KHNUM PRIVACY POLICY
Last updated: 2026-06-26
Contents
1. Who We Are (Data Controller / Business Identity)
KHNUM is operated by:
Khnum (postal address available on request) Privacy contact: khnumtracker@gmail.com
This Privacy Policy explains how KHNUM ("KHNUM," "we," "us," or "our") collects, uses, stores, shares, and protects information when you use the KHNUM application, the website at khnum.io, and related services (collectively, the "Service"). It is part of and incorporated into the KHNUM Terms of Service (the "Terms"). Capitalized terms not defined here have the meaning given in the Terms.
KHNUM is a self-tracking and educational tool for adults 18 and older. It is not a medical device, not a healthcare provider, and not a substitute for professional medical advice.
For the EU and UK General Data Protection Regulation (collectively, "GDPR"), the entity named above is the "data controller." For US state privacy laws such as the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA"), that entity is the "business."
2. The Short Version (Summary — Not a Substitute for the Full Policy)
- We collect the minimum we need: your email (to sign you in) and the measurements and training data you choose to enter (to track for you).
- Your data is stored in Supabase (a hosted Postgres database) under an executed Data Processing Agreement, protected with row-level security so each account can access only its own rows.
- We do not sell your data, do not share it for advertising, and run no third-party analytics or advertising trackers.
- Your tracking data is sexual-health-adjacent and sensitive. We treat it that way, and we collect it only after a separate, specific consent.
- You can export all your data to CSV at any time and delete your account and data with one tap.
- The Service is for adults 18 and older only.
- We are not a HIPAA-covered entity and not a CMIA provider of health care; your data is not a medical record.
The rest of this Policy is the controlling, detailed version.
3. Sensitive, Sexual-Health-Adjacent Data — and Your Consent
3.1 We Recognize This Data Is Sensitive. The information you enter — body measurements, training-session logs, and EQ ratings — relates to your sexual and physical health. We expressly recognize it may be classified as "Sensitive Personal Information" under CCPA/CPRA (Cal. Civ. Code section 1798.121) and as "Special Category Data" under GDPR Article 9 (data concerning health and/or sex life) for EU/UK users. We apply heightened protections accordingly.
3.2 You Provide This Data Voluntarily and By Self-Report. All measurement, session, and EQ data is self-reported by you. KHNUM does not measure you, does not connect to any wearable, sensor, or external health record, and does not infer any medical diagnosis or clinical condition from your entries.
3.3 Separate, Unbundled Consent. Processing of sensitive data is conditioned on a separate, un-pre-checked consent checkbox presented at account creation, distinct from acceptance of the Terms, that specifically identifies health-adjacent and sex-life data as its subject and links this Policy. For EU/UK users this constitutes explicit consent under GDPR Art. 9(2)(a) that is freely given, specific, informed, unambiguous, and freely withdrawable; it is never bundled into general Terms acceptance. For US users, it operates as your opt-in to processing of Sensitive Personal Information and your direction to limit its use to the purposes in Section 6. We do not process sensitive data before this consent is captured and logged server-side. You may withdraw consent at any time by deleting the relevant data or your account, without affecting the lawfulness of prior processing.
4. Information We Collect — Exhaustive Inventory
4.1 Account / Authentication Data. Email address — to create your account, sign you in, send essential service and security messages, and respond to requests. We use email-based authentication and do not require a name, phone number, or social-login profile.
4.2 Self-Reported Health-Adjacent Data (Sensitive). Measurements (e.g., BPEL, BPFSL, girth); training-session logs (exercises, routines, duration, intensity, dates); EQ ratings and lifestyle check-ins you choose to enter; and free-text notes/journal entries you choose to write — each collected to let you record and review your own data over time.
4.3 Optional Push-Notification Data. Push subscription token/endpoint, only if you enable push notifications, to deliver the reminders you opt into. Push is off unless you turn it on.
4.4 Limited Technical Data. IP address and basic request metadata at authentication time, and standard server logs from our hosting provider, for security, abuse and fraud prevention, and operation/debugging; and local storage/on-device data to keep you signed in and store preferences.
4.5 What We Do NOT Collect. No inferred medical diagnoses, clinical scores, or risk classifications beyond what you enter; no third-party advertising identifiers; no third-party analytics (no Google Analytics, no Meta Pixel, no comparable SDK); no behavioral profiling for advertising; no biometric identifiers; no precise geolocation; and no contact lists, photos, or device files beyond what you deliberately enter. This do-not-collect list is a binding description of the Service.
6. How We Use Your Information (Purpose Limitation)
We use your information only to: (1) provide the Service to you (store, display, and let you track your own data); (2) authenticate you; (3) deliver optional push notifications you enable; (4) maintain security, fraud prevention, and integrity; (5) respond to support and privacy-rights requests; and (6) comply with law and enforce our Terms.
We will not profile you for advertising, sell or rent your data to data brokers, share your data with insurers or employers for their own use, or aggregate your sensitive data for research without your separate, explicit opt-in consent to that specific purpose.
6.1 Lawful Bases (GDPR — EU/UK Users). Performance of a contract (Art. 6(1)(b)) to authenticate and provide the Service; legitimate interests (Art. 6(1)(f)) for security, fraud prevention, and maintenance, balanced against your rights; and, for special-category data, your explicit consent under Art. 9(2)(a) (Section 3.3).
6.2 No Automated Decision-Making With Legal Effect. KHNUM does not use your data to make decisions producing legal or similarly significant effects. Any in-app coach, plateau, deload, or trend readouts are Pattern Summaries derived from your own logged data for informational purposes only; they are not medical advice and create no doctor-patient relationship (Section 9).
7. Service Providers (Processors)
7.1 Supabase — Database and Storage. We use Supabase (hosted Postgres and backend operated by Supabase, Inc. and affiliates) as our cloud database and storage provider, acting as our data processor (GDPR) / service provider (CCPA), processing data only on our documented instructions. Your data is stored in Supabase's infrastructure (built on cloud infrastructure such as AWS) with encryption in transit and at rest, and we apply row-level security so each account's queries are scoped to its own rows. We have entered into Supabase's Data Processing Agreement, including its Standard Contractual Clauses annexes for any EU/UK data, executed in the Supabase dashboard.
7.2 Push-Notification Delivery (Only If You Enable Push). Delivery is handled by the standard Web Push infrastructure provided by your browser/operating-system vendor; only the minimum routing information needed to deliver a notification is processed for that purpose. If we introduce a separate third-party push vendor, we will name it here and bind it as a processor.
7.3 No Other Processors. Apart from the providers above (and the infrastructure they rely on), no third party is given access to your measurement, session, EQ, or note data. We engage no advertising networks, analytics vendors, or data-enrichment services.
9. Not a Medical Record; Not Medical Advice; HIPAA and CMIA Do Not Apply
- KHNUM is a self-tracking and educational tool, not a healthcare provider and not a medical device.
- No physician-patient, therapist-client, or other professional-client relationship is created by your use of the Service. Coach outputs, plateau/deload/decon-break readouts, exercise instructions, and form cues are educational and informational only, derived solely from your own logged data, and are not medical advice, diagnosis, or treatment.
- Consult a licensed physician before beginning any physical training program, and seek prompt medical attention upon pain, numbness, bruising, discoloration, erectile changes, or any other warning sign.
- HIPAA does not apply. We are not a HIPAA "covered entity" and Supabase is not our HIPAA "business associate." Your data is not a HIPAA-protected medical record, and we do not claim HIPAA compliance.
- CMIA. KHNUM is not a "provider of health care," "health care service plan," "contractor," or "employer" within the meaning of the California Confidentiality of Medical Information Act (Cal. Health & Safety Code section 56.05) or any comparable state statute. The data you enter is personal tracking data you record for your own self-monitoring, not medical information created in the course of treatment.
10. Data Retention and Deletion
10.1 Retention. We retain your account and self-reported data for as long as your account is active. We retain limited security and server-log metadata only as long as needed for the security purposes in Section 6, then delete or anonymize it.
10.2 Export Before You Delete. You can export all your data to CSV at any time, so you can keep your own copy before deleting your account.
10.3 One-Tap Account Deletion. When you use the in-app "Delete Account" function, your account and personal data are deleted from the active Supabase database promptly (logical deletion is immediate; full purge from the active store follows without undue delay). Residual copies may persist in encrypted backups/point-in-time-recovery snapshots for up to 30 days before they age out and are overwritten; backups are not used for any other purpose and are not restored except for disaster recovery.
10.4 Litigation-Preservation Exception. Where a legal claim or regulatory inquiry is reasonably anticipated, we may suspend rather than delete an account and preserve associated data, because deletion after a claim arises may constitute spoliation of evidence (see Terms Section 2.7). We may also retain a minimal record that an account was deleted (without the underlying sensitive data) where necessary to comply with law or prevent abuse.
11. Security and Breach Posture
11.1 Security Measures. We use measures designed to be appropriate to the sensitivity of the data, including encryption in transit (TLS) and at rest via our hosting infrastructure; row-level security scoping each account to its own data; email-based authentication with no third-party social-login ingestion; and data minimization (we collect only what Section 4 lists and run no third-party trackers).
11.2 Reasonable Care, Not Perfection. Our obligation is to apply commercially reasonable technical and organizational measures appropriate to the sensitivity of your data, including the measures in Section 11.1. No security system is impenetrable, and we cannot guarantee that unauthorized access will never occur. We commit to reasonable care, not perfection; a breach attributable to a sophisticated external attack despite reasonable precautions is not a breach of that standard.
11.3 Breach Notification. If we discover a breach affecting your personal data, we will notify you and the appropriate authorities consistent with the strictest applicable legal standard, which may include: the FTC Health Breach Notification Rule (16 C.F.R. Part 318, as amended 2024) — notice to affected individuals and the FTC generally within 60 days of discovery, and to media where required; state breach-notification laws — for example California (Cal. Civ. Code section 1798.82), for which we target notification within 30 days for sensitive/medical-adjacent information; and GDPR (Arts. 33-34, EU/UK users) — notification to the relevant supervisory authority within 72 hours of becoming aware where required, and to affected individuals without undue delay for high-risk breaches (sensitive health data is high-risk by default). To report a suspected vulnerability or breach, contact khnumtracker@gmail.com.
12. Your Privacy Rights
We honor the rights below for all users to the extent available under applicable law, regardless of where you live.
12.1 Rights. Access/Know; Export/Portability (in-app CSV export); Correct/Rectify (edit entries directly); Delete/Erase (in-app one-tap Delete Account, or contact us); Withdraw consent (EU/UK users, for sensitive-data processing, without affecting prior lawful processing); Limit use of Sensitive Personal Information (we already limit it to the Section 6 purposes); Opt out of sale/sharing (not applicable, as we do not sell or share); and Non-discrimination for exercising any right.
12.2 How to Exercise. Most rights can be exercised in-app; for anything else, email khnumtracker@gmail.com. We respond within the timeframes required by law — generally within 45 days under CCPA/CPRA (extendable once where permitted) and within one month under GDPR (extendable by two months for complex requests). We may verify your identity (e.g., control of your account email) before fulfilling a request.
12.3 Authorized Agents, Appeals, and CCPA Non-Waiver. Where the law allows, you may use an authorized agent. If we decline a request, you may appeal by replying to our response; we honor formal appeal rights under laws such as Virginia and Colorado. Nothing in this Policy or the Terms waives or limits any right under the CCPA/CPRA, including any right to statutory damages under Cal. Civ. Code section 1798.150, consistent with section 1798.192.
13. International Users and Cross-Border Data Transfers
KHNUM is operated from the United States and your data is processed and stored on US-based infrastructure.
13.1 Intended Audience. KHNUM is intended for users in the United States, and we apply geo-controls intended to restrict access from jurisdictions whose mandatory laws conflict with our Terms. If EU/UK residents nonetheless access the Service, GDPR may apply to the sensitive health/sex-life data we process regardless of where our servers sit.
13.2 Transfer Mechanism. If we process personal data of EU or UK residents, transfers to our US infrastructure rely on the EU Standard Contractual Clauses (2021 implementing decision), incorporated into our processor agreement with Supabase, and the UK International Data Transfer Addendum (IDTA) for UK personal data. You may request more information at khnumtracker@gmail.com.
13.3 Right to Lodge a Complaint. EU/UK users may lodge a complaint with their local supervisory authority (e.g., their national DPA, or the UK Information Commissioner's Office).
13.4 US State Residents. If you are a resident of California, Virginia, Colorado, Texas, or another US state with a comprehensive privacy law, the rights in Section 12 are available to the extent provided by your state's law.
14. Children — Adults Only (18+)
- The Service is intended solely for adults 18 years of age or older. By creating an account you represent and warrant you are at least 18; affirmation of age at signup is a condition of use.
- We apply technical age-assurance measures beyond the affirmation, including email verification before activation, no social-login bypass of age capture, server-side logging of the age affirmation with timestamp and IP, and geo-restriction of jurisdictions whose age-verification laws we have not yet met (Terms Sections 2.4-2.5).
- We do not knowingly collect personal data from anyone under 18, and we do not knowingly collect personal data from children under 13 within the meaning of COPPA. We operationalize the COPPA "actual knowledge" standard: upon credible information that a user may be a minor, we act under the incident-response protocol below.
- Incident Response. Upon credible information that a user is under 18, we suspend the account pending investigation; where litigation or regulatory inquiry is reasonably anticipated we preserve rather than delete the data (to avoid spoliation) and notify counsel; otherwise we terminate the account and delete the associated data. If you believe a minor has provided us data, contact khnumtracker@gmail.com.
15. Business Transfers
If KHNUM is involved in a merger, acquisition, financing, reorganization, or sale of assets, your data may be transferred as part of that transaction. The acquirer will remain bound by the commitments in this Policy (including the no-sale and purpose-limitation commitments) with respect to data collected before the transaction, unless and until you are given notice and, where required, the opportunity to consent to or decline any materially different practices.
16. Changes to This Policy
We may update this Policy as the Service and the legal landscape evolve. We will revise the "Last Updated" date, and for material changes provide reasonable advance notice by email and/or prominent in-app notice before the change takes effect. Where the law requires — for example a material change to how we process sensitive data, or the introduction of any selling/sharing — we will obtain your renewed, explicit consent before the new practice applies, rather than relying on continued use alone.
17. Contact Us
Questions, requests, or complaints about this Policy or your data:
Privacy contact: khnumtracker@gmail.com Operator: Khnum Notice address: (available on request)
A designated privacy contact (khnumtracker@gmail.com) is the single point of contact. If EU/UK users are served at scale, a GDPR Art. 27 EU/UK representative and/or Art. 37 Data Protection Officer may be designated and identified here.
18. Governing Law
This Policy is governed by the laws of Texas, without regard to conflict-of-laws rules, except that EU/UK and US-state-resident users retain the mandatory consumer and data-protection rights of their home jurisdiction that cannot be waived by a governing-law clause. This Section is coordinated with the governing-law, arbitration, and dispute-resolution provisions of the Terms.