1. Controller
The controller responsible for the processing described in this notice is:
KestivoOwner: Alexander Volkov
Alexander Volkov Software- und App-Entwicklung
Kreuelskamp 39
41169 Mönchengladbach
Germany
Email: hello@kestivo.app
VAT identification number: DE464474746
Kestivo is the business designation of a German sole proprietorship that is not entered in the commercial register.
2. Scope
This notice applies to the public website at kestivo.app, the private-beta waitlist, email enquiries and support, and the Kestivo iOS application when it is used internally or made available to beta users.
It covers account data, athlete-profile and race data, training preferences, planned and completed workouts, Apple Health workout imports, derived training-load and physiology information, AI-planning requests, and connected-service data where a user voluntarily enables an integration.
Payments and subscriptions are not currently part of the private-beta processing described here. If Kestivo introduces materially different processing, such as additional wellness data, advertising analytics, payments or new connected services, this notice will be updated before or when that processing begins.
3. Categories of personal data and sources
Depending on the features you use, Kestivo may process:
- Account and contact data: email address, first and last name, display name, account identifiers, verification status and support correspondence.
- Athlete profile data: date of birth, height, weight, timezone, selected sports, experience, goals, availability, preferred rest days, training preferences, equipment and facility access.
- Race and planning data: race goals and dates, target information, known holidays or dated exceptions, Training Roadmap content, weekly-plan drafts, approvals, rejections, edits and workout-calendar data.
- Training-zone and threshold data: cycling FTP, run threshold pace, swim CSS, heart-rate thresholds and the training zones derived from or adjusted from those values.
- Completed-training data: sport, activity start and end time, duration, distance and, where available, heart rate, pace or speed, power, cadence, elevation, device/source information and related activity metadata.
- Athlete feedback: RPE, feeling, completion notes and other text that you deliberately enter.
- Derived coaching data: planned-versus-actual matching, training-load results, daily load evidence, ATL, CTL, TSB, confidence, limitations and other deterministic planning evidence.
- AI operational metadata: request ID, feature type, prompt/context version, model identifier, lifecycle and validation status, token counts, estimated cost, safe error codes and execution timestamps.
- Technical data: IP address, request time, device and operating-system information, application version, network/security information and service logs required for delivery, security and troubleshooting.
Personal data is obtained directly from you; from Apple Health / HealthKit after you grant iOS permission; from Garmin Connect if you later connect Garmin and authorize access; from Kestivo's own deterministic calculations and AI-assisted planning processes; and from infrastructure providers when they operate Kestivo services.
4. Purposes and legal bases
| Purpose | Typical data | Legal basis |
|---|---|---|
| Create and secure the app account | Account, verification and technical security data | Art. 6(1)(b) GDPR; Art. 6(1)(f) GDPR for account and service security |
| Provide athlete profile, Roadmap, weekly planning, calendar, workout and history functions | Athlete, race, planning, workout and feedback data | Art. 6(1)(b) GDPR |
| Import and use health-related workout information | Apple Health or connected-service activity data and derived physiology | Art. 6(1)(a) and, where the data is health data, explicit consent under Art. 9(2)(a) GDPR |
| Provide AI-assisted Roadmap and weekly-planning functions | Selected athlete context, planning data and recent training evidence | Art. 6(1)(b) GDPR; where health data is included, Art. 9(2)(a) GDPR |
| Operate usage limits, security, error handling and cost controls | Minimal operational metadata and technical logs | Art. 6(1)(f) GDPR; legitimate interests in secure, reliable and economically controlled service operation |
| Manage the private-beta waitlist and beta communications | Name, email, consent and delivery data | Art. 6(1)(a) GDPR |
| Answer enquiries and provide support | Email and correspondence | Art. 6(1)(b) GDPR for pre-contractual matters; otherwise Art. 6(1)(f) GDPR |
| Comply with legal obligations and defend legal claims | Relevant records where necessary | Art. 6(1)(c) GDPR and Art. 6(1)(f) GDPR |
5. Health and training data
Some workout, physiological and performance data can constitute data concerning health within the meaning of Article 9 GDPR. Kestivo processes such data only for athlete-facing training, planning, history, analysis and related product functions. Where Article 9 applies, Kestivo relies on explicit consent under Article 9(2)(a) GDPR.
Kestivo does not request Garmin Health API access for the initial Garmin integration and does not currently need all-day Garmin wellness data such as sleep, stress, Pulse Ox or Body Battery for the core product loop. The current Apple Health integration is focused on completed workout data, not a general extraction of the user's complete Health database.
Kestivo does not sell health or training data, use it for advertising, or disclose it to other Kestivo users.
6. App account and athlete profile
Kestivo uses Supabase Auth and Supabase PostgreSQL to authenticate users and store app data. Supabase processes login and verification information required to establish an authenticated session. Kestivo does not store plain-text passwords in its application database.
Athlete records are associated with the authenticated user. Row Level Security and authenticated ownership rules are used so that users can access only data authorized for their account. The app may require certain profile information to generate meaningful training plans. Other fields are optional; leaving them blank can reduce the specificity of planning.
7. Apple Health / HealthKit
If you authorize Apple Health access, Kestivo may read permitted completed-workout records through Apple's HealthKit framework. The current synchronization uses a bounded initial history window and then incremental change tracking. Kestivo normalizes permitted workout facts into its own completed-activity model so they can be displayed, matched against planned sessions, used in training-load calculations and considered in future planning.
Depending on the workout and source, imported facts may include workout type, time, duration, distance, heart-rate values, pace/speed, cycling power, cadence, elevation and source/device metadata where available.
HealthKit permission is controlled by you in iOS. You can revoke Kestivo's Health permissions in Apple settings. Revoking permission stops future access but does not necessarily delete workout data that was already imported into Kestivo. You may request deletion of imported data or your account as described below.
Kestivo does not write or modify your Apple Health records as part of the completed-workout ingestion described in this notice unless a future feature is specifically introduced and disclosed.
8. Garmin Connect
Direct Garmin integration is planned and is subject to Garmin approval. If and when you connect Garmin, Kestivo will access Garmin data only after your authorization through Garmin's connection flow and only for the functionality made available in Kestivo.
The intended initial scope is the Garmin Activity API and Training API:
- Activity import: receive completed activity information such as activity identity, sport, time, duration, distance and available workout metrics so Kestivo can show training history, match planned and completed sessions, calculate supported training load and use recent training as planning evidence.
- Structured workout delivery: send Kestivo workouts selected for synchronization to Garmin Connect so they can be executed on compatible Garmin devices.
Kestivo will store only the integration credentials, external identifiers and sync metadata needed to operate the connection, together with the normalized workout/activity information required for Kestivo functionality. Garmin credentials and client secrets are handled through secure backend components and are not embedded as privileged secrets in the iOS app.
Disconnecting Garmin stops future access or synchronization. Data already imported into Kestivo may remain until you delete it or request deletion. Garmin remains an independent provider with its own privacy terms. See Garmin Connect Privacy Policy.
9. AI-assisted planning and OpenAI
Kestivo uses the OpenAI API through secure backend functions for AI-assisted planning features. Depending on the feature, Kestivo may send a minimized selection of athlete-owned context such as race goals, availability, relevant zones or thresholds, equipment/access, current Roadmap direction, recent completed training, derived physiology/limitations and a bounded instruction that you choose to provide.
Kestivo does not intentionally send authentication credentials, access tokens, API secrets or complete raw HealthKit payloads to OpenAI. Context is selected for the requested planning function and should be limited to what is needed for that function.
Production AI request logs are deliberately minimized. They store operational metadata such as request ID, feature type, prompt/context version, model, status, token counts, estimated cost, safe error codes and timing. They do not persist complete prompts, raw provider request bodies, athlete profiles, health metrics, workout history or provider response bodies in the normal ai_request_logs lifecycle.
OpenAI processes API customer data on Kestivo's behalf under contractual data-processing terms. For customers in the EEA, OpenAI's current DPA identifies OpenAI Ireland Ltd. as the contracting data processor. International processing may involve approved subprocessors and transfer safeguards. See the OpenAI Data Processing Addendum.
10. Training load, physiology and profiling
Kestivo derives training and coaching information from your athlete profile and training history. This can include planned-versus-actual relationships, sport-specific training load, daily load evidence, fitness/fatigue/form metrics such as CTL, ATL and TSB, confidence levels, limitations and training-phase or planning context.
These values are training-planning tools and are not medical diagnoses, medical-device outputs or guarantees of readiness or performance. Missing or uncertain data is retained as missing or uncertain rather than automatically converted into a healthy or zero-load state.
This processing is used to provide the requested training service under Art. 6(1)(b) GDPR and, where derived information constitutes health data, on the basis of explicit consent under Art. 9(2)(a) GDPR.
11. On-device storage and cached reads
The iOS app uses limited local storage for application operation. This can include authenticated session state managed by the Supabase client, user-scoped HealthKit synchronization state and versioned read-only snapshots used to show previously loaded Dashboard, Week, Workouts, Roadmap or Profile information during temporary connectivity problems.
These local read snapshots are presentation caches, not a separate source of truth. They are designed to exclude API keys, service-role credentials, raw HealthKit payloads and AI request bodies. Supabase remains authoritative for account identity and server-side data.
12. Website hosting and technical request data
The public website is delivered using Cloudflare Workers Static Assets and related Cloudflare network services. Cloudflare may process technical request data such as IP address, date and time, requested URL, HTTP method and status, referrer, browser, operating system, device, network and security information.
This processing is necessary for delivery, security, abuse prevention and troubleshooting. The legal basis is Art. 6(1)(f) GDPR. Kestivo's legitimate interests are secure and efficient website operation and protection of its infrastructure.
13. Private-beta waitlist and Brevo
When you join the beta waitlist, Kestivo processes your email address, first name if provided, consent status, registration/confirmation status and technical delivery information needed to manage the waitlist.
Kestivo uses Brevo as the waitlist and email-service provider. Registration uses double opt in. The legal basis is consent under Art. 6(1)(a) GDPR. You may withdraw that consent at any time using the unsubscribe link or by contacting hello@kestivo.app.
Joining the waitlist does not itself create an app account, guarantee a beta place or create a paid subscription.
14. Email communication and email events
When you contact Kestivo by email, Kestivo processes your email address, name where supplied, message, attachments and transmission metadata to answer and manage your enquiry.
Brevo may record technical email events such as sending, delivery, bounce and unsubscribe status. If open or link tracking is enabled for a communication, such measurement is based on consent where required and can be stopped by withdrawing the relevant communication consent.
16. Recipients and processors
Kestivo discloses personal data only where necessary to provide, secure or support the service, or where required by law. Current or planned relevant categories include:
| Provider / category | Role / purpose |
|---|---|
| Supabase | Authentication, PostgreSQL database, Row Level Security, backend functions and related infrastructure. |
| OpenAI | Processor for AI-assisted planning requests sent through Kestivo's backend. |
| Cloudflare | Website delivery, network security and infrastructure protection. |
| Brevo | Beta waitlist, double-opt-in confirmation and beta-related email delivery. |
| Apple | iOS / HealthKit platform provider. HealthKit access occurs through user-controlled iOS permissions; Apple's own processing is governed by Apple's terms. |
| Garmin | Independent connected-service provider when the athlete voluntarily connects Garmin; Garmin processes Garmin Connect data under its own privacy terms. |
| Professional advisers / authorities | Only where necessary for legal compliance, legal claims, security incidents or professional advice. |
17. International data transfers
Some service providers or their subprocessors may process data outside Germany or the European Economic Area. Where Chapter V GDPR requires a transfer mechanism, Kestivo relies on applicable safeguards such as an adequacy decision, the EU-U.S. Data Privacy Framework where available, or European Commission Standard Contractual Clauses together with contractual and technical safeguards.
Kestivo uses data-processing agreements with processors where required. Provider locations and subprocessor lists can change over time; the applicable contractual safeguards are reviewed as part of vendor management.
18. Retention
Kestivo keeps personal data only as long as required for the purposes described above, legal obligations, security or the establishment, exercise or defence of legal claims. Because the service is still in private-beta development, exact periods can depend on the type of record and service configuration. The following criteria apply:
- Account, athlete profile, planning, workout and imported activity data: generally retained while the account is active and the data is needed for Kestivo functionality; deleted or anonymised after account deletion unless retention is legally required.
- Garmin integration tokens and connection metadata: retained only while required to operate the connection and removed or invalidated after disconnect/account deletion subject to technical and legal requirements.
- AI operational request logs: retained only as long as reasonably necessary for usage control, cost monitoring, security, reliability and audit needs. Normal request logs exclude raw athlete context and raw provider bodies.
- Local app caches and synchronization state: kept on the device only as needed for operation and removed or replaced according to app/session lifecycle; deleting the app removes app-local storage subject to normal iOS behaviour.
- Waitlist data: retained until consent is withdrawn, the waitlist purpose ends or continued storage is no longer necessary. Limited suppression or consent evidence may be retained to respect opt-outs and demonstrate compliance.
- Website, security and delivery logs: retained according to the configured infrastructure services and only for as long as necessary for security and operational purposes.
- Email correspondence: retained until the enquiry is resolved and no legal or legitimate business reason requires further storage.
- Backups: deleted data may remain temporarily in restricted backup systems until normal backup rotation completes, unless longer retention is legally required.
19. Your rights
Subject to the requirements of applicable law, you may have the rights to access, rectification, erasure, restriction of processing, data portability and objection under Articles 15–21 GDPR. Where processing is based on consent, you may withdraw consent at any time with effect for the future.
To exercise these rights or request deletion/export of Kestivo account data, contact hello@kestivo.app. Kestivo may need to verify your identity before fulfilling a request.
20. Consent, Apple Health permissions and disconnecting integrations
Apple Health and Garmin connections are optional. Declining or revoking access does not prevent basic account use where the relevant feature can operate without the integration, but it may limit automatic workout import, execution sync, training-load evidence or AI-planning specificity.
Where Kestivo relies on consent, withdrawal does not affect the lawfulness of processing carried out before withdrawal. Disconnecting a provider normally prevents future synchronization; already imported information is not necessarily deleted automatically and can be removed through account/data deletion processes.
21. Automated decision-making
Kestivo uses deterministic calculations and AI-assisted generation to support training planning. It does not use the described system to make solely automated decisions that produce legal effects or similarly significant effects within the meaning of Article 22 GDPR.
AI-generated Roadmaps and workouts are proposals. Kestivo validates defined constraints and the athlete reviews, edits, rejects or approves training before it becomes the operative plan. Kestivo does not provide medical diagnoses or automated medical decisions.
22. Security
Kestivo applies technical and organisational measures appropriate to the nature of the service. Current measures include encrypted HTTPS communication, authenticated backend access, Supabase Row Level Security for user-owned data, least-privilege architecture, backend-only storage of privileged integration and AI secrets, privacy-safe logging and deterministic ownership validation.
No internet service or storage system can guarantee absolute security. If Kestivo becomes aware of a personal-data breach, it will assess and handle notification obligations in accordance with applicable law.
23. Right to complain
You may lodge a complaint with a competent data-protection supervisory authority, particularly in the Member State of your habitual residence, workplace or the alleged infringement.
Authority responsible for North Rhine-Westphalia:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenPostfach 20 04 44
40102 Düsseldorf
Germany
www.ldi.nrw.de
24. Changes to this Privacy Policy
This notice may be updated when Kestivo changes its app, website, integrations, service providers, data categories, AI functions or legal requirements. Material changes affecting consent-based processing will be handled in accordance with applicable law. The current version and date are published on this page.