Privacy Policy
The Japanese Privacy Policy is the original text. This English version follows it faithfully, and adds Sections 13–14 for users outside Japan. If the two versions conflict, the Japanese version prevails, except where the mandatory law of your place of residence provides otherwise.
Sports Reflection Journal (VoiSpo; “the app”) is an app for recording reflections on practices and games by voice or keyboard. This policy explains how the app handles your information.
Operator (data controller): Catalyst Inc. (株式会社カタリスト)
Mitsuhashi Bldg. 3F, 1-3-3 Kita-Aoyama, Minato-ku, Tokyo 107-0061, Japan
Contact: support@sports-reflection-journal.com
1. Where your notes are stored
Your practice notes (the original text, AI-tidied text, categories, photos, and so on) are all stored in a database on your device. They are not stored on our server (except for encrypted data kept when you turn on the optional cloud backup — see Section 6). There is no account registration, and we do not collect information that identifies you personally, such as your name or email address. We do, however, handle an anonymous identifier on our server to manage AI usage limits and friend referrals (Sections 9 and 10). Your reflections may include information about your physical and mental state — condition, injuries, fatigue, mood. Like everything else you record, it is stored only on your device, and the app never sends it off the device except in the cases described below (AI organizing, form video analysis, and cloud backup).
Files stored on your device may be included in the device backup features provided by your OS (iCloud Backup on iOS, device-to-device transfer on iPhone / iPad, and the like). This is not a transmission by the app; it follows your own OS settings. On Android, the app opts out of the OS automatic backup (allowBackup=false) so that its data is not included. If you do not want the app included in your iOS device backup, turn off its backup in the OS settings.
2. How your voice is handled
Speech recognition uses only the standard speech-recognition service of your OS (iOS / Android). Depending on the OS, recognition runs on the device or on the OS vendor’s servers, and may use a network connection. The app itself never sends audio data (recordings) to our server. A recording is saved only if you turn on the setting “Keep the voice” (off by default), and it is stored only on your device. Recordings are never sent to our server or to the AI, and they are not included in the optional cloud backup (Section 6). Backups of the device itself are handled as described in Section 1.
3. Place, weather, and map (optional; off by default)
You can attach the name of the place you were at, the weather, and a small map image to a note. The three settings — place, weather, and map — are all off by default, and the app does not read your location unless you turn them on. The first time you turn one on, the app shows a screen explaining what is sent where, and then asks for the OS location permission. You can turn them off anytime under Settings → “Place & weather”, and remove the chip from any single note with ×. Your location is read only while the recording screen is open — never in the background. Reading your location and converting it to a place name (city / town) is done by the OS location service and may use a network connection, per the OS.
The app sends location data off your device in only the two cases below. In both cases, the text of your note, the place name, and the note’s identifier are never sent together with the coordinates. Place and weather are not sent to AI organizing (Section 4) or to form video analysis (Section 5) either.
- If you turn on attaching the weather: coordinates rounded to about 1 km and the time of the note are sent via our API server to Apple’s weather service (WeatherKit), and the weather and temperature come back
- If you turn on attaching a map: once, when the note is saved, coordinates rounded to the granularity needed to draw the map image (roughly 100 m — finer than the weather) are sent via our API server to Apple’s map service (Apple Maps), and a map image comes back. The image is stored on your device and shown from there, so coordinates are not sent again each time you re-read the note
Our API server does not store the coordinates it receives and does not write them to logs (it keeps no error logs containing coordinates either). Coordinates are sent in the request body or headers, never in the URL. For weather only, to batch queries from the same area and time window, the rounded coordinates and the weather result are held in the server’s memory for at most 10 minutes (never written to disk or a database, and never linked to anything that identifies you). Note that rounding the coordinates is not a guarantee that you cannot be identified. We round them to keep what leaves your device to a minimum; what we can promise is the “no storage, no logging” described above.
On the other hand, the un-rounded coordinates, the place name from the OS, the place names you typed yourself, and the received map images are stored on your device (we never store them on our server). You can delete them with “Delete all data” (Section 11) or by uninstalling the app. To delete just a place name, you can remove it individually under Settings → “Place & weather”. If cloud backup (Section 6) is on, the coordinates, place names, and your own labels are kept encrypted on your device first, the same as notes and photos (map images are not included in the backup — they stay on the device only).
If you revoke the location permission in the OS settings, the app stops reading your location, and later notes will no longer get a place, weather, or map (notes already saved are unchanged).
4. AI organizing (optional; you can turn it off)
When AI organizing is on, the text of the note you saved — plus some context that improves the organizing — is sent via our API server to Google’s Gemini API. What is sent:
- The text of the note (the speech-recognition result, or what you typed)
- The selected sport and context type (practice, game, and so on)
- Your tag names (category names)
- The text and deadline of your small goal
- The words in your frequent names & words list. These exist to fix speech-recognition misspellings, and may include the names of other people — teammates, coaches, clubs. You can remove any word from the list in Settings anytime
Other AI features exist, and they all travel the same route (our API server, then Google’s Gemini API). “Ask the AI supporter more” sends the text of that note plus your question. The weekly reflection and the practice-plan suggestion send not the text itself but the points the AI has already extracted from it (what went well, what to work on, the next step, and the like).
About this processing:
- We ask for your consent on first launch, and you can turn it off anytime in Settings (everything else — recording and reading — keeps working with it off)
- Our server does not store the text and does not write it to logs
- We use a configuration (a paid API) in which the AI input is not used to train AI models
- Photos are never sent to the AI (they stay on your device, and are kept — encrypted — only if you turn on cloud backup)
- To manage usage limits, however, an anonymous identifier and the time of use are recorded on our server (Section 9)
5. Form video analysis (optional; explicit action only)
In versions where form video analysis is available, a video is sent for analysis to Google’s Gemini API directly from your device (it does not pass through our server) — and only when you explicitly choose that video and run the analysis. About this processing:
- We ask for your consent on first use. It never runs automatically
- After the analysis completes, our server asks Google to delete the uploaded video
- We use a configuration (a paid API) in which the AI input is not used to train AI models
- The video file itself is stored only on your device and is never stored on our server
6. Cloud backup (optional; off by default)
On the paid plan (Pro) you can use automatic cloud backup of your notes and photos (opt-in; nothing is sent unless you turn it on). When it is on:
- All notes and photos are encrypted on your device (AES-256-GCM) first, then sent to and kept on our server (the latest 3 generations)
- The key that decrypts the backup (your recovery code) exists only on your device and is never sent to us. No one — including us — can read the contents of your backup
- If you lose the recovery code, no one — including us — can restore the backup
- You can turn it off anytime, and you can delete the backup on the server anytime from inside the app
- The contents of the backup (text and photos) stay sealed, but we do handle incidental information such as its size and timestamps in order to store and operate it
7. Usage analytics (optional; you can turn it off)
To improve the app, we use the analytics service of PostHog, Inc. to collect anonymous usage data. Only behavioral metadata — “which features are used, and how much” — is sent (for example: a note was saved, AI organizing succeeded, a screen was opened, whether input was voice or keyboard, a rough length bucket of the text). About this measurement:
- The text of your notes, category names, goal text, and photos are never sent
- The only identifier is a random anonymous ID per device; it is never linked to your name, email address, or other personal information
- No advertising use, and no matching against third-party data (no tracking)
- You can turn it off anytime with the setting “Share usage data” (everything keeps working with it off)
Separately, to fix bugs, technical information at the time of a crash or error (the error, OS type, and the like) is sent to Sentry (Functional Software, Inc., USA). The text of your notes is never included, and turning off “Share usage data” stops this too.
The app contains no advertising SDKs.
Separately, if — and only if — you send us a message from “Feedback & issues” in the app, that message is sent to our server together with an optional reply address you choose to provide, your device type, and the app version. The text of your notes, your photos, and your videos are never sent with it. Nothing is sent unless you tap send on that screen.
8. In-app purchases
Payments for in-app purchases (subscriptions) are processed by Apple or Google; we never receive your payment details such as credit card numbers. We use RevenueCat, Inc. to manage purchase state, and an anonymous identifier plus purchase information (the plan purchased, purchase date, and so on) is sent to RevenueCat. The text of your notes is never sent to RevenueCat. The same anonymous identifier is attached to AI organizing requests to confirm purchase state.
We also pass the anonymous identifier issued by the analytics service in Section 7 to RevenueCat as a customer attribute, so that purchases can be counted as belonging to the same person as the usage data. We do this only while the “Share usage data” setting is on; turning it off deletes that identifier from RevenueCat as well, and we stop passing it.
Running the app setting “Delete all data” also deletes this purchase record on RevenueCat (the anonymous identifier and purchase history). Note that deleting your data does not cancel your subscription (cancel it from your App Store / Google Play subscription settings), and a purchased plan can be brought back anytime with “Restore purchases” in the app.
9. Managing AI usage limits
AI features have usage limits — per day, per week, or per 30 days, depending on the feature — so that everyone can use them fairly. To count usage, our server records the anonymous identifier from Section 8, the feature used, and the time of use. The text of your notes, your photos, and your videos are never part of this record.
- We record only “which feature, when”; it is never linked to your name, email address, or anything similar
- Records older than a set period are deleted the next time the same person uses the same feature
- Running “Delete all data” in the app deletes this record too (Section 11). If you uninstall without running it, the record remains on the server
10. Friend referrals (invite codes)
If you use the friend-referral feature, our server stores the information below. The text of your notes, your photos, and your videos are never involved.
- For the person who issued an invite code: the anonymous identifier from Section 8, the code, and when it was issued
- For the person who entered an invite code: the anonymous identifier from Section 8, the code entered, when it was entered, and when the reward was granted
The referrer sees only the number of people who used their code. Neither side can ever see the contents of the other’s notes. We keep these records to prevent duplicate rewards and abuse; they are deleted once 400 days have passed since their last use, and running “Delete all data” in the app deletes the records about you at that moment (your own invite code and its usage records are deleted together — Section 11).
11. Deleting your data
Because your data (practice notes and photos, plus the coordinates, place names, and map images of Section 3) lives on your device, you can delete it yourself with the app setting “Delete all data” or by uninstalling the app. If cloud backup was on, you can also delete the backup on the server anytime with “Delete the cloud backup” inside the app (uninstalling alone does not delete the encrypted backup on the server — if you want everything gone, delete it before uninstalling). The RevenueCat purchase record of Section 8 is also deleted as part of “Delete all data” (cancelling the subscription itself must be done on the store side, and a purchased plan can be restored with “Restore purchases”).
The server-side records described in Section 9 (AI usage limits) and Section 10 (friend referrals) are also deleted as part of “Delete all data”. If deletion cannot finish right away — a connection problem, for example — only the anonymous identifier is kept on the device, and deletion is retried automatically the next time the app starts. Uninstalling alone does not delete these server-side records, so if you want everything gone, run “Delete all data” before uninstalling. For any question about deletion, contact us via Section 16.
12. Use by minors
Children under 13 may not use the app. If you are a minor, use it with the consent of a parent or legal guardian (Terms of Service, Section 2). The app is not directed to children under 13, and we do not knowingly collect personal information from children under 13 — because there are no accounts, the app does not ask for a name, birthday, or contact details in the first place. If you believe a child has used the app and information about them has reached our server, contact us via Section 16 and we will delete it.
13. International data transfers
We operate from Japan, and the service providers named in this policy (Apple, Google, RevenueCat, PostHog, Sentry) process data in the United States and other countries. The limited information described in this policy may therefore be processed outside your country of residence. Wherever it is processed, it remains subject to the commitments in this policy — and the strongest protections here do not depend on location: your notes stay on your device, and a cloud backup is encrypted on your device before it leaves. If you are in the EU/EEA or the United Kingdom, note that Japan is recognized as providing an adequate level of data protection (European Commission adequacy decision 2019/419 and the corresponding UK adequacy regulations).
14. Your privacy rights
Depending on where you live — for example the EEA, the United Kingdom, or certain US states — the law may give you rights over your personal information, such as the rights to access, correct, delete, or receive a copy of it, and to object to or restrict some processing. The app is built so that you can exercise the substance of these rights directly: your notes live on your device, where you can read, edit, and delete them anytime; “Delete all data” also deletes the server-side records described in Sections 8, 9, and 10; and you can delete the cloud backup anytime from inside the app (Section 6). For anything the in-app controls do not cover, contact us via Section 16.
Two honest limitations that follow from the app’s design:
- Because there are no accounts, we usually cannot link server-side records to a person without the anonymous identifier (we will explain how to find it when you contact us)
- We cannot read or produce the contents of an encrypted cloud backup for anyone — including you — without your device or recovery code
We do not sell your personal information, we do not share it for targeted advertising, and we do not use it for profiling that produces legal or similarly significant effects. If you live in the EEA or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.
15. Changes to this policy
If we revise this policy, we will publish the revision on this page. Important changes will also be announced in the app.
16. Contact
Questions about this policy: support@sports-reflection-journal.com
Established: July 5, 2026 / Last revised: August 30, 2026