Skip to main content
Privacy Policy | JudoLytics

Privacy Policy.

How we at JudoLytics process, protect, and respect your personal data.

Last updated: September 25, 2026

01Who we are

JudoLytics is a sports analysis platform for judo. We help judokas, coaches, and club administrators analyze match performance, track training and body measurements, monitor recovery, create development plans, and manage judo clubs.

Data controller: Bloei.ai

Chamber of Commerce number: 66950376

Address: Clavisstraat 33, 6515GA, Nijmegen, Nederland

Email: info@judolytics.com

The Dutch Data Protection Authority (Autoriteit Persoonsgegevens) is the Dutch supervisory authority for the protection of personal data. More information at autoriteitpersoonsgegevens.nl.

02What data we collect

We only collect data that is necessary for providing our service or for which we have another legal basis. Below you will find an overview per category.

CategoryDataPurposeLegal basis
Account dataEmail address, name, year of birth, profile photoAccount management and authenticationPerformance of contract
Sports performance dataMatch results, scores, techniques, match duration, weight categoryAnalysis and performance insightsPerformance of contract
Strategic notesMatch plans, reflections, opponent notesPersonal match preparationPerformance of contract
Opponent dataName, country, birth year, weight category, IJF and JudoManager IDProfile building and analysisLegitimate interest
Payment dataStripe customer ID, subscription status, billing periodSubscription management and billingPerformance of contract
Technical dataIP address (at registration), browser information (when submitting feedback), session tokensSecurity and debuggingLegitimate interest
Recovery dataSleep quality, physical recovery, energy level, stress, motivation, soreness (each on a 1-5 scale), readiness score, recovery notesRecovery monitoring and recovery adviceExplicit consent (Art. 9 GDPR)
Training dataSession date, duration, type, intensity (RPE), training load, exercises, techniques, coach notes, reflectionsTraining logging and load monitoringPerformance of contract
Body measurementsWeight, height, body fat percentage, strength, endurance, power, and flexibility measurementsPhysical progress and performance monitoringHealth data: explicit consent (Art. 9 GDPR) for body composition; performance of contract for performance metrics
Development plansGoals, categories (technique, tactics, strength, mental, etc.), check-ins, self-assessments, coach feedback, progress indicatorsPersonal development and goal managementPerformance of contract
Notification preferencesEmail and push settings, quiet hours, notification types, frequency limitsPersonalized communicationPerformance of contract
Referral dataReferral code, click and signup tracking, reward statusReferral program and rewardsPerformance of contract
GamificationBadges, streaks, achievements, and associated timestampsMotivation and engagementPerformance of contract
Club and membership dataYour club memberships, your role in the club (administrator, coach, or judoka), and group assignment; for club administrators also the club name, address, location (coordinates), and club logoClub and group management and coach functionalityPerformance of contract
DocumentsFiles in your record (a PDF, an image, a Word, Excel or PowerPoint file or its OpenDocument equivalent, or a CSV or text file), with the file name, file type, size, date added and who added it: you, or a coach or manager of your clubKeeping your own record and, if you turn it on, letting your coaches see it. If you gave your club consent, the coaches and managers of that club can add documents to it themselves, such as a test result or a progress reportExplicit consent (Art. 9 GDPR). For documents from your club a separate consent, per club

Please note: recovery data (sleep quality, physical recovery, energy, motivation, soreness) is considered health data within the meaning of Article 9 GDPR. We process this data exclusively on the basis of your explicit consent, which you provide by voluntarily entering this data. You can stop entering recovery data at any time and delete existing data.

Please note: a document can contain health data. A test result, for example, or a letter about an injury. We do not know what is inside it: there is no text recognition and nobody on our side opens your files. When you add a file, our server does check it automatically, without anyone reading along and without keeping anything: it rejects macros and other content that runs something or fetches something from outside when the file is opened, and in a CSV file any cell a spreadsheet would run as a formula. The app first makes a photo smaller on your device. Our server then removes the details a camera or phone writes into it, such as where and when it was taken. We only keep the image itself, with a small copy for the overview. That is why we treat every document as if it contains health data, and process it solely on the basis of your explicit consent (Article 9 GDPR). You decide what you add and whether you share it. If you withdraw that consent, sharing with your coaches stops immediately, including for documents that were already there. The files themselves stay until you delete them. You can do that at any time. The same goes for an overview report saved as a PDF in your record: that copy is a document like any other and stays until it is deleted. The retention period of the report in the app does not apply to it.

A coach or manager of your club can only add a document to your record if you gave that club separate consent for it. You get that question per club, separate from the consent for your own documents, and the coaches and managers of that club can see whether you said yes or no. Only you and the coaches and managers of that club see such a document. If a coach only works with certain groups, they only see it when you are in one of those groups. Your teammates never see it. A document your club adds belongs to you. It sits in your record, and we store it for you, not on the club's behalf. You can delete any document yourself. The coaches and managers who can add documents can also delete a document the club added. You'll get a notification when they do. If you withdraw your consent or leave the club, that club's staff can no longer see the documents, and the club can't add anything new.

Explanation of legal bases: "Performance of contract" means that the processing is necessary to provide you with the service. "Legitimate interest" means that we have a business interest in the processing, always weighing it against your privacy interests.

03External data sources

When you link an opponent to an external profile, we retrieve additional data from publicly accessible sports databases at your request:

  • IJF (International Judo Federation): Public match data, world rankings, competition history, and weight category via the IJF database (Judobase).
  • JudoManager: National match data, statistics, and club information via the JudoManager API.

This data is cached to keep the platform fast, with a fixed retention period per type: a retrieved judoka profile is kept for at most one year after it was last fetched, and a tournament's draw and entry list for at most 30 days. On your own device, the draw and entry list stay available for 7 days so the app works offline. If you linked the profile to an opponent in your account, the cache disappears as soon as you delete that opponent; if you only searched without linking, the cache expires with the retention period.

If you want to import your own matches from the IJF database or from JudoManager, you first confirm that the linked profile is yours and authorize us to retrieve your competition data from it. This consent also covers retrieving that data again later, for example to add video times to imported matches, and we record it with its date and time. Matches you confirm after importing become regular matches in your account, which you can delete there yourself. You can withdraw your consent at any time via Settings > Privacy. After that we retrieve nothing more, and we immediately delete imported matches you had not confirmed yet.

04Club functionality and shared data

JudoLytics offers the ability to join a judo club within the platform. Within a club, coaches, administrators and, depending on your settings, fellow club members can view certain member data, but only to the extent you have set this yourself. One thing your club's coaches and administrators always see: which club sessions you are scheduled for and whether you attended. That is part of organizing a session. Your own sessions, the intensity, your reflections and your reason for canceling stay under your own settings. When you join a new club, nothing is shared by default until you make a choice.

You decide per topic who you share with, through the privacy settings in your dashboard. Each time you choose between not sharing, only your coaches, or your whole club. For a number of topics "your whole club" is deliberately not an option: those go to your coaches at most. This is what you can set:

  • Match results, scores, and statistics. Can also be shared with your whole club.
  • Opponent information and notes. Can also be shared with your whole club.
  • Match plans. Can also be shared with your whole club.
  • Sport measurements such as strength and fitness tests. Can also be shared with your whole club.
  • Your weight and your match reflections. These go to your coaches at most, never to fellow club members.
  • Training sessions and training reflections, your recovery checks, your development plan, and your tournament data. These too go to your coaches at most.

A sharing setting applies to all your data in that category, including data you entered earlier. If you set a category to private, coaches and fellow club members will no longer see your older data in that category either. You can change all of these settings at any time via your privacy settings in the dashboard.

05Anonymization and aggregated use

We reserve the right to anonymize and aggregate your data for the following purposes:

Product improvement

Analysis of usage patterns, performance benchmarks, and feature usage to improve the platform and develop new features.

Research and publication

Sharing aggregated insights about judo performance, training patterns, and sports analysis with third parties, including in marketing materials, public reports, and research publications.

When anonymizing, we ensure that:

  • Data is aggregated at group level (minimum 5 users)
  • Individual identifiers are irrevocably removed
  • It is impossible to trace results back to individual persons
  • Anonymized data is not combined with other sources for re-identification

Anonymized and aggregated data no longer falls under the General Data Protection Regulation (GDPR) and can therefore be used without restriction, including for external publication and marketing purposes.

Legal basis: Legitimate interest (Article 6(1)(f) GDPR). We have conducted a balancing test weighing the interest of product improvement and knowledge development in judo against your privacy interests. Since the data is fully anonymized, we consider the risk to your privacy minimal.

06Retention periods

We do not retain your data longer than necessary for the purpose for which it was collected, unless a legal retention obligation applies.

DataRetention periodExplanation
Account dataUntil account deletion + 30 daysDeletion upon request
Sports performance dataUntil account deletionAfter deletion, the data is stored in anonymized form
Payment data7 years after last transactionLegal retention obligation (tax law)
Email logs1 yearDebugging and auditing
In-app notifications (read/dismissed/failed)90 daysUnread notifications remain available until interaction
Cached external dataUntil opponent removed or 1 yearPerformance optimization
Technical logs90 daysSecurity and debugging
Recovery dataUntil account deletionStored in anonymized form after deletion
Training dataUntil account deletionStored in anonymized form after deletion
Body measurementsUntil account deletionStored in anonymized form after deletion
Analytics data (PostHog)1 yearAnonymized product analytics

07Security

We know your recovery, performance, and health data is personal. That is why security is not an add-on but the foundation JudoLytics is built on. Your data is protected in layers, from the connection with your browser to the way it is stored in the database. We take appropriate technical and organizational measures to protect your personal data against unauthorized access, loss, or modification. Below we explain, in plain language, how.

  • Encryption: All your data is encrypted in transit (the entire app runs only over a secure HTTPS connection, enforced via HSTS) and encrypted at rest (encryption at rest via Supabase).
  • Passwords stay secret, even from us: Your password is never stored as readable text. We keep only an encrypted, one-way version (bcrypt hashing with a salt). No one at JudoLytics can view or recover your password.
  • Secure login: Login is via email and password or via Google (OAuth 2.0), with a PKCE-secured login flow and optional two-step verification (MFA/2FA) via authenticator apps.
  • MFA enforcement: Two-step verification is mandatory for administrator and support roles. Regular users can enable MFA voluntarily, with recovery codes. Once MFA is on, their own match, training and measurement data is only readable on a session that has completed the second step; this is enforced in the database, not in the app.
  • Access control (Row-Level Security): At the database level, it is enforced that you can only access your own data. No other judoka or coach can see your data unless you choose to share it. This rule is enforced in the database itself, not only in the app, and is tested automatically.
  • Documents sit in shielded storage: files attached to your record go into a closed storage area with no public links. Your browser cannot write to it directly; adding a file always goes through our server. Every file path starts with the judoka the file is about, so a deletion request hits exactly the right files and never someone else’s. If you delete your account, the files themselves are erased, not just the reference to them. A document always opens as a download, never inside the app itself.
  • Notifications about documents never name the file. When your club adds a document to your record, you get a notification in the app, a push message and an email. You always get the email; you can turn the push message off. None of the three names the file: a push message shows on your lock screen, and a file name can already say something about your health.
  • Access on a need-to-know basis: Even within our own team, access to personal data is limited to what is strictly necessary. Internal keys and passwords are stored encrypted and rotated regularly.
  • CAPTCHA protection: Cloudflare Turnstile protects the registration process against automated attacks.
  • Rate limiting: Protection against brute-force login attempts and API abuse.
  • Security headers: A strict Content Security Policy and additional security headers counter common web attacks, such as clickjacking and code injection.
  • Input validation: Everything you enter is checked both in your browser and on the server before it is stored.
  • Continuous monitoring: We monitor the platform around the clock for errors and suspicious activity, so we notice and fix problems quickly.
  • Audit logging: Administrative actions are logged for accountability and debugging.
  • Automatic backups: Regular automatic backups are made, so your data can be restored after a technical failure and is not lost in an unexpected problem.
  • Payment details never enter our system: Your card or bank details are processed solely by our payment partner Stripe, which meets the strictest payment-security standard (PCI-DSS). JudoLytics itself stores no card data.
  • Stored in the European Union: Your data is held in a database within the European Union (Frankfurt, Germany) and is therefore covered by European privacy law.
  • You stay in control: You can download all your data at any time or have your account and data permanently deleted, directly from your settings.

In short: your data is encrypted and technically isolated. No other user, not even a coach in your club, can see your data unless you choose to share it. Our database is hosted in the European Union; where we use service providers outside the EU, appropriate safeguards apply (see section 11). You remain the owner of your data and stay in control at all times.

No online service can guarantee absolute security. That is why we keep our protection up to date at all times and follow a set procedure if something does go wrong: in the event of a data breach that poses a risk to you, we report it to the supervisory authority within 72 hours and, where necessary, directly to you.

Think you have found a security issue? Let us know at info@judolytics.com. We take every report seriously.

08Your rights

Under the General Data Protection Regulation (GDPR), you have the following rights regarding your personal data:

Right of access (Article 15 GDPR)

You can request which personal data we process about you and receive a copy thereof.

Right to rectification (Article 16 GDPR)

You can request correction of inaccurate or incomplete data. You can adjust much of this data yourself via your settings page at judolytics.com/dashboard/settings.

Right to erasure (Article 17 GDPR)

You can delete your account and personal data. You can do this yourself via Settings > Privacy at judolytics.com/dashboard/settings. After the request, your account is permanently deleted after 30 days. Anonymized aggregated data and data we are legally obligated to retain (such as payment data for tax purposes) fall outside this right.

Right to restriction of processing (Article 18 GDPR)

You can request temporary suspension of the processing of your data, for example when you dispute the accuracy of your data.

Right to data portability (Article 20 GDPR)

You can download your data in a structured, commonly used, and machine-readable format (JSON) via Settings > Privacy at judolytics.com/dashboard/settings. This enables you to transfer your data to another service provider.

Right to object (Article 21 GDPR)

You can object to the processing of your data based on our legitimate interest. We will cease processing unless we demonstrate compelling legitimate grounds for the processing.

Right regarding automated decision-making (Article 22 GDPR)

JudoLytics does not make automated decisions with legal effects or similarly significant consequences for you. All analyses and insights are informational in nature.

Submit a request: Send your request by email to info@judolytics.com. We will respond within 30 days. To verify your identity, we may ask you for additional information.

Self-service

Many rights can be exercised directly without an email request:

  • Edit profile: Settings > Account
  • Download data (JSON): Settings > Privacy
  • Delete account: Settings > Privacy
  • Manage club privacy: Dashboard > Club > Privacy
  • Notification preferences: Settings > Notifications
  • Email preferences: Settings > Notifications

09Cookies and local storage

JudoLytics uses cookies and local storage in your browser for the functioning of the application. Below you will find a complete overview of all cookies and storage mechanisms we use, divided into strictly necessary and optional (consent required).

Strictly necessary cookies and storage

These cookies and storage items are necessary for the website to function. They cannot be disabled.

TypePurposeStrictly necessaryConsent required
Session token (Supabase Auth)Authentication and session management (localStorage). Contains your login token, expiration time, and PKCE verification code.YesNo
Role cachePlatform role caching for performance optimization (localStorage, valid for 60 minutes)YesNo
Consent cookie (CookieYes)Storage of your cookie consent preferences (cookie)YesNo
Sidebar stateRemembers whether the side menu is expanded or collapsed (cookie, valid for 7 days)YesNo
Language preferenceYour selected language setting and whether you dismissed the language banner (localStorage and cookie, valid for 1 year)YesNo
UI preferences and application stateOnboarding status, module settings, referral codes, guides, MFA reminders, and other interface preferences (localStorage)YesNo

Analytics cookies (consent required)

These cookies are only placed after your explicit consent via the cookie banner. You can withdraw or adjust your consent at any time.

TypePurposeStrictly necessaryConsent required
PostHogProduct analytics, usage statistics, and session recordings (all text and input masked). Without consent, PostHog runs in memory mode without any storage. If you have also allowed advertising cookies, PostHog reads the Meta cookies _fbp and _fbc. The Meta browser ID (_fbp) is linked to your user profile and the moment you clicked a Meta ad (_fbc) to the visit, so we can measure which ad led to a sign-up.NoYes (via cookie banner)
Google Tag ManagerManages the loading of analytics scripts. Activated based on your CookieYes consent choice.NoYes (via cookie banner)
Google Analytics 4 (via GTM)Website analytics, page views, Core Web Vitals, and visitor statistics. Sets cookies such as _ga and _ga_* (valid up to 2 years).NoYes (via cookie banner)
Microsoft Clarity (via GTM)Session recordings and heatmaps for usability analysis. Sets cookies _clck (1 year) and _clsk (1 day).NoYes (via cookie banner)

Advertising cookies (consent required)

These cookies are used to measure the effectiveness of advertising campaigns. They are only placed after your explicit consent.

TypePurposeStrictly necessaryConsent required
Meta/Facebook Pixel (via GTM)Measures conversions and page views for advertising campaigns. Sets the cookie _fbp (3 months) and, if you arrive via a Meta ad, _fbc (3 months). PostHog reads both (see PostHog above).NoYes (via cookie banner)

Embedded third-party content

Some pages may embed third-party content. This content only loads when you use it, and may then set cookies from that party. We therefore do not place these cookies in advance.

TypePurposeStrictly necessaryConsent required
YouTube (embedded video)Plays instructional or match videos. Loads only when you click play. YouTube may then set cookies such as VISITOR_INFO1_LIVE and YSC.NoLoads only when you play a video
Vimeo (embedded video)Plays videos shared from Vimeo. Loads only when you click play. Vimeo may then set its own cookies.NoLoads only when you play a video
Google Maps (map and address autocomplete)Shows club locations on a map and helps you enter an address. Loads only when you use the map or address feature. Google may then set cookies.NoLoads only when you use the map or address search

You can view and adjust your cookie preferences at any time by reopening the cookie banner. Click the button at the bottom of the page or use the link:

The strictly necessary cookies and storage are required for the functioning of the service. Under the Dutch Telecommunications Act (Article 11.7a), prior consent is not required for these. Analytics and advertising cookies are only placed after your explicit consent via the CookieYes cookie banner. Fonts are self-hosted; no external requests are made to Google Fonts or other CDN services.

10Processors and recipients

We share your personal data with the following service providers (processors) who process data on our behalf. We have concluded a data processing agreement with each processor in accordance with Article 28 GDPR.

ProcessorServiceDataCountrySafeguard
SupabaseDatabase, hosting, and authenticationAll stored dataEU/USData processing agreement + SCCs
StripePayment processingCustomer ID, subscription dataUSData processing agreement + EU-US Data Privacy Framework + SCCs
ResendEmail deliveryEmail address, name, email contentUSData processing agreement + EU-US Data Privacy Framework + SCCs
CloudflareCAPTCHA verification (Turnstile)IP address, browser characteristicsUSData processing agreement + EU-US Data Privacy Framework + SCCs
PostHogProduct analytics and session recordingsAnonymized usage events, session recordings (all text and input masked); with consent to advertising cookies, also the Meta browser ID (_fbp) and the Meta ad-click time (_fbc)EUData processing agreement
SentryError monitoringError messages, stack traces, performance metrics, a pseudonymous user ID and session recordings (all text, input and media masked)USData processing agreement + EU-US Data Privacy Framework + SCCs
GoogleOAuth authentication (sign in with Google)Email address, name (only when using Google sign-in)USData processing agreement + EU-US Data Privacy Framework + SCCs
CookieYesConsent management (cookie banner)Consent preferencesEUData processing agreement
GoogleWebsite analytics (Google Analytics 4 via Google Tag Manager)Page views, visitor statistics, Core Web Vitals (anonymized)USData processing agreement + EU-US Data Privacy Framework + SCCs
MicrosoftSession recordings and heatmaps (via Google Tag Manager)Click and scroll behavior, session recordings (text masked)USData processing agreement + EU-US Data Privacy Framework + SCCs
MetaAdvertising measurement (Meta/Facebook Pixel via Google Tag Manager)Page views, conversion eventsUSData processing agreement + EU-US Data Privacy Framework + SCCs
VercelHosting, CDN, and application deliveryIP address, browser characteristics, and technical request dataUSData processing agreement + EU-US Data Privacy Framework + SCCs
GoogleAddress autocomplete and map display for club locations (Google Maps Platform)Entered address searches, club location (coordinates), IP addressUSData processing agreement + EU-US Data Privacy Framework + SCCs
YouTubeEmbedding instructional videos (loads only when you play a video)IP address, video and playback dataUSData processing agreement + EU-US Data Privacy Framework + SCCs
VimeoEmbedding Vimeo videos (loads only when you play a video)IP address, video and playback dataUSEU-US Data Privacy Framework + Standard Contractual Clauses (SCCs)

SCCs = Standard Contractual Clauses: contractual safeguards approved by the European Commission for international data transfers (Implementing Decision (EU) 2021/914). The EU-US Data Privacy Framework is an additional safeguard: US organizations certified under the framework provide an adequate level of protection for personal data transferred from the EU (European Commission adequacy decision of 10 July 2023).

To display country flags, we load static images from a public flag CDN (flagcdn.com). This only exposes the IP address that every internet request requires; no account data is shared.

If you turn on push notifications, the push service of your own browser or operating system delivers them (Google, Apple, Mozilla or Microsoft). That service receives only the address at which your device can be reached and an encrypted message: it cannot read the content of the notification, and no account data is included. If you turn push notifications off, nothing is sent to these parties.

11International transfers

Some of our service providers are based in the United States. This means that your personal data may be processed outside the European Economic Area (EEA).

To ensure an adequate level of protection, we use:

  • Standard Contractual Clauses (SCCs): Standard contractual clauses approved by the European Commission in accordance with Implementing Decision (EU) 2021/914.
  • EU-US Data Privacy Framework: Some of our US-based processors are certified under the EU-US Data Privacy Framework, which provides an adequate level of protection under the European Commission’s adequacy decision of 10 July 2023.
  • Data processing agreements: Written agreements have been concluded with all processors that comply with Article 28 GDPR.
  • Additional technical measures: Encryption of data in transit and at rest.

12Children

JudoLytics is intended for judokas and coaches of all ages. Judo is a sport practiced from a young age, and we understand that minors may also use our platform.

In accordance with Article 8 GDPR and Article 5 of the Dutch GDPR Implementation Act (UAVG), consent from a parent or legal guardian is required for users under 16 years of age to create an account.

The platform offers the ability to enter recovery and health data (such as sleep quality and physical recovery). For minor users, the parent or legal guardian must give consent for the processing of this special category of personal data.

We do not actively verify age at registration. If we become aware that a minor is using our platform without parental or guardian consent, we will delete the relevant account and associated data. Parents or guardians can contact us at info@judolytics.com.

13Changes

We may update this privacy policy from time to time, for example in response to new features, legal obligations, or changes in our service.

For substantial changes, we will inform you via:

  • An email notification to the email address we have on file
  • A notification within the application

The "Last updated" date at the top of this page is updated with each change. We recommend reviewing this privacy policy regularly.

14Contact and complaints

Do you have questions about this privacy policy or about the processing of your personal data? Please contact us:

Bloei.ai

Email: info@judolytics.com

Address: Clavisstraat 33, 6515GA, Nijmegen, Nederland

Chamber of Commerce: 66950376

If you believe that we are not processing your personal data correctly, you have the right to file a complaint with the Dutch Data Protection Authority:

Dutch Data Protection Authority (Autoriteit Persoonsgegevens)

Postbus 93374, 2509 AJ Den Haag

Phone: 088 - 1805 250

Website: autoriteitpersoonsgegevens.nl

This privacy policy has been drawn up in conjunction with the Terms of Service of JudoLytics. In case of conflict between this privacy policy and the Terms of Service, this privacy policy prevails insofar as it concerns the processing of personal data. Terms of Service