Privacy Policy
MoveKind Application
Last updated: February 15, 2026
1. Data Controller
Eaglets, a French single-member limited liability company (EURL)
Registered office: 18 rue Pierre Curie, 92800 Puteaux, France
Email: contact@movekind.io
Website: https://movekind.io
2. Core Principles
MoveKind is designed with privacy as a core priority.
Our commitments:
- No mandatory account. The Application works without signup, email, or password.
- Local-first storage. Most of your data stays on your device and does not pass through our servers.
- No data resale. We never sell, rent, or share personal data for commercial or advertising purposes.
- No ads in the mobile app.
- Data minimization. We only process data strictly necessary to operate the service.
3. Data We Collect
3.1 Data Stored Locally on Your Device
These data are stored only on your iPhone through SwiftData (local storage). They are not transmitted to our servers unless stated otherwise.
| Data | Purpose | Storage |
|---|---|---|
| First name | Coaching personalization (Maya addresses you by first name) | Local only |
| Age range | Exercise intensity adjustment | Local only |
| Fitness goal | Training path and session personalization | Local only |
| Selected coach (Maya or Leo) | UI and messaging personalization | Local only |
| Training location | Filtering suitable exercises | Local only |
| Preferred discipline | Exercise selection | Local only |
| Preferred training days | Path planning | Local only |
| Preferred session duration | Session calibration | Local only |
| Daily mood check-in | Coaching adaptation | Local only |
| Session history | Progress tracking, streak, statistics | Local only |
| Difficulty feedback | Future session adaptation | Local only |
| Subscription preferences | Premium subscription management | Local + Apple |
These data do not leave your device, except in the cases described in sections 3.2 and 3.3.
3.2 Data Sent to Our Servers (Referral Program)
The referral program is the only feature requiring communication with our servers.
| Data | Purpose | Storage |
|---|---|---|
| Referral code | Referrer identification | EU server |
| Anonymous device identifier | Anti-abuse (prevent fake referrals) | EU server |
| Referred user’s first name | Display in referrer referral dashboard | EU server |
| Referral status | Activation tracking (pending / validated) | EU server |
These data are hosted in the European Union (see section 7).
3.3 Automatically Collected Data
| Data | Purpose | Legal basis |
|---|---|---|
| Device model, iOS version, app version | Bug reports (only when user sends a report) | Consent |
| Anonymized crash logs | Bug detection and fixes | Legitimate interest |
3.4 Data We Do Not Collect
MoveKind does not collect:
- Email address (no account)
- Password
- Phone number
- GPS location data
- Health data from HealthKit / Apple Health
- Biometric data
- Contacts / address book
- Photos or phone content (except screenshot voluntarily attached in a bug report)
- Payment data (fully handled by Apple)
- Advertising identifier (IDFA)
3.5 Health Data
Calories shown in the Application are algorithmic estimates based on workout duration and intensity. They are not sourced from health sensors, Apple Health, or HealthKit, and are not treated as special category health data under GDPR Article 9.
4. Legal Bases (GDPR)
In accordance with GDPR (EU) 2016/679, each processing activity relies on a legal basis:
| Processing | Legal basis | Rationale |
|---|---|---|
| Profile data (first name, age, goal) | Contract performance (Art. 6.1.b) | Required to provide personalized coaching |
| Session history and progress | Contract performance (Art. 6.1.b) | Required for progress tracking and training paths |
| Subscription management | Contract performance (Art. 6.1.b) | Required to provide premium features |
| Referral program | Contract performance (Art. 6.1.b) | Required to grant referral rewards |
| Anonymized crash logs | Legitimate interest (Art. 6.1.f) | Stability and quality improvement |
| Bug reports (voluntarily sent) | Consent (Art. 6.1.a) | User actively chooses to send a report |
| Ideas and suggestions (voluntarily sent) | Consent (Art. 6.1.a) | User actively chooses to send feedback |
| Website analytics (Google Analytics) | Consent (Art. 6.1.a), where required | Audience measurement for movekind.io |
5. Sharing with Third Parties
5.1 Principle
We do not sell, rent, or share your personal data for commercial, advertising, or marketing purposes.
5.2 Processors
Data transmitted to our servers (section 3.2) may be processed by:
| Processor | Service | Data involved | Location |
|---|---|---|---|
| Firebase (Google Cloud) or Supabase | Referral backend hosting | Referral code, anonymous identifier, referred first name, status | European Union (europe-west1) |
| Apple Inc. | In-App Purchase processing | Transaction data (managed by Apple, not accessible to Eaglets) | USA |
| Google LLC | Website audience measurement (Google Analytics) | Navigation data (pages, language, technical info) | USA / EU depending on Google configuration |
Each processor is bound by a data processing agreement compliant with GDPR Article 28.
5.3 Other Disclosures
We may disclose data when required to:
- Comply with legal obligations
- Protect our legal rights
- Prevent fraudulent activities
6. International Transfers
6.1 Principle
We strive to keep all data within the European Union.
6.2 Transfer Cases
| Recipient | Country | Safeguards |
|---|---|---|
| Apple Inc. (payments) | USA | Applicable legal transfer framework at time of processing |
| Google LLC (Google Analytics) | USA | Standard Contractual Clauses and supplementary measures by Google |
| Firebase/Supabase (backend) | EU (europe-west1) | No transfer outside EU when EU region is configured |
If future transfers outside the EU are required, we will implement appropriate safeguards (such as Standard Contractual Clauses) and update this policy.
7. Hosting and Security
7.1 Local Data
Most data are stored locally on your device using SwiftData, protected by iOS security mechanisms (storage encryption, biometrics, passcode).
7.2 Server Data
Referral data are hosted on EU servers (europe-west1 / eu-west-3), with:
- Encryption in transit (TLS 1.2+)
- Encryption at rest (AES-256)
- Strict access controls
7.3 Payment Security
Eaglets does not access payment data. Transactions are fully handled by Apple through StoreKit. No card number or bank detail transits through our systems.
8. Retention Periods
| Data type | Retention period |
|---|---|
| Local profile data | Until app deletion or manual deletion by user |
| Local workout history | Until app deletion or manual deletion by user |
| Referral data (server) | 2 years after last referral-related activity |
| Bug reports and suggestions | 1 year after receipt |
| Anonymized crash logs | 6 months |
| Website analytics (Google Analytics) | According to retention settings configured in Google Analytics |
When data are no longer needed for their original purpose, they are deleted or anonymized.
9. Your Rights
Under GDPR and French data protection law, you have the following rights:
| Right | Description |
|---|---|
| Access | Obtain a copy of your personal data |
| Rectification | Correct inaccurate or incomplete data |
| Erasure | Request deletion of your data |
| Restriction | Request restricted processing |
| Portability | Receive your data in a structured, machine-readable format |
| Objection | Object to processing based on legitimate interest |
| Withdraw consent | Withdraw consent at any time (without affecting prior lawfulness) |
How to Exercise Your Rights
Email: contact@movekind.io
We respond within 30 days. This period may be extended by up to 2 additional months for complex requests, with notice to you.
For security reasons, we may request identity verification before processing a request.
Complaint
If you consider data processing non-compliant, you may file a complaint with the French Data Protection Authority (CNIL):
- Website: https://www.cnil.fr
- Address: CNIL, 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07
10. Data Deletion
10.1 Local Data
As no account is required, deleting the Application from your device removes local data (profile, history, progress).
10.2 Server Data (Referral)
To request deletion of referral data stored on our servers, email contact@movekind.io. Deletion will be completed within 30 days.
10.3 In-App Deletion Feature
A “Delete my account” button is available in Application Settings. It:
- Deletes local Application data
- Sends a server-side referral data deletion request
- Is irreversible
Important: Data deletion does not cancel an active subscription. Subscription cancellation must be done separately in iPhone settings.
11. Cookies and Trackers
11.1 Mobile Application
The MoveKind app uses no cookies and no advertising trackers. It does not use Apple IDFA and does not participate in ad networks.
11.2 movekind.io Website
The movekind.io website uses Google Analytics (gtag.js, Measurement ID G-60Z8JL4B00) for audience measurement. This may involve cookies or similar technologies depending on browser and settings.
Where required by law, consent must be collected before enabling non-essential trackers.
12. Minors
The Application is intended for users 16 years or older. We do not knowingly collect personal data from children under 16. If we discover such data, we will delete them promptly.
If you are a parent or guardian and believe a child under 16 uses the Application, contact us at contact@movekind.io.
13. Policy Updates
We may update this Privacy Policy at any time. In case of significant changes, users will be informed through an in-app notice.
The last update date appears at the top of this document. We encourage regular review.
14. Contact
For any privacy-related question:
Eaglets EURL
18 rue Pierre Curie, 92800 Puteaux, France
Email: contact@movekind.io