Your health is not ad inventory.
Effective August 31, 2026 · Privacy policy
Kivo does not sell personal data, track you across other companies’ apps or sites, or use Health, fitness, food, photo, prompt, or conversation data for advertising.
Who operates Kivo
Kivo is operated by Pragmatic Developments Inc. Questions, access requests, corrections, and privacy requests can be sent to admin@pragmatic.onl.
Your choices before AI data leaves the device
The public iOS and iPadOS release offers two coaching modes: Apple Private, which uses Apple Intelligence on supported devices, and Kivo Auto, which can use Cloudflare Workers AI only after a separate affirmative permission. Kivo does not enable direct or arbitrary AI endpoints in the public release. Apple Watch does not send AI requests.
On Android, Gemini Nano is an optional on-device mode when the device supports it. KivoAI uses the authenticated Cloudflare Workers AI path described below only after its recipient-specific permission. Android also lets you deliberately choose a supported direct provider, including OpenAI-compatible or Anthropic service endpoints, and supply your own API key. Before a direct request, Kivo identifies the exact recipient and purpose; the request may contain your current prompt or meal description and a bounded, non-Health summary of your Kivo profile, goals, training preferences, nutrition totals, allergies, and exclusions. Kivo never includes Health Connect-derived values or prior coaching messages in a direct-provider request. Direct-provider keys are protected with Android Keystore, bound to the selected account and endpoint, excluded from backup and export, and sent only to that endpoint for authentication. Turning off, changing, or removing that provider stops future requests and invalidates its permission.
Before Kivo Auto may transmit a request, the app names Cloudflare, Inc. — Workers AI, explains the purpose, lists the exact categories below, and asks you to turn on “Allow Cloudflare Workers AI sharing.” A legacy setting, account sign-in, subscription purchase, or Health authorization is not consent. Permission is versioned and bound to that recipient and the current account or device-only profile; signing out or changing accounts revokes it. You may decline and use Apple Private, or turn permission off in Kivo Settings → AI coach; future Cloudflare AI requests then stop.
- Data that may be sent: your prompt and recent conversation; name; goals and experience; body and energy settings; training preferences, equipment, plan, completed workouts and set performance, and check-ins; injury or health notes you type; pantry, favorites, dietary needs, meals, and nutrition totals.
- Purpose: to answer the request with personalized general fitness, nutrition, recovery, workout, or meal guidance.
- Optional Health trends: excluded unless you separately opt in for the current supported recipient. On Android, compact Health Connect trends may be sent only through managed KivoAI; Gemini Nano processes them on device, and direct providers never receive them. Raw HealthKit or Health Connect samples and workout routes are never sent to an AI provider.
AI recipient, retention, and equal protection
Apple Private
Supported text coaching and nutrition requests use Apple’s on-device Foundation Models. Kivo does not send those requests to Kivo, Cloudflare, or another model provider. If the on-device model is unavailable, Apple Private pauses rather than silently falling back to cloud processing.
Cloudflare, Inc. — Workers AI
Kivo sends allowed requests over HTTPS through Kivo’s authenticated Cloudflare Worker to Workers AI. Workers AI runs Kivo’s approved models, currently GLM-5.3 Flash for complex coaching and planning, GLM-4.7 Flash for suitable utility work, and Moondream 3.1 for separately permitted food-photo fallback. Kivo does not send these requests directly to the model authors.
Kivo’s gateway does not persist prompt or response text. Cloudflare processes request content only to provide Workers AI; Cloudflare states that customer content is not used to train or improve models or services without explicit consent and is not used for advertising. See Cloudflare’s Workers AI data-usage terms.
Pragmatic Developments Inc. requires Cloudflare, as a processor, to follow Kivo’s instructions, confidentiality, security, deletion, and purpose limits under Cloudflare’s Data Processing Addendum. Any Cloudflare subprocessors must be bound to data-protection obligations no less protective than Cloudflare’s obligations. These controls provide the same or equal protection described in this policy for data sent through Kivo Auto. Kivo will not add a cloud AI recipient without reviewing its protections and presenting a new recipient-specific permission when required.
Food photos, visible text, and barcodes
Kivo first checks barcodes and reads visible text with Apple Vision, and supported devices can analyze a food image with Apple Intelligence on device. Kivo does not silently use Apple Private Cloud Compute for a food photo.
Before the first food-photo scan, Kivo asks separately whether to allow Cloudflare, Inc. — Workers AI fallback. Every scan still runs local checks first, and nothing is sent for fallback unless local evidence is insufficient. If allowed and needed, Kivo strips embedded camera metadata, resizes the image, and sends the resized photo, visible package and nutrition-label text, package-front identity text, on-device visual classification labels, barcode, capture type, and optional note through Kivo’s authenticated service solely to identify food and estimate nutrition. Kivo’s gateway does not persist that content or place it in a Cloudflare storage service. Cloudflare states customer content is not used to train or improve models or services without explicit consent and is not used for advertising. If you choose “Keep Photos On Device,” neither the image nor photo-derived text, labels, or barcode evidence is sent to a cloud model. Turning fallback off cancels pending cloud-enabled scans.
Barcode lookups use Open Food Facts, whose community data may be incomplete. Official restaurant results may load a matching product image from the publisher’s public image service; those requests contain no meal history or Health data. A separate “Contribute to Open Food Facts” action is optional and public: after ownership and CC BY-SA confirmation, Kivo removes embedded metadata and sends the photo, barcode, and your connected credentials directly to Open Food Facts under its terms.
Apple Health and Fitness
Apple Health access is optional and controlled by Apple’s permission sheet. Depending on what you approve, Kivo may read activity, workouts and routes, sleep, heart and recovery trends, body measurements, nutrition, and hydration. Kivo may write meals, Kivo-only workouts, weight, body composition, or hydration when you separately enable those features. Health data is used only for Kivo’s fitness, nutrition, and recovery experience.
Apple Health remains the source of truth. Raw HealthKit samples and workout routes stay on device and are not placed in Kivo’s account backup. Only after “Use Health trends with my AI” is enabled for the currently named recipient may AI receive derived activity and energy, workouts, sleep, heart/recovery/respiratory/VO₂ max, body and energy-profile, nutrition, and hydration context. Switching recipients, signing out, or changing accounts invalidates that permission. When it is off, Kivo removes the derived summary, every Health-capable profile field, Apple Health journey entry, and Apple Health workout record before constructing AI context.
Android Health Connect and Wear OS
Health Connect access is optional and controlled by Android’s category permission sheet. Depending on what you approve, Kivo may read steps, active and total energy, workouts, sleep, resting heart rate, heart-rate variability, and respiratory rate. Kivo writes meals, hydration, and Kivo-recorded workouts only when you separately enable their matching switches. Raw Health Connect records and routes are not placed in Kivo’s account backup.
The Wear OS companion may read live heart rate during a workout after permission; that heart-rate value stays on the watch. Quick check-ins, hydration, and workout-completion messages use Google’s private Wear data layer and become ordinary Kivo entries on the phone. Those Kivo entries are included in Kivo’s encrypted account backup when you Continue with Google; Google sign-in automatically enables account recovery across devices. Kivo does not sell or use those values for advertising.
Data kept by Kivo
The apps keep your profile, goals, plans, meals, pantry, favorite foods, coaching conversation, check-ins, workout history, and corrections in protected platform storage. Tokens use Apple Keychain or Android Keystore and are excluded from exports and backups.
If you choose Continue with Apple or Continue with Google, Kivo stores an encrypted Kivo account backup (the Kivo-history backup) in its account service so the same account can recover it on another device. It is not iCloud, CloudKit, or Google Drive. Local food-photo files, raw Health records, and workout routes are excluded. Apple or Google receives your sign-in or purchase transaction under its own terms; Kivo receives the stable account subject and any name or relay/account email supplied, plus the entitlement fields needed to unlock and restore membership.
Kivo records allow-listed product events such as setup completed or a core flow succeeding. Events never include prompts, replies, meal names, Health values, body measurements, workout details, routes, photos, location, or advertising identifiers. In-app feedback contains only the message and the optional diagnostics shown before sending. If you choose to report an Android AI response for safety review, Kivo receives that exact selected response, your chosen reason, an optional note, and the disclosed app build, Android version, screen, and selected AI provider. Kivo does not attach your prompt, other messages, account identity, or raw Health records, but the response you review may itself repeat identifying information used to answer you. The request uses a separate, unlinked random report-installation ID only long enough to derive an ephemeral one-way abuse-limiting hash; neither identifier nor hash is stored with the report.
Retention and deletion
- AI prompt, response, and cloud food photo content: not persisted by Kivo’s gateway and processed only for the request, except when you explicitly submit the selected response as an AI safety report.
- AI operational metadata: opaque account/request ID, route, token counts, status, and time; deleted after 32 days.
- Allow-listed product events: deleted after 180 days.
- Sessions: expire within 30 days and are replaced or deleted; signing out revokes the current session.
- Feedback: deleted 90 days after resolution and no later than 400 days after submission, or sooner with account deletion.
- Android AI safety reports submitted without account authentication: stored without a user ID, expire no later than 90 days after submission, and are deleted 30 days after resolution. The Android device keeps an encrypted deletion receipt so you can ask Kivo to delete submitted reports sooner from Data Controls. Before account or local erasure clears those receipts, Kivo requires deletion of every unexpired report it can address.
- Account, encrypted Kivo-history backup, and entitlement record: retained while the account exists so Kivo can provide recovery and purchases; deleted when the account is deleted, subject only to records legally required for fraud, tax, or transaction compliance.
- Local app data: remains until you erase it, delete the app, or delete the account.
Use Kivo Settings → Account, backup & deletion → Delete account, or follow the deletion guide. Kivo deletes active account records, clears queued Wear actions, removes Kivo-created Health Connect records it can access, and revokes available sign-in credentials as part of the request. If Health Connect access was revoked first, Android may require you to remove remaining Kivo-origin records from Health Connect directly. Processor backup remnants, if any, are isolated from active use and expire under the processor’s secure backup lifecycle.
Connected devices, security, and transfers
A connected Bluetooth food scale supplies live weight locally to resize a reviewed portion; nearby-device names, identifiers, and raw packets are not uploaded. Kivo uses HTTPS, encrypted platform storage, Keychain/Keystore protection, opaque short-lived tokens, least-data request validation, and server-side quotas. AI processing may occur outside your country under the contractual safeguards above. No system can promise absolute security.
Health guidance and medical limits
Kivo is intended for adults and provides general fitness and nutrition education. It is not a medical device, emergency service, diagnosis, treatment, rehabilitation plan, or exercise clearance. Kivo identifies app-authored estimates and limitations and links the supporting publications in Sources & Kivo methodology.
Changes
Material changes will be dated here. If a change expands AI data, purpose, or recipient, Kivo will invalidate the earlier permission and explain the new use before transmission.