Beta — last updated 2026-10-02
PoseDuel Privacy Policy (Draft)
DRAFT — NOT PUBLISHED. Requires review by qualified Swiss counsel before publication; nothing here is legal advice.
Corrected 2026-09-14. The retention description in Sections 3 and 4 was factually wrong: it described raw video being kept for up to 90 days and said nothing about the on-device face blur that has shipped since 2026-08-30. The video rows/bullets now describe the architecture actually in production — faces pixelated on the device before upload, raw footage transient (~24 h), only a face-pixelated + background-blurred clip retained. The engineering source of truth is
PRIVACY.mdanddocs/specs/2026-08-30-privacy-blur.md; if this draft and those disagree, those are right and this is a bug.Repositioned 2026-10-02. PoseDuel is an adult-first prehab and movement-practice game; younger players are not excluded, but the service is not designed for or directed at children. The audience wording below was rewritten to match, Section 6 now covers minors who play, and AI-provider processing is limited to recordings of confirmed adults (
docs/specs/2026-10-02-adult-first-llm-compliance.md).Blur is a default, not an absolute (2026-10-03). Every account blurs the player's face and the background, and either can now be switched off for an account (
docs/specs/2026-10-03-per-account-privacy-settings.md). The sentences below that said faces never leave the device now say "by default" and Section 1 describes the two settings. The privacy modes and retention figures in Sections 3 and 4 still describe more than the product does — a known gap (PRIVACY.md), not touched here.
Effective date: to be set on publication (this draft: 2 October 2026) Who we are (the "controller"): Iris360 SA, Chemin Davel 14, 1009 Pully, Switzerland — the company that makes PoseDuel (poseduel.com). Privacy contact: privacy@poseduel.com. EU representative (GDPR Art. 27): Mike Nolet — reachable via privacy@poseduel.com.
PoseDuel is a webcam prehab and movement-practice game: it uses your cameras to count your reps and score your form while you play. It is built for adults. Younger players may also play, but only through an account held by a parent or legal guardian (Section 6). Either way we handle video and movement data recorded in your home — sensitive data that deserves care. This policy explains, in plain language, exactly what we collect, why, how long we keep it, and the controls you have. The short version: you choose a privacy mode, the strictest cloud mode is the default, all modes are free, faces are blurred on your device unless the account holder switches that off, recordings of minors never go to an AI provider, and we never sell data or show ads.
1. What we collect
| Category | What it is | Who it's about |
|---|---|---|
| Camera video | Live video from the laptop/desktop webcam and, if you pair one, a phone camera, while you play. Whether video ever leaves the device depends on your privacy mode (Section 3) — and when it does leave, the faces in it have already been pixelated on the device, unless the account holder switched the face blur off (see below). | The player (and anyone who walks into frame — keep the play space clear) |
| Pose data | Skeleton keypoints (dots-and-lines stick-figure coordinates) computed from the video, plus rep counts, movement-quality scores, and exercise timing. Pose data is not a photo, but it is still personal data — movement patterns can be identifying. | The player |
| Account data | The account holder's email address, password (hashed), display/hero names (we ask you to use nicknames, not real names), whether a player is an adult or a minor, subscription and payment status. We do not collect a minor's email, phone number, or precise location. | The account holder (an adult); minimal player info |
| Health-context data | The exercise program configured for the player (which exercises, targets, difficulty tiers). We do not ask for diagnoses, and we ask you not to enter medical details in free-text fields. | The player |
| Telemetry | Technical logs: session times, feature usage, errors, device/browser type, approximate region from IP (for security and server routing), performance metrics. No advertising identifiers, no cross-site tracking, no third-party analytics cookies. | Mixed |
| Communications | Emails you send us, and consent records (what you agreed to, when, and — for a minor — how we verified you're their parent or guardian). | The account holder |
By default, faces never leave the device. In the modes where video is uploaded
at all (Balanced, Full Analysis), the player's head is pixelated on your device,
inside the recorder, before the video is encoded and sent, so the upload does not
carry the player's identifiable face. The treatment fails closed: if pose
tracking goes stale for more than 400 ms, the whole frame is blurred rather than
risk a single unpixelated frame. Before the clip is stored for any length of
time, the background is blurred too, so the stored clip shows a pixelated head
against a blurred room. These are enforced in code, not by policy alone — the
implementation and the deletion guards are documented in
PRIVACY.md.
The two blur settings. Every account has two settings, both on unless the account holder asks for one to be turned off: blur the face and blur the background. There is no in-app control yet — write to privacy@poseduel.com. A change applies to recordings made after it; earlier recordings keep what they were made with. With the face blur off, the player's face is recorded, stored and visible to the people who review clips — and, on an adult's account, to the AI provider that generates form feedback. With the background blur off, the room and anyone else in frame are visible in the stored clip. The face blur covers the player being tracked; other people in the room are covered by the background blur.
We never: sell personal data, show ads, use advertising trackers, or use your data to train third-party AI models. Where we use an AI provider (Google Gemini) to generate form feedback, it receives clips of confirmed adult players only — a recording of a minor, or one whose player we have not confirmed is an adult, is never sent to it. We use it via API, whose terms prohibit using our data to train Google's models.
2. Why we process it (purposes and legal bases)
European and Swiss law require us to name a legal basis for every use of personal data — this table is that list, in plain language.
| Purpose | Data used | Our legal basis |
|---|---|---|
| Running the game: detecting reps, scoring movement quality, progressing the player through encounters | Video (per mode), pose data, exercise config | Running the platform: our contract with you. Video, pose and health-context data: your explicit consent — for a minor, their parent's or guardian's (GDPR Arts. 6(1)(a), 9(2)(a); FADP Art. 6(7)) |
| AI feedback on exercise form (our AI movement coach — an AI, not a health professional) | Video clips (Balanced/Full Analysis modes; adult players only for any AI-provider step), pose data | Explicit consent |
| Personalised difficulty thresholds | Pose data history | Explicit consent |
| Improving our detection and scoring models | Pose data and (Full Analysis mode only) video, per Section 3 | Separate, optional explicit consent — never required to play |
| Review of selected clips by qualified movement professionals under confidentiality contract, to keep scoring honest | Selected face-pixelated, blurred clips (Balanced/Full Analysis only) | Explicit consent (called out in the mode description) |
| Accounts, billing, support | Account data, communications | Contract performance; legal obligations (accounting) |
| Security, abuse prevention, debugging | Telemetry | Legitimate interest — narrow logs, short retention (GDPR Art. 6(1)(f)) |
| Proving we obtained proper consent (including parental consent for a minor) | Consent records | Legal obligation / legitimate interest |
Where the person giving consent is a minor's parent or guardian, "your consent" above means theirs. For US users, if a player is under 13 we comply with COPPA (16 CFR Part 312): we obtain verifiable parental consent before collecting any personal information from that child, we collect no more than is reasonably necessary for them to play, and we maintain a written data retention policy (this Section 3 and Section 4 are its public summary).
3. The four privacy modes — your choice, all free
You (the account holder) pick the mode during setup and can change it anytime in Settings. No mode is ever paywalled. The default is Private. Switching down takes effect immediately; switching up requires re-confirming consent.
| Mode | What leaves the device | Video retention | Pose data retention | What you trade off |
|---|---|---|---|---|
| Local-Only | Nothing. All processing happens in the browser on your device. | Never uploaded | Never uploaded; stays on-device | No AI form feedback, no personalised thresholds, no cross-device sync |
| Private (default) | Pose/skeleton data only — video never leaves your device | Never uploaded | Kept while the account is active, to power thresholds and progress | No AI video feedback, no clip review |
| Balanced | Video with faces pixelated on-device before upload; pose data | The uploaded working copy is deleted within ~24 hours (24 h after the clip is scored; 72 h if it is never scored; 24 h outright if processing fails). What remains afterwards is only the face-pixelated, background-blurred clip, kept while the account is active — see Section 4 | Kept while account active; contributed to model improvement | Some blurred clips are seen by our contracted movement professionals |
| Full Analysis | Video with faces pixelated on-device before upload; pose data | Same lanes as Balanced: raw working copy gone within ~24 hours, only the face-pixelated, background-blurred clip retained while the account is active — see Section 4 | Kept while account active; contributed to model improvement | Most data shared with us; full AI analysis and fastest personalisation |
"Model improvement" means we use the data to make rep detection and form scoring better for everyone. It never means advertising, sale, or unrelated AI training. You can withdraw from model improvement at any time; we stop using that data going forward and delete it from our training sets within 30 days.
4. How long we keep things (retention)
- Video: Local-Only/Private — we never have it. Balanced/Full Analysis — every uploaded clip arrives with faces already pixelated (Section 1), and the raw upload is a transient processing input, not a stored asset: it is deleted 24 hours after the clip has been scored, 72 hours if it never gets scored, and 24 hours outright if processing fails before a stored clip exists. After that only the face-pixelated, background-blurred clip remains; it is kept while the account is active and deleted within 30 days of account deletion (Section 8) or of withdrawing model-improvement consent (Section 3).
- Pose data and game progress: while the account is active. Deleted within 30 days of account deletion.
- Account data: while the account is active; billing records as long as Swiss accounting law requires (10 years, invoices only).
- Telemetry/logs: 90 days.
- Consent records: as long as the account exists plus 5 years (to prove compliance).
When you no longer need the service, delete the account (Section 8) — we do not keep anyone's data "just in case."
5. Who processes data for us (sub-processors)
We use a small set of infrastructure providers under data-processing agreements. They may only process data on our instructions.
| Provider | What they do | Where |
|---|---|---|
| Google Cloud Platform (GCP) | Video/pose storage and processing | europe-west1 (Belgium) |
| Supabase | Database (accounts, progress, pose data) | EU |
| Vercel | Web hosting and serverless functions | EU (its edge network is global) |
| Google Gemini (via API) | Generates AI form feedback from clips/pose data — recordings of confirmed adult players only; never a minor's | EU; our data is not used to train Google's models |
| Resend | Sends account and consent emails to account holders | EU |
| Qualified movement professionals under contract | Review selected face-pixelated, blurred clips (Balanced/Full Analysis only) | Switzerland/EU |
ElevenLabs generates the game's sound effects and music during development; no user data is ever sent to it. A payment processor will be added to this table before subscriptions launch. We will update this table before adding any sub-processor and notify account holders of material changes.
6. Minors who play
PoseDuel is built for adults, and accounts may only be held by adults. It is not designed for or directed at children, but a minor may play through an account held by their parent or legal guardian, who consents for them. When a minor plays:
- We collect no personal information about the minor until the parent or guardian has been verified and has consented (COPPA "verifiable parental consent" for players under 13; GDPR Art. 8; Swiss FADP). Verification method we use: payment-card verification (additional methods may be added).
- Their recordings are never sent to an AI provider. AI-provider processing is limited to recordings of confirmed adult players; a recording of a minor — or of any player we have not confirmed is an adult — is excluded.
- By default, faces never leave the device, exactly as for every player (Section 1), and the same retention lanes apply (Section 4).
- The consent ceremony shows exactly what each privacy mode collects before the parent or guardian chooses. Consent to play is never bundled with consent to model improvement — those are separate choices.
- We never condition a minor's participation, or any prize or feature, on providing more data than the game needs (16 CFR §312.7). Their game experience is identical in every privacy mode except for the features that technically require the data (AI video feedback needs video).
- Minors never see privacy-mode choices, and nothing in-game rewards or pressures data sharing.
- A recording indicator is shown on every capturing camera while a session runs.
- If we learn we collected a minor's data without valid parental consent, we delete it.
7. No sale, no ads
We do not sell or rent personal data. We do not show advertising. We do not permit third parties to collect data through PoseDuel for their own purposes. If US state privacy laws apply to you (e.g., CCPA/CPRA): we do not "sell" or "share" personal information as those laws define it.
8. Your rights and how to use them
Every account holder, everywhere: a Settings dashboard where you can view the account's data (including any minor's you consented for), change privacy mode, withdraw any consent, export data (machine-readable), and delete the account and all associated data — self-serve, no email required, effective within 30 days across our systems and sub-processors (backups purge within 90 days).
- Switzerland (FADP): right to information (Art. 25), rectification, deletion, data portability (Art. 28), and to complain to the FDPIC (Federal Data Protection and Information Commissioner, Bern — edoeb.admin.ch).
- EU/EEA (GDPR): access (Art. 15), rectification (16), erasure (17), restriction (18), portability (20), objection (21), withdrawal of consent at any time without affecting past lawfulness (Art. 7(3)), and complaint to your national supervisory authority.
- US (COPPA parental rights, players under 13): review the personal information collected from your child, refuse further collection or use, and direct us to delete it — and we may not deny the child access to the service for exercising deletion rights beyond the data the service genuinely needs.
Withdrawing a consent never degrades your subscription and is as easy as giving it (one click in Settings).
9. International transfers
Data lives in Europe (GCP europe-west1; Supabase EU region). Should a sub-processor ever process data outside Switzerland/EEA, we rely on the Swiss–US Data Privacy Framework / EU–US Data Privacy Framework where the provider is certified, or on the EU Standard Contractual Clauses with the Swiss addendum, plus technical measures (encryption in transit and at rest). Details available on request.
10. Security
Encryption in transit (TLS) and at rest; access to video restricted to the minimum staff and contracted reviewers needed, all under confidentiality obligations, with access logging; signed, expiring URLs for media; regular deletion jobs enforcing the retention table above. No system is perfectly secure — if a breach affects your data, we will notify you and the competent authority as the FADP/GDPR require.
11. Changes to this policy
We'll post changes here and email account holders before material changes take effect. If a change expands what we collect, we will ask for fresh consent first — including a parent's or guardian's for any minor — and silence never equals consent.
12. Contact
Iris360 SA — Chemin Davel 14, 1009 Pully, Switzerland · privacy@poseduel.com EU representative: Mike Nolet (via privacy@poseduel.com) · US COPPA inquiries: same email.
This policy is written to satisfy the Swiss FADP, the EU GDPR, and the US COPPA Rule (as amended 2025). If a translation conflicts with the English original, the original governs.