KanonBack to Kanon

Private pilot legal document

Privacy Notice

Status
Active
Version
2026-08-06-kanon.1
Published
August 6, 2026

This notice describes how the Kanon private pilot collects, uses, protects, exports, retains, and deletes information today.

1. Scope and operator

Kanon is an invite-only personal life operating system for adults. Its home surface brings together calendar events available on the device, while nutrition and training remain its first activity modules. The private pilot is operated by an individual in the United States. Kanon is not represented as a health care provider, health plan, HIPAA covered entity, or HIPAA business associate.

Questions or requests may be sent to jp@themarkos.com.

2. Information collected today

Kanon collects only information needed to authenticate an invited account and provide the features currently available.

  • Account information, including email address, display name, Supabase user ID, sign-in events, and private-pilot access history.
  • Profile and goal information, including adult confirmation, age, height, weight, waist, goal weight, energy-estimate sex, training experience, activity level, timezone, units, and nutrition targets.
  • Nutrition information, including planned meals, custom foods, USDA food selections, exact food quantities, calories, macros, meal logs, and daily nutrition summaries.
  • Training information, including schedule, home or gym locations, available equipment, generated plans, and workout context. Completed workout-session logging is not yet available.
  • Technical records needed for security and operation, including request IDs, audit events, local device IDs, synchronization cursors, row versions, conflict records, and sanitized diagnostic categories.
  • Food search terms sent through Kanon to USDA FoodData Central. Kanon does not attach the user's name or email address to that USDA search request.
  • When the calendar day is available in the installed native build, Kanon reads calendar names and capabilities and event titles, dates, times, all-day status, locations, time-zone metadata, and source identifiers through Apple's EventKit framework on the device to assemble the day. EventKit may make notes available to the native framework, but Kanon does not use, display, persist, or upload them. Calendar event details are not uploaded to Kanon's servers or included in server backups.

3. How information is used

  • Authenticate invited accounts and enforce owner-scoped access.
  • Calculate and display nutrition targets, exact intake, meal history, and training plans.
  • Assemble a unified calendar day locally on the device and apply the user's local display and filtering choices.
  • Support offline meal logging, synchronization, conflict review, security auditing, backup, troubleshooting, and recovery.
  • Operate and improve the private pilot without advertising, behavioral tracking, or sale of personal information.

4. Service providers and disclosures

Supabase provides authentication and the PostgreSQL database. Vercel serves the web application and API. USDA FoodData Central receives food search terms and returns food records. Sign-in email is delivered through the authentication service's configured email delivery path.

On Apple devices with a compatible native build, Kanon reads calendar information through Apple's EventKit framework only after the user grants full calendar access. EventKit access occurs locally. Kanon does not send calendar event details to Supabase, Vercel, USDA, or another server-side provider.

Kanon does not sell personal information and does not use advertising, third-party analytics, cross-app tracking, data brokers, or social sharing. Personal information may also be disclosed when reasonably necessary to protect the service, comply with law, or respond to a valid legal process.

Kanon-controlled pilot records are stored in a Supabase US East project. Infrastructure providers may process limited operational metadata in other locations under their own service terms. Encrypted database backups are controlled by the operator.

5. Data stored on the device

The installed web app stores a short-lived Today cache, food-search cache, meal-log outbox, synchronization metadata, and the active user's Supabase UUID in the browser. Today and food-search cache records expire after no more than seven days. An unsynchronized meal-log operation remains in the outbox until the server accepts it, the user resolves or discards it, or sign-out cleanup removes it. Cache Storage contains only approved static application files and the offline page.

IndexedDB is not encrypted by Kanon. Its practical protection is the device lock, operating-system protections, and a private browser profile. Anyone with access to the unlocked device or browser profile may be able to inspect local data. Signing out attempts to purge the local health cache and outbox, and the application blocks use if that privacy cleanup cannot be confirmed.

The native TestFlight app stores authentication material in iOS Keychain and owner-scoped offline health records and interface choices in a local SQLite database. In a compatible build, calendar event details are held in app memory only while the calendar-day screen is active and are cleared when that screen is hidden or loses focus; they are not written to the health cache or uploaded. Local calendar overlay choices may store EventKit source and occurrence identifiers on the device; those identifiers are removed by the same owner-scoped sign-out cleanup as the other native cache records.

6. Security and limits

Kanon uses encrypted network connections, passwordless Supabase authentication, secure browser cookies or native bearer tokens, owner-scoped repositories, forced PostgreSQL row-level security, input validation, audit history, and encrypted database backups. These controls reduce risk but cannot guarantee absolute security.

Kanon is not currently represented as HIPAA compliant, HIPAA certified, or suitable for storing clinical records. Do not enter information that is not needed for the private pilot.

7. Retention, export, and deletion

Primary records are retained while the invited pilot account remains active and as needed to operate, secure, and recover the pilot. Authentication rate-limit hashes are removed after their short operational window. A person-created export remains wherever that person saved it and is not controlled by Kanon.

A signed-in user can confirm their identity and download a complete, machine-readable JSON copy of every row visible to that identity through Kanon's owner-scoped application database. The download includes current records and stored version, consent, legal, pilot-access, synchronization, and audit history. Shared exercise and equipment catalogs, one-way hashed abuse-control counters, provider authentication internals, and migration metadata are excluded because they are not owner-scoped user records. Kanon does not silently truncate an export.

Self-service deletion requires a fresh email-code identity confirmation for both the request and the final typed-email confirmation. Confirmation starts a seven-day grace period. The user can cancel until automated cleanup starts. Cleanup is scheduled to begin within 25 hours after the grace period ends.

Final cleanup removes the user's Kanon health workspace, sessions, and Supabase authentication account. Append-only legal acceptances, pilot-access history, and the minimal request and step record proving completion remain without automatic expiry during this private pilot. They remain pseudonymous by user ID after the authentication account is removed. Supabase or Vercel may separately retain limited security and operational logs under their provider policies.

Encrypted backups follow a 14-day age policy. Because backups currently run weekly, a deleted primary record can normally remain in encrypted backup copies for up to 21 days. Removal occurs on the first successful scheduled maintenance run after an archive reaches 14 days, so a sleeping operator Mac or failed backup run can delay rotation. Backups are not used to restore a deleted account into the live service.

8. Features that do not exist today

Kanon does not currently process data with Claude, OpenAI, Codex, or another AI provider. It does not currently accept progress-photo uploads, share information with accountability partners, send reminders or marketing notifications, integrate with wearables, or read Apple Health data.

AI, progress photos, and accountability-partner capabilities are explicitly restricted for invited pilot accounts. A future release of any of these features requires new technical controls, updated disclosures, and an explicit user choice.

9. Choices and changes

Users can choose what optional profile and meal information to enter, can sign out, and can ask the operator questions or request an administrative review. Some baseline information is required to calculate a plan.

A material change to this notice will receive a new version and content hash. Kanon will ask the user to review and accept the new version rather than treating continued use as acceptance.

Questions or requests may be sent to jp@themarkos.com.

Privacy NoticeTerms of Use