App Privacy Policy

Last updated: 21 August 2026

This Privacy Policy explains what personal data KARADIA collects, why we collect it, how we use and protect it, and what choices you have - including how to delete your account and your data.

Controller: KARADIA is provided by Largiter (“we”, “us”, “our”). For privacy questions or requests, contact us at largiter.dev@gmail.com.

This policy applies to the KARADIA mobile application on iOS and Android (the “App”) and related support communications. It does not govern third-party services you connect (such as Apple Health or Health Connect), which have their own privacy policies.


1. Data we collect

1.1 Account data

  • Email address and password (password is stored in hashed form; we never store it in plain text).
  • A unique account identifier.

1.2 Profile data

  • Name, bio, avatar photo, sex, birth date, height, workout frequency and daily activity level - provided by you during onboarding or in your profile settings.

1.3 Health and fitness data

This data is central to how KARADIA works and is treated with additional care (see Section 4).

  • Body weight entries you log manually, including the measurement date/time, an optional note, and optional progress photos you attach.
  • Weight data read from and written to Apple Health (HealthKit) or Health Connect, if you choose to connect these integrations. We only read/write weight samples for the purpose of keeping your in-app weight log in sync with your Health app.
  • Heart rate data streamed from Bluetooth heart rate monitors you pair with the App, used to show live heart rate and heart-rate charts during and after your workouts.
  • Workout data: exercises, sets, reps, weights used, workout templates, workout history, and computed muscle-activation/workload statistics derived from the above.

1.4 Photos

  • Progress photos you attach to weight entries.
  • Your profile avatar image.

1.5 Device, diagnostic and usage data

  • Crash reports and error diagnostics via PostHog Error Tracking, which may include stack traces, app/OS version, and related technical metadata. Autocapture covers native crashes, uncaught exceptions, and unhandled promise rejections.
  • App usage analytics via the PostHog React Native SDK, including:
    • screen views and interaction events (autocapture);
    • app lifecycle events (e.g. open / background);
    • feature usage, navigation events, and feature-flag evaluation events;
    • device and app technical information (e.g. device model, OS version, app version);
    • an analytics identifier linked to your account when you are signed in (identify), so usage can be associated with your account for product improvement and support;
    • session replay (see Sections 4 and 5 for masking and health-data protections).
  • On Android, Bluetooth scanning requires the OS to request location-related permissions (ACCESS_FINE_LOCATION, BLUETOOTH_SCAN, BLUETOOTH_CONNECT). We do not use these permissions to determine, collect, or store your geographic location. They exist solely because Android requires them to discover nearby Bluetooth devices (heart rate monitors).

1.6 AI feature data

When you actively use optional AI features in the App (for example by submitting a prompt), we may process:

  • The text of your prompt and any instructions you provide.
  • Limited fitness or profile context needed to generate a useful response (for example recent workout or weight information you already store in the App), only as required for that request.
  • The AI-generated response returned to you.

We do not send any of this data to our AI provider automatically or in the background. Data is sent only when you consciously use an AI feature. You can simply choose not to use AI features; they are not required to use the rest of the App.

1.7 Support communications

If you contact us (for example by email), we receive the content of your message and any contact details you include, and may retain them to handle your request.

We do not collect precise GPS location, contacts, or any data beyond what is listed above.


2. How we use your data

We use the data described above to:

  • Provide the core functionality of the App (tracking workouts, weight, and heart rate; syncing with Apple Health / Health Connect; showing your progress and statistics).
  • Authenticate you and secure your account.
  • Store and back up your data on servers we operate so it is available across sessions and devices.
  • Diagnose crashes and technical issues, and improve the App’s stability and performance.
  • Understand feature usage (including via analytics and session replay) so we can improve the App.
  • Communicate with you about your account or in response to support/feature requests you submit.
  • Provide optional AI features you choose to use (for example training suggestions or answers to your prompts), by sending your request and the limited context needed for that request to Google’s Gemini API and showing you the generated response.

We do not use your health data, workout data, or any personal data to serve you advertising, and we do not sell your personal data to third parties.

KARADIA is a fitness tracking tool and is not a substitute for professional medical advice, diagnosis, or treatment. Fitness and heart-rate data in the App are for informational purposes only. Optional AI outputs are likewise informational and may be inaccurate; they are not medical, coaching, or professional advice.


Where the General Data Protection Regulation (GDPR) applies, we process your data on the following legal bases:

  • Performance of a contract - to provide the App’s features you have requested, including optional AI features you actively invoke (Art. 6(1)(b)).
  • Consent - for optional integrations you explicitly enable, such as Apple Health, Health Connect, and Bluetooth heart rate monitors (Art. 6(1)(a)). You may withdraw consent at any time by disconnecting the integration or unpairing the device in Settings / your device settings.
  • Legitimate interests - for crash/error diagnostics, security, and product analytics (including PostHog autocapture, account-linked analytics identifiers, feature flags, and session replay with the masking described in this policy), and for handling support requests (Art. 6(1)(f)). You may object to processing based on legitimate interests by contacting us at largiter.dev@gmail.com.
  • Legal obligation - where we must retain or disclose information to comply with applicable law (Art. 6(1)(c)).

4. Health data - additional commitments

Because KARADIA integrates with Apple HealthKit and Health Connect, we make the following specific commitments regarding health data obtained through these integrations:

  • We use HealthKit/Health Connect data only to provide health and fitness features within the App (displaying and syncing your weight).
  • We do not use HealthKit/Health Connect data for advertising, marketing, or other use unrelated to health/fitness purposes.
  • We do not share HealthKit/Health Connect data with data brokers or advertising platforms.
  • We do not sell HealthKit/Health Connect data.
  • Our use of information received from Health Connect adheres to the Health Connect Permissions Policy, including the Limited Use requirements.
  • You can revoke HealthKit or Health Connect access at any time in your device settings (and by disconnecting the integration in the App). Revoking access stops future sync; data already stored in Apple Health or Health Connect remains under your control in those apps.
  • For session replay, we configure PostHog to mask all text inputs and mask all images, and we do not capture app logs or network-request contents in replays. Health data (including weight and heart-rate values displayed in the App) is masked/excluded from PostHog session replay and is not sent to PostHog via network telemetry from the App.
  • If you use optional AI features and the request includes fitness or health-related context already stored in the App, that context is sent to Google’s Gemini API only for that request, solely to generate the AI response you asked for. We do not use AI features to advertise, market, or sell health data. HealthKit/Health Connect data is not sent to Gemini unless it is already stored in KARADIA for App features and is included in the limited context for a request you initiate.

5. Third-party services

We use the following third-party services to help us operate the App:

  • PostHog (EU cloud) - product analytics, session replay, feature flags, and error tracking via the PostHog React Native SDK. PostHog may process:

    • usage events and autocaptured screen/interaction and app-lifecycle data;
    • feature-flag requests/evaluations used to operate and improve the App;
    • device/app technical metadata;
    • an analytics identity linked to your KARADIA account when you are signed in;
    • session replay recordings (with text inputs and images masked; without app logs or network payload capture);
    • error/crash reports (including native crashes and uncaught errors). Data processed by PostHog for us is hosted in the European Union. PostHog acts as our data processor and does not use your data for its own independent purposes. See also PostHog’s privacy policy.
  • Google (Gemini API) - optional AI features you actively use in the App. When you submit an AI request, we send your prompt and the limited context needed for that request to Google’s Gemini API, and Google returns a generated response. We use a paid Gemini API plan: Google does not use your prompts or responses to improve its products, and processes them as our data processor under Google’s Data Processing Addendum for applicable products. Google may log prompts and responses for a limited period solely for abuse detection, safety, and legal/regulatory purposes, as described in the Gemini API terms. See also Google’s privacy policy and the Gemini API additional terms.

We do not use third-party advertising networks or data brokers.


6. How we share data

We share personal data only as needed to operate the App:

  • Service providers / processors - such as PostHog (analytics, session replay, and error tracking) and Google (Gemini API for optional AI features you initiate), who process data on our instructions.
  • Legal requirements - if required by law, regulation, legal process, or governmental request, or to protect the rights, safety, or property of KARADIA, our users, or others.
  • Business transfers - if we are involved in a merger, acquisition, financing, or sale of assets, personal data may be transferred as part of that transaction, subject to appropriate confidentiality protections.

We do not sell your personal data.


7. Data retention

Data category Retention
Account, profile, workout, weight, and related fitness data While your account is active
Progress photos and avatar While associated with your account / entries
AI prompts and responses we store in the App (if any) While associated with your account, or until you delete them / your account
PostHog analytics, session replay, and error reports According to our PostHog project retention settings (and PostHog’s defaults where not customized), then deleted or aggregated
Support emails For as long as needed to resolve your request and for a reasonable period afterward

Prompts and responses processed by Google’s Gemini API may also be retained by Google for a limited period for abuse monitoring and related purposes under the Gemini API terms; we do not control Google’s side retention beyond those terms.

If you delete your account (see Section 9), we delete your personal data from our production systems within 30 days, except where we must retain certain data to comply with legal obligations, resolve disputes, or enforce our agreements. Where feasible, we also delete or unlink analytics identifiers associated with your account in PostHog; residual analytics events may remain in aggregated or provider-side backups for a limited period under PostHog’s retention. Aggregated or de-identified data that cannot reasonably identify you may be retained for product improvement.


8. Data security

We use industry-standard measures to protect your data, including encrypted network connections (HTTPS/TLS), hashed password storage, and secure on-device storage for authentication tokens. No method of transmission or storage is 100% secure, but we work to protect your data to the best of our ability.

If we become aware of a personal data breach that requires notification under applicable law, we will notify affected users and/or authorities as required.


9. Your rights and account deletion

Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. Under the GDPR (EEA/UK), this includes access, rectification, erasure, restriction, portability, objection, and withdrawal of consent where processing is based on consent.

You can delete your account and associated data directly in the App: go to Profile → Settings → Account → Delete account and confirm in the dialog. This permanently and irreversibly deletes your account and the data associated with it. For step-by-step instructions, including how to request deletion by email if you can no longer sign in, see Delete your account and data.

You can also delete specific data without deleting your account - for example progress photos or workout history. See Delete your data for the steps and how to request data deletion by email.

Data export: to receive a copy of your personal data, contact us at largiter.dev@gmail.com from the email address associated with your account.

You can also exercise any of these rights, or ask us questions about this policy, by contacting us at largiter.dev@gmail.com. If you are in the EEA/UK, you also have the right to lodge a complaint with your local data protection authority.


10. Children’s privacy

KARADIA is not directed at children under the age of 16, and we do not knowingly collect personal data from children under 16. If you believe a child has provided us with personal data, please contact us so we can delete it.


11. International data transfers

Your data may be processed in countries other than your country of residence. Analytics and error data processed by PostHog for the App are hosted in the EU. When you use optional AI features, prompts and related context may be processed by Google on infrastructure that may be located outside the EEA/UK. Where we transfer personal data outside the EEA/UK, we rely on appropriate safeguards (such as Standard Contractual Clauses and Google’s Data Processing Addendum for paid Gemini API processing) as required by applicable law.


12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the App or by other appropriate means. The “Last updated” date above indicates when this policy was last revised.


13. Contact us

If you have any questions about this Privacy Policy or how we handle your data, contact us at: largiter.dev@gmail.com.