Privacy at KYNTIVO
Updated 3 October 2026
This page explains how KYNTIVO handles data when you use the app and the website. The operator is also the data controller.
Account and signing in
You can start without linking an account. For that path the service creates a technical identifier and keeps a session so you can carry on. You can link the account later with any available method.
When you sign in by email, we process the email address and its verification.
For Google sign-in we request only the openid, email and basic profile scopes. That gives us the account identifier, the email address and the basic profile details Google provides in that scope. We use them to sign you in and to link the account.
We do not take the name or picture from your Google account as your public name or profile photo — you set those in the app.
KYNTIVO does not request access to Gmail messages, Drive, contacts or calendar. Basic Google sign-in is not a request for health data held by Google.
Apple provides the details according to the option you choose, including a hidden email address if you pick one. We keep the provider token so that access for the app can be revoked when the account is deleted; it is not reachable from the app and is removed once revoked.
Profile, friends and challenges
We keep your chosen name, profile picture and profile look, friendships, requests and invitations, challenge entries and game progress.
Depending on the feature in use, others can see your public name, profile picture, profile look, placement and the relevant step totals or results.
A published profile photo is stored at a publicly readable address, so anyone who knows that address can open it even without signing in.
Your sign-in email, age, height, weight and private form of address are not part of the public profile. Content that is not public stays available only to the people entitled to see it.
Movement and data on your phone
Once you turn measuring on and grant permission, the app reads steps measured by your phone or supported watches. On iPhone from health data: steps from iPhone, Apple Watch and Garmin Connect, or from the phone's own step sensor. On Android from Health Connect: steps saved there by the phone itself, Samsung Health or Garmin Connect. If you allow it, KYNTIVO also writes the steps your phone measures through Google Play services to Health Connect. When several sources record steps for the same time, the source order in Health Connect decides what counts. On Android without Health Connect, the app reads steps directly from Google Play services measurement, starting from when you turn measuring on. Manually entered steps and steps from other apps do not count.
To sync your profile and settle competitions, steps are sent to the server split into the time buckets we need. Alongside them go the app installation identifier, the snapshot order and the device time zone, so the same steps are not counted twice. Where the verification path in use requires a proof of app authenticity issued by the device system (Apple App Attest, Google Play Integrity), that is sent as well; it serves to limit forged writes.
Optional age, height, weight and form of address stay in protected storage on the phone and are not sent to the server. They are not public profile details.
You can remove access to health data and physical activity at any time in the device settings. The app then stops reading from that source. On iPhone, a separately allowed motion sensor can keep working and can be removed the same way. On Android, steps are not counted without reading from Health Connect, or without physical activity on a phone without Health Connect. Steps KYNTIVO has already written to Health Connect stay there and you manage them in Health Connect. The record of when your steps started counting and your progress so far stay stored until you delete your account.
We do not use movement or health data for ad targeting and we do not sell it.
Optional rewarded videos
Rewarded videos are an optional feature we are rolling out gradually. Where the app offers it, you can choose to watch an ad video for coins or an Atlas point. A video never starts on its own and the app works without it. Until the feature is fully launched, the app may show only a trial video that does not add a reward.
Videos are provided by Google AdMob (Google Ireland Limited) under its own policies. When a video loads and plays, Google's software development kit (SDK) in the app itself collects device and app information, identifiers, IP address (approximate location), ad interactions and diagnostics. Google uses them to show ads, for analytics and to prevent fraud; the data is encrypted in transit.
When showing ads, Google may work with other advertising partners (ad technology providers). You can find the list of these partners in the consent choice, where it is shown.
On Android, Google may use the device advertising ID, which you can reset or delete in Android settings. On iPhone we do not ask for tracking permission, so Google does not get the device advertising identifier (IDFA); the SDK may still use other app or developer identifiers.
Where the law requires it (for example in the EEA, the UK and Switzerland), a Google consent choice appears before the first ad. Where Google offers this choice, you can change it later in Settings → Ad consent.
KYNTIVO itself gives Google only a random one-time code for each video, so Google can confirm the reward after it is watched. We never pass your name, email, steps or health data to ads. The information described above is collected directly by Google's SDK.
We keep a record of each video with your account (purpose, day, status, time and Google's confirmation). This lets us enforce the daily limit and add each reward only once. The records are deleted with your account.
Why we use the data
Accounts, syncing and the game features you ask for are provided to deliver the service you choose by using it.
Necessary operational and security data is used to protect accounts, prevent abuse, resolve problems and provide support; this is our legitimate interest.
Optional access to data on your device is used only when you allow it on the device, and only in the scope described here. Where the law requires consent for a particular processing, we rely on it only where consent has actually been given.
Statutory requests are handled on the basis of a legal obligation.
Providing optional profile details is not a condition of registration. Without a sign-in credential the matching sign-in method cannot be used, and without permission steps cannot be measured from that source.
Who provides the technical operation
Supabase provides accounts, the database and storage for profile photos. Vercel provides the website and its server parts. Resend sends verification and operational emails. Expo handles app distribution and updates. Google AdMob and its advertising partners provide optional rewarded videos (see the rewarded videos section).
If you allow notifications, we store your device's notification token with your account and send notifications (for example with a friend's name) through the Expo service and Apple's and Google's system services; when they arrive depends on the device and these services. When you sign out, the app tries to disconnect the token from your account; if that fails, the link may remain. We also delete the token when the service stops accepting it and when you delete your account.
Apple and Google process their own sign-in under their own policies. On Android devices, verification that the installation is genuine may run through a Google service.
Technical providers may process an IP address, the time of a request and necessary diagnostic data. Our own database does not store IP addresses; to protect sign-in to the administration it only derives a keyed fingerprint of part of the address together with a timestamp, kept for a limited time.
Access is limited to authorised operations staff and to the providers needed to deliver the service.
Providers and their sub-processors may also process data outside the European Economic Area. Where such transfers are needed, the European Commission standard contractual clauses included in the data processing agreements with those providers apply. You can obtain information about these safeguards at support@kyntivo.com.
Provider data processing agreements
How long we keep data and how to delete it
Account and game data is kept for as long as the account is in use, unless a particular feature needs a shorter time.
In the app you will find Delete my data in Settings.
Without the app, use the account deletion page or write to support@kyntivo.com. Requests made outside the app are handled manually, and we may check that the account is yours before deleting it.
Personal account data leaves the database when the deletion is confirmed. Profile photos and the KYNTIVO sign-in account itself are finished by a server cleanup; until it completes, the account is blocked and signed out on every device.
Challenges already under way keep running for the others; your entry and your progress are removed from them and you no longer appear in the standings. Challenges created from your account that are still waiting for participants and have not started are cancelled, as are the invitations that came from it.
This does not delete your Google or Apple account, nor health data held in other apps.
Backups are not the database in everyday use. If the database is ever restored from a backup, we apply completed deletions again from a separate record kept outside the database.
We keep a minimal record of a completed deletion — the account identifier and timestamps, without name or email. It exists so the deletion can be applied again after a restore and so that a device connecting later learns about it. We keep it for as long as it is needed for those purposes.
Operational and security counters that prevent repeated or abusive use are kept for a short time; those that outlive the deletion hold no detail about a particular account.
Your rights and contact
Depending on the applicable legal basis you can request access to your data, its correction, erasure, restriction of processing or portability, and object to processing based on legitimate interest.
Where processing is based on consent, that consent can be withdrawn; withdrawal does not affect the lawfulness of earlier processing. Reading your steps is governed by the permission in your device settings — you can withdraw it there at any time.
Requests are handled at support@kyntivo.com. We do not require a national ID number or identity document for an ordinary request.
You can also contact the Czech Office for Personal Data Protection: uoou.gov.cz
We do not carry out decisions with legal or similarly significant effects based solely on automated processing; a game score is not such a decision by itself.
Google API data and changes to this page
Use of data obtained through Google APIs is limited to the features described here and follows the Google API Services User Data Policy, including the applicable Limited Use requirements.
Before introducing a new purpose, or features that process further data, we update this page and ask for any choice or consent needed.
Who operates the service
KYNTIVO is operated by Petr Jergon, company ID 02074079, registered at Štichova 581/23, Háje, 149 00 Prague 11, Czech Republic.
Contact for questions and for requests about your data: support@kyntivo.com