Privacy Policy for Kudoro

Effective date: 11.08.2026

Introduction

This Privacy Policy applies to the Kudoro app, which is developed and maintained by Klippros Studios AB. Use of Kudoro is also subject to our Terms of Service. Most feature processing (including media library content and Strava activity data used for overlays) happens on the user's device. Certain subscription-related data is processed by third-party providers (Apple App Store, Google Play Store, and RevenueCat) as described below. Unless you opt out, Kudoro may also send pseudonymous product usage analytics to PostHog in the EU, as described in the "Product analytics (PostHog)" section. The app is provided “as is” and used entirely at your own risk.

Kudoro does not use advertising SDKs or sell personal information. Kudoro uses PostHog for product analytics (unless you opt out), and interacts with Strava and subscription providers as described in this policy. For questions or concerns, please contact [email protected].

What information does Kudoro obtain and how is it used?

Kudoro does not collect personal information beyond what is necessary to provide its features and, unless you opt out, to improve the product through usage analytics. Most feature processing happens on your device. Subscription-related information is processed by third-party providers as described in the "Subscriptions and RevenueCat" section. Product usage analytics are described in the "Product analytics (PostHog)" section.

The app may access the following types of data:

Media library

Kudoro may request access to your device's media library (photos and videos) so you can create overlays with your own content. This data is only accessed with your permission, processed entirely on your device, and never transmitted to Kudoro servers or third parties (including PostHog). Any content you generate (e.g., overlays) is stored only on your device; it is up to you to share it.

Data from Strava

Strava activity data, profile information, and related data are accessed only with your explicit authorization via the official Strava API. Kudoro has access to both public and private activities from your Strava account when you choose to connect.

Strava data used to generate overlays (including activity details, maps/routes, titles, and profile content) is processed on-device and is not transmitted to Kudoro servers or to PostHog. Separately, if product analytics are enabled, Kudoro may include the activity sport type (for example, Ride or Run) in usage analytics sent to PostHog, as described in the Product analytics section. Users may revoke Strava access at any time in Kudoro's settings or via Strava settings.

It is in the nature of the generated overlays that they include activity data. These overlays are stored only on your device. Choosing who to share them with is entirely up to you, for example, through social media, messaging apps, or any other method.

Subscriptions and RevenueCat

Kudoro uses RevenueCat to manage in-app subscriptions through the Apple App Store and Google Play Store. The following data is processed by RevenueCat and Apple/Google to provide subscription functionality:

Subscriptions are auto-renewing unless canceled by the user via Apple or Google. Kudoro does not access or store your payment information, email, or personal account details. Purchases are subject to your agreement with Apple or Google and Kudoro's Terms of Service.

The app displays subscription status, renewal date, and provides a Restore Purchases button. Users cannot cancel subscriptions within the app but are given instructions for managing subscriptions through Apple or Google accounts.

RevenueCat processes subscription data to manage purchases, restore access, synchronize subscription status across devices, and provide subscription reporting to the developer. Kudoro does not use advertising or cross-app behavioral advertising. Product usage analytics (separate from payment processing) are described in the "Product analytics (PostHog)" section.

RevenueCat and the respective app store may generate and store pseudonymous customer identifiers (such as an App User ID), country information, subscription history, transaction dates, and total spend related to your subscription. Kudoro may access this subscription-related information through the RevenueCat dashboard for revenue reporting and limited customer support purposes.

RevenueCat and the respective app stores act as independent data controllers for subscription processing. Kudoro does not determine the purposes or means of payment processing and does not act as a data controller for payment data processed by Apple, Google, or RevenueCat.

These subscription records are pseudonymous and do not include your name, email address, payment details, or other directly identifying information. The same RevenueCat User ID may also be used as the identifier for product analytics (see below) so we can improve the product and help with support requests. Kudoro does not receive your name or email from RevenueCat for these purposes.

Product analytics (PostHog)

Unless you opt out, Kudoro sends pseudonymous product usage analytics to PostHog to help us improve the app and debug issues. Klippros Studios AB (Kudoro) is the controller of this processing. PostHog acts as our processor and hosts the data on PostHog Cloud EU (Frankfurt / European Union). See PostHog's privacy policy.

Identifier. Analytics events are associated with your pseudonymous RevenueCat User ID (shown in Settings → Subscription). This is the same identifier used for support. It is not your name, email address, or Strava ID.

What we collect. We send explicit product events only (for example, preview, share, export, and paywall-related events), together with feature and usage metadata such as layout, Strava activity sport type (for example, Ride or Run), selected metric names (not metric values), Pro feature flags, overlay/theme settings, media type, dimensions, duration, aspect mode, export destination, and paywall outcome. We may also attach Pro status, an approximate account first-seen time from RevenueCat, and technical metadata such as app version/build, operating system, device type, manufacturer, device name/model, screen size, locale, timezone, and a session identifier. Approximate country and timezone may be derived from IP address for analytics; IP addresses are not stored, and we do not retain location information in finer detail than the country and timezone.

What we do not collect. We do not send photos, videos, overlay text, activity titles, GPS routes, metric values, Strava profile content, or other Strava activity details beyond the sport type noted above. We also do not use advertising identifiers, session replay, or automatic tap/screen capture. Analytics are limited to the explicit events and metadata described above.

Purpose. We use this data to understand how features are used, improve Kudoro, and help diagnose issues when you contact support. We do not use it for advertising, and we do not sell it.

Legal basis. We process product analytics based on our legitimate interests in operating, improving, and supporting Kudoro. You may opt out at any time as described below.

Retention. Usage analytics data is retained for at most one (1) year, and may be deleted earlier once it is no longer needed for product improvement or debugging.

Opt-out. Analytics are on by default. You can turn them off in Settings → Analytics → “Share usage analytics.” Existing users may also be offered this choice on the in-app privacy update notice.

Deletion. To request deletion of analytics data associated with your account, email [email protected] and include your RevenueCat User ID from Settings → Subscription. We will delete the associated analytics profile/data. In any case, we do not keep analytics longer than one (1) year.

Location data

Kudoro does not independently collect or track your device's real-time location. However, Kudoro allows you to create and share visual representations of workouts, including maps derived from Strava activity data. These maps may reveal:

Location data from Strava is processed locally on your device to generate maps and overlays and is never transmitted to Kudoro servers or to PostHog. Separately, product analytics may include approximate country and timezone derived from IP address as described in the Product analytics section; IP addresses are not stored. Any decision to share workout maps or location-based overlay content is made by you at your own discretion. Kudoro does not modify, anonymize, or obscure location data retrieved from Strava. You are solely responsible for evaluating the privacy implications of sharing workout maps or location-based content.

Local Storage

Kudoro stores app settings and cached data locally on your device to improve performance. Local settings and cache are stored on your device. Separately, if analytics are enabled, usage analytics may be sent to PostHog as described above.

Do third parties see and/or have access to information obtained by Kudoro?

Kudoro does not share any information with third parties except as described in the Third-Party Services section below.

Third-Party Services

Kudoro interacts with external services for essential features and, unless you opt out, product analytics:

Strava API: Accessed only if you choose to connect your Strava account. Strava activity and profile data used for overlays are processed on-device and are not transmitted to Kudoro servers or to PostHog, except that activity sport type may be included in product analytics if enabled, as described above.

RevenueCat: Used for subscription management. RevenueCat processes subscription status, purchase history, pseudonymous identifiers, country information, transaction dates, and total spend to enable subscription functionality and reporting. Kudoro does not receive payment details, names, email addresses, or other directly identifying information.

PostHog: Used for product usage analytics on PostHog Cloud EU, as described in the Product analytics section. See PostHog's privacy policy.

Kudoro does not use advertising SDKs or session replay. Analytics are limited to the explicit product events described in this policy, unless you opt out.

Giveaways

From time to time, Kudoro may run giveaways or promotions, for example on social media.

If you participate in a giveaway, we may process minimal information:

We use this information only to administer the giveaway, verify entries, select and contact winners, activate prizes, and help prevent abuse or fraudulent entries.

We keep giveaway-related information only for the duration of the giveaway and delete it as soon as all winners are confirmed and prizes are activated (so no redraws are necessary).

Your Rights & Opt-Out

Depending on how you use Kudoro, you may:

We aim to respond to valid privacy requests (including analytics deletion requests) within 30 days.

Legal Basis for Processing

Kudoro primarily processes feature data locally on your device. Subscription-related data is processed externally by Apple App Store, Google Play Store, and RevenueCat for payment handling and subscription management. Product usage analytics are processed by PostHog in the EU as described above. Kudoro does not receive directly identifying personal information such as your name or email from these providers for analytics or subscription status display.

The legal bases for processing are: your consent when granting permissions (such as media library access or connecting your Strava account); performance of a contract for subscription-related processing; and our legitimate interests in operating, improving, and supporting Kudoro for product analytics (which you may opt out of at any time). You may withdraw permission-based consent by revoking permissions or uninstalling the app.

GDPR (European Economic Area and United Kingdom)

If you are located in the EEA or the United Kingdom:

For requests or complaints, contact [email protected]. We aim to respond to valid privacy requests within 30 days. You may also contact your local data protection authority (supervisory authority).

California Privacy Rights

California Residents – Your Rights under CCPA, CPRA, and CalOPPA

If you are a California resident, the following applies to your use of Kudoro:

1. Personal Information We Access

Media and Strava overlay data are processed locally on your device and are not transmitted to Kudoro servers or to PostHog, except that activity sport type may be included in product analytics if enabled. Subscription-related data is processed by Apple App Store, Google Play Store, and RevenueCat to enable purchases and subscription management. Product analytics are processed by PostHog in the EU unless you opt out.

2. Your Rights under CCPA/CPRA

California residents have the right to:

3. How to Exercise Your Rights

Contact [email protected] with your name, email, a clear description of your request, and, for analytics-related requests, your RevenueCat User ID from Settings → Subscription. We aim to respond to valid privacy requests within 30 days (and in any event within applicable California timelines, which may allow up to 45 days).

4. CalOPPA - Do Not Track (DNT)

Kudoro does not track users across third-party apps or websites for advertising. Kudoro may collect in-app product usage analytics unless you opt out in Settings → Analytics. If your device sends a Do Not Track signal, Kudoro does not change its practices based on that signal; use the in-app analytics setting to opt out.

5. Changes to this Policy

We may update this California-specific section from time to time. The latest version is always available at https://kudoro.cc/privacy-policy. Continued use of Kudoro constitutes acceptance of any updates.

Children's Privacy

Kudoro is not intended for users under the minimum age required to hold a Strava account in their jurisdiction. If a child below this minimum age connects a Strava account, access may be revoked or the app uninstalled. Parents or guardians may contact [email protected] to request deletion.

Security

Strava data accessed by Kudoro for overlays is stored locally on your device. Subscription-related data is stored and processed by Apple App Store, Google Play Store, and RevenueCat. Kudoro only retrieves subscription status information as needed. Kudoro does not transmit media or Strava overlay content externally, except that activity sport type may be included in product analytics when enabled. Subscription-related data is transmitted directly to Apple App Store, Google Play Store, and RevenueCat for payment and subscription processing. When analytics are enabled, usage analytics are sent to PostHog over encrypted connections. You are responsible for securing your device using passcodes, biometrics, or encryption.

Changes to This Privacy Policy

This privacy policy may be updated from time to time. The most current version will always be available at https://kudoro.cc/privacy-policy.

Consult this Privacy Policy regularly, as continued use of Kudoro constitutes acceptance of any changes.

Consent

By using Kudoro, you acknowledge and agree to the practices described in this Privacy Policy. By using Kudoro, you also agree to our Terms of Service.

Contact

For privacy questions or concerns, contact [email protected].