Khilo

Privacy Policy

Last updated: 6 October 2026

Who We Are

Khilo is provided by Khilo Ltd ("we", "us" or "our"), a company registered in England and Wales under company number 17495470. We are the controller of the personal data described in this policy, which means we decide how and why it is used. We are registered with the Information Commissioner's Office, the UK's data protection authority, under registration number ZC266358. Our registered office and postal address is 66 Paul Street, London, EC2A 4NA, United Kingdom, and our email address is support@khilo.io; write to either about anything in this policy, including a request to use your data protection rights. Khilo is offered to people in the United Kingdom and the European Union.

EU Representative

We value your privacy and your rights as a data subject and have therefore appointed Prighter Group with its local partners as our privacy representative and your point of contact for the following region: the European Union (EU). Prighter gives you an easy way to exercise your privacy-related rights (e.g. requests to access or erase personal data). If you want to contact us via our representative, Prighter, or make use of your data subject rights, please visit the following website: https://app.prighter.com/portal/khilo

Data We Collect

We collect the information you provide when creating an account — your email address, display name, and username, or the name and email shared by Google or Apple if you sign in with those providers (Apple may give us a private relay address instead of your own) — and the data you enter while using Khilo. This includes workout logs, biometric measurements (height, weight, body fat, muscle mass, bone mass, VO2 max, date of birth, age, and biological sex), routine configurations, your training preferences, content you publish to the community, the sections of your public profile you choose to show, the members you follow, leaderboard entries, and bug reports you submit. If you subscribe, we record your plan, its status and renewal dates, and where you bought it: for a subscription paid on the web, the customer and subscription identifiers Stripe gives us; for one bought through the App Store or Google Play, the transaction or purchase identifiers Apple or Google give us, which we use to confirm the purchase with the store and to stop one purchase being used by two accounts. We also record whether you have had a free trial. If you use the referral programme, we record your referral code, who referred you, the members you referred, and the rewards each of you earned and how each was given. If you are a personal trainer or a trainer's client, we record the link between you, the invitations sent and accepted (including the email address an invitation was sent to), and the routines a trainer assigns. We keep a record of each moderation decision about content you publish and about your username and display name, reports you make about other members' content and reports about yours, any strikes on your account and their history, appeals you make, and any restriction on your publishing. If you turn on two-factor authentication, the authenticator app you enrolled is held by our sign-in provider, Firebase Authentication, not in your profile. If you are a personal trainer and connect a social account to prove you own the demo videos you link, we store that account's identifier, handle, display name, profile and avatar URLs, and the permissions you granted, along with encrypted access and refresh tokens so the connection can be kept alive, and, for each demo video you link, the ID and name of the account that published it. When you submit a bug report we also record technical details about the device you sent it from: operating system and version, device model, app version, screen resolution, and an approximate measure of your device's memory. When your device connects to our services, they receive its IP address, as every internet service does; we do not store it with your account. If you allow usage analytics, Google Analytics for Firebase uses your IP address to estimate your approximate location (such as your country and city) and records an identifier for your installation of the app (an app instance ID) with the usage events it collects — see Cookies & Local Storage.

How We Use Your Data

Your workout and biometric data is used to calculate your Lift Rating (R), generate performance analytics, and provide personalised training recommendations such as suggested weights, reps, and deloads. They are calculated automatically from what you log, to guide your training; they have no legal or similarly significant effect on you. User-generated content that is shared with others — community routine and exercise names and descriptions, usernames and display names, and leaderboard removal requests — is reviewed by AI-powered moderation (via Anthropic) for policy compliance, as Automated Decisions & Moderation below describes. Connected social accounts are used only to confirm that a linked demo video belongs to the trainer who linked it. Subscription and purchase records are used to give you the plan you paid for, to confirm purchases with Stripe, Apple or Google, and to stop a purchase, a free trial or a referral reward being used twice. Device details attached to a bug report are used to reproduce and fix the problem you reported. If you allow it, we use usage analytics and performance monitoring to understand how features are used and how quickly the app responds, so we can improve it. We send you transactional emails about your account and subscription, and the optional emails you choose in your profile settings.

Lawful Basis for Processing

UK and EU data protection law requires us to have a lawful basis for everything we do with your personal data, and to tell you what it is. Most of what Khilo does with your data is necessary to provide the service you signed up for (GDPR Article 6(1)(b), performance of a contract): your account and sign-in details, your workout logs and routines, your Lift Rating and training recommendations, your subscription and billing, the emails we send about your account, and the personal trainer features you use. Your date of birth and biological sex are processed on the same basis, to age- and sex-adjust your scores; neither is health data. Some processing rests on our legitimate interests (Article 6(1)(f)) in running a safe and working service: AI moderation of content and names you publish, bug reports and crash reports, checking that requests come from a genuine copy of the app, preventing abuse of the referral programme and of store receipts, and keeping records of moderation decisions. You can object to any of it, as Your Right to Object explains. We keep records of payments made to us, including after your account is deleted, for six years after the end of the financial year in which they were made, because UK tax and accounting law requires us to keep them (Article 6(1)(c), legal obligation). Where a feature is optional we rely on your consent (Article 6(1)(a)): usage analytics and performance monitoring, the sections of your public profile you choose to show, and any social account you connect. Storing analytics identifiers on your device also needs your consent under the UK's Privacy and Electronic Communications Regulations and the EU's ePrivacy rules, which is why we ask before starting them. Your body measurements — height, body weight, body fat percentage, muscle mass, bone mass and VO2 max, together with the history of those measurements — are data concerning health, which the law treats as special category data (Article 9). We process them only with your explicit consent (Article 9(2)(a)). We ask for that consent on its own, not as part of accepting our terms, when you first enter a measurement, and we record against your account when you gave it and which version of this policy it referred to. You can withdraw it at any time from Health Data Consent in your profile settings. Withdrawing deletes those measurements and their history from your account, after which your Lift Rating is calculated without them; it does not affect your workout logs, which are not health data, and it does not affect the lawfulness of anything done before you withdrew.

Automated Decisions & Moderation

Before content you publish reaches other members, an AI model provided by Anthropic checks it against our community rules: the name, description and exercises of a routine, the name, description and details of an exercise, and your username and display name. The model receives only that content, never your email address or account ID. It decides whether the content breaks a rule, how confident it is, and which kind of rule (for example offensive, dangerous, spam or copyright). Content it approves with enough confidence is published. Content it rejects is not published, or is withdrawn if it was already live, and stays in your own library with the reason. When the model is confident that content breaks one of those rules, a strike is added to your account automatically. A strike expires after 28 days, and while you have 3 active strikes you cannot publish and your published content is withdrawn from the community. A username or display name the model rejects cannot be used, or is released if it was already in use, and you are asked to choose another; a name never leads to a strike. Where the model is not confident enough to approve something, it is held for a person on our team to review rather than published, and if the model cannot be reached nothing is published until the item has been checked. A leaderboard's creator can ask for another member's entry to be removed; the model checks the request, and our team can reverse its decision. These decisions are made without a person involved, and some of them — a strike, or a restriction on publishing — can significantly affect how you use Khilo. We make them because checking what is published is necessary to provide a community that follows the rules in our Terms & Conditions. You have the right to ask for a person to review any of them, to give your view, and to contest the decision: use Appeal on a rejected routine in the app, or email us at support@khilo.io about any other decision. A member of our team reviews every appeal, and if we agree the decision was wrong we restore your content and remove the strike.

Data Sharing

We share data only as needed to run Khilo. We do not sell your personal data to any third party. Our service providers process data for us, under contract and only on our instructions: Stripe processes subscription payments made on the web and receives your email and payment details. Anthropic provides AI moderation and receives the text of user-generated content, such as routine and exercise names and descriptions, usernames and display names, and leaderboard removal requests. SendGrid (Twilio) delivers our emails and receives your email address and display name, records whether you have unsubscribed from an optional email, and receives the device details included in the critical-bug alerts we send to our own team. Atlassian (Jira) receives the content of bug reports that our team escalates for tracking, including the device model, operating system and version, app version, and screen resolution recorded with the report. Prighter, our representative in the European Union, receives what you send it through its portal, such as a request to use your data protection rights, and passes it to us. Firebase (Google) hosts your data and provides authentication, crash reporting, and — only if you allow them — usage analytics and performance monitoring; a crash report records the error and technical details of the app at the time, and is not tied to your account. Google reCAPTCHA Enterprise on the web, Google Play Integrity on Android and Apple's DeviceCheck on iOS check that requests come from a genuine copy of Khilo, and receive technical information about your browser or device to do so. Some organisations receive data as controllers in their own right. Apple and Google do when you sign in with them, and when you subscribe through the App Store or Google Play: they take the payment under their own terms, and we confirm your purchase with them using its transaction or purchase identifier. If you connect a social account, we exchange data with that platform — Google (YouTube), Meta (Instagram), or TikTok — to establish and maintain the connection: we send the authorisation you granted and receive your account identity, handle, and channel details (see Connected Social Accounts below). Other Khilo members see what the features you use are designed to show them: your username and display name wherever you appear, the sections of your public profile you choose to show, the routines and exercises you publish with your name as their creator, and your entries on leaderboards you join (your name, your scores and your Lift Rating when you took part). If you are a personal trainer's client, your trainer sees what they need to coach you: your name, email address and plan, your Lift Rating and recent training activity, your workouts and the routines they assign, your training preferences and warm-up settings, your strength estimates and any deload or overtraining signal, and your body measurements, age and biological sex, but not your date of birth. Your trainer uses that data as an independent controller: they decide how they use it in coaching you, and are responsible for doing so lawfully, and our terms allow them to use it only to coach you. Your trainer stops seeing it when you are no longer their client. We may also disclose data where the law requires it, such as to comply with a court order, or where it is necessary to protect the safety of our users or others.

Connected Social Accounts

A personal trainer can connect a YouTube, Instagram or TikTok account so that the demo videos they link can be checked as theirs. Connecting asks the platform for read-only access. We use it to read the account's identity — its ID, handle, name and profile picture — and to check that a video you link was published by that account. We never post, edit or delete anything on it. Khilo uses YouTube API Services to do this for YouTube: by connecting a YouTube account you agree to the YouTube Terms of Service (https://www.youtube.com/t/terms), and Google's own use of your data is described in the Google Privacy Policy (https://www.google.com/policies/privacy). Khilo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements. While a YouTube account is connected, we check every day that your authorisation still stands, re-read the channel details we hold from YouTube at least every 7 days, and check again at least every 14 days that each linked video is still published by that channel; we hide a link YouTube no longer confirms, and delete anything read from YouTube that we could not refresh within 28 days. You can disconnect a connected account at any time from your profile. That deletes the connection and the access tokens we hold, withdraws our access with YouTube or TikTok, and stops the demo videos it verified from showing; we keep those video links on your exercises, so they return if you reconnect the same account. For YouTube, disconnecting also deletes at once the channel ID and name stored with each of those links, and the links you entered are kept on their own, to be checked with YouTube again if you reconnect. If you withdraw Khilo's access from your Google Account instead, we find out at our next daily check, and then delete everything we read from YouTube and hide your YouTube video links until you reconnect. Instagram gives apps no way to withdraw their own access, so to remove Khilo there as well, use Instagram's settings. You can also revoke Khilo's access from the platform itself at any time: for YouTube, in your Google Account's security settings (https://security.google.com/settings/security/permissions); for Instagram or TikTok, in the list of connected apps in that platform's settings. If you ask Instagram to have Khilo delete your data, we delete the connection, its tokens and the demo video links it verified, and give you a confirmation code whose status you can check at https://khilo.io/data-deletion.

International Transfers

Your account data is stored in the United Kingdom, as Data Storage & Security describes. Some of our processing happens elsewhere. Our servers also run in Google Cloud data centres in Belgium and Germany, and the step that sets up a new account runs in the United States. Several of our providers process data in the United States, or give access to it from there: Google (Firebase Authentication, crash reporting, usage analytics and performance monitoring, and reCAPTCHA), Stripe, Anthropic, SendGrid (Twilio) and Atlassian, as do Apple, Google, Meta and TikTok as the platforms you choose to use. The UK and the EU recognise each other as protecting personal data adequately, so data moves between them without further safeguards. Where data goes outside the UK and the EU, it is protected by a safeguard the law recognises: the EU-U.S. Data Privacy Framework and its UK Extension, where the recipient is certified under them, or otherwise the European Commission's standard contractual clauses together with the UK's International Data Transfer Addendum, which our providers include in their data processing terms. You can ask us at support@khilo.io for details of these safeguards.

Data Storage & Security

Your account data — your profile, workout logs, measurements, routines and the other records the app keeps for you — is stored in Google Cloud Firestore in the europe-west2 (London) region. All data is encrypted in transit via HTTPS and at rest by Google Cloud. Access tokens for connected social accounts are additionally encrypted with Google Cloud KMS and are never readable by the app. Access to your data is protected by Firebase Authentication and Firestore Security Rules that ensure only you can access your own records, apart from what this policy says other members and your trainer can see.

Data Retention

We retain your workout history, biometric measurements, and account data for as long as your account is active. When you delete your account it is deactivated immediately, you are signed out on every device, and it is permanently erased 30 days later; you can cancel by signing back in at any point during that window. Erasure covers everything your account holds, including your routines and exercises, the bug reports and content reports you filed, and your subscription and referral records, and we withdraw Khilo's access to any social account you connected. You may correct or update your profile and biometric data at any time from your profile settings. A small amount of information outlives that erasure, and we set it out plainly rather than promise more than we deliver: records of referral bonuses earned by people you referred stay with those accounts, because they determine rewards those members were promised; moderation decisions and leaderboard removal records, including reports about content you published, are kept as an audit trail of enforcement for 2 years after the decision, and then deleted; the record of any store purchase our support team moved between accounts is kept for 6 years after the move, with our payment records; a leaderboard you created passes, with its routine, to its longest-standing remaining member, or is archived if none of them can take it over, so the other members keep their results; and when your account is erased we cancel a subscription billed on the web or through Google Play and delete our own copy of your billing data. The customer record Stripe keeps for us when you pay on the web, with your payment history and invoices, is not deleted with your account: it is our record of payments made to us, which UK tax and accounting law requires us to keep. We keep it for six years after the end of the financial year in which you last paid, and then delete it. Stripe also keeps its own record of the payments it processed, under its own legal obligations. Nothing in this list identifies you to other users. A subscription bought through the App Store is the exception: Apple does not let us cancel it, so it keeps renewing until you cancel it yourself in your App Store subscription settings. The app tells you this, with a link to those settings, when you ask to delete your account. Some records have periods of their own, whether or not you delete your account: a copy of your data prepared by Download My Data is deleted about a day after it is made; the status of an Instagram data deletion request stays checkable for 365 days and is then deleted; emails we have sent you are logged for 90 days; a bug report our team copied into Jira holds no email address or account ID, and is deleted there 2 years after it was copied; our servers' logs are kept for 30 days; crash reports are kept by Firebase for 90 days; and usage analytics, if you allow them, are kept by Google Analytics for no more than 14 months.

Your Rights

You have the right to access the personal data we hold about you, to have it corrected, to have it erased, to restrict how we use it, to receive it in a portable form, and to object to how we use it. You can view your profile, workout history, and biometric data directly within the app, and download a complete copy of your data using the Download My Data option in your profile settings (available once per 24 hours); the copy is a structured, machine-readable file (JSON), which you can also take to another service. You can correct or update your profile and biometric data at any time from your profile settings. You may request deletion of your account using the Delete Account option on the Terms & Conditions page, reached from your profile settings; the Data Retention section above describes exactly what is erased, when, and what is kept. Where we rely on your consent you can withdraw it at any time — for your body measurements, from Health Data Consent in your profile settings, and for usage analytics, from Usage Analytics in the same settings list — without affecting the lawfulness of what was done before. You can ask for a person to review a decision made automatically, as Automated Decisions & Moderation explains. For anything the app does not let you do yourself, email us at support@khilo.io or write to us at the address in Who We Are. We reply within one month, free of charge; if a request is complex, or you send us several, we can take up to two more months, and we will tell you within the first month if we need to. If you are unhappy with how we have used your data, you can complain to a data protection authority: in the UK, the Information Commissioner's Office (ICO), at https://ico.org.uk/make-a-complaint or on 0303 123 1113; in the EU, the authority in the country where you live or work. We would appreciate the chance to put things right first.

Your Right to Object

You have the right to object, at any time, to our use of your personal data where we rely on our legitimate interests, which Lawful Basis for Processing lists, on grounds relating to your particular situation. When you object, we stop, unless we have compelling legitimate grounds that override your interests, rights and freedoms, or we need the data to establish, exercise or defend legal claims. Some of that processing, such as moderating what you publish and checking that requests come from a genuine copy of the app, is part of how the community and the service work, so objecting to it may mean you can no longer publish or use Khilo; we will tell you if so. To object, email us at support@khilo.io. We do not use your data for direct marketing, and if we ever did, you could object to that at any time and we would stop.

Cookies & Local Storage

Khilo stores some information on your device. Most of it is strictly necessary for the service you ask for, so it needs no consent: your sign-in session (Firebase Authentication, in local storage and IndexedDB), a copy of your data in IndexedDB so the app works offline and loads quickly, the app's own settings in local storage (such as your theme, your choice about usage analytics and a workout in progress), on the web a service worker cache of the app's files, and the security check that requests come from a genuine copy of the app, which on the web is Google reCAPTCHA Enterprise and may set its own cookies. Two things run only if you allow usage analytics, which the app asks you about the first time you open it and you can change at any time from Usage Analytics in your profile settings: Google Analytics for Firebase stores an app instance identifier (on the web, in the _ga cookies, which last up to two years) and records usage events such as sign-ins and workout completions, linked to your account while you are signed in; and Firebase Performance Monitoring stores an installation identifier and records how long screens and requests take. Your choice is kept on the device you make it on, so another device or browser asks again. Turning usage analytics off stops both and deletes the Google Analytics cookies. We do not use advertising or cross-site tracking cookies.

Children

Khilo is for people aged 16 and over, and you must be at least 16 to create an account. We do not knowingly collect personal data from anyone younger. If you believe someone under 16 has an account, email us and we will delete it.

Changes to This Policy

We may update this privacy policy from time to time, for example when we add a feature or the law changes. We will update the "Last updated" date at the top of this page, and before a change that materially affects how we use your personal data takes effect, we will tell you by email or in the app. Where a change needs your consent, we will ask for it, and will not rely on it until you have given it.

Contact

If you have questions about this privacy policy, or want to exercise your data rights, email us at support@khilo.io — the same address handles every data protection request — or write to us at Khilo Ltd, 66 Paul Street, London, EC2A 4NA, United Kingdom. You can also use the Report a Bug option in your profile settings.