Privacy Policy

Last updated: [EFFECTIVE_DATE]

The short version.

The rest of this page is the detail behind those five points.

1. Who we are

The controller of your personal data is [OPERATOR_NAME], an individual sole trader operating as "Kinetic", of [OPERATOR_ADDRESS], [OPERATOR_COUNTRY]. You can reach us at [email protected].

Kinetic is not a company — it is built and operated by one individual. We are not required to appoint a Data Protection Officer, so data protection questions go to the address above and are answered by the operator personally.

This policy covers the Kinetic iPhone app and the website kineticai.me (together, the "Service").

2. What we collect

CategoryWhat it includesRequired?
Account Username, email address, and a password stored only as a salted hash. Email verification and password reset tokens. Yes
Sign-in providers If you use Google or Apple Sign-In, we receive your name and email from that provider. We never see your Google or Apple password. If you use Apple's Hide My Email, we only ever receive the relay address. Optional
Profile Display name and profile picture, if you add them. Optional
Training Exercises, sets, reps, weights, effort (RPE), session duration, personal records, the programs you create or follow, skipped sessions, and XP. Yes
Body & nutrition Body weight and any measurements you log; height, biological sex, date of birth and activity level; nutrition entries and calorie/protein targets. Partly — see §3
Social Friend connections, feed posts, photos, cheers, comments, and friends-only leaderboard standings. Optional
AI Coach Your chat messages, any photos you attach, and coach memory — durable notes the coach saves about your goals, injuries and limitations, preferences, and life context. Optional
Technical Push notification token; crash and error reports (see §7); standard server request logs. Yes

We do not collect your precise location, your contacts, any advertising identifier, or data from Apple Health / HealthKit. We show no ads, use no third-party advertising or analytics SDKs, and do not sell or share your personal data.

3. Health data — and why we ask permission for it

Some of what Kinetic stores is "special category" data concerning health under Article 9 of the UK and EU GDPR. It gets a higher standard of protection than the rest, and we only process it with your explicit consent.

We treat all of the following as health data:

Biological sex and date of birth are not health data in themselves, but we use them together with your height and weight to estimate your metabolic rate, so we hold them to the same standard rather than a lower one.

Our lawful basis

We rely on your explicit consent under Article 9(2)(a). Because health data is essential to what Kinetic does, if you withdraw that consent we can no longer provide the Service, and your account will be closed and your data deleted.

How you give it

[VERIFY — CONSENT UI] We ask for this consent during onboarding, before you enter any body metrics, as a separate opt-in that is not bundled with anything else.

Do not publish this paragraph until the consent step exists in the app. At the time of writing, the only consent artefact is a line of non-interactive text on the sign-in screen. Saying "we obtain your explicit consent" before that is built would be a false statement in a privacy policy.

How you withdraw it

You can withdraw at whatever level you want, without asking us:

Withdrawing consent doesn't undo processing that already happened.

PurposeLegal basis
Create and operate your account, and sign you inPerformance of a contract — Art. 6(1)(b)
Store and show your workouts, programs, analytics, PRs and XPPerformance of a contract — Art. 6(1)(b)
Friends, feed, cheers, comments and leaderboardsPerformance of a contract — Art. 6(1)(b)
AI Coach chat, program generation and coach memoryContract — Art. 6(1)(b), and explicit consent for the health elements — Art. 9(2)(a)
Transactional email (verification, password reset)Performance of a contract — Art. 6(1)(b)
Push notifications you switch onConsent — Art. 6(1)(a), withdrawable in Settings
Crash reporting, debugging, security and abuse preventionLegitimate interests — Art. 6(1)(f)
Meeting legal obligations and defending legal claimsLegal obligation — Art. 6(1)(c) / legitimate interests — Art. 6(1)(f)

Where we rely on legitimate interests, we've weighed our interest in keeping a free service working and safe against your rights, and limited what those systems collect accordingly — crash reports carry no email address, no IP address and none of your training or health data. You can object to this processing; see §9.

5. Who we share it with

We share data only with the providers we need to run the Service.

ProviderWhat it doesWhere
DigitalOceanApp hosting and the managed database that holds your accountLondon, United Kingdom
SupabaseStorage for photos and profile pictures you upload[VERIFY — REGION]
CloudflareDNS and content delivery for kineticai.me, and routing for our support emailGlobal edge network
Google (Gemini API)Generates AI Coach replies and programs — see §6United States
Google (Gmail)The inbox that receives mail sent to [email protected]United States
Google / Apple Sign-InOptional authentication
ResendDelivery of transactional emailUnited States
ExpoDelivery of push notificationsUnited States
SentryCrash and error reporting — see §7Frankfurt, European Union

Each of these acts as our processor under a written data processing agreement and may use your data only to provide its service to us. We may also disclose data where the law requires it, or where it's necessary to protect the rights and safety of our users.

6. The AI Coach and Google Gemini

When you use the AI Coach, the following leaves your device and is sent to Google's Gemini API: your message, any photo you attach, and the training and body context needed to answer — which can include your recent workouts, your programs, your body weight trend, and the notes the coach has saved about you. Replies are generated by Google's gemini-3.5-flash model.

The AI Coach can also propose changes to your training program and to your calorie and protein targets. Those take effect only when you accept them.

[VERIFY — GEMINI TIER] This section must be finalised before launch. Kinetic uses the Gemini Developer API. Google's terms for the free tier and the paid tier differ materially: on the free tier Google may use submitted conversations to improve its products, and human reviewers may read them. Given that these conversations can contain injury and other health information, the tier in use must be confirmed and the wording here written to match it — and moving to the paid tier before launch is strongly recommended.

AI Coach usage is capped — currently 3 generated programs per calendar month and a daily message limit shown in the app. That keeps the feature free, and it also limits how much of your data is sent to a third party.

7. Crash and error reports

Crash and error reports go to Sentry, processed in the European Union. They contain your Kinetic user ID and username, your device model, OS version and app version, the screens you moved through before the error, the API request that failed (method, path and status code), whether you were online or offline, and the technical details of the error.

They do not contain your email address, your IP address, your password, your workouts, your body metrics, your nutrition entries or your AI Coach conversations. Crash reporting is switched off entirely in development builds, and we do not use session replay or screen recording.

8. How long we keep it

DataRetention
Your account and everything in itFor as long as your account is open
After you delete your accountRemoved from live systems immediately
Encrypted database backups[VERIFY — BACKUP WINDOW] days, then overwritten
Photos you uploaded[VERIFY — MEDIA DELETION]
Crash reports[VERIFY — SENTRY RETENTION]
Server access logs[VERIFY — LOG RETENTION]
Data kept to meet a legal duty or defend a claimOnly as long as necessary for that purpose

Note that content you posted where friends could see it may stay visible in their app until it next refreshes.

9. Your rights

You have all of the following rights over your data. We don't charge for any of them, and we won't ask you to justify the request — we may just ask you to email from the address on your account so we know it's you.

Automated decisions

The AI Coach generates training programs and can propose calorie and protein targets. These are suggestions: they take effect only when you accept them, you can change or reject any of them at any time, and they are not decisions producing legal or similarly significant effects.

Complaints

You have the right to complain to a data protection supervisory authority, particularly in the country where you live or work — in [OPERATOR_COUNTRY] that is [SUPERVISORY_AUTHORITY]. We'd genuinely appreciate the chance to put things right first.

10. International transfers

Your account data is hosted in the United Kingdom (DigitalOcean, London). Crash reports are processed in the European Union (Sentry, Frankfurt). Some providers — Google, Expo, Resend, Supabase and Cloudflare — process data in the United States or elsewhere outside the UK and EEA.

Where data leaves the UK or EEA we rely on the UK–US Data Bridge and the EU–US Data Privacy Framework where the provider is certified under them, and otherwise on the European Commission's Standard Contractual Clauses together with the UK International Data Transfer Addendum. You can ask us which safeguard applies to a specific provider. [VERIFY — DPF CERTIFICATIONS]

11. California privacy rights

If you are a California resident, you have the right to know what personal information we collect and why, to delete it, to correct it, to opt out of its sale or sharing, and not to be treated differently for exercising those rights.

We do not sell your personal information and we do not share it for cross-context behavioural advertising, as the CCPA defines those terms. We haven't done so in the previous 12 months, and we don't sell or share the personal information of anyone under 16. Because we don't sell or share, there is no "Do Not Sell or Share My Personal Information" link to offer.

In the CCPA's categories, we collect: identifiers; customer records; protected classifications (age, sex); internet activity (crash and error data); visual information (photos you upload); inferences (training analytics and coaching suggestions); and sensitive personal information in the form of health and fitness data. We use sensitive personal information only to provide the Service you asked for and to keep it secure — never to infer characteristics about you.

To exercise any of these, email [email protected]. You may use an authorised agent. We verify requests by confirming control of the account email, and respond within 45 days.

12. Age requirement

You must be at least 16 to use Kinetic. The Service is not intended for children, and we do not knowingly collect data from anyone under that age. If you believe someone underage has an account, contact us and we'll delete it promptly.

We set the floor at 16 deliberately. The age at which someone can consent to an online service on their own varies between 13 and 16 across the EEA; choosing 16 means one rule that is valid everywhere we operate, and it avoids collecting children's health data altogether.

[VERIFY — AGE FLOOR] The app's onboarding currently accepts ages from 12. That must be raised to match this page, and the same number must appear in the Terms and in App Store Connect, before publishing.

13. Security

Data is encrypted in transit with TLS, and encrypted at rest by our hosting and database providers. Passwords are stored as salted hashes and never in plain text. Access to production systems is limited to the operator.

We hold no formal security certification (no SOC 2, no ISO 27001) and don't claim one. If a breach affects your rights we will notify the relevant supervisory authority within 72 hours where required, and tell you without undue delay where the risk to you is high.

Found a security problem? Please tell us at [email protected] before disclosing it publicly.

[VERIFY — MEDIA ACCESS CONTROL] Photos and profile pictures are currently uploaded to a storage bucket that serves them over public URLs. Anyone holding such a URL can open the file without signing in. This must be moved to private storage with time-limited signed URLs — or, if it is not, this section must say so plainly, since coach photo attachments can contain health information.

14. The website

kineticai.me is a set of static pages. It sets no cookies of our own, runs no analytics, and contains no tracking pixels, advertising tags or third-party scripts. Fonts are served from our own domain, not a third-party font CDN. There is nothing here to consent to, which is why you won't see a cookie banner.

The site is served by DigitalOcean through Cloudflare, which process standard web request information — including your IP address — to deliver pages and protect the site from abuse. Cloudflare may set a strictly necessary security cookie as part of that.

15. Changes to this policy

We may update this policy as the Service changes. We'll post the new version here and update the date at the top. Where a change materially affects how we use your health data, we will ask for your consent again rather than relying on notice alone. Previous versions are available on request.

16. Contact

Any question or request about your data: [email protected], or by post to [OPERATOR_NAME], [OPERATOR_ADDRESS].