Kallo Train Together
Privacy
Policy
How Kallo collects, uses, and protects your data — from workout plans to identity verification to partner matching.
— Document Details —
Effective DateJuly 23, 2026
Version1.0
ScopeGlobal — 18+
LanguageEnglish (controlling)
Contactservice@kallo.app
Welcome to Kallo — a global fitness platform where you can build personalized workout plans, share your fitness results with the community, and find training partners to complete the same program together. Because Kallo connects real people around shared fitness goals — including in-person training — we require identity verification before you can publicly share fitness results or use our partner-matching feature. This Privacy Policy ("Policy") describes how Kallo ("we," "our," or "us") collects, uses, stores, shares, and protects your personal information when you use our mobile application and all related services (the "Service"). By using Kallo, you agree to this Policy. If you do not agree, please discontinue use of the Service.
01
Information We Collect
1.1 — Account & Profile Information

When you create a Kallo account, we collect the information you voluntarily provide: your display name, email address, date of birth (to verify you are 18 years of age or older), profile photo, country of residence, fitness goals, and any personal bio you choose to write. If you register via Apple Sign-In or Google, we receive a limited profile dataset authorized by you and that provider.

1.2 — Identity Verification Data

To share fitness results publicly or use partner matching, you must complete identity verification. This involves submitting a photo and taking a live comparison photo for facial matching, processed as described in Section 3.

1.3 — Workout Plan Data

We collect the workout plans you build or select, including exercises, sets, reps, weights, duration, rest intervals, scheduling, and plan templates you save or customize.

1.4 — Fitness Results & Body Metrics

Where you choose to log or share them, we collect fitness results and body metrics: progress photos, weight, body measurements, personal records (PRs), completed workouts, and achievement badges. This data may be considered sensitive in certain jurisdictions; see Sections 17–19.

1.5 — Partner Matching Data

If you use the partner-matching feature, we collect your matching preferences (target plan, availability, training level), city-level location, and messages you exchange with matched partners within the app.

1.6 — Device & Technical Information

We automatically collect device model, operating system version, unique device identifiers, IP address, mobile carrier, app version, crash logs, and performance diagnostics to maintain service quality and diagnose technical issues.

1.7 — Usage & Behavioral Data

We record how you use the Service: workouts logged, features accessed, plans followed, search queries, and session frequency and duration. This data informs product improvements and optional personalization.

1.8 — User-Generated Content

Posts, comments, fitness result shares, photos, and other content you make public constitute User-Generated Content (UGC). See Section 7 for full details.

1.9 — Communications & Support Data

If you contact our support team, submit a report, or participate in surveys, we retain the content and metadata of those communications for resolution and service improvement purposes.

1.10 — Payment & Transaction Data

All payments are processed exclusively by Apple App Store or Google Play. We do not store your payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data to activate in-app premium features.

02
How We Use Your Data
2.1 — Operating the Service

We use your information to authenticate your account, deliver the plan-building and tracking experience, operate community and matching features, enforce content policies, process purchases, and provide all core Service functions.

2.2 — Identity Verification & Safety

We use verification photos and their comparison results to confirm you are a real, unique individual before granting access to fitness-results sharing and partner matching, and to detect duplicate or fraudulent accounts. See Section 3.

2.3 — Workout Plan Delivery

Your logged workout data and preferences power plan recommendations, progress tracking, and personal record calculations.

2.4 — Partner Matching

Your matching preferences, city-level location, and plan selection are used to suggest compatible training partners pursuing the same or similar programs.

2.5 — Community & Discovery

Where you choose to share fitness results publicly, your submitted content populates community feeds and enables discovery by other users.

2.6 — Personalization

Your training history, viewing patterns, and preferences are used to personalize plan suggestions, community content, and partner recommendations. See Section 9.

2.7 — Safety & Platform Integrity

We process behavioral signals, verification status, and user reports to detect and prevent prohibited content, harassment, impersonation, and policy violations.

2.8 — Product Improvement

Aggregated and de-identified usage data is analyzed to improve plan recommendations, matching accuracy, and overall platform performance.

2.9 — Marketing & Communications

With your consent where required by applicable law, we may send promotional communications about new plan templates, features, and platform offers. You may withdraw consent at any time via in-app settings or the unsubscribe link in any email.

2.10 — Legal Compliance

We process personal data as necessary to comply with applicable laws, respond to valid legal process, enforce our Terms of Service, and protect the safety of our users and the public.

03
Identity Verification
3.1 — Why Verification Is Required

Kallo connects real people for real, often in-person, training. To protect our community, you must complete identity verification before you can share fitness results publicly or access the workout partner-matching feature. Building and following private workout plans does not require verification.

3.2 — What We Collect

The verification flow collects: (a) a photo you submit; and (b) a live comparison photo ("selfie") captured at the moment of verification, used to confirm the two images depict the same person. We also generate and store a verification outcome (verified / not verified) associated with your account.

3.3 — Third-Party Verification Processor

Verification is performed with the assistance of a specialized third-party identity verification vendor operating under a data processing agreement. The vendor processes your verification images solely to perform the comparison and is contractually prohibited from using your images for any other purpose, including training its own facial recognition models beyond what is necessary to deliver the verification service to us.

3.4 — Biometric & Sensitive Data Treatment
Facial comparison involves processing of biometric-adjacent data, which may be treated as a special category of personal data under laws such as the EU/UK GDPR, or as "sensitive personal information" under laws such as the CCPA/CPRA. Where required, we obtain your explicit, opt-in consent before performing identity verification. You may decline verification; declining means you will not be able to share fitness results publicly or use partner matching, but you may continue to use Kallo's private plan-building and tracking features.
3.5 — Retention of Verification Images

Raw verification and comparison photos are retained only as long as necessary to complete and audit the verification process, and are deleted within 30 days of a successful verification. We retain only the resulting verification status (verified/not verified) associated with your account thereafter, not the underlying images.

3.6 — Re-Verification

We may require re-verification periodically or if we detect signals suggesting your account may have been compromised, transferred, or associated with suspicious activity.

3.7 — Consequences of Declining or Failing Verification

If you decline verification or do not pass it, you will not be able to publicly share fitness results or use the partner-matching feature. Core plan-building and private tracking functionality remain available regardless of verification status.

04
Workout Plans & Fitness Data
4.1 — Your Plans Belong to You

Workout plans you build or customize in Kallo are yours. We store your plan data on our servers solely to deliver the plan-building and tracking experience across devices. We do not sell your individual plan data to third parties.

4.2 — Storage & Sync

Your plans, logged workouts, and progress data are stored on our secure cloud infrastructure and synced across your devices associated with your account.

4.3 — Plan Sharing & Templates

Where you choose to publish a plan as a public template for others to follow, the plan structure (exercises, sets, reps, schedule) becomes visible to other users; your personal logged performance data within that plan remains private unless you separately choose to share it.

4.4 — Health Metric Sensitivity

Body metrics (weight, measurements, body composition) you optionally log are used only to personalize your own plan suggestions and progress tracking. This data is not shared with other users or third parties without your explicit action to make it public.

05
Fitness Results & Sharing
5.1 — What Counts as Fitness Results

Fitness results include progress photos, before/after comparisons, personal records, completed workout summaries, and achievement milestones you choose to publish to the community.

5.2 — Verification Required Before Sharing

You must complete identity verification (Section 3) before your account can publish fitness results publicly. This helps ensure that shared results and achievements on Kallo come from real, verified community members.

5.3 — Visibility Controls

Each fitness result can be set to Private (visible only to you), Followers Only, or Public. Results are Private by default; publishing is always an explicit choice you make, and you may change visibility at any time.

5.4 — Content Standards

Shared results remain subject to our Community Guidelines and content moderation, including prohibitions on misleading before/after claims and deceptive supplement or product promotion — see the Terms of Service for full details.

06
Workout Partner Matching
6.1 — How Matching Works

Kallo's partner-matching feature suggests other verified users pursuing the same or a similar workout plan, based on your stated preferences, training level, and city-level location.

6.2 — Verification Required

Only identity-verified users may access or appear in partner matching, as described in Section 3. This is a core safety measure given that partner matching may lead to in-person training.

6.3 — Location Data Use

For matching purposes, we use city-level (not precise GPS) location. Your exact real-time location is never shared with other users through the matching feature.

6.4 — In-App Messaging

Messages exchanged with matched partners within Kallo are stored to enable the conversation feature, support moderation, and allow reporting of abuse. See Section 12 for retention details.

6.5 — No Guarantee of Compatibility or Safety

Identity verification confirms that a user is a real, verified individual; it is not a criminal background check and does not guarantee the safety, compatibility, or conduct of any matched partner. See the Terms of Service, Section 8, for important safety information about in-person meetings.

07
User-Generated Content
7.1 — Collection & Storage

Fitness result posts, progress photos, comments, and community posts you publish publicly constitute User-Generated Content (UGC). UGC is stored on our secure cloud servers associated with your account.

7.2 — License Grant

By publishing UGC publicly on Kallo, you grant us a non-exclusive, worldwide, royalty-free, sublicensable license to host, store, reproduce, display, and distribute your content within the Service and in connection with promoting Kallo, subject to your visibility settings. You retain full ownership of your original content.

7.3 — Content Moderation

Community-shared UGC is subject to automated screening and human review for compliance with our Community Guidelines. Content that violates our policies will be removed, and responsible accounts may face suspension or termination.

7.4 — Content Deletion

You may delete any published result or UGC at any time. Deleted content is removed from public view within 48 hours, from production servers within 30 days, and from backup archives within 90 days.

08
Community Features
8.1 — Community Feed

Public fitness results appear in Kallo's community feed for other users to discover and be inspired by. Public entries include your display name, the shared content, and reactions or comments from other users.

8.2 — Reactions & Comments

Other users may react to or comment on your public results. Comments are associated with the commenter's display name and are visible to all viewers. You may moderate and delete comments on your own posts at any time.

8.3 — Following

You may follow other users whose training resonates with you. Follower relationships are visible in your profile activity unless you set your profile to private.

8.4 — Reporting & Blocking

You may report or block any user or content at any time. Reports are reviewed by our safety team, and your identity as the reporting user is kept confidential from the reported party.

09
Personalization Engine
9.1 — How It Works

Kallo uses your training history, logged results, preferences, and engagement signals to personalize plan suggestions, community content, and potential training partners.

9.2 — No External Advertising Use

Your fitness data, body metrics, and behavioral signals are not used to build an advertising profile or shared with supplement brands, gyms, or third-party advertising networks without your explicit consent.

9.3 — Opting Out

You may disable personalized recommendations at any time in Settings > Privacy > Personalization. Kallo will then present a non-personalized, editorially curated experience.

10
Sharing & Disclosure
10.1 — Service Providers

We share personal information with trusted third-party service providers supporting our operations: cloud infrastructure providers, CDN services, the identity verification vendor described in Section 3, payment processors, analytics platforms, customer support tools, and content moderation systems. All providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.

10.2 — No Sale of Personal Data

We do not sell your personal information, verification images, body metrics, or fitness data to any third party, including advertisers, supplement brands, or data brokers.

10.3 — Business Transfers

In the event of a merger, acquisition, or asset sale, your data may transfer to the acquiring entity. We will notify you in advance before your data becomes subject to a materially different privacy policy, giving you the opportunity to request account deletion.

10.4 — Legal Disclosure

We may disclose your information to law enforcement or government authorities when required by applicable law, valid legal process, or where necessary to protect the safety of any person. Where legally permitted, we will notify affected users prior to such disclosure.

10.5 — Publicly Visible Content

Your display name, profile photo, and publicly shared fitness results are visible to all Kallo users. You may set your profile or individual results to private in account settings at any time.

11
Third-Party Services & SDKs
11.1 — Identity Verification Vendor

As described in Section 3, we use a specialized third-party vendor to process verification photos. This vendor operates under strict data processing agreements limiting use of your images to the verification purpose.

11.2 — Analytics SDKs

Mobile analytics SDKs measure app performance and feature engagement, configured with privacy-preserving settings including anonymized event collection and suppression of advertising identifiers absent your consent.

11.3 — Cloud Storage & CDN

Progress photos and other media are stored on cloud infrastructure and delivered via CDN providers to ensure fast, reliable loading, under data processing agreements.

11.4 — Authentication Providers

Apple Sign-In and Google authentication are governed by their own terms and privacy policies. Our use of data from these services is limited to account creation and basic profile population.

12
Data Retention
12.1 — Active Account Data

We retain your personal information for as long as your account is active. Accounts with no login activity for 24 consecutive months will receive a dormancy notice; following the notice period, inactive data may be anonymized or deleted.

12.2 — Verification Images

As described in Section 3.5, raw verification and comparison photos are deleted within 30 days of successful verification. Only the resulting verification status is retained thereafter.

12.3 — Fitness & Plan Data

Your workout plans, logged results, and progress data are retained for the life of your account. You may delete individual entries or your entire history at any time.

12.4 — Matching Messages

In-app messages with matched partners are retained for the life of your account or until you delete them, whichever is earlier, except where retained longer for safety investigations or legal compliance.

12.5 — Transaction Records

Financial transaction records are retained for a minimum of seven years to comply with applicable accounting, tax, and consumer protection obligations.

12.6 — Safety & Moderation Records

Records of content moderation actions, user reports, and enforcement decisions are retained for up to 36 months after account closure.

13
Data Security
13.1 — Technical Safeguards

We implement TLS 1.2+ encryption for all data in transit, AES-256 encryption for sensitive data at rest (including verification images during their limited retention period), strict role-based access controls, and automated anomaly detection.

13.2 — Organizational Safeguards

Data access is restricted on a need-to-know basis, requires multi-factor authentication, and is comprehensively audit-logged. Personnel with access to verification data receive specialized training and sign confidentiality agreements.

13.3 — Vulnerability Management

We conduct regular security assessments and third-party penetration testing. Report security vulnerabilities responsibly to service@kallo.app.

13.4 — Breach Notification

In the event of a personal data breach posing risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours where required by law and inform affected users without undue delay.

14
Tracking Technologies
14.1 — In-App Technologies

Kallo uses session tokens, local storage, and analytics SDKs (not traditional browser cookies) to maintain your authenticated session, remember preferences, and sync your training data across devices.

14.2 — Advertising Identifiers

On iOS, we request ATT consent before accessing your IDFA. On Android, we respect your opt-out via device advertising settings. Advertising identifiers are used only to measure our own user acquisition campaigns.

14.3 — Web Properties

Our website may use standard browser cookies for session management and analytics, manageable via your browser settings.

15
Cross-Border Transfers
15.1 — Global Infrastructure

Kallo serves a global community and operates cloud infrastructure across multiple regions. Your personal data may be transferred to and processed in countries other than your country of residence.

15.2 — Transfer Safeguards

For transfers from the EEA, UK, or Switzerland to countries lacking an adequacy decision, we rely on EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA). Equivalent safeguards apply to other cross-border transfers, including for verification data processed by our identity verification vendor.

15.3 — Data Localization

Where applicable national laws impose mandatory data localization requirements, we take reasonable steps to store and process the required data categories within the mandated territory.

16
Your Privacy Rights
16.1 — Access

Request a copy of personal data we hold, including your fitness data and verification status, via in-app settings or by emailing service@kallo.app with subject "Data Access Request."

16.2 — Rectification

Correct inaccurate personal information directly in account settings. For data that cannot be self-corrected, contact us and we will action the correction within 30 days.

16.3 — Erasure

Request deletion via Settings > Account > Delete Account or by emailing us. See Section 22 for full account deletion details.

16.4 — Portability

Request your fitness data and personal data in a structured, machine-readable format suitable for personal archiving or transfer to another platform.

16.5 — Objection & Restriction

Object to or request restriction of processing in certain circumstances, including processing of verification data. We pause relevant processing while assessing your objection.

16.6 — Consent Withdrawal

Withdraw consent for identity verification, marketing, or personalization at any time via in-app settings or by contacting us. Withdrawing verification consent will disable public result sharing and partner matching going forward.

16.7 — How to Submit

Email service@kallo.app with "Privacy Rights Request" in the subject, your registered email, and a description of your request. We verify your identity and respond within applicable legal timeframes.

17
GDPR — EEA & UK Users
17.1 — Data Controller

For EEA and UK users, Kallo acts as the data controller of your personal information under the GDPR and UK GDPR respectively.

17.2 — Legal Bases

We process your data under: (a) contractual necessity (to provide the Service); (b) legal obligation (regulatory compliance); (c) legitimate interests (safety, service improvement, fraud prevention), where not overridden by your rights; and (d) consent (for marketing, optional personalization, and identity verification, which involves special category biometric-adjacent data under Article 9 and requires your explicit consent).

17.3 — Supervisory Authority

You may lodge a complaint with your national data protection supervisory authority if you believe your data has not been handled lawfully. We encourage you to contact us first to attempt direct resolution.

18
CCPA / CPRA — California
18.1 — California Rights

California residents have rights under the CCPA as amended by the CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information, and additional rights regarding sensitive personal information (which may include your verification images and health/fitness data). Kallo does not sell personal information and does not share it for cross-context behavioral advertising.

18.2 — Non-Discrimination

Exercising your California privacy rights will not result in denial of services, different pricing, or reduced quality of experience.

18.3 — Authorized Agents

California residents may designate an authorized agent by providing written proof of authorization. We verify both agent and resident identity before processing any request.

19
Brazil — LGPD
19.1 — Rights Under LGPD

Brazilian users have rights under the Lei Geral de Proteção de Dados (LGPD) including confirmation, access, correction, anonymization, deletion, portability, and withdrawal of consent — including consent for the processing of sensitive personal data under Article 11, such as identity verification data.

19.2 — Legal Bases

We process Brazilian users' data based on contract performance, legal obligation, and consent where applicable, including explicit consent for identity verification.

19.3 — ANPD Complaints

Brazilian users may lodge complaints with the Autoridade Nacional de Proteção de Dados (ANPD) where they believe data processing violates the LGPD.

20
Children's Privacy & CSAE Policy
20.1 — Age Restriction

Kallo is designed for users who are 18 years of age or older. We implement date-of-birth verification at registration, and our identity verification process for results-sharing and partner matching provides an additional safeguard. Confirmed underage accounts are immediately and permanently terminated with all associated data deleted.

20.2 — Parental Notification

If you are a parent or guardian and believe a minor has created a Kallo account, contact us immediately at service@kallo.app. We will investigate and, where confirmed, permanently delete the account and all associated data without delay.

20.3 — Child Sexual Abuse and Exploitation (CSAE)
Zero tolerance — absolute and without exception. Kallo enforces an unconditional zero-tolerance policy toward any content, conduct, or activity that constitutes, facilitates, promotes, or glorifies Child Sexual Abuse and Exploitation (CSAE) in any form. Prohibited conduct includes without limitation: child sexual abuse material (CSAM); grooming, solicitation, or exploitation of individuals under 18; and any content depicting, targeting, or endangering persons under 18.

We deploy automated CSAM hash-matching on all uploaded media, AI-assisted content analysis on community posts, and dedicated human safety reviewers. Upon confirmed detection or credible report: all associated content is immediately and permanently removed; the responsible account is permanently terminated and all associated identifiers are blocked; a mandatory report is filed with the NCMEC CyberTipline or the legally required equivalent national authority; and we cooperate fully with all resulting law enforcement investigations. CSAE-related terminations carry no right of appeal.

To report: use the in-app Report function on any content or user profile, or email service@kallo.app immediately with subject "CSAE Report."
21
In-App Purchases
21.1 — Payment Processing

All in-app purchases are processed exclusively through Apple App Store or Google Play. Kallo does not store your payment card details. We receive only anonymized transaction confirmation tokens and entitlement data to activate premium features.

21.2 — Premium Features

If Kallo offers premium features (such as advanced plan templates, detailed analytics, or expanded matching filters): access is non-transferable between accounts; non-refundable except as required by applicable law or app store policy; and may be forfeited upon account termination for cause.

21.3 — Transaction Records

Transaction records are retained for a minimum of seven years to satisfy applicable accounting, tax, and consumer protection requirements.

22
Account Deletion & Data Erasure
22.1 — How to Delete

Delete your account at any time via Settings > Account > Delete Account, or by emailing service@kallo.app with subject "Account Deletion Request."

22.2 — What Is Deleted

Your profile, workout plans, fitness results, community posts, matching data, messages, and all associated data are removed from public view within 48 hours and from production servers within 30 days. Backup archives are purged within 90 days of the next scheduled rotation. Any residual verification images (already subject to the 30-day deletion in Section 3.5) are confirmed deleted if not already removed.

22.3 — Export Before Deletion
We encourage you to export your training history and fitness data before deleting your account, as deletion is permanent. You can export your data from Settings > Data > Export.
22.4 — Retained Data

Certain data is retained where required by law: transaction records (up to 7 years); safety and moderation records (up to 3 years); data subject to a legal hold. All retained data is isolated and processed only for the specific legal purpose requiring its retention.

23
Policy Updates
23.1 — Notification

Material changes are communicated at least 14 days before taking effect via in-app notice, push notification, and/or email to your registered address. Non-material corrections may be made without advance notice.

23.2 — Continued Use

Continued use of Kallo after any revised Policy's effective date constitutes acceptance. If you do not agree, delete your account before the changes take effect.

23.3 — Version Archive

Prior versions are available upon request at service@kallo.app.

24
Contact Us
24.1 — Privacy Inquiries

For questions, data rights requests, or privacy concerns:

We acknowledge inquiries within 5 business days and respond within 30 days.

24.2 — CSAE & Child Safety Reports

Use the in-app Report function on any content or user profile, or email service@kallo.app immediately with subject "CSAE Report." These are our highest-priority safety matter, actioned without delay.

© 2026 Kallo. All rights reserved. Privacy Policy · Version 1.0 · July 23, 2026