Privacy Policy and Terms of Use for the Kova app.
Effective date: August 12, 2026 Last updated: August 31, 2026
This Privacy Policy explains how James Craig, a sole proprietor operating as “Kova” (“Kova,” “we,” “us”), handles your information in the Kova iPhone app. We built Kova to be private by default: we do not show ads, we do not sell your data, and you can delete your account and its active Kova data from inside the app at any time. Limited provider logs and backup copies follow the retention rules in §8.
If you have questions, contact us at james20june@gmail.com.
James Craig (a sole proprietor operating as Kova), located in Ontario, Canada, is the controller (and, under Canadian law, the organization) responsible for your personal information. For users in the EU/UK, we are the “controller” under the GDPR/UK GDPR.
You provide directly:
Collected automatically:
We process this information to perform our contract with you (to provide the app), and, where applicable, based on your consent or our legitimate interest in operating and securing Kova.
Kova’s meal scanning and AI coach are powered by Google’s Gemini API.
Google processes this data as our service provider to return results to Kova. Google may log prompts, responses, and associated technical metadata for a limited period for abuse monitoring, service security, and required legal or regulatory disclosures. Kova does not use this content for advertising, and we do not sell it. Google’s handling of Gemini API data, including the applicable retention and paid-service restrictions, is described in Google’s terms and data-retention documentation; see https://ai.google.dev/gemini-api/terms, https://ai.google.dev/gemini-api/docs/zdr, and https://policies.google.com/privacy.
AI estimates are approximations, not medical or dietary advice. Nutrition figures are AI-generated estimates; where a food is matched, we link its source in the U.S. Department of Agriculture (USDA) FoodData Central database.
Food search and citations use USDA FoodData Central, a public U.S. government database. When you search or when a scanned food is matched, we send the food term to USDA to retrieve nutrition data. Kova does not intentionally include your Kova account identifier with that request. Because a search box can contain any text, do not enter personal or sensitive information as a food-search term.
Food search also uses Open Food Facts, a community database of packaged products, to cover branded items — including when you scan a product barcode, in which case we send the barcode number to USDA and Open Food Facts to look up the product. As with USDA, Kova does not intentionally include your account identifier and sends only the food term or barcode. Where a result comes from Open Food Facts we credit it in the app (“Data from Open Food Facts”). Open Food Facts data is made available under the Open Database License (ODbL).
We do not sell your personal information and we do not share it for advertising. We use a small set of service providers to run Kova:
| Provider | Purpose | Notes |
|---|---|---|
| Supabase | Database, authentication, and backend hosting | Your data is stored in Postgres hosted in Canada (ca-central-1) |
| Apple | Sign in with Apple; subscription billing; optional speech recognition | Speech is processed in real time and on-device where supported; governed by Apple’s Privacy Policy |
| Google (Gemini API) | AI meal/receipt/menu analysis, voice-input interpretation, coach responses, Plate Twin images, and spoken-voice (text-to-speech) audio (§4) | Receives photos, voice transcripts, the disclosed coach context (including optional Health signals), food names for Plate Twin, and text to be spoken; limited provider logging is described in §4 |
| USDA FoodData Central | Nutrition data source (§5) | Receives food terms or barcodes without an intentionally included Kova account identifier |
| Open Food Facts | Branded/packaged food data (§5) | Receives food terms or barcodes without an intentionally included Kova account identifier; data under ODbL |
Apple Health: Apple Health itself is not a sub-processor. If you connect it, Kova reads and writes the categories you choose on your device, syncs workout and sleep records to your private Kova account, and keeps the Pulse Check baseline on your device. Your body signals are never shown in any shared, exportable, or public part of the app. If you separately enable AI processing, the signals described in §4 may be sent to Google’s Gemini API for your own private coaching.
Your Kova account data is stored in Canada (Supabase, ca-central-1). Some processing necessarily occurs outside Canada — for example, Apple (authentication, payments, and optional off-device speech recognition) and Google (Gemini AI processing) may process data in the United States or other countries. Where we transfer personal data internationally, we rely on appropriate safeguards as required by applicable law (including, for the EU/UK, standard contractual clauses used by these providers).
We generally keep account data while your account exists. Operational, crash, and performance diagnostics are automatically deleted after about 30 days. Plate Twin images are also deleted automatically after about 30 days.
You can delete your account at any time in the app: Settings → Delete account. Deletion is permanent and removes active, attributable data from Kova’s database, including your profile, subscription/entitlement record, usage counters, logs, journal, workouts, sleep records, and coach history. Kova also removes files in your private user folders, including Plate Twin images and account-scoped generated voice clips. Meal, receipt, and menu photos and raw microphone audio are not stored in Kova’s database or private file storage.
Limited copies can remain temporarily in encrypted backups and in service-provider security or operational logs, including the limited Gemini logging described in §4. These copies are isolated from normal app use and are removed according to the provider’s retention schedule, unless a longer period is legally required.
If you connect Apple Health, the Pulse Check heart-rate baseline is stored only on your device. Kova clears that baseline, its app-level Health connection choice, local Health sync markers, local breathwork history, cached private images, and other account-derived local state when you sign out or delete your account. iOS controls the underlying Apple Health permission; another Kova account on the device must still explicitly reconnect before Kova reads or syncs Health data. Synced workout and sleep records are stored in your private Kova account and deleted with that account. Health signals used for AI coaching are processed by Google as described in §4 and are not separately stored by Kova beyond the resulting coach history. A check-in you open from a Pulse Check is saved with a small context tag (for example, “elevated stretch”) in your account so the coach has context; it is deleted when you delete your account.
Depending on where you live, you have rights over your personal information:
You can exercise most of these rights directly in the app (edit your profile; delete your account). For anything else, email james20june@gmail.com and we will respond as required by law. We will not discriminate against you for exercising your rights.
Data is encrypted in transit (HTTPS/TLS). Access to your data is protected by per-user database security rules so that you can only access your own records. Sensitive keys (AI and other service credentials) are held server-side and never shipped in the app. No method of transmission or storage is 100% secure, but we work to protect your information.
Kova is rated 13+ on the App Store and is not directed to children under 13. Sign in with Apple occurs before the in-app birth-date check. That sign-in automatically creates the temporary authentication record and default account records described in §2 before the date of birth is requested. If the date entered indicates the person is under 13, Kova blocks setup, deletes the local onboarding draft, and requests deletion of the authentication and default account records; access remains blocked while a network retry is pending. Until that retry succeeds, those temporary records may remain in Kova’s backend. The birth date is not saved to the account, and no Health connection, user logs, meal photos, or coach messages are created for that attempt. Kova does not use the temporary records to provide app features and tries the deletion again when the app next launches or its session state changes. If you believe a child has provided us information, contact us and we will delete it.
We may update this policy from time to time. We will change the “Last updated” date above and, for material changes, provide notice in the app.
James Craig (operating as Kova) Ontario, Canada james20june@gmail.com