Privacy policy
The short version. Keho has no accounts and no server that holds your health data. Everything Keho reads from Apple Health, everything it writes back, every statistic and every readiness verdict is processed on your iPhone. Future Coach features, including plans and fueling guidance, will be processed there too. We cannot see any of it. The rest of this page explains the narrow exceptions — connecting a Polar account, paying Apple and counting anonymous taps — because a privacy claim without the small print is worthless.
Who is responsible
Coinlex – Thaiss GbR, Am Dorfanger 12, 25486 Alveslohe, Germany. Responsible person: Cornelius Thaiss. Email: support@coinlex.com.
We have not appointed a data protection officer, as we are not required to. Write to the address above with any data protection question and it reaches the person who can answer it.
The app
Health data
Keho reads from and writes to Apple Health (HealthKit) on your device. That data — sleep, heart rate, heart-rate variability, breathing rate, blood oxygen, temperature, workouts, steps, energy and the rest — stays on the device and in your iCloud backup if you have one enabled. It is never transmitted to us, and we have no technical means of requesting it.
You grant HealthKit permissions per data type, and you can review or revoke any of them at any time in the Health app under Sharing, or in Settings › Privacy & Security › Health. Revoking a permission stops Keho reading or writing that type immediately.
Coaching features work the same way. Readiness and briefings are computed from this data on the device; future plans, weekly reports and fueling guidance will be too. No Coach feature sends your data anywhere to be analysed.
Keho does not use health data for advertising, does not share it with third parties, and does not use it to train any model. Apple’s own rules forbid all three, and the architecture makes them impossible anyway.
Polar-only metrics stored on your device
Some things Polar measures have no equivalent in Apple Health — sleep score, Nightly Recharge, cardio load, per-workout detail. Keho keeps those in a database inside the app’s own storage on your iPhone, because Polar’s API forgets them after roughly four weeks. This store never leaves the device, and disconnecting your Polar account deletes it.
Connecting a Polar account
If you choose to connect Polar, you sign in on Polar’s own website and authorise Keho there. Two things follow:
- One token exchange passes through a service we operate. Completing the sign-in requires a client secret that must not be shipped inside an app, so a single small function we host performs that one step: it receives the authorisation code, exchanges it with Polar, and returns the access token to your device. It does not store the token, and no health data ever passes through it.
- Everything after that is direct. The access token is stored in your device’s Keychain, and your iPhone then talks to Polar’s API directly. Your Polar data travels from Polar to your phone, not via us.
What Polar does with your data as its own controller is governed by Polar’s privacy policy, not this one. You can revoke Keho’s access at any time in your Polar account, or by disconnecting inside the app.
Purchases
Purchases are made through the App Store, with Apple as the seller. We never see or handle payment details. To know which unlocks your device owns, the app uses RevenueCat, Inc. (United States) as a processor: it receives the App Store transaction receipt and an anonymous identifier generated by the app on your device. It does not receive your name, your email address, or any health data. Transfers are covered by the European Commission’s standard contractual clauses.
Product analytics
To find out where the app is broken or confusing, Keho records a small, fixed set of product events — screens opened, whether a sync succeeded, whether onboarding was completed. This uses PostHog on its EU cloud (data stored in the European Union). Specifically:
- Events come from a closed list defined in the app’s source; there is no free-form logging.
- No health values are ever included — not a heart rate, not a sleep duration, not a readiness score.
- The events are attached to a random identifier generated on your device, not to a person, an account, an email address or an advertising identifier. No person profiles are created.
- Nothing is sent from development or simulator builds.
- We do not track you across other apps or websites, and the app’s privacy manifest declares no tracking.
Legal basis: our legitimate interest in a working, improvable app (Art. 6(1)(f) GDPR). You can object to this processing at any time — see Your rights below.
Notifications
The morning briefing, the overnight-vitals alert and sync warnings are local notifications, scheduled on your device by the app. They are not push messages, no server is involved, and their content is composed on the phone. They are opt-in and can be turned off in the app or in iOS Settings.
On-device AI
On iPhones that support Apple Intelligence, the wording of your morning briefing is generated by Apple’s on-device foundation model. On every other iPhone the app uses a fixed template. In both cases the text is produced on the device and no prompt or result is sent anywhere.
This website
Hosting
keho.app is a set of static pages served by Vercel Inc. (United States) as our processor. Like any web server, it processes technical request data — IP address, the page requested, timestamp, referrer and browser user agent — to deliver the page and to defend against abuse. Legal basis: legitimate interest in secure, functioning delivery (Art. 6(1)(f) GDPR). Transfers are covered by standard contractual clauses.
Cookies
This site sets no cookies and embeds nothing from third parties — no fonts fetched from a font service, no analytics script, no video player from another domain, no social buttons. That is why you were not asked to accept anything.
Newsletter
If a signup form is offered and you use it, we process the email address you give us in order to send you the newsletter. Legal basis: your consent (Art. 6(1)(a) GDPR), confirmed by a double opt-in email. Every issue carries a one-click unsubscribe link, and unsubscribing deletes the address from the list. We do not sell or share it, and we do not use it for anything else.
If you contact us
If you email us, we process your address and what you wrote in order to answer. Legal basis: performance of a contract or steps prior to one where your question concerns the app or a purchase (Art. 6(1)(b) GDPR), otherwise our legitimate interest in answering the people who write to us (Art. 6(1)(f) GDPR). We delete the correspondence once the matter is closed, unless commercial or tax law requires keeping it longer.
How long we keep things
- Your health data: we never receive it, so we keep it for no time at all. On your device it lives in Apple Health and is yours to delete.
- Server request logs: retained briefly for security, then discarded.
- Analytics events: retained in aggregate for product analysis and deleted when no longer needed for that purpose.
- Purchase records: retained as long as needed to honour your purchase, and as required by tax and commercial law.
- Newsletter address: until you unsubscribe.
- Support emails: until the matter is closed, then deleted unless a statutory retention period applies.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you (Art. 15);
- have inaccurate data corrected (Art. 16);
- have data erased (Art. 17);
- restrict processing (Art. 18);
- receive your data in a portable form (Art. 20);
- object to processing based on legitimate interest, including our analytics (Art. 21);
- withdraw consent at any time, without affecting what was lawful before (Art. 7(3)).
Write to support@coinlex.com to exercise any of these. One honest caveat: because there is no account, we usually cannot connect a request to a specific device — which is the same property that protects you.
You also have the right to complain to a supervisory authority. Ours is the Unabhängiges Landeszentrum für Datenschutz Schleswig-Holstein (ULD), Holstenstraße 98, 24103 Kiel, Germany.
Children
Keho is not directed at children and we do not knowingly process data from anyone under 16.
Changes
If we change how Keho handles data, this page changes with it and the date at the top moves. Material changes will also be noted in the app’s release notes.