Kasvu · Privacy Policy
Privacy Policy
Kasvu is a DBA of Create Business Solutions, LLC (“we”). Kasvu is a recovery and training app. It reads your heart rate to score how recovered you are each morning and plans strength and endurance sessions from your own logged training. This policy explains what the app collects, where it goes, and how you control it. It is written to be read, not skimmed.
The short version
- Core recording and planning work on your phone without an account. Backup, sync, Circle and the AI connector require an account and a connection.
- If you sign in, training data is backed up to your account. Circle sharing and connecting an AI assistant are separate choices.
- We do not sell your data, do not show ads, and do not share your data with advertisers or data brokers. Ever.
- You can export your locally stored training data and request account deletion from inside the app. See the controls and retention sections for scope and limitations.
What the app collects
Health and fitness data
- Heart rate and beat-to-beat intervals from a Bluetooth heart rate strap you connect, during morning readings and training sessions.
- Derived recovery metrics: HRV (RMSSD, SDNN, pNN50), resting heart rate, and the recovery score computed from them.
- How you feel: an optional 1–10 rating you enter each morning.
- Training sessions: exercises, weights, reps, sets, reps in reserve, rest times, and heart rate during and after sets.
- Apple Health: with your permission, heart rate variability, resting and active heart rate, sleep, workouts and workout routes, steps, walking/running distance and flights climbed. Kasvu uses these for recovery and training insights, importing activities, and suggesting activities you may have forgotten to record. It reads only the types you allow and can write completed workouts back if you separately permit it.
Location
During an outdoor session you start (run, walk, ride), the app records your GPS route to compute distance, pace and elevation and show the route afterwards, including while the screen is locked. With Health permission, it can also import routes recorded by other apps or devices. Motion and Health data can suggest missed activities without starting a new GPS recording. Saved routes may sync to your account; Circle route sharing is off by default.
Profile and setup
Sex, age, units, the equipment you have, your training goal, the days you can train, and any injuries or limits you type in. These are used to configure your plan and, if you connect one, are shown to your AI assistant. The app never interprets your injury notes itself.
Account
If you sign in with Apple, we receive an identifier and, if you allow it, your name and email (or Apple's relay address). Email sign-in uses your email address. Where password sign-in is used, our authentication provider stores a password hash, not a plaintext password.
Device and diagnostics
Kasvu remembers the identifier and name of a paired heart rate strap to reconnect. It records application errors and stack traces with build, platform and diagnostic context; these reports can sync to your account to help diagnose failures. Error text can reflect the operation that failed.
If you enable remote notifications, Kasvu registers a device push token and platform with your account and records notification delivery attempts. Coach notifications use Expo's push service and Apple's notification delivery. Local reminders are scheduled on your phone. Widgets and Live Activities may show workout measurements on your lock screen when you enable them.
What the app does not collect
No advertising identifiers, no tracking across other apps or websites, no contacts, no photos, no microphone, no analytics SDKs that profile you. We do not use the data for advertising or for training AI models.
Where your data lives
On your phone, in a local database. This is the source of truth and it works offline.
In your account, if you sign in. Data is stored with our hosting provider, Supabase, in a data centre in the eastern United States, encrypted in transit and at rest. Access is enforced per user by database row-level security: you can read and write only your own rows. Circle members can view shared information through restricted sharing endpoints. Authorized service operators may access account data when needed to operate, secure or support the service.
Circle sharing and routes
Joining a Circle allows its members to see shared recovery and workout information, including session details and history. Members cannot edit your workouts. Route sharing starts off. You can opt in to masked routes or full routes for your Circle. Masking removes areas within 500 metres of the start and end, including returns to those areas; remaining segments can still reveal places you visit. Full routes reveal the recorded path. Share only with people you trust.
Leaving the Circle stops new access through that membership. Turning route sharing off stops new access to routes through Circle. An already open view may take a few seconds to clear. Revocation cannot erase information someone has already seen, copied or captured.
Sharing with your own AI assistant
You can connect Kasvu to an AI assistant you already use (Claude or ChatGPT) so it can discuss your training with you. This happens only when you set it up and sign in to Kasvu from inside that assistant (OAuth); nothing is shared until you tap Allow. The assistant can then read your recovery readings, sessions, lift log, program and setup answers, answer questions you left open, leave short notes in the app, and propose a program for you to accept or reject. The tools do not log completed workouts or activate proposed programs. They can save or replace question answers, store day and increment-hold proposals, and update connection timestamps. Notification delivery can remove invalid device registrations.
When an authorized assistant calls a tool, our connector returns information to that assistant. Its provider processes it under its own terms and privacy settings. Kasvu stores notes, answers, proposals and connection metadata in your account; hosting services also process requests and operational logs. Revoke authorization under Me → Connect your AI → Connected apps, and remove the connection in your assistant too. Revocation prevents token renewal, but an already-issued access token may work until it expires. Signing out of the Kasvu phone app is not a connector revocation control. Disconnecting cannot erase information already delivered to the assistant or its provider.
Service providers
Supabase provides account authentication, database storage and server functions. Vercel hosts the website and connector. Expo and Apple deliver remote notifications; Apple also processes App Store purchases. Postmark sends account sign-in messages and processes recipient addresses, message content and delivery records. These services process information needed for those functions. An AI provider receives training information through a connection you authorize.
Your controls
- Export: the JSON export contains locally stored readings, sessions and routes, lift sets, programs and settings, excluding paired-device identifiers. The lift log is also available as CSV. It does not include all server-only records, such as connector notes, questions, proposals or Circle membership. Contact us for an account-data request.
- Delete a reading from its detail screen; if you are signed in, it is removed from your account on the next sync.
- Erase this phone: Me → Danger zone → Erase data on this phone clears the local training database and settings. Synced account records, Apple Health records and exported copies remain.
- Delete your account: Me → Danger zone → Delete account removes associated live account records when the request succeeds, then clears local app data. Check for errors before assuming deletion completed. This cannot be undone.
- Permissions: Bluetooth, Location and Health access can be withdrawn at any time in iOS Settings. The corresponding features stop working; nothing else does.
Retention
Account data is retained while you use the account unless you delete records or the account. Successful account deletion removes associated records from the live database. Our database hosting plan keeps seven days of daily backups; deleted records may remain in those backups until they age out. Postmark retains sign-in email content and activity for 45 days under our current setting, with deletion processing afterward; aggregate statistics and suppression records may remain longer. Hosting operational logs have separate provider retention periods and are not removed by the live-database deletion request. Copies you export or share with Circle members or an AI provider are outside that deletion process. If you use only offline features without signing in, your training records remain on the phone.
Children
Kasvu is not directed at children under 13 and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Changes
We will post revisions at this address with an updated effective date. Changes that require a new sharing choice will require that choice before the additional sharing is enabled.
Contact
Questions or requests about your data: nicknowlin@createbusinesssolutions.com.