Kurro processes the following categories of personal data so we can deliver your training plan, analytics and coaching advice:
When you sign up you also record three consents (terms, health data, AI coach). Terms stays account-lifetime only: the app is not usable without agreeing to it, so a standalone withdrawal would be a button with no real effect, and deleting your account is the only way to end it. Health data and AI coach are different: you can withdraw either one at any time from Settings → “Manage consent”, without deleting your account. Withdrawing health data permanently deletes the health and training history we derived from it, including your manual check-ins, taper notes and manually logged weight (activities, health metrics, recovery scores, thresholds and more); withdrawing AI coach permanently deletes your chat history and any pending proposals. Both take effect immediately and cannot be undone, this is a real, immediate stop: the following all check your health-data consent first and refuse to process anything new the moment you withdraw, not just a registrational preference: a wearable (Apple HealthKit) sync, manual activity entries, manual weight entries, check-ins, taper notes, and every Strava path (connecting or reconnecting your account, a manual sync, deep history sync, and incoming Strava webhook events). A reconnect after withdrawal is deliberately blocked, not treated as an implicit re-grant: use “Grant again” in Settings → “Manage consent” first. Menstrual-cycle logging is the one exception: it sits under its own, separate cycle-tracking setting rather than this consent. Whether withdrawing health-data consent should also delete those self-entered logs is a decision we have deliberately left open rather than deleting them silently (documented in the consent-withdrawal database migration); today they stay unless you delete your account.
Separately, and only if you opt in, you can allow your anonymised data to be aggregated with other athletes' to improve Kurro's models for everyone. Cross-athlete model learning does not exist yet, nothing reads this consent to act on your data, so we do not currently show a way to grant it; asking for consent to something that never runs would only undermine the consent we do need once a real use exists. If you granted it in the past, it is off by default, never affected your own plan, and you can still withdraw it at any time from Settings → “Manage consent”. Withdrawing only updates your consent record; there is no data to delete, since nothing uses it today.
We process your data based on your consent (Art. 6(1)(a) GDPR) and for the performance of the contract (Art. 6(1)(b) GDPR) between you and Kurro. For health data we rely on your explicit consent (Art. 9(2)(a) GDPR).
Under the GDPR you have the right to:
We use encrypted connections (HTTPS/TLS), Row Level Security on the database, and only verified, EU-based processors where possible. Access to production data is restricted to authorised administrators. When an administrator opens, exports, recomputes, regenerates an individual user's data, or searches/lists the athlete roster, we record that action in a persistent, access-controlled audit log: which administrator, which user (where a single user applies), which action, and when. Automated maintenance jobs remain captured in our server logs.
Questions about this privacy policy or your data? Email us at privacy@kurro.run.