Privacy Policy

Last updated: 2026-08-22
Effective date: 2026-08-22

This Privacy Policy applies to the products and services provided through the SportArc App (the "App").

This Privacy Policy explains the following:

SportArc is provided by Rongchang District Sijin Software Development Studio ("we", "us" or "our"). We attach great importance to protecting the personal information and privacy of users ("you"). We understand the importance of personal information and will take appropriate security measures in accordance with applicable laws, regulations and mature industry security standards. This Privacy Policy is intended to explain how we process your personal information when you use our products and services, and how we protect that information.

Special Notice: Before using our products or services, please carefully read and fully understand this Privacy Policy. By using or continuing to use our products or services, you acknowledge that we will process relevant information in accordance with this Privacy Policy. If you are a minor, you should read this Privacy Policy under the supervision and guidance of your parent or legal guardian, and use our products or services or provide personal information only with your parent or legal guardian's consent where required. If you are the parent or guardian of a minor, please read this Privacy Policy carefully and decide whether to allow the minor to use our products or services.

This Privacy Policy applies only to personal information collected by us and to the services and features we provide. It does not apply to personal information collected by third parties, services provided by third parties, or third-party rules regarding the use of information.

Our product is developed as a native iOS app. During app operation, in order to ensure normal software operation, investigate crashes, prevent account abuse, and provide file upload, download and related services, we may generate and store a random identifier for your device or account using a UUID algorithm. We may also collect necessary device and network-related information, including device model, operating system version, network connection status, network information such as IP address, and app crash logs. The identifier and the above information are used only for account and service security, troubleshooting, statistics and service improvement. They are not used to track your activities across other companies' apps or websites, and are not used for personalized advertising.

1. How We Collect and Use Your Information

1. Account registration and sign-in

When you register for or sign in to SportArc, you may use Sign in with Apple, Sign in with Google, or other login methods made available in the App. For Sign in with Apple, we may process the Apple user identifier associated with your account, the stable Apple identifier used by our service, email address if provided by Apple, full name if provided by Apple, authentication records, login records, and session tokens necessary for account security. For Sign in with Google, we may process the Google account identifier associated with your account, email address if provided by Google, full name if provided by Google, Google ID token or authentication information necessary to verify your identity with our server, authentication records, login records, and session tokens necessary for account security. We do not request access to your Gmail, Google Drive, contacts, calendar, or other Google content through Sign in with Google. We may also process optional Profile Information that you choose to provide, such as nickname, gender, birthday, region, playing hand, fitness goals, sports experience, training preferences, physical condition, and profile introduction. This information is used to create and maintain your account, identify your account securely, provide app features, personalize your experience, and protect account security.

2. Normal operation of the product

When you use our services, in order to ensure normal operation of the software and services, maintain service security, and support app functions, we may collect the following data:

2.1 Hardware model, operating system version, app version, network access method and type, and operation log information such as error information. Collecting this information helps us understand issues you may encounter and optimize our product.

2.2 Usage information and analysis. To ensure normal operation of product features, improve performance, locate and resolve issues, we may record necessary information related to app operation when you use the App and related services, including network request logs, crash logs, feature usage frequency, performance data and overall usage information. This type of information is used for product operation, security protection and service optimization.

2.3 Activity data, uploaded content, training plans and AI features. When you record, upload or link training, match or other sports activities, or use training plan features, we may process related Activity Data, including training or match records, analysis results, training plan execution information and feedback you choose to provide. SportArc also allows users to upload table tennis training or match videos. We process uploaded videos and related files to provide AI-assisted analysis, auto editing, match review, result generation, history records, troubleshooting and service improvement. You retain your rights in the videos and other content you upload, and we do not publicly display your videos by default. We may use Profile Information and Activity Data to personalize your experience, generate individualized training plans based on your goals and preferences, and provide training analysis, recommendations and personalized training insights using artificial intelligence, machine learning and large language models. To provide these features, relevant information may be processed by our servers, cloud storage, and service providers that provide infrastructure, AI or GPU processing capabilities.

3. Product and service information display

If you become a registered user, we may send you service updates, feature notices or activity-related commercial messages through in-app notifications, email or other methods. You may choose to opt out of or turn off relevant notifications at any time. If you choose not to receive such messages, this will not affect your normal use of core features.

4. Device permissions

When providing certain features, we may need you to authorize the App to access certain system permissions. We will request permissions only within the scope necessary to implement the relevant feature, and will not access your device information without authorization. You may refuse authorization. Refusal will not affect the use of basic features, but certain features that depend on the permission may not be available.

4.1 Photo library access: when you need to upload local images, videos or other content, or save generated videos to your photo library, we may request photo library access. If you do not grant this permission, other app features may still be available, but the relevant upload or save function may not work.

5. Third-party SDKs and service providers

To implement necessary features such as file upload, download, storage, analysis processing and performance optimization, the App may integrate software development kits (SDKs) or services provided by third-party technical service providers. Third-party SDKs and service providers should follow the principle of data minimization and perform technical processing activities related to feature implementation. We conduct security assessments for third-party SDKs and require service providers to follow data protection standards no less protective than this Privacy Policy where applicable, and to collect and use personal information only within the scope necessary to implement the relevant function. Before using third-party services, we recommend that you review their privacy policies where available.

To maintain app operation, the App integrates the following third-party SDKs:

SDK name: COS V5 iOS SDK

Package name: QCloudCOSXML

Developer: Tencent Cloud Computing (Beijing) Co., Ltd.

Purpose: object storage, including uploading images, videos or other files selected by users in the App to Tencent Cloud Object Storage (COS), storing them in the cloud, and downloading or managing related files from COS.

Information collected: network status information used to optimize SDK requests under different network conditions; specific agreed identifier characters in the clipboard used to trigger SDK log feedback and troubleshooting, read only inside the SDK and not transmitted by us; and local multimedia files processed when you authorize and actively select files for upload or download. Please refer to the COS V5 SDK Personal Information Protection Rules for details.

Privacy link:

https://privacy.qq.com/document/preview/a76038ae5ee242d18d3a45a34cdd744c

SDK name: Google Sign-In SDK for iOS

Package name: GoogleSignIn / GoogleSignInSwift

Developer: Google LLC

Purpose: Google account sign-in and identity authentication, allowing users to sign in to SportArc with a Google Account and allowing our server to verify the Google ID token.

Information processed: Google ID token or authentication information needed for identity verification, Google account identifier, email address, full name or basic profile information if provided by Google, login records, and device or network information necessary for authentication and security. We do not use Google Sign-In for advertising tracking and do not request access to Gmail, Google Drive, contacts, calendar, or other Google content.

Privacy link:

https://policies.google.com/privacy

The App may also use Apple services, such as Sign in with Apple and App Store purchases. Purchases and subscriptions are processed by Apple. To provide paid features and account entitlements, we may receive and store information related to subscription status, product ID, transaction ID, original transaction ID, expiration or renewal status, and related entitlement information. This Privacy Policy does not describe the commercial terms of paid services.

6. Exceptions and legal bases

Depending on the applicable law and the specific context, we process personal information based on performance of our contract with you, your consent where applicable, our legitimate interests in maintaining security and improving services, and legal compliance. Under applicable laws and standards, we may collect and use relevant personal information without separately obtaining your authorization in the following circumstances:

For generating training plans, personalizing your experience, and providing personalized training insights using AI and ML, the information processed may include Profile Information and Activity Data. Depending on the applicable law and context, the legal basis may include performance of our contract with you, consent where required, and our legitimate interests subject to appropriate safeguards.

6.1 Where it is necessary to enter into or perform a contract to which you are a party;

6.2 Where it is necessary for us to fulfill legal duties or legal obligations;

6.3 Where it is necessary to respond to public health emergencies or to protect the life, health and property safety of natural persons in emergencies;

6.4 Where personal information is processed within a reasonable scope for public interest purposes such as news reporting or public supervision, where applicable;

6.5 Where personal information disclosed by you or otherwise legally disclosed is processed within a reasonable scope;

6.6 Other circumstances provided by applicable laws and regulations.

The current version of the SportArc App does not use the Identifier for Advertisers (IDFA), and does not combine personal information collected by us with data from other companies' apps or websites for cross-app or cross-site personalized advertising or profiling.

If future business needs involve "tracking" as defined by Apple, we will comply with App Tracking Transparency requirements, explain the specific purpose through the system prompt, process such information only after obtaining your explicit authorization, and update this Privacy Policy accordingly.

2. Identity and Session Mechanism

To identify you and maintain your signed-in state while you use the service, we store session identifiers, such as session tokens, on the client after you sign in or complete identity verification. These identifiers are valid only for a certain period and will expire or be updated to protect your account and service security.

We may use the above session identifiers for the following purposes:

  1. Authentication and session maintenance: to confirm your current sign-in state so you do not need to repeatedly enter account credentials while using the service;
  2. Service experience: to support page navigation and feature switching, and to provide a consistent and smooth user experience;
  3. Security protection: to identify abnormal behavior, verify request legitimacy, prevent fraud and prevent violations of the Terms of Use;
  4. System operation and quality optimization: to help us improve service stability, performance and overall quality.

Except for the purposes above, we will not use these session identifiers for other purposes not described in this Privacy Policy.

3. How We Share and Publicly Disclose Personal Information

1. Sharing

We do not share your personal information with any company, organization or individual, except in the following circumstances:

1.1 Sharing with your separate authorization or consent

After obtaining your explicit authorization or consent, we may share your personal information with specified third parties within the scope of your authorization. Such sharing will be limited to what is necessary and subject to this Privacy Policy and the content of your consent.

1.2 Sharing required by law

Within the scope required by applicable laws and regulations, or in response to legally valid requests from administrative, judicial or regulatory authorities, we may share personal information to fulfill legal obligations. Before sharing, we will review the legality and necessity of such requests in accordance with applicable law.

1.3 Sharing in business changes

If a merger, division, reorganization, acquisition, transfer of assets, bankruptcy liquidation or similar business change may involve the transfer of your personal information, we will require the recipient of the personal information to continue to be bound by this Privacy Policy. If the recipient needs to change the purpose or method of processing, we will require it to obtain your authorization or consent again where required.

1.4 Sharing with authorized partners

1.4.1 Permissions and functions used by third-party SDKs

To implement necessary product functions such as file upload, download and network transmission management, the App integrates SDKs provided by third-party technical service providers. Such SDKs may need to use system capabilities related to network access and file reading or writing with your authorization to ensure normal operation of relevant functions. We will carefully assess the system capabilities used by third-party SDKs under the principle of data minimization, and require third-party technical service providers to comply with applicable laws, fulfill personal information protection obligations, and take appropriate security measures to ensure that your personal information is not used for unauthorized purposes.

1.4.2 Types of personal information collected by third-party SDKs and purposes of use

To support upload, download, network routing, performance monitoring and related functions, third-party SDKs may collect necessary information related to network status, system operating environment, and file reading or writing operations based on your actual use and authorization. This information is used only to implement required functions, improve service stability, investigate exceptions, and protect data transmission security. Third-party SDKs should follow the principle of data minimization and apply security measures such as encrypted transmission and access control. We will allow third-party SDKs to process relevant information only within the scope described in this Privacy Policy and will not actively provide third parties with sensitive personal information that directly identifies you for unauthorized purposes.

2. Entrusted processing

2.1 Circumstances of entrusted processing

To provide products or services, maintain service quality and stability, and process uploaded videos or generated analysis results, we may entrust carefully evaluated partners to process personal information related to service functions on our behalf. We will conduct entrusted processing only for lawful, legitimate, necessary, specific and explicit purposes, and will provide the processor only with personal information necessary for the entrusted purpose. Before entrusting partners to process personal information, we will require them to process personal information in accordance with this Privacy Policy, our agreements and applicable laws, and not to use entrusted personal information for any unauthorized purpose.

2.2 Types of entrusted partners

The types of partners we may entrust include, but are not limited to:

2.2.1 Technical service partners: To implement file storage, data transmission, network optimization, infrastructure support, AI-assisted analysis and GPU processing, we may entrust partners that provide cloud computing, object storage, network request processing, computing or other technical capabilities to process relevant information to maintain service operation.

2.2.2 Data processing and operational support partners: To improve service performance, locate technical issues, or conduct necessary statistical analysis, we may entrust qualified partners to process necessary information related to system operating status, network performance or feature usage. Such partners should not process sensitive information directly associated with your identity unless necessary for providing the relevant service and protected by appropriate safeguards.

2.3 Management and supervision of processors

We will continuously supervise partners entrusted to process personal information, including their security management measures, access control, data retention and deletion requirements. If a partner violates our agreement or applicable laws, we will take measures such as suspending service, terminating cooperation and requiring the partner to assume responsibility in accordance with law.

2.4 Cross-region processing

Because our services may be supported by cloud infrastructure and technical service providers in different regions, your personal information may be processed in regions where we or our service providers maintain facilities or personnel. Where applicable, we will take appropriate measures to protect your personal information in accordance with this Privacy Policy and applicable legal requirements.

3. Public disclosure

We do not actively publicly disclose your personal information. Public disclosure may occur only when permitted by applicable laws or after obtaining your separate consent. Public disclosure will be subject to security protection measures consistent with industry standards.

3.1 Disclosure with your separate consent

Within the scope of your explicit authorization and according to the information type, disclosure method and disclosure recipient specified by you, we may publicly disclose information you authorize.

3.2 Disclosure required by law

Where required by applicable laws, judicial procedures, administrative enforcement or competent government authorities, we may disclose personal information as required. Before disclosure, we will review the request in accordance with applicable law and, where appropriate, require the requesting institution to provide valid legal documents such as a subpoena or investigation letter, and disclose only necessary information.

4. Security Protection of Personal Information

  1. To improve the security of the services we provide, we continue to strengthen the security capabilities of the software installed on your device to help prevent leakage of personal information. We establish management systems, processes and organizational measures to protect information security. We will make reasonable efforts to protect your personal information, but please understand that no security measure can be guaranteed to be perfect.
  2. We work to protect user information from leakage, loss, misuse, unauthorized access and disclosure. We use multiple security measures to maintain a reasonable level of protection, including technical measures, management controls and security systems. Technical measures may include firewalls, encryption such as SSL, de-identification or anonymization, and access control. We also continue to strengthen the security capability of the App installed on your device, such as local encryption of certain information to support secure transmission.
  3. In the event of a personal information security incident, we will initiate an emergency response plan, seek to prevent the incident from expanding, and notify you as required by applicable law of the basic situation and possible impact of the incident, measures we have taken or will take, suggestions for you to prevent and reduce risks, and remedial measures where applicable. We may notify you by email, letter, phone, push notification or other reasonable methods. Where individual notification is difficult, we may issue an announcement in a reasonable and effective manner. We will also report the handling of personal information security incidents to competent authorities where required.

5. Retention Period

  1. We retain your personal information only for the shortest period necessary to achieve the purposes described in this Privacy Policy, and will shorten the retention period as much as reasonably possible while complying with applicable legal requirements.
  2. In general:
    1. Account information: retained while you use the App. When you delete your account, we will delete or anonymize it, unless otherwise required by applicable laws or necessary for dispute resolution or legal compliance.
    2. Profile Information, Activity Data, uploaded videos, analysis records and training plans: retained as needed to provide the related services. Information associated with your account is generally retained until you delete it or we no longer need it to provide the services, unless a longer retention period is required by product rules or applicable law.
    3. Logs and diagnostic information: retained to protect service security and troubleshoot issues, usually for no more than six months from collection, after which it will be deleted or anonymized.
    4. Transaction-related information: retained to fulfill tax, financial, accounting, entitlement and regulatory obligations, generally for no less than three years after the transaction is completed, or for a longer period required by applicable law.
  3. When we terminate part or all of the services, we will stop collecting relevant personal information in a timely manner and delete or anonymize the personal information we hold within a reasonable period, unless otherwise required by applicable laws or regulatory authorities.

6. How You Manage Your Personal Information

You may access and manage your information through the following methods. We will respond to your requests in accordance with applicable legal requirements:

1. Access your personal information

You have the right to access your personal information, subject to exceptions provided by applicable law. You may access your personal information by the following methods:

Profile information: if you wish to access or edit your birthday, username, nickname, Apple sign-in related account information where displayed, email address where provided, gender, region, playing hand or other profile details, you may do so after signing in through "Me" - "Personal Settings" in the App.

Permissions: you may manage system permissions such as photo library access through the device settings or privacy settings. After you disable a permission, we will no longer collect information through that permission, but the corresponding feature may no longer be available.

2. Correct or supplement your personal information

If you find that personal information processed by us is inaccurate or incomplete, you have the right to request correction or supplementation. You may submit a correction or supplementation request through the methods listed in "1. Access your personal information" above.

3. Delete your personal information

You may delete part of your personal information through the methods listed in "1. Access your personal information" above.

You may also contact customer support to request deletion of personal information in the following circumstances:

3.1 If our processing of personal information violates applicable laws or regulations;

3.2 If we collect or use your personal information without the required consent;

3.3 If our processing of personal information seriously violates our agreement with you;

3.4 If you no longer use our products or services, or you delete your account;

3.5 If we no longer provide products or services to you.

If we decide to respond to your deletion request, we will also notify, where reasonably possible, entities that obtained your personal information from us and require them to delete it in a timely manner, unless otherwise required by law or unless those entities have independently obtained your authorization.

After you or we help you delete relevant information, due to technical and security limitations, corresponding information may not be immediately removed from backup systems. We will securely store such personal information and restrict further processing until the backup can be cleared or anonymized.

4. Change the scope of your authorization or consent

Each business function may require some basic personal information to be completed, as described in Section 1 of this Privacy Policy. For additional personal information collection and use, or information obtained based on system permissions such as photo library access, you may disable the corresponding permission at any time in your device's settings or privacy settings. After you disable the permission, we will no longer collect relevant information through that permission.

5. Automated decision-making

In some business functions, we may make decisions based only on automated decision-making mechanisms, including information systems and algorithms. If such decisions have a significant impact on your legal rights and interests, you may contact us through customer support.

6. Responding to your requests

To protect security, you may need to provide a written request or otherwise verify your identity. We may first ask you to verify your identity before processing your request.

We will respond within 15 business days where applicable. If you are not satisfied, you may submit a complaint through customer support in the App.

For reasonable requests, we generally do not charge a fee. For repeated requests or requests that exceed a reasonable scope, we may charge a reasonable cost-based fee where permitted. We may refuse requests that are repeatedly submitted without justification, require excessive technical means, create risks to the lawful rights and interests of others, or are impractical.

Depending on where you reside, you may also have rights to access, correct, delete, restrict or object to certain processing, request portability of certain personal information, and withdraw consent where processing is based on consent. California users may have rights to know, access, correct, delete, and opt out of certain sale or sharing of personal information where applicable. We do not sell personal information in the ordinary meaning of the word, and the current version does not use IDFA for cross-app tracking or personalized advertising. If this changes, we will update this Privacy Policy and provide required choices.

In the following circumstances, we may be unable to respond to your request in accordance with applicable laws:

6.1 Where it is directly related to national security or defense security;

6.2 Where it is directly related to public security, public health or major public interests;

6.3 Where it is directly related to criminal investigation, prosecution, trial or enforcement of judgments;

6.4 Where there is sufficient evidence that you have subjective malice or abuse rights;

6.5 Where responding to your request would seriously harm the lawful rights and interests of you or other individuals or organizations;

6.6 Where trade secrets are involved.

7. Account deletion

You may request account deletion through "Me - Settings - Account Deletion" in the App. After account deletion is completed, we will stop providing products or services to you and delete or anonymize personal information related to the account, and will no longer retain your account data, unless otherwise required by applicable laws or necessary for regulatory obligations, dispute resolution or legal compliance. In such cases, we will retain the information only within the necessary scope and period, and delete or anonymize it after the period expires. We will not impose unreasonable conditions on your deletion request, such as requiring you to agree to additional collection of personal information or long-term retention unrelated to account deletion.

If you cannot access the relevant personal information through the above path, you may contact us through customer support in the App at any time. We will respond to your access request within 15 business days where applicable.

7. Protection of Minors' Personal Information

  1. We attach great importance to protecting minors' personal information. Parents or guardians should carefully read this Privacy Policy and accompany their minor children in using our services or providing information only when they agree to do so.
  2. For personal information of minors collected with the consent of parents or guardians, we will use, share, transfer or disclose such information only where permitted by applicable laws, with explicit consent from parents or guardians where required, or where necessary to protect minors.
  3. If we discover that we have collected personal information of a minor without verifiable consent from a parent or legal guardian where required, we will seek to delete the relevant data as soon as possible.

8. How This Privacy Policy Is Updated

To provide you with a better product and service experience, we continue to improve our products, services and technology. When new services are introduced or business processes change, we may update this Privacy Policy to inform you of your rights under this Policy.

For material changes, we will provide more prominent notice, such as in-app notices, pop-up prompts or other reasonable methods.

Without your explicit consent, we will not reduce the rights you should have under this Privacy Policy. We will publish any changes to this Policy on this page.

For material changes, we may also provide more prominent notice, including email notices for certain services, to explain the specific changes to the Privacy Policy.

Material changes referred to in this Policy include, but are not limited to:

  1. Material changes to our service model, such as the purposes of processing personal information, types of personal information processed, or ways personal information is used;
  2. Material changes to our ownership structure or organizational structure, such as owner changes caused by business adjustments, bankruptcy or merger;
  3. Changes to the main recipients of personal information sharing, transfer or public disclosure;
  4. Material changes to your rights regarding personal information processing and the ways you exercise those rights;
  5. Changes to the department responsible for personal information security, contact information or complaint channels;
  6. Where a personal information security impact assessment indicates a high risk.

We may also archive previous versions of this Policy on a dedicated page in the App for your review.

9. How to Contact Us

You may contact us through the following methods. We will respond to your request within 15 business days where applicable:

  1. If you have any questions, comments or suggestions about this Policy, you may contact us through "Me" - "Settings" - "Help & Support" - "Contact Us" in the App;
  2. If you discover that personal information may have been leaked, you may report it through "Me" - "Settings" - "Help & Support" - "Feedback" in the App;
  3. Email: support@sportarc.ai

10. Definitions

Personal information: personal information refers to various information recorded electronically or otherwise that can identify a natural person alone or in combination with other information, including but not limited to name, date of birth, identification document number, personal biometric information, address and telephone number.

Sensitive personal information: sensitive personal information refers to personal information that, once leaked, illegally provided or misused, may endanger personal or property safety, or may easily lead to damage to personal reputation, physical or mental health, or discriminatory treatment. Examples may include identification document numbers, personal biometric information, bank accounts, communications content, and health or physiological information.

De-identification: the process of technically processing personal information so that the personal information subject cannot be identified without additional information.

Anonymization: the process of technically processing personal information so that the personal information subject cannot be identified and the processed information cannot be restored.

Child: a minor under the age defined by applicable law for special protection of children's personal information.