Privacy
Privacy policy
This policy walks the same path you will walk: you pick up a phone, you film yourself swinging a club, and a piece of software looks at your body. At every step it tells you what we now know about you, where that knowledge sits, how long it stays, and how to end it.
Effective 12 August 2026Version 2.0Privacy Act 1988 (Cth)
Start where you would start
You are about to hand a camera a recording of your own body, in motion, probably in a garage or on a range mat, possibly in shorts. That is a bigger thing to hand over than an email address, and it deserves to be explained in the order it actually happens rather than in the order a compliance checklist would prefer.
So this page follows you. It begins with your phone in your hand and works outward from there, and it stops at the point where you have asked us to erase the lot. Where the law gives that step a name, we give you the name too, because you will need it if you ever want to argue with us in front of a regulator.
On the other side of this sits AI GOLF COACH PTY LTD, ACN 698 412 467, ABN 57 698 412 467, a proprietary company on the New South Wales register. Whenever this page says "we", that company is who it means. Whenever it says "you", it means the person filmed, the person doing the filming, or the person writing to us, and in most cases those are the same person.
This policy governs the website you are reading, the AI Golf Coach application on any platform we publish it to, and the mail you send to our published address. It does not govern Apple or Google, who run the stores and handle any payment under their own terms, nor your handset maker, nor your mobile carrier, nor anywhere you end up after following a link out of here.
How to read the present tense on this page
The application is in development, so everything below written in the present tense describes how it is being designed and how it will behave the day it ships. We are publishing it now, in advance, so that the first person who ever taps allow camera access has been able to read the terms of that decision beforehand rather than reconstructing them afterwards. It also means you can hold the shipped product against this page and tell us where the two disagree.
One deciding mind. Organisations here are not sorted into controllers and processors the way Europe sorts them, but you may still want to know whose decision any of this actually is. For everything described here, that is us. We handle no personal information on anybody else's behalf, we have no business customers issuing instructions, and no other organisation has a say in what happens to a recording of you.
You open the app and we still do not know you
Installing the application and analysing a swing on your own handset will not require an account, an email address, a phone number or a sign-in of any kind. That is a deliberate design decision, and it is also the position Australian Privacy Principle 2 pushes towards: where it is lawful and practicable, you get to deal with an organisation without identifying yourself. For local analysis it is entirely practicable, so you get it.
An account only becomes necessary if you want something that genuinely cannot work without one, such as having a recording processed on our servers, or being able to recover your own history on a replacement handset. At that point we ask for an email address and nothing else. We will not ask your age, your gender, your height, your handicap, your club membership or your home course as a condition of using the software, because none of those are needed to time a backswing.
If you offer information anyway, in a support message or a note attached to a swing, we will read it and then treat it under the same rules as everything else here. Australian Privacy Principle 4 deals with information nobody asked for. Where it emerges that collecting it ourselves would not have been lawful, and it forms no part of a Commonwealth record, it gets destroyed or has the identifiers taken out as soon as we spot it.
You film a swing and the file stays put
You prop the phone on a tripod, hit record, and swing. The video file that results is written by your phone into your phone's own storage, and it belongs to you in exactly the way every other clip in your camera roll does. We do not copy it, index it, back it up or transmit it as a consequence of you recording it.
To analyse that clip, the application reads it and runs a pose model over the frames on the device itself. In that mode there is no upload, no background sync, no silent trickle of frames to a server for quality assurance, and no moment at which a file of you swinging leaves the handset without you having asked for that specifically. Analysis happening locally is the default, not a paid tier and not a setting buried three screens deep.
The application will ask your operating system for camera access, for permission to read the clip you point it at, and for permission to write its own output. Those permissions are granted by you, are visible in your system settings, and can be withdrawn there at any time without asking us. Withdrawing camera access stops new recordings; it does not by itself delete recordings you already made, which is what the deletion section further down is for.
Video of an identifiable person is personal information under Australian law. It does not stop being personal information because it is about a sport, because your face is small in the frame, or because you filmed it yourself. We treat every clip that reaches us on that footing, and the length of this page is mostly a consequence of taking that sentence seriously.
The model turns you into about thirty dots
Here is what the analysis actually produces. The pose model looks at each frame and places a small set of landmarks on your body, the sort of thing you would draw as dots on a stick figure: ankles, knees, hips, shoulders, elbows, wrists, and a handful of points around the head. Repeat that across a few hundred frames and you have a table of coordinates over time. That table, plus the timing of the frames, is what the coaching output is built from.
Those landmarks describe a body, which is why we handle them with the same care as the video rather than treating them as anonymous numbers. Being precise about what they are not is worth a moment. They are not a face template. They are not a fingerprint, an iris pattern, a gait signature or anything else designed to recognise you again later. The application does not match one person's landmarks against another's, does not attempt to identify anybody, and builds no template capable of doing so.
That distinction matters legally as well as practically. The Privacy Act treats biometric information as sensitive information when it is used for biometric verification or identification, and treats biometric templates the same way. We deliberately stay on the other side of that line: pose landmarks are used to describe motion for coaching, never to establish who somebody is. If that ever changes, it would be a new purpose requiring fresh consent from you, and it would be written on this page before it shipped, not after.
We also do not attempt to infer anything about your health from your body. Nothing in the software will tell you that your back hurts, that you have an impingement, that you are carrying an injury, or that your posture indicates a condition. Health information is sensitive information under the Act, it is the single easiest thing for a swing analyser to start inventing, and we have chosen not to have that feature at all.
A guess about your body is still about you
Some of what the application reports is measured and some of it is estimated, and the difference has a privacy consequence that most software of this kind quietly ignores. Frame timing is measured: the file records when each frame was captured, so the interval between the top of your backswing and impact is a real number. Where your knee appeared inside the flat picture is observed. Those we can stand behind.
Shoulder turn, hip turn, spine angle, elbow angle and wrist hinge are different. To state any of those in degrees, a model has to take a flat picture and reconstruct depth from it, and it does that using assumptions about how human bodies are proportioned on average. On you specifically, those assumptions may be wrong. They get worse the further the camera sits off your target line, worse again at close range on a wide lens, and worse still for a body the training data did not represent well.
An estimate produced that way is still a statement about you, held by us, and it is therefore personal information with all the rights attached that any other personal information has. You can ask to see it. You can tell us it is wrong. If it is wrong, we have an obligation under Australian Privacy Principle 10 to do something about it rather than shrug at the model.
So the application shows its working. Every derived angle appears with a confidence band, and with a plain warning where the camera position makes it unreliable. Where it cannot produce a figure it is willing to defend, it leaves the field empty and says why, rather than printing a confident number that happens to be wrong. We would rather look less impressive than teach you to trust a reading you should not.
What we refuse to derive from your video
There is a category of number that a single phone camera cannot produce honestly, and we do not produce it. Club head speed, ball speed, spin rate, launch angle, smash factor, face angle at impact and carry distance are all absent from the software. At ordinary phone frame rates the club head travels more than a metre between exposures near impact, and what reaches the sensor is a smear rather than an object with a measurable velocity.
Software that prints a speed in miles per hour from a phone clip is inferring it from your body motion and dressing the inference up as a reading. That is a marketing choice rather than a technical achievement, and it also generates a new personal-information record about you that has no defensible basis. Declining to make the number up is the privacy-respecting option as well as the accurate one, since the safest inference about you is the one nobody bothered to fabricate.
We also derive no profile of you across sessions beyond what you can see in your own history. There is no scoring of your ability against other users, no ranking, no segmentation for advertising, and no model of you as a customer sitting behind the one that looks at your swing. The application exists to describe what a body did in front of a lens, and the record we keep is bounded by that.
You decide to upload, and this is what goes
Sometimes local analysis is not enough. Your handset may be too old to run the model at a usable speed, or you may want a person to look at a swing rather than a machine. Either way, sending a recording to a server is a separate decision you make about one specific clip, on a screen that shows you the retention period next to the button, and it is never a background setting that silently applies to everything you film afterwards.
When you do send one, the package contains the video file itself, the frame timing and frame rate read out of it, the landmark table already described, the camera and lens metadata the file exposes, and a device model string so we can reproduce a problem on the right hardware. It also carries whatever note you typed to accompany it, because you wrote that on purpose.
Before any upload is offered, faces detected in the clip are blurred on your device. That happens locally, before transmission, and it applies to every face the detector finds rather than only to yours. Precise location is stripped from the file on the device as well: knowing which range you were standing on is of no use to a swing analyser, so it is removed rather than uploaded and ignored.
Australian Privacy Principle 3 holds us to gathering only what our functions reasonably require. Australian Privacy Principle 5 says you have to be told who we are and what is happening, at the time it happens or close to it. The upload screen is where we satisfy the second of those in the moment rather than by reference to a page you read weeks earlier, and the list above is what makes the first true.
Somebody else walks into your frame
Ranges are public, bays are shared, and the person setting up two mats down did not agree to anything. Anyone who appears in a clip you upload has the same rights over that footage as you do, whether or not they have ever heard of us, and this section exists so they can find out what those are.
If you appear in a recording somebody else made, you can write to us about it. No account is needed. Being a customer is not needed. Nor is establishing any connection to whoever uploaded it, past the point where we are satisfied that you are the person in shot and that you are asking in earnest. It gets handled on its substance, and you will never be asked to justify yourself to whoever uploaded it.
On your side of it, we ask you to be reasonable about what you film. If a recording captures somebody clearly and they would object, do not upload it. That is also a term of use, but it belongs here as well, because the practical protection for a bystander at a driving range is a person behind a phone deciding not to be careless with them.
Your swing trains nothing unless you say so
Your footage, the frames inside it, and the landmark table pulled out of it all stay away from model training, tuning, evaluation and improvement, unless you have said yes to exactly that, in a request that asks for nothing else alongside it. Agreeing to have a swing analysed is not agreeing to be learned from, and putting both behind a single checkbox is precisely the practice this paragraph exists to rule out.
If you do agree, the consent is revocable and revoking it is not a negotiation. Tell us and we stop using your material going forward and remove it from the training corpus we hold. We will tell you the honest limit of that too: where a model has already been trained on a dataset that included your recording, withdrawal removes you from the data and from all subsequent training runs, but it does not reach back into weights already computed. We will not pretend otherwise, and we will not use that limitation as a reason to refuse the request.
There is no arrangement anywhere under which your recordings are sold, licensed, contributed to a shared dataset, or handed to a third party building models of their own. There is an obvious second business in a large corpus of swing footage, and we have decided not to be in it. The revenue model is people paying for software, which points our incentives in the same direction as yours.
The dull information we also end up with
Not everything about you is video. Write to us and we then hold your address, the contents of what you sent, and the exchange that grows out of it. An inbox cannot work any other way. If you create an account, we hold the address you registered and a record of the consents you have given or withdrawn, since being able to prove what you agreed to is part of respecting it.
If the application crashes and you choose to send the report, we receive a diagnostic bundle: the error, the point in the code it happened at, the operating system version and the device model. That bundle is designed to carry no video, no frames and no landmark data. Sending it is your choice each time and the software runs perfectly well if you always decline.
Should paid features ever exist, the card details will belong to Apple or Google, not to us. Store purchases are processed entirely by the store, we never see a card number, and what would reach us is a receipt identifier and the fact that a subscription is active. If we ever bill anybody outside a store, this page will be updated to name the payment processor before that happens rather than afterwards.
Reading this website leaves almost no trace
The pages you are reading now set no cookies, run no analytics, embed no tracking pixel, load no advertising network and contain no social media button that phones home. No consent banner appears, for the simple reason that nothing exists to put in one. That absence is deliberate and we mean to keep it, rather than a job nobody has got round to.
Two things still happen that you should know about. Our host records ordinary server logs in the course of serving a page to you, which is how any web server works. And the lettering comes from Google's font service, so a request from your browser lands on a Google domain, where Google's servers can see it. The cookie notice sets out both in detail, including how to stop the second one at your end.
The law we are answering to
An Australian company handling Australian personal information answers to the Privacy Act 1988 (Cth), and the working rules inside it are the thirteen Australian Privacy Principles that Schedule 1 sets out. Where this page says "APP 6" or similar, it means the corresponding numbered principle in that schedule.
Several other Commonwealth statutes bear on what we do. Part IIIC of the Privacy Act carries the Notifiable Data Breaches scheme, which has a section of its own further down. The Spam Act 2003 (Cth) governs commercial electronic messages and the consent, identification and unsubscribe requirements attached to them. The Do Not Call Register Act 2006 (Cth) sits over telemarketing, an activity wholly absent from this business. The Privacy and Other Legislation Amendment Act 2024 (Cth) brought in the statutory tort described near the end of this page, along with a Children's Online Privacy Code whose substance we expect to follow whatever its final reach turns out to be.
The Australian Information Commissioner publishes guidance on all of this, and where the guidance and our own preference differ we follow the guidance. Nothing on this page is intended to give you less than the Act gives you, and if we have drafted something that reads that way, the Act wins and we will fix the wording.
We could claim an exemption and we are not going to
Here is an awkward fact we would rather you heard from us. Section 6D of the Privacy Act lets most businesses turning over three million dollars a year or less sit outside the Australian Privacy Principles altogether. This company sits under that line, and a lawyer could tell you we are not currently bound by most of what this page promises.
We are writing it as though we were bound in full, and we will handle every request and complaint on that basis. Three reasons. The exemption is an accident of our turnover rather than a finding that video of your body matters less than video of somebody else's. Several carve-outs inside section 6D would drag a business like this one back under the Act as it grows anyway, and the two likeliest to catch us are trading in personal information and supplying a health service. And the only promise worth putting in public is one made while it still costs nothing to make.
Should the Act one day bind this company by operation of law rather than by our own election, not a line here would need altering. That is precisely why it is drafted this way today.
Where each of the thirteen principles turns up
Since the principles are numbered and this page is not, here is the map between them. APP 1 requires open and transparent management of personal information and a clearly expressed, up-to-date policy, which is the document you are reading. APP 2 lets you deal with us anonymously or under a pseudonym, honoured by never demanding an account for analysis done on your own handset. APP 3 limits what we may collect to what we reasonably need, and sets a higher bar for sensitive information, which we address by not collecting health information at all.
APP 4 handles information nobody solicited, obliging us to destroy or de-identify whatever we could not lawfully have gathered ourselves. APP 5 requires notification at the point of collection, which the upload screen provides in the moment. APP 6 confines use and disclosure to the purpose we collected for, or a related purpose you would reasonably expect. APP 7 governs direct marketing, dealt with by not doing any.
APP 8 is the overseas disclosure rule and has its own section below, as does section 16C of the Act which makes us answerable for what those recipients do. APP 9 puts limits on adopting and using government related identifiers, none of which we collect. APP 10 asks that what we hold be correct, current and whole, which is the reason confidence bands exist at all. APP 11 asks for sensible security, and for information to be destroyed or stripped of identifiers once its purpose has run out.
APP 12 is your way in to what we hold, and APP 13 is your way of putting it right. Both get a section of their own. That is the full set, and if you think one of them is not being honoured here, that is exactly the kind of complaint we would like to receive.
Why we use any of it
We use your recordings and landmark data to produce the analysis you asked for, and to show you your own history so you can compare one session against another. We use crash reports and device strings to find and fix defects. We use your email address to answer you and to send the transactional messages an account needs, such as confirming a deletion has completed. Where you have consented to model training, we use what that consent covers and nothing beyond it.
We also use what we have to meet obligations that are not optional: responding to a request or complaint, keeping the records the Act expects us to keep about breaches and consents, and complying with a lawful demand from a court, a regulator or a law enforcement agency acting within its powers. If such a demand arrives we will tell you unless we are legally prohibited from telling you, and we will not read a request that merely sounds official as an order we are obliged to obey.
APP 6 is the boundary here: information collected to analyse your swing gets used to analyse your swing and for purposes you would reasonably expect to follow from that. It does not get quietly repurposed into something you would be surprised by. Where we want to do something genuinely new with it, we come back and ask.
Who else gets to see it
Nobody buys anything from us. Personal information is not sold, rented, bartered or contributed to any data pool, and no advertising network receives anything about you from us in any form at all.
What does exist is a short list of suppliers who make the software run. There is a hosting and storage provider, which is where an uploaded recording physically sits. There is a mail provider, which carries messages between you and us. There is an error reporting service, which receives crash bundles. And the app stores handle distribution and any payment. Each of them is engaged under terms that bind them to act on our instructions, to keep the information secure, and not to use it for their own purposes.
The list is short on purpose, and we would rather add a section to this page than a supplier to that list. When a new one becomes necessary, this page changes before the switch is flipped, not in a quarterly review afterwards.
Some of those companies are not in Australia
Where we can choose an Australian region for a service, we choose one, and uploaded video is stored in Australia. But parts of the supply chain sit elsewhere. Mail infrastructure, error reporting and support tooling are commonly operated from the United States or the European Union, and a supplier's own staff may access systems from wherever they happen to be.
APP 8 is the rule for overseas disclosure, and it applies the moment personal information about you goes to a recipient outside Australia. Sensible steps have to be taken beforehand to make sure the recipient will not break the principles. Ours run through the data processing terms each provider publishes, which tie them down on what the data may be used for, how it is secured, who they may pass it to, and when it is deleted.
An exception sits in APP 8.2(a) for recipients in countries whose laws are substantially similar, and we leave it alone. Working out whether a particular jurisdiction qualifies is a legal judgement we are not equipped to make for you, and the effect of relying on it would be to reduce what you can hold us to. So we sit on the default, which section 16C of the Act would impose on us regardless. Should an overseas recipient handle your information in a way that would have broken the Australian Privacy Principles here, the breach counts as ours, and your complaint comes to us. Being answerable in Australia for what a supplier does elsewhere is the arrangement we want, because it is the one you can actually enforce.
How long each thing lives
A recording you uploaded is kept for the period shown on the upload screen at the time you sent it, and the default is the shortest one that lets you actually use the result. When that period ends it is deleted automatically, without you asking and without a reminder email inviting you to extend it. You can delete it earlier from inside the application at any point.
Landmark data derived from a recording is kept with the recording and goes when it goes, except where you have asked us to retain your history, in which case the numeric series stays until you delete the account. Your account record and consent history last as long as the account and are removed with it. Crash reports are kept for twelve months, which is long enough to find a pattern in a rare fault.
Correspondence lasts longer than you might expect, and for a reason. Ordinary support threads are kept for 24 months. Complaint threads, including anything that touched a privacy request, are kept for 7 years, because if you ever take a complaint about us to the regulator, the file has to still exist for the regulator to look at. Anything a law obliges us to retain sits for exactly as long as that law says, then goes.
Backups are the honest caveat on all of the above. Deleting something removes it from the live systems immediately, and it then persists in encrypted backups until those rotate, which completes within 35 days. Nothing deleted is ever restored from a backup into live use. APP 11 says that when nothing we are permitted to do with information remains to be done, it gets destroyed or stripped of anything identifying. The retention periods above are how that obligation is actually operated.
We do not want your licence number
APP 9 stops an organisation adopting a government related identifier as its own handle for you, and narrows to a few situations the times it may use or pass one on. We keep out of that territory entirely: no tax file number, no Medicare number, no driver licence number, no passport number and no other government issued identifier is collected, requested or used as a way of identifying you to us. If you send one to us in a message, we will remove it and ask you not to do it again.
Keeping it accurate, estimates included
APP 10 sets a quality bar at both ends. What arrives has to be correct, current and not missing pieces; whatever we then act on or hand onward has to be relevant to the job as well. For an email address that is a simple obligation. For a shoulder turn figure produced by a model working from a flat picture, it is more interesting, and we would rather engage with that than pretend the principle does not reach inferences.
Our answer has three parts. We publish, on the home page, which signals are measured and which are estimated, so nobody has to guess which category a number falls into. We attach a confidence band to every derived angle inside the application, so an unreliable figure announces itself. And we treat a disputed estimate as a correction request under APP 13 rather than as a support ticket about model performance, which means it gets the process and the timeframe described below.
Security, and the parts we cannot promise
APP 11 requires reasonable steps to protect what we hold from misuse, interference, loss and unauthorised access, and the honest way to describe our steps is to start with what we avoid holding. Analysis runs locally by default, so most recordings never become our problem. We do not collect health information. We collect no government identifiers. We store no card numbers. For an outfit this small, the strongest control going is simply owning very little that anybody would want.
For what we will hold, these are the commitments the build is being held to. Uploaded recordings encrypted in transit and at rest. Access to production systems restricted to the people who need it and protected by multi-factor authentication. Administrative actions logged. Dependencies patched on a schedule rather than when something breaks. Backups encrypted, with the restore path tested rather than assumed. Read that list as the standard we are to be held to rather than as a report on something finished.
What we will not tell you is that any of this makes a breach impossible, because it does not. If you find a weakness, write to us with the subject line Security. Chasing a false alarm costs us an afternoon; missing a real one costs you. Report something in good faith and it will never be treated as hostile.
Asking what we hold, and saying it is wrong
APP 12 is your right to look at the personal information held about you. APP 13 is your right to have it put right. Both are free. Email us, head it Privacy request, and if the settings screen has handed you a support identifier, quote it. Your records surface faster that way.
We will confirm we have the request, check that you are who you say you are in a way proportionate to what is being asked for, and answer within 30 days. Identity checking happens inside that window rather than being added on top of it. What comes back is the actual content, in a form you can read and keep, not a summary of the categories of data we hold.
If you are telling us something is wrong, say what is wrong and what the right version is, and we will correct it and tell you when it is done. Should the wrong version already have gone out to somebody else, ask us to tell them about the fix and we will, unless doing so would be unlawful or genuinely cannot be managed.
Both principles have narrow grounds for refusal, and if we ever rely on one you will get written reasons, the specific ground, and the route to challenge it, all inside the same 30 days. Where we cannot give you access in the form you asked for, we will look for another way to get you the substance of it rather than treating the refusal as the end of the conversation. If we decline a correction, you can require us to attach a statement of your view to the record, and anyone who looks at it afterwards sees your version alongside ours.
Deleting one recording, or all of it
Deletion means the file is gone, not that a flag has been set on a row while the object quietly stays in a bucket. That distinction is the whole point of this section.
Any single recording can be deleted from inside the application whenever you like. Where a copy had reached our servers, it is removed from live systems within 7 days of the request, and it expires from encrypted backups on the ordinary rotation described above. We run that faster than the statutory response period on purpose, because video is the most sensitive thing here and a shorter clock is the correct default for it.
You can also delete your account outright, and account deletion takes with it the account record, the consent history, every recording still held, and the landmark data derived from them, subject only to material we are legally required to keep, which is limited to complaint files and anything a law obliges us to retain. If any of that survives your deletion request, we tell you what it is and when it goes. Would you rather not use the control inside the software? Send a message headed Delete my data, saying whether you mean a single clip or everything.
We are not going to email you about anything
Sending us a message puts you on no list. No newsletter exists. Neither does a product announcement list, nor a win-you-back sequence, nor any arrangement that hands your address to somebody running one. APP 7 restricts direct marketing using personal information, and the simplest way to satisfy it is to have nothing to restrict.
Should a mailing list ever exist, you would have to actively join it. Every message would name its sender and carry an unsubscribe link that works, which the Spam Act 2003 (Cth) demands in any event, and leaving would bite at once instead of after some stated number of working days. Nobody here telemarkets, so the Do Not Call Register Act 2006 (Cth) is a statute we stay well clear of. You can also ask us at any point to tell you where we got your details, and we will.
If it goes wrong, this is the clock we run
The Notifiable Data Breaches scheme is the machinery for this, and it sits in Part IIIC of the Privacy Act. It engages on what the Act labels an eligible data breach. Three things can set that off: somebody reaches information who had no business reaching it, information travels somewhere it should never have gone, or it is simply lost. On top of any of those, a sensible observer has to think somebody caught up in it is likely to come to serious harm. A breach involving video of people is exactly the kind that clears that bar, and we have planned for it accordingly.
The first move is containment. Shut off whatever is open, kill the credential behind it, pull a component out of service if the situation demands it. How the incident will read comes later. Then comes the assessment. From the moment there are grounds to suspect a breach might qualify, a 30 day clock runs, and inside it we have to settle whether it does. The Act wants that work done carefully and quickly at the same time, which in practice means starting the same day rather than after a week of internal discussion. Where what we did in response removes the likelihood of serious harm, the breach stops being notifiable, and the reasoning that got us there is written down.
If it does qualify, a statement goes to the Commissioner. That statement has to name this company and say how to reach us, describe what actually happened, set out which categories of information were caught up in it, and spell out the steps we think you should take. The Office of the Australian Information Commissioner gets it first, and then you do. Where reaching people one by one is workable, that is what happens. Where it genuinely is not, the statement goes up on this website and we take sensible steps to point people at it.
What you will get from us is a plain description of what happened, what was in it, and what you should do. It will not be padded with reassurance we have not earned, and where we do not yet know something we will say that we do not know it rather than filling the gap with something comfortable.
Children, and why a golf app must think about them
Golf is full of juniors, so pretending this is an adults-only concern would be silly. The application is intended for people aged 16 and over, and it is not designed, marketed or presented in a way aimed at younger children. We do not knowingly create accounts for under-16s, and we do not run age-gating theatre that collects a birth date and then ignores the answer.
If a parent, guardian or carer believes a child has an account or that footage of a child has been uploaded, write to us and we will find it, delete it and confirm that it is gone. We will not require the child's own cooperation, and we will not use the request as an opportunity to collect more information about the family than the deletion needs.
Where a child is old enough to understand what handing over a video of themselves means, their own consent can be meaningful; where they are not, it cannot, and a parent's involvement is required. A Children's Online Privacy Code is coming under the Privacy and Other Legislation Amendment Act 2024 (Cth). Waiting around to discover exactly which services it catches strikes us as the wrong instinct, so the aim is to be behaving acceptably before anybody makes us.
What Apple makes us declare
On iOS, an application that wants to track you across other companies' apps and websites has to ask through App Tracking Transparency, and you get a system prompt with a real refusal button. You will not see that prompt from us. We do not track you across other apps or websites, we do not access the advertising identifier, we run no advertising or attribution software development kits, and we share nothing with data brokers. There is no tracking to request permission for, so we do not request it.
Our App Store privacy labels will describe the video and derived pose data as data collected and linked to you when, and only when, you upload a recording, and will show local-only use where the analysis stays on your handset. Diagnostics will be declared as not linked to you. Nothing will be declared under the tracking category, because nothing belongs there. If a future version of the software ever needed that to change, the labels would change first and this page with them.
Apple also requires that a stated reason exists for each permission the software asks for. Camera access is to record a swing. Photo library access is to read a clip you select. That is the extent of it, and neither is used for any other purpose in the background.
What Google Play makes us declare
Google Play asks the same questions in a different shape, through the Data Safety section of the store listing. Ours will say that video and derived body-position data are collected when you upload a recording and not otherwise; that the data is encrypted in transit; that you can request deletion and can do it yourself in the application; that data is not shared with third parties for their own purposes; and that none of it is used for advertising or for any of the marketing purposes the form enumerates.
Where the form asks whether data collection is optional, the answer for video is yes, because local analysis works without any upload ever happening. Where it asks about account data, the answer is an email address, collected only if you choose to create an account. We will keep the Data Safety declaration matched to this page: if the two ever disagree, one of them is wrong and we want to be told.
Android permissions follow the same rule as on iOS. The application asks for camera and media access for the stated purpose and nothing else, and it does not request location, contacts, or any permission whose relevance to filming a golf swing you would struggle to explain.
You can now sue over privacy, separately from us
Most privacy policies do not mention this, and a right you have never heard of is not much of a right. Since 10 June 2025 there has been a statutory tort of serious invasion of privacy, brought into force by Schedule 2 to the Privacy and Other Legislation Amendment Act 2024 (Cth). It covers two kinds of wrong: prying into somebody's private affairs, and misusing information about them. Winning means showing the conduct was deliberate or reckless rather than merely clumsy, that anybody standing where you stood would fairly have expected privacy, and that the invasion was grave enough to outweigh whatever public interest points the other way.
That is a right you hold against anybody, including us, and it runs independently of the complaint process described in the next section. You do not have to come to us first, and choosing to complain to us instead does not waive it. We mention it because a company that is comfortable with the way it handles video should be comfortable telling you that this exists.
Complaining, first to us and then over our heads
Think something about you has been mishandled? Write to hello@aigolfcoach.im, put Privacy complaint at the top, and tell us what went wrong and what you want done about it. Receipt gets confirmed inside 5 business days, and a proper answer follows within 30. It will tell you what we found, what is being done about it, and what we are declining to do along with the reason.
Nobody here will ask you to sign a non-disclosure agreement before we will engage with a complaint, and having made one changes nothing about how anything else you ask us for gets handled.
Unhappy with the answer, or still waiting once 30 days have gone by? The regulator is the next stop. The Office of the Australian Information Commissioner takes privacy complaints about Australian organisations at GPO Box 5218, Sydney NSW 2001, on 1300 363 992, and through oaic.gov.au. Complaining costs nothing and does not require a lawyer or our consent. The Commissioner will usually want to see that you raised it with us first and gave us a month, though a complaint can be accepted without that where the circumstances warrant it.
You can also skip us entirely and go straight there. We would prefer the chance to fix it, but that preference is not a condition of anything.
If you are reading this outside Australia
Australian law is what this policy is drafted to, because Australian law is what binds the company. Nothing in it is meant to signal that rights you hold elsewhere are being refused, and the absence of a mention is not a denial.
Where the General Data Protection Regulation or its UK counterpart catches something we are doing, the rights it carries come with it. You can see what is held, correct it, have it erased, restrict what happens to it, take a copy elsewhere, and object outright, and you can complain to your own supervisory authority. Where the California Consumer Privacy Act as amended reaches us, it gives you the right to know what is held, to have it erased, to have it put right, and to opt out of any sale or sharing. That last one is quick to answer. Neither selling nor cross-context behavioural advertising happens here, in the particular senses that statute gives both phrases.
The practical rule is simple. Tell us what you are entitled to where you are, and we will answer the substance of it. Spending a fortnight establishing whether refusal was technically open to us is nobody's idea of a good use of time, least of all yours.
When this page changes
This policy will change, because the product does not exist yet and reality has a way of correcting plans. Whenever it does, the version and the date at the top move with it, and they move before the practice being described starts rather than once it is already running.
Where a change materially reduces what you get, or would extend an existing use of your information into something new, we will tell account holders directly rather than relying on you to notice a new date on a web page. Consent already given for model training is not carried over into a broader purpose by a policy update; a new purpose needs a new yes from you.
Writing to us
One address handles all of this: hello@aigolfcoach.im. Privacy requests, complaints, deletion, withdrawal of training consent, security reports and questions about anything on this page all arrive in the same inbox, and the subject line is what routes them. The contact page lists the subject lines and the time each one takes.
The company is AI GOLF COACH PTY LTD, ACN 698 412 467, ABN 57 698 412 467, registered in New South Wales, Australia. We do not publish a street address on this website; for formal service of documents, the registered office recorded against the ACN on the ASIC register is the one that counts, and it is available from that register.
The people who read that inbox are the people who build the software. If this company grows to the point where a dedicated privacy role exists, this paragraph will say who holds it.