ShotStep Interim Privacy Policy

Last updated: July 30, 2026
Operator: Harbor Muse LLC

This interim policy corrects the public description of ShotStep while final release, retention, and deletion work continues. It distinguishes the current TestFlight app, features implemented for a later release, and the public deletion-request route that is available now.

1. Scope and release boundary

This policy explains how the ShotStep mobile app and the informational website at shotstep.com handle information for the planned United States release.

The current distributed app is TestFlight build 13 (version 0.1.4). It is not the final release candidate. Features that exist only in next-release source are labeled separately below.

ShotStep is free to use. It has no paid subscriptions, in-app purchases, advertising, or cross-company tracking feature.

2. Information in the current distributed app

Account and profile information

ShotStep uses an email address and a passwordless email code to create and authenticate an account. It stores the account role and a structured account name. A coach also chooses whether a connected player sees the coach's first name, first name and last initial, or full name.

The app keeps limited authentication and profile data on the device so the signed-in session and account screen can work.

Coach invitations and relationships

A coach may invite a player by email. The invitation can include the invited email address, coach and player names, an optional coach message, and a join link and code. If a player accepts, ShotStep stores the coach-player relationship.

Connected coaches and players can see the relationship records and shared lesson, assignment, task, completion, and practice information needed for their coaching relationship. They do not receive unrelated users' records.

Coaching and review information

ShotStep stores lesson and practice content, including goals, notes, assignments, tasks, completion history, and related coaching records. A coach can also keep private coach notes, reminders, concerns, and concern history. Those private records are visible to that coach and not to the player.

A coach who applies for ShotStep Verified can provide identity and coaching context, service-area text, an evidence or reference route, and an application note. Authorised ShotStep reviewers can record a decision, private reviewer notes, and audit events. ShotStep Verified means only that ShotStep performed the limited review described in the app. It is not an identity check, background check, qualification, certification, or guarantee of coaching quality or safety.

3. Website intake and next-release information

A public deletion-request intake is available at shotstep.com/delete-account. It uses the submitted account email, a random purpose intent, and a fresh email code. To limit automated abuse, the Edge Function derives a keyed HMAC from the caller's network address and stores only that pseudonymous key, a one-minute request count, and an expiry in Supabase. The deletion-intake tables do not store the raw network address.

The following app features are implemented but not yet distributed:

Push messages use small generic content, but may include a coach's public name and routing identifiers needed to open the right destination. A user can decline notifications or change permission in device settings. The next-release app does not provide a switch to disable the limited first-party product analytics or Sentry collection.

4. How ShotStep uses information

ShotStep uses information to:

ShotStep does not collect passwords entered into ShotStep, advertising data, precise or approximate location, address-book contacts, photos, videos, audio, financial information, or browsing or search history as part of these features.

5. Who receives information

Recipient Purpose and information
Supabase Account authentication and storage of account, relationship, coaching, application, review, schedule, notification, public deletion-intake, and next-release account-linked product analytics records and protected aggregate results, including a short-lived keyed deletion-abuse counter.
Cloudflare Delivery of the public ShotStep website and ordinary website request logs.
Resend Passwordless sign-in and deletion-verification codes using the account email address and email-code message content through Supabase Auth custom SMTP; and coach invitation email using the recipient email, coach and player names, optional message, join link and code, and email body.
Expo Push Service Next-release delivery of a push token and small notification payload to a platform push provider.
Apple Push Notification service Next-release delivery of notifications to Apple devices.
Firebase Cloud Messaging Next-release delivery of notifications to supported non-Apple devices.
PostHog Next-release receipt from the server-only exporter of thresholded aggregate counts, rates, and distributions with approved coarse dimensions and date windows under one fixed non-person exporter identity. PostHog receives no mobile events or account, person, source-record, device, exact-time, or coaching-content identifiers from this revised path.
Sentry Next-release receipt of the sanitised technical diagnostics described above.

An accepted coach and player also receive the shared records needed for their coaching relationship. A player's private coach records stay with the coach. Authorised ShotStep reviewers can access coach application and review material for the review process.

ShotStep does not use this information for advertising or to track people across other companies' apps or websites.

6. Retention

Private coach application evidence expires 90 days after submission or an earlier first decision. Each private reviewer note expires 90 days after its decision. A scheduled database job redacts those expired private fields.

The United States Sentry project is configured for 30-day retention.

Public deletion purpose intents and keyed request-abuse counters expire after 10 minutes. The account-linked email-send throttle is removed after no active intent remains. These are intake controls, not the completed deletion-request audit.

Both observed United States PostHog projects report an 84-month product-event setting and report that event-retention enforcement is disabled. ShotStep approved that observed configuration only for the planned clean project after it receives exclusively finalized, thresholded statistics that are not designed to identify a person. The legacy mobile project must be deleted whole during the migration. ShotStep does not promise automatic PostHog deletion at month 84 because that provider behavior has not been verified.

The revised analytics design deletes account-linked raw analytics in Supabase after 30 days or earlier during account deletion. It also removes affected unsent aggregate snapshots and recomputes protected results. Finalized statistics may remain longer only after they have at least ten qualifying contributors and no account, person, journey, relationship, lesson, device, exact-time, content, or contribution lookup. The Supabase recording, cleanup, compilation, export boundary, and mobile PostHog removal are implemented for the next release. Legacy-project deletion and clean-project aggregate-only provider proof remain separate release gates.

Complete retention schedules are not yet approved for every account, relationship, lesson, practice, acceptance, notification, audit, website, email, and platform-push record. This interim policy does not promise an unapproved period or vendor deletion behavior.

7. Choices and account deletion

A user can edit their account name. A coach can edit the name format shown to connected players. A player with an accepted coach can end that relationship, which stops new sharing and coach access to the player's active relationship data. A user can deny or change optional notification permission in device settings.

The distributed app has no completed self-service data-export flow. The public deletion-request route gives the same response whether an email belongs to an account, uses a fresh email code, queues only the verified account, freezes new account activity, and revokes sessions.

ShotStep acknowledges a verified request immediately, provides a human response within five business days, and targets completion within 30 calendar days. A queued request is not completed deletion, and a completion notice is sent only after the required checks pass. The process may be handled manually while the role-specific fulfillment worker completes release proof.

The available name edit, request queue, and database deletion marker are not complete account deletion. Access, correction, export, appeal, complaint, and other support routes will be described only when the real product and support processes can honor them.

8. Age and release scope

The planned release is limited to the United States. Players must be at least 13. Players aged 13 through 17 need permission from a parent or guardian. Coaches must be at least 18. The final date-of-birth handling and guardian permission process are still being designed and must be approved before release. ShotStep is not intended for children under 13.

9. Security and policy changes

ShotStep limits access according to account role and coaching relationship and limits next-release analytics and diagnostic payloads in app code. No technical system can guarantee absolute security.

The app stores versioned policy-acceptance records where an acceptance step is presented. Material future changes will use the approved notice and renewed-acceptance process for the release.

10. Contact

ShotStep is operated by Harbor Muse LLC.
Privacy inquiries: privacy@shotstep.com
General support: support@shotstep.com
Legal inquiries: legal@shotstep.com