Scope and operator
Brian Blanchard is the sole operator of Stroke Gains. This draft covers the marketing site, web app, and iPhone app. It describes the implementation reviewed on October 1, 2026, and separately identifies planned billing.
Review required: Confirm the operator’s location, applicable privacy requirements, service regions, and minimum user age. No children’s-use or parental-consent policy has been approved.
Information handled
- Account information: Clerk account identifier, a Stroke Gains profile identifier, primary email address and verification status, and full name. Profile synchronization also stores update and account-deletion markers.
- Golf records: Uploaded scorecard photographs and their readings, manually entered or corrected shots, course and tee selections, round dates, optional tee times, time zones, tournaments, and a drawn signature when supplied. Course records can include course addresses and coordinates. Calculated records include scores and strokes-gained statistics.
- Invitation requests: An email submitted through the app’s waitlist goes to Clerk.
- Operational diagnostics: Scorecard-processing events include round identifiers, attempt counts, timing measurements, and failure information. Upload diagnostics can include photograph counts and processing timings. Errors may include information returned by a provider.
- Planned billing information: Apple and RevenueCat will handle subscription purchases. The in-flight subscription implementation associates subscription status with a Clerk account identifier and stores entitlement and billing-event information. Production billing is disabled.
Photographs can contain information beyond the golf notation. Review what is visible before uploading a card.
Review required: Verify the complete production logging and billing inventory, including payment-provider records, before launch. This list does not establish what infrastructure providers independently collect.
How the app uses information
The implementation uses account identifiers to authenticate requests and associate golfers with their records. It stores golf records, processes submitted photos into scorecard readings, saves corrections, calculates statistics, and presents round history and insights. A saved name can identify a user-directed stats share.
Operational diagnostics record processing progress and failures. Planned billing uses account-linked subscription status to determine access to subscription features.
Review required: Confirm the purposes and legal bases required in the service’s jurisdictions, invitation-email practices, and any additional operational uses. This draft makes no claims about sale of data, advertising, or AI-training restrictions without verified provider arrangements and operator approval.
Service providers
- Clerk: Account authentication, invitation requests, and account-profile information.
- Convex: Application backend, database records, and uploaded photo storage.
- Vercel: Hosting for the marketing site and web app.
- Anthropic: Claude processes submitted scorecard images to extract readings.
- Course services: GolfCourseAPI receives course search text or a course identifier. Open-Meteo receives course address/location search text or course coordinates to resolve a course’s time zone. These requests describe the golf course and do not include a golfer’s account identifier in the reviewed implementation.
- Apple: iPhone beta distribution through TestFlight. Apple In-App Purchase is planned for launch.
- RevenueCat, planned: Web billing and subscription-status management, including iOS subscription status. Production billing remains disabled.
Review required: Verify provider contracts, subprocessors, data regions and international transfers, security measures, and provider retention or training settings. No specific retention period, data-location guarantee, or training guarantee is asserted here.
Sharing and external tools
Stats sharing is user-controlled. When enabled, a token-based link exposes the shared name and statistics to anyone who has the link. The app can revoke the link. Revoking access does not retract information a recipient has already copied.
Connecting a compatible tool through the authenticated MCP integration allows that tool to retrieve golf records and calculated round, hole, shot, metric, and trend data. For example, you can connect ChatGPT to ask questions about your record. Information delivered to the tool is also subject to that tool’s policies and your account settings with it.
Review required: Confirm integration-consent and disconnect instructions, the exact exported fields, and any required disclosures for legal requests or other disclosures before publication.
Device and browser storage
The marketing site and web app store a theme preference in browser local storage. The web app also stores onboarding completion locally and writes a sidebar-state cookie. The iPhone app stores appearance, onboarding, and statistics-window preferences in device settings. Authentication is provided by Clerk and its client libraries.
The in-flight web billing implementation also uses a per-account browser marker for a pending checkout. It is part of planned billing, which is currently disabled in production.
Review required: Audit deployed cookies, authentication storage, infrastructure logging, and any analytics before publication. The repository alone does not establish an exhaustive cookie or tracking inventory.
Retention and deletion
Golf records remain stored until a deletion operation removes them; no fixed retention schedule is implemented in the reviewed code. Deleting an individual round removes its record and calculated facts and attempts to remove its stored photos.
When the current Clerk account-deletion handler runs, it clears the Stroke Gains profile’s email and name, marks it deleted, and revokes its stats-sharing link. It keeps the account-to-profile mapping and historical golf records and photos. Deleting a Clerk account therefore does not currently erase all Stroke Gains data.
Review required: Approve retention durations, deletion-request handling, identity verification, exceptions, and treatment of diagnostics and provider copies. Verify backups and provider deletion behavior. A full account-erasure endpoint and a fixed retention schedule are not currently implemented.
Requests and contact
The proposed hello@strokegains.golf inbox is not set up and cannot currently receive privacy, deletion, legal, or support requests.
Review required: Establish and test a working contact channel, confirm any required mailing address, and publish the process for privacy requests. Determine applicable access, correction, deletion, portability, objection, consent-withdrawal, and complaint rights for the service’s regions. No response deadline or complete-erasure guarantee has been approved.
This draft has no effective date. Final text, a verified contact channel, and the outstanding policy and implementation decisions need approval before publication.