Privacy Policy
Last updated 2 October 2026
The short version
- Your core account, training, and health records are stored in our Supabase project in Ireland.
- We do not sell your data, use it for advertising, or track you across other companies' apps or websites.
- We do not use your data to train our own AI models.
- You can export your data and delete your active account data inside the app. Limited exceptions are listed below.
- We collect and use health data for product features only after you give separate, explicit permission. You can withdraw it in Settings.
Who we are
Kaive is operated by ElCapStudios, based in Ireland. We are the data controller for the information described here.
Email privacy@kaive.app for any data protection request. A person reads that inbox.
What we collect
Account and profile
- Your email address, password hash, internal account ID, and sign-in records.
- Your name, date of birth, height, weight, biological sex, activity level, goals, food preferences, and how you move when training. The movement choice can reveal disability information.
- Subscription status, store purchase references, and purchase history. We do not receive your card or App Store payment details.
- A one-way hash of your email address used to stop the free trial from being claimed more than once.
Health, fitness, and content
- Workouts, activities, sets, distances, duration, heart rate, routes, training plans, events, and connected-service sync records.
- Meals, food searches and cached search results, drinks, supplements, fasting, and nutrition targets.
- Weight, measurements, progress photos, sleep, recovery, injuries, symptoms, and notes you choose to record.
- Coach conversations, feedback, support requests, and diagnostic reports you explicitly choose to send.
- A connected sensor's name, type, and device-level identifier, and tokens for services you choose to connect.
Information from health services and devices
If you connect Apple Health, Health Connect, a watch, band, ring, heart-rate strap, trainer, or another fitness service, we read only the categories you permit. Depending on the source, this can include workouts, heart rate, steps, sleep, resting heart rate, heart-rate variability, blood oxygen, respiratory rate, weight, distance, calories, and exercise routes.
Apple Health and Health Connect permissions are separate from Kaive's health data permission. You can revoke the operating-system permission at any time. Withdrawing Kaive's permission in Settings also stops Kaive health screens and future health sync.
Diagnostics and app use
- App version, platform, operating system, and device class.
- IP addresses in Supabase authentication audit records, used for account security and diagnostics, not to build a location history.
- Feature sync status and connected-service activity tied to your account.
- When monitoring is enabled, scrubbed crash reports, performance traces, and sampled navigation events.
Location and maps
We do not read location in the background. We store precise GPS when you record or import an activity route. If you allow location while opening the route builder, the app also reads your current position to centre the map before a session is recorded. Kaive does not store that centring position by itself.
Map tile requests go directly to OpenFreeMap and reveal the map area being viewed. When route planning is configured, the route waypoints are sent to OpenRouteService to calculate a path.
Photos and dictation
Progress photos are stored in a private account folder. Meal and fridge or pantry photos are sent to the configured AI provider for the requested analysis. Kaive does not save those analysis images as progress photos unless you separately choose to upload them there.
Dictation uses the phone or browser speech-recognition service. Kaive receives the resulting text, not a raw voice recording. Text you then save becomes part of the note, workout, or support message where you used dictation.
Why we process it
| Use | Lawful basis |
|---|---|
| Running your account, connected features, support, and purchases | Performance of our contract with you |
| Health and fitness data | Your explicit consent, GDPR Article 9(2)(a) |
| Service security, diagnostics, and preventing repeat trial abuse | Our legitimate interests |
| Required tax and transaction records | Legal obligation |
You can withdraw health data permission in Settings. That stops health screens, automatic sync, new health collection, and scheduled health reminders. Your reminder preferences stay on the device in case you give permission again. Withdrawal does not delete records already saved. They remain stored until you give permission again and delete them individually, or delete the whole account without giving permission again.
AI features and support automation
Coaching, training analysis, meal planning, injury guidance, food-photo analysis, and fridge or pantry recognition send only the information needed for that request to Microsoft Azure OpenAI, our only AI provider. The main resource is in the United States. A backup resource is available in the European Union. Kaive sends a request to the backup only when the main resource cannot answer it. The code can also support OpenAI API or Anthropic API, but neither is configured. We must update this policy before we enable another provider.
AI coach chat sends only your question and that conversation by default. You can choose to include your Kaive profile, training, recovery, schedule, diet, fasting, and supplement data for a reply. If you open chat from a specific session, that session is included because you selected it, and the app tells you before you send.
Feedback and support messages are also sent to the configured AI chain for classification and to prepare a reply draft. A person reads each draft and decides what to send. We send support replies by email from support@kaive.app through Cloudflare.
- We do not intentionally send an AI provider your account ID, name, or email.
- We record the time and the feature of each AI request, linked to your account. We delete each record after 31 days, in a daily cleanup. We use this record only to apply fair-use limits and to find abuse.
- Personal prompts, support messages, and images are not stored in Kaive's shared AI cache.
- We do not use prompts, images, responses, or support messages to train our own models.
- Provider processing and retention follow the terms for the provider active at the time of the request.
AI output can be wrong. It is not medical advice. See the Terms.
Services that receive data
| Service | When and what |
|---|---|
| Supabase | Account, database, and private file storage. The live project is in Ireland. |
| Cloudflare | Hosts the web app and server routes, handles request logs, routes the domain and email, sends our support replies by email, and redirects kaive.ie to kaive.app. |
| Microsoft Azure OpenAI | AI features and support classification or drafting. The main resource is in the United States. A backup resource in the European Union receives a request only when the main resource cannot answer it. |
| Apple and Google | Native purchases, health permissions, and platform speech recognition when used. |
| Stripe | Web checkout. Stripe collects the billing address needed for tax. This is not used for native StoreKit purchases. |
| Resend | Sends account emails: the sign-up confirmation, sign-in links, and password reset. |
| Sentry | Scrubbed crashes, performance, and sampled navigation when monitoring is enabled. |
| OpenFreeMap and OpenRouteService | Map tiles for the viewed area, and route waypoints when route calculation is used. |
| Strava, intervals.icu, and Liftosaur | Only when you connect that service and ask Kaive to sync. |
| Open Food Facts | Food names or barcodes sent for a requested public catalogue lookup. |
| USDA and CoFID | Reference food data is copied into Kaive. Your query is not sent to them. |
We never sell your data or share it for advertising. Connected services receive data only after you connect them or request the feature.
Crash reports
Sentry reports can contain the error, app route, stack trace, operating-system and device context, and sampled navigation or performance timing. Kaive removes the user object, request bodies, cookies, raw query strings, console breadcrumbs, and free-form diagnostic fields before an event is sent. Session replay is disabled. Reports are not linked to your Kaive account.
International processing
Core account and health records are stored in Ireland. AI requests go to our main Azure OpenAI resource in the United States. Its Global Standard deployment can process a request in any Azure region. When the backup resource answers a request, Azure processes it inside the European Union. Any Azure processing outside the European Economic Area, including in the United States, is protected by the Standard Contractual Clauses of the European Commission, in Microsoft's data processing terms. Microsoft is also certified under the EU-U.S. Data Privacy Framework.
Other services named above can also process data outside Ireland or the European Economic Area. Their transfer safeguards and locations depend on the service and account configuration. Email privacy@kaive.app to get a copy of the safeguards for a service.
How long we keep it
- Account, health, and training records remain while your account exists, unless you delete an item sooner.
- Account deletion removes active database records and private progress-photo objects immediately. It is not a soft delete.
- Deleted records can remain in encrypted backups until the backup containing them expires under the live Supabase project's backup schedule. They are not used from backup, and deletion must be reapplied if a backup is restored.
- Payment and tax records can be kept for six years where Irish tax law requires them. These are transaction records, not your health history.
- A SHA-256 hash of your email address and the date the trial was granted are kept after account deletion to enforce one free trial per address. The value is pseudonymous, not anonymous. We do not store the address in this table, but someone with a candidate address can hash it and test for a match. Our basis is legitimate interest in preventing repeat trial abuse, including the GDPR Article 17(3) exception.
- Support, email, request-log, AI-provider, and Sentry retention follows the configured service account and the legal or operational need for the record.
See deleting your data for the account deletion steps and retained exceptions.
Your rights
You can:
- Access and export your account records from Settings as JSON or CSV. Private progress-photo files are not bundled in that export.
- Correct editable profile and training information in the app.
- Delete individual records or your whole account.
- Take your data elsewhere using the machine-readable export.
- Object or restrict processing by emailing us.
- Withdraw health consent in Settings at any time.
Email privacy@kaive.app. You can also complain to the Irish Data Protection Commission at dataprotection.ie.
Security
- Data is encrypted in transit and at rest.
- Database row-level security limits account data to its owner.
- Progress photos use a private bucket and short-lived signed links.
- Passwords are hashed and are never stored in readable form.
Children
Kaive is not for children under 16. Before you give permission to use your health data, Kaive asks you to confirm that you are 16 or older. When you set up your account, Kaive does not accept a date of birth that makes you younger than 16. If you are under 16, you can delete your account in Settings. If you believe a child has created an account, email us and we will investigate and delete it where required.
Changes
If a material change needs new health consent, the app will ask again before health features continue. The current policy is always at https://kaive.app/privacy.