Privacy Policy
Version 1.0 · Last updated 19 August 2026
1. Who is responsible for your data
Jiu Jitsu Science is owned and operated by a sole trader established in the Hong Kong Special Administrative Region ("the Operator"), who is the data user (Hong Kong PDPO) and data controller (UK and EU GDPR) for the personal data described here.
The Operator's full legal name and address are available on request from [email protected] and are provided without charge to anyone who asks. If you are in the EEA or the UK and want the controller's identity before deciding whether to register, email us and we will send it before you sign up.
Contact: [email protected]
This policy explains what we collect, why, who we share it with, and what you can do about it. It applies to jiujitsu.science and any subdomain.
2. What we collect
2.1 Information you give us
| Data | When |
|---|---|
| Email address | Registration |
| Password (stored only as a salted hash — we never see it) | Registration, if you use email sign-in |
| Name and profile picture, if you sign in with Google | Registration via Google |
| Billing name, country, and payment method details | Subscribing |
| Anything you write to us | Support, enquiries |
2.2 Information we collect automatically
| Data | Why it exists |
|---|---|
| IP address | Every web request carries one |
| Browser, device type, operating system | Sent by your browser |
| Session identifiers and authentication cookies | Keeping you signed in |
| Sign-in times, sign-in method, and failed attempts | Account security |
| Which videos and pages you open, when, and for how long | Playback and product analytics |
| Number and origin of concurrent playback sessions | Enforcing the subscription terms — see 3.4 |
| Approximate location derived from IP (country/city level) | Fraud and sharing detection; we do not use precise GPS location |
2.3 What we do not collect
We do not receive or store full payment card numbers — those go directly to our payment provider. We do not sell personal data. We do not use advertising trackers or third-party ad networks, and we do not build advertising profiles.
3. Why we use it, and our legal basis
| Purpose | Legal basis (GDPR) |
|---|---|
| Creating and running your account | Performance of a contract |
| Taking payment and managing your subscription | Performance of a contract |
| Sending service email — confirmations, password resets, billing notices | Performance of a contract |
| Keeping the Platform secure and investigating abuse | Legitimate interests |
| Detecting and preventing account sharing, credential sharing and piracy | Legitimate interests |
| Understanding which content is used, to decide what to make next | Legitimate interests |
| Meeting legal and tax obligations | Legal obligation |
Where we rely on legitimate interests, we have considered your rights and concluded our interest does not override them. You can object — see section 8.
3.4 Monitoring for account sharing, explained plainly
Access to paid content is licensed to one named individual, and shared accounts are the main way a platform like this loses the ability to keep making content. So we monitor for it, and you should know exactly how.
We look at signals attached to your account: how many playback sessions are running at once, how many distinct devices and IP addresses appear over a short window, the geographic spread between them, and patterns of simultaneous use that a single person could not produce.
If those signals indicate sharing, we may limit concurrent streams, require re-authentication, suspend the account, or terminate it under the Terms and Conditions.
Two commitments about this. First, a human reviews before any account is terminated — no account is closed by an automated score alone. Second, if we get it wrong, tell us at [email protected] and we will look again; you also have the right under section 8 to contest the outcome.
4. Who we share it with
We use third-party providers to run the Platform. Each receives only what it needs, and each is bound to protect it.
| Provider | What it handles | Where |
|---|---|---|
| Supabase | Accounts, authentication, database | Singapore |
| Vercel | Website hosting, request logs, product analytics | Global edge network |
| Cloudflare | Video hosting and delivery, DNS, playback telemetry | Global edge network |
| Airwallex | Payment processing, subscription billing | Hong Kong / global |
| Resend | Sending account email | United States / EU |
| Sign-in, if you choose Google | Global |
We may also disclose personal data where we are legally required to, where it is necessary to establish or defend a legal claim, or to a buyer if the Platform is sold — in which case this policy continues to apply until you are told otherwise.
5. International transfers
We are in Hong Kong; our providers operate globally. Your data will be transferred outside your country, including outside the EEA and the UK.
Where data originating in the EEA or UK is transferred, we rely on the European Commission's Standard Contractual Clauses, or the UK International Data Transfer Addendum, as incorporated into our agreements with each provider.
6. How long we keep it
| Data | Retention |
|---|---|
| Account data | While your account is open, then 90 days after closure |
| Billing and tax records | 7 years, as required by Hong Kong law |
| Authentication and security logs | 12 months |
| Playback and sharing-detection signals | 13 months |
| Support correspondence | 24 months |
| Records of an account terminated for sharing or piracy | 3 years, to prevent re-registration |
7. Security
Passwords are stored as salted hashes and are never visible to us. Traffic is encrypted in transit. Access to production systems is limited and protected by multi-factor authentication. Payment details never touch our servers.
No system is perfectly secure. If a breach affects your personal data and is likely to cause you harm, we will notify you and any relevant regulator as the law requires.
8. Your rights
Depending on where you live, you may have the right to:
- access the personal data we hold about you;
- correct data that is inaccurate;
- erase data, where we have no overriding basis for keeping it — note that billing records and records of terminated accounts are usually kept, see section 6;
- object to processing based on legitimate interests, including the sharing detection described in 3.4;
- restrict processing while a dispute is resolved;
- port data you gave us, in a machine-readable format;
- withdraw consent where we relied on it;
- not be subject to a decision based solely on automated processing that significantly affects you — which is why a human reviews terminations.
Write to [email protected]. We will respond within 30 days. You do not have to pay to exercise these rights.
If you are unhappy with our response, you may complain to the Office of the Privacy Commissioner for Personal Data, Hong Kong, or to your local supervisory authority if you are in the EEA or the UK.
9. Cookies and similar technologies
We use:
- Strictly necessary cookies — to keep you signed in and to protect the session. The Platform does not work without these.
- Analytics — aggregated, privacy-preserving page and playback metrics that tell us which content is watched. We do not use cookie-based cross-site tracking or advertising cookies.
You can block cookies in your browser, but you will not be able to sign in.
10. Children
The Platform is not intended for anyone under 18 and we do not knowingly collect personal data from children. If you believe a child has given us personal data, write to [email protected] and we will delete it.
11. Changes
We may update this policy. The "last updated" date above will change, and for material changes we will email the address on your account before they take effect.
12. Contact
Privacy and data requests: [email protected] Account security: [email protected]