Privacy Policy — RingVision
Last updated: September 2026
1. Data Controller
RingVision is developed by Ridge Iyamu, with registered office at Via Castelletto 11/3b, Almese (TO), Italy.
For any privacy-related request: privacy@ringvision.app
2. Data collected
We collect the following personal data:
- Registration data: email, name/nickname
- Athlete profile data: age, weight, height, stance (optional)
- Usage data: uploaded videos, saved combinations, tags, training sessions
- Training videos: they portray you and, when you submit them to AI Analysis, they give rise to biometric data pursuant to art. 9 GDPR (section 4bis)
- Training journal (optional): session duration, feeling, RPE (1–10), non-clinical mental state, text notes and optional links to videos/sessions. All fields are optional except feeling, owner-only, never shared with coaches/gyms nor used for profiling or medical purposes.
- Body weight (optional, consent required): recorded in a dedicated collection, one measurement per day. It is health-related data — section 4quater.
- Personal goals (optional): target values on videos/combos/weight/custom, with a weekly, monthly or quarterly deadline. Owner-only, never shared.
- Payment data: handled by the Apple App Store, Google Play or Stripe (gym plans). We do not access card data.
- Diagnostic data: crash reports via Firebase Crashlytics
- Analytics data: usage statistics via Firebase Analytics, collected only after your consent
3. Purposes of processing
Data is processed to:
- Provide the RingVision service
- Manage the account and authentication
- Process in-app subscriptions and gym plans
- Analyse your videos technically, only with your explicit consent (section 4bis)
- Improve the product through usage statistics, only with your consent (Firebase Analytics)
- Improve the AI analysis model through movement data retained in pseudonymised form, only with a separate and optional consent (section 4ter)
- Send training-related notifications (only if authorised)
4. Legal basis (GDPR)
- Performance of the contract (art. 6.1.b): to deliver the service
- Legitimate interest (art. 6.1.f): for security and fraud prevention
- Consent (art. 6.1.a): for optional notifications and usage statistics
- Explicit consent (art. 9.2.a): for biometric video analysis (4bis), for retaining movement data to improve the model (4ter) and for recording body weight (4quater)
The four consents listed above are separate and independent: you may give one without giving the others, and withdraw them individually at any time from Settings → Privacy in the app (art. 7.3 GDPR). No app feature is conditional on the consent described in section 4ter (art. 7.4 GDPR).
4bis. Biometric data — AI Analysis (GDPR art. 9)
The "AI Analysis" feature processes shadow boxing videos to detect body posture (skeleton key points) via MediaPipe on Google Cloud Run. This data falls under the category of BIOMETRIC DATA pursuant to art. 9 GDPR.
Legal basis: Art. 9.2.a — EXPLICIT CONSENT of the data subject. Consent is requested the first time you start AI analysis on a video, with a dedicated explanation and no pre-ticked boxes.
Withdrawal: you may withdraw consent at any time from Settings → Privacy → Biometric video analysis. After withdrawal no new video is analysed; analyses already performed remain available until you delete the corresponding videos, and are deleted together with them. Withdrawal does not affect the lawfulness of prior processing (art. 7.3 GDPR).
Processing: the detected skeleton points are never displayed as an overlay on the video nor shared with coaches, gyms or third parties. They are used to compute the session metrics (punch count, punches per minute, distribution, rhythm). Processing takes place on Google Cloud Run servers in the European Union (europe-west1) and the skeleton points are not retained: they exist in memory for the duration of the processing and are never written to disk nor associated with your account.
What is retained: the computed metrics and the list of detected punches (punch type, timestamp, estimated velocity), associated with the video. We do not retain frames nor body coordinates. If you have also given the separate consent described in section 4ter, a pseudonymised copy of this same information enters the model improvement dataset.
Retention: metrics are associated with the video document and are deleted when the video or the account is deleted (art. 17 GDPR). The aggregated statistical summary is retained for a maximum of 365 days.
4ter. AI improvement dataset (separate and optional consent)
If you wish, you can help improve the RingVision analysis model. This is a separate and entirely optional choice, distinct from the consent in section 4bis: you can use AI Analysis without enabling it, and no app feature is conditional on this consent (art. 7.4 GDPR).
Legal basis: Art. 9.2.a — EXPLICIT CONSENT, collected through a dedicated box that is never pre-ticked, separate from the analysis one.
What we retain: at the end of each analysis, and only if the consent is active, we retain in a separate archive:
- the computed session metrics (punch count, punches per minute, distribution, processing quality indicators);
- the list of detected punches: punch type, timestamp and estimated velocity;
- some technical attributes of the session: sport, stance, duration, model version.
What we do NOT retain: never the video, never the frames, never body coordinates, never your name, your email or any other data identifying you directly. The record does not even contain a reference to the video it comes from.
Pseudonymisation: the record is associated with an identifier derived from your user identifier through a keyed cryptographic function (HMAC-SHA256), which cannot be computed or reversed by the app nor by anyone accessing the archive without the key. We transparently inform you that this is pseudonymisation and not anonymisation: as long as the key exists, this data remains personal data in all respects (Recital 26 GDPR) and continues to enjoy all the protections of this policy, including the right to erasure.
Purpose: measuring the quality of the analysis, identifying its errors and improving the model that computes your metrics. The data is not sold, transferred or shared with third parties, and is not used to profile you nor to make automated decisions concerning you.
Withdrawal and retention: you may withdraw consent at any time from Settings → Privacy → Improve the AI with your data. From withdrawal onwards no new data is retained in the archive. Data already retained, in pseudonymised form, remains in the archive until your account is deleted, which erases it entirely along with everything else (section 6). If you want it erased sooner, you may request so at any time by writing to privacy@ringvision.app: we will act without undue delay (art. 17 GDPR).
Where it is stored: Firestore and Cloudflare R2, within the same infrastructure described in section 5, in a separate area not accessible from the app.
4quater. Body weight (health-related data, GDPR art. 9)
You can record your body weight from the journal and from the Fight Camp module. This is health-related data and is collected only after explicit, dedicated consent, requested the first time you use the feature.
Legal basis: Art. 9.2.a — explicit consent. Withdrawal: Settings → Privacy → Body weight logging. After withdrawal the field is hidden again and we record no new measurements; the entries already recorded remain yours and visible until you delete them.
Visibility: your weight is accessible only to you. It is not visible to coaches, gyms or administrators, not even when you belong to a gym. It is stored in a dedicated collection (one measurement per day) and deleted with the account.
The feature is intended for sports self-monitoring and has no medical purpose: we provide no diagnosis, nutritional advice or health assessment.
5. Sharing with third parties
Data is shared exclusively with:
- Google Firebase (hosting, database, authentication, analytics, crashlytics, notifications)
- Google Cloud Run (AI video processing in a secure server-side environment, europe-west1)
- Cloudflare R2 (secure video storage)
- RevenueCat (in-app subscription management)
- Stripe, Inc. (B2B payment processing for gym plans)
- Apple / Google (social authentication and in-app payments)
We do not sell or rent your data to third parties.
Transfer outside the EU: some of the providers listed above (Google Firebase, Cloudflare R2, RevenueCat) may process data outside the European Union. The transfer takes place in compliance with the Standard Contractual Clauses (SCC 2021) adopted by the European Commission pursuant to art. 46 GDPR. The relevant Data Processing Agreements (DPA) are available on each provider's official website:
- Google Firebase / Google LLC: participant in the EU-US Data Privacy Framework (DPF). DPA available at: https://business.safety.google/adsprocessorterms/
- Cloudflare, Inc.: SCCs 2021 included in the DPA available at: https://www.cloudflare.com/cloudflare-customer-dpa/
- RevenueCat, Inc.: DPA available at: https://www.revenuecat.com/dpa/
- Stripe, Inc.: DPA and SCCs 2021 available at: https://stripe.com/en-it/legal/dpa
6. Data retention
Data is retained for the entire duration of the account. Upon account deletion, all personal data is deleted within 30 days. Specifically:
- Videos and combinations: deleted immediately (Cloudflare R2) or within 30 days (Firestore)
- Videos above the free plan limit: when a paid plan ends they are deleted after a 60-day grace period, with prior notice — see section 5quater of the Terms of Service
- AI improvement dataset (section 4ter): the pseudonymised records and the associated movement data are deleted upon account deletion
- Statistical summary of AI analyses: maximum 365 days
- Coach notes: maximum 730 days
- Push notification token: deleted within 24 hours of account deletion, and in any case removed after 365 days of device inactivity
- Technical events related to subscriptions and payments: maximum 365 days; they may survive account deletion for the accounting reconciliation of billing events (legitimate interest, art. 6.1.f)
- Diagnostic data (Crashlytics): retained for 90 days according to Google's policy
- Firebase access logs: retained for 60 days according to Google's policy
- Tax data relating to gym payments (Stripe): 10 years, as required by law
6bis. Record of processing activities (GDPR art. 30)
Below is the detail of the data processed, the relevant purpose, legal basis and retention period for each data category:
| Data / Firestore field | Purpose | Legal basis | Retention |
|---|---|---|---|
| email, name | Authentication | Art. 6.1.b | Account duration |
| age, weight, height, stance | Athlete profile | Art. 6.1.b | Account duration |
| wins, draws, losses, matchCount | Boxer statistics | Art. 6.1.b | Account duration |
| role (Athlete/Coach/Gym) | Feature access | Art. 6.1.b | Account duration |
| plan, planExpiresAt, planUpdatedAt | Subscription management | Art. 6.1.b | Account duration |
| referralProUntil, referralGrantSource | Refer-a-friend programme | Art. 6.1.b | Account duration |
| lastTrainingDate, totalTrainingSessions, lastVideoUploadAt | Training reminders and summaries | Art. 6.1.f | Account duration |
| palestraId, palestraName, palestraRole | Gym relationship | Art. 6.1.b | Account duration / leaving the gym |
| coachIds | Coach relationship | Art. 6.1.b | Account duration |
| videos/* (Firestore + R2) | Core service | Art. 6.1.b | Account duration; above the free limit: 60 days after a paid plan ends (Terms, sec. 5quater) |
| video.analysis (metrics and punch events; skeleton points are not retained) | Biometric analysis on explicit consent — shadow boxing only | Art. 9.2.a (explicit consent) | Video duration; deleted with video or account. Aggregated summary: 365 days |
| analysis_records/* + event copy on R2 (pseudonymised, no reference to the video) | Improvement of the AI analysis model — section 4ter | Art. 9.2.a (separate, optional explicit consent) | Until account deletion (or upon request). Withdrawal stops new records |
| combinations/*, combo_templates/* | Core service, technique library | Art. 6.1.b | Account duration |
| training_sessions/* | Calendar and gym agenda | Art. 6.1.b | Account duration |
| training_programs/* | Training plans assigned by the coach | Art. 6.1.b | Account duration |
| coachNotes/*, tags/*, combo feedback | Coach feedback | Art. 6.1.b | coachNotes 730 days; the rest account duration |
| fight_camps/* + notes and objectives | Match preparation | Art. 6.1.b | Event date + 90 days |
| training_goals/* (target, period, type) | Private athlete goals (week/month/quarter) | Art. 6.1.b | Account duration, owner-only |
| training_logs/* (durationMin, feeling, rpe, mentalState, notes) | Training journal — personal self-monitoring, non-clinical wording | Art. 6.1.b (data entered by the user in the feature being used) | Account duration, owner-only, not shared with coach or gym |
| users/{uid}/body_weights/* (one measurement per day) | Body weight logging — section 4quater | Art. 9.2.a (explicit consent) | Account duration, owner-only including read access |
| users/{coachId}/athlete_payments/* | Status of the fee the athlete pays the coach, recorded manually by the coach. No in-app collection | Art. 6.1.f | Until the athlete is removed from the roster |
| referral_codes/*, referral_events/*, credit_ledger/* | Refer-a-friend programme and rewards | Art. 6.1.b | Account duration |
| users/{uid}/notifications/* | History of notifications received in the app | Art. 6.1.b | 90 days |
| analyticsConsentAt, biometricAnalysisConsentAt, consentDatasetAt, bodyWeightConsentAt (+ related withdrawals) | Proof of the consents given and withdrawn | Art. 7.1 | Account duration; deleted with the account |
| fcmToken, devices/* | Push notifications | Art. 6.1.a | < 24h post-deletion; 365 days if the device is inactive |
| analytics_monetization/* | Reconciliation of subscription events | Art. 6.1.f | 365 days |
| Firebase Analytics | Usage statistics, only after consent | Art. 6.1.a | 14 months (Google) |
| Firebase Crashlytics | Diagnostics | Art. 6.1.f | 90 days (Google) |
| Firebase Auth access logs | Security | Art. 6.1.f | 60 days (Google) |
| Hive (local, AES-256 encrypted) | Local device preferences | Art. 6.1.b | Until uninstall |
| Stripe customerId (B2B) | Gym payments | Art. 6.1.b | Tax obligation: 10y |
Upon account deletion, the onUserDeleted Cloud Function automatically removes all personal data (cascade delete) from Firestore, Cloudflare R2 and the associated collections: videos, tags, notes, combos, sessions, plans, journal, weight entries, goals, referrals, gym invitations and the pseudonymised records of the AI improvement dataset. The fields recording your consents are deleted together with the account.
7. User rights (GDPR art. 15-22)
You have the right to:
- Access your data (art. 15) — available in Settings → Export my data
- Rectify inaccurate data (art. 16) — available in Settings → Edit profile
- Erase your data, "right to be forgotten" (art. 17) — available in Settings → Delete account
- Withdraw the consents given (art. 7.3) — available in Settings → Privacy, with a switch for each of the four consents
- Restrict processing (art. 18) — request by email to privacy@ringvision.app
- Data portability (art. 20) — available in Settings → Export my data (JSON format)
- Object to processing (art. 21) — available in Settings → Privacy
To exercise your rights: privacy@ringvision.app
7bis. Complaint to the supervisory authority (GDPR art. 77)
You have the right to lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) if you believe that the processing of your personal data infringes the GDPR.
Italian Data Protection Authority (Garante per la protezione dei dati personali):
- Website: https://www.garanteprivacy.it
- Email: garante@gpdp.it
- Fax: +39 06 696773785
- Address: Piazza Venezia 11, 00187 Rome (RM), Italy
8. Security
Data is protected through:
- Encrypted connections (HTTPS/TLS)
- Firebase authentication with granular access rules
- App integrity verification (App Check) on content access
- No access to payment data (handled by Apple, Google and Stripe)
9. Minimum age
You must be at least 16 years old to use RingVision. On first access we ask you to confirm this together with your acceptance of the Terms of Service. If we become aware of an account created by someone below that age, we delete it along with the associated data.
10. Changes to the Privacy Policy
Any changes will be notified via in-app update. When the changes concern the processing described in this policy, we ask you to review and accept it again before continuing to use the app.
11. Contacts
For any questions: privacy@ringvision.app
12. Personal data breach (GDPR arts. 33-34)
In the event of a personal data breach that entails a risk to the rights and freedoms of data subjects, we will:
- Notify the Italian Data Protection Authority within 72 hours of becoming aware of the breach (art. 33 GDPR), unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.
- Communicate the breach to the data subjects without undue delay where it may result in a high risk to their rights and freedoms (art. 34 GDPR).
The communication to data subjects will include: the nature of the breach, the contact details of the data protection officer (or point of contact), the likely consequences of the breach and the measures taken or proposed to address it.
13. Right to object to processing (GDPR art. 21)
You have the right to object at any time to the processing of your personal data for:
a) Analytics purposes (Firebase Analytics): you can exercise this right directly from the app in Settings → Privacy → Anonymous usage statistics, or by sending a request to privacy@ringvision.app.
b) Marketing purposes (promotional notifications): you can withdraw consent to marketing notifications at any time via Settings → Notifications, or by sending a request to privacy@ringvision.app. Withdrawal does not affect the lawfulness of processing prior to the withdrawal itself (art. 7.3 GDPR).