Privacy Policy

Last updated: May 7, 2026


This Privacy Policy explains what information Kiatu collects, how we use it, how we protect it, and your rights regarding your data. We believe in plain language, with no legalese traps.

1. Information We Collect

Account Information

  • Email address
  • Password (we never see it; it is hashed using bcrypt before storage)
  • Optional display name

Fitness & Training Data

  • Running activities you log: distance, duration, date, terrain, perceived effort, personal notes
  • Shoe inventory and per-shoe mileage
  • Shoe memories, retirement records, lineage, and life-stage history

Health Information You Voluntarily Provide

  • Injury type and phase (if you choose to use the injury tracking feature)
  • Foot arch type and gait information (from the optional gait quiz)

This data is used solely to generate personalized shoe recommendations and is never sold, shared with advertisers, or disclosed to third parties.

Third-Party Data (Strava)

  • If you connect Strava, we receive only the activity data you explicitly authorize
  • We do not access your Strava profile, social connections, kudos, or segment data
  • You can disconnect Strava at any time from within the App

Technical Data

  • Device operating system and version (for compatibility)
  • App version (for bug tracking)
  • We do not collect advertising identifiers, precise GPS location, or biometric data

2. How We Use Your Information

  • Provide, personalize, and improve the App's features
  • Sync your data across your devices when you are signed in
  • Calculate shoe mileage, life stages, memories, and match quality
  • Generate local shoe recommendations from your quiz answers
  • Maintain a legal record of your consent to these policies
  • Respond to your support requests

We do not use your data for advertising, profiling for marketing purposes, or selling to data brokers. We do not build advertising profiles from your health or fitness data.

3. How We Protect Your Data

We take security seriously. Here is exactly what is in place:

  • Row Level Security (RLS): Every table in our database enforces database-level access policies. Even with a valid authentication token, it is cryptographically impossible for one user to read, write, or delete another user's data. This is enforced at the database engine level, not just application code.
  • Encryption in transit: All data sent between the App and our servers is encrypted using TLS (HTTPS).
  • Encrypted at rest: Authentication tokens are stored in your device's hardware-backed encrypted storage (iOS Keychain or Android Keystore). They are never written to unencrypted local storage.
  • Password hashing: Passwords are hashed with bcrypt before storage. We have no mechanism to retrieve your original password.
  • Immutable consent log: Your agreement to these policies is recorded with a timestamp in a database table that cannot be updated or deleted.
  • No admin backdoor: No Kiatu employee or developer can read your personal data without bypassing the same RLS policies that protect you from other users.

4. Data Sharing & Disclosure

We do not sell your personal data. We do not rent it. We do not trade it.

We may disclose your data only in these limited circumstances:

  • Strava: Only if you actively connect your Strava account, and only the data scope you explicitly authorize.
  • Legal obligation: If required by law, court order, or governmental authority to protect the rights, property, or safety of users or the public.
  • Business transfer: In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred, but only under commitments of confidentiality and the same privacy protections described here.

5. Recommendations & Data Processing

Shoe recommendations are generated locally from your quiz answers and the app's shoe database.

  • Kiatu does not require external AI API keys for the current app experience
  • Recommendations and shoe dialogue are not medical advice. See the Terms of Service health disclaimer.

6. Your Rights

Depending on where you live, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you
  • Correction: Request correction of inaccurate data
  • Deletion: Request permanent deletion of your account and all associated data (right to be forgotten)
  • Portability: Request your data in a portable format
  • Objection: Object to certain processing of your data
  • Withdraw consent: Withdraw consent at any time by deleting your account

To exercise any of these rights, delete your account from within the App (which triggers immediate data deletion) or contact us at hello@kiatu.run.

7. Data Retention

We retain your data for as long as your account remains active. When you delete your account:

  • Your profile, runs, arsenal, and all personal data are permanently deleted from our active database within 30 days
  • Consent records are retained for a legally required period to demonstrate compliance, then deleted
  • Backups are purged on their normal rotation cycle (within 90 days)

8. Children's Privacy

The App is not directed to children under the age of 13 (or 16 in the European Economic Area). We do not knowingly collect personal information from children below these ages. If you are a parent or guardian and believe your child has provided us with personal data, please contact us immediately so we can delete it.

9. International Users

If you access the App from outside the country in which our servers are located, your data may be transferred across international borders. By using the App, you consent to such transfers. We ensure that such transfers comply with applicable data protection laws.

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, you have additional rights under GDPR. Our legal basis for processing your data is your explicit consent (provided when you create your account and accept these policies) and the performance of our contract with you.

10. Changes to This Policy

We will notify you of material changes to this Privacy Policy through the App before they take effect. The "Last updated" date at the top of this document will always reflect when changes were made. Continued use of the App after changes take effect constitutes your acceptance of the updated Policy.

11. Contact

For privacy-related questions, data requests, or to report a potential security vulnerability, email us at hello@kiatu.run. We take all security reports seriously and will acknowledge receipt within 72 hours.