KMOI: Running
EULA Privacy ← Main site

Privacy Policy

Last updated: 22 May 2026

This Privacy Policy explains how Egor Golovitsyn ("I", "me", "my") collects, uses, and protects your personal data when you use the mobile application KMOI: Running (the "App").

I am the data controller responsible for your personal data within the meaning of the EU General Data Protection Regulation (GDPR). For any privacy question or request, contact support@golovitsyn.com.

1. Summary

  • KMOI: Running requires an account so your training plan can be saved and synced.
  • The App collects four categories of personal data: email address, name, health data, and fitness data.
  • Health and fitness data are stored in Google Firebase under your account.
  • Only you and I (the operator) can access the data tied to your account.
  • Personalised plans are generated by Anthropic's Claude AI. Only pseudonymised health and fitness data is sent — your name, email, and account ID are never shared with Anthropic, so Claude cannot tell who the data belongs to.
  • The App does not show ads and does not sell or share your data for marketing.
  • You can request access to or deletion of all your data at any time by emailing me.

2. Data I collect

2.1 Email address

Collected when you create an account. Used to identify your account, sign you in, send password-reset emails, and contact you about important changes to the App.

2.2 Name

Collected when you set up your profile. Used to personalise the App (e.g. greetings, training plan headings).

2.3 Health data

Information you enter about yourself for the purpose of generating a personalised training plan, such as age, weight, height, sex, resting heart rate (if provided), injuries, or other health information you choose to share.

Health data is a "special category" of personal data under Art. 9 GDPR. I process it only on the basis of your explicit consent, which you give when you create your profile. You can withdraw this consent at any time by deleting your account.

2.4 Fitness data

Information about your training activity: workouts completed, distance, duration, pace, perceived effort, training goals, plan progress, and similar metrics you enter or that the App calculates from your input.

2.5 Account and technical data

To keep the App working, Firebase collects basic technical data such as a randomly assigned user ID, sign-in timestamps, and (briefly) your IP address for security and abuse prevention. The App does not use third-party analytics, advertising SDKs, or tracking pixels.

3. How I use your data

  • To create and maintain your account.
  • To generate, store, and update your personalised training plan. Plans are created with the help of an AI service (Anthropic's Claude) using only pseudonymised data — see Section 6.
  • To sync your data across devices when you sign in.
  • To process your subscription (handled by RevenueCat — see below).
  • To respond to your support requests.
  • To fix bugs and improve the App.
  • To comply with legal obligations.

I do not use your data for advertising, profiling for marketing purposes, or selling to third parties.

4. Legal basis (GDPR)

  • Explicit consent (Art. 9(2)(a) GDPR) — for processing your health data.
  • Contract (Art. 6(1)(b) GDPR) — to provide the App and your subscription.
  • Legitimate interest (Art. 6(1)(f) GDPR) — for security, fraud prevention, and basic technical operation.
  • Legal obligation (Art. 6(1)(c) GDPR) — for tax records and similar requirements.

5. Who can access your data

Only two parties can access the personal data linked to your account:

  1. You, by signing in to the App.
  2. Me (Egor Golovitsyn), the operator. I access your data only when necessary — for example to respond to your support request, fix a bug you reported, or comply with a legal obligation. I do not browse user data for any other reason.

The infrastructure providers listed below (Firebase, Anthropic, RevenueCat, the app stores) process limited data on my behalf as data processors. They are bound by contract not to use it for their own purposes. None of them, including Anthropic, receives information that would let them identify you personally.

6. Third-party services (data processors)

6.1 Google Firebase

Account authentication and data storage are provided by Firebase, operated by Google Ireland Limited (for EU users) and Google LLC. Firebase stores your email, name, health data, fitness data, and account metadata on Google's secured infrastructure.

Privacy policy: firebase.google.com/support/privacy

6.2 Anthropic (Claude API)

Your personalised training plans are generated with help from Claude, an AI assistant operated by Anthropic, PBC. When the App needs a new plan, it sends only your pseudonymised health and fitness data (such as age, weight, fitness level, goals, and recent training history) to the Claude API. Your name, email address, account ID, and any other directly identifying information are not sent — Anthropic has no way to know whose data it is processing.

Under Anthropic's commercial API terms, customer inputs and outputs are not used to train Anthropic's AI models. Data may be retained for up to 30 days for trust-and-safety purposes and is then deleted.

Privacy policy: anthropic.com/legal/privacy

6.3 RevenueCat

Subscriptions are managed by RevenueCat, Inc. RevenueCat receives a randomly generated user identifier and your subscription transaction details (from Apple or Google) so it can tell the App whether your subscription is active. It does not receive your health or fitness data.

Privacy policy: revenuecat.com/privacy

6.4 Apple App Store / Google Play

Subscription payments are processed by Apple or Google depending on your device. I never see your payment-card details. They share with me only the transaction receipts needed to confirm your purchase.

Apple: apple.com/legal/privacy
Google: policies.google.com/privacy

7. International data transfers

Firebase, Anthropic, and RevenueCat may transfer data outside the European Economic Area (mainly to the United States). These transfers rely on appropriate safeguards under GDPR, including the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework. For Anthropic specifically, only pseudonymised data is transferred — no direct identifiers leave the EU under your real name.

8. Data retention

  • Your account and the data it contains are kept for as long as your account exists.
  • When you delete your account, all personal data — including health and fitness data — is permanently deleted from Firebase within 30 days, except where I am required by law to retain certain records (e.g. invoices for tax purposes, typically 10 years under German law).
  • Support emails are kept for up to 12 months after your request is resolved.

9. Your rights under GDPR

You have the right to:

  • Access the personal data I hold about you.
  • Rectify any data that is wrong or incomplete.
  • Erase your data ("right to be forgotten").
  • Restrict or object to certain processing.
  • Receive your data in a portable, machine-readable format.
  • Withdraw consent at any time (does not affect lawfulness of past processing).
  • Lodge a complaint with a supervisory authority. In Germany this is the data-protection authority of your federal state (Landesdatenschutzbehörde).

To exercise any of these rights, email support@golovitsyn.com. I will respond within 30 days at most, usually sooner.

10. How to delete your account

You can delete your account at any time from within the App: Settings → Account → Delete account. This permanently removes your email, name, health data, and fitness data from Firebase. Alternatively, email support@golovitsyn.com and I will delete it for you.

Deletion is irreversible. Active subscriptions are not automatically cancelled by account deletion — please cancel them in the App Store / Google Play settings if you no longer want them.

11. Children

KMOI: Running is not intended for children under 16. I do not knowingly collect personal data from children under 16. If you believe a child has created an account, please contact me and I will delete it.

12. Security

Data in Firebase is encrypted at rest and in transit. Access is restricted via Firebase security rules so that each user can only read and write their own data. I use strong authentication for any administrative access to the backend.

No system is 100% secure, but I take reasonable technical and organisational measures appropriate to the sensitivity of health data.

13. Changes to this policy

I may update this Privacy Policy from time to time. The "Last updated" date at the top tells you when it last changed. If a change materially affects how I process your data, I will notify you in the App or by email before it takes effect.

14. Contact

Egor Golovitsyn
Email: support@golovitsyn.com
Full contact details: see the Imprint.

© 2026 Egor Golovitsyn. All rights reserved.
Privacy EULA Imprint