Privacy

How we handle your data

1. Who handles your data

The data controller is [legal name, registered office and VAT number to be filled in], which operates the Koræi application.

For anything about this notice or about your data, write to [contact email address to be filled in]. [If a data protection officer is appointed, their details go here.]

2. The short version

3. What we handle

Your account

Email address, password (kept only as a bcrypt hash: the password in the clear exists nowhere, not even in the logs), the name you choose to show, language, theme, colour, time zone, and when the account was created and last changed.

Data about your health

This is the sensitive part, and the reason for the explicit consent in section 4: date of birth, sex, weight, height, maximum heart rate, measurements (waist, neck, hips), lifestyle, goals and disciplines, target weight and how your weight moves over time, and the answers you give to the three questions the coach asks before writing — past or current injuries, limitations, dietary, metabolic or insulin-related conditions, and allergies.

Your training

Activities (discipline, date and time, duration, distance, elevation, calories, pace, heart rate, power, cadence, training load) and the second-by-second telemetry that comes with them; gym sessions logged in the application with their exercises, sets, reps and loads; gym schedules; scheduled sessions and proposed weeks.

If you upload .FIT files, the original file is kept exactly as it is, and a .FIT file recorded by a watch also contains the GPS track. The application neither uses nor shows the coordinates — no position is written to the database — but the file stays what you uploaded. Deleting your account deletes it too.

Food

What you log as eaten, with its estimated calories and macronutrients, your nutrition targets, and the eating plan when you ask for one.

Conversations and the coach's memory

The questions you ask Koræi and its answers, the comments it writes on the dashboard's sections, and the notes the coach keeps about you — the ones under "AI notes", which you can read, correct and delete one by one.

Photographs

Your profile photo, if you upload one, is kept until you replace it or delete your account. Photographs of meals and of gym schedules are not: they are sent to the model, read, and dropped when the request ends. They never reach the disk and never reach the database. What remains is the text — the foods estimated, the exercises recognised — not the image.

Technical data

To run your session and keep sign-in safe we handle your IP address at the moment you sign in (to throttle brute-force attempts at passwords), the cookies in section 9, and application logs. Neither passwords nor the contents of conversations reach the logs.

4. Why we handle it, and on what legal basis

Consent for health data is separate from everything else and is the box you tick when you sign up, next to your acceptance of this notice. You can withdraw it whenever you want: withdrawal does not affect what was lawfully done before it, but from that moment the coach no longer has the information it works from — which in practice means the service can no longer advise you. The way to withdraw it entirely is to delete your account, which is in section 8.

5. Artificial intelligence: what leaves this application

Koræi does not reason on its own: to write an answer, a plan or an estimate it sends a language-model provider the text of your question and a summary of where you are — goals, recent training, weight, what you declared about injuries and food, and photographs of meals or schedules when it is you who sends one.

That provider is OpenAI, which handles this data as our processor and does not use it to train its models. The data travels to the United States: the transfer is made on the basis of the European Commission's standard contractual clauses, together with the measures set out in our contract with the provider.

We do not send it your email address, your name, your password or your original files.

No automated decisions with legal effects. What Koræi produces is advice about training and food: it decides nothing about you that has legal or similarly significant effects within the meaning of art. 22 GDPR, and it is not medical advice. If you have a doubt about your health, the person to ask is a doctor.

6. Who else sees your data

No sale, no transfer for advertising, no commercial profiling. Your data is seen only by the providers we need in order to run the application, each appointed as a processor under art. 28 GDPR:

Your data may also be disclosed to judicial or other authorities where the law requires it.

7. How long we keep it

8. Your rights, and how to exercise them

You have the right to access your data, correct it, delete it, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time.

Account deletion is self-service: inside the application, under "Your data", you can permanently delete the account and its stored data after confirming your password. Access and portability requests are handled on request rather than generated synchronously by the application.

To exercise access, portability, restriction, objection or any other right, write to [contact email address to be filled in]: we answer within one month, as art. 12 GDPR requires.

If you believe we are handling your data wrongly you can complain to the Italian Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to the supervisory authority of the country you live in.

9. Cookies

Koræi uses no profiling cookies, carries no advertising and has no third-party analytics. The only cookies you will find are these, and all of them are technical:

None of these needs a consent banner, because all of them are strictly necessary to provide the service you asked for.

10. Children

You must be at least 16 to sign up. Date of birth is asked on the registration form, and somebody who has not yet turned sixteen does not get an account: this is a check, not a warning. Sixteen is the age at which a minor may consent for themselves in Italy (art. 8 GDPR with art. 2-quinquies of the Codice privacy), and this application asks for health data on its very first screen.

The date of birth also makes the application work — heart-rate zones, calorie needs and the readiness score all depend on age — and it is treated like every other piece of health data described in section 3.

If we find that an account belongs to someone under 16 anyway, we delete it.

11. How we protect all of this

12. If this notice changes

If what we do with your data changes, this page changes, and the date at the top changes with it. If the change concerns something you gave consent for, we ask you again rather than treating it as renewed.