Black Belt
Black Belt is a private Brazilian jiu-jitsu training journal. Your live journal is stored on your device. We don't operate an account or hosted training-journal database.
Training sessions, profile and rank history, goals, focus records, competition records, check-ins, return plans, and imported wellness summaries are stored in the app's local database. There is no public profile, feed, messaging system, or advertising profile.
We don't upload journal content to a Black Belt database. Two features can move data outside the app only when you choose them:
Black Belt uses RevenueCat to operate its App Store subscription. RevenueCat processes App Store purchase history and an anonymous RevenueCat app user ID for app functionality. Black Belt doesn't identify that ID with your name or email and doesn't send RevenueCat your journal, profile, or health data.
The App Store privacy manifest declares Purchase History and User ID as data not linked to you, used for App Functionality, and not used for tracking.
You can tag a session with a place, only when you ask for it. The tag (a name and coordinates) is stored in your local journal on your device and is not uploaded to a Black Belt database. If you choose Use current location, iOS asks for when-in-use permission and the app takes a single location fix, then sends those coordinates once to Apple's location service to look up a place name; that request is handled by Apple under its own privacy terms. Choosing a saved place or dropping a pin never contacts that service. Tags are excluded from the optional sanitized iCloud backup unless you turn on Back up location tags. You can revoke location access in iOS Settings, and tagging is never required to log a session.
If you connect Apple Health, Black Belt reads the categories you enable only after iOS permission: workouts, sleep, heart and recovery metrics, steps, and active energy. Heart-rate and active-energy readings across an eligible manual session can fill its empty heart-rate and calorie fields. Black Belt can write a jiu-jitsu workout only when you choose that separate option. A persisted Health connection can register hourly background delivery; Apple decides when an update is delivered. Raw imported measurements stay in the local journal and the system Health store. The optional sanitized iCloud backup can retain provider-derived session metadata and reconciliation identifiers as described above. You can narrow or revoke access in iOS Settings, and manual logging keeps working.
If you connect WHOOP, wellness API requests travel between the app and WHOOP. OAuth tokens are stored in the device Keychain.
A Cloudflare OAuth broker receives an authorization code, refresh token, or access token only long enough to exchange, refresh, or revoke it with WHOOP. It doesn't persist those values and returns no-store responses. A separate App Attest verifier stores a device public key, assertion counter, registration timestamp, and short-lived server-issued registration or migration nonce. Request proofs use two-minute stateless challenge tokens bound to the key, method, route, and SHA-256 body digest, so no request record, OAuth body, or OAuth token is stored. Per-key counters live inside a fixed set of Cloudflare coordination shards. The verifier derives a SHA-256 digest from the source network address for public-route rate limiting. During new-key registration it also temporarily stores that digest, a ten-minute window start, and an admission count. It doesn't store the raw address. The private key never leaves Apple's Secure Enclave. The verifier receives the one-time Apple attestation object during key registration but doesn't retain its receipt or call Apple's fraud-metric service.
The Workers necessarily process network metadata, such as an IP address, for rate limiting. The hashed address remains pseudonymous network metadata rather than anonymous data. Application logs are designed to contain generated request IDs, routes, and bounded error types rather than tokens, assertions, health data, or journal data. Cloudflare is the hosting processor. WHOOP use is also governed by WHOOP's privacy policy.
Apple's MetricKit framework can deliver crash and hang reports to the app. Black Belt keeps at most 25 local records for at most 30 days. It doesn't upload them. Settings → Diagnostics lets you view, export through the share sheet, or clear them.
Black Belt can schedule training reminders, streak-at-risk notices, weekly recaps, and welcome-back notices on your device. It asks for notification permission only after you enable a reminder or choose Allow notifications.
Training reminders use generic copy. Retention notices can include session or streak counts, but never partner names, competition details, notes, health measurements, or wellness/recovery values. Notification settings stay on the device and are removed by Erase All Data.
Restore validates a selected archive before replacing the local journal and applies the swap before the store reopens. An invalid, incompatible, or interrupted restore leaves the existing journal available.
Manual export, restore validation, and diagnostics sharing use app-owned temporary copies. Black Belt removes an export when its share sheet closes and removes restore staging after cancel, failure, or commit. Erase All Data also sweeps the app-owned temporary prefix families before it erases the journal; a cleanup failure leaves the journal available for retry.
Restore and Erase All Data show an operation-specific progress surface and disable the rest of the app while they finish. Conflicting or stale Local Journal actions are rejected, a duplicate erase joins the active erase, and a restore won't replace the journal while an iCloud backup mutation is active.
Erase All Data is an explicit confirmed action. It removes the local journal, WHOOP tokens, the local App Attest key identifier, notifications and preferences, Health import-category choices, diagnostics, pending restore, owned temporary artifacts, and the production or Beta iCloud backup artifacts before reporting success. The app confirms cloud absence through iCloud metadata; unavailable, cancelled, or timed-out confirmation keeps erase retryable. It also attempts to delete workouts Black Belt created in Apple Health when Health access permits, then removes local Health import anchors. The anonymous subscription cache remains because it isn't journal data. The verifier's residual public-key and replay record remains because the current protocol has no authenticated remote-delete operation; it contains no journal, health data, token, or WHOOP account association.
The app contains no analytics SDK, advertising identifier, tracking domain, or third-party crash-reporting SDK. RevenueCat is the only app-target third-party SDK and is used for subscription entitlement. Black Belt's privacy manifest declares no tracking.
If behavior changes in a way that affects this policy, we will update this page and its effective date before shipping the change.
Questions about privacy: support@andeslabs.ai