Last updated: July 31, 2026
Privacy Policy
Korra is a personal training app for athletes, available on iOS and Android, operated at https://korra.app.br. This Policy explains what data we collect, how we use and protect it, who we share it with, and your rights. We process personal data in line with the Brazilian General Data Protection Law (LGPD, Law 13.709/2018) and, where applicable, the EU GDPR.
1. Who we are (Controller)
The data controller is the operator of Korra. Contact: korraapp@gmail.com · https://korra.app.br. Use this address for any privacy question or to exercise your rights.
2. Data we collect
Account: name/display name and handle, email, sign-in identifiers (e.g. Google), and profile info you choose to provide (avatar, bio, birthday, sport preferences).
Activity & training: workouts you record or import (distance, duration, pace, elevation, heart rate, sport, date, and location where applicable), races, goals, streaks, challenges, groups, photos you upload, and content you post.
Health (Apple Health / Google Health Connect): with your explicit permission, we read training and health data from Apple Health (iOS) and Google Health Connect (Android) — workouts from many watches and devices, heart rate, and related metrics. This is your own data and forms the permanent base of your training history. You can revoke this permission in your device settings at any time.
Strava (only if you connect it): if you choose to connect your own Strava account, we access activity data from your own Strava account only. See Section 5.
Technical: app version, device type, OS, and diagnostic/error data used to keep the service running.
3. How we use your data
To create and manage your account; record, import, display and organize your activities, races, goals and history; show your progress, rankings, challenges and (where you opt in) social and community features; provide personalized training features based on your own data; send notifications you enable; keep the service secure and diagnose problems; and comply with the law.
Legal bases (LGPD/GDPR): your consent (e.g. health-data access and connecting Strava), performance of a contract (providing the app), our legitimate interests (security and functioning), and legal compliance. You may withdraw consent at any time. We do not sell your personal data.
4. Strava — owner-only, transient, and deletable
This section applies only if you connect your Strava account. It reflects the Strava API Agreement and Brand Guidelines, which are stricter than the rest of this Policy and take precedence for Strava data.
Your own account, with your consent. You connect using the official “Connect with Strava” button and the standard OAuth flow (scope activity:read). We only ever access your own Strava account.
Owner-only. Any data we retrieve from Strava is shown only to you, the owner of that Strava account. It is never shown to other users and never appears in the feed, rankings, comparisons, groups, or any shared or public screen. This is enforced technically and verified in production.
Fetched on demand, cached at most 7 days — never stored permanently. Strava data is fetched live when you open your own activity and held only in a transient cache for up to 7 days (re-fetched as needed). We do not keep a permanent copy and do not build any persistent store or index of Strava data or anything derived from it.
No advertising, resale, or AI training. We do not use Strava data for advertising, resale, or to train any AI/machine-learning model. Strava data is technically excluded from any call to a large language model and from any aggregate AI/analytics processing.
Attribution and links. For each activity imported from Strava we display a “View on Strava” link back to the original activity and the source device attribution (e.g. Garmin), and we use the official “Connect with Strava” button.
Deletion. When you disconnect Strava (deauthorize) or delete your Korra account, all of your Strava data is permanently deleted. Deletions you make on Strava are reflected in Korra within 48 hours. Upon deauthorization or account deletion, all Strava data is removed within the timeframe required by Strava (no later than 30 days).
5. Sharing and third parties
We share personal data only with service providers acting on our behalf under appropriate safeguards — cloud/infrastructure and object storage (hosting your data and photos), the sign-in provider you choose (e.g. Google), and error-monitoring tooling. We do not sell your personal data and do not share it for third-party advertising. Strava data is never shared with any third party.
6. Data retention
Account, activity and health data are kept while your account is active and for as long as needed to provide the service or comply with the law; you can delete them (see Section 8). Strava data is kept only in a transient cache for at most 7 days and is deleted on disconnect or account deletion.
7. Your rights (LGPD / GDPR)
You may request access to your data, correction, deletion, portability, information about sharing, and withdrawal of consent. To exercise any right, contact korraapp@gmail.com. You may also disconnect Strava or delete your account directly in the app.
8. How to disconnect Strava or delete your account
In the app, open Settings / My Account to disconnect Strava (which permanently deletes your Strava data) or to delete your Korra account (which deletes your personal data, subject to any legal retention obligations).
9. Security
We use industry-standard measures (encrypted transport, access controls, private storage) to protect your data. No method of transmission or storage is 100% secure, but we work to protect your information and to address issues promptly.
10. Changes and contact
We may update this Policy; we will change the “Last updated” date above when we do. For any question about this Policy or your data, contact korraapp@gmail.com.