The short version. Kin builds your training plan on your phone, and that is where your plan, your logged sessions and your health data stay. What you type to Kin is sent to an AI provider to be understood, never to be answered: every sentence Kin says is written by us or computed by the app from your own data. We don’t sell your data, we don’t run ads, and you can delete everything from inside the app.
Kin is operated by [LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY]. In this policy “Kin”, “we” and “us” mean that company. We are the data controller for the personal data described here.
For anything about your privacy, including requests under this policy, write to our Data Protection Officer at [PRIVACY EMAIL].
The Kin iOS app and [SITE DOMAIN] (the “Site”). It does not cover Apple Health, Google Calendar, Whoop or the App Store, which have their own policies. Where Kin connects to one of them, this policy says exactly what Kin takes from it.
Kin is local-first. Your plan is calculated and stored on your phone.
Account. When you sign in with Apple we receive a stable identifier and either your email address or Apple’s Hide My Email relay address. If you hide your email, we never see the real one. This is stored with our authentication provider, Supabase, so you can sign in again.
Training data. Your goal, the plan Kin builds, the sessions you complete, the loads, reps and distances you log, and every change Kin makes to your plan with the reason for it. This stays on your device. We hold no copy, so we cannot see it, and we cannot restore it if you lose your phone without an iOS backup. Your own iOS backup, to iCloud or a computer, may include Kin’s data under Apple’s terms; Kin itself does not use iCloud.
Health and recovery data. With your permission, Kin reads from Apple Health: workouts, heart rate, heart rate variability, resting heart rate and sleep. Kin reads them on your phone to work out how recovered you are and what today’s session should be. Kin never uploads Apple Health data to our servers, to iCloud or to any AI provider. If you connect Whoop, Whoop sends your daily recovery score, sleep and strain to our server so the app can pick them up. We keep the latest [NUMBER] days and delete them when you disconnect.
Calendar. If you connect Google Calendar, Kin reads when you are busy and when you are free so it can place sessions in real gaps, and writes Kin’s sessions to a “Kin” calendar it creates in your account. Kin does not read your events’ titles, attendees, descriptions or attachments. Kin’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
What you type to Kin. Messages you send in Kin’s chat, such as “flying Thursday, hotel gym, and my legs are wrecked”. These often describe how your body feels, which makes them health data. Section 6 says where they go.
Subscription. Payment is processed by Apple; we never see your card. Through RevenueCat we receive your subscription status, the product you bought and pseudonymous transaction identifiers.
Usage and device data. Product analytics through PostHog: screens opened, features used, app version, device model, iOS version and a pseudonymous device identifier. Pseudonymous, not anonymous: we cannot name you from it, but we can tell one device from another. We do not record your screen, your keystrokes or what you type to Kin. If you have allowed crash sharing in iOS, Apple passes us crash reports.
Connected-service tokens. When you connect Whoop or Google, the access tokens are stored encrypted, on your phone in the Keychain or on our server where the connection needs it, and deleted when you disconnect.
The Site. The email address you give the early-access form, and the standard server logs Webflow keeps: IP address, browser and pages visited.
We do not sell personal data. We do not share it with advertisers, data brokers, insurers or employers. We do not build advertising profiles. We do not use your data to train AI models, and neither do our providers (section 6).
Health data gets its own section because Apple requires one, and because it deserves one.
Kin uses a language model for one job: understanding what you type. It does not decide your training and it does not write what Kin says. Your plan is calculated by Kin’s own rules, in code. Every sentence Kin shows you is either computed by the app from your data or quoted from coaching guidance we wrote and reviewed ourselves. The model only picks which one applies.
When you send a message, our server passes the provider your message and a small structured context: the names and times of your upcoming sessions, the names of your exercises, and which question Kin just asked. It does not send your name, your email, your calendar events, your Apple Health or Whoop measurements, or the loads you have logged.
Your message itself may say how you feel: “my knee hurts”, “got a cold”. That is health data, and it goes to the provider with the message. We ask for your explicit consent before your first message, and you can stop at any time by using the buttons instead of typing.
Our providers are OpenAI, and Anthropic as a fallback, both in the United States. Under their API terms, neither uses our data to train models. Both may keep a request for up to 30 days for abuse monitoring, then delete it. Our servers do not store your messages after answering them.
Kin’s plan changes are automated and rule-based. Nothing changes in your plan until you tap Apply, and none of these decisions has a legal or similarly significant effect on you.
A small number of service providers run parts of Kin. Each processes data only on our instructions, under a written data-processing agreement, and none may use it for its own purposes.
We may also disclose personal data if the law requires it, to enforce our terms, or to protect someone’s safety. If Kin is acquired or merges with another business, your data may transfer with it, and this policy continues to apply until you are told otherwise.
Our providers operate internationally, so your data may be processed outside your country, including in the United States. For data from the EEA, the UK and Switzerland we rely on the European Commission’s Standard Contractual Clauses, with the UK Addendum where relevant, or on the EU-US Data Privacy Framework where a provider is certified under it. Transfers out of Singapore meet the Personal Data Protection Act’s transfer limitation obligation.
Wherever you live, inside the app:
By region:
Email [PRIVACY EMAIL]. We reply within 30 days and may ask you to confirm it is you. Requests are free unless they are clearly excessive.
Data is encrypted in transit and at rest. On your phone, Kin’s data is protected by iOS data protection and your passcode, and connection tokens live in the Keychain. Access to our production systems is limited to the people who need it and protected by two-factor authentication. No system is perfectly secure and we will not pretend otherwise. If a breach affects you, we will tell you without undue delay, and notify the regulator within 72 hours where the GDPR applies.
Kin is for adults. You must be 18 or older to use it. We do not knowingly collect personal data from anyone under 18; if you believe we have, email us and we will delete it.
The Site collects the email address you submit to the early-access form and the standard server logs Webflow keeps. It sets only the cookies Webflow needs to serve the page. There are no advertising trackers.
We update this policy as Kin changes. The date at the top is always the current version. If a change materially affects how we handle your data, we will tell you in the app or by email before it takes effect, and ask for your consent again where the law requires it.
[PRIVACY EMAIL]
[LEGAL ENTITY NAME], [REGISTERED ADDRESS], [COUNTRY]. Data Protection Officer: the same address.