Privacy Policy
Last updated: September 6, 2026
1. Operator (Data Controller)
"Punchy" (formerly "AI Boxing Trainer"; the "Service") is a Progressive Web App (PWA) operated by Do the right thing (a sole proprietorship; "we", "us", or "our"). We are responsible for the handling of personal information within the Service.
Information related to payments for previously sold paid plans is managed independently by the payment provider, Paddle.com Market Limited ("Paddle"), acting as the seller of record (Merchant of Record). See Section 5.
2. Information We Collect
The Service handles the following information.
- Camera video: used to analyze your posture and punches during training. It is processed through two separate paths:
- On-device analysis (no external transmission): detection of wrist, elbow and other landmarks via MediaPipe is performed entirely within your browser, and the video is not sent externally.
- Transmission for AI coaching: so that the AI coach can understand the situation, the video is thinned to still images (JPEG) at approximately 0.5 fps (about one frame every two seconds) and sent to Google's Gemini Live API. We do not retain the video on our servers.
- Microphone audio: for two-way voice interaction with the AI coach, audio (a PCM stream) is sent to the Gemini Live API. We do not retain the audio on our servers.
- Anonymous usage ID: to understand retention (for service improvement), a random, non-identifying string is stored in your browser's
localStorage and sent to the server when a session connects. This ID is never linked to your name or other personal information, and is only temporarily recorded in server logs. To prevent abuse (enforcing the daily free-time limit), we also aggregate usage time (seconds only) per anonymous ID and per IP address on a daily basis; only the current day is retained and older records are deleted automatically.
- Session statistics: non-personal data such as punch counts, types, combination rate and duration are stored in your browser's
localStorage (up to 30 entries). They are not stored on our servers.
- Settings and nickname: punch-effect on/off, coaching interval/style, volume, voice settings, and any nickname you optionally enter are stored in
localStorage. All of this remains on your device.
- Authentication token: a random string issued upon successful authentication is stored in
sessionStorage (expires automatically after 24 hours).
- Access logs: for fraud detection and rate limiting, we temporarily retain your IP address and connection time on the server.
The Service (the app) does not collect any directly identifying information such as your name, address, phone number, email address or date of birth. Where such information was required for past paid-plan payments, it was collected by Paddle, not by us (see Section 5).
3. Purposes of Use
We use the information only within the following purposes.
- To pass camera stills and audio to the AI in real time and generate coaching responses.
- To detect punches and display particle effects via in-browser MediaPipe.
- To display statistics and improvement feedback after a session.
- To improve the Service through anonymous, aggregated retention metrics.
- To detect unauthorized access, apply rate limiting, and operate the Service reliably.
We do not use the information beyond the scope necessary to achieve these purposes.
4. Transmission to External Services / Third Parties
The following external services handle data to provide the Service or support past purchases.
- Google Gemini Live API (Google LLC, a U.S. company): camera video (JPEG stills at ~0.5 fps) and audio (a PCM stream) are sent to generate AI responses and are processed on Google's servers in the United States, in accordance with the Google Privacy Policy. The Service uses the paid Gemini API; data sent is not used to train Google's generative AI models (per the paid Gemini API terms).
- Paddle.com Market Limited (a UK company; Merchant of Record): processed past paid-plan purchases and handles information relating to their receipts, billing and refunds. See Section 5.
- Fly.io (a U.S. company): our hosting infrastructure, handling application logs and connection information. It runs in the Tokyo (NRT) region.
- MediaPipe (client-side only): image analysis is completed within your browser and is not sent externally.
We do not sell or provide user data to any third party other than the above.
Cross-border transfers:
Through transmission to the Gemini API (Google LLC), video and audio are processed mainly on servers in the United States. Payment information from past purchases is processed by Paddle (a UK company) mainly in the UK, EU and US. The data protection regimes of these countries may differ from that of Japan. By using the Service, you are deemed to consent to such cross-border transfers. Please review each provider's privacy policy for details of their safeguards.
5. Past Payments and Information Held by Paddle
Punchy is currently free to use, with no card required. New paid-plan sales are paused. Free use does not open a Paddle checkout or verify a new purchase entitlement.
Payments for previously sold paid plans were provided by Paddle (Paddle.com Market Limited, a UK company) acting as the seller of record (Merchant of Record). Paddle handles card and billing information, taxation and refunds for past purchases. We do not receive or store your credit card information. Records used to confirm past purchases, such as customer IDs, subscription IDs and purchase status, are not automatically deleted when the Service becomes free.
Paddle processes the name, email address, billing address, card details and similar information needed to manage past purchases, as an independent data controller/processor in its own right. The handling of that information is governed by Paddle's privacy policy and data processing terms.
| Type of information | Us (Punchy operator) | Paddle (past payments) | Google (Gemini) |
| Camera video (0.5 fps stills) | Not received (no retention; on-device analysis not sent externally) | Not received | Received (AI processing; not used for training) |
| Microphone audio | Not received (no retention) | Not received | Received (AI processing; not used for training) |
| Name, email, billing address | Not collected | Past purchase information managed | Not received |
| Credit card details | Not received / not stored | Past purchase information managed (PCI DSS compliant) | Not received |
| Past purchase entitlement token (claim) | May remain on device; not used to determine current free access | Purchase confirmation information provider | Not received |
| Past purchase records (customer ID, purchase status, etc.) | Past purchase records retained on server | Past purchase information managed | Not received |
| Anonymous usage ID / usage logs | Temporarily logged + daily free-time aggregation (current day only) | Not received | Not received |
For details of information Paddle handles for past purchases, your rights, and how to contact Paddle, please see:
For questions about past purchase receipts, refunds or billing, Paddle's support channel (or the contact shown in your receipt email) is the primary point of contact.
6. Free Access and Usage Time
- AI practice: free for up to 5 minutes in total per day. Camera video and audio are handled as described in Sections 2 and 4. No card required.
- Demonstrations and the gym timer: can be used repeatedly without using your AI time.
- Usage-time limits use daily totals per anonymous usage ID and IP address. Past purchase entitlement tokens do not extend the current usage time.
7. Data Storage and Retention
- Camera stills / audio: discarded immediately after processing (no server storage).
- WebSocket session: ends according to the daily AI practice limit (5 minutes in total) and per-connection limits.
- Server-side access logs: about 24 hours.
- Free-time usage aggregation (seconds only, per anonymous ID / IP address): current day only (older records deleted automatically).
- Authentication token: expires 24 hours after issuance.
- Payment information from past purchases (name, billing address, card details, etc.): retained by Paddle in accordance with Paddle's policy and its statutory retention obligations.
- Data in your browser's
localStorage: until you delete it.
8. Security Measures
We implement the following measures.
- Encryption of communications via HTTPS (with HSTS).
- Authentication and automatic token expiry.
- Security headers (CSP / X-Frame-Options / Permissions-Policy, etc.).
- Per-IP rate limiting and lockout.
- A WebSocket message size limit.
- A design in which highly sensitive information such as card details is not held by us (current free use requires no card; Paddle manages past payment information).
9. Your Rights and Data Deletion
- Deleting in-browser data: you can delete site data for this domain from your browser settings (this erases statistics, settings and the anonymous ID).
- Stopping use: after you stop accessing the Service, access logs and daily usage totals follow the retention periods in Section 7. Questions about past purchase records can be sent to the contact below.
- Disclosure, correction or suspension of information we hold: we do not hold directly identifying information on the app side, but requests can be made via our contact channel.
- Requests regarding past payment information (name, billing address, card details, etc.): these are managed by Paddle; please make such requests via the channel stated in the Paddle Privacy Policy.
10. Cookies and SDKs
- The Service uses
localStorage / sessionStorage to maintain authentication state and save settings.
- We do not use advertising tracking cookies or third-party advertising SDKs.
- The Service no longer loads the Paddle payment SDK. If you visit Paddle's website to check a past purchase, review Paddle's policy for its use of cookies.
11. Notes
- The Service is not a medical act, diagnosis or treatment. Please train at your own risk.
- Specifications may change without notice.
- Minors should use the Service with the consent of a guardian. Users under 13 may use it only with the consent and supervision of a guardian.
12. Contact
For privacy inquiries about the Service, please contact us at punchy.trainer@gmail.com. For payment inquiries about a past purchase, use the Paddle contact shown in your receipt email.
13. Changes to This Policy
This policy may change without notice. Where changes are material, we will announce them within the Service or on the home page.