Privacy Policy
KrayoFit is built around your own progress. This draft describes the app behavior recorded in our current data inventory. It requires owner and legal review before publication as the final policy.
Draft updated 24 September 2026.
What we handle
When you create an account, Supabase Auth handles your email, account identifier, authentication, and recovery. A profile name and your confirmed time zone may be stored with your account. Your habits, check-ins, Arc activity, workout sessions, progress, and selected illustrated avatar are currently stored in account-scoped data on your device. Server tables are prepared for future sync, but app activity is not yet fully synced across devices.
Home-screen access
The mobile web experience can be added to your home screen through a supported browser. This creates an app icon, not a live widget. Browser data remains on the device unless you clear it.
Optional AI planning
If an eligible adult explicitly requests a Qwen draft in Plan Studio, selected planning inputs such as goal, schedule, equipment, broad body-context ranges, preferences, and optional notes are sent through an authenticated Supabase function to ModelScope/Qwen. KrayoFit does not send your name, email, or full account history in that request. Unsaved drafts remain in screen memory; saved edits become local habits or private challenges. The service records a short-lived quota timestamp. Provider-side retention and processing locations must be confirmed before production AI is enabled.
Photos and location
The current profile picker uses bundled illustrated avatars. It does not upload a personal photo or scan your photo library. KrayoFit currently uses a time-zone name, not GPS coordinates, for day boundaries and does not request background or continuous location access.
Notifications, analytics, and diagnostics
Notification delivery, product analytics, and crash-reporting providers are not finalized for the current release. We will update this policy and release disclosures before enabling any collection beyond the implemented behavior.
Subscriptions
Paid Pro subscriptions are not active in the current free version. If paid features become available later, we will update this policy with the payment provider and transaction handling before enabling billing.
Website and hosting
This public website is designed for AWS S3 and CloudFront. Standard web requests may expose IP address, user agent, requested path, and timing to AWS for delivery and security. Website analytics and contact forms are not enabled in this build.
Retention and deletion
Account information remains while your account exists, subject to backups and any legal retention that must be specified before launch. Auth deletion removes related database rows that cascade from the account. The app attempts to clear that account's on-device cache after confirmed in-app deletion; a web deletion cannot directly erase app data on a device that is offline or no longer in use. Local app data can also be removed by clearing app storage or uninstalling. Provider-side backup and AI retention must be verified.
Security and your choices
KrayoFit uses HTTPS for network requests and account ownership checks on the server. You can review or correct activity in the app, choose whether to use optional planning, and request deletion via Delete Account. Requests about access, correction, or other privacy rights need a verified privacy contact.
Contact and changes
The operator's privacy mailbox and postal address must be added before this policy is published for public release.
Material changes to data practices will be reflected here with a revised date and communicated through the app where required.
