Legal
Last updated September 5, 2026
Sushi Golf is operated by Voltaire Technologies LLC, a limited liability company registered in Illinois, USA (“we”, “us”). This policy explains how information is handled when you use the Sushi Golf web app or native iOS app (together, the “Service”). Questions or requests: support@sushigolf.io.
The native app stores sign-in tokens, an appearance preference, and your GPS on/off preference in iOS secure storage. It uses an app-private SQLite database for user-scoped round snapshots, work in progress, and an offline change queue. It also stores public, shared course-map artifact files and their cache metadata on the device so maps can reopen reliably.
A JSON or CSV export is downloaded to an app-private temporary cache file before the iOS share sheet opens. The app attempts to remove that temporary file afterward; any copy you send to Files, another app, or another person is controlled by that destination. iOS or an app uninstall may remove local data under Apple’s platform rules.
The native app requests foreground Location Services only after you tap the location control in an open round. While that control is on, the location and accuracy supplied by iOS are used in memory to show where you are on the course map, calculate the distance to the pin, and let you set the tee or place the next shot at your position. The raw device coordinate is not sent to Sushi Golf, GolfCourseAPI, PostHog, or Sentry and is not retained. The app remembers whether you turned GPS on or off. Location updates stop when you turn the control off or leave the round workspace.
The app does not request background location, Motion, Photos, Camera, or Microphone permission. A social sign-in provider can still supply a profile image through Clerk without Sushi Golf reading your photo library. Your device connects to Sushi Golf’s Vercel-hosted service and may also connect directly to Clerk for authentication, PostHog for product analytics, and Sentry for configured error diagnostics. Those services can see ordinary network information, including the source IP needed to make a connection.
We use information to authenticate accounts; save and synchronize the shot locations and details you enter; provide course search, optional on-device proximity ranking, and maps; compute scores, handicap estimates, strokes gained, and other statistics; support offline work and exports; prevent abuse; diagnose errors; deliver feedback; support prior transactions; and understand and improve the Service. We do not sell personal information or show ads.
We use providers to operate the Service. Depending on the feature and configuration, information is handled by:
These providers process information under their own terms, security controls, locations, and retention practices. Public course-map source data may also come from public mapping sources.
Voice and natural-language shot logging are not part of the current public product. When that legacy feature was available, voice clips were sent to OpenAI for transcription and transcribed or typed text was sent to Anthropic to produce structured golf data. Existing rounds created through that feature remain available and analyzable.
We did not create voiceprints or use recordings to identify anyone. The application did not intentionally retain audio after transcription, but provider-side processing and retention were governed by the providers’ applicable API terms and settings.
On the web, Clerk uses cookies or similar storage needed to sign you in and secure your session. PostHog uses cookies or local storage for product analytics, and a historical referral link may set a 30-day attribution cookie. The iOS app uses the secure storage, SQLite, and file caches described above. We do not use advertising cookies or sell data for targeted advertising.
We generally keep account and golf data while your account exists. The current in-app deletion flow deletes active account-scoped golf, profile (including a retained original player photo), transcript, credit, and billing rows from our primary application database, and de-identifies limited retained referral attribution. It deletes the corresponding Clerk user only after that database step succeeds. If Clerk provides a Sign in with Apple access token, Sushi Golf asks Apple to revoke it before deleting the Clerk user; if no usable token is available, the app gives instructions for removing the remaining authorization in Apple Account settings. The iOS app first records local cleanup intent, clears that user’s private workspace and analytics queue on the device, then signs out. When PostHog analytics is enabled, Sushi Golf also queues provider-side deletion of the matching analytics person, events, recordings, aliases, and associated identifiers before deleting the Clerk user; a provider failure leaves the account retryable. PostHog completes that erasure asynchronously. Shared public course data and course-map caches are not account records.
To prevent an old signed-in request from recreating deleted account data, we retain a minimal deletion marker: a SHA-256 hash of the opaque Clerk user ID and the time the marker was created. It contains no raw Clerk ID, email address, name, or golf data, and we do not use it for analytics, profiling, advertising, or marketing. Because the hash is deterministic, it can be matched if the same opaque Clerk ID is presented again; it is pseudonymous, not anonymous. We retain it while Sushi Golf operates, with no automatic expiration, so the deletion remains enforceable and stale requests cannot recreate the account.
Deletion does not promise immediate erasure from every backup, security or request log, error event, feedback message, financial record, export, recipient, or other provider system. PostHog analytics deletion is queued as described above; historical Discord feedback retention and other provider-level procedures still require production verification. Limited records may also be retained where required for security, fraud prevention, accounting, or law. You can export your golf data before deletion and can ask for deletion help or provider-specific follow-up by emailing support@sushigolf.io.
Public links are optional and are created only when you select Share. Treat a shared link as public: recipients may forward it and link-preview services may fetch its recap. Deleting the associated round or your account removes the recap from Sushi Golf’s primary app data, but cannot remove copies, screenshots, exports, or previews already made by other people or services.
We use encrypted network connections and access controls appropriate to the Service. Secret provider credentials stay server-side; mobile and web clients necessarily contain public configuration values used to connect to Clerk, PostHog, or Sentry. No storage, transmission, or filtering system is perfectly secure.
Sushi Golf is not directed at children under 13, and we do not knowingly collect personal information from them. If you believe a child has created an account, contact us and we’ll address it.
If we change this policy, we’ll update the date at the top and, for material changes, provide notice through an appropriate channel. Continued use after a change takes effect means you accept the updated policy.
Voltaire Technologies LLC · Illinois, USA · support@sushigolf.io