← Back to Sign In
Peak Performance AI

Privacy Policy

Pixels Point Ltd (Company No. 11129649)  ·  Last updated: 16 September 2026  ·  Version 1.1

This Privacy Policy explains how Pixels Point Ltd collects, uses, and protects personal data in connection with the Peak Performance AI platform (the "Service"). We have written this policy with particular care because the Service is used by sports clubs to record information about children and young people, including, in some cases, health and wellness information.

Please read this policy alongside our Terms of Service. If you are a Parent/Guardian or Player and have questions about how a specific Club uses your or your child's data, you should also contact that Club directly, as explained in Section 2 below.

1. Who We Are

Pixels Point Ltd is a company registered in England and Wales under company number 11129649, with its registered office at 44 Stornoway Road, Birmingham, England, B35 6NT. We operate the Peak Performance AI platform.

You can contact us about any privacy matter at: enquirepixelspoint@pixelspoint.co.uk.

2. Our Role: Data Controller and Data Processor

Because of how the Service works, Pixels Point acts in two different capacities depending on whose data is involved. This distinction matters because it determines who you should contact first with a query or request.

2.1. Where Pixels Point is the Data Controller

Pixels Point is the Data Controller in respect of the personal data of Club Administrators and Coaches who register for and use the Service — for example, their name, email address, password, and account activity. If you are a Club Administrator or Coach, you can direct questions about your own personal data to us directly using the details in Section 1.

2.2. Where Pixels Point is a Data Processor

Where a Club enters personal data about its Players and their Parents/Guardians into the Service (such as a Player's name, date of birth, team, session records, or wellness/medical notes), the Club is the Data Controller of that data, and Pixels Point acts only as a Data Processor, processing it strictly on the Club's instructions and under the terms of a Data Processing Agreement accepted by the Club at registration. If you are a Player, or a Parent/Guardian of a Player, and you have a question about how your or your child's data is used, you should contact the Club directly in the first instance, as they are responsible for that data. Pixels Point will support the Club in responding to any such request where needed.

3. Personal Data We Collect

3.1. Account and Club Data (collected directly)

  • Club Administrator and Coach details: name, email address, password (stored securely, not in plain text), role, and account activity.
  • Club details: club name, sport, city/town, contact email, contact phone number.
  • Billing information: once a paid Subscription Plan is selected, billing-related data is processed by our payment processor, Stripe. We do not directly store full payment card numbers.

3.2. Player and Team Data (entered by the Club)

  • Player details: name, age/date of birth, team, sport, squad number, and playing position.
  • Session data: training and match session logs, including notes entered manually or via voice input.
  • Match preparation data: opposition details and tactical notes entered by Coaches.
  • Wellness and medical information: where a Club chooses to record it, notes relating to a Player's injuries, wellness scores, or medical flags. This is Special Category Data under Article 9 UK GDPR — see Section 4 below.
  • Communications: messages sent between Coaches within the Service (direct messages).

3.3. Technical and Usage Data

  • Log-in and session data (via Supabase Authentication), including timestamps of account activity.
  • Basic technical data such as browser type and general usage patterns, used to maintain and improve the Service.
  • Language preference (the Service supports multiple languages).

4. Special Category Data (Health and Medical Information)

Where a Club records wellness, injury, or medical information about a Player within the Service, this constitutes Special Category Data under Article 9 UK GDPR, which receives additional legal protection. The Club, as Data Controller, is responsible for ensuring an appropriate condition under Article 9 applies — most commonly, explicit consent from the Player's Parent/Guardian (or the Player themselves, where old enough to provide informed consent) — before entering such data into the Service. Pixels Point processes this data only as instructed by the Club and does not independently determine the legal basis on which it is collected.

Access to medical and wellness data within a Club's Account can be restricted by the Club Administrator to specific Coaches on a need-to-know basis, using the Service's permission controls.

5. Children's Personal Data

We recognise that a significant proportion of the personal data processed through the Service relates to children and young people (Players under the age of 18). We have designed the Service, and this policy, with reference to the Information Commissioner's Office (ICO) Age Appropriate Design Code (the "Children's Code").

Key points about how we approach children's data:

  • Players do not, at this time, register their own accounts or log in to the Service directly — their personal data is entered and managed on their behalf by the Club, under arrangements the Club is responsible for putting in place with Parents/Guardians (for example, through the Club's own registration or membership forms).
  • Where the Service is extended in future to allow direct access by Players or by Parents/Guardians, we will review this policy and our design of that functionality specifically against the Children's Code before launch, including default privacy settings, use of nudge techniques, and profiling.
  • We do not knowingly use children's personal data for marketing purposes, nor do we permit it to be used to train third-party AI models (see Section 7).
  • We rely on Clubs, as Data Controllers, to ensure that appropriate parental consent is obtained before a child's personal data — particularly Special Category Data — is entered into the Service.

6. How We Use Personal Data and Our Legal Bases

We use personal data for the following purposes, relying on the UK GDPR legal bases indicated:

  • To provide and operate the Service (creating accounts, storing Club/Player/session data, generating reports) — necessary for the performance of our contract with the Club, or, in respect of Player/Parent data, processed on the Club's instructions as Data Processor.
  • To generate AI-assisted coaching reports and insights — performance of our contract with the Club (see Section 7 for detail on AI processing).
  • To process payments for paid Subscription Plans — necessary for the performance of our contract with the Club.
  • To communicate with Club Administrators about their Account, billing, or support queries — necessary for the performance of our contract, and our legitimate interest in providing customer support.
  • To maintain the security and integrity of the Service, including detecting and preventing unauthorised access — our legitimate interest in protecting the Service and the personal data within it.
  • To comply with our legal obligations, such as responding to lawful requests from regulators or retaining records for tax purposes.
  • Where explicit consent has been given (for example, for Special Category Data entered by a Club) — consent, obtained and managed by the Club as Data Controller.

7. AI Processing (Anthropic Claude API)

Certain features of the Service — including AI-generated session reports, insights, and match preparation summaries — are powered by Anthropic's Claude AI models, accessed via Anthropic's commercial API. When a Coach uses one of these features, relevant data (which may include Player names, session notes, and in some cases wellness-related information) is transmitted securely to Anthropic for the sole purpose of generating the requested output.

Anthropic's commercial terms (which govern API use, as distinct from Anthropic's consumer Claude.ai product) contractually commit that data submitted via the API is not used to train Anthropic's underlying models. Anthropic's Data Processing Addendum is automatically incorporated into those commercial terms and includes the EU Standard Contractual Clauses (Module Two, controller-to-processor, and Module Three, processor-to-processor) together with a UK International Data Transfer Addendum, providing a recognised transfer mechanism for personal data sent to Anthropic. Anthropic publishes its current list of sub-processors and their locations, which we review periodically.

Anthropic's AI processing currently takes place on infrastructure located in the United States — Anthropic does not currently offer EU/UK data residency for this processing. This means Player and session data used to generate AI content is transferred outside the UK/EEA, safeguarded by the mechanisms described above rather than by data residency. We keep this under review and will update this policy if that changes.

AI-generated output should always be reviewed by a Coach before being relied upon, particularly in relation to a Player's health or wellbeing — see Section 9 of our Terms of Service.

8. Who We Share Personal Data With

We do not sell personal data. We share personal data only with the following categories of recipient, each acting under contractual obligations to protect it:

  • Supabase — provides our database, authentication, and backend infrastructure. Personal data is hosted on servers located in Sweden (EU), within the European Economic Area.
  • Vercel — hosts and delivers the Service's web application.
  • Anthropic, PBC — processes certain data to generate AI-assisted content, as described in Section 7.
  • Stripe — processes payment card data for paid Subscription Plans. Stripe is a PCI-DSS compliant payment processor; we do not directly store full card details.
  • Professional advisers, regulators, or law enforcement, where required by law or necessary to establish, exercise, or defend our legal rights.

9. International Data Transfers

Our primary database is hosted within the European Economic Area (Sweden). Where personal data is transferred outside the UK or EEA — principally to Anthropic in the United States, for AI processing as described in Section 7 — we ensure an appropriate safeguard recognised under UK GDPR is in place before the transfer takes place, such as the Standard Contractual Clauses and UK International Data Transfer Addendum incorporated into Anthropic's Data Processing Addendum.

10. Data Retention

We retain personal data for as long as a Club's Account remains active, and for a limited period afterwards to allow for account recovery, to comply with legal or tax obligations, and to resolve any disputes. Our systems apply a default data retention period, which a Club may request to have adjusted within the bounds permitted by the Service. Where a Club terminates its Account, we will delete or anonymise Player, Parent/Guardian, and Club data within a reasonable period, save for data we are required to retain by law (such as financial records).

11. Data Security

We apply technical and organisational measures designed to protect personal data, including: encryption of data in transit; database-level access controls (Row Level Security) that restrict each Club's data to that Club's own authorised users; secure password storage; and restricting access to Special Category Data within a Club's Account to Coaches the Club Administrator has specifically authorised. No system can be guaranteed completely secure, and we continually review and improve our security measures.

12. Your Rights Under UK GDPR

Subject to certain exemptions, you have the right to:

  • be informed about how your personal data is used (as set out in this policy);
  • access a copy of your personal data;
  • request correction of inaccurate or incomplete personal data;
  • request erasure of your personal data in certain circumstances;
  • request that processing of your personal data be restricted;
  • object to processing based on legitimate interests;
  • request a portable copy of personal data you have provided to us, in certain circumstances;
  • withdraw consent at any time, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.

If you are a Club Administrator or Coach, you can exercise these rights by contacting us directly at enquirepixelspoint@pixelspoint.co.uk. If you are a Player or Parent/Guardian, please contact your Club in the first instance, as explained in Section 2.2 — we will support the Club in responding to your request.

You also have the right to lodge a complaint with the Information Commissioner's Office (ICO), the UK's data protection regulator, at ico.org.uk or by calling 0303 123 1113, if you believe your personal data has been mishandled.

13. Cookies and Similar Technologies

The Service uses essential cookies and similar technologies (such as local storage) required for authentication and to keep you securely signed in. We do not currently use non-essential cookies for advertising or cross-site tracking purposes. If this changes, we will update this policy and, where required, seek your consent.

14. Changes to This Policy

We may update this Privacy Policy from time to time, for example to reflect changes in the Service, the law, or our data processing practices. Where changes are material, we will notify Club Administrators by email or via an in-Service notice before the changes take effect. The "last updated" date at the top of this document indicates when it was last revised.

15. Contact Us and Complaints

Pixels Point Ltd

Company number: 11129649

Registered office: 44 Stornoway Road, Birmingham, England, B35 6NT

Email: enquirepixelspoint@pixelspoint.co.uk

Information Commissioner's Office (ICO): ico.org.uk | Telephone: 0303 123 1113

🔒 UK GDPR Compliant · ICO Registered · Data stored in EU