JB_DRILL · ANDROID & WINDOWS
Privacy Policy
JB_Drill is a local-first tool for creating and presenting training drills. It does not require a byBartonek user account. The current Android and Windows applications do not include advertising, behavioral tracking or analytics SDKs.
Want to delete your data? Follow the Data deletion instructions below to request removal by email. No new account or purchase is required to submit a request.
1. Who operates JB_Drill
JB_Drill is provided by Jiří Bartoněk under the byBartonek name, Czech business identification number (IČO) 07924381. Privacy questions: privacy@bybartonek.com. Support and data deletion requests: support@bybartonek.com.
2. Drills, files and local settings
The application processes drill drawings, player labels, notes, tags, equipment layouts, animation timing, tactical keyframes, file names and library metadata to provide editing, playback and export. It also stores local preferences, selected-folder references and cached license information.
Drills and exports normally remain on your device or in a storage folder you choose. Ordinary editing does not upload your drill library to our license server. A playback copy is uploaded to byBartonek only when you deliberately create a JB_Play sharing link.
You can select a local folder or a folder exposed by a provider such as Google Drive. Your operating system and chosen provider control any cloud synchronization under their own terms. We do not operate that synchronization. You can change or revoke folder access using the application or operating-system settings.
You control deletion of local files and files in your chosen storage. Clearing app data or uninstalling can remove local settings, but does not necessarily delete exported files, files in a selected folder or cloud copies. Back up anything you want to keep first.
3. Subscriptions and linked devices
Google Play and Microsoft Store process purchases, payments and store accounts under their own policies. We do not receive or store your full payment-card details or store password.
To verify paid access and support device linking, JB_Drill communicates over HTTPS with license.bybartonek.com, hosted using Cloudflare Workers and D1. The service processes license references, product/plan and subscription status, verified expiry dates, and verification timestamps. For Google Play it stores the purchase token and package name server-side so it can re-check the subscription with Google. Microsoft purchase evidence is submitted for verification with Microsoft.
Each installation creates an identifier and cryptographic key pair. The server stores the installation identifier, public key, platform, device label and activation, last-contact and deactivation timestamps. The private device key remains on the device. These are installation identifiers, not a requirement to provide your real name or email address.
Linking uses short-lived, single-use pairing codes, stored as hashes, and signed requests. A license can connect several devices; authorized linked installations can view the linked-device list and manage links. Use a device label that does not reveal unnecessary personal information. Removing a linked device disables its access but is not deletion of its database record.
To limit attempts to guess access codes, the license service processes the requesting IP address and installation identifier. It stores short-lived attempt counters keyed by salted hashes, not raw IP addresses or submitted codes. These counters are used for security, not advertising, location inference or behavioral analytics.
Verification and refresh requests protect paid access, enforce device limits and recover subscription status. The app can use a signed cached license while offline within its validity period. This does not mean server-side license records expire or are deleted at the same time.
4. Optional JB_Play sharing
Choosing Share (JB_Play Link) uploads a playback copy of selected drills over HTTPS to play.bybartonek.com. It may contain session and drill names, rink layouts, player labels, routes, notes, timing and tactical keyframes. Cloudflare Workers and Workers KV host the sharing service.
Playback copies have an automatic 14-day expiry. The random link is unlisted but is not password-protected: anyone with it can view the content and forward the link. Do not include confidential material or unnecessary information about athletes, especially minors.
The service uses requesting IP addresses for rate limiting and abuse prevention. Cloudflare may process network, request and security metadata to provide and protect its services. These are not used by JB_Drill for advertising or behavioral analytics.
You can instead export a PDF, video or .jbplay file and share it through a service of your choice. Other storage or messaging services, and copies saved by recipients, are outside our control.
5. Support, purposes and service providers
Support messages contain the email address, text, device details and attachments you choose to provide. We use them to answer requests and diagnose issues. Only send example files if needed, and remove unnecessary personal information first.
Processing supports requested application features and subscriptions, optional sharing, support, fraud and abuse prevention, and applicable legal obligations. Depending on the purpose, the legal basis is performance of a contract or requested service, legitimate interests in secure operation and support, or compliance with a legal obligation.
Cloudflare processes hosted license and sharing data for us. Email and technical service providers may process correspondence. Store providers and your chosen storage providers process data under their own relationships with you. Providers may process data internationally subject to their applicable data-protection arrangements. We do not sell personal data.
6. Retention
- Local files and settings: remain until you delete them or clear the relevant storage.
- JB_Play playback copies: expire 14 days after upload; earlier removal may be requested below.
- License, purchase-verification and device records: there is currently no automatic deletion deadline. They remain in the service to support verification, linking and restoration, including after a subscription expires or a device is unlinked. You can request deletion of your records.
- Pairing and replay-protection records: expired/used pairing codes and old request nonces are cleaned during subsequent service activity; this is not an instant scheduled deletion guarantee.
- Access-code attempt counters: normally expire after a 15-minute counting window or the end of a 15-minute cooldown, if later. Scheduled cleanup runs every 15 minutes to remove expired counters. If cleanup is delayed, the records remain until it resumes; expired counters do not prolong the restriction. D1 recovery history has the separate retention described below.
- Managed Workers Logs: Cloudflare's standard retention is 3 days on Free and 7 days on Paid plans. These operational logs therefore have a standard retention window of up to 7 days, separate from the license database.
- D1 recovery history: Cloudflare Time Travel retains database history for 7 days on Free and 30 days on Paid plans. A deleted database record can therefore remain in recovery history for up to 30 additional days, rather than disappearing immediately from all copies.
- Support and request correspondence: retained according to the ongoing request and any specific security, dispute or legal need, rather than a single fixed period for every conversation. If records must remain after a deletion request, we explain what, why and the applicable period.
These managed log and database-history windows are documented by Cloudflare Workers Logs and D1 Time Travel. They do not describe copies independently held by stores, email providers, recipients or your chosen storage provider, which follow their own retention rules.
7. Request data deletion
To request deletion of your JB_Drill data held by byBartonek, email support@bybartonek.com with the subject JB_Drill — Data deletion request. Requests are reviewed and handled manually, not by an automatic erase button.
What to include
- Say which data you want removed: a JB_Play share, records for your installation, an entire license you own, or support correspondence.
- For a shared drill, provide the complete JB_Play link and explain your relationship to the content.
- For licensing, include the device label/platform and any available license or store order reference. These help locate records; they do not by themselves prove ownership.
- For correspondence, identify the message or conversation. If you no longer have the app or the references, explain that and we will discuss another way to identify the data.
Do not send passwords, full payment-card details, purchase tokens, private keys or unnecessary identity documents. We will request only additional information reasonably needed to identify the records and verify your authority.
What happens next
We confirm the scope and verify your authority before acting. Possession of a share link, device label or license identifier alone is not sufficient authorization to delete another person's data. A team member's request does not automatically authorize deletion of the team's license or other members' records.
Depending on the verified request, removal from our active service can cover the hosted playback copy, your device-link records and associated pairing/request records, license and purchase-verification records for a license you own, or relevant support correspondence. We explain any consequences for paid access before removing license records, and confirm the outcome or any limitation.
Necessary records may be retained where a specific legal, security or dispute-related reason applies. We explain the retained data and the reason and period for retention. Operational logs and recovery history can remain until the windows in section 6 expire; we do not promise immediate erasure from every backup or provider system.
Deletion is not subscription cancellation. Manage recurring payments separately in Google Play or Microsoft Store. We cannot erase the stores' own transaction records, remotely erase your local drill files, or recall copies saved by recipients. Continued use, a new upload, purchase restoration or re-linking may create new service records.
8. Your rights and security
Depending on applicable law, you may request access, correction, deletion, restriction, objection or data portability. Contact privacy@bybartonek.com or use the deletion process above. You may lodge a complaint with the Czech Office for Personal Data Protection or another competent supervisory authority.
JB_Drill is intended for coaches and other adult users, not for collecting personal information from children. Avoid unnecessary athlete names or other identifying details in files and shares. We do not use support data for automated decision-making or profiling.
License and JB_Play transfers use HTTPS. Access verification and random share links serve different purposes: a share link is not authenticated private storage. No electronic storage or transmission is completely secure; protect your devices, backups and shared links.
9. Changes and website privacy
This policy will be updated as JB_Drill changes. The current revision date appears above. For the public website and general correspondence, see byBartonek Website Privacy.