Privacy Policy
Last updated: September 21, 2026
Operator Information
Operator: Yoon
Email: stringgoat.dev@gmail.com
1. Personal Information We Collect
String GOAT ("Service") collects the following personal information:
- Account information: Email address, name (provided via social login)
- Service usage information: String records, racket information, feedback ratings, and photos you upload (e.g. racket or session photos)
- Device information: Device identifier, OS version, app version
- Web session information: Cookies and session tokens (for maintaining web dashboard login)
- Wearable and workout data (collected when you use the Apple Watch or Wear OS companion app during a tennis session): heart rate, active calories, motion sensor data (accelerometer and gyroscope), swing/stroke counts, step counts, and GPS location if you enable it.
- Profile information: Birth year and maximum heart rate setting you optionally enter (used to calculate heart rate zones), and profile photo
- Customer information (stringer features): Name, contact number, email, club, and notes of your customers that you enter to manage stringing jobs
- Feature usage events: Records of in-app actions such as screen views, saves, and subscription screen views (used only to improve the Service)
- Usage analytics (Google Analytics): App and website usage records (app launches, sessions, screen and page views, engagement time, and the product and price of in-app purchases), analytics identifiers (app instance ID, website cookies), device model, operating system and app version, and approximate location inferred from your IP address. This information is not linked to your account, and app analytics does not use the advertising identifier (IDFA/GAID).
- Promotion information: Coupon/partner code redemption records, referral codes and referral relationships, and the IP address collected when claiming a promotional link (used only to prevent abuse)
If you enter your customers' personal information (stringer features), you are responsible for collecting it lawfully and obtaining any required consent. String GOAT stores such information solely to provide the Service to you, never uses it for any other purpose, and deletes it together with your account upon account deletion.
2. Purpose and Legal Basis for Processing Personal Information
Collected personal information is used for the following purposes. For EU/EEA users, processing is based on performance of a service contract (GDPR Article 6(1)(b)); usage analytics and personalized advertising are based on your consent (GDPR Article 6(1)(a)):
- Service provision and operation (mobile app and web dashboard)
- User authentication and account management
- Cloud synchronization and backup
- AI string analysis service provision
- Push notification delivery (replacement timing alerts, etc.)
- Subscription payment processing and management
- Service improvement and new service development
- Workout session recording and statistics (companion watch app)
The companion watch app collects motion, location, and health-related data (such as heart rate) only after you grant the corresponding permissions in your device's system prompts (Motion & Fitness, Location, and Health / Body Sensors). You can withdraw these permissions at any time in your device settings. For EU/EEA users, health-related data is special-category data processed solely on the basis of your explicit consent (GDPR Article 9(2)(a)). On Apple Watch, heart rate and calorie data are read through Apple HealthKit; on Wear OS, through the Android Body Sensors permission.
3. Third-Party Services and International Data Transfers
String GOAT uses the following third-party services. These services are primarily hosted in the US and data may be transferred to that country:
- Supabase (US) — Database storage and user authentication. Includes Google and Apple social login. GDPR DPA in place. Privacy Policy
- Google Gemini API (US) — AI string analysis. Only anonymized equipment (racket and string) data and usage records (including feedback and workout session statistics) are sent; no personally identifiable information is included.
- Firebase Cloud Messaging (US) — Mobile push notifications.
- RevenueCat (US) — In-app subscription payment management for the mobile app. Privacy Policy
- Polar (US) — Web subscription payment processing (via Stripe). Privacy Policy
- Google AdMob (US) — In-app advertising for free-tier users of the mobile app. Uses the advertising identifier (IDFA/GAID) to serve and measure ads. Privacy Policy
- Google Analytics (US) — Usage analytics for the mobile app and website to improve the service. The app uses Google Analytics for Firebase. Privacy Policy
- Meta Pixel (US) — Website advertising measurement and conversion tracking for marketing. Privacy Policy
- Vercel (US) — Website hosting and content delivery infrastructure. Privacy Policy
- Slack (US) — Internal operational alerts for the operator (notifications of events such as new signups). We transmit the signup time, signup path (app/web), trial end date, referral code, and the country estimated from the IP address. Identifying information such as name and email address is not transmitted. Privacy Policy
Advertising and tracking: Free-tier users of the mobile app see ads served by Google AdMob. On iOS, the app requests App Tracking Transparency permission before the advertising identifier is used for personalized ads; if you decline, ads are shown non-personalized. You can change this at any time in your device settings (iOS: Settings > Privacy & Security > Tracking; Android: ad personalization settings). Subscribers (Pro/Premium) do not see ads. Health and workout data (heart rate, motion sensor data, and location) is never used for advertising purposes and is never shared with advertisers or data brokers.
Consent management: For users in the European Economic Area (EEA), the United Kingdom and Switzerland, the app shows a consent message through Google's certified consent management platform (User Messaging Platform), and your choices determine ad personalization and whether app usage analytics is performed. If you do not consent to storing or accessing information on your device, the app does not perform usage analytics. You can change your choices at any time in the app under Settings > Privacy Choices. On the website, you can make your choice in the cookie consent banner; for visitors from these regions, analytics and advertising cookies are not used until you consent.
4. Cookies and Sessions
The web dashboard uses cookies to maintain login status. The website also uses cookies for usage analytics (Google Analytics) and advertising measurement (Meta Pixel), which you can decline in the cookie consent banner. Cookies can be disabled in your browser settings, but disabling login cookies may limit some features.
5. Data Retention Period
Personal information is retained for the duration of service use. Upon account deletion request, all data is immediately and permanently deleted. If you only cancel your subscription, your data is retained. However, usage analytics data (Google Analytics) is not linked to your account and is therefore not removed by account deletion; under our retention settings, event data linked to identifiers is automatically deleted after 2 months, and user-level data 14 months after your last activity. Aggregated statistics that cannot identify individuals may continue to be retained.
6. User Rights
Users may exercise the following rights at any time:
- Request to access personal information
- Request to correct personal information
- Request to delete personal information (account deletion)
- Right to data portability (Excel/CSV export)
- Request to restrict processing
EU/EEA: EU/EEA users: If the above rights are denied, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
You can also request account and data deletion without the app on our dedicated page: Account & Data Deletion
7. Automated Decision-Making
The AI string analysis feature provides reference information for string selection. This does not constitute binding automated decision-making; the final choice is always yours.
8. Data Security
All data is transmitted encrypted (HTTPS/TLS) and stored encrypted on the server. Row Level Security (RLS) ensures that only you can access your own data.
9. Children's Privacy
The Service is not directed to children under the age of 14 (or the applicable legal minimum age in your jurisdiction), and we do not knowingly collect personal information from such children. If we become aware that personal information of a child has been collected, we will delete it immediately. If you believe a child has provided us with personal information, please contact us at the email address below.
10. Contact
For privacy-related inquiries, please contact stringgoat.dev@gmail.com.