Privacy Policy
Official Privacy Policy for Kratos — detailing data collection, processing, third-party disclosures, security protocols, user rights, and Google Play Console compliance.
Package ID: app.kratos.strength
1. Overview & Data Controller Identification
This Privacy Policy ("Policy") governs the processing of personal data collected through the Kratos mobile application (Google Play Package ID: app.kratos.strength), the progressive web application, and associated online services operating under https://kratos.mudoker.com (collectively, the "Service" or "Application"), operated and developed by the Kratos development team ("Kratos", "we", "us", or "our").
We are committed to full compliance with applicable data protection legislation worldwide, including the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the Children's Online Privacy Protection Act (COPPA), and the Google Play Developer Distribution Agreement and User Data Policies.
For questions, data subject requests, or regulatory inquiries, the Data Protection Contact can be reached at: huuquoc7603@gmail.com.
2. Categories of Information Collected & Processed
We collect and process only the minimal categories of data necessary to provide personalized strength training routines, progressive overload computation, biometric workload analysis, and artificial intelligence coaching features:
2.1 Account & Identity Information
- •OAuth Authentication Data: When you sign in via Google OAuth or federated authentication services, we collect your verified email address, display name, user identifier (UID), and profile picture URL.
- •Security Session Credentials: Cryptographic session cookies and authentication tokens necessary to maintain secure access across client sessions.
2.2 Biometric, Physical & Training Profile Data
- •Anthropometric Attributes: Self-reported chronological age, body weight, height, and biological/anatomical model selection (used exclusively to calculate body mass index (BMI), relative power-to-weight ratios, and metabolic expenditure estimates).
- •Athletic Parameters: Stated fitness goal (e.g., Maximum Strength, Hypertrophy, Powerlifting), training experience tier (Beginner, Intermediate, Advanced), baseline sleep duration, and scheduled weekly training frequency.
- •Non-Clinical Health & Injury Notes (Optional): Voluntary, user-entered non-diagnostic notes concerning physical discomfort or joint limitations (e.g., knee sensitivity, shoulder impingement), processed strictly to filter incompatible exercise movements.
2.3 Workout Execution & Athletic Performance Logs
- •Training Session Records: Specific exercise movements, sets completed, repetition counts, resistance load (weight), Rate of Perceived Exertion (RPE), rest period durations, and precise session timestamps.
- •Personal Records (PRs): Calculated One-Repetition Maximums (1RM), volume tonnage records, and historic progression trends.
- •Custom Programs & Workout Splits: User-authored or AI-generated multi-day periodization splits and exercise templates.
2.4 Artificial Intelligence Prompts & Interactions
- •AI Coach Messages: Prompt text and conversational inquiries submitted to the AI Coach interface for workout planning and technical advice.
- •Client-Side API Key Storage: When you provide a custom Google Gemini API Key, it is encrypted and persisted locally within your client browser's local sandbox storage (localStorage) and is never transmitted to or retained in our backend database.
2.5 Device & Diagnostic Telemetry
- •Technical Metadata: Device operating system version, browser user-agent string, client application version, screen resolution, and anonymized performance diagnostic logs used strictly to ensure application stability, prevent crashes, and resolve runtime errors.
3. Legal Bases for Data Processing (GDPR Compliance)
Under GDPR Article 6 and Article 9, we process personal information pursuant to the following lawful grounds:
• Performance of a Contract (Art. 6(1)(b)): Processing account credentials, workout metrics, and profile data to deliver core strength logging, progressive overload calculations, and synchronized workout routines as requested by the user.
• Legitimate Interests (Art. 6(1)(f)): Ensuring network and information security, authenticating authorized users, debugging application faults, and optimizing user experience.
• Explicit Consent (Art. 6(1)(a) & Art. 9(2)(a)): Where you voluntarily enter optional health notes, injury history, or request generative AI coaching adaptations based on personal biometric inputs.
• Compliance with Legal Obligations (Art. 6(1)(c)): Retaining minimal records as strictly required to demonstrate compliance with consumer protection and privacy statutes.
4. Third-Party Data Processors & Infrastructure Providers
We do not sell, rent, lease, or monetize your personal data. We do not engage in cross-context behavioral advertising or share information with third-party data brokers. Data is processed only through trusted infrastructure providers subject to binding Data Processing Agreements (DPAs):
Authorized Sub-Processors
- •Neon Serverless PostgreSQL (Neon, Inc.): Encrypted relational database hosting with data storage located in secure, SOC 2 Type II and ISO 27001 certified data center facilities.
- •Vercel Inc.: Application delivery network and serverless runtime infrastructure providing TLS encryption and high-availability application hosting.
- •Google Cloud Platform & Google AI: Google OAuth for identity authentication and Google Gemini APIs for generative artificial intelligence strength coaching calculations.
- •Local Client Sandbox: Personal API tokens and theme preferences are stored exclusively on your device's client storage.
5. Information Security & Technical Safeguards
We implement comprehensive technical, administrative, and physical security measures to safeguard user data:
• Cryptographic Transit Encryption: All network communications between client devices and servers are strictly enforced via Transport Layer Security (TLS 1.3 / HTTPS) with HTTP Strict Transport Security (HSTS).
• Encryption at Rest: Database volumes and athlete record storage utilize industry-standard AES-256 cryptographic encryption at rest.
• Session Protection: Authentication tokens are generated with secure, HTTP-only, SameSite cookie configurations to prevent Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF).
• Local Sandbox Isolation: User-supplied Gemini API keys reside in browser client sandbox memory, isolated from third-party scripts.
• Principle of Least Privilege: Backend administrative access is strictly restricted, authenticated via multi-factor authentication (MFA), and regularly audited.
6. Data Retention, User Rights & Account Deletion Protocol
In accordance with Google Play Developer User Data Policies and international privacy statutes (GDPR, CCPA), you hold full authority over your data:
• Right to Access & Data Portability: You may view your complete workout logs, PR milestones, and profile data directly within the application at any time.
• Right to Rectification: You may update or correct your physical profile, workout metrics, and preferences through in-app settings.
• Right to Permanent Deletion: You have the right to request full, irreversible erasure of your user account, profile, workout history, and personal records.
• In-App Deletion Execution: Users can initiate account erasure via Settings -> App Info / Account -> Request Account & Data Deletion.
• Web / Email Deletion Request: Users may submit a verified deletion request without logging in by visiting https://kratos.mudoker.com/data-deletion or emailing huuquoc7603@gmail.com.
• Processing Timeline: Upon verified receipt, all active database records are permanently deleted immediately or within a maximum of 30 calendar days. Automated encrypted disaster-recovery backup snapshots are purged pursuant to a standard 30-day rotation cycle.
7. Protection of Children's Privacy (COPPA / GDPR Notice)
Kratos is strictly designed for adults and individuals possessing the legal capacity to engage in progressive resistance exercise. The Application is NOT directed to, nor do we knowingly collect or solicit personal information from, children under 13 years of age (or under 16 years of age for residents of the European Economic Area / UK).
If we obtain actual knowledge that personal data of a minor under these age limits has been collected without verifiable parental consent, we will take immediate operational steps to expunge such data and terminate the corresponding account. If you believe a minor has provided us with personal information, please alert us immediately at huuquoc7603@gmail.com.
8. California Privacy Rights (CCPA / CPRA Notice)
For California residents, pursuant to the California Consumer Privacy Act as amended by the CPRA:
• We do NOT sell your personal information or share it for cross-context behavioral advertising.
• We do not process sensitive personal information for purposes other than providing the requested training services.
• You possess the right to know, access, correct, and delete personal data held by Kratos without receiving discriminatory treatment.
• Exercise your California privacy rights by contacting huuquoc7603@gmail.com.
9. Policy Revisions & Notification of Changes
We reserve the right to amend this Privacy Policy periodically to reflect technological advancements, service enhancements, statutory developments, or Google Play Console policy revisions. When amendments are enacted, the 'Last Updated' date at the top of this document will be updated. For material alterations, prominent in-app notification will be provided prior to the effective date.
10. Contact & Privacy Inquiries
For all privacy inquiries, data subject access requests, account deletion demands, or regulatory compliance questions, please contact:
• Primary Developer & Privacy Contact: huuquoc7603@gmail.com
• Application: Kratos — Strength Training & AI Coach
• Host URL: https://kratos.mudoker.com
For official inquiries or to exercise your rights under GDPR, CCPA, or Google Play policies, please contact our privacy compliance representative at huuquoc7603@gmail.com.