Privacy Policy
Last Updated: August 6, 2026
At Kalios, we are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy outlines how we collect, use, and safeguard your data when you use our platform and services.
1. Information We Collect
We collect information that you provide directly to us, such as when you create an account, complete forms, or communicate with us. This may include:
- Personal Information: Name, email address, phone number, and billing information.
- Account Data: Username, password, and profile details.
- Usage Data: Information about your interactions with our platform, including IP address, device information, and browser type.
- Health and Fitness Data: Workout details, activity logs, nutritional information, and other health metrics you input or sync through the platform.
- Health Integration Data: If — and only if — you connect a health source described in Section 5 (Apple Health, Android Health Connect, or the Google Health / Fitbit cloud connection), the daily health summaries described there, and, for the cloud connection specifically, the OAuth tokens Kalios stores to keep it connected.
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve our platform and services.
- Process payments and manage subscriptions.
- Communicate with you regarding updates, promotions, and support.
- Analyze usage trends to enhance user experience.
- Track your health and fitness progress and provide personalized recommendations.
3. Sharing Your Information
We do not sell your personal information to third parties. However, we may share your information with:
- Service Providers: Third-party vendors who assist with payment processing, hosting, and analytics.
- Legal Authorities: When required to comply with applicable laws or legal processes.
- Business Transfers: In the event of a merger, acquisition, or sale of our assets.
4. Health and Fitness Data
We understand the sensitive nature of health and fitness data and take extra precautions to safeguard this information. Your health and fitness data, including activity logs, workout plans, and nutrition details, will only be used to:
- Provide personalized coaching and fitness recommendations.
- Track and analyze your fitness progress.
- Enable integrations with third-party health apps, devices, or connected cloud accounts, if authorized by you.
- Allow your coach and their authorized team members to access and utilize this data to support your fitness goals.
This data will not be shared with unauthorized third parties without your explicit consent, except as necessary to provide the services you have requested or comply with legal obligations.
5. Health Integrations (Device Sync & Cloud Connection)
Kalios offers two independent ways to bring outside health data into your account. Both are entirely optional, off until you turn them on, and read-only — Kalios never writes, modifies, or deletes data at the source, on either path. They differ in where your data comes from and whether your phone is involved:
- On-device sync — Apple Health (HealthKit) and Android Health Connect. Your phone reads from these frameworks and sends only day-level summaries to our servers.
- Cloud connection — Google Health (Fitbit). You grant our servers direct access to your Google/Fitbit account, and our servers fetch your data straight from Google's API. Your phone is never part of this path — it keeps working even while your phone is off or the app isn't installed.
On-device sync: Apple Health & Health Connect
Our mobile app can connect to Apple Health (HealthKit) on iOS and Android Health Connect on Android.
What we read
You grant access per data type, and you can grant some types and refuse others. The types we may request are:
- Steps
- Sleep (duration and, where available, sleep stages, bedtime, and wake time)
- Resting heart rate and average heart rate
- Heart rate variability (HRV)
- Active energy burned
- Water intake and calories consumed
- Body weight and body-fat percentage
What leaves your device
Only day-level summaries are sent to Kalios — for example one step total or one average heart rate for a given day. Individual samples and raw readings stay on your device. Summaries are transmitted over an encrypted connection (HTTPS) to our own servers at api.kalios.fit. Syncing may also run periodically in the background, so that your data stays current without you opening the app; background syncing reads only the data types you have already granted.
Your control
- Choose which data types to share when you connect, and change that choice later.
- Disconnect at any time from within the app, or revoke access in iOS Settings or Health Connect.
- Disconnecting stops all future syncing immediately. Summaries already synced remain in your Kalios account until you delete your account or ask us to remove them (see Section 6).
Cloud connection: Google Health (Fitbit)
Our mobile app can also connect to Google Health, Google's platform for Fitbit and other connected devices. Connecting here does not read anything from your phone: you sign in to your Google/Fitbit account and grant Kalios's servers permission to read your data directly from Google, server to server. Because of that, this connection keeps working even when your phone is off, out of battery, or the app isn't installed.
What Kalios's servers access
Google groups the permissions our servers request into four categories, all read-only — Kalios never requests permission to write to your Google/Fitbit account. You review and grant these on Google's own consent screen, and, like the device data types above, you may grant a subset:
- Activity and fitness — steps and active energy burned.
- Health metrics and measurements — heart rate, resting heart rate, heart rate variability (HRV), weight, and body-fat percentage.
- Sleep — sleep sessions.
- Nutrition — water intake and calories consumed.
What we store, and how your data reaches us
To keep this connection working, Kalios stores the OAuth access and refresh tokens Google issues for your account, encrypted at rest (AES-256-GCM). We use them to fetch the same day-level health summaries listed above directly from Google's API: an initial 90-day backfill when you connect, ongoing fetches triggered by Google notifying our servers of changes to your account, and a periodic check when you open the Kalios app. This fetching runs in the background and does not require your phone to be on, unlocked, or running the app.
Your control
- Disconnect at any time from within the app.
- You can also revoke Kalios's access directly from Google, at myaccount.google.com/permissions.
- Disconnecting (from either place) revokes our access at Google and deletes the stored connection, including your OAuth tokens, from our systems. Day-level summaries already fetched remain in your Kalios account until you delete your account or ask us to remove them (see Section 6) — the same posture as the on-device sync above.
How we use this data
- Personalizing your training plan and adjusting it to your recovery and readiness.
- Tracking your progress and displaying your trends inside the app.
- Providing AI coaching responses and recovery or check-in notifications.
We do not use health data from either integration for advertising or marketing, we do not sell it, we do not share it with data brokers, and we do not send it to third-party advertising or analytics services. It is never used for any purpose beyond providing and improving the health and fitness features you asked for, and it is not disclosed to third parties except as strictly necessary to operate the service or to comply with the law.
Kalios's use of information received from Health Connect adheres to the Health Connect Permissions policy, including the Limited Use requirements, and our use of HealthKit data complies with Apple's HealthKit terms. Kalios's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Data Retention and Deletion
We retain your personal information for as long as your account is active or as needed to provide our services, and afterwards only as long as required to comply with our legal obligations, resolve disputes, and enforce our agreements. When data is no longer needed, we securely delete or anonymize it.
- Account and training data — retained for the lifetime of your account so your history, progress, and statistics remain available to you.
- Health integration data — day-level summaries from either the device sync or the cloud connection (Section 5) are retained for the lifetime of your account to power trends and personalization; they are not kept on a separate timer. The cloud connection's OAuth tokens are retained only while it stays connected — disconnecting deletes them immediately, as described in Section 5. Everything here is deleted when your account is deleted.
- Deleting your account — you can delete your account at any time from within the app. When you do, your private data is deleted from our systems: workout logs, body and exercise metrics, goals, plan history, notifications, AI chat history, coaching notes, health summaries from any connected integration, and every health-integration connection record (including any stored OAuth tokens).
- Shared and social content — content you shared with others (such as coach conversations or community posts) is not deleted, because it also belongs to those conversations. Instead your profile is anonymized in place, so that content no longer identifies you.
- Backups and legal records — residual copies may persist in encrypted backups for a limited period, and we may retain records we are legally required to keep, such as billing and tax records.
You can also request deletion of your data, including any device-sync or cloud-connection health data, by contacting us at contact@kalios.fit.
7. Security Measures
We implement appropriate technical and organizational measures to protect your data from unauthorized access, loss, or misuse. However, no method of transmission or storage is completely secure.
8. Your Rights
Depending on your jurisdiction, you may have the right to access, update, or delete your personal information. You can exercise these rights by contacting us at contact@kalios.fit.
9. Cookies and Tracking Technologies
Our platform uses cookies and similar technologies to enhance your experience and analyze usage patterns. You can manage your cookie preferences through your browser settings.
10. Children's Privacy
Our platform is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware of such data, we will delete it promptly.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make significant changes, we will notify you by email or by posting an updated policy on our platform. Your continued use of our services constitutes acceptance of the updated policy.
12. Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at contact@kalios.fit.