Privacy
Privacy Policy.
Version of 6 September 2026
1 Controller
BSNS GmbHBirkenstrasse 47
6343 Rotkreuz, Switzerland
contact@yourkata.com
BSNS GmbH is the controller for the processing described in this policy. It covers the websites yourkata.com and docs.yourkata.com, the Kata web app at app.yourkata.com, and the Kata mobile apps for iOS and Android.
BSNS GmbH has not appointed, and is not required to appoint, a statutory data protection officer. For every privacy matter, contact@yourkata.com is the direct line to the people responsible.
2 The short version
Your health data belongs to you. All logs, chats, photos and Kata's memory of you are written to your device, not into a content database of ours: in the browser and in the mobile apps alike. We never advertise to you, never sell data, and never profile your health data. The only measurement we run is basic, aggregate visitor analytics on this marketing website (Google Analytics), which you can decline in the banner and which never touches your health or account data (section 4). Beyond the email address and account identifier that sign you in, two things leave your device: your message to Kata, sent to the AI to generate your reply and kept by no one, not even us; and, on Android and the web, one restore snapshot of your account, encrypted on your device before it is uploaded, under a key we never receive. We hold that snapshot as ciphertext, we have no technical means to open it, and your photos are never in it (section 7). Two features you switch on yourself add more, deliberately: Kata Duo shares one yes-or-no value a day with the partners you invite and nothing about what you did (section 14), and a secure share sends a summary you assemble to a person you name, sealed on your device so it stays unreadable to us as well (section 15).
3 Legal framework
We process personal data in accordance with the Swiss Federal Act on Data Protection (FADP, revised version in force since 1 September 2023) and, where it applies to users in the European Economic Area, the EU General Data Protection Regulation (GDPR). Where this policy names a legal basis, it refers to Art. 6(1) GDPR; under the FADP, the processing described here is covered by the principles of Art. 6 FADP and does not rely on consent unless stated.
4 Website visits
- Analytics: this website uses Google Analytics (provided by Google Ireland Limited) to measure visits and traffic in aggregate: pages viewed, approximate region from a shortened IP address, device and browser type, and how you arrived. It sets its own cookies. This is anonymous, aggregate usage data about the website only; it is never linked to your Kata account and never includes health or personal-account data. It loads only if you accept it in the consent banner, and you can decline. Legal basis: your consent (Art. 6 (1) (a) GDPR; Swiss FADP).
- Consent banner: analytics load only after you accept. Your choice, accepted or declined, is remembered as a single flag in your browser’s localStorage, and until you accept no analytics cookies are set and no analytics data is sent. Clearing that storage lets you choose again.
- Hosting: Vercel Inc., USA, delivers the website and processes technical server logs (IP address, request time, user agent) to run and defend the service (legitimate interest). Processing can take place in the EU and the US; transfers are covered by the EU standard contractual clauses and the Swiss transborder data flow rules.
- Fonts are self-hosted and delivered by the same hosting as the pages. No third-party font service is contacted, and no request of yours reaches one.
5 Website forms (contact and partnership)
If you use the contact or partnership form, we process the details you submit (name, email address, topic, company where given, and your message) to answer your request (performance of a contract or steps prior to entering one; legitimate interest for general enquiries). The messages are delivered to our mailboxes by Resend, Inc., USA, acting as our processor, and are kept as long as needed to handle the conversation and any follow-up. Form data is never used for advertising and never shared beyond this purpose.
6 App: account data
To create and secure your account we process your email address, a user identifier (your account ID), the authentication method and authentication timestamps, on every surface (web and mobile apps). Authentication is provided by Supabase, acting as our processor, with the project hosted in the EU (Zurich region). You can sign in with email and password, Google, Apple or a magic link; when you use a third-party sign-in, that provider confirms your identity to us and we store only your email address and account ID. If you sign in with Apple and choose Hide My Email, Apple gives us a private relay address instead of your real email; our transactional emails are sent to that relay and forwarded by Apple to you. Supabase holds no readable health data. What else sits in that database is described in sections 7, 14 and 15: ciphertext we cannot open and, if you use Kata Duo, one yes-or-no value a day.
7 Your health data and where it lives
Kata is local-first on every surface. All health logs (weight, food, water, training, sleep, supplements), your chat history, Kata’s memory of you, your photos and your decisions log are written to your device: in the browser’s storage in the web app (localStorage for settings and structured logs, IndexedDB for larger content such as photos) and in the app’s local storage on iOS and Android. That is the only place any of it exists in readable form. We run no content database, and there is nothing on our side that we could open, read or hand over. If you delete the app or clear its site data, it is gone; the built-in export exists so you can back it up first.
One thing does leave your device, and this is exactly what it is. So that a lost or replaced phone does not mean a lost history, the app keeps a single restore snapshot of your account. On iOS it goes to your own private iCloud and never to us (section 11). On Android and the web, where there is no private per-user cloud to lean on, we store it as one row per account. Before that snapshot leaves your device it is encrypted there with AES-256-GCM, under a random 256 bit key that is generated on your device, kept in the device’s secure storage and shown to you once as your recovery code. That key is never sent to us in any form: not in the row, not in a column, not in a request header, not in a log.
The row holds the sealed envelope and nothing else: a format marker, a version number, the algorithm name, the random initialization vector, the ciphertext, the time it was sealed and the schema version of the data inside. No key, no key identifier, no hash of the key, no salt and no check value is stored beside it, so there is nothing on our side against which a guess could even be tested. We hold ciphertext we have no technical means to read, and only you hold what opens it. Your photos are never part of this snapshot. Row-level security is the second lock: the row is tied to your signed-in account and no other account can reach it. It is refreshed at most once every six hours, overwritten each time, and deleted with your account. If your device cannot encrypt, nothing is uploaded at all.
Health data you import from Apple HealthKit or Google Health Connect is treated exactly like every other health entry: it lives on your device, and it never reaches us in readable form.
8 AI coach
When you talk to Kata, your message and the minimum context needed to answer it are transmitted over an encrypted connection to our AI provider (currently Anthropic PBC, USA) and processed there transiently to generate the reply. We do not store the content of these requests on our servers; we record only aggregate token counts per account for cost control. Voice input is transcribed and photos are analyzed the same way, only when you send them.
9 Abstracted product signals
To improve Kata, understand our audience and enforce fair use, we store a small set of abstracted, non-personal signals per account: app-open counts and last-active timestamps; aggregate AI usage numbers (token counts per account, never message content); an abstract persona summary that the app computes on your device (an archetype word plus coarse traits such as activity level, top sport types, eating consistency, sleep pattern, current phase, optional self-stated gender, country and timezone); invite and voucher attribution; and your subscription plan.
Explicitly not held in readable form on our servers: your chats and conversation history, your health logs, Kata’s memory of you and your decisions log. Your photos are not uploaded to us at all. The rest reaches us only inside the encrypted account snapshot described in section 7, as ciphertext we cannot open. The abstracted signals listed here are computed on your device and cannot be used to reconstruct any of it. Legal basis: our legitimate interest in operating and improving the service (Art. 6 (1) (f) GDPR; Swiss FADP).
Two further things on our servers are health-derived without being product signals, because they exist only for as long as you ask for them: the daily yes-or-no value of Kata Duo (section 14) and the sealed summary of a secure share (section 15). They are named here so this section stays a complete picture of what we hold, and each is described in full in its own section.
10 Consent records
When you accept the Terms of Service or give a consent in the app, we store the record of that acceptance: the document version, the timestamp, the surface (web, iOS or Android) and the language you accepted in. These records prove contract formation and the consents you gave. Legal basis: performance of a contract and compliance with legal obligations (Art. 6 (1) (b) and (c) GDPR; Swiss FADP). They are kept for as long as your account exists and thereafter for the applicable statutory limitation periods.
11 Mobile apps: permissions and push notifications
- Push notifications: if you enable them, a device push token tied to your account is processed to deliver notifications, via Google Firebase Cloud Messaging on both iOS and Android (on iOS it relies on the Apple Push Notification service underneath). The token is an identifier used solely to deliver the notifications Kata authors: it is never used for tracking or advertising, we run no Firebase Analytics, and no personal or health data is sent to Firebase, only the token and the notification text. Tokens are deleted when you disable notifications or delete your account.
- iCloud backup (iOS): you can back up your local Kata data to your own private iCloud (Apple CloudKit private database) and restore it on your devices. The snapshot is encrypted on your device first, and it goes to your personal iCloud account under your Apple ID, never to our servers; it stays entirely in your control. Apple provides your iCloud storage.
- Camera, microphone and photo library: accessed only when you actively take or attach a photo, or speak to Kata. The access happens locally on your device; content is transmitted only at the moment you send it to Kata (section 8) and is not stored by us.
- Apple HealthKit and Google Health Connect: health data you choose to import stays on your device like all health content (section 7). We do not receive, store or share it, and we never use it for advertising.
- The privacy labels shown in the Apple App Store and Google Play describe the same practices as this policy. Should a label and this policy ever appear to differ, this policy is the authoritative description of what we do.
12 WHOOP integration
Connecting WHOOP is optional. The OAuth tokens are stored on your device, unreadable to scripts where the platform allows it, and are used solely to fetch your recovery, HRV, sleep and strain data for display on your device; they are not stored in any server database. You can revoke the connection at any time in the app or in your WHOOP account settings.
13 Invite a friend
If you invite a friend, we process the invited email address and the state of the reward (Months given and earned) to run Invite a friend. Invited addresses are used for the invitation and reward matching only, never for marketing lists.
14 Kata Duo and Kata Groups
Kata Duo is optional and only exists once you start it: you share an invitation link, and whoever accepts it becomes one of at most five duo partners. To run a pairing we store the two account identifiers, the random invitation code, whether the pairing is still pending or active, one flag per side for hiding a partner on your own profile, and the times the pairing was created and joined. The name you give a partner is not part of that: it stays on the device you typed it on, your partner never sees it, and neither do we.
What Duo actually shares is one row per person per day, holding your account identifier, the date and a single yes-or-no value: whether you kept your form that day. Your device works that value out from your own local day, and it says nothing about what you did. No log, no number, no score, no streak, no content of any kind, and nothing about what was kept. A day with nothing logged produces no row at all, which is why the third state your partner sees is an honest grey rather than a claim. Only an account you have an active pairing with can read your rows, and that boundary is enforced in the database itself; when either side ends the duo, the pairing and the visibility go at once, in both directions.
Legal basis: your consent, given when you create or accept a duo invitation and withdrawn by ending the duo (Art. 6 (1) (a) and, because the value is derived from your health use, Art. 9 (2) (a) GDPR; Swiss FADP). Retention: as part of its daily write the app deletes your own rows once they are older than 21 days, so at most about three weeks of yes-or-no values exist at any time. Ending a duo removes the pairing immediately, and everything goes when you delete your account.
Kata Groups is the same mechanism for more than two people, and it holds no more than Kata Duo does. When you start a group we store a group identifier, a group name and a label for the one thing the group tracks, the random invitation codes, and, for each member, an account identifier and a per-group display name. What a group shares is the same single yes-or-no value per member per day, whether that member kept the day, and nothing about what anyone did: no log, no number, no score, no content of any kind. Only members of a group can read that group's rows, and that boundary is enforced in the database itself; your values and your membership go the moment you leave the group or delete your account. The legal basis, and the derivation of the value from your health use, are the same as for Kata Duo above.
15 Secure share with a doctor or another person you choose
You can send a summary of exactly what you select to a person you name, typically a doctor. It happens only when you ask for it, and it happens like this. The summary is assembled on your device and encrypted there with AES-256-GCM. The key is placed in the share link itself, in the fragment that browsers never transmit to a server, so it reaches your recipient and never reaches us. We store one row per share: the ciphertext, your account identifier as its owner, a salted SHA-256 hash of the recipient’s email address, the expiry, the time the share was created and the time it was first opened.
The recipient’s address itself is not stored, only that hash, salted with the share’s own identifier so it cannot be resolved against a table of common addresses. It exists so the invitation and the access code reach the invited inbox and no other. The invitation link passes through the request once so the invitation email can carry it, and is never stored. To open a share the recipient confirms the invited address with a 6-digit code, so we also hold the bookkeeping that check needs: a hash of the active code, its ten minute expiry, the number of wrong attempts against it, which is capped at five, the number of codes sent and the time of the last one. The code is single use and the code itself is never stored. Everything else is ciphertext: we have no technical means to read the summary, and nor does anyone without the link.
Legal basis: your consent, given each time you create a share and withdrawn by revoking it (Art. 6 (1) (a) and Art. 9 (2) (a) GDPR; Swiss FADP). Retention: a share expires 14 days after you create it, and an expired row is deleted outright the next time it is touched. You can revoke a share in the app at any moment, which deletes the row and the ciphertext with it, and shares go with your account when you delete it. Creating shares is limited to ten per account and day.
16 Payment and subscription data
When you take a paid plan, we process the data needed to run your subscription: your plan and its status, the billing period, the currency and country used for tax, a customer and subscription identifier, and a record of payments and refunds. We do not receive or store your full card number; card details are handled by the payment provider.
- Web purchases: payments are processed by Stripe (Stripe Payments Europe, Ltd., Ireland, with Stripe, Inc., USA), which handles your card details and calculates applicable tax. We receive confirmation of the subscription and the limited billing details above, never the full card number.
- App Store purchases: Apple is the seller and processes the payment; we receive the verified subscription status (product, period, renewal and cancellation) needed to unlock your plan, not your payment details.
- Google Play purchases: Google is the seller and processes the payment; we receive the verified subscription status needed to unlock your plan, not your payment details.
Legal basis: performance of your subscription contract and compliance with our legal obligations, including tax and accounting retention (Art. 6 (1) (b) and (c) GDPR; Swiss FADP). Billing records are kept for the statutory retention periods.
Corporate wellness: if an organisation such as your employer covers your plan, we store your membership in that organisation (the email address it invited, whether the seat is invited, joined or removed, and the plan its deal grants) so the coverage can be applied and withdrawn. What the organisation’s manager sees is engagement only: the membership state of the people it invited, and seats, activation and active members as counts for the group, computed only once at least five members have joined so nobody can be singled out. The organisation never sees your health data, your logs, your chats or Kata’s memory of you: none of that exists on our servers in readable form, for the organisation any more than for us. Legal basis: performance of the contract that covers your seat (Art. 6 (1) (b) GDPR; Swiss FADP). Leaving the organisation, or being removed from it, ends the coverage and leaves your own data untouched.
17 Recipients and transfers abroad
- Supabase (authentication, and the database holding the encrypted account snapshot, the Kata Duo pairings and daily values, and the sealed secure shares): project hosted in the EU, Zurich region.
- Anthropic (AI processing): USA, transient processing only.
- ElevenLabs (Kata voices, on the paid plans only: reading your weekly review and letters aloud, Mégane's occasional voice notes, and the spoken replies when you Talk with Kata): USA, transient processing only, the text is turned into audio and not stored.
- Resend (transactional email, including the invitation and the access code for a secure share): USA.
- Vercel (hosting): EU and USA.
- Stripe (payment processing for web purchases): Stripe Payments Europe, Ltd., Ireland, with processing by Stripe, Inc., USA.
- Apple and Google (payment and subscription processing for purchases made in the App Store and Google Play): USA.
- Google Analytics (aggregate website usage measurement, only with your consent): Google Ireland Limited, Ireland, with processing by Google LLC, USA.
- Google / Firebase Cloud Messaging (push notification token delivery on iOS and Android; no analytics): USA.
- Apple (Apple Push Notification service underlying iOS push, Sign in with Apple and its private email relay, and your own personal iCloud backup storage): USA.
Where data reaches providers in the USA, the transfer is safeguarded by the EU standard contractual clauses and, where certified, the Swiss-U.S. Data Privacy Framework. We do not sell or rent personal data, and no other recipients exist.
18 Retention
Account data is kept for as long as your account exists and deleted when you delete the account. Consent records are kept for the statutory limitation periods (section 10). Form correspondence is kept as long as needed to handle the request. Aggregate token counts are kept for cost accounting. Billing and payment records are kept for the statutory tax and accounting retention periods. Push tokens are deleted when notifications are disabled or the account is deleted. Health data on your device is retained solely by you. The encrypted account snapshot (section 7) is a single row that each backup overwrites and that is deleted with your account; we hold no readable copy of your health data at any point. Kata Duo values are deleted once they are older than 21 days, and a pairing with all its values goes the moment either side ends the duo (section 14). A secure share expires 14 days after it is created, and its row, ciphertext included, is deleted then or the moment you revoke it (section 15).
19 Security and data incidents
All transport is encrypted (TLS). The server holds the minimum data described above, protected by access controls and the security programs of our processors. The strongest measure is architectural: your health content is either not on our servers at all or lies there only as ciphertext to which we hold no key, so a breach on our side cannot expose it.
Should a security incident nevertheless affect personal data we hold, we will assess it without undue delay and notify the competent supervisory authority and, where required, the affected persons, in accordance with Art. 24 FADP and, where applicable, Art. 33 and 34 GDPR.
20 Your rights
You have the right to access, rectification, erasure and portability of your personal data, and the right to object to processing. Since almost all data lives on your device, most of these rights are in your own hands: export, correct or wipe your data directly in the app. For anything relating to your account or a form you submitted, write to contact@yourkata.com. You may also lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or, where the GDPR applies, with your local supervisory authority.
21 Changes
We will update this policy when the service changes. The current version, with its date, is always published on this page. Material changes are announced in the app.
22 Governing law
This policy and any privacy dispute are governed by Swiss law. The engineering view of the same facts lives in the Your data docs.