Privacy policy

What this app records about you, why, who else can see it, and how to get it back or have it erased.

Version 1.0 · Last updated August 7, 2026

Who is responsible

Ristep Studio is the data controller for this app. Write to pistol@ristep.studio about anything on this page — including any of the rights described below. A person reads that address.

The registered address is Via di Monte Giordano 36, 00186 Roma, Italia.

The controller is established in Italy. If you think your data is being handled wrongly and we have not put it right, you may complain to a supervisory authority — for us that is the Garante per la protezione dei dati personali (the Italian data protection authority).

What the app records

Only what the app needs to do its job. There is no analytics package, no advertising, no third-party tracking and no profiling of you for anyone else's purposes.

  • Account: your email address, a password (stored only as a cryptographic hash — nobody can read it back, including us), your display name, and your chosen language.
  • Profile, all optional: discipline, level, club, national-team status, dominant eye and hand, year of birth, and a profile photo if you upload one.
  • Training: the date, time and place of a session, every individual shot score, the equipment used, session duration, and any notes you write.
  • Your own ratings of a session: how stable you felt, trigger control, sight alignment, follow-through, breathing, grip and shoulder fatigue.
  • Health-related ratings: sleep hours, stress, mental fatigue and concentration. These are treated separately — see the next section.
  • Coaching: invitations you send, which coach may see what, and the messages exchanged between you and a coach.
  • Technical: failed sign-in attempts are counted against your email address and against the IP address they came from, so that guessing your password can be slowed down. A record of access changes and deletions is kept — who did what, and when.

The app never asks for, and has no way to store, a payment card, an identity document or a national identifier.

Sleep, stress, mental fatigue and concentration

These four are treated as health data — special-category data under Article 9 of the GDPR. They are collected only if you say yes, separately and explicitly, and never by default.

The law protects information about your health more strictly than the rest, and it is arguable whether four training self-ratings really rise to that level. We have decided not to have that argument at your expense: they are treated as though they certainly do.

What that means in practice:

  • Consent is asked for on its own. It is not bundled into accepting the terms, and refusing it does not cost you the app.
  • If you decline, those four inputs are not shown, and the database refuses to store a value for them even if a request tries to. The rest of the app — scores, series, consistency, trends, matches, coaching — works exactly as before.
  • Analyses that would need them say so, and say why they are unavailable. They never quietly show a zero.
  • You may withdraw at any time in Settings, as easily as you gave it. Withdrawal stops future collection AND erases the values already recorded. The app tells you how many values that is before you confirm, because it cannot be undone.
  • On iOS, if you allow it, sleep hours can be read from Apple Health to save you typing them. That reading happens on your device; the number you keep is stored under this same consent, and nothing else from Health is read or sent anywhere.

The lawful basis is your explicit consent, under Article 9(2)(a). There is no other basis behind it: withdraw and there is nothing left holding the data.

Why we are allowed to hold it

DataWhyLegal basis
Account and profileTo give you an account and let you sign in.Performance of a contract (Art. 6(1)(b))
Sessions, shots, equipment, notesThis is the service — recording and analysing your training.Performance of a contract (Art. 6(1)(b))
Sleep, stress, mental fatigue, concentrationTo let you see whether they move with your scores.Explicit consent (Art. 9(2)(a))
Coach access and messagesBecause you invited a coach and set what they may see.Performance of a contract (Art. 6(1)(b))
Failed sign-ins, access logTo keep your account from being broken into, and to keep a record of who changed access.Legitimate interests — security (Art. 6(1)(f))

There is no legal basis anywhere in this app for marketing, for selling data, or for sharing it with anyone not listed on this page.

Coaches, and what they can see

Nobody sees your training data unless you invite them. A coach connects only through an invitation you send to a specific address, and connecting alone grants nothing — each kind of access is a separate permission you switch on.

  • Your self-ratings, including the four health-related ones, sit behind their own permission and are off for every coach type by default. A coach labelled 'mental' is not thereby consented to.
  • A coach can never change your data. Not a score, not a note, not a rating. This is enforced by the database, not by hiding a button.
  • You can revoke a coach at any moment, and the moment you do they see nothing further.
  • If you and a coach exchange messages, that conversation is private to the two of you. A second coach cannot read it.
  • If you enter a postal match, the other entrants see your name and your score for that match, and nothing else. Joining a match shares one result, not your training log.

Who else touches it

These companies process data on our instructions, under a contract, and for no purpose of their own. Nobody else receives it.

ServiceWhat it doesWhere
SupabaseDatabase, authentication and file storage. Holds all account and training data.Frankfurt, Germany (EU)
VercelRuns the application. Processes requests in transit; stores nothing.Paris, France (EU) for server functions; global edge network for static files
ResendSends password-reset and coach-invitation emails. Sees the recipient address and the message.United States (transfers covered by Standard Contractual Clauses)
CloudflareTurnstile: the bot check on the sign-in form. Sees the sign-in request, never the password.Global (transfers covered by Standard Contractual Clauses)
AppleDelivers push notifications. Health data read on the device is never sent to Apple by this app.Global — applies only to the iOS app

Your account and training data live in the European Union. Where a service above operates outside it, the transfer is covered by the European Commission's Standard Contractual Clauses — and in those cases it is the message or the request in transit, never the training database.

How long it is kept

  • Training data: until you delete it. It is yours, it is the point of the app, and nothing expires it on a timer.
  • Your account: until you delete it, in Settings. Deleting the account removes the profile, the sessions, the shots, the ratings, the messages and the profile photo.
  • Health-related ratings: erased when you withdraw that consent, or when you delete the account, whichever is first.
  • Failed sign-in counters: cleared as soon as you sign in successfully, and in any case within a day.
  • The access log: kept after an account is deleted, with the actor's name as it was at the time. That record is the only evidence of who changed access or destroyed data, so it has to outlive the account — it never contains message content or a working invitation link.

Your rights

Under the GDPR you may ask for a copy of your data, ask for it to be corrected, ask for it to be deleted, object to some processing, ask for it in a portable form, and withdraw a consent. Write to pistol@ristep.studio. We answer within one month.

Two of these you do not need to ask for — they are buttons in Settings:

  • Export everything you have, as a file, at any time.
  • Delete your account and everything in it, at any time.

If you are not satisfied with how we handle a request, you can complain to your local data protection authority, or to the Garante per la protezione dei dati personali (the Italian data protection authority) (https://www.garanteprivacy.it/).

How it is protected

  • Every row of training data is locked to its owner in the database itself, so a mistake in the application cannot show one person another person's data.
  • Your sign-in token is stored in a cookie that page scripts cannot read, which stops one class of attack from turning into a stolen session.
  • Passwords are stored only as hashes and are never readable by anyone, including us.
  • Repeated failed sign-ins are slowed progressively, and a bot check stands in front of the sign-in form.
  • Data is encrypted in transit, and at rest by the hosting provider.

No system is perfect. If we ever discover a breach that puts you at risk, you will be told — and so will the supervisory authority, within 72 hours.

Children

This app is not intended for people under 16. If a younger athlete is to use it, the account must be created and consented to by whoever holds parental responsibility, and that person is the one who should read this page — including the separate question about sleep, stress, mental fatigue and concentration.

Changes to this policy

If what we collect or why changes in substance, this document changes and its version number moves. Where the change touches something you consented to, you will be asked again rather than assumed to agree. The date at the top is always the date of the last change.