Privacy Policy — Kydos Health L.L.C.
Effective Date: June 6, 2026 Last Updated: August 30, 2026 Version: 5.13
Our Position
Kydos Health L.L.C. does not sell your data. We do not share your health data with third parties for commercial purposes. We do not use your data to train machine learning models. We serve no ads, use no ad SDKs, and use no third-party behavioral analytics tools. These are not aspirational statements — they are binding commitments reflected in how we built this product.
1. Who This Applies To
This Privacy Policy applies to all users of the KYDOS mobile application ("App"), operated by Kydos Health L.L.C. ("KYDOS," "we," "us"). Contact us at privacy@kydoshealth.com.
2. What We Collect
Account and profile information When you create an account, you provide your email address, username, and display name — either directly, or by signing in with Apple or Google. If you use Sign in with Apple or Google, we receive your name and email address (or, if you choose Apple's private relay option, a private forwarding address that reaches your real inbox without revealing it to us) directly from Apple or Google to create your account; we never receive or store your Apple ID or Google password. You may also provide your height, weight, body composition, fitness goals, training preferences, and a profile photo. Your age is derived from your date of birth (see below) and is used to personalize your training and nutrition guidance.
Date of birth When you create an account, we require your date of birth. We use it solely to verify your age: to prevent anyone under 13 from creating an account (as required by the U.S. Children's Online Privacy Protection Act, "COPPA"), to apply the higher minimum age (16) for users in the EEA and UK (GDPR Article 8 / UK data-protection rules), and to determine whether an account belongs to a minor (ages 13–17). Minor accounts are automatically set to maximum-privacy defaults (Stealth Mode on, profile photo private, community features hidden) that cannot be turned off until the account holder turns 18. Your date of birth is stored in your account profile; it is never shared with third parties, is included when you export your data, and is permanently deleted when you delete your account.
Activity data We collect the fitness data you log: workouts, food intake, sleep records, water intake, body weight entries, strength training sessions (exercises, sets, reps, weights, personal records, and estimated one-rep maxes), and hydration logs (beverage type and volume). We also collect type-specific detail for the workout you're doing: interval/HIIT sessions record the number of rounds you actually completed; pool swims record lap count and pool length; other workout types record the duration and, where applicable, distance and pace appropriate to that activity. During active workouts where you have granted location permission, we collect GPS route data. You may optionally tag a workout's surface type (trail, road, or mixed) to enable like-for-like performance comparisons. You may also import historical activities by uploading GPX or TCX files from other apps or devices — this data is treated identically to activities recorded in the app.
Saved routes (Route Builder) Using the Route Builder, you may draw and save custom running or cycling routes, storing the route name, an ordered list of GPS waypoints, and the calculated distance. Building and saving your own routes is free. Saved routes are private to your account. You can delete any saved route from the Route Library at any time.
Community Routes (opt-in, anonymized sharing) You may choose to share a route you have run to Community Routes, so other KYDOS users can discover it. Sharing is strictly opt-in and confirmed by you each time. When you share a route, it is published anonymously and privacy-protected: your identity is not attached to the shared route (the link between a shared route and its author is kept only in an internal record that is never shown to other users and is removed if you delete your account); the start and end of the route are automatically clipped so a shared route does not reveal where you began or finished; and only the month it was shared is retained, not exact dates or times. If a route's starting point cannot be sufficiently anonymized, we decline to publish it. Browsing, searching, and voting on Community Routes is free; saving another user's community route into your own library is a KYDOS Premium feature. You may up/down-vote a route, report a route, or add fixed condition tags (for example "muddy" or "poorly lit"); those actions are tied to your account and are deleted when your account is deleted. The anonymous shared route itself has no personal identifier and remains after your account is deleted.
Referral program If you share a KYDOS referral link from Settings, we record that link activity when someone uses it to create an account. Specifically: your user ID is stored as the referrer, and the new user's ID is stored as the referred user. We also track whether the referred user later subscribes to KYDOS Premium, which triggers a free promotional month for you (the referrer). This data is stored privately in your account. Referral records for both you and your referred contacts are permanently deleted when your account is deleted.
Squads (invite-only groups) KYDOS Squads let you form a small, invite-only training group. You may belong to one Squad at a time. Squads are joined only via an invite code or link you receive directly from an existing member — there is no user search, no public directory, and no algorithmic suggestion of other users. When you generate a Squad invite, a short-lived code (and, if you share it as a link, a deep link containing that code) is created; using it records the joining user's account against your Squad. Once you're in a Squad, the following becomes visible to your fellow Squad members only: your username, display name, Founding Member status, your profile photo (only if you've separately opted your photo public — see §8), and your position on that Squad's private leaderboard (workout stats used to rank Squad members). Nothing about you is visible to anyone outside your Squad as a result of this feature. Minors and users in Stealth Mode are never shown in a Squad roster or leaderboard — even to their own Squad members — and a user in Stealth Mode does not see their Squad's roster or leaderboard either, in either direction. Leaving a Squad or deleting your account removes your membership and roster visibility immediately.
Challenges If you join a Challenge (a time-bound fitness goal you opt into), your participation and progress toward that Challenge's goal are visible to other participants of that same Challenge, scoped to that Challenge only. Minors and users in Stealth Mode do not appear in Challenge participant lists.
Hydration data We collect beverage logs you enter: the type of beverage, volume consumed, and time logged. On the Premium tier, we also compute a smart hydration adjustment based on your workout duration, ambient temperature, and beverage dehydration factors (coffee, alcohol). Hydration data is stored in your private account and is never shared or made public.
Weather and air quality conditions With your location permission, we fetch current weather and air quality data from Open-Meteo (an open-source weather API with no advertising or user tracking) to display temperature, wind, heat index, wind chill, Air Quality Index (AQI), and running conditions on your post-workout summary and pre-workout safety screens. Two requests are made per location lookup — one for weather, one for air quality — both to Open-Meteo's public API. Your coordinates are sent per request. No account, persistent identifier, or personal data is transmitted. This data is used solely to calculate safety alerts (extreme heat, cold, storm, air quality) and your outdoor run score.
Guest and on-device data Before you create an account, workout and nutrition data you log is stored locally on your device using AsyncStorage. This data never leaves your device until you create an account and choose to sync it. Guest/local mode is a clean slate: it never displays check-in history, referral links, Guardian SOS, Squads, or any other data or feature tied to a previously-signed-in account on the same device. Daily check-in answers — energy, sleep, soreness, and nutrition — are stored locally keyed by date and by account, and are not transmitted to our servers; guest/local mode does not have an account to key by and does not save or read back check-in answers at all. Your answers may be used, entirely on-device, to select a supportive Coach message and to surface (never automatically activate) the Stand Down feature; this processing never leaves your device and nothing about your check-in answers is sent to us. KYDOS is not a medical provider and does not diagnose or treat any condition — see §4a.
Biometric unlock (optional, on-device only) If you enable the optional "Unlock with Face ID" (or Touch ID) feature in Settings, KYDOS stores your encrypted Supabase session tokens in the device's secure enclave (iOS Keychain via expo-secure-store). Authentication is performed entirely by iOS — KYDOS never receives, stores, or transmits your biometric data. The session tokens stored on-device are encrypted by the OS and cannot be read by other apps. You can disable biometric unlock at any time in Settings > Security, which immediately deletes the stored tokens from your device.
App-switcher and foreground privacy screen On iOS, KYDOS displays a branded, blurred cover screen — showing no health data or account content — whenever the app is backgrounded (including in the iOS App Switcher preview) and while it is re-establishing whether a Face ID unlock is required on return. This is a local, on-device display behavior with no data collection or transmission of its own — it exists purely to prevent your health information from being visible in system-level app previews or momentarily on foreground before any enabled Face ID check completes.
Password breach check (signup and password change) When you create an account or change your password, KYDOS performs a privacy-preserving check against the HaveIBeenPwned (HIBP) breach database. Your password is hashed on-device using SHA-1, and only the first 5 characters of that hash (out of 40) are sent to our Edge Function proxy, which forwards them to the HIBP API. Neither KYDOS nor HIBP ever receives your password or enough of the hash to identify it. If our proxy is unreachable, the check is skipped (fail-open) rather than blocking you. This check is performed for your security only; no data is retained.
Body and nutrition data You may optionally log body measurements (waist, hips, chest, arms, thighs, neck, body fat percentage) and detailed nutrition data (macronutrients and micronutrients). You may also create custom foods — your own reusable food entries — which are stored privately in your account. When you search for a food, your search text is sent to third-party nutrition databases (USDA FoodData Central and Open Food Facts) to return matching foods; those databases receive only the search text, no account information or other personal data (see §7). This data is stored in your private account and is never shared or made public.
Menstrual cycle data (strictly opt-in) If you choose to enable Cycle Tracking in the App, you may log period start dates, cycle length, and period length. This data is highly sensitive. It is stored privately in your account, is never shared with any third party, is never used in community features or public-facing surfaces, and is never sold or used to train models. You can disable Cycle Tracking and delete all cycle data at any time from your Profile. Cycle information is used solely to display your estimated current cycle phase as a training context tool, not as medical advice.
Guardian SOS contact (third-party PII) If you choose to enable Guardian SOS, you provide a name and phone number for an emergency contact. This person is not required to be a KYDOS user. Their name and phone number are stored in your profile and used exclusively to send SMS emergency alerts via Twilio when you activate Guardian SOS. You can update or remove your guardian contact at any time. Guardian contact data is permanently deleted when your account is deleted. We disclose guardian contact information only to Twilio for the sole purpose of message delivery.
Push notification token and preferences When you grant push notification permission, your device's push notification token (from Apple APNs or Google FCM) is stored in your profile to deliver notifications you have enabled. We also store your notification preference settings — which types of alerts you have chosen to receive (such as streak reminders, readiness updates, weekly summaries, and coach check-ins) and, for reminders you can schedule, the time of day you've set. Neither your push token nor your notification preferences are shared with advertising networks or third parties. Both are permanently deleted when your account is deleted.
Measurement units preference KYDOS stores a display preference for whether you see Imperial (miles, pounds, feet) or Metric (kilometers, kilograms, meters) units. This is a display setting only — it does not change what data is collected — and defaults to your device's locale unless you change it in Settings.
Device timezone KYDOS stores your device's timezone (for example, "America/New_York") in your account. This is used solely to calculate calendar-day boundaries correctly for your streaks, Daily Readiness, and Earn Your Glory points, so that "today" matches your local day rather than a fixed reference timezone.
Apple Watch and HealthKit (iOS) When you grant HealthKit permission, KYDOS reads health and fitness data from your iPhone and any paired Apple Watch. Data categories include: activity metrics (steps, active calories burned, and exercise minutes — displayed as the Activity Bars); heart rate, resting heart rate, heart rate variability (HRV), blood oxygen saturation (SpO2), and respiratory rate; VO2Max estimates; sleep analysis; body weight and composition; height; running-specific metrics (power, cadence, stride length, ground contact time, and vertical oscillation); hydration; mindfulness session data; and workout sessions, including ones recorded by other apps or devices that write to Apple Health (for example Garmin or Nike Run Club). Data collected on Apple Watch syncs through the paired iPhone and is treated identically to data recorded on the phone. No additional data categories are introduced by Apple Watch use.
KYDOS also writes data back to Apple Health so it appears in your health record: your completed workout sessions; the nutrition data you log (calories, protein, carbohydrates, fat, fiber, sugar, sodium, potassium, magnesium, calcium, iron, vitamin C, vitamin D, folate, and zinc); and mindfulness session data when you complete a guided mind-body session in the App.
Standalone Apple Watch coaching: The KYDOS Apple Watch app supports phone-free workout coaching. To enable this, your coach personality selection and subscription entitlement status are cached locally on your Apple Watch when it is in range of your iPhone. This allows the Watch to deliver coached workouts independently. No additional data categories are transmitted to our servers as a result — only the same profile and subscription data already described in this policy is involved.
You may revoke HealthKit access at any time: Settings > Privacy & Security > Health > KYDOS.
Android Health Connect On Android, KYDOS reads the following Health Connect data types: steps, heart rate, resting heart rate, heart rate variability, active and total calories, distance, sleep, body weight, height, body fat percentage, blood oxygen saturation (SpO2), respiratory rate, VO2Max, and exercise records. KYDOS also writes to Health Connect so it appears alongside other health data: your completed workout sessions (ExerciseSession and Distance records) and the nutrition data you log (calories, protein, carbohydrates, fat, fiber, sugar, sodium, potassium, magnesium, calcium, iron, vitamin C, vitamin D, folate, and zinc, as Nutrition records). You may revoke permissions at any time: Health Connect > App Permissions > KYDOS.
Health store write-back (both platforms) KYDOS writes your completed workout sessions to your device's health app — Apple Health on iOS and Health Connect on Android. No other data is written to either health store.
Third-party workout display Workout sessions recorded by other apps or devices (such as Garmin, Nike Run Club, or your Apple Watch's own Workout app) may appear in your KYDOS workout history if they were written to Apple Health or Health Connect, so you can see your full activity picture in one place. These are shown for reference only, clearly attributed to their source app, and are never sent to KYDOS servers or stored in your account — they are read live from your device's health store each time your history loads. Because KYDOS cannot verify how that data was originally recorded, these workouts do not count toward Earn Your Glory points, Glory Index, or streaks; only workouts you record directly through KYDOS (including via a paired KYDOS Apple Watch or Wear OS app) are eligible.
Diagnostics KYDOS uses Sentry for crash and error monitoring. Crash and diagnostic data is linked only to an anonymous internal account identifier (your account's UUID) — never to your name, email address, phone number, or IP address, which are actively stripped before any report is transmitted. Health measurements and GPS data are also removed before transmission. For users in EU/EEA/UK/Switzerland, Sentry is initialized only after you grant analytics consent via the in-app consent screen.
Glory metrics and Founding Member status Your Glory Index score, tier, earned point history, and Founding Member status (if applicable) are derived from your activity and stored in your account. These power the Earn Your Glory feature, your profile display, and the Apple Watch glance.
Subscription status Your KYDOS subscription status (active, trial, cancelled) is stored in your account and shared with RevenueCat to manage entitlements. RevenueCat receives your anonymous user identifier (Supabase UUID) only — no email address, payment details, or health data. Apple and Google process your subscription payments directly under their own terms and privacy policies.
Music playback control KYDOS can optionally show and control the music playing during your workout — pause, resume, skip, and display the track title and artist.
On Android, this works with whatever music or podcast app you're playing, without requiring any specific app's SDK. It requires you to grant Android's "Notification access" permission, which is the only way Android exposes another app's active media session. KYDOS does not read notification content: the permission is used solely to query playback metadata (title, artist, album artwork, play/pause state) and send standard transport commands. Granting this permission is optional — if declined, you can still use every other workout feature. You can revoke it at any time in Settings > Apps > Special app access > Notification access > KYDOS.
On iOS, this works with the Music app (Apple Music and your local library) via Apple's MediaPlayer framework. No account connection is required, and this data never leaves your device.
You can also optionally connect your Spotify account from Settings > Devices & Apps for the same playback control and now-playing display. Connecting uses Spotify's standard account sign-in (OAuth); completing that sign-in requires relaying an authorization exchange through a KYDOS server function, which forwards it to Spotify and does not retain your Spotify credentials or listening history — it is not stored in our database. The resulting Spotify session token is stored only on your device and is used to show the current track and send play/pause/skip commands to the Spotify app. You can disconnect your Spotify account at any time from the same Settings screen.
Except for the one-time Spotify sign-in exchange described above, this data stays on your device for the duration of your workout and is never transmitted, stored, or logged by KYDOS.
What we do not collect We do not collect advertising identifiers, cross-app tracking data, background health data, or microphone data. We do not collect any data for advertising purposes. We do not use any third-party behavioral analytics SDKs — no Amplitude, Mixpanel, Segment, Firebase Analytics, or similar product exists in this app. We do not track you across other apps or services.
3. How We Use Your Data
We use your data solely to operate the App:
- To calculate your Glory Index, personal records, and streaks
- To deliver KYDOS Coach guidance during workouts
- To sync your data across your devices
- To send push notifications you have enabled
- To process your subscription
- To resolve crashes and technical errors
- To send Guardian SOS emergency alerts when you initiate them
- To compute nutrition targets, weight trend analysis, and adaptive calorie estimates
- To surface optional personal insights that correlate the data you have already logged — for example, whether your logged food relates to your workout pace or your recovery (heart-rate variability). These correlations are computed on your device from data already synced to your account; no additional data is collected or transmitted to produce them, and they are presented as informational patterns, not medical advice.
- To display body measurement history (visible only to you)
- To show your estimated cycle phase as a training context tool, when Cycle Tracking is enabled (informational only — not medical advice)
- To display real-time workout metrics (elapsed time, distance, pace, Ghost Pacing Delta) on your iOS Lock Screen and Dynamic Island via iOS Live Activities during active workouts. This display is local to your device. No additional data is transmitted as a result of Live Activity use. Live Activity display collapses to a minimal view when Stealth Mode is active.
- To surface longitudinal health trends (fitness arc, training load, readiness, body) in your Health Profile — using data you have already logged. No additional data is collected for this feature.
- To generate an Official Activity Record upon your request — a formatted export of your completed workout data (timestamps, distance, duration, pace, HR, source) shared via your device's native share sheet to a destination you choose. KYDOS does not receive or store data transmitted through that share.
- To track your daily hydration goal, log beverage consumption, and (on Premium) calculate smart hydration adjustments based on workout sweat-loss estimates and beverage hydration factors.
- To record strength training sessions, calculate personal records, and (on Premium) surface volume and tonnage trends and progression analytics using only your own historical data.
4. Health Data
Your health data is used only to power the features you have enabled. We do not sell it, license it, or share it with insurers, employers, or data brokers. We do not use it to train artificial intelligence or machine learning models.
You may revoke health data access at any time:
- iOS: Settings > Privacy & Security > Health > KYDOS
- Android: Health Connect > App Permissions > KYDOS
Glory Points earned through sleep and active energy require Apple Watch as the verified data source. Manually entered health data does not qualify.
If you delete a body-weight reading that was automatically imported from Apple Health, KYDOS keeps a small record of that deletion (the calendar date only, with no weight value) so the reading is not re-imported the next time your health data syncs. This record contains no health measurement, is visible only to your account, and is permanently deleted when you delete your account.
4a. Daily Check-In
The optional daily check-in (energy, sleep, soreness, nutrition) is a physical-training-readiness tool only. Your answers stay on your device — they are never transmitted to our servers — and are used only to select a supportive Coach message and to optionally surface (not activate) the Stand Down feature, both processed locally. KYDOS is not a medical provider and does not diagnose, treat, or assess any physical or mental condition. Mental-health monitoring is not a feature of KYDOS today.
5. Stealth Mode
When Stealth Mode is active:
- Your location is not transmitted during workouts
- Completed workouts are saved to your device only and are never sent to our servers — including after Stealth Mode is disabled
- GPS coordinates are not stored by KYDOS
- Community features (planned for a future update) are not active
- Live Activity display on the iOS Lock Screen and Dynamic Island collapses to a minimal view that shows no workout metrics
- Tracking continues to function fully on your device — timer, heart rate, laps, coach cues, and saving to Apple Health / Health Connect all work normally
- Earn Your Glory points, Glory Index, and streaks are not earned for Stealth workouts. These are computed from workouts synced to our servers, and Stealth workouts are never synced — not even after Stealth Mode is later turned off. This is a deliberate trade-off, not a bug: full privacy or Glory, not both. Minor accounts (Stealth Mode locked on) are not penalized for this — it is a safety default, not a restriction placed on them individually.
5a. Using KYDOS Without an Account
KYDOS offers a "Continue Without an Account" option on first launch. Choosing it does not create an account of any kind, anonymous or otherwise — no request is sent to our servers at all. It sets a flag stored only in your device's local app storage, so the app knows to keep working without you signing in. No email, password, or any identifying information is collected, transmitted, or stored anywhere but your device.
While using KYDOS this way, your workouts and all other activity stay entirely on your device — nothing syncs to our servers, no server-side record of any kind is created, and no Glory accrues, for the same reason described in Section 5 above: Earn Your Glory points, Glory Index, and streaks are computed from data on our servers, and nothing reaches our servers in this mode. You can still see your own workout history within the app at any time — it's simply read from your device instead of from our servers.
If you later create an account (email, password, and username), your on-device workout history is uploaded to that new account so it isn't lost, and your local data is then cleared from the device — this is the only path by which any of this locally-stored data ever reaches our servers, and it happens only when you actively choose to create an account. This is different from Stealth Mode on an account you already have: Stealth Mode workouts are never retroactively synced even after Stealth Mode is turned off, because that data was deliberately kept private on an account that already existed at the time. Using KYDOS without an account has no existing account for anything to be private "on" — creating one afterward simply brings your data with you, rather than exposing something that was previously protected.
6. Community Routes
Public route sharing and cross-user route discovery are not available in this version of KYDOS. All saved routes are private to your account. If we introduce public route sharing in a future version, it will be strictly opt-in and this Privacy Policy will be updated before the feature becomes available. (This is separate from Squads and Challenges, described in §2 above, which are available today.)
7. Data Sharing
We share your data only as follows:
| Recipient | Purpose | Data |
|---|---|---|
| Supabase | Database, authentication, storage, and edge functions (data hosting) | Encrypted account data |
| RevenueCat | Subscription management — entitlements only; never receives payment or bank data | Anonymous user identifier (UUID), subscription status |
| Twilio | Guardian SOS SMS alerts | Guardian emergency contact's phone number |
| Resend | Transactional email | Email address |
| Sentry | Crash and error diagnostics (PII-scrubbed, EU-consent gated) | Anonymous crash reports |
| Expo | Push notification delivery | Device push token only (no health data) |
| Sign in with Google (account creation/login); Android push (FCM); Health Connect data sync, and workout/nutrition write-back if granted | Name and email address, if you sign in with Google; push token; health data you authorize | |
| Apple | Sign in with Apple (account creation/login); HealthKit data sync — KYDOS writes completed workout sessions, logged nutrition data, and mindfulness session data to Apple Health | Name and email address (or Apple's private relay address), if you sign in with Apple; health data you authorize; completed workout sessions, nutrition data, mindfulness session data |
| USDA FoodData Central | Nutritional food database lookup | Search query text (no user PII transmitted) |
| Open Food Facts | Food search and barcode lookup | Search text and scanned barcode (no account, no PII) |
| HaveIBeenPwned | Password breach check (k-anonymity) | 5-char SHA-1 hash prefix only — no password, no full hash |
| Open-Meteo (weather) | Weather on post-workout summary and pre-workout safety screen | Latitude/longitude (no account, no tracking) |
| Open-Meteo (air quality) | AQI, UV index for pre-workout safety alerts | Latitude/longitude (no account, no tracking) |
| Law enforcement | Legal obligation | Minimum required by law |
Apple and Google process subscription payments directly under their own terms and privacy policies.
Food data returned by Open Food Facts is made available under the Open Database License (ODbL); Open Food Facts is a collaborative, non-commercial database.
We do not share data with advertisers, data brokers, or third-party analytics services.
8. Data Security
We implement reasonable technical and organizational measures to protect your data, including encryption in transit and at rest and access controls that ensure each user can only access their own records. However, no system is completely secure, and we cannot guarantee absolute security. You provide your data at your own risk.
We are not responsible for the independent privacy or security practices of the third-party services listed in §7. Each provider named there operates under its own security program and terms.
Profile photos are stored in private storage and delivered via short-lived signed links. By default your profile photo is visible only to you. You may opt in to make it visible to other signed-in KYDOS users from your Profile settings (Profile > tap your avatar area). If you enable Stealth Mode, your photo reverts to private regardless of this setting. Minor accounts (under 18) can never make their photo public — this restriction is enforced at the database level and cannot be overridden.
Body photos (progress photos) are always private — visible only to you, regardless of any setting.
Social profile information. When you're in a Squad, the app reads your fellow Squad members' profile fields — username, display name, Founding Member status, and (if they have separately enabled the public-photo toggle) their profile photo — to display your Squad roster and Squad leaderboard. This read is performed through a SECURITY DEFINER database function that enforces the same privacy guards used elsewhere in the app: minors are never exposed, stealth users are never exposed, and users who have not opted in to public photo visibility never have their photo returned. If you are in Stealth Mode, you see no Squad roster/leaderboard data and no one sees yours, regardless of anyone's settings.
9. Your Rights
Export Export all your data at any time: Settings > Privacy & Data > Export My Data.
Deletion Delete your account: Profile > Settings > Danger Zone > Delete Account. Deletion is immediate, covers all tables, and is permanent — workouts, routes, food logs, body measurements, strength history, hydration logs, referral records, push tokens, notification preferences, and your profile are all deleted.
Two narrow exceptions are retained in de-identified form only, with the link to your account removed: (1) if you gave data consent, a record containing only the timestamp and consent version is retained for GDPR Art. 5(2) / Art. 7(1) accountability — no personal data remains; (2) if you ever triggered Guardian SOS, a record containing only the send timestamp is retained to meet legal accountability obligations — no personal data, no guardian phone number, no location data remains. These anonymized records cannot be linked back to you after deletion.
EU, UK, and California users EU/UK/CA users have additional rights — including access, correction, erasure, portability, and the right to object to processing. Submit requests to privacy@kydoshealth.com with subject: "Data Rights Request."
10. EU / EEA / UK / Switzerland
Data controller: Kydos Health L.L.C. — privacy@kydoshealth.com
In-app consent screen: Users whose device locale indicates an EU/EEA/UK/Switzerland region are presented with a consent screen on first launch. This screen covers our one optional data practice — crash analytics (Sentry) — which you may grant or decline. You can update your analytics preference, and exercise your data-export and deletion rights, at any time from Settings > Privacy & Data (available to all users, not only EU regions). Coaching personalization is not a separate consent category: tailoring coaching and readiness to your own logged data is part of the core service you sign up for, processed under Art. 6(1)(b) — see the legal-bases table below.
Legal bases:
| Activity | Basis |
|---|---|
| Account and workout data | Contract (Art. 6(1)(b)) |
| Subscription processing | Contract (Art. 6(1)(b)) |
| Glory Points and streaks | Contract (Art. 6(1)(b)) |
| Hydration and strength tracking | Contract (Art. 6(1)(b)) |
| Push notifications | Consent (Art. 6(1)(a)) |
| Transactional email (welcome, signup confirmation, password reset) | Legitimate interest (Art. 6(1)(f)) |
| Crash monitoring (Sentry) | Consent (Art. 6(1)(a)) — optional, controlled via consent screen |
| Coaching personalization (tailoring to your own logged data) | Contract (Art. 6(1)(b)) — core service, not a separate consent |
| Legal compliance | Legal obligation (Art. 6(1)(c)) |
Health data (HealthKit / Health Connect) is processed under Art. 9(2)(a) — explicit consent granted when you enable HealthKit or Health Connect. You may withdraw at any time in device settings. Withdrawal does not affect prior processing.
Your rights (Art. 15–22): You have the right to access, rectify, erase, restrict, and port your personal data, and to object to its processing. You may also withdraw consent at any time without affecting the lawfulness of processing before withdrawal. To exercise any right, contact privacy@kydoshealth.com or use the in-app tools at Settings > Privacy & Data.
Retention: Personal data is retained until you delete your account. Crash reports are retained for 90 days. Authentication tokens expire automatically.
International transfers: Data is stored on servers in the United States. Transfers from the EEA or UK are governed by Standard Contractual Clauses. Contact privacy@kydoshealth.com for documentation.
Supervisory authority: You may file a complaint with your local data protection authority. EU: edpb.europa.eu. UK: ico.org.uk.
11. Children
KYDOS is not intended for users under 13 (under 16 in the EEA/UK). We actively enforce this at account creation:
- Under 13: Users who report an age below 13 during sign-up are blocked from creating an account. No account data is collected for users blocked at this step.
- Ages 13–17 (minors): Users aged 13–17 are permitted to use KYDOS with the following default protections applied automatically at account creation: Stealth Mode is enabled (location is not transmitted; workouts are stored on-device only); public route sharing, Squads, Challenges, Leaderboard participation, and the referral program are disabled by default. Minors may not disable Stealth Mode from the app.
- Parental notice: Users under 18 are advised during onboarding that parent or guardian awareness is required.
If you believe a child under 13 has created an account, contact privacy@kydoshealth.com and we will delete it immediately. The EEA/UK minimum age is 16; users who indicate they are 13–15 and whose device locale indicates EEA/UK are blocked from account creation.
12. Changes
We will notify you of material changes via in-app notice before they take effect. Continued use after the effective date constitutes acceptance.
13. Contact
Kydos Health L.L.C. Privacy inquiries and data subject requests: privacy@kydoshealth.com General inquiries: contact@kydoshealth.com Website: kydoshealth.com