Skip to content

KINOS Privacy Policy

Version: 2026-10-02-v1

Effective when first published for production use.

1. Who we are

Keptly Software Inc., Alberta, Canada, operates KINOS. This policy covers our websites, gym-management services, member applications and support activities. Contact our privacy team at info@kinos.fit.

Gyms generally decide why member information is collected and how it is used for their operations. We process it to provide KINOS under authorized instructions. We separately manage information needed for our own platform accounts, billing, security and support. Neither role removes our own privacy obligations. A gym's privacy notice also applies to its activities; this policy does not replace it.

2. Information we handle

Depending on the features used, information may include:

  • Account and contact details, protected authentication information, staff roles and account-access records.
  • Member profiles, dates of birth, household and guardian relationships, memberships, bookings, attendance, ranks, progress notes and communications.
  • Profile photos, waivers, signatures and other uploaded documents.
  • Billing contacts, transactions, invoices, payment status and provider references. Payment providers process payment details under their own privacy notices.
  • Optional face check-in photos and biometric templates, also called embeddings, used to recognize an enrolled member.
  • Support correspondence and technical records such as IP addresses, browser or device information, authentication events and service-error logs.

We receive information from users, their gyms, authorized household members, connected providers and service use. Gyms should collect only what they need and avoid placing unnecessary sensitive information in free-text fields.

3. Purposes and restrictions

We use information to provide accounts and gym operations, process billing, deliver requested communications, support users, fulfil privacy requests, maintain and secure the service, investigate misuse and meet applicable legal obligations.

We do not sell identifiable gym or member information or use it for our own advertising. Optional owner product news is addressed separately below.

We may use properly de-identified aggregate statistics for internal analytics, product improvement and published benchmarks only where they do not identify or reasonably permit identification of a person or gym. We do not sell datasets or attempt re-identification. Removing names alone is insufficient; small-group results require safeguards before publication.

4. Optional face check-in

Face check-in is optional. A non-biometric alternative, such as QR or another supported check-in method, remains available. Photos and embeddings used for face check-in are sensitive personal information, not anonymous information.

Gyms must provide appropriate notices and obtain required permission. Members may withdraw permission and request deletion of their face check-in photos and embeddings without ending their membership. Contact the gym or our privacy team. Withdrawal stops future authorized face-check-in use; it does not require deleting unrelated attendance records.

Embeddings and biometric templates are never included in tenant-downloadable exports, including support-assisted exports. Ordinary profile photos may be included. Retained face check-in photos require a verified owner's support request and appropriate authority; they are not routine self-service downloads. This does not make deleted photos recoverable or limit a person's applicable legal rights.

5. Children and households

Gyms may manage children's records, and guardians may manage dependents through supported household features. Minors may have their own member-app accounts with gym authorization and any required guardian permission. Gyms must obtain required permissions; Keptly retains its own obligations. We do not market to children.

The app supports minor accounts but does not automatically verify guardian approval as a condition of independent minor login. Guardian access to a dependent's records is a separate authorization process.

6. Providers and international processing

Our production PostgreSQL and face-recognition service are self-hosted in Alberta, Canada. Database backups are stored in our private Garage service on storage in Alberta, separately from application objects. Production application providers include:

  • Cloudflare R2: uploaded documents, profile and media assets, and stored face check-in photos. These application buckets are private, without public bucket domains. Application-object backups are not currently configured.
  • Stripe: payment processing, billing details, transactions and payment references.
  • Resend: transactional email, including recipient addresses and message content.
  • Hosted Healthchecks: backup-job status signals, not database dump contents.

A gym may connect additional providers for its enabled features, such as email, optional push notifications or AI assistance. Those providers and their functions must be disclosed when enabled; this policy does not authorize sending unrelated member information to them. Some providers, particularly payment providers, also have independent purposes and obligations described in their own notices.

Information may be processed in Canada, the United States and other countries where vetted providers operate. Foreign laws and lawful government-access requirements may differ. We do not promise Canada-only storage. Contact our privacy team for information about international processing practices.

7. AI and model training

We do not use gym or member information, face photos, embeddings or derived aggregate datasets to train our own general-purpose or face-recognition models. This policy does not give an AI provider permission to train on customer information. Provider terms and settings must be reviewed before enabling AI processing of that information. Running an authorized face match is different from training a model on customer data. This policy does not authorize unrelated AI processing.

8. Cookies and communications

KINOS uses cookies or similar storage for login, security and preferences. Enabled payment and notification integrations may also use their own cookies or similar storage to provide the requested function. Disabling essential storage may prevent requested features from working.

Keptly's product marketing is separate from essential service messages. We will not send promotional emails without appropriate permission and an unsubscribe mechanism. Marketing consent is not required to create or use an account. Essential account, security and billing messages remain separate. Gym-directed member communications are sent under the gym's authority, not as Keptly's own marketing.

9. Personnel access, security and incidents

Authorized personnel may access customer information only when needed for support, security, maintenance or legal obligations. Access must be limited to the task. This policy does not claim that every privileged action is currently covered by an audit log. Safeguards must reflect information sensitivity; no system can guarantee absolute security.

We will notify affected gyms promptly after confirming an incident involving their personal information, explain the known impact and response, and help them notify affected people where necessary. We will also meet our own applicable reporting, notification and recordkeeping obligations. Investigation or lack of full certainty does not extend a mandatory deadline.

10. Retention and platform backups

Information is retained only as needed for its purpose and applicable obligations. Canceled or terminated gyms receive the 30-day export window described in the Business Terms. After that window, operational data becomes eligible for deletion; the end of the window does not mean all copies have been erased. No fixed operational-deletion or backup-expiry deadline is promised in this policy. Backup copies may remain after operational deletion; backup expiry is not currently automated. Narrow accounting requirements and documented legal holds are handled separately. Properly de-identified aggregates may remain only while the conditions above hold.

These backups are platform disaster-recovery backups, not tenant-downloadable backups. They may contain embeddings if the backed-up store contains them. Backup access must be restricted to authorized platform operations. Tenant exports never include embeddings. Completed deletion requests must be considered before restored records return to operational use. This is an operational responsibility, not a claim that automatic deletion replay is currently implemented.

11. Choices and privacy requests

For access, correction or deletion of gym-managed information, contact the gym first. We assist gyms and help route requests received directly, rather than simply rejecting them. We handle requests about our own account, billing and support records directly and respond directly where required by our obligations.

Email info@kinos.fit. We verify identity and representative authority before releasing or deleting information, using proportionate information. Do not send passwords, payment credentials or face photos with an initial request. Some information may need to be retained or withheld under applicable exceptions; we explain limitations where permitted and respond within applicable periods. You may raise concerns with us or the relevant privacy regulator. This policy does not limit statutory rights.

12. Changes

We will date and version this policy and notify affected users of material changes. Where new consent or authorization is required, we will obtain it before changed processing begins. Updating this policy is not advance permission for new purposes, model training or sale of information.