Privacy Policy

Effective Date: February 21, 2026 Last Updated: February 21, 2026

Fieldhouse Athletic LLC ("Company," "we," "us," or "our") operates the Kiln Fit mobile application, website, and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, share, and protect your personal information when you use the Service. By using the Service, you consent to the practices described in this Privacy Policy.

1. Information We Collect

1.1 Account Information

1.2 Profile and Fitness Information

We collect the following information to generate and adapt your training programs. All fields beyond email are optional and provided at your discretion:

1.3 Training and Activity Data

1.4 Military and Tactical Information (Optional)

If you use our tactical training features, you may optionally provide:

This information is used solely to tailor your training program. We do not share this information with any government agency, military branch, or third party except as described in Section 3.

1.5 Device and Technical Information

We do not collect device information directly. Our crash-reporting service (Sentry) automatically collects limited technical data when errors occur, including:

Sentry is configured to actively scrub personal and sensitive data from all error reports. See Section 3.4 for details.

1.6 Information We Do NOT Collect

1.7 Waitlist Information

If you join our waitlist before creating an account, we collect:

We do not collect your name, IP address, device information, or browsing history as part of waitlist signup. Waitlist emails are retained until a launch notification has been sent, after which they are deleted within 30 days unless you have since created a Kiln account.

2. How We Use Your Information

We use your information for the following purposes:

Purpose Data Used
Create and manage your account Email, password (via auth provider)
Generate personalized training programs Age, fitness profile, goals, injury flags, training preferences, schedule, equipment
Adapt training based on your performance Workout logs, endurance logs, readiness check-ins
Generate AI-powered training sessions See Section 3.1 for specific data sent to AI providers
Tailor programming for tactical users Military branch, occupational category, fitness test info, school/field training dates
Diagnose technical issues and fix bugs Crash reports and error logs via Sentry
Communicate with you about your account Email address
Comply with legal obligations As required by applicable law
Notify you when the Service launches Waitlist email address

We do not use your information to:

3. How We Share Your Information

We do not sell your personal information. We share information only with the following categories of service providers, solely for the purposes of operating the Service.

3.1 AI / Large Language Model Providers

Providers: OpenAI, Inc. and Anthropic, PBC

We use third-party AI models to generate and modify training sessions. All AI calls are made server-side — the app on your device never communicates directly with AI providers.

The following data may be sent to AI providers depending on the function:

Function Data Sent Data NOT Sent
Goal interpretation Goal text, age, training history text, injury history text Email, user ID, name, workout logs, check-in data
Session generation Workout parameters, equipment tags, training age, session duration, limitation tags, exercise library Email, user ID, name, workout logs, check-in data, goal text
Session modification Original session structure, your modification request text, equipment, time available, pain description if relevant Email, user ID, name, workout logs, check-in data

No personally identifiable information (email, user ID, name) is ever sent to AI providers. The only user-authored free text that reaches AI providers is your goal description and session modification requests, which contain only what you choose to type.

We have executed Data Processing Agreements (DPAs) with our AI providers. Under these agreements and their API terms of service, your data is not used to train their AI models.

We do not store prompt content. We log only metadata (function name, model used, token counts, latency, success/failure) for cost tracking and debugging purposes.

3.2 Infrastructure and Authentication

Provider: Supabase, Inc. (hosted on Amazon Web Services)

Supabase provides our database, authentication, and backend serverless functions. All user data stored in our database resides on Supabase's infrastructure (AWS). Row-Level Security (RLS) is enabled on every database table, ensuring users can only access their own data.

3.3 Authentication

Provider: Supabase Auth

Supabase Auth handles account creation and login. Passwords are hashed and managed entirely by Supabase Auth — our application code never accesses or stores plaintext passwords.

3.4 Crash Reporting

Provider: Sentry (Functional Software, Inc.)

Sentry collects crash reports and error data to help us identify and fix bugs. Sentry is configured with the following privacy protections:

3.5 Legal Requirements

We may disclose your information if required to do so by law, regulation, legal process, or governmental request, or if we believe disclosure is necessary to protect the rights, property, or safety of the Company, our users, or the public.

4. Data Storage and Security

4.1 Where Your Data Is Stored

4.2 Security Measures

4.3 Data Retention

5. Payment Information

The Service does not currently process payments. When paid subscriptions become available, payment will be handled entirely by Apple (App Store) or Google (Play Store). We will not collect, store, or have access to your payment card information, bank account details, or other financial data. For information on how Apple or Google handles your payment data, please refer to their respective privacy policies.

6. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we learn that we have collected personal information from a child under 18, we will delete that information promptly. If you believe a child has provided us with personal information, please contact us at privacy@kiln.fit.

7. Your Rights and Choices

7.1 All Users

7.2 California Residents (CCPA/CPRA)

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise these rights, contact us at privacy@kiln.fit. We will verify your identity before processing your request.

7.3 European Economic Area, UK, and Swiss Residents (GDPR)

If you are located in the EEA, UK, or Switzerland, you have rights under the General Data Protection Regulation (GDPR):

Data Transfers: Your data is stored in the United States. By using the Service, you consent to the transfer of your data to the United States. We rely on Data Processing Agreements with our service providers (including Standard Contractual Clauses where applicable) to ensure adequate protection of your data.

To exercise these rights, contact us at privacy@kiln.fit.

8. Third-Party Links and Services

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.

9. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through the Service. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated Privacy Policy.

10. Contact Us

If you have questions about this Privacy Policy or wish to exercise your privacy rights, contact us at:

Fieldhouse Athletic LLC
312 W. 2nd St #2433
Casper, WY 82601
privacy@kiln.fit


Sub-Processor List

Provider Purpose Data Shared Location
OpenAI, Inc. AI training session generation Fitness parameters, goal text, modification requests (no PII) United States
Anthropic, PBC AI training session generation (alternate) Fitness parameters, goal text, modification requests (no PII) United States
Supabase, Inc. Database, authentication, backend functions All user data United States (AWS)
Functional Software, Inc. (Sentry) Crash reporting and error tracking Device info, pseudonymous user ID, navigation breadcrumbs United States