← Back

Privacy Policy

Last updated on 2026-08-03.

1. What data we process

Kurro processes the following categories of personal data so we can deliver your training plan, analytics and coaching advice:

  • Account data: email address, name, birth year.
  • Training data: activities from Strava and/or Apple HealthKit (distance, pace, heart rate, calories; location is not stored).
  • Health data (special category under Art. 9 GDPR): sleep, resting heart rate, HRV, respiration, SpO₂, wrist temperature — only if you explicitly consent via HealthKit.
  • Training goal, plan and the status of planned workouts.
  • Messages you exchange with the AI coach.
  • Daily check-ins and readiness inputs, and — only if you enable cycle tracking — menstrual-cycle logs.
  • Notification preference: whether you receive the weekly digest email (on by default), and, only for the duration a link is valid, a hashed unsubscribe token used solely to verify the link in that email; we never store the raw token, and it is replaced whenever a new digest is sent.

When you sign up you also record three consents (terms, health data, AI coach). Terms stays account-lifetime only: the app is not usable without agreeing to it, so a standalone withdrawal would be a button with no real effect, and deleting your account is the only way to end it. Health data and AI coach are different: you can withdraw either one at any time from Settings → “Manage consent”, without deleting your account. Withdrawing health data permanently deletes the health and training history we derived from it, including your manual check-ins, taper notes and manually logged weight (activities, health metrics, recovery scores, thresholds and more); withdrawing AI coach permanently deletes your chat history and any pending proposals. Both take effect immediately and cannot be undone, this is a real, immediate stop: the following all check your health-data consent first and refuse to process anything new the moment you withdraw, not just a registrational preference: a wearable (Apple HealthKit) sync, manual activity entries, manual weight entries, check-ins, taper notes, and every Strava path (connecting or reconnecting your account, a manual sync, deep history sync, and incoming Strava webhook events). A reconnect after withdrawal is deliberately blocked, not treated as an implicit re-grant: use “Grant again” in Settings → “Manage consent” first. Menstrual-cycle logging is the one exception: it sits under its own, separate cycle-tracking setting rather than this consent. Whether withdrawing health-data consent should also delete those self-entered logs is a decision we have deliberately left open rather than deleting them silently (documented in the consent-withdrawal database migration); today they stay unless you delete your account.

Improving our models (optional)

Separately, and only if you opt in, you can allow your anonymised data to be aggregated with other athletes' to improve Kurro's models for everyone. Cross-athlete model learning does not exist yet, nothing reads this consent to act on your data, so we do not currently show a way to grant it; asking for consent to something that never runs would only undermine the consent we do need once a real use exists. If you granted it in the past, it is off by default, never affected your own plan, and you can still withdraw it at any time from Settings → “Manage consent”. Withdrawing only updates your consent record; there is no data to delete, since nothing uses it today.

2. Legal basis

We process your data based on your consent (Art. 6(1)(a) GDPR) and for the performance of the contract (Art. 6(1)(b) GDPR) between you and Kurro. For health data we rely on your explicit consent (Art. 9(2)(a) GDPR).

3. Processors

  • Supabase (database + authentication).
  • Netlify (web app hosting).
  • Strava (optional — only if you connect it to import activities).
  • OpenAI (AI coach; messages and a training summary are sent to the model). OpenAI does not use this data for model training under their API terms.
  • Apple (HealthKit — data stays local on your device until you explicitly sync).

4. Retention periods

  • Coach messages: up to 365 days, then automatically deleted.
  • Training and health data: as long as your account is active. On account deletion, all data is permanently removed within 30 days.
  • Disconnecting Strava (or revoking access from Strava's side): your Strava activities and the fitness history derived from them (load, thresholds, recovery scores) are permanently removed within 30 days, whether or not you also delete your account. Activities from another source, or entries you added by hand, are kept.
  • Model-improvement data (only if you opted in): your source data follows the same account-lifetime retention above; withdrawing consent stops any future use immediately. Aggregated model parameters are anonymised and hold no personal data.
  • Weekly digest unsubscribe tokens: replaced (the previous one deleted) every time a new digest email is sent, so at most one is ever live per account.
  • Accounting/tax data: 7 years where applicable.

5. Your rights

Under the GDPR you have the right to:

  • Access and data portability: you can request a full, machine-readable JSON export of all your data at any time by emailing privacy@kurro.run. We respond within one month, as the GDPR requires.
  • Rectification: you can edit your profile yourself in Settings.
  • Erasure: the "Delete account" button in Settings wipes all your data and also revokes our app's access to your connected Strava account.
  • Withdraw consent: health data and AI coach consent can each be withdrawn separately from Settings → “Manage consent” (see above), with no need to delete your whole account. You can also object to and restrict processing more broadly by emailing privacy@kurro.run.
  • Lodge a complaint with your national data protection authority (e.g. the GBA in Belgium or the AP in the Netherlands).

6. Security

We use encrypted connections (HTTPS/TLS), Row Level Security on the database, and only verified, EU-based processors where possible. Access to production data is restricted to authorised administrators. When an administrator opens, exports, recomputes, regenerates an individual user's data, or searches/lists the athlete roster, we record that action in a persistent, access-controlled audit log: which administrator, which user (where a single user applies), which action, and when. Automated maintenance jobs remain captured in our server logs.

7. Contact

Questions about this privacy policy or your data? Email us at privacy@kurro.run.