Privacy Policy
Last updated: 2026-07-25
No account required
Shankdit works anonymously by default. The first time you upload a swing, we hand your browser (or the iOS app) a random session id and store it — as a cookie on web, in the device Keychain on iOS. That id is what proves you own a given swing later (so you can publish it or see it on your "me" page). Web also supports optional sign-in with your Apple ID; the iOS app is anonymous-only. If you never sign in, we have no way to independently verify that a deletion request actually belongs to you — see "Your rights" below.
What we collect
- Your uploaded swing video, stored in Vercel Blob.
- Four still keyframes (setup / top / impact / follow) extracted from your video, also stored in Vercel Blob.
- Pose/joint data: your device detects body-joint positions at each keyframe (on-device, in your browser) and we store the resulting coordinates to draw the stick-figure overlay. This is numeric joint-position data, not a face or identity signature.
- The AI-generated roast text and your handle (a generated nickname, or a custom one you choose).
- Your IP address and session id, logged solely to enforce daily upload limits and block abuse.
- Your account email, only if you sign in with Apple (web).
How your swing gets analyzed
Your video is sent to Google Gemini 2.5 Pro (routed through the Vercel AI Gateway) to generate the roast and coaching feedback — Gemini is currently the only major model we use that can read video directly. Before your roast text (and any custom handle you pick) can be published, it's screened by a second model, Anthropic Claude Haiku, also via the Vercel AI Gateway, to catch unsafe or abusive content. We do not send your video or roast text to any other AI provider.
Analytics
We use PostHog for product analytics — understanding which parts of the funnel (upload, roast, share, publish) people actually use. This is not advertising or ad-tracking. On iOS, we've turned off screen-view capture, element/click capture, and session replay — we only send the specific funnel events listed below. Events we log include: upload_started, upload_failed, roast_requested, roast_created, publish_panel_viewed, publish_opened, paywall_viewed, checkout_started, checkout_failed, checkout_needs_signin, roast_published, publish_failed, share_clicked, share_completed, and camera_failed. Their properties are things like sport, handedness, file size, duration, and coarse error labels — never your raw roast text or video content.
Retention
How long we keep things depends on what you do with a swing:
- Uploaded but never published, no account: deleted — video, keyframes, and the database record — 7 days after upload.
- Published to a leaderboard: kept indefinitely, since a published roast is a public artifact (see below).
- Uploaded while signed in:currently kept indefinitely. We don't yet have an account-deletion flow that removes these automatically — see "Your rights" for how to request removal manually.
Public leaderboard
Publishing a swing is public by design: your roast text, your handle, and a link to the playable video all become visible to anyone who views the leaderboard — no account or login needed to view it. Separately, every swing (published or not) can be viewed by anyone who has its link, since that link is how sharing works before you decide to publish. Don't publish, or don't share the link to, a swing you don't want strangers to see.
Camera & microphone
The iOS app requests camera access to record your swing, and microphone access solely to detect the sound of ball/club impact so we can automatically pick the right frame — we are not recording audio for any other purpose, and we don't transcribe or analyze speech.
Who processes your data
- Vercel — hosting, and video/keyframe storage (Vercel Blob).
- Supabase — our database and (for web sign-in) authentication.
- Google — Gemini, for roast/coaching generation.
- Anthropic — Claude, for content moderation.
- PostHog — product analytics.
Your rights
You can ask us to delete your data at any time by emailing support@shankdit.com with the link to your swing (or your account email, if you signed in). Because most usage is anonymous by design, we generally can only act on a deletion request for a swing if you can point us to it — we have no independent way to prove a given anonymous swing is yours. We are not making a claim of GDPR or CCPA compliance here; this section describes what we can practically do today.
Children
Shankdit is not intended for users under 13. We do not knowingly collect data from children.