Draft for review. This document describes how the Kipp app handles your data. Have it reviewed by qualified counsel before launch and replace the contact details and entity name below.
Kipp ("Kipp", "we", "us") is a recovery-aware AI coaching app for athletes. This Privacy Policy explains what we collect, why, who we share it with, and the choices you have. By using Kipp you agree to this policy.
1. Information we collect
Account & identity. When you sign in with Apple or Google, we receive a unique account identifier and, on first sign-in, your name and email address.
Profile & intake. Information you provide during onboarding and coaching — name, sex, age, height, weight, goals, training history, lifestyle, and the free-text answers you give the coach.
Health & fitness data. With your permission, data read from Apple Health and connected wearables (e.g., heart-rate variability, resting heart rate, sleep, workouts, body weight). If you connect Strava or Garmin, we access your activity and recovery history from those services.
Bloodwork / lab data. If you choose to share lab results (a photo, PDF, or description), we extract the marker values and a summary. Lab images are only stored if you give explicit consent; otherwise the image is processed and discarded and only the extracted markers/summary are kept.
Photos. Meal photos you send are used to estimate nutrition and may be stored to your private account so they appear in your conversation history.
Conversations. Your messages with the coach, including voice notes (which are transcribed to text), are stored to provide continuity and to debug and improve the service.
Logged data. Meals, workouts, bodyweight, hydration, body measurements, and daily recovery snapshots you log or that sync from connected sources.
Device & usage. Basic technical data needed to operate the app (e.g., app version, an on-device identifier used to link connected services).
2. How we use your information
To provide personalized coaching across recovery, training, and nutrition.
To maintain your account, history, and the continuity of your conversation with the coach.
To operate, secure, debug, and improve the service.
We do not sell your data, and we do not use your health data for advertising.
3. AI processing
Kipp's coaching is powered by large language models. To generate responses, the relevant context (your messages, profile, and logged data, and images you send) is sent to our AI provider, Anthropic, for processing. Image bytes are excluded from our internal tracing. We rely on our providers' commitments not to use data submitted through their APIs to train their general models.
4. Apple Health (HealthKit)
If you grant access, Kipp reads HealthKit data solely to provide in-app coaching. We do not use HealthKit data for advertising or marketing, do not share it with third parties for those purposes, and do not store it in iCloud. You can revoke access at any time in the iOS Settings app.
5. Service providers
We share data only with providers that help us run the service, under their respective terms:
Anthropic — AI model processing.
Supabase — authentication, database, and file storage.
OpenAI — voice-note transcription.
Strava, Garmin — if you connect them, to import your activity and recovery data.
Open Food Facts, USDA FoodData Central — nutrition lookups (no personal data sent).
Langfuse — operational tracing (configured to exclude message text in production).
6. Data retention & deletion
We keep your data for as long as your account is active. You can permanently delete your account and all associated data at any time from Settings → Delete account in the app. Deletion removes your profile, conversations, logged data, lab panels, stored images, and connected-service tokens, and revokes connected sessions.
7. Security
Data is encrypted in transit and stored in access-controlled systems scoped so that you can only access your own records. No system is perfectly secure, but we take reasonable measures to protect your information.
8. Children
Kipp is not intended for anyone under 17. We do not knowingly collect data from children.
9. Your rights
You can access, correct, export, or delete your data. Account deletion is available in-app (Section 6); for other requests, contact us below.
10. Changes
We may update this policy. Material changes will be reflected by the "Last updated" date and, where appropriate, surfaced in the app.