Who is responsible
The controller for all processing described here, within the meaning of Art. 4(7) of the General Data Protection Regulation (GDPR), is:
Damon Basler
Kampstraße 20
20357 Hamburg
Germany
Email: kosoku@damonbasler.de
Imprint: kosoku.app/imprint
No data protection officer is appointed; the legal thresholds for a mandatory appointment are not met. Questions about this policy go to the address above.
What this policy covers
This policy applies to every Kosoku surface:
- kosoku.app — this website, including the waitlist and contact form;
- coach.kosoku.app — the coach web app, and the documentation site that shares its sign-in;
- the Kosoku athlete apps for iOS and Android;
- emails and WhatsApp messages we send you as part of the service.
Cookies and analytics are covered here in section 06 and, in detail, in the Cookie Policy.
Our role: controller or processor
Kosoku is a platform on which an organization — a club, a team or an individual coach — manages the training of its athletes. That shapes who is responsible for what:
- Kosoku is the controller for your account, for your visits to our sites and apps, for analytics, support and feedback, for the waitlist and contact form, and for security logging.
- The organization is the controller for the training, health, attendance and messaging data it manages about its athletes. It decides which athletes to invite, what to record and for how long. Kosoku processes that data on the organization's behalf as a processor under Art. 28 GDPR, based on our Terms and a data processing agreement, which we provide to organizations on request.
If you are an athlete and want to exercise your rights over data your club recorded about you, we may forward your request to the club or ask you to contact it directly — it is the party that can decide. We will always help you find the right contact.
The data we process
Account
Name, email address, password (stored only as a hash) or the identifier of your Google or Apple account if you sign in with them, profile picture, role, unit preference (metric/imperial), and — if you set them up — passkeys (a public key and credential id, never the private key) and coach API keys.
Organization membership
Which organizations you belong to, your role there (owner, admin, coach or athlete), team and group memberships, and — for athletes — a playing position if the coach records one. Invitations store the invited email address until they are accepted or expire.
Training data
Programs and workouts assigned to you, the sets you log (reps, weight, duration, distance, perceived exertion), session notes, your coach's feedback, and performance test results such as jump height or sprint times.
Health data (special category)
The athlete app can read body weight, body fat, lean mass, height, resting heart rate, steps, active energy and sleep from Apple Health or Health Connect — only after you grant that permission on your device, and only the types you allow. The same values can be entered manually by you or by your coach. This is health data under Art. 9 GDPR. It is stored with your organization id and is visible to the coaches of that organization.
Attendance and events
Events your organization schedules, your RSVP, check-ins and absences recorded by the coach, and notes attached to them.
Messages
In-app chats between you and your coaches (sender, text, time). If you connect WhatsApp: your phone number, the verification code we send, your opt-in, and every message exchanged with the Kosoku WhatsApp number including delivery identifiers from our messaging provider.
AI features (coach web app)
Conversations with the AI assistants (stored as chat history in your organization), documents a coach uploads for the assistant to search (the extracted text and its numerical representation), and voice dictation audio, which is streamed to the transcription provider and not stored by us. Section 07 explains which providers see what.
Files
Exercise videos and images, organization logos and resources uploaded by coaches.
Feedback
If you use the in-app feedback button: category, rating, your message, the screen you were on, the app version, browser, viewport, language and time zone — and, only if you consented to analytics, the PostHog session id and a link to the session replay.
Technical data
IP address and browser identification stored with each sign-in session, server logs, and error reports (the error, the page or request it happened on and the time). An activity log records account events such as sign-in, sign-out or an invitation.
Website forms
Waitlist: email, name, role and organization. Contact form: name, email, subject and message.
Analytics (only with consent)
See section 06.
Purposes and legal bases
| Purpose | Data | Legal basis |
|---|---|---|
| Providing Kosoku: accounts, organizations, programs, logging, attendance, chat, files, notifications | Account, membership, training, attendance, messages, files, technical data | Contract — Art. 6(1)(b) GDPR |
| Importing and showing health metrics to you and your coaches | Health data | Your explicit consent — Art. 9(2)(a) GDPR, given by connecting Apple Health / Health Connect or entering values. Organizations entering values for an athlete must hold that athlete's consent. |
| WhatsApp reminders and the WhatsApp assistant | Phone number, messages | Consent — Art. 6(1)(a) GDPR (the opt-in you send us); withdraw by replying STOP or in the app |
| AI assistants, document search, voice dictation | AI conversations, documents, audio, training data the assistant looks up | Contract — Art. 6(1)(b) GDPR; coaches decide when to use them |
| Product analytics, session replay, client error tracking | See section 06 | Consent — Art. 6(1)(a) GDPR, § 25(1) TDDDG |
| Security, abuse prevention, server-side error reporting, keeping the service available | Technical data, activity log | Legitimate interests — Art. 6(1)(f) GDPR |
| Transactional email: verification, notifications you enabled, organization invitations | Email address, name, notification content | Contract — Art. 6(1)(b) GDPR |
| Waitlist updates and launch news | Waitlist form data | Consent — Art. 6(1)(a) GDPR; every email has an unsubscribe link |
| Answering contact form messages and support requests | Contact form data, your message | Legitimate interests — Art. 6(1)(f) GDPR; contract where you are a customer |
| Meeting legal obligations, e.g. retention of accounting records | Whatever the obligation requires | Legal obligation — Art. 6(1)(c) GDPR |
You can withdraw any consent at any time with effect for the future (Art. 7(3) GDPR) — analytics under Cookie settings, health import by disconnecting it on your device, WhatsApp by replying STOP, the waitlist via the unsubscribe link.
Cookies, analytics and session replay
kosoku.app sets no cookies and runs no analytics. The coach web app uses a handful of strictly necessary cookies to keep you signed in and remember your preferences; they are listed in the Cookie Policy.
Analytics run only after you accept them in the banner. We use PostHog (PostHog, Inc., San Francisco, USA) on its EU cloud in Frankfurt, Germany, so analytics data does not leave the EU. With your consent PostHog receives page views, clicks, browser and device information, the approximate location derived from your IP address, JavaScript errors, and session replays in which all on-screen text and everything you type is masked before it leaves your browser. Once you are signed in, your user id, email address, name, role and organization are attached so we can follow up on support requests and feedback. Replays are deleted after 30 days, events after 12 months at the latest. Withdraw at any time under Cookie settings (footer) or Settings → Preferences; this deletes the PostHog cookie and stops all collection immediately.
Independently of your cookie choice, the server reports errors that occur while handling your requests (the error, the request path, the time) to PostHog and records the usage of the AI features (tokens, model, duration, cost — never the text of a prompt or an answer) with your user id. This happens without any cookie and serves the stability and cost control of the service — Art. 6(1)(f) GDPR.
In the athlete apps the same PostHog analytics (screen views, masked session replays, crash reports, app version, your user id and name) run only after you accept them inside the app. No cookies are involved; the app keeps the analytics identifier in its local storage until you withdraw.
AI features and model providers
The coach web app includes AI assistants that help build workouts and answer questions about an organization's data. When a coach uses them, the conversation and the data the assistant looks up (which can include athlete names, programs, logs and, if the coach asks for it, health metrics) are sent to a language-model provider:
- By default requests go through OpenRouter (OpenRouter, Inc., USA) to Google Geminimodels. We send them with the “no data collection” setting, which excludes providers that would keep or train on the content.
- An organization can connect its own provider key(OpenAI, Anthropic, Google or Cohere). Requests then go directly to that provider under the organization's contract with it. Keys are stored encrypted (AES-256-GCM).
- Voice dictation streams microphone audio to OpenAI for transcription; only the transcript comes back, and we store neither.
- Document search: PDFs a coach uploads are split into passages, summarised and converted into numerical representations by OpenAI (or via OpenRouter); with an organization's own Cohere key, search results are re-ranked by Cohere.
- The WhatsApp assistantsends the athlete's message, first name and the relevant event details through OpenRouter to answer.
Our own analytics see only usage metadata of these calls (tokens, model, duration, cost), never prompts or answers. Coaches can also connect external AI tools to Kosoku with their API key; data those tools request then flows to whatever provider the tool uses, which is outside our control.
Recipients and processors
We run Kosoku on the services below. Each provider processes data only on our instructions under a data processing agreement, or — where marked — under its own responsibility.
| Provider | What for | Location |
|---|---|---|
| Vercel Inc. | Hosting of all sites and the API, serverless functions, background jobs, file storage, request logs | USA (EU-US Data Privacy Framework); edge locations worldwide |
| Neon, Inc. | The Kosoku database (Postgres) holding all data of sections 04 | USA (Data Privacy Framework); database hosted in the AWS region of our project |
| Amazon Web Services | Object storage (S3) for exercise media, logos and documents | USA (Data Privacy Framework) |
| PostHog, Inc. | Analytics, session replay, error tracking, AI usage metrics | USA; data hosted exclusively in the EU (Frankfurt) |
| OpenRouter, Inc. / Google LLC | Default AI model routing and Gemini models | USA (Standard Contractual Clauses / Data Privacy Framework) |
| OpenAI, L.L.C. | Voice transcription, document embeddings; chat models if an organization brings its own key | USA (Data Privacy Framework) |
| Anthropic PBC, Cohere Inc. | Only if an organization connects its own key | USA / Canada — under the organization's own contract |
| Resend, Inc. | Sending transactional and waitlist emails | USA (Data Privacy Framework) |
| Twilio Inc. / Meta Platforms Ireland Ltd. | WhatsApp messages via the WhatsApp Business Platform | USA / Ireland (Data Privacy Framework) |
| Pusher Ltd. | Real-time delivery of notifications and chat messages | United Kingdom (adequacy decision) |
| Expo (650 Industries, Inc.) | Push notifications for the legacy athlete app | USA (Standard Contractual Clauses) |
| Capgo (capgo.app) | Delivering updates to the athlete app: on each launch the app reports a device id, platform and app/bundle version | EU |
| Apple Inc. / Google LLC | Sign in with Apple / Google (independent controllers); Apple Health and Health Connect stay on your device until you grant access | USA (Data Privacy Framework) |
| YouTube (Google) / Vimeo Inc. | Embedded exercise videos — your IP address and browser reach them when a video loads (independent controllers) | USA (Data Privacy Framework) |
Beyond providers, the coaches and organizations you belong to see your training, health, attendance and messaging data — that is what the platform is for. We never sell personal data and do not share it with advertisers.
Transfers outside the EU
Several providers above are based in the USA. Where they are certified under the EU-US Data Privacy Framework, the transfer rests on the European Commission's adequacy decision of 10 July 2023. Otherwise we rely on the Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR) with additional safeguards such as encryption in transit and at rest. Analytics data stays in the EU. Copies of the safeguards are available on request.
How long we keep data
- Account and everything tied to it — until you delete your account or your organization removes you. Deleting a user removes their account, sessions, memberships, health data, logs, messages, phone numbers, AI chats and feedback in one step; organization content they created (e.g. programs) stays with the organization.
- Sign-in sessions — 7 days without activity; the IP address and browser identification stored with a session go with it.
- Server logs and error reports — hosting logs for a few days; error reports in PostHog for 12 months at the latest.
- Analytics — session replays 30 days, events 12 months at the latest.
- Waitlist — until launch communication is finished or you unsubscribe. Contact form — until your request is handled, then up to 12 months.
- Backups — the database provider keeps point-in-time recovery data for a short window, after which deleted data disappears from backups too.
- Where the law requires longer retention (e.g. invoices), that period applies.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data erased (Art. 17);
- have processing restricted (Art. 18);
- receive the data you provided in a portable format (Art. 20);
- object to processing based on legitimate interests (Art. 21);
- withdraw any consent with effect for the future (Art. 7(3)).
Write to kosoku@damonbasler.de. We answer within one month. For data your organization controls (section 03) we will involve the organization.
You also have the right to complain to a supervisory authority (Art. 77). The authority responsible for us is:
Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit
Ludwig-Erhard-Str. 22, 7. OG
20459 Hamburg, Germany
Deleting your account
- Athlete app: Settings → Delete account. You confirm with your password or by signing in again with Apple or Google; deletion is immediate and cannot be undone.
- Coach web app: self-service deletion is not available yet — email kosoku@damonbasler.de from your account address and we delete the account within a few days.
What remains after deletion: content belonging to your organization (programs, workouts, events), analytics data until its retention lapses, backups for the recovery window, and anything we must keep by law.
Children and young athletes
Kosoku accounts are for people aged 16 and over. Clubs and coaches who want to use Kosoku with younger athletes must obtain the consent of a parent or guardian before inviting them, and remain responsible for that consent as the controller of the athlete's data (section 03). If you believe a child's data has been recorded without such consent, contact us and we will delete it.
Security
All connections use TLS. Data is encrypted at rest by our hosting and database providers. Passwords are stored as salted hashes, provider API keys are encrypted with AES-256-GCM, sign-in cookies are HttpOnly and Secure, and passkeys are supported as a phishing-resistant alternative to passwords. Access to production data is limited to what operating the service requires.
Changes to this policy
We update this policy when the service or the law changes; the date at the top tells you the current version. Material changes are announced in the app or by email before they take effect.
This English version is authoritative; the German version at kosoku.app/datenschutz is a translation of the same text.