Draft — pending legal review. This document is a working draft written to reflect how rollog actually handles data. It has not been reviewed by counsel and contains placeholders (shown in [brackets]) that must be completed before it is relied upon.
Privacy Policy
Effective date: [EFFECTIVE DATE]
This policy explains what personal information rollog (“rollog”, “we”, “us”), operated by [ENTITY], collects, how we use it, and who we share it with. It covers both the rollog mobile app and the rollog studio web dashboard.
rollog serves two kinds of people: individual practitioners who track their own training, and jiu-jitsu studios that manage their members. Our privacy role differs between them, so please read section 1 first.
1. Who we are, and when we are responsible for your data
Depending on the data, rollog acts either as a “controller” (we decide how and why data is used) or a “processor” (we handle data on a studio’s behalf, under its instructions).
- We are the controller for your individual account, the data you enter about your own training, product analytics, error diagnostics, and our billing relationship with studios.
- We are a processor for data a studio enters or manages about its members — roster details, attendance, age group, waivers, emergency contacts, and membership/payment status. For that data the studio is the controller. If you are a member and want to access or delete studio-held data, ask your studio first; we assist them.
2. What we collect
Information you enter about your own training:
- Profile: display name, belt and stripes, training start date, gi/no-gi preference, weekly training goal, avatar, and time zone.
- Sessions: your free-text notes, how a session felt, perceived intensity, and any video link you add.
- Training rounds, which may include a training partner’s name that you enter, and round notes.
- Belt history notes, custom moves, and your saved sequences.
- Voice notes — see section 3, which covers voice data specifically.
Information a studio enters about you (studio is controller):
- Roster fields: age group (which may be marked as a child), phone number, whether a waiver is signed, and an emergency contact name and phone number (a third person’s details).
- Attendance records, your membership and payment status, and any cancellation notes.
If you sign up as a studio owner:
- Your account email and studio billing status.
Guests (no account):
- If you sign a waiver at a studio kiosk without an account, we store your name and your signature image on the studio’s behalf.
Collected automatically:
- Your account email (held by our authentication provider). Diagnostic error logs, which include your account identifier and technical context; we make a best effort to strip personal content from these, but cannot guarantee it.
- When you sign an onboarding document, we record your signature image, the IP address, and the browser user-agent at the time of signing.
- A device push token, if you enable notifications.
3. Voice notes and voice data
Voice notes are recordings of your voice, so we treat them as sensitive. When you record and save a voice note, the audio file is uploaded to our private storage (accessible only to you under access controls) and is retained until you or we delete it.
Turning speech into text happens on your device. The audio of a spoken note is not sent to us or to any third party for transcription. See section 4 for how the resulting text is then used.
4. How AI features use your data
Our AI features (for example, turning a spoken description into a sequence) work from the text transcript produced on your device. Only that text — never the audio — is sent to our AI provider, and it is sent without any identifier linking it to you.
AI output is assistive and may contain errors; you are responsible for how you use it.
5. Service providers we share data with
We use the following providers to run rollog. We do not sell your personal information.
- Vercel — hosting and delivery of our websites and studio dashboard (United States); data passes through Vercel en route to our database.
- Supabase / AWS — hosting, database, and file storage (United States).
- Anthropic — AI processing — receives transcript text only, with no identifier attached.
- Stripe — payment processing. For studio subscriptions, the studio owner's email. For member dues paid through a studio, your name and email are provided to the studio's own payment account (see section 6).
- Resend — sending email — receives recipient email addresses and the full content of the emails we send on a studio's behalf.
- TelemetryDeck — product analytics — receives an identifier that is hashed on your device plus non-identifying event details (for example, session length). This is pseudonymous, not anonymous, and remains personal data.
- Google — sign-in, only if you choose to sign in with your Google account. Google verifies your identity and returns a signed token to us; we do not send Google your training data. This is Google's authentication service, not Google Analytics.
- Apple / Expo — delivery of push notifications. If you choose Sign in with Apple, Apple verifies your identity and returns a signed token that may include your name and an email address (your real address or Apple's private relay). On-device speech recognition on Apple devices keeps audio on the device.
We do not use third-party advertising or web-analytics trackers. Notion is used only to author our move library before release and receives none of your data.
6. What your studio can see about you
If you belong to a studio, its staff can see a limited summary about you:
- Your name, belt, attendance counts, training start date, gi/no-gi preference, weekly goal, age group, phone, waiver status, and emergency contact.
- The studio’s owner (not its instructors) can also see your account email address, for roster and billing communication.
Your studio cannot see your session notes, voice notes, how sessions felt, perceived intensity, custom moves, or sequences. Those stay private to you.
One exception to be clear about: if you pay membership dues through your studio, your name and email are shared with the studio’s own payment account via Stripe. That transfer is separate from the in-app controls above.
7. Analytics and cookies
Our only product analytics is TelemetryDeck, described in section 5 (pseudonymous, hashed on your device). We do not use advertising trackers, and our websites set no cookies other than the session cookie required to keep you signed in. On mobile, you can turn off product analytics at any time in Profile → Privacy & account; it is on by default.
8. Children
rollog accounts are intended for people aged 13 and over. We do not knowingly let children under 13 create their own accounts.
Studios may enroll minors and may record a member’s age group as a child. Where a studio does so, the studio is the controller of that data and is responsible for obtaining verifiable parental or guardian consent, as set out in our Terms of Service. If you believe a child under 13 has given us data directly, contact [PRIVACY CONTACT EMAIL] and we will remove it.
9. Retention and deletion
You can delete your account yourself in the rolllog mobile app, from your Privacy & account settings. You can also request deletion by emailing hello@rollog.app. We action deletion requests within 30 days.
When you delete your account there is a short grace period (currently 7 days) during which you can sign back in and cancel. After it ends, we permanently delete your rollog account and the personal training data we control — including your sessions, belt history, custom moves, sequences, voice notes, and avatar image.
Some records stay with your studio, which is their controller (see section 1). After your account is deleted, your studio keeps — attributed to your name, belt, and stripes — your attendance history, membership record, any waivers you signed, and any classes you taught. Deleting your rollog account does not cancel your studio membership or stop any dues; those are separate and arranged with your studio. To have the studio’s records erased, contact your studio directly.
To be honest about the limits: diagnostic error logs are kept with your account identifier removed, and routine backups age out over time.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, export, or object to the use of your personal information. To exercise them, email [PRIVACY CONTACT EMAIL] or hello@rollog.app. For data your studio controls (section 1), please make the request through your studio; we will help them fulfil it. We do not sell personal information.
11. Security
We protect data with private storage buckets, database row-level access controls, and encryption in transit. No system is perfectly secure, and our automated stripping of personal content from diagnostic logs is best-effort rather than guaranteed.
12. International data transfers
rollog is hosted in the United States (our database in AWS us-west-1; our email provider in AWS us-east-1). Our other providers may also process data in the United States. If you are in the EU or UK, transfers rely on [INTERNATIONAL TRANSFER MECHANISM], and our representative for these regions is [EU/UK REPRESENTATIVE].
13. Changes to this policy
We may update this policy. When we make material changes we will update the effective date above and, where appropriate, notify you.
14. Contact us
[ENTITY], established in [JURISDICTION], [BUSINESS ADDRESS]. Privacy enquiries: [PRIVACY CONTACT EMAIL] or hello@rollog.app.