Privacy & Data Processing Policy
This policy explains how the openkoutsi public instance at app.koutsi.dev (“the App”, “we”, “us”) collects, processes, stores, and protects your personal data — including biometric health data — in accordance with Regulation (EU) 2016/679 (the “GDPR”). It reflects a core design principle of openkoutsi: your fitness data belongs to you, is accessible only to you, and is never exposed to other users.
openkoutsi is open-source software that anyone can self-host. This policy covers only the public instance we operate at app.koutsi.dev. If you use a different instance, the operator of that instance is your data controller and provides their own policy.
1. Who we are (Data Controller)
Data controller: Lassi Heikkilä. The public instance at app.koutsi.dev is operated by an individual, not a company, so there is no company registration number.
Contact for privacy matters: lassi@koutsi.dev.
No Data Protection Officer (DPO) or Article 27 representative has been appointed; neither is required for an instance of this nature and scale. This will be updated here if that changes.
2. Our privacy-by-design approach
Each user's data is held in its own isolated per-user database. Only two kinds of “actors” ever have access to your data:
- You — the only human who can view your raw data and results.
- Automated processing — algorithms running on our server, and (only if you opt in) an AI model that analyses your data to produce insights.
No other user, and no administrator of the instance, can read your decrypted fitness or biometric data in the ordinary course of operation. openkoutsi ships with zero telemetry: no analytics and no third-party tracking SDKs.
3. What data we process
3.1 Data you provide or generate
- Biometric and health data — heart rate, weight, heart-rate and power zones, and other fitness metrics you record or connect. This is “special-category data” under Article 9 GDPR and receives heightened protection.
- Activity and derived data — workouts, training-load metrics (fitness/fatigue/form), trends, goals, and insights calculated from your metrics.
- Account and configuration data — your username, your email address (if you sign up with one or verify one for password resets), display name, an optional profile picture, and your settings and preferences.
3.2 Technical data
- Diagnostic data — app/server error logs used to keep the service working and secure. We do not run web analytics on you.
4. How your data is processed and stored
4.1 Storage
Your data is stored on a single UpCloud server in Helsinki, Finland — an EU-owned provider, on EU soil, under EU and Finnish law. Storage is encrypted at rest and backed up daily, and each user has a private database that no one else — not even an administrator — can read. Data is transmitted between your device and the server over an encrypted connection (TLS).
4.2 Automated algorithmic processing
Algorithms on the server calculate your metrics, detect trends, and generate insights. This runs automatically and produces results only you can see; it involves no human reviewer.
4.3 Optional AI analysis
AI analysis is optional and off by default. If — and only if — you enable it, the relevant metrics for the requested insight are sent to a large language model (“LLM”) to produce a natural-language analysis. The provider and model are shown to you before analysis runs, and you can disable the feature at any time, after which no further data is sent to any provider. When you enable it, the submitted data is processed by the third-party provider under that provider's own terms and privacy policy (including any decisions they make about model training, retention, and processing location).
5. Lawful bases for processing
| Processing activity | Lawful basis (Art. 6) | Special-category condition (Art. 9) |
|---|---|---|
| Core processing of your fitness/biometric data to provide the App | Art. 6(1)(b) — performance of a contract with you | Art. 9(2)(a) — your explicit consent |
| Optional AI/LLM analysis of your data | Art. 6(1)(a) — consent | Art. 9(2)(a) — your explicit consent, per feature |
| Security, diagnostics, and stability | Art. 6(1)(f) — legitimate interests | N/A (no health data used for this purpose) |
Because biometric health data is special-category data, we rely on your explicit consent, requested clearly and separately when you first sign in. You can withdraw consent at any time without affecting processing carried out beforehand. Withdrawing consent to AI analysis stops that feature; withdrawing consent to core processing means the App can no longer function, and you may export or delete your data.
6. Who can access your data
- You — full access to your own data and insights.
- Automated processing — algorithms and, if enabled, your chosen LLM.
- No other users — the App does not expose your data to any other user.
- Administrators — cannot read your decrypted fitness/biometric data; it is per-user and encrypted at rest. The one exception is any message you choose to send to the published contact address (see below): like any email you send someone, its contents are readable by the administrators who receive it.
- Third-party AI providers — only the provider you select, only when you enable AI analysis, and only for the data sent for that analysis.
- Email provider — if this instance sends email (sign-up verification, password-reset links), your email address is shared with the configured provider (Lettermint or EuroMail) solely to deliver those messages. Mail you send to the instance's published contact address is received and processed by Proton Mail (the operator's email provider) and read by the instance's administrator(s).
7. Automated decision-making
The insights and suggestions the App generates are informational. They do not produce legal or similarly significant effects on you within the meaning of Article 22 GDPR — they are decision-support, not automated decisions about your rights or obligations.
8. Third-party services and international transfers
If you connect them, the App exchanges activity data with Strava and/or Wahoo under their respective terms — these integrations are entirely optional. See their privacy policies for how they handle your data: Strava and Wahoo. If you enable AI analysis, your data is sent to the LLM provider you configure. Some providers may process data outside the EU/UK; where that happens, transfers rely on an appropriate safeguard such as the EU Standard Contractual Clauses or an adequacy decision. Because the App shows you the provider before analysis, you can decline if you prefer not to transfer data internationally. Where a third party processes data on our behalf, we put an Article 28 data processing agreement in place; this includes our hosting provider, UpCloud.
If this instance is configured to send transactional email (such as sign-up verification or password-reset links), your email address is processed by the configured email provider to deliver those messages. Both supported providers are EU-based, so the data stays within the EU. See their privacy policies for how they handle it: Lettermint and EuroMail.
Any message you send to the instance's published contact address (for this instance, lassi@koutsi.dev) is received and processed by Proton Mail (Proton AG, Switzerland — recognised by the EU as providing an adequate level of data protection) and read by the instance's administrator(s) so they can respond. Only send information you are comfortable sharing with the operator — this channel is for reaching a person, and is separate from your private, encrypted training data, which administrators still cannot read.
9. Data retention
- Your fitness and biometric data is kept until you delete it or close your account, after which it is removed from the live system, with backups rotating out on our daily backup cycle.
- Data sent to an AI provider is retained according to that provider's policy.
- Diagnostic logs are kept only as long as needed for security and stability.
10. Your rights
Under the GDPR you have the right to access, rectification, erasure, restriction, data portability, objection, and to withdraw consent at any time. You can:
- Export your data (profile and raw activity data) as a downloadable archive from within the App at any time.
- Delete your account and all associated data from within the App at any time.
- Withdraw consent to health-data processing or AI analysis at any time.
For anything else, contact us at lassi@koutsi.dev; we respond within one month as required by Article 12. You also have the right to lodge a complaint with the Finnish supervisory authority, the Office of the Data Protection Ombudsman.
11. Security
We protect your data with encryption at rest, encryption in transit (TLS), per-user database isolation, data minimisation (only the data needed for a feature is processed or transmitted), and daily backups. If a breach is likely to risk your rights and freedoms, we will notify the supervisory authority within 72 hours (Article 33) and, where the risk is high, inform you without undue delay (Article 34).
12. Children
The App is not intended for or directed at children under 16. We do not perform age verification, but we do not knowingly collect or process data from anyone under that age. If you believe a child has created an account, contact us at lassi@koutsi.dev and we will delete the account and its data.
13. Changes to this policy
We may update this policy from time to time. Material changes — particularly to the data processed, the third parties involved, or the lawful bases — are notified in the App before they take effect and require your renewed consent. The version and date at the top reflect the current text.
14. Contact
Data controller: Lassi Heikkilä (an individual).
Privacy contact: lassi@koutsi.dev.
Supervisory authority:
Office of the Data Protection Ombudsman (Finland).