Privacy policy — KAI Fitness

iOS app “KAI Fitness” · Last updated: June 21, 2026

Welcome to “KAI Fitness”. Your privacy is important to us and we are committed to protecting your personal data. This Privacy Policy, issued pursuant to Articles 13 and 14 of Regulation (EU) 2016/679 (“GDPR”), explains how data is collected, used, and protected when you use the “KAI Fitness” app.

In this Policy, any reference to “the app” or “this application” refers to “KAI Fitness”. KAI Fitness is available on the App Store under localized titles (for example, in English, “KAI: Gym & HIIT Tracker”).

1. Data controller

The data controller is:

Davide Pergola
Pioltello (MI), Italy
Contact email: [email protected]

No Data Protection Officer (DPO) has been appointed, as the conditions making such appointment mandatory under Article 37 GDPR do not apply.

2. Data collected and purposes of processing

2.1 Data collected directly by KAI Fitness

The app does not require registration and does not collect or store personally identifiable data of users on its own servers. All information entered by the user (e.g., workout preferences, progress) is saved locally on the device and is not transmitted to the Data Controller.

2.2 Data potentially collected through Google AdMob (free version)

Advertising is currently not active in the app. The free version may integrate the Google AdMob SDK for displaying advertisements. When this feature is active, Google may collect the following categories of data:

For users located in the European Union, the United Kingdom, and Switzerland, when advertising is active, KAI Fitness will show only non-personalized ads. This means that ads are not selected based on a user profile built through the massive collection of behavioral data. Google may still collect limited data for accounting purposes (frequency capping), fraud prevention, diagnostics, and ad contextualization.

Legal basis: legitimate interest of the Data Controller and of Google (Art. 6.1.f GDPR) in the proper functioning and financing of the free service through non-personalized advertising; interest in preventing advertising fraud.

For more information on Google AdMob’s data collection practices: https://policies.google.com/privacy and https://policies.google.com/technologies/partner-sites.

2.3 Subscription-related data (iOS)

For users who subscribe to the Premium plan on iOS, the purchase and payment management are entirely handled by Apple Inc. through the In-App Purchase system. KAI Fitness does not have access to the user’s payment data (card number, Apple ID, name, address, email).

The app receives only an anonymous transaction identifier (receipt) necessary to validate the subscription status (active / expired) and unlock premium content on the device. This identifier does not allow identification of the user.

Legal basis: performance of the subscription contract (Art. 6.1.b GDPR).

For the processing of payment data, Apple’s privacy policy applies: https://www.apple.com/legal/privacy/.

2.4 Anonymous usage data (TelemetryDeck)

To understand how the app is used and to improve it, KAI Fitness integrates TelemetryDeck, a privacy-focused, GDPR-compliant analytics service provided by TelemetryDeck GmbH (Hamburg, Germany), with servers located exclusively within the European Union (Germany).

Through TelemetryDeck, the app collects only anonymous, aggregated usage data — that is, technical signals indicating whether, in which sections, and for how long the app is used. Specifically:

TelemetryDeck does not collect or receive any personal or profile data of the user (name, email, weight, height, age, sex, goals) nor any free text entered by the user (e.g., workout names or notes). The service does not use the advertising identifier (IDFA), does not use cookies, and does not perform any individual tracking of the user across apps or over time: session identifiers are generated through a one-way hash function with a periodically rotating “salt”, so that it is not possible to identify the user or reconstruct their long-term behavior.

Unlike the providers listed in Section 3 below, TelemetryDeck acts as a data processor on behalf of the Data Controller, on the basis of a specific Data Processing Agreement (DPA) pursuant to Article 28 GDPR. Data is processed and stored on servers located within the European Union (Germany).

Legal basis: legitimate interest of the Data Controller (Art. 6.1.f GDPR) in understanding app usage in anonymous and aggregated form, in order to improve its features and stability. As this concerns anonymous data that does not allow user identification, the processing does not entail a high risk to the rights and freedoms of data subjects.

For more information: https://telemetrydeck.com/privacy/.

3. Data recipients

Data collected through third-party SDKs is processed by the respective providers as independent data controllers or joint controllers:

In addition, TelemetryDeck GmbH (Hamburg, Germany) processes the anonymous usage data referred to in Section 2.4 as a data processor on behalf of the Data Controller, on the basis of a Data Processing Agreement (DPA) pursuant to Article 28 GDPR – https://telemetrydeck.com/privacy/.

The Data Controller does not communicate personal data to third parties other than those listed above.

4. Extra-EU data transfers

The providers listed above (Google, Apple) may transfer data outside the European Economic Area, particularly to the United States. Such transfers take place based on Standard Contractual Clauses approved by the European Commission (Art. 46 GDPR) and/or the EU-US Data Privacy Framework, where applicable. Please refer to the individual providers' policies for details.

The anonymous usage data collected through TelemetryDeck is instead processed and stored entirely within the European Union (Germany) and is not subject to extra-EU transfers.

5. Data retention

As KAI Fitness does not directly collect personal data, no retention takes place on the Data Controller’s side.

Data collected by Google AdMob and Apple is retained according to their respective retention policies, available in their privacy notices.

The usage data collected through TelemetryDeck, being anonymous and not attributable to an identifiable user, is retained in aggregated form according to TelemetryDeck’s retention policies.

6. Rights of the data subject

Pursuant to Articles 15-22 of the GDPR, the user has the right to:

To exercise these rights towards the Data Controller, please write to: [email protected]. As KAI Fitness does not directly collect identifying data, requests related to data collected by third-party SDKs (Google, Apple) must be addressed directly to the respective independent controllers.

The user can also at any time:

Right to lodge a complaint: the user has the right to lodge a complaint with the competent supervisory authority. In Italy, the authority is the Italian Data Protection Authority (Garante per la Protezione dei Dati Personali) (https://www.garanteprivacy.it).

7. Minors

The app is intended for users aged 16 or older, in compliance with Article 8 of the GDPR. We do not knowingly collect data from minors under 16. Should we become aware of the unintended collection of data from a minor under 16 through third-party services, the Data Controller will take all reasonably necessary steps to request its deletion.

8. International compliance

8.1 US users (CCPA/CPRA)

For users residing in California, KAI Fitness does not “sell” personal data within the meaning of the California Consumer Privacy Act (CCPA). Data processed by Google AdMob is subject to Google’s CCPA policies.

8.2 Other jurisdictions

The app is available internationally. In some countries, Google AdMob services may be unavailable or function in a limited manner. Users are responsible for verifying the compliance of their app usage with local regulations.

Some countries require personal data to be stored on local servers: since KAI Fitness does not directly collect personal data, such obligations do not apply to the Data Controller. For data processed by third parties (Google, Apple), their respective policies apply.

9. Links to third-party sites

The app may contain links to third-party sites (mainly through advertisements). The Data Controller is not responsible for the privacy practices of such sites and recommends reviewing their privacy policies before providing personal data.

10. Security

The Data Controller adopts reasonable technical and organizational measures to protect the integrity of the app. As there is no direct collection of personal data by the Data Controller, there are no server-side databases at risk of data breach.

11. Changes to this policy

We reserve the right to update this Policy at any time. Updates will be published within the app and/or on the website. The “Last updated” date at the top of the document indicates the current version. Continued use of the app after the changes constitutes acceptance of the new Policy.

12. Contact

For any questions regarding this Policy or the processing of personal data:

Davide Pergola – Pioltello (MI), Italy
Email: [email protected]

Note: In case of discrepancies between this English version and the Italian version, the Italian version shall prevail for interpretive and legal purposes.

By using KAI Fitness, you acknowledge that you have read and understood this Privacy Policy. Thank you for choosing KAI Fitness.

← Back to KAI Fitness