When you create a Kallo account, we collect the information you voluntarily provide: your display name, email address, date of birth (to verify you are 18 years of age or older), profile photo, country of residence, fitness goals, and any personal bio you choose to write. If you register via Apple Sign-In or Google, we receive a limited profile dataset authorized by you and that provider.
To share fitness results publicly or use partner matching, you must complete identity verification. This involves submitting a photo and taking a live comparison photo for facial matching, processed as described in Section 3.
We collect the workout plans you build or select, including exercises, sets, reps, weights, duration, rest intervals, scheduling, and plan templates you save or customize.
Where you choose to log or share them, we collect fitness results and body metrics: progress photos, weight, body measurements, personal records (PRs), completed workouts, and achievement badges. This data may be considered sensitive in certain jurisdictions; see Sections 17–19.
If you use the partner-matching feature, we collect your matching preferences (target plan, availability, training level), city-level location, and messages you exchange with matched partners within the app.
We automatically collect device model, operating system version, unique device identifiers, IP address, mobile carrier, app version, crash logs, and performance diagnostics to maintain service quality and diagnose technical issues.
We record how you use the Service: workouts logged, features accessed, plans followed, search queries, and session frequency and duration. This data informs product improvements and optional personalization.
Posts, comments, fitness result shares, photos, and other content you make public constitute User-Generated Content (UGC). See Section 7 for full details.
If you contact our support team, submit a report, or participate in surveys, we retain the content and metadata of those communications for resolution and service improvement purposes.
All payments are processed exclusively by Apple App Store or Google Play. We do not store your payment card details. We receive only anonymized transaction confirmation tokens and purchase entitlement data to activate in-app premium features.
We use your information to authenticate your account, deliver the plan-building and tracking experience, operate community and matching features, enforce content policies, process purchases, and provide all core Service functions.
We use verification photos and their comparison results to confirm you are a real, unique individual before granting access to fitness-results sharing and partner matching, and to detect duplicate or fraudulent accounts. See Section 3.
Your logged workout data and preferences power plan recommendations, progress tracking, and personal record calculations.
Your matching preferences, city-level location, and plan selection are used to suggest compatible training partners pursuing the same or similar programs.
Where you choose to share fitness results publicly, your submitted content populates community feeds and enables discovery by other users.
Your training history, viewing patterns, and preferences are used to personalize plan suggestions, community content, and partner recommendations. See Section 9.
We process behavioral signals, verification status, and user reports to detect and prevent prohibited content, harassment, impersonation, and policy violations.
Aggregated and de-identified usage data is analyzed to improve plan recommendations, matching accuracy, and overall platform performance.
With your consent where required by applicable law, we may send promotional communications about new plan templates, features, and platform offers. You may withdraw consent at any time via in-app settings or the unsubscribe link in any email.
We process personal data as necessary to comply with applicable laws, respond to valid legal process, enforce our Terms of Service, and protect the safety of our users and the public.
Kallo connects real people for real, often in-person, training. To protect our community, you must complete identity verification before you can share fitness results publicly or access the workout partner-matching feature. Building and following private workout plans does not require verification.
The verification flow collects: (a) a photo you submit; and (b) a live comparison photo ("selfie") captured at the moment of verification, used to confirm the two images depict the same person. We also generate and store a verification outcome (verified / not verified) associated with your account.
Verification is performed with the assistance of a specialized third-party identity verification vendor operating under a data processing agreement. The vendor processes your verification images solely to perform the comparison and is contractually prohibited from using your images for any other purpose, including training its own facial recognition models beyond what is necessary to deliver the verification service to us.
Raw verification and comparison photos are retained only as long as necessary to complete and audit the verification process, and are deleted within 30 days of a successful verification. We retain only the resulting verification status (verified/not verified) associated with your account thereafter, not the underlying images.
We may require re-verification periodically or if we detect signals suggesting your account may have been compromised, transferred, or associated with suspicious activity.
If you decline verification or do not pass it, you will not be able to publicly share fitness results or use the partner-matching feature. Core plan-building and private tracking functionality remain available regardless of verification status.
Workout plans you build or customize in Kallo are yours. We store your plan data on our servers solely to deliver the plan-building and tracking experience across devices. We do not sell your individual plan data to third parties.
Your plans, logged workouts, and progress data are stored on our secure cloud infrastructure and synced across your devices associated with your account.
Where you choose to publish a plan as a public template for others to follow, the plan structure (exercises, sets, reps, schedule) becomes visible to other users; your personal logged performance data within that plan remains private unless you separately choose to share it.
Body metrics (weight, measurements, body composition) you optionally log are used only to personalize your own plan suggestions and progress tracking. This data is not shared with other users or third parties without your explicit action to make it public.
Fitness results include progress photos, before/after comparisons, personal records, completed workout summaries, and achievement milestones you choose to publish to the community.
You must complete identity verification (Section 3) before your account can publish fitness results publicly. This helps ensure that shared results and achievements on Kallo come from real, verified community members.
Each fitness result can be set to Private (visible only to you), Followers Only, or Public. Results are Private by default; publishing is always an explicit choice you make, and you may change visibility at any time.
Shared results remain subject to our Community Guidelines and content moderation, including prohibitions on misleading before/after claims and deceptive supplement or product promotion — see the Terms of Service for full details.
Kallo's partner-matching feature suggests other verified users pursuing the same or a similar workout plan, based on your stated preferences, training level, and city-level location.
Only identity-verified users may access or appear in partner matching, as described in Section 3. This is a core safety measure given that partner matching may lead to in-person training.
For matching purposes, we use city-level (not precise GPS) location. Your exact real-time location is never shared with other users through the matching feature.
Messages exchanged with matched partners within Kallo are stored to enable the conversation feature, support moderation, and allow reporting of abuse. See Section 12 for retention details.
Identity verification confirms that a user is a real, verified individual; it is not a criminal background check and does not guarantee the safety, compatibility, or conduct of any matched partner. See the Terms of Service, Section 8, for important safety information about in-person meetings.
Fitness result posts, progress photos, comments, and community posts you publish publicly constitute User-Generated Content (UGC). UGC is stored on our secure cloud servers associated with your account.
By publishing UGC publicly on Kallo, you grant us a non-exclusive, worldwide, royalty-free, sublicensable license to host, store, reproduce, display, and distribute your content within the Service and in connection with promoting Kallo, subject to your visibility settings. You retain full ownership of your original content.
Community-shared UGC is subject to automated screening and human review for compliance with our Community Guidelines. Content that violates our policies will be removed, and responsible accounts may face suspension or termination.
You may delete any published result or UGC at any time. Deleted content is removed from public view within 48 hours, from production servers within 30 days, and from backup archives within 90 days.
Public fitness results appear in Kallo's community feed for other users to discover and be inspired by. Public entries include your display name, the shared content, and reactions or comments from other users.
Other users may react to or comment on your public results. Comments are associated with the commenter's display name and are visible to all viewers. You may moderate and delete comments on your own posts at any time.
You may follow other users whose training resonates with you. Follower relationships are visible in your profile activity unless you set your profile to private.
You may report or block any user or content at any time. Reports are reviewed by our safety team, and your identity as the reporting user is kept confidential from the reported party.
Kallo uses your training history, logged results, preferences, and engagement signals to personalize plan suggestions, community content, and potential training partners.
Your fitness data, body metrics, and behavioral signals are not used to build an advertising profile or shared with supplement brands, gyms, or third-party advertising networks without your explicit consent.
You may disable personalized recommendations at any time in Settings > Privacy > Personalization. Kallo will then present a non-personalized, editorially curated experience.
We share personal information with trusted third-party service providers supporting our operations: cloud infrastructure providers, CDN services, the identity verification vendor described in Section 3, payment processors, analytics platforms, customer support tools, and content moderation systems. All providers are contractually bound to process your data only on our instructions and in compliance with applicable data protection law.
We do not sell your personal information, verification images, body metrics, or fitness data to any third party, including advertisers, supplement brands, or data brokers.
In the event of a merger, acquisition, or asset sale, your data may transfer to the acquiring entity. We will notify you in advance before your data becomes subject to a materially different privacy policy, giving you the opportunity to request account deletion.
We may disclose your information to law enforcement or government authorities when required by applicable law, valid legal process, or where necessary to protect the safety of any person. Where legally permitted, we will notify affected users prior to such disclosure.
Your display name, profile photo, and publicly shared fitness results are visible to all Kallo users. You may set your profile or individual results to private in account settings at any time.
As described in Section 3, we use a specialized third-party vendor to process verification photos. This vendor operates under strict data processing agreements limiting use of your images to the verification purpose.
Mobile analytics SDKs measure app performance and feature engagement, configured with privacy-preserving settings including anonymized event collection and suppression of advertising identifiers absent your consent.
Progress photos and other media are stored on cloud infrastructure and delivered via CDN providers to ensure fast, reliable loading, under data processing agreements.
Apple Sign-In and Google authentication are governed by their own terms and privacy policies. Our use of data from these services is limited to account creation and basic profile population.
We retain your personal information for as long as your account is active. Accounts with no login activity for 24 consecutive months will receive a dormancy notice; following the notice period, inactive data may be anonymized or deleted.
As described in Section 3.5, raw verification and comparison photos are deleted within 30 days of successful verification. Only the resulting verification status is retained thereafter.
Your workout plans, logged results, and progress data are retained for the life of your account. You may delete individual entries or your entire history at any time.
In-app messages with matched partners are retained for the life of your account or until you delete them, whichever is earlier, except where retained longer for safety investigations or legal compliance.
Financial transaction records are retained for a minimum of seven years to comply with applicable accounting, tax, and consumer protection obligations.
Records of content moderation actions, user reports, and enforcement decisions are retained for up to 36 months after account closure.
We implement TLS 1.2+ encryption for all data in transit, AES-256 encryption for sensitive data at rest (including verification images during their limited retention period), strict role-based access controls, and automated anomaly detection.
Data access is restricted on a need-to-know basis, requires multi-factor authentication, and is comprehensively audit-logged. Personnel with access to verification data receive specialized training and sign confidentiality agreements.
We conduct regular security assessments and third-party penetration testing. Report security vulnerabilities responsibly to service@kallo.app.
In the event of a personal data breach posing risk to your rights and freedoms, we will notify relevant supervisory authorities within 72 hours where required by law and inform affected users without undue delay.
Kallo uses session tokens, local storage, and analytics SDKs (not traditional browser cookies) to maintain your authenticated session, remember preferences, and sync your training data across devices.
On iOS, we request ATT consent before accessing your IDFA. On Android, we respect your opt-out via device advertising settings. Advertising identifiers are used only to measure our own user acquisition campaigns.
Our website may use standard browser cookies for session management and analytics, manageable via your browser settings.
Kallo serves a global community and operates cloud infrastructure across multiple regions. Your personal data may be transferred to and processed in countries other than your country of residence.
For transfers from the EEA, UK, or Switzerland to countries lacking an adequacy decision, we rely on EU Standard Contractual Clauses (SCCs) and, where applicable, the UK International Data Transfer Addendum (IDTA). Equivalent safeguards apply to other cross-border transfers, including for verification data processed by our identity verification vendor.
Where applicable national laws impose mandatory data localization requirements, we take reasonable steps to store and process the required data categories within the mandated territory.
Request a copy of personal data we hold, including your fitness data and verification status, via in-app settings or by emailing service@kallo.app with subject "Data Access Request."
Correct inaccurate personal information directly in account settings. For data that cannot be self-corrected, contact us and we will action the correction within 30 days.
Request deletion via Settings > Account > Delete Account or by emailing us. See Section 22 for full account deletion details.
Request your fitness data and personal data in a structured, machine-readable format suitable for personal archiving or transfer to another platform.
Object to or request restriction of processing in certain circumstances, including processing of verification data. We pause relevant processing while assessing your objection.
Withdraw consent for identity verification, marketing, or personalization at any time via in-app settings or by contacting us. Withdrawing verification consent will disable public result sharing and partner matching going forward.
Email service@kallo.app with "Privacy Rights Request" in the subject, your registered email, and a description of your request. We verify your identity and respond within applicable legal timeframes.
For EEA and UK users, Kallo acts as the data controller of your personal information under the GDPR and UK GDPR respectively.
We process your data under: (a) contractual necessity (to provide the Service); (b) legal obligation (regulatory compliance); (c) legitimate interests (safety, service improvement, fraud prevention), where not overridden by your rights; and (d) consent (for marketing, optional personalization, and identity verification, which involves special category biometric-adjacent data under Article 9 and requires your explicit consent).
You may lodge a complaint with your national data protection supervisory authority if you believe your data has not been handled lawfully. We encourage you to contact us first to attempt direct resolution.
California residents have rights under the CCPA as amended by the CPRA, including the right to know, delete, correct, and opt out of the sale or sharing of personal information, and additional rights regarding sensitive personal information (which may include your verification images and health/fitness data). Kallo does not sell personal information and does not share it for cross-context behavioral advertising.
Exercising your California privacy rights will not result in denial of services, different pricing, or reduced quality of experience.
California residents may designate an authorized agent by providing written proof of authorization. We verify both agent and resident identity before processing any request.
Brazilian users have rights under the Lei Geral de Proteção de Dados (LGPD) including confirmation, access, correction, anonymization, deletion, portability, and withdrawal of consent — including consent for the processing of sensitive personal data under Article 11, such as identity verification data.
We process Brazilian users' data based on contract performance, legal obligation, and consent where applicable, including explicit consent for identity verification.
Brazilian users may lodge complaints with the Autoridade Nacional de Proteção de Dados (ANPD) where they believe data processing violates the LGPD.
Kallo is designed for users who are 18 years of age or older. We implement date-of-birth verification at registration, and our identity verification process for results-sharing and partner matching provides an additional safeguard. Confirmed underage accounts are immediately and permanently terminated with all associated data deleted.
If you are a parent or guardian and believe a minor has created a Kallo account, contact us immediately at service@kallo.app. We will investigate and, where confirmed, permanently delete the account and all associated data without delay.
We deploy automated CSAM hash-matching on all uploaded media, AI-assisted content analysis on community posts, and dedicated human safety reviewers. Upon confirmed detection or credible report: all associated content is immediately and permanently removed; the responsible account is permanently terminated and all associated identifiers are blocked; a mandatory report is filed with the NCMEC CyberTipline or the legally required equivalent national authority; and we cooperate fully with all resulting law enforcement investigations. CSAE-related terminations carry no right of appeal.
To report: use the in-app Report function on any content or user profile, or email service@kallo.app immediately with subject "CSAE Report."
All in-app purchases are processed exclusively through Apple App Store or Google Play. Kallo does not store your payment card details. We receive only anonymized transaction confirmation tokens and entitlement data to activate premium features.
If Kallo offers premium features (such as advanced plan templates, detailed analytics, or expanded matching filters): access is non-transferable between accounts; non-refundable except as required by applicable law or app store policy; and may be forfeited upon account termination for cause.
Transaction records are retained for a minimum of seven years to satisfy applicable accounting, tax, and consumer protection requirements.
Delete your account at any time via Settings > Account > Delete Account, or by emailing service@kallo.app with subject "Account Deletion Request."
Your profile, workout plans, fitness results, community posts, matching data, messages, and all associated data are removed from public view within 48 hours and from production servers within 30 days. Backup archives are purged within 90 days of the next scheduled rotation. Any residual verification images (already subject to the 30-day deletion in Section 3.5) are confirmed deleted if not already removed.
Certain data is retained where required by law: transaction records (up to 7 years); safety and moderation records (up to 3 years); data subject to a legal hold. All retained data is isolated and processed only for the specific legal purpose requiring its retention.
Material changes are communicated at least 14 days before taking effect via in-app notice, push notification, and/or email to your registered address. Non-material corrections may be made without advance notice.
Continued use of Kallo after any revised Policy's effective date constitutes acceptance. If you do not agree, delete your account before the changes take effect.
Prior versions are available upon request at service@kallo.app.
For questions, data rights requests, or privacy concerns:
- Email: service@kallo.app
- Subject: "Privacy Inquiry — [Your Name]"
We acknowledge inquiries within 5 business days and respond within 30 days.
Use the in-app Report function on any content or user profile, or email service@kallo.app immediately with subject "CSAE Report." These are our highest-priority safety matter, actioned without delay.