Kratos

Privacy Policy

Effective 8 August 2026 · Last updated 15 August 2026

Kratos is a workout logging app. This policy explains exactly what it collects, why, who else can see it, and how to get rid of it. It covers the Kratos iOS app and the backend it talks to.

The short version. Kratos stores the workouts you log and the email and password you sign in with (the password only ever in securely hashed form). When you log a set by voice, the short audio clip you record is sent to our speech provider (OpenAI) to turn it into text — that is the only time audio leaves your device, and it happens only when you tap the mic. There is no analytics SDK, no advertising, and no tracking. Two providers process data on our behalf: Supabase (database and sign-in) and OpenAI (voice transcription). Nothing is ever sold or used for advertising. You can delete everything from inside the app at any time, and the deletion is immediate and permanent.

What data is collected, and how

Everything below is data you enter or import yourself. Nothing is gathered in the background.

Kratos does not collect your name (unless you type one), precise or coarse location, contacts, photos, advertising identifiers, device identifiers, or any usage, diagnostic, or behavioural analytics. It contains no analytics, attribution, advertising, or crash-reporting software of any kind. Aside from the optional Apple Health backfill described above, it reads nothing from Apple Health.

How the data is used

Your data is used to run the app for you — to save your workouts, show your history and progress, and keep you signed in. Your email address and password are used to authenticate you, and your email is additionally used to send you a one-time code if you need to recover a forgotten password. When you log by voice, your audio clip and its transcript are used only to work out which sets you meant and to log them; the transcript may be kept with the workout it created so you can see what was logged.

Your data is never sold, rented, or shared for advertising; never used to build a profile of you; never used to send you marketing. Your voice recordings and their transcripts are used only to provide voice logging — our speech provider (OpenAI) processes them to return the transcription and does not use them to train its models (OpenAI does not train on data sent through its API). There is no advertising in Kratos.

Who else can access it

Kratos is built and run by an individual developer. Two third parties process your data, each only to provide a specific part of the app:

There is no parent company, subsidiary, or affiliated entity with access to your data. Data may be disclosed if required by law, but you will be told unless the law forbids it.

How long it is kept, and how to delete it

Your data is kept for as long as your account exists. There is no separate retention period and no archival copy kept for analysis.

You can delete your account at any time from inside the app: Settings → Account → Delete account. This permanently deletes your account together with every workout, routine, set, and custom exercise on it. It happens immediately, it cannot be undone, and there is nothing left to recover afterwards. You do not need to contact anyone to do it.

Because signing in is what creates your account, deleting the account is also how you withdraw consent to any processing described here. If you would rather keep a copy of your history first, Settings → Data → Export workouts produces a CSV file of your workouts that you can save or share before you delete.

Backups taken by the hosting provider may briefly retain deleted rows before they age out on the provider's normal backup cycle; they are not accessible through the app and are not used for any purpose.

Your rights

Wherever you live, you can access your data (it is all visible in the app), export it, correct it by editing it in the app, and delete it — using the in-app controls described above, with no request or approval needed. If you would prefer to exercise any of these rights by writing to a human instead, use the contact address below.

Security

All traffic between the app and the server is encrypted with TLS. Data is protected at the database level by row-level security policies, meaning the database itself enforces that a signed-in account can only ever read or write its own rows. No API keys or secrets are embedded in the app. No system is perfectly secure, but no data is stored that is not described above.

Children

Kratos is not directed to children and is not intended for use by anyone under 13. No data is knowingly collected from children. If you believe a child has created an account, use the contact address below and it will be deleted.

Changes to this policy

If this policy changes, the updated version will be posted at this URL with a new "last updated" date. Material changes to what is collected or who receives it will be announced in the app before they take effect.

Contact

Questions about this policy or your data: dsooseven@gmail.com.