← Home
# HoopLix Privacy Policy

**Last updated: 2026-08-05** (strengthened in your favour: we do not train AI models on your content — the previous opt-in carve-out is removed entirely)

---

## 1. Who we are

HoopLix is a basketball video-analysis service operated by **Hooplix Technology Inc.**, a Canadian federal corporation (incorporated under the *Canada Business Corporations Act*) extra-provincially registered in Saskatchewan, with its principal place of business at 2014 Aurora Blvd, Suite 1014, Regina, SK S4V 3T7, Canada.

For privacy questions or to exercise any of the rights described below, contact:

- **Email:** [email protected]
- **Privacy Officer:** Our Privacy Officer — the person in charge of protecting personal information, as required by Quebec's *Act respecting the protection of personal information in the private sector* (Law 25) — can be reached at [email protected].
- **DSA / EU representative:** The Service is not directed at users in the European Union. A representative authorised to receive notifications under DSA Article 13 will be appointed before the Service is directed at the EU market.
- **Postal mail:** Hooplix Technology Inc., 2014 Aurora Blvd, Suite 1014, Regina, SK S4V 3T7, Canada

We are the **controller** of the personal data you submit to us. When you copy a clip another user shared with you (see § 7 below), you become an **independent controller** of the data in that copy.

Before we launch a new feature that processes personal information, we carry out a privacy impact assessment, as contemplated by Quebec's Law 25.

---

## 2. What data we collect and why

### 2.1 Account data

When you create an account we collect:

| Data | Source | Why we have it | Legal basis (GDPR Art. 6) |
|------|--------|----------------|---------------------------|
| Email address | You | Login + transactional email + recovery | Contract (Art. 6(1)(b)) |
| Username | You | Public display name in community | Contract |
| Hashed password | You (optional — Google OAuth users have none) | Authentication | Contract |
| Google account ID + email | Google (if you sign in with Google) | Authentication | Contract |
| `tos_accepted_at` timestamp | System | Evidence of consent to ToS | Legal obligation (Art. 6(1)(c)) |
| Avatar image (if you upload one) | You | Profile display | Contract |

### 2.2 Content data

When you upload basketball footage, we and our processors store and analyse:

| Data | Why | Retention |
|------|-----|-----------|
| Original video file | To run the analysis you requested | Until you delete it. Free-tier accounts inactive for **12 months** are sent a 30-day deletion warning, then purged. |
| Derivative files (thumbnails, transcoded proxies, exported clips, animation videos) | Faster playback + the export you asked for | Until you delete them (or their parent item); they count against your plan's storage quota. Files shared into a club expire from the club's shared area after **7 days**. |
| AI analysis output (court keyframes, player tracks, segment boundaries) | What the product does | Until you delete the parent video |
| User-supplied annotations (text, voice, drawings) | Inline with the clip | Until you delete the parent video |

We do **not** train HoopLix's AI models on your audiovisual content. There is no opt-in for this and we do not collect user content for model training.

### 2.3 Operational data

| Data | Source | Why | Retention |
|------|--------|-----|-----------|
| IP address + user-agent on share-link streams | Network | DMCA / subpoena response under §512 + DSA notice handling | **90 days** |
| Email send log (recipient + template + status) | System | Debugging delivery + audit trail for transactional mail | **90 days** |
| Audit log of admin actions on your account | System | Accountability for moderation and tier changes | **12 months** |
| Security events on your account (sign-in success/failure, account lockout, password reset, two-factor changes, data-export requests, upload completions, share-link creation/revocation) with IP address + user-agent | System / Network | Detect and investigate account compromise; keep a tamper-evident security trail | **180 days** (IP + user-agent erased immediately on account deletion) |
| Usage ledger (per-job duration, GPU-seconds) | System | Quota enforcement + billing reconciliation | Calendar-month aggregate retained **24 months**; row-level detail retained **13 months** |
| Application access logs (HTTP requests) | Network | Security + debugging | **30 days** |
| Audience-analytics session (active dwell time, device class, plan tier, approximate location — country/region/city) linked to your account when you are signed in | In-app usage beacon + Cloudflare edge geolocation | Understand product usage and produce **aggregate** ad-audience reporting | Raw session rows **7 days**; de-identified daily aggregates retained longer |

### 2.4 Payment data

If you subscribe to a paid plan, **billing details are handled by Stripe** — see § 4. We never store your full card number; Stripe gives us a tokenised customer ID and subscription status.

### 2.5 Cookies

See our [Cookie Policy](/legal/cookies) for the per-cookie breakdown. Summary: we use functional cookies for login session and CSRF protection only. We do **not** use third-party advertising or analytics cookies on the HoopLix application surface (the future ad slots inside `/s/{token}` share pages run within VAST players and do not set cookies on the HoopLix origin).

**Approximate location for ads.** We derive an approximate location (country and city) from your IP address when an ad is served, to show geographically relevant first-party ads (for example, a local sponsor) and for aggregate ad reporting. This lookup runs on our own servers using a local geolocation database (MaxMind GeoLite2); your IP address is used only for this momentary lookup and is **not stored** with the ad record — we keep only the resolved country/city. We do **not** share your IP address or location with third-party advertisers.

**Approximate location for audience analytics.** For the audience-analytics session described in § 2.3, approximate location (country/region/city) is derived **at the Cloudflare edge** from the network connection and forwarded to us with the session; your raw IP address is **not stored** with the analytics session — we keep only the resolved country/region/city, linked to your account while you are signed in. Raw session rows are deleted after 7 days; only de-identified aggregates are retained for reporting, and these are never sold or shared with third-party advertisers.

### 2.6 Desktop application (HoopLix Smart Clip)

HoopLix Smart Clip is a downloadable desktop application for Windows and macOS. It is governed by this policy and the [Desktop App EULA](/legal/desktop-eula). What it does with your data differs from the web app in these specific ways:

| Data | What happens | Where it goes |
|------|--------------|---------------|
| **Sign-in** | Sign in with Google uses your system browser (not an embedded window) and the OAuth scopes `openid email profile`. The exchange happens on our server; the app never holds Google's client secret. | Your Google email + account ID, sent to our API to mint a HoopLix session — same account as the web app. |
| **Authentication tokens** | Your HoopLix access + refresh tokens are stored **encrypted in your operating system's keychain** (Windows DPAPI / macOS Keychain via Electron `safeStorage`). | Stay on your computer. **Sign out** deletes them. |
| **Your videos** | Clip extraction and trimming run **entirely on your computer** using the bundled FFmpeg — those videos are never uploaded. Only when you choose **Smart Clip** is a single low-resolution span uploaded for cloud analysis. | The Smart Clip span is uploaded to our processing pipeline (Cloudflare R2 → Modal GPU) and metered against your quota, exactly like the web app. Your original video never leaves the machine. |
| **Game Library** | The library is a set of small `.library` project files on your disk that *reference* your videos by path. | **Stored only on your computer** — never uploaded. Deleting a project never touches your video file. |
| **Analytics / crash reporting** | **None.** The desktop app contains no analytics, telemetry, or crash-reporting SDK. | Nothing is sent. |

**Uninstalling** the app does not automatically remove your local data: the encrypted token file (`auth.bin`) and your `.library` project files remain on disk until you delete them (or sign out, which clears the tokens). On Windows they live under `%APPDATA%\HoopLix Smart Clip`; on macOS under `~/Library/Application Support/HoopLix Smart Clip` and your chosen Game Library folder.

### 2.7 Social features (Academy)

The Academy is a **logged-in-only** social layer: it is visible to signed-in HoopLix members and is **not published to the public web**. Your profile and avatar are covered by § 2.1; the additional data the Academy collects is:

| Data | Source | Why we have it | Retention | Legal basis (GDPR Art. 6) |
|------|--------|----------------|-----------|---------------------------|
| Profile bio (≤ 280 characters) | You | Members-visible profile display | Until you edit or delete it — but see the *Deletion and tombstones* note below | Contract (Art. 6(1)(b)) |
| Social + resource links (title, URL, description, uploaded thumbnail) | You | Lets you surface resources and links on your profile | Until you delete the card — see tombstone note | Contract |
| Follow graph (who you follow; who follows you) | You + other members | Builds your feed and your connections | Until you unfollow, or delete your account | Contract |
| Block list (members you have blocked) | You | Enforces a user-safety control you chose — see [AUP § 4.5](/legal/aup) | Until you unblock, or delete your account | Legitimate interest — user safety (Art. 6(1)(f)) |
| Guestbook comments (yours, and comments other members leave on your profile) | You + other members | The profile guestbook feature | Until deleted — see tombstone note | Contract |
| Direct messages (message content + the two participants) | You + your correspondent | Delivers the 1:1 messages you send; stored on our servers so both participants can read the thread | Until deleted — see tombstone note; a *reported* message is read by moderation (see below) | Contract; the moderation read is legitimate interest (Art. 6(1)(f)) |
| In-app notifications | System | Tells you about follows, comments, messages, and moderation outcomes | Until read/cleared, or your account is deleted | Contract |
| Moderation reports you file, or that name you (`community_reports`: reporter identity + the allegation) | You (as reporter) + system | Triage abuse and keep an audit trail of what was reported and how we actioned it | See the *Moderation records* note below | Legitimate interest — platform safety (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) where retention is legally required |

**Deletion and tombstones.** You can delete your Academy posts, resource links, guestbook comments, direct messages and profile bio individually in-app. Deleting content removes it from view, but we keep a **tombstone that retains the original text indefinitely** as a moderation and audit record. This retention is deliberate: abuse such as harassment, threats, and grooming is frequently reported *after* the author has deleted the message, and a permanent record prevents a bad actor from erasing the evidence simply by deleting it. Tombstones are access-restricted to our moderation and legal functions and are never shown to other members.

**Moderation records.** Records in `community_reports` (who reported, what was alleged, and how we actioned it) are retained in line with our moderation records. Where a report led to a **copyright** action, the associated record is retained for at least **5 years** under our [Repeat Infringer Policy § 5](/legal/repeat-infringer); other moderation records are retained for the period needed to enforce this policy and defend against repeat conduct, consistent with the audit-log periods in § 2.3.

**Direct messages and moderation.** Direct messages are private between the two participants. However, if a message is **reported** to us, our moderation team reads the reported message (and adjacent messages in the same thread where needed to judge context) in order to assess the report; where the report concerns a minor-safety matter our internal minor-safety procedures also apply. We do not otherwise read your private messages.

We identify these purposes, seek your consent, and describe this processing in line with **PIPEDA Principles 2 (Identifying Purposes), 3 (Consent) and 8 (Openness)**, and — for users to whom the GDPR applies — **Article 13** (information provided at the point of collection) together with the Article 6 bases set out in the table above.

### 2.8 Custom Court designs and entitlements

Custom Court lets an entitled user restyle the **appearance** of the tactical court and apply that design to exported videos. The additional data this feature collects is:

| Data | Source | Why we have it | Retention | Legal basis (GDPR Art. 6) |
|------|--------|----------------|-----------|---------------------------|
| Court design library (design name, chosen colours, and the sideline / baseline / infield design text) | You | Stores the court appearance you configured so you can re-use it and apply it to exports | Until you delete the design or your account — **including after your Custom Court entitlement lapses** (see the note below) | Contract (Art. 6(1)(b)) |
| Custom Court design images (a floor image, a paint/key image, and a centre-circle logo), stored in Cloudflare R2 | You | The uploaded images composited into your court design and its exports | Until you delete the design or your account; the images **count against your plan's storage quota** | Contract |
| Custom Court entitlement and pack records (grant history, whether purchased or gifted, price paid, and the source of the grant) | System + you | Determines whether you may apply a Custom Court design and export without the watermark, and reconciles billing for any purchased pack | For the life of the account, plus the period needed for billing, tax, and audit reconciliation | Contract; legal obligation (Art. 6(1)(c)) for billing/tax records |

**Retention after an entitlement lapses.** By design, your saved court designs and their uploaded images are **kept after a Custom Court pack expires or a paid plan ends** — they are not automatically deleted when the entitlement lapses, so your design is still there if you become entitled again. Because they are kept, the design images continue to count against your storage quota until you delete the design (or your account). You can delete any design at any time in-app, and deleting a design removes its rows and its uploaded images.

The PIPEDA Principle 2, 3 and 8 and GDPR Article 13 transparency described at the end of § 2.7 applies to this processing as well.

---

## 3. How we use your data

We process the data above to:

- Provide the HoopLix service to you (account login, video analysis, sharing, community features);
- Enforce quotas and abuse rules (rate limits, daily caps, concurrent-job caps);
- Communicate with you about your account (verification, password reset, quota warnings, abuse-report acknowledgements);
- Comply with legal obligations (DMCA / DSA notice-and-action, tax accounting);
- Improve the service (aggregated usage statistics with personal data stripped — see § 2.2: we do not train AI models on your content).

We do **not**:

- Sell or rent your personal data to third parties;
- Share your data with advertisers or data brokers;
- Use your videos to train HoopLix's AI models.

---

## 4. Sub-processors and data transfers

We use the following sub-processors. Each has its own privacy commitments and Standard Contractual Clauses or equivalent transfer mechanisms in place where personal data crosses jurisdictions.

| Sub-processor | What they do for us | Data shared | Region |
|---------------|---------------------|-------------|--------|
| **Stripe** | Subscription billing | Email, billing address, card token | US / global |
| **Resend** | Transactional email delivery | Recipient email + message body | US |
| **Cloudflare** | DNS, CDN, DDoS protection, R2 object storage, Pages hosting | Request metadata, IP, video files | Global edge |
| **Fly.io** | API + worker compute | Request payloads, stored DB rows | IAD (US East — Ashburn) |
| **Neon** | Postgres database | All structured data described in § 2 | us-east-2 (Ohio) |
| **Upstash** | Redis (job queue, rate-limit counters, SSE pub/sub) | Job IDs, IP-keyed counters | us-east-1 (Virginia) |
| **Modal** | Elastic GPU inference (Smart Clip / Scan H) | Video frames during processing only | US |
| **Backblaze B2** | Encrypted off-site database backups (disaster recovery) | Full encrypted database snapshot (all structured data in § 2), Object-Lock retained | US |
| **Sentry** | Application error and performance monitoring | Opaque account ID + plan tier/role tags and error/stack context (request path only — query strings are scrubbed); **no email, no IP address** | US |
| **Google** | Sign in with Google | Your Google email + account ID | Global |

We do **not** allow these sub-processors to use your data for their own purposes. Stripe processes payments under the relevant card-network and PCI rules; the others act purely as service providers.

**International transfers:** because the providers above include US-based infrastructure, personal data of EU/UK residents will be transferred to the US under Standard Contractual Clauses (EU Commission decision 2021/914) or the EU-US Data Privacy Framework where applicable.

---

## 5. Your rights

### 5.1 Universal rights

You can, at any time:

- **Access** your data via Settings → Profile + Settings → Usage (current month) + a CSV export of your activity ledger at `GET /api/users/me/usage/ledger.csv`.
- **Correct** your username, password, and avatar from Settings.
- **Delete** any video, segment, or animation clip from the corresponding tile menu (share links: contact [email protected] — a self-service revocation page is planned). Your Academy profile content, posts, resource links, guestbook comments and direct messages are each individually deletable in-app; note that a redacted moderation tombstone may be retained after deletion (see § 2.7). Account-level deletion: Settings → Danger Zone → Delete account (soft-deletes immediately; hard-deletes after a 30-day cooling-off window).
- **Object** to specific processing activities (e.g. quota notification emails) via the unsubscribe link in those emails.

### 5.2 GDPR / EU rights (if you are in the EU/UK/EEA)

In addition to the universal rights above, you have the right to:

- **Restrict processing** while you contest accuracy or legitimate basis;
- **Portability** — receive your data in a machine-readable format. The CSV export in § 5.1 covers your **activity and usage** data; it does **not** include your Academy profile, posts, resource links, guestbook comments, direct messages or social graph. Your **Custom Court designs (their names, colours and design text, together with the three uploaded design images) and your Custom Court pack/entitlement records** can be exported by you at any time from `GET /api/users/me/usage/custom-court-data.json`. For a full copy of your account data including your Academy content, email [email protected] and we will provide a machine-readable export within the applicable statutory window (this export is currently produced manually — see § 5.5 for timing);
- **Lodge a complaint** with your national supervisory authority.

**Erasure and encrypted backups.** When you delete your account we erase your data from our live systems (database and object storage) after the 30-day cooling-off window. Your data may still exist inside our **encrypted, off-site disaster-recovery backups** (Backblaze B2, § 4) for up to the backup retention window — currently **35 days** — because those backups are held under an immutability lock (Object-Lock) that, by design, prevents anyone (including us) from selectively editing or early-deleting a snapshot. Erasure from backups therefore completes when the affected snapshots **expire**, not immediately. Backups are only ever read to recover from a disaster; an erased account is not restored except as an unavoidable side effect of a full disaster-recovery event, after which we re-apply your erasure.

### 5.3 California rights (CCPA / CPRA)

If you are a California resident:

- We do not sell or share personal data, so the "Do Not Sell or Share" disclosure does not change anything for HoopLix users.
- You may request a copy of the personal information we hold about you, request its deletion, and request that we correct inaccuracies. Use [email protected] or the Settings → Danger Zone → Delete account flow.
- We will not retaliate (e.g. by reducing service quality) for exercising these rights.

### 5.4 Other jurisdictions

We honour broadly equivalent rights for users in jurisdictions with similar laws (e.g. LGPD in Brazil, PIPEDA in Canada, the UK GDPR). Contact [email protected] to make a request.

### 5.5 Response time

Two different clocks, because these are two different requests:

| Request | We reply within |
|---|---|
| **Takedown** — "remove this content" / "remove my child from this footage" | **2 business days** |
| **Data-subject request** — access, export, correction, deletion of *your account's* data | **30 days** (the statutory window is typically 30–45 days; we will tell you if we need an extension) |

The 2-business-day figure is when you hear from a human, not necessarily when the matter is closed — a takedown that needs the uploader's cooperation can take longer, and we will say so rather than go quiet.

---

## 6. Children's data (COPPA / under-16)

HoopLix is **not directed at children under 16**. We use the EU GDPR-K ceiling (16) rather than COPPA's 13 so the same age rule applies to every jurisdiction we serve. We do not knowingly collect personal data from children under that age. Registration requires you to attest that you are at least 16 years old (this attestation is part of the sign-up consent), and if we learn that an account holder is under 16 we close the account and delete the data. If you believe a child created an account, contact [email protected] and we will close the account and delete the data.

### 6.1 People who appear in footage but are not users

Basketball footage frequently shows minors (youth-league, high-school, amateur). Someone *appearing in* uploaded footage is not a "user" of HoopLix and has no account with us, and the uploader's obligations for that footage are set by ToS § 9 (Minor Identifiability and Consent) — but that describes the uploader's duty, not your route to us. This section is your route.

**If you are a parent or guardian and your child appears in footage on HoopLix**, email **[email protected]**. Tell us as much as you can about where you saw it — a link if you have one, otherwise the coach, club or team, and roughly when. **We will reply within 2 business days.**

Please be aware of what we can and cannot do, so that our answer is not a surprise:

- **With a link, we can act quickly.** We can identify the material, remove it, and tell you when it is gone.
- **Without a link, we may not be able to find it.** We do not keep any record of who appears in any video — no names, no faces, no team or school rosters. The only thing we can search is text an uploader happened to type. This is a deliberate design choice: making a child findable in our system would require building exactly the identification system we do not think we should have.
- We will contact the uploader on your behalf if you would rather not.

We will not ask you to prove your child's identity. Removing a child's data should not require us to collect more of it.

**Do not use this address for an emergency.** If a child is in immediate danger, contact local police. If the material appears to be child sexual abuse material, report it to the [CyberTipline](https://report.cybertip.org) (US) or [Cybertip.ca](https://cybertip.ca) (Canada) — and to us at [email protected], which we treat as the highest priority.

---

## 7. Share links

When you create a share link, the recipient sees a public URL of the form `https://hooplix.com/s/{token}`. The token is a 22-character random string (~132 bits of entropy) and is **the** access control — anyone with the token can view the clip.

We log every successful stream of a share link (token + IP + user-agent + bytes served) for **90 days** (§ 2.3). This log exists to support DMCA / subpoena requests and abuse triage; we do not use it for advertising or analytics.

When you (or our abuse team) revoke a share link, the underlying file is purged within **48 hours** — longer where a legal hold applies (e.g. a pending DMCA counter-notice window) — and the database row is retained for **12 months** for auditability before being hard-deleted.

If you toggle `allow_copy=true` on a share, recipients may clone the clip into their own library. They become an independent controller (see § 1) and accept the responsibilities listed in our ToS § 9.3.

---

## 8. Security

We protect your data using industry-standard practices:

- TLS 1.2+ on every public endpoint;
- Passwords hashed with bcrypt;
- JWTs scoped per-origin (admin panel and main app run on separate origins, so a token compromise on one cannot escalate to the other);
- Refresh-token revocation on password change and admin-initiated session termination;
- Rate limiting (per-IP + per-user) on every job-creation endpoint;
- Daily backups of the primary database with monthly restore drills;
- Sub-processors selected on the basis of their own published security standards (Stripe PCI-DSS, Cloudflare ISO 27001, etc.).

If a breach affects your data we will notify you within **72 hours** of becoming aware, in line with GDPR Art. 33–34 and analogous laws.

---

## 9. Changes to this policy

We will update this page when our data practices change. Material changes are announced in-product and by email at least **30 days** before they take effect. The "Last updated" date at the top tracks the most recent revision.

The revision dated **2026-07-13** — which introduces the Academy social features (§ 2.7) — takes effect on publication. It was made during closed beta, before the Service became generally available, so there were no existing users to notify in advance; the 30-day advance-notice commitment above applies to material changes made once the Service is generally available.

The revision dated **2026-07-14** — which introduces the Custom Court feature and its data (§ 2.8) and adds the self-service Custom Court export to the portability right (§ 5.2) — takes effect on publication on the same closed-beta basis.

---

## 10. Contact

- Privacy questions: [email protected]
- Abuse / DSA Article 16: [email protected] (or in-product **Report this clip**)
- DMCA: [email protected] (registered Designated Agent — see [DMCA Policy](/legal/dmca))
- Third-party licence inventory: [`/api/legal/licenses`](/api/legal/licenses)