Privacy Policy
Effective August 29, 2026
Controller and contact details
Mark Isayan, Avan, Kuchak 47 Building, Apartment 14, Yerevan, Armenia, is responsible for the personal information Kurobi processes. Send privacy, support, or rights requests to kurobi@devcrafts.io.
Kurobi does not currently designate a separate data-protection officer or European or United Kingdom representative. If applicable law requires one, this Policy will be updated before Kurobi is intentionally offered in that jurisdiction.
Scope
This Policy applies to information processed through the Kurobi mobile application and related services. It does not govern independent processing by Apple or other third parties under their own consumer relationships and privacy policies, including Apple’s operation of the App Store, Apple Account, or Speech Recognition services.
Information we collect
- Account and identity information: an Apple authentication identifier; any name, email address, or private relay address Apple makes available based on your choices; a Kurobi or Supabase user identifier; and authentication and session information.
- Profile and onboarding information: belt level, training frequency, current note-taking method, onboarding status, starting positions, technique-familiarity ratings, favorites, exclusions, and practice preferences.
- Training and app content: drills, rolls, competitions, positions, transitions, perspective, repetitions, duration, quality, outcomes, problem signals, notes, timestamps, chat messages, and conversation titles.
- Audio and speech information: optional local audio notes, attachment metadata, transcription status, and resulting transcripts.
- Derived training information: progress stages, mastery estimates, gap signals, practice queues, and recommendation rankings. These are software estimates, not professional assessments or legally significant decisions.
- Purchase information: the Kurobi user identifier, App Store product and package identifiers, subscription and entitlement status, receipt or transaction information, renewal and expiration events, and localized offering information processed with Apple and RevenueCat.
- Technical information: app version, build, environment, platform, controlled product events, crash information, diagnostics, logs, performance traces, request timestamps, IP addresses, and security information.
- Waitlist email address and metadata: the email address you voluntarily submitted while this website offered its waitlist, the source attribution value when present, and associated website metadata described below.
- Website attribution and technical information: the source attribution value from a landing-page URL with a non-empty
sparameter; the normalized campaign value for every visit to the/getdownload route, which defaults todirectwhen no valid value is supplied; request time; IP address; user agent; referrer; language; approximate IP-derived country, region, city, latitude, and longitude when Vercel supplies them; request identifiers; and, for landing-page source visits, client-reported screen and viewport dimensions, pixel ratio, color depth, language, time zone, and touch capability. - Support communications: your email address, message, attachments, and other information you choose to provide.
Local storage and cloud sync
Kurobi is offline-first. Training records and related app data are stored locally using WatermelonDB, while smaller settings and session information use platform storage. Signed-in user-owned records synchronize to Supabase when connectivity is available.
Recorded audio files stay in Kurobi’s app storage on your device and are not uploaded by Kurobi’s current synchronization service. Attachment metadata and resulting transcripts may synchronize with the training log. Because Kurobi permits server-based iOS speech recognition, audio may be sent to Apple for transcription depending on device capabilities and settings.
Removing an attachment may remove its reference without immediately deleting its underlying local file. Account-data cleanup attempts to delete files still referenced by local logs. You can deny or withdraw microphone and speech-recognition permission in iOS Settings without losing Kurobi’s non-audio features.
Analytics and diagnostics
Usage analytics and crash diagnostics are on by default. You can disable either one using its separate control in Kurobi’s profile settings.
While Share usage analytics is enabled, PostHog receives a Kurobi user identifier after sign-in and controlled events such as app and screen opens, onboarding steps, training-log actions, audio feature status, map interactions, recommendation actions, profile updates, and subscription-funnel events. Events may include app version, build, environment, platform, controlled screen or action names, and limited counts or categories.
To understand which catalog content is useful or missing, PostHog may receive controlled catalog identifiers for positions and techniques included in logged chains, together with sanitized catalog searches and result counts. Kurobi is designed not to send training-note text, audio, transcripts, SensAI prompts or responses, opponent information, email addresses, arbitrary free-text fields, or raw error messages to PostHog. Kurobi does not use PostHog for cross-app advertising tracking.
While Share crash diagnostics is enabled, Sentry may receive crash reports, performance traces, logs, breadcrumbs, app environment and version, device-related technical information, error categories, synchronization counts, and other diagnostic details. Default personally identifying information is disabled, but technical reports can sometimes contain incidental identifiers or information included in errors.
The website uses Vercel Web Analytics for aggregate page-view, referrer, device, browser, operating-system, and location reporting. Vercel Web Analytics does not use cookies and does not associate its analytics records with a persistent cross-site identifier. Kurobi removes the s query parameter before a page-view URL is sent to Vercel Web Analytics.
Separately, when the landing-page URL contains a non-empty s parameter, Kurobi saves a source-attribution visit in Supabase with the limited technical metadata listed in this Policy. Every visit to the /get download route creates a separate download-attribution record before redirecting to the App Store. These dedicated records may include an IP address and are not the same as Vercel’s aggregated Web Analytics records.
Sources and uses
We obtain information directly from you, from Apple through Sign in with Apple and App Store transactions, automatically from your use of Kurobi when the relevant optional control is enabled, from RevenueCat about subscription lifecycle and entitlement status, and by deriving training insights from your saved activity.
We use information to create and authenticate accounts; provide local storage and synchronization; save and display training records; calculate progress, gaps, and recommendations; provide SensAI and requested transcription; validate purchases; operate, troubleshoot, and secure Kurobi; respond to support; prevent misuse; enforce the Terms; and comply with law. We use website analytics, source-attribution records, and download-attribution records to understand landing-page performance and referral campaigns. We retain historical waitlist information for the purposes described when it was collected.
Where European Economic Area, United Kingdom, or similar law applies, the legal bases may be performance of the service you request, your consent, legitimate interests in proportionate product operation and security, or compliance with legal obligations. Account authentication is necessary to create an account. Other profile content, notes, audio, reviews, telemetry choices, and SensAI use are optional.
SensAI processing
When you submit a SensAI request, Kurobi sends Anthropic your prompt; approximately 12 recent user and assistant messages used as conversation context; relevant recent training logs, gap signals, notes, and ratings; graph positions and transitions with related names and derived stages or scores; and a system instruction defining SensAI’s limited role. The request travels through a Supabase Edge Function to Anthropic’s commercial API.
Kurobi tells you before the message input that your message and relevant training context will be sent to Anthropic. Sending after seeing that disclosure is your request for this processing. SensAI is optional, and choosing not to use it does not remove non-AI features.
Anthropic states that commercial API inputs and outputs are not used to train its generative models by default unless the customer opts in or submits relevant feedback, and that standard API inputs and outputs are generally deleted from its backend within 30 days, subject to contractual, safety, or legal exceptions. See Anthropic’s Privacy Center.
Kurobi separately stores chat history locally and synchronizes it to Supabase. The current app does not provide individual-chat deletion; you can remove saved history by deleting your account or requesting deletion at kurobi@devcrafts.io.
How information is disclosed
We do not sell personal information, share it for cross-context behavioral advertising, or display third-party advertising. We disclose information to the following recipients only for the described purposes or where legally required:
- Supabase: authentication, database hosting, synchronization, and Edge Functions involving account identifiers, profiles, synchronized content, chat content, transcripts, preferences, historical waitlist information, website attribution records, and security data.
- Vercel: website hosting, request delivery, security, and cookie-free Web Analytics involving page views and aggregated referrer, device, browser, operating-system, and approximate-location data.
- Anthropic: SensAI prompts, limited chat and training context, notes, graph context, derived information, and generated responses.
- Apple: Sign in with Apple, App Store distribution and payment, campaign measurement using the normalized Apple campaign token included in the download link, subscriptions, permissions, and requested speech recognition under Apple’s own terms.
- RevenueCat: purchase validation and subscription entitlements involving user identifiers, receipts, transactions, products, offerings, and status. RevenueCat may send subscription lifecycle events associated with the same identifier to PostHog.
- PostHog: optional product analytics and subscription-funnel measurement.
- Sentry: optional crash reporting, performance monitoring, logging, and diagnostics.
- Professional advisers, authorities, or business transferees: where reasonably necessary, legally permitted, and subject to appropriate safeguards.
International transfers
Kurobi is operated from Armenia and uses providers that may process information in the United States, European Economic Area, United Kingdom, or other countries where they or their subprocessors operate. Where required, we rely on lawful transfer mechanisms such as adequacy decisions, contractual safeguards, standard contractual clauses or equivalent terms, and supplementary measures.
Retention
We retain information only as long as reasonably necessary to provide Kurobi, maintain security, resolve disputes, and meet legal obligations. Principal criteria include:
- Account, profile, synchronized training data, preferences, and chat: while the account remains active, then removed from Kurobi’s active Supabase user tables when account deletion succeeds.
- Local app data: while needed for offline use; account deletion resets the local user database and attempts to remove audio still referenced by local logs.
- SensAI API inputs and outputs: generally up to 30 days under Anthropic’s stated standard commercial API practice, subject to its exceptions; Kurobi’s saved copy remains until deleted as described here.
- PostHog analytics and Sentry diagnostics: according to Kurobi’s project configuration and operational needs, then deleted or aggregated. Resetting an analytics identity does not itself erase historical provider events.
- Waitlist information: until you ask us to remove it or it is no longer reasonably needed for launch communications, subject to legal or security requirements.
- Website source-attribution and download-attribution visits: until they are no longer reasonably needed to evaluate referral campaigns, maintain security, or meet legal requirements, after which they are deleted or aggregated.
- Subscription, support, legal, backup, and security records: for the applicable provider rotation, transaction integrity, request handling, fraud prevention, accounting, legal compliance, or dispute period.
Because fixed production PostHog and Sentry periods have not been adopted, Kurobi currently uses necessity and configured provider retention limits as the criteria. This Policy will be updated when specific production periods are adopted.
Security
We use reasonable administrative, technical, and organizational measures, including authenticated access, encrypted network transmission, row-level database controls intended to separate users’ records, secrets kept outside the mobile client, and restricted synchronization fields. No system is completely secure, so we cannot guarantee information will never be lost, corrupted, intercepted, or accessed without authorization.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, receive portable information, appeal a denied request, or complain to a data-protection or consumer authority. Legal exceptions may apply, and we may need to verify your identity.
- Update supported profile information or delete individual training logs in Kurobi.
- Withdraw microphone or speech-recognition permission in iOS Settings.
- Enable or disable Share usage analytics under Profile → Privacy Choices.
- Enable or disable Share crash diagnostics under Profile → Privacy Choices.
- Manage or cancel subscriptions in Apple Account settings.
- Initiate account deletion under Profile → Delete profile.
Successful account deletion removes your Kurobi authentication account and the active Kurobi user data described above. It does not cancel an Apple subscription or automatically erase records independently controlled or lawfully retained by Apple and other providers. For broader access, correction, portability, restriction, objection, or deletion requests, email kurobi@devcrafts.io.
United States state disclosures
For residents of California and other states with applicable comprehensive privacy laws, categories collected may include identifiers, customer records, commercial information, product interactions, audio you choose to record, training-related information, voluntarily submitted sensitive information, and inferences about progress and recommendations. We use and disclose these categories for the purposes described above, do not sell them or share them for cross-context behavioral advertising, and do not knowingly use sensitive information to infer characteristics for unrelated purposes.
Children and teenagers
Kurobi is not directed to children under 16, and we do not knowingly permit them to create accounts. If we learn that a user is under 16, we will take reasonable steps to delete the account and associated information. Users aged 16 or 17 need parental or guardian authorization where applicable law requires it.
Automated processing
Kurobi uses rules, scoring formulas, and AI systems to calculate mastery estimates, identify possible gaps, order practice suggestions, and generate SensAI text. These tools support your own training decisions and do not make solely automated decisions producing legal or similarly significant effects.
This website
This website previously offered a waitlist form that sent the email address and associated technical metadata you chose to submit to Kurobi's Supabase database. If the landing-page URL contains a non-empty source attribution value in the s parameter, the website records the visit and limited technical metadata in Supabase.
Every visit to the /get download route records limited request and approximate-location metadata in Supabase, then redirects to Apple’s App Store campaign link. The normalized s value becomes the Apple campaign token; it defaults to direct when no valid value is supplied. When Instagram’s in-app browser is detected, the route asks Instagram to open the same App Store campaign link in the device’s external browser.
The website metadata collection is allowlist-based. It does not store cookie or authorization header values, and it does not copy arbitrary request headers into the database. Screen and viewport dimensions on source-attribution visits come from the browser because they are not HTTP request headers. Source values and metadata fields are length-limited to reduce misuse.
We do not intentionally set advertising cookies. Vercel may process ordinary infrastructure information such as IP address, request headers, and access logs to deliver and secure the site, and provides the cookie-free Web Analytics described above.
Changes and contact
We may update this Policy when Kurobi, its providers, law, or data practices change. We will update the effective date and provide additional notice of material changes where required. We will not materially expand use of previously collected personal information without any notice or choice required by law.
Mark IsayanAvan, Kuchak 47 Building, Apartment 14
Yerevan, Armenia
Email: kurobi@devcrafts.io
Telephone: +37441040394