Privacy Policy
Last updated 18 August 2026
The short version
Kaive holds information about your body and your training, which is about as personal as data gets. So:
- Your data is stored in Ireland, in the EU.
- We do not sell it, and we do not use it for advertising. Ever.
- We do not use it to train AI models.
- You can export everything, and you can delete everything, from inside the app.
- Health data is only processed because you explicitly agree to it, and you can withdraw that agreement at any time.
The rest of this document is the detail behind those five points, and the specific things the law requires us to tell you.
Who we are
Kaive is operated by ElCapStudios, based in Ireland. For data protection purposes we are the data controller for the information described here.
For anything to do with your data, email privacy@kaive.app. A person reads it.
What we collect
Information you give us
- Account — your email address and a password, which is stored only as a cryptographic hash and is never visible to us.
- About you — name, date of birth, height, weight, sex, activity level and your goals. Used to work out calorie and training targets.
- Training — sessions, sets, distances, durations, routes and how they felt.
- Nutrition — meals, drinks, supplements and fasting.
- Body and health — weights, measurements, progress photos, injuries and symptoms you record.
Information from devices you connect
If you connect a watch, band, ring, heart rate strap or trainer, we read only what you have granted: workouts, heart rate, steps, sleep, resting heart rate, heart rate variability, blood oxygen, respiratory rate, weight and distance.
On Android this comes through Health Connect, and on iOS through Apple Health. You control it per data type, in those apps, and can revoke any of it at any time without uninstalling Kaive.
Information we collect automatically
- Which app version and platform you are on, so we can fix things that break.
- Errors and crashes, so we know when something is broken before you have to tell us.
What we deliberately do not collect
- Your location in the background. GPS is read only from sessions you record.
- Your contacts, your photos beyond the ones you attach, or your messages.
- Advertising identifiers. There is no advertising in Kaive.
Why we are allowed to process it
Under the GDPR every use of your data needs a lawful basis. Ours are:
| What | Why we may |
|---|---|
| Running your account, and taking payment | Performance of our contract with you |
| Health and fitness data | Your explicit consent (Article 9(2)(a)) |
| Keeping the service secure and working | Our legitimate interests |
| Keeping tax and payment records | Legal obligation |
Health data is special category data under Article 9, which means we cannot rely on legitimate interests for it. We process it only because you have explicitly agreed, and you can withdraw that agreement at any time — in Settings, in the same number of taps it took to give.
Withdrawing does not delete what you have already recorded. Deleting your account does.
AI features
Coaching, session analysis, meal planning and photo recognition send the relevant parts of your data to Microsoft Azure OpenAI to generate a response.
- Microsoft does not use data sent through Azure OpenAI to train or improve their models. This is contractual, not a promise we are making on their behalf.
- We send the minimum needed for the feature, not your whole history.
- If you would rather none of your data went to an AI provider, do not use the AI features. Everything else in Kaive works without them.
AI output can be wrong. It is there to help you think, not to be obeyed. See the Terms on this, particularly the part about medical advice.
Who else touches your data
We use a small number of processors. Each is bound by a data processing agreement and may only act on our instructions.
| Who | What for | Where |
|---|---|---|
| Supabase | Database and sign-in | Ireland (EU) |
| Vercel | Running the app | EU and US |
| Microsoft Azure OpenAI | AI features | EU and US |
| Stripe | Payments | EU and US |
| Cloudflare | Domain and email routing | Global |
| Resend | Sending account emails, such as password resets | EU (Ireland) |
| Sentry | Crash and error reports, stripped of personal data | EU (Germany) |
| OpenRouteService | Route planning, only when you use it | EU |
We never sell your data, and we never share it for advertising. Both Apple and Google separately forbid using health data for advertising, and we would not do it regardless.
Crash reports
When the app breaks we need to know why, so a crash report is sent to Sentry. These are deliberately stripped before they leave your device: no request contents, no cookies, no console output, and no health data. What is sent is the error itself, where in the app it happened, and your account's internal ID so we can connect it to a support request if you contact us.
We do not use session replay. Some apps record what is on your screen when something goes wrong — on an app like this that screen is your weight, your heart rate or your injury notes, so we have turned that off entirely rather than relying on it to hide the right things.
Data leaving the EU
Your core data sits in Ireland. Some processors above operate in the United States. Where data is transferred there, it is covered by the EU-US Data Privacy Framework or by Standard Contractual Clauses approved by the European Commission.
How long we keep it
- While your account exists — your data stays, because a training history is only useful over years.
- When you delete your account — everything is removed immediately. Not archived, not soft-deleted.
- Backups — deleted data may persist in encrypted backups for up to 30 days before those rotate out.
- Payment records — kept for six years, because Irish tax law requires it. This is invoices, not your health data.
Your rights
Under the GDPR you have the right to:
- See what we hold — Settings has an export that gives you all of it.
- Correct anything wrong — editable in the app.
- Delete everything — Settings, Account, Delete account. It is immediate and irreversible.
- Take it elsewhere — the export is machine-readable.
- Object or restrict — email us.
- Withdraw consent for health data processing, at any time.
Two of these are deliberately in the app rather than behind an email, because a right you have to ask permission to use is not much of a right.
If you think we have got something wrong, tell us at privacy@kaive.app. You also have the right to complain to the Irish Data Protection Commission at dataprotection.ie, and we would rather you did that than stayed unhappy.
Security
- Everything is encrypted in transit and at rest.
- Access to your rows is enforced at the database level, so one account cannot read another's data even if the app has a bug.
- Passwords are hashed, never stored or transmitted in a readable form.
- Found a vulnerability? security@kaive.app. We will not take legal action against anyone reporting in good faith.
Children
Kaive is not for under-16s. That is the age of digital consent in Ireland, and an app that gives calorie targets and training loads is not something we are prepared to offer children. If you believe a child has created an account, email us and we will delete it.
Changes
If we change anything that matters, we will tell you in the app before it takes effect — not by quietly updating this page and changing the date at the top. The current version always lives at https://kaive.app/privacy.