Privacy Policy — Luko
This Privacy Policy explains how we collect, use, share, and protect information when you use the Luko iOS app and related services (the “Service”).
Previous version: August 31, 2026
1. Who we are
Luko is a consumer wellness app focused on food logging, personal nutrition targets, and optional guided workouts (“Workout with Luko”). You can complete onboarding, set a calorie/macro plan, log meals (photo, text, or voice description), see an AI note after a log, generate recipe ideas, get a Home briefing about today’s food and workout status, train with a daily plan and session, unlock Adventure companions as you log meals or workouts, send private product feedback from Home, and manage your profile in Settings. Food and workout tools also appear under the More tab.
Luko is not a medical device and does not provide medical advice, diagnosis, or treatment.
This version does not include a free-form daily context/condition journal, open-ended AI chat or voice coaching outside the flows described here, or paid subscriptions. If we add those later, we will update this Policy.
2. Information we collect
A. Account & identity
When you create or sign in (via Clerk and supported sign-in methods), we may collect name, email address, authentication identifiers/tokens, and account settings (e.g., timezone). After onboarding, we ask you to create an account so your plan and logs can be saved.
B. Profile & wellness information you provide
During onboarding and in settings, you may provide age/birthday, sex, height, weight, goals (lose/maintain/gain), activity level, pace, dietary preferences, allergies, and disliked foods. This may be treated as health-related personal data under some laws. We use it to personalize calorie/macro targets and to seed workout preferences where applicable.
C. Food-logging content
Meal photos (camera or photo library), typed or spoken meal descriptions, structured meal logs, estimated calories/macros, meal history, and optional AI follow-up text/audio about a logged meal (“honest summary”).
D. Workout & fitness content
If you use Workout with Luko, we collect and store on our servers:
- Luko’s note — training preferences you set or ask us to update, such as training mix (e.g., strength, mobility, conditioning), workout length, focus areas, equipment, and optional context (e.g., low impact, prioritize recovery), including any short custom text you enter in those fields;
- Daily plans — generated exercise steps (exercise identifiers, sets, reps, load), plan status, coach lines, and related revisions;
- Session logs — when you finish, save and leave, or skip remaining work: timing, duration, completed and skipped exercises, and an estimated calorie burn (an estimate, not a sensor measurement);
- Home briefing — a short AI line (and emotion tag) about today’s food and workout status when that feature runs.
We do not use Apple Health / HealthKit, continuous heart-rate monitoring, or GPS fitness tracking for workouts. Motion permission (if enabled) is only for the on-device Meal-token tumble animation described below — not for counting steps or measuring workouts.
Exercise demonstration media (images/animations) may be loaded from a content delivery network so the session UI can show form references.
E. Recipe ideas
If you use Plan my meals / recipe ideas, we send your request (and any extra note you type) to our servers so we can return suggested meals.
F. Adventure progress
Companion unlock progress, map progress, and related Adventure state are stored on your device in this version so you can keep Stars / Companions as you log meals or workouts. If we sync Adventure later, we will update this Policy.
G. Feedback portal (UserJot)
From Home (top-right chip) you can open an in-app feedback board hosted by UserJot. Submissions may include idea or bug text and, if you type one, an email address. Boards in this version are private: a post is visible only to you (as the author) and the Luko team — not a public feed. Image uploads are off. We do not pass your Luko/Clerk account identity into UserJot. Guest posting does not require a UserJot account. An email you type there is stored by UserJot and is not sent to PostHog or AppsFlyer.
H. Device & technical data
Device type, OS/app version, diagnostics needed to operate and secure the Service, push notification tokens (if enabled), and local preferences on device.
I. Analytics (PostHog)
We send product-usage events to PostHog (for example: app opens, onboarding steps, meal-log funnel, workout and toolbox funnels, Home briefing readiness, which settings were changed — not their values). We also store categorical onboarding answers as PostHog person properties: main goal, secondary goals, goal pace, activity level, sex, and self-reported install source. We may use PostHog to run in-app experiments (feature flags) that choose among complete product experiences; flags do not add extra personal data beyond the events and properties described here.
We do not send to analytics: your name, age, height, weight, target weight, message/chat content, meal photos, voice transcripts, Luko’s note free-text, or workout prescription details (sets, reps, loads). Session replay (screen recording) is disabled.
PostHog may receive a technical identifier and, by default, IP address used to infer an approximate region (not precise GPS).
J. Advertising measurement (AppsFlyer)
AppsFlyer measures which ads or campaigns led to your install and a small set of campaign events (registration completed, onboarding completed, and a meal logged). Meal-log events sent to AppsFlyer do not include meal photos, descriptions, or nutrition values. Workout session events are not sent to AppsFlyer in this version. That measurement is “tracking” under Apple’s rules: it can link data from Luko with data from other companies’ apps or sites for ad measurement.
On iOS we show Apple’s App Tracking Transparency prompt. If you allow it, AppsFlyer may use the advertising identifier (IDFA). If you decline, the app works the same; attribution falls back to Apple’s SKAdNetwork (delayed, aggregate, no user-level IDFA). We may still set an AppsFlyer customer user ID after you sign in (your account ID) for attribution matching. SKAdNetwork postbacks may be received via our measurement partner’s endpoints configured for the app.
We do not show third-party ads in the app in this version.
K. Permissions (iOS)
| Permission | Purpose |
|---|---|
| Camera | Scan meals |
| Photo Library | Choose meal photos |
| Microphone | Voice meal descriptions (optional). Speech is on-device when the device supports it; otherwise it may use Apple’s speech service |
| Speech Recognition | Turn speech into a meal description you can edit before sending |
| Notifications | Optional habit reminders |
| Motion | Optional: make Meal tokens tumble when you tilt or shake your phone. Motion stays on device and is not used to track workouts |
| Tracking | Optional: measure which ads brought you to Luko (AppsFlyer). Declining does not change how the app works |
You can change permissions in iOS Settings.
L. Children
We do not knowingly collect personal information from children under 13 (or the minimum age required in your country). Contact us to request deletion if needed.
3. How we use information
We use information to:
- provide the Service (account, plan targets, meal logging, recipe ideas, Workout with Luko plans and sessions, Home briefing, Adventure progress, the feedback portal, history, settings);
- analyze meals with AI to estimate nutrition and, after a log, generate a short spoken/text note;
- generate and update workout preferences, daily plans, coach lines, estimated burn, and Home briefing copy with AI and/or our servers;
- authenticate and secure accounts;
- send optional push reminders you opt into;
- understand product usage, run in-app experiments, and improve reliability (PostHog);
- measure advertising campaigns (AppsFlyer);
- comply with law and enforce our Terms.
We do not sell your personal information. This version does not process payments or subscription data.
4. AI processing
When you log food by photo, text, or voice, relevant content may be sent to our servers and/or subprocessors so we can return nutrition estimates. After you confirm a log, we may generate a short AI note (text and, on iOS, spoken audio). Recipe-idea requests are also processed by AI.
For workouts, Luko’s note, plan generation, coach lines, estimated burn, Ask Luko to update, and Home briefing may be processed on our servers and/or by AI subprocessors using the preferences and session data described above.
Outputs are estimates and may be inaccurate. Do not rely on them for medical decisions or as a substitute for professional training advice.
5. How we share information
We may share information with:
- Service providers under contracts that limit use to serving us: hosting, Clerk (authentication), AI providers (meal analysis, honest summary, recipe ideas, workout planning / briefing), content delivery for exercise media, PostHog (product analytics and experiments), AppsFlyer (install and campaign measurement), UserJot (feedback board hosting), support;
- Apple for Sign in, speech recognition (if used), App Store operations, and SKAdNetwork attribution;
- legal/safety recipients when required by law or to protect rights, or in a merger/acquisition (with notice where required).
We do not share meal photos, health profile data, or workout prescription details for third-party advertising. AppsFlyer receives account identifiers and campaign events (including that a meal was logged) for ad measurement, not meal photos, meal descriptions, body metrics, or workout logs. Feedback text and any email typed in the portal are processed by UserJot as described in section 2.G; we do not send that content to PostHog or AppsFlyer.
6. Retention
We keep information while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. Delete your account in-app (Settings → Accounts → Delete My Account) or by emailing us; we will delete or anonymize personal data except where law requires retention. Analytics and attribution vendors retain data under their own retention settings.
On-device Adventure progress is removed when you delete the app or account data on the device.
Guest feedback posts are not tied to your Luko account. Deleting your Luko account does not automatically delete UserJot submissions. Email us from the address you used on the board (or describe the post) to request removal. UserJot retains data under its own settings.
7. Security
We use reasonable administrative, technical, and organizational measures (including encrypted transit and access controls). No method of transmission or storage is 100% secure.
8. Your choices & rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent.
- Account deletion: Settings → Accounts → Delete My Account, or email us from your account email.
- Feedback posts: email hu@zentarilabsinc.com to request deletion of UserJot submissions (especially guest posts).
- Tracking: decline Apple’s tracking prompt, or later iOS Settings → Privacy & Security → Tracking.
- Notifications, camera, photos, microphone, motion: iOS Settings.
- Sign out: Settings → Accounts.
9. International transfers
We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards.
10. Changes
We may update this Policy when features or data practices change. We will post a new last-updated date. Continued use after changes means you accept the updated Policy where permitted by law.
11. Contact
hu@zentarilabsinc.com
Zentari Labs Inc.
650 California St, Fl 7
San Francisco, CA 94108