KinFit Privacy Policy

Effective date: August 8, 2026

KinFit ("we," "us") is a group fitness app that lets you track workouts, steps, and sleep, follow training plans, and share progress with small groups of friends. We do not run ads, sell personal data, or track you across other companies' apps or websites.

What we collect

Account information. Your email address, display name, username, optional bio, and account identifiers.

Health and fitness data. With your permission, we read step count and sleep data from Apple Health (HealthKit). When you choose to record a completed workout in Apple Health, KinFit writes that workout. We also store the workouts, runs, recovery sessions, habits, meals, plans, and goals you record in KinFit.

Location. If you use GPS run tracking, we record your route so KinFit can show your pace, distance, and route map. Routes are stored with your run history.

Content you create. Posts, comments, reactions, encouragement notes ("cheers"), group names, nicknames, profile information, and photos you choose to upload.

Device and notification information. We store the push-notification token needed to deliver notifications to your device. We do not collect advertising identifiers.

Product analytics and diagnostics. KinFit uses PostHog to collect device-anonymous product interactions such as screen views, feature usage, and non-text counts or durations. KinFit does not send PostHog your account ID, email address, messages, post or comment text, raw HealthKit samples, precise GPS routes, meal details, or private notes. KinFit uses Sentry to receive crash reports and technical diagnostics needed to find and fix reliability problems.

Safety records. If you block a user or report content, we store that block or report, including a snapshot of the reported content, so we can review and act on it.

How we use data

  • To provide KinFit, sync your activity, and show progress toward your goals.
  • To share the information you choose with members of groups you join.
  • To deliver notifications you have enabled.
  • To prevent objectionable content, investigate reports, and enforce our Terms.
  • To understand which product features are used and diagnose crashes without advertising or cross-app tracking.

Apple Health data

Health data read from HealthKit is used only to provide KinFit's health and fitness features. It is never used for advertising or marketing, sold, shared with data brokers, or used to make employment, insurance, or credit decisions. Product analytics and crash reports do not include raw HealthKit samples.

You control KinFit's Health permissions in iOS Settings and in the Health app. Removing Health permission stops future reading or writing; it does not delete activity you previously chose to store in KinFit.

Who processes data

We use service providers only as needed to operate KinFit:

  • Supabase provides authentication, database, file storage, and backend services.
  • Apple provides HealthKit, push notifications, and platform services.
  • PostHog provides device-anonymous product analytics.
  • Sentry provides crash reporting and technical diagnostics.
  • Google Maps Platform displays maps and GPS routes.
  • Cloudflare Turnstile helps protect account and authentication forms from automated abuse.
  • Resend delivers authentication and account emails.

These providers process information for the purposes described above. We may also disclose information when required by law.

What we do not do

  • No advertising or advertising SDKs.
  • No tracking across other companies' apps or websites.
  • No selling or renting personal data.
  • No sharing with data brokers.

Visibility and sharing

Members of groups you join can see the profile, activity, progress, posts, comments, reactions, and achievements you share within those groups. Group invitations require your acceptance. Encouragement notes are shared with their recipient under the visibility rules shown in the app.

Retention and deletion

Your account data is retained while your account is active. You can delete your account at any time in Settings → Account → Delete Account. Deletion permanently removes your authentication account, database records, uploaded files, posts, comments, group memberships, and reports authored by or about the account. Device-anonymous product analytics and unlinked crash diagnostics cannot be used to identify a deleted KinFit account. Internal operational logs are pruned on a rolling schedule.

Security

Data is encrypted in transit using TLS. Data cached by KinFit on your device is stored encrypted. Server-side access is enforced with per-user row-level security.

Children

KinFit is not directed to children under 13, and you must be at least 13 to create an account.

Your choices and rights

You can change notification permissions in iOS Settings, change Health access in iOS Settings or the Health app, edit profile information in KinFit, and delete your account in the app. Depending on where you live, you may also have rights to access, correct, export, or delete personal data. Contact us for help with those requests.

Changes

If we make material changes to this policy, we will update the effective date and provide notice where appropriate.

Contact

support@kinfit.co

After publishing, they should confirm that https://kinfit.co/privacy opens publicly in a logged-out/private browser without a Squarespace password or “Coming Soon” screen.