FITKIKU / PRIVACY POLICY

Your health data stays on your terms.

FitKiku gives a compatible AI agent you choose read-only access to recent Apple Health Steps and Sleep. You review and approve the destination and scope on your iPhone.

Available on the App Store Effective August 29, 2026

At a glance

Reads
Steps and Sleep Analysis only
Sends after approval
Daily aggregates, coverage, and source details
Never
Writes to Health or uses Health data for advertising

Read-only by design

FitKiku never writes or changes Apple Health records.

Missing is not zero

Unknown and partial coverage stay visible instead of becoming false values.

Future access is revocable

Revoke the private AI link, disconnect all access, or delete the anonymous FitKiku account and synced data in Settings.

1. Scope and current status

This policy covers the FitKiku iPhone companion and the FitKiku Health Gateway operated by KikuAI. FitKiku 1.0 is available free in the configured non-EU App Store storefronts. EU-27 storefronts are not enabled. Release 1.0 uses the compatible-agent Pair Link protocol. The simpler private-URL path described below is an unreleased 1.1 source candidate; this policy discloses its boundary before any later release. Public app distribution does not promise compatibility with every chat runtime or a hosted-service availability level.

The policy covers the current native data contract, schema 1.1. Older private test records may use a legacy schema. FitKiku will not describe a legacy record as aggregate-only.

The release-candidate setup creates an anonymous FitKiku guest without an email address, password, or recovery identity. The same account and deletion boundary is used by the limited reviewer connection path; it is not a separate privileged demo account.

The general KikuAI Privacy Policy separately covers normal use of the kikuai.dev website, including standard website logs.

2. What FitKiku reads from Apple Health

FitKiku requests read access only to:

  • Steps — daily step count.
  • Sleep Analysis — sleep samples used on the iPhone to calculate daily asleep minutes.
  • Source metadata — source name, bundle identifier, and product type used to explain provenance.

FitKiku does not request permission to write any Apple Health category. It does not read workouts, heart rate, body mass, active energy, clinical records, or the rest of your Health database in the current product scope.

Apple protects read decisions: the app cannot distinguish denied access from Health data that is not available. FitKiku therefore shows missing information as Unknown or Partial, never as a manufactured zero.

3. What can leave your iPhone

Health data transfer starts only after you approve the named HTTPS destination and Apple Health grants the requested read access. FitKiku can then send:

  • local date, the release 1.0 Europe/Kyiv daily boundary, generation time, and sync revision;
  • daily step count and daily asleep minutes, when available;
  • Steps and Sleep coverage: complete, partial, or unknown;
  • Health source name, bundle identifier, and product type;
  • a stable app installation identifier used for authentication, idempotency, and revocation;
  • delivery status such as receipt/fetch times, freshness, and missing recent dates.

For the unreleased 1.1 AI-chat candidate, FitKiku creates a random private URL. The URL returns only a bounded recent summary: dates, Steps, asleep minutes, coverage, freshness, and missing-date status. It does not return Health source identifiers, raw samples, installation identifiers, or write access. Copying the prepared message would intentionally disclose that bearer URL to the AI chat you choose. The private URL is a bearer credential: anyone with it can make the same bounded read until you replace or revoke it.

Release 1.0 does not dynamically regroup daily summaries for another local timezone. App Store territory configuration does not change that boundary.

Sleep interval boundary

The current schema sends daily asleep minutes with an empty sleep-interval array. Sleep interval timestamps and categories stay on the iPhone. Protected local storage may retain interval detail for retry and recovery, but that detail is not part of a schema 1.1 upload.

4. How data is used and shared

FitKiku uses the transferred data only to:

  • give the agent you approved bounded recent Steps and Sleep context;
  • show delivery, freshness, missing-data, and correction status;
  • retry safely, prevent duplicate processing, and revoke credentials;
  • operate, secure, diagnose, and support the service without putting health values in application logs.

FitKiku makes health summaries available only through the destination and access path you approve. The consent preview shows the destination origin, requested categories, retention statement, and whether an agent or AI provider may receive daily summaries. In the unreleased 1.1 candidate, anyone who obtains a valid private URL can read its bounded summary until you replace or revoke it, so share it only in a private chat you trust.

The FitKiku gateway runs on KikuAI-controlled server infrastructure. Cloudflare provides DNS, TLS, and tunnel transport and may process standard network metadata. The gateway does not push Health summaries to an AI model provider by default. Release 1.0 agents fetch through their approved credential. In the unreleased 1.1 candidate, the chosen chat fetches the private URL and may retain the message, URL, and returned summary under its operator's privacy and retention policy. Revoking access does not delete copies already retained by that provider.

FitKiku does not use Apple Health data for advertising, marketing, cross-user training, unrelated profiling, insurance, employment decisions, or data brokerage.

5. Retention, revocation, and deletion

Revoke future access

Revoking the private AI link makes that URL inactive without disconnecting the iPhone. Disconnecting revokes future device delivery and all agent reads. Neither action automatically deletes summaries already stored by an AI provider.

Delete an anonymous account

In iPhone Settings, choose “Delete FitKiku account and data.” After server confirmation, FitKiku deletes the anonymous guest, device and agent credentials, and synced daily summaries. This does not delete or change anything in Apple Health.

FitKiku retains only a nonidentifying completion receipt with a domain-separated digest, timestamps, and record counts. It can acknowledge a retry after a lost response but cannot restore the deleted account or authorize health reads. Anonymous users should use in-app deletion. Private-test owners and people seeking process guidance can contact support without sending health values or credentials.

Operator-only recovery copies are retained for no more than 35 days. A deletion removes the anonymous account from the active service after server confirmation; records present in an older recovery copy age out with that copy and are not available to agents. Recovery copies are used only for disaster recovery, not advertising, profiling, or routine product access.

6. Security and operational logs

FitKiku requires HTTPS outside explicit local development, stores connection credentials in the iOS Keychain, uses separate device, agent, and private-link credentials, stores the private-link token on the backend only as a digest, bounds reads, and rejects malformed, expired, redirected, or revoked connection material.

Application logs are designed not to contain health values, health payloads, Pair Links, credentials, or Health source identifiers. Hosting infrastructure may process standard network metadata such as IP address, request time, requested path, and response status for delivery and security. Because the private-link token is part of the requested path, browser history, the chosen AI provider, and hosting access logs may process it as part of the URL.

No Internet service can guarantee absolute security. FitKiku does not claim end-to-end encryption or guaranteed background delivery. Background updates are best effort and foreground catch-up may be needed.

7. Your choices

  • Before sharing: review the destination, categories, retention, and AI-processing disclosure in FitKiku.
  • Apple Health access: change FitKiku permissions in Apple Health or iOS privacy settings.
  • Private AI link: replace or revoke it in FitKiku Settings without disconnecting the iPhone.
  • Future transfer: disconnect and revoke all access inside FitKiku.
  • Anonymous account and stored data: delete it in FitKiku Settings; email support for process guidance or private-test deletion help.

8. Contact and policy changes

For privacy questions, data access, or deletion requests, email fitkiku@kikuai.dev. Do not include health values, private AI links, Pair Links, tokens, or server credentials.

Material changes to FitKiku data categories, retention, destinations, or AI-provider sharing will be reflected in this policy and in the in-app consent flow before the new practice applies.