SURGE+ Logo

PRIVACY POLICY

Last updated June 01, 2026

This Privacy Notice for Suhas Suren (doing business as Shot AI) (“we,” “us,” or “our”) describes how and why we might access, collect, store, use, and/or share (“process”) your personal information when you use our services (“Services”), including when you:

  • Download and use our mobile application (Shot AI), or any other application of ours that links to this Privacy Notice
  • Use Shot AI. The App is a mobile application that provides multi-sport AI swing and form analysis, including video upload, on-device pose detection, AI-powered analysis using Google's Gemini models, performance tracking, and subscription access.
  • Engage with us in other related ways, including any sales, marketing, or events
Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. If you still have any questions or concerns, please contact us at support@surgeplus.app.

SUMMARY OF KEY POINTS


What personal information do we process? We process personal information you provide to us, including account details and video recordings you upload of your athletic performance.

Do we process any sensitive personal information? Yes. We process biometric and health-related information (such as body-pose and movement data derived from your videos) when necessary, with your consent or as otherwise permitted by applicable law.

Do your videos leave your device? Yes. While some pose detection runs on your device, the videos and images you upload are transmitted to our third-party AI provider (Google) for analysis. See “DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?” below.

Do we collect any information from third parties? We do not collect personal information about you from third parties, but we do use third-party tools (such as analytics and advertising-attribution SDKs) that collect information automatically.

How do we process your information? To provide, improve, and administer our Services, to communicate with you, for security and fraud prevention, for advertising attribution and analytics, and to comply with law.

In what situations and with which parties do we share personal information? We share information with service providers including Google (AI analysis, analytics, crash reporting), Meta/Facebook (advertising attribution), and Apple (payments). See Section 4.

How do we keep your information safe? We use organizational and technical measures to protect your personal information. However, no electronic transmission or storage can be guaranteed 100% secure.

What are your rights? Depending on where you are located, you may have rights regarding your personal information.

How do you exercise your rights? By visiting http://www.surgeplus.app/contact or by contacting us. We will act on any request in accordance with applicable data protection laws.

TABLE OF CONTENTS

1. WHAT INFORMATION DO WE COLLECT?
2. HOW DO WE PROCESS YOUR INFORMATION?
3. WHAT LEGAL BASES DO WE RELY ON?
4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
5. DO WE USE COOKIES AND TRACKING TECHNOLOGIES?
6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?
7. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
8. HOW LONG DO WE KEEP YOUR INFORMATION?
9. HOW DO WE KEEP YOUR INFORMATION SAFE?
10. WHAT ARE YOUR PRIVACY RIGHTS?
11. CONTROLS FOR DO-NOT-TRACK FEATURES
12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
14. DO WE MAKE UPDATES TO THIS NOTICE?
15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide when you register, express interest in our products, participate in activities on the Services, or contact us. This may include:
  • names
  • email addresses
  • contact or authentication data
  • user-uploaded media (e.g., videos of your athletic performance)
  • athletic profile data (e.g., chosen sport, performance goals, practice style)
Sensitive Information. When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:
  • biometric data (e.g., body-pose, joint position, and movement data derived from your uploaded videos)
  • health-related data (e.g., physical performance and technique information)
Because biometric and health-related data are sensitive, we process them only to provide your swing/form analysis and only with your consent, which you may withdraw at any time as described in Section 10.

Payment Data. We may collect data necessary to process your payment if you make purchases. All payment data is handled and stored by Apple Inc. (https://www.apple.com/legal/privacy/). All subscriptions and financial transactions are processed securely and exclusively by Apple through their App Store In-App Purchase system. Shot AI does not collect, receive, process, or store your financial data such as credit card numbers or billing addresses.

Social Media Login Data. If you choose to register using a social media account, we collect certain profile information from that provider, as described in Section 7.

Application Data. If you use our application(s), we may collect:
  • Mobile Device Access. We may request access to your device's camera, photo library/storage, and other features. You can change permissions in your device settings.
  • Mobile Device Data. We automatically collect device information, operating system and version, device and application identifiers, hardware model, internet service provider and/or mobile carrier, and IP address.
  • Push Notifications. We may request to send you push notifications. You can opt out in your device settings.

Information automatically collected

In Short: Some information — such as your IP address and device characteristics — is collected automatically.

We automatically collect device and usage information, such as IP address, device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services. We collect this through our own systems and through third-party SDKs (see Sections 4 and 5), including:
  • Log and Usage Data — diagnostic, usage, and performance information.
  • Device Data — information about the device you use to access the Services.
  • Location Data — precise or imprecise location, depending on your device permissions.
  • Advertising and Attribution Data — identifiers used to measure the performance of our marketing (see the Meta/Facebook disclosure in Section 4).

Google API

Our use of information received from Google APIs adheres to the
Google API Services User Data Policy, including the Limited Use requirements.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, for advertising and analytics, and to comply with law.

  • To facilitate account creation and authentication and manage user accounts.
  • To provide your swing/form analysis, which requires transmitting your uploaded video to our AI provider (Google) for processing.
  • To request feedback and to contact you about your use of our Services.
  • To send marketing and promotional communications, in line with your preferences.
  • To protect our Services, including fraud monitoring and prevention.
  • To identify usage trends and improve our Services.
  • To measure and improve the effectiveness of our marketing and advertising campaigns, including through advertising-attribution partners such as Meta/Facebook.
  • To improve our AI models — only if you opt in. Analyzing a diverse range of videos helps us train more effective coaching models. You can decline this without losing access to the core analysis feature.

3. WHAT LEGAL BASES DO WE RELY ON?

In Short: We only process your personal information when we have a valid legal reason to do so under applicable law.

Where GDPR/UK GDPR applies, we rely on:
  • Consent — including your explicit consent to process biometric and health-related data. You can withdraw consent at any time.
  • Legitimate Interests — to operate, secure, and improve our Services and measure our marketing.
  • Legal Obligations — to comply with applicable law.
  • Vital Interests — to protect someone's vital interests where necessary.
If you are located in Canada, we may process your information where you have given permission (express or implied). You can withdraw consent at any time.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share information with the service providers and in the situations described below.

We share personal information with the following categories of third parties:
  • Google (AI analysis, analytics, crash reporting, authentication). We transmit your uploaded videos and images to Google's Gemini models to generate your Analysis. We also use Google Firebase for analytics, crash reporting, and authentication. Google's processing is governed by the Google Privacy Policy and the Google API Services User Data Policy.
  • Meta Platforms, Inc. (Facebook). We use the Meta/Facebook SDK to measure the performance of our advertising and to attribute app installs and events to our marketing campaigns. This may involve sharing device and advertising identifiers with Meta. On iOS, this tracking occurs only where you have granted permission through Apple's App Tracking Transparency prompt. You can review Meta's practices in the Meta Privacy Policy.
  • Apple Inc. (payments). All purchases are processed by Apple; we do not receive your financial data.
  • Business Transfers. We may share or transfer your information in connection with any merger, sale of assets, financing, or acquisition of all or part of our business.
We do not sell your personal information for money. Certain advertising-attribution activity may be considered a “sale” or “sharing” under some US state laws; see Section 12 for your opt-out rights.

5. DO WE USE COOKIES AND TRACKING TECHNOLOGIES?

In Short: We use tracking technologies to collect and store information.

We use tracking technologies (including mobile SDKs and device identifiers) to maintain security, prevent crashes, fix bugs, save preferences, support core functions, and measure usage and advertising performance.
  • Google Firebase Analytics & Crashlytics — to understand usage and diagnose crashes.
  • Meta/Facebook SDK — for advertising attribution and measurement, subject to your App Tracking Transparency choice.
You can limit tracking through your device's privacy settings and the App Tracking Transparency prompt.

6. DO WE OFFER ARTIFICIAL INTELLIGENCE-BASED PRODUCTS?

In Short: Yes. Our Services include features powered by artificial intelligence, and using them involves sending your content to a third-party AI provider.

We provide AI features (“AI Products”) through third-party AI service providers, including Google (Gemini models via Google Cloud / the Gemini API). To analyze your performance, the videos and images you upload are transmitted to Google for processing. While some pose detection runs locally on your device, the AI analysis itself requires sending your content off-device to Google.

Your input (uploaded media and related data) and output (the resulting Analysis) are processed by these AI providers to enable the feature. You must not use the AI Products in any way that violates the providers' terms or policies. All personal information processed through our AI Products is handled in line with this Privacy Notice and our agreements with these providers.

7. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you log in using a social media account, we may receive certain profile information.

If you register or log in using a third-party social media account, we receive certain profile information from that provider (such as name and email). We use it only as described in this Notice.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information only as long as necessary.

We keep your personal information only as long as necessary for the purposes set out in this Notice, unless a longer period is required by law. After you terminate your account, we delete or anonymize your personal information within a reasonable period, except where we must retain certain information to prevent fraud, resolve disputes, enforce our terms, or comply with legal requirements.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We use organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect your personal information. However, no electronic transmission or storage technology can be guaranteed 100% secure.

10. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: Depending on your location, you may have rights to access, change, or delete your personal information.

Depending on your region, you may have the right to: request access to and a copy of your personal information; request correction or deletion; restrict or object to processing; data portability; and to withdraw consent (including for biometric/health data processing) at any time.

Withdrawing consent. Where we rely on your consent, you can withdraw it at any time by contacting us at support@surgeplus.app. Withdrawal does not affect prior lawful processing.

Account Information

To review, change, or terminate your account, you can:
  • Log in to your account settings and update your account, or delete your account in-app.
Upon request, we will deactivate or delete your account and information from our active databases, subject to the retention exceptions in Section 8.

For privacy questions, email support@surgeplus.app.

11. CONTROLS FOR DO-NOT-TRACK FEATURES

Most browsers and some mobile systems offer a Do-Not-Track (“DNT”) feature. As no uniform DNT standard has been finalized, we do not currently respond to DNT signals. On iOS, you can control tracking through the App Tracking Transparency prompt and your device settings.

12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: Residents of certain US states have specific rights.

Depending on your state, you may have the right to: know whether we process your personal data; access it; correct inaccuracies; request deletion; obtain a copy; non-discrimination for exercising your rights; and opt out of processing for targeted advertising, the sale of personal data, or profiling. Because we use advertising-attribution partners (e.g., Meta), you may exercise your opt-out by adjusting your App Tracking Transparency setting and by contacting us.

To exercise these rights, visit http://www.surgeplus.app/contact, email support@surgeplus.app, or use the contact details below.

13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?


Australia and New Zealand

We process your personal information under Australia's Privacy Act 1988 and New Zealand's Privacy Act 2020.

Republic of South Africa

You may request access to or correction of your personal information by contacting us (see Section 16).

14. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, as necessary to stay compliant.

We may update this Privacy Notice. The updated version will be indicated by a revised date. If we make material changes, we may notify you by prominent posting or direct notification.

15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

Email support@surgeplus.app or write to:

Suhas Suren
Bhudigere Cross
Bengaluru, Karnataka 560067
India
Phone: +91 6360855691
support@surgeplus.app

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

You may have the right to request access to, correction of, or deletion of your personal information. To do so, visit http://www.surgeplus.app/contact or delete your account in-app.