Your privacy
Privacy Policy
This policy explains how VBall AI handles information when you use our website and Android application.
Last updated: 12 August 2026
About this policy
This Privacy Policy applies to VBall AI, available at vballai.com and through the VBall AI Android application. It describes the data practices of the current app architecture.
Information processed by VBall AI
- Account information: when you use Google Sign-In, Firebase Authentication processes and stores your Google/Firebase user identifier (UID), email address and, when provided by Google, your display name.
- Original selected video: when you request an analysis, the volleyball clip you select is uploaded once from your device to VBall AI's server-side video processor so that the relevant volleyball action and analysis frames can be selected.
- Derived analysis media: candidate frames, contact sheets, dense frames and final selected frames may be created temporarily. When video-native analysis is enabled, the processor may also create a shortened, compressed action clip, normally limited to approximately four seconds at up to 720p and without audio.
- Analysis context: selected volleyball skill, player or profile context needed for coaching, prompts, verification information and other context needed to perform and validate the requested analysis.
- AI analysis result: the service generates technique feedback, scores and personalized drills. Validated results may be temporarily cached by the Worker or Cloudflare for up to 30 days.
- Local app data: analysis results, profile preferences, onboarding state and related app state are stored primarily on your device. Development keyframes are saved locally only when keyframe debugging is enabled in Profile.
- Crash and stability diagnostics: release builds use Firebase Crashlytics to report crashes, non-fatal errors and Application Not Responding (ANR) events. Reports may contain stack traces, exception or error details, relevant application and thread state, app version or build information, operating-system and device metadata, event time, a Crashlytics installation UUID and a Firebase installation ID.
- Operational data: the backend stores account records, usage or credit records, analysis-job metadata and operational metadata, but does not use the database to store permanent video, contact-sheet or keyframe files.
- Aggregate product analytics: the backend also records a limited set of non-identifying, aggregate analytics events about each analysis (for example: whether it started, completed, failed or was rejected, the selected skill, processing duration, retry count, confidence scores and feedback category). These events are tied to your internal account identifier, not your email address, and never include the video itself, extracted frames, contact sheets, or full AI prompts or responses. This data is used only to monitor and improve analysis quality and reliability, is kept for a limited period (90 days by default), and is deleted when you delete your account.
- Communications: we process information you choose to provide when you email support, privacy or general contact addresses.
Crashlytics collection is disabled in debug builds. VBall AI does not attach your email address or display name to Crashlytics reports and does not set those account details as a Crashlytics user identifier.
App usage analytics
Firebase Analytics processes basic app-usage and device information such as first opens, sessions, engagement, app version, device model, operating system, approximate region, fixed screen names and a Firebase app-instance identifier. VBall AI also sends a small fixed event set for onboarding completion, analysis-flow milestones, training opens and feedback submission. A custom event contains at most the selected volleyball skill; it never contains an account ID, email address, filename, video metadata, player context, coaching text or free-form feedback.
VBall AI uses this information only to understand early-access adoption and feature use. Advertising-ID collection and advertising-personalization signals are disabled, and Analytics is not used for advertising. Google processes this information as the provider of Firebase Analytics. See Firebase Privacy and Security and the Google Privacy Policy.
Analytics retention and choices
Firebase Analytics data is retained according to the retention settings of VBall AI's Google Analytics property and Google's applicable processing terms. Aggregated reporting may not be directly linked by VBall AI to your account. You can stop future app analytics collection by uninstalling the app. For questions, objections or other privacy requests, contact privacy@vballai.com.
Choosing a video on Android
VBall AI uses the Android Photo Picker for a one-time selection of a video. The app does not request broad access to your media library. Android media and legacy storage permissions are explicitly excluded from the app manifest, including READ_MEDIA_VIDEO, READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE and WRITE_EXTERNAL_STORAGE.
How information is used
- Authenticate your account and provide Google Sign-In.
- Upload the video you select and identify the relevant volleyball action.
- Prepare a short action clip and/or selected frames, contact sheets and context for frame selection, verification, fallback and coaching analysis.
- Generate, validate and return volleyball technique and movement feedback, scores and personalized coaching drills.
- Measure aggregate app adoption and feature use during early access.
- Manage beta usage, analysis credits and account roles.
- Detect, investigate and fix crashes, non-fatal errors, ANRs and app-stability problems in release builds.
- Respond to support, privacy and account-deletion requests.
- Secure, operate and maintain the service.
VBall AI uses Firebase Analytics only for product analytics, not advertising or ad personalization. VBall AI does not currently use advertising SDKs, RevenueCat or other payment processing. There is no Meta SDK in the app; Meta advertising is used only outside the app to recruit testers. VBall AI does not sell personal data.
Where processing takes place
- Firebase Authentication: provides Google Sign-In and stores the account identifiers described above.
- Firebase Crashlytics / Google: receives and processes crash, non-fatal and ANR diagnostics from release builds on behalf of VBall AI so we can monitor and improve app stability. Crashlytics is active in release builds; its operation has been verified with a test report. See Firebase Privacy and Security and the Google Privacy Policy.
- VBall AI Node video processor: receives the original selected clip over HTTPS and temporarily writes it to a unique analysis work directory. It selects the relevant action and prepares candidate frames, contact sheets, context frames, final selected frames and, when video-native mode is enabled, a short compressed action clip without audio.
- VBall AI backend and Cloudflare Worker: orchestrate the analysis steps and send only the inputs needed for the configured step to the selected AI provider. The current early-access production route calls Google directly and does not use Rork credit-based AI processing.
- Google Gemini API: current early access uses Gemini 3.6 Flash through a paid Google AI project. Tester analysis data is not processed through the free Gemini API tier. For video-native analysis, the shortened action clip may be sent to Gemini. Gemini may also process contact sheets, selected frames, context frames and analysis context for frame selection, verification or coaching analysis.
- OpenAI API: if a specific frame-selection, verification or fallback step is configured to use OpenAI, it may process contact sheets, selected frames, context frames and related player or analysis context. OpenAI is not the current primary early-access coaching route.
The media and context sent to an AI provider depend on the configured analysis mode and step. These providers process data on behalf of VBall AI to deliver, secure and operate the requested service. Their handling of data is governed by the applicable paid project configuration and provider terms. See the Gemini API Additional Terms, Gemini API data-retention controls, Google Privacy Policy, OpenAI API data controls and OpenAI Privacy Policy. VBall AI does not claim guaranteed zero retention unless that control is confirmed for the active project and request configuration. Processing may take place outside your country as described below.
Legal bases and international transfers
Where the GDPR applies, we process information to perform our agreement with you, pursue legitimate interests such as service security and improvement, comply with legal obligations, or based on consent where required. Providers may process data outside your country; when required, we use recognized transfer safeguards.
Storage and retention
- Firebase account data: account identifiers are kept in Firebase Authentication while your VBall AI account remains active and are removed when account deletion is completed, subject to Firebase’s processing.
- Crashlytics diagnostics: Google states that Firebase Crashlytics keeps crash stack traces, extracted minidump data and associated identifiers, including Crashlytics installation UUIDs and Firebase installation IDs, for 90 days before starting removal from live and backup systems. VBall AI does not separately copy these reports into its own backend database.
- Original clips and temporary processing files: the selected clip is temporarily written under a unique
/tmp/vball-analysis-{uuid}work directory. Candidate frames, contact sheets, context or dense frames, final frames and any short compressed action clip are created under the same directory. The complete work directory is deleted after the job finishes, whether the analysis succeeds or fails. A separate cleanup process automatically removes crash remnants older than one hour. VBall AI does not permanently store these media files. - External AI-provider processing: current early-access requests use a paid Google AI project rather than the free Gemini API tier. A short derived action clip and/or contact sheets, selected frames, context frames and analysis context may be sent directly to Gemini. OpenAI may receive frames and related context only when a configured selection, verification or fallback step uses it. Provider-side retention depends on the active paid service tier, project settings, endpoint and provider terms. VBall AI does not represent this processing as zero retention unless that setting is expressly confirmed.
- Validated AI responses: validated analysis results, but not media files, may remain in Worker or Cloudflare Cache for no longer than 30 days under the current
Cache-Control: max-age=2592000setting. - Backend account data: the backend stores account data, beta usage or credit records and roles while the account remains active.
- Analysis-job metadata: limited operational
analysis_jobsrecords are normally deleted after 30 days. If an account is deleted earlier, the user relationship is removed so that any remaining job record is no longer linked to the deleted account. - Aggregate product analytics: the non-identifying analytics events described above are kept for 90 days by default and are then automatically deleted. They are also deleted immediately when you delete your account.
- Server logs: operational server logs are rotated after 14 days. They are used for security, reliability and troubleshooting and do not contain permanent video, contact-sheet or keyframe files.
- Local app data: analysis results are stored primarily on the device in Android SharedPreferences. Development keyframes are stored locally only when keyframe debugging is enabled. This local data can be removed through in-app account deletion, by clearing app storage or by uninstalling VBall AI.
- Emails: support and privacy correspondence is kept only as long as reasonably necessary to respond to and document the request.
Your choices and rights
Depending on your location, you may request access, correction, deletion, restriction, objection or portability of personal data, and may withdraw consent where processing relies on consent. You may also complain to your local data-protection authority. Contact privacy@vballai.com to exercise these rights or ask about Crashlytics diagnostics.
To delete your account, follow our account deletion instructions. In-app deletion removes your Firebase Authentication account, linked backend account data, usage or credit records and roles, as well as local analyses, profile preferences, onboarding state and authentication session. Existing analysis-job records are anonymized by removing the user relationship. A durable pending-deletion process retries incomplete backend deletion steps when necessary. Because Crashlytics reports are not linked by VBall AI to your email address or display name, deleting your VBall AI account does not immediately remove existing Crashlytics diagnostics; Google applies the retention schedule described above.
Children
VBall AI is not intended for children below the minimum age required to consent to digital services in their country without involvement of a parent or guardian. If we learn that personal data was collected contrary to applicable law, we will take appropriate steps to delete it.
Security and changes
The selected clip and other data sent between the app and VBall AI services are transmitted over HTTPS. Firebase App Check with Play Integrity may be used to verify that requests come from the authentic app and help prevent abuse. This is a security control, not an advertising tracker. No online service can guarantee absolute security. We may update this policy when the app architecture or data practices change and will update the date at the top when we do.
Contact
Privacy questions and rights requests: privacy@vballai.com
General support: support@vballai.com
