Privacy Policy — Karb AI

Last updated: March 2026

Overview

Karb AI ("we," "us," or "our") operates an AI-powered nutrition coaching service delivered via SMS at karbnut.ai. This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data.

By using our service, you agree to the practices described in this policy. We collect only what we need to provide coaching and we do not sell your personal data to third parties.

Data We Collect

Information you provide directly:

• Name, email address, and phone number

• Age, biological sex, height, and body weight

• Athletic goals, training history, and race information

• Dietary preferences, restrictions, and food logs submitted via SMS

• Responses to our intake questionnaire

Information collected automatically:

• SMS message content and timestamps

• Coaching interaction history

• Macro and nutrition tracking data derived from your logs

Information from connected devices (with your permission):

• Workout activity, distance, pace, and heart rate data from Strava

• Recovery scores, sleep data, and strain scores from WHOOP (if connected)

Third-Party Integrations

Strava: When you connect your Strava account, we access your activity data including workout type, distance, duration, and heart rate via the Strava API. You may revoke access at any time through your Strava settings.

WHOOP: When you connect your WHOOP account, we access recovery scores, HRV, sleep data, and strain scores via the WHOOP API. You may revoke access at any time through the WHOOP app.

We do not access data from these platforms beyond what is necessary to deliver your coaching service.

How We Use Your Data

We use data solely to:

• Deliver personalized nutrition coaching via SMS

• Calculate and adjust your macro targets and nutrition plan

• Analyze your training load and recovery data to inform coaching

• Send proactive coaching messages when relevant training data triggers them

• Identify patterns in your nutrition and performance over time

• Communicate with you about your account, billing, or service updates

We do not use your data for advertising or any purpose unrelated to your coaching service.

Data Sharing

We do not sell your personal data. We share data only with:

Service providers: Airtable (database), Twilio (SMS delivery), Stripe (payments), and Anthropic (AI processing). Each receives only the data necessary for their function.

Legal requirements: We may disclose data if required by law or to protect the rights and safety of our users.

Data Retention

• Food logs and coaching history are retained for the duration of your subscription and up to 12 months after cancellation

• Training data from Strava and WHOOP is retained for the duration of your subscription

• Payment records are retained for 7 years as required by law

• Upon a verified deletion request, we will delete your personal data within 30 days

Security

All data is stored in encrypted databases with access controls limited to authorized personnel. API tokens for integrations are stored securely and never exposed in client-facing systems. SMS communications are delivered through Twilio's secure messaging infrastructure.

Your Rights

You have the right to access, correct, delete, or export your personal data at any time. To exercise these rights, contact us at the email below. We will respond within 30 days.

Children's Privacy

Karb AI is not directed at individuals under the age of 18. We do not knowingly collect personal data from minors.

Contact

Karb AI

privacy@karbnut.ai

We may update this Privacy Policy from time to time. When we make material changes, we will notify you via SMS or email at least 14 days before changes take effect.