Privacy.
Last updated · 27 August 2026
Who is responsible?
The data controller is the operator listed in the imprint. For any data-related question: contact@kimbia.app.
What data do we collect?
Three families of data:
- Account
- Your atproto handle (your public identifier as a domain, e.g.
alice.bsky.social) and DID (the protocol's stable identifier). We never store passwords: authentication is handled entirely by the protocol. If you give us one, your email address is used to verify your account and send you service messages. - Training data
- Activities, plans, sessions, metrics (heart rate, pace, distance, duration, sleep, HRV, etc.) that you import via Strava, Suunto, Polar and similar services, or enter manually. This includes activity files (FIT/GPX/TCX) and their metadata.
- Technical data
- Minimal server logs (IP address, user-agent, request timestamps) retained for security and abuse prevention. If you accept analytics, PostHog also records product-usage events (pages viewed, features used) and Sentry records error diagnostics - see the Cookies section below.
Why?
To deliver the service you use: showing your activities, computing your zones, comparing planned vs. actual, letting you export your data. Legal basis: performance of the contract (GDPR art. 6.1.b) and legitimate interest for security (art. 6.1.f). Heart rate, HRV, sleep and pace are special-category data under art. 9 GDPR; we process them on your explicit consent (art. 9.2.a), which you give by connecting a service or importing a file, and withdraw by disconnecting that service or deleting the data.
Where is data stored?
On Hetzner servers located in Germany (European Union): that is where your account and your training data live. The few peripheral tools not hosted in the EU are covered by the European Commission's Standard Contractual Clauses (GDPR art. 46).
Sources and processors
We never sell your data and we share it with no ad network. Two roles to tell apart. Sources - Strava, Suunto, Polar and similar services - do not work for us: you trigger the import, each stays a controller on its own side under its own terms, and once the data arrives Kimbia is a separate controller for it. Processors, on the other hand, handle data on our behalf:
- Hetzner Online GmbH (Germany) - data hosting
- Service emails and push notifications - only what it takes to reach you
- PostHog (EU region) for product analytics and Sentry for error monitoring - only if you accept analytics in the consent banner, and revocable at any time
- atproto - decentralised identity protocol for your account
The current, named list of these providers is available on request at contact@kimbia.app.
How long do we keep your data?
As long as your account exists. You can export all of your data at any time in open formats. When you delete your account, your data is removed within 30 days, except for security logs (90 days maximum) and any retention required by law.
Your rights (GDPR)
You can access your data, rectify it, delete it, export it (portability), restrict or object to processing, and withdraw your consent at any time. A full export is self-service in your settings. You can also lodge a complaint with a data-protection authority: the one in your country of residence, or ours in Austria (Datenschutzbehörde, dsb.gv.at).
Cookies and local storage
No advertising cookies, no third-party pixels. Only what's strictly needed, with no consent required: the signed cookies of your atproto session (did and scope, 180 days), your language preference (cleared when you close the browser), and a few ten-minute technical cookies during an OAuth flow or a coach invitation.
On your device, in local storage and never sent to our servers: your analytics choice and its date, plus display preferences (collapsed panels, app-install and notification reminders).
Usage measurement runs in anonymous mode by default: PostHog (hosted in the EU, and called through our own domain - no request leaves for a third-party domain) records pages viewed and features used, with a first-party cookie lasting one year to recognise your session. Nothing is tied to your handle, DID or name. Legal basis: legitimate interest, within the limits of audience measurement. The banner offers to accept linking to your account on top of that (basis: your consent, art. 6.1.a); that is the only case where PostHog session recording starts. Your choice is remembered on this device and, once you sign in, on your account - changeable at any time.
Inside the app - not on public pages - Sentry reports errors: stack trace, IP address, and a short replay of the moment the error happened, with text masked. There is no continuous recording. Your handle is attached only if you accepted. Its servers are in the United States, covered by the Standard Contractual Clauses, and the data is purged after 30 days.
Security
Everything travels over HTTPS, data is encrypted at rest, and database access is restricted and logged. If a breach ever poses a high risk to you, we notify the Austrian authority (DSB) within 72 hours and inform you without undue delay (GDPR art. 33 and 34).
Contact
For any data-related request: contact@kimbia.app.