Privacy
What we collect. Why. And how to make us forget you.
Last updated · June 14, 2026
Plain version
Kaya is a coaching platform. We move three kinds of data: who you are (name, email), what you trained (sessions, sets, runs, weight), and what your coach said to you (voice memos, messages, prescribed workouts). We don't sell any of it. We don't use it to target ads. We don't share it with data brokers. Coaches only see the athletes who connected to them with their invite code; nobody else can see anyone else.
What we collect
- Account: your name, email, and Apple user ID. Stored in Supabase Auth and our public.users row.
- Profile: city, primary sport, optional gym free-text, optional avatar photo. You enter these yourself.
- Training: sessions, sets, reps, weights, runs, GPS routes, heart-rate, calories. Either logged in-app or pulled from Apple Health with your permission.
- Coaching: messages, voice memos, prescribed workouts, check-ins. Only between you and the one coach you're connected to.
- Telemetry: anonymous funnel events (sign-in, first session, plan generated). No identifiers attached — just buckets.
- Device & app: iOS version, app version, locale. Standard crash diagnostics.
What we don't collect
- Contacts, calendar, photos library (beyond the avatar / share card you explicitly attach).
- Apple Health data we didn't ask permission for. We only read the categories listed in the HealthKit prompt.
- Anything from your browser, social accounts, or other apps.
- We don't fingerprint your device.
Who can see what
- You: everything about you.
- Your coach (if connected): your training history, your messages with them, your prescribed sessions, your voice memos to/from them. Nothing else.
- Other athletes: nothing — there is no athlete-to-athlete surface.
- Other coaches: nothing — coaches can't see athletes who didn't redeem their invite code.
- Yoshi Labs (us): only what the support process requires, and only when you ask for support.
Apple Health
Kaya reads/writes Apple Health only with your explicit per-category permission. We pull workouts, heart-rate, distance, route samples, calories. We write workouts we logged in Kaya back so your Apple Activity ring stays accurate. We never read or write categories you didn't grant.
Voice memos & messages
Voice memos and chat messages between you and your coach live in Supabase Storage with row-level security that gates them to the two parties involved. They are not shared with us, with other coaches, with other athletes, or with any third party. Deleting your account deletes them.
Deleting your account
Settings → Delete account. Deletion is immediate and permanent — we remove your profile, training history, messages, voice memos, prescribed sessions, and telemetry, and your audio and avatar files are deleted from storage. Your Sign in with Apple link is revoked at the same time through Apple's revoke endpoint. We keep only a minimal, non-identifying record that a deletion happened (a random id and a timestamp) so we can confirm it later. This cannot be undone.
Payments
Athletes never pay Kaya — there is no athlete-facing billing. Coaches pay through Stripe; we don't store card numbers. Stripe stores them. We see only the subscription state (tier, status) needed to enforce capacity caps.
Where data lives
Supabase (Postgres + Storage), hosted in their default US region. Anthropic Claude for "Ask Kaya" plan generation (prompt + response, no identifiers). Apple for Sign in with Apple. Stripe for coach billing. That is the entire vendor list as of this date.
Contact
For questions or to request a copy of your data: privacy@trainwithkaya.com. We respond within 30 days, usually faster.
Kaya is operated by Yoshi Labs, a Philippine sole-proprietorship. This policy is governed by Philippine law (RA 10173 — Data Privacy Act of 2012). If we materially change it, we'll notify everyone via the email on their account.