Kinect · Legal

Privacy Policy

Last updated: 1 September 2026

In short

1. Who is the data controller

The controller of personal data processed in the Kinect application is Kuba Borkowski, operating the application as unregistered business activity (Polish: działalność nierejestrowana), Plac Wilsona 4/24, 01-626 Warsaw, Poland. For data-protection matters, write to us at contact@getkinect.app.

2. What data we process and why

For the application to work, we process the following data:

We do not collect: PESEL number (Polish national identification number), location data, or health data within the meaning of Article 9 GDPR. Please do not enter health information or medical diagnoses into the application — the body-related fields serve training purposes only.

3. Artificial-intelligence features

In order to generate training plans, next-session suggestions, and weekly recaps, your training data is processed using AI services (OpenAI). Data is transferred only to the extent necessary to generate a given feature. The AI features do not make decisions concerning you that produce legal effects or similarly significant effects.

4. Legal basis (GDPR)

5. Where we store data and for how long

Data is stored in a Supabase database (PostgreSQL, TLS-encrypted connection) in the European Union region (Frankfurt, Germany). We make automatic backups, stored in secure storage; we keep a limited number of the most recent backups, with older ones overwritten.

We store data for as long as you have an account. After an account is deleted, the data is removed — except for data we are required to retain for accounting purposes or to defend against claims, for the period resulting from applicable law. Data contained in backups is removed as part of the backup rotation cycle.

6. Who we entrust data to

To provide the service, we use trusted processors that process data on our behalf:

We do not sell personal data and do not transfer it for marketing purposes.

7. Transfers outside the EEA

Data is stored in the European Union region. If any processor processes data outside the European Economic Area, this takes place on the basis of appropriate safeguards, in particular standard contractual clauses approved by the European Commission.

8. Cookies and analytics

The application uses only the essential technical mechanisms (including the browser's local storage) needed to maintain your login session. We do not use advertising cookies, tracking pixels, Google Analytics, or any other external analytics tools — which is why we do not display a cookie consent banner.

9. Your rights (GDPR)

You have the right to:

You can review and edit most of your data yourself in the application, and delete it by deleting your account. For other matters, write to contact@getkinect.app. You also have the right to lodge a complaint with the President of the Personal Data Protection Office (ul. Stawki 2, 00-193 Warsaw, Poland).

10. Data security

We store passwords only as an encrypted hash. Access to data is protected by database-level security mechanisms (Row Level Security), under which a user has access only to their own data and data shared within communities they belong to. The connection to the application is encrypted with the TLS protocol.

11. Visibility of data within communities

If you join a community (Tribe), your nickname, profile picture, and selected achievements and statistics may be visible to other members of that community. You can limit the scope of this visibility in your profile settings.

12. Children

The application is intended for persons aged 16 and over. We do not direct the application at children below that age and do not knowingly collect their data.

13. Changes to this policy

We will inform you of material changes to this policy in the application or by email. The date of the last update is always shown at the top of this page.


Questions? contact@getkinect.app

Kinect · last updated 1 September 2026