Skip to content
KineticFit
  • Features
  • How it works
  • About
  • Support

Your data, clearly explained

Privacy Policy

This policy explains how Rokuru handles personal data when you use the KineticFit app and website.

Last updated: 16 August 2026 · Version 2026-08-03 · Effective for this model-training flow: 16 August 2026

1. Who is responsible

Rokuru, based in Norway, operates KineticFit and is the controller of personal data described in this policy. Questions or privacy requests can be sent by email.

Email privacy support

2. Data flow at a glance

On-device inference and off-device storage are separate processes. Model-training eligibility is also separate: consent and policy version are stored in Firestore, while in-app inference still runs on-device.

KineticFit data destinations, purposes, and retention
Data Where it is processed Purpose Retention or control
Account and settings Firebase Authentication and Cloud Firestore Sign-in, account operation, preferences, and device synchronization Generally while your account is active; removed through account deletion, subject to limited backups and legal records
Health and fitness data Apple HealthKit on your device; selected synchronized data in Cloud Firestore Health and training insights, synchronization, and eligibility gating for optional model-training features HealthKit access is controlled in iOS. Firestore keeps a rolling window of detailed daily snapshots and longer-term aggregate rollups as described below
Workouts and routes Your device and Cloud Firestore Workout history, routes, synchronization, and insights. Optional model-training use is controlled separately by explicit consent. Generally while your account is active; removed through account deletion, subject to limited exceptions described below
Foundation Models and Core ML inference Your device Generate intelligent app features from models already available to KineticFit No remote inference request is made; this is separate from Firestore storage and model-training state
Model-training consent state Cloud Firestore Store explicit consent state, policy version metadata, and append-only audit events for accountability Current state and version metadata are kept while your account is active; immutable audit entries are kept as required for legal and security review
Model-training feature data Cloud Firestore Prepared for optional model-training workflows; no model-training jobs are running in this app version. Subject to the same retention and deletion rules as workout/health data while optional features are enabled.
Diagnostics Firebase Crashlytics and Performance Monitoring Reliability, fault diagnosis, performance, and security According to our provider configuration and only as long as reasonably needed for those purposes

3. Data we handle

Account data

If you create an account, we process an account identifier and information provided by your sign-in provider, such as your email address, display name, and whether you use Sign in with Apple or Google Sign-In. Your provider controls the information it shares with KineticFit.

Health and fitness data

With your permission, KineticFit reads selected health and fitness information from Apple HealthKit and may write completed workouts back to HealthKit. This may include activity, workout, heart-rate, energy, mobility, body-measurement, sleep, and related fitness signals needed for features you enable.

Workout content

We process workout plans and templates, exercise selections, sets, repetitions, weights, intervals, climbing sessions, completed workouts, notes, feedback, personal records, and derived training insights.

Machine learning and on-device inference

KineticFit uses Apple’s Foundation Models framework and Core ML for intelligent features. Model inference runs on your device. A future model-training feature is designed to use account-synchronized health, fitness, workout, and derived data only when the explicit consent state is Enabled and aligned with the current policy version. We do not sell the training data or models trained from it.

Precise location and routes

If you enable location access for an outdoor activity, KineticFit processes precise location, route coordinates, distance, pace, speed, elevation, and related workout information. Location is used to record and present the route and is not used for advertising.

Diagnostics and performance

We may receive crash reports, error details, app and OS version, device model, performance traces, and technical event metadata through Firebase Crashlytics and Firebase Performance Monitoring. We configure diagnostics to help find faults and improve reliability, not to build advertising profiles.

Support communications

If you contact support, we process your email address, message, and any information you choose to include so we can answer and resolve the request.

4. How and why we use data

  • Provide the app: authenticate you, save settings, record workouts, run intelligent features on-device, synchronize data across devices, and support app features.
  • Develop KineticFit’s models: with separate consent, use relevant health, fitness, workout, and derived data stored in Firestore for future optional model-training features; no model-training jobs are running in this app version.
  • Use permissions you choose: access HealthKit, precise location, motion, notifications, and Live Activities only for the relevant functionality.
  • Keep KineticFit reliable and secure: diagnose crashes, monitor performance, prevent misuse and fraud patterns, and protect accounts and services.
  • Provide support: respond to questions, deletion requests, and technical issues.
  • Meet legal obligations: comply with applicable law and respond to valid legal requests.

For people in the EEA, our legal bases are performance of our agreement with you, your consent, compliance with legal obligations, and our legitimate interests in operating, securing, and improving KineticFit. We rely on explicit consent to process health data for model training and whenever applicable law otherwise requires it. HealthKit access, location access, and model-training consent are separate choices.

5. Apple HealthKit

KineticFit requests HealthKit access only after you choose to grant it. Apple lets you review or revoke individual categories at any time. Granting HealthKit access allows KineticFit to read the categories you select; it does not by itself grant consent to use that data for model training. We do not use HealthKit data for advertising, marketing, data brokerage, or sale. For model training, separate model-training consent is required and tracked independently from HealthKit permission states. Removing KineticFit or deleting your KineticFit account does not automatically delete records already stored in Apple Health; you can manage those records in the Health app.

6. Service providers and sharing

We do not sell personal data, training data, or models trained from that data. We do not share personal data for cross-context behavioral advertising. We use service providers only as needed to operate KineticFit:

  • Google Firebase: Authentication, Cloud Firestore storage and synchronization, Crashlytics, and Performance Monitoring.
  • Apple: Sign in with Apple, HealthKit, MapKit and location services, iCloud/device services, and App Store distribution.
  • Google: Google Sign-In when you select it.
  • Cloudflare: hosting, security, DNS, and email routing for this website and support address.

Inference using Foundation Models and Core ML occurs locally on your device. Separate model-training use of Firestore data is currently prepared for future releases and is gated by explicit consent and policy version rules. We do not share training data for advertising or behavioural profiling.

Providers process data under their own terms and our applicable agreements. We may also disclose information if required by law, to protect rights or safety, or as part of a business reorganization with appropriate safeguards.

7. Storage, transfers, and security

Data may be processed in Norway, the EEA, the United States, and other countries where our providers operate. Where required, international transfers use recognized safeguards such as adequacy decisions or standard contractual clauses.

We use reasonable technical and organizational safeguards, including encrypted network transport, authenticated access, and access controls. No system can be guaranteed completely secure, so please protect your device and sign-in credentials.

8. Retention and deletion

Account, workout, route, and other synchronized training data are generally kept while your account is active. For synchronized HealthKit snapshots, KineticFit keeps detailed daily data in a rolling window of approximately 30 days. Weekly and monthly aggregate rollups are kept while your account is active. Consent state and consent-event audit records are retained while your account is active and for any additional period required by law for accountability, security, and auditability. Support messages are kept as long as needed to handle the request and maintain a reasonable service record. Diagnostic information is retained according to the applicable provider settings and only as long as reasonably needed for reliability and security.

You can delete your account in KineticFit under Settings → Privacy & Security → Authentication → Delete Account. This starts permanent deletion of your KineticFit account and user-scoped data in active Firestore storage. Limited information may remain temporarily in backups, security logs, or records we must retain by law, after which it is deleted or de-identified. Data stored separately by Apple Health or a sign-in provider must be managed through that service.

Deleting source data does not technically reverse model training already completed before deletion. You can, however, request that your account-linked data be excluded from future model training from the moment consent is withdrawn or where no model-training decision exists.

9. Your choices and rights

You can control HealthKit, location, motion, notification, and other permissions through iOS settings. You can also use KineticFit without granting optional permissions, although affected features will be unavailable.

Model-training consent

Model-training consent is separate from Apple Health permission and is controlled by explicit user choice in-app. Before using account-linked health, fitness, workout, or derived data for optional model-training features, KineticFit requires an explicit decision.

Consent states

  • Not decided — no valid persisted model-training decision exists for the current policy version, so no model training is allowed.
  • Enabled — you explicitly allow model training and allow eligible synchronized data to be considered for model improvement.
  • Declined — you explicitly refuse model training. Your account-linked health/fitness and workout data are excluded from all future training.
  • Withdrawn — you previously enabled and later revoked consent. This behaves like declined for future training, while existing model assets already trained may still reflect prior data and cannot typically be undone.

You can find and change this setting in the app under Settings → Privacy & Model Training where the model-training preference is shown.

Policy versioning and re-consent

Each decision stores a policy version and current consent state. If the policy version changes, previous decisions become invalid and are treated as Not decided until you re-consent. Re-consent is required before new eligibility can be restored.

When training is allowed

Model training can only use data from accounts with an Enabled state, a successful sync of that state, and a current policy version. Data can still be used for app operation (for example, workout tracking and synchronization) regardless of this setting.

Data excluded when you decline or withdraw

When in Declined or Withdrawn, your account-linked health and fitness history, workout records, route data, and derived training features remain available for app functionality, but are excluded from optional model-training feature use.

Offline sync and save states

Consent decisions can be captured while offline. In that case the app shows Saving your choice… and then queued, and retries when the app returns to foreground, when you sign in, or when sync runs again. If transport fails, the queued state stays until it can be retried.

If the server has already accepted the choice and a queued request is replayed, the app treats that as success rather than duplicate failure. If the server refuses a write, the user sees Your choice couldn't be saved and can acknowledge before deciding next steps. Updates use a fixed event ID so retries are idempotent and do not create duplicate consent-event entries.

Consent processing is auditable state tracking: one current consent record for operational behavior plus an immutable append-only audit event for each successful change.

Decision date and withdrawals

Every persisted state change has an auditable decision date. You can withdraw consent at any time in-app or by email. Withdrawal blocks future training immediately once synced, but does not reverse completed training runs.

Email about model-training consent

Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, or receive a portable copy of personal data. EEA users may complain to their local supervisory authority or Norway’s Data Protection Authority (Datatilsynet). Email us to exercise a right. We may need to verify your identity before fulfilling a request.

Email a privacy request

Re-enable is possible after withdrawal by selecting Enabled again. Re-enabling creates a new state event and starts model eligibility from that date onward; it is not retroactive.

10. Children

KineticFit is not directed to children under 16. If you believe a child has provided personal data without valid authorization, contact us so we can investigate and delete it where required.

11. This website

The KineticFit website is static. It does not set cookies, run analytics, load advertising trackers, or provide account forms. Standard hosting and security logs may include technical request information such as IP address, requested URL, user agent, and timestamp for short-term delivery, abuse prevention, and security.

12. Changes to this policy

We may update this policy when KineticFit, our providers, or legal requirements change. We will post the updated version here, change the effective date, and provide additional notice in the app when a change is material.

© 2026 Rokuru. KineticFit is made in Norway.

  • Features
  • Insights
  • Health & privacy
  • About
  • Privacy
  • Support
  • Terms