Koyaro
FeaturesHow it worksPricingAboutIntegrationsWho it's forScienceSign inJoin the waitlist
FeaturesHow it worksPricingAboutIntegrationsWho it's forScienceSign inJoin the waitlist

Legal

Privacy Policy

Effective date: 7 September 2026. This document is a working draft for product use; have it reviewed by counsel before public launch and update the legal entity details when the Danish ApS is registered.

1. Introduction

This Privacy Policy explains how Koyaro (the operator of the Koyaro service (a Danish company to be registered as an ApS; company registration details will be published here when available)) (“Koyaro”, “we”, “us”) collects, uses, and shares personal data when you use the Koyaro websites, apps, and related services (the “Service”).

It should be read together with our Terms of Service. Effective date: 7 September 2026.

Contact for privacy requests: legal@koyaro.com.

2. Data controller

Koyaro is the data controller for personal data processed to provide the Service. When Stripe acts as merchant of record for payments, Stripe is an independent controller (or otherwise processes payment data under its own terms) for payment transactions. Device and third-party training platforms (for example Garmin, Wahoo, or intervals.icu) process data under their own policies when you connect them.

3. Data we collect

Depending on how you use the Service, we may process:

  • Account data — email, display name, authentication identifiers, and account settings.
  • Athlete profile & training data — physiology inputs you provide (for example FTP, weight, heart-rate markers), goals, plans, activities, streams, wellness entries, nutrition logs, equipment records, and related derived metrics.
  • Integration data — data imported from connected services and uploaded files (for example FIT files), including identifiers those services provide.
  • Billing data — subscription and credit status in our systems; payment card details are handled by Stripe and are not stored on our servers.
  • AI interaction data — prompts and responses when you use AI features, plus credit usage metadata.
  • Usage, device & diagnostics — IP address, device/browser type, approximate location derived from IP, pages and features used, performance and error logs, and similar telemetry.
  • Support communications — messages you send us.

4. How we use data

We use personal data to:

  • Provide, secure, and maintain the Service;
  • Compute training metrics, plans, and in-product recommendations;
  • Process subscriptions, AI credit balances, and any trial or promotional period we offer on an account;
  • Send transactional messages (for example account and billing);
  • Analyze product usage and improve the Service — including via PostHog and similar tools (see §5);
  • Detect abuse, debug errors, and ensure reliability;
  • Comply with law and enforce our Terms.

Where GDPR (or UK GDPR) applies, we rely on one or more of: performance of a contract; legitimate interests (for example securing and improving the Service, product analytics that are proportionate and privacy-aware); consent where required (for example certain cookies or marketing); and legal obligation.

5. Product analytics (PostHog)

We use PostHog (and may use similar analytics or error-tracking tools) to understand how people use Koyaro so we can fix bugs, improve onboarding and features, and prioritise product work.

Depending on configuration, PostHog may process:

  • Event data (for example feature usage, funnels, and conversion steps);
  • Device and browser information;
  • Approximate location from IP;
  • Identifiers that link events to your account (for example an internal user id) after you sign in;
  • Error and performance information;
  • Optionally, session replay or similar diagnostics — if enabled, we will configure privacy controls (for example masking sensitive inputs) and describe that practice here.

We do not use PostHog to sell your personal data. We use it to operate and improve Koyaro. We aim not to send unnecessary health or training stream contents into analytics properties.

PostHog acts as a processor (or equivalent) on our instructions. PostHog’s own documentation explains its security and subprocessors. Data may be processed in the EU and/or other regions depending on our PostHog project configuration; we will favour EU hosting where practical for EU users.

By creating an account and accepting our Terms and this Privacy Policy, you acknowledge this analytics processing. Where local law requires prior consent for non-essential cookies or similar technologies, we request that consent via a cookie banner on this marketing site and honour opt-outs where required. You can change your choice later using Cookie settings in the site footer.

6. Sharing and subprocessors

We share personal data only as needed with:

  • Infrastructure providers (hosting, database, object storage, email/push) that process data on our behalf;
  • Stripe for payments and related billing;
  • PostHog and similar analytics/error tools (§5);
  • AI model providers when you use AI features (to generate responses under our instructions);
  • Notification / email providers (for example Resend) for transactional alerts;
  • Professional advisers or authorities when required by law or to protect rights and safety;
  • A successor entity in connection with a merger, acquisition, or asset transfer, subject to appropriate protections.

We do not sell personal data. A current subprocessor list may be published or provided on request as the production stack stabilises.

7. Retention

We keep account and training data while your account is active and for a reasonable period afterward (for backups, dispute resolution, and legal requirements), then delete or anonymise it. You may request deletion subject to legal retention needs. Analytics events may be retained in aggregated or pseudonymised form according to our analytics tool settings.

8. Your rights

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent where processing is consent-based. You may also lodge a complaint with your local supervisory authority (in Denmark, Datatilsynet).

To exercise rights, email legal@koyaro.com from your account email, or use in-product export and delete controls in Settings (Data & account).

9. International transfers

If we transfer personal data outside your country (including outside the EEA/UK), we use appropriate safeguards such as Standard Contractual Clauses or an adequacy decision, unless another lawful mechanism applies.

10. Security

We use administrative, technical, and organisational measures designed to protect personal data. No method of transmission or storage is completely secure; please use a strong unique password and protect your devices.

11. Children

The Service is not directed to children under 16 (or a higher age of digital consent where applicable). We do not knowingly collect personal data from children below that age. If you believe we have, contact us and we will take appropriate steps.

12. Changes

We may update this Privacy Policy from time to time. We will post the updated version with a new effective date and provide additional notice for material changes when appropriate.

13. Contact

Privacy questions and requests: legal@koyaro.com.

Koyaro

Science-first cycling training with native AI. Every recommendation explainable.

Product

FeaturesHow it worksIntegrationsPricingFAQ

Explore

Who it's forScienceGuidesAboutChangelogClub waitlist

Account

Sign inJoin the waitlist

Legal

Terms of ServicePrivacy Policy

© 2026 Koyaro