Back to Kriterion

Privacy policy

Last updated: DRAFT, not yet published. Applies to the Kriterion app on iOS, Android and Wear OS.

Kriterion holds the most sensitive information an app can hold, so this document is written to be read rather than to protect us. The short version: what you log stays on your device, we have no account system and no analytics, and exactly three things ever leave your phone. All three are listed below.

This is a draft. It is factually accurate about what the app does, but it has not been reviewed by a solicitor and it is not yet a published legal document. Have it checked before you rely on it, and before submitting to the App Store or Google Play.

Who we are

Kriterion is the data controller for the limited processing described here. You can reach us at privacy@kriterionapp.com. A postal address and registered company details will be added here before publication.

This website

Everything above and below describes the app. This marketing site, the one you are reading this on, does one additional and much smaller thing: if you leave an email address in the box asking to be told when Kriterion ships, that address is stored for exactly that purpose and nothing else. It is not linked to any app data, because at the point you sign up there is no app data to link it to. The whole list is deleted once the launch email has gone out. Nothing else on this site sets a cookie, loads a tracker, or fingerprints you.

What we are still deciding

Neither of the following exists in Kriterion today. Both are genuine possibilities we are weighing, not features already built and left undisclosed, and this document will be updated before either ships, not after.

What stays on your device

Everything you log lives in a private database on your phone. We never receive it, and there is no account to sign into, because there is no server holding your history.

Deleting the app removes all of it. There is no copy anywhere else, which also means we cannot restore it for you. Use the in-app encrypted export if you want a backup you control.

Health app data

If you allow it, Kriterion reads from and writes to Apple Health or Android Health Connect. This is entirely optional, the app works without it, and you can revoke it at any time in Apple Health or Health Connect rather than having to ask us.

PlatformData types
Apple Health Body mass, active energy burned, step count, resting heart rate, heart rate variability (SDNN), sleep analysis
Health Connect Weight, active and total calories burned, steps, exercise sessions, resting heart rate, heart rate variability (RMSSD), sleep sessions

This data is read on your device to calculate your readiness score, your metabolic rate and your trends. It is never transmitted to us or to anyone else. Health data is never used for advertising, and never shared or sold. That is both our policy and a platform requirement we are bound by.

The three things that leave your phone

1. Food searches

When you search for a food or scan a barcode, the search term or barcode is sent to the food databases we use: Open Food Facts, USDA FoodData Central, and our own index built from those plus the UK government's Composition of Foods Integrated Dataset and published restaurant menus.

What is sent is the thing you typed or scanned. What is not sent: your food log, your health data, your weight, your identity, or anything about you.

2. Label and food photographs

If you photograph a nutrition label or a meal, that image is sent to our processing service to be read, and the extracted numbers come back. The photograph is used for that request and is not added to any profile of you.

Alongside the image we send a per-installation identifier. It exists for one reason: enforcing the daily free scan limit. It is stored only as a salted hash on our side, it is not linked to your name, email or health data, and it is not used for analytics, advertising or tracking. It deliberately survives reinstalling the app, because otherwise the limit would not be a limit.

3. Exercise demonstration media

Exercise demonstration clips are fetched from a content host when you view an exercise. This sends the usual technical information any web request sends, such as your IP address. No information about your training is included.

What we do not do

Permissions, and why each one exists

PermissionWhy
CameraScanning barcodes and photographing nutrition labels. Images are used for that scan only.
InternetFood lookups, label reading and exercise media.
NotificationsOnly the reminders you switch on.
Foreground service and audioThe HIIT timer keeps counting and speaking intervals with the screen off.
Run at startupRestores your scheduled reminders after the phone restarts.
VibrationHaptic feedback, which you can turn off.
Photo library (add only)Saving a workout share card to your gallery, when you ask for it.

Your rights

Under UK GDPR you have rights of access, correction, erasure, restriction, portability and objection. In practice most of these are already in your hands rather than ours, because we do not hold your data:

If you think we have handled your information badly, please tell us first, and you also have the right to complain to the Information Commissioner's Office at ico.org.uk.

Children

Kriterion is not designed for or directed at children under 16, and we do not knowingly process their information.

Not a medical service

Kriterion is a wellness and training tracker. It is not a medical device, it does not diagnose, treat, cure or prevent any condition, and nothing in it is medical advice. Cycle phases are estimates from the dates you enter, and are not a contraceptive method and not a fertility test. Speak to a qualified clinician before making significant changes to how you eat or train.

Changes

If this policy changes in a way that affects what leaves your device, we will say so in the app rather than quietly updating this page.