ArcheryNow Privacy Policy
Last updated and effective: August 29, 2026
Document version: 2026-08-29-club-service-access-v1
Club invitation privacy notice key for this document: club-join-2026-08-29
Language: This English translation is provided for convenience. If it conflicts with the Japanese Privacy Policy, the Japanese text prevails for governing-law interpretation.
ArcheryNow (the “App”) respects your privacy. This policy describes the App's current data handling, including the free, time-bound Club Beta. It is implementation-aligned general information, not legal advice. The canonical page is the ArcheryNow legal site on kitokito.app; see also the Terms of Service.
1. Scope and local-first boundary
This policy applies to the iOS and Android App. Core personal scorekeeping is local-first: scores, ends, arrows, plot positions, sessions, templates, goals, settings, notes and personal media remain on your device and, when you choose Pro sync or backup, in your iCloud or Google Drive account.
The hosted Club, Team, sharing and Selection Event features are a separate boundary. When you create or use a Club Account, selected information is processed on ArcheryNow's hosted service. Joining a Club does not upload or share your existing personal history automatically. Only records you expressly share or submit are copied to the hosted Club service.
2. Information we process
2.1 Personal and device data
- Personal score records, sessions, templates, goals, notes, plot data, media and App settings stored locally.
- iCloud or Google Drive backup/sync data when you choose the corresponding feature.
- Technical settings needed to operate the App, such as language, appearance and default bow type.
Deleting the App or local data may remove device copies. Cloud copies follow the controls and retention of the cloud provider. Deleting a Club Account does not itself delete separate local, iCloud or Google Drive copies.
2.2 Club Account and authentication
The hosted Club boundary uses Supabase Auth, Database, Storage and Edge Functions.
Club features require a hosted Account. Depending on the enabled sign-in method, Supabase Auth, Apple or Google may process:
- an internal Account identifier and Supabase authentication identifier;
- the unique provider identifier supplied by Apple or Google;
- an email address or Apple private relay address if the provider supplies one;
- authentication method, session identifier, token and expiry metadata needed to create, refresh, secure and revoke a session; and
- sign-in security and abuse-prevention signals.
The App exchanges provider credentials with Supabase for verification and is designed not to retain Apple or Google provider credentials as the ArcheryNow session. The Supabase session is stored in protected device storage. See Supabase Privacy, Sign in with Apple & Privacy and Google Privacy Policy.
2.3 Profile and Club service eligibility
We process a display name, locale, time zone, generated avatar value and, if you upload one, a profile image. Your email address is not displayed in the Club directory.
Club Account setup does not require a general 18-or-older confirmation. We store the current Club service-policy version and the server-recorded time when service access was requested. This record is not a birth date, age declaration, age estimate, government-ID check or identity-verification claim. Where applicable law requires parental or guardian authorization, a minimum age or another safeguard for a particular user, region or feature, we may request the necessary information or limit access until the requirement is satisfied.
2.4 Club, Team, membership and invitation data
The hosted database processes Club and Team names and icons; membership and Team assignments; owner, administrator, coach and other roles; display roles and tags; status and revision history; invitations, expiry and redemption evidence; operational capability and feature-policy results; and security, idempotency and audit records.
An invitation may disclose the intended Club, Team and role before acceptance. The invitation recipient must expressly accept the displayed privacy notice version. Invitations and access are restricted to the intended scope and may be revoked or expire.
2.5 Expressly shared records
When you choose to share a personal session, the Club service may receive a versioned snapshot containing the selected round label, time, score, maximum score, arrow count, 10 and X counts, self-recorded/verified status and, when selected, structured scorecard and Arrow Plot payloads. It also stores the chosen audience: Club members, Team members or Team coaches.
A shared snapshot is separate from the source record on your device. You can revoke the hosted publication, subject to limited audit, integrity, safety and legal retention. Membership alone does not authorize access to all personal history.
2.6 Selection Event data
Where enabled, Selection Events process structured data such as the event name, eligibility, roles, dates and time zone; round, bowstyle, distance, target-face and arrow-count rules; selected session snapshots and arrow values; totals, 10s, Xs and other score metrics; review results; and decision or leaderboard rows. A leaderboard may use a display-name snapshot or an anonymous participant number, according to the event configuration.
This feature does not create a general public social feed or direct messaging service. Event retention is configured as 90, 180 or 365 days in the current contract, after which bounded cleanup may purge event payloads, subject to safety, audit, dispute and legal requirements.
2.7 Private Club media
If you upload a Club icon or member avatar, Supabase Storage processes the private image and metadata needed to validate, crop, authorize, replace and delete it, such as file type and size, dimensions, digest, object path, revision and lifecycle timestamps. Access is limited by Account, membership and role authorization; uploads use short-lived authorization. Replaced, failed, expired and deleted objects are queued for cleanup.
2.8 Reports, blocks and moderation
Users can report a member/profile, shared record, Selection Event/submission or media item using a fixed reason category, and can block or unblock another Account. We process the reporter and target's opaque identifiers, Club and subject identifiers, reason category, block display label, status, correlation/idempotency values and timestamps. The current report contract has no free-text report body.
We use this information to apply block-based access restrictions, prevent blocked invitation or content interactions, investigate misuse, moderate content and preserve safety evidence. Reports may not result in a particular outcome, and necessary access may be limited while a matter is reviewed.
2.9 Free Club Beta and commercial state
For the v1.5.0 free Club Beta, we process a server-issued Pilot grant and Club contract state, plan and feature keys, limits and current usage, restrictions, period, provider type, revisions, short-lived entitlement snapshots and audited operator actions. The Pilot is generally available to eligible authenticated Accounts, remains time- and capacity-limited, and permits at most one Pilot Club per Account; App version alone does not create eligibility. Access remains subject to safeguards required by applicable law.
The Club Beta does not start a paid Club subscription and does not cause automatic billing when it ends. If a future paid Club offering is enabled, billing data may include an App Store product, purchase state, provider event and pseudonymous Account binding after the owner or billing manager expressly purchases it. RevenueCat is a possible provider for that later paid boundary; it is not the source of free Pilot eligibility.
Personal Pro is separate. Personal Pro purchase and entitlement data may currently be processed by Apple and RevenueCat, but Personal Pro does not by itself grant or bill a Club plan.
2.10 Ads, analytics, support and other services
- RevenueCat / Apple (Personal Pro and any expressly enabled future purchase): purchase, subscription and restore status, pseudonymous App user identifier and technical data. Payments are processed by the applicable store. See RevenueCat Privacy and Apple Privacy.
- iCloud / Google Drive: optional personal backup and sync, under the provider's controls.
- GitHub Issues: support, privacy requests and feedback; posts and public profile data are processed by GitHub. See GitHub Privacy Statement.
- On-device AI: where available, coach summaries and responses are generated on the device; the App does not send the conversation to ArcheryNow's server. Platform processing follows Apple's policies.
- Google AdMob / User Messaging Platform: ads, consent, fraud protection and measurement. Google may process advertising identifiers where permitted, IP address, device and ad interaction data, App-use signals and consent state. See Google Privacy Policy and Google advertising technologies.
- Google Analytics for Firebase: aggregated screen, feature, onboarding, score-flow and purchase-flow outcomes, App-instance identifier, App/OS/device technical information, logical screen names and bounded count/duration categories. Analytics events do not include names, email, Club/internal record IDs, scores, arrow order, plot coordinates, titles, locations, notes, tags, searches, AI text, media names or raw errors. You can stop future collection using the in-App Usage Analytics setting; this is separate from advertising consent. See Google Analytics for Firebase.
2.11 Tracking
AdMob may use advertising and usage data for delivery and measurement depending on consent and iOS App Tracking Transparency permission. If personalized ads are not allowed, non-personalized ads and aggregated measurement such as SKAdNetwork may still operate.
3. Purposes
We process information to provide and secure the App; authenticate Accounts; operate Clubs, Teams, invitations, sharing, Selection Events and private media; enforce roles, entitlements and quotas; prevent fraud and abuse; provide reporting, blocking, moderation, support, export and deletion; verify expressly initiated purchases; show ads according to choices; measure aggregated usage; diagnose failures; comply with law; and protect users and the service. We do not use Club content for unrelated advertising.
4. Disclosure and Club audiences
We do not sell personal information. Information may be disclosed:
- to authorized Club or Team members and coaches within the audience you select or the role-based event scope;
- to Supabase, Apple, Google, RevenueCat, GitHub and other processors described above as needed to provide the feature;
- when required by law or reasonably necessary to protect rights, safety, life, body or property; or
- in aggregated or de-identified form that does not reasonably identify a person.
AdMob personalized advertising may be considered “sharing” for cross-context behavioral advertising under some laws. Consent, OS and in-App privacy controls are provided where applicable.
5. Retention and deletion
- Local/iCloud/Google Drive data remains until you remove it, subject to the provider's controls.
- Active Club data is kept while needed to provide the Club service. A Club deletion is scheduled with a current seven-day recovery window before cleanup; authorized cancellation may be available during that window.
- Selection Event payloads use the configured 90/180/365-day retention and bounded cleanup described above.
- Pending, replaced or deleted private media is removed through a cleanup queue; short operational delay and retry are possible.
- Account deletion first checks ownership, billing-management, active-event and other integrity blockers. You may need to transfer ownership, close or cancel an operation, revoke a share, or otherwise resolve a listed blocker before deletion can finish.
- On finalization, authentication is detached, sessions are invalidated, memberships and active invitations/roles are ended, shared identity is removed or replaced with a deleted-participant label, Club service-eligibility records and profile media are removed, and the profile is de-identified. Separate local/cloud personal records remain under your control.
- We may retain minimum audit, security, moderation, transaction and integrity records when necessary. Billing references used for deletion safety, reconciliation, fraud prevention or legal obligations are detached from the raw Account and may be represented by an immutable HMAC-based pseudonymous tombstone. The tombstone does not contain the raw Account/Auth/Profile/email/Club identifier and cannot itself authorize access.
- Apple, Google, RevenueCat, Supabase and GitHub apply their own retention policies to data they process.
6. International transfers
Service providers may process data outside Japan, including in the United States or the selected Supabase project region. Their policies describe the locations and safeguards that may apply. If you do not want a provider to process the relevant data, you may be unable to use the corresponding authentication, hosted Club, billing, advertising, analytics, cloud or support feature.
7. Children and applicable age safeguards
The general App is not directed at children under 13, and we do not knowingly collect their personal information in circumstances where parental authorization is required. Club Account setup has no blanket 18-or-older confirmation. Depending on applicable law and the user's region or feature, parental or guardian authorization, a minimum age or another safeguard may be required, and access may be limited until that requirement is satisfied. Parents and guardians may use OS parental controls and contact us regarding child-related privacy concerns.
8. Your choices and rights
Depending on applicable law, you may request access, correction, deletion, restriction, portability or objection, withdraw consent, or complain to a supervisory authority. You can also manage sharing, leave a Club, revoke publications, block/unblock Accounts, export permitted data, change analytics/advertising choices and request Account deletion through available App controls. Identity verification may be required.
For Japan, EEA/UK and California rights, use the contact route below. We do not sell personal information; where AdMob activity is treated as “sharing,” available opt-out controls apply. We do not discriminate for exercising applicable privacy rights.
9. Security
We use reasonable technical and organizational measures, including private schemas and storage, role/resource authorization, short-lived signed access, row-level controls, idempotency, audit trails, credential redaction and bounded cleanup. No transmission or storage method is completely secure.
10. app-ads.txt and legal-site cookies
We publish app-ads.txt at the developer website root for AdMob authorized sellers. These static legal pages are generated with Astro and delivered from kitokito.app using Cloudflare infrastructure. We do not intend to set first-party cookies on them, although Cloudflare infrastructure may process technical request data, including cookies when present.
11. Changes
We may update this policy. The current effective date and document version appear above. We will try to give appropriate notice of material changes through the App, invitation notice, store notes or this site. A new Club invitation notice key must be deployed consistently across the displayed notice, client and server before it is accepted.
12. Contact
There is no public support or moderation email address. Use GitHub Issues or the applicable App Store developer support route. Avoid posting tokens, private invitations, sensitive personal information or private Club content in a public Issue.
The operator does not publish a legal name or street address in this policy or README. Any disclosure required by applicable law may be made through another legally permitted method after appropriate professional review.
This policy is interpreted under the laws of Japan.
For questions about ArcheryNow, please contact us from Support.