Privacy Policy
Last updated: 25 August 2026
1. Introduction & Data Controller
This Privacy Policy explains how Kovio GmbH ("we", "us", "our") collects, uses, and protects your personal data when you use the Treya website (treya.app) and the Treya mobile application.
We are committed to protecting your privacy and handling your data in an open and transparent manner, in compliance with the Swiss Federal Act on Data Protection (nDSG) and the EU General Data Protection Regulation (GDPR).
Data Controller:
Kovio GmbH
Ussbergstrasse 4d, 8864 Reichenburg, Switzerland
Email: office@kovio.ch
2. What Data We Collect
Data collected on our website (treya.app)
- Beta Registration: Email addresses submitted for our beta waitlist.
- Authentication: Supabase authentication session cookies (strictly necessary).
Data collected by the Treya mobile app
- Account Profile: Email, display name, avatar, bio, sex, birthday, preferred units, privacy settings.
- Health & Wearable Metrics: Data imported from Apple HealthKit / Google Health Connect (body weight, body fat %, HRV, resting heart rate, sleep duration, sleep quality, workout heart rate time-series, active calories).
- Body Measurements: Chest, waist, hips, biceps, thighs (in cm).
- Injury Records: Body region (18-item taxonomy), side, severity, description, dates.
- Daily Readiness & Wellness: Readiness score, sleep score, recovery score, energy level (1-5), stress level (1-5), notes.
- Workout Logs: Exercises, sets, reps, weight, RPE, rest times, notes, personal records, session duration, volume tonnage.
- Social: Followers/following relationships, shared workouts.
- Push Notifications (optional): A device registration token and the platform name, stored only after you allow notifications. The Firebase software in the app also registers an installation identifier with Google whenever the app starts, whether or not you allow notifications. We do not store that identifier. See Section 5.
3. Health & Sensitive Data
The Treya mobile app collects extensive health and biometric data to provide you with personalised fitness insights. Because this is considered sensitive personal data under the nDSG and special category data under the GDPR, we only process this data based on your explicit consent.
When you first use the app or connect external health services (like Apple HealthKit or Google Health Connect), we will ask for your explicit consent to collect and process this data. You may withdraw this consent at any time within the app settings.
AI coaching features
Several features write text for you with an external AI provider: your daily tip, your weekly and monthly reviews, workout recaps, plateau and progressive-overload advice, injury suggestions, plan generation, and the Coach chat. To do that, parts of the data above are sent to that provider inside the request. Depending on the feature this can include your sleep duration, resting heart rate, heart rate variability, your reported energy, stress and feeling, your active injuries, and your workout history.
We do not send your name, your email address, or your account identifier with these requests. Section 5 names each AI provider and Section 7 explains where the processing happens. This is part of the health processing you consent to under this section, and withdrawing that consent turns these features off.
4. Purpose and Legal Basis
We process your data for the following purposes:
- Service Provision: To provide and maintain the Treya app and website (Contractual necessity).
- Health Analytics: To calculate readiness, track progress, and provide personalised fitness insights (Explicit consent - nDSG Art. 5(c) and GDPR Art. 9(2)(a)).
- Beta Program: To manage the waitlist and send invitations (Legitimate interest / Consent).
- Communication: To send transactional emails such as account confirmations (Legitimate interest).
- Push Notifications: To tell you that a plan you asked for is ready, or that it could not be written (Consent). You give this consent in the system prompt, and you can withdraw it in your device settings.
5. Third-Party Services & Data Sharing
We use the following trusted third-party services to operate Treya:
- Supabase: Used for database hosting, authentication, and file storage. Hosted in the EU (Frankfurt).
- Brevo (formerly Sendinblue): Used for transactional emails (e.g., beta confirmations). Based in the EU.
- Google Fonts: Loaded via Next.js for website typography (no cookies used).
- Apple HealthKit / Google Health Connect: Device-local APIs. Data is only pulled to the app with your explicit permission.
- Cloudflare: Used for three things: hosting the treya.app website, delivering the exercise animations you see in the app, and running the AI models behind the coaching features described in Section 3. Cloudflare's terms state that it does not use this content to train any AI model or to improve any Cloudflare or third-party service, and Treya stores nothing on the AI service. A Data Processing Addendum is in place.
- TokenRouter (ATR): A second AI gateway. It is used when the Cloudflare daily allowance is spent, and for the larger model available on the paid tier. ATR removes end-user identity markers before it forwards a request. Its terms state that it does not train on your data, and its Data Processing Agreement restates that rule with an exception for what is required to provide the model service you were routed to. ATR then forwards the request to a model provider — Anthropic for the paid tier's model, and other inference hosts for the shared model — and each provider's own terms govern that step. We do not choose which host answers a given request. A Data Processing Agreement is in place with ATR. See Section 7.
- Google (Firebase Cloud Messaging): Used to deliver push notifications to your device, and only if you allow notifications. The Firebase software is part of the mobile app, so it registers a Firebase installation identifier with Google when the app starts, whether or not you allow notifications. If you allow them, Google also receives four things for each notification: the registration token for your install of the app, the title, the body, and the in-app screen the notification opens when you tap it. A notification body can name the workout plan you asked for, and the screen it opens can carry that plan's identifier. Google does not receive your email address, your account identifier, or any health or workout record. Google acts as a processor for this service under its own Data Processing Terms. Firebase Cloud Messaging runs on Google's global network, so a notification can be processed outside Switzerland and the European Union, including in the United States. See Section 7.
We do not sell your personal data to third parties.
6. Cookies
Our website uses only strictly necessary cookies, specifically Supabase authentication session cookies required for administrative access. We do not use any analytics, tracking, or marketing cookies.
7. Cross-Border Data Transfers
Storage. Your account, workout and health records are stored within the European Union (Frankfurt, Germany) via Supabase. Transactional email runs through Brevo, which is also EU-based.
AI processing is different, and we state it plainly. The AI providers named in Section 5 run on global networks, and neither Cloudflare nor TokenRouter guarantees the country in which a single request is processed. So a coaching request that carries health data can be processed outside Switzerland and the European Union, including in the United States. We rely on Data Processing Agreements with Standard Contractual Clauses for these transfers.
Push notifications also leave the European Union.Google does not guarantee the country in which a notification is handled, so everything Section 5 lists for that service can be processed outside Switzerland and the European Union, including in the United States. It is a narrow transfer: a token, a few lines of text, and one screen name. It carries no health record, no workout history and no account identifier. We rely on Google's Data Processing Terms, which carry Standard Contractual Clauses, and on Google's certification under the Swiss-U.S. Data Privacy Framework.
Push is optional, and you lose nothing by refusing it. Notifications are off until you allow them, and you can turn them off again in your device settings. If you refuse, the app registers no token with us, so no notification and no token ever reach Google. Every plan, review and record still waits for you in the app. The installation identifier described in Section 5 is the one thing that is sent either way, and we do not link it to your Treya account.
Retention. Cloudflare stores no content from this service. ATR processes a request in memory and purges it once the answer is delivered, except where it must keep the request to investigate an incident or to meet a legal requirement. We cannot make the same statement for the model providers ATR forwards to, because each of those providers applies its own terms to that step.
8. Data Retention
We retain your data only as long as necessary to fulfill the purposes for which it was collected:
- Beta Emails: Retained until the end of the beta program or upon your deletion request.
- Account & Health Data: Retained until you request account deletion. Once you delete your account, your personal data and workout history will be permanently deleted.
- Push Notifications: Google holds a notification for up to one day, until your device collects it. A device that never collects it does not get it, and Google discards it. A registration token is retained while the device is registered. If somebody else signs in on the same device, the token moves to their account and stops reaching you. It is deleted when Google reports that it is no longer valid, and when you delete your account.
9. Data Security
We implement robust technical and organisational measures to protect your personal and health data against unauthorised access, alteration, disclosure, or destruction.
10. Your Rights (nDSG + GDPR)
You have the following rights regarding your personal data:
- Right to Information: Know what data we collect and how we use it.
- Right to Rectification: Correct inaccurate or incomplete data.
- Right to Deletion: Request the deletion of your personal data ("right to be forgotten").
- Right to Data Portability: Receive a copy of your data in a structured, machine-readable format.
- Right to Restriction of Processing: Limit how we process your data.
- Right to Objection: Object to our processing of your data.
- Right to Withdraw Consent: Withdraw explicit consent for processing health data at any time.
To exercise these rights, please contact us at office@kovio.ch. You also have the right to lodge a complaint with your supervisory authority (the FDPIC in Switzerland, or the relevant Data Protection Authority in your EU country).
11. Children's Privacy
Treya is not intended for individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected such data, we will take steps to delete it immediately.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will notify users of significant changes, and the "Last updated" date at the top will reflect the latest version.
13. Contact
If you have any questions or concerns about this Privacy Policy or your data, please contact us at:
Kovio GmbH
Ussbergstrasse 4d, 8864 Reichenburg, Switzerland
Email: office@kovio.ch