Legal

Privacy Policy

Effective Sep 5, 2026. What Konjo collects, why it is kept, and how to get it deleted — written against the real product, not from a template.

Effective date: Sep 5, 2026
Last updated: Sep 5, 2026
Operator: Konjo, an unincorporated project operated by Galen Jauss (no incorporated company yet)
Contact: galen@getkonjo.com

This policy explains what Konjo (formerly “Mojo Martial Arts”; “Konjo,” “we,” “us”) collects, why, where it lives, who can see it, and how to delete it. Konjo is a multi-style martial arts platform.

Konjo has two parts, and this one policy covers both:

  • The Konjo app — the iOS, Android, and web app students and instructors use to log training, learn curriculum, ask for coaching, follow events, and talk to their community.
  • Konjo Studio — the web dashboard at studio.getkonjo.com that dojo owners and their staff use to run the school: members, families, schedule, attendance, testing, waivers, messages, money, and reports.

It also covers our marketing website at getkonjo.com.

We wrote this policy ourselves rather than using a template generator so that every claim below maps to a real database column or code path. The names in code font are the real tables and storage buckets in our database, accurate as of the effective date. They are there so a technical reviewer can check us against the product; you can skip them and the policy still reads straight through. Once Konjo incorporates, this policy will be updated to name the new entity.

The short version: We collect what we need to run Konjo and nothing for advertising. Your dojo controls its own member records. Card numbers go to Stripe and never reach us. You can delete your account from inside the app. Section 1 has the full summary.

Table of Contents

1. Summary

In plain English:

  • We collect what we need to run Konjo: account details, the training content you create, a date of birth to check your age, and a push token if you turn on notifications.
  • If you train at a dojo that uses Konjo Studio, your dojo also keeps a member record about you — contact details, attendance, rank, waivers, notes, and money owed or paid. Your dojo decides what goes in that record and who at the school can see it. We store and protect it on their behalf.
  • Photos live in Supabase storage. Videos go to Mux. Card numbers go to Stripe and never reach us.
  • We do not run ads. We do not use marketing analytics or tracking SDKs. We do use Sentry on production builds of the mobile app to capture crashes and a sampled, masked session replay, so we can fix bugs. See Section 16.
  • Konjo Studio includes an optional AI assistant for adult staff. It runs through Vercel AI Gateway with prompt training turned off. See Section 10.
  • You can delete your Konjo account from inside the app at any time. Records your dojo keeps about your membership belong to the dojo, so ask them to delete those, or ask us and we will pass the request on.
  • Our production data lives on US infrastructure.
  • The minimum age for a Konjo login is 13. Children under 13 can be tracked by their dojo as guardian-managed profiles that cannot sign in. See Section 5.
  • Our marketing website sets no cookies and loads no analytics.

2. Who this policy covers, and who is in charge of your data

This policy covers anyone who creates a Konjo account, appears in a dojo’s records inside Konjo Studio, receives an email or text sent through Konjo, fills in a form on a dojo’s public page, or contacts us at the address above.

Privacy law splits responsibility into two roles. Konjo sits in both, depending on the record.

Your dojo is in charge of its member records. When a dojo signs up for Konjo Studio, it decides what to record about its members, which staff can see what, how long to keep it, and what to do with it. In GDPR terms the dojo is the controller and Konjo is a processor acting on its instructions. In US state-law terms the dojo is the business and Konjo is a service provider. This covers everything in Section 4: member profiles, family links, attendance, rank and testing, waivers, notes, incident reports, messages, and payment records.

Konjo is in charge of Konjo accounts and its own business data. Your login, the training content you create for yourself, your app settings, crash diagnostics, and anything you send us directly (a support email, a demo request on our website) are ours to answer for. So is the account we hold for a dojo that subscribes to Studio.

Practically, that means:

  • To correct or delete something in your member record, ask your dojo first. They can change it themselves in Studio. If they will not or cannot, email us and we will help.
  • To delete your Konjo account, use Settings → Account → Delete Account in the app. That removes your login and the content you created. It does not erase the business records your dojo is required to keep, such as an attendance history or a paid invoice.

This policy does not cover a dojo’s own practices outside Konjo — its paper files, its website, its own mailing list, or its in-person programs. Each dojo handles those on its own.

3. What the Konjo app collects

3.1 Account data (public.users)

  • Email address — used to sign you in and send transactional messages. Not used for marketing by us.
  • Name — stored as a display name plus separate given and family name fields, so rosters and certificates can sort correctly.
  • Avatar image and bio (optional).
  • Date of birth — collected at signup to enforce the 13+ age floor and, for members of a dojo, to route age-appropriate classes and content. Not visible to other members.
  • Belt rank and per-style ranks — your verified rank. Drives curriculum visibility and coaching eligibility. Verified rank can only be set by an instructor at your dojo or by rank history recorded in Studio.
  • Claimed rank, role, and dojo, and verification status — what you submit when you ask a dojo to verify you, and where that request stands.
  • Dojo membership.
  • Age group — adult or kids, used to route content and set safe audience defaults.
  • Training goal, profile stat visibility, and follower counts.
  • Training visibility (training_visibility) — who can see your logged sessions. Settings gives you two choices: only you, shown as “Private” and stored as private, which is the default; and instructors at your dojo, shown as “Same-dojo instructors” and stored as instructors_same_dojo. The column also accepts public, which makes a session visible to any signed-in user.
  • Notification preferences and push token (push_token) — see Section 15.
  • Terms acceptance — which version of these documents you accepted, and when.
  • Managed-account flags — see Section 5.
  • Moderation fields if we ever have to suspend an account.

Not every field is visible to other people. Other signed-in users can read only a fixed list of columns from your row. Your email address, date of birth, push token, notification preferences, and terms-acceptance record are excluded from that list at the database level, not just hidden in the interface.

You can edit your name, bio, avatar, age group, training goal, training visibility, and notification preferences at any time from your profile or Settings.

3.2 What you create in the app

These are yours. They are stored against your user ID and removed when you delete your account.

  • Posts, media, likes, comments, and mentions — captions, images or video, group scope, reactions, replies, and @-tags.
  • Training sessions — what you log on the Train tab: name, duration, activity tags, hashtags, an optional note, an optional link to a class, and any photos or video you attach.
  • Reflections — short journal entries on a session.
  • Coaching — the video or post you submit, the audience and rank limits you set on the request, and the structured feedback (strength, focus area, next step) you give or receive.
  • Curriculum progress and flashcard state — your checklist for the next rank and your spaced-repetition review data.
  • Attendance you record yourself — a class you check into, and attendance created from a session you logged.
  • Class bookings and waitlist entries.
  • Follows, notifications, groups, and achievements.
  • Verification requests you send to a dojo.
  • Reports you file about content — the reason and any notes you write.
  • Announcements you post, if you are an instructor.
  • A calendar subscription token (user_calendar_tokens) if you subscribe to your class schedule in a calendar app. Anyone holding that URL can read your subscribed schedule, so treat it as a secret. You can rotate it.

3.3 Photos and video

  • Photos go to Supabase Storage in the post-media bucket, under a path scoped to your user ID. Three smaller versions are generated on your device before upload. These image URLs are public so the app can display them, but they are unguessable.
  • Videos go straight to Mux for transcoding and streaming. We never serve raw video files ourselves. Each video stores a Mux asset ID and playback ID. During upload the file is briefly cached on your own device and then cleared.
  • Documents your dojo uploads about you go to a private member-docs bucket, and signed waivers to a private waivers bucket. Those are not public.

3.4 Identifiers

Your Supabase user ID (a UUID) is your stable identifier. Push tokens are covered in Section 15. We do not use the iOS advertising identifier, the Android Advertising ID, or any other cross-app advertising identifier.

3.5 How you sign in

You can sign in with an email address and password, with a six-digit code sent to your email, with Sign in with Google, or with Sign in with Apple. Passwords are handled by Supabase Auth and stored as hashes; we never store or log a plaintext password. When you use Google or Apple, that provider tells us your email address and, if you allow it, your name — nothing else. Apple’s private relay addresses work normally.

If you sign in with Google or Apple, we then ask you for a date of birth and for agreement to these documents before the app opens, because the provider does not give us your age.

3.6 What we do not collect

We do not collect your precise location, your contacts, your calendars, or an index of your photo library — we only see the photos you pick during a post or session. We do not embed advertising or marketing analytics SDKs. We do not collect biometric identifiers. We do not receive your full card number (see Section 6). We do embed a diagnostics SDK, Sentry, on production builds of the mobile app; Section 16 is the full disclosure.

Konjo has journaling, reflection, coaching, and incident features in which someone may describe an injury or a physical limit (“tweaked my knee sparring”). We do not require this content, do not analyze it to infer anything about your health, and do not share it outside the audience you choose or the staff your dojo authorizes. Some state laws, including the Washington My Health My Data Act, treat self-reported health text as sensitive consumer health data. You can delete any session, reflection, post, or coaching row from inside the app, and all of it at once through Settings → Account → Delete Account. Health notes your dojo records about you (Section 4.5) are the dojo’s record; ask them to change or remove those.

3.8 Other stored fields

For completeness we also store:

  • where an attendance record came from;
  • who canceled a class and when and why;
  • upload-error rows with limited device metadata (platform, OS version, app version — never serial numbers, advertising IDs, or precise location);
  • a service-only Mux webhook log that no client can read; and
  • Supabase Auth’s own fields (account creation time, email confirmation time, last sign-in time, last sign-in IP).

4. What your dojo records in Konjo Studio

Everything in this section is your dojo’s record about you. Your dojo controls it; we hold it for them. Row-level security scopes every table below to one dojo, so no other school can read it.

4.1 Member and family records

  • Member profile (member_profiles) — mailing address, phone number, and archive status. Your account row holds no phone number; phone lives here.
  • Emergency contacts — name, phone, relationship, priority, and whether that person may pick a student up.
  • Family records — a household with a shared email and phone, an address, emergency notes, internal notes, tags, and links between guardians and dependants.
  • Documents — files a staff member uploads about you (file name, type, size, and a private storage path).
  • Notes and tags — staff notes about a student, who wrote them, and when. These are internal to your dojo.

4.2 Attendance and class records

Attendance, class bookings and waitlists, class delivery records, technique assessments and notes, class plans, breakouts, homework, and structured student feedback bundles. These record who attended, what was taught, what a student practised, and what an instructor observed.

4.3 Rank, testing, and promotions

Rank history (belt_rank_history — old rank, new rank, who changed it, when, and why), rank requirements and expectations, test events and candidates, curriculum mastery records, and promotion certificates generated from a finalized test.

4.4 Incidents and safety

If your dojo uses the incident feature: incident reports with a narrative, category, severity, location, first-aid details, immediate actions, whether and how a guardian was notified, people involved, evidence, follow-up tasks, and reviews. Related student safety flags hold instructions staff should follow, with a review date and a visibility setting. These records can describe injuries and are treated as sensitive.

4.5 Staff, hours, and pay

Staff memberships, roles and capabilities, invitations, availability and substitution requests, clock-in and clock-out punches, and — if your dojo runs payroll in Konjo — worker records, pay rates, payroll runs, run lines, disputes, and an export handoff to a payroll provider. We do not store Social Security numbers, tax identification numbers, or bank account details. Konjo records hours, rates, and amounts; the payroll provider handles the rest.

4.6 Money records

Billing accounts, memberships, invoices, payments, refunds, point-of-sale sales, class packs, private lesson bookings, family orders, credits, and payment authorizations. Section 6 covers card data specifically.

4.7 Leads and prospects

People who fill in a dojo’s public trial form become leads: name, email, phone, an age bracket, an interest note, referral and campaign fields, staff notes, and a hashed IP address kept only for rate limiting. A lead who joins is linked to the member account they become.

4.8 Audit history

Konjo keeps audit trails so a dojo can see who did what: an entity audit log, a family audit log, a staff-role audit, and — for Konjo app administration — an admin audit log. These record the actor, the action, the affected record, and a timestamp.

4.9 Outbound integrations a dojo turns on

A dojo owner can register webhook endpoints and API keys. When they do, Konjo sends signed event payloads about members, payments, attendance, and leads to a URL the owner chose. Once data leaves for that URL it is governed by whoever runs that system, not by this policy. Ask your dojo what they have connected.

4.10 Getting a school set up

If a dojo asks us to move it onto Konjo, it sends us its existing member export. We keep the raw upload in a private bucket that only Konjo administrators can read, publish a sanitized version for the owner to review section by section, and the owner approves the exact configuration before anything goes live. Snapshots reject anything that looks like a secret, a bank detail, or a payment-processor identifier before it is saved.

5. Family accounts, guardians, and children

No one under 13 can have a Konjo login. The signup form asks for a date of birth and refuses ages below 13, and the same floor is enforced on the server. This is deliberate: it keeps Konjo out of COPPA’s verifiable-parental-consent regime for accounts.

Younger students are still part of a dojo, so Konjo represents them as guardian-managed child profiles:

  • A guardian (or dojo staff) creates the child profile. It is a real record so that attendance, membership, rosters, and rank all work — but it is created with a synthetic, unroutable email address and no password. Nobody can sign in as the child. The app and Studio also refuse a managed session outright.
  • The child’s record is flagged as managed and points at both the guardian who manages it and the dojo.
  • What is stored about a child is the same as for any member and no more: name, date of birth, rank and rank history, attendance and bookings, membership and payment records tied to the household, emergency contacts, waivers signed on their behalf, instructor notes, and any incident or safety record that involves them.
  • Children have no feed, no posts, no coaching requests, and no push token, because they cannot sign in.

Who can see a child’s record: the guardians linked to them, and authorized staff at their dojo. The family record carries a permission for each guardian — manage the profile, manage bookings, manage communications, sign waivers, view billing, view training — so one parent can be given billing access and another not. A guardian can be revoked.

What a guardian can do: review everything in the child’s profile from the app or by asking the dojo, correct it, ask the dojo to delete it, sign or decline waivers, and control communications about the child. Email us at galen@getkonjo.com if a dojo does not respond and we will act on the request ourselves.

When a child turns 13: a guardian can hand the account over. Konjo checks the recorded date of birth, swaps in the teenager’s real email address, clears the managed flag, and emails them a link to set their own password. From then on it is their account, under Section 3.

If a child under 13 creates a login anyway: we delete it. Anyone who reports an age below the floor during the compliance step is deleted immediately by a server function that removes their auth record. If you believe a child under 13 has an account, email galen@getkonjo.com with the account email; we will respond within 7 days and delete within 30.

Children in other people’s posts: dojos run kids’ classes, so a post or training video may show a child. Whoever posts is responsible for having the parent’s or guardian’s consent first. If you are a parent or guardian and want content showing your child removed, email galen@getkonjo.com with a description; we will remove it within 7 days and will not ask you to prove the relationship.

6. Payments

Card numbers never touch Konjo. Every card is entered directly into a form hosted by Stripe — Stripe Elements on the web, Stripe’s payment sheet in the mobile app — which sends the number to Stripe and returns a token to us.

Each dojo connects its own Stripe account through Stripe Connect. Card payments start working for a dojo when its Stripe account is connected during launch. The dojo is the merchant of record for what its members pay it. Stripe’s own terms and privacy policy apply to that relationship, and Konjo is not a party to the transaction between you and your dojo.

What Konjo does store for a saved card:

  • the brand;
  • the last four digits;
  • the expiry month and year;
  • Stripe’s identifiers for the customer and payment method;
  • a card fingerprint Stripe returns;
  • the address- and code-verification results Stripe returns; and
  • when a staff member takes a card at the desk with your permission, the consent text you agreed to, its version, the timestamp, and a hashed IP address and user agent.

We store no full card number, no CVC, and no bank account number.

Konjo also records the money facts a dojo needs to run its books: amounts, currency, status, what the payment was for, refunds, fees, and Stripe’s identifiers for the charge, invoice, or transfer.

If your dojo sells merchandise through the print-on-demand shop, an order carries a shipping name, address, email, and phone. That shop is not switched on in production today; when a dojo enables it, those shipping details go to Printify so the item can be printed and posted.

7. Email and text messages from your dojo

Konjo sends email and text messages on behalf of your dojo, through Brevo. Every message is queued as a row that records the channel, recipient, subject, body, status, and whether it was transactional or not, so an owner can see exactly what was sent.

  • Transactional messages — a receipt, a class reminder, a waiver link, a password email — are sent because you have a relationship with the dojo.
  • Everything else respects your preferences: marketing email, automated messages, and text messages are three separate settings. Text messages are opt-in, not opt-out.
  • Every non-transactional email carries an unsubscribe link and one-click unsubscribe headers. The link is a signed token; opening it records a suppression against your address and, if we can match you to an account, turns off both marketing and automation messages.
  • Replying STOP to a text records a suppression against your phone number and turns off your SMS opt-in. Suppressions always win over any later send.
  • When a message concerns a child, it is addressed to the household contact, and it is the parent’s consent record that is checked.

Konjo itself does not send you marketing email. If we ever do, it will be opt-in and will carry the same unsubscribe.

8. Waivers and electronic signatures

A dojo can publish a waiver in Studio and email a signing link. The signing page runs without a login; the emailed token is the credential, and only its hash is stored.

When you sign, Konjo records: your typed name, your email address, who you signed for (yourself or a child), the template and its exact version, a hash of the document text you saw, the timestamp, your IP address, and your browser user agent. Your drawn signature is saved as an image and a signed PDF is generated. Both live in a private storage bucket that no anonymous request can read.

The IP address, user agent, document hash, and version exist so that the signature can be shown to be genuine later. That is the point of an electronic signature record, and it is why we keep more here than elsewhere. The record belongs to your dojo.

9. Public pages, trial bookings, and event registration

Some Konjo pages are open to people with no account.

  • A dojo’s public page — a web address ending in /d/ and the dojo’s short name — shows what the owner chose to publish: the school’s name, description, address, phone, email, photo, and schedule. Turning the page on is the owner’s decision.
  • The trial form on that page collects a name, an email address, an optional phone number, an age bracket, and an interest note, and creates a lead for the dojo (Section 4.7). We keep a hashed IP address to stop abuse, plus referral and campaign fields if the link carried them. A hidden field catches bots.
  • Public event registration — an address ending in /e/ and the event’s short name — collects a name, email, and optional phone for a free event, and creates a registration row. Paid events go through Stripe Checkout instead. The same hashed-IP rate limiting applies.
  • The family wallet and payment links open from a token in a link rather than a login, so a parent can pay without an account.
  • The check-in kiosk runs on a dojo’s own tablet with a device token in the URL. It can list today’s classes, search students at that dojo by name, and record a check-in or a staff punch. It never issues a login, and it is scoped to one dojo.

10. Konjo Assistant (AI for staff)

Konjo Studio includes an optional documentation assistant for authorized dojo staff aged 18 or over. It has its own supplemental terms, which staff must accept before it will run, published at studio.getkonjo.com/legal/ai-terms.

What you should know as a member:

  • The Assistant can read only records the signed-in staff member is already permitted to read. It is scoped to one dojo.
  • Konjo sends those records to a large language model through Vercel AI Gateway, currently Google’s Gemini. Konjo requests a zero-data-retention route first; if none is available it falls back to a standard paid route with prompt training disabled, and the product shows a notice when that happens. Provider and routing metadata are recorded so an owner can audit it.
  • It cannot save anything on its own. A staff member must review the complete proposed change and press Confirm. Confirmed changes are audited with their author.
  • It is blocked from payroll, payments, role changes, deletions, and from submitting, closing, or setting severity on an incident. It may summarize a recorded injury or accommodation instruction, but it does not diagnose or give medical advice.
  • Conversations expire after one year. Records of confirmed actions are kept with the documentation they created.

11. The Konjo website

getkonjo.com is a static marketing site. It sets no cookies, loads no analytics, and embeds no third-party scripts or trackers. There is nothing to opt out of.

One form on it writes to our database:

  • Demo request (demo_requests) — your name, your dojo’s name, your email address, a rough student-count band, what software you use today (optional), a country code, and which page you came from. It emails us and sends you an acknowledgement. The table has no read access for anonymous or signed-in callers; only we can read it, with the service role. We rate-limit by email address.

An earlier version of this site had an email signup form (landing_signups). It collected an address and which part of the page it came from, nothing else. Those rows are still held until you ask us to delete them.

We use this to reply to you and to plan the product. We do not sell it, share it, or add you to an advertising audience. Email us to have any of it deleted.

Our web hosting provider (Vercel) keeps ordinary server access logs, described in Section 17.4.

12. How we use your information

We use what we collect to operate Konjo:

  • to run your account;
  • to show the right content for your rank and dojo;
  • to render social features to the audience you choose;
  • to deliver notifications you asked for;
  • to give instructors the tools they need on the floor;
  • to let a dojo run its school in Studio;
  • to send messages on a dojo’s behalf;
  • to take payments a dojo is owed; and
  • to find and fix bugs.

We do not use your information for advertising, for profiling on behalf of anyone else, or for any purpose unrelated to running Konjo.

If you are in the EU or UK, GDPR / UK GDPR requires us to name a lawful basis for each activity. Where Konjo is the controller we rely on:

  • Performance of a contract (Art. 6(1)(b)) — creating and running your account, storing what you create, and providing the features you use.
  • Legitimate interests (Art. 6(1)(f)) — diagnosing failures, preventing abuse, rate-limiting public forms, and running the service safely. You can object at any time by emailing us.
  • Consent (Art. 6(1)(a)) — push notifications, marketing messages, and text messages. You can withdraw consent at any time.
  • Legal obligations (Art. 6(1)(c)) — responding to lawful requests from regulators or courts.

Where Konjo is a processor for a dojo, the dojo is responsible for identifying its own lawful basis for its member records, and we process only on its instructions.

12.2 Automated decisions

We do not subject you to automated decisions that produce legal or similarly significant effects. Some features apply rules that people configured — a coaching request’s rank gate, a class’s age range, an automation that emails a member after a missed class. Those are rules a person set, not decisions we make about you.

13. How content is shared inside the app

What other people see depends on the surface. Defaults are conservative, and every rule below is enforced by row-level security in the database, not only in the interface.

  • Profile — display name, avatar, bio, rank, dojo, and follower counts are visible to signed-in users.
  • Posts — posts in the All feed are visible to signed-in users. Posts scoped to a group are visible only to that group’s members, and so are their comment and like counts.
  • Training sessions — controlled by your training visibility setting, which defaults to private.
  • Coaching feedback — visible only to the requester and the audience set on that request.
  • Attendance — visible to you and to staff at the dojo where the class was held.
  • Verification requests — visible to you and to head instructors and admin staff at the dojo you claimed.
  • Mentions — an @-mention notifies that person; the post or comment itself still follows its own visibility rules.
  • Dojo announcements — visible to verified members of that dojo.
  • Member records in Studio — visible to authorized staff at that dojo only, scoped by their role.

13.1 Feedback about you

If you receive coaching feedback that is unwanted or mischaracterizes you, email galen@getkonjo.com and we will remove the row. The person who wrote it can also delete it.

14. Where your data is stored (subprocessors)

Production data is pinned to US infrastructure.

Our subprocessors run on their own providers — Supabase on AWS, Mux on AWS and Cloudflare, and so on. Each of their privacy policies describes those further relationships.

We are an individually operated project today and rely on each vendor’s standard customer terms. When Konjo incorporates or takes on customers who require it, we will execute formal data processing agreements and update this section.

15. Push notifications

If you allow push notifications, we get an Expo push token from your device and store it on your user row. We use it to tell you when someone likes, comments on, mentions or follows you, when coaching feedback arrives, when your dojo posts an announcement, when a class or event changes, and when a verification step involves you. Each type can be turned off individually in Settings; turning all of them off keeps the token on file but stops delivery. Revoking permission in your device settings invalidates the token at the operating-system level.

Push tokens sit in our Supabase database and can be read by operator-side service processes for the sole purpose of delivering notifications you opted into. Other members cannot read them — the column is excluded from the shared read grant.

16. Diagnostics and telemetry

When a media upload fails, the app writes a structured row with the stage that failed, an error code and message, the retry attempt, and limited device information (platform, OS version, app version). Row-level security scopes those rows to you. They contain no media bytes, captions, or message content.

Konjo Studio loads Vercel Speed Insights when it runs on Vercel. It reports anonymous page-performance timings so we can find slow screens. It is not linked to your account and is not used for marketing.

16.1 Sentry (mobile app only)

We use Sentry on production builds of the mobile app to capture crashes and errors, record a sampled session replay, accept feedback you choose to submit, and capture diagnostic logs. Sentry is disabled in development builds and is not used in Konjo Studio or on the marketing site.

What Sentry receives:

  • Crash and error events — JavaScript and native stack traces, the error message, and source context, captured automatically on an unhandled error.
  • Breadcrumbs — a short trail of what happened first: screen changes, network request URLs without bodies, and interface interactions such as a tap on a named button. Breadcrumbs do not include the contents of posts, coaching feedback, reflections, or media.
  • Device and network context — platform, OS version, app version, build number, locale, device model class, IP address, and HTTP request headers. Authorization, cookie, and API-key headers are stripped on the device before anything is sent. We do not send serial numbers, advertising identifiers, or precise location.
  • Session replay — 10% of ordinary sessions and 100% of sessions with an error are recorded. The replay captures layout and your sequence of taps and scrolls. Text, images, icons, and web views are masked by default and appear as solid blocks, so the replay does not show the literal contents of your posts, captions, comments, coaching feedback, reflections, or media. It does show which screens you visited and in what order.
  • Feedback you submit — if you use the in-app feedback widget, the message you type, an email address if you provide one, and a screenshot if you attach one. Nothing is captured unless you submit it.
  • Logs — diagnostic log lines so context follows a crash. We do not log post contents, message bodies, coaching feedback, reflections, passwords, or push tokens.
  • Your user ID — attached to every event so we can correlate a report with the affected account. We do not send your email, name, avatar, push token, dojo, rank, or date of birth.

Sentry processes these events on its US infrastructure. Only the operator has access to them. Sentry applies its own retention schedule, typically 30 to 90 days for errors and replays on its standard plans.

You can email galen@getkonjo.com to have Sentry events tied to your user ID deleted; we will run the deletion within 30 days. You can also ask us to add your user ID to a server-side deny list so future events are dropped before they are sent. Deleting your Konjo account makes existing Sentry events unjoinable to any active account, and they then age out.

If we change sample rates, add integrations, collect more personal information, or change vendor, we will update this section and our App Store privacy disclosure before shipping the change.

17. Retention and deletion

17.1 While your account is active

What you create stays until you delete it or delete your account. A post you delete is removed within seconds, and its notifications and counts go with it.

17.2 Deleting your Konjo account

Settings → Account → Delete Account. You type your account email to confirm. The app calls a server function that deletes your row in auth.users. Cascading foreign keys then remove your public.users row and the records that hang off it:

  • posts and their media;
  • likes;
  • comments;
  • mentions;
  • training sessions and session media;
  • attendance;
  • coaching sessions;
  • requests and feedback you wrote;
  • follows in both directions;
  • notifications;
  • verification and promotion requests;
  • group memberships;
  • review state;
  • curriculum progress;
  • instructor memberships;
  • calendar tokens; and
  • announcements you authored.

Rows that reference you only as an actor — who canceled a class, who resolved a request — keep the row and drop your name. You cannot recover the account afterwards.

If you report an age under 13 at the compliance step, your account is deleted straight away by a server function rather than being kept in any form.

17.3 Records your dojo keeps

Deleting your Konjo login does not delete your dojo’s member record. A school has its own reasons and obligations to keep an attendance history, a signed waiver, a promotion record, an incident report, or a paid invoice. To have those changed or removed, ask your dojo; they can do it in Studio. If they will not, email us and we will act on the request.

When a dojo leaves Konjo, we provide CSV exports of its people, family links, memberships, attendance, rank and progress, invoices, and payment records during the paid period and for 30 days afterwards, along with instructions for downloading media. After that window we delete or de-identify the dojo’s data, except where a legal, tax, fraud-prevention, backup-cycle, or security requirement described here applies.

17.4 Retention by record type

Some objects can be orphaned if a deletion job retries past its window. An orphaned file is referenced by no database row, so it cannot appear anywhere in the product, has an unguessable URL, is not indexed, and is removed on a cleanup pass. Email us if you want a manual sweep.

18. Your rights

Wherever you live, you may have rights to access, correct, delete, or port your personal information and to object to or restrict some processing. We honor these for everyone, not only where the law requires it.

For records your dojo controls, send the request to your dojo first — they can act immediately in Studio. Tell us if they do not respond and we will help.

18.1 Categories of personal information (California)

Under the CCPA / CPRA we collect the following statutory categories. We do not sell or share any of them for cross-context behavioral advertising.

18.2 Right to Know / Access

Email us and we will provide an export of your personal information within 45 days.

18.3 Right to Delete

Use Settings → Account → Delete Account, or email us to delete a specific item. For a dojo’s member record, see Section 17.3.

18.4 Right to Correct

Most fields are editable in the app or by your dojo in Studio; email us for the rest.

18.5 Right to Opt Out of Sale or Sharing

We do not sell or share. See Section 21.

18.6 Right to Limit Use of Sensitive Personal Information

We use sensitive personal information only for the purposes in Section 12 and never to infer characteristics about you.

18.7 Right to Non-Discrimination

We will not deny service, charge differently, or give you a worse experience because you exercised a right.

18.8 Other states

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Tennessee, Indiana, Delaware, New Jersey, New Hampshire, Minnesota, Maryland, Rhode Island, and other states with comprehensive privacy laws have similar rights. The same email address and the same in-app deletion flow apply, and we respond within the timeline your state’s law requires, usually 30 to 45 days. Some state laws set the sensitive-data threshold at 16 rather than 13; where that applies, we use the stricter one.

19. Children

Konjo is not directed to children under 13, and no one under 13 can create a login. Section 5 explains how younger students are represented instead, what a guardian can do, and what happens if a child signs up anyway.

If we learn that we hold personal information from a child under 13 in a way COPPA does not allow, we will delete it within 30 days. Parents and guardians can email galen@getkonjo.com; we respond within 7 days.

20. Security and breach notification

Connections use TLS 1.2 or higher. Database and file storage are encrypted at rest by our infrastructure providers. Row-level security is enabled on every user-facing table, and policy review is part of every migration. Server functions that touch sensitive columns run with a pinned search path and explicit grants, and are not exposed to anonymous callers. Privileged columns cannot be changed by ordinary users; database triggers refuse the update. Public endpoints — the trial form, event registration, waiver signing, the kiosk, unsubscribe — are protected by hashed or signed tokens and rate limits rather than by trusting the caller. Passwords are stored as hashes by Supabase Auth; we never store or log a plaintext password.

No system is perfect. If you think your account is compromised, change your password and email galen@getkonjo.com.

20.1 If there is a breach

If we discover unauthorized access to or disclosure of personal information, we will notify affected people by email and, where the law requires, the relevant regulator: within 72 hours of becoming aware for EU/UK users under GDPR, and within the applicable state-law window (typically 30 to 60 days) for US users. Where the affected records belong to a dojo, we will notify the dojo without undue delay so it can meet its own obligations.

21. No advertising, tracking, or sale of data

To be unambiguous: we do not run ads; we do not embed advertising or marketing analytics SDKs; we do not share your data with data brokers; we do not sell your data; we do not use your data to target you anywhere else; and “tracking” as Apple’s App Tracking Transparency defines it does not occur. We do embed a diagnostics SDK in the mobile app (Sentry, Section 16.1) and a page-performance measurement in Studio (Section 16), and neither is used for marketing.

If we ever introduce advertising, marketing analytics, or a third-party tracking SDK, we will get in-app consent from existing users before any data flows to the new vendor, honor Global Privacy Control signals, and update our App Store disclosure first.

21.1 Do Not Sell or Share My Personal Information

We do not sell or share your personal information for cross-context behavioral advertising as the CCPA / CPRA define those terms. We honor Global Privacy Control signals in browsers that send them.

22. International users and data residency

Production data is stored on US infrastructure and delivered globally through our providers’ networks. If you use Konjo from outside the United States, your data is processed in the United States.

22.1 EU / UK representative

Konjo does not currently appoint an EU / UK representative under GDPR Article 27 or UK GDPR Article 27, because our processing of EU / UK personal data is occasional and does not involve large-scale processing of special-category data. We will appoint one if that changes.

22.2 International transfers

When EU / UK personal data is transferred to the United States, we rely on Standard Contractual Clauses approved by the European Commission and the corresponding UK International Data Transfer Addendum. Our subprocessors provide these in their data-processing addenda.

23. Changes to this policy

We may update this policy as Konjo evolves. A material change means a new category of data, a new subprocessor, a new use, or a change to how long we keep something. When one happens we will:

  • update the effective and last-updated dates;
  • show a notice the next time you open the app;
  • send a push notification if you have them turned on; and
  • email the address on your account.

Dojo owners are notified by email as well, because a change may affect what they must tell their own members. Smaller edits may be made without notice; the version at this URL is always the current one. Past versions are available on request.

24. Contact

For privacy questions, data requests, or anything else in this policy:

Email: galen@getkonjo.com
Operator: Konjo, an unincorporated project operated by Galen Jauss

We usually reply within a few business days. If you need this policy in another format, such as large print or something screen-reader friendly, email us and we will provide it.