← Back to openkoutsi

Privacy & Data Processing Policy

Version 1.0 · Effective 2026-07-14 · Applies to the public instance at app.koutsi.dev

This policy explains how the openkoutsi public instance at app.koutsi.dev (“the App”, “we”, “us”) collects, processes, stores, and protects your personal data — including biometric health data — in accordance with Regulation (EU) 2016/679 (the “GDPR”). It reflects a core design principle of openkoutsi: your fitness data belongs to you, is accessible only to you, and is never exposed to other users.

openkoutsi is open-source software that anyone can self-host. This policy covers only the public instance we operate at app.koutsi.dev. If you use a different instance, the operator of that instance is your data controller and provides their own policy.

1. Who we are (Data Controller)

Data controller: Lassi Heikkilä. The public instance at app.koutsi.dev is operated by an individual, not a company, so there is no company registration number.

Contact for privacy matters: lassi@koutsi.dev.

No Data Protection Officer (DPO) or Article 27 representative has been appointed; neither is required for an instance of this nature and scale. This will be updated here if that changes.

2. Our privacy-by-design approach

Each user's data is held in its own isolated per-user database. Only two kinds of “actors” ever have access to your data:

No other user, and no administrator of the instance, can read your decrypted fitness or biometric data in the ordinary course of operation. openkoutsi ships with zero telemetry: no analytics and no third-party tracking SDKs.

3. What data we process

3.1 Data you provide or generate

3.2 Technical data

4. How your data is processed and stored

4.1 Storage

Your data is stored on a single UpCloud server in Helsinki, Finland — an EU-owned provider, on EU soil, under EU and Finnish law. Storage is encrypted at rest and backed up daily, and each user has a private database that no one else — not even an administrator — can read. Data is transmitted between your device and the server over an encrypted connection (TLS).

4.2 Automated algorithmic processing

Algorithms on the server calculate your metrics, detect trends, and generate insights. This runs automatically and produces results only you can see; it involves no human reviewer.

4.3 Optional AI analysis

AI analysis is optional and off by default. If — and only if — you enable it, the relevant metrics for the requested insight are sent to a large language model (“LLM”) to produce a natural-language analysis. The provider and model are shown to you before analysis runs, and you can disable the feature at any time, after which no further data is sent to any provider. When you enable it, the submitted data is processed by the third-party provider under that provider's own terms and privacy policy (including any decisions they make about model training, retention, and processing location).

5. Lawful bases for processing

Processing activityLawful basis (Art. 6)Special-category condition (Art. 9)
Core processing of your fitness/biometric data to provide the AppArt. 6(1)(b) — performance of a contract with youArt. 9(2)(a) — your explicit consent
Optional AI/LLM analysis of your dataArt. 6(1)(a) — consentArt. 9(2)(a) — your explicit consent, per feature
Security, diagnostics, and stabilityArt. 6(1)(f) — legitimate interestsN/A (no health data used for this purpose)

Because biometric health data is special-category data, we rely on your explicit consent, requested clearly and separately when you first sign in. You can withdraw consent at any time without affecting processing carried out beforehand. Withdrawing consent to AI analysis stops that feature; withdrawing consent to core processing means the App can no longer function, and you may export or delete your data.

6. Who can access your data

7. Automated decision-making

The insights and suggestions the App generates are informational. They do not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR — they are decision-support, not automated decisions about your rights or obligations.

8. Third-party services and international transfers

If you connect them, the App exchanges activity data with Strava and/or Wahoo under their respective terms — these integrations are entirely optional. See their privacy policies for how they handle your data: Strava and Wahoo. If you enable AI analysis, your data is sent to the LLM provider you configure. Some providers may process data outside the EU/UK; where that happens, transfers rely on an appropriate safeguard such as the EU Standard Contractual Clauses or an adequacy decision. Because the App shows you the provider before analysis, you can decline if you prefer not to transfer data internationally. Where a third party processes data on our behalf, we put an Article 28 data processing agreement in place; this includes our hosting provider, UpCloud.

If this instance is configured to send transactional email (such as sign-up verification or password-reset links), your email address is processed by the configured email provider to deliver those messages. Both supported providers are EU-based, so the data stays within the EU. See their privacy policies for how they handle it: Lettermint and EuroMail.

Any message you send to the instance's published contact address (for this instance, lassi@koutsi.dev) is received and processed by Proton Mail (Proton AG, Switzerland — recognised by the EU as providing an adequate level of data protection) and read by the instance's administrator(s) so they can respond. Only send information you are comfortable sharing with the operator — this channel is for reaching a person, and is separate from your private, encrypted training data, which administrators still cannot read.

9. Data retention

10. Your rights

Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, objection, and to withdraw consent at any time. You can:

For anything else, contact us at lassi@koutsi.dev; we respond within one month as required by Article 12. You also have the right to lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman.

11. Security

We protect your data with encryption at rest, encryption in transit (TLS), per-user database isolation, data minimisation (only the data needed for a feature is processed or transmitted), and daily backups. If a breach is likely to risk your rights and freedoms, we will notify the supervisory authority within 72 hours (Article 33) and, where the risk is high, inform you without undue delay (Article 34).

12. Children

The App is not intended for or directed at children under 16. We do not perform age verification, but we do not knowingly collect or process data from anyone under that age. If you believe a child has created an account, contact us at lassi@koutsi.dev and we will delete the account and its data.

13. Changes to this policy

We may update this policy from time to time. Material changes — particularly to the data processed, the third parties involved, or the lawful bases — are notified in the App before they take effect and require your renewed consent. The version and date at the top reflect the current text.

14. Contact

Data controller: Lassi Heikkilä (an individual).
Privacy contact: lassi@koutsi.dev.
Supervisory authority: Office of the Data Protection Ombudsman (Finland).