/ LEGAL · PRIVACY

Privacy Policy

Last updated · August 27, 2026

Deutsche Fassung →

01

Who is responsible

The controller for all processing described here, within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR), is:

Damon Basler
Kampstraße 20
20357 Hamburg
Germany

Email: kosoku@damonbasler.de

Imprint: kosoku.app/imprint

No data protection officer is appointed; the legal thresholds for a mandatory appointment are not met. Questions about this policy go to the address above.

02

What this policy covers

This policy applies to every Kosoku surface:

  • kosoku.app — this website, including the waitlist and contact form;
  • coach.kosoku.app — the coach web app, and the documentation site that shares its sign-in;
  • the Kosoku athlete apps for iOS and Android;
  • emails and WhatsApp messages we send you as part of the service.

Cookies and analytics are covered here in section 06 and, in detail, in the Cookie Policy.

03

Our role: controller or processor

Kosoku is a platform on which an organization — a club, a team or an individual coach — manages the training of its athletes. That shapes who is responsible for what:

  • Kosoku is the controller for your account, for your visits to our sites and apps, for analytics, support and feedback, for the waitlist and contact form, and for security logging.
  • The organization is the controller for the training, health, attendance and messaging data it manages about its athletes. It decides which athletes to invite, what to record and for how long. Kosoku processes that data on the organization's behalf as a processor under Art. 28 GDPR, based on our Terms and a data processing agreement, which we provide to organizations on request.

If you are an athlete and want to exercise your rights over data your club recorded about you, we may forward your request to the club or ask you to contact it directly — it is the party that can decide. We will always help you find the right contact.

04

The data we process

Account

Name, email address, password (stored only as a hash) or the identifier of your Google or Apple account if you sign in with them, profile picture, role, unit preference (metric/imperial), and — if you set them up — passkeys (a public key and credential id, never the private key) and coach API keys.

Organization membership

Which organizations you belong to, your role there (owner, admin, coach or athlete), team and group memberships, and — for athletes — a playing position if the coach records one. Invitations store the invited email address until they are accepted or expire.

Training data

Programs and workouts assigned to you, the sets you log (reps, weight, duration, distance, perceived exertion), session notes, your coach's feedback, and performance test results such as jump height or sprint times.

Health data (special category)

The athlete app can read body weight, body fat, lean mass, height, resting heart rate, steps, active energy and sleep from Apple Health or Health Connect — only after you grant that permission on your device, and only the types you allow. The same values can be entered manually by you or by your coach. This is health data under Art. 9 GDPR. It is stored with your organization id and is visible to the coaches of that organization.

Attendance and events

Events your organization schedules, your RSVP, check-ins and absences recorded by the coach, and notes attached to them.

Messages

In-app chats between you and your coaches (sender, text, time). If you connect WhatsApp: your phone number, the verification code we send, your opt-in, and every message exchanged with the Kosoku WhatsApp number including delivery identifiers from our messaging provider.

AI features (coach web app)

Conversations with the AI assistants (stored as chat history in your organization), documents a coach uploads for the assistant to search (the extracted text and its numerical representation), and voice dictation audio, which is streamed to the transcription provider and not stored by us. Section 07 explains which providers see what.

Files

Exercise videos and images, organization logos and resources uploaded by coaches.

Feedback

If you use the in-app feedback button: category, rating, your message, the screen you were on, the app version, browser, viewport, language and time zone — and, only if you consented to analytics, the PostHog session id and a link to the session replay.

Technical data

IP address and browser identification stored with each sign-in session, server logs, and error reports (the error, the page or request it happened on and the time). An activity log records account events such as sign-in, sign-out or an invitation.

Website forms

Waitlist: email, name, role and organization. Contact form: name, email, subject and message.

Analytics (only with consent)

See section 06.

05

Purposes and legal bases

PurposeDataLegal basis
Providing Kosoku: accounts, organizations, programs, logging, attendance, chat, files, notificationsAccount, membership, training, attendance, messages, files, technical dataContract — Art. 6(1)(b) GDPR
Importing and showing health metrics to you and your coachesHealth dataYour explicit consent — Art. 9(2)(a) GDPR, given by connecting Apple Health / Health Connect or entering values. Organizations entering values for an athlete must hold that athlete's consent.
WhatsApp reminders and the WhatsApp assistantPhone number, messagesConsent — Art. 6(1)(a) GDPR (the opt-in you send us); withdraw by replying STOP or in the app
AI assistants, document search, voice dictationAI conversations, documents, audio, training data the assistant looks upContract — Art. 6(1)(b) GDPR; coaches decide when to use them
Product analytics, session replay, client error trackingSee section 06Consent — Art. 6(1)(a) GDPR, § 25(1) TDDDG
Security, abuse prevention, server-side error reporting, keeping the service availableTechnical data, activity logLegitimate interests — Art. 6(1)(f) GDPR
Transactional email: verification, notifications you enabled, organization invitationsEmail address, name, notification contentContract — Art. 6(1)(b) GDPR
Waitlist updates and launch newsWaitlist form dataConsent — Art. 6(1)(a) GDPR; every email has an unsubscribe link
Answering contact form messages and support requestsContact form data, your messageLegitimate interests — Art. 6(1)(f) GDPR; contract where you are a customer
Meeting legal obligations, e.g. retention of accounting recordsWhatever the obligation requiresLegal obligation — Art. 6(1)(c) GDPR

You can withdraw any consent at any time with effect for the future (Art. 7(3) GDPR) — analytics under Cookie settings, health import by disconnecting it on your device, WhatsApp by replying STOP, the waitlist via the unsubscribe link.

06

Cookies, analytics and session replay

kosoku.app sets no cookies and runs no analytics. The coach web app uses a handful of strictly necessary cookies to keep you signed in and remember your preferences; they are listed in the Cookie Policy.

Analytics run only after you accept them in the banner. We use PostHog (PostHog, Inc., San Francisco, USA) on its EU cloud in Frankfurt, Germany, so analytics data does not leave the EU. With your consent PostHog receives page views, clicks, browser and device information, the approximate location derived from your IP address, JavaScript errors, and session replays in which all on-screen text and everything you type is masked before it leaves your browser. Once you are signed in, your user id, email address, name, role and organization are attached so we can follow up on support requests and feedback. Replays are deleted after 30 days, events after 12 months at the latest. Withdraw at any time under Cookie settings (footer) or Settings → Preferences; this deletes the PostHog cookie and stops all collection immediately.

Independently of your cookie choice, the server reports errors that occur while handling your requests (the error, the request path, the time) to PostHog and records the usage of the AI features (tokens, model, duration, cost — never the text of a prompt or an answer) with your user id. This happens without any cookie and serves the stability and cost control of the service — Art. 6(1)(f) GDPR.

In the athlete apps the same PostHog analytics (screen views, masked session replays, crash reports, app version, your user id and name) run only after you accept them inside the app. No cookies are involved; the app keeps the analytics identifier in its local storage until you withdraw.

07

AI features and model providers

The coach web app includes AI assistants that help build workouts and answer questions about an organization's data. When a coach uses them, the conversation and the data the assistant looks up (which can include athlete names, programs, logs and, if the coach asks for it, health metrics) are sent to a language-model provider:

  • By default requests go through OpenRouter (OpenRouter, Inc., USA) to Google Geminimodels. We send them with the “no data collection” setting, which excludes providers that would keep or train on the content.
  • An organization can connect its own provider key(OpenAI, Anthropic, Google or Cohere). Requests then go directly to that provider under the organization's contract with it. Keys are stored encrypted (AES-256-GCM).
  • Voice dictation streams microphone audio to OpenAI for transcription; only the transcript comes back, and we store neither.
  • Document search: PDFs a coach uploads are split into passages, summarised and converted into numerical representations by OpenAI (or via OpenRouter); with an organization's own Cohere key, search results are re-ranked by Cohere.
  • The WhatsApp assistantsends the athlete's message, first name and the relevant event details through OpenRouter to answer.

Our own analytics see only usage metadata of these calls (tokens, model, duration, cost), never prompts or answers. Coaches can also connect external AI tools to Kosoku with their API key; data those tools request then flows to whatever provider the tool uses, which is outside our control.

08

Recipients and processors

We run Kosoku on the services below. Each provider processes data only on our instructions under a data processing agreement, or — where marked — under its own responsibility.

ProviderWhat forLocation
Vercel Inc.Hosting of all sites and the API, serverless functions, background jobs, file storage, request logsUSA (EU-US Data Privacy Framework); edge locations worldwide
Neon, Inc.The Kosoku database (Postgres) holding all data of sections 04USA (Data Privacy Framework); database hosted in the AWS region of our project
Amazon Web ServicesObject storage (S3) for exercise media, logos and documentsUSA (Data Privacy Framework)
PostHog, Inc.Analytics, session replay, error tracking, AI usage metricsUSA; data hosted exclusively in the EU (Frankfurt)
OpenRouter, Inc. / Google LLCDefault AI model routing and Gemini modelsUSA (Standard Contractual Clauses / Data Privacy Framework)
OpenAI, L.L.C.Voice transcription, document embeddings; chat models if an organization brings its own keyUSA (Data Privacy Framework)
Anthropic PBC, Cohere Inc.Only if an organization connects its own keyUSA / Canada — under the organization's own contract
Resend, Inc.Sending transactional and waitlist emailsUSA (Data Privacy Framework)
Twilio Inc. / Meta Platforms Ireland Ltd.WhatsApp messages via the WhatsApp Business PlatformUSA / Ireland (Data Privacy Framework)
Pusher Ltd.Real-time delivery of notifications and chat messagesUnited Kingdom (adequacy decision)
Expo (650 Industries, Inc.)Push notifications for the legacy athlete appUSA (Standard Contractual Clauses)
Capgo (capgo.app)Delivering updates to the athlete app: on each launch the app reports a device id, platform and app/bundle versionEU
Apple Inc. / Google LLCSign in with Apple / Google (independent controllers); Apple Health and Health Connect stay on your device until you grant accessUSA (Data Privacy Framework)
YouTube (Google) / Vimeo Inc.Embedded exercise videos — your IP address and browser reach them when a video loads (independent controllers)USA (Data Privacy Framework)

Beyond providers, the coaches and organizations you belong to see your training, health, attendance and messaging data — that is what the platform is for. We never sell personal data and do not share it with advertisers.

09

Transfers outside the EU

Several providers above are based in the USA. Where they are certified under the EU-US Data Privacy Framework, the transfer rests on the European Commission's adequacy decision of 10 July 2023. Otherwise we rely on the Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with additional safeguards such as encryption in transit and at rest. Analytics data stays in the EU. Copies of the safeguards are available on request.

10

How long we keep data

  • Account and everything tied to it — until you delete your account or your organization removes you. Deleting a user removes their account, sessions, memberships, health data, logs, messages, phone numbers, AI chats and feedback in one step; organization content they created (e.g. programs) stays with the organization.
  • Sign-in sessions — 7 days without activity; the IP address and browser identification stored with a session go with it.
  • Server logs and error reports — hosting logs for a few days; error reports in PostHog for 12 months at the latest.
  • Analytics — session replays 30 days, events 12 months at the latest.
  • Waitlist — until launch communication is finished or you unsubscribe. Contact form — until your request is handled, then up to 12 months.
  • Backups — the database provider keeps point-in-time recovery data for a short window, after which deleted data disappears from backups too.
  • Where the law requires longer retention (e.g. invoices), that period applies.
11

Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you (Art. 15);
  • have inaccurate data corrected (Art. 16);
  • have data erased (Art. 17);
  • have processing restricted (Art. 18);
  • receive the data you provided in a portable format (Art. 20);
  • object to processing based on legitimate interests (Art. 21);
  • withdraw any consent with effect for the future (Art. 7(3)).

Write to kosoku@damonbasler.de. We answer within one month. For data your organization controls (section 03) we will involve the organization.

You also have the right to complain to a supervisory authority (Art. 77). The authority responsible for us is:

Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 7. OG
20459 Hamburg, Germany

mailbox@datenschutz.hamburg.de · datenschutz-hamburg.de

12

Deleting your account

  • Athlete app: Settings → Delete account. You confirm with your password or by signing in again with Apple or Google; deletion is immediate and cannot be undone.
  • Coach web app: self-service deletion is not available yet — email kosoku@damonbasler.de from your account address and we delete the account within a few days.

What remains after deletion: content belonging to your organization (programs, workouts, events), analytics data until its retention lapses, backups for the recovery window, and anything we must keep by law.

13

Children and young athletes

Kosoku accounts are for people aged 16 and over. Clubs and coaches who want to use Kosoku with younger athletes must obtain the consent of a parent or guardian before inviting them, and remain responsible for that consent as the controller of the athlete's data (section 03). If you believe a child's data has been recorded without such consent, contact us and we will delete it.

14

Security

All connections use TLS. Data is encrypted at rest by our hosting and database providers. Passwords are stored as salted hashes, provider API keys are encrypted with AES-256-GCM, sign-in cookies are HttpOnly and Secure, and passkeys are supported as a phishing-resistant alternative to passwords. Access to production data is limited to what operating the service requires.

15

Changes to this policy

We update this policy when the service or the law changes; the date at the top tells you the current version. Material changes are announced in the app or by email before they take effect.

This English version is authoritative; the German version at kosoku.app/datenschutz is a translation of the same text.