Privacy Policy · GifGif Studio
This policy describes exactly what KUKO AI Fitness does with your data. Every statement here corresponds to behaviour enforced in the app's code, not to an intention.
We do not sell your personal data. We do not share health data with advertisers.
Written to local storage on your phone. Not transmitted anywhere unless you enable cloud sync (§6).
| Data | Purpose | Legal basis (GDPR) |
|---|---|---|
| Age, sex, height, weight, target weight, activity level, goal | Calculating your calorie and macro targets | Consent — Art. 6(1)(a), Art. 9(2)(a) |
| Food diary entries (name, portion, calories, macros, time) | Showing your daily and weekly nutrition | Consent |
| Workout sessions (plan, duration, estimated calories) | Showing your training history | Consent |
| Favourite recipes | Letting you find them again | Legitimate interest — Art. 6(1)(f) |
| Reminder times and on/off state | Scheduling meal and activity reminders | Consent |
| Language, theme, consent choices | Restoring your preferences | Legitimate interest |
Retention: kept until you delete it in-app or uninstall the app. There is no server-side copy unless you enable sync.
Health and fitness information is a special category of personal data under GDPR Article 9. We process it only with your explicit consent, only on your device, and only to show it back to you.
Requested only at the moment you use the scan feature. Declining leaves every other part of the app fully usable.
Nutrition figures are estimates, not measurements. They are not medical, clinical, or dietary advice, and must not be used to manage a medical condition. If you have a health condition, an eating disorder, are pregnant, or have specific dietary requirements, consult a qualified professional.
Two paths, in this order:
On-device (preferred). When an on-device recognition model is present, the photo is analysed locally. It never leaves your phone and no network connection is used.
Our analysis service (fallback). If there is no on-device model, or the on-device model cannot identify the dish, the photo may be sent over an encrypted connection to our analysis service, which uses Google's Gemini API to identify it. This fallback also has a shared daily limit; once it is reached for the day, the app asks you to add the meal manually instead of sending the photo anywhere.
In that case:
If you would rather no photo ever leaves your device or is subject to Google's free-tier terms, do not use the scan feature — you can log every meal manually, and the app is fully functional that way.
Off by default. If you switch it on and grant the platform permission, the app reads:
What happens to it:
Withdraw access at any time in the app, or in Health Connect / Apple Health settings. Turning it off in the app also deletes the locally cached totals.
This use complies with the Health Connect Permissions policy and Apple's HealthKit requirements: health data is used only for the user-facing fitness features described here.
If you sign in with Google, we receive your name, email address and profile picture from Google, and show them in the app.
Cloud backup is not implemented in this version. Signing in does not upload your diary, workouts, profile or favourites anywhere — all of it stays on your device. Sign-in currently only links the account for a backup feature planned for a later release. When that ships, this policy will be updated before it is switched on, and it will be opt-in.
Retention: the name, email and photo are held only in the app's local session and are discarded when you sign out. We operate no server that stores them. To be certain nothing remains, sign out and uninstall, or use Settings → Privacy and data → Delete all my data.
The app is free and supported by ads served through Google AdMob.
We never send your health data, diary content or profile to advertising networks. Google's handling is described at policies.google.com/technologies/partner-sites.
Not currently collected. The app contains an opt-in analytics toggle that is off by default and no analytics SDK is integrated in this version. If that changes, this policy will be updated before the change ships, and the toggle will remain opt-in.
| Recipient | What they receive | When |
|---|---|---|
| Google AdMob | Advertising identifier, IP address, ad interactions | Always (non-personalised) / with consent (personalised) |
| Google Sign-In | Authentication request | Only if you sign in — no app data is sent |
| Google Gemini API (via our proxy) | The meal photo, IP address | Only when on-device recognition cannot identify a photo |
| Health Connect / Apple Health | Nothing — we only read, plus optional workout write-back | Only with your permission |
No other party receives your data. We use no data brokers and no cross-app tracking.
No system is perfectly secure. If you discover a vulnerability, please report it to [email protected].
KUKO AI Fitness is not directed at children under 13 (under 16 in the EEA where required) and we do not knowingly collect their data. Calorie targets are only calculated for ages 13 and above. If you believe a child has provided us data, contact us and we will delete it.
Regardless of where you live, you can:
EEA/UK (GDPR) additionally: rectification, restriction, portability, objection, and the right to complain to your data protection authority.
Türkiye (KVKK) — rights under Article 11, including learning whether your data is processed and requesting its deletion.
California (CCPA/CPRA) — the right to know, delete, correct, and opt out of "sale"/"sharing". We do not sell personal information. Opting out of personalised ads is available in-app to everyone.
Exercise any of these at [email protected]. We respond within 30 days. There is no charge, and we will not discriminate against you for asking.
Our analysis service and Google's advertising and API infrastructure may process data outside your country, including in the United States. Transfers rely on the European Commission's Standard Contractual Clauses and the equivalent UK addendum where applicable.
Material changes are announced in the app before they take effect, and the "Last updated" date above changes. Continuing to use the app after a change means you accept the updated policy.
GifGif Studio
[email protected]
For privacy requests, put "Privacy request" in the subject line so we can route it correctly.