Effective date: September 3, 2026 · Last updated: September 12, 2026
SmartPlay Caddie ("the App", "we", "us") is a golf companion mobile application operated by SmartPlay AI LLC, 29003 Navigator Way, Menifee, CA 92585. You can contact us at support@smartplaycaddie.com for any privacy-related question, request, or complaint.
This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have over it.
We collect the categories of data below. We collect the minimum needed to make each feature work, and we tell you in the App when a feature is about to use a new category (for example, the first time we ask for microphone access).
| Category | What | Why | When |
|---|---|---|---|
| Profile data | Name, golf handicap, home course, preferences | Personalize your caddie's advice and surface your stats | You enter this during onboarding and in Settings |
| Location (GPS) | Coarse and precise device location while the App is open or during an active round in the background | Find courses near you, compute yardages to greens and hazards, detect hole transitions during a round | Only after you grant permission, and only while the App or an active round needs it |
| Audio (voice) | Recordings of your spoken queries to your caddie | Transcribe your question and route it to a response | Only while a listening session is open; recordings are not retained after transcription |
| Audio (practice) | Microphone capture during practice sessions | Acoustic strike detection and ball-speed estimation | Only while a practice session is recording |
| Video | Camera capture during swing recording, lie analysis, and SmartFinder | Swing analysis, lie and turf analysis, on-course distance assistance | Only while you are actively in those features; videos save locally to your device unless you choose to upload |
| Round data | Shot-by-shot history, per-club statistics, scoring, hole-by-hole performance | Generate your scorecard, recap, and long-term trends | Created during rounds you start in the App |
| Practice data | Practice session results, swing analyses, drill recommendations | Track practice performance and detect patterns over time | Created when you use the practice and swing-analysis features |
| Backup identifier | An email address and a passphrase you choose, used only in hashed form | Identify your backup so you can restore it on a new device | Only if you turn on optional cloud backup |
| Device data | Operating system, app version, device model, language, timezone | Diagnostic context for crash reports and feature compatibility | At app start and on crash |
| Crash and diagnostic data | Stack traces and breadcrumb logs | Debugging and stability | When a crash or error occurs |
| Issue reports and round traces | Error entries, notes you write in the in-app issue log, and a technical timeline of a round (which features ran, what resolved, what failed). Identified by a random install identifier — not your name or email. | Finding and fixing bugs we cannot reproduce | While “Share diagnostics” is on in Settings. You can turn it off at any time. |
| Course map data | Tee, green and hole coordinates for courses you play. No personal data, and nothing about your round or your scores. | Building the shared course database so unmapped courses work for everyone | While “Share community data” is on in Settings. You can turn it off at any time. |
| Where | What's stored | How long |
|---|---|---|
| On your device | All profile data, round history, practice history, and swing videos saved locally | Until you uninstall the App or clear app data; you can also delete specific items in-app |
| Our backend (Vercel-hosted serverless API) | Transient request and response state for AI features. Logs may include redacted timing data and error messages | API request logs ≤ 30 days; no user content beyond the duration of the request |
| Cloud backup (optional, opt-in) | If you turn on cloud backup, a snapshot of your on-device data (rounds, practice history, settings) is stored in our Supabase database | Until you overwrite it with a newer backup or ask us to delete it |
| Third-party processors (see §4) | Your audio, video, or text is sent to the relevant provider only for the duration of the request | Processor retention varies; see §4 |
How cloud backup works. SmartPlay Caddie does not maintain user accounts and has no sign-in. Cloud backup is entirely optional. When you enable it, you choose an email address and a passphrase; your backup row is keyed by a one-way hash of the two combined. We do not store your email address or your passphrase on their own — only that hash. This means an email address alone cannot be used to find, read, or overwrite your data, and a wrong passphrase is indistinguishable from "no backup exists". It also means a lost passphrase cannot be recovered and your backup cannot be restored without it. Backup rows are readable only by our server, never by the app or by other users.
If you never enable cloud backup, your profile, rounds, and practice history exist only on your device, and uninstalling the App or losing the device will erase them.
We send data to the following providers solely to deliver the feature you requested. Each is bound by its own privacy and security commitments.
| Provider | What we send | Purpose | Retention by provider |
|---|---|---|---|
| Anthropic (privacy) | Voice query transcripts, swing and lie context | Generate caddie, coaching, and conversational responses | Not used for training on API data; logs retained ≤ 30 days |
| OpenAI (privacy) | Voice transcription audio, text-to-speech text, hole overhead images | Speech-to-text, text-to-speech, vision-based hole reads | Not used for training on API data; logs retained ≤ 30 days |
| ElevenLabs (privacy) | Text to be synthesised as speech | Caddie voice synthesis | Per ElevenLabs API policy |
| Mapbox (privacy) | Hole bounding-box coordinates and zoom requests | Satellite imagery and static map tiles | Mapbox-side request logs |
| Google (Maps Platform) (privacy) | Course search queries and coordinates | Course discovery and place lookup | Per Google Maps Platform terms |
| golfcourseapi.com | Course identifiers and queries | Course information, hole geometry, tee and green coordinates | Per provider policy |
| Supabase (privacy) | Your opt-in cloud backup snapshot, keyed by a hash of your email and passphrase | Database hosting for cloud backup | Until overwritten or deleted at your request |
| Sentry (privacy) | Crash stack traces, breadcrumb logs, device and app version | Crash reporting and stability diagnostics | Per Sentry retention settings |
| Vercel (privacy) | Standard hosting telemetry (request IPs, user-agent) for our backend | Hosting and infrastructure | Per Vercel data processing terms |
| Apple App Store / Google Play | App distribution and, if introduced, subscription billing | Distribution channel | Per Apple and Google privacy policies |
If we add a processor in the future, we will update this policy and notify you in-app.
Depending on where you live, you may have the rights below. To exercise any of them, email support@smartplaycaddie.com with the subject line "Privacy request".
We respond within 30 days. We do not charge for reasonable requests.
You have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell your personal information and do not "share" it for cross-context behavioral advertising. To exercise California-specific rights, email support@smartplaycaddie.com.
Our legal bases for processing are:
Where data is sent to processors outside the EEA or UK, transfers rely on the Standard Contractual Clauses or each provider's adequacy decision.
SmartPlay Caddie is not directed at children under 13 (or under 16 in jurisdictions that apply that age limit). We do not knowingly collect personal data from children. If you believe a child has provided personal data to us, contact support@smartplaycaddie.com and we will delete it.
We use industry-standard transport encryption (HTTPS / TLS) for all communication between the App and our backend. Voice and video uploads are sent over encrypted channels. On-device data is protected by your device's operating-system-level security (PIN, passcode, biometrics). Cloud backup rows are accessible only to our server and are keyed by a one-way hash, never by a plaintext identifier. No system is perfectly secure; if you become aware of a vulnerability, please email support@smartplaycaddie.com.
The App requests the following device permissions, each with a specific human-readable reason shown in the operating system prompt:
Denying any permission disables the corresponding feature; the rest of the App continues to work.
We may update this policy as the App evolves. When we make material changes, we will update the "Last updated" date at the top, post the new policy at the same URL, and notify you in-app. Continued use of the App after a material change constitutes acceptance of the updated policy.
For any privacy question, request, or complaint:
Email: support@smartplaycaddie.com
Entity: SmartPlay AI LLC
Email is our contact channel of record for privacy requests. We respond to verified requests within the timeframes set out in section 5.