Kettle Muscle

Privacy Policy

Last updated: July 19, 2026 Version: 1

This Privacy Policy explains how Kettle Muscle handles your information. It is written in plain language first, with the detailed legal disclosures below. If anything is unclear, email us at contact@kettlemuscle.com.


Quick summary (the plain-English version)


1. Who we are

Data controller. The person responsible for your data under this policy is:

Kettle Muscle is currently offered only to users in the United States and Canada. We do not offer the app, or knowingly provide the Service, to users in other countries.

We do not knowingly collect personal information from anyone under 16. If you believe we have inadvertently collected personal information from someone under that age, contact us at contact@kettlemuscle.com so we can review, delete, or refuse further collection of that information.

Kettle Muscle is a consumer fitness application. It is not a medical device, not a healthcare provider, and not a HIPAA-covered entity (see §12).

1.1 Privacy contact


2. What we collect and why

We group everything we collect into four buckets. You can see the legal basis for each one in §4.

2.1 Account data (required to use the Service)

Kettle Muscle requires an account. The choices are Sign in with Apple, Sign in with Google, or email + password. The data we collect to maintain the account is:

Why. An account lets your data survive a lost or wiped device, lets you exercise the data-export and deletion rights described in §8, anchors the children's-privacy age gate to a verified identity, and lets us honour Apple's account-deletion requirement (App Store Review Guideline 5.1.1(v)).

Legal basis. Processing this category is necessary for the performance of the contract between you and us — PIPEDA Principle 3 (Consent, read with the "necessary to fulfil an explicitly specified purpose" exception) and, for US-state purposes, as processing necessary to provide the Service you requested. It is not processed on the basis of consent, so you cannot withdraw it without closing the account (see §8.1 right to erasure).

2.2 Fitness and body data (the core of the app)

Why. To run the fatigue engine, plan sessions, show progress, and let you review your own training. This is sensitive data — "consumer health data" under the Washington My Health My Data Act and the parallel Nevada and Connecticut laws, and sensitive personal information under Quebec Law 25, PIPEDA, and the California CPRA. It is collected only with your specific, unbundled consent at the onboarding screen titled "Built around your workouts," and only after the age gate (see §11).

2.3 Stability telemetry (kept as anonymous as possible)

Why. We need this to know the app isn't crashing for you. It is the equivalent of a server log file and is essential to keeping the service running. We process this on the basis of our legitimate interest in operating and securing the service, consistent with PIPEDA's implied-consent standard for safeguarding the Service. You can still opt out under Profile → Privacy → Diagnostics; doing so limits our ability to fix bugs that affect you.

2.4 Product analytics (only if you turn it on)

Why. To learn which features are worth investing in. This is off by default and only enabled after a separate, plainly-worded in-app prompt that names this purpose. You can turn it off again at any time under Profile → Privacy → Analytics.

2.5 Research aggregation (only if you turn it on)

Why. To make the fatigue engine and recommendation logic better for everyone. This is off by default, requires your separate opt-in on the consent screen, and can be toggled off at any time under Profile → Privacy → Research aggregation. We never combine research data with your account.

2.6 What we specifically do not collect today

2.7 Email verification (email + password sign-ups only)

If you sign up with email + password, Firebase sends a verification email to the address you provided. Until you click the link, the account exists in an "unverified" state and you cannot reach the rest of the app. Firebase logs the verification event, the IP address of the click, and the user-agent of the browser that opened the link. That metadata is held by Google as our processor under the Firebase DPA and is purged when the account is deleted (or, for accounts never verified, on the 30-day abandonment-purge schedule described in our Data Retention Policy).


3. Subscription and payment processing

When you purchase a Kettle Muscle paid subscription on iOS, two third parties handle the transaction on our behalf:

3.1 What we share with RevenueCat

CategorySpecific fieldsPurpose
Pseudonymous account IDYour Firebase UID (a random opaque string; not your email, name, or any directly identifying value)To attach the subscription entitlement to the correct account across your devices
Apple-issued purchase eventsApple transaction ID, original transaction ID, product identifier, purchase date, expiry date, country/storefront code, currencyTo verify your subscription is current and to honor the entitlement
Platform metadataiOS version, device model class, app version, device languageTo diagnose purchase-flow issues and (if you opted in to analytics) measure cohorts

3.2 What we do not share with RevenueCat

We do not share — and RevenueCat does not receive — any of the following: your name, email address, password, Apple ID, payment-card information, App Store receipt body, fitness or workout data, exercises performed, sets / reps / weights, body composition, age, sex, height, weight, or any free-text content you entered into the app. The pseudonymous identifier we send cannot be linked back to you by RevenueCat without information held only by Kettle Muscle.

3.3 Lawful basis

We process subscription-billing data because it is necessary to perform the paid-subscription agreement between you and us, set out in our Terms of Use. For the corresponding PIPEDA and US-state bases, see the table in §4. No sensitive/consumer-health data is shared for billing.

3.4 International transfer

RevenueCat is established in the United States and processes the data above on US infrastructure. Because Kettle Muscle is offered only in the United States and Canada, the only cross-border element is the routine transfer of Canadian users' pseudonymous billing identifiers to the United States. That transfer is made under contractual safeguards consistent with PIPEDA and Quebec Law 25, incorporated by reference into our Data Processing Addendum with RevenueCat (current text at https://www.revenuecat.com/dpa/).

3.5 Retention

RevenueCat retains the pseudonymous transaction record described in §3.1 for the duration of your subscription plus seven (7) years from the date of the last billing event, to support financial recordkeeping required of an internet-payment processor under US tax and accounting rules. If you delete your Kettle Muscle account, we will instruct RevenueCat to delete the pseudonymous account identifier within thirty (30) days via RevenueCat's DELETE /v1/subscribers/{appUserID} REST endpoint. The transaction-event records that are required for tax recordkeeping are retained in pseudonymized form (no identifier linking back to you) for the seven-year statutory period and then purged.

3.6 Your right to erasure

Account deletion under §8 of this Policy invokes a server-side wipeRevenueCatUser call that will issue the REST DELETE described in §3.5. If RevenueCat is unavailable at the time of deletion, the call is queued and retried; you will not be billed during the retry window because Apple, not RevenueCat, controls billing. Deleting your Kettle Muscle account does not, by itself, cancel an active Apple subscription — see §9.9 of the Terms of Use for how to cancel through Apple.

3.7 Apple's role

Apple acts as the payment processor for every iOS in-app purchase. Apple's collection and use of your payment information is governed by Apple's Privacy Policy (https://www.apple.com/legal/privacy/) and the Apple Media Services Terms (https://www.apple.com/legal/internet-services/itunes/). Apple does not share your name, email, payment card, or billing address with Kettle Muscle. The receipt body that StoreKit issues for each purchase is verified server-side at Apple via RevenueCat's verification call and never reaches Kettle Muscle's own servers.


4. Legal bases on which we rely (Canada and the United States)

PurposeData usedCanada (PIPEDA / Quebec Law 25)United States (state privacy laws)
Run the core app (fatigue engine, workout history, progress)Fitness + body data (§2.2)Express, unbundled consent for sensitive personal information (PIPEDA Principle 3; Law 25 s.12)Consent to process consumer health data / sensitive personal information (WMHMDA; CCPA/CPRA §1798.121)
Maintain your account, sync across devices, enforce export and deletion rights, enforce age thresholdAccount data (§2.1)Necessary to fulfil the explicitly specified purpose of providing the Service (PIPEDA Principle 3)Processing necessary to provide the Service you requested
Keep the app stable and secureStability telemetry (§2.3)Implied consent for safeguarding and continuity of the Service (PIPEDA)Processing necessary for security and integrity of the Service
Improve the product through usage dataProduct analytics (§2.4)Consent (opt-in)Consent (opt-in)
Aggregated / de-identified researchDerived research aggregates (§2.5)Consent (opt-in) before data is aggregatedConsent (opt-in) before data is aggregated
Comply with law or defend legal claimsAny of the above, as strictly necessaryCompliance with a legal obligationCompliance with a legal obligation

You may withdraw any consent-based processing at any time. Withdrawing consent for a purpose we rely on to operate the core app means we can no longer operate the core app for you — in that case we will help you export your data before your account is closed.


5. How long we keep your data (retention)

We keep personal information only as long as we need it for the purpose for which we collected it, or for a related legal purpose, then we delete it. A fuller policy is set out in our Data Retention Policy, maintained consistent with the retention provisions of the California CPRA §1798.100(a)(3), PIPEDA Principle 4.5, and Quebec Law 25 s.23. In summary:

Category of dataRetention periodTrigger to delete
Account identity (email, name, provider ID, Firebase UID)Life of the accountAccount deletion
Authentication tokens (Apple authorisation code, refresh tokens)Life of the account; Apple authorisation code up to 6 months to support Sign-in-with-Apple revocationAccount deletion
Subscription transaction records held by RevenueCat (pseudonymous Firebase UID + Apple transaction IDs)Duration of subscription + 7 years from last billing event for financial recordkeeping; pseudonymous identifier deleted within 30 days of account deletionAccount deletion (identifier); 7-year tax-record purge (transaction body)
Apple-side payment records (held by Apple, not by us)Per Apple's published retention policyPer Apple
Fitness and body data (workouts, sets, body stats, sex, personal records)Until you delete each record, or until account deletionRecord deletion / account deletion
Cloud-synced mirror of fitness dataLife of the accountAccount deletion
Date of birthUntil you pass the age gate; we then retain the accepted birth year and the fact the gate was passed, not the exact day / monthAccount deletion
Under-age block stateRetained only as a "blocked" signal with no personal identifier, for as long as the operating system retains app-installation stateDevice wipe or re-install
Consent records (version, timestamps, opt-in toggles, Terms / Privacy version hash)Life of the account + 24 months after account deletion, to evidence lawful processing on later inquiryScheduled purge, 24 months after deletion
Stability telemetry (crash reports, non-fatal errors)90 daysAutomatic purge
Product analytics events (only if you opted in)14 months, aggregatedAutomatic purge
Research aggregates (only if you opted in)Indefinite only if irreversibly aggregated and not re-identifiablePurge if re-identification becomes feasible
Data-subject-request records (access, deletion, correction, export requests)3 years from the date of the requestAutomatic purge
Legal, tax, dispute, or audit recordsAs long as the applicable legal obligation requiresExpiry of the obligation

If you delete your account, a "deleting" marker is placed on your account record first so that a mid-delete crash can resume the cascade. Within ninety (90) days of account deletion, no data tied to your personal identity remains in our backend other than the consent records and data-subject-request log entries listed above, which are retained for the stated periods so we can evidence compliance on later inquiry.


6. Who else sees your data

We use a small set of third parties strictly to deliver the service. Each one is bound by the service's own privacy terms, and by a data-processing agreement where available.

ProcessorWhat it doesWhat it seesLocation
Google LLC (Firebase and Google Cloud services — Authentication, Firestore, Cloud Functions, App Check, Analytics)Sign-in, cloud sync, abuse prevention, telemetryAccount ID, cloud-synced workout records, diagnostic eventsUnited States (default region)
Apple — Sign in with AppleAuth federation if you choose itYour choice to sign inApple's infrastructure
Google — Sign in with GoogleAuth federation if you choose itYour choice to sign inGoogle's infrastructure
RevenueCat, Inc. (San Francisco, CA, USA) — subscription processorTranslates Apple purchase events into entitlement state; manages subscription lifecyclePseudonymous Firebase UID; Apple-issued transaction IDs, product IDs, prices, country code; iOS / device / app version; language. Not name, email, health, or fitness dataUnited States
Apple Inc. — App Store payment processorProcesses every iOS in-app purchase as merchant of recordYour payment method and billing details; processed by Apple, not received by usApple's infrastructure
Apple Health — inbound profile import (iOS, on-device API)Reads your DOB, biological sex, latest body weight and latest height with your explicit permission, to pre-fill your profileThe HK fields named above. Imported values are persisted in your user profile and follow the same cloud-sync path as other profile data — see Google LLC row aboveiOS device → on-device → mirrored to United States via Firestore
Apple Health — outbound workout + body-mass write (iOS, on-device API)When you complete a workout we write the session (times, activity type, calories, distance where applicable) and body-weight changes to your Apple Health store; deletes in-app cascade to a matching delete in Apple HealthThe workout and body-mass values we sendOn-device only; never routed through our servers

We do not use Meta Pixel, Google Ads, IAB TCF vendors, or any other advertising or ad-tech processor. If that ever changes, we will update this table and require a separate opt-in.

We also do not share your data with data brokers and we do not "sell" personal information as that term is defined in the California CCPA/CPRA, Colorado CPA, Virginia VCDPA, or equivalent state laws.


7. Where your data is stored and moved across borders

Cloud-synced data is stored in the United States on Google Cloud infrastructure operated by Firebase. Kettle Muscle is offered only in the United States and Canada. When you use the app from Canada, your data is transferred to the United States for storage and processing.

We rely on the following transfer mechanism:

You can request a copy of the relevant transfer safeguards by emailing contact@kettlemuscle.com.


8. Your rights

8.1 Rights that every user has, everywhere

8.2 If you are in California

You have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA"), including: the right to know, access, delete, correct, portability, opt out of sale/sharing (we do not sell or share), opt out of profiling in furtherance of decisions that produce legal or similarly significant effects (we do not do this), and to limit the use of sensitive personal information ("Limit SPI"). The Limit SPI toggle is available under Profile → Privacy.

On a verified consumer request, we will disclose the specific pieces of personal information we collected about you, and the sources, purposes, and recipients of that collection, in the twelve (12) months preceding your request, in accordance with Cal. Civ. Code §1798.130(a)(5).

You may also designate an authorised agent to make requests on your behalf. We will verify your identity before acting on a request.

We do not knowingly sell or share the personal information of minors under 16. We do not need to, because the app is gated at 16+ and no data collected is used for advertising.

We honour browser-level Global Privacy Control signals where technically applicable.

8.3 If you are in Washington State (or another US state with consumer-health-data laws)

In addition to any rights under your state's general privacy law (if any), you have rights under the Washington My Health My Data Act (Wash. Rev. Code 19.373), which treats fitness-tracker data as "consumer health data". Because WMHMDA requires a separately-accessible disclosure, we maintain a stand-alone Consumer Health Data Privacy Policy that sets out the categories of consumer health data we collect, the specific third parties that receive it, the purposes for which we process it, and the six WMHMDA rights you have and how to exercise them. Equivalent rights apply to residents of Nevada (under SB 370) and Connecticut (under the Data Privacy Act's consumer-health-data provisions); contact us the same way.

In short: we do not sell consumer health data, and general acceptance of these Terms or this Policy is not authorisation to do so. You may contact contact@kettlemuscle.com with the subject line "Consumer Health Data Request" to exercise any of your rights, and we will respond within forty-five (45) days (extendable by a further forty-five days where reasonably necessary). You may also contact the Washington Attorney General's Office at atg.wa.gov, which has a private right of action under the Washington Consumer Protection Act.

8.4 If you are in Canada

You have rights under the federal Personal Information Protection and Electronic Documents Act (PIPEDA), including access, correction, and withdrawal of consent.

8.5 How to make a request

Email contact@kettlemuscle.com with the subject line "Privacy Request" and tell us what you want. You do not need to write it in any particular form. To protect your account, we may ask you to verify you are the account holder before we act on a request that concerns an account.

We will respond within the time frame required by your local law — at most, within thirty (30) days of verifying your request, extendable by a further thirty (30) days (or forty-five (45) days under WMHMDA) where reasonably necessary, with notice to you.


9. Security

We take security as seriously as a solo developer reasonably can. Our full practice is documented in the Information Security Program. In summary:

No system is perfectly secure. If we experience a breach affecting your data, we will notify you and the applicable regulators within the time frames required by law.


10. Cookies, tracking, and device permissions

Kettle Muscle is a native mobile app. It does not set browser cookies.


11. Children's privacy

Kettle Muscle is not directed to, and we do not knowingly collect personal information from, anyone under 16. This single threshold applies to every user in the United States and Canada — the only regions where the app is offered. It sits above the 13-year floor of the US Children's Online Privacy Protection Act (COPPA) and above the 14-year threshold in Quebec's Law 25, so we do not process the personal information of a child in either country.

We enforce this through an age gate presented before any sign-up or sign-in option is shown and before any personal data — including an email address — is collected. If a user indicates an age below 16, the app blocks onboarding, does not present any account-creation control, and does not retain the date of birth beyond what is needed to display the block screen and prevent re-entry on the same device.

If you believe someone under 16 has nonetheless provided us with data, email contact@kettlemuscle.com and we will delete it promptly.

This policy and our age gate are designed to comply with the US Children's Online Privacy Protection Act (COPPA), the California Age-Appropriate Design Code Act, and the children's-data provisions of Quebec's Law 25 and PIPEDA.


12. HIPAA does not apply

Kettle Muscle is a consumer wellness service that collects data directly from you, the user. We are not a HIPAA-covered entity (a healthcare provider, health plan, or healthcare clearinghouse), and we are not a business associate of any such entity. The information you enter into Kettle Muscle is not Protected Health Information under HIPAA, and HIPAA's Privacy, Security, and Breach Notification Rules do not govern our handling of it.

What governs our handling of that information is this Privacy Policy, the consumer privacy laws listed in §8, and the security practices in §9.

If you use Kettle Muscle in a professional capacity (for example, as a coach or trainer logging a client's workouts), you remain responsible for any obligations you have to that client under the laws that apply to you.


13. Changes to this policy

If we make material changes — for example, a new category of data, a new processor, or a new advertising feature — we will:

  1. Update the "Last updated" date and bump the version number at the top of this policy.
  2. Surface an in-app notice before the change takes effect.
  3. Where a change requires fresh consent (for example, a new processing purpose for sensitive personal information), re-present the consent screen and require your affirmative action before the change applies to you.

For non-material changes (such as improving the wording of a section without changing what we do), we will update the "Last updated" date without a separate notice.


14. Contact, complaints, and regulators

The best first step for any question or request is to email us at contact@kettlemuscle.com.

If you are not satisfied with our response, you may contact the supervisory authority or regulator in your region:


End of Privacy Policy.