ShotStep Interim Privacy Policy
This interim policy corrects the public description of ShotStep while final release, retention, and deletion work continues. It distinguishes the current TestFlight app, features implemented for a later release, and the public deletion-request route that is available now.
1. Scope and release boundary
This policy explains how the ShotStep mobile app and the informational website at shotstep.com handle information for the planned United States release.
The current distributed app is TestFlight build 13 (version 0.1.4). It is not the final release candidate. Features that exist only in next-release source are labeled separately below.
ShotStep is free to use. It has no paid subscriptions, in-app purchases, advertising, or cross-company tracking feature.
2. Information in the current distributed app
Account and profile information
ShotStep uses an email address and a passwordless email code to create and authenticate an account. It stores the account role and a structured account name. A coach also chooses whether a connected player sees the coach's first name, first name and last initial, or full name.
The app keeps limited authentication and profile data on the device so the signed-in session and account screen can work.
Coach invitations and relationships
A coach may invite a player by email. The invitation can include the invited email address, coach and player names, an optional coach message, and a join link and code. If a player accepts, ShotStep stores the coach-player relationship.
Connected coaches and players can see the relationship records and shared lesson, assignment, task, completion, and practice information needed for their coaching relationship. They do not receive unrelated users' records.
Coaching and review information
ShotStep stores lesson and practice content, including goals, notes, assignments, tasks, completion history, and related coaching records. A coach can also keep private coach notes, reminders, concerns, and concern history. Those private records are visible to that coach and not to the player.
A coach who applies for ShotStep Verified can provide identity and coaching context, service-area text, an evidence or reference route, and an application note. Authorised ShotStep reviewers can record a decision, private reviewer notes, and audit events. ShotStep Verified means only that ShotStep performed the limited review described in the app. It is not an identity check, background check, qualification, certification, or guarantee of coaching quality or safety.
3. Website intake and next-release information
A public deletion-request intake is available at shotstep.com/delete-account. It uses the submitted account email, a random purpose intent, and a fresh email code. To limit automated abuse, the Edge Function derives a keyed HMAC from the caller's network address and stores only that pseudonymous key, a one-minute request count, and an expiry in Supabase. The deletion-intake tables do not store the raw network address.
The following app features are implemented but not yet distributed:
- Scheduled lesson time and focus.
- An account-linked notification installation record containing a random app installation identifier, Expo push token, permission status, platform, and delivery timestamps or errors.
- Notification event and delivery records containing actor, recipient, relationship, subject and destination identifiers; a relationship-safe public actor name; fixed copy and event keys; and delivery state and attempt information.
- Account-linked first-party product analytics stored privately in Supabase. The app records eight fixed allowlisted behavior event types with only the authenticated account and role, the minimum source-record references needed to verify and later delete the event, app release and platform, server receipt time, a coarse local time bucket for coach events, and fixed categorical facts. It does not record coaching words, names, emails, arbitrary properties, screen or tap streams, location, advertising identifiers, or device fingerprints.
- The revised mobile source contains no PostHog SDK or token. A server-only exporter may send PostHog only thresholded aggregate counts, rates, and distributions with at least ten qualifying contributors, approved coarse dimensions and date windows, and one fixed non-person exporter identity. It sends no account, person, journey, relationship, lesson, assignment, task, or device identifier; exact event time; or coaching content.
- Limited Sentry crash, error, and loading diagnostics. Sentry receives exception types and scrubbed stack frames, limited app, device, and operating-system context, and allowlisted loading measurements. It does not retain a ShotStep user or installation identity, error messages, requests, tags, extras, or breadcrumbs.
Push messages use small generic content, but may include a coach's public name and routing identifiers needed to open the right destination. A user can decline notifications or change permission in device settings. The next-release app does not provide a switch to disable the limited first-party product analytics or Sentry collection.
4. How ShotStep uses information
ShotStep uses information to:
- create and authenticate accounts;
- provide profiles, invitations, coaching relationships, lessons, practice, assignments, and private coach records;
- review coach applications and keep an auditable decision record;
- schedule lessons and deliver optional notifications;
- verify public deletion requests and limit automated abuse of that route;
- compile daily and rolling aggregate product metrics, and export only thresholded non-identifying statistics to PostHog; and
- find and fix crashes, errors, and loading problems.
ShotStep does not collect passwords entered into ShotStep, advertising data, precise or approximate location, address-book contacts, photos, videos, audio, financial information, or browsing or search history as part of these features.
5. Who receives information
| Recipient | Purpose and information |
|---|---|
| Supabase | Account authentication and storage of account, relationship, coaching, application, review, schedule, notification, public deletion-intake, and next-release account-linked product analytics records and protected aggregate results, including a short-lived keyed deletion-abuse counter. |
| Cloudflare | Delivery of the public ShotStep website and ordinary website request logs. |
| Resend | Passwordless sign-in and deletion-verification codes using the account email address and email-code message content through Supabase Auth custom SMTP; and coach invitation email using the recipient email, coach and player names, optional message, join link and code, and email body. |
| Expo Push Service | Next-release delivery of a push token and small notification payload to a platform push provider. |
| Apple Push Notification service | Next-release delivery of notifications to Apple devices. |
| Firebase Cloud Messaging | Next-release delivery of notifications to supported non-Apple devices. |
| PostHog | Next-release receipt from the server-only exporter of thresholded aggregate counts, rates, and distributions with approved coarse dimensions and date windows under one fixed non-person exporter identity. PostHog receives no mobile events or account, person, source-record, device, exact-time, or coaching-content identifiers from this revised path. |
| Sentry | Next-release receipt of the sanitised technical diagnostics described above. |
An accepted coach and player also receive the shared records needed for their coaching relationship. A player's private coach records stay with the coach. Authorised ShotStep reviewers can access coach application and review material for the review process.
ShotStep does not use this information for advertising or to track people across other companies' apps or websites.
6. Retention
Private coach application evidence expires 90 days after submission or an earlier first decision. Each private reviewer note expires 90 days after its decision. A scheduled database job redacts those expired private fields.
The United States Sentry project is configured for 30-day retention.
Public deletion purpose intents and keyed request-abuse counters expire after 10 minutes. The account-linked email-send throttle is removed after no active intent remains. These are intake controls, not the completed deletion-request audit.
Both observed United States PostHog projects report an 84-month product-event setting and report that event-retention enforcement is disabled. ShotStep approved that observed configuration only for the planned clean project after it receives exclusively finalized, thresholded statistics that are not designed to identify a person. The legacy mobile project must be deleted whole during the migration. ShotStep does not promise automatic PostHog deletion at month 84 because that provider behavior has not been verified.
The revised analytics design deletes account-linked raw analytics in Supabase after 30 days or earlier during account deletion. It also removes affected unsent aggregate snapshots and recomputes protected results. Finalized statistics may remain longer only after they have at least ten qualifying contributors and no account, person, journey, relationship, lesson, device, exact-time, content, or contribution lookup. The Supabase recording, cleanup, compilation, export boundary, and mobile PostHog removal are implemented for the next release. Legacy-project deletion and clean-project aggregate-only provider proof remain separate release gates.
Complete retention schedules are not yet approved for every account, relationship, lesson, practice, acceptance, notification, audit, website, email, and platform-push record. This interim policy does not promise an unapproved period or vendor deletion behavior.
7. Choices and account deletion
A user can edit their account name. A coach can edit the name format shown to connected players. A player with an accepted coach can end that relationship, which stops new sharing and coach access to the player's active relationship data. A user can deny or change optional notification permission in device settings.
The distributed app has no completed self-service data-export flow. The public deletion-request route gives the same response whether an email belongs to an account, uses a fresh email code, queues only the verified account, freezes new account activity, and revokes sessions.
ShotStep acknowledges a verified request immediately, provides a human response within five business days, and targets completion within 30 calendar days. A queued request is not completed deletion, and a completion notice is sent only after the required checks pass. The process may be handled manually while the role-specific fulfillment worker completes release proof.
The available name edit, request queue, and database deletion marker are not complete account deletion. Access, correction, export, appeal, complaint, and other support routes will be described only when the real product and support processes can honor them.
8. Age and release scope
The planned release is limited to the United States. Players must be at least 13. Players aged 13 through 17 need permission from a parent or guardian. Coaches must be at least 18. The final date-of-birth handling and guardian permission process are still being designed and must be approved before release. ShotStep is not intended for children under 13.
9. Security and policy changes
ShotStep limits access according to account role and coaching relationship and limits next-release analytics and diagnostic payloads in app code. No technical system can guarantee absolute security.
The app stores versioned policy-acceptance records where an acceptance step is presented. Material future changes will use the approved notice and renewed-acceptance process for the release.
10. Contact
ShotStep is operated by Harbor Muse LLC.
Privacy inquiries:
privacy@shotstep.com
General support:
support@shotstep.com
Legal inquiries:
legal@shotstep.com