Security

Private by architecture.

A health coach only works if you can tell it everything, so this page says plainly what stays on your device, what leaves it and why, and how everything that moves is protected. Every claim here describes how Kata is actually built, not how we hope it behaves.

On your device

What lives on your device.

Your personal content is written to your device, in the app's own local storage. Nothing here flows through a Kata content database, because there is none. The one thing that also travels is the restore snapshot, and it leaves your device already sealed: it has its own section below.

Your health logs

Meals, water, workouts, weigh-ins, sleep, supplements, trackers and your day reviews, mood included.

Your conversations

Every chat with the coach, and the memory of locked-in facts it builds with you.

Your photos

Progress and food photos live in the device's local database, never in ours. They are the one thing the account snapshot never carries, not even sealed.

The especially private

Health concerns, medication names, your cycle log and Sensei letters are kept on device like everything else, and treated with extra care on top.

Your seasons and weeks

Closed weeks, kept seasons and every insight derived from your data are computed and stored locally.

Yours to see and delete

The app's What Kata knows page lists every fact the coach knows, with its source, and lets you delete any of it.

Across the wire

What leaves, and why.

Kata's servers are deliberately boring: accounts, counters, and one sealed restore snapshot per account. That is the whole list. These are the moments data crosses, always over an encrypted connection.

When you talk to the coach

Your message and just enough context travel to the AI, answer that one request, and come back. Nothing you say is kept at the coach endpoint: what remains there is a content free row of token counts and model tier.

Your account

An email address and a sign in: exactly enough for your account to exist and to be recovered, and nothing more. Delete your account and every operational row about you goes with it, in one clean move.

A daily heartbeat

Once a day the app reports that your platform was active, and sends three plain facts: platform, app version and a country code derived on our server. No health data, no behavior, nothing about your day.

Shares, letters and the snapshot

A secured share and the existence of a letter cross only when you ask for them. The restore snapshot is the one that runs on its own, at most once every six hours, so a new device brings your history back. It is encrypted on your device before it goes, so what crosses is ciphertext.

When Mégane speaks

On the paid plans, the text of a read-aloud, a voice note or a spoken Talk reply is sent to a voice provider to be turned into audio. It is transient, and nothing is recorded or stored.

The measures

How the moving parts are protected.

Where data does move, the protection is structural: encryption and ownership rules that are part of the code, not a policy promise.

Encrypted in transit

Every connection between the app, our servers and the AI runs over TLS. There is no unencrypted path.

Sealed connection tokens

Your WHOOP sign-in never lands in a server token database. On your phone the token is handed back as a sealed, encrypted blob only our server functions can open; on the web it lives in an httpOnly cookie.

The encrypted share

When you send a doctor a data share, the summary is encrypted on your device with AES-256-GCM. The key travels only in the link itself and is never sent to or stored on our servers: we hold ciphertext, a salted hash of the recipient's email, and an expiry.

The sealed account snapshot

Your restore snapshot is encrypted on your device with AES-256-GCM before it is uploaded. The key is a random 256 bit value that lives in your device's secure storage and in your recovery code, and it is never sent to us: not in the row, not in a column, not in a header. What we store is the sealed envelope alone, with no key, no key id and no check value beside it, so there is nothing here to read and nothing to test a guess against.

Owner-only tables

Every operational table is guarded by row-level security. The one row that holds account content, the sealed restore snapshot, is locked to your own signed-in account: no other account can reach it, and nobody can read it, us included.

Backups

Your backup, your cloud.

Backups exist so a lost phone never means a lost history, and they follow the same ownership rules as everything else.

  • The iPhone appKata backs up to your own private iCloud, photos included: sealed on your device before it is written, so it is opaque to us and to Apple. Sign in on a new iPhone and the key comes with your Apple ID, so Kata offers the restore straight away. With iCloud Keychain switched off, your recovery code is the way across.
  • Android and webThere is no private per-user cloud to lean on, so Kata keeps one restore snapshot per account in our database: one row, locked to your account by row-level security, no photos, refreshed at most once every six hours. It is encrypted on your device before it leaves, under a key we never receive, so the row holds ciphertext we have no technical means to read. Your recovery code is what opens it on a new device, and if the seal cannot be made, nothing is uploaded at all.
  • Export my dataIndependent of both, one complete file of everything, prepared on your device. Keep it wherever you like, import it anywhere.

FAQ

Fair questions, straight answers.

Where does my data actually live?

On your device. Logs, chat history, Kata's memory of you, photos and integration tokens are written to your device, not into a content database of ours. Two things travel: your message and the context it needs go to the AI to generate a reply and are kept by no one afterwards, and on Android and web one restore snapshot of your account, encrypted on your device with a key we never receive, so what we hold is ciphertext we cannot open. That is how Kata is built, not just a promise. Details in the data & privacy model.

What does the server see?
  • Your account basics: email and sign-in timestamps.
  • How often the app is opened and when it was last active.
  • Aggregate AI usage numbers for fair use: never what was said.
  • An abstract picture of you the app computes on your device: an archetype word and coarse traits like activity level, sleep pattern or phase. Never names, numbers or content.
  • Your invite status and your plan.
  • On Android and web, one restore snapshot of your account: a sealed blob we hold no key for.
  • Standard technical hosting logs (IP, request time) at Vercel.

Never readable to us: your chats, your logs, Kata’s memory of you, your decisions. Your photos are never uploaded to us at all. What the restore snapshot carries is ciphertext, sealed on your device with a key we never receive, so we can hold it but not open it. We never build an advertising profile from any of this and never sell it. The marketing website does use basic, aggregate visitor analytics you can decline, and it never touches any of this.

Can I export or wipe my data?

Yes. The app has a full JSON export, worth keeping as your own backup, and a wipe that clears everything from the device. Deleting your account removes the email record and the encrypted snapshot with it. Keep your recovery code: a snapshot opens only with your device key or that code, and not even we can open it for you.

What happens when I talk to Kata?

Your message plus the minimum context needed to answer is sent, encrypted, to our AI provider and processed there, transiently. We do not store these requests. Voice is transcribed and photos are analyzed the same way, only when you send them.

Does Kata learn from my data?

Yes, in a way we are proud of. Kata learns from abstract patterns: things like “morning trainers with a steady sleep rhythm stick to their plans”: so the product gets better for everyone. What it learns from is a coarse, anonymous sketch (an archetype and traits like activity level or sleep pattern), computed on your device. Never your chats, never your logs, never your photos, never anything that tells your story. Those stay with you, full stop.

What happens to my data if I delete my account?

Deleting your account removes your email and sign-in record from our systems, and the encrypted account snapshot with them. Nothing readable about your health was ever there: the snapshot is sealed on your device with a key we never receive. Wiping the app clears your local data completely and instantly. Export first if you want a backup, and keep your recovery code, because without it nobody can open a snapshot, us included.

How do the physique photos stay private?

Progress photos are written to your device, like everything else personal. They are never uploaded to us: they are left out of the account snapshot entirely, and they serve nothing but your own before/after view. On iPhone they can travel inside your own private iCloud backup, sealed on your device first, where only you reach them. If you ask Kata to analyze one, the image is processed transiently for that answer and not stored.

All questions