Kinvex
Privacy Policy
Last updated: 12 September 2026
This policy explains how Kinvex handles personal data when you use the iOS or Android app and this website.
Kinvex is intended for people aged 13 and over and is not directed to children under 13. If you are under 18, use Kinvex only with any consent required where you live.
1. Who we are
Kinvex is operated by Didem Erol, trading as Kinvex, based in the United Kingdom. For privacy questions or requests, contact privacy@kinvex.app.
2. Data we collect
We collect the information needed to provide Kinvex:
- Account and authentication data: a Kinvex account identifier; email address and password when you register with email; and, if you choose Apple or Google sign-in, the provider identifier, email address or Apple relay address, and any name supplied by that provider.
- Training data: workout plans, exercises, set targets and completions, training notes, session dates and duration, volume, personal records, body-weight entries, and training preferences.
- Subscription data: your Kinvex account identifier, product and entitlement status, and purchase/subscription status needed to provide Premium. Payments are processed by Apple or Google; Kinvex does not receive your full payment-card number.
- Support correspondence: your email address, name if supplied, and the contents of messages you send us.
- Technical and service data: data stored on your device to run the app, and standard connection or request data processed by the services that host the app, website, and email.
- Crash diagnostics: when the app encounters an error, Sentry receives limited technical diagnostic data such as the app version, operating system, device model, and an approximate geographic area inferred from the report connection so we can diagnose and fix it. Kinvex's Sentry project is configured not to retain IP addresses. Before an event is sent, Kinvex removes all user, request, and breadcrumb context; it does not send account identifiers, names, email addresses, workout data, exercise names, notes, or body-weight entries to Sentry.
- Optional product analytics: only after you choose Share anonymous analytics in Settings, Firebase Analytics processes an app-instance identifier, limited device and app information, approximate geography, and fixed product events. Those events contain only selected feature names, counts, durations, and predefined categories. Kinvex does not send your name, email, Supabase account identifier, workout names, exercise names, notes, weight entries, or other free text in these events.
You may use Kinvex as a guest. Guest use still creates an anonymous account identifier so your data can be synchronised; it is not linked to an email address unless you choose to add one.
3. Optional Health integration
Save workouts to Health is on by default, but Kinvex asks for platform permission before its first write. With permission, it sends each completed strength workout’s start time, end time, and title to Apple Health or Health Connect. Kinvex does not read data from Apple Health or Health Connect. You can turn future writes off in Settings and revoke permission in your device settings.
4. How we use data and our lawful bases
- To create and maintain your account, save and synchronise training data, provide exports and account deletion, and provide purchased subscriptions: performance of our contract with you.
- To respond to support requests, keep the service secure, prevent misuse, and establish or defend legal claims: our legitimate interests or a legal obligation where applicable.
- To diagnose and fix app errors through the limited crash diagnostics described above: our Legitimate interests in providing a reliable and secure service.
- To write workouts to Apple Health or Health Connect: your permission through the relevant platform.
- To understand which product features and subscription prompts are useful: your consent, given by turning on Share anonymous analytics. You can withdraw consent at any time in Settings; collection stops when you turn it off.
We do not sell personal data, show advertising, or use advertising identifiers. Kinvex uses Firebase Analytics only after the optional consent described above. It uses Sentry only for the limited crash diagnostics described in this policy, not for advertising or product analytics.
5. Who receives data
We use service providers to operate Kinvex. They process data only as needed to provide their services:
- Supabase for authentication, cloud database storage, and account-deletion functions.
- RevenueCat for subscription status and purchase entitlement management.
- Google Firebase for the optional Firebase Analytics service described above.
- Sentry for the limited crash diagnostics described above.
- Apple and Google for sign-in and store purchases; Apple Health or Health Connect only when you enable the optional Health integration.
- Cloudflare for this website and Kinvex email routing.
When you choose to export or share data, the operating-system share sheet sends it only to the person or service you select. Their privacy practices then apply.
6. International transfers
Our providers may process data outside the United Kingdom or European Economic Area. Where this happens, we rely on the safeguards required by applicable data-protection law, such as contractual protections adopted by the relevant provider.
7. Retention and deletion
We keep account and training data while your account remains active. You can export your data from Settings and permanently delete your account from Settings at any time, including a guest account. Deletion removes active account data and Kinvex-owned local export files. Limited copies may remain in service-provider backups until their normal backup cycle replaces them, or where retention is necessary for a legal obligation or claim.
8. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of your personal data. You can export or delete data in Settings, or contact us at privacy@kinvex.app. We may need to verify your request.
If you are in the UK, you can complain to the Information Commissioner’s Office. If you are in the EU/EEA, you can contact your local data-protection authority. We do not sell or share personal information for cross-context behavioural advertising.
9. Changes to this policy
We may update this policy when Kinvex or applicable law changes. We will publish the updated version here and change the “Last updated” date. If a change materially affects how we use personal data, we will provide additional notice where required.
10. Contact
For privacy questions or requests, email privacy@kinvex.app.