Privacy
How we handle your data
Koræi reads your workouts, your weight and your meals in order to give you advice. That is data about your body, and this page says in full what we collect, why, who else sees it, how long we keep it and what you can ask us for at any time. It is written to be read, not to be ticked.
Last updated: 25 August 2026 · version 1.4
1. Who handles your data
The data controller is [legal name, registered office and VAT number to be filled in], which operates the Koræi application.
For anything about this notice or about your data, write to [contact email address to be filled in]. [If a data protection officer is appointed, their details go here.]
2. The short version
- We collect what it takes to coach you: who you are, how you are, what you have done.
- Health data is handled only with your explicit consent, which you give when you sign up and can withdraw whenever you want.
- We sell nothing to anybody, and we do no advertising profiling.
- Photographs of meals and of gym schedules are read once and never stored.
- You can delete your account from inside the application. For access or portability requests, contact us using the address in this notice.
3. What we handle
Your account
Email address, password (kept only as a bcrypt hash: the password in the clear exists nowhere, not even in the logs), the name you choose to show, language, theme, colour, time zone, and when the account was created and last changed.
Data about your health
This is the sensitive part, and the reason for the explicit consent in section 4: date of birth, sex, weight, height, maximum heart rate, measurements (waist, neck, hips), lifestyle, goals and disciplines, target weight and how your weight moves over time, and the answers you give to the three questions the coach asks before writing — past or current injuries, limitations, dietary, metabolic or insulin-related conditions, and allergies.
Your training
Activities (discipline, date and time, duration, distance, elevation, calories, pace, heart rate, power, cadence, training load) and the second-by-second telemetry that comes with them; gym sessions logged in the application with their exercises, sets, reps and loads; gym schedules; scheduled sessions and proposed weeks.
If you upload .FIT files, the original file is kept exactly as it is, and a .FIT file recorded by a watch also contains the GPS track. The application neither uses nor shows the coordinates — no position is written to the database — but the file stays what you uploaded. Deleting your account deletes it too.
Food
What you log as eaten, with its estimated calories and macronutrients, your nutrition targets, and the eating plan when you ask for one.
Conversations and the coach's memory
The questions you ask Koræi and its answers, the comments it writes on the dashboard's sections, and the notes the coach keeps about you — the ones under "AI notes", which you can read, correct and delete one by one.
Photographs
Your profile photo, if you upload one, is kept until you replace it or delete your account. Photographs of meals and of gym schedules are not: they are sent to the model, read, and dropped when the request ends. They never reach the disk and never reach the database. What remains is the text — the foods estimated, the exercises recognised — not the image.
Technical data
To run your session and keep sign-in safe we handle your IP address at the moment you sign in (to throttle brute-force attempts at passwords), the cookies in section 9, and application logs. Neither passwords nor the contents of conversations reach the logs.
4. Why we handle it, and on what legal basis
| Purpose | Legal basis |
|---|---|
| Giving you the account and the service: registration, sign-in, your own area, your training. | Performance of a contract — art. 6(1)(b) GDPR |
| Processing data about your health to work out condition, load, requirements and advice on training and food. | Explicit consent — art. 9(2)(a) GDPR |
| Importing your activities from Strava or from a file you upload. | Contract, and your consent for the Strava connection |
| Keeping the service up and safe: throttling sign-in attempts, diagnosing faults, defending against abuse. | Legitimate interest — art. 6(1)(f) GDPR |
| Meeting legal obligations where there are any. | Legal obligation — art. 6(1)(c) GDPR |
Consent for health data is separate from everything else and is the box you tick when you sign up, next to your acceptance of this notice. You can withdraw it whenever you want: withdrawal does not affect what was lawfully done before it, but from that moment the coach no longer has the information it works from — which in practice means the service can no longer advise you. The way to withdraw it entirely is to delete your account, which is in section 8.
5. Artificial intelligence: what leaves this application
Koræi does not reason on its own: to write an answer, a plan or an estimate it sends a language-model provider the text of your question and a summary of where you are — goals, recent training, weight, what you declared about injuries and food, and photographs of meals or schedules when it is you who sends one.
That provider is OpenAI, which handles this data as our processor and does not use it to train its models. The data travels to the United States: the transfer is made on the basis of the European Commission's standard contractual clauses, together with the measures set out in our contract with the provider.
We do not send it your email address, your name, your password or your original files.
No automated decisions with legal effects. What Koræi produces is advice about training and food: it decides nothing about you that has legal or similarly significant effects within the meaning of art. 22 GDPR, and it is not medical advice. If you have a doubt about your health, the person to ask is a doctor.
6. Who else sees your data
No sale, no transfer for advertising, no commercial profiling. Your data is seen only by the providers we need in order to run the application, each appointed as a processor under art. 28 GDPR:
- The infrastructure provider, which hosts the application, the database and uploaded files: [provider, location and server region to be confirmed].
- OpenAI, for what is described in section 5.
- Strava, only if you connect your account: we receive your activities from there, and we send them nothing beyond what that connection requires. You can disconnect it whenever you want, under "Connections".
Your data may also be disclosed to judicial or other authorities where the law requires it.
7. How long we keep it
- As long as you have the account. Account, training, weight, food, conversations, the coach's memory and uploaded files stay while your account exists: they are your history, and history is what makes advice different from generic advice.
- Second-by-second telemetry: 13 months. The detail of the beats and paces of each single workout is deleted automatically after thirteen months. Activity summaries stay.
- "Keep me signed in": 30 days. The cookie that keeps you signed in expires after thirty days and is invalidated when you sign out.
- On account deletion: immediately. Account, activities, telemetry, the coach's memory, conversations, photos and uploaded files are deleted. It cannot be undone and there is no bin to recover them from.
8. Your rights, and how to exercise them
You have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time.
Account deletion is self-service: inside the application, under "Your data", you can permanently delete the account and its stored data after confirming your password. Access and portability requests are handled on request rather than generated synchronously by the application.
To exercise access, portability, restriction, objection or any other right, write to [contact email address to be filled in]: we answer within one month, as art. 12 GDPR requires.
If you believe we are handling your data wrongly you can complain to the Italian Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to the supervisory authority of the country you live in.
9. Cookies
Koræi uses no profiling cookies, carries no advertising and has no third-party analytics. The only cookies you will find are these, and all of them are technical:
- The session cookie, which keeps you signed in while you use the application and disappears when you close the browser.
- The "keep me signed in" cookie, if you choose to stay signed in: it lasts thirty days and is invalidated when you sign out.
- The anti-CSRF cookie, which stops another site from submitting forms in your name.
- The appearance cookie, which remembers the theme and the colour you chose so that the pages before sign-in keep them. It holds two words — dark.tiffany, for instance — and nothing else: no identifier, nothing that says who you are. It lasts a year.
None of these needs a consent banner, because all of them are strictly necessary to provide the service you asked for.
10. Children
You must be at least 16 to sign up. Date of birth is asked on the registration form, and somebody who has not yet turned sixteen does not get an account: this is a check, not a warning. Sixteen is the age at which a minor may consent for themselves in Italy (art. 8 GDPR with art. 2-quinquies of the Codice privacy), and this application asks for health data on its very first screen.
The date of birth also makes the application work — heart-rate zones, calorie needs and the readiness score all depend on age — and it is treated like every other piece of health data described in section 3.
If we find that an account belongs to someone under 16 anyway, we delete it.
11. How we protect all of this
- Passwords are stored as bcrypt hashes: not even we can read them.
- Strava connection tokens are encrypted in the database.
- Traffic travels over HTTPS.
- Every request reads only the data of whoever made it: the separation between athletes is checked by automated tests on every change to the code.
- Sign-in attempts are throttled, which is what makes brute force impractical.
12. If this notice changes
If what we do with your data changes, this page changes, and the date at the top changes with it. If the change concerns something you gave consent for, we ask you again rather than treating it as renewed.