PokoFit

Privacy Policy

Effective: September 4, 2026 · Controller: CJH22 (시제이에이치22)

CJH22 (“we,” “us,” or “our”) operates PokoFit. This Policy explains what personal information we process, why we process it, how long we keep it, whom we share it with, and the choices available to you.

1. Information we process

CategoryExamplesPurpose
Account and authenticationInternal user ID; Google or Apple account identifier; email, name, or profile data the provider makes available; authentication records and IP/security logsCreate and secure accounts, sign in, recover and synchronize data, prevent abuse
Profile and preferencesNickname, profile image or character, locale, country, time zone, notification settingsPersonalize the Service and apply your settings
Fitness and activitySelected exercise types, goals, routines, planned days and reminder times, workout check-ins, completion dates, streaks and progressProvide workout planning, tracking, reminders, progress, and reports
Group and safetyGroup membership, reactions, shared progress, reports, blocks, and content needed to review a safety reportOperate groups, maintain safety, investigate reports, enforce rules
PurchasesStore, product and entitlement identifiers, purchase status, transaction-related metadata; not full payment-card detailsProvide Pro features, validate and restore purchases, support customers
Push notificationsFirebase installation ID, push token, app/platform, locale, time zone, notification preferencesDeliver reminders and service notifications
AnalyticsRandom app-instance ID, app events and feature interactions, sessions, approximate location derived from IP, app/device/OS informationUnderstand adoption and usage, measure performance, improve features
Crash and diagnosticsCrashlytics installation UUID, Firebase installation ID, session ID, crash time and stack trace, app version, device model, OS, architecture, memory/disk state, root/jailbreak status, and technical logs associated with a crashDetect, diagnose, prioritize, and prevent crashes and reliability problems
SupportEmail address, correspondence, screenshots or diagnostic details you choose to sendRespond to requests and resolve problems

Fitness information. Exercise goals and activity records can reveal health-related information. We process the information you choose to enter to provide PokoFit’s requested features. PokoFit does not currently import data from Apple Health, HealthKit, Health Connect, or a medical provider. We will update this Policy and obtain any consent required by law before introducing such an integration.

2. How we collect information

We receive information directly from you, automatically from the app and device when you use the Service, from Google or Apple when you choose social sign-in, from app stores and RevenueCat when you make or restore a purchase, and from other users when they interact with you or submit a safety report.

3. Legal grounds

Depending on applicable law, we process information to perform our contract with you, comply with law, protect our legitimate interests in security and service improvement, or based on consent. Where Korean law requires separate consent for sensitive information, optional analytics, overseas transfer, or another activity, we will present that consent separately rather than treating this Policy alone as consent. You may withdraw consent, but this does not affect processing already lawfully performed.

4. Analytics and crash reporting

Firebase Analytics

We use Google Analytics for Firebase to measure app usage. Its default implementation may collect an app-instance identifier, user and session statistics, approximate geolocation, and device information. We configure analytics for product measurement rather than advertising personalization and do not intentionally send names, email addresses, workout notes, profile images, or other directly identifying or sensitive content as analytics event parameters. User- and event-level Analytics data is retained for up to 14 months; aggregated reporting may remain longer.

Firebase Crashlytics

We use Firebase Crashlytics to understand crashes and stability problems. Crashlytics may process installation and session identifiers, crash traces, device and app details, and related diagnostic logs. Google states that Crashlytics crash traces and associated identifiers are retained for 90 days before removal begins. We do not intentionally place account credentials, workout content, or other sensitive personal information in custom crash logs.

More information is available in Firebase Privacy and Security and Google’s Privacy Policy.

5. Service providers and overseas processing

We use providers only as needed to operate the Service. Because they use global infrastructure, information may be processed outside your country, including in the United States and other locations where a provider or its subprocessors operate. Transfers occur electronically over encrypted connections when you use the relevant feature.

Recipient / serviceInformation and purposeLocation and retention
Google LLC — Firebase Analytics, Crashlytics, Cloud Messaging, HostingAnalytics, diagnostics, installation IDs, push token, device/app data, and Hosting request IP; measurement, crash diagnosis, notifications, and serving these pagesUnited States and global Google infrastructure; Analytics up to 14 months for user/event data, Crashlytics 90 days before removal begins, FCM installation data until deletion is requested, Hosting IP for several months, subject to Google’s backup-removal periods
Supabase, Inc. and configured infrastructure providersAccount identifiers, profile, fitness/activity, group, safety, settings, and push registration data; authentication, database, storage, server functions, and synchronizationConfigured project region and provider infrastructure; until account deletion or the applicable period below, including backup-removal time
RevenueCat, Inc.App user ID, purchase/entitlement and device/app metadata; validate, manage, and restore purchasesUnited States and provider infrastructure; while needed for subscription records, support, fraud prevention, and legal obligations
Apple Inc. / Google LLCSign-in token and provider account identifier; store transaction and subscription data; authentication and payment processingProvider infrastructure under the provider’s terms and privacy policy

You may decline an optional overseas transfer by not enabling the related optional feature or by contacting us. Transfers essential to account synchronization, purchases, notifications, analytics/crash reporting when enabled, or hosting may need to be disabled with the corresponding feature; some Service functions may then be unavailable. We will provide a separate choice where applicable law requires consent.

6. Disclosure

We do not sell personal information. We may disclose it to the service providers above under appropriate contractual safeguards; to comply with law or a valid legal process; to protect users, the public, our rights, or service security; or as part of a merger, financing, acquisition, or asset transfer with appropriate notice and safeguards. Group content is disclosed to members according to the feature’s design.

7. Retention and deletion

When retention ends, we securely delete or irreversibly de-identify information. Electronic records are deleted using methods designed to prevent recovery; physical records, if any, are shredded or destroyed. Backups are isolated and removed on the applicable provider’s cycle.

8. Your rights and choices

Subject to applicable law, you may request access, correction, deletion, restriction or suspension of processing, withdrawal of consent, and a copy of your information. You may change profile and notification settings in the app, manage platform permissions in device settings, and manage or cancel subscriptions in your app-store account. Contact us to exercise another right. We may verify your identity and will respond within the period required by law. You may also complain to your local data-protection authority.

9. Security

We use reasonable administrative, technical, and physical safeguards, including encrypted network transport, access controls, least-privilege practices, credential separation, and service monitoring. No system is completely secure, so we cannot guarantee absolute security.

10. Children

PokoFit is not directed to children under 14, and we do not knowingly collect their personal information. If you believe a child under 14 has provided information, contact us so we can investigate and delete it. Where another jurisdiction sets a higher age for independent consent, its requirements apply.

11. Changes to this Policy

We may update this Policy as the Service or law changes. We will publish the new effective date and provide reasonable advance notice of material changes. If law requires new consent, we will request it separately.

12. Controller and contact

Controller and privacy contact: CJH22 (시제이에이치22)
Email: a2nin.lab@gmail.com

This Policy is available in English and Korean. Both are intended to have the same meaning. If an inconsistency exists, the Korean version controls to the extent permitted by applicable law.