Home  ›  Privacy Policy
Legal

Privacy Policy

Your workouts. Your data. Your control.

Effective 20 July 2026 Last updated 20 July 2026 Applies to iPhone · Apple Watch · Widgets

1 Introduction

Kugi (“Kugi,” “we,” “us,” or “our”) is a workout tracking application for iPhone and Apple Watch that helps you log strength and cardio training, follow routines, track progress, and share your achievements. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have.

We built Kugi around a simple principle: your workout history belongs to you. The training data you create is stored in your own private Apple iCloud account and on your device — not on Kugi-controlled servers. We only collect the limited information needed to sign you in, keep the app running reliably, and improve the product.

By creating a Kugi account or using the app, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use Kugi.

2 Who Is Responsible for Your Data

Kugi is operated by Kevin Cereno, the developer of the Kugi app, who is the “Data Controller” responsible for the personal data described in this policy. If you have any questions about this policy or how your data is handled, you can reach us using the details in the Contact Us section at the end of this document.

3 Information We Collect

We collect information in three ways: information you provide, information created as you use the app, and information collected automatically for security and analytics.

3.1 Account and Sign-In Information

To create and secure your account, Kugi uses Firebase Authentication (a Google service). Depending on the sign-in method you choose, we process:

  • Email & password sign-up: your email address and a password. Passwords are handled and stored in hashed form by Firebase Authentication — we never see or store your plain-text password.
  • Sign in with Apple: a unique Apple identifier and, if you choose to share it, your name and email address. You may hide your email, in which case Apple provides a private relay address.
  • Sign in with Google: your email address and basic Google profile information provided during sign-in.

Each account is assigned a unique user identifier (UID) that we use to associate your data with your account.

3.2 Profile and Onboarding Information

When you set up and personalize your account, you may provide:

  • A display name and a personal fitness goal.
  • An optional profile photo (avatar), which you can select from your photo library.
  • Onboarding responses such as your training goal, workout frequency, gender, how you heard about Kugi, and whether you have tried other fitness apps.

Your display name and goal are stored on your device and synced across your Apple devices using Apple’s iCloud key-value store. Your profile photo is stored locally on your device.

3.3 Workout and Fitness Data

This is the core content you create in Kugi. It includes:

  • Workout sessions, including exercises, sets, reps, weights, drop sets, effort ratings (RPE/RIR), rest presets, and notes.
  • Cardio activities, including machine, duration, distance, and resistance.
  • Workout templates, routines, repeating plans, and scheduled workouts.
  • Custom exercises you create and exercise preferences (pinned, favorite, or hidden exercises).
  • Body-weight entries you log.
Important: Your workout and fitness data is stored using Apple’s frameworks in your private iCloud database (CloudKit private database) and on your device. This data resides in your own Apple iCloud account, is synced by Apple across your signed-in devices, and is not transmitted to or accessible by Kugi’s developer. We do not host, read, or store your workout content on our own servers.

3.4 Apple Health (HealthKit) Data

If you enable the Apple Health integration — an optional feature available to all users at no cost — Kugi requests permission to:

  • Read from Apple Health: body mass (weight), active energy burned, resting heart rate, step count, and workouts.
  • Write to Apple Health: body-weight entries you log in Kugi and completed Kugi workouts.
Health data is accessed on your device through Apple’s HealthKit framework and is used to display your progress charts. Kugi does not send your Apple Health data to our servers or to any third party. You control this access at any time in iOS Settings › Privacy & Security › Health, and you can revoke it whenever you choose.

3.5 Analytics and Usage Information

To understand how features are used and to improve the app, Kugi uses Firebase Analytics (a Google service). We log app events such as: onboarding progress, tab and screen views, workout starts, share actions, widget deep-link opens, custom-exercise creation, and Health permission results. Firebase Analytics may also collect standard device and usage information (for example, device model, operating system version, approximate app-usage metrics, and a non-identifying analytics identifier).

We deliberately minimize what is sent to analytics. Kugi strips out free-text content — including workout names, template names, exercise names, machine names, and plan names — before any event is logged, so your personal workout labels are not included in analytics data.

3.6 Security and Anti-Abuse Information

Kugi uses Firebase App Check to help verify that requests to backend services come from a genuine, unmodified copy of the app. This helps protect the service against abuse and fraud.

3.7 Exercise Demonstration Media

Kugi downloads exercise demonstration images and videos from Firebase Storage (a Google service) to show you how to perform exercises. This is one-directional content delivery — app content is downloaded to your device. Your personal workout data is not uploaded to Firebase Storage.

3.8 Subscription and Purchase Information

If you purchase Kugi Pro, Kugi uses RevenueCat to manage and verify your subscription entitlement. RevenueCat processes information such as your App Store transaction and receipt data, an anonymous app-user identifier, your subscription status and product identifier, and basic device and platform information.

Payments are processed by Apple, not by Kugi. Your purchase is made through your Apple Account, and we never receive or store your payment-card details. RevenueCat is used only to confirm whether your Pro entitlement is active so the app can unlock the corresponding features.

4 How We Use Your Information

We use the information described above to:

  • Create, authenticate, and secure your account.
  • Provide core functionality — logging workouts, building routines, scheduling, and tracking progress.
  • Sync your data across your Apple devices and to your Apple Watch and home-screen/lock-screen widgets.
  • Display progress insights, including optional Apple Health metrics.
  • Deliver rest-timer alarms and other on-device notifications you enable.
  • Verify and manage your Kugi Pro subscription and unlock the features it includes.
  • Understand feature usage and improve the app’s stability, performance, and design.
  • Protect the service and our users against fraud, abuse, and security threats.
  • Respond to your support requests and comply with legal obligations.

5 Sharing Your Workouts and Achievements

Kugi includes features that let you share images or videos of your workouts, achievements, and progress — for example, sharing a workout card to Instagram Stories or Reels, or saving an image to your photo library. These actions are always initiated by you.

When you share to a third-party platform such as Instagram, the content you choose to share is handed off to that platform through iOS and becomes subject to that platform’s own privacy policy and terms. We do not control how third-party platforms handle content you post to them.

6 How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We share information only in the limited circumstances below:

  • Service providers: We rely on trusted providers who process data on our behalf, as listed in Section 7 (for example, Google Firebase for authentication, analytics, security, and media delivery; Apple for iCloud sync, Health, and payment processing; and RevenueCat for subscription entitlement management).
  • At your direction: When you use a share feature, the content you choose is sent to the destination you select (such as Instagram or the iOS share sheet).
  • Legal reasons: We may disclose information if required by law, regulation, legal process, or governmental request, or to protect the rights, property, or safety of Kugi, our users, or the public.
  • Business transfers: If Kugi is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy.

7 Third-Party Services We Use

The following third-party services support Kugi. Each operates under its own privacy policy.

ServiceProviderPurposeData involved
Firebase AuthenticationGoogleAccount sign-in & securityEmail, auth identifiers, hashed password
Firebase AnalyticsGoogleUsage analytics & improvementApp events, device & usage data (no workout text)
Firebase App CheckGoogleAnti-abuse / app integrityApp-attestation signals
Firebase StorageGoogleExercise media deliveryDownloaded content only
RevenueCatRevenueCat, Inc.Subscription & entitlement managementPurchase receipts, subscription status, app-user ID
Sign in with AppleAppleAccount sign-inApple ID identifier, optional name/email
Sign in with GoogleGoogleAccount sign-inEmail, basic profile
iCloud / CloudKitApplePrivate sync of your dataYour workout & app data (private DB)
Apple HealthKitAppleOptional health metrics (on device)Weight, energy, heart rate, steps, workouts
Instagram / iOS ShareMeta / AppleOptional user-initiated sharingContent you choose to share

Note: Firebase and Google Sign-In are provided by Google LLC. See Google’s Privacy Policy and Apple’s Privacy Policy for details on how those companies handle data.

8 Data Storage, Location, and Security

  • Your workout data lives in your private Apple iCloud account and on your device, protected by Apple’s account security and encryption. Apple may store this data on servers in various locations as part of iCloud.
  • Account credentials and analytics are processed by Google Firebase, which may store and process data on servers in the United States and other countries.

We take reasonable technical and organizational measures to protect your information, and we rely on the security infrastructure of Apple and Google. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9 Data Retention

We retain information for as long as your account is active or as needed to provide the app:

  • Your workout data remains in your iCloud account and on your device until you delete it or delete your account.
  • Account credentials are retained by Firebase Authentication for as long as your account exists.
  • Analytics data is retained according to Firebase Analytics’ standard retention settings.
  • Subscription and purchase records are retained by RevenueCat and Apple for as long as needed to manage your entitlement and to meet their own legal, tax, and accounting obligations.

When you delete your account, we delete the associated data as described in Section 10.

10 Your Rights and Choices

You have meaningful control over your data in Kugi.

10.1 Export Your Data

You can export your workout history, sets, cardio, templates, and repeating plans at any time from within the app as a downloadable ZIP archive of CSV files. Your data is yours to keep and take with you.

10.2 Delete Your Account and Data

You can permanently delete your account directly in the app (Settings › Delete Account). When you delete your account, Kugi:

  • Deletes the workout data owned by your account from the private iCloud store (workouts, templates, plans, scheduled workouts, custom exercises, exercise preferences, and body-weight entries).
  • Removes your profile information, avatar, and account-scoped settings from your device and iCloud key-value store.
  • Deletes your authentication account from Firebase and, for Apple sign-in, revokes the associated token.
Deletion is permanent and cannot be undone. Some information may persist temporarily in backups or in aggregated, non-identifying analytics that cannot be linked back to you.

10.3 Manage Permissions

  • Revoke Apple Health access anytime in iOS Settings › Privacy & Security › Health.
  • Manage notification permissions in iOS Settings › Notifications.
  • Turn off iCloud sync by signing out of iCloud or disabling it for Kugi in iOS Settings.

10.4 Regional Privacy Rights (GDPR / UK GDPR / CCPA)

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to the processing of your personal data, to data portability, and to withdraw consent. Where GDPR applies, our legal bases for processing are: performance of a contract (providing the app), legitimate interests (securing and improving the app), consent (for optional features such as Apple Health and analytics where required), and legal obligation. If you are in California, we do not sell your personal information. To exercise any of these rights, contact us using the details below. You also have the right to lodge a complaint with your local data protection authority.

11 Children’s Privacy

Kugi is not directed to children under 13 (or the minimum age required in your country), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take steps to delete it.

12 International Users

Kugi is available in multiple regions. By using the app, you understand that your information may be processed and stored by Apple and Google in the United States and other countries where these providers operate, which may have different data-protection laws than your own.

13 Changes to This Privacy Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you within the app. Your continued use of Kugi after an update means you accept the revised policy.

14 Contact Us

If you have questions, requests, or concerns about this Privacy Policy or your data, please contact us:

Kugi — Privacy
Data Controller: Kevin Cereno
Mailing address: 1008 N Monterey St, Apt 201, Alhambra, CA 91801, USA

This document is based on Kugi’s current data practices and has not been reviewed by an attorney. Confirm any region-specific requirements with a qualified professional before relying on it.

↑ Back to top