Privacy & Model Improvement
Last updated: September 8, 2026
arc golf ("arc", "we", "our", "us") operates the arc mobile application. This page explains how we collect, use, disclose, safeguard, and delete information when you use the app, and how we approach model improvement. Questions go to [email protected].
| Area | Default | Your control |
|---|---|---|
| Account and Arc+. | Practice recording requires an arc account and an active Arc+ subscription, apart from a one-time promotional trial started from an arc promotional link. | Delete the account in the app. Cancel the subscription through Apple. |
| Camera and swing clips. | Camera frames are analyzed on the device. While you are signed in, swing clips, session records, and analysis evidence upload to our cloud storage automatically. | There is no in-app switch to turn that synchronization off while you are signed in. Deleting your arc account removes the cloud copies. |
| Microphone audio. | Impact sound and voice commands are processed live. Practice capture does not upload microphone recordings. | Speech recognition prefers on-device processing and can fall back to Apple's speech service. A coach voice note is uploaded only when you record and send one. |
| Apple Health. | Read-only, and on iPhone only two data types: heart rate variability and heart rate. arc never writes to Apple Health. | Grant or revoke Health access in iOS Settings. |
| AI coaching. | Coaching is generated through Apple's Foundation Models. | The optional Anthropic route stays off unless you turn it on and supply your own API key. |
| Model improvement. | arc does not currently run a model-improvement or research-contribution program. | Ordinary practice use is not permission to train on what you record. |
| Website beta applications. | Email, application type, source page, and the profile details you submit are stored with limited attribution and request metadata. | You can ask us to delete your application record at any time. |
1. Information We Collect
Account Data: Practice recording requires signing in to an arc account, apart from a one-time promotional trial started from an arc promotional link, which records a limited number of swings without an account or a subscription. You can sign in with Apple, with Google, or with an email address and password. Account information includes your email address, an arc profile identifier, and information associated with the sign-in method you chose. Authentication and the account database are provided by Supabase; Apple or Google processes the sign-in itself when you choose that provider.
Camera & Video Data: arc accesses your device camera to record golf swings during practice sessions. Video frames are processed on-device for pose detection, swing analysis, and clip creation. While you are signed in, swing clips, session records, and analysis evidence synchronize automatically to our cloud storage. There is no separate optional-backup switch in the practice flow. Per-swing analysis evidence sent to arc includes the club, camera angle, swing index and timestamp, verification state, a pose summary and pose-artifact path, motion, audio and impact evidence, swing metrics, the clip identifier and its pre- and post-impact timing, the session focus and passive cue, and whether the swing was recorded without an active subscription. Clips also leave the device when you share them or send them to a coach.
Microphone & Audio Data: arc uses microphone input to detect impact sounds for swing detection and to process voice commands ("Hey Arc"). Impact audio is analyzed on the device, and practice capture does not upload microphone recordings. Speech recognition is configured to prefer on-device processing and falls back to Apple's speech service only when your device does not support on-device recognition for the selected language; Apple's handling of any audio sent to that service is governed by Apple's own privacy policy.
Body Pose Data: arc uses Apple Vision framework to extract body keypoint positions (joints, limbs) from camera frames. This data is used to compute swing biomechanics (spine angle, hip rotation, wrist speed, etc.). Pose detection runs on-device, and a pose summary is uploaded with the swing as part of the analysis evidence described above.
LiDAR Depth Data: On supported devices, arc uses LiDAR for depth measurement to improve distance estimation. Depth frames are processed on-device and are not uploaded.
Motion Sensor Data: arc accesses accelerometer and gyroscope data for camera stability detection.
Apple Music: arc's first-run setup screen includes a request for Apple Music access. It is preselected there, and you can turn it off on that screen or decline the system prompt. arc does not send music or listening information to our servers.
Apple Health Data: On iPhone, arc requests read-only access to exactly two Apple Health data types and no others: heart rate variability (SDNN) and heart rate. arc never writes to Apple Health from the iPhone. The heart-rate-variability reading is used only to render a breathing insight on the session report card; it stays on the device, is not stored in our cloud, and is not sent anywhere. The heart-rate reading is used differently: at the start of a session arc averages your recent heart-rate samples into a resting baseline, and when an Apple Watch supplies a heart rate for a swing, the difference between that heart rate and the baseline is uploaded with the swing.
Apple Watch Data: The optional Apple Watch app requests read access to workouts, heart rate, active energy, step count, and walking or running distance, and permission to record a workout. It discards that workout when practice ends instead of saving it to Apple Health. The Watch app performs no network transmission of its own: everything it produces reaches arc only after the iPhone packages it. Per-swing telemetry the iPhone uploads to your account includes Watch motion and timing measures (rotation, tempo, address stability, and impact sharpness) and, when a Watch workout is running, workout context read from Apple Health: heart rate and its change from the session baseline, active energy burned, step count, walking or running distance, cadence, elapsed session time, and movement activity.
Location Data: Wind-aware carry is enabled by default, so arc asks for location permission on your first practice session. When it is on, arc sends your coordinates, rounded to four decimal places (roughly 11 meters), to the Open-Meteo weather service to retrieve wind conditions. If you allow location, arc also records a venue coordinate in the on-device capture log for the session, independently of the wind setting.
Purchase Data: Apple handles App Store purchases. arc passes your arc profile identifier to Apple as the purchase's app account token, and sends its own backend only the transaction identifier, product identifier, purchase source, and app version in order to verify Arc+ access. arc does not receive your payment-card details through this purchase flow.
Usage Analytics: While you are signed in, arc records in-app usage analytics through a single reporting pipeline. These records include, among other event types, screen views, practice-session start and finish, the first verified swing of a session, purchase-screen product loads, and Second Screen connection-state changes, together with app version and device and installation information. The set of event types changes as the app changes, so this list is illustrative rather than exhaustive. These records are stored with your arc profile identifier, have no automatic expiry, and are destroyed when you delete your account. There is no in-app switch to turn them off.
Installation Identifier: arc's configuration request, which runs at every launch including before you sign in, carries a durable installation identifier generated on your device and stored in its Keychain, together with app and capability information. The same installation identifier is attached to the usage analytics described above: while you are signed in, each of those records carries both the installation identifier and your arc profile identifier on the same row, so the two are linked in our database. Deleting your account destroys those records and removes that link; the identifier itself lives in your device's Keychain and is not removed by account deletion. Activation telemetry recorded before sign-in is different: it identifies the install only by a hash of that identifier computed with a secret we hold, and it is deleted automatically 90 days after it is received.
Crash & Performance Diagnostics: The app can send crash and performance diagnostics collected by Apple's MetricKit. Each report contains the device model, OS version, app version, the build's source revision, and the MetricKit payload itself, which for crash reports includes stack traces. These reports are sent with arc's public application key and never with your account credential, so they arrive with no account identifier attached and cannot be located by, or deleted through, your arc account. They contain no device identifier and no installation identifier.
Coaching & Collaboration Data: Sharing with a coach or another person sends the selected content and the related collaboration information. Coach conversations can include text, clips, and voice notes. A coach voice note is uploaded to our private Supabase Storage as part of that conversation and is deleted when the note, the conversation, or your account is deleted; a voice note that is never attached to a message or reply is deleted automatically within 24 hours of upload, or within an hour if the upload never completed. Coach subscription billing, where used, is processed by Stripe, and coach notification emails are sent through Resend. Opening the coach web dashboard from the app passes your arc session tokens to a page hosted by Cloudflare Pages. A connected local Second Screen receives clip video directly over a local peer-to-peer connection, so no server receives that video; its connection state is reported to arc as telemetry.
Launch Monitor Data: arc requests Bluetooth access, which it uses to discover and connect to a supported launch monitor. If you connect a supported MLM2PRO launch monitor, arc's backend exchanges the simulator user identifier the device provides for a short-lived token with Rapsodo. The vendor credential is never held by the app.
Optional External AI Request Data: If you explicitly enable the optional Anthropic route and provide your own Claude API key, arc sends summarized coaching request data to Anthropic. That summarized data can include your skill level, session goals, trend and delta summaries, a coach-memory summary, your questionnaire and coach-note text, locale and units, focus areas, drill profile, and per-swing metric summaries. arc does not send raw camera video, raw microphone audio, depth frames, your arc account email, or your arc profile identifier as part of that optional provider flow.
Support Correspondence: If you email us, we receive the message and whatever you choose to include in it.
Website Beta Application Data: If you join the golfer beta or apply through a coach or partner form, we collect your email address, signup type, and source page. A coach application also includes the roster size and any organization name you choose to provide. A partner application includes the organization and partner type you submit. We use these fields to route the application and follow up about the relevant beta.
Website Attribution & Request Data: This website records visits, not only submissions. Opening one of our campaign or QR landing pages stores a persistent visitor identifier in your browser's local storage under arc_marketing_anon_id_v1, stores an attribution snapshot under arc_marketing_attribution_v2, and sends a page-view record to us even if you submit nothing. A page-view record and a form submission both carry that visitor identifier, the page address, the referring page, your browser user agent, browser language, timezone and screen size, campaign parameters, ad-click identifiers, and both your first-visit and most-recent-visit attribution. Cloudflare adds your country, a Cloudflare ray identifier, and a hash of your IP address, which we store in place of the address itself; that hash is a plain SHA-256 with no secret added, so it is not a guarantee of anonymity. Clearing this site's data in your browser removes the stored visitor identifier and attribution snapshot; a later visit creates new ones.
2. How We Use Your Information
- To provide real-time swing analysis and coaching feedback
- To generate biomechanics reports and session analytics
- To synchronize your swing clips, sessions, and analysis evidence to your account so they are available across your devices
- To generate coaching reports or session reflection questions using Apple's Foundation Models and, only if you explicitly enable it, an optional Anthropic route using your own API key
- To process voice commands for hands-free operation
- To verify your Arc+ entitlement with Apple and unlock practice recording
- To improve app performance and fix bugs, including through crash and performance diagnostics
- To communicate with you about the app and to answer support requests
- To route golfer, coach, and partner beta applications, evaluate public-page attribution, prevent form abuse, and follow up about the relevant program
3. Model Improvement
Using arc does not give us blanket permission to train on everything you do in the app.
arc does not currently run a model-improvement or research-contribution program. There is no such control in the app and no consent record has been collected.
If we introduce one, we will describe it on this page — its purpose, the scope of data involved, whether humans may review that data, and how to make and withdraw the choice — before it operates.
If we ever offer such a choice and you withdraw it, we will stop using newly collected data for that purpose and remove eligible stored material from future training and dataset exports. Models trained before a deletion or withdrawal request may remain in service until they are retrained if unlearning is not available for that model family.
4. On-Device Processing
arc analyzes camera frames, audio, pose, and swing motion on your iPhone. That inference runs locally using Apple's Neural Engine. On-device inference does not mean the resulting data stays on the phone: while you are signed in, swing clips, session records, and the per-swing analysis evidence described in section 1 upload to our cloud storage automatically, and there is no in-app switch to stop that. Depth frames and microphone recordings from practice capture are not uploaded. The heart-rate-variability reading used for the breathing insight stays on the device.
5. Optional Third-Party AI Providers
Supported coaching is generated through Apple's Foundation Models, which is the backend selected in arc's production configuration. Apple decides whether a given request is served by the model on your device or by Apple's Private Cloud Compute, under Apple's own privacy terms. arc neither controls nor observes that routing, and we do not claim that coaching never leaves the device.
The optional Claude route is off unless you turn it on and paste your own Anthropic API key. No key ships in the app, and the key you supply is held in your device Keychain. When you enable it, summarized coaching requests go to Anthropic as plain text, and the request authenticates with your own key rather than an arc credential.
That route does not send raw camera video, raw microphone audio, depth frames, your arc account email, or your arc profile identifier. You can remove your stored Claude key from arc at any time to stop new requests from using that route. Our cloud logging of coaching prompts and model output is disabled in production.
We also reserve the right to run arc's proprietary models on servers we host or control in the future if costs, infrastructure constraints, legal or political pressure, outages, or other force-majeure events make that necessary. If we introduce a hosted arc model path, we intend to update this policy, explain what data is involved, and provide any additional notice or controls required by law or platform rules before using that hosted path for user data.
6. Data We Do NOT Collect
- arc does not upload microphone recordings from practice capture
- arc does not upload LiDAR or depth frames
- The optional Anthropic route does not send raw camera video, raw microphone audio, depth frames, your account email, or your arc profile identifier
- arc never writes anything to Apple Health
- The Apple Watch app performs no network transmission of its own
- arc does not receive your payment-card details from the App Store purchase flow
- We do not log coaching prompts or model output in production
- We do not sell your data to third parties
- We do not use your practice or swing data for advertising
- We do not treat acceptance of our terms as permission to use app data for model training
7. Third-Party Services
arc uses the following third-party services:
- Apple: Sign in with Apple, App Store billing, Vision framework pose detection, Foundation Models coaching, Speech recognition when on-device recognition is unavailable, HealthKit, MetricKit diagnostics, and Apple Music if you allow the access arc requests during setup
- Google: Sign-in, if you choose that provider
- Supabase: Authentication and the account, session, swing, evidence, and telemetry database, hosted in the United States (AWS us-east-1); Supabase Storage also holds swing clips uploaded before 8 September 2026, along with coach voice notes and other private media
- Cloudflare: Cloudflare R2 object storage for swing video clips uploaded from 8 September 2026 onward; Cloudflare Pages for the coach web dashboard; and Cloudflare Workers KV for website beta application, attribution, and request-security records
- Anthropic: Optional user-enabled coaching route using a Claude API key you provide; summarized coaching request data is processed by Anthropic only when you explicitly enable that route
- Open-Meteo: Wind conditions for wind-aware carry, from coordinates rounded to four decimal places
- Stripe: Coach subscription billing, where used
- Resend: Coach notification email
- Rapsodo: Short-lived token exchange when you connect a supported MLM2PRO launch monitor
8. Data Retention & Deletion
Deleting a session is a local operation. It removes the session from that device and from your practice history in the app. It does not remove the cloud copy: the app has no server-side session-delete route. Cloud copies are kept until you delete your arc account or ask us to remove them.
arc does not delete your practice records or swing video on a schedule. There is no automatic expiry on saved clips, sessions, or per-swing evidence. Some narrower categories do expire on their own: pre-sign-in activation telemetry after 90 days, this website's page-interaction event records after 180 days, and a coach voice note that is never attached to a message or reply within 24 hours of upload.
To delete your account and its cloud data, open Account → Account safety → Delete account in the app. Account deletion removes your swing video from Cloudflare R2 and from our Supabase Storage buckets; deletes your practice sessions, swings, evidence, media records, and pairings; deletes your coach collaborations and their annotations, replies, and voice notes; deletes your entitlement and commerce rows; destroys your raw and diagnostic telemetry payloads rather than merely detaching them from your profile; deletes your session logs; and deletes your arc profile and sign-in record. On the device it clears arc's identity items and any stored Claude key from the Keychain. Read the app's result: if it reports an error, do not assume deletion completed.
Five things survive account deletion:
- A permanent enforcement record, so that an upload already in flight cannot recreate deleted content. It holds an opaque profile identifier and cleanup scheduling fields.
- A per-object cleanup list for the deleted account, covering storage bucket and object paths, media identifiers, and media kind. Those paths embed the deleted account's identifier. No scheduled job removes it.
- A permanent fingerprint of the billing identifiers that account used — a hash of the Apple App Store original transaction identifier and of any Stripe customer or subscription identifier — kept against the deleted profile's identifier so that a deleted account's purchase cannot be re-attached to a new account. The fingerprint is a plain SHA-256 of the identifier with no secret added, so anyone who already holds the same billing identifier can recompute it and match it back to the deleted profile's identifier. No scheduled job removes these rows.
- Billing audit rows, reduced to their provider and event columns with a redaction marker rather than erased.
- Crash and performance diagnostics, which arrived with no account identifier attached and so cannot be located by your account.
The durable installation identifier in your device's Keychain also survives account deletion, as described in section 1.
Deleting arc or your arc account does not cancel an Apple subscription. See the Terms of Service for how to cancel.
Our database and object storage are operated by Supabase and Cloudflare. We do not control those providers' internal backup rotation, so a copy may persist in provider backups after a deletion completes on the live systems. Local media may also be removed under on-device storage limits, so we do not promise unlimited permanent clip availability on the phone.
Website beta application records are associated with your normalized email address and may preserve separate golfer, coach, and partner applications when you apply to more than one program. Waitlist entries have no automatic expiry and are kept until you ask us to remove them. To request deletion, email [email protected].
If you enabled the optional Claude route with your own key, requests sent through that route are also subject to Anthropic's terms and retention policies. Removing your stored key from arc stops new requests from being sent through that provider route from the app, but does not delete records already held by that provider.
Step-by-step instructions are on our data deletion page.
9. Children's Privacy
arc is not directed at children under 13. We do not knowingly collect personal information from children under 13. If we learn we have collected such information, we will delete it promptly.
10. Your Rights
You have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data
- Withdraw consent for data processing
If you are in California, the EEA, the UK, or another region with additional privacy rights, you may also have rights to know more about how your data is used, to object to certain processing, or to limit the use of sensitive personal information where applicable. Email [email protected] to exercise any of these. We may ask for enough information to verify the request before acting on it.
11. Security
We implement appropriate technical and organizational measures to protect your data. Data that traverses the internet — account synchronization, clip uploads, coaching requests, and website forms — is sent using encrypted transport. Uploads to Cloudflare R2 are write-once and integrity-bound: the signed request fixes content length, checksum, and type. The older Supabase upload path, which still holds clips uploaded before 8 September 2026, signs only the content type. Your Claude API key, if you supply one, is held in your device's Keychain rather than on our servers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
13. Contact Us
If you have questions about this Privacy & Model Improvement page, contact us at:
[email protected]