1 Introduction
Kugi (“Kugi,” “we,” “us,” or “our”) is a workout tracking application for iPhone and Apple Watch that helps you log strength and cardio training, follow routines, track progress, and share your achievements. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have.
We built Kugi around a simple principle: your workout history belongs to you. The training data you create is stored in your own private Apple iCloud account and on your device — not on Kugi-controlled servers. We only collect the limited information needed to sign you in, keep the app running reliably, and improve the product.
By creating a Kugi account or using the app, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use Kugi.
2 Who Is Responsible for Your Data
Kugi is operated by Kevin Cereno, the developer of the Kugi app, who is the “Data Controller” responsible for the personal data described in this policy. If you have any questions about this policy or how your data is handled, you can reach us using the details in the Contact Us section at the end of this document.
3 Information We Collect
We collect information in three ways: information you provide, information created as you use the app, and information collected automatically for security and analytics.
3.1 Account and Sign-In Information
To create and secure your account, Kugi uses Firebase Authentication (a Google service). Depending on the sign-in method you choose, we process:
- Email & password sign-up: your email address and a password. Passwords are handled and stored in hashed form by Firebase Authentication — we never see or store your plain-text password.
- Sign in with Apple: a unique Apple identifier and, if you choose to share it, your name and email address. You may hide your email, in which case Apple provides a private relay address.
- Sign in with Google: your email address and basic Google profile information provided during sign-in.
Each account is assigned a unique user identifier (UID) that we use to associate your data with your account.
3.2 Profile and Onboarding Information
When you set up and personalize your account, you may provide:
- A display name and a personal fitness goal.
- An optional profile photo (avatar), which you can select from your photo library.
- Onboarding responses such as your training goal, workout frequency, gender, how you heard about Kugi, and whether you have tried other fitness apps.
Your display name and goal are stored on your device and synced across your Apple devices using Apple’s iCloud key-value store. Your profile photo is stored locally on your device.
3.3 Workout and Fitness Data
This is the core content you create in Kugi. It includes:
- Workout sessions, including exercises, sets, reps, weights, drop sets, effort ratings (RPE/RIR), rest presets, and notes.
- Cardio activities, including machine, duration, distance, and resistance.
- Workout templates, routines, repeating plans, and scheduled workouts.
- Custom exercises you create and exercise preferences (pinned, favorite, or hidden exercises).
- Body-weight entries you log.
3.4 Apple Health (HealthKit) Data
If you enable the Apple Health integration — an optional feature available to all users at no cost — Kugi requests permission to:
- Read from Apple Health: body mass (weight), active energy burned, resting heart rate, step count, and workouts.
- Write to Apple Health: body-weight entries you log in Kugi and completed Kugi workouts.
3.5 Analytics and Usage Information
To understand how features are used and to improve the app, Kugi uses Firebase Analytics (a Google service). We log app events such as: onboarding progress, tab and screen views, workout starts, share actions, widget deep-link opens, custom-exercise creation, and Health permission results. Firebase Analytics may also collect standard device and usage information (for example, device model, operating system version, approximate app-usage metrics, and a non-identifying analytics identifier).
We deliberately minimize what is sent to analytics. Kugi strips out free-text content — including workout names, template names, exercise names, machine names, and plan names — before any event is logged, so your personal workout labels are not included in analytics data.
3.6 Security and Anti-Abuse Information
Kugi uses Firebase App Check to help verify that requests to backend services come from a genuine, unmodified copy of the app. This helps protect the service against abuse and fraud.
3.7 Exercise Demonstration Media
Kugi downloads exercise demonstration images and videos from Firebase Storage (a Google service) to show you how to perform exercises. This is one-directional content delivery — app content is downloaded to your device. Your personal workout data is not uploaded to Firebase Storage.
3.8 Subscription and Purchase Information
If you purchase Kugi Pro, Kugi uses RevenueCat to manage and verify your subscription entitlement. RevenueCat processes information such as your App Store transaction and receipt data, an anonymous app-user identifier, your subscription status and product identifier, and basic device and platform information.
4 How We Use Your Information
We use the information described above to:
- Create, authenticate, and secure your account.
- Provide core functionality — logging workouts, building routines, scheduling, and tracking progress.
- Sync your data across your Apple devices and to your Apple Watch and home-screen/lock-screen widgets.
- Display progress insights, including optional Apple Health metrics.
- Deliver rest-timer alarms and other on-device notifications you enable.
- Verify and manage your Kugi Pro subscription and unlock the features it includes.
- Understand feature usage and improve the app’s stability, performance, and design.
- Protect the service and our users against fraud, abuse, and security threats.
- Respond to your support requests and comply with legal obligations.
7 Third-Party Services We Use
The following third-party services support Kugi. Each operates under its own privacy policy.
| Service | Provider | Purpose | Data involved |
|---|---|---|---|
| Firebase Authentication | Account sign-in & security | Email, auth identifiers, hashed password | |
| Firebase Analytics | Usage analytics & improvement | App events, device & usage data (no workout text) | |
| Firebase App Check | Anti-abuse / app integrity | App-attestation signals | |
| Firebase Storage | Exercise media delivery | Downloaded content only | |
| RevenueCat | RevenueCat, Inc. | Subscription & entitlement management | Purchase receipts, subscription status, app-user ID |
| Sign in with Apple | Apple | Account sign-in | Apple ID identifier, optional name/email |
| Sign in with Google | Account sign-in | Email, basic profile | |
| iCloud / CloudKit | Apple | Private sync of your data | Your workout & app data (private DB) |
| Apple HealthKit | Apple | Optional health metrics (on device) | Weight, energy, heart rate, steps, workouts |
| Instagram / iOS Share | Meta / Apple | Optional user-initiated sharing | Content you choose to share |
Note: Firebase and Google Sign-In are provided by Google LLC. See Google’s Privacy Policy and Apple’s Privacy Policy for details on how those companies handle data.
8 Data Storage, Location, and Security
- Your workout data lives in your private Apple iCloud account and on your device, protected by Apple’s account security and encryption. Apple may store this data on servers in various locations as part of iCloud.
- Account credentials and analytics are processed by Google Firebase, which may store and process data on servers in the United States and other countries.
We take reasonable technical and organizational measures to protect your information, and we rely on the security infrastructure of Apple and Google. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9 Data Retention
We retain information for as long as your account is active or as needed to provide the app:
- Your workout data remains in your iCloud account and on your device until you delete it or delete your account.
- Account credentials are retained by Firebase Authentication for as long as your account exists.
- Analytics data is retained according to Firebase Analytics’ standard retention settings.
- Subscription and purchase records are retained by RevenueCat and Apple for as long as needed to manage your entitlement and to meet their own legal, tax, and accounting obligations.
When you delete your account, we delete the associated data as described in Section 10.
10 Your Rights and Choices
You have meaningful control over your data in Kugi.
10.1 Export Your Data
You can export your workout history, sets, cardio, templates, and repeating plans at any time from within the app as a downloadable ZIP archive of CSV files. Your data is yours to keep and take with you.
10.2 Delete Your Account and Data
You can permanently delete your account directly in the app (Settings › Delete Account). When you delete your account, Kugi:
- Deletes the workout data owned by your account from the private iCloud store (workouts, templates, plans, scheduled workouts, custom exercises, exercise preferences, and body-weight entries).
- Removes your profile information, avatar, and account-scoped settings from your device and iCloud key-value store.
- Deletes your authentication account from Firebase and, for Apple sign-in, revokes the associated token.
10.3 Manage Permissions
- Revoke Apple Health access anytime in iOS Settings › Privacy & Security › Health.
- Manage notification permissions in iOS Settings › Notifications.
- Turn off iCloud sync by signing out of iCloud or disabling it for Kugi in iOS Settings.
10.4 Regional Privacy Rights (GDPR / UK GDPR / CCPA)
Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Where GDPR applies, our legal bases for processing are: performance of a contract (providing the app), legitimate interests (securing and improving the app), consent (for optional features such as Apple Health and analytics where required), and legal obligation. If you are in California, we do not sell your personal information. To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with your local data protection authority.
11 Children’s Privacy
Kugi is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.
12 International Users
Kugi is available in multiple regions. By using the app, you understand that your information may be processed and stored by Apple and Google in the United States and other countries where these providers operate, which may have different data-protection laws than your own.
13 Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the app. Your continued use of Kugi after an update means you accept the revised policy.
14 Contact Us
If you have questions, requests, or concerns about this Privacy Policy or your data, please contact us:
This document is based on Kugi’s current data practices and has not been reviewed by an attorney. Confirm any region-specific requirements with a qualified professional before relying on it.
↑ Back to top