Privacy Policy

Last updated: 2 September 2026

This policy explains what Komezano collects, why, who we share it with, and how you can control it. The data controller is [LEGAL ENTITY NAME], [ADDRESS], Dominican Republic. For any privacy question or request, contact privacy@komezano.com.

1. What we collect

  • Account data: name, email address, password hash, and language preference.
  • Health and fitness data: workouts, exercises, body measurements, goals, meals and nutrition logs. This is sensitive personal data, and we process it only to provide the features you use.
  • AI conversations: the messages you send to AI features and the responses generated for you.
  • Billing data: your subscription and credit-purchase history, plus the customer identifier our payment processor issues. We never see or store your card number — card details go directly to Paddle.
  • Abuse-prevention signals: at registration we store a salted, one-way hash of your IP address and, where available, a device fingerprint. These hashes are used only to stop the same person claiming a one-time signup credit bonus repeatedly. They cannot be reversed to recover the original values, and we do not store the raw IP address or fingerprint.
  • Technical data: server logs needed to operate and secure the service.

2. Why we process it

  • To perform our contract with you: running your account, delivering the features you use, and billing.
  • With your consent: processing health and fitness data, which you give by entering it. You may withdraw consent by deleting the data or your account.
  • Our legitimate interests: keeping the service secure, preventing fraud and credit-bonus abuse, and fixing faults.
  • Legal obligation: keeping transaction records for the period tax law requires.

3. Who we share it with

We use a small number of processors, each for a stated purpose:

  • Paddle.com Market Ltd — payment processing as merchant of record. Receives your email and billing details; we receive back only transaction and subscription metadata.
  • DeepSeek — AI model provider. Receives the content of your AI prompts, which may include fitness and nutrition details you have entered.
  • MongoDB Atlas — database hosting.
  • Cloudinary — image storage for photos you upload.
  • Resend — transactional email (verification, password reset).

We do not sell your personal data, and we do not share it for advertising. Some processors are outside the Dominican Republic, so your data may be transferred internationally under the safeguards in their respective agreements.

4. How long we keep it

  • Account and health data: until you delete it or close your account, then removed within 30 days except where we must retain it by law.
  • Billing records: retained as long as tax and accounting law requires.
  • Abuse-prevention hashes: 12 months from registration.
  • Server logs: up to 90 days.

5. Your rights

You can request access to your data, correct it, export it, or have it deleted; you can object to processing based on legitimate interests, and withdraw consent for health-data processing at any time. Email privacy@komezano.com and we will respond within 30 days. Account deletion is also available directly in your settings.

6. Security

Passwords are hashed with bcrypt and never stored in plain text. Traffic is encrypted in transit. Access to production data is limited to the people who need it to operate the service. No system is perfectly secure, and we will notify affected users without undue delay if a breach puts their data at risk.

7. Children

Komezano is not intended for anyone under 16. If we learn we have collected data from a child under 16, we will delete it.

8. Changes

We will post changes here with a new "last updated" date, and email registered users about any change that materially affects how we use their data.