Skip to content
Kosh

Privacy Policy

Last updated September 11, 2026

On this page

Kosh is a running training app that builds an adaptive plan for you. This policy explains what information we collect, how we use it, and the choices you have.

We collect only the data needed to generate and adapt your plan. We do not sell your data. You can delete your account and associated data at any time.

What we collect

  • Account. A user identifier, plus the name and email address your sign-in provider shares with us (with Sign in with Apple that can be a private relay address). We use them to name your profile and tie your plan to your account. Also an email address if you provide one for waitlist or support.
  • Training inputs. Experience level, race goal, plan duration, and recent race time (used to estimate VDOT).
  • Workout logs. Distance, duration, perceived effort, and notes you record against workouts Kosh plans.
  • Health metrics, if you connect them. With your explicit permission, Kosh reads heart rate variability, resting heart rate, sleep, and completed-run data from Apple Health (iOS), Health Connect (Android), Whoop, or Garmin Connect. Connections can be revoked in Settings, and each permission can be withdrawn individually from Apple Health or Health Connect at any time.
  • Friends and social activity. If you add friends, they can see your completed runs (distance, duration, pace, elevation, and how the run felt), your current training week, and a single upcoming key workout so they can cheer you on. They cannot see your private workout notes, your location, or any route data. Kosh does not collect route or precise GPS data at all. Your display name and profile photo, if you set one, are visible to people you have accepted as friends.
  • Training Partners, if you opt in. Creating a Training Partners profile shares the information you enter (your display name, city (typed by you, never taken from your device's location), race distance, race date, goal time, a short blurb, and the contact handle you choose) with runners matched to the same metro area and race distance, so you can find someone to train with. Your profile is only visible while you keep it listed, and removing it removes it from matching.
  • Device notification token. So we can send you a push notification when a friend reacts to your run or your weekly coach review is ready. This is a routing address, not an advertising identifier, and it is deleted when you sign out.
  • Approximate location, only if you turn on weather-aware coaching. Off by default. When it is on, Kosh asks your device for a single coarse, city-scale fix so it can look up the day's forecast and adjust hot-day guidance. We use it for that request and cache the forecast on your device; we do not store your location on our servers, build a location history, or read your position in the background. Turning the setting off stops it, and the permission can be revoked in system settings at any time.

How we use it

  • To generate your training plan.
  • To adapt paces and volume based on how workouts felt and on the readiness signals your connected devices provide.
  • To display your own training history inside the app.

What we do not do

  • We do not sell your data.
  • We do not share your data with advertisers.
  • We do not train third-party AI models on your personal health data.

Third parties

Kosh uses these services to operate. Each processes only the data strictly required for its function:

  • Supabase: stores your plan and workout logs.
  • Apple HealthKit (iOS): reads health metrics on your device, at your permission. Health data accessed via Apple HealthKit (HRV, resting heart rate, sleep, workouts) is processed on-device to adapt your training. Kosh stores on its servers the readiness result and the small set of daily inputs behind it (heart rate variability, sleep duration, and resting heart rate), plus the summary of each run (including average heart rate), so your readiness history and coach work across devices. Route and GPS data are never collected.
  • Health Connect (Android): the Android equivalent of the above, and the only way Kosh reads health data on Android. Heart rate variability, resting heart rate, sleep, exercise sessions, distance, and elevation are read on your device at your permission and processed on-device. Only the resulting adjustment value and the summary of a completed run you choose to log are stored on our servers; the raw readings are not. Kosh also requests background read access so that a run you record while Kosh is closed still appears in your training history without you having to open the app. Kosh writes completed Kosh workouts back to Health Connect so your other apps see them. You can revoke any of this in Health Connect at any time, and doing so does not delete data already saved to your Kosh account. To remove that data, delete your account.
  • Sign in with Apple (iOS): if you choose to sign in with Apple, Apple provides a stable identifier, your name, and your email address (or a private relay address if you choose Hide My Email). Kosh stores the name and email to name your profile and keep your plan tied to your account. Kosh never sees your Apple password and reads nothing else from your Apple ID.
  • Sign in with Google (Android): if you choose to sign in with Google, Google provides a stable identifier and your account email address so we can create and recover your account. We never see your Google password, and Kosh reads nothing else from your Google account.
  • Terra: the wearable-integration provider that brokers the Garmin, Polar, Coros, and Suunto connections. If you connect one of those devices, Terra processes the activity, sleep, and daily-summary data it forwards to us.
  • Firebase Cloud Messaging (Android) and Apple Push Notification service (iOS): deliver push notifications. They receive a device token and the notification text, never your health data.
  • Anthropic: powers the daily coach read, the optional weekly coach review, and the coach chat on each day page. It receives a summary of your recent training (planned and completed sessions, weekly mileage, how sessions felt, a derived readiness band, and a weather note), the display name you set on your profile, and whatever you type to the coach, in order to write the read, answer you, or suggest an adjustment. It does not receive your email, raw health readings, or location, and under our agreement your data is not used to train models.
  • Whoop Developer API: if you connect, retrieves recovery, sleep, and workout data.
  • Garmin Connect: if you connect, receives daily summaries and workout data via a webhook on our servers.
  • Apple WeatherKit: if you turn on weather-aware coaching, provides the forecast Kosh uses to adjust hot-day guidance. On iOS your device requests the forecast from Apple directly; on Android our servers request it on your behalf. Either way WeatherKit receives an approximate location (city-scale, never a precise position or route) and never your identity or training data.
  • Vercel: hosts this website and our backend API routes.

Talk to Jehan: human plan review

Kosh includes an optional chat for a human review of your training, currently provided by Kosh's founder. The coach can see your chat messages together with a summary of your training: your race goal and date, plan progress, recent weeks' planned and completed mileage, your fitness estimate, and your latest daily readiness scores (which are derived from the health metrics you've connected). The coach sees your profile name, or your account email if you have no profile yet, but never raw health readings or location. If you never use the chat, nothing changes about how your data is handled; this access exists so a human can review plans, and for no other purpose.

How we handle health data

  • Health data is used only to adapt your training plan. This includes adjusting today's workout to your recovery and updating your fitness estimate from completed runs.
  • Health readings are processed on your device. What reaches our servers is your daily readiness score together with the three inputs that produced it (heart rate variability, sleep duration, resting heart rate), your fitness adjustment, and the summary of any run you log (distance, duration, pace, elevation, average heart rate, and how it felt). Nothing else read from Health leaves your device.
  • We do not sell health data, share it with advertisers or data brokers, or use it for advertising or any other product.
  • We do not use health data to train AI models, and our agreements with the providers listed above prohibit them from doing so either.
  • Health data is never transferred to a third party except the processors named above, each strictly to operate the feature you enabled.
  • Deleting your account deletes the health-derived data we hold. Data in Apple Health or Health Connect belongs to you and is unaffected by deleting your Kosh account.

Retention & deletion

We retain your plan, workout logs, and connected-device data for as long as your account is active. You can delete your account and all associated data from Settings → Privacy → Delete account, or by emailing jehan@kosh.run. We honor deletion requests within 30 days.

Children

Kosh is not directed at children under 13 and we do not knowingly collect data from them.

Changes to this policy

When we change this policy, we'll update the date above and, for material changes, notify you in the app or by email.

Contact

For privacy questions, email jehan@kosh.run.