Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how Softure UG (haftungsbeschränkt) ("we", "us", "Softure") processes personal data when you use Kavi (the "app"), available at kavi.fit. We are the controller within the meaning of the EU General Data Protection Regulation (GDPR).
1. Who we are
Softure UG (haftungsbeschränkt)
Scharfenberger Str. 28, 13505 Berlin, Germany
Email: customers@softure-ug.de
2. What data we collect
Kavi is a fitness and nutrition companion, so some of the data we process is health-related. We collect:
- Account data — your email address and authentication details.
- Health & fitness data — the workouts, meals, body weight, supplements, goals and plans you log, either by chatting with Kavi or through the app.
- Chat content — the messages you exchange with your AI assistant and, on the Coach plan, with your human coach.
- Payment data — handled by our payment processor; we do not store your full card details.
- Technical data — device type, app version and basic usage logs needed to run and secure the service.
3. Why we process it (legal bases)
- To provide the service (Art. 6(1)(b) GDPR — performance of a contract): logging your entries, generating targets and plans, and delivering coach reviews.
- Special-category health data (Art. 9(2)(a) GDPR): we process your fitness and nutrition data on the basis of your explicit consent, which you give when you create an account and start logging. You can withdraw consent at any time.
- Payments and legal obligations (Art. 6(1)(b) and (c) GDPR).
- Security and improvement (Art. 6(1)(f) GDPR — legitimate interests).
4. Processors and third parties
We share data only with providers that help us run Kavi, under data processing agreements:
- Anthropic — powers the AI assistant. Your messages and relevant logged data are sent to Anthropic solely to generate responses. This data is not used to train their models.
- Stripe — processes subscription payments. Stripe receives the data needed to complete your transaction.
- Hosting and infrastructure providers — used to store data and run the service, located within the EU where possible.
Where data is transferred outside the EU/EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.
5. Retention
We keep your account and health data for as long as your account is active. If you delete your account, we delete or anonymise your personal data within 90 days, except where we must retain limited records to meet legal obligations (e.g. tax records for payments).
6. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased ("right to be forgotten");
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting prior processing;
- lodge a complaint with a supervisory authority.
To exercise any of these rights, email customers@softure-ug.de.
7. Data security
We use encryption in transit, access controls and other technical and organisational measures to protect your data.
8. Changes to this policy
We may update this policy from time to time. Material changes will be communicated in the app or by email.