Privacy Policy
Last updated 8 June 2026
This Privacy Policy explains how koholo (“we”, “us”) collects, uses, and protects your information when you use our apps and website. By using koholo, you agree to the practices described here.
1. Information we collect
- Account details — your name, email address, and profile information (including whether you sign up as an individual or a trainer).
- Health & fitness data — workouts, nutrition logs, body metrics, progress photos, and check-ins you choose to record.
- Coaching data — if you connect with a trainer (or a client), the plans, messages, and check-ins shared between you as part of that relationship.
- Usage data — basic technical information such as device type, browser, and how you interact with the app, used to keep the service reliable and secure.
2. How we use your information
- To provide the core features of koholo — tracking workouts, nutrition, and progress, and connecting you with your trainer or clients.
- To personalise your experience, such as showing relevant plans, suggestions, and progress trends.
- To maintain the security and integrity of the platform, including authentication via Supabase and (where you choose) Apple or Google sign-in.
- To communicate with you about your account, such as confirmations, password resets, and important service updates.
3. How your data is shared
- Trainer–client relationships — if you connect with a trainer (or accept a client), certain data such as plans, check-ins, and progress may be visible to that person, governed by the permissions of that relationship.
- Service providers — we use Supabase for authentication, database, and storage. Your data is stored securely and is never sold to third parties.
- We do not share your personal or health data with advertisers, and we do not use your data to train external models.
4. Data storage & security
- Your data is stored with Supabase using row-level security, meaning only you (and, where applicable, your connected trainer or client) can access it.
- Progress photos are stored in a private bucket and accessed only via short-lived signed URLs.
- We use industry-standard practices to protect your data in transit and at rest, but no system can be guaranteed 100% secure.
5. Your choices & rights
- You can review and update your profile information at any time from Settings.
- You can disconnect a trainer–client relationship, which stops further data sharing between accounts.
- You can request a copy of your data or request that your account and associated data be deleted by contacting us (see below).
6. Cookies & sessions
- koholo uses essential cookies to keep you signed in and to keep your session secure across the web app. We do not use tracking or advertising cookies.
7. Changes to this policy
- We may update this policy from time to time as koholo evolves. If we make material changes, we will let you know in the app or by email before they take effect.
8. Contact us
- If you have questions about this Privacy Policy or how your data is handled, reach out to us at support@koholo.com.
See also our Terms & Conditions.
