1. Information we collect
What we collect depends on the OFFMAT features you choose to use.
- Account and profile: name, email address, authentication and account identifiers, profile name, avatar, belt, weight or weight class, training preferences, goals, competition information, and academy membership or role.
- Training and athlete context: session logs, techniques, partners, notes, reflections, game organization, progress, competition planning, recovery, injury, fatigue, nutrition entries, meal photos, and related information you choose to record.
- Community and communication: posts, comments, reactions, follows, blocks, reports, direct messages, voice reflections, and other content you choose to create or share.
- Media: photos, video, audio, voice recordings, and other files you choose to capture, upload, analyze, or share.
- AI features: prompts, messages, selected training context, transcripts, uploads, generated responses, derived coaching memory or patterns, and feedback you provide.
- Support: messages, bug details, attachments, and other information you send when asking for help, reporting content, or providing feedback.
- Technical and usage information: installation and application identifiers, device platform, browser or operating-system type, locale, time zone, app version and build, push token and notification preferences, feature events, diagnostic logs, and crash or error information.
OFFMAT does not request precise device location. Camera, microphone, and photo-library access are requested only when you choose a feature that needs them. Push notifications are processed only after you enable them, and you can change permission choices in device settings.
2. How we use information
We use information to:
- create, authenticate, secure, and support your account;
- record and organize training, reflections, progress, academy context, and community activity;
- host and deliver content, messages, media, and notifications you choose to use;
- provide requested AI coaching, transcription, media analysis, nutrition, and barcode features;
- personalize useful next actions and saved context where the feature supports it;
- diagnose failures, measure product reliability, prevent abuse, enforce our Terms, and protect users; and
- comply with applicable legal obligations.
We do not sell personal information. OFFMAT does not offer paid purchasing in the current public release.
3. Visibility and sharing
Private training reflections, recovery context, direct messages, and private AI context are not public by default. Content you post to a community, send to another user, or share with an academy is visible to the audience shown by that feature. Academy administrators may see membership and operational information needed to manage their academy, but private athlete context is not made visible simply because someone is an administrator.
We may disclose limited information where reasonably necessary to investigate abuse, protect users or the Service, enforce our Terms, comply with law, or complete a business transaction subject to appropriate safeguards.
4. Service providers
OFFMAT uses the providers below only for the listed operations and only when the corresponding production service or feature is configured and used. If a feature is unavailable or you do not invoke it, information is not sent to its feature-specific provider for that purpose.
- Supabase — account and product infrastructure: receives account and authentication identifiers, profile and training records, community and message data, uploaded media, AI records, support-related metadata, and technical events as needed to provide authentication, database, file-storage, realtime, and backend-function services.
- Vercel — public website delivery: receives website requests, IP address, request headers, browser or device metadata, and information submitted to OFFMAT’s website endpoints as needed to host, secure, and deliver the website and its serverless routes.
- Namecheap Private Email — support communications: receives sender and recipient addresses, subject lines, message content, attachments, timestamps, mail headers, mailbox identifiers, and delivery metadata when you contact OFFMAT by email. It is used to receive, store, protect, and send support, bug-report, safety, privacy, and account-deletion communications. Messages remain in OFFMAT’s support mailbox only while reasonably needed for the request, security, disputes, or legal obligations, subject to the provider’s operational backup and retention processes.
- Google Identity Services — optional website sign-in: receives the Google identity token and account identifier involved when you choose Google sign-in on a supported OFFMAT website surface.
- Expo, Apple, and Google — app delivery and notifications: receive app-distribution information and, when notifications are enabled, push tokens and delivery metadata needed to deliver notifications. Apple or Google also processes the account and device information involved in downloading the app through its store.
- Sentry — error diagnosis: may receive sanitized stack traces, error details, app version, device or platform details, and diagnostic context when production error reporting is configured. OFFMAT disables default personal-data attachment and performance tracing in its app configuration.
- OpenAI and Google Gemini — requested AI features: may receive the prompt, selected training context, transcript, image, or other content needed for the AI feature you invoke, along with the generated response and limited technical metadata needed to return it.
- Rork Toolkit — requested app-assisted processing: may receive the specific text, image, nutrition, schedule, or other feature input you submit when an OFFMAT feature is implemented through that service, plus the output needed to return the result.
- OFFMAT’s Render-hosted media-processing service — requested media analysis: may receive uploaded video or image content, its storage locator, processing request identifiers, and generated analysis needed to perform a media feature you request.
- Cloudflare Turnstile — abuse prevention: may receive IP and network information, browser or device signals, challenge interaction data, and a verification token when the public AI Coach requires an abuse check.
- Google Tag Manager and Google Analytics — limited public-site measurement: may receive consent state, allowlisted page or interaction events, and browser, device, and request metadata on public marketing and BJJ guide pages. OFFMAT’s website integration excludes account, coaching, message, media, and content identifiers from those events.
- Open Food Facts — optional barcode lookup: receives the barcode or food-product query needed to return reference information. OFFMAT does not send your OFFMAT account identity with that lookup.
Providers process information under their own legal obligations and our applicable agreements. OFFMAT may process information in countries other than yours and uses appropriate transfer safeguards where required.
5. Website analytics and AI Coach
Marketing and guide pages
On OFFMAT’s public marketing and BJJ guide pages, Google Tag Manager may route a limited, allowlisted set of website events to Google Analytics 4. Consent Mode defaults analytics and advertising storage to denied. This integration does not enable advertising features or session replay.
AI Coach website
AI Coach pages are outside that marketing-analytics boundary: Google Tag Manager is not loaded on those AI surfaces, and coaching prompts, answers, photos, credentials, email addresses, user or guest identifiers, request identifiers, and continuation codes are not sent to Google Analytics through our website integration.
When the public AI Coach and its guest flow are available, OFFMAT processes the messages and uploads you submit, generated answers, technical request data, time zone, essential session or recovery tokens, and hashed network or device risk signals used to prevent abuse. Guest conversations stay in that browser unless you explicitly use a supported continuation or account flow. When the server-side cleanup rules for that guest flow are enabled, uploaded guest attachments are scheduled for removal after 24 hours and inactive unclaimed guest threads after 90 days. Cloudflare Turnstile may process verification data when a challenge is required.
For account-based AI features, OFFMAT may retain prompts, selected training context, uploads, generated responses, derived coaching memory or patterns, and feedback with your account until you remove supported AI history or memory, request account deletion, or the information is no longer reasonably needed for the feature, security, disputes, or legal obligations. Feature-specific temporary files may be removed earlier.
AI output is generated from the content and context submitted for the requested feature. It can be incomplete, inaccurate, or unsuitable, and it may not reflect the full context of a training situation. Use your own judgment and qualified coaching where appropriate. OFFMAT’s AI is not a medical authority, does not diagnose or treat injury or illness, and must not be relied on for an emergency or medical decision.
6. Retention and deletion
We keep information only for as long as reasonably needed to provide the Service, secure accounts, preserve user-requested history, investigate abuse, resolve disputes, and meet legal obligations. The period varies by data type and purpose.
When account deletion is requested and confirmed, OFFMAT restricts access and begins server-side cleanup. Private profile, training, social, and AI information is deleted or anonymized. Shared conversations, posts, comments, messages, competition history, or necessary academy context may retain non-identifying structure so another person’s record does not break; the deleted member is shown generically as “Deleted Athlete”. Media owned only by the deleted account is removed when ownership can be established safely. Limited records may be retained where necessary for security, fraud prevention, disputes, or legal obligations.
Deletion is not represented as complete until OFFMAT confirms the server process has finished. See the Delete Account page for the exact app and external request paths.
7. Your choices and rights
You can update profile and preference information in the app, choose the audience for supported sharing features, change device permissions, turn push notifications off, remove supported AI conversations or memory, report or block community activity, and request account deletion.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal information we hold. We may need to verify that a request belongs to you. Contact support@offmat.app for a privacy request.
8. Security and transfers
We use administrative, technical, and organizational safeguards designed to protect information, including access controls and transport encryption. No system can guarantee absolute security. Keep your credentials and verification codes private, and contact us if you believe your account has been compromised.
9. Changes and contact
We may update this policy when the Service, law, or our practices change. We will publish the updated text and date here and provide additional notice where required.
Privacy, legal, and account-support contact
Email: support@offmat.app
OFFMAT is operated by Yassin Gamil and Youssef Roshdy, trading as OFFMAT.