Privacy Policy
Effective September 5, 2026 · last updated September 5, 2026
The short version: analysis video is deleted as soon as it is analyzed, while photos and videos you deliberately post to Community stay for your club until the post is deleted. Current club members can view and download Community media, and a downloaded copy may remain after deletion. We don't sell your data, there are no ads inside PaddleLens, and we never train AI on your text, images or video. Section 3 separates analysis video, private Community media and the club's Google Drive photo drop.
- 1 ·Who is responsible for your data
- 2 ·What we collect
- 3 ·Video: three separate paths
- 4 ·Body-landmark data
- 5 ·Why we use your data
- 6 ·Who your data is shared with
- 7 ·How long we keep things
- 8 ·Children and guardians
- 9 ·Cookies
- 10 ·Security
- 11 ·Your rights
- 12 ·Where your data is
- 13 ·Changes to this policy
- 14 ·Contact
This policy explains what PaddleLens collects, why, who it goes to, how long we keep it, and how to get it removed. It applies to the PaddleLens website and app, operated by Get Skilled LLC, a Wyoming limited liability company (United States).
1. Who is responsible for your data
For account data and purchases made from us, Get Skilled LLC is the business responsible. For athlete data, analysis video, Community content, and whether a member owes a club-posted fee, your club is in the driver's seat — the coach decides who is on the roster and therefore who can access the feed, while each member decides what they post, comment on, react to and download. We process that information on the club's behalf. We separately decide the minimum connected-account, transaction, fraud and security, support, and application-fee records needed to operate Stripe Connect and meet our legal and accounting obligations. If you're a paddler, ask your coach first about your club's data; if you'd rather come straight to us, email info@paddlelens.com and we'll help.
2. What we collect
You give us
- Account data: name, email address, your role, and the club you belong to. If you use a PaddleLens password we store only its hash. If you choose Google sign-in, Google confirms a stable account identifier, verified email and display name; we keep the identifier to link the right account and discard Google's sign-in tokens. Google does not receive your phone number, birth date, club or athlete data from us.
- Your mobile number — only if you choose to give one. We send a one-time code to it and nothing else happens until you type that code back, so a number nobody proved they hold is never texted. What it is then used for is a closed list: session cancellations, urgent notices, coach-posted lineup notices and optional coded RSVP questions from your own club, and the verification code itself. Never marketing, never another club's messages, and never a link — nothing we text contains one, so a message that claims to be us and does is not. Reply STOP to any of them to end them, at any time, with no need to tell us anything. Leave the field empty and everything still reaches you by email.
- If you use RSVP by text: we store the six-character correlation code, the internal practice, club and account records it belongs to, the phone it was sent to, when it expires, whether delivery succeeded and whether it was answered. For an inbound reply we store Twilio's message ID, the phone, the short reply text, when it arrived, how it was handled and — only when it matched — the intended practice and account. The code, not the phone number, selects the practice.
- Your date of birth, at sign-up only. We ask for the whole date because it makes a better age check, we use it to confirm you are at least 13 — and then we store only the year. The day and month are never written down.
- A record that you accepted these documents: the date, and which version.
- Athlete data, entered by you or your coach: weight, height, paddling side, squad, trial results, discipline, and coach notes.
- A coach's notes and marks on your report. What a coach writes under a technique report, and what they draw on its analyzed frames, with a caption. They are kept beside the machine-written report, never mixed into it, and everyone who can open the report can read them.
- Video you upload for analysis.
- Photos and video you send to your club's photo drop, if your club has switched it on. These do not stay with us — they pass through to the club's Google Drive. Section 3 explains, and you are shown the same explanation before your first upload.
- Private Community activity: the posts and comments you write, your reactions, the photos and videos you attach, their safe file names and technical properties, and the club they were shared with. Current authorized members of that club can see them; section 6 explains who that includes.
- Other club activity: messages, announcements, practice RSVPs, crew and boat plans, and feedback you send us.
- If your club aims a session at one squad instead of the whole club: that a coach put you on the candidate list for it, whether you are Core or Reserve, what you answered and when, whether you were given a place and in which seat, and whether you were marked present or absent once the session ran — being left unmarked is not the same as being marked absent, and records nothing. If the answer was recorded for you — by a coach, or by an assistant your club granted that permission — we store that it was recorded rather than typed by you, who recorded it and when; your own answer replaces it whenever you say so. Every one of those changes is also written to a roster history of version numbers and status codes, carrying no names and no notes. Who sees any of it is your club's choice, not ours: coaches see the whole roster, an assistant coach only what their club has granted them, and section 6 gives the three settings a club picks between for what the other people asked can see — plus the separate setting for what members who were not asked see of the session on the calendar, which can be nothing at all, a reserved slot with no name or place, or its name, time and place. That last one shares that the session exists; it never shares who was asked or what anyone answered.
- Club-fee records, if your club uses Stripe Connect: the connected-account ID, country, currency and readiness status; the fee title, description, amount and due date; the payer's email and our internal club, fee and member IDs; Stripe's Checkout Session, PaymentIntent, Charge and application-fee references; and payment, refund and dispute amounts and status. Identity checks, full bank details and full card details are entered with Stripe and are not stored by us.
- What you write on the contact form, and how to reach you about it. The form is open to anyone, with or without an account: it takes your message, your email address so we can reply, and — only if you choose to give it — your name and phone number. The phone number is used to solve the thing you wrote about and nothing else. It is never used for marketing, never shared, and never added to any mailing list. Once we mark your message resolved, your name, email and phone are erased within 30 days; the message itself is kept, so we remember what was broken. Ask us at any time and we'll erase them sooner.
- Photos and files you attach to messages. These stay on our server and are deleted automatically 14 days after they were sent — the retention table in section 7 lists them, and the notice before your first upload says the same. Camera metadata (EXIF), including the GPS position your phone embeds in photos, is removed at upload and never stored.
- A screenshot you choose to attach to feedback. Optional, and only from inside the app. It is visible to us alone — never to your club, your coach or anyone else — and it is not emailed anywhere: the alert we get says a screenshot exists and we open it here. Camera metadata (EXIF) is removed at upload, exactly as for message attachments. It is erased when the contact details on that message are, and deleting your account deletes it even though the message itself stays.
We derive from your video
- Body-landmark measurements: the positions of up to 33 body points per frame, and the joint angles, stroke rate, timing and consistency computed from them.
- Scores against your coach's criteria, and an AI-written report.
- Up to about 60 small annotated still frames per analysis, showing the tracked skeleton over the paddler — these are photographs of a person.
We collect automatically
- Technical basics: IP address, browser and device type, and timestamps in server logs — used for security, abuse prevention and rate-limiting.
- Error and job diagnostics when an analysis fails.
- Only if you accept analytics cookies: Google Analytics receives normalized public acquisition pages plus successful signup and checkout-start; a signed-in account may carry GA's separate server-generated pseudonymous reserved User-ID, never its database ID, name or email. PostHog, on US servers, receives normalized private product screens and shape-only product moments such as an analysis completing, a report opening, an RSVP, lineup save or credit purchase landing. Its signed-in identity is a different server-generated pseudonymous code, never a database ID, name or email. Neither receives club or athlete content, messages, typed form content or raw record IDs. PostHog strips all queries and fragments; GA retains only shape-checked campaign tags on approved public landing pages. Autocapture, session replay and form-interaction capture are off.
- Only if you accept cookies, and only on our public pages: that a browser opened one of them, and whether the visit reached a step we're measuring such as opening the sign-up page — sent to the platform we bought an ad on, so we can tell whether the ad brought anyone here. Today that platform is Meta (Facebook and Instagram); if we add another it is named on this page and on the subprocessors page before it runs. It works on the marketing pages, the blog, and the sign-in and sign-up screens — never once you are inside the app, so no page carrying a report, a message, an athlete or a club is ever reported to it. Meta is an advertising company and will connect the visit to your Facebook or Instagram account if you have one; that is what accepting means, and section 9 is the detail.
- Only after ads consent, a newly created account and the server's adult check: Meta may receive anonymous CompleteRegistration, deduplicated between browser and server with one event ID. The browser copy naturally exposes its browser type; the server copy carries only that event ID, the validated request IP and Meta's own browser/ad-click IDs, and does not forward the raw User-Agent header — never name, email, phone, birth date, PaddleLens account ID, club or athlete data. There is no Meta Purchase event. Declining, never answering or being under 18 means no signup event.
We do not track where you are: there is no device location in PaddleLens, we never ask your browser for it, and GPS coordinates are stripped out of every photo you upload. Beyond the country/region estimate above, the only place we store is your club's training venue — a lake, a river or a town that a coach picks from a search box when scheduling, so the calendar can show the forecast for that session. It describes the water, not a person; it is the same for every member of the club; and the only thing it is ever used for is asking WeatherAPI.com what the weather will be. We do not collect your contacts. Advertising cookies are the one thing on this page that is genuinely new: the measurement tag above sets them, it is cross-site tracking by any honest definition, and it is why the cookie banner names Meta rather than hiding it under "analytics". It stays off unless you switch it on, it never runs on a signed-in screen, and section 9 tells you how to turn it back off.
3. Video: three separate paths
Analysis video is temporary
- You upload it. It is stored on our server only while it waits in the queue and while it is being analyzed.
- Pose tracking runs on our own server. The video file is not sent to any AI provider.
- When the analysis finishes, the video file is deleted — normally within minutes of the upload.
- If the analysis fails, or the video is never analyzed, it is deleted automatically within 24 hours.
- We do not keep an analysis-video library, we do not review analysis footage, and we do not use it to train models.
Community media is durable and private to your club
A photo or video attached to a Community post is stored on our server until the post is deleted. Only current authorized members of the selected club can open or download the live file; access is checked again on every request, so leaving or being removed from the club blocks it immediately. A downloaded copy is then on that member's device and cannot be recalled by deleting the post.
- We remove embedded camera and location metadata: photos are re-encoded, and videos are rewritten without embedded location, camera-comment and similar container metadata.
- We do not analyze Community media and never use its text, photos or videos to train a model.
- Unpublished uploads are erased within 24 hours. A deleted post is hidden immediately, remains recoverable for a nine-second Undo, and then has its live media permanently purged by an automated sweep no later than 24 hours. Section 7 gives the backup limit.
- Posting an identifiable minor requires their parent or guardian's permission for club sharing and member downloads. A guardian can ask the club or us to remove the live copy at any time.
The club photo drop is a third, separate path — and it works the other way round
Everything above is about analysis. A club can also switch on a photo drop: a coach or club manager connects their own Google Drive, and after that members can send photos and video — from practices, races, socials — through PaddleLens into a folder inside that person's Google account. It is a club album, not an analysis.
- The files pass through our server and are not kept by us. They are kept by the club, in that manager's Drive, for as long as the club leaves them there.
- The album is reachable by anyone who has its link — no account, no password. The folder is created that way on purpose: it is how a paddler with no Google account gets to see the club's photos. It also means the people who can see the album are the people holding the link, which is not the same set as the club's roster, and a link can be forwarded. Your club chooses who to give it to; we cannot know who has it.
- We cannot delete them, and neither can you. Only the owner of that Google account can — so a request goes to the coach who connected it. Deleting your PaddleLens account does not touch them. This is the one place where "ask us and it's gone" does not apply, which is exactly why it is spelled out here and again on screen before your first upload.
- Our access to that Drive is deliberately narrow: we hold a token scoped so it can only see and write the folder PaddleLens created for the club. We cannot read anything else in the manager's Drive, and we do not.
- Nobody is opted in silently. You are shown this before your first upload and have to accept it, and we record your answer — including a refusal — with the date and the Google account it named.
These are three different routes: analysis video is temporary on our server; Community media is durable on our server but restricted to current club members; and photo-drop media lives in the club manager's Google Drive and may be reachable by anyone holding its link. The screen where you upload identifies the route before you share.
4. Body-landmark data
To measure technique we compute the positions of body points — shoulders, elbows, hips, knees, and points on the head — through each stroke, and we keep the resulting numbers along with the annotated frames. We use this data only to produce your technique report, your progress history and your club's aggregates.
We do not use it to identify anyone, we do not run face recognition, we do not build a biometric template capable of identifying a person, and we do not sell, lease, trade or otherwise profit from it. Where the law treats this kind of measurement as biometric information, we treat it that way too: we collect it only after the paddler (or their guardian) has agreed through their club, we store it under the retention schedule in section 7, and we destroy it on request or once it is no longer needed for the purpose above.
The permission itself is held by your club, not by us: a coach confirms, at the moment they invite you, that they hold your written permission — or your parent or guardian's, if you are under 18 — covering being filmed and having the video analyzed automatically. We record that confirmation with the date and the coach who gave it. If you are not sure what your club has on file for you, ask them, and email info@paddlelens.com if you do not get an answer.
5. Why we use your data
| What we do | Data used | Why |
|---|---|---|
| Run your account and club | Account, role, club | To perform our agreement with you |
| Produce technique analyses | Video, athlete data, landmark measurements | You or your coach requested it |
| Build crews and boats | Athlete data, scores | You or your coach requested it |
| Host the private Community feed | Posts, comments, reactions, photos and videos | To perform our agreement with you and your club |
| Practices, messaging, announcements | Club activity | To perform our agreement with you |
| Run a session aimed at one squad rather than the whole club | Who your coach asked, whether you are Core or Reserve, what you answered and when, who ended up in the boat, who turned up, and the record of each of those changes | To perform our agreement with you and your club — a squad that is asked instead of the whole club is how a club fills a boat |
| Pass club photos through to the club's Google Drive | The photos and video you choose to send | You asked us to send them |
| Keep a record of what you were told and what you agreed to | Your answer to the photo notice, the Terms version you accepted, a coach's confirmation of permission, and — for an act that needed the current documents, such as publishing a targeted session — a one-way code in place of your name beside the two version numbers you had accepted | Our legitimate interest in being able to show what was asked and answered — and yours |
| Billing and receipts | Club/coach account and payment metadata | To perform our agreement, and tax law |
| Collect a club's own fees through its connected Stripe account | Connected-account status, club fee and transaction/refund/dispute records | To perform the club's request, keep its ledger accurate, secure the payment flow, and meet accounting obligations |
| Security, abuse prevention, rate limits | IP, logs, timestamps | Our legitimate interest in a working, safe service |
| Review reports of harmful or prohibited content | The reported post, comment, link or file and the surrounding context needed to assess it | Our legitimate interest in protecting members, enforcing the Terms and meeting legal duties |
| Support, bug fixing and analysis quality review | Whatever the problem touches; for quality review, the annotated frames and measurements of past analyses | Our legitimate interest in fixing what's broken and keeping the analyzer accurate |
| See which pages and features are worth keeping | Google Analytics: normalized public acquisition pages, signup and checkout-start. PostHog: normalized private product screens and shape-only product moments (record IDs removed first). For signed-in members, GA has its separate reserved User-ID and PostHog its distinct product identity, never a name | Your consent — and only your consent. Decline and none of this is collected |
| Measure whether the ads we buy on other platforms work | That a browser opened an eligible public page, plus the IP, browser type and Meta browser or ad-click ID it already holds. Only after advertising consent, a successful newly created adult account may also send anonymous CompleteRegistration with a random event ID. No name, email, phone, birth date, PaddleLens account ID or purchase is sent | Your consent — and only your consent. Decline and none of this is sent |
6. Who your data is shared with
People
- You: always, all of your own data — including your own place on any session roster, whatever else your club shows the rest of the squad.
- Your coach: your athlete profile, your reports and frames, your attendance, your session responses and your standing on any roster, messages sent to them or to shared groups, and Community content posted to their club. If your club is part of an organization, its owners can see the same.
- Your assistant coaches: the same list, narrowed to what your club has granted each of them — seeing squad rosters, taking roll call, picking reserves, placing someone in a boat, recording an answer for you and reading coaching notes are separate permissions a coach switches on one at a time. They are checked as each screen is drawn, not at the moment they were granted, so withdrawing one takes effect immediately rather than at the next sign-in.
- Your club's administrator: roster and club-level information for the clubs they manage.
- Other current members of the same club: never your reports. They can see what you post in shared groups and Community, including your name, comments, reactions, photos and videos. They may download Community media; leaving or removal blocks future access but cannot recall an earlier download. What they see of a session roster is your club's choice, and it is described just below.
- Get Skilled LLC staff (currently, one person): operational access to accounts, usage and billing needed to run and support the platform, technical access to stored data when diagnosing a problem, and review of the annotated analysis frames and their measurements to check the analyzer is measuring correctly.
Session rosters, and what "attendance" does and does not mean
A session can be aimed at one squad rather than the whole club. The people asked are the candidates: some are Core, whose place is held for them, and the rest are Reserve, who can be picked when a place opens. Your club chooses one of three settings for what a candidate sees of everybody else, and the choice in force when a session is published is the one that governs it:
- Your own place only. You see what you were asked, what you answered and whether you are in the boat. You see nobody else.
- The confirmed line-up, by name. You also see who is in the boat and in which seat — the people who will be on the water beside you.
- Everyone who was asked. You also see the full candidate list with each person's Core or Reserve standing and the seats they can take.
Companies (processors and payment providers)
| Provider | What it receives | Purpose |
|---|---|---|
| Anthropic (Claude API) — United States | Text only, never video and never images. For a technique report: the measurements and scores, the paddler's first name, and the coach's notes. For a crew plan: each selected athlete's name, height, weight, paddling side, trial results, scores and coach notes — the model needs them to seat a boat. Coach notes are free text and may mention an injury, so treat them as you would any note about a person. | Writing the report and the crew plan |
| Stripe — United States | Name and email; connected-club identity, business and bank details; and the payment details entered directly with Stripe | PaddleLens purchases, connected-club onboarding, direct club-fee payments, payouts, refunds, disputes, fraud prevention and legal identity checks — we never see full card or bank numbers or Stripe identity documents |
| Hetzner Online GmbH — Germany | Everything, as it passes through the server it hosts. What stays stored there: uploaded video while it is analyzed, annotated frames, Community media, and the encrypted local backup archives | Running the servers (see section 12) |
| Supabase, Inc. — database resident in Frankfurt, Germany; Supabase is a US company | The primary database: accounts, athlete data, measurements, reports, Community text and the app's operational records. The records themselves — never video, media files or annotated frames, which stay on the Hetzner server | Managed hosting of the primary PostgreSQL database (see section 12) |
| Brevo (Sendinblue) — France | Your email address and the message | Invites, receipts, password resets and service notices |
| Google Identity Services — United States and elsewhere | Only if you choose Google sign-in: a stable Google account identifier and the verified email and display name Google returns, plus the ordinary network and device information Google sees while you sign in. No PaddleLens password, phone number, birth date, club or athlete data. We do not keep a Google access or refresh token. | Authenticating you and linking that Google account to the correct PaddleLens account |
| Twilio Inc. — United States — only if you gave us a mobile number | Your mobile number and the text of one of the six short templates described on our Text messages page — plus the one-time code, generated at Twilio, that confirms the number is yours. An RSVP prompt contains a club name, session label, date, time and six-character code. If you reply, Twilio receives the reply text, time and provider message ID and passes them to us. Twilio and the phone companies also learn that a message was delivered and when. No athlete-performance data is in a text: never a report, score, measurement or image, and never a link. | Sending the texts you asked for, receiving coded RSVP replies, and verifying the number |
| Google (Drive) — only if your club switched on the club photo drop | The photos and video you send to the club album, and the file name they are saved under, which carries the first name of whoever uploaded them and the date. They are written into a folder in your club manager's own Google account, and they stay there — see section 3. | Storing the club's photo album, in the club's own Drive |
| Your browser's push service — only if you turn notifications on. Run by the maker of your browser: Google, Mozilla, Apple or Microsoft | An encrypted notification payload it cannot read — the message is enciphered to keys held only by your browser — and the delivery address your browser assigned to itself. We do not choose this company; your browser does, and turning notifications off in PaddleLens deletes the address. | Delivering the notifications you asked for to your device |
| WeatherAPI.com — United Kingdom | The coordinates of your club's training venue, if a coach has set one, and the date. Nothing that identifies a person: not your name, not your email, not that you are going. It answers with a forecast, which we keep for a few hours and then throw away. | Showing the weather for a scheduled session |
| Google (Analytics 4) — only if you accept analytics cookies | Normalized public acquisition pages plus successful signup and checkout-start events, a browser ID, device/browser type and approximate region. A signed-in account may carry GA's separate server-generated pseudonymous reserved User-ID — never the database ID, name or email. Google never receives product-feature events, athlete data, reports or images. | Counting public acquisition |
| PostHog — US cloud, data stored in the United States — only if you accept analytics cookies | Private product pages and shape-only product moments — every address is rewritten first, so record ids become placeholders and the query string never leaves your browser — plus a local visitor ID and device/browser type. If you are signed in, PostHog uses its own server-generated pseudonymous code, different from both the database ID and GA User-ID. It never receives your name, email, or anything you film, type or message. Session replay, autocapture, surveys and remote configuration are off, and PostHog discards IP addresses at ingestion. | Understanding which features get used and where people get stuck, so we improve the right things |
| Our advertising and measurement partners — today that is Meta Platforms (Facebook, Instagram), and the subprocessors page always names the current ones. Only if you accept cookies, and only on public pages | That a browser opened an eligible public page, plus IP, browser type and Meta browser/ad-click IDs. Only after ads consent and the server's adult check, a newly created account may send anonymous `CompleteRegistration` with a shared event ID; the server copy contains validated IP and Meta browser/ad-click IDs, but no raw User-Agent header. No name, email, phone, birth date, PaddleLens account ID, purchase, athlete data, reports or images goes. We never report a private app page. Meta may match the visit to your Facebook or Instagram account and uses what it collects for its own advertising purposes, which is why this row is not simply acting on our instructions. | Measuring whether the ads we pay for on other platforms bring anyone here |
Most service providers above act on our instructions. Stripe also acts under its own payment, fraud-prevention, identity-verification and regulatory duties, as its terms and privacy policy explain. The advertising row is different, and the difference has a name. For what the measurement tag collects and sends, we and Meta Platforms Ireland Limited are joint controllers under Article 26 of the GDPR. That is not our characterisation — it is Meta's, set out in the Controller Addendum that forms part of Meta's Business Tools Terms, and it is the arrangement that decides which of us answers for what.
Who answers for what, in plain terms
- Us, for putting it there. Asking your permission first, having a lawful basis for it, telling you what it collects, keeping it off every signed-in screen, and configuring it correctly. That is the part this policy is.
- Meta, for everything after it arrives. Once the visit reaches Meta, what it is used for and how long it is kept are Meta's decisions under Meta's Privacy Policy, and Meta is responsible for answering requests about that half — access, deletion, objection. Your Facebook or Instagram settings are the fastest route to it.
- Either of us will take the request. You never have to work out which. Write to info@paddlelens.com about any of it and we will answer what is ours and pass the rest to Meta — the Addendum gives us seven days to do that, and we treat it as a deadline rather than a target. You will get an answer from us whether or not Meta gives you one.
The full text of that arrangement is Meta's to publish and it is linked above; this is the substance of it, which is what Article 26(2) asks us to give you. All of it sits behind a yes-or-no you can change at any time, which remains the simplest way to be outside it entirely.
The full, dated list — with each company's jurisdiction — is on the subprocessors page. When a provider that touches club, athlete or account data is added or replaced, that page is updated before it starts and PaddleLens asks you to accept the updated policy the next time you open the app — so a change cannot pass you by unread. You can object on reasonable data protection grounds by writing to info@paddlelens.com before you accept, and if we cannot settle it you can stop using the Service and we will delete your data. Advertising and measurement partners hold none of that data; they are subject to a promise that is narrower and easier to check — we name each one on that page before it goes live, and every one of them inherits the same two limits: your consent, and public pages only. We may also disclose data if legally required, to protect someone's safety, or in connection with a merger or sale of the business — in which case we'll tell you, and this policy continues to apply until replaced.
"Sharing" is where we have to be straight with you. California law counts sending a page view to an ad network as sharing for cross-context behavioral advertising, and that is exactly what a measurement pixel does. So: if you accept cookies, we share with the advertising platform the fact that a browser opened one of our public pages — no account data, no athlete data, no app screens. If you are an adult and create a new account, we may also share one anonymous CompleteRegistration event — only after your advertising consent — with a random event ID, IP, browser details exposed by the browser request and Meta browser or ad-click ID. Our server does not forward the raw User-Agent header. We do not send your name, email, phone number, birth date, PaddleLens account ID or any purchase. If you decline, or never answer, or your browser sends a Global Privacy Control signal, we share nothing at all — not the page view or the sign-up. You can withdraw at any time from Cookie settings, and section 11 lists this as an opt-out right you can exercise without ever contacting us. This is a change: until August 2026 this policy said we shared nothing for advertising, because we didn't.
Here is the line that does not move. Advertising is something we do on other companies' platforms to be found; it is not something we do to the people already inside PaddleLens. We will never hand an advertising platform your phone number, your date of birth, a roster, an athlete profile, a measurement, a report, a frame, a photo or a message — not as a file, not as a hashed list, not as a custom or lookalike audience, and not as a server-side event. A new adult signup may send only the anonymous event and connection identifiers described above, only with your permission, and never if you are under 18. We build no audience from our members, and we upload no customer list. If any of that ever changes we will ask you first, separately, in a way you have to answer — not by editing this page.
7. How long we keep things
This table is also our published retention and destruction schedule for the body-landmark data in section 4. Reports do not quietly expire on a timer: they last while your account does and go when you or your coach remove them. Temporary uploads and deleted Community media do have the firm clocks listed below.
| Data | Kept for |
|---|---|
| Uploaded video file | Until the analysis completes (usually minutes); at most 24 hours |
| Measurements, scores, reports and the body-landmark data in section 4 | While your account is active, or until you or your coach delete them. No automatic expiry |
| Annotated frames | Same as the analysis they belong to; deleted with it |
| A coach's notes and marks on a report | With the report: deleted when the report is deleted, and when the account that owns the report is. If the coach who wrote them deletes their own account, the words stay on the paddler's report signed "A former coach" — the link to the account is removed, not the coaching |
| Athlete profile and notes | While the profile exists. A coach can delete it at any time, and deleting your account deletes the profiles you own |
| Photos and video sent to a club's Google Drive | Not ours to keep or to delete. They stay in the club manager's own Google account until that manager removes them — see section 3 |
| Community posts, comments and reactions | While the post or club exists, or until the author or we delete it. Deleting a post hides the whole post immediately and starts the media-deletion clock below |
| Community reports and moderation records | Open and resolved reports, the reported text or media metadata needed to assess them, and the manager's decision are kept while the club exists. They remain even if the author edits or deletes the live content, so a report cannot erase its own evidence. Deleting the reporter's or moderator's account removes that account link; deleting the club erases the report and audit records |
| Unpublished Community photos and videos | At most 24 hours from upload, then permanently erased from live storage |
| Photos and videos attached to a Community post | While the post exists. Deleting the post hides them immediately and allows a nine-second Undo; after that they become purgeable and the automated sweep permanently removes the live files, normally within five minutes and always within 24 hours. Permanently deleting the uploader's account or the club erases its associated live Community media immediately. Copies members downloaded are outside our control |
| Messages and announcements | While the club exists, or until deleted |
| Photos and files attached to messages | 14 days from when they were sent, then deleted automatically for everyone. Deleting the message deletes the attachment immediately. What remains afterwards is the file's name in the conversation, marked expired |
| Session rosters — who was asked, what they answered, who ended up in the boat and who turned up | Your club's own record of its sessions, kept while the session and the club exist. No timer: a roster is club records, the way a paper attendance book is, and the club controls it — deleting the session deletes it, and deleting the club deletes all of them. If your athlete profile is deleted, your name in these records becomes "Former athlete" and every link back to you is cut in the same instant. Deleting your account cuts the account link; a profile your coach created stays with the club, because it is the club's record rather than your account's |
| The calendar entry we published to each person | One row per person the session was published to, holding its start, how long it runs, a version number and whether it was withdrawn. No name, no answer, nothing about who attended. It exists so a cancelled or narrowed session can be cancelled in your own calendar app instead of sitting there for ever. Deleted automatically about 67 days after the session — the 60 days our calendar feed reaches back, plus a week — and immediately if you delete your account |
| A record that a roster notification was queued for you | One row per person per notice: the club, the session, which kind of notice, which channel, a 64-character code identifying that exact message so the same one cannot reach you twice, whether it went, and a machine code for why if it did not. Never the message text, and never your phone number. Deleted automatically when that notice's own deadline passes — for most of them, the start of the session they are about. Deleting your account deletes yours |
| The roster's change history | Kept — and it cannot be edited or deleted by anyone, including us; the database refuses the attempt outright. It is what answers a disputed place: what changed, in which order, and which role acted. It holds machine state only — version numbers, before-and-after status codes, a seat role, counts — and no names, no notes and no free text: a record containing them is rejected as it is written, not tidied up afterwards. Deleting your athlete profile erases the links from this history back to you, and deleting an account erases the id of the person who acted. What is left identifies nobody, which is the reason it can be kept |
| Account record | While the account is open. Deleting it yourself in the app removes it — with your reports and frames — straight away; a request by email is actioned within 30 days |
| Google sign-in hand-offs | The callback cookie and server record are usable for at most 10 minutes and erased when the callback returns. If you need to link or finish an account, the verified email, display name and Google identifier are held behind a second random cookie for at most 20 minutes; that hand-off is erased as soon as you finish and automatically after it expires. The stable Google identifier on a finished account is kept with the account record until you disconnect Google, and is deleted with the account if you do not |
| Year of birth | With the account record, and deleted with it. The day and month are never stored at all |
| Record that you accepted the Terms and this policy (date and version) | With the account record, and deleted with it. One narrow exception survives: when you do something that needed the current documents — publishing a session aimed at a squad — we keep a note that the act was covered by wording you had accepted. It holds a one-way code in place of your name, the two version numbers, and the date; no name, no email, no account number, and nothing about the session or the club. It survives for the same reason as the roster history it belongs to — that history outlives the account, so the record of what was agreed at the time has to outlive it too |
| Your mobile number on your account | While you keep it there. Removing it in Settings deletes it from the account immediately, and deleting your account does too. A recent coded RSVP prompt or inbound reply can still contain the number for the separate 90-day windows listed below. We hold one current number per account: if you add a number that is already on somebody else's account it moves to yours and we email them to say so, because a number that stops working silently is how a person misses a cancellation and never learns why |
| A record that you replied STOP | Kept indefinitely, and it survives deleting your account — deliberately. It is stored against the number rather than against you, because that is the only thing that still means anything once the account is gone, and because an opt-out we erased would quietly start texting whoever holds that number next. It holds the number, the date, and nothing else. Text START from that handset to undo it; nothing inside the app can, since an opt-out belongs to whoever holds the phone |
| A log that a text was sent | No timer — it is kept. It is how the per-club daily ceiling is counted, how we answer a member asking why they got a message, and the trail a misused coach account leaves. What it holds is the club, the date, whether it arrived, and the internal record numbers of the member and the coach — not the message text and not the number. Deleting your account does not delete these rows; it deletes the account those numbers pointed at, after which they identify nobody |
| An RSVP text prompt and its correlation code | Until 90 days after the code expires, then deleted automatically. It is kept long enough to explain a delayed or failed reply, and it disappears sooner if the practice or account is deleted |
| An inbound RSVP text event | 90 days from arrival, then deleted automatically. It holds Twilio's retry-stable message ID, the phone, short reply text, outcome and any matched internal practice/account records so the same webhook cannot apply twice and support can explain a refusal |
| Your answer to the photo-drop notice, and a coach's confirmation that they hold your permission to film you | Kept as a record of what was asked and answered, including if you said no. The photo-drop answer survives account deletion, because photos it relates to may still sit in a club's Drive — it holds your email, the date, your answer, the Google account it named, which version of the notice you saw, and the IP address the answer came from |
| Contact-form messages | Kept while they're useful for fixing what they describe — there's no timer on the message itself |
| Contact details you gave with a message (name, email, phone) | Erased within 30 days of us marking the message resolved, automatically. We keep them that long because people reply to our reply. Ask and we'll erase them immediately; deleting your account erases them too |
| A screenshot attached to feedback | Erased on the same clock as the contact details above — within 30 days of us marking that message resolved, or immediately on request. A screenshot can show a roster of real names or somebody's face, so it is treated as a contact detail rather than as part of the message: the words stay, the picture does not. Deleting your account deletes it straight away |
| Billing records | As long as tax and accounting law requires (typically 7 years) |
| A club's fee ledger | While the club needs it and subject to the club's lawful instructions; card-transaction history is retained where needed for refunds, disputes and required financial records |
| Connected-account, application-fee and settlement references we must keep | As long as payment, tax and accounting law requires; disconnecting a club does not erase this financial history |
| Server logs | Rotated automatically at a fixed size cap — old lines are overwritten as new ones arrive, typically within a few weeks |
| Analytics cookies (only if accepted) | Up to 2 years in your browser — clear them any time by declining in Cookie settings |
| Analytics reports at Google | 14 months, then Google deletes them automatically |
| Meta Pixel cookies (only if accepted) | Up to 90 days in your browser — declining in Cookie settings deletes them straight away |
| What Meta keeps at its end | On Meta's own schedule, not ours. Meta says pixel event data is kept in identifiable form for up to 2 years; ask Meta to delete it through your Facebook or Instagram account settings |
Community media is included only in encrypted backups. We keep the last seven available daily generations and the last four available weekly generations. If a scheduled run is missed, the oldest weekly generation may be older than four calendar weeks; a deleted file remains encrypted until the generation containing it is replaced. Each generation is one atomic snapshot containing both the private media and its matching encrypted database archive, so routine retention keeps or removes the complete restore pair. The current backup location is operator-controlled storage in Falkenstein, Germany. No off-site Community backup provider is currently approved or configured; the backup job refuses a remote destination in this mode. Backups are used only for disaster recovery, never to retrieve a deleted post or restore an individual file. Before a disaster-restored Service reopens, we run the deletion sweep recorded in that snapshot and reconcile known later deletion requests. A snapshot cannot record a deletion made after its timestamp, so we do not claim that restoring it alone can preserve every later deletion.
The current backup job does not create split restore pairs. If an encrypted database archive was isolated by an older backup version because its matching media snapshot could not be verified, later Community backup runs stop instead of silently accumulating more isolated archives. That archive is not used for restore and is not deleted automatically: the backup and privacy owner must reconcile its exact snapshot stamp and resolve it under this retention and deletion schedule before automated Community backups resume.
8. Children and guardians
Paddling clubs include young people, and we've designed for that rather than pretending otherwise.
- Under 13: no accounts. PaddleLens is not directed to children under 13, and children under 13 may not register. A coach may keep an athlete profile for a younger paddler — no login, no email address for the child, no sign-up by the child — only where the club holds a parent or guardian's written permission covering filming and automated analysis.
- 13–17: accounts allowed with guardian permission, which the club is responsible for obtaining before sending the invite.
- Community media needs separate permission. Before anyone posts an identifiable minor, the person posting must have the parent or guardian's permission to share it with the club and let current members download it. Permission for analysis alone is not permission to publish it in Community.
- We collect no more data about a minor than about an adult. We don't profile them or use their data for advertising. Analysis data goes only where needed to produce the report; Community content is visible to current members of the club only when it was posted with the separate permission above.
- Advertising and minors, stated exactly. We never sell or share the personal information of anyone we know to be under 16, and we never build an advertising audience out of our members, of any age — section 6 is the promise, and it has no age exception because it doesn't need one. Our ads on other platforms are set to 18 and over wherever the platform lets us set an age at all. The one caveat worth stating plainly: the website measurement in section 9 runs on public pages only, before anyone signs in, so it cannot tell a 15-year-old from an adult and does not try to. It never runs on a signed-in screen, which is the only place we know anyone's age at all — and if a parent tells us their child used the site before signing up, write to info@paddlelens.com and we will ask the platform to delete what it holds.
- Guardians can act at any time. Email info@paddlelens.com to see what we hold about a child, correct it, refuse further collection, or have it all deleted. We can remove a live Community copy but cannot retrieve a copy another club member already downloaded. We'll respond within 30 days and won't ask for more information than we need to verify the request.
- Photos in a club album are the one thing we can't delete for you. If a club uses the photo drop, pictures of a child may be in a coach's own Google Drive. We will tell you whose account it is and can disconnect the club's Drive so nothing more is sent to it, but the coach is the only person who can remove what's already there. Section 3 explains why.
If we learn we've collected personal information from a child under 13 without the required permission, we delete it.
9. Cookies
Strictly necessary cookies keep sign-in working. Analytics and advertising cookies are two separate, optional choices.
| Cookie | What it's for | How long | Optional? |
|---|---|---|---|
| pa_session | Keeps you signed in. Without it there is no way to stay logged in from one page to the next. | 30 days | No — strictly necessary |
| pl_google_oauth | A random one-time key that binds Google's callback to the browser that started sign-in. It contains no Google profile or token and is set only when you choose Google sign-in. | 10 minutes, or until Google returns | No — strictly necessary for Google sign-in |
| pl_google_pending | A random one-time key used only while you link an existing PaddleLens account or finish creating one after Google has confirmed your identity. Your details stay in the short-lived server record described in section 7, not inside the cookie. | 20 minutes, or until you finish | No — strictly necessary for Google sign-in |
| _ga, _ga_* | Set by Google Analytics if you accept. Gives your browser a random ID so repeat visits count as one visitor rather than several, and records only the approved public acquisition pages plus signup and checkout-start described above. | Up to 2 years | Yes — off until you accept |
| _fbp, _fbc | Set by the Meta Pixel if you accept. A random ID so Meta can recognise a returning browser, and — if you arrived by clicking one of our ads — the identifier of that click, which is what lets Meta tell us the ad worked. Set on our public pages only. If we ever add a second advertising platform its cookies are named here before it runs, and they work the same way. | Up to 90 days | Yes — off until you accept |
| ph_* (browser storage, not a cookie) | Written by PostHog if you accept analytics. A random ID kept in this site's own browser storage so repeat visits count as one visitor, and the queue of events waiting to send. Nothing is readable by any other website, and no PostHog cookie is set at all. | Until you withdraw or clear the site's data | Yes — off until you accept |
How the choice works
- Nothing loads until you answer. While the banner is unanswered, and after you've declined, we don't set a cookie or a browser-storage ID, start a tracking tag, or contact Google, PostHog or Meta at all. There is no "reject and we track you anyway".
- Two separate questions, and you can answer them differently. The banner has one switch for GA public-acquisition and PostHog product analytics, and another for Meta advertising measurement. Say yes to analytics and no to advertising and Meta is never requested and no signup is reported. Both switches start off, and neither is needed to use PaddleLens.
- The advertising tag is switched off inside the app. It runs on the public pages — the marketing pages, the blog, the FAQ, and the sign-in and sign-up screens — and nowhere else. It cannot fire on a report, a message, an athlete, a club, or any other signed-in screen, and it is also held back on any public link carrying something private in it, such as an invite code or a password-reset link. This is enforced in our own code, not by a setting at the platform, and any advertising platform we add is subject to the same code.
- Analytics identities are separate and pseudonymous. PostHog and GA receive different server-generated codes. Neither is a name, email or database ID, and neither goes to Meta.
- What it is never allowed to be about. We do not build, buy or ask for audiences based on health, injury, disability, body measurements, weight, race, religion, politics, sexual orientation, union membership, precise location or immigration status, and we do not let an advertising platform infer any of those from us. A page about training or technique is a page we wrote, not a fact about your body — and everything that is a fact about your body lives behind the sign-in, where no advertising tag runs.
- Declining costs you nothing. Every part of PaddleLens works identically either way. We ask again only if the disclosed analytics boundary changes; otherwise your choice stays put until you reopen settings.
- Change your mind whenever, one switch at a time. Cookie settings stops the matching browser collection and future Meta signup reporting. What a provider already received remains subject to that provider's controls.
- Consent is the server gate too. The server sends Meta's sole signup event only when the live ads answer and adult check both pass; a missing answer or unknown age means no event. It never sends a Purchase event.
- We keep reporting blunt. Google keeps only shape-checked campaign tags on approved public landing pages and strips every other query plus all fragments; PostHog strips every query and is product-only. Meta has no equivalent URL override, so its public PageViews do not fire from an address carrying a query or hash.
Counting the one described above, we use a single advertising measurement tag, and any we add is named on this page and on the subprocessors page before it runs. Beyond that we use no session replay, no heatmaps, no fingerprinting, and no data brokers. If your browser sends a Global Privacy Control signal we honor it: we treat it as a request to leave all of this off, and under California, Colorado and Connecticut law as an opt-out of sale, sharing and targeted advertising. It overrides an earlier acceptance — turn GPC on and the analytics, PostHog and the pixel all stop, even if you once said yes — and it takes effect without you telling us anything. It only ever switches them off; it can't switch them on. You'll see the cookie banner say so rather than offer you a choice that wouldn't do anything.
Your own browser can also block or delete all of this — every browser lets you clear cookies for a site — and PaddleLens will keep working, though you'll be signed out when the session cookie goes.
10. Security
- Passwords are stored hashed with bcrypt — we can't read yours.
- Traffic is encrypted in transit with HTTPS.
- Access is scoped by role and current club membership, checked again whenever Community media is viewed or downloaded; administrative access is limited to what's needed to operate the Service.
- Text is displayed as text rather than executable page code. Community accepts only supported image and video formats, verifies their contents, limits file size and video length, rewrites media to remove embedded metadata, and serves downloads without trusting the uploader's file name.
- Uploads are rate-limited and deleted on the schedule above. Encrypted backups are kept separately for disaster recovery.
- We review our safeguards at least annually, and whenever we make a significant change.
No system is perfect, and you send us data at your own risk. If a breach affects your personal data we will notify affected users, and any regulator we're required to notify, without undue delay.
11. Your rights
Wherever you live, you can ask us to give you a copy of your data, correct it, delete it, or stop a particular use. Email info@paddlelens.com from your account address and we'll respond within 30 days (45 where the law allows longer and the request is complex — we'll tell you). We will not treat you differently for exercising these rights.
If you're in California, Colorado, Connecticut, Virginia, Texas or another state with a comprehensive privacy law, you also have the rights that law gives you — including access, correction, deletion, portability, and the right to opt out of sale, targeted advertising and profiling. Taking those three one at a time, because two of the answers are still no and one of them changed in August 2026:
- Sale — no, and there never has been one. We have never taken money, or anything else of value, for anyone's personal information.
- Profiling — no. Nothing we do makes an automated decision that produces a legal or similarly significant effect about you. Your technique report is an estimate about a paddle stroke, and no one but you and your coach ever sees it.
- Targeted advertising and "sharing" — yes, if you accept cookies, and only in the narrow sense described in section 9. A visit to one of our public pages is reported to the advertising platform we bought the ad on. Under California law that counts as sharing for cross-context behavioral advertising; under Colorado, Connecticut, Virginia and Texas law it counts as targeted advertising. So we say it rather than hide behind the word "analytics".
You may appeal a refused request by replying to our decision, and if we get it wrong you may contact your state attorney general. An authorized agent may act for you with written proof. We do not sell or share the personal information of anyone we know to be under 16.
Note that some data is your club's to manage. If your coach entered a note about you and we can't remove it without breaking your club's records, we'll tell you and put you in touch.
12. Where your data is
Get Skilled LLC is a Wyoming company in the United States. Our servers are not.
| Where | What is there |
|---|---|
| Falkenstein, Germany — Hetzner Online GmbH | The server that runs PaddleLens, and the files it keeps: uploaded video while it is being analyzed, annotated frames, and Community media. Encrypted backup archives are currently kept in operator-controlled storage there as the last seven available daily and four available weekly generations. No off-site Community backup provider is currently configured |
| Frankfurt, Germany — Supabase, Inc. (a US company) | The database itself: accounts, athlete data, measurements, reports, Community text and the app's records about them. This is where those records actually live — resident in Frankfurt, on infrastructure Supabase manages |
| France — Brevo | Email addresses and the contents of the messages we send you |
| United States — Anthropic | The text sent for a report or a crew plan (section 6). No video, no images |
| United States — Stripe | Payment and receipt data for PaddleLens purchases; connected-club identity and bank details; direct club-fee payments, payouts, refunds and disputes |
| Your club manager's Google account — wherever Google keeps it | Photos and video sent to the club photo drop, if your club uses it (section 3) |
| United States and elsewhere — Google Identity Services | A stable Google account identifier and verified email and display name, only if you choose Google sign-in. PaddleLens keeps no Google access or refresh token |
| United Kingdom — WeatherAPI.com | The coordinates of your club's training venue, when a coach has set one. Nothing about any person |
| United States and elsewhere — Google | Public acquisition analytics, signup and checkout-start only, and only if you accepted cookies |
| United States — PostHog's US cloud | Private product analytics — normalized screens and shape-only events under a separate server-generated pseudonymous code for signed-in members — only if you accepted analytics cookies. PostHog is a US company; data is stored in the United States and IPs are discarded at ingestion |
| Ireland, the United States and elsewhere — Meta | Eligible public PageViews and, only after ads consent and the adult check, anonymous `CompleteRegistration` for a newly created account. Across the browser and server copies Meta receives the event ID, IP, browser details exposed by the browser request and its own browser/ad-click IDs; our server does not forward the raw User-Agent header — never name, email, phone, birth date, account ID or Purchase |
So: if you are in the United States, your data is transferred to and processed in Germany, and to France for email. If you are in Europe, it stays closer to home than you might expect. Either way it crosses a border, we rely on the standard contractual protections our providers offer for those transfers, and Germany's data-protection regime is at least as strict as anything in the United States.
If you accept cookies, Google, PostHog and our advertising and measurement partners may also process what they collect on servers outside your country, including in the United States, under their own transfer safeguards — standard contractual clauses, and the EU–US Data Privacy Framework where the company is certified under it. PostHog runs on its US cloud, so if you are in the United States its product analytics never leave your own country, and if you are in Europe they are one of the transfers those safeguards cover. Declining keeps any of it from being collected at all, which is the one transfer safeguard that needs nobody's paperwork.
13. Changes to this policy
We'll show you material changes in the app — and email you where the change affects how we use data you've already given us. The date at the top says when a version takes effect. If we show it early, the prompt says it is advance notice and can be dismissed until that date; once it takes effect, acceptance is required to carry on. A new optional feature may require acceptance sooner, before it handles data under the new rules. The prompt names what moved in plain language, and you can decline and stop using PaddleLens, with your data deleted on request. The "last updated" date at the top always identifies the current version.
14. Contact
Get Skilled LLC, a Wyoming limited liability company · United States · info@paddlelens.com. Privacy requests, guardian requests and complaints all go to the same address, and reach a human.
Questions, or a request about your data? Write to info@paddlelens.com.