Privacy Policy

Last updated: September 10, 2026

Introduction

KovaFit ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").

Information We Collect

Personal Information

We may collect personal information that you voluntarily provide to us, including but not limited to:

  • Name and email address (if you create an account)
  • Profile information (age, gender, fitness goals, experience level)
  • Workout data (exercises performed, sets, reps, weights, duration)
  • Progress photos and measurements (if you choose to add them)

Apple Health and Analytics

Apple Health permission is optional. Health samples used to calculate daily summaries are processed on your device. Sanitized daily summaries are retained in account-scoped device storage for up to 180 days. Imported Apple Health and Strava workout history is stored separately on your device, including source identifiers, workout timestamps and bounded chart data; it is not subject to the daily-summary retention period. Disconnecting an integration removes its locally imported records. Raw Apple Health samples and imported workouts are not uploaded to KovaFit servers or telemetry. Derived Analytics values remain local except for the bounded evidence you explicitly consent to send for an AI explanation, as described below.

Private Journal factors, custom tag text, experiments, and correlation discoveries are stored only in hashed account-scoped storage on your device. They are not sent to product analytics, cloud AI, or KovaFit's servers.

Usage Data

We automatically collect certain information when you use the App:

  • Device information (device type, operating system, unique device identifiers)
  • App usage data (features used, time spent, interaction patterns)
  • Crash reports and performance data

Analytics product telemetry contains only allowlisted interaction names such as screen view, 7D/28D/90D range selection, permission-button selection, insight open, or consent-state change. It contains no health, workout, metric, score, sleep, chart, evidence, or free-text values.

How We Use Your Information

We use the collected information for the following purposes:

  • Provide Services: To deliver personalized workout plans and AI coaching recommendations
  • Improve App: To understand how users interact with our features and improve the user experience
  • Analytics: To track your progress and provide meaningful insights
  • Communications: To send you important updates, notifications, and promotional content (with your consent)
  • Support: To respond to your inquiries and provide customer support

Third-Party Services

We use the following third-party services that may collect information:

RevenueCat

We use RevenueCat to manage in-app subscriptions. RevenueCat collects purchase data and subscription status. View their privacy policy at www.revenuecat.com/privacy

Firebase

We use Firebase for authentication, App Check, cloud data and file storage, and Crashlytics reliability reporting. KovaFit does not package Firebase Analytics. View Firebase's privacy policy at firebase.google.com/support/privacy

PostHog

We use PostHog's United States ingestion host for allowlisted product-usage and reliability telemetry. While you are signed in, KovaFit uses identified-only person profiles and associates structural events with an account identifier so sessions can be analyzed consistently; health samples, workout values, scores, sleep data, free text, and AI prompts are excluded. KovaFit disables PostHog session recording, surveys, automatic application-lifecycle capture, native-exception capture, and feature-flag event capture. Retention is governed by KovaFit's configured PostHog project policy. When account deletion begins, the app stops sending identified telemetry and KovaFit's retryable server workflow deletes the identified PostHog person and linked events before deleting Firebase Authentication. View PostHog's privacy policy at posthog.com/privacy

Google AdMob

Free users may see advertisements powered by Google AdMob. KovaFit requests non-personalized ads and does not request App Tracking Transparency permission or use IDFA for personalized advertising. View AdMob's privacy policy at support.google.com/admob/answer/6128543

Vercel AI Gateway and Google Gemini AI

Cloud AI requests pass through KovaFit's authenticated Vercel server and Vercel AI Gateway to Google Gemini as the default underlying model. The server enforces App Check, trusted entitlements, quota, idempotency, payload allowlists, and redacted errors. Free Analytics insights do not use AI. Optional Pro explanations require explicit, revocable consent and send only the exact bounded derived evidence previewed in the app; raw Apple Health samples, exact sleep intervals, source/device identifiers, medical history, and unrelated workouts are excluded. Every KovaFit Gateway request opts out of provider prompt training, and Gateway reporting receives fixed app attribution rather than user IDs, email, health/workout values, prompts, or chat text. Credentials never enter the mobile app or product telemetry. Zero Data Retention is a separate plan-dependent control and is not claimed unless verified for production. View the Vercel privacy policy and Google AI principles.

Strava (Optional Integration)

If you connect Strava, KovaFit stores an encrypted Strava refresh token and non-sensitive connection metadata on our backend. A short-lived access token is kept in protected device storage. Imported Strava activities remain in KovaFit's device-local health cache and are not uploaded to our cloud database. You can revoke the connection in the app at any time. Strava privacy policy

Subscription Management

When you subscribe to KovaFit Pro, your subscription is managed through the Apple App Store or Google Play Store. We do not store your payment information directly. Subscriptions and billing are handled by:

  • Apple App Store: For iOS users - governed by Apple's privacy policy
  • Google Play Store: For Android users - governed by Google's privacy policy
  • RevenueCat: Processes purchase history, transaction and subscription status, and your account identifier to validate Pro access, restore purchases, and manage subscription entitlements. Payment card details are handled by the app store, not KovaFit.

You can manage or cancel your subscription through your App Store account settings.

Data Security

We implement appropriate technical and organizational security measures to protect your personal information. However, no method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.

Your Rights

Depending on your location, you may have the following rights:

  • Access: Request access to your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Delete your account from Settings. KovaFit uses a retryable server process to revoke connected Strava access and erase the identified PostHog person and linked telemetry, KovaFit cloud data, storage objects, and the RevenueCat customer record before deleting Firebase Authentication. App Store and Play Store transaction records remain controlled by those stores, and deleting an account does not cancel an active store subscription.
  • Data Portability: Request a copy of your data in a portable format
  • Withdraw Consent: Withdraw consent for data processing where consent was the legal basis
  • Local Analytics Controls: In Settings, you can change your sleep goal, review Apple Health permissions, revoke AI explanation consent, and clear the private Journal together with local Analytics summaries, history, and cached explanations. The separate Private Journal screen can copy a versioned JSON export of journal entries and experiments to the system clipboard; that export does not include raw Apple Health samples, other local Analytics summaries, insight history, or cached explanations.

Children's Privacy

Our App is not intended for individuals under the age of 13. We do not knowingly collect personal information from children under 13. If you become aware that a child has provided us with personal information, please contact us, and we will take steps to delete such information.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.

Contact Us

If you have any questions about this Privacy Policy, please contact us:

Email: support@kovafit.app