VECTO Privacy Policy

Last updated: 1 September 2026 · Version 2026-09-01 · United States

VECTO turns a recording of your pickleball match into a highlight reel. The video analysis happens on your phone — we never receive your footage. This page explains the small amount of information that does reach our servers, exactly what each piece is for, and how to get rid of it. It is written to be read, not to be survived.

The short version

Who we are, and where this applies

VECTO is an independent iPhone app that makes pickleball highlight reels. This policy covers the VECTO app and the servers it talks to. It does not cover anything else — other companies' apps, the App Store itself, or what happens to a reel after you share it.

VECTO is offered in the United States only at this time, and this policy is written to United States law. If you are outside the US, the app is not being offered to you and this page has not been written for your jurisdiction.

For anything in this policy — questions, requests, complaints — write to support@vectopb.com. A person reads it.

Your video is analysed on your phone

This is the central design decision of the app, so it is worth being precise about what it does and does not mean.

When you record or import a match, the video is written to VECTO's own folder on your phone. Everything the app does with it — finding the players, following the rally, deciding where each point starts and ends, scoring which moments are worth keeping, and cutting the finished reel — runs on your device, using models that ship inside the app. There is no server-side processing step and no upload queue.

The app contains no code path that sends us:

Being concrete about what "analysis" means, because it is more than watching pixels: to find the rallies, the app tracks where the players are on the court and how their bodies move — shoulders, hips, wrists — frame by frame. It does not try to work out who anyone is: there is no face recognition, no identification of players, and no attempt to match a person across matches or across users. All of that tracking data is produced on your phone, used on your phone, and stays on your phone.

On body tracking, specifically

Tracking how a body moves is the kind of thing privacy laws are increasingly written about, so rather than leave it at "we do not do face recognition", here is exactly what the app does and does not do with it:

We do not use body-tracking data to identify anyone, and we will not start without telling you first and asking again.

The only network destinations the app has are our database and the sign-in and purchase services run by Apple and Google. Everything we receive is listed by name in the next section, and every item on that list is text — no video, no audio, no images, and none of the tracking data described above.

The honest caveats

"Never leaves your phone" would be an overstatement, so here is the precise version. Your recordings, the analysis data, and your finished reels sit in VECTO's folder in your phone's Documents area. Three things can move them, and none of them involves us:

You can also see and delete these files yourself: VECTO's folder is visible in the iOS Files app under "On My iPhone".

What we collect, and why

Six kinds of record, and that is the whole list. Each one is described below with what it holds and what it is for.

1. Your account

Signing in creates an account record. It holds:

The account is created automatically the first time you sign in. Its job is to tell the app which plan you are on and how many reels you have left this month. Your plan is set on our side and the app can only read it — the app cannot write it. We store no password. There is no password to store: sign-in is handled entirely by Apple and Google.

2. How you sign in

There are two ways in, and neither gives us a password:

Both flows happen inside Apple's or Google's own interface and hand us a signed token. What those companies choose to tell us, and what they record about the sign-in on their side, is governed by their privacy policies as well as this one.

3. Usage events — what you did in the app

The app records a short, structured event when you do certain things. Every event carries the event name, your account id, the app version, the time your phone recorded it and the time we received it, plus a handful of plain-text properties. Events are tied to your account, so they are not anonymous — but each one only ever describes your own use of VECTO.

This is the complete list of events the app sends:

EventSent whenWhat it records
sign_in You sign in. Your training-data preference at that moment.
match_analyzed A match finishes analysing on your phone. The match's id on your phone, and whether it was a quick or a full analysis.
reel_built You keep a finished reel. Match id, your plan, and the settings used: length, format, clip order, transition, style, number of clips, the titles of any music tracks, whether you hand-trimmed clips, and whether the watermark was on. This event is also how your free monthly allowance is counted.
clip_trimmed You nudge a clip's start or end in the review screen. The size of the adjustment, which edge you moved, the running total for that clip, the clip's internal highlight score, and whether it was a mini reel.
full_studio_unlocked The full reel studio opens for a match. Match id.
quota_blocked You hit the free monthly limit. Match id.
upgrade_intent You tap something that is Premium-only. Which control or screen it was.
paywall_shown The subscription screen appears. Which screen sent you there.
premium_purchase_tap,
premium_purchased
You start, and complete, a subscription purchase. Which screen it started from, and which product.
offer_redeem_sheet_opened,
offer_redeemed
You open, and use, a promotional offer code. Which screen; the offer type and id, and the product.
support_ticket_opened You send a support message from inside the app. The number of characters in the subject line — not its text.

What these events do not contain: no video, no audio, no analysis data, no location, no advertising identifier, no device fingerprint, no contact list, and nothing you typed. Match ids are the app's own local identifiers and are meaningless outside your phone.

Events are queued on your device and sent when you are online and signed in, so a session spent offline arrives later rather than being lost. The queue holds at most 500 events; beyond that the oldest are dropped. We use these events for exactly two things: seeing which features people actually use, and — for reel_built — counting the free plan's monthly allowance.

4. Your consent record

Every time the "Allow my clips to improve the app" switch is set, we append a row recording the new setting, the version of this policy that was in force, and your plan at the time. The log is append-only by construction: rows can be added but never edited or erased in place. That is what makes it a trustworthy record of what you agreed to and when — including a record of you turning it off. It is deleted along with everything else if you delete your account.

5. Technical logs of analysis and reel building

When an on-device analysis or reel build finishes or fails, the app sends one row describing the outcome: whether it was an analysis or a build, whether it succeeded, the match's local id, the stage it reached, how long it took, an error message if it failed (truncated), your device model (for example iPhone16,1), the app version, and the start and finish times.

This is how we discover that reel building is failing on a particular iPhone model, or that one stage has become slow, without waiting for someone to write in. It contains no video and no analysis content. These rows are best-effort — if one fails to send, it is dropped rather than retried.

6. Support messages

If you use Help & feedback in the app, we store the subject and message you typed (up to 200 and 4,000 characters), plus your plan, the app version and your iOS version, so we can reproduce the problem. Please do not put anything in a support message that you would not want kept.

One deliberate exception to deletion, stated here rather than in the fine print: support messages survive account deletion — but they are unlinked from your account, so what remains is the text you wrote with no account attached. We do this so an open support conversation can still be finished. If you would rather a support message be erased outright, email support@vectopb.com and we will delete it.

Purchases

Subscriptions are sold and processed by Apple through the App Store. We never see your card details, billing address, or Apple ID. When Apple confirms a subscription, the app tells our server which product you bought and when it expires; what gets written to your account is the resulting plan and that expiry date. Apple's transaction identifier is sent along with the request but is not stored. That is the whole of what we hold about a purchase.

Helping improve the app

Settings contains one switch: "Allow my clips to improve the app."

As the app ships today, this switch does not cause anything to be uploaded. VECTO currently has no mechanism to send us your video, audio, analysis data or clips — the section above describes what the software is able to do, not merely what we choose to do with it. Your setting records your preference for if and when such a feature is built. If we ever build one, we will update this page, raise its version, describe precisely what would be sent, and ask you again before anything leaves your phone.

Deleting your account

Settings → Delete account deletes your account from inside the app. No email, no form, no waiting period. It removes, immediately and permanently:

Those rows are removed by the database itself as a direct consequence of the account being deleted, not by a cleanup job that might not run. We tested this end to end on a real device on 27 August 2026 and confirmed in the database that every dependent row went. Deletion cannot be undone, and we cannot restore the account afterwards.

Three things deliberately survive, and you should know about all three:

  1. Everything already on your phone. Your recordings, the analysis data derived from them, and the reels you built live on your device, not on our servers, so deleting your account does not touch them. That is on purpose — deleting an account should not destroy your own videos. To remove those, delete them in the app, delete them from the Files app, or delete the app itself. Reels already saved to Photos or sent to other people are likewise outside our reach.
  2. Support messages, unlinked from your account, as described above.
  3. One anti-abuse record, described immediately below.

The one record that outlives your account

The free plan allows a limited number of matches per calendar month, counted from your usage events. The unit is the match, not the reel: re-editing and rebuilding the same match as many times as you like costs nothing extra, and only the first reel from a given match uses part of your allowance. Because deleting an account erases those events, deleting and immediately re-registering would otherwise hand out a fresh monthly allowance every few minutes — an unlimited free plan for anyone willing to tap "delete" repeatedly. To prevent that, deleting your account writes a record containing exactly three things. If you have not built a reel from any match that month, no record is written at all — there would be nothing to carry forward.

What the record does not contain: your email address, your name, your account id, your device, or anything else. The hash is one-way and salted with a secret held in a part of the database that the app's own credentials cannot read at all. It cannot be turned back into your email address or any other identifier: someone holding the table alone learns nothing from it, and all the system itself ever does is compare it against a hash computed the same way when someone signs in.

Being exact about the limit, since a privacy policy that overstates its protection is worth less than one that admits an edge: a hash of this kind cannot be reversed, but anyone holding the secret could confirm a guess — take an email address they already suspected and check whether it matches. That is precisely why the secret is stored where the app cannot reach it, and why nothing in our own tooling is built to do it. We do not do it, and there is no purpose in the product that would be served by it.

What it is for, and nothing else: if the same identity signs up again during the same calendar month, the reels already used that month count against the new free account instead of resetting to zero. The record does not restore your deleted account, does not bring back any of your data, does not follow you into a later month, and is never used for analytics, advertising, profiling, or building any picture of you. It is consulted only for free accounts.

How long it lasts. A record stops having any effect once the month it covers has passed. Records older than the previous month are swept away — but the sweep runs as part of the next account deletion, so in a quiet month a spent record may sit unused for a while before it is removed. It cannot be matched to anything by then, but we would rather say so than imply a timer that does not exist.

We are disclosing this in detail because it is the one thing on this page that behaves in a way a reader would not assume: something survives a deletion that we told you was complete. It is pseudonymous, it is narrow, and this is the whole of it.

How long we keep things

RecordKept
AccountUntil you delete your account.
Usage eventsUntil you delete your account.
Consent logUntil you delete your account.
Analysis / build logsUntil you delete your account.
Support messagesKept after deletion, unlinked from your account, so open issues can be closed. Erased on request.
Anti-abuse recordEffective only for the month it covers; swept once the following month begins and another deletion triggers the sweep.
Your videos, analysis data and reelsOn your device only, for as long as you keep them.

Who else touches your information

The records described above are stored with Supabase, our database and authentication provider, in their East US (N. Virginia) region in the United States.

Our only other providers are Apple (Sign in with Apple, and App Store purchases) and Google (Google sign-in only). We use no advertising networks, no third-party analytics SDKs, and no crash-reporting services beyond the technical logs described above. The app does not track you across other companies' apps or websites, and contains no tracking domains.

We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are used in California and other US state privacy laws. We have never done so. We do not disclose your information to anyone other than the providers named here, each acting on our behalf to run the service, except where we are legally required to (for example, a valid legal order) or where it is necessary to protect someone's safety.

Your privacy rights

Depending on the US state you live in, you may have the right to know what personal information we hold about you and to get a copy of it, to have it corrected, to have it deleted, to opt out of its sale or of targeted advertising or of certain profiling (none of which we do), and not to be treated worse for exercising any of these rights. We honour these requests from every VECTO user in the United States, regardless of which state you are in — sorting people by ZIP code would cost more than simply saying yes.

You can do the two most important things yourself, immediately, without asking us:

For anything else — a copy of your data, a correction, a question about what we hold — email support@vectopb.com. We aim to answer within a few days, and in any case within 45 days, and we will tell you if we need the extension the law allows. If you authorise someone to make a request for you, we will need to confirm both that they are authorised and that you are you. If we have to decline a request, we will tell you why, and you can appeal that decision by replying to the same address; if we turn down your appeal you may be able to complain to your state attorney general.

Verifying a request usually means nothing more than sending it from the email address on the account. We ask for as little as possible to establish that, and we do not use anything you send us for verification for any other purpose.

For readers who want the California framing specifically: over the past twelve months we have collected identifiers (email address, name, account id), commercial information (your plan, subscription status, promotional offers used), and internet or other electronic network activity (the usage events and technical logs listed above), all directly from you or your device, all for the app-functionality and product-analytics purposes described alongside each item, and all retained for the periods in the retention table. We receive no sensitive personal information, no biometric identifiers and no precise geolocation — the on-device body tracking described above never leaves your phone — so there is nothing for us to limit the use of. We do not sell or share personal information, and we do not knowingly do so for anyone under 16.

Children

VECTO is not directed at children. You must be at least 13 years old to create a VECTO account, and we do not knowingly collect personal information from anyone under 13. If we learn that we have, we delete it.

If you are a parent or guardian and believe a child under 13 has created an account, write to support@vectopb.com and we will delete the account and its data. We do not sell or share the personal information of anyone under 16, and we do not use anyone's information for targeted advertising at any age.

People other than you

Pickleball is played in pairs, and your footage will usually contain other people. The app's on-device analysis follows everyone on the court, opponents included — that is how it finds the rallies. But because the footage and everything derived from it stay on your phone, we hold nothing at all about anyone who appears in your recordings: no faces, no names, no measurements, no record that they were ever there. Nobody is identified, and nothing is matched across matches or between users.

What you do with a reel is your decision and your responsibility. Once you export it or send it, it is outside our control and yours. Please be considerate about the people in it, and ask them first if you are going to post it somewhere public.

Keeping it safe

Every record described here is protected by row-level security rules enforced by the database itself: your app's credentials can insert only rows belonging to you, can read back only your own account row, and cannot read other people's data even in principle. The key embedded in the app is a public one, designed to be embedded, and it carries no privileges of its own. The anti-abuse table described above is reachable by no client credential at all.

No system is perfectly secure, and we will not pretend otherwise. If we ever discover a breach affecting your personal information, we will notify you and the relevant authorities as US state law requires.

Changes to this policy

If we change how we handle your data, we will update this page, change the version at the top, and add a line to the changelog below. For any change that meaningfully affects what we collect or what we do with it, the app will ask you again rather than relying on your old answer — and the version recorded against your consent tells us which policy you actually agreed to.

Contact

Questions, requests, corrections, or anything at all about this policy:
support@vectopb.com

Changelog

2026-09-01 — version 2026-09-01 (current)
Added "On body tracking, specifically" to the on-device section, after an outside review pointed out that saying "no face recognition" leaves the more important question unanswered. It sets out what the joint-position data is, that nothing capable of identifying a person is built from it, that it is discarded with the match, and that it covers everyone in frame rather than only the account holder — plus a commitment not to start using it to identify anyone without asking again. Nothing about what the app does changed; this describes behaviour that was already true and was previously covered in one sentence.
2026-08-30 — version 2026-08-30
Rewritten. The training-data switch is now described as one switch in Settings, identical on every plan and freely withdrawable; the earlier draft's distinction between free and paid plans has been removed entirely, because a setting you can turn off in Settings was never a condition of the free plan in the first place. Added the honest caveats about iCloud Backup, Photos and sharing, and a plain statement that the on-device analysis tracks players' bodies — opponents included — while identifying nobody. Added the support-message and security sections, and the full US state-privacy-rights section including the California categories disclosure. Corrected the anti-abuse record's retention: it is swept during the next account deletion, not on a fixed timer, so the previous "about two months" wording is gone, and stated the real limit of a salted hash rather than implying it is beyond anyone's reach. Corrected the response window to 45 days. Scope stated explicitly as United States only.
2026-08-28 — internal draft, never published
First draft. Written against a plan model in which contributing training data was a term of the free plan and a choice on paid plans. That model was withdrawn before anything shipped, so the draft was replaced rather than amended. It was never published and no user ever saw it or agreed to it.