Your health logs
Meals, water, workouts, weigh-ins, sleep, supplements, trackers and your day reviews, mood included.
Security
A health coach only works if you can tell it everything, so this page says plainly what stays on your device, what leaves it and why, and how everything that moves is protected. Every claim here describes how Kata is actually built, not how we hope it behaves.
On your device
Your personal content is written to your device, in the app's own local storage. Nothing here flows through a Kata content database, because there is none. The one thing that also travels is the restore snapshot, and it leaves your device already sealed: it has its own section below.
Meals, water, workouts, weigh-ins, sleep, supplements, trackers and your day reviews, mood included.
Every chat with the coach, and the memory of locked-in facts it builds with you.
Progress and food photos live in the device's local database, never in ours. They are the one thing the account snapshot never carries, not even sealed.
Health concerns, medication names, your cycle log and Sensei letters are kept on device like everything else, and treated with extra care on top.
Closed weeks, kept seasons and every insight derived from your data are computed and stored locally.
The app's What Kata knows page lists every fact the coach knows, with its source, and lets you delete any of it.
Across the wire
Kata's servers are deliberately boring: accounts, counters, and one sealed restore snapshot per account. That is the whole list. These are the moments data crosses, always over an encrypted connection.
Your message and just enough context travel to the AI, answer that one request, and come back. Nothing you say is kept at the coach endpoint: what remains there is a content free row of token counts and model tier.
An email address and a sign in: exactly enough for your account to exist and to be recovered, and nothing more. Delete your account and every operational row about you goes with it, in one clean move.
Once a day the app reports that your platform was active, and sends three plain facts: platform, app version and a country code derived on our server. No health data, no behavior, nothing about your day.
A secured share and the existence of a letter cross only when you ask for them. The restore snapshot is the one that runs on its own, at most once every six hours, so a new device brings your history back. It is encrypted on your device before it goes, so what crosses is ciphertext.
On the paid plans, the text of a read-aloud, a voice note or a spoken Talk reply is sent to a voice provider to be turned into audio. It is transient, and nothing is recorded or stored.
The measures
Where data does move, the protection is structural: encryption and ownership rules that are part of the code, not a policy promise.
Every connection between the app, our servers and the AI runs over TLS. There is no unencrypted path.
Your WHOOP sign-in never lands in a server token database. On your phone the token is handed back as a sealed, encrypted blob only our server functions can open; on the web it lives in an httpOnly cookie.
When you send a doctor a data share, the summary is encrypted on your device with AES-256-GCM. The key travels only in the link itself and is never sent to or stored on our servers: we hold ciphertext, a salted hash of the recipient's email, and an expiry.
Your restore snapshot is encrypted on your device with AES-256-GCM before it is uploaded. The key is a random 256 bit value that lives in your device's secure storage and in your recovery code, and it is never sent to us: not in the row, not in a column, not in a header. What we store is the sealed envelope alone, with no key, no key id and no check value beside it, so there is nothing here to read and nothing to test a guess against.
Every operational table is guarded by row-level security. The one row that holds account content, the sealed restore snapshot, is locked to your own signed-in account: no other account can reach it, and nobody can read it, us included.
Backups
Backups exist so a lost phone never means a lost history, and they follow the same ownership rules as everything else.
FAQ
On your device. Logs, chat history, Kata's memory of you, photos and integration tokens are written to your device, not into a content database of ours. Two things travel: your message and the context it needs go to the AI to generate a reply and are kept by no one afterwards, and on Android and web one restore snapshot of your account, encrypted on your device with a key we never receive, so what we hold is ciphertext we cannot open. That is how Kata is built, not just a promise. Details in the data & privacy model.
Never readable to us: your chats, your logs, Kata’s memory of you, your decisions. Your photos are never uploaded to us at all. What the restore snapshot carries is ciphertext, sealed on your device with a key we never receive, so we can hold it but not open it. We never build an advertising profile from any of this and never sell it. The marketing website does use basic, aggregate visitor analytics you can decline, and it never touches any of this.
Yes. The app has a full JSON export, worth keeping as your own backup, and a wipe that clears everything from the device. Deleting your account removes the email record and the encrypted snapshot with it. Keep your recovery code: a snapshot opens only with your device key or that code, and not even we can open it for you.
Your message plus the minimum context needed to answer is sent, encrypted, to our AI provider and processed there, transiently. We do not store these requests. Voice is transcribed and photos are analyzed the same way, only when you send them.
Yes, in a way we are proud of. Kata learns from abstract patterns: things like “morning trainers with a steady sleep rhythm stick to their plans”: so the product gets better for everyone. What it learns from is a coarse, anonymous sketch (an archetype and traits like activity level or sleep pattern), computed on your device. Never your chats, never your logs, never your photos, never anything that tells your story. Those stay with you, full stop.
Deleting your account removes your email and sign-in record from our systems, and the encrypted account snapshot with them. Nothing readable about your health was ever there: the snapshot is sealed on your device with a key we never receive. Wiping the app clears your local data completely and instantly. Export first if you want a backup, and keep your recovery code, because without it nobody can open a snapshot, us included.
Progress photos are written to your device, like everything else personal. They are never uploaded to us: they are left out of the account snapshot entirely, and they serve nothing but your own before/after view. On iPhone they can travel inside your own private iCloud backup, sealed on your device first, where only you reach them. If you ask Kata to analyze one, the image is processed transiently for that answer and not stored.