Privacy Policy
Boxing Fitness AI ("we", "our", or "us") is committed to protecting your privacy worldwide. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Boxing Fitness AI mobile application (the "App"), available globally through the Apple App Store. It complies with applicable data protection laws worldwide, including the EU General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), California Online Privacy Protection Act (CalOPPA), Personal Information Protection and Electronic Documents Act (PIPEDA — Canada), Loi 25 (Quebec, Canada), Lei Geral de Proteção de Dados (LGPD — Brazil), Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP — Mexico), and other applicable regional privacy laws.
1. Definitions
Capitalized terms in this Policy have the following meanings:
- Account — the unique profile created for You to access the Service.
- App — the Boxing Fitness AI mobile application.
- AI Analysis Service — the third-party AI model (Google Gemini) used to analyze boxing technique from your video frames and pose data, and to power the in-app AI coach chat.
- Device — any device used to access the App (smartphone, tablet, etc.).
- Health Data — information relating to your physical characteristics, fitness activity, or performance, including weight, height, workout metrics, session scores, and coaching feedback.
- Pose Data — body-position and movement information (skeletal keypoints such as the position of your shoulders, elbows, wrists, hips, and knees over time) generated on your Device from your training video to evaluate boxing technique. Pose Data describes body geometry and motion; it is not used to identify you.
- Community Profile — the limited profile information shown to other users in the in-app leaderboard when community visibility is on: your display name, initials, profile photo (if set), level, experience points (XP), and ranking.
- Personal Data — information that identifies or can reasonably be linked to you as an individual, including Health Data.
- Usage Data — data collected automatically through use of the App, including device information, activity logs, and crash analytics.
- User Content — videos, images (frames), and other inputs you upload or submit through the App for analysis.
- We / Us / Our — Boxing Fitness AI, the operator of this App.
- You — the individual using the App.
2. Information We Collect
Personal Information You Provide
- Full name and email address (account creation and authentication)
- Password (stored encrypted; we never access your plain-text password)
- Profile details you choose to provide (e.g., age, weight class)
Health & Fitness Data
- Workout sessions (type, duration, intensity, rounds completed)
- Physical metrics you enter (weight, height, body measurements)
- Fitness goals and training preferences
- AI-generated coaching scores, metrics, and feedback from your sessions
- Caloric estimates and exercise logs
User Content (Video & Frames)
- Training videos you record and upload for AI analysis
- Still frames automatically extracted from your videos for technique analysis
Pose & Movement Data
- Skeletal keypoints (e.g., shoulders, elbows, wrists, hips, knees) detected from your training video to measure technique such as guard position, punch mechanics, and combinations
- Pose Data is generated on your Device using Google's MediaPipe on-device technology and is stored with your session; a compact summary of it is also sent to the AI Analysis Service alongside your frames to improve the analysis
Profile Photo & Community Information
- An optional profile photo (avatar) you choose to upload
- Display name, initials, level, experience points (XP), streaks, and ranking
- Your device time zone — used to anchor streaks and weekly rankings to your local calendar (we do not collect GPS or precise location)
Usage Data (Automatically Collected)
- Device type and operating system version
- App usage statistics and crash reports (anonymized)
- IP address (collected at login for security purposes only)
- Feature usage analytics
3. Legal Basis for Processing (GDPR / LGPD)
For users in the EEA and Brazil, we rely on the following legal bases:
| Purpose | Legal Basis |
|---|---|
| Creating and managing your account | Performance of a contract (Art. 6(1)(b) GDPR) |
| Providing AI boxing coaching | Performance of a contract (Art. 6(1)(b) GDPR) |
| Processing Health & fitness data | Explicit consent (Art. 9(2)(a) GDPR) |
| Sending video frames and pose data to AI Analysis Service | Performance of a contract (Art. 6(1)(b) GDPR) |
| Powering the in-app AI coach chat | Performance of a contract (Art. 6(1)(b) GDPR) |
| Displaying your Community Profile in the leaderboard | Legitimate interest, with an opt-out in Settings (Art. 6(1)(f) GDPR) |
| Improving the App and fixing bugs | Legitimate interest (Art. 6(1)(f) GDPR) |
| Fraud detection and security | Legitimate interest (Art. 6(1)(f) GDPR) |
| Complying with legal obligations | Legal obligation (Art. 6(1)(c) GDPR) |
You may withdraw consent for Health Data processing at any time by deleting your account or contacting us. Withdrawal does not affect lawfulness of prior processing.
4. How We Use Your Information
- Create and manage your account
- Provide personalized AI-powered boxing technique coaching
- Analyze your training videos to generate scores and feedback
- Track your progress over time and generate training recommendations
- Power the in-app AI coach chat that answers your training questions
- Generate your weekly training plan and daily drills
- Show the community leaderboard and your ranking (when community visibility is on)
- Send transactional emails (account confirmation, password reset)
- Send optional promotional communications (you may opt out at any time)
- Detect and prevent fraud or unauthorized access
- Improve and debug the App's features and performance
- Comply with our legal obligations worldwide
We do not use your Health Data or User Content for advertising.
5. User Content & License
You retain full ownership of your User Content (training videos, frames, and pose data). By submitting User Content, you grant us a worldwide, royalty-free license to store, process, and transmit it solely to provide the App's services — including sending frames and a summary of your Pose Data to the AI Analysis Service for technique evaluation. We do not publicly display your training videos, frames, or pose data. Your profile photo, display name, level, XP, and ranking are shown to other users in the community leaderboard only while community visibility is on — you can turn this off at any time in Settings.
AI training: We do not use your User Content to train any proprietary AI model of our own. Your frames, pose summary, and coach-chat messages are sent to Google's Gemini API for inference only (to return your analysis or coach reply). Because we use the paid tier of the Gemini API, Google does not use this data to train or improve its models; see Section 6.
6. AI Analysis Service — Google Gemini
The App uses Google's Gemini AI (Gemini 2.5 Flash, via the Google Gemini API) to analyze boxing technique and to power the in-app AI coach chat. When you upload a training video, our system:
- Extracts a small number of still frames (typically around 6) from your video
- Builds a compact summary of the Pose Data captured during your session
- Transmits those frames and the pose summary securely to Google's Gemini API over an encrypted connection (TLS)
- Receives a structured analysis (scores, metrics, coaching feedback) in return and stores it in your account
When you use the AI coach chat, your messages — along with a short summary of your profile and recent sessions — are sent to the same Gemini API to generate the coach's reply.
Google processes this data as a service provider to return the analysis or reply. We use the paid tier of the Gemini API; under Google's terms for paid services, Google does not use your prompts, frames, pose data, or responses to train or improve its AI models, and retains them only for a limited period for abuse monitoring and legal compliance. Google's handling of this data is governed by the Gemini API Additional Terms of Service and the Google Privacy Policy.
7. Sharing of Information
We do not sell, trade, or rent your Personal Data. We may share data only in these circumstances:
- AI Analysis Service (Google Gemini): Video frames, a pose-data summary, and coach-chat messages are sent to Google for analysis and coaching replies as described in Section 6.
- Infrastructure providers: Supabase (database and storage), RevenueCat (subscription management) — under strict data processing agreements.
- Other users (community): While community visibility is on, your Community Profile (display name, initials, photo, level, XP, ranking) is visible to other users in the in-app leaderboard. You can turn this off at any time in Settings.
- Legal requirements: When required by law, court order, or governmental authority in any applicable jurisdiction.
- Fraud prevention: With security or law enforcement partners when necessary to protect users or the integrity of the App.
- Business transfers: If we merge, are acquired, or sell assets, user data may be transferred. We will provide notice beforehand.
- With your explicit consent: In any other case, only with your permission.
We never sell Personal Data to third parties, including under the definitions of the CCPA and LGPD.
8. International Data Transfers
Your data may be transferred to and stored on servers outside your country of residence, including in the United States (Supabase, Google, RevenueCat). We ensure appropriate safeguards:
- EU/EEA users: Transfers are made under Standard Contractual Clauses (SCCs) approved by the European Commission.
- Brazilian users: Transfers comply with LGPD Art. 33 requirements.
- All users: Data is encrypted in transit (TLS 1.2+) and at rest (AES-256) regardless of storage location.
9. Your Privacy Rights
Depending on your location, you have the following rights:
All Users
- Access a copy of your personal data
- Correct inaccurate or incomplete data
- Delete your account and associated data (videos, health data, profile)
- Opt out of non-transactional communications
🇪🇺 GDPR — EU / EEA Users
- Data portability: Receive your data in a structured, machine-readable format
- Restriction of processing: Request we limit how we use your data
- Right to object: Object to processing based on legitimate interests
- Withdraw consent: At any time, for consent-based processing
- Lodge a complaint with your national Data Protection Authority (DPA)
🇺🇸 CCPA & CalOPPA — California Users
- Right to know what personal information we collect and how it is used or shared
- Right to delete personal information we hold about you
- Right to opt-out of the sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your CCPA rights
- Right to correct inaccurate personal information
This Privacy Policy is accessible via a clearly labeled "Privacy Policy" link. We do not track users across third-party websites or apps. To submit a CCPA request, contact us at ihoaiprolabs@gmail.com. We will respond within 45 days.
🇧🇷 LGPD — Brazilian Users
- Confirmation of the existence of processing
- Access, correction, anonymization, blocking, or deletion of unnecessary data
- Data portability to another service provider
- Information about entities with which we share data
- Right to revoke consent at any time
- Right to lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados)
🇨🇦 PIPEDA & Loi 25 — Canadian Users
- Access the personal information we hold about you
- Challenge accuracy and request corrections
- Withdraw consent to collection, use, or disclosure of your data
- Data portability (Quebec residents, under Loi 25)
- Lodge a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca, or with the CAI if you are in Quebec
🇲🇽 LFPDPPP — Usuarios en México (Aviso de Privacidad)
En cumplimiento con la Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), este documento funge como Aviso de Privacidad.
Responsable: Boxing Fitness AI · Contacto: ihoaiprolabs@gmail.com
Sus Derechos ARCO:
- Acceso: Conocer qué datos tenemos de usted y cómo los usamos
- Rectificación: Solicitar corrección de datos inexactos
- Cancelación: Solicitar eliminación de sus datos
- Oposición: Oponerse al uso de sus datos para fines específicos
Envíe su solicitud a ihoaiprolabs@gmail.com. Responderemos en un plazo no mayor a 20 días hábiles. También puede presentar queja ante el INAI en inai.org.mx.
To exercise any of the above rights, contact us at ihoaiprolabs@gmail.com.
10. Data Retention
We retain different types of data for different periods:
- Account & profile data: Retained while your account is active. Deleted within 30 days of a verified account deletion request.
- Training videos, frames & pose data: Stored in your account until you delete them or delete your account.
- Health & fitness data (scores, metrics, feedback): Retained while your account is active and deleted upon account deletion.
- Usage data & crash logs: Retained for up to 12 months, then anonymized or deleted.
- Backups: Retained for a limited period as part of standard data backup practices, then permanently deleted.
Some data may be retained longer where required by applicable law.
11. Deleting Your Data
You may request deletion of specific data at any time:
- Individual training sessions and videos
- Your full account and all associated data
- Health metrics and performance history
- Profile information
You can delete your entire account and its associated data directly in the App, under Settings → Delete Account. You may also request deletion by contacting us at ihoaiprolabs@gmail.com. We will complete the request within 30 days (20 business days for Mexican users).
12. Security
We implement industry-standard security measures including encryption in transit (TLS 1.2+) and at rest (AES-256), role-based access controls, and regular security reviews. Video frames sent to the AI Analysis Service are transmitted over encrypted connections and are not permanently stored by that service. No method of internet transmission is 100% secure. We encourage you to use a strong, unique password for your account.
13. Children's Privacy
The App is not directed to children under 13 (or under 16 in EU jurisdictions where applicable). We do not knowingly collect Personal Data from children below the applicable minimum age. If we become aware of such collection, we will delete the data promptly. Parents or guardians who believe we may have data from a child should contact us immediately.
14. Third-Party Services & Links
The App uses the following third-party services, each with their own privacy policies:
- Google (Gemini API): AI analysis of boxing technique and AI coach chat — policies.google.com/privacy
- Supabase: Database, authentication, and file storage — supabase.com/privacy
- RevenueCat: Subscription management — revenuecat.com/privacy
- Apple: App Store distribution and payment processing — apple.com/privacy
The App may also contain links to third-party websites. We do not control, endorse, or accept responsibility for the privacy practices of those sites. We encourage you to review their policies.
15. Cookies & Tracking
The App itself does not use cookies. We may use anonymous analytics SDKs to understand usage patterns and improve the App. These tools do not track you across third-party apps or websites and do not build advertising profiles.
16. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of significant changes by updating the "Last Updated" date above and, where required by law, by sending a notification through the App or requesting renewed consent. Your continued use of the App after changes take effect constitutes acceptance of the revised policy.
17. Contact Us
For any questions, rights requests, or privacy concerns:
- Email: ihoaiprolabs@gmail.com
- App: Boxing Fitness AI
EU/EEA users may contact their local Data Protection Authority (DPA) if they believe their rights have not been adequately addressed.