1. Who we are
PerfHQ is a trading name of Kieron McAuley-Kinchin, a sole trader. There is no company and no company registration number.
The data controller is Kieron McAuley-Kinchin, and the way to reach us about anything in this notice — including any request about your own data — is [email protected]. We answer to that address. For help with the app rather than your data, use [email protected].
We are not yet registered with the Information Commissioner's Office. Registration is in progress and this notice will be updated with the registration number when it is issued.
2. Our role, and your organisation's role
PerfHQ is supplied to sports coaching organisations. When your academy or club uses PerfHQ to coach athletes, two different responsibilities apply, and it matters which one is which.
Your organisation is the controller for coaching data
Your organisation decides who to enrol, what medical information to collect, who may see it, and how long to keep athletes on its roster. For that data we act on its instructions as a processor. This is an accurate description of who makes the decisions, not an attempt to move responsibility. If you are an athlete or a parent, your first point of contact for questions about coaching records is normally your organisation.
We are the controller for account and identity data
Some information belongs to the person rather than to any one organisation: your name, email address, password, two-factor settings, date of birth, and — deliberately — your medical notes and emergency contacts. These are shared across every organisation you belong to, so that a person who trains at two clubs does not have two divergent medical records. That is our architectural decision, not your organisation's, and we are the controller for it.
Certain duties stay with us regardless of any contract: keeping the service secure, telling your organisation about a breach, and answering for the providers we rely on. You may also bring a claim directly against us.
3. What data we handle
Account and identity
Name, email address, phone number, postal address, date of birth, password (stored only as an Argon2id hash), two-factor settings, and a record of sign-in attempts.
Health and emergency information
Medical notes, allergies, dietary requirements and emergency contact details. Under UK GDPR this is special category data and is treated as the most sensitive information in the service. Emergency contact details describe a third party, who is usually a parent or guardian.
Coaching records
Assessments, performance metrics, session bookings, group memberships, attendance and coaching feedback. Coaches can also record two kinds of note: general notes, visible to the athlete and their guardians, and internal notes, visible only to coaches with the relevant permission.
Photos, video and audio
Video and photographs captured or uploaded for coaching feedback, including the audio recorded alongside video, and any drawings a coach saves onto a frame.
Technical records
Server logs, audit records of changes made in the system, notification delivery records, and error reports. These can contain user identifiers, IP addresses and device information.
Sign-in records. Every sign-in attempt is recorded with the time, whether it succeeded, the IP address it came from, and the device or browser. For an active session we also store an approximate city and country, which our network provider derives from that IP address. That is an inference from the network, not a location reading: the app itself never asks for location permission and does not collect your device's location.
Device identifier. The app generates its own identifier for your installation and sends it with each request, so that you can see and sign out individual devices. It is created by the app rather than taken from the operating system, and it identifies the installation, not you.
4. Children
PerfHQ holds health information about children, some of whom are under 13 and many of whom have no email address of their own. We treat a breach of this data as a safeguarding matter rather than a technical one.
Accounts for children are created by the organisation, not by the child signing up. There is no way to register for PerfHQ from the app or from this website. A parent or guardian is linked to the child's record for a specific organisation, which is what allows them to see and manage that child's profile, medical information and emergency contacts. That link ends automatically when the child turns 18.
Your organisation is responsible for obtaining consent from parents and guardians before entering a child's information, and for deciding which of its coaches may see sensitive records.
5. What we do not do
We do not use your data to train machine learning models. Body-tracking data, video and coaching records are not used to train any model, ours or anyone else's. If that ever changes it will require a new version of this notice, an explicit opt-in that is off by default, and your active agreement. We are not reserving the right to do it quietly.
We do not sell or rent personal data. We do not use it for advertising or profiling. We do not track you across other websites or apps.
6. The app on your device
What the app asks permission for
The iOS app asks for six permissions, each only when you first use the feature that needs it:
What it never asks for
The app does not request your location, your contacts, your calendar, health data from Apple Health, or permission to track you. It does not use push notifications.
It contains no third-party code
There is no analytics, advertising, crash-reporting or tracking library in the PerfHQ app. It has no external code dependencies at all. Apple's App Tracking Transparency prompt never appears because there is nothing to ask about.
The app also sends no automatic diagnostic or crash reports. The version and device details support asks for are assembled only when you tap to copy them or to email us, and they go nowhere until you send them.
Processing that stays on your device
Movement analysis — extracting skeletal joint positions and depth from a recording — runs entirely on your device using Apple's Vision and ARKit frameworks. Because the app has no third-party code in it, no body-tracking data is shared with any external analytics or machine learning provider.
The joint and depth files produced during capture are written to your device's local storage, are excluded from device backups, and are never uploaded to us. The app has no code path that sends them.
To be precise about what this does and does not mean: the video and audio recorded at the same time are uploaded to our storage in the normal way, because coaching feedback depends on them. So the movement analysis is local, and stays local; the footage it was derived from is not.
What else is held on your device
Your sign-in tokens are stored in the iOS Keychain, marked so that they are available only after you have unlocked the device and only on that device — which keeps them out of iCloud Keychain and out of encrypted backups. If you turn on Face ID sign-in, that is held in a separate Keychain entry that is invalidated automatically if the faces or fingerprints enrolled on your device change.
Video and photos you capture are held on the device until they upload, along with any drawings and analysis attached to them. These are excluded from device backups. Removing the app removes them.
7. Where your data is stored
We use a small number of providers to run the service. We do not use any advertising or analytics networks.
| Provider | Purpose | Location |
|---|---|---|
| IONOS | Servers and the main database, which holds account, coaching and health data | Europe. The specific datacentre is being confirmed and will be named here. |
| Amazon Web Services | Storage for photos, video and audio; database backups; sending email | eu-west-2 (London) |
| Cloudflare | DNS and network protection. All traffic to our API passes through it. | Global network. Routing is not currently restricted to a region. |
| Serves the typefaces used on this website. Your browser fetches them directly, which discloses your IP address to Google. This applies to the website only — the app itself contacts no third party. | Global network | |
| Apple | Distribution of the app through the App Store | Apple's infrastructure |
We cannot yet state that all personal data remains within the UK or EEA, because the items above marked as unconfirmed or global are exactly that. We would rather say so than imply a guarantee we have not verified.
8. How long we keep things
These are the periods the system actually enforces today.
- Sign-in attempt records, including IP addresses90 days
- Expired or revoked session tokens, including the city and country held against them30 days
- Authentication audit records365 days
- Notification delivery records365 days
- Inactive device registrations30 days
- Photos, video and audioKept until deleted. There is no automatic time limit unless your organisation sets one, and by default none is set.
- Account, coaching and health recordsKept while the account is active.
Our change-audit log, which records what was altered and by whom, currently has no expiry.
9. Your rights
Under UK GDPR you have the right to access your data, correct it, ask for it to be erased, restrict or object to how it is used, and ask for a copy in a portable format. You can also complain to the Information Commissioner's Office at ico.org.uk, and we would ask that you raise it with us first so we have a chance to fix it.
For coaching records, ask your organisation first — it decides what is held. For your account, identity and health information, contact us at [email protected]. A parent or guardian linked to a child may exercise these rights on the child's behalf.
We will respond within one month. Some of these requests currently need manual work on our side rather than a button in the app, and the next section explains where that is the case.
10. Deleting your account, or getting a copy of your data
There is no delete-account button in the app yet. Email [email protected] from the address on your account and we will action it. If you are a parent asking on behalf of a child, tell us which child and which organisation.
What deletion removes today
Your identity record, your medical notes, your emergency contacts, your date of birth and your sign-in history are deleted from our accounts system, and the deletion is propagated to the rest of the platform.
What it does not yet remove
Some coaching records cannot be removed automatically because performance data depends on them, and our change-audit log retains previous values indefinitely. We cannot currently promise that erasure removes every trace. Ask us and we will tell you specifically what remains for your account.
Getting a copy of your data
Email the same address. The export we can produce automatically covers your identity, medical information, emergency contacts, guardian links, organisation memberships, recent sign-in attempts and active sessions. It deliberately excludes your password hash, two-factor secret and session tokens, and it lists them as withheld rather than pretending they were not there. Coaching records held in the wider platform are not yet included in that export and must be requested separately; we will gather them by hand.
11. Security
Passwords are stored using Argon2id and are never recoverable in readable form. Session and reset tokens are stored only as cryptographic digests. Access to sensitive records is controlled by permissions, so a coach sees only what their role allows, and medical and emergency information is restricted further. All traffic is encrypted in transit. Access to the servers themselves is restricted to a private network.
We do not currently apply our own encryption at rest on top of what our hosting provider offers. We think it is more useful to tell you that than to describe our security in general terms that sound stronger than they are.
If a breach occurs that is likely to result in a risk to people, we will notify the ICO within 72 hours and tell affected organisations without undue delay.
12. Changes to this notice
If we change this notice materially we will update the date at the top and tell organisation administrators. If a change affects how we use data you have already given us — rather than simply describing something more clearly — we will ask you to agree to it rather than relying on your continued use of the service.
13. Contact
Kieron McAuley-Kinchin, trading as PerfHQ. Email [email protected]. This is the contact point for access, correction, erasure and any other request under this notice, and it is monitored. For help with the app rather than your data, email [email protected].
You can also complain to the Information Commissioner's Office at ico.org.uk.