Skip to main content

Privacy Policy

Last updated: August 29, 2026

Overview

The Koach app and this website are operated by Equival. This policy covers both equival.io, the marketing website, and the Koach app. It explains what information each collects, how it's used, and the rights you have over it. Neither the website nor the app shows ads or tracks you across other apps or websites. The website and the app collect different things, so the sections below are split by scope: what applies when you browse the website, and what applies when you use the app.

The website

What the website collects

The website has no accounts and stores no fitness or health data. We collect anonymous usage analytics, but only after you accept our cookie banner, via Google Analytics 4 and Microsoft Clarity. We also collect crash and error diagnostics via Sentry, with emails and tokens automatically removed. The contact page links to our WhatsApp and Discord communities - following one of those links takes you to that third-party platform, governed by its own privacy policy, not ours.

How the website uses it

We use the website's analytics only to understand how visitors use it and to improve it. We never sell data. Beyond Google Analytics, Microsoft Clarity, and Sentry, the website doesn't share data with any third party.

Consent and analytics on the website

On your first visit you choose whether to accept or decline analytics. That choice is remembered in your browser and can be changed at any time from the "Privacy choices" link in the footer. Declining fully disables analytics collection. Crash and error diagnostics are handled separately: the website has no accounts, so any report is anonymous, and we send it to Sentry under our legitimate interest in keeping the site reliable (GDPR Art. 6(1)(f)) - it doesn't depend on your analytics choice, and the website currently has no separate opt-out for it. Your consent choice itself is stored in your browser's local storage until you change it; if you accept, Google Analytics 4 sets cookies retained for up to 2 years and Microsoft Clarity sets cookies retained for up to 1 year.

The Koach app

What the app collects

When you sign in with Google, we receive your account email and name. We use that address to email you, which the "Email we send you" section below explains in full. You control the fitness data you enter - weight, body measurements, meals, workouts, and check-in photos. On iOS and Android, the app reads health and activity data - steps, weight, active energy, and workouts - from your device's health service (Apple Health on iOS, Health Connect on Android) to prefill your log, and writes completed workouts and weight back to it - only on-device and only after you grant permission. When you record a weight for a day the app has already written a weight for, it first deletes the entry it wrote earlier that day, so your health service keeps one value per day instead of a duplicate; it only ever deletes entries the app itself created, never entries written by you or by another app. We also collect crash and error diagnostics via Sentry, with emails, access tokens, and body-profile fields such as height, date of birth, and sex automatically removed before a report is sent. We collect anonymous product-usage analytics: on the web via Google Analytics 4 and Microsoft Clarity, and only after you accept the consent banner; in the iOS and Android apps via Microsoft Clarity alone - they run no Google Analytics - and only if you turn on "Share usage analytics" in Settings, which is off by default. Providing this data is voluntary - without it, we can't provide the app's features to you.

How the app uses it

We use your data only to provide the app to you - tracking your nutrition, workouts, and progress. We never sell your data. Beyond the processors listed here - Supabase, Google Analytics, Microsoft Clarity, Sentry, and Resend, which sends our email - we don't share your data with any third party, except services you explicitly connect (see the AI assistants section).

Sharing data with a coach

A coach you connect with is a third party of your own choosing. When you accept a coach's invite, you decide exactly what to share with them: workouts and nutrition, each set separately to no access, view only, or view & edit, plus daily check-ins. Progress photos are handled separately from these and are off by default for every coach - they're shared only if you actively turn photo sharing on, and we never pre-select or enable it for you. This is health and fitness data, including special-category health data under GDPR Art. 9, so every category is shared only with your explicit, informed, and specific consent - nothing is shared until you've reviewed and actively confirmed it. A coach you've given edit access can create and change your workout and meal plans for you. You set these permissions separately for each coach, and can change or revoke any of them at any time from Settings → My coaches on the web app. Revoking a permission stops any new access immediately, though data already downloaded to your coach's device beforehand may remain visible there for a while - we have no way to remotely delete a copy already on their device. Removing a coach, or deleting your account, ends the sharing relationship. We don't vet, certify, or otherwise check coaches - choosing who to share with, and how much, is entirely your decision. If your coach connects an AI assistant to their own account, that assistant can access whatever you've chosen to share with them as your coach - see the AI assistants section for what that means and how revoking a share stops it.

Connecting AI assistants

You can optionally connect an AI assistant - such as Claude by Anthropic or ChatGPT by OpenAI - to the app through the Koach connector. Once you connect one and ask it questions, your Koach data - including health data such as your weight, meals, workouts, check-ins, and progress photos - is sent to that provider, which is based in the United States, so it can answer your request. Progress photos are the most sensitive data the connector can share: if you ask about a check-in that has photos, the assistant is handed a short-lived link and the provider's own servers fetch and view the photo, the same as any photo view inside the app. This transfer to the United States happens at your own direction and on your explicit consent, only when you choose to connect an assistant (GDPR Art. 49(1)(a)). This only happens for accounts that explicitly connect an assistant and approve its access; nothing is sent before you do. Disconnecting the assistant at any time immediately stops this data flow and revokes its access to your data. If you coach clients, connecting an assistant also lets it access data those clients have shared with you as their coach - their name, check-ins, workouts, nutrition adherence, and progress photos if they've turned photo sharing on - so it can answer questions about them on your behalf. For that disclosure, you act as the controller: making sure you have a lawful basis to share it with the provider is your responsibility, the same as it would be for any other tool you use in your coaching. Your clients can stop this at any time by narrowing or revoking what they share with you from their own coach settings (see the coaching section) - the assistant only ever sees what a client currently shares with you as their coach.

Storage and security

Your data is stored with Supabase in the EU region and encrypted in transit. Check-in photos are kept in private storage that only you can access, and are only ever shown through short-lived links that expire within minutes, never a public URL. If you connect an AI assistant and ask it about a check-in with photos, it is handed one of these same short-lived links so it can view the photo directly - see the AI assistants section for what that means and how to stop it. Health data read from your device's health service stays on your device - it syncs to Supabase only once it becomes part of an entry you log, like today's steps or a weight check-in. Health data is never copied to iCloud or to Android's cloud backup, and it is never used for advertising or marketing, sold, or shared with any third party except services you explicitly connect (see the AI assistants section) - its only purpose is powering the app's own features for you.

Data retention

Your data is kept until you delete it, with one exception: the record of who changed your plans and settings - you, your coach, or an AI assistant you connected - is kept for 30 days and then deleted automatically. You can delete individual entries (a meal, a workout, a check-in photo) at any time, or delete your account entirely from Settings, which immediately erases all of your rows and check-in photos. Our infrastructure providers also keep short-lived backups for disaster recovery; those expire on the provider's own rotation schedule, and once they do, they're beyond use and can't be restored back into the app. We also keep our own full-system backups, retained for up to about two months and expiring on a fixed rotation schedule. Data you delete from live systems disappears from these backups once they expire on their own rotation - we never restore an individual's data selectively out of a backup.

Consent and analytics in the app

On the web, your first visit shows a consent banner where you choose whether to accept or decline analytics; that choice is remembered in your browser and can be changed at any time from the "Share usage analytics" toggle in Settings. In the iOS and Android apps, product analytics are off by default and only start once you turn on "Share usage analytics" in Settings, which you can turn off again at any time. Declining or turning analytics off fully disables analytics collection. Crash and error diagnostics are handled separately: we send them to Sentry under our legitimate interest in keeping the app reliable (GDPR Art. 6(1)(f)), since fixing bugs doesn't depend on your analytics choice. They're on by default, but you can turn them off at any time from the "Crash reports" toggle in Settings - turning it off stops any further reports from being sent. Your consent choice on the web is stored in your browser's local storage until you change it; if you accept, Google Analytics 4 sets cookies retained for up to 2 years and Microsoft Clarity sets cookies retained for up to 1 year.

Email we send you

We send three kinds of email, and you control them separately. Account email keeps your account working: sign-in links, security notices, and answers to a request you sent us. We send it because we need it to give you the service you signed up for (GDPR Art. 6(1)(b)), and it keeps coming for as long as you have an account. Service email helps you use the app you already signed up for: a reminder to finish setting up if you haven't logged a meal yet, or a note to a coach whose client invite is still waiting. We send it under our legitimate interest in helping you get value out of the product (GDPR Art. 6(1)(f)), and you can turn it off. Marketing email is a different thing: an invitation to book a call with us promotes our coaching service, it isn't part of running your account. We send it only to people who already signed up, under our legitimate interest in direct marketing to our own users (GDPR Art. 6(1)(f); Recital 47 names direct marketing as such an interest), and you have an absolute right to object (GDPR Art. 21(2)). So every marketing email carries an unsubscribe link, and one click stops it. The link works without signing in, and we keep a record of the choice so that kind of email doesn't reach you again. Turning marketing off never stops your account or service email, and turning service email off never stops account email. We keep these messages short and about your account: we don't put the health or fitness data you logged into them. Our email is sent for us by Resend (Resend, Inc., United States), from notify.equival.io. Resend receives your email address, your name, and the message itself, then sends it on through Amazon SES in the Tokyo region (ap-northeast-1), so your email address leaves the EU. Both providers act only on our instructions, under the standard contractual clauses in their data processing terms.

Minimum age

The app is intended for users aged 16 and over. It is not directed at children, and we do not knowingly collect personal or health data from anyone under 16. If you believe we've collected data from someone under 16, contact us using the details below and we'll delete it.

Your rights

You can delete your account and all its data at any time from Settings inside the app. You can also request an export of your data, or ask us to help with a deletion, by contacting us below. If you are in the EU or EEA, you have the right to access, rectify, and erase your data, to restrict or object to its processing, to receive a copy of it in a portable format, and to withdraw any consent you've given at any time - and you may lodge a complaint with the supervisory authority in your EU member state. If you are in Israel, you have similar rights under the Protection of Privacy Law, 5741-1981 - including the right to access and correct data we hold about you - and may lodge a complaint with the Israeli Privacy Protection Authority.

Consumer health data (US)

If you're in a US state with its own consumer-health-data law, such as Washington's My Health My Data Act or Nevada's SB 370, the fitness and wellness data you enter or that we read from your device's health service - weight, workouts, meals, check-ins, and the health categories listed above - is "consumer health data" under those laws. We collect it to provide the app's tracking and coaching features to you, and for the crash and analytics purposes described elsewhere in this policy. We never sell your health data, and we never share it for advertising. You can access or delete it at any time using the same contact details and in-app deletion described in "Your rights" above.

Contact

Questions or requests about this website, the app, or your data? Email us at shonp@equival.io.

Back