Privacy Policy

Kivra Fitness Privacy Policy

Kivra Fitness (mobile app, PWA, admin, and super admin products) is provided by Kivra Services. This policy explains what we collect, how we use and share data, and the rights you have.

Data we collect

  • Account data: name, email, password (hashed), phone (if provided).
  • Profile and fitness data: age, gender, height, weight, BMI, goals, activity level, preferences, focus areas.
  • Usage data: workouts, sets/reps/weights, nutrition logs, water intake, check-ins, progress entries, chat history with the AI coach.
  • Device data: app version, device type, OS, browser (PWA), language; camera use for QR scanning.
  • Location: gym location lookup and check-in (when you use those features).
  • Subscription/billing (if applicable): plan, status, payment metadata (processed by the gateway; we do not store card numbers).

How we use data

  • Deliver core features: personalized workouts, nutrition targets, progress tracking, gym check-ins, subscriptions.
  • AI assistance: send relevant context to Google Vertex AI/Gemini to generate responses for workouts, nutrition, and guidance.
  • Sync and improve service reliability: real-time updates across devices via Firebase.
  • Analytics and product improvement: usage trends, feature performance (aggregated/anonymized where possible).
  • Security and abuse prevention: authentication, fraud/abuse checks, access control.
  • Communications: service updates, transactional emails, support responses.

Sharing

  • Service providers: Firebase (auth, database, hosting), Google Vertex AI/Gemini (AI responses), analytics providers. They process data on our behalf.
  • Gyms (if you are a member): check-in records, membership status, and relevant profile data for attendance and billing.
  • Legal/compliance: if required to comply with law, protect rights, or prevent fraud.
  • No selling of personal data. No third-party advertising networks.

Data retention

We keep data while your account is active and as needed for legitimate business, legal, or security reasons. You can request deletion; some records may be retained where required by law or for legitimate interests (for example fraud prevention, tax/financial records).

Account Deletion

You can delete your account and all associated data directly within the Kivra Fitness app: Profile > Settings > Delete Account.

If you are unable to access the app, request deletion by emailing ashwin@kivraservices.com with the subject "Account Deletion Request". We process requests within 30 days.

What gets deleted: your profile information, workout history, nutrition logs, and progress photos. This action cannot be undone.

Your choices and rights

  • Access and update your profile and fitness data in the app.
  • Export data (on request) and delete your account (on request); deletion may remove access to paid features.
  • Control communications: unsubscribe from non-essential emails; transactional messages may still be sent.
  • Cookies/local storage (PWA/web): used for authentication/session and experience.

Security

  • Encryption in transit (HTTPS) and secure authentication via Firebase Auth.
  • Role-based access for admin/super admin panels; Firestore security rules.
  • Regular reviews to reduce risks of unauthorized access or misuse.

Children

Kivra Fitness is not directed to children under 16. Do not use the service if you do not meet local age requirements.

International transfers

Data may be processed in India and other regions where our providers operate. We use appropriate safeguards as required by applicable law.

Changes to this policy

We may update this policy. Material changes will be communicated via the app or email. Continued use means you accept the updated policy.

Contact

Email: ashwin@kivraservices.com

Email: harshavardhan@kivraservices.com

Kivra Services Website and Regular Services (Non-Fitness)

For regular Kivra website browsing and non-fitness services, we generally do not collect personal data by default and we do not sell personal data.

If you share information voluntarily through contact channels, it is used only to respond and provide service support.

We do not run third-party advertising networks on this site.

Instagram Messaging + CRM Lead Capture (Real Estate)

If you send a direct message (DM) to our Instagram business account, we may process that information in our CRM to manage inquiries and follow up on real estate requirements.

Data collected from Instagram

  • Instagram user ID and username
  • Message content you send to us (text, media, quick replies)
  • Message metadata (message ID, timestamps)
  • Conversation metadata (thread status, assignment, follow-up status)
  • Any contact details you voluntarily provide in chat (for example phone number, preferred location, budget)

We do not collect your Instagram password.

How we use this data

  • Respond to your inquiry and provide property assistance
  • Create or update lead records in our CRM
  • Classify inquiry intent (for example buy/rent/commercial/residential)
  • Route the lead to the appropriate team member
  • Maintain service quality, audit logs, and abuse prevention

Legal basis / permission basis

By initiating a conversation with our Instagram business account, you consent to processing of your message data for customer support and sales follow-up.

Sharing

We may share data only with:

  • Authorized internal team members (sales/support)
  • Service providers operating our systems (cloud hosting, database, monitoring)
  • Meta Platforms, as required for Instagram messaging APIs
  • Legal authorities, where required by law

We do not sell personal data and do not use third-party ad networks for this CRM flow.

Retention

Instagram inquiry and CRM lead records are retained for operational, legal, and audit needs, and are periodically reviewed for deletion or anonymization when no longer required.

Your choices and rights

You can request access, correction, or deletion of your Instagram/CRM lead data by emailing:

Please include your Instagram username and, if possible, message date/time to help us locate records. We process deletion requests within 30 days.

You can also stop future processing by discontinuing conversation and removing app permissions in Instagram/Facebook account settings.