Privacy Policy
CJH22 (“we,” “us,” or “our”) operates PokoFit. This Policy explains what personal information we process, why we process it, how long we keep it, whom we share it with, and the choices available to you.
1. Information we process
| Category | Examples | Purpose |
|---|---|---|
| Account and authentication | Internal user ID; Google or Apple account identifier; email, name, or profile data the provider makes available; authentication records and IP/security logs | Create and secure accounts, sign in, recover and synchronize data, prevent abuse |
| Profile and preferences | Nickname, profile image or character, locale, country, time zone, notification settings | Personalize the Service and apply your settings |
| Fitness and activity | Selected exercise types, goals, routines, planned days and reminder times, workout check-ins, completion dates, streaks and progress | Provide workout planning, tracking, reminders, progress, and reports |
| Group and safety | Group membership, reactions, shared progress, reports, blocks, and content needed to review a safety report | Operate groups, maintain safety, investigate reports, enforce rules |
| Purchases | Store, product and entitlement identifiers, purchase status, transaction-related metadata; not full payment-card details | Provide Pro features, validate and restore purchases, support customers |
| Push notifications | Firebase installation ID, push token, app/platform, locale, time zone, notification preferences | Deliver reminders and service notifications |
| Analytics | Random app-instance ID, app events and feature interactions, sessions, approximate location derived from IP, app/device/OS information | Understand adoption and usage, measure performance, improve features |
| Crash and diagnostics | Crashlytics installation UUID, Firebase installation ID, session ID, crash time and stack trace, app version, device model, OS, architecture, memory/disk state, root/jailbreak status, and technical logs associated with a crash | Detect, diagnose, prioritize, and prevent crashes and reliability problems |
| Support | Email address, correspondence, screenshots or diagnostic details you choose to send | Respond to requests and resolve problems |
Fitness information. Exercise goals and activity records can reveal health-related information. We process the information you choose to enter to provide PokoFit’s requested features. PokoFit does not currently import data from Apple Health, HealthKit, Health Connect, or a medical provider. We will update this Policy and obtain any consent required by law before introducing such an integration.
2. How we collect information
We receive information directly from you, automatically from the app and device when you use the Service, from Google or Apple when you choose social sign-in, from app stores and RevenueCat when you make or restore a purchase, and from other users when they interact with you or submit a safety report.
3. Legal grounds
Depending on applicable law, we process information to perform our contract with you, comply with law, protect our legitimate interests in security and service improvement, or based on consent. Where Korean law requires separate consent for sensitive information, optional analytics, overseas transfer, or another activity, we will present that consent separately rather than treating this Policy alone as consent. You may withdraw consent, but this does not affect processing already lawfully performed.
4. Analytics and crash reporting
Firebase Analytics
We use Google Analytics for Firebase to measure app usage. Its default implementation may collect an app-instance identifier, user and session statistics, approximate geolocation, and device information. We configure analytics for product measurement rather than advertising personalization and do not intentionally send names, email addresses, workout notes, profile images, or other directly identifying or sensitive content as analytics event parameters. User- and event-level Analytics data is retained for up to 14 months; aggregated reporting may remain longer.
Firebase Crashlytics
We use Firebase Crashlytics to understand crashes and stability problems. Crashlytics may process installation and session identifiers, crash traces, device and app details, and related diagnostic logs. Google states that Crashlytics crash traces and associated identifiers are retained for 90 days before removal begins. We do not intentionally place account credentials, workout content, or other sensitive personal information in custom crash logs.
More information is available in Firebase Privacy and Security and Google’s Privacy Policy.
5. Service providers and overseas processing
We use providers only as needed to operate the Service. Because they use global infrastructure, information may be processed outside your country, including in the United States and other locations where a provider or its subprocessors operate. Transfers occur electronically over encrypted connections when you use the relevant feature.
| Recipient / service | Information and purpose | Location and retention |
|---|---|---|
| Google LLC — Firebase Analytics, Crashlytics, Cloud Messaging, Hosting | Analytics, diagnostics, installation IDs, push token, device/app data, and Hosting request IP; measurement, crash diagnosis, notifications, and serving these pages | United States and global Google infrastructure; Analytics up to 14 months for user/event data, Crashlytics 90 days before removal begins, FCM installation data until deletion is requested, Hosting IP for several months, subject to Google’s backup-removal periods |
| Supabase, Inc. and configured infrastructure providers | Account identifiers, profile, fitness/activity, group, safety, settings, and push registration data; authentication, database, storage, server functions, and synchronization | Configured project region and provider infrastructure; until account deletion or the applicable period below, including backup-removal time |
| RevenueCat, Inc. | App user ID, purchase/entitlement and device/app metadata; validate, manage, and restore purchases | United States and provider infrastructure; while needed for subscription records, support, fraud prevention, and legal obligations |
| Apple Inc. / Google LLC | Sign-in token and provider account identifier; store transaction and subscription data; authentication and payment processing | Provider infrastructure under the provider’s terms and privacy policy |
You may decline an optional overseas transfer by not enabling the related optional feature or by contacting us. Transfers essential to account synchronization, purchases, notifications, analytics/crash reporting when enabled, or hosting may need to be disabled with the corresponding feature; some Service functions may then be unavailable. We will provide a separate choice where applicable law requires consent.
6. Disclosure
We do not sell personal information. We may disclose it to the service providers above under appropriate contractual safeguards; to comply with law or a valid legal process; to protect users, the public, our rights, or service security; or as part of a merger, financing, acquisition, or asset transfer with appropriate notice and safeguards. Group content is disclosed to members according to the feature’s design.
7. Retention and deletion
- Account, profile, workout, group, and settings data: while your account is active, then deleted or de-identified after an account-deletion request, subject to backup processing.
- Guest data stored only on your device: until you clear app data or uninstall, unless synchronized after account linking.
- Safety reports and enforcement records: up to 3 years after resolution where reasonably needed to prevent abuse and handle disputes.
- Purchase and transaction records: for the period required by tax, accounting, electronic-commerce, and consumer-protection law.
- Support correspondence: up to 3 years after the request is resolved, unless a longer period is needed for a dispute or required by law.
- Analytics and Crashlytics: as stated in Section 4.
When retention ends, we securely delete or irreversibly de-identify information. Electronic records are deleted using methods designed to prevent recovery; physical records, if any, are shredded or destroyed. Backups are isolated and removed on the applicable provider’s cycle.
8. Your rights and choices
Subject to applicable law, you may request access, correction, deletion, restriction or suspension of processing, withdrawal of consent, and a copy of your information. You may change profile and notification settings in the app, manage platform permissions in device settings, and manage or cancel subscriptions in your app-store account. Contact us to exercise another right. We may verify your identity and will respond within the period required by law. You may also complain to your local data-protection authority.
9. Security
We use reasonable administrative, technical, and physical safeguards, including encrypted network transport, access controls, least-privilege practices, credential separation, and service monitoring. No system is completely secure, so we cannot guarantee absolute security.
10. Children
PokoFit is not directed to children under 14, and we do not knowingly collect their personal information. If you believe a child under 14 has provided information, contact us so we can investigate and delete it. Where another jurisdiction sets a higher age for independent consent, its requirements apply.
11. Changes to this Policy
We may update this Policy as the Service or law changes. We will publish the new effective date and provide reasonable advance notice of material changes. If law requires new consent, we will request it separately.
12. Controller and contact
Controller and privacy contact: CJH22 (시제이에이치22)
Email: a2nin.lab@gmail.com
This Policy is available in English and Korean. Both are intended to have the same meaning. If an inconsistency exists, the Korean version controls to the extent permitted by applicable law.