Privacy Policy

Last Updated: February 14, 2026

Everline Holdings LLC (“we,” “us,” or “our”) operates the Kova mobile application, its companion Apple Watch application, and the withkova.com website (collectively, the “Service”). This Privacy Policy describes how we collect, use, store, and protect your information when you use the Service.

1. Information We Collect

Account Information

Beta Waitlist Information

If you apply for beta access through our website, we collect the information you provide in the application form, including your name, email address, user type, fitness apps you currently use, fitness goals, logging frequency, and any optional details you share. This data is used solely to evaluate your application and contact you about beta access.

Body & Health Data

Fitness & Nutrition Data

AI-Powered Food Recognition

When you use the photo-based food logging feature, photos of food you take or select are sent to Google's Gemini API (via our secure server) for nutritional analysis. The photo is processed to identify food items and estimate portion sizes. We do not store the photos on Google's servers — they are used for real-time analysis only and are subject to Google's API Terms of Service.

Food searches may also query the USDA Food Data Central API and Open Food Facts API. Only the search term or barcode is sent — no personal information is included in these requests.

Running & Location Data

Location data is collected only during active run tracking — either on your phone or Apple Watch — and only when you have granted location permission. We do not track your location in the background outside of active runs.

Apple Watch Data

If you use the companion Apple Watch app, the following data may be collected on the watch and transmitted to your phone:

Data is transmitted between the watch and phone using Apple's encrypted WatchConnectivity framework. Watch-tracked run data (including GPS routes) is transferred to your phone for storage when a run is completed. The Apple Watch does not independently communicate with our servers.

Health Platform Data

With your explicit permission, the App may read from and write to:

This integration is optional and requires your explicit consent through the platform's permission dialogs. Health platform data is used solely to sync your fitness data between the App and your device's health platform. Health sync settings are stored locally on your device and are not sent to our servers.

Third-Party Fitness Platform Data

With your explicit action, the App can sync activity data with the following third-party fitness platforms:

When you connect a platform, the following data may be shared:

DataStravaGarminFitbit
Activity name & typeYesYesYes
Start time & durationYesYesYes
DistanceYesYesYes
CaloriesYesYesYes
GPS route & elevationYesYesNo
Heart rateYesYesYes (runs only)
Splits/lapsYesYesNo
Workout exercise detailsYes (summary)Yes (summary)No

Strava import: If you enable Strava import, the App can also retrieve your activity history from Strava (activity names, distances, durations, routes, heart rate, and calories) and store it as run logs.

Connecting to these platforms requires you to authenticate through each platform's own login screen. See Section 4 for details on how authentication tokens are handled.

Strava API usage monitoring: Strava may collect data about your use of Kova's Strava integration, including API usage metrics. This data is collected by Strava and is subject to Strava's Privacy Policy.

Motion & Sensor Data

Reproductive Health Data (Primarily Local)

The App includes an optional reproductive health tracker. This data is stored on your device by default and is not transmitted to our servers. This includes:

This data is encrypted on your device using keys stored in your device's secure enclave (iOS Keychain / Android Keystore). See Section 3 for details.

Voluntary sharing with a trainer or partner: If you explicitly choose to share cycle or pregnancy information with a connected trainer or partner, a limited summary (cycle phase and day, or pregnancy week and due date) is transmitted to our servers. This shared data auto-expires after 48 hours and is deleted immediately if you revoke sharing or disconnect. Full detailed logs (symptoms, temperatures, discharge, etc.) are never shared — only high-level summaries.

Optional encrypted cloud backup: You may choose to back up your reproductive health data to our servers. If you enable this feature, your data is encrypted on your device with a password you set before it leaves your device. We cannot read, decrypt, or access the contents of these backups. See Section 3 for details.

Messaging Data

If you use the messaging feature (trainer–client or partner communication):

You may enable auto-deletion of message history (30, 60, or 90 days) in your settings.

Subscription & Purchase Data

In-app purchases and subscriptions are processed through Apple's App Store or Google Play. We use RevenueCat to manage subscription status. RevenueCat receives your anonymized app user ID and purchase receipts from the app store — we do not receive or store your payment card details. See RevenueCat's Privacy Policy for details.

Analytics & Usage Data

We use PostHog to collect anonymous usage analytics to understand how the App is used and improve the experience. This includes:

PostHog is configured to mask all text and images in session recordings and block sensitive fields (weight, height, email, coordinates, period data, messages, photos). You can opt out of analytics in the App's settings. See PostHog's Privacy Policy for details.

Device & Technical Data

2. How We Use Your Information

We use the information we collect to:

We do not:

3. Data Storage & Security

Cloud Data

Most app data is stored on servers provided by Supabase (a cloud database provider). We use the following security measures:

Local-Only Data (Reproductive Health)

Reproductive health data is stored on your device using encrypted SQLite:

Encrypted Cloud Backup (Reproductive Health — Optional)

If you enable cloud backup for your reproductive health data:

Third-Party Platform Tokens

When you connect to Strava, Garmin Connect, or Fitbit:

Apple Watch Data

4. Third-Party Services

The App uses the following third-party services:

ServicePurposeData Shared
SupabaseAuthentication, database, file storage, edge functionsAccount and app data (excluding reproductive health data, unless encrypted cloud backup is enabled or cycle/pregnancy summary is shared)
Google Sign-InOptional login methodEmail, name (from Google)
Apple Sign-InOptional login methodEmail, name (from Apple)
Google Gemini APIAI-powered food photo recognitionFood photos (processed in real-time, not stored by us)
Open Food FactsFood/nutrition database lookupsSearch queries, barcode scans (no user-identifiable data)
USDA Food Data CentralFood/nutrition database lookupsSearch queries (no user-identifiable data)
Google MapsMap display for run trackingMap tile requests with viewport coordinates (no user-identifiable data)
RevenueCatSubscription and purchase managementAnonymized app user ID, purchase receipts from app stores
PostHogAnonymous usage analyticsFeature usage events, device type, app version (PII masked, opt-out available)
Expo Push NotificationsDelivering push notificationsExpo push token, notification content
Expo Application ServicesApp updates (over-the-air)Device platform, app version, runtime version
Apple Health / Health ConnectOptional health data syncSteps, weight, heart rate, workouts (only with your explicit permission)
StravaOptional activity sync & importRun/workout data including GPS routes, heart rate, and exercise summaries (only with your explicit action)
Garmin ConnectOptional activity syncRun/workout data including GPS routes and heart rate (only with your explicit action)
FitbitOptional activity syncRun/workout summaries including duration, distance, and calories (only with your explicit action)

Each third-party service has its own privacy policy governing how it handles data. In particular, data obtained from Strava is also subject to Strava's Privacy Policy. We encourage you to review the privacy policies of all connected services.

5. Trainer–Client Data Sharing

If you connect with a personal trainer through the App:

6. Partner Sharing

You may optionally link a partner account for mutual sharing. Partner sharing is controlled independently from trainer sharing. You can choose to share:

All partner sharing can be disabled at any time. Disconnecting a partner immediately revokes all shared data access.

7. Push Notifications

The App may send push notifications for:

You can disable any or all notification categories within the App's settings. Your Expo push token is stored on our servers and deleted when you sign out or delete your account.

Notifications related to reproductive health use intentionally vague titles and descriptions to protect your privacy if your lock screen is visible to others.

8. Data Retention & Deletion

9. Your Rights

You have the right to:

To exercise any of these rights, contact us at the email address below.

10. Children's Privacy

The App is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal data, please contact us and we will delete it.

11. Health Disclaimer

The App is a fitness tracking tool and does not provide medical advice. Workout suggestions, nutrition calculations (including TDEE and macro targets), AI-powered food recognition estimates, body composition data, cycle predictions, fertility window estimates, menopause symptom tracking, and pregnancy tracking features are for informational purposes only and should not be used as a method of contraception or medical diagnosis. Consult a qualified healthcare professional before beginning any exercise or nutrition program, and for all reproductive health decisions.

12. Beta Software Disclaimer

The App is currently in beta and provided on an “as-is” basis. While we implement the security measures described in this policy, beta software may contain bugs or vulnerabilities. To the fullest extent permitted by applicable law, we disclaim liability for any data loss, unauthorized access, or other damages arising from the use of pre-release versions of the App. By participating in the beta, you acknowledge and accept these risks.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy within the App and on our website. Your continued use of the Service after changes are posted constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy, your data, or wish to request account deletion, contact us at:

Everline Holdings LLC
Email: privacy@everlineholdings.com


This privacy policy applies to the Kova mobile application, its companion Apple Watch application, and the withkova.com website.