GDPR · Personal data · EU hosting

Privacy.

Pick a default privacy policy for your activities. Each activity can then be changed one by one. contact@kimbia.app.

Last updated · 1 July 2026

01

Who is responsible?

The data controller is the operator listed in the imprint. For any data-related question: contact@kimbia.app.

02

What data do we collect?

Three families of data:

Account
Your atproto handle (your public identifier as a domain, e.g. alice.bsky.social) and DID (the protocol's stable identifier). We never store passwords: authentication is handled entirely by the protocol.
Training data
Activities, plans, sessions, metrics (heart rate, pace, distance, duration, sleep, HRV, etc.) that you import via Garmin, Wahoo, Coros and similar services, or enter manually. This includes activity files (FIT/GPX/TCX) and their metadata.
Technical data
Minimal server logs (IP address, user-agent, request timestamps) retained for security and abuse prevention. If you accept analytics, PostHog also records product-usage events (pages viewed, features used) and Sentry records error diagnostics - see the Cookies section below.
03

Why?

To deliver the service you use: showing your activities, computing your zones, comparing planned vs. actual, letting you export your data. Legal basis: performance of the contract (GDPR art. 6.1.b) and legitimate interest for security (art. 6.1.f). Heart rate, HRV, sleep and pace are special-category data under art. 9 GDPR; we process them on your explicit consent (art. 9.2.a), captured at signup and revocable at any time.

04

Where is data stored?

On Hetzner servers located in Germany (European Union). No transfers to third countries outside the EEA take place for primary storage.

05

Processors and third parties

We never sell your data. We do not share it with ad networks. Once imported, Kimbia is the controller for that data, distinct from the source platform. The only third parties involved are:

  • Hetzner Online GmbH (Germany) - data hosting
  • Garmin, Wahoo, Coros and similar services - only when you connect one of those services and authorise the import (each under its own terms)
  • PostHog (EU region) for product analytics and Sentry for error monitoring - only if you accept analytics in the consent banner, and revocable at any time
  • atproto - decentralised identity protocol for your account
06

How long do we keep your data?

As long as your account exists. You can export all of your data at any time in open formats. When you delete your account, your data is removed within 30 days, except for security logs (90 days maximum) and any retention required by law.

07

Your rights (GDPR)

You have the right to access your data, rectify it, delete it, export it (portability), object to processing, and lodge a complaint with a data-protection authority (in Austria: the DSB).

08

Cookies and local storage

No advertising cookies, no third-party pixels. We set what's strictly needed with no consent required: your language preference, and session cookies tied to your atproto authentication. All of it falls under the e-Privacy and GDPR exemptions.

Analytics and error tracking are opt-in. On your first visit a banner offers three choices: Reject (nothing loads, no analytics cookie), Anonymous (analytics load but are never linked to your identity - no handle, DID or name attached), or Accept (analytics linked to your account). Nothing loads and no analytics cookie is set until you choose. Your choice is remembered on this device and, once you sign in, saved to your account so it follows you across devices - and you can change it at any time.

If you accept or choose anonymous: PostHog (hosted in the EU) records product-usage events and sets a first-party analytics cookie to recognise your session; and Sentry, our error-monitoring tool, may capture an error stack, your IP, and a session replay (text masked) when an error occurs - your handle/DID is attached only if you fully accept. Sentry purges this data after 30 days. Legal basis: your consent (GDPR art. 6.1.a).

09

Contact

For any data-related request: contact@kimbia.app.