Privacy Policy - Kiiro

PRIVACY POLICY

Last updated December 18, 2025

This Privacy Notice for endurance101 OÜ ("we," "us," or "our"), describes how and why we might access, collect, store, use, and/or share ("process") your personal information when you use our services ("Services"), including when you:

  • Download and use our mobile application (Kiiro), or any other application of ours that links to this Privacy Notice
  • Engage with us in other related ways, including any sales, marketing, or events

Age Requirement: Our Services are intended for users who are at least 16 years of age. By using the Services, you confirm that you are 16 years or older. We do not knowingly collect information from persons under 16. If we become aware that a user is under 16, we will terminate their account and delete their information.

Questions or concerns? Reading this Privacy Notice will help you understand your privacy rights and choices. We are responsible for making decisions about how your personal information is processed. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at [email protected].

SUMMARY OF KEY POINTS

This summary provides key points from our Privacy Notice, but you can find out more details about any of these topics by clicking the link following each key point or by using our table of contents below to find the section you are looking for.

What personal information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us and the Services, the choices you make, and the products and features you use. Learn more about personal information you disclose to us.

Do we process any sensitive personal information? We process sensitive personal information when necessary with your consent or as otherwise permitted by applicable law. Learn more about sensitive information we process.

Do we collect any information from third parties? We do not collect any information from third parties.

How do we process your information? We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law. We process your information only when we have a valid legal reason to do so. Learn more about how we process your information.

In what situations and with which parties do we share personal information? We share information with essential service providers including Firebase Authentication, Amplitude Analytics, and Apple for payment processing. Learn more about when and with whom we share your personal information.

How do we keep your information safe? We have adequate organizational and technical processes and procedures in place to protect your personal information. Learn more about how we keep your information safe.

What are your rights? Depending on where you are located geographically, the applicable privacy law may mean you have certain rights regarding your personal information. Learn more about your privacy rights.

How do you exercise your rights? The easiest way to exercise your rights is by visiting https://endurance101.com/contact, or by contacting us. We will consider and act upon any request in accordance with applicable data protection laws.

TABLE OF CONTENTS

  1. WHAT INFORMATION DO WE COLLECT?
  2. HOW DO WE PROCESS YOUR INFORMATION?
  3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR PERSONAL INFORMATION?
  4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?
  5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?
  6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?
  7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?
  8. HOW LONG DO WE KEEP YOUR INFORMATION?
  9. HOW DO WE KEEP YOUR INFORMATION SAFE?
  10. WHAT ARE YOUR PRIVACY RIGHTS?
  11. CONTROLS FOR DO-NOT-TRACK FEATURES
  12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?
  13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?
  14. DO WE MAKE UPDATES TO THIS NOTICE?
  15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?
  16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

1. WHAT INFORMATION DO WE COLLECT?

Personal information you disclose to us

In Short: We collect personal information that you provide to us.

We collect personal information that you voluntarily provide to us when you register on the Services, express an interest in obtaining information about us or our products and Services, when you participate in activities on the Services, or otherwise when you contact us.

Personal Information Provided by You. The personal information that we collect depends on the context of your interactions with us and the Services, the choices you make, and the products and features you use. The personal information we collect may include the following:

  • names
  • email addresses
  • date of birth (used for age-based heart rate calculations)
  • gender (used for training load calculations)
  • contact preferences
  • contact or authentication data
  • health and fitness data from Apple HealthKit (including heart rate, workout duration, distance, calories burned, pace, power, cadence, stride length, vertical oscillation, and ground contact time)
  • precise geolocation data (GPS coordinates and routes of your workouts)

Sensitive Information

When necessary, with your consent or as otherwise permitted by applicable law, we process the following categories of sensitive information:

  • health data (workout metrics from Apple HealthKit including heart rate, workout performance data, and fitness calculations derived from your date of birth and gender)
  • precise geolocation data (GPS coordinates showing the exact routes and locations of your workouts, displayed on maps within the app)

Payment Data. We may collect data necessary to process your payment if you choose to make purchases, such as your payment instrument number, and the security code associated with your payment instrument. All payment data is handled and stored by Apple. You may find their privacy notice here: https://www.apple.com/legal/privacy/.

Social Media Login Data. We may provide you with the option to register with us using your existing social media account details. If you choose to register in this way, we will collect certain profile information about you from the social media provider.

Application Data. If you use our application(s), we also may collect the following information:

  • Geolocation Information. We collect precise GPS coordinates from your workouts synced through Apple HealthKit. This location data includes the complete route of your workouts, start and end points, and is used to generate maps and analyze your training routes. Location data is only collected during workouts and is stored along with your workout data.
  • Mobile Device Access. We may request access or permission to certain features from your mobile device, including your mobile device's bluetooth and reminders.
  • Mobile Device Data. We automatically collect device information (such as your mobile device ID, model, and manufacturer), operating system, version information and system configuration information, device and application identification numbers, browser type and version, hardware model Internet service provider and/or mobile carrier.

Information automatically collected

In Short: Some information — such as your Internet Protocol (IP) address and/or browser and device characteristics — is collected automatically when you visit our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not reveal your specific identity (like your name or contact information) but may include device and usage information, such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, information about how and when you use our Services, and other technical information.

2. HOW DO WE PROCESS YOUR INFORMATION?

In Short: We process your information to provide, improve, and administer our Services, communicate with you, for security and fraud prevention, and to comply with law.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts.
  • To deliver and facilitate delivery of services to the user.
  • To respond to user inquiries/offer support to users.
  • To send administrative information to you.
  • To request feedback.
  • To send you marketing and promotional communications (with your consent).
  • To protect our Services.
  • To identify usage trends.
  • To determine the effectiveness of our marketing and promotional campaigns.

3. WHAT LEGAL BASES DO WE RELY ON TO PROCESS YOUR INFORMATION?

In Short: We only process your personal information when we believe it is necessary and we have a valid legal reason (i.e., legal basis) to do so under applicable law, like with your consent, to comply with laws, to provide you with services to enter into or fulfill our contractual obligations, to protect your rights, or to fulfill our legitimate business interests.

If you are located in the EU or UK

The General Data Protection Regulation (GDPR) and UK GDPR require us to explain the valid legal bases we rely on in order to process your personal information. As such, we may rely on the following legal bases to process your personal information:

  • Consent. We process your health data and other sensitive personal information based on your explicit consent (GDPR Article 9(2)(a)). During onboarding, after you authenticate, we present a screen asking you to connect your health data from Apple HealthKit. By tapping "Allow All" on this screen, you provide explicit consent for us to:
    • Access and process your health and workout data from Apple HealthKit
    • Store this data securely on our servers
    • Analyze and display your workout metrics and training insights

    Because processing your health data is the core function of Kiiro (a fitness tracking and training analysis app), withdrawing your consent means we cannot continue to provide the Services. You can withdraw consent at any time by:

    • Requesting account deletion: Contact us at [email protected] or use the in-app deletion feature (Settings → Account → Request Deletion). We will process your request within 30 days.
    • Revoking HealthKit permissions: Go to iOS Settings → Privacy & Security → Health → Kiiro to stop new data syncing. This prevents new data from being collected but preserves your historical data on our servers until you request full account deletion.
  • Performance of a Contract. We may process your personal information when we believe it is necessary to fulfill our contractual obligations to you, including providing our Services or at your request prior to entering into a contract with you.
  • Legitimate Interests. We may process your information when we believe it is reasonably necessary to achieve our legitimate business interests and those interests do not outweigh your interests and fundamental rights and freedoms. For example, we may process your personal information for some of the purposes described in order to:
    • Analyze how our Services are used so we can improve them to engage and retain users
    • Support our marketing activities
    • Diagnose problems and/or prevent fraudulent activities
    • Understand how our users use our products and services so we can improve user experience
  • Legal Obligations. We may process your information where we believe it is necessary for compliance with our legal obligations.
  • Vital Interests. We may process your information where we believe it is necessary to protect your vital interests or the vital interests of a third party, such as situations involving potential threats to the safety of any person.

4. WHEN AND WITH WHOM DO WE SHARE YOUR PERSONAL INFORMATION?

In Short: We share your information with essential service providers to operate our Services, including authentication and analytics providers.

We share your personal information with the following third-party service providers who process data on our behalf:

Authentication Services

We use Firebase Authentication (provided by Google LLC, United States) to securely manage user authentication and account access. Firebase processes your email address, username, and authentication credentials.

Firebase is certified under the EU-US Data Privacy Framework.

For more information, see Google's privacy policy: https://policies.google.com/privacy

Analytics Services

We use Amplitude (Amplitude, Inc., United States) to collect and analyze usage data to improve our Services. Amplitude processes behavioral analytics data such as feature usage, session duration, and user interactions.

We have disabled IP address tracking and city-level location tracking. No personally identifiable information (PII) is shared with Amplitude. Amplitude tracking is enabled only after you create an account and log in to the Services.

Amplitude is certified under the EU-US Data Privacy Framework.

For more information, see Amplitude's privacy policy: https://amplitude.com/privacy

Payment Processing

All payment processing is handled exclusively by Apple Inc. through their in-app purchase system. We do not collect or store your payment information.

For more information, see Apple's privacy policy: https://www.apple.com/legal/privacy/

AI-Powered Training Insights

We use Anthropic (Anthropic PBC, United States) to generate personalized training insights using their Claude AI. To protect your privacy, we only send anonymized, aggregated statistics (such as training load trends and workout summaries) that cannot be used to identify you. Your name, email, account details, and location data are never shared with Anthropic, and your data is not used to train AI models.

Anthropic is certified under the EU-US Data Privacy Framework.

For more information, see Anthropic's privacy policy: https://www.anthropic.com/legal/privacy

Data Transfer Safeguards

We have executed Data Processing Agreements (DPAs) with all service providers in accordance with GDPR Article 28. These agreements ensure our processors handle your data securely and in compliance with data protection regulations.

We have implemented Standard Contractual Clauses (SCCs) approved by the European Commission for transfers of personal information to service providers located outside the European Economic Area. These clauses ensure your data receives adequate protection in accordance with GDPR requirements.

We may also share your personal information in the following situations:

  • Business Transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business to another company.

5. DO WE USE COOKIES AND OTHER TRACKING TECHNOLOGIES?

In Short: We may use cookies and other tracking technologies to collect and store your information.

We may use cookies and similar tracking technologies to gather information when you interact with our Services. Some online tracking technologies help us maintain the security of our Services and your account, prevent crashes, fix bugs, save your preferences, and assist with basic site functions.

Amplitude Analytics

We use Amplitude to collect anonymous usage analytics to understand how users interact with our Services and to improve user experience. Amplitude tracking is enabled only after you create an account and log in to the Services.

The data collected by Amplitude includes:

  • Feature usage and interaction patterns
  • Session duration and frequency
  • Device type and operating system information
  • In-app behavior and navigation flows

We have configured Amplitude to:

  • Disable IP address collection
  • Disable city-level geolocation tracking
  • Exclude all personally identifiable information (PII)
  • Process data in accordance with GDPR requirements

Legal Basis for Analytics Processing: We process behavioral analytics through Amplitude based on our legitimate interest (GDPR Article 6(1)(f)) in improving our Services, detecting technical issues, and understanding feature usage. We have balanced this interest against your privacy rights by disabling IP tracking, geolocation, and excluding all personally identifiable information (PII). You have the right to object to this processing at any time by requesting account deletion as described in Section 10.

For more information about Amplitude's privacy practices, please visit: https://amplitude.com/privacy

6. HOW DO WE HANDLE YOUR SOCIAL LOGINS?

In Short: If you choose to register or log in to our Services using a social media account, we may have access to certain information about you.

Our Services offer you the ability to register and log in using your third-party social media account details. Where you choose to do this, we will receive certain profile information about you from your social media provider. The profile information we receive may vary depending on the social media provider concerned, but will often include your name, email address, and profile picture.

7. IS YOUR INFORMATION TRANSFERRED INTERNATIONALLY?

In Short: We may transfer, store, and process your information in countries other than your own.

Our primary servers are located in Germany (hosted by Hetzner Online GmbH). However, we use certain service providers whose infrastructure is located in the United States, including:

  • Firebase Authentication (Google LLC)
  • Amplitude analytics (Amplitude, Inc.)
  • Apple payment processing (Apple Inc.)
  • Anthropic AI services (Anthropic PBC)

Regardless of your location, please be aware that your information may be transferred to, stored by, and processed by us in our facilities and in the facilities of the third parties with whom we may share your personal information.

If you are a resident in the European Economic Area (EEA), United Kingdom (UK), or Switzerland, then these countries may not necessarily have data protection laws or other similar laws as comprehensive as those in your country. However, we will take all necessary measures to protect your personal information in accordance with this Privacy Notice and applicable law.

European Commission's Standard Contractual Clauses: We have implemented measures to protect your personal information, including by using the European Commission's Standard Contractual Clauses for transfers of personal information between our group companies and between us and our third-party providers. These clauses require all recipients to protect all personal information that they process originating from the EEA or UK in accordance with European data protection laws and regulations.

8. HOW LONG DO WE KEEP YOUR INFORMATION?

In Short: We keep your information for as long as necessary to fulfill the purposes outlined in this Privacy Notice unless otherwise required by law.

We will only keep your personal information for as long as it is necessary for the purposes set out in this Privacy Notice, unless a longer retention period is required or permitted by law. No purpose in this notice will require us keeping your personal information for longer than the period of time in which users have an account with us.

Account Deletion

If you request deletion of your account, we will process your request within 30 days. Upon completion, we will send you an email confirmation. We will permanently delete all your personal information from our active systems, including:

  • Account credentials and profile information
  • All health and workout data synced from HealthKit
  • Usage analytics and behavioral data
  • Any other data associated with your account

Deleted data may remain in encrypted database backups for up to 6 months, after which backups are automatically purged according to our backup retention policy. This retention period is necessary for disaster recovery purposes and data integrity. Your data will also be removed from our service providers (Firebase, Amplitude, Apple) in accordance with their data retention policies.

9. HOW DO WE KEEP YOUR INFORMATION SAFE?

In Short: We aim to protect your personal information through a system of organizational and technical security measures.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process. However, despite our safeguards and efforts to secure your information, no electronic transmission over the Internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that hackers, cybercriminals, or other unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information.

10. WHAT ARE YOUR PRIVACY RIGHTS?

In Short: Depending on your state of residence in the US or in some regions, such as the European Economic Area (EEA), United Kingdom (UK), Switzerland, and Canada, you have rights that allow you greater access to and control over your personal information.

In some regions (like the EEA, UK, Switzerland, and Canada), you have certain rights under applicable data protection laws. These may include the right (i) to request access and obtain a copy of your personal information, (ii) to request rectification or erasure; (iii) to restrict the processing of your personal information; (iv) if applicable, to data portability; and (v) not to be subject to automated decision-making.

Data Portability

You have the right to receive your personal data in a structured, commonly used, and machine-readable format (GDPR Article 20). Since we sync data from iOS HealthKit, you can export your raw health data directly from the iOS Health app at any time. For any additional data processed or created within our Services (such as workout analytics, aggregations, or custom settings), you may request an export by contacting us at [email protected].

Withdrawing Your Consent

You have the right to withdraw your consent to health data processing at any time. However, because processing your health data is the core function of Kiiro, withdrawing consent means we cannot continue to provide the Services. You can withdraw consent by:

  • Requesting account deletion: Contact us at [email protected] or use the in-app feature (Settings → Account → Request Deletion). We will process your request within 30 days.
  • Revoking HealthKit permissions: Go to iOS Settings → Privacy & Security → Health → Kiiro. This stops new data syncing but preserves your historical data on our servers until you request full account deletion.

Objecting to Analytics Processing

You have the right to object to our processing of behavioral analytics based on legitimate interest. To exercise this right, you can request account deletion by contacting us at [email protected] or using the in-app deletion feature (Settings → Account → Request Deletion). When you delete your account, all analytics data associated with your account will be permanently removed.

Account Information

If you would at any time like to review or change the information in your account or terminate your account, you can contact us using the contact information provided.

Upon your request to terminate your account, we will process your deletion request within 30 days and send you email confirmation once completed. We will permanently delete your account and all associated information from our active systems, including all health data, workout information, and personal details. Data may remain in encrypted backups for up to 6 months as described in Section 8.

To request account deletion, contact us at [email protected].

11. CONTROLS FOR DO-NOT-TRACK FEATURES

Most web browsers and some mobile operating systems and mobile applications include a Do-Not-Track ("DNT") feature or setting you can activate to signal your privacy preference not to have data about your online browsing activities monitored and collected. At this stage, no uniform technology standard for recognizing and implementing DNT signals has been finalized. As such, we do not currently respond to DNT browser signals or any other mechanism that automatically communicates your choice not to be tracked online.

12. DO UNITED STATES RESIDENTS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: If you are a resident of certain US states, you may have the right to request access to and receive details about the personal information we maintain about you and how we have processed it, correct inaccuracies, get a copy of, or delete your personal information.

Certain US state data protection laws give residents specific rights regarding their personal information. If you are a resident of California, Colorado, Connecticut, or other states with comprehensive privacy laws, you may have additional rights. Please contact us to exercise these rights.

13. DO OTHER REGIONS HAVE SPECIFIC PRIVACY RIGHTS?

In Short: You may have additional rights based on the country you reside in.

If you are located in Australia, New Zealand, South Africa, or other regions with specific privacy laws, you may have additional rights. At any time, you have the right to request access to or correction of your personal information. You can make such a request by contacting us using the contact details provided in this notice.

14. DO WE MAKE UPDATES TO THIS NOTICE?

In Short: Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this Privacy Notice from time to time. The updated version will be indicated by an updated "Last updated" date at the top of this Privacy Notice. If we make material changes to this Privacy Notice, we may notify you either by prominently posting a notice of such changes or by directly sending you a notification. We encourage you to review this Privacy Notice frequently to be informed of how we are protecting your information.

15. HOW CAN YOU CONTACT US ABOUT THIS NOTICE?

If you have questions or comments about this notice, you may email us at [email protected] or contact us by post at:

endurance101 OÜ

Härma 1-101

Tallinn 13615

Estonia

16. HOW CAN YOU REVIEW, UPDATE, OR DELETE THE DATA WE COLLECT FROM YOU?

Based on the applicable laws of your country or state of residence in the US, you may have the right to request access to the personal information we collect from you, details about how we have processed it, correct inaccuracies, or delete your personal information. You may also have the right to withdraw your consent to our processing of your personal information.

To request to review, update, or delete your personal information, please visit: https://endurance101.com/contact or email us at [email protected].