Privacy Policy – Hercule – Fitness Chronicle
Effective date: 1 September 2026
Previous version: 17 October 2025
This Privacy Policy explains how Hercule – fitness chronicle (the “App”) collects, uses, and shares information.
The data controller is:
Zafer Siar Konyar (“we”, “us”, or “our”)
Flat 5, Avery Hill Road, Greenwich, London SE9 2ER, United Kingdom
siarkonyar@gmail.com
We are established in the United Kingdom. If you have questions about this policy or about how your data is handled, contact us at the address above.
0. What changed in this version
This update reflects the following changes:
- Analytics. The App now reports app-usage events to Google Analytics for Firebase. We ask before collecting anything, and you can change your answer in Settings. See section 2.6.
- AI coach (beta). The App now includes an AI assistant. Using it sends your messages, and training data it reads on your behalf, to Google’s Gemini API. See sections 2.5 and 4.
- Profile and programs. The App now asks for a name, gender, and birthday, and stores workout programs and body-weight entries you create. See sections 2.2 and 2.3.
- Minimum age. You now have to be at least 13 to open an account, and setup checks the birthday you enter. See section 11.
- Clearer retention periods. We now state how long diagnostic and analytics data is kept rather than referring to our providers’ schedules. See section 7.
- Controller details. We now give our full postal address and the route for raising a complaint. See section 15.
1. Scope
This policy applies to the App on Android and iOS and to any related services that link to this policy.
2. What we collect
2.1 Account and authentication
- Account identifiers (e.g., email address) when you sign up or sign in.
- Authentication tokens and basic profile info provided by Google Sign-In and Sign in with Apple (as applicable).
- A Firebase user ID (“UID”), which is the identifier we use internally to associate your data with your account.
2.2 Profile information you provide
When you first set up the App, we ask for:
- Name (required to finish setup) — this can be any name you choose and does not have to be your legal name.
- Gender (required to finish setup) — male, female, non-binary, or “prefer not to say”.
- Birthday (required to finish setup) — we ask for it to confirm you are old enough to hold an account, and we store it on your account record. Setup will not complete for a date of birth below the minimum age in section 11.
This information is stored on your account record and is used to personalise the App. It is not sent to the AI coach or to any advertising service.
2.3 App content you create
- Exercise logs you enter (e.g., exercise names, sets, reps, weights, set types, and any notes you write).
- Date labels and their metadata (e.g., emoji/icon, label name, optional description, colour).
- Workout programs you build or accept, including the training days, rest days, exercises, sets, and reps they contain.
- Body-weight entries you record, with their dates and your chosen unit (kg or lbs).
- App settings, such as your preferred unit of measurement, your currently selected program and program day, and your analytics preference.
- Timestamps and usage metadata (e.g., when an item was created or updated), and streak information derived from your logging activity.
Some of this — body weight in particular, and information you choose to write into notes — may be considered health-related data. We treat it accordingly: see section 4.
2.4 Data we hold about your use of the AI coach
Covered in detail in section 2.5. In summary, we retain a running count of AI tokens you have used (to enforce usage limits) and server-side operational logs of each AI request. We do not store the content of your AI conversations.
2.5 The AI coach (beta)
The AI coach is an optional feature of the App. Nothing in this section happens unless you open the AI tab and send a message: the App does not contact our AI provider in the background, and it never sends anything on its own initiative. If you do not use the coach, none of the processing described here takes place.
Sending a message is what starts it. Each message you send is a deliberate act on your part, and it is that act — made knowing what this policy and our Terms of Service tell you — that we treat as your agreement to the processing described here. This section is the notice: it is where we set out what leaves your device, and we ask you to read it before you use the coach. You can stop at any time by not sending further messages. Stopping does not undo requests already made, and it does not by itself remove the token-usage total or the operational logs described below.
What is sent when you send a message. When you send a message to the coach, the following leaves your device and is processed by our server and by Google’s Gemini API:
- The text of the message you typed.
- The earlier messages in that same conversation, so the coach can follow the thread.
- Today’s date on your device, and your unit and rep-format preferences.
What the coach can read on your behalf. To answer questions about your training, the coach can request your own data from our database. It can read:
- Your exercise logs for a date range it asks for, including exercise names, sets, reps, weights, and notes (limited to a maximum range of 366 days and a capped number of entries per request).
- Your labels, including their names and descriptions.
- Your saved workout programs.
Anything the coach reads this way is included in what is sent to Google’s Gemini API in order to generate a reply. The coach can only ever read your own data: the account it reads from is taken from your verified sign-in session on the server, never from anything the AI model itself produces.
How Google handles it. We use a paid tier of the Gemini API. Under its terms, Google does not use your prompts or the coach’s replies to train or improve its models, and does not have them reviewed by humans for that purpose. They are processed to generate your reply and for Google’s own limited abuse-monitoring and legal obligations.
What the coach is not given. Your name, gender, birthday, and email address are not sent to the AI coach or to Google’s Gemini API.
What we store. Your conversation with the coach is held in the App while you are using it and is not saved to our database. Closing or clearing the chat discards it. A program the coach proposes is only saved if you explicitly accept it.
Operational logs. For each AI request we write a server log entry containing your Firebase UID, whether the request succeeded, your usage tier, the model used, the reasoning level requested of it, token counts (total, input, output, and reasoning), response time, how many characters your message contained, how many messages were in the conversation, which internal tools were called and how many times, whether the reply contained a proposed program, and whether a fallback reply was substituted because the model produced no text. The content of your message is never recorded in these logs — only its length.
Usage limits. We store a running total of the AI tokens used by your account, so we can apply the usage limit shown in the chat. We also apply rate limiting to prevent abuse.
What the coach will not discuss. The coach is limited to training, technique, and programming. It is instructed to decline questions about injuries, pain, and medical issues and to refer you to a doctor or physiotherapist, and to decline questions about nutrition, diet, calories, and supplements and to refer you to a dietitian or doctor. Please treat those limits as real: do not use the coach for health decisions.
Please do not put health information into the App. This matters more than it may look. Anything you type into an exercise note can be read by the coach and sent to Google’s Gemini API along with your message, and we have no way to detect that a note contains medical information rather than training information — to us and to our systems, it is all just text you wrote. Keep injuries, symptoms, diagnoses, medication, and anything else about your health out of your notes and out of the chat. If you have already written something of that kind into a note, you can edit or delete that entry at any time.
Reporting an answer. If the coach produces an answer that is offensive, unsafe, or otherwise inappropriate, a “Report” option under that answer opens your own mail app with the flagged message, and the message you sent that prompted it, already filled in and addressed to us. Nothing is sent unless you choose to send that email yourself. Once you do, that content reaches our inbox like any other email you send us, and is kept for as long as we need it to review the report and improve the coach, then deleted.
Please note. You are interacting with an artificial intelligence system, not a person. The AI coach is in beta and can be wrong. It is not a medical professional and it is not a qualified trainer, and nothing it says is medical, diagnostic, nutritional, or professional advice. Its refusals above are instructions given to a language model, not a guarantee about every answer it will ever produce — so if it does respond to a health or nutrition question, that answer carries no more authority than the rest and should not be relied on. Consult a qualified professional for anything concerning your health. No decision with legal or similarly significant effects is made about you by automated means.
2.6 Analytics
We use Google Analytics for Firebase to understand how the App is used so we can improve it.
We ask first, and you can change your mind. Analytics are off until you agree to them. When you finish setting up your account the App asks whether you are willing to share usage data, and nothing is collected unless you choose “Allow”. Declining costs you nothing — every feature works either way. Whatever you choose, there is an analytics switch in the App’s Settings screen that you can move at any time; turning it off stops collection, including the automatic events described below. Users who set up the App before this question existed have analytics switched off until they turn it on in Settings.
What we report. Analytics events are limited to counts, fixed categories, and yes/no values. We record events for:
- AI coach: a message was sent (where it was sent from, how many characters it contained, how many messages were in the conversation); a reply was received (response time, whether it included a program, what percentage of your allowance is used); a reply failed (the reason); a message could not be sent because one was already in flight or your allowance was spent; the chat was cleared (number of messages); a suggestion was tapped; a proposed program was accepted, regenerated, or failed to save.
- Account: sign-in and sign-up (whether Google or Apple), sign-out, account deletion started, account deleted.
- Exercises: an exercise was logged (unit, number of sets, whether online or offline), edited, or deleted.
- Programs and labels: a program was created (number of days, whether manual or AI-generated), selected, edited, or deleted; a label was created or assigned.
- Body weight: a weight was logged, and the unit used. The weight value itself is not reported.
- Other: offline mode was entered; a setting was changed (which setting, and its new on/off or category value).
- Screen views: the name of the screen you navigated to, e.g.
/(tabs)/calendar.
What is never reported to analytics. By design, no analytics event contains the text of an AI message, an exercise name, a label name or description, a note, a body-weight value, your name, your email address, or any other free text you have written.
Identifiers and automatic data. Your Firebase UID is attached to analytics events so that activity can be grouped per account; it is cleared when you sign out. Google Analytics for Firebase additionally collects its own standard data, which typically includes an app instance identifier, device model, operating system version, app version, language, and an approximate location (such as country or region) derived from your IP address. It also generates automatic events such as first open, app open, and session start. We do not collect precise or GPS location.
2.7 Crash reporting
The App includes Firebase Crashlytics, which collects crash and error reports so we can find and fix the faults that would otherwise keep breaking the App. A crash report typically includes device model, operating system version, app version, the state of the app at the moment of the crash, and a Crashlytics installation identifier, which is stored on your device so that reports from the same installation can be grouped together. We do not deliberately attach your logs, labels, messages, or profile information to crash reports: a crash report does not contain an exercise name, a label, a note, a body-weight value, or anything you typed to the AI coach.
How this differs from analytics. Crash reporting starts with the App and is not governed by the analytics switch in section 2.6 — turning analytics off does not stop it. The two are separated deliberately: analytics measures how the App is used and is therefore asked for and switchable, whereas crash reporting records only that something broke and what the App was doing at the time. We rely on our legitimate interest in keeping the App stable and secure as the basis for it (see section 4). It reports faults, not behaviour, and we do not use it to build any picture of how you use the App.
If you would rather we did not. You have the right to object to processing based on our legitimate interests. Email siarkonyar@gmail.com and we will tell you what we can do to stop it for your installation. Uninstalling the App stops it immediately and completely. We keep this arrangement under review.
2.8 Anti-abuse and device attestation
The App uses Firebase App Check to confirm that requests genuinely come from an unmodified copy of the App rather than from an automated script. This uses Apple’s App Attest / DeviceCheck on iOS and Google Play Integrity on Android. These services assess the integrity of your device and app installation and return a token; the assessment is performed by Apple and Google under their own privacy policies. This is a security measure and cannot be disabled.
2.9 Consent records
We keep a record of the permissions you grant and withdraw. This currently covers one setting: your analytics preference (section 2.6).
Each time you change it, we append a record to a server-side log containing your Firebase UID, which setting changed, the new value, the previous value (or an indication that this was your first choice), and a timestamp generated by our server rather than taken from your device. We keep this so that we can demonstrate what you chose and when. Records of an earlier, separate AI coach permission remain in this log from the period when the App asked for one; they are not removed, because a log that can be edited afterwards cannot evidence anything.
The log is deliberately append-only: entries are added, and are not edited or removed in the ordinary course. It is stored separately from your account data and is retained after account deletion — see section 7 for how long and why. It contains no message content, none of the content you create, and no contact details.
2.10 Device and network data
- Basic technical data sent by your device when contacting Firebase and our server functions (e.g., IP address at the time of the request, device model, OS version). We do not collect precise location.
2.11 Local (offline) storage on your device
- When you are offline, exercises you log are stored locally on your device using AsyncStorage.
- The App also caches data it has already loaded — such as your logs, labels, programs, weight entries, and settings — on your device so screens open quickly and work without a connection.
- This local data stays on your device. It is removed when you uninstall the App or clear the App’s data.
2.12 Data we do not collect
- We do not collect your precise geolocation, contacts, photos, camera, or microphone data.
- We do not collect payment information within the App.
- We do not use advertising SDKs and do not build advertising profiles.
3. How we use your information
- To provide core features: account creation, secure sign-in, creating and viewing exercise logs, assigning labels to dates, building and following programs, tracking body weight, and syncing data across devices.
- To provide the AI coach when you choose to use it, and to enforce its usage limits fairly.
- To maintain and improve the App, including debugging, crash analysis, and understanding which features are used.
- To protect the App and our infrastructure against abuse, automated attacks, and excessive use.
- To communicate with you about important updates, security alerts, and changes to this policy or terms.
- To comply with legal obligations and enforce our terms and policies.
We do not use your content to train our own machine-learning models, and our AI provider does not use it to train theirs (see section 2.5).
4. Legal bases for processing (EEA/UK users)
- Performance of a contract: to provide and operate the App and your account; to store and display the exercise logs, labels, programs, body-weight entries, and settings that make up its core features; and to run the AI coach when you send it a message. Sending a message is a request for a service, and passing that message and the context it needs to our AI provider is what delivering the service requires.
- Legitimate interests: to maintain security, prevent misuse and abuse, understand aggregate feature usage, and improve the App.
- Legitimate interests — crash reporting: crash and error reports (section 2.7) are collected on the basis of our legitimate interest in keeping the App stable, functional, and secure, rather than on your consent. We have weighed that interest against your rights and consider it proportionate: the data is limited to technical fault information and a device-level installation identifier, it contains none of the content you create, and it is not used to profile you, to measure your behaviour, or for any advertising purpose. You may object at any time — see sections 2.7 and 8.
- Consent — analytics (Article 6(1)(a)): analytics are processed on the basis of your consent, asked for during setup and withdrawable at any time through the Settings switch. Withdrawing stops future collection; it does not undo collection that already happened.
- Health-related data you store in the App (Article 9(2)(a)): body-weight entries, and any health information you choose to write into a note, may be special category data. We process them for one purpose only — recording and showing you your own training history — and never to profile you, to advertise to you, or to make any decision about you. You can withdraw at any time by deleting the entries or your account, which leaves nothing behind.
- Health-related data sent to our AI provider (Article 9(2)(a)): when you send a message to the AI coach, the coach may read your exercise logs — including anything you have written into a note — and that content is sent to Google’s Gemini API to generate your reply. Where that content is health-related, we rely on your explicit consent, given by your deliberate act of sending a message to the coach after being told, in section 2.5 of this policy and in section 5 of the Terms of Service, what doing so involves. You withdraw it by not sending further messages, and you can remove the underlying content at any time by deleting the entries or your account. Because we cannot inspect what you write, the safest course is not to put medical or health information into your notes or into a message to the coach at all — see section 2.5.
- Legitimate interests — consent records: the consent log described in section 2.9 is retained, including after account deletion, on the basis of our legitimate interest in being able to establish, exercise, and defend legal claims about what you agreed to and when. This is also why the right to erasure does not reach it — see Article 17(3)(e), section 7, and section 8.1. The log holds only your Firebase UID, the setting, the values, and the timestamp.
- Legal obligation: to comply with applicable laws and requests from authorities.
5. Sharing and disclosure
- Google Firebase: Firebase Authentication, Cloud Firestore, Cloud Functions, Cloud Logging, Firebase App Check, Google Analytics for Firebase, and Firebase Crashlytics host and process data on our behalf.
- Google Gemini API: when you use the AI coach, your messages and the training data described in section 2.5 are sent to Google’s Gemini API to generate a reply. We use a paid tier of that API, under which Google does not use your prompts or the replies to train or improve its models, and does not subject them to human review for that purpose. Google processes this data as our service provider.
- Authentication providers: Google and Apple process your sign-in data per their own privacy policies.
- Device attestation: Apple (App Attest / DeviceCheck) and Google (Play Integrity) assess device and app integrity as described in section 2.8.
- Legal reasons: We may disclose information if required to comply with law, regulation, or legal process, or to protect rights, property, or safety.
- Business changes: If we are involved in a merger, acquisition, or asset sale, your information may be transferred as permitted by law and you will be notified where required.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
6. Advertising
No ads at this time. If we later introduce advertising or ad-related SDKs (e.g., AdMob), we will update this policy, request any required consent (where applicable), and reflect the change in the app stores’ Data Safety/App Privacy sections before ads begin.
7. Data retention
- We keep your account data and content — exercise logs, labels, programs, body-weight entries, profile, and settings — for as long as your account is active.
- Account deletion. You can delete your account from within the App. This deletes your account content from our database and deletes your authentication account. For your security you will be asked to sign in again before the deletion proceeds; if you cancel at that point, nothing is deleted.
- AI usage counter. The running total of AI tokens used by your account (section 2.5) is deleted automatically once your authentication account is deleted. It holds a number and nothing else — no message content and no training data.
- AI conversations are not stored on our servers at all, so there is nothing to delete server-side. They are discarded when you clear the chat or close the App. The exception is a message you choose to report, which reaches us by email; we keep that for as long as we need it to review the report, then delete it.
- AI operational logs (section 2.5) are held in Google Cloud Logging for the purpose of monitoring cost and abuse and expire automatically after 30 days, which is the retention period of the default log bucket.
- Consent records (section 2.9) are retained after account deletion. We keep them because their purpose is to evidence what you chose and when, and a record that can be erased by the party it concerns cannot serve that purpose. They contain only your Firebase UID, the setting, the values, and the timestamp — no content and no contact details. We keep them for six years from the date of the record, which matches the period in which a related legal claim could be brought against us, and then delete them.
- Crash reports are retained by Firebase Crashlytics for 90 days under Google’s retention schedule, and then expire automatically.
- Analytics data collected through Google Analytics for Firebase is retained under the retention period configured for our property, which is currently two months for user-level and event-level data. Aggregated reports that contain no individual-level data may be retained for longer.
- Local data on your device remains until you uninstall the App or clear its data.
- If you request deletion by email instead, we will delete or anonymise your personal data within a reasonable period unless we must retain it for legal, security, or operational continuity reasons.
8. Your rights
8.1 EEA/UK residents (GDPR/UK GDPR)
- Access, rectification, erasure, restriction, objection, and data portability.
- One limit on erasure. The consent records described in section 2.9 are not erased when you delete your account. Article 17(3)(e) of the UK GDPR permits us to keep personal data where it is necessary for the establishment, exercise, or defence of legal claims, and a record of what you agreed to that the other party can delete could not serve that purpose. Everything else we hold about you is deleted. Section 7 gives the retention period.
- Where processing is based on consent, you may withdraw consent at any time. Withdrawal does not affect processing carried out before you withdrew.
- You may lodge a complaint with your local supervisory authority.
8.2 California residents (CCPA/CPRA)
- Right to know, delete, correct, and non-discrimination.
- We do not “sell” or “share” personal information as defined by the CPRA.
8.3 Exercising your rights
You can delete your account and its content directly in the App, under Settings. To exercise any other right, or to request a copy of your data, email siarkonyar@gmail.com. We may need to verify your identity and the ownership of the account.
9. International data transfers
Our database and server functions are hosted in the United Kingdom region (europe-west2). Other services we rely on — including Google Analytics for Firebase, Firebase Crashlytics, Google Cloud Logging, and the Google Gemini API — may process data in other regions, including the United States. Where required, we rely on appropriate safeguards for international transfers, such as the standard contractual clauses or equivalent mechanisms offered by those service providers.
10. Security
We use reasonable technical and organisational measures to protect your information, including Firebase Authentication, database security rules that restrict each account to its own data, server-side verification of your identity on every AI request, Firebase App Check to reject requests that do not come from the genuine App, rate limiting, and encrypted transport. Our AI provider credentials are held in a managed secret store and are not present in the App. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
11. Children’s privacy
You must be at least 13 years old to hold an account. Setup asks for your date of birth, and an account is not created for a date of birth below that age. The App is intended for a general audience and is not directed at children.
Some countries in the EEA set a higher age — up to 16 — below which a child cannot consent to a service like this one on their own. If you are under that age where you live, you may use the App only with the permission of a parent or guardian.
We do not knowingly collect personal data from anyone below the minimum age. If you believe a child has provided us with personal data, contact us at siarkonyar@gmail.com and we will delete it.
12. Third-party services
- Google Firebase — Authentication, Cloud Firestore, Cloud Functions, Cloud Logging, App Check, Analytics, Crashlytics.
- Google Gemini API — powers the AI coach.
- Google Sign-In and Sign in with Apple — authentication.
- Apple App Attest / DeviceCheck and Google Play Integrity — device and app integrity checks.
These services process your data under their own terms and privacy policies.
13. Data Safety (Google Play) and App Privacy (App Store)
We disclose our data practices in the stores’ required sections. Those disclosures reflect the data types described in this policy and will be updated if our practices change.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy at the link provided in the app stores and update the effective date. Material changes will be communicated as required by law.
15. Contact
Data controller: Zafer Siar Konyar
Address: Flat 5, Avery Hill Road, Greenwich, London SE9 2ER, United Kingdom
Email: siarkonyar@gmail.com
If you are in the UK and are not satisfied with our response, you may complain to the Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the EEA, you may complain to the supervisory authority in your country.
16. Summary of data categories
- Account: email address, authentication tokens, Firebase UID.
- Profile: name, gender, birthday (required at setup, used to check the minimum age of 13).
- Content you create: exercise logs (including notes), labels, programs, body-weight entries, settings, streaks.
- AI coach (used only when you send it a message): your messages and conversation history plus the logs, labels, and programs the coach reads, sent to Google’s Gemini API. Your name, gender, birthday, and email are not. Conversations are not stored on our servers. Token usage totals and content-free operational logs are retained; the usage total is deleted with your account.
- Analytics (off until you agree; switchable in Settings): feature-usage events limited to counts, categories, and yes/no values; screen names; Firebase UID; plus Google’s standard app-instance, device, and approximate-location-from-IP data. No free text, no weight values, no message content.
- Diagnostics: crash and error reports via Crashlytics; AI operational logs in Cloud Logging.
- Security: device and app integrity assessments via App Check, App Attest/DeviceCheck, and Play Integrity.
- Stored on device: offline exercise logs and a cache of your loaded data, until you uninstall or clear the App’s data.
- Not collected: precise location, contacts, photos, camera, microphone, payment data.
- Sharing: with the service providers listed in section 12. Not sold, not shared for advertising.