PRIVACY POLICY
Privacy Policy
kynikOS is a personal concierge service that acts on your behalf — scheduling, booking, coordinating, and managing life logistics. This Privacy Policy explains how we collect, use, store, and protect your information, including health and fitness data from connected devices.
Last updated: July 2026
1. Information We Collect
We collect the following categories of information:
Account information
- Your Telegram identity — the Telegram user ID and the profile name you choose to share. Identity and sign-in are handled through Telegram; kynikOS does not use, store, or ask for passwords.
- Profile details you provide during onboarding (such as display name and time zone) and any contact information you add (email, phone number)
Messages and instructions
- Messages you send to kynikOS via Telegram or other channels
- Preferences, constraints, and goals you express
- Photos and files you share for processing
Calendar and scheduling data
- Events from connected calendars (Google Calendar, iCal, etc.)
- Bookings and appointments created on your behalf
- Availability and scheduling preferences
Health and fitness data
- Activity, sleep, heart rate, steps, and training metrics from wearables you connect (currently Garmin Connect, Withings, and WHOOP)
- Body composition and weight measurements from connected devices
- Nutrition information you log (meals, photos, macronutrient data)
- Recovery scores and health metrics synced from your connected sources
Action and audit data
- Records of all actions taken on your behalf (calls made, emails sent, bookings placed)
- Voice call transcripts, when kynikOS calls a business for you (raw call audio is not retained once transcribed)
- Execution logs and outcomes
2. How We Use Your Information
We use your information solely to provide and improve the kynikOS service:
- Execute tasks on your behalf — making bookings, phone calls, sending emails, managing your calendar
- Learn your preferences — understanding your routines, constraints, and priorities to act more effectively over time
- Health and fitness insights — using data from connected devices to optimize scheduling around your training, recovery, and well-being
- Coordination — helping you coordinate schedules with family, friends, and other kynikOS users (only with your explicit permission)
- Audit and transparency — maintaining a complete log of all actions for your review
- Service improvement — analyzing usage patterns (in aggregate) to improve the service
We do not use your data for advertising, profiling for third parties, or any purpose unrelated to providing you with the kynikOS service.
3. Health and Fitness Data
Health and fitness data from connected devices and services (collectively “Health Data”) is treated under stricter rules than any other category of data described in this Policy. At the date of this Policy, the wearable/fitness integrations supported by kynikOS are Garmin Connect, Withings, and WHOOP; kynikOS does not integrate with Apple Health, Google Fit, Fitbit, Oura, or any other comparable service, and does not receive Health Data from any such source. The commitments in this Section 3 apply in addition to, and where inconsistent override, the provisions of Section 6 (Information Sharing) and Section 11 (International Data Transfers).
What Health Data includes
- Sleep, heart rate, heart-rate variability (HRV), respiration, SpO2, stress, and Body Battery metrics
- Activity, workout, and training data (including GPS tracks, power, pace, cadence, and FIT-file derived metrics)
- Recovery, training readiness, training load, and training status indicators
- Body composition, weight, and wellness measurements
- Cycle and women's health data
- Any insights, summaries, or derived values computed by kynikOS directly from the above
How Health Data is handled
- No selling or third-party sharing. Health Data is never sold, rented, licensed, disclosed, or otherwise made available to any third party — including affiliates, advertisers, brokers, analytics providers, insurers, or employers — except (i) to infrastructure providers strictly necessary to operate kynikOS's own systems (e.g. encrypted database hosting), bound by written data processing agreements and prohibited from any independent use of the data, or (ii) where required by law.
- Raw metrics never reach an external AI provider. Your raw wearable measurements — numeric heart rate, heart-rate variability, sleep stages, respiration, SpO2, GPS tracks, power, pace, and the full FIT-file data behind them — are never sent to, processed by, or used to train any external artificial-intelligence, machine-learning, or large-language-model provider (including OpenAI, Anthropic, Google, Meta, Mistral, Cohere, xAI, or any comparable service). This boundary is enforced in kynikOS's database layer and in the contracts of the tools the assistant may call — it is a technical guarantee, not merely a policy statement.
- Only coarse derived bands inform the assistant. So that scheduling and morning briefings can be recovery-aware, the assistant may receive a small number of derived categorical bands computed by kynikOS from your Health Data — for example a readiness or recovery band such as “low”, “moderate”, or “high”. These are non-numeric summaries; the underlying raw metrics are never transmitted. Where such a derived band is processed by the external AI provider, that transfer is governed by Standard Contractual Clauses (see Section 11).
- Purpose limitation. Health Data is used exclusively to deliver the user-facing features you have enabled: morning recovery briefings, training program management, activity tracking and attribution, recovery-aware scheduling, and personal health baselines. It is never used for advertising, profiling for third parties, insurance or employment decisions, or any purpose unrelated to your own use of kynikOS.
- Collection is opt-in. Health Data is only collected after you explicitly connect a device or service and grant the corresponding permissions. You can disconnect any source at any time from your dashboard.
- Storage. Health Data is stored encrypted at rest in databases controlled by kynikOS and hosted in Europe (Switzerland, recognised as adequate by the EU). Access is restricted to automated systems acting on your behalf and a small number of authorised personnel under confidentiality obligations.
- Retention and deletion. Health Data is retained only while the corresponding source is connected. On disconnection or on your request, all associated Health Data is deleted within 30 days, subject to any legal retention obligation.
3.1 Garmin Connect Data
Data obtained through the Garmin Connect Developer Program API (“Garmin Data”) is Health Data and is therefore fully subject to the commitments in Section 3 above. In particular, and in accordance with the Garmin Connect Developer Program requirements:
- Garmin Data is never shared with, or otherwise made available to, any third party, and is never processed by any third-party data processor, beyond the limited infrastructure-provider exception described in Section 3 above.
- Raw Garmin metrics are never sent to, processed by, or used to train any external AI or LLM provider (including OpenAI, Anthropic, Google, or any comparable service). Only coarse derived categorical bands computed by kynikOS on its own infrastructure (for example a recovery band) may inform the assistant, as described in Section 3 above.
- Garmin Data is processed exclusively within kynikOS's own infrastructure, solely to provide the features described in Section 3 above to the individual user the data belongs to.
- Garmin Data is attributed to Garmin in accordance with the Garmin Brand Guidelines wherever it is displayed (primary dashboards, detail views, charts, and derived insights).
- The Garmin Connect connection can be revoked at any time from your dashboard or from Garmin Connect; upon revocation (whether initiated by you, by Garmin, or as a result of termination of kynikOS's access to the Garmin Connect Developer Program), all Garmin Data held by kynikOS will be deleted within 30 days.
- kynikOS does not aggregate, anonymise, pseudonymise, or otherwise transform Garmin Data for sale, licensing, benchmarking, or the creation of derivative datasets; nor does it use Garmin Data to develop products that compete with Garmin, or to train any general-purpose model, whether internal or external.
3.2 WHOOP Data
Data obtained through the WHOOP Developer Platform API (“WHOOP Data”) is Health Data and is therefore fully subject to the commitments in Section 3 above. In particular, and in accordance with the WHOOP API Terms of Use:
- WHOOP Data is accessed only with your express authorisation, given when you connect your WHOOP account, and only under the scopes you approve. You can revoke access at any time from your dashboard or from your WHOOP account settings.
- WHOOP Data is never marketed, sold, licensed, or leased, and is never transferred or disclosed to third parties beyond the limited infrastructure-provider exception described in Section 3 above.
- Raw WHOOP metrics — your recovery score, HRV, resting heart rate, SpO2, skin temperature, sleep stages, and strain values — are never sent to, processed by, or used to train any external AI or LLM provider. Only coarse derived categorical bands computed by kynikOS on its own infrastructure (for example a recovery band) may inform the assistant, as described in Section 3 above.
- Raw WHOOP records may be retained on a limited rolling window; long-term history is kept only as aggregate summaries computed by kynikOS. On disconnection or on your request, WHOOP Data is deleted under the retention-and-deletion commitment in Section 3 above.
- kynikOS consumes WHOOP's scores as provided and does not attempt to reverse engineer or reconstruct WHOOP's algorithms, and does not use WHOOP Data for any medical purpose.
3.3 Explicit Consent for Special-Category Data
Health Data qualifies as a special category of personal data under Article 9 of the GDPR. By connecting a health source (currently Garmin Connect, Withings, or WHOOP) you give your explicit consent under Article 9(2)(a) GDPR to the processing of that data by kynikOS for the purposes described in this Section 3. You may withdraw this consent at any time by disconnecting the source from your dashboard; withdrawal does not affect the lawfulness of processing carried out before withdrawal.
3.4 No Medical Advice; Not a Medical Device
kynikOS is a personal productivity and concierge service. It is not a medical device within the meaning of Regulation (EU) 2017/745 (MDR), the US Food, Drug, and Cosmetic Act, or any equivalent legislation, and is not intended for the diagnosis, prevention, monitoring, prediction, prognosis, treatment, or alleviation of any disease, injury, or disability. Recovery briefings, training suggestions, nudges, summaries, and any other health-related output are informational and lifestyle-oriented only and do not constitute medical advice, diagnosis, or treatment. You should always consult a qualified healthcare professional before making decisions that affect your health, and you should not disregard or delay seeking professional advice because of anything produced by kynikOS.
4. Actions Taken on Your Behalf
kynikOS executes actions on your behalf — making bookings, sending emails, placing voice calls, creating calendar events, and coordinating with businesses and other kynikOS users. The following framework governs those actions:
- Agency. When kynikOS contacts a third party in your name, it acts as your authorised agent, with you as the principal. You are responsible for the instructions you give and for reviewing the actions taken. You may revoke this authority, in whole or for a specific action, at any time.
- Human oversight (GDPR Art. 22). Actions executed by kynikOS do not constitute solely-automated decisions producing legal or similarly significant effects on you. You remain in the loop through (i) the instructions you issue, (ii) approval requests surfaced before high-impact actions, (iii) a complete audit log available in your dashboard, and (iv) the ability to cancel, reverse, or contest any action.
- AI limitations. kynikOS's agent is powered by large language models and other AI components, which can produce incorrect, incomplete, or unexpected outputs. You should review the actions proposed or executed, in particular those involving bookings, purchases, external communications, and anything with financial, legal, or health implications.
- No use of your data to train models. Your personal data, messages, Health Data, and the content of actions taken on your behalf are not used to train any AI model, whether operated by kynikOS or by a third party.
- Voice calls to third parties. When kynikOS calls a business on your behalf, the agent identifies itself as an AI assistant calling on your behalf where legally required. Calls are transcribed for audit, quality, and dispute-resolution purposes, on the legal basis of legitimate interest (yours and ours). Raw call audio is not retained once it has been transcribed; the resulting transcript is kept like your other messages and is deleted when you delete it. The called party may request deletion of the transcript of their call at any time via the contact address in Section 14 below.
- Liability. Subject to mandatory law, kynikOS is not liable for the outcomes of actions you instructed or authorised kynikOS to take, including actions you had the opportunity to review, reject, or cancel. Further allocation of responsibility between you and kynikOS is set out in our Terms of Service.
5. Connected Third-Party Services
kynikOS integrates with third-party services to act on your behalf. These include:
- Telegram — for messaging and authentication
- Calendar providers (Google Calendar, Apple Calendar) — for scheduling
- Wearables and fitness trackers (Garmin Connect, Withings, WHOOP) — for health and activity data
- Communication services (telephony and voice providers for calls, email delivery, browser automation for online bookings) — for acting on your behalf
We only access data from these services that you explicitly authorize. Your use of these services is also governed by their respective privacy policies. We request the minimum permissions necessary and you can revoke access at any time.
6. Information Sharing
We do not sell your personal information. We may share information only in these cases:
- At your direction — when you ask kynikOS to contact a business, share your availability, or coordinate with others
- Service providers — infrastructure providers who help us operate (e.g. cloud hosting, and, for non-Health Data only, AI processing). These providers are bound by data processing agreements and act only on our documented instructions
- Legal requirements — when required by law or to protect rights and safety
The sharing described in this Section 6 does not apply to Health Data, which is governed exclusively by the stricter rules set out in Section 3 (including the rule that raw wearable metrics never reach an external AI provider).
7. Data Storage and Security
- Data is stored in encrypted databases hosted in Europe (Switzerland, recognised as adequate by the EU)
- Your conversations and the payloads of tasks the assistant runs are additionally encrypted at rest with keys held outside the database provider, so the stored contents are not readable by the hosting provider alone
- All data in transit is encrypted using TLS 1.2+
- Access to production systems is restricted and audited
- Health and fitness data receives additional encryption at rest
- Voice call transcripts can be deleted at your request; raw call audio is not retained once transcribed
- We conduct regular security reviews of our infrastructure. To report a vulnerability, contact [email protected]
8. Data Retention
We retain your data for as long as your account is active and as needed to provide the service. Specifically:
- Account data — retained while your account is active
- Chat and message history — kept until you delete it, because it is the assistant's working memory: it is what lets kynikOS remember your preferences, context, and past instructions. When you delete a message or conversation, it is removed from the live system immediately and disappears from encrypted backups as they roll off, within approximately 30 days
- Health and fitness data — retained while the data source is connected; deleted within 30 days of disconnection or upon request
- Voice call transcripts — retained like your other messages and deleted when you delete them; raw call audio is not retained once transcribed
- Bookings and action logs — retained so you have a reviewable record of what was done on your behalf; deletable on request
You can request deletion of all your data at any time. Deletion takes effect immediately in our live systems and clears from encrypted backups as they roll off (approximately 30 days), except where a specific retention obligation is required by law.
9. Your Rights
Under the GDPR and applicable data protection laws, you have the right to:
- Access — request a copy of all personal data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — request deletion of your data (“right to be forgotten”)
- Portability — receive your data in a structured, machine-readable format
- Restriction — request that we limit processing of your data
- Objection — object to processing based on legitimate interests
- Withdraw consent — withdraw any consent you have given, at any time
- Revoke permissions — disconnect any connected service or revoke any permission granted to kynikOS
To exercise any of these rights, including a full export or deletion of your data, email [email protected]. A self-serve export and deletion flow is not yet available in the dashboard, so these requests are handled by our team and honoured promptly. You can also disconnect any connected service at any time from your dashboard.
Every action performed by kynikOS on your behalf is logged and available for your review through your dashboard. This audit trail is part of our commitment to transparency.
10. Legal Basis for Processing
We process your personal data on the following legal bases:
- Contract — processing necessary to provide the kynikOS service you have subscribed to
- Consent — for health and fitness data, and for connecting third-party services. You can withdraw consent at any time
- Legitimate interest — for service improvement and security, balanced against your privacy rights
11. International Data Transfers
Your data is stored in Europe — specifically Switzerland, which the European Commission recognises as providing an adequate level of data protection. Some of the providers that help operate kynikOS are located outside Europe. In particular, the AI model that powers the assistant is operated by a provider in the United States, and receives your message text, calendar event titles, the personal context you declare, and coarse derived health bands (never raw wearable metrics — see Section 3). Where data is transferred to a country without an adequacy decision, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission. Traffic sent to the AI provider is not used to train its models.
12. Children's Privacy
kynikOS is not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
13. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes via the service or email. Continued use of the service after changes constitutes acceptance of the updated policy.
14. Contact
The data controller is Kynikos OÜ, Järvevana tee 9, Kesklinna linnaosa, 11314 Tallinn, Estonia (registry code 17330279). For privacy-related questions, to exercise your rights, or to file a complaint:
- Privacy and data requests: [email protected]
- Security vulnerabilities: [email protected]
- Through your kynikOS Telegram bot
You also have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon) or with the supervisory authority in your country of residence.