top of page

Privacy Policy

KYGO HEALTH PRIVACY POLICY

Effective Date: September 30, 2025 | Last Updated: September 13, 2026

1. Introduction

Kygo Health LLC ("we," "our," or "us") is committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application, our web app at app.kygo.app, our website at kygo.app, and related services (the "Service").

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with these terms, please do not use the Service.

Limited Use Compliance Statement: Kygo Health's use of information received from Google APIs, including the Google Health API (Fitbit data), will adhere to the Google API Services User Data Policy, including its Limited Use requirements. We only use this data to provide and improve the health and fitness features you have requested, and we do not transfer or use it for advertising, creditworthiness, or any purpose unrelated to those features.

2. Information We Collect

 

2.1 Account Information

  • Email address, and a password stored only as a salted cryptographic hash if you register with email

  • If you use Sign in with Google or Sign in with Apple, the account identifier and email address that provider returns to us

  • Name, age, sex, weight, and height (optional, used to calculate your targets)

  • Dietary preferences, goals, and restrictions

 

2.2 Nutrition and Wellness Data You Provide

  • Food and drink entries, portion sizes, meal timing, and the nutrition values derived from them

  • Saved foods, custom meals, and recipes

  • Supplements you log and the regimen you set up

  • Weight entries you record in the app

  • Photos of meals, product barcodes, and supplement labels that you choose to capture

  • Spoken food entries, when you use voice logging

  • Support requests, any information you include in them, and any screenshots or photos you choose to attach to them

 

How meal photos and voice are handled is described in sections 3.2 and 6, because both are treated differently from the rest of your data. Images you attach to a support request are different again: they are stored with your ticket, with location and camera metadata stripped, so we can answer you, and they are deleted with your account.

2.3 Wearable and Platform Health Data

With your explicit authorization, we access the following data from connected devices and health platforms. You choose which to connect, and you can disconnect any of them at any time (section 7.2).

Oura Ring (via Oura API):

  • Sleep metrics (duration, quality, stages, efficiency)

  • Heart rate and heart rate variability (HRV)

  • Body temperature variations and respiratory rate

  • Activity levels, readiness, and recovery scores

  • Stress and resilience metrics, blood oxygen (SpO2), and VO2 max

 

Fitbit (via the Google Health API):

  • Activity and exercise data (steps, distance, calories)

  • Sleep metrics and sleep stages

  • Heart rate, HRV, and SpO2 measurements

  • Respiratory rate, skin temperature, and cardio fitness (VO2 max)

Fitbit data is accessed through Google's Health API using Google OAuth 2.0. Our use of this data is governed by the Google API Services User Data Policy, including its Limited Use requirements.

 

Garmin (via Garmin Connect API):

  • Daily activity summaries and workout data

  • Sleep analysis and stress tracking

  • Heart rate, HRV, and body battery

  • Respiration and pulse ox data

 

WHOOP (via WHOOP API):

  • Recovery score, resting heart rate, and heart rate variability (HRV)

  • Skin temperature and blood oxygen (SpO2)

  • Sleep performance, sleep consistency, sleep efficiency, and sleep stage durations (for example REM and deep)

  • Respiratory rate

  • Day strain and energy burned

  • Workout activity strain, activity type, average heart rate, max heart rate, and heart rate zone durations

  • Profile information (name, email, body measurements)

 

Apple Health (via HealthKit, iOS):

  • Activity, exercise minutes, and workout data

  • Sleep analysis, heart rate, HRV, and resting heart rate

  • Body measurements, including weight

  • Nutrition and hydration records

  • Mindfulness and respiratory data

With your separate permission we also write the nutrition and hydration you log in Kygo back to Apple Health, so your records stay consistent across apps.

 

Android Health Connect:

  • Steps, active and basal calories, and sleep

  • Heart rate variability and resting heart rate

  • Weight

  • Nutrition and hydration records

 

Where you grant it, we read this data in the background and read historical records so your trends are complete from the day you connect. With your separate permission we write the nutrition and hydration you log in Kygo back to Health Connect. You can revoke any of these permissions in Android Settings.

2.4 Subscription and Purchase Information

Purchases in the mobile app are processed by Apple or Google, not by us. Purchases on the web app are processed by Stripe, our payment processor; Stripe receives your card details and billing address directly and we never receive or store them. Our subscription provider, RevenueCat, gives us your subscription status, trial state, renewal and expiration dates, the product purchased, which store or processor billed it, and the anonymous transaction identifiers needed to restore purchases across your devices and to open your billing portal on the web.

2.5 Technical and Device Information

  • Device model, operating system version, app version, timezone, and locale

  • On the web app: browser type, screen size, the page you arrived from, and campaign tags in the link you followed

  • App usage patterns, screens viewed, and feature preferences

  • Crash reports, error diagnostics, and performance data

  • A push notification token, if you enable notifications

  • Device identifiers used for subscription and install measurement, described in section 4.2

 

Cookies and similar storage (web app only): app.kygo.app keeps your sign-in session and your preferences in your browser's local storage, which is essential to the Service. Analytics and error reporting on the web use cookies or local storage only after you accept them in the banner shown on your first visit; declining keeps the Service fully usable, and you can change your choice by clearing the site's data in your browser. Stripe sets its own cookies during checkout for fraud prevention.

2.6 The kygo.app Website

You can read the website, its blog, and its free tools without an account, and we do not ask you to sign in to use them. When you visit kygo.app we and our providers collect:

  • Standard server and hosting data, including your IP address, browser and device type, referring page, and the pages you view. Our hosting platform, Wix, sets essential cookies that keep the site working and protect it from abuse

  • Website analytics through Google Analytics 4, which records page views, approximate location derived from your IP address, device and browser type, and the campaign tags in any link you followed. Google Analytics sets cookies in your browser

  • Product and usage analytics through Microsoft Clarity, which records how pages are used, including clicks, scrolling, and session replays that reconstruct how a page was navigated. Clarity masks text input by default, and we do not use it to identify you

  • Error diagnostics through Sentry, so we can see when a page or a tool breaks

  • Anything you type into a tool on the site, such as a weight or an age in a calculator. Tool inputs are processed in your browser to show you a result. We do not store them against you, and they are not linked to any Kygo account

  • If you contact us through the site or by email, the name, email address, and message you send, so we can reply

 

Website analytics data is separate from your Kygo account. We do not join it to your food logs, wearable data, or anything else in the app. See section 7.5 for how to turn website analytics off.

 

3. How We Use Your Information

 

3.1 Core Service Functionality

  • Provide personalized nutrition, supplement, and weight tracking

  • Analyze correlations between what you consume and your health metrics

  • Generate health insights and evidence-based recommendations

  • Sync and display data from connected wearable devices

  • Track progress toward your health and wellness goals

  • Deliver the reminders and notifications you have turned on

  • Manage your subscription, trial, and entitlements

 

3.2 AI-Assisted Logging and Insights

Several features use AI to save you typing. In each case the processing happens inside our own private Google Cloud project, under the Google Cloud Data Processing terms, and your data is not used to train Google's models.

Photos. When you photograph a meal or a supplement label, the image is uploaded to our servers and sent to Google Vertex AI to identify what it contains. The image is held in server memory for up to 30 minutes so the result can be refined without asking you to retake the photo, and is then discarded. Meal photos are never written to our database and are never stored on our servers permanently.

Voice. Spoken food entries are transcribed by your device's built-in speech recognition. Depending on your device and its settings, your operating system may send that audio to Apple or Google for transcription under their privacy policies. We receive only the resulting text. We never record, upload, or store your voice audio.

Insights. To generate your personalized insights we send relevant food and health information, which may include wearable metrics accessed via the Google Health API, to Vertex AI in the same private project. This happens solely to return the insight to you, it is not shared with any other party, and our use complies with the Google API Services User Data Policy, including its Limited Use requirements.

Food lookup. When you search for or describe a food, the search text or barcode is sent to our nutrition data providers (section 4.1) to retrieve nutrition values. Your identity, account, and health data are never included in those lookups.

3.3 Service Improvement

  • Enhance app features and fix bugs

  • Develop new features based on usage patterns

  • Measure which acquisition channels bring people to the app, as described in section 4.2

  • Understand which website articles and tools are useful, and improve them

 

Your data is used to run these features for you. We do not pool your health, nutrition, or wearable data with other users' data to train, develop, or improve any AI or machine learning model, and we do not license it to anyone who does.

4. Data Sharing and Disclosure

 

We do not sell, rent, or trade your personal information. We never sell, lease, license, syndicate, or otherwise transfer your health, nutrition, or wearable data to advertisers, data brokers, or information resellers, and we will not do so even if you ask us to. The only data that reaches an advertising or measurement partner is the limited device identifier described in section 4.2, which carries none of your health or nutrition data.

4.1 Service Providers

We work with the following providers, each of which processes data only to enable our Service:

 

Oura Health Oy: Health metrics via OAuth 2.0 authorization. We comply with the Oura API Agreement. Oura may collect usage data related to our API access.

Google (Fitbit data via the Google Health API): Fitbit health metrics accessed through the Google Health API via Google OAuth 2.0. Our access to and use of this data complies with the Google API Services User Data Policy, including its Limited Use requirements.

 

Garmin International: Health metrics via OAuth 2.0 authorization. Data submitted through our app is submitted to Kygo Health, not Garmin. We comply with the Garmin Connect Developer Program Agreement.

 

Whoop, Inc.: Health and recovery metrics via OAuth 2.0 authorization. We comply with the WHOOP API Terms of Use, including all restrictions on data use, storage, and disclosure. WHOOP data is not sold, leased, licensed, or syndicated to any third party, even with user consent.

 

Apple HealthKit: Local device data access with your explicit permission. We comply with Apple's HealthKit guidelines and App Store Review Guidelines.

 

Nutrition data providers: Nutritionix, Edamam, Open Food Facts, and USDA FoodData Central supply the nutrition values behind food search, text and voice entry, and barcode scanning. Only the search text or barcode is sent. No account, identity, or health data is transmitted, and all requests are proxied through our servers.

Google Cloud (Vertex AI): Photo recognition, supplement label reading, and insight generation inside our own private Google Cloud project, as described in section 3.2. This data is not used to train AI models and is not shared with any other party.

MongoDB Atlas: Encrypted cloud database storage.

Render: Application hosting for our backend servers.

RevenueCat: Subscription and entitlement management, as described in section 2.4.

Stripe: Payment processing for subscriptions bought on the web app, as described in section 2.4. Stripe is an independent controller of the card data it collects and is PCI DSS certified.

Expo, Apple Push Notification service, and Google Firebase Cloud Messaging: Delivery of the push notifications you have enabled, and delivery of over-the-air app updates. These services receive a push token and the notification content, not your health or nutrition data.

Sentry (crash and error diagnostics): We use Sentry to detect and diagnose crashes and errors so we can fix them. Error reports are automatically scrubbed of personal and authentication data. We do not send your health metrics, food data, access tokens, or IP address, and events are associated only with a pseudonymous account identifier.

Mixpanel (product analytics): Pseudonymous product-usage analytics used to understand how the app is used and improve it. Mixpanel receives feature engagement events, your device model and operating system, an approximate location derived from your IP address, and account attributes such as signup method and subscription status. It does not receive your health metrics, food entries, or the contents of anything you log.

Wix (website hosting): Hosting and delivery of kygo.app, including the essential cookies that keep the site working.

Google Analytics 4 and Microsoft Clarity (website analytics): Website traffic measurement and page-usage analytics for kygo.app, as described in section 2.6. Neither receives any health, nutrition, or wearable data, and neither is connected to your Kygo account.

Google Workspace (email): Delivery of transactional email such as password resets and replies to your support requests.

4.2 Advertising Identifiers and Install Measurement

So we can tell which channels bring people to Kygo, we work with Tenjin, a mobile measurement partner, and use RevenueCat's attribution integration. This is the one place where a device identifier leaves the app, so we want to be exact about it.

  • On Android, we collect your Google Advertising ID (an identifier you can reset or delete in Android Settings) and your Android App Set ID

  • On iOS, we collect the Identifier for Vendor, which is specific to our app and cannot be used to track you elsewhere. We do not present an App Tracking Transparency prompt and therefore do not receive your IDFA

  • On iOS, install measurement also uses Apple's SKAdNetwork, which reports a single coarse number to the ad network and reveals nothing about you individually

  • These partners receive install, signup, trial, subscription, and revenue events. They never receive your health metrics, wearable data, food entries, weight, supplements, photos, or voice data

 

We do not use this, or anything else, to serve you personalized or interest-based advertising inside the app, and we do not build advertising profiles about you. To limit this on Android, delete or reset your advertising ID and turn on "Opt out of Ads Personalization" in Android Settings. On iOS, turn off "Allow Apps to Request to Track" in iOS Settings.

4.3 Prohibited Uses

We will NEVER:

  • Use health, nutrition, or wearable data for advertising or marketing purposes

  • Sell or transfer health or nutrition data to advertisers, data brokers, or resellers

  • Use your health or nutrition data to serve personalized or interest-based advertising

  • Use your data to determine creditworthiness or for lending purposes

  • Share HealthKit or Health Connect data with third parties without your explicit consent

  • Write false or inaccurate data to HealthKit, Health Connect, or any other platform

 

4.4 Legal Requirements and Business Transfers

We may disclose information if required by law, subpoena, or valid legal process. Where permitted, we will notify you of such requests. In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity, which will remain bound by this Privacy Policy or give you notice before any material change.

4.5 Affiliate Links on the Website

Some links on kygo.app are affiliate links, including links to Amazon. As an Amazon Associate we earn from qualifying purchases. When you click one, the merchant may set its own cookie so it can credit us for a resulting purchase. We receive only aggregate reporting from those programs, such as how many clicks and orders came from our links. We do not receive your name, your payment details, or what else you bought, and we never share your Kygo account or health data with a merchant or affiliate network.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption: All data encrypted in transit (TLS 1.3) and at rest (AES-256)

  • Credentials: Passwords are stored only as salted cryptographic hashes, never in a readable form

  • Authentication: Secure OAuth 2.0 authentication for all wearable integrations

  • Access Controls: Least-privilege database credentials, role-based access, and regular security audits

  • Independent Assessment: We have completed Google's CASA Tier 2 security assessment for our health data integrations

  • Data Minimization: We only collect data necessary for Service functionality

  • Breach Notification: We will notify affected users and relevant authorities within 72 hours of discovering a data breach, and notify applicable wearable platform providers within 24 hours as required

 

6. Data Retention

  • Account, nutrition, supplement, and weight data: retained while your account is active

  • Detailed wearable samples: retained no longer than 12 months, and high-frequency Apple Health heart rate and workout records no longer than 90 days

  • Daily health summaries: retained no longer than 2 years, so long-range trends and correlations stay available to you. A small number of older records imported before 2025 that carry no source label are cleared after 3 years

  • Meal and supplement photos: held in server memory for up to 30 minutes, then discarded. Never written to our database

  • Images attached to support requests: stored with the ticket while your account exists

  • Voice audio: never stored

  • Revoked access: when you disconnect a wearable or revoke authorization, we stop retrieving new data and delete the data we hold from that provider

  • Wearable data generally: we keep it only as long as it is needed for the features you use, and we delete a provider's data within 72 hours of your request, which is what the Oura API Agreement requires of us and what we apply to every provider

  • Deleted accounts: all personal data associated with your account is deleted immediately from our live systems when you delete your account. Our database backups are daily snapshots that expire on a rolling schedule, so your data is gone from backups within 30 days as well

  • Purchase records: a minimal record of a lifetime purchase is kept after deletion where we need it for refunds, chargebacks, and tax or accounting obligations. It contains no health or nutrition data

  • Website analytics: Google Analytics event data is retained for the period set in our Google Analytics configuration, up to a maximum of 14 months, and Microsoft Clarity session data expires on that product's rolling schedule

  • Aggregate statistics that cannot identify you may be retained indefinitely

 

7. Your Rights and Choices

7.1 Data Control Rights

  • Access: Request a copy of your personal data

  • Correction: Update or correct inaccurate information

  • Deletion: Delete your account and all associated data at any time from Settings, or by request

  • Portability: Request an export of your data in a machine-readable format

  • Restriction: Limit how we process your data

  • Objection: Object to certain data processing activities

  • Withdraw Consent: Withdraw consent at any time without affecting the lawfulness of prior processing

Account deletion is self-service under Settings > Privacy & Data > Delete Account. For access, correction, portability, restriction, or objection, email info@kygo.app and we will respond within the period required by applicable law.

 

7.2 Managing Wearable Connections

You may disconnect any wearable device at any time:

  • Oura: Disconnect via App Settings or revoke at cloud.ouraring.com

  • Fitbit: Disconnect via App Settings, or revoke access at myaccount.google.com/permissions (Google-connected) or fitbit.com/settings/applications (legacy)

  • Garmin: Disconnect via App Settings or revoke at connect.garmin.com

  • WHOOP: Disconnect via App Settings or revoke via your WHOOP account settings

  • Apple Health: Manage permissions via iOS Settings > Health > Data Access & Devices

  • Android Health Connect: Manage permissions via the Health Connect settings on your device

 

7.3 Device Permissions and Notifications

Camera, photo library, microphone, speech recognition, and notification access are all optional and requested only when you first use the feature that needs them. You can revoke any of them in your device settings, and turn individual reminders off under Settings in the app. Declining them limits the related feature but never blocks the rest of the app.

 

7.4 Contact Preferences

We do not send marketing email. The email you receive from us is limited to essential service messages such as password resets, security notices, replies to your support requests, and notices about changes to these policies or your subscription. Reminders and other push notifications are controlled by you under Settings in the app and in your device settings. If we ever introduce marketing communications, they will be opt-in and this section will be updated first.

 

7.5 Website Cookies and Analytics Choices

On kygo.app you can block or delete cookies in your browser settings, use a private window, or install the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout. Blocking analytics cookies does not affect any article or tool on the site. We honor a Global Privacy Control signal sent by your browser where we are required to. Essential hosting and security cookies set by Wix cannot be turned off without breaking the site.

8. Apple HealthKit Compliance

For iOS users who integrate with Apple HealthKit, we adhere to Apple's strict requirements:

  • We only access HealthKit data you explicitly authorize

  • HealthKit data is used solely for health and fitness features within the app

  • We will NEVER use HealthKit data for advertising or marketing

  • We will NEVER sell HealthKit data to third parties

  • We will NEVER share HealthKit data for advertising or data mining purposes

  • We will NEVER write false or inaccurate data to HealthKit

  • We do not store HealthKit data in iCloud

 

You may revoke HealthKit permissions at any time through iOS Settings. Revoking permissions will limit certain app features.

 

9. Children's Privacy

Our Service is not intended for children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe we have collected information from your child, please contact us immediately at info@kygo.app.

 

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States. These countries may have different data protection laws. We implement appropriate safeguards for international transfers as required by applicable law.

11. California Privacy Rights (CCPA/CPRA)

California residents have additional rights under the California Consumer Privacy Act:

  • Right to know what personal information is collected, used, and shared

  • Right to delete personal information

  • Right to correct inaccurate personal information

  • Right to limit the use of sensitive personal information

  • Right to opt out of the sale or sharing of personal information

  • Right to non-discrimination for exercising privacy rights

 

We do not sell your personal information for money. Two things some laws treat as "sharing" for cross-context behavioral advertising: the advertising identifier described in section 4.2, which is shared with our measurement partner to attribute app installs, and the analytics cookies on kygo.app described in section 2.6. You can stop the first using your device controls in section 4.2 and the second using the browser controls in section 7.5, or by emailing info@kygo.app, and we will honor a Global Privacy Control signal where we are required to. Your health and nutrition data is treated as sensitive personal information and is never used for advertising.

12. Washington and Nevada Consumer Health Data

Washington's My Health My Data Act and Nevada's SB 370 treat the information you log in Kygo as consumer health data and require a separate policy for it. Ours is at kygo.app/consumer-health-data. It sets out the categories of consumer health data we collect, why we collect them, where they come from, who we share them with, and how to confirm, access, withdraw consent for, or delete that data. We do not sell consumer health data, and we do not collect or share it for any purpose beyond the ones that policy lists.

13. European Privacy Rights (GDPR)

If you are in the European Economic Area or the United Kingdom, you have additional rights under the General Data Protection Regulation, including the rights of access, rectification, erasure, restriction, portability, and objection, the right to withdraw consent at any time, the right to object to automated decision-making, and the right to lodge a complaint with your supervisory authority.

Our legal bases are: performance of our contract with you for account and subscription data; your explicit consent for health data, which is special category data under Article 9, and for each wearable connection, camera, microphone, and notification permission you grant; and our legitimate interest in securing the Service, diagnosing crashes, and measuring how the app and website are used. Withdrawing consent for a health integration is as simple as disconnecting it in App Settings, and it does not affect processing carried out before you withdrew.

14. Changes to This Privacy Policy

We may update this Privacy Policy periodically. We will notify you of material changes through in-app notifications, email to your registered address, and by updating the "Last Updated" date. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

 

15. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us:

Email: info@kygo.app

Address: Kygo Health LLC, 30 N Gould St Ste N, Sheridan, WY 82801

 

For HealthKit-specific inquiries you may also contact Apple Support or review Apple's Health privacy documentation at apple.com/privacy/features.

 

Last Updated: September 13, 2026

© 2026 Kygo Health LLC. All rights reserved.

New York, NY​

© 2025 by KYGO Health LLC Kygo Health LLC is not intended to diagnose, treat, cure, or prevent any disease. The information provided is for educational purposes only and is not a substitute for professional medical advice. Consult your physician before making any health decisions.

bottom of page