Privacy Policy
This English version is a translation provided for information only. The Turkish version is the governing text; if the two differ, the Turkish version prevails.
A plain-language explanation of what data we keep and why.
What we collect
Only what the app needs to work: your account details (name, email, phone number), your answers to the nutrition questionnaire, what you check off each day, your workout and measurement records, the photos you upload, your messages, your subscription status and, so that we can send you notifications, your device's notification address. If you give permission, your daily step count and active calorie totals from your phone's health app. A hash of your internet (IP) address, used to limit repeated attempts at sign-in, sign-up and form submissions; it is deleted within 10 days at the latest. We do not use analytics trackers, advertising pixels, advertising identifiers or third-party cookies; we do not track you across apps or websites, and we do not sell your data.
Age
Kiovita is for people aged 13 and over. Users under 18 use Kiovita with the knowledge and approval of their parent or guardian, and declare this when they create an account. We do not knowingly process the personal data of children under 13; if we learn that someone under 13 has created an account, we close the account and delete their data. Weight-loss (calorie deficit) programs are not generated for users under 18; their menus are built on calories for maintaining weight or gaining muscle. Coach accounts are for people aged 18 and over.
Health app data (Apple Health, Health Connect)
- Only when you give permission, and only with read permission: daily step count and active calories (the calories you burn through movement). We write nothing to the health app, and we read no other data, such as heart rate, sleep or clinical records.
- Only daily totals are read from your phone: today's total while the app is open, and, once a day, yesterday's final total. There is no background reading, and individual records are not collected. The date, steps and active calories are sent to our server over an encrypted connection (HTTPS) and kept for as long as your account is open.
- This data is used for only two things: your steps and active calories are shown on the Today screen, and your steps are counted in a step challenge you choose to join. It is not used for advertising, marketing, profiling, or credit or insurance assessments; it is not shared with anyone, not transferred to data brokers and not sold; and it is not written to iCloud. A person accesses this data only at your request, or when security or the law requires it.
- Your step total is shared only in a step challenge you choose to join: people in that challenge's group (members of your gym, or your coach and their clients) see your nickname and your step totals for the challenge days on the leaderboard. Your friends do not see your steps; active calories are not shown to anyone.
- You can withdraw permission at any time under Settings > Health data, or in your phone's Health Connect / Health app; from then on, no new data is read. Daily totals already saved stay until you delete your account; if you want only these deleted, write to kobeeagency@gmail.com. When you delete your account, these records are deleted too.
- The database and backups are stored on encrypted disks at our hosting provider (Supabase (Frankfurt, Germany) and Vercel); only authorized service accounts can access the database.
Photos
Your profile photo is visible to your friends and your coach, and on the coach card. Your progress photos are kept in a private area and only you can see them; no one can access them unless you share them.
Coach and gym applications
The full name, email, phone number, gym name and message entered in the application form are used only to evaluate the application, open the account and send the temporary password. Only the operator of Kiovita sees applications. Like other data, applications are stored on servers outside Türkiye; the separate checkbox on the form shows that you have read this, and it is not consent. The application record is deleted within 6 months at the latest after a decision is made; details are in the privacy notice (Aydınlatma Metni, in Turkish).
Early access list
The email address you leave on the early access page, your optional Instagram username, the tag of the link you came from and the discount code assigned to you are used only for the launch announcement, to show the code on screen, to send it by email and to match it to the discount in the app. The form has two separate checkboxes: one is your approval to receive commercial electronic messages for the launch announcement and the code email (it is registered with İYS, Türkiye's commercial message management system, within 3 business days; if it cannot be registered, it becomes invalid and no email is sent), and the other shows that you have read that the data is kept on servers outside Türkiye; we record the time of both. If you withdraw your approval through İYS, this opt-out is applied to the list within the 24 hours before each send, and no email is sent. When you enter the code in the app, the record is linked to your account; on iPhone, the App Store code assigned to you is kept, and on Android, the time the discount was assigned. The record is deleted within 6 months at the latest after the code is sent by email (once the record is deleted, the code also becomes invalid); if the email was never sent, 6 months after launch; and in any case, 12 months after you joined the list. Details are in the privacy notice (Aydınlatma Metni, in Turkish).
Cookies
We use only the cookies the service needs to work: a session cookie that keeps you signed in (deleted when you sign out), a cookie that remembers the selected branch for gym managers with more than one branch (12 hours), and a cookie used for the read-only view the operator opens for support (30 minutes). They are not for advertising or tracking, so no consent banner is needed.
Who can see your data
- You.
- The coach you are connected to.
- Your gym's manager.
- Your friends and people on a challenge leaderboard see only your profile card: nickname, photo, streak, badges and workout count. Your real name, email, phone number, weight, measurements and nutrition are not on this card. People you block cannot see your card.
- If you are a coach and have turned on the "Accepting clients" option, your name, photo, bio, specialty and the province/district where you work are visible to members in the Find a coach list.
- The system operator can view your panel in read-only mode, only for support and troubleshooting. No records can be changed while this happens.
Your password is stored in a form that cannot be reversed: no one, including us, can read it. If you forget it, it is reset; there is no password reminder.
Service providers
- Supabase (Frankfurt, Germany) and Vercel: database, file storage and servers.
- Apple and Google: payment collection for in-app purchases, and "Sign in with Apple" / "Sign in with Google". Your card details never reach us.
- RevenueCat: verifying app store subscriptions (account ID and purchase record).
- Expo, Apple (APNs) and Google (Firebase Cloud Messaging): delivering notifications to your phone (device notification address and the notification text).
- Sentry: error reports when the app crashes (where the error occurred, device model, operating system and app version). Your name, email, account ID, IP address and screenshots are not sent.
- Resend: sending the launch email to the early access list (email address and discount code).
These providers process the data only to provide this service; they may not use it for their own purposes.
Where your data is stored
On Supabase (Frankfurt, Germany) and Vercel infrastructure, on servers outside Türkiye (Germany and the USA). What you enter in the application and early access forms is stored there too; the launch email is sent through Resend (USA). For all personal data, not only health data, this is a transfer abroad under Article 9 of KVKK (Kişisel Verilerin Korunması Kanunu No. 6698, Türkiye's Personal Data Protection Law). Because under KVKK explicit consent can be a legal basis only for incidental (non-recurring) transfers, we do not base this transfer on your consent; the transfer-abroad checkbox on the application and early access forms is not consent, it shows that you have read this. In these countries, protection may not be the same as under KVKK, and it may be harder for you to exercise your rights. The framework for the transfer under Article 9 of KVKK and the risks are explained in the privacy notice (Aydınlatma Metni, in Turkish).
Deletion requests
You can delete your account yourself from your account page, or, if you prefer, write to kobeeagency@gmail.com. Deletion cannot be undone: your plans, measurements, photos and past records are deleted too. Records of payments you made to your gym (cash, bank transfer, card or installments) are the gym's accounting records: your name, the amount and the date are kept for the legal retention period, for up to 10 years; the record is not linked to your account, and your name is removed from it when the period ends. The purchase history of a subscription you bought through an app store stays with Apple or Google and with RevenueCat; to have it deleted, see the account deletion page (in Turkish).
Security
Connections are encrypted, each gym sees only its own members, and each coach sees only their own clients. Still, no system is completely secure; do not stay signed in on a shared device.
Data controller: Efe Yağız Subaşı (operator of Kiovita), Şirintepe Mahallesi, Aşiyan Sokak No 39, Kağıthane / İstanbul.
Privacy Policy · Terms of Use · Privacy notice (in Turkish) · Support · Account deletion · Licenses