Legal
Privacy Policy
Last updated: 2026-09-03
This page explains how the Kinoku Android app handles data. It matches what the app does today and the controls you have in the app.
The short version
Kinoku is a privacy-first Android fitness tracker. Core processing happens on your device, with no mandatory Kinoku account and no Kinoku server for your workout history. Eligible main-database and app-file data may enter Android Auto Backup in your personal Google account. There are no advertising SDKs and no data-broker SDKs.
A few features use networked services. Google Play Billing verifies subscriptions and purchases. Social Bets (multiplayer challenges) is turned off right now, so no bet data is sent. Diagnostics (crash reports and analytics) are off by default. You can turn them on in Settings. Weather context for runs (off by default) sends rounded run-start coordinates (about 1.1 km precision) to Open-Meteo. This fetches temperature, wind, conditions, and (if you turn it on) air quality, pollen, UV, and sea-level pressure. Maps fetch map tiles from third-party tile providers when you open a map screen. Gift codes are turned off right now, so nothing is sent to Firebase for one.
On a cold start, Kinoku checks Firebase Remote Config for friends-and-family promo access. In release builds the Firebase SDK is configured with a 12-hour minimum fetch interval, so a cold start may use cached configuration instead of making a fresh network request. The section below explains what the service can receive.
Your dedicated Cycle Tracking records (periods, symptoms, fertility signals, pregnancy entries) live in a separate on-device database, together with generated cycle state, private Change History, and your Cycle Tracking configuration. That database is left out of Google’s automatic cloud backup. General app settings and custom metrics remain in the eligible main database, along with main Change History; a manual ZIP or user-initiated device transfer can carry the dedicated database. It never reaches Kinoku’s servers. See the reproductive-health section below.
Who we are
Kinoku is operated by DREAM SOFT DISTRIBUTED EOOD, a single-member limited liability company registered in Plovdiv, Bulgaria. "Kinoku" is the product and trading name. For GDPR purposes, DREAM SOFT DISTRIBUTED EOOD is the data controller. Contact: privacy@kinoku.app. Supervisory authority: the Bulgarian Commission for Personal Data Protection.
Data stored on your device
These categories are stored on your device. Normal app use does not send them to Kinoku servers:
- Workouts, sets, reps, weight, RPE/RIR, rest times, notes
- Run routes, splits, pace, elevation, heart-rate overlays
- Routines, programs, training calendar, periodization plans
- Body metrics, custom metrics, progress photos, share cards
- Step data, achievements, rewards state
- App preferences, theme, locale
- Readable Change History for committed changes to user-owned records
- Cycle Tracking records. Dedicated records, generated cycle state, and your Cycle Tracking configuration receive the enhanced protections below; custom metric logs use the main app database.
Change History
Change History stores a local record of committed changes to user-owned data. Main training history stays in the eligible main database. Cycle, symptom, pregnancy, and private cycle-setting history stays in the separate cycle database and is merged into the screen only while you read it. Kinoku does not send either history to its servers.
Main Change History may enter Android Auto Backup, the manual Kinoku ZIP backup, and the normal Change History CSV export. Private Change History is excluded from Android automatic cloud backup and the normal export. It is included only in a manual Kinoku ZIP backup, a user-initiated device transfer, or the separate cycle-data export.
The history begins after the feature upgrade and does not reconstruct older edits. It excludes background analytics, sensor and Health Connect samples, caches, credentials, tokens, photo paths, and other maintenance or secret values. You can permanently clear both histories from Settings → Data & Storage → Change History without deleting the current records they described.
Health Connect
Kinoku reads from and writes to Android Health Connect. This is opt-in, one permission at a time. Read permissions requested: Steps, Weight, Sleep, Resting Heart Rate, Heart Rate, Heart Rate Variability, Blood Pressure, Blood Glucose, Hydration, Body Fat, and Menstruation. Menstruation is read-only. Kinoku never writes menstruation data back to Health Connect under any circumstances. Write permissions: Exercise sessions and Steps. Steps cover paired Wear-device totals AND cadence-derived estimates from completed GPS walks and runs. This way, off-body sessions credit your daily total, and your step history survives a reinstall through the Health Connect store. You can turn step writing off at Settings → Run Tracking → Sensors & Privacy → "Write steps to Health Connect". Health Connect is an on-device data broker operated by Google. Kinoku does not receive your Health Connect data over any network path.
Sensors, camera, and voice input
Kinoku uses Android's activity-recognition permission, step counter and step detector sensors, and accelerometer data. These power step tracking, cadence, suspected-vehicle filtering, and live step displays. Run-form features may use device motion sensors such as linear acceleration and gyroscope readings. Kinoku processes these sensor streams on your device and does not send them to Kinoku servers.
If you use camera or gallery features, Kinoku stores selected photos in its private app storage or uses them to build a share image on your device. Photos are not uploaded to Kinoku.
If you use voice logging, Kinoku launches Android's system speech recognizer. It prefers on-device recognition where available. But the system recognizer may use your device's internet connection or a Google speech service. This depends on your device and Android setup. Kinoku receives only the returned text, uses it to pre-fill workout fields, and does not store raw audio.
Social Bets (Firebase / Firestore)
Turned off right now. Every way into Social Bets is closed in this release, so no bet is created and no bet data is sent to Firestore. The rest of this section describes how the feature works when it is switched back on.
Social Bets is an optional multiplayer feature. If you don't use it, this data flow never happens. When you create or join a bet, Kinoku generates an anonymous Firebase UID (no email, no phone number). A Firestore document holds the bet rules, each participant's UID and display alias, and each participant's progress number. Workout details, health data, and cycle data never reach Firestore.
You can remove yourself from every bet at Settings → Import & Export → Your Data Rights → Leave all Social Bets. If you need server-side deletion beyond the in-app control, email privacy@kinoku.app.
Diagnostics (Analytics, Crashlytics, Performance)
Firebase Analytics, Crashlytics, and Performance Monitoring are off at the manifest level on first launch. They only send data after you opt in at Settings → Help improve Kinoku. After you opt in, Kinoku may send Firebase app interaction events, crash stack traces, performance traces, and limited event metadata. That metadata can include subscription tier, theme, training-goal label, scene actions, and billing product IDs. It can also include coarse workout interaction counts, such as whether a workout started or completed, duration in seconds, and exercise count. It does not include exercise names, set-by-set logs, notes, route coordinates, Health Connect values, cycle data, photos, or contact details. Google's ad-consent flags are set to denied in the app manifest, and nothing in the app ever turns them back on. The advertising ID permission is stripped from the manifest too, so Kinoku cannot read your advertising ID.
Routine follow-along videos (YouTube and Vimeo)
When you paste a YouTube or Vimeo URL into a routine, Kinoku makes one oEmbed call to the provider. That call goes to youtube.com/oembed or vimeo.com/api/oembed.json. It reads the video title, the address of the thumbnail image, the author or channel name, and, from Vimeo, the video length and description. You can switch this off at Settings → Import & Export → "Fetch video metadata".
YouTube's oEmbed reply does not include the video length or its chapters. To get those, Kinoku can fetch the public watch page, the same page anyone can open in a browser. That second call is off by default. You turn it on at Settings → Import & Export → "Detect chapters from YouTube videos". The fetch is capped at 5 MB. Chapter timestamps let the editor offer to build your exercise list from the chapters.
Kinoku refuses redirects on the watch-page fetch. A 30x response from YouTube is treated as "no chapter data available." This stops a malicious upstream from redirecting Kinoku's HTTP request to a LAN or loopback address.
Kinoku saves what it fetched on your device with the routine. The thumbnail is saved as an address, not as a picture, so every place that routine's thumbnail appears the app loads the image from the provider's image server. That is a separate request, and YouTube or Vimeo sees it.
For all of these requests, the video address and your IP address are visible to Google or Vimeo. No Kinoku account, advertising identifier, workout ID, or health profile is attached. Pasting a URL never embeds, downloads, or proxies the video itself. Tapping the play control opens the URL in your browser or in the YouTube or Vimeo app, the same way any link would.
Weather context for runs (Open-Meteo)
Off by default. When you turn on "Add weather context to runs" at Settings → Run Tracking, Kinoku sends your run-start coordinates to Open-Meteo's API. The coordinates are rounded to two decimal places (about 1.1 km precision) before any URL is built. The call fetches temperature, apparent temperature, wind, and weather condition. With the AQI sub-toggle on, it also fetches US Air Quality Index, pollen index, UV index, and mean sea-level pressure. No Kinoku account, email, advertising identifier, or workout ID is attached. Open-Meteo must receive your IP address and the API URL, which holds the rounded coordinates. Kinoku asks at most once per run session, the first time the run screen gets a location fix, and the run does not wait for the reply. Four checks each skip the call quietly: the settings toggle is off, there is no confirmed internet, a 4-second timeout, or a defensive limit of 200 calls per day. The returned values are stored on your device with the rest of your run data.
Open-Meteo is the third-party API provider for this feature. Its privacy policy and terms are at open-meteo.com.
Reproductive health
If you use cycle tracking or pregnancy logging, dedicated raw records (period dates, symptoms, fertility observations, pregnancy history, generated cycle insights, private cycle prompts, and Change History for private changes) are held in a separate Room database (kinoku_cycle_db). Your Cycle Tracking configuration lives there too: whether Cycle Tracking and Health Connect import are enabled, typical cycle/luteal/period lengths, and irregular-cycle status. User-created metrics remain in the eligible main database.
- Left out of Google's Auto Backup cloud path. An automated test (
CycleCloudBackupExclusionTest) pins this. Take the exclusion out and the test fails. - Never sent to Kinoku. Kinoku operates no server that holds cycle, fertility, or pregnancy data.
- Never written to Health Connect. Kinoku may read menstruation entries to avoid duplicate logging. This is opt-in, with your explicit Health Connect consent. Kinoku does not and cannot write back.
- Never included in share cards, Your Story, photo overlays, the main CSV export, or Firestore bet payloads. The CSV exporter skips the cycle tables, and cycle phase is never persisted on the main Pulse or Readiness rows it exports. Automated privacy-boundary tests guard these paths.
- Included in a device-to-device transfer that you start (Android setup wizard) and in the manual ZIP backup. Those are under your control.
Post-Dobbs note. Kinoku operates no server holding cycle data. So Kinoku cannot answer a subpoena by producing that data, because Kinoku does not have it. Profile → Wellness → Delete all cycle data permanently removes the dedicated period, symptom, BBT, fertility, correlation, and pregnancy records, generated cycle insights, private Change History, and private one-time prompt state. It also records a private date-only deletion cutoff in the excluded cycle database: future Health Connect imports ignore periods beginning on or before that day, including same-day entries because Health Connect supplies no time-of-day, while genuinely later periods may import. A read started before deletion is rejected at commit. Pregnancy or TTC mode resets to Tracking. Health Connect opt-in, Cycle Tracking, other settings, custom metrics and logs, saved exports, achievements, workouts, and insight mute or feedback choices are preserved.
Washington MHMDA. For users who obtained the app in Washington State, cycle and pregnancy entries are classified as "consumer health data" under RCW 19.373. For deletion or access requests: privacy@kinoku.app.
Maps and tiles
GPS run tracking stores route polylines in the eligible main app database and never uploads them to a Kinoku server; Android system backup may copy that database to your Google account. When you open a map screen or make a route share image, Kinoku fetches map tiles from OpenFreeMap. If you choose the topographic style, it fetches them from OpenTopoMap. Neither host needs an API key or an account, and the style definitions ship inside the app rather than being downloaded. Tile providers receive the tile coordinates needed to draw the visible map area, the map fonts and icons those tiles are drawn with, and your IP address for the request. Kinoku does not attach a Kinoku account, advertising identifier, workout ID, or health profile to tile requests.
Google Play Billing
Google Play Billing processes paid subscriptions. Kinoku does not receive your card details, billing address, or payment information. The app receives product IDs, purchase status, subscription tier, and the purchase tokens needed to acknowledge or restore purchases. Purchase tokens are not kept after normal acknowledgement. If acknowledgement fails, a token may be stored on your device for retry and is removed after the refund window. Refunds and subscription management are handled through Google Play.
Rating prompt
Now and then, after a good moment in the app, Kinoku asks Google Play to show its own in-app rating sheet. Kinoku attaches no data to that request. Google Play does not tell Kinoku what you rated, or even whether the sheet appeared. The counters that decide when to ask are stored on your device and are left out of backup and device transfer, so a restore cannot re-arm or block the prompt.
App integrity, promo access, and gift codes
Kinoku uses Firebase App Check with Play Integrity to protect Firebase-backed features from abuse.
Promo access. Friends-and-family promo access uses Firebase Remote Config. Kinoku checks on cold start; release builds set a 12-hour minimum network-fetch interval, so later starts can use cached configuration. The app compares the downloaded allowlist on-device with a salted code derived from the Android device ID. The raw ID stays on the device unless you choose to share its support code. On a network fetch, Firebase can receive your IP address and the app-install identifiers its SDK uses. These are not advertising IDs.
Gift codes. Turned off right now. Every way to enter a code is closed in this release, so no code is sent to Firebase. The rest of this paragraph describes how it works when it is switched back on. Kinoku's server rules require a signed-in caller, so redeeming a code signs the app in to Firebase with an anonymous ID first. That ID carries no email, name, or phone number. Kinoku then sends the code you entered to Firestore, checks the matching gift_codes document, and increases its use count.
If you redeemed a code on an earlier version, your plan still works. Kinoku reads that from your device. It makes no Firebase call to check it.
None of these flows send workout, health, cycle, route, or photo data to Firebase.
Android Auto Backup
If you turn on Android Auto Backup (a device setting), the eligible main Kinoku database and files directory may be backed up to your personal Google account. Main Change History is part of that database. The dedicated cycle and pregnancy database is left out (see the reproductive-health section), and it holds private Change History and your Cycle Tracking configuration as well; user-created metrics in the main database are eligible. Since app-file backup can occur before an updated app is first opened, older main-database snapshots may contain historical cycle-phase derivatives or Cycle Tracking settings from before they moved to the dedicated database. Version 159 removes the phase copies the first time the upgraded main database opens; Kinoku cannot retroactively rewrite a snapshot Google already holds. You can turn off Auto Backup in your device's Google One Backup settings.
Wear OS companion
Wear OS sync runs over Google Play Services' Wearable Data Layer, which moves data between your phone and your watch over their own connection. Kinoku operates no server in that path and receives none of it.
Third-party services
The third parties below can process limited data when you use a networked feature, an Android platform service, or this website. Kinoku uses no advertising, data-broker, or A/B-testing third parties.
| Service | What they process | When |
|---|---|---|
| Google LLC: Firebase Auth, Firestore | When gift codes are switched on: an anonymous Firebase sign-in ID (no email, name, or phone number), the code you entered, its validity, its tier and duration, and its use count. When Social Bets is switched on: also the bet display alias and bet progress number. | Gift codes and Social Bets are both turned off right now, so nothing is sent to this service. |
| Google LLC: Firebase Remote Config | The promo allowlist, downloaded by the app and compared on your device to your Android device ID. Firebase sees your IP address and an app install ID it creates for this copy of Kinoku. | Checked on cold start; release network fetches are cached for at least 12 hours |
| Google LLC: Firebase App Check with Play Integrity | A Play Integrity token showing the request came from a genuine copy of Kinoku | When a Firebase-backed request runs. In this release that is promo access. |
| Google LLC: Firebase Crashlytics, Analytics, Performance | Crash stack traces, app interaction events, performance traces, and limited metadata such as tier, theme, training-goal label, billing product IDs, and coarse workout interaction counts | Only after you opt in via Settings → Help improve Kinoku |
| Google LLC: YouTube | The video URL, your IP address, and request metadata needed to return oEmbed details, a thumbnail, or, when separately enabled, public watch-page chapter data | When you paste a YouTube routine link and video-metadata fetching is on; watch-page chapter detection is off by default |
| Vimeo.com, Inc. | The video URL, your IP address, and request metadata needed to return oEmbed details and thumbnails | When you paste a Vimeo routine link and video-metadata fetching is on |
| Android system speech-recognition provider | Your spoken audio may be processed by the recognizer configured on your device; Kinoku receives the returned text and does not store raw audio | Only when you choose voice logging and on-device recognition is unavailable or not selected by Android |
| Open-Meteo (operated by Patrick Zippenfenig) | Run-start coordinates rounded to ≈1.1 km precision in the API URL; your IP address is visible to Open-Meteo for the request | Only when "Add weather context to runs" is enabled |
| OpenFreeMap and OpenTopoMap | Tile coordinates for the visible map area, plus the map fonts and icons those tiles are drawn with; your IP must be visible to the tile operator for the length of each request | When you open a map screen or make a route share image |
| Google LLC: Google Play Billing | Product IDs, purchase status, subscription tier, and purchase tokens needed to acknowledge or restore purchases; Kinoku never receives your payment details, card, or billing address | When you purchase or manage a subscription |
| Google LLC: Google Play In-App Review | The request that asks Google Play to show its own rating sheet. Kinoku attaches no data to it, and Google Play does not tell Kinoku what you rated or whether the sheet appeared. | Rarely, after a good moment in the app, with a long cooldown between asks |
| Cloudflare, Inc. | Standard web-request data needed to serve kinoku.app, such as IP address, requested path, user agent, and security or operational metadata | When you visit the Kinoku website |
International transfers
Google LLC operates Firebase services (Auth, Firestore, App Check, Remote Config, Crashlytics, Analytics, Performance), Google Play Billing, Google Play In-App Review, YouTube, and, on some devices, the system speech-recognition service. Vimeo operates its own video and metadata services. Cloudflare serves the Kinoku website. Requests to these providers may be processed in the United States or other countries outside the EEA under their applicable transfer mechanisms and privacy terms. The Open-Meteo API call sends rounded coordinates and receives the request IP address; its CDN decides routing. Tile fetches to OpenFreeMap or OpenTopoMap may be served from EU or non-EU infrastructure, depending on geographic routing.
Retention
- On-device data (workouts, routines, body metrics, photos, cycle entries, settings): kept until you delete it in the app or uninstall the app.
- Change History: kept until you clear it. Ordinary target deletion does not remove its readable history. Delete all cycle data removes private Change History with the dedicated cycle and pregnancy record.
- Legacy Social Bets Firestore documents: the current release creates no new bet data. If a document exists from an earlier enabled build, use the available in-app data-rights control or email privacy@kinoku.app for deletion.
- Legacy gift-code and current promo records: gift redemption is disabled. Existing redemption records and promo-access records are kept only as needed to prevent duplicate use and manage access.
- An anonymous Firebase sign-in from an earlier version. You have one only if you redeemed a gift code or joined a bet back then. It stays with Firebase Auth and on your device until you clear the app's storage or uninstall. This release creates no new one. To have an old one removed sooner, email privacy@kinoku.app.
- Diagnostics (Analytics, Crashlytics, Performance): subject to Google's Firebase retention policy. Turning diagnostics off stops future collection and tells the app to delete unsent crash reports queued on your device.
- Google Play Billing records: held by Google Play under its own retention schedule. Kinoku stores only the local billing cache needed to remember your tier offline. Failed acknowledgement tokens are local-only and removed after the refund window.
- Email correspondence with privacy@kinoku.app or hello@kinoku.app: kept for as long as needed to handle the request and to meet record-keeping duties under Bulgarian and EU law (typically up to 3 years from last contact).
The Kinoku website (kinoku.app)
The marketing website at kinoku.app is a static site served by Cloudflare. It uses no analytics, no cookies, no fingerprinting, and no third-party trackers. That means no Google Analytics, no Plausible, no Meta Pixel, and no Hotjar, or anything like them. Served pages do not intentionally load third-party analytics scripts, tracking pixels, or externally hosted fonts. Cloudflare may process and retain standard request or security logs under its own operational policies. Kinoku does not use those logs for product analytics.
Automated decision-making
AI Coach, Training Insights, Smart Suggestions, Readiness Score, Autoregulation, and Weight Progression are informational aids only. They do not produce legal or similarly significant effects. There is no profiling for marketing or advertising.
What Kinoku does not do
- No ad SDKs, no data brokers, no cross-app tracking
- No sale or sharing of personal information (CCPA/CPRA)
- No required account creation
- No Kinoku-operated server storing workout, cycle, or health data
Your rights
If you are in the EU, EEA, or UK, you have rights of access, rectification, erasure, restriction, portability, and objection. You also have the right to lodge a complaint with a supervisory authority. Most data lives on your device, so you use these rights directly through the app's export and deletion controls (Settings → Import & Export, Settings → Data & Storage → Change History, and Profile → Wellness → Delete all cycle data for dedicated cycle data). Deleted workouts go to Trash first, where you can restore them, delete single items for good, or empty the Trash. To clear everything local at once, uninstall Kinoku or clear its storage in Android's app settings. For requests that need Kinoku to act, email privacy@kinoku.app.
Under CCPA/CPRA: Kinoku does not sell or share personal information. Kinoku does not use sensitive personal information outside providing the service. Requests: same email.
Data Protection Officer
Kinoku has not appointed a Data Protection Officer. Kinoku's processing does not meet the criteria in GDPR Article 37(1). Kinoku is not a public authority. Its core activities do not consist of large-scale systematic monitoring of data subjects. And it does not engage in large-scale processing of special categories of data on systems it operates. The cycle, period, fertility, and pregnancy data described above lives only on user devices and is never sent to Kinoku-operated servers. For all data-protection matters, contact privacy@kinoku.app.
Children
Kinoku is not directed at children under 16 and is not intended for use by them. Kinoku does not knowingly collect personal data from users under 16.
Data breach notification
Kinoku holds no copies of your workout, cycle, or health data on servers it operates. If a qualifying breach affects the Firestore bet, gift-code, promo, or Firebase diagnostics data, Kinoku will notify affected users. Where the law requires it, Kinoku will also notify the relevant supervisory authority within 72 hours.
Changes
Material changes raise the policy version and the "Last updated" date above. If a change requires consent, Kinoku will ask before turning on the affected processing.
Contact
DREAM SOFT DISTRIBUTED EOOD, Plovdiv, Bulgaria (EU). privacy@kinoku.app.

