Last updated: 31 August 2026
This Privacy Policy explains how MatPilot Limited collects, uses, shares and protects personal data when you use the MatPilot mobile app, websites and related services (together, the "Service"). It applies wherever you are.
We do not sell your personal information, and we never have. We do not share it for cross-context behavioral advertising, we do not run advertising trackers on this site, and we do not use your academy's member data to train models. If you are in a state with a privacy law, that means most of what you would want to opt out of is something we do not do.
MatPilot applies one standard everywhere, and it is the strictest one we are subject to, rather than giving people in some states or countries fewer rights than people in others. Your rights under your own state's law are set out in clause 10, along with how to exercise them and who to complain to. Clause 4 covers children, including how we handle students under 13.
1. Controller & processor roles · 2. Data we collect · 3. How & why we use it (legal bases) · 4. Children · 5. Email & messaging · 6. Who we share with (sub-processors) · 7. International transfers · 8. Retention · 9. Your rights · 10. Your rights where you live · 11. Automated decisions & AI · 12. Security · 13. Cookies · 14. Operator data-processing terms · 15. Complaints · 16. Changes
MatPilot is used by martial arts academies, gyms and coaches ("Operators") to run their business, and by their students and clients ("Members"). Who is responsible for which data depends on the data:
If you are a Member and want to exercise your rights over data held by your academy, contact your academy (the controller) and we will help them respond.
We do not intentionally collect sensitive personal information (health, biometric, precise geolocation, or the other categories your state may define). If an academy chooses to record an injury note or similar health data about a member, the academy is the controller of it and is responsible for handling it lawfully, including any consent its state requires.
| Purpose | What this covers |
|---|---|
| Run the Service | Accounts, classes, bookings, attendance, billing, grading, messaging and support. For member data this is done on the academy's instructions. |
| Take payments | Subscription charges and platform fees, through Stripe. |
| Send account notifications | Transactional only: a payment received or failed, a trial converting, a new member joining. |
| Keep it secure and working | Preventing abuse and fraud, debugging, and improving reliability. |
| Keep required records | Financial, invoice, tax and audit records we are legally required to retain. |
| Features you turn on | Optional features that ask permission first, such as geofenced check-in. You can withdraw permission at any time. |
What we do not do, in any state: we do not sell personal information; we do not share it for cross-context behavioral advertising; we do not use it for targeted advertising; we do not profile you in a way that produces legal or similarly significant effects; and we do not use an academy's member data to train AI models. We collect only what the purposes above need, and keep it only as long as clause 8 says.
You must be at least 16 to create your own MatPilot account. That is higher than the Children's Online Privacy Protection Act (COPPA) requires, and deliberately so: we apply one minimum worldwide rather than a different one per country, and we set it above every threshold we are subject to. We do not knowingly collect personal information from a child under 13 directly, and a child cannot create an account.
Kids' programs are a large part of martial arts, so most academies do manage members who are minors. When they do, the child's record is created and controlled by the academy, not by the child, and the academy is responsible for obtaining and keeping verifiable parent or guardian consent before entering a minor's information, including their photograph. MatPilot provides the tools for this: a family portal where a parent or guardian holds the login and signs on the child's behalf, per-member photo-consent controls, and a warning to staff before a class photo including a minor without consent on file is posted.
If you are a parent or guardian and believe your child's information was entered without your consent, contact the academy, or email us at admin@matpilot.io and we will help get it corrected or deleted.
MatPilot sends transactional, account-related email only (for example: a payment
received or failed, a trial converting, a new member joining, grading ready). These
are triggered by activity in the account and include a List-Unsubscribe header.
We do not send marketing email through this channel and we do not email purchased
or scraped lists. Owner notifications can be turned off per category in-app. Email is
delivered via Resend; we suppress addresses that hard-bounce or complain. Any
member-facing messages an Operator sends must comply with the electronic-marketing
law that applies to its members. In the US that is the CAN-SPAM Act, the TCPA for text
messages (which requires prior express consent and working STOP handling), and your
state's own rules. Opt-outs must be honored.
If you receive a message through the in-app inbox that is harmful, offensive, or unlawful, you can report it directly within the app. We review reports promptly.
We do not sell personal data. We share it only with the service providers that help us run the Service:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting, database, authentication (Cognito), file storage | EU (Stockholm, eu-north-1) |
| Amazon Bedrock / Anthropic | AI assistant & co-pilot (processes limited member context: names, plan and payment status) | USA (us-east-1) |
| Stripe | Payment processing & subscriptions (independent controller for payment data) | EU / USA |
| Resend | Transactional email delivery | EU (Ireland) / USA |
| Expo | Push notifications & crash/update services | USA |
| Twilio | SMS / WhatsApp, only if an academy enables it | USA |
| Apple & Google | App distribution and optional federated sign-in | USA / EU |
Each is bound by a data-processing agreement. We may also disclose data where required by law, to establish or defend legal claims, or to protect the rights and safety of users.
MatPilot is operated from Ireland, and our core infrastructure runs on Amazon Web Services in the EU. Several providers process data in the United States: the AI features (Amazon Bedrock / Anthropic), push notifications (Expo), and parts of Stripe and Twilio. So your data crosses the Atlantic in both directions, and we tell you that plainly rather than burying it.
Every provider is bound by a written data-processing agreement, and the transfers are covered by appropriate safeguards: the European Commission's Standard Contractual Clauses (2021/914), the providers' own supplementary measures, and the EU–US Data Privacy Framework where a provider is certified to it. The protection does not depend on which side of the transfer you are on. We minimize what is sent (for the AI features, only the limited context noted above). You can ask us for more information about these safeguards.
| Data | Retention |
|---|---|
| Account & academy/member data | While the account is active; deleted on verified request, subject to the exceptions below |
| Financial, invoice & tax records | Retained as long as the tax and company law we are subject to requires, generally up to 6 years. Academies have their own retention obligations under federal and state law, which may be longer |
| Audit logs of changes | Up to 1 year |
| Backups | Rolling, then overwritten |
When we erase data, we remove or irreversibly anonymise it except where we must keep limited records (e.g. transaction IDs for tax) by law.
Wherever you live, and whichever law covers you, we give you the right to:
Exercise any of these in-app (you can update your details, manage notifications, and file an export or deletion request from your account), on our Data & privacy rights page (sign in to request a copy of your data, or delete some or all of it), or by emailing admin@matpilot.io. We respond within one month (extendable by two months for complex requests, with notice), free of charge in normal cases. For data held by an academy about its Members, we route the request to that academy as controller and assist it.
Clause 9 is what we give everyone, in every state, whether or not your state has passed a privacy law. Where your state has one, it names these rights specifically:
| Right | What it means here |
|---|---|
| Know / access | What we hold about you, where it came from, why we have it, and who we share it with. Clause 2 and clause 6 answer this in advance; you can also download the actual data from your account. |
| Delete | Delete your account, or specific categories of data without closing it. Some financial and tax records must be retained (clause 8) and we will tell you which. |
| Correct | Fix anything inaccurate, mostly editable directly in the app. |
| Portability | Get your data in a machine-readable file you can take elsewhere. |
| Opt out of sale, sharing and targeted advertising | Nothing to opt out of: we do not sell personal information, do not share it for cross-context behavioral advertising, and do not use it for targeted advertising. There is no "Do Not Sell or Share My Personal Information" link on this site because there is nothing behind it. |
| Limit use of sensitive information | We do not collect sensitive personal information for the purposes this right restricts. |
| No retaliation | We will not deny you service, charge you a different price, or give you a lesser experience for exercising any of these rights. |
| Appeal | Where your state provides it (Virginia, Colorado, Connecticut and others), you may appeal a decision by replying to our response. We will answer the appeal in writing within the time your state allows. |
These rights are recognized in different words by the state laws now in force, including the CCPA as amended by the CPRA (California), the VCDPA (Virginia), the CPA (Colorado), the CTDPA (Connecticut), the UCPA (Utah) and the comparable acts in Texas, Oregon, Montana and the other states that have followed them. We do not check which state you are in before honoring a request.
Authorized agents. You may use an authorized agent to make a request. We will ask for proof that you gave them permission, and we may ask you to verify your own identity directly.
Complaints. If you are not satisfied with how we handled a request, you can complain to your state attorney general. In California you may also contact the California Privacy Protection Agency at cppa.ca.gov. We would rather hear from you first at admin@matpilot.io.
You exercise all of them the same way: in-app, on the Data & privacy rights page, or by emailing admin@matpilot.io. If your state's law gives you a right this policy does not mention, you still have it, and asking us is enough.
We do not make decisions producing legal or similarly significant effects about an individual by solely automated means. The AI assistant and co-pilot summarise data and suggest or draft actions, but anything that affects a Member (such as sending a message) requires a human at the academy to confirm it. AI processing uses Amazon Bedrock / Anthropic in the US with the safeguards in clause 7, and is limited to the context needed to answer.
The AI may surface informational alerts about compliance matters, such as an applicable sales-tax rate or an Operator responsibility, to help Operators run their business. These are for information only and do not constitute legal, tax or professional advice.
We use appropriate technical and organizational measures: encryption in transit (TLS), encryption at rest, scoped role-based access controls, EU-hosted managed infrastructure, audit logging, and least-privilege service permissions. No system is perfectly secure, but we work to protect your data and will notify you, our lead supervisory authority and any other regulator entitled to be told of a personal-data breach, within the deadline the law that covers you sets.
Our marketing website uses only what is strictly necessary to serve the pages and does not use advertising or cross-site tracking cookies. The mobile app uses secure device storage (not browser cookies) to keep you signed in. If we ever introduce non-essential cookies, we will ask for your consent first, everywhere, as the ePrivacy rules require in the EEA and the UK.
Where MatPilot processes Member personal data on an Operator's behalf, the following terms apply and form part of our agreement. MatPilot will:
Subject matter: provision of the Service. Duration: the term of the account. Nature/purpose: academy management. Data types/subjects: as in clause 2, concerning the Operator's Members and staff.
We would like the chance to resolve any concern first. Please contact admin@matpilot.io. You also have the right to complain to a regulator, and you can always choose the one where you live rather than the one where we are.
In the United States that regulator is your state attorney general. In California you may also complain to the California Privacy Protection Agency (cppa.ca.gov), and you can report unfair or deceptive practices to the Federal Trade Commission (reportfraud.ftc.gov). Clause 10 covers the appeal you may have first.
We may update this policy from time to time. We will update the date above and, for material changes, give reasonable notice (by email or in-app) before they take effect.
MatPilot Limited (Company No. 819708, Republic of Ireland): admin@matpilot.io. See also our Terms & Conditions.