Privacy policy
Kriterion holds the most sensitive information an app can hold, so this document is written to be read rather than to protect us. The short version: what you log stays on your device, we have no account system and no analytics, and exactly three things ever leave your phone. All three are listed below.
Who we are
Kriterion is the data controller for the limited processing described here. You can reach us at privacy@kriterionapp.com. A postal address and registered company details will be added here before publication.
This website
Everything above and below describes the app. This marketing site, the one you are reading this on, does one additional and much smaller thing: if you leave an email address in the box asking to be told when Kriterion ships, that address is stored for exactly that purpose and nothing else. It is not linked to any app data, because at the point you sign up there is no app data to link it to. The whole list is deleted once the launch email has gone out. Nothing else on this site sets a cookie, loads a tracker, or fingerprints you.
What we are still deciding
Neither of the following exists in Kriterion today. Both are genuine possibilities we are weighing, not features already built and left undisclosed, and this document will be updated before either ships, not after.
- Product analytics, so we can see where people get stuck instead of guessing. If this happens, the intent is aggregate, on-device counts you can turn off in Settings, not a third-party SDK reading your food log. No vendor has been chosen.
- Encrypted cloud backup, most likely via Supabase, so a phone can be restored onto a new device without your local export file. The app's existing backup export is already encrypted end to end with a password only you hold; a cloud copy would store that same ciphertext, unreadable to us or to Supabase, not a plaintext copy of your data.
What stays on your device
Everything you log lives in a private database on your phone. We never receive it, and there is no account to sign into, because there is no server holding your history.
- Food, drink and supplement entries, including anything you scan or search for
- Workouts, sets, reps, weights and personal records
- Body weight, body composition and measurements
- Menstrual cycle dates and symptom check-ins, if you use them
- Progress photos, which are stored in the app's own storage and never uploaded
- Your targets, coaching tone, accent colour and other settings
Deleting the app removes all of it. There is no copy anywhere else, which also means we cannot restore it for you. Use the in-app encrypted export if you want a backup you control.
Health app data
If you allow it, Kriterion reads from and writes to Apple Health or Android Health Connect. This is entirely optional, the app works without it, and you can revoke it at any time in Apple Health or Health Connect rather than having to ask us.
| Platform | Data types |
|---|---|
| Apple Health | Body mass, active energy burned, step count, resting heart rate, heart rate variability (SDNN), sleep analysis |
| Health Connect | Weight, active and total calories burned, steps, exercise sessions, resting heart rate, heart rate variability (RMSSD), sleep sessions |
This data is read on your device to calculate your readiness score, your metabolic rate and your trends. It is never transmitted to us or to anyone else. Health data is never used for advertising, and never shared or sold. That is both our policy and a platform requirement we are bound by.
The three things that leave your phone
1. Food searches
When you search for a food or scan a barcode, the search term or barcode is sent to the food databases we use: Open Food Facts, USDA FoodData Central, and our own index built from those plus the UK government's Composition of Foods Integrated Dataset and published restaurant menus.
What is sent is the thing you typed or scanned. What is not sent: your food log, your health data, your weight, your identity, or anything about you.
2. Label and food photographs
If you photograph a nutrition label or a meal, that image is sent to our processing service to be read, and the extracted numbers come back. The photograph is used for that request and is not added to any profile of you.
Alongside the image we send a per-installation identifier. It exists for one reason: enforcing the daily free scan limit. It is stored only as a salted hash on our side, it is not linked to your name, email or health data, and it is not used for analytics, advertising or tracking. It deliberately survives reinstalling the app, because otherwise the limit would not be a limit.
3. Exercise demonstration media
Exercise demonstration clips are fetched from a content host when you view an exercise. This sends the usual technical information any web request sends, such as your IP address. No information about your training is included.
What we do not do
- No advertising, and no advertising identifiers
- No analytics SDK. There is no Google Analytics, Firebase Analytics, Crashlytics, Mixpanel, Amplitude, Segment, Sentry or similar in the app
- No third-party trackers of any kind
- No selling or sharing of your data. There is no business model here that depends on knowing what you ate
- No account inside the app, so no in-app email list, no password to leak, and no database of app users to breach. The one email list that exists is the launch waitlist on this website, covered above
Permissions, and why each one exists
| Permission | Why |
|---|---|
| Camera | Scanning barcodes and photographing nutrition labels. Images are used for that scan only. |
| Internet | Food lookups, label reading and exercise media. |
| Notifications | Only the reminders you switch on. |
| Foreground service and audio | The HIIT timer keeps counting and speaking intervals with the screen off. |
| Run at startup | Restores your scheduled reminders after the phone restarts. |
| Vibration | Haptic feedback, which you can turn off. |
| Photo library (add only) | Saving a workout share card to your gallery, when you ask for it. |
Your rights
Under UK GDPR you have rights of access, correction, erasure, restriction, portability and objection. In practice most of these are already in your hands rather than ours, because we do not hold your data:
- Access and portability: export your full history from the app at any time
- Erasure: deleting the app erases everything it holds. To have the installation identifier removed from our quota records, email us
- Withdrawing consent: revoke health access in Apple Health or Health Connect, and the app carries on without it
If you think we have handled your information badly, please tell us first, and you also have the right to complain to the Information Commissioner's Office at ico.org.uk.
Children
Kriterion is not designed for or directed at children under 16, and we do not knowingly process their information.
Not a medical service
Kriterion is a wellness and training tracker. It is not a medical device, it does not diagnose, treat, cure or prevent any condition, and nothing in it is medical advice. Cycle phases are estimates from the dates you enter, and are not a contraceptive method and not a fertility test. Speak to a qualified clinician before making significant changes to how you eat or train.
Changes
If this policy changes in a way that affects what leaves your device, we will say so in the app rather than quietly updating this page.