Legal
Privacy policy
Last updated: May 2026 (draft)
This policy explains what Kip26 collects, why, and what we do with it. It applies to the Kip26 web app, the marketing site at this domain, and any mobile apps we ship under the Kip26 name.
Information we collect
Account information
When you sign up we store your email address, your name (if provided), and a hashed password. Sessions are managed by a cookie-based authentication service (Better Auth).
Training data from connected services
If you connect Garmin Connect or Strava, we read your activities (runs, heart rate, pace, laps) and store them in our database so the coach can reference them.
Strava access uses OAuth 2.0. Garmin access currently uses credentials you provide to us; those credentials are encrypted at rest using AES-256-GCM with keys held only on our server. You can disconnect either service at any time from Settings.
Coaching content
Chat messages, plans, races, lactate tests, and the coach's long-term memory are stored to make the product work. You can view what the coach remembers about you at any time on the Memories page in the app.
Beta signup list
If you submit the beta form on this site, we keep your email, name (optional), and any message you sent so we can invite you when seats open up.
How we use AI
Coaching responses are generated by Anthropic's Claude models. To produce a useful answer, we send the model a context block containing your recent activity summary, active plan, upcoming races, lactate data, and salient memories — plus the conversation so far.
Anthropic processes that data on our behalf as a sub-processor. We do not use your training data to train any model.
How we share data
We do not sell your data and we do not run third-party advertising. We share data only:
- With sub-processors we need to operate the service (hosting, database, AI inference).
- If required by law or to protect the rights and safety of users.
Your rights
You can request a copy of your data, delete your account, or revoke a connected service at any time. For now, please email us at hello@kip26.com.
Contact
Questions about this policy: hello@kip26.com.
TODO before public launch: confirm legal basis under GDPR, list sub-processors with links, add data retention periods, jurisdiction-specific rights (CCPA, etc.), DPO contact if required.