Privacy Policy

Privacy Policy

1. Introduction 

The Coachi mobile application and related services (the “Service”) are operated by Sport Autonomy (“Coachi”, “we”, “us”, “our”).

Registered address:

Sport Autonomy

38 Cherry Tree Avenue

St Albans

United Kingdom

Contact email: privacy@coachi.app

Sport Autonomy is the data controller responsible for your personal data under the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

This Privacy Policy is accessible within the app without signing in and from the Apple App Store and Google Play Store listings.

2. What Coachi Does

Coachi helps users improve their skiing technique by analysing videos they choose to analyse and generating AI-based coaching feedback.

The Service uses computer vision and machine-learning models to extract movement and pose data (such as joint positions, angles, timing, and symmetry) from uploaded videos and, where enabled, device sensors.

Coachi is not a medical device and does not provide medical advice.

3. Why We Collect Your Information

Depending on how you use the Service, we may collect the following categories of personal data:

3.1 Account Information
  • Username

  • Country and language preferences

  • Learning goals

Currently we only support guest accounts and we do not request a user’s email address

3.2 Video Submissions
  • Videos you voluntarily analyse for skiing technique analysis

  • Optional notes or metadata you add

3.3  Anonymous Installation Identifier

When Coachi is installed for the first time, we generate a random installation secret (a cryptographic nonce). This value has no connection to your identity and is used solely as a security mechanism to authenticate token requests and session refreshes between your device and our servers. It is not shared with third parties and is not used for tracking or advertising purposes.

This value is stored in AWS Cognito in our EU-West-1 (Ireland) data centre alongside a generated dummy email address. Neither value can be used to identify you as an individual.

3.4 Movement / Pose Data
  • Estimated joint or keypoint positions

  • Angles, timing, rhythm, symmetry, and motion patterns

  • Derived performance metrics

This data is extracted from analysis videos and (only if you enable permissions)

Important: We do not use this data to uniquely identify you. Where applicable, this processing may be treated as biometric or health-related data under data protection law, and we rely on your explicit consent.

3.5 AI-Generated Outputs
  • Coaching feedback

  • Session summaries

  • Technique scores and progress indicators

3.6 Technical & Usage Data
  • Device type, operating system, app version
  • IP address

  • Crash logs and diagnostics

  • App usage analytics

3.6.A  App Performance & Diagnostics (Embrace.io and OpenTelemetry)

From the moment Coachi launches, we collect performance and diagnostic data using Embrace.io and OpenTelemetry instrumentation. This data collection begins immediately on app bootstrap and includes:

  • App session traces and durations

  • Crash reports and stack traces

  • Network request timings (excluding request body content)

  • Device type, operating system version, and app version

  • Device identifiers assigned by the Embrace SDK

  • Performance metrics such as CPU usage, memory consumption, and frame rate

This data is used exclusively to monitor app stability, diagnose technical issues, and improve performance. It is not used for advertising or to build behavioural profiles.

Embrace.io is a third-party mobile observability service. Data collected by the Embrace SDK is processed by Embrace, Inc. and may be transferred to servers in the United States. Embrace processes this data under contract with Sport Autonomy as a data processor. For details of Embrace’s data handling, please see their privacy policy at https://embrace.io/privacy-policy.

3.6.B  Application Logging (AWS CloudWatch)

We collect application logs in AWS CloudWatch (EU-West-1, Ireland). These logs may include:

  • App events and error messages

  • Device and OS version

  • IP addresses (captured as part of standard server-side logging)

  • Anonymous session identifiers

Log data is used for debugging and operational monitoring only. IP addresses captured in logs are not used to identify individuals and are subject to standard log retention policies (see Section 9).

3.6.C  Infrastructure & Data Storage (AWS)

Your app data is stored using Amazon Web Services (AWS) infrastructure located in the EU-West-1 (Ireland) region. This includes:

  • AWS Cognito — stores your anonymous installation identifier and a system-generated dummy email address for session management purposes

  • AWS DynamoDB — stores app data such as session records and coaching outputs

At this time, no personally identifiable information is stored in these systems. AWS acts as a data processor under contract with Sport Autonomy. AWS infrastructure in EU-West-1 is subject to EU data protection standards. For details, see the AWS Privacy Notice at https://aws.amazon.com/privacy.

3.7 Support Communications
3.8 Marketing Preferences
  • Newsletter opt-in or opt-out

4. Age Restrictions

The Service is intended for users aged 13 and over. Users aged 13–17 must have permission from a parent or legal guardian to use the Service and purchase subscriptions. We do not knowingly collect personal data from children under 13.

5. How We Collect Data

  • Directly from you (account creation, uploads, settings, support messages)

  • Automatically (app diagnostics and usage analytics)

  • From app platforms (Apple and Google for subscription status)

  • From device sensors (only if you grant permission)

6.Consent for Video and Ai Analysis

  • AI models analyse videos to estimate pose and movement

  • Metrics are calculated and converted into coaching feedback

  • AI outputs are advisory only and may be imperfect

  • No automated decisions with legal or similarly significant effects are made

  • User videos are not used for model training or marketing

6.A. Apple App Store Privacy Nutrition Label

Apple requires us to declare all data collected by Coachi and its third-party SDKs in the App Store listing. The following reflects our current data collection practices. 

The app collects several categories of data related primarily to device functionality and diagnostics. Identifiers include a Device ID provided by the Embrace SDK, which is linked to the user’s device, and an anonymous installation ID generated by Cognito, which is not linked to the user’s identity. Diagnostic information collected includes crash data, performance data, and other diagnostic data, all of which are linked to the device to help monitor and improve app stability and performance. The app also collects usage data, specifically app interaction and session data, which is linked to the device to understand how the app is used. Additionally, IP addresses may appear in server logs, but these are not used to identify the user.

7. Sharing Your Data

  • We do not sell personal data.

  • We may share data with trusted service providers acting under contract, including:

    • Cloud hosting and storage providers (UK-based)

    • AI and compute infrastructure providers

    • Analytics and crash-reporting services

    • Customer support platforms

    • Apple and Google (subscriptions and billing)

  • We may also disclose data where required by law or to protect legal rights.

8. International Data Transfers

Our primary infrastructure is hosted in AWS EU-West-1 (Dublin, Ireland). As Ireland is a member of the European Union, data stored there benefits from the same protections as data held in the UK under the EU-UK adequacy decision currently in effect.

 

Certain third-party service providers used by Coachi may process data outside the UK and EU:

Certain third-party service providers used by Coachi may process data outside the UK and EU. Embrace.io is used for mobile observability and crash reporting, and data processed through this service may be transferred to the United States. AWS CloudWatch is used for application logging, with data processed within AWS EU-West-1 (Ireland). AWS Cognito and DynamoDB are used for authentication and data storage, and these services also operate within AWS EU-West-1 (Ireland).

Where data is transferred to the United States or other countries outside the UK/EU, we ensure appropriate safeguards are in place, including the use of Standard Contractual Clauses (SCCs) or reliance on an adequacy decision where applicable.

8.A Lawful Basis for Processing (UK & EU GDPR)

Under UK GDPR and EU GDPR, we rely on the following lawful bases to process your data:

 Coachi processes certain data for specific activities based on defined lawful bases. App diagnostics and crash reportingare processed under legitimate interests, as they are necessary to maintain a stable and functional service. Performance monitoring, carried out using Embrace and OpenTelemetry (OTel), also relies on legitimate interests, enabling the identification and resolution of technical issues. Application logging through AWS CloudWatch is processed under legitimate interests to support security monitoring and maintain operational integrity. Anonymous session management using AWS Cognito is processed under contract performance, as it is required to provide the core service of the app. Video and pose analysis is carried out based on user consent, with explicit consent obtained before processing begins. AI coaching feedback generation is also based on consent, as it follows from the user’s consent to video analysis.

Where we rely on legitimate interests, users have the right to object to that processing. Please contact us at support@coachiapp.com to exercise this right.

9. Data Retention

The following retention periods apply to data collected by Coachi and its service providers:

Coachi retains different types of data for defined periods depending on their operational purpose. AWS CloudWatch logsare retained for 90 days to support operational debugging and are automatically deleted after this period. Cognito installation records are stored for the duration of the app installation plus an additional 30 days, as they are required for session management. DynamoDB session and coaching data are retained for as long as the user account remains active, plus 12 months, enabling coaching history and progress tracking. Embrace.io diagnostic data is retained according to Embrace’s own retention policy, typically around 13 months, as it is processed by a third-party provider (see the Embrace privacy policy for details). OpenTelemetry trace data is retained for 90 days to allow performance analysis and is automatically deleted afterwards.

You may request deletion of your data at any time by contacting support@coachiapp.com. Where data is held by third-party processors, we will request deletion on your behalf where we have the ability to do so.

10. Your Rights

As a user located in the UK or EU, you have the following rights under UK GDPR and EU GDPR:

  • Right of access — request a copy of personal data we hold about you

  • Right to rectification — request correction of inaccurate data

  • Right to erasure (‘right to be forgotten’) — request deletion of your data

  • Right to restriction — request that we limit how we use your data

  • Right to data portability — request your data in a machine-readable format

  • Right to object — object to processing based on legitimate interests

  • Right to withdraw consent — where processing is based on consent, you may withdraw it at any time without affecting the lawfulness of prior processing

To exercise any of these rights, contact us at support@coachiapp.com. We will respond within 30 days. If you are unhappy with our response, you have the right to lodge a complaint with the Information Commissioner’s Office (ICO) at https://ico.org.uk or, for EU users, with your local supervisory authority.

11. Future Changes to Data Collection

We intend to introduce social login functionality (Sign in with Apple and Sign in with Google) in a future version of Coachi. When this feature is released:

  • Your name and email address will be collected and associated with your account

  • This privacy policy will be updated before that version is submitted to the App Store

  • The Apple App Store privacy nutrition label will be updated to reflect the additional data types

You will be notified of the changes and, where required, asked to provide fresh consent

Apple requires that any app offering third-party social login must also offer Sign in with Apple. Both options will be offered simultaneously when social login is introduced.



© 2025 Sport Autonomy — Coachi: Ski instructor in your pocket.