This Privacy Policy explains what data Judo Academy collects, how it is used and how it is protected. Judo Academy is designed to be used by learners of all ages, including children, and this policy has been written to comply with the Google Play Families Policy, COPPA (US) and the GDPR, including its provisions on children's data (GDPR-K). Our principle is simple: we collect only what is necessary for the application to function.
The following data is stored on your device. Items marked with an asterisk (*) are also securely synced to our servers if you sign in with a Google account, so your progress stays available across devices:
Clearing application data or uninstalling the application permanently deletes all local data. Synced data can be deleted at any time as described in Section 2.2.
The following data is transmitted to our servers only if you sign in with a Google account:
Without Google sign-in, no data is transmitted to the server. The application is fully functional without signing in.
Server data is stored on servers located in the European Union. Data is not transferred outside the EU, except where described in Section 3.3 (third-party services) for the specific, limited purposes listed there.
Data is retained for as long as you use the application. You, or — for a child's account — a parent or guardian, may request deletion of all data, or of a specific part of it (for example only the AI Sensei conversation history), without needing to delete the whole account, at any time:
Requests are processed within 30 days. Data stored only locally on your device (see Section 1) is not affected by a server-side deletion request and is removed by uninstalling the application or clearing its data.
The application uses a cloud AI service for: AI Sensei (personalised judo advisor), Scouting (opponent analysis) and Judo Journal (training analysis). The AI provider is Anthropic (Claude models).
Anthropic processes this data as our data processor, in accordance with its own privacy policy, solely to generate a response to your request. Data sent to the AI service is not permanently stored on our servers beyond what is described in Section 1. If our AI provider changes, this policy and the in-app settings will be updated accordingly.
Besides our AI provider, we use a small number of other services to operate the application. Each only receives the specific data needed for its purpose:
We do not use any advertising SDKs, and we do not share data with data brokers or use it for behavioural advertising.
The application does not use third-party analytics or crash-reporting tools (Google Analytics, Firebase, Crashlytics, Mixpanel or similar). Basic app-interaction events and error diagnostics are recorded only in our own database, for the sole purpose of improving the application — they are never sold, shared with advertisers, or used for behavioural advertising. We do not use cookies. The only server logs are standard access logs (IP address, request time, endpoint), automatically deleted after 7 days.
Judo Academy is designed to be usable by young learners, including children under 13, alongside teenagers and adults. Registration requires a minimum age of 8. We are committed to following the Google Play Families Policy, COPPA and GDPR-K.
Because of this, the application applies the following safeguards for accounts identified as belonging to a child, based on the birth year provided at sign-up:
A parent or guardian may review, correct, or request deletion of a child's data at any time using the methods described in Section 2.2. If you believe a child has provided us with more personal data than is described in this policy, please contact us at judo.academy.world@gmail.com so that we can review and, where appropriate, delete it promptly.
If you use the application from the European Union, you (or, for a child's account, a parent or guardian acting on the child's behalf) have the following rights:
To exercise your rights, write to judo.academy.world@gmail.com. We respond within 30 days.
All communication between the application and the server is encrypted (HTTPS/TLS). Server access is restricted and protected by authentication. Passwords are not stored — we use Google OAuth exclusively, together with a signed session token to keep you securely signed in.
You will be notified of significant changes via an in-app notification at least 14 days in advance. The date of the last update is always visible in the header of this document.
If you believe your data has not been handled correctly, you have the right to lodge a complaint with the data protection authority in your country.