Privacy Policy

Last updated: 15 August 2026

This policy explains what StrikeLab collects, why it collects it, and what control you have over it. It covers the StrikeLab iPhone app and this website (strikelab-app.com). In this policy, "StrikeLab", "we" and "us" mean the developer of the StrikeLab app, reachable at unfold.apps@gmail.com.

The short version

  • Your camera feed never leaves your iPhone. Punch and movement detection runs entirely on the device, and no photo or video is recorded, saved or uploaded.
  • We store the results of your training (scores, streaks, progression, ranking position), not the footage that produced them.
  • We use analytics and crash reporting to fix bugs and improve the training modes.
  • We do not sell your personal information, and we do not run third party ad networks.

Camera and motion data

StrikeLab needs camera access to work. When you start a drill, the front camera feed is analysed on your iPhone using Apple's on-device vision and machine learning frameworks to estimate body position and recognise punches, guards, slips and footwork.

Frames are processed in memory and discarded immediately. StrikeLab does not record video, does not write images to your photo library, and does not transmit any camera data to us or to any third party. What leaves your device is only the derived result of a round, for example the number of punches thrown, timing accuracy, technique score and round outcome.

You can revoke camera access at any time in iOS Settings, Privacy and Security, Camera. Interactive drills will not function without it, since there is no other way for the app to see your movement.

Information we collect

Account and device identifiers

When you first open StrikeLab, an account is created for you through Firebase Authentication so that your progress can sync and your ranking can be attributed to you. This account holds an identifier, and, if you choose to sign in, the identifier or email address supplied by your sign-in provider. If you set a display name for the leaderboards, that name is stored with your account and is visible to other players.

Training and progression data

Round scores, punch counts, combination accuracy, Shadow mode analysis results, session length, streaks, achievements, unlocked content and your position in the global rankings are stored in our Firebase backend so that they persist across sessions and devices.

Analytics and crash reports

We use Firebase Analytics and crash reporting, together with the aggregate statistics Apple provides in App Store Connect. These tell us which drills are used, where users drop out of a session, and what caused a crash. They include technical information such as device model, iOS version, app version, coarse region, session timing and error traces. We use this to fix problems and decide what to build next.

Purchases

StrikeLab Pro is billed by Apple through the App Store. Apple handles the payment and tells the app whether your subscription is active. We never see or store your card number, billing address or Apple ID password.

Support messages

If you email support, we receive your email address and whatever you include in the message, and we keep the thread so we can follow up.

This website

strikelab-app.com is a static site. It sets no advertising or tracking cookies and asks you for no personal information. Our host, Vercel, keeps standard server logs (IP address, user agent, requested page) for security and operational purposes.

How we use this information

  • To run the app: score rounds, save progress, unlock content and rank players.
  • To keep leaderboards fair and detect manipulated results.
  • To diagnose crashes, fix bugs and improve detection accuracy and drill design.
  • To confirm your subscription status and provide the Pro features you paid for.
  • To answer support requests.

Where the GDPR applies, our legal bases are performance of a contract (running the app and your subscription), legitimate interests (security, fraud prevention, product improvement) and consent where required, for example for optional analytics under Apple's tracking permission.

Who we share it with

We do not sell personal information. We share it only with:

  • Google (Firebase), which provides authentication, the database that stores progression and rankings, analytics and crash reporting.
  • Apple, which distributes the app, processes subscription payments and provides aggregate App Store analytics.
  • Vercel, which hosts this website.
  • Authorities or other parties where we are legally required to do so, or where it is necessary to protect our rights or the safety of users.

These providers operate servers in several countries, including the United States, so your data may be transferred outside your country of residence. Transfers out of the EEA and the UK rely on the European Commission's standard contractual clauses or an equivalent safeguard offered by the provider.

How long we keep it

Account, progression and ranking data is kept while your account exists. Analytics and crash data is retained on the retention schedule of the underlying service, typically up to 14 months for analytics events and shorter for crash reports. Support email threads are kept for up to two years. If you ask us to delete your account, we remove your account record and training data, and your entries leave the leaderboards.

Your rights

Depending on where you live, you may have the right to access the personal data we hold about you, correct it, delete it, restrict or object to its processing, withdraw consent, and receive a copy in a portable format. Residents of California may request disclosure of the categories of information collected and may opt out of any "sale" or "sharing" of it, though we do neither.

To exercise any of these rights, including account deletion, email unfold.apps@gmail.com from the address linked to your account, or with your in-app display name so we can find the right record. We respond within 30 days. If you are in the EEA or the UK and you are not satisfied with our response, you can complain to your local data protection authority.

Children

StrikeLab is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we will delete it.

Security

Data in transit is encrypted with TLS, and stored data sits behind the access controls of Google Cloud and Firebase, with database rules that restrict each account to its own records. No system is perfectly secure, but we design the app to hold as little personal data as possible, which is why the camera feed never leaves your phone.

Changes to this policy

If we change how we handle your data, we will update this page and the date at the top. Material changes will also be announced in the app.

Contact

Questions about this policy or your data: unfold.apps@gmail.com.