Legal
Privacy Policy
This policy explains what data Racket Locker collects, why we collect it, and how it is kept secure. We do not sell your personal data.
1. Who we are
Racket Locker ("we", "us", or "our") is a web application that helps tennis players track their racket inventory, monitor string life, and log play sessions. The service is operated as a personal project and is currently free to use.
2. What data we collect
When you create an account and use Racket Locker, we collect:
- Account information — your email address, display name, and a hashed (never plain-text) password if you register with email.
- Profile data — details you enter yourself: play style, skill level, location or climate preferences, and a profile photo URL if provided.
- Racket and equipment data — racket specifications, stringing records (tension, gauge, date, stringer), and setup notes you log.
- Play session logs — session date, duration, court type, and any notes you add.
- Feedback submissions — text and optional screenshots you choose to send through the in-app feedback form.
- Mobile launch notification signup — the email address you voluntarily submit on our public website so we can tell you when the Racket Locker mobile apps launch.
- Session data — a server-side session cookie (stored in our database) that keeps you logged in. No tracking cookies are set.
If you sign in with Google or Apple, we receive only the identifier and email address provided by that service. We do not receive your social passwords.
3. How we use your data
We use the data you provide solely to operate and improve the service:
- To authenticate you and secure your account.
- To store and display your racket inventory, stringing history, and play logs.
- To send transactional emails you request (e.g. password reset).
- To send the one-purpose mobile app launch notification you requested. Signing up does not subscribe you to a general newsletter.
- To review feedback and fix issues you report.
- To send in-app notifications relevant to your account (e.g. restringing reminders).
- To provide optional features you choose to use, such as AI-assisted racket insights and the WHOOP workout reminder described below.
We do not use your data for advertising, profiling, or any automated decision-making that has legal or significant effects on you.
4. WHOOP integration
Connecting WHOOP is optional. When you choose to connect it, you authorize Racket Locker through WHOOP's OAuth consent flow to access workout/activity timing under the workout scope configured for this service (currently read:workout by default). We also make a basic WHOOP profile request to obtain the WHOOP user identifier needed to associate the connection with your Racket Locker account. We do not use that request to import a WHOOP name, email address, or profile.
For a connected account, Racket Locker may receive and retain:
- Connection identifiers — the Racket Locker user ID and WHOOP user ID.
- OAuth security data — encrypted access and refresh credentials, token expiry metadata, connection status, and connection timestamps. The credentials are stored encrypted at rest and are never shown in the app.
- Workout receipt data — the WHOOP workout identifier, the canonical workout type/classification, workout start and end timestamps, and the local calendar date calculated using your selected timezone.
- Reminder processing data — your timezone, the scheduled reminder time, processing status, retry counts, reminder time, error details when applicable, and created/updated/cancellation timestamps needed to operate and troubleshoot the reminder.
Racket Locker uses eligible workout timing only to determine whether to send an in-app reminder, normally one hour after the workout ends. The reminder opens the activity flow; you must manually confirm the date, duration, and racket before any session is saved. Racket Locker does not automatically create a play session, choose a racket, or change string-life or hit-count totals.
WHOOP health data: Racket Locker does not import or store WHOOP health metrics, sleep, recovery, strain, heart rate, calories, or other health or medical data. Non-eligible workouts may be recorded only as a skipped processing receipt so the same workout is not repeatedly considered; they are not imported as Racket Locker sessions.
You can disconnect WHOOP from Account Settings. Disconnecting makes a best-effort revocation request to WHOOP, immediately clears the locally stored OAuth credentials and expiry metadata, and cancels pending WHOOP reminders. If you revoke access in WHOOP first, Racket Locker may mark the connection as needing reconnection. Disconnecting does not rewrite sessions you already saved manually, and limited non-credential receipt or status history may remain with your account until it is deleted.
5. Data sharing
We do not sell, rent, or share your personal data with third parties for their own purposes. Limited sharing occurs only as necessary to operate the service:
- Hosting infrastructure — the application runs on Replit, which hosts the server and database. Data is stored in a PostgreSQL database provisioned by Replit.
- Email delivery — transactional emails are sent through the email delivery services configured for Racket Locker (including Replit Mail and, for account emails where enabled, Resend). Mobile launch signup addresses are stored in a dedicated Resend audience and processed by Resend so we can send the requested launch notice. These addresses are not placed on a general newsletter list.
- Authentication providers — if you use Google or Apple sign-in, your browser communicates with those services directly under their own privacy policies.
- WHOOP — when you connect WHOOP, Racket Locker exchanges OAuth and workout requests with WHOOP to provide the reminder feature. WHOOP's own privacy policy governs data it handles on its service.
- AI-assisted insights — if you request an AI-generated insight, the relevant racket, stringing, play-session, and selected profile context needed for that insight is sent through Racket Locker's managed OpenAI integration. Generated insights may be stored in your account. WHOOP credentials and WHOOP health data are not sent for these insights.
6. Data retention
Your account data, including connected-integration records, is kept for as long as your account is active. Disconnecting WHOOP clears local OAuth credentials and stops future WHOOP reminder processing, but non-credential receipt and status history may be retained as described above. If you request account deletion, we will delete your account and associated WHOOP connection and receipt data within 30 days, subject to limited copies that may remain temporarily in backups or security records until they are rotated or no longer needed.
Mobile launch signup addresses are retained in the dedicated Resend audience until the launch notification has been sent and any short operational follow-up is complete, or until you ask us to remove your address, whichever comes first. Any launch email will include an opt-out method. You may also request removal at any time using the contact method below.
7. Security
We take reasonable technical precautions to protect your data:
- Passwords are hashed with bcrypt before storage. We never store plain-text passwords.
- WHOOP access and refresh credentials are encrypted at rest with authenticated encryption. They are used server-side and are not sent to the browser.
- All traffic is served over HTTPS.
- Session identifiers are stored server-side in the database, not in client-readable cookies.
- API routes that access personal data require an authenticated session.
No system is perfectly secure. If you discover a security concern, please contact us promptly.
8. Your rights
You have the right to:
- Access the data we hold about you.
- Correct inaccurate data in your account settings.
- Request deletion of your account and all associated data.
- Export your data (racket and session records are visible in the app at any time).
- Ask us to remove your email address from the mobile launch notification audience.
To exercise any of these rights, contact us using the details below.
9. Children's privacy
Racket Locker is not directed at children under 13. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of the service after changes take effect constitutes acceptance of the revised policy.
11. Contact
Questions about this policy, WHOOP access, or a data access or deletion request? Use the feedback form or your account's feedback option once logged in. Please do not include a password, WHOOP access or refresh token, or any other credential in a request. We may need enough account information to locate the correct record, but we will not ask you to send credentials.