Privacy Policy – Hercule – Fitness Chronicle

Effective date: 1 September 2026
Previous version: 17 October 2025

This Privacy Policy explains how Hercule – fitness chronicle (the “App”) collects, uses, and shares information.

The data controller is:
Zafer Siar Konyar (“we”, “us”, or “our”)
Flat 5, Avery Hill Road, Greenwich, London SE9 2ER, United Kingdom
siarkonyar@gmail.com

We are established in the United Kingdom. If you have questions about this policy or about how your data is handled, contact us at the address above.

0. What changed in this version

This update reflects the following changes:

1. Scope

This policy applies to the App on Android and iOS and to any related services that link to this policy.

2. What we collect

2.1 Account and authentication

2.2 Profile information you provide

When you first set up the App, we ask for:

This information is stored on your account record and is used to personalise the App. It is not sent to the AI coach or to any advertising service.

2.3 App content you create

Some of this — body weight in particular, and information you choose to write into notes — may be considered health-related data. We treat it accordingly: see section 4.

2.4 Data we hold about your use of the AI coach

Covered in detail in section 2.5. In summary, we retain a running count of AI tokens you have used (to enforce usage limits) and server-side operational logs of each AI request. We do not store the content of your AI conversations.

2.5 The AI coach (beta)

The AI coach is an optional feature of the App. Nothing in this section happens unless you open the AI tab and send a message: the App does not contact our AI provider in the background, and it never sends anything on its own initiative. If you do not use the coach, none of the processing described here takes place.

Sending a message is what starts it. Each message you send is a deliberate act on your part, and it is that act — made knowing what this policy and our Terms of Service tell you — that we treat as your agreement to the processing described here. This section is the notice: it is where we set out what leaves your device, and we ask you to read it before you use the coach. You can stop at any time by not sending further messages. Stopping does not undo requests already made, and it does not by itself remove the token-usage total or the operational logs described below.

What is sent when you send a message. When you send a message to the coach, the following leaves your device and is processed by our server and by Google’s Gemini API:

What the coach can read on your behalf. To answer questions about your training, the coach can request your own data from our database. It can read:

Anything the coach reads this way is included in what is sent to Google’s Gemini API in order to generate a reply. The coach can only ever read your own data: the account it reads from is taken from your verified sign-in session on the server, never from anything the AI model itself produces.

How Google handles it. We use a paid tier of the Gemini API. Under its terms, Google does not use your prompts or the coach’s replies to train or improve its models, and does not have them reviewed by humans for that purpose. They are processed to generate your reply and for Google’s own limited abuse-monitoring and legal obligations.

What the coach is not given. Your name, gender, birthday, and email address are not sent to the AI coach or to Google’s Gemini API.

What we store. Your conversation with the coach is held in the App while you are using it and is not saved to our database. Closing or clearing the chat discards it. A program the coach proposes is only saved if you explicitly accept it.

Operational logs. For each AI request we write a server log entry containing your Firebase UID, whether the request succeeded, your usage tier, the model used, the reasoning level requested of it, token counts (total, input, output, and reasoning), response time, how many characters your message contained, how many messages were in the conversation, which internal tools were called and how many times, whether the reply contained a proposed program, and whether a fallback reply was substituted because the model produced no text. The content of your message is never recorded in these logs — only its length.

Usage limits. We store a running total of the AI tokens used by your account, so we can apply the usage limit shown in the chat. We also apply rate limiting to prevent abuse.

What the coach will not discuss. The coach is limited to training, technique, and programming. It is instructed to decline questions about injuries, pain, and medical issues and to refer you to a doctor or physiotherapist, and to decline questions about nutrition, diet, calories, and supplements and to refer you to a dietitian or doctor. Please treat those limits as real: do not use the coach for health decisions.

Please do not put health information into the App. This matters more than it may look. Anything you type into an exercise note can be read by the coach and sent to Google’s Gemini API along with your message, and we have no way to detect that a note contains medical information rather than training information — to us and to our systems, it is all just text you wrote. Keep injuries, symptoms, diagnoses, medication, and anything else about your health out of your notes and out of the chat. If you have already written something of that kind into a note, you can edit or delete that entry at any time.

Reporting an answer. If the coach produces an answer that is offensive, unsafe, or otherwise inappropriate, a “Report” option under that answer opens your own mail app with the flagged message, and the message you sent that prompted it, already filled in and addressed to us. Nothing is sent unless you choose to send that email yourself. Once you do, that content reaches our inbox like any other email you send us, and is kept for as long as we need it to review the report and improve the coach, then deleted.

Please note. You are interacting with an artificial intelligence system, not a person. The AI coach is in beta and can be wrong. It is not a medical professional and it is not a qualified trainer, and nothing it says is medical, diagnostic, nutritional, or professional advice. Its refusals above are instructions given to a language model, not a guarantee about every answer it will ever produce — so if it does respond to a health or nutrition question, that answer carries no more authority than the rest and should not be relied on. Consult a qualified professional for anything concerning your health. No decision with legal or similarly significant effects is made about you by automated means.

2.6 Analytics

We use Google Analytics for Firebase to understand how the App is used so we can improve it.

We ask first, and you can change your mind. Analytics are off until you agree to them. When you finish setting up your account the App asks whether you are willing to share usage data, and nothing is collected unless you choose “Allow”. Declining costs you nothing — every feature works either way. Whatever you choose, there is an analytics switch in the App’s Settings screen that you can move at any time; turning it off stops collection, including the automatic events described below. Users who set up the App before this question existed have analytics switched off until they turn it on in Settings.

What we report. Analytics events are limited to counts, fixed categories, and yes/no values. We record events for:

What is never reported to analytics. By design, no analytics event contains the text of an AI message, an exercise name, a label name or description, a note, a body-weight value, your name, your email address, or any other free text you have written.

Identifiers and automatic data. Your Firebase UID is attached to analytics events so that activity can be grouped per account; it is cleared when you sign out. Google Analytics for Firebase additionally collects its own standard data, which typically includes an app instance identifier, device model, operating system version, app version, language, and an approximate location (such as country or region) derived from your IP address. It also generates automatic events such as first open, app open, and session start. We do not collect precise or GPS location.

2.7 Crash reporting

The App includes Firebase Crashlytics, which collects crash and error reports so we can find and fix the faults that would otherwise keep breaking the App. A crash report typically includes device model, operating system version, app version, the state of the app at the moment of the crash, and a Crashlytics installation identifier, which is stored on your device so that reports from the same installation can be grouped together. We do not deliberately attach your logs, labels, messages, or profile information to crash reports: a crash report does not contain an exercise name, a label, a note, a body-weight value, or anything you typed to the AI coach.

How this differs from analytics. Crash reporting starts with the App and is not governed by the analytics switch in section 2.6 — turning analytics off does not stop it. The two are separated deliberately: analytics measures how the App is used and is therefore asked for and switchable, whereas crash reporting records only that something broke and what the App was doing at the time. We rely on our legitimate interest in keeping the App stable and secure as the basis for it (see section 4). It reports faults, not behaviour, and we do not use it to build any picture of how you use the App.

If you would rather we did not. You have the right to object to processing based on our legitimate interests. Email siarkonyar@gmail.com and we will tell you what we can do to stop it for your installation. Uninstalling the App stops it immediately and completely. We keep this arrangement under review.

2.8 Anti-abuse and device attestation

The App uses Firebase App Check to confirm that requests genuinely come from an unmodified copy of the App rather than from an automated script. This uses Apple’s App Attest / DeviceCheck on iOS and Google Play Integrity on Android. These services assess the integrity of your device and app installation and return a token; the assessment is performed by Apple and Google under their own privacy policies. This is a security measure and cannot be disabled.

2.9 Consent records

We keep a record of the permissions you grant and withdraw. This currently covers one setting: your analytics preference (section 2.6).

Each time you change it, we append a record to a server-side log containing your Firebase UID, which setting changed, the new value, the previous value (or an indication that this was your first choice), and a timestamp generated by our server rather than taken from your device. We keep this so that we can demonstrate what you chose and when. Records of an earlier, separate AI coach permission remain in this log from the period when the App asked for one; they are not removed, because a log that can be edited afterwards cannot evidence anything.

The log is deliberately append-only: entries are added, and are not edited or removed in the ordinary course. It is stored separately from your account data and is retained after account deletion — see section 7 for how long and why. It contains no message content, none of the content you create, and no contact details.

2.10 Device and network data

2.11 Local (offline) storage on your device

2.12 Data we do not collect

3. How we use your information

We do not use your content to train our own machine-learning models, and our AI provider does not use it to train theirs (see section 2.5).

4. Legal bases for processing (EEA/UK users)

5. Sharing and disclosure

6. Advertising

No ads at this time. If we later introduce advertising or ad-related SDKs (e.g., AdMob), we will update this policy, request any required consent (where applicable), and reflect the change in the app stores’ Data Safety/App Privacy sections before ads begin.

7. Data retention

8. Your rights

8.1 EEA/UK residents (GDPR/UK GDPR)

8.2 California residents (CCPA/CPRA)

8.3 Exercising your rights

You can delete your account and its content directly in the App, under Settings. To exercise any other right, or to request a copy of your data, email siarkonyar@gmail.com. We may need to verify your identity and the ownership of the account.

9. International data transfers

Our database and server functions are hosted in the United Kingdom region (europe-west2). Other services we rely on — including Google Analytics for Firebase, Firebase Crashlytics, Google Cloud Logging, and the Google Gemini API — may process data in other regions, including the United States. Where required, we rely on appropriate safeguards for international transfers, such as the standard contractual clauses or equivalent mechanisms offered by those service providers.

10. Security

We use reasonable technical and organisational measures to protect your information, including Firebase Authentication, database security rules that restrict each account to its own data, server-side verification of your identity on every AI request, Firebase App Check to reject requests that do not come from the genuine App, rate limiting, and encrypted transport. Our AI provider credentials are held in a managed secret store and are not present in the App. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

11. Children’s privacy

You must be at least 13 years old to hold an account. Setup asks for your date of birth, and an account is not created for a date of birth below that age. The App is intended for a general audience and is not directed at children.

Some countries in the EEA set a higher age — up to 16 — below which a child cannot consent to a service like this one on their own. If you are under that age where you live, you may use the App only with the permission of a parent or guardian.

We do not knowingly collect personal data from anyone below the minimum age. If you believe a child has provided us with personal data, contact us at siarkonyar@gmail.com and we will delete it.

12. Third-party services

These services process your data under their own terms and privacy policies.

13. Data Safety (Google Play) and App Privacy (App Store)

We disclose our data practices in the stores’ required sections. Those disclosures reflect the data types described in this policy and will be updated if our practices change.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy at the link provided in the app stores and update the effective date. Material changes will be communicated as required by law.

15. Contact

Data controller: Zafer Siar Konyar
Address: Flat 5, Avery Hill Road, Greenwich, London SE9 2ER, United Kingdom
Email: siarkonyar@gmail.com

If you are in the UK and are not satisfied with our response, you may complain to the Information Commissioner’s Office (ICO) at ico.org.uk. If you are in the EEA, you may complain to the supervisory authority in your country.

16. Summary of data categories