---|---|---|---|
| Account‑ & Profile data | Name, handle, email, avatar URL, auth provider (Apple/Google/email), provider_sub, password hash (for email login), age confirmation (time stamp) | Art. 6 Paragraph 1 lit. b | Servers (EU) | Until account deletion |
| Community content | Videos, captions, overlay flag | Art. 6 Paragraph 1 lit. b | Servers (EU) | Automatically 14 days |
| Community interactions | Comments, replies, likes | Art. 6 Paragraph 1 lit. b | Servers (EU) | Until the post or account is deleted |
| Notifications | Inbox entries about likes, comments, replies | Art. 6 Paragraph 1 lit. b | Servers (EU) | Until the post or account is deleted |
| Support chat | Messages, category (question/feedback/bug), optional contact email, device ID, app version, timestamp | Art. 6 Paragraph 1 lit. b | Servers (EU) | As long as required for support |
| Reports/moderation | Reported content, reason, reporter ID, IP, user agent | Art. 6 Paragraph 1 lit. f/c | Server/Email | As long as necessary |
| Server log data | IP address, timestamp, request path, user agent | Art. 6 Paragraph 1 lit. f | Servers (EU) | In the short term for safety |
| Video‑ & Audio data (local) | Recorded/imported swing videos (optional sound) | Art. 6 Paragraph 1 lit. b + Consent to device release | Only locally on the device / if necessary iCloud backup of the user | Until user deletes / uninstalls app |
| Analysis data (local) | Calculated body points, angles, phase ratings, scores | Art. 6 Paragraph 1 lit. b | Local (App Sandbox) | Until deletion/uninstallation |
| Subscription status | Verified in-app purchase (Receipt / Boolean Status) | Art. 6 paragraph 1 letter b; Legal storage Apple: Art. 6 paragraph 1 lit. c | Local Flag; Original transaction data only for Apple | Status check ongoing; Apple saves according to its own deadlines |
| Crash/diagnosis data (optional) | Anonymous crash logs if iOS “Share app analytics” is active | Art. 6 Paragraph 1 lit. f – Opt-in at OS level | Apple infrastructure | Through Apple rotation cycles |
Note: In the community area, name/handle, avatar, videos, captions, comments and likes are visible to other users. Community uploads only happen when you actively share.
4. Purposes & Legal basis (Art. 6 GDPR)
- Providing core functions: Recording, analysis, visualization – Art. 6 Paragraph 1 lit. b.
- Community features: Account, uploads, feed, comments, likes, inbox – Art. 6 Paragraph 1 lit. b.
- Support & Troubleshooting: Support chat, answers, follow-up – Art. 6 Paragraph 1 lit. b.
- Moderation & Security: Prevention of misuse, reports, log data – Art. 6 Paragraph 1 lit. f / c.
- Subscription activation: Checking in-app purchases – Art. 6 paragraph 1 lit. b / c.
- Consent: System dialogs (camera / microphone / photo library) – Art. 6 Paragraph 1 lit. a.
Note on AI functions (EU AI Act): The app uses AI models to analyze swings on the device. This analysis is for informational purposes and does not replace professional advice. In the support chat, answers – if activated – can be generated automatically by AI. There will be no automated decision with legal or similarly significant effect. You can request human support at any time (see contact details below).
5. Community & Degree of publicity
When you publish content in the community, it is visible to other users. Please only upload content that you have the necessary rights to and that does not contain sensitive personal information. You can report posts or request early deletion.
6. Recipient/Distribution
- Hosting/Servers: Hetzner Online GmbH (Germany) – Operation of API, database and video storage.
- E-mail dispatch (messages): Lima‑City (Germany) – Shipped to info@deepswing.io.
- Support AI (optional): AI-powered support responses push support messages to the configured AI provider (e.g. OpenAI or Google Gemini) to generate a response.
- Apple/Google: At Social Login, Apple/Google are independent controllers.
Community content is displayed to other users in the community. Furthermore, we do not pass on any personal data to third parties.
7. Third country transfers
When using Apple/Google Login, data can be processed outside the EU. Google Analytics on the website may also contain third country transfers. These providers use their own protective mechanisms (e.g. standard contractual clauses). If Support AI is activated, processing can take place by the respective AI provider in third countries. We ourselves host community data in the EU.
8. Storage period & Deletion
- Community posts: Automatic deletion after 14 days including comments, likes, notifications.
- Account details: Until account deletion.
- Support conversations: As long as necessary for support and follow-up.
- Log data: Short-term storage for security.
- Local data: Remains until deleted by the user or uninstalled.
9. Delete account
You can delete your community account at any time in the app (Settings > Community Account > Delete account). In doing so, we remove account, posts, comments, likes and notifications. Technical backups may remain in place for a limited period of time. If you no longer have access to the app, you can also initiate deletion via our public request page: deepswing.io/delete-account.
10. Your rights (Art. 15–22 GDPR)
You have the rights to information, correction, deletion, restriction, data portability, objection and revocation of consent. You can request deletion via deepswing.io/delete-account or by email bo@deep-platforms.com put.
11. Objection according to Art. 21 GDPR
Processing is only minimally based on legitimate interests (security/moderation). You can object to the processing - we will then check whether there are compelling, legitimate reasons to the contrary.
12. Data security (Art. 32 GDPR)
- On-device processing, where possible.
- TLS encrypted transmission for community uploads & API accesses.
- Passwords are not stored in plain text (hash & Salt).
- Access and role restrictions on server systems.
13. Cookies & Web analytics (Google Analytics 4)
The DeepSwing app itself does not set cookies and does not integrate any external tracking SDKs. On our marketing website (https://deepswing.io/) we use Google Analytics 4 of Google Ireland Limited to obtain aggregated usage statistics and optimize content.
Data categories collected: pages/events accessed, browser & Device information (e.g. version, language), referrer URL, approximate location assignment (based on anonymized IP) and technical event data. We have activated IP anonymization, do not store user IDs and do not combine analytics data with app data or other profiles.
The legal basis is Art. 6 Paragraph 1 lit. f GDPR (legitimate interest in range measurement). You can object to this processing at any time - we provide a local opt-out function for this purpose. When activated, we set an opt-out flag (localStorage) in your browser, which means that future hits will no longer be sent to Google. Data that has already been transmitted remains unaffected by this setting.
Alternatively, you can use browser-side Do-Not-Track settings, ad blockers or the opt-out plugin offered by Google (tools.google.com/dlpage/gaoptout). Further information on data processing by Google can be found at policies.google.com/privacy and policies.google.com/technologies/partner-sites.
14. Minors
The community is intended for users aged 16 and over. If we learn of unauthorized use, we may suspend the account and remove content.
15. Changes to this Statement
If new features or regulatory changes occur, this statement will be updated. The current version is available at any time in the app / on this page. We mark significant changes within the app.
16. Contact & Right of appeal
Contact: info@deep-platforms.com • Tel: 0179 / 4508754.
Complaint: Competent data protection supervisory authority (e.g. Bavaria) or any other authority where you are located (Art. 77 GDPR). Overview: bfdi.bund.de.
17. Delimitation & Note
This declaration is based on the principle of maximum data economy. If additional cloud functions are introduced in the future, we will inform you separately before activation.