Security

Private by architecture.

A health coach only works if you can tell it everything, so this page says plainly what stays on your device, what leaves it and why, and how everything that moves is protected. Every claim here describes how Kata is actually built, not how we hope it behaves.

On your device

What never leaves your phone.

Your personal content is stored on your device, in the app's own local storage. It is not synced to a Kata content database, because there is none.

Your health logs

Meals, water, workouts, weigh-ins, sleep, supplements, trackers and your day reviews, mood included.

Your conversations

Every chat with the coach, and the memory of locked-in facts it builds with you.

Your photos

Progress and food photos live in the device's local database, never on our servers.

The especially private

Health concerns, medication names, your cycle log and Sensei letters are kept on device like everything else, and treated with extra care on top.

Your seasons and weeks

Closed weeks, kept seasons and every insight derived from your data are computed and stored locally.

Yours to see and delete

The app's What Kata knows page lists every fact the coach knows, with its source, and lets you delete any of it.

Across the wire

What leaves, and why.

Kata's servers are deliberately boring: they hold accounts and counters, not content. These are the moments data crosses, always over an encrypted connection.

When you talk to the coach

Your message and the relevant context travel to the AI to answer that one request, and the reply comes back. Our servers keep no conversation content: what gets recorded is a content-free usage row with token counts and the model tier. The processor behind Kata AI is named in the privacy policy.

Your account

An email address and your sign-in, so your account exists and can be recovered. Deleting your account removes the operational rows about you.

A daily heartbeat

Once a day the app reports that your platform was active: platform, app version and a server-derived country code. No health data, no behavior beyond being active today.

Only when you choose it

A secured share you send, a backup snapshot on Android and web, a letter's existence for your account history: each crosses only on your explicit action or setting, and each is described below.

The measures

How the moving parts are protected.

Where data does move, the protection is structural: encryption and ownership rules that are part of the code, not a policy promise.

Encrypted in transit

Every connection between the app, our servers and the AI runs over TLS. There is no unencrypted path.

Sealed connection tokens

WHOOP and Strava sign-ins never land in a server token database. On your phone the tokens are handed back as sealed, encrypted blobs only our server functions can open; on the web they live in an httpOnly cookie. Strava is read-only by design.

The encrypted share

When you send a doctor a data share, the summary is encrypted on your device with AES-256-GCM. The key travels only in the link itself and is never sent to or stored on our servers: we hold ciphertext, a salted hash of the recipient's email, and an expiry.

Owner-only tables

Every operational table is guarded by row-level security. The one row that holds account content, the optional restore snapshot, can only ever be read by your own signed-in account.

Backups

Your backup, your cloud.

Backups exist so a lost phone never means a lost history, and they follow the same ownership rules as everything else.

  • iPhoneKata backs up to your own private iCloud: encrypted to your Apple ID, invisible to us, restored automatically when you sign in on a new device.
  • Android and webThere is no private per-user cloud to lean on, so Kata keeps one restore snapshot per account on our database: guarded by owner-only row-level security, readable by your signed-in account and no one else, photos not included. It is the one deliberate exception to servers that hold no content, and it exists so a new device brings your data back.
  • Export my dataIndependent of both, one complete file of everything, prepared on your device. Keep it wherever you like, import it anywhere.

Independent review

No badge today. Honestly.

There is no third-party security certification on this page yet, and we will not decorate it with one that means nothing. When an independent security review of Kata is completed and published, it will be linked here with its date and scope.

Until then, everything above is stated so it can be checked: against the app, against the privacy policy, and against what the product actually does.

FAQ

Fair questions, straight answers.

Where does my data actually live?

On your device. Logs, chat history, Kata's memory of you, photos and integration tokens are stored locally, never on our servers. To coach you, your messages and context are sent to the AI to generate a reply, then kept by no one: that is how Kata is built, not just a promise. Details in the data & privacy model.

What does the server see?
  • Your account basics: email and sign-in timestamps.
  • How often the app is opened and when it was last active.
  • Aggregate AI usage numbers for fair use: never what was said.
  • An abstract picture of you the app computes on your device: an archetype word and coarse traits like activity level, sleep pattern or phase. Never names, numbers or content.
  • Your invite status and your plan.
  • Standard technical hosting logs (IP, request time) at Vercel.

Never on our servers: your chats, your logs, your photos, Kata’s memory of you, your decisions. Those live only on your device. We never build an advertising profile from this data and never sell it. The marketing website does use basic, aggregate visitor analytics you can decline, and it never touches any of this.

Can I export or wipe my data?

Yes. The app has a full JSON export (use it as your backup, since we cannot restore what we never had) and a wipe that clears everything from the device. Deleting your account removes the email record too.

What happens when I talk to Kata?

Your message plus the minimum context needed to answer is sent, encrypted, to our AI provider and processed there, transiently. We do not store these requests. Voice is transcribed and photos are analyzed the same way, only when you send them.

Does Kata learn from my data?

Yes, in a way we are proud of. Kata learns from abstract patterns: things like “morning trainers with a steady sleep rhythm stick to their plans”: so the product gets better for everyone. What it learns from is a coarse, anonymous sketch (an archetype and traits like activity level or sleep pattern), computed on your device. Never your chats, never your logs, never your photos, never anything that tells your story. Those stay with you, full stop.

What happens to my data if I delete my account?

Deleting your account removes your email and sign-in record from our systems; that is all we ever held. Your health data is only ever stored on your device, so wiping the app clears it completely and instantly. There is no server copy to hunt down, which is the point. Export first if you want a backup: we cannot restore what we never had.

How do the physique photos stay private?

Progress photos are stored only on your device, like everything else personal. They are not uploaded to a gallery, not synced to a server and never used for anything but your own before/after view. If you ask Kata to analyze one, the image is processed transiently for that answer and not stored.

All questions