VECTO Privacy Policy
VECTO turns a recording of your pickleball match into a highlight reel. The video analysis happens on your phone — we never receive your footage. This page explains the small amount of information that does reach our servers, exactly what each piece is for, and how to get rid of it. It is written to be read, not to be survived.
The short version
- Your match video is analysed on your phone and is never sent to us. The app has no code that uploads video, audio, or the data derived from them. There is one honest caveat about Apple's own iCloud Backup — it is in the next section, not buried.
- We store an account (your email address, and a name if your sign-in provider gives us one), a log of what you tapped, a consent record, and technical logs of whether analysis succeeded. All of it is text.
- One switch, in Settings, controls whether your clips may be used to improve the app — the same switch on every plan, free or paid, and turning it off is as easy as turning it on.
- We do not sell or share your personal information, do not show ads, and do not track you across other companies' apps or websites.
- You can delete your account inside the app, and it really deletes your rows. One pseudonymous, irreversible record survives to stop the free allowance being reset by deleting and re-registering — we describe it in full.
Who we are, and where this applies
VECTO is an independent iPhone app that makes pickleball highlight reels. This policy covers the VECTO app and the servers it talks to. It does not cover anything else — other companies' apps, the App Store itself, or what happens to a reel after you share it.
VECTO is offered in the United States only at this time, and this policy is written to United States law. If you are outside the US, the app is not being offered to you and this page has not been written for your jurisdiction.
For anything in this policy — questions, requests, complaints — write to support@vectopb.com. A person reads it.
Your video is analysed on your phone
This is the central design decision of the app, so it is worth being precise about what it does and does not mean.
When you record or import a match, the video is written to VECTO's own folder on your phone. Everything the app does with it — finding the players, following the rally, deciding where each point starts and ends, scoring which moments are worth keeping, and cutting the finished reel — runs on your device, using models that ship inside the app. There is no server-side processing step and no upload queue.
The app contains no code path that sends us:
- your match video, or any single frame of it;
- the audio recorded alongside it;
- the analysis data derived from it — player positions, rally boundaries, clip lists, the adjustments you make in the review screen;
- the finished highlight reel.
Being concrete about what "analysis" means, because it is more than watching pixels: to find the rallies, the app tracks where the players are on the court and how their bodies move — shoulders, hips, wrists — frame by frame. It does not try to work out who anyone is: there is no face recognition, no identification of players, and no attempt to match a person across matches or across users. All of that tracking data is produced on your phone, used on your phone, and stays on your phone.
On body tracking, specifically
Tracking how a body moves is the kind of thing privacy laws are increasingly written about, so rather than leave it at "we do not do face recognition", here is exactly what the app does and does not do with it:
- The points it tracks are joint positions in a video frame — where a shoulder or a wrist is, in pixels, at a moment in time. They exist to tell a rally from a pause and a smash from a dink.
- No face is detected, measured or recognised. The app contains no face detection of any kind.
- Nothing is built that could identify a person. There is no template, no signature, no profile, and no matching of a player to a name, an account, another match, or another user. Two people who look nothing alike produce the same kind of data, and neither can be picked out of it.
- It is discarded with the match. Delete the match and the tracking data goes with it. It is never sent anywhere, so there is no copy to delete on our side.
- This applies to everyone in frame — you, your partner, your opponents, and anyone on the next court who wanders through the shot. None of it identifies any of them.
We do not use body-tracking data to identify anyone, and we will not start without telling you first and asking again.
The only network destinations the app has are our database and the sign-in and purchase services run by Apple and Google. Everything we receive is listed by name in the next section, and every item on that list is text — no video, no audio, no images, and none of the tracking data described above.
The honest caveats
"Never leaves your phone" would be an overstatement, so here is the precise version. Your recordings, the analysis data, and your finished reels sit in VECTO's folder in your phone's Documents area. Three things can move them, and none of them involves us:
- Apple's iCloud Backup. If you have iCloud Backup switched on, iOS includes that folder in your device backup, the same way it backs up other apps' documents. Those copies go to your Apple account under Apple's terms — not to VECTO, and we have no access to them. You control this in the iOS Settings app.
- Saving to Photos. If you turn on "Save recordings to Photos", or save a finished reel, the file is copied to your photo library — which may in turn sync to iCloud Photos, again under your Apple account.
- Sharing. When you send a reel to someone or post it, you are sending it. Where it goes then is between you and whoever receives it.
You can also see and delete these files yourself: VECTO's folder is visible in the iOS Files app under "On My iPhone".
What we collect, and why
Six kinds of record, and that is the whole list. Each one is described below with what it holds and what it is for.
1. Your account
Signing in creates an account record. It holds:
- your email address;
- a name, if your sign-in provider passes one along (several do not, and the app
works fine without it — it falls back to the part of your email before the
@); - your plan — Free or Premium — and, for a paid plan, the date it expires;
- your monthly reel allowance on the free plan;
- your training-data preference and the moment you last set it;
- the dates the record was created and last changed.
The account is created automatically the first time you sign in. Its job is to tell the app which plan you are on and how many reels you have left this month. Your plan is set on our side and the app can only read it — the app cannot write it. We store no password. There is no password to store: sign-in is handled entirely by Apple and Google.
2. How you sign in
There are two ways in, and neither gives us a password:
- Sign in with Apple. Apple gives us your email address, plus your name on the
first sign-in only. If you choose Apple's Hide My Email, what we receive is an
anonymous
@privaterelay.appleid.comforwarding address, and that is all we ever have — mail we send still reaches you, your real address never reaches us. This is fully supported; nothing in the app needs your real address. - Continue with Google. Google gives us the email address and name on the Google account you pick.
Both flows happen inside Apple's or Google's own interface and hand us a signed token. What those companies choose to tell us, and what they record about the sign-in on their side, is governed by their privacy policies as well as this one.
3. Usage events — what you did in the app
The app records a short, structured event when you do certain things. Every event carries the event name, your account id, the app version, the time your phone recorded it and the time we received it, plus a handful of plain-text properties. Events are tied to your account, so they are not anonymous — but each one only ever describes your own use of VECTO.
This is the complete list of events the app sends:
| Event | Sent when | What it records |
|---|---|---|
sign_in |
You sign in. | Your training-data preference at that moment. |
match_analyzed |
A match finishes analysing on your phone. | The match's id on your phone, and whether it was a quick or a full analysis. |
reel_built |
You keep a finished reel. | Match id, your plan, and the settings used: length, format, clip order, transition, style, number of clips, the titles of any music tracks, whether you hand-trimmed clips, and whether the watermark was on. This event is also how your free monthly allowance is counted. |
clip_trimmed |
You nudge a clip's start or end in the review screen. | The size of the adjustment, which edge you moved, the running total for that clip, the clip's internal highlight score, and whether it was a mini reel. |
full_studio_unlocked |
The full reel studio opens for a match. | Match id. |
quota_blocked |
You hit the free monthly limit. | Match id. |
upgrade_intent |
You tap something that is Premium-only. | Which control or screen it was. |
paywall_shown |
The subscription screen appears. | Which screen sent you there. |
premium_purchase_tap,premium_purchased |
You start, and complete, a subscription purchase. | Which screen it started from, and which product. |
offer_redeem_sheet_opened,offer_redeemed |
You open, and use, a promotional offer code. | Which screen; the offer type and id, and the product. |
support_ticket_opened |
You send a support message from inside the app. | The number of characters in the subject line — not its text. |
What these events do not contain: no video, no audio, no analysis data, no location, no advertising identifier, no device fingerprint, no contact list, and nothing you typed. Match ids are the app's own local identifiers and are meaningless outside your phone.
Events are queued on your device and sent when you are online and signed in, so a session spent
offline arrives later rather than being lost. The queue holds at most 500 events; beyond that the
oldest are dropped. We use these events for exactly two things: seeing which features people
actually use, and — for reel_built — counting the free plan's monthly allowance.
4. Your consent record
Every time the "Allow my clips to improve the app" switch is set, we append a row recording the new setting, the version of this policy that was in force, and your plan at the time. The log is append-only by construction: rows can be added but never edited or erased in place. That is what makes it a trustworthy record of what you agreed to and when — including a record of you turning it off. It is deleted along with everything else if you delete your account.
5. Technical logs of analysis and reel building
When an on-device analysis or reel build finishes or fails, the app sends one row describing the
outcome: whether it was an analysis or a build, whether it succeeded, the match's local id, the
stage it reached, how long it took, an error message if it failed (truncated), your device model
(for example iPhone16,1), the app version, and the start and finish times.
This is how we discover that reel building is failing on a particular iPhone model, or that one stage has become slow, without waiting for someone to write in. It contains no video and no analysis content. These rows are best-effort — if one fails to send, it is dropped rather than retried.
6. Support messages
If you use Help & feedback in the app, we store the subject and message you typed (up to 200 and 4,000 characters), plus your plan, the app version and your iOS version, so we can reproduce the problem. Please do not put anything in a support message that you would not want kept.
One deliberate exception to deletion, stated here rather than in the fine print: support messages survive account deletion — but they are unlinked from your account, so what remains is the text you wrote with no account attached. We do this so an open support conversation can still be finished. If you would rather a support message be erased outright, email support@vectopb.com and we will delete it.
Purchases
Subscriptions are sold and processed by Apple through the App Store. We never see your card details, billing address, or Apple ID. When Apple confirms a subscription, the app tells our server which product you bought and when it expires; what gets written to your account is the resulting plan and that expiry date. Apple's transaction identifier is sent along with the request but is not stored. That is the whole of what we hold about a purchase.
Helping improve the app
Settings contains one switch: "Allow my clips to improve the app."
- It lives only in Settings. We do not ask for it during sign-in, because a choice put in front of you while you are trying to get into the product is not a choice you have really made.
- It is the same on every plan, free and paid alike. There is no tier on which the switch is decorative, and no tier on which contributing data is a condition of using the app.
- Turning it off is exactly as easy as turning it on — one tap, in the same place, at any time. Your most recent setting is the one that counts.
As the app ships today, this switch does not cause anything to be uploaded. VECTO currently has no mechanism to send us your video, audio, analysis data or clips — the section above describes what the software is able to do, not merely what we choose to do with it. Your setting records your preference for if and when such a feature is built. If we ever build one, we will update this page, raise its version, describe precisely what would be sent, and ask you again before anything leaves your phone.
Deleting your account
Settings → Delete account deletes your account from inside the app. No email, no form, no waiting period. It removes, immediately and permanently:
- your sign-in credentials and the account itself;
- your account record — email, name, plan, preferences;
- every usage event ever recorded for you;
- your entire consent history;
- every technical log row from your device.
Those rows are removed by the database itself as a direct consequence of the account being deleted, not by a cleanup job that might not run. We tested this end to end on a real device on 27 August 2026 and confirmed in the database that every dependent row went. Deletion cannot be undone, and we cannot restore the account afterwards.
Three things deliberately survive, and you should know about all three:
- Everything already on your phone. Your recordings, the analysis data derived from them, and the reels you built live on your device, not on our servers, so deleting your account does not touch them. That is on purpose — deleting an account should not destroy your own videos. To remove those, delete them in the app, delete them from the Files app, or delete the app itself. Reels already saved to Photos or sent to other people are likewise outside our reach.
- Support messages, unlinked from your account, as described above.
- One anti-abuse record, described immediately below.
The one record that outlives your account
The free plan allows a limited number of matches per calendar month, counted from your usage events. The unit is the match, not the reel: re-editing and rebuilding the same match as many times as you like costs nothing extra, and only the first reel from a given match uses part of your allowance. Because deleting an account erases those events, deleting and immediately re-registering would otherwise hand out a fresh monthly allowance every few minutes — an unlimited free plan for anyone willing to tap "delete" repeatedly. To prevent that, deleting your account writes a record containing exactly three things. If you have not built a reel from any match that month, no record is written at all — there would be nothing to carry forward.
- a salted, one-way cryptographic hash (SHA-256) of the identity you signed in with — one for your email address and one for each sign-in identity on the account, so a return through either route is recognised;
- the calendar month the deletion happened in;
- the number of matches already used that month.
What the record does not contain: your email address, your name, your account id, your device, or anything else. The hash is one-way and salted with a secret held in a part of the database that the app's own credentials cannot read at all. It cannot be turned back into your email address or any other identifier: someone holding the table alone learns nothing from it, and all the system itself ever does is compare it against a hash computed the same way when someone signs in.
Being exact about the limit, since a privacy policy that overstates its protection is worth less than one that admits an edge: a hash of this kind cannot be reversed, but anyone holding the secret could confirm a guess — take an email address they already suspected and check whether it matches. That is precisely why the secret is stored where the app cannot reach it, and why nothing in our own tooling is built to do it. We do not do it, and there is no purpose in the product that would be served by it.
What it is for, and nothing else: if the same identity signs up again during the same calendar month, the reels already used that month count against the new free account instead of resetting to zero. The record does not restore your deleted account, does not bring back any of your data, does not follow you into a later month, and is never used for analytics, advertising, profiling, or building any picture of you. It is consulted only for free accounts.
How long it lasts. A record stops having any effect once the month it covers has passed. Records older than the previous month are swept away — but the sweep runs as part of the next account deletion, so in a quiet month a spent record may sit unused for a while before it is removed. It cannot be matched to anything by then, but we would rather say so than imply a timer that does not exist.
We are disclosing this in detail because it is the one thing on this page that behaves in a way a reader would not assume: something survives a deletion that we told you was complete. It is pseudonymous, it is narrow, and this is the whole of it.
How long we keep things
| Record | Kept |
|---|---|
| Account | Until you delete your account. |
| Usage events | Until you delete your account. |
| Consent log | Until you delete your account. |
| Analysis / build logs | Until you delete your account. |
| Support messages | Kept after deletion, unlinked from your account, so open issues can be closed. Erased on request. |
| Anti-abuse record | Effective only for the month it covers; swept once the following month begins and another deletion triggers the sweep. |
| Your videos, analysis data and reels | On your device only, for as long as you keep them. |
Who else touches your information
The records described above are stored with Supabase, our database and authentication provider, in their East US (N. Virginia) region in the United States.
Our only other providers are Apple (Sign in with Apple, and App Store purchases) and Google (Google sign-in only). We use no advertising networks, no third-party analytics SDKs, and no crash-reporting services beyond the technical logs described above. The app does not track you across other companies' apps or websites, and contains no tracking domains.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are used in California and other US state privacy laws. We have never done so. We do not disclose your information to anyone other than the providers named here, each acting on our behalf to run the service, except where we are legally required to (for example, a valid legal order) or where it is necessary to protect someone's safety.
Your privacy rights
Depending on the US state you live in, you may have the right to know what personal information we hold about you and to get a copy of it, to have it corrected, to have it deleted, to opt out of its sale or of targeted advertising or of certain profiling (none of which we do), and not to be treated worse for exercising any of these rights. We honour these requests from every VECTO user in the United States, regardless of which state you are in — sorting people by ZIP code would cost more than simply saying yes.
You can do the two most important things yourself, immediately, without asking us:
- Delete everything — Settings → Delete account, in the app.
- Change your training-data preference — Settings, in the app.
For anything else — a copy of your data, a correction, a question about what we hold — email support@vectopb.com. We aim to answer within a few days, and in any case within 45 days, and we will tell you if we need the extension the law allows. If you authorise someone to make a request for you, we will need to confirm both that they are authorised and that you are you. If we have to decline a request, we will tell you why, and you can appeal that decision by replying to the same address; if we turn down your appeal you may be able to complain to your state attorney general.
Verifying a request usually means nothing more than sending it from the email address on the account. We ask for as little as possible to establish that, and we do not use anything you send us for verification for any other purpose.
For readers who want the California framing specifically: over the past twelve months we have collected identifiers (email address, name, account id), commercial information (your plan, subscription status, promotional offers used), and internet or other electronic network activity (the usage events and technical logs listed above), all directly from you or your device, all for the app-functionality and product-analytics purposes described alongside each item, and all retained for the periods in the retention table. We receive no sensitive personal information, no biometric identifiers and no precise geolocation — the on-device body tracking described above never leaves your phone — so there is nothing for us to limit the use of. We do not sell or share personal information, and we do not knowingly do so for anyone under 16.
Children
VECTO is not directed at children. You must be at least 13 years old to create a VECTO account, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we delete it.
If you are a parent or guardian and believe a child under 13 has created an account, write to support@vectopb.com and we will delete the account and its data. We do not sell or share the personal information of anyone under 16, and we do not use anyone's information for targeted advertising at any age.
People other than you
Pickleball is played in pairs, and your footage will usually contain other people. The app's on-device analysis follows everyone on the court, opponents included — that is how it finds the rallies. But because the footage and everything derived from it stay on your phone, we hold nothing at all about anyone who appears in your recordings: no faces, no names, no measurements, no record that they were ever there. Nobody is identified, and nothing is matched across matches or between users.
What you do with a reel is your decision and your responsibility. Once you export it or send it, it is outside our control and yours. Please be considerate about the people in it, and ask them first if you are going to post it somewhere public.
Keeping it safe
Every record described here is protected by row-level security rules enforced by the database itself: your app's credentials can insert only rows belonging to you, can read back only your own account row, and cannot read other people's data even in principle. The key embedded in the app is a public one, designed to be embedded, and it carries no privileges of its own. The anti-abuse table described above is reachable by no client credential at all.
No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach affecting your personal information, we will notify you and the relevant authorities as US state law requires.
Changes to this policy
If we change how we handle your data, we will update this page, change the version at the top, and add a line to the changelog below. For any change that meaningfully affects what we collect or what we do with it, the app will ask you again rather than relying on your old answer — and the version recorded against your consent tells us which policy you actually agreed to.
Contact
Questions, requests, corrections, or anything at all about this policy:
support@vectopb.com
Changelog
- 2026-09-01 — version 2026-09-01 (current)
- Added "On body tracking, specifically" to the on-device section, after an outside review pointed out that saying "no face recognition" leaves the more important question unanswered. It sets out what the joint-position data is, that nothing capable of identifying a person is built from it, that it is discarded with the match, and that it covers everyone in frame rather than only the account holder — plus a commitment not to start using it to identify anyone without asking again. Nothing about what the app does changed; this describes behaviour that was already true and was previously covered in one sentence.
- 2026-08-30 — version 2026-08-30
- Rewritten. The training-data switch is now described as one switch in Settings, identical on every plan and freely withdrawable; the earlier draft's distinction between free and paid plans has been removed entirely, because a setting you can turn off in Settings was never a condition of the free plan in the first place. Added the honest caveats about iCloud Backup, Photos and sharing, and a plain statement that the on-device analysis tracks players' bodies — opponents included — while identifying nobody. Added the support-message and security sections, and the full US state-privacy-rights section including the California categories disclosure. Corrected the anti-abuse record's retention: it is swept during the next account deletion, not on a fixed timer, so the previous "about two months" wording is gone, and stated the real limit of a salted hash rather than implying it is beyond anyone's reach. Corrected the response window to 45 days. Scope stated explicitly as United States only.
- 2026-08-28 — internal draft, never published
- First draft. Written against a plan model in which contributing training data was a term of the free plan and a choice on paid plans. That model was withdrawn before anything shipped, so the draft was replaced rather than amended. It was never published and no user ever saw it or agreed to it.