Privacy policy
Last updated 29 August 2026
Khepri holds an unusual amount of information about the people who use it — what they weigh, how they slept, where they ran, and what they wrote in a journal at eleven at night. This page says exactly what is stored, where it goes, and how to get it back or delete it.
OPERATOR_LEGAL_NAME_UNSET (OPERATOR_ADDRESS_UNSET) is the controller of that data. Questions, requests and complaints: privacy@khepri.invalid.
What is stored
Only what you or an integration you connected put there. Nothing is bought from a data broker and nothing is inferred from third-party tracking.
- Account — email address, display name, a password hash (never the password), timezone, coaching-tone preference. If you sign in with Google or a passkey, the identifier that provider gives us.
- Health and body data — weight, body measurements, sleep, hydration, and any biometric readings you record or a connected device pushes.
- Activity and location — workouts, training plans, activity sessions, and, if you connect Strava, your activities including the route traces they carry. A route trace is location data about where you actually were.
- Nutrition — foods, meal plans and what you logged.
- Your writing — check-ins, journal entries, decisions, goals, and every message you exchange with the coach.
- Memory — durable facts the system derives from your conversations so it does not have to ask twice. You can see, edit, pin and delete these.
- Documents — files you upload, the text extracted from them, and numeric embeddings of that text used for search.
- Integrations — access tokens for services you connect, encrypted at rest; your Telegram chat identifier if you link it; tokens issued to agents you authorise.
- Operational records — sign-in events, account activity, model usage and cost, and error logs.
Health data needs your explicit consent
Most of the list above is ordinary personal data. Weight, sleep, biometrics and anything health-related in your journal are special category data under Article 9 of the UK and EU GDPR, and are processed only on your explicit consent, given when you create an account and record it.
You can withdraw that consent at any time by deleting the data or your account. Withdrawal does not undo processing that already happened, and Khepri stops working in any meaningful way without it — a coach with no health data is a chat window.
Where your data goes
Khepri is not advertising-funded and sells nothing to anyone. Data reaches other companies only where the product cannot work otherwise:
- AI providers. This is the disclosure that matters most. To answer you, the coach sends the model your message together with the context it assembled — which can include your goals, recent conversations, check-ins, training and nutrition summaries, and passages from your own documents. Which company receives it depends on the provider configured for your account, and you may supply your own API key instead, in which case your data goes to your provider under your own agreement with them.
- Strava — only if you connect it, and only to read your activities.
- Telegram — only if you link a chat. Your messages and the coach's replies pass through Telegram's servers, under Telegram's own policy.
- Product analytics. A small number of events — account created, onboarding finished, a source connected, the coach answered — recorded against your account identifier to see whether the product works. No health data, no message content, no document text.
- Hosting, storage and email — the servers the application runs on, object storage for files you upload, and a mail provider for account email such as password resets.
How long it is kept
Until you delete it. Long conversations are summarised rather than discarded, because the point of the product is that it remembers — so a thread you had months ago may survive as a summary after its individual messages are compacted.
Deleting your account removes your data. Backups and logs containing incidental records may persist for a short period before rotating out.
What you can do
Under the UK and EU GDPR you may access, correct, delete, export, restrict or object to the processing of your data, and withdraw consent. Two of these need no request at all:
- Export — Settings → a complete archive of your data, downloaded immediately.
- Deletion — Settings → delete account.
For anything else, write to privacy@khepri.invalid. If you are unhappy with the response you may complain to your data protection authority — in the UK, the Information Commissioner's Office.
Security, honestly stated
Passwords are hashed. Integration tokens are encrypted at rest. Sessions are protected against cross-site request forgery, and you can see your account's sign-in history.
Khepri is built and run by a very small team. It is not independently audited and holds no security certification. If that is not an acceptable custodian for your health data, the honest advice is not to store it here.
Changes
Material changes will be announced in the application before they take effect. The date at the top of this page is when it last changed.