Kynatx

Legal

Privacy

What we store, who can see it, and how to get rid of it.

Not yet in force. This notice is accurate about how Kynatx works — it was written from the data model and the deployed configuration — but the controller’s legal name, address and governing law are still placeholders, and it has not been reviewed by a lawyer. Fill them in src/lib/legal.ts and set CONTROLLER_READY to true, and this banner disappears from every legal page at once.

The short version

If you never sign in, none of your training reaches us at all. It stays in a database on your phone and we have no copy of it.

If you do sign in, we store what you log so it can sync to your other devices and so a coach you have chosen can see it. We do not sell it, we do not advertise against it, and there is no analytics or tracking in the app or on this site.

Who is responsible

Kynatx is run by [FULL LEGAL NAME], [POSTAL ADDRESS, CITY, COUNTRY], who is the data controller for everything described here. Kynatx is not a registered company; the controller is an individual, and that is what makes them answerable for it.

Questions, corrections and complaints: hello@kynatx.com.

What we store about you

To let you in

Your phone number, which is how you log in. Optionally an email address, which exists so you can still get in if you lose the number. A display name if you set one.

Your training, but only when signed in

Workouts, sets, exercises, body weight and measurements, the plans you follow and the schedule you follow them on.

If you work with a professional

Messages between you, programs and meal plans they assign, anything you log against them, forms they ask you to fill in, documents either of you attach, goals and habits, and what you have paid them if they record it.

If you post to the community

Your post, any photo or clip on it, your likes and comments.

Automatically

Standard server logs, and crash reports when something goes wrong. Crash reports include your IP address and which account hit the error.

Why we are allowed to store it

Where GDPR applies, the legal bases are: performance of a contract for your account, sync, and anything a professional you engaged delivers through the platform; legitimate interests for keeping the service secure, debugging it, and preventing abuse; consent for anything you publish — a community post, or a public professional profile — which you can withdraw by deleting the post or switching the profile off; and legal obligation for records we have to keep.

We never rely on legitimate interests to share your training with a professional. That happens only because you accepted the link, and only for as long as it lasts.

Who can see your training

You. And a coach or nutritionist you have an active link with — which exists only because you accepted it, redeemed their invite code, or because they created the account for you before you had one.

You can turn history sharing off for any professional individually. They then see only the sessions they wrote themselves, and never what you did before you met.

Gym staff never see your training data. A gym you belong to can see your membership and your check-ins, and nothing else. That boundary is enforced in the code, not by policy.

When a professional can write into your history

A professional you are actively linked with can log a workout into your history, and that is on unless you turn it off. It is a single switch, it is per professional, it lives in your own settings in the app, and only you can change it — a coach or nutritionist can never turn it back on for themselves. Turning it off ends their writing and nothing else; the relationship, their programs and their plans all carry on.

Beyond that switch they can write only in ways that expire by themselves: while you are in a live session together, when you accept a specific workout they sent you, or while a shared workout you joined from your own device is open. If they created your account before you ever logged in, they can write until the first time you log in — and never again after that.

Writing is not reading. Whether a professional can write a session is a different switch from how much of your history they can see, and turning one on never changes the other.

Every time a professional reads or changes something of yours, it is recorded where you can read it, in the app.

What is public

If you are a coach or nutritionist, your professional profile is listed on this site by default — your display name, photo, bio, city, specialties, qualifications and any rate range you set. You can turn that off in the app at any time, and doing so removes it from the site and from search results as they refresh.

Your ratings and your client count are never published, and no training data of any client is ever published, in any form.

A community post is visible to everyone signed in to Kynatx. It is not on the public web.

Who else processes your data

Each of these receives only what it needs to do its job. None of them may use your data for their own purposes.

WhoWhat forWhat reaches themWhere
HetznerHosting and databaseEverything stored in the account — this is where the platform runsGermany (EU)
VercelHosting for this websiteStandard request logs, including IP address, for pages on kynatx.comEU / United States
WhatsApp (Meta)Delivers the login codePhone number and the six-digit codeUnited States
ResendDelivers emailEmail address and the message sent to itUnited States
StripeTakes payment from professionalsPayment details and billing contact. Card numbers never reach KynatxUnited States
Whish PayTakes payment from professionals in LebanonPayment amount and referenceLebanon
AgoraCarries video and audio callsThe call itself, and a session identifier. Calls are not recordedUnited States
Backblaze B2Stores filesProfile pictures, meal photos, community posts, coach video, client documentsEuropean Union
SentryError monitoringCrash and error reports, including IP address and the account identifier of whoever hit the errorEuropean Union
MuscleWikiSupplies exercise demonstration clipsYour IP address, when a clip you asked to watch is playedUnited States
Google PlayDistributes the Android appWhatever Google collects as the store — governed by Google’s own policyUnited States

The platform itself runs on servers in Germany. Some of the services above are outside the European Economic Area; where they are, transfers rely on the European Commission’s standard contractual clauses or an equivalent safeguard.

We have never sold personal data and will not.

How long we keep it

WhatHow long
Training logged while signed outNever leaves the phone. Removed by uninstalling the app
Your account and training historyUntil you delete the account
Login codesTen minutes, single use
Signed-in sessionsUp to a year, and immediately when you log out
Read notificationsDeleted after 90 days. Unread ones are kept
Community postsUntil you or a moderator deletes them
Files you uploadWhile the post, profile, plan or message using them exists
A deleted accountMarked deleted and made unreachable straight away; the phone number is released for reuse. There is no restore

Your rights

You can ask for a copy of what we hold, ask us to correct it, ask us to delete it, object to a particular use, or ask for it in a portable form. Two of those you can do yourself without asking anyone: export a full backup from the app’s settings, and delete your account from the same screen.

For anything else, email hello@kynatx.com. We will answer within 30 days.

If you are in the EU or UK and think we have handled your data badly, you can complain to your national data protection authority. We would rather you told us first.

Deleting your account

You can delete your account from the app, or request it without installing anything on the account deletion page.

Your record is marked deleted and becomes unreachable, and your phone number is released so it can be used again — including by whoever gets that number next. There is no restore, so export anything you want to keep first.

Anything stored only on your phone is removed by uninstalling the app.

Children

Kynatx is not intended for anyone under 18, and the Google Play listing says so. We do not knowingly collect data from children. If you believe a child has an account, email us and it will be removed.

Security

Everything travels over an encrypted connection. There are no passwords to steal — you log in with a code sent to your phone. Access to another person’s training data has one single path through the code, and it requires a link that person accepted.

No system is perfect. If something goes wrong in a way that puts you at risk, we will tell you rather than wait to be asked.

Cookies

This site sets no analytics, advertising or tracking cookies, and neither does the app. The detail is on the cookies page.

In effect from 23 August 2026. If this changes in a way that affects you, the app will say so rather than relying on you re-reading this page.