EN·УКР

Privacy Policy

Last updated: 25 August 2026

This policy explains what data Fitkolo collects, why, who else sees it, and what control you have over it. Fitkolo is operated by Pavlo Yuriiovych Klymenko, a registered private entrepreneur (ФОП) in Ukraine, who is the data controller (“we”). Contact: support@fitkolo.com.

1. Data we collect

DataWhy we collect it
Email address and name (received from Google or Apple when you sign in), and the account identifier the provider gives usAccount creation and login. Apple sends your email address only the first time you sign in, so we also keep the identifier it gives us — otherwise we could not recognise your account when you sign in again
Display name, role (trainer/client), age, gender, languages, photos, intro video, specialties, experience, hourly and group ratesYour public profile shown to potential matches
“About you” free textShown on your profile. For clients the prompt asks about goals, fitness level and any injuries — see section 2
Location coordinates, search radius, and the city name derived from themShowing nearby trainers and clients, and the distance between you
Matches, chat messages, booking requests, availability and blocked-out hoursCore functioning of the service
Reports and blocks you submit, including your free-text descriptionSafety and moderation
Push notification token, device language and timezoneDelivering notifications, the right interface language, and correct booking times
Which screens you open and for how long, which controls you tap, how far you scroll, and your platform, operating-system major version, app version and interface languageAnonymous usage statistics, so we can see where signing up or filling in a profile goes wrong. Not connected to your account or your device, and you can switch it off — see below

You sign in with Google or Apple; Fitkolo has no password of its own. When you sign in, the provider confirms your identity and shares your email address and name with us — we never receive your Google or Apple password. With Sign in with Apple you may choose “Hide My Email”, in which case we receive a private relay address instead of your real one. Your use of these sign-in methods is also governed by Google's and Apple's privacy policies.

We do not collect payment details (Fitkolo processes no payments), we run no third-party analytics SDK and no advertising SDK in the app, and we do not sell your data or use it for third-party advertising. The usage statistics described next are collected by us, stored on our own servers, and given to nobody.

Usage statistics, and why they are not about you. To find out where the app is confusing — which step of signing up people give up on, which form takes too long — we record which screens are opened, how long each stays open, which controls are tapped and how far a screen is scrolled. Each record carries nothing but a session identifier that is created in memory when the app starts and destroyed when it closes: it is never written to your phone, never survives a restart, and cannot be joined to any earlier or later session. There is no account identifier, no device identifier, no advertising identifier and no IP address in these records, and nothing you have typed — the screen and control names come from a fixed list we wrote, which cannot contain a name, an address or anything else you entered.

Because nothing in them identifies a person or a device, we cannot tell you which records are “yours”, and neither can anybody else. You can switch the whole thing off at any time in Settings → “Help improve Fitkolo”, after which the app records nothing at all. These records are kept for 90 days and then deleted.

2. Health information

A client's “About you” prompt invites you to describe your goals, your fitness level and any injuries. Anything you write there about your body or your health is health data — a special category under Article 9 of the GDPR — and it is treated as such.

3. Legal bases

Under the GDPR we rely on: contract (Article 6(1)(b)) for your account, profile, matching, chat and bookings — these are the service itself; legitimate interests (Article 6(1)(f)) for safety, moderation, preventing abuse, and the anonymous usage statistics described in section 1; consent for your device location, push notifications and health information, each of which you grant and can withdraw separately; and legal obligation where the law requires us to keep or disclose something.

4. Who else receives your data

We use a small number of outside services. They receive only what is listed here.

RecipientWhat reaches themWhy
Hostinger (Lithuania, EU)Your account, profile, messages and bookings, as our hosting provider; and the address we email, for account and waitlist messagesServers and email delivery
Cloudflare — R2 object storageThe photos and video you upload. Cloudflare stores them in its global network, which is not limited to the EU; they are served only through short-lived signed linksStoring and serving your photos and video
Google — Firebase Cloud MessagingYour device's notification token, and the contents of each notification: the sender's name and the first 100 characters of a chat message, or the fact that a booking was requested, confirmed, declined or cancelledDelivering push notifications to your phone. On iPhones the notification is passed to Apple's push service for the final delivery. This is what lets a message preview appear on your lock screen
Google / AppleThe sign-in token your device presents, which we verify with themConfirming it is really you signing in
OpenStreetMap Foundation — map images and place namesWhen you open the map to place your pin, your device asks them for the map images, so your IP address and the part of the map you are looking at reach them. When the app turns a position into a city name it sends your coordinates rounded to roughly 110 m. Both go straight from your device, never through our serverDrawing the map you choose your location on, and naming the place you picked so you can check it is right
TelegramAn operational alert to a private moderation channel when someone signs up, activates a profile, changes the photos, video, bio or display name on a profile that is already visible to others, joins the waitlist, or is reported. It carries the person's display name and email address, and for a change of display name the previous one; for a waitlist entry, the email, platform, language and any social handle given; and for a report also the reason, the reporter's name and what they wroteSo that new, edited and reported profiles are reviewed promptly
Google FontsWebsite only — your browser's IP address and user agent when you load a page on fitkolo.com. The app does not use itWeb page typefaces

Google and Apple may process data outside the EU/EEA under their own safeguards (standard contractual clauses). Telegram Messenger and the OpenStreetMap Foundation likewise operate internationally. Our own servers are in the EU; our backups are not — see section 6.

Links out are not on that list, on purpose. Settings offers our Instagram and Threads accounts beside the support address, and a chat message or a session link may point anywhere. Tapping one hands the address to your browser or to that company's app, exactly as a link in an email would — we send them nothing about you, which is why Meta is not a recipient above. From that moment you are on their site, under their privacy policy and not this one.

5. Who can see what inside the app

6. Where data lives, and what leaves the EU

Fitkolo is operated from Ukraine. Your account, profile, messages and bookings are stored on servers in the European Union (Lithuania), operated for us by Hostinger. Your photos and video are stored by Cloudflare in its global network, which may place copies outside the EU/EEA; Cloudflare is bound by its data processing addendum and the EU standard contractual clauses.

Backups leave the EU. Every night a copy of the database and of all uploaded photos and video is pulled to hardware we run ourselves in Ukraine, and fourteen nights are kept. Ukraine is outside the EU/EEA, and the European Commission has not adopted an adequacy decision for it — so if you are in the EU/EEA, this is a transfer of your data to a third country, and you should know about it before you decide to use Fitkolo. What protects those copies is that the database in them is encrypted before it ever leaves our servers, with a key kept on none of that hardware; that the hardware is ours alone and nothing on the internet can reach it; and that a copy is discarded after fourteen nights. Deleting your account removes your data from the live service immediately and from those copies within fourteen days.

7. Retention and deletion

Data is kept while your account is active. Deleting your account (Settings → Delete account) takes effect immediately: your profile fields, email address, photos and video are removed, and your user record is anonymised. Message history is retained in anonymised form so that the other person's conversation stays intact — a chat is a record of an arrangement between two people, and deleting one side's copy would destroy the other's.

If you no longer have the app installed you can still have your account deleted by writing to us. Delete your account sets out both routes, and exactly what is removed and what is kept.

The anonymous usage statistics in section 1 are kept for 90 days and then deleted. They are the one thing deleting your account does not touch, and cannot: they are not linked to your account, so there is nothing in them to find and remove — which is also why they can never be traced back to you.

Backups are taken nightly and 14 nights are kept, so anything deleted disappears from our backups within 14 days. Operational alerts already delivered to the moderation channel (section 4) are not retro-actively deleted; they contain names and email addresses, and for a report also what the reporter wrote.

8. Your rights

You can access and edit your profile data in the app at any time. You may request a copy of your data, or its correction or erasure, by writing to support@fitkolo.com. If you are in the EU/EEA these rights follow the GDPR — access, rectification, erasure, restriction, portability, objection, and the right to withdraw a consent you have given — and you may lodge a complaint with your local supervisory authority.

9. Security

All traffic between the app and our servers is TLS-encrypted. We store no passwords — sign-in is delegated to Google and Apple. Photos and video are not publicly listed; the app reaches them through signed links that expire, issued to signed-in users allowed to see that profile — or, for a trainer's own share link, to anyone who opens it. Anyone given one of those links can open it until it expires, so treat a copied photo link as you would the photo. The copy of the database in our backups is encrypted before it leaves our servers, with a key that is not held on the machine that stores it; access to all backups is restricted.

10. The website and the waitlist

fitkolo.com sets no cookies and runs no analytics. If you join the trainer waitlist we store the email address you enter, whether you chose Android or iPhone, an optional social handle and the page language, and we use them only to invite you to sign up as a trainer. Ask us at support@fitkolo.com and we will remove you.

11. Children

You must be 18 or older to use Fitkolo. The app does not accept an age below 18, and we do not knowingly collect data from anyone under 18.

12. Changes

We may update this policy as the Service evolves; material changes will be announced in the app or by email. The date above always reflects the current version.