Tennis Decision Engine

PRIVACY POLICY

Your planning data stays private by design.

Effective 18 September 2026. This notice describes the current TDE web service and packaged iPhone app.

What we collect

Optional coach connections store the recipient’s self-reported display name, account references, invitation status and access-change audit. Names are not identity verification. A connection code is stored only as a hash, expires after 7 days and is removed by daily cleanup 30 days after expiry. Invitations expire after 7 days; closed invitations are removed after 180 days, and unaccepted expired invitations 180 days after expiry. Accepted invitations remain while access is active. Access audit entries are removed after 180 days. Account deletion removes your connection codes and invitations and clears your attributable account references from this audit.

Team decision reviews and their replies are visible to people currently authorized to view that Career’s decisions. They include the author account reference, relationship role, time and a bounded saved-decision context. Do not include private financial, medical or verification material in a team message. Reviews follow the Career/account lifetime; deleting an account removes its authored review and response text while preserving other people’s shared work where applicable.

Team safety controls store account-to-account message blocks, action receipts and reports about a specific team message or reply. Reports include its text, reported account, reporter, category and optional private context. Only the reporter can see their report status; authorized moderators can inspect the report and captured text. The reported account does not receive your report or identity from this feature. Moderators may hide reported content from team views without changing its original record. Closed reports are removed after 180 days by daily cleanup; open reports remain until handled or account/Career deletion. Blocks and minimal action receipts remain until account deletion; unblocking removes the active block but retains the action receipt. Deleting either involved account removes its report copies, blocks and attributable action receipts.

Saved decision evidence is also kept in a Career archive so it remains available after the working plan changes. It includes the saved choice, model and source context, reason, author account reference, role and time. Authorized Career members can view it; private and financial fields follow their current permissions. Account deletion removes attributable archived decisions and their copies in working decision history. A restricted Career reference and decision ID remain, without the author or decision text, until that Career is deleted to prevent stale imports from restoring the same records. These deletion receipts are restricted metadata, not anonymous data.

Optional product usage sharing is off until you explicitly enable it in More. When collection is open and you opt in, TDE records bounded screen names, saved-decision events and coach-review-created events with your TDE account, Career reference where relevant, session reference, time, platform and app version when available. Usage events exclude private notes, message text, claim images and payment details. They are removed after 90 days by daily cleanup; turning the choice off deletes your previous usage events immediately from the active store. Provider backups follow their retention periods. Security and billing records are separate from this optional choice.

The current iPhone build does not sell data, show advertising, use advertising identifiers or track activity across other companies’ apps and websites. Push permission is optional; the current build does not persist an APNs token on TDE servers.

Why we use it

We use this information to authenticate you, provide and synchronize your private decision workspace, calculate and explain tournament options, secure the service, investigate failures and respond to support or privacy requests. We do not use private planning data for third-party advertising.

Service providers

Clerk provides authentication, Vercel hosts the application and Neon provides database infrastructure. Tournament, mapping and travel providers may receive bounded search facts such as locations, dates and routes from our servers; they do not receive your TDE session token or private notes. Providers may process technical information under their own infrastructure policies.

Career verification evidence

If you choose account verification, we process your claimed Instagram username and a short-lived code, or a private screenshot of your signed-in official player account. Do not submit passwords, recovery codes, passports or unrelated sensitive information. Images are normalized to remove metadata and encrypted on the server. Only authorized reviewers with recent multi-factor authentication can view them, and each view is audited. Image access expires after 30 days; encrypted images are removed by the next daily cleanup, or with account deletion. Operational backup copies follow provider retention periods. Review decisions and minimal security audit records may be retained for fraud prevention and disputes.

Storage and retention

Account and saved planning data are kept while your account is active or while needed to provide the service. A bounded Today snapshot may remain in the iPhone Keychain for up to 24 hours and is removed on sign-out, lost access or account deletion. Operational logs and infrastructure backups may remain for limited provider retention periods before deletion or overwrite. We retain information longer only when required for security, dispute resolution or law.

Your choices

Signed-in users can export their account data and initiate account deletion from Account settings. Deletion removes private TDE workspaces that can be safely removed, revokes TDE access and deletes the Clerk authentication identity. Shared or legacy-linked workspaces must be resolved first so another person’s data is not deleted. Files you previously downloaded must be removed by you.

After account deletion, we keep a restricted record of the authentication provider and a one-way hash of its account identifier to prevent deleted sign-in links from being recreated by an invitation. This record does not contain your email, raw provider identifier, password or session token. It is a security record, separate from deleted planning content.

You can decline push notifications in iOS Settings and continue using Today and online planning. Internal security audit records may be retained separately from deleted planning content for security or dispute resolution.

Contact

For privacy questions or a request you cannot complete in the app, email stanislavpashkov8@gmail.com.