Privacy Policy

Last updated: 2026-09-05

This Privacy Policy explains what information Kronos collects, how we use it, and the choices you have. It applies to the Kronos mobile application and related services, which are operated by Muller Labs, LLC (“we,” “us”), the data controller for the personal information described here. Our contact details appear at the end of this Policy.

1. Information You Provide

When you create an account and use the Service, we collect:

• Account details: email address, display name, locale, and region. • Fitness preferences: gender, date of birth, self-reported fitness level, primary training goal, and any free-text notes you enter in the “injuries” or “guidelines” fields. • Equipment and locations: names of training locations and lists of equipment you tell us are available. • Workout activity: the workouts generated for you, the sessions you start, time spent active, exercises modified or skipped, perceived difficulty ratings, and any notes you add. • Exercise feedback: love/like/neutral/dislike/hate ratings you assign to individual exercises. • Challenge participation: the challenges you create or join, the display name you choose for them, and your daily completion within them. • Feedback submissions: messages, optional screenshots, and the in-app context (such as which screen you were on) when you tap the feedback button. • Health and fitness data: if you connect Apple Health or Health Connect, your completed workouts and body weight; if you run a workout from your Apple Watch, a summary of your heart rate during that workout. Both are described in section 5.

2. Information Collected Automatically

When you use the app we automatically collect:

• AI usage data: the AI model used to generate each workout, token counts, and estimated cost. We use this to monitor system health and enforce free-tier limits. • Device context attached to feedback submissions: app version, platform (iOS / Android / web), and current locale. • Subscription state: whether your account currently has an active Kronos Pro entitlement, the store of purchase, and the renewal/expiry date. Payment card information is handled directly by Apple or Google and never reaches our servers. • Product analytics events (only if analytics is enabled in your build): interaction events linked to your account ID. These are pseudonymous (they identify your account, not your name) and are used to understand which features are working and which need improvement. • Push notification tokens: if you allow notifications, a device push token used to deliver them. You can revoke this at any time in your device settings. • Crash and diagnostic data: when the app crashes or hits an error, our crash-reporting provider receives diagnostic events including your device model, OS version, app version, IP address, and (for a sample of sessions) a masked session replay, a screen recording in which text and images are blanked out before leaving your device. We use this to find and fix bugs.

3. What We Do Not Collect

Kronos does not request or collect any of the following:

• Apple Health or Health Connect data, unless you choose to connect them as described in section 5. • Precise or coarse location (the app does not request location permission). • Motion or accelerometer data. • Camera images, except screenshots you explicitly attach to feedback. • Microphone audio. • Contacts, calendar, or photos beyond what you explicitly share.

4. How We Use Information

We use the information we collect to:

• Provide the Service, including generating personalised workouts. The free-text contents of your preferences (including the “injuries” field) are included in prompts sent to our AI providers so that the models can take them into account. • Authenticate you and maintain your account. • Operate billing and entitlement features through our payment partners. • Improve the Service, debug issues, and develop new features. • Communicate with you about the Service, including responding to feedback and (if you opt in) sending marketing messages. • Comply with legal obligations and protect against fraud, abuse, and harm to users or the Service.

Where laws such as the GDPR apply, our legal bases for this processing are: performance of our contract with you (providing the Service, your account, and billing), our legitimate interests (improving, securing, and debugging the Service), your consent (marketing messages and the health-related details described in the next section), and compliance with legal obligations.

The optional “injuries” and “guidelines” fields may contain information about your health, such as an injury, surgery, pregnancy, or medical condition. We treat that text as sensitive information: we use it only to generate your workouts, we send it to our AI providers only for that purpose, and we never use it for advertising, never sell it, and never share it except as described in this Policy.

By entering information into these fields, you expressly consent to this processing. If you prefer not to share health information, leave the fields blank; the Service works without them, and you can edit or clear them at any time in your preferences.

Apple Health and Health Connect: if you choose to connect Kronos to Apple Health (on iOS) or Health Connect (on Android), Kronos can, with your permission, add your completed workouts to your health record (the workout type, start and end time, duration, and an estimated energy burn) and read your body weight so that your log and load recommendations stay current. We request only the data types listed here, we use data received from Apple Health or Health Connect only to provide these features, and we never use it for advertising, never sell it, and never share it except as described in this Policy. Our use of data received from Health Connect complies with the Health Connect permissions policy, including its Limited Use requirements.

Apple Watch: if you run a workout from your Apple Watch, Kronos also reads your heart rate during that workout and stores a summary of it (average, maximum, and per-block recovery) with the workout in your account. Kronos never stores individual heart-rate samples, never uses this data for advertising, never sells it, and deletes it with your account.

Connecting is optional and off by default. You can disconnect at any time (on iOS in the Health app’s sharing settings, on Android in Health Connect’s app permissions), which stops all reading and writing. Body weight readings imported this way are stored with your account like weight you enter yourself and are deleted when you delete your account.

6. Information Shared With Other Users

Some features of Kronos are social, and using them shares some of your information with other people:

• Challenges and crews: when you join a challenge, the other members can see the display name you chose, whether you have completed each day, your streak within the challenge, and kudos you send or receive. Someone opening an invite link can see the challenge name and the display names of members who have already joined. • Crew digests: challenges can send members a periodic summary that includes each member’s recent activity in that challenge. • Sharing features: result cards and invite links that you choose to share contain your display name and the data shown on them, and anyone you share them with can see that content.

Your display name is chosen by you and does not have to be your real name. Leaving a challenge stops the sharing described above for that challenge. We never share your “injuries” or “guidelines” text, your preferences, or your full workout history with other users.

7. Third-Party Service Providers

We share information with the following processors who help us operate the Service:

• Convex (database and backend hosting): stores essentially all of your account data, preferences, workouts, and sessions. • AI providers, currently Google (Gemini API) and OpenAI: receive the prompt content used to generate each workout, including your preferences, equipment, goals, the free-text “injuries” and “guidelines” fields. We use these providers under paid API terms that prohibit them from using this content to train their models. If we change providers, we will hold any new provider to the same standard and update this Policy. • Expo (push notification delivery): receives your device push token and the content of notifications sent to you, if you allow notifications. • RevenueCat (subscription management): receives a pseudonymous identifier and your purchase history. • PostHog (product analytics): receives the pseudonymous interaction events described above, when analytics is enabled. • Sentry (crash reporting and diagnostics): receives the crash and diagnostic data described above, processed on Sentry’s European Union servers. • Resend (transactional email): receives your email address and display name to deliver account emails such as verification codes, password resets, and welcome messages. • Apple and Google: handle authentication and in-app purchases according to their own privacy policies.

Separately from these processors, you can choose to connect services that operate under their own privacy policies:

• Strava: if you connect your Strava account, we store your Strava athlete ID and access tokens, and after each completed workout we send Strava an activity that includes the workout title, duration, and (depending on your sync settings) the exercise list, your notes, and the name of any challenge the workout was part of. What Strava then shows to other people is controlled by your Strava privacy settings, not by us. You can disconnect Strava at any time in the app, which stops all syncing.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising (as those terms are defined by the CCPA).

8. International Transfers

We are based in the United States, and the providers listed above process your information mainly on servers in the United States (crash and diagnostic data is processed on Sentry’s European Union servers). If you use the Service from outside the U.S. (including Latin America, the United Kingdom, or the European Economic Area), your information will be transferred to and processed in the United States, which may have different data-protection laws than your country. Where required, we rely on safeguards such as our processors’ data-processing agreements and standard contractual clauses.

9. Data Retention

We retain your information for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce our agreements. You can delete your account and its data at any time directly in the app (Profile, then Delete account), or by emailing us at the address below. Deleting your account does not cancel an active subscription; manage that through your Apple or Google account settings.

10. Your Choices and Rights

Depending on where you live, you may have rights under laws such as the GDPR, the UK GDPR, Brazil’s LGPD, or the CCPA to access, correct, port, or delete your personal information, to object to or restrict certain processing, and to withdraw consent you have given. You also have the right to lodge a complaint with your local data-protection authority.

You may opt out of marketing communications at any time from within the app or by following the unsubscribe link in any marketing email.

Other controls in the app: you can disable notifications in your device settings, choose what a Strava sync includes (or disconnect Strava entirely), leave a challenge at any time, choose any display name for community features, and edit or clear the “injuries” and “guidelines” fields whenever you like.

To exercise any of these rights, please contact us at the address below. We will not discriminate against you for exercising them.

11. Children

The Service is intended for adults aged 18 and over. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us with personal information, please contact us so we can delete it.

12. Security

We use commercially reasonable administrative, technical, and physical safeguards to protect the information we hold. No method of transmission or storage is fully secure, however, and we cannot guarantee absolute security.

13. Changes

We may update this Policy from time to time. Material changes will be signalled by an updated version date above and a new in-app consent prompt the next time you open the app.

14. Contact

Privacy questions or rights requests can be sent to legal@kronosstudio.app, or by mail to Muller Labs, LLC, c/o Legalinc Corporate Services Inc., 131 Continental Dr, Suite 305, Newark, DE 19713, USA.