Privacy Policy
Last updated: 2026-07-24
Scope & contact
BJJ Training App (“we”, “us”) operates this website and app. This notice describes the processing we control. A linked provider may also process data under its own notice. Questions or privacy requests can be sent to support@bjjtraining.app.
This is a training journal, not a medical service. Injury and weight entries can still be sensitive and receive the same private-by-default access controls as other account data.
Data we process
- Account and identity: email, name, optional phone, avatar, belt, role, authentication/session records, locale, and preferences.
- Training: journal text, dates, techniques, partners, outcomes, goals, review history, belt history, timer presets, private lessons, coach feedback, and legacy Training Mode cards.
- Health-adjacent and competition: injury notes, weight and weight goals, perceived effort, readiness signals, competitions, matches, and target divisions.
- Travel: saved gyms, locations, planned training dates, and reminder preferences.
- Media: photos or other journal media you choose to upload to the private journal-media storage bucket.
- Video Library: public YouTube, Instagram, or X links you save, plus your title, creator, position, technique, tags, rating, study status, favorite choice, and notes. When you add a public YouTube link, the canonical link is sent to YouTube's oEmbed service to request a title and channel suggestion. Your Library notes, categories, account id, and other private app data are not included in that request. Instagram and X links are not sent to their providers for metadata. If you use the installed app's Android or ChromeOS share action, the app briefly checks the shared URL, text, and title to find one supported public link; it discards the raw text and title, stages only the canonical link in the add form, and never saves without your action.
- Organizations: gym membership, role, invitations, directory/activity sharing choices, consent/revocation timestamps, and organization administration records.
- Billing: Stripe customer/subscription identifiers, plan status, invoices and payment details held by Stripe. We do not store full card numbers.
- Support and security: support messages, email, optional name, IP address, user agent, referrer, rate-limit records, audit events, and server logs.
- AI operations: the selected training context or transcript sent for a requested feature, generated output/cache, provider/model, token counts, latency, cost, and redacted error metadata.
Purposes & legal bases
Where data-protection law requires a legal basis, we rely on:
- Contract: account, journal, goals, billing, export, and the features you request.
- Consent: public member directory publication, future community activity sharing, and marketing communications when available. Voice recording is disabled for this release. You can withdraw consent without affecting earlier processing.
- Legitimate interests: security, abuse prevention, support, service reliability, and aggregate privacy-focused performance measurement, balanced against user rights.
- Legal obligation: tax, accounting, fraud prevention, lawful requests, and records we must retain.
We do not sell your training, injury, weight, travel, or voice data.
Gym, community & coach sharing
- Organizations are private unless a manager explicitly publishes the gym page.
- Every member starts with directory and activity sharing off.
- If both the gym and member publish, the public gym page can show the member’s name, avatar, and belt. The member can revoke directory publication in Settings; pages are rendered dynamically so revocation takes effect on the next request.
- Gym managers can see member identity, email, membership state, and coach feedback to administer the gym. Broader coach training summaries require the member’s directory and activity sharing choices.
- Community feed and leaderboard activity sharing are disabled for this release, even if a stored preference exists.
- Membership data and consent evidence remain private records after publication is revoked; revocation stops disclosure rather than deleting the membership.
AI & disabled voice transcription
AI features run only when you request them. Selected journal text, reflections, goals, training statistics, or competition context may be sent to the configured provider. The launch runtime is configured to select Google Gemini; the OpenAI and Anthropic code paths must be separately configured and certified before they can receive launch requests. Do not include information about another person unless you have permission.
Voice transcription is disabled for this release. Recording controls are not shown, the browser Permissions Policy denies microphone access, and the voice endpoint rejects requests before it reads an upload or contacts a provider, so BJJ Training App does not collect or send voice audio. The voice panel in the public demo uses fixed synthetic text, never opens the microphone, and never saves a journal entry. Re-enabling recording requires a new release review and a point-of-action privacy notice.
If the OpenAI Responses path is configured in a future release, requests set store=false. Provider safety and abuse monitoring can still apply. The app keeps generated response caches for use for up to 24 hours and request metadata for operations; raw prompts and model output are excluded from routine application logs.
Analytics & browser storage
Necessary cookies/local storage keep sessions, theme, locale, and short-lived app handoffs working. Vercel Web Analytics and Speed Insights collect route-level, device, geography, and performance measurements designed not to identify an individual; query strings and fragments are removed before Web Analytics events are sent. You can disable both for the current browser below or in Settings under Your data.
Allow Vercel Web Analytics and Speed Insights on this browser.
Reading this browser’s preference…
Google Analytics and campaign/referrer attribution cookies are disabled for this release. Supplying a Google measurement ID does not activate tracking. Newsletter enrollment and application-managed marketing email are also disabled until double opt-in and unsubscribe controls exist.
Service providers
- Supabase: authentication, Postgres database, Storage, backups, and auth email delivery.
- Vercel: hosting, request/runtime logs, Web Analytics, and Speed Insights.
- Stripe: checkout, subscriptions, invoices, portal, fraud controls, and payment records.
- YouTube (Google): receives a canonical public YouTube link only when an authenticated user requests add-form title and channel suggestions. We do not send Video Library notes, categories, ratings, or account identity to that service.
- Google Gemini: selected by the launch runtime for requested AI generation, subject to candidate model-availability and quality checks. OpenAI and Anthropic integration code is present but neither is configured to receive launch requests; voice transcription is disabled.
- Resend: present in code for application email, but application-managed delivery is disabled for this release.
Class Booking integrations and Web Push are disabled, so those providers receive no launch-release data. Providers may process data in other countries under their contracts and transfer safeguards.
Retention
- Account, training, injury, weight, travel, organization, and media data: kept while the account is active or until a verified deletion request is completed, unless a legal/security exception applies. No inactivity auto-delete is currently applied.
- Deletion safety evidence: after completion, we retain a service-only SHA-256 fingerprint of the account ID to reject stale account recreation and authorize cleanup of late Stripe records. It is excluded from account exports and normal data APIs, but can be linked by someone who already knows the account ID. No fixed purge is currently enforced.
- Directory/activity consent evidence: kept with the membership to prove the current choice; public disclosure stops immediately after revocation.
- Support and audit records: kept while needed to resolve the request, secure the service, and meet legal obligations. No automatic fixed-period purge is currently claimed.
- AI: app response caches are used for 24 hours; operational metadata remains with the account. Google may retain safety-monitoring data for up to 55 days. If OpenAI or Anthropic is configured in a future reviewed release, its standard retention controls apply. Exceptions can apply for suspected abuse or law.
- Vercel: anonymous visitor hashes expire after 24 hours; aggregate reporting/log retention depends on the configured Vercel plan and operational policy.
- Stripe: Stripe and we may retain transaction and billing records for tax, accounting, fraud, dispute, and legal requirements after account closure.
- Backups: deleted data may remain inaccessible in provider backups until the provider’s backup cycle expires.
Your rights & choices
- Correct profile data in Profile and change preferences in Settings.
- Revoke gym directory sharing in Settings and control anonymous analytics here or in Settings.
- Download a versioned JSON account manifest covering every reviewed app data domain. Journal media is represented by stable object paths and an inventory; the JSON does not embed media binaries or expiring signed URLs. Contact support@bjjtraining.app if you also need help retrieving the binary files.
- Request access, correction, restriction, objection, portability, or deletion by contacting support@bjjtraining.app. We may verify identity and normally respond within the period required by applicable law.
- Use self-service account deletion in Profile or contact support@bjjtraining.app. The workflow cancels linked Stripe billing and removes the app's Stripe customer before erasing live app data. Stripe can retain transaction records required for tax, disputes, fraud prevention, or law.
Self-service deletion uses a durable, retryable workflow: it first resolves organization ownership, then cancels billing, removes the account's journal-media prefix, anonymizes retained security evidence, deletes live database domains, and removes Supabase Auth last. If you are the only manager for an organization with other active members, transfer ownership or add another active manager before retrying. Provider legal records and expiring backups may outlive the live-account deletion window described above.
Children & security
The service is not directed to children under 13, and users who are not legally able to consent in their country should use it only with a parent or guardian. We use TLS, access controls, row-level database policies, private Storage, rate limiting, and audit/security monitoring, but no system can guarantee absolute security.
For help, visit the Help Center or email support@bjjtraining.app. We may update this notice when processing changes and will update the date above.