Plain-language privacy

Your health is not ad inventory.

Effective August 31, 2026 · Privacy policy

Kivo does not sell personal data, track you across other companies’ apps or sites, or use Health, fitness, food, photo, prompt, or conversation data for advertising.

Who operates Kivo

Kivo is operated by Pragmatic Developments Inc. Questions, access requests, corrections, and privacy requests can be sent to admin@pragmatic.onl.

Your choices before AI data leaves the device

The public iOS and iPadOS release offers two coaching modes: Apple Private, which uses Apple Intelligence on supported devices, and Kivo Auto, which can use Cloudflare Workers AI only after a separate affirmative permission. Kivo does not enable direct or arbitrary AI endpoints in the public release. Apple Watch does not send AI requests.

On Android, Gemini Nano is an optional on-device mode when the device supports it. KivoAI uses the authenticated Cloudflare Workers AI path described below only after its recipient-specific permission. Android also lets you deliberately choose a supported direct provider, including OpenAI-compatible or Anthropic service endpoints, and supply your own API key. Before a direct request, Kivo identifies the exact recipient and purpose; the request may contain your current prompt or meal description and a bounded, non-Health summary of your Kivo profile, goals, training preferences, nutrition totals, allergies, and exclusions. Kivo never includes Health Connect-derived values or prior coaching messages in a direct-provider request. Direct-provider keys are protected with Android Keystore, bound to the selected account and endpoint, excluded from backup and export, and sent only to that endpoint for authentication. Turning off, changing, or removing that provider stops future requests and invalidates its permission.

Before Kivo Auto may transmit a request, the app names Cloudflare, Inc. — Workers AI, explains the purpose, lists the exact categories below, and asks you to turn on “Allow Cloudflare Workers AI sharing.” A legacy setting, account sign-in, subscription purchase, or Health authorization is not consent. Permission is versioned and bound to that recipient and the current account or device-only profile; signing out or changing accounts revokes it. You may decline and use Apple Private, or turn permission off in Kivo Settings → AI coach; future Cloudflare AI requests then stop.

AI recipient, retention, and equal protection

Apple Private

Supported text coaching and nutrition requests use Apple’s on-device Foundation Models. Kivo does not send those requests to Kivo, Cloudflare, or another model provider. If the on-device model is unavailable, Apple Private pauses rather than silently falling back to cloud processing.

Cloudflare, Inc. — Workers AI

Kivo sends allowed requests over HTTPS through Kivo’s authenticated Cloudflare Worker to Workers AI. Workers AI runs Kivo’s approved models, currently GLM-5.3 Flash for complex coaching and planning, GLM-4.7 Flash for suitable utility work, and Moondream 3.1 for separately permitted food-photo fallback. Kivo does not send these requests directly to the model authors.

Kivo’s gateway does not persist prompt or response text. Cloudflare processes request content only to provide Workers AI; Cloudflare states that customer content is not used to train or improve models or services without explicit consent and is not used for advertising. See Cloudflare’s Workers AI data-usage terms.

Pragmatic Developments Inc. requires Cloudflare, as a processor, to follow Kivo’s instructions, confidentiality, security, deletion, and purpose limits under Cloudflare’s Data Processing Addendum. Any Cloudflare subprocessors must be bound to data-protection obligations no less protective than Cloudflare’s obligations. These controls provide the same or equal protection described in this policy for data sent through Kivo Auto. Kivo will not add a cloud AI recipient without reviewing its protections and presenting a new recipient-specific permission when required.

Food photos, visible text, and barcodes

Kivo first checks barcodes and reads visible text with Apple Vision, and supported devices can analyze a food image with Apple Intelligence on device. Kivo does not silently use Apple Private Cloud Compute for a food photo.

Before the first food-photo scan, Kivo asks separately whether to allow Cloudflare, Inc. — Workers AI fallback. Every scan still runs local checks first, and nothing is sent for fallback unless local evidence is insufficient. If allowed and needed, Kivo strips embedded camera metadata, resizes the image, and sends the resized photo, visible package and nutrition-label text, package-front identity text, on-device visual classification labels, barcode, capture type, and optional note through Kivo’s authenticated service solely to identify food and estimate nutrition. Kivo’s gateway does not persist that content or place it in a Cloudflare storage service. Cloudflare states customer content is not used to train or improve models or services without explicit consent and is not used for advertising. If you choose “Keep Photos On Device,” neither the image nor photo-derived text, labels, or barcode evidence is sent to a cloud model. Turning fallback off cancels pending cloud-enabled scans.

Barcode lookups use Open Food Facts, whose community data may be incomplete. Official restaurant results may load a matching product image from the publisher’s public image service; those requests contain no meal history or Health data. A separate “Contribute to Open Food Facts” action is optional and public: after ownership and CC BY-SA confirmation, Kivo removes embedded metadata and sends the photo, barcode, and your connected credentials directly to Open Food Facts under its terms.

Apple Health and Fitness

Apple Health access is optional and controlled by Apple’s permission sheet. Depending on what you approve, Kivo may read activity, workouts and routes, sleep, heart and recovery trends, body measurements, nutrition, and hydration. Kivo may write meals, Kivo-only workouts, weight, body composition, or hydration when you separately enable those features. Health data is used only for Kivo’s fitness, nutrition, and recovery experience.

Apple Health remains the source of truth. Raw HealthKit samples and workout routes stay on device and are not placed in Kivo’s account backup. Only after “Use Health trends with my AI” is enabled for the currently named recipient may AI receive derived activity and energy, workouts, sleep, heart/recovery/respiratory/VO₂ max, body and energy-profile, nutrition, and hydration context. Switching recipients, signing out, or changing accounts invalidates that permission. When it is off, Kivo removes the derived summary, every Health-capable profile field, Apple Health journey entry, and Apple Health workout record before constructing AI context.

Android Health Connect and Wear OS

Health Connect access is optional and controlled by Android’s category permission sheet. Depending on what you approve, Kivo may read steps, active and total energy, workouts, sleep, resting heart rate, heart-rate variability, and respiratory rate. Kivo writes meals, hydration, and Kivo-recorded workouts only when you separately enable their matching switches. Raw Health Connect records and routes are not placed in Kivo’s account backup.

The Wear OS companion may read live heart rate during a workout after permission; that heart-rate value stays on the watch. Quick check-ins, hydration, and workout-completion messages use Google’s private Wear data layer and become ordinary Kivo entries on the phone. Those Kivo entries are included in Kivo’s encrypted account backup when you Continue with Google; Google sign-in automatically enables account recovery across devices. Kivo does not sell or use those values for advertising.

Data kept by Kivo

The apps keep your profile, goals, plans, meals, pantry, favorite foods, coaching conversation, check-ins, workout history, and corrections in protected platform storage. Tokens use Apple Keychain or Android Keystore and are excluded from exports and backups.

If you choose Continue with Apple or Continue with Google, Kivo stores an encrypted Kivo account backup (the Kivo-history backup) in its account service so the same account can recover it on another device. It is not iCloud, CloudKit, or Google Drive. Local food-photo files, raw Health records, and workout routes are excluded. Apple or Google receives your sign-in or purchase transaction under its own terms; Kivo receives the stable account subject and any name or relay/account email supplied, plus the entitlement fields needed to unlock and restore membership.

Kivo records allow-listed product events such as setup completed or a core flow succeeding. Events never include prompts, replies, meal names, Health values, body measurements, workout details, routes, photos, location, or advertising identifiers. In-app feedback contains only the message and the optional diagnostics shown before sending. If you choose to report an Android AI response for safety review, Kivo receives that exact selected response, your chosen reason, an optional note, and the disclosed app build, Android version, screen, and selected AI provider. Kivo does not attach your prompt, other messages, account identity, or raw Health records, but the response you review may itself repeat identifying information used to answer you. The request uses a separate, unlinked random report-installation ID only long enough to derive an ephemeral one-way abuse-limiting hash; neither identifier nor hash is stored with the report.

Retention and deletion

Use Kivo Settings → Account, backup & deletion → Delete account, or follow the deletion guide. Kivo deletes active account records, clears queued Wear actions, removes Kivo-created Health Connect records it can access, and revokes available sign-in credentials as part of the request. If Health Connect access was revoked first, Android may require you to remove remaining Kivo-origin records from Health Connect directly. Processor backup remnants, if any, are isolated from active use and expire under the processor’s secure backup lifecycle.

Connected devices, security, and transfers

A connected Bluetooth food scale supplies live weight locally to resize a reviewed portion; nearby-device names, identifiers, and raw packets are not uploaded. Kivo uses HTTPS, encrypted platform storage, Keychain/Keystore protection, opaque short-lived tokens, least-data request validation, and server-side quotas. AI processing may occur outside your country under the contractual safeguards above. No system can promise absolute security.

Health guidance and medical limits

Kivo is intended for adults and provides general fitness and nutrition education. It is not a medical device, emergency service, diagnosis, treatment, rehabilitation plan, or exercise clearance. Kivo identifies app-authored estimates and limitations and links the supporting publications in Sources & Kivo methodology.

Changes

Material changes will be dated here. If a change expands AI data, purpose, or recipient, Kivo will invalidate the earlier permission and explain the new use before transmission.