Privacy Policy

This policy explains what personal data Kadre collects, why we collect it, how we protect it, and the rights you have over it. We designed Kadre to hold as little of your data as possible and to give you control over what we do hold.

Last updated: 27 July 2026.

Who we are

Kadre operates the strength-coaching platform at kadre.so (the “Service”). For questions about this policy or your data, contact us at privacy@kadre.so. Where this policy refers to a “data controller,” Kadre is the controller of your account and platform data; coaches are independent controllers of the athlete relationships they bring to or build on Kadre.

Data we collect

How we use your data

Legal bases (GDPR)

Where the GDPR applies, we rely on: performance of a contract (to run your account and fulfil purchases), your consent (for analytics cookies and marketing you opt into), our legitimate interests (to secure and improve the Service), and legal obligation (tax and accounting records).

Who we share data with

We do not sell your personal data. We share it only with the processors that run the Service under contract: Supabase (database, authentication, storage), Stripe (payments and payouts), Resend (transactional email), Mux (exercise video), and PostHog (consented product analytics). Each processes data on our instructions. We may also disclose data if required by law.

Your rights

You can access, correct, export, or delete your data at any time. Coaches can export their full client list and purchase history from their dashboard; athletes can request a copy or deletion of their data. Depending on where you live, you also have the right to object to or restrict certain processing, and to withdraw consent. To exercise any right, email privacy@kadre.so — we respond within the time limits set by applicable law.

Data retention

We keep your data for as long as your account is active and as needed to provide the Service. When you delete your account we delete or anonymise your personal data, except records we must retain for legal, tax, or fraud-prevention reasons.

Security & international transfers

Access to data is controlled by row-level security so people only see what they are entitled to. Passwords are hashed and payment details are handled by Stripe. Where data is transferred internationally, we rely on appropriate safeguards such as Standard Contractual Clauses.

Children

Kadre is not directed to children under 16, and we do not knowingly collect their data. If you believe a minor has given us data, contact privacy@kadre.so and we will remove it.

California privacy rights (CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect, to request its deletion, to correct it, and to opt out of its “sale” or “sharing.” Kadre does not sell or share your personal information as those terms are defined under the CCPA/CPRA. To make a request, email privacy@kadre.so. We will not discriminate against you for exercising these rights.

Changes to this policy

We will update this policy as the Service evolves and post the new version here with a revised date. Material changes will be communicated in-product or by email.