← KOBUSHI
KOBUSHI Privacy Policy
This is an English translation provided for convenience. If there is any discrepancy, the Japanese version prevails.
KOBUSHI (X: @arimimai_tekken; the "Operator") sets out below how user information is handled in the application "KOBUSHI" (the desktop app and the web version; the "App").
1. Information We Collect
The Operator does not collect any information except what you choose to send us. Specifically:
- Account: The App's core features can be used without an account. If you create an account, we hold your email address and a random user ID issued by the system. We do not use or store a password (authentication is via Google, Discord, or anonymous sign-in only). If you sign in with Google or Discord, we receive the identifier and email address that the service provides.
- Your content: Sheets, cards, notes and other data you create are first stored on your device (browser local storage, etc.). While you use an account, the content is automatically sent to and stored in the cloud (Supabase) each time you edit it (auto-save).
- Community sharing: The knowledge you enter is shared with other users. See Section 3 for details.
- Match Scan (screen recognition): Screen images captured by this feature are processed only on your device and are never transmitted anywhere. Only when a character name cannot be identified, an image and a log are temporarily written to a temporary folder on your device for troubleshooting (overwritten each time; they do not accumulate).
- Feedback form: Only when you submit the form, its contents together with a random device identifier and your browser/OS information are sent to the Operator. The contents of the form are never sent without your action.
- Automatic fault reports: Only when the App detects an unexpected condition (reaching the limit on the number of shared notes, a Match Scan recognition failure, the App unexpectedly stopping, and the like), it automatically sends the Operator information for troubleshooting. In addition, for analysis aimed at improving Match Scan accuracy, the App may send measurements related to recognition, including from screens that were recognized successfully. What is sent is the type of event, counts, a random device identifier, your browser/OS information, in the case of Match Scan the measurements described above (candidate character names with their match scores, the black-and-white pattern of the name area, and the like), and — when the App stops unexpectedly — the error text (up to 200 characters), where it occurred, and which screen was open at the time. We never send screen images, player names, or the text of notes you have written. Note, however, that error text can contain a fragment of the data the App was processing; for this reason it is truncated to 200 characters, and each distinct error is sent only once per device, up to 10 in total.
- Usage analytics: The App sends and aggregates the following to (1) count update checks and downloads, (2) understand continued use, and (3) understand how users progress through its key features (automatic fault reports are covered above). We do not use this information for advertising or to identify individuals.
- (1) Connection & download counts: The desktop app connects to the official site on startup to check for updates. The Operator counts these connections and downloads on the serving side. To know how many devices launched on a given day, we also record an irreversible string derived from the IP address combined with a secret value that changes daily (we do not store the IP address itself; because the string differs the next day, this record alone cannot track the same user across days).
- (2) Continued use: On startup the App sends an anonymous installation ID generated and stored on your device (the same random value used for the feedback form; not linked to your name, email address, account, or IP address). Because this ID is stable, we can tell whether the same device keeps using the App over time, but we do not use it to identify individuals. The App also sends one of four values indicating how it was opened (the desktop app, launched from the home screen, a smartphone or tablet browser, or a desktop browser). We never send your device model, OS version, browser type, or screen size.
- (3) Progress through key features: The App sends the type and outcome of a predefined set of actions, such as selecting a character, viewing a sheet, starting Match Scan and whether it succeeds, creating or adopting a Quick Check item, note, or practice item, starting and completing sign-in, viewing plan prompts and plan details, and starting and completing checkout. These events include the anonymous installation ID described above, an anonymous ID for the current usage session, and how the App was opened. For Live streams, however, the App sends only whether the list was viewed and whether a stream link was opened, together with the anonymous installation ID. It does not send the anonymous session ID, how the App was opened, or which stream was opened, including its name, URL, or streamer. We do not send the text of notes or cards, match results, player names, search terms, or email addresses. We ordinarily do not send the selected character either; only events used to measure engagement with prompts introducing the new character BOB distinguish BOB from other characters. We do not link these anonymous IDs to the user ID associated with an account.
2. Cloud Save (optional, free)
- Purpose: A backup against device failure, replacement, or browser-data clearing, and to let you use the same notes on multiple devices.
- Optional: Cloud save is an optional, free feature. If you don't use it, the core features work as they are (your data stays only on your device).
- Auto-save: While cloud save is enabled, your content is sent automatically each time you edit it, replacing the cloud copy with the latest state. No manual save is needed.
- Where it's stored: In a service (database) provided by Supabase Inc. What is stored is your sheets, cards, notes and similar data as of the last auto-save, your email address, and your user ID.
- Protection: Row-level security ensures you can only read and write your own data. Communications are encrypted.
- Limited purpose: The Operator does not use stored data for any purpose other than providing the service to you (no analytics, advertising, or disclosure to third parties).
- Deletion: You can completely delete your account and your cloud data at any time from "Delete account" in Settings (data on your device remains).
3. Community Sharing
- Purpose: So that players build up and share their knowledge with each other, allowing the core features to be offered for free.
- What is shared: The knowledge you enter in the App (moves you register, the text of your notes, the drills you create, and other counterplay information you write yourself). This content is sent to the KOBUSHI community database, where it is aggregated and shown to other users. A full list of what is shared is provided in the App (Settings → Support & info → "See what is shared", and the notice displayed on first launch).
- Translation: Knowledge you have submitted may be translated by the Operator and shown so that users in other languages can read it. External AI or translation services may be used. In that case, the submitted knowledge is sent to those services only to the extent necessary for translation. Translations are stored in the KOBUSHI community database and shown to other users.
- What is not sent: Screenshots, and anything you have not entered, are never sent.
- Condition of use: Sharing is a condition of using an account; there is no setting to disable it. If you do not wish to share, do not enter the relevant information.
- Deletion: If a submission is problematic, or you would like something removed, contact us at the address at the end of this Policy.
4. Access Logs for This Site and the Web Version
This site and the web version are served from Vercel. In the course of delivery, that provider may technically record access logs such as IP addresses. Their handling is subject to that provider's privacy policy. The Operator does not use those logs to identify individuals.
5. Cookies
The App does not use cookies for advertising or tracking. It uses browser local storage and session storage to store your settings and the data you create, to keep you signed in, to store the anonymous installation ID and the anonymous session ID described in Section 1 above, and to keep a record of what has already been sent so that the same event is not sent twice.
6. Showing Videos and Posts (YouTube and X)
When a link you added to Clips is shown or played, your device connects directly to YouTube (Google LLC) or X (X Corp.). Fetching a thumbnail for a post on X is the one exception: it passes through the Operator's server once (see below). These connections happen at the following points.
- Showing a YouTube thumbnail and title: as soon as a clip appears in a list, your device connects to Google/YouTube to fetch the image, the title and the author name (this happens even if you do not press play).
- Showing the text and thumbnail of a post on X: this happens as soon as a clip appears in a list (even if you do not open it). Your device fetches the text directly from X. The thumbnail's image URL cannot be fetched by your device directly, so the post ID is sent to the Operator's server (kobushi.app), which asks X and returns only the image URL. Your device then fetches the image itself directly from X.
- Playing a video or opening a post: connects to YouTube or X. The web version shows it in the official player or official embed on the page; the desktop app shows it in a small window opened from KOBUSHI.
About the part that passes through the Operator's server: the response from X described above contains the text of the post, but the Operator does not store it and does not return it to your device (only the image URL is returned). However, which post was shown may appear in the Operator's access logs (see Section 4 above). This uses the route that X's own embeds rely on, and it may stop working at any time at X's discretion (if that happens, thumbnails simply stop appearing; nothing else is affected).
Through these connections, those providers may obtain your IP address, information about your browser and OS, and which video or post was shown. Their handling is subject to each provider's privacy policy (Google Privacy Policy / X Privacy Policy). The Operator is not in a position to guarantee how long those providers retain such information or how they handle it.
If you send a link to KOBUSHI from another app's share menu, the shared content is removed from the address as soon as the screen opens, and only the link itself is held temporarily on your device (it is cleared when you close the browser tab). That first load does, however, reach the site's hosting provider, so it may appear in the access logs described in Section 4 above.
The Operator does not store or redistribute the video files themselves or the text of posts on X. For community sharing, KOBUSHI stores the URL you added, the character it is filed under, the note you wrote with it, the video title and author name obtained from YouTube, and the video/post ID used to identify it.
7. Disclosure to Third Parties
Except as required by law, the Operator does not disclose user information to third parties. If you use cloud save, storage of the data is entrusted to Supabase Inc. (storage location: Tokyo region).
8. Changes to this Policy
The Operator may amend this Policy. An amended Policy takes effect when posted within the App or on the official website. If there is a material change to how information is handled, we will announce it within the App or on the official website.
9. Contact
Questions about this Policy: kobushi.tekken@gmail.com / X: @arimimai_tekken
Effective: 2026-07-10 / Last updated: 2026-09-08 (documented in Section 6, for thumbnails of posts on X: that the post ID is sent to the Operator's server, that the Operator's server asks X, that the text of the post contained in that response is neither stored nor returned, and that which post was shown may appear in the access logs. Also revised the statement about X, because connections to X now happen when a list is shown rather than only when a post is opened) / 2026-09-07 (documented in Section 6, for the Clips feature, the points at which your device connects directly to YouTube and X — when a thumbnail is shown, when a video is played, and when a post on X is opened — and what is stored for sharing: the URL, the character, your note, the video title and author name obtained from YouTube, and the identifying video/post ID. The video files themselves and the text of posts on X are not stored on the Operator's servers) / 2026-08-26 (documented in Section 1(3) what is and is not sent for Live streams; also spelled out in Section 5 what is kept on your device — the anonymous installation ID, the anonymous session ID, and a record of what has already been sent so the same event is not sent twice — no change to what is sent, and the storage wording describes what was already being stored) / 2026-08-22 (documented anonymous measurement of progress through key features, including what is and is not sent) / 2026-08-19 (documented that submitted knowledge may be translated into other languages, stored and shown, and that external AI or translation services may be used — no change to what is never sent: screenshots, or anything you have not entered) / 2026-08-18 (documented that, to understand continued use, the App also sends how it was opened alongside the anonymous installation ID — no change to what is never sent: device model, OS version, browser type, or screen size) / 2026-08-17 (generalized the description of what is automatically sent for analysis to "measurements related to recognition", no longer limited to screens that could not be recognized — no change to what is never sent: screen images, player names, or the text of notes you have written) / 2026-08-13 (removed the feature-by-feature examples of what is shared; the full breakdown is now provided in the App — no change to what is shared) / 2026-08-12 (added to automatic fault reports: the error text, where it occurred, and which screen was open when the App stops unexpectedly) / 2026-08-07 (documented analysis-oriented automatic sends: measurements of unrecognized screens, and capture-method information) / 2026-08-04 (documented automatic fault reports) / 2026-07-25 (documented usage measurement: counting connections/downloads, and sending an anonymous installation ID to understand continued use)