01Who this covers
This policy covers the FormCheck app for iPhone and Android, and this website. FormCheck films a rugby goal kick, measures the technique against published biomechanics research, and gives the kicker one thing to work on.
FormCheck is an independent Australian project, operated from Sydney, New South Wales. We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and — where they apply to you — the UK/EU GDPR.
The short version of everything below: the app is built so that there is almost nothing to have a privacy policy about. That is a design decision, not a marketing line, and the rest of this page is the detail behind it, including the parts that are inconvenient.
02What stays, what leaves
- Your video, and every still frame taken from it
- The 33-point skeleton the app tracks through the kick
- Your scores, reports and history
- Athlete names you type into Squad
- Your logged drill sets and training sessions
- Anything read from Apple Health
- The usage log the app keeps about itself
- Your account record and any redeemed club code
- Only this: a question you type into the Coach tab, together with your own 0–100 scores, sent to an AI provider so it can be answered.
- Anything you choose to send with the iOS share sheet — a result, or a challenge link. That goes wherever you send it, in your own messaging app.
FormCheck's own code makes network requests in exactly one file, and that file is the Coach. src/ai/coach.ts
03Your video
Video is analysed on the device and is never uploaded. When you film a kick or pick one from your camera roll, the app pulls a still out of the clip at each timestamp and runs Google's MediaPipe pose model on that still, on the phone. Each still is deleted as the next one is read.
We never receive a clip. There is no upload endpoint in the app, so we could not retrieve one if we were asked to.
A clip you film in the app is written to the app's own storage on your device. It is not saved to your camera roll and it is not referenced by the report the app keeps — a saved report holds the measured numbers and nothing that points at a file.
Where this is verifiable
- On-device frame extraction and pose detection — src/pose/index.ts
- The saved record holds scores and a report, never a clip path — src/state/coach.ts
- The camera and photo-library permission strings say the same thing on the permission sheet itself — app.json
Filming records audio alongside the video, because that is how phone cameras work. Audio is never analysed and never leaves the device either.
04What is kept on your phone
All of this is stored in the app's own storage on your device, is readable only by the app, and goes with the app if you delete it:
- Each kick: the date, the per-measure scores, the overall score, a confidence figure and the full report
- The athletes in your Squad, under whatever names you typed
- Your logged drill sets and any training session you saved
- A redeemed club code and when it expires
- Your saved Coach conversation
- Your account record (see section 8)
- The usage log (see section 7)
- Which milestones you have been shown, and whether you have seen the introduction
None of it is backed up to a server by us. If you have iCloud or Android backup switched on, your device's own backup may include app data; that is between you and Apple or Google, and we never see it.
05The Coach — the one exception
The Coach tab answers questions about your kick. Most of what you ask is answered entirely on the phone, from your own stored numbers and the published research the app is built on — offline, free, and without anything being sent.
An open-ended question the app cannot answer from its own record is sent to our AI
provider, DeepSeek, at api.deepseek.com. This is what goes
with it, exactly:
Read this before you type
A question you type is text you are sending to a third party. The app says so on the Settings screen in the same words: do not type anything into the Coach that you would not want sent. Do not put a name, a school, an address, a phone number or a description of an injury into it.
DeepSeek receives that text and handles it under its own privacy policy and terms. We do not control how long it retains it. This is a disclosure of personal information to an overseas recipient for the purposes of Australian Privacy Principle 8, and it is the only one FormCheck makes.
If you never open the Coach tab, nothing ever leaves your device. If the build you are running has no coach configured, the open-ended path is switched off entirely and the Coach answers only from your own phone — the app tells you when that is the case rather than failing silently.
The Coach's answers are checked before you see them. A reply that quotes a measurement the app has not measured, or that strays into pain, injury or diagnosis, is thrown away rather than shown. src/ai/coach.ts
06Apple Health
If you connect Apple Health from Settings, the app reads three things and nothing else:
- Sleep analysis — to show last night's sleep
- Resting heart rate — to show today's figure against your own recent median
- Workouts — to show how many sessions are in Health this week
Because your Watch, WHOOP, Garmin, Fitbit, Oura and Strava all write into Apple Health, connecting Health brings whatever those already wrote there. The app asks for read access only and never writes anything back into Health.
None of it leaves the device. It is read when a screen needs it, shown as it is, and not stored by the app. It is never scored, never turned into a readiness or risk figure, and it never changes how a kick is measured. The app is deliberately incapable of that: the rule is enforced by tests, not by a promise. src/health/read.ts, src/health/health.ts
Health access is yours to withdraw at any time, in iOS Settings → Health → Data Access & Devices. Erasing everything inside the app cannot revoke it — only iOS can — but since nothing read from Health is stored, there is nothing of it left behind.
07The usage log
The app keeps a small log of what it did for you: a camera opened, a kick read, a baseline set, a drill logged. Without it, a bad camera screen and a bad first-run experience look identical to us.
This log is on your phone and is not sent anywhere. There is no analytics, advertising or attribution SDK in the app — no PostHog, no Mixpanel, no Firebase, none. There is no App Tracking Transparency prompt because there is nothing to track, and the app's privacy manifest declares no tracking.
An entry can only ever hold three things: an event name from a fixed list of ten, a timestamp, and one small number. There is no text field, so there is nowhere for a name, a score, a file path or anything about you to be written — and the app re-checks that every time it reads the log off disk. At most 400 entries are kept.
You can see every entry in Settings → Things recorded, and erase the log on its own from the row underneath it. A random install identifier is generated on the phone for a future opt-in aggregate; it is derived from nothing about you or your device, no aggregate upload exists today, and it is erased with everything else. src/state/analytics.ts
08Accounts and club codes
There is no account server. Signing in creates a record on your phone and nothing else — no password is checked, no email is collected, no verified identity is stored, and no network request is made. The app says so on the sign-in screen and in Settings rather than implying otherwise. src/state/account.ts
A club code redeemed for a funded place is checked on the device. Nothing about a redemption reaches us, which is why the app cannot and does not count how many places have been used.
If real sign-in is ever added, this section will be rewritten before it ships, and it will bring a real server-side account deletion with it.
09The community feature
Not switched onFormCheck contains a community feature — a group feed for a club or a school — that is not active. With no backend configured, the tab is not shown, the feature is unreachable, and nothing you could write in it would reach another person. Anything a development build stores locally is erased along with everything else.
It is described here so that the commitments it is built on are on the record before it is switched on, not after. When it is enabled:
- There is no private one-to-one channel, anywhere. No direct messages, no threads between two people. This is not a rule we intend to keep — it is a shape the data model cannot express, and there is a test that fails the build if one appears.
- Posts are not public until they have been reviewed. A post is created in a pending state and only a moderator can publish it.
- Clips live in a private store. No public link, no guessable URL. A clip is reachable only through a signed link that expires, minted for a published post.
- Contact details are refused in every text field. A phone number, an email, a link, a social handle or "add me on Snap" is rejected before it posts. With no private channel in the app, moving a conversation off it is the risk, and this is the defence.
- A sponsor can never learn which child they funded. A funder has no permission to read individual members at all; what they see is a group total and thank-you notes with no author attached. This is enforced in the database, not in the app.
- Every group has a named adult accountable for it, verified out of band. Nobody can tick a box in the app to declare themselves an adult; the database refuses that write outright.
- Blocking is enforced on the server, in both directions — a blocked person's content is never sent to your device, rather than hidden once it arrives.
- Reports are visible only to the person who filed them, and to the review queue.
- Full names are refused as display names. First name or a nickname only.
Before it is switched on, this policy will be updated to name where that data is stored, how long it is kept, who reviews it and how quickly, and what parental consent is required. supabase/migrations/0001_community.sql, src/community/safety.ts
10Children and young players
Most people who use FormCheck are school-age rugby players, and many are under 18. That is the reason the app is built the way it is, so this section is written plainly rather than defensively.
What the app asks a young person for
Nothing. The app does not ask for an age, a date of birth, a name, an email address, a phone number or a school. It does not ask a child to create an account, because there is no account to create. It does not know who you are and has no way to find out.
A first name typed into Squad, by a coach or by the athlete, stays on that phone.
Age rating and the App Store
FormCheck is rated for general audiences and is not submitted to the App Store's Kids Category. It does not contain third-party advertising, third-party analytics, in-app purchase aimed at a child, or any link out of the app other than to this site and to a published research paper.
Parents, coaches and teachers
If you are filming a young player: get a parent or guardian's permission first, film them side-on, and keep the clip yours. FormCheck never receives it. If you are a parent and would like to see what the app holds about your child, it is all on their phone, visible in the app, and erasable from Settings in two taps.
Anyone under 16 should use the Coach tab with a parent, guardian or coach aware of it, because it is the one part of the app that sends anything anywhere.
COPPA, GDPR-K and the Australian Privacy Principles
FormCheck does not knowingly collect personal information from anyone, of any age. We do not operate a service directed at children under 13 in the sense COPPA regulates, and because nothing about a user is transmitted or stored by us, there is no profile of a child anywhere for a parent to access, correct or have deleted — the deletion is the Erase control inside the app, and it is complete.
Under the Australian Privacy Principles we collect no personal information we do not need (APP 3), use it for nothing but running the app (APP 6), and make exactly one overseas disclosure, which is the Coach question described in section 5 (APP 8).
If you believe a child has typed personal information into the Coach tab and you want it addressed, email us at hello@formcheckco.app and we will raise it with the provider and tell you what came of it.
11Deleting your data
Settings → Erase everything is the delete, and it is complete. It is a deliberate two-tap control so it cannot be hit by accident. It removes, in one action:
- Every kick, every score and every report, for every athlete in the Squad
- Every logged drill set and saved training session
- Any redeemed club code
- Your account record
- Your saved Coach conversation
- The usage log and the random install identifier
- Anything the community feature stored locally
- Any scheduled notification, and the record of which milestones and offers you were shown
Deleting the app does the same thing. There is no remote account to close, because one was never created.
Three honest limits
- Apple Health access can only be revoked in iOS Settings. Erasing inside the app clears our record of having asked, but the grant is yours to withdraw. Nothing read from Health is stored, so nothing of it is left behind.
- A clip you saved elsewhere — to your camera roll, or sent to someone — is outside the app and yours to delete.
- Text already sent to the Coach cannot be recalled from the provider. Nothing sent identifies you, but it has been sent.
12Retention
13Your rights
Australian privacy law, and the GDPR where it applies to you, give you rights to access, correct, delete and export your personal information, and to complain.
In FormCheck's case those rights are unusually easy to exercise, because we hold nothing: access is the app itself, which shows you everything it has including its own usage log; deletion is the Erase control; correction is editing it in the app. There is no request for us to fulfil because there is no copy for us to hold.
If you want to complain about how FormCheck handles data, email hello@formcheckco.app first — we will respond within a reasonable time and tell you what we did. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to your local supervisory authority if you are in the UK or the EU.
14What we never do
- We never sell, rent or trade anything about you. There is nothing to sell and nowhere it goes.
- We never show advertising, and there is no advertising SDK in the app.
- We never track you across apps or websites, and never build a profile of you.
- We never upload a clip, a still, or landmark data.
- We never hide a number the app has measured behind a payment.
- We never claim the app can predict or prevent an injury for an individual. See the terms and what it is not.
15Changes and contact
If this policy changes in a way that matters — a new thing leaving the device, the community feature being switched on, a real account server — we will change the version and the effective date at the top of this page, and say what changed. We will not quietly broaden it.
hello@formcheckco.app
A real person reads these. See also the support page.
Effective 7 September 2026 · version 2.0 · supersedes the policy dated 5 September 2026