●ACEAI
PrivacyTermsContactOpen ACEAI

Privacy

Your training data, explained.

This policy describes what ACEAI collects, why it is needed, where it is processed, and how you can request access, correction, or deletion.

Effective and last updated August 21, 2026
The original video stays in your browser.

In the current ACEAI web workflow, video decoding, motion scanning, and key-frame selection happen on your device. ACEAI receives selected JPEG evidence frames—not the original uploaded video file.

1. Scope and contact

This policy applies to the ACEAI website at aceai.mlmanual.com and its authenticated web application. “ACEAI,” “we,” and “us” refer to the operator of this service.

Questions and privacy requests can be sent to mengliucs@gmail.com. We do not publish a postal address or telephone support channel.

2. Information we collect

Google identity and account information

When you choose Google sign-in, we receive your stable Google account identifier, verified email address, display name, profile image, and locale when supplied by Google. For a managed Google account, Google may also supply a hosted-domain indicator. We use the stable identifier—not your email address—as the identity key for your ACEAI account.

ACEAI does not receive your Google password. We do not retain Google access tokens or refresh tokens.

Session and security information

We set essential cookies for the short-lived Google sign-in transaction and for your ACEAI session. The sign-in transaction expires after about 10 minutes. An ACEAI session can remain valid for up to 30 days unless you sign out or it is revoked. The database stores a cryptographic hash of the session token and a hash derived from the browser user agent, rather than the raw session token.

Security access logs

The production reverse proxy writes limited access logs for reliability and abuse investigation. A log can include request time, method, path, response status, latency, browser user-agent string, and a masked network address. Google OAuth code and state query values are replaced before logging. Log files rotate by size and are capped at three 10 MB files per production container, so retention is traffic-dependent rather than a fixed number of days.

Anonymous funnel analytics

Before you sign in, ACEAI uses first-party HttpOnly cookies to distinguish a pseudonymous browser visitor for about 180 days and a visit for about 30 minutes. The cookie values are random identifiers; the analytics database stores only cryptographic hashes of those values. If you later sign in, funnel events tied to that browser identifier can be associated with your ACEAI account so we can understand whether the product is working from first visit through completed analysis.

These records are limited to coarse product events, the page path, campaign parameters such as UTM source and campaign, and the referring site's host name. ACEAI does not store an IP address, complete referrer URL, uploaded file name, or raw error message in this funnel. Requests from obvious automated scanners and bots are discarded rather than written to the analytics database.

Profile, product activity, and coaching history

Depending on how you use ACEAI, we store:

  • Your tennis level, city, timezone, goals, and racket-hand preference.
  • Product events such as navigation, video selection and playback, analysis lifecycle, issue review, correction visibility, drill completion, and profile updates.
  • Coaching observations, scores, feedback, technique memories, memory revisions, improvement plans, and your confirmations or rejections.

Video metadata and analysis evidence

We store the original file's name, size, duration, and a SHA-256 content hash so that analysis can be associated with your account and safely reused. A filename can itself contain personal information, so consider renaming a file before analysis if needed.

For a new analysis, the browser sends up to eight downsampled JPEG key frames, their timestamps, locally detected pose landmarks, and sampling information. We retain those selected frames together with the model prompt, raw model response, normalized analysis report, and an artifact manifest. We do not retain the original video bytes.

3. How we use information

  • Authenticate you and keep your account and sessions secure.
  • Analyze visible tennis technique and produce coaching feedback.
  • Incrementally update your technique memory and training plan without repeatedly processing the original video.
  • Restore your recent results and respond to support requests.
  • Understand service operation, diagnose failures, prevent abuse, and improve product reliability and usability.
  • Comply with applicable legal obligations and protect users.

We do not sell your personal information and do not use third-party advertising trackers on the ACEAI web application.

4. Where information is processed

ACEAI uses service providers to operate the product. These currently include Google for OpenID Connect sign-in, OpenRouter and the selected model provider for multimodal analysis, and Tencent Cloud infrastructure for application hosting, PostgreSQL, and private object storage in its Silicon Valley region.

Selected key frames, pose evidence, and the coaching prompt are sent through OpenRouter to the selected model provider. ACEAI requests a provider route with data collection disabled; this is a routing request, not a substitute for the third parties' own terms and privacy practices.

The coaching prompt can include the video filename, selected analysis focus, player level, frame timestamps, pose evidence, and prior tracked skill keys. Rename a file and avoid entering sensitive profile or goal text if you do not want that context included in model processing.

Analysis bundles in Tencent Cloud Object Storage are account-scoped, private, and written with server-side encryption. Data may therefore be processed outside your country, including in the United States.

5. Browser storage and cookies

ACEAI uses first-party HttpOnly cookies for the pseudonymous visitor and visit measurements described above, to complete sign-in, and to maintain your session. The visitor cookie lasts about 180 days and the visit cookie about 30 minutes. The web app also keeps the latest analysis report in account-scoped browser local storage to make the interface responsive. Signing out removes that local report cache from the current browser.

Google may set its own cookies while you are on Google's sign-in pages. Those cookies are controlled by Google, not ACEAI.

6. Retention

One-time OAuth transaction records are short-lived, and application sessions expire after 30 days. The anonymous funnel cookies expire on the approximate schedules described above; their hashed event records are retained to measure product performance and can be associated with your account after sign-in. Analysis evidence, coaching artifacts, memory, profile information, and product events are otherwise retained while your account is active so ACEAI can provide longitudinal progress tracking and incremental analysis.

Security access logs use the size-based rotation described above. The exact time represented by those files depends on traffic volume.

You can request deletion at any time. We may preserve limited records when reasonably necessary for security, fraud prevention, dispute resolution, or a legal obligation. Any copy remaining in a disaster recovery backup will not be used for ordinary product activity and is removed through the backup's normal lifecycle.

7. Security

ACEAI uses HTTPS, private user-scoped storage, hashed session tokens, server-side ownership checks, private database networking, and encrypted object storage. No system can guarantee absolute security; contact us promptly if you believe your account or data has been compromised.

8. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, restrict, export, or object to certain processing of personal information. You may update supported profile fields in the application, sign out to revoke the current session, or contact us for another request.

To delete the account and associated private analysis artifacts, follow the steps on the account deletion page. We may need to verify that the requester controls the signed-in account.

9. Children

ACEAI is not directed to children under 13, or a higher minimum age where local law requires it. We do not knowingly collect personal information from a child who cannot lawfully consent. A parent or guardian who believes a child submitted data should contact us.

10. Changes to this policy

We may update this policy as the service changes. The effective date at the top will be revised when that happens. Material changes will be presented through an appropriate notice in the service when reasonably practicable.

Need help with your data?

Send your request from the email address connected to your ACEAI account whenever possible. Never send a password, API key, or session token.

Email privacy supportDelete my account

ACEAI · Personal tennis intelligence

HomePrivacyTermsContactDelete account