The database refuses, not the screen.
Every table carries a rule about who may read each row, and the database is what enforces it. A query that asks for someone else’s members does not get a filtered list. It gets nothing.
Staff see one school
An instructor or desk staff member reaches one dojo: its members, attendance, waivers and billing. Nothing at any other school. Their role inside that dojo narrows it further.
Sensitive columns are held back
Email addresses, push tokens and notification settings are left out of the broad read permission other members have. Privileged fields cannot be edited by ordinary users at all — the database refuses the change.
Public pages carry a token, not trust
A trial form, an event registration, a waiver signing link, the lobby kiosk and an unsubscribe link all work without a login. Each one is protected by a hashed or signed token and a rate limit. None of them trusts whoever is calling.
Where your dojo’s records live
Production data is pinned to United States infrastructure.
Supabase holds the data
Supabase runs the database, the sign-in system and the file storage behind Konjo, on United States infrastructure. Your records sit with one named company rather than scattered across a dozen. Passwords are stored as hashes by Supabase, and Konjo never stores or logs one.
Vercel serves the web
Vercel hosts the web app, Konjo Studio and this site. It keeps ordinary server access logs. Those are described in the privacy policy, and they are deleted within 30 days.
In transit and at rest
Connections use TLS 1.2 or higher. The database and the file storage are encrypted at rest by the infrastructure providers. Files that should not be public sit in private buckets, and an anonymous request cannot read them.
Card numbers never touch Konjo.
Memberships and billing run on Stripe Connect and launch with your dojo. Members type a card into a form hosted by Stripe. Stripe returns a token, and the token is what Konjo stores.
Each school connects its own Stripe account through Stripe Connect. Stripe pays your dojo, and Konjo is not a party to what a member pays you. Card processing is Stripe’s own rate, paid to Stripe. Konjo adds no markup and takes no cut.
What is stored for a saved card
- The card brand and the last four digits.
- The expiry date.
- Stripe’s own identifiers for the card.
- The consent text a member agreed to, if staff took the card at the desk.
What is never stored
- The full card number.
- The security code.
- Any bank account number.
About the money itself, Konjo keeps the amount, the currency, the status, what it was for, refunds, fees, and Stripe’s reference for the charge or invoice. The facts your books need, and nothing more.
Every company that touches your data
Konjo is one project with a small set of vendors behind it. These are the ones involved in everyday use, and what each of them receives.
Supabase
Database, sign-in, file storage and server functions
Everything the app and Studio store, on US infrastructure.
Vercel
Hosting for the web app, Konjo Studio and this site
Ordinary server request logs.
Stripe
Payments and payouts under Stripe Connect
Card details typed into Stripe’s own form, payer name and email, amounts, and your Connect account details.
Mux
Video transcoding and playback
Video that members upload, the playback files made from it, and playback metadata.
Brevo
Email sent on your dojo’s behalf
Recipient address, subject and message body.
Google Gemini, through Vercel AI Gateway
The language model behind the Studio assistant
The conversation, and the records that staff member was already allowed to read. Prompt training is disabled.
Expo Push and Apple Push Notification service
Delivering push notifications
A device push token and the text of the notification.
Sentry
Crash and error reporting — the mobile app only
The details of a crash, the device it happened on, and a recording of the screens with all text hidden. Not used in Studio or on this site.
A few more appear only when something specific happens.
- Address autocomplete, on the event form.
- An embedded reference video, inside the curriculum.
- Apple or Google sign-in, if that is how you sign in.
- Apple TestFlight, while the iOS app is in beta.
- Printify, if a dojo turns on merchandise.
Each vendor’s own policy is listed in the privacy policy.
Last reviewed Sep 5, 2026. When a vendor is added or removed, this page changes before the change ships.
What the Studio assistant can and cannot do
Konjo Studio includes an optional documentation assistant for authorized staff aged 18 or over. It has its own terms, which staff accept before it will run.
It reads only what that person can read
The assistant is scoped to one dojo, and to the records the signed-in staff member is already permitted to open. It cannot widen its own access.
Nothing is retained for training
Records go to a language model through Vercel AI Gateway, currently Google Gemini. Konjo first asks for a connection that keeps nothing at all. If none is available, it uses one that keeps the conversation only long enough to answer. The product says so on screen when that happens. Neither connection is ever used to train a model. Which provider answered is recorded, so an owner can check it later.
It cannot save anything on its own
A staff member reads the complete proposed change and presses Confirm. Confirmed changes are recorded with the person who made them.
It is locked out of the serious things
Payroll, payments, role changes, deletions, and submitting, closing or setting the severity of an incident are all blocked. Conversations expire after a year.
You decide what each staff member can open.
Roles are the owner’s to set
An owner invites staff and gives each of them a role. The role decides what they see in Studio and what they can change. It can be narrowed or removed at any time.
Actions leave a record
Promotions, waivers, payments, messages and assistant-confirmed changes are stored with who did them and when. An owner can see what happened instead of asking around.
Messages are auditable
Every email sent on your dojo’s behalf is stored as a row: its recipient, its subject and its body. An unsubscribe sticks for good.
This page is not watching you.
No analytics script, no cookie of any kind, and nothing that follows you to another site — check the network tab.
There is no consent banner because there is nothing to consent to. The only thing this site writes down is the form you fill in yourself.
That form is the demo request. It holds your name, your dojo’s name, your email, roughly how many students you have, what you use today, and which page you came from. No anonymous or signed-in caller can read that table. Only we can, and only from the server. You can ask for your row to be deleted at any time.
Getting it out, and getting rid of it
Export while you are a customer
CSV exports of your people, family links, memberships, attendance, rank and progress, invoices and payments, plus instructions for downloading media. Free, at any time, and for 30 days after your service ends.
A member can delete their account
Settings, Account, Delete Account. The login and what hangs off it are removed and cannot be recovered. Your dojo’s own member record belongs to the school: attendance, a signed waiver, a promotion. That stays until the school removes it.
When a dojo leaves
After the export window closes, the school’s data is deleted, or stripped of anything that names a person. The exceptions are the legal, tax and backup-cycle rules set out in the privacy policy.
If something goes wrong
A roster, a stack of waivers and a year of payment records are only worth what stands behind them. Konjo is one project with one person on call. This is the shape of that, including the parts that do not exist yet.
Backups are Supabase’s
Supabase backs up the database on its standard schedule for the plan Konjo runs. Each backup rolls off that provider’s window, typically 7 to 30 days. Konjo keeps no second copy of your dojo’s database anywhere else.
A restore is Supabase’s restore, not ours
If the database ever has to be recovered, it comes back from the provider’s most recent backup, and anything entered after that point is gone. The copy you control is the CSV export. Take it whenever you like, and keep it where you keep your other records.
There is no uptime guarantee
Konjo publishes no uptime commitment and runs no status page today. If the product is down or slow, the dojos affected get an email from the person fixing it. Write to galen@getkonjo.com if you see it before we do.
If Konjo stops
If Konjo is ever discontinued, paying dojos get at least 90 days’ notice. Exports keep working through that whole window, and the unused part of any period already paid is refunded. That is written into the terms, so it is a commitment rather than a reassurance on a marketing page.
What Konjo does not claim
Konjo has no SOC 2 report, no ISO 27001 certificate and no HIPAA compliance program. It is an individually operated project, running on each vendor’s standard customer terms. Formal data processing agreements get signed when there is a company to sign them. If a certification is a requirement for your school, say so early. You will get a straight answer rather than a maybe.
If unauthorized access to personal information is ever discovered, the people affected are emailed. Dojos are told without undue delay, so they can meet their own obligations. The deadlines are in the privacy policy.
Ask the hard questions on the call.
Bring the ones this page did not answer: where a record lives, who at your school can read it, and what leaves with you the day you go. The call is with the person who wrote both the policy and the code underneath it.
If you are reporting one: send what you found and how to reproduce it. Please do not access, change or keep anyone else’s data while testing, and give us a reasonable window to fix an issue before publishing it. A person reads it, and you will hear what happened to it.
The same ground in legal language is in the privacy policy and the terms of service.