Privacy Policy
Last updated: June 11, 2026
1. Introduction
Kluvit ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and website (collectively, the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
2.1 Information you provide directly
- Account information: name, email address, password
- Profile information: profile photo, date of birth, fitness preferences
- Habit and workout logs you create manually
- Club, challenge, and social feed content you post
- Communications you send us (support emails)
2.2 Information collected automatically
- Device identifiers and operating system version
- App usage data and crash reports
- Approximate location (only when you grant permission, for nearby club discovery)
- Step count via the device pedometer (only with permission)
2.3 Information from connected fitness apps
If you connect third-party apps (Strava, Hevy, Apple Health, Adidas Running), we receive workout data including activity type, distance, duration, and start time. We use this solely to log habits and award XP in Kluvit. We do not sell or share this data with third parties. OAuth access tokens are stored encrypted server-side and never transmitted to your device.
3. How We Use Your Information
- To provide, maintain, and improve the Service
- To calculate XP, levels, and streaks
- To enable social features (friends, clubs, challenges, feed)
- To send push notifications you have opted into
- To respond to support requests
- To detect and prevent fraud or abuse
- To comply with legal obligations
We do not use your health or workout data for advertising purposes.
4. Data Sharing and Disclosure
We do not sell your personal data. We share data only in these circumstances:
- Service providers: Supabase (database and auth), Expo (push notifications), Stripe (payments). Each is bound by data processing agreements.
- Other users: Your display name, avatar, level, habit feed posts, and club participation are visible to other users per your privacy settings.
- Legal requirements: We may disclose data if required by law or to protect safety.
5. Apple Health Data
Kluvit requests read-only access to Apple HealthKit data. We use this data exclusively to log habits and award XP within Kluvit. We do not share HealthKit data with third parties, do not use it for advertising, and do not store it beyond what is required for habit logging. You can revoke access at any time from iOS Settings → Health → Data Access & Devices → Kluvit.
6. Data Retention
We retain your data for as long as your account is active. You may delete your account at any time from Settings → Account → Delete Account, which will permanently remove all your personal data within 30 days. Anonymized aggregate statistics may be retained indefinitely.
7. Security
We implement industry-standard security measures including encryption at rest, TLS in transit, Row Level Security (RLS) in our database, and server-side-only storage of OAuth tokens. No method of transmission over the internet is 100% secure, and we cannot guarantee absolute security.
8. Children's Privacy
Kluvit is not directed to children under 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such data, please contact us and we will delete it promptly.
9. Your Rights
Depending on your jurisdiction, you may have rights to access, correct, delete, or export your personal data. To exercise these rights, contact us at privacy@kluvit.app.
10. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via in-app notification or email. Continued use of the Service after changes constitutes acceptance.
11. Contact Us
For privacy-related questions, contact us at privacy@kluvit.app.