Kern
SupportSourcesPrivacyTermsCookies

Legal

Privacy Policy

This page explains what Kern collects, how that data is used, and the choices available to users.

Last updated: August 17, 2026

Last updated

26 September 2026. This policy applies to the Kern mobile app and the public pages at joinkern.com.

Data you provide

Account and profile data may include your email address, name, username, date of birth, units, goals, availability, injuries, training preferences, notification choices, and other onboarding answers.

Nutrition and training data may include foods, calories, macronutrients, supplements, planned sessions, completed workouts, exercise sets, feedback, routes, and performance targets that you enter or import.

Age requirement

Kern is only available to people aged 18 or older. We use the date of birth connected to your account to verify this requirement and block access when the requirement is not met.

The age check does not make Kern a medical service and is separate from any age rating displayed by an app store.

Data from services you connect

With your permission, Kern may receive health and wearable signals such as steps, sleep, heart rate, resting heart rate, heart-rate variability, weight, body measurements, energy, and workout data from Apple Health, Strava, Fitbit, or another service you choose to connect.

If you connect a calendar, Kern may process event titles, dates, and times needed to place training around your schedule. Kern also stores connection identifiers and access tokens needed to keep an integration working; these credentials are not shown to other users.

How and why we use data

We use these data to authenticate you, sync the services you choose, calculate informational readiness and training guidance, show nutrition and schedule features, personalize Kern, prevent abuse, maintain security, troubleshoot failures, and answer support requests.

Kern does not sell personal data or use health data for advertising. We limit access to people and service providers who need it to operate, secure, or support Kern, or when disclosure is required by law.

Health information and safety limits

Kern is a general fitness and wellness product, not a regulated medical device. Its readiness scores, recovery interpretations, nutrition estimates, and training suggestions are informational heuristics and have not been clinically validated for diagnosis or treatment.

Kern does not diagnose conditions, prescribe treatment, or replace a healthcare professional or emergency service. The methods and supporting sources are published at joinkern.com/sources. Seek qualified medical advice before making medical decisions and contact local emergency services for potentially life-threatening symptoms.

Ask Kern and OpenAI

Before Ask Kern sends anything to an external AI provider, the app asks for separate, explicit permission. If you allow it, your question, up to eight recent chat messages, and selected context may be sent to OpenAI to generate the requested response. Depending on the question, context can include recovery and wearable summaries, recent workouts, training plans and goals, nutrition totals and targets, calendar titles and times, weather, or saved preferences. Locally generated direct-answer messages are excluded from the conversation history sent to OpenAI.

Context selection is conservative and question-based, not a guarantee that automated selection is perfect. General unrecognised questions send no additional personal context. Kern excludes account identifiers, connection tokens and arbitrary database metadata from server-generated plan context; session identifiers needed to prepare a reviewable plan proposal are included. Avoid putting unnecessary sensitive information in questions, event titles or workout names.

Without that permission, Kern does not send Ask Kern questions or context to OpenAI. The permission is stored with your authenticated account and checked by Kern before each external AI request. Tap the profile icon to open Settings → Data & Privacy → External AI (OpenAI) to revoke permission; the app must ask again before a later transfer. Changing the disclosed AI data use also invalidates the stored permission and requires a new choice.

Kern keeps Coach conversation content out of crash-diagnostic events. OpenAI processes submitted content as Kern’s service provider under the data-protection and retention settings applicable to Kern’s API account.

Location, weather and routes

You may choose live device location, manually enter a city, or continue without weather. Your preference and any saved weather location are scoped to your signed-in account. Live mode requests device permission and sends coordinates to the weather provider for local conditions. Manual mode uses only the location you entered.

When you choose without weather, Kern does not request device location, infer location from your IP address, use stored coordinates, or call the weather service for that feature. Kern does not use IP-based location as a fallback.

Route creation is a separate optional feature. When you search for an address or place in route planning, the search text is sent directly to OpenStreetMap Nominatim, which also receives normal network information such as your IP address. When you generate a route, start, destination or waypoint coordinates and route preferences are sent through Kern’s server to openrouteservice. These requests do not contain your Kern account ID, but an address or coordinates can still identify a sensitive location.

On iOS, imported route points, heart-rate samples and derived route segments may be cached on your device to support personal routes. This rebuildable cache is stored outside iCloud device backups and is removed when you sign out or delete your account. Kern also removes the older backed-up route-cache location when upgrading.

Aggregate onboarding conversion measurement

Kern keeps daily totals of which fixed onboarding steps are reached, so we can understand the overall signup conversion funnel. Each total is grouped only by day, platform and app version. The conversion table does not contain an account ID, session ID, device identifier, precise timestamp, IP address, onboarding answer, health value, message or location.

The private dashboard shows totals only. It cannot reconstruct an individual journey or identify which person reached a step. A restarted signup can add another reach, so these figures describe onboarding attempts rather than unique people.

Conversion totals are not sold, used for advertising, or shared with advertisers. We keep them for up to 24 months and then delete them automatically.

Subscriptions and Superwall

Apple processes App Store purchases. Kern uses Superwall to display subscription offers, restore purchases and determine access. Superwall receives your Kern account identifier, app and device information needed by its SDK, and purchase or subscription status. Kern does not send your health readings, workout details, nutrition records, calendar events, routes or Coach messages to Superwall.

Kern configures Superwall with event tracking disabled and resets its device identity when you sign out or change accounts. Required purchase processing and provider network connections still occur. Resetting the SDK does not erase existing provider records or cancel an Apple subscription. Account deletion creates a restricted request for Kern support to arrange erasure with Superwall; the account identifier is removed from that queue after provider confirmation. Transaction records that must be retained by Apple or a provider follow their applicable retention obligations. Contact support@joinkern.com about the status of a request or retained provider records.

Optional notifications and Expo Push

Rest-timer alerts and planned-workout reminders are scheduled locally after you opt in. If you enable Activity Completed, Kern stores an Expo device push token linked to your account and current sign-in session. Kern sends that token, your account identifier for delivery checks, and a generic activity-update message through Expo Push and Apple Push Notification service. It does not include workout names, health readings or route coordinates in the message.

Notification choices are separate for each Kern account. Signing out or deleting your account cancels scheduled notifications and unregisters this device. Kern also requests invalidation of the server session used for push delivery; this server step requires a working connection. Workout-reminder frequency and quiet hours apply to planned-workout reminders, while rest-timer alerts and Strava activity updates follow their own switches.

Other service providers

Kern uses Supabase for account authentication, database storage, and server functions; connected providers you select for health, training, and calendar sync; Superwall for subscription access and paywalls; Expo Push and Apple for opted-in push delivery; Open-Meteo for opted-in weather; OpenStreetMap Nominatim for route-place searches; openrouteservice for route calculation; and Sentry for scrubbed technical crash and performance diagnostics.

Sentry events are restricted to technical release/timing information, generic error types, source-code locations and fixed breadcrumb codes. Request data, network spans, URL queries, dynamic route names, free-form messages, stack variables and unknown event fields are removed before sending. Provider network infrastructure still receives normal connection information such as an IP address; the production Sentry project must not store it as a user identifier.

Providers receive only the data needed for their task. We use encrypted connections, access controls, secret storage, and provider configuration intended to protect personal data. A provider may process data in another country, subject to the safeguards available for that service.

Retention and deletion

Kern keeps account and connected data while your account is active and for as long as needed to provide the features you use. You can disconnect an integration to stop new syncs and can remove local permissions in your device settings.

Tap the profile icon to open Settings, scroll to Delete account, type DELETE, and confirm Delete account permanently to delete your Kern account and synced data from active systems. Limited security or legal records may be kept only when required, and protected backup copies expire through the normal backup lifecycle rather than being used as an active account.

For accounts linked to Sign in with Apple, Kern attempts to revoke Apple access during deletion when a valid revocation credential is available. If Apple requires manual removal, the app provides the official Apple Account steps after Kern deletion completes.

Deleting your Kern account does not cancel an App Store subscription. Cancel it separately in your Apple Account to stop future renewal; the app provides a Manage Apple subscriptions link before deletion.

Your rights and choices

Depending on where you live, you may have rights to access, correct, export, restrict, object to, or delete personal data, and to withdraw consent without affecting earlier lawful processing. You may also complain to your local data-protection authority.

Use the in-app controls where available or contact support@joinkern.com from the email address connected to your account. We may need to verify your identity before completing a request.

Security

We use technical and organizational safeguards designed to protect personal data. No online service can guarantee perfect security, so you should only connect services you are comfortable using with Kern.

Contact

Kern is responsible for the processing described in this policy. For privacy questions, requests, or complaints, email support@joinkern.com.