Privacy Policy — Luko
This Privacy Policy explains how we collect, use, share, and protect information when you use the Luko iOS app and related services (the “Service”).
Previous version: September 2, 2026
1. Who we are
Luko is a consumer wellness app focused on food logging, personal nutrition targets, optional guided workouts (“Workout with Luko”), and an Adventure destination called the Homestead Planet. You can complete onboarding, set a calorie/macro plan, log meals (photo, text, or voice description), see an AI note after a log, generate recipe ideas, get a Home briefing about today’s food and workout status, train with a daily plan and session, grow a Planet and unlock seasonal residents as you log meals or workouts, send private product feedback from Home, and manage your profile in Settings. Food and workout tools also appear under the More tab.
Luko is not a medical device and does not provide medical advice, diagnosis, or treatment. Planet weather and daylight are decorative scene effects, not health readings or clinical assessments.
This version does not include a free-form daily context/condition journal, open-ended AI chat or voice coaching outside the flows described here, or paid subscriptions. If we add those later, we will update this Policy.
2. Information we collect
A. Account & identity
When you create or sign in (via Clerk and supported sign-in methods), we may collect name, email address, authentication identifiers/tokens, and account settings (e.g., timezone). After onboarding, we ask you to create an account so your plan and logs can be saved.
B. Profile & wellness information you provide
During onboarding and in settings, you may provide age/birthday, sex, height, weight, goals (lose/maintain/gain), activity level, pace, dietary preferences, allergies, and disliked foods. This may be treated as health-related personal data under some laws. We use it to personalize calorie/macro targets and to seed workout preferences where applicable.
C. Food-logging content
Meal photos (camera or photo library), typed or spoken meal descriptions, structured meal logs, estimated calories/macros, meal history, and optional AI follow-up text/audio about a logged meal (“honest summary”).
D. Workout & fitness content
If you use Workout with Luko, we collect and store on our servers:
- Luko’s note — training preferences you set or ask us to update, such as training mix (e.g., strength, mobility, conditioning), workout length, focus areas, equipment, and optional context (e.g., low impact, prioritize recovery), including any short custom text you enter in those fields;
- Daily plans — generated exercise steps (exercise identifiers, sets, reps, load), plan status, coach lines, and related revisions;
- Session logs — when you finish, save and leave, or skip remaining work: timing, duration, completed and skipped exercises, and an estimated calorie burn (an estimate, not a sensor measurement);
- Home briefing — a short AI line (and emotion tag) about today’s food and workout status when that feature runs.
Workout with Luko does not use Apple Health / HealthKit, continuous heart-rate monitoring, or GPS to measure a session. Estimated burn is computed from the session snapshot above. Motion permission (if enabled) is only for the on-device Meal-token tumble animation described below — not for counting steps or measuring workouts.
Separately, if you allow Apple Health access for Adventure, we may read workout samples already stored in HealthKit to update Planet weather on your device (see section G). We do not write Luko workouts into Apple Health, and we do not use HealthKit to calculate the in-app estimated burn.
Exercise demonstration media (images/animations) may be loaded from a content delivery network so the session UI can show form references.
E. Recipe ideas
If you use Plan my meals / recipe ideas, we send your request (and any extra note you type) to our servers so we can return suggested meals.
F. Adventure / Homestead Planet progress
Adventure is Luko’s planet destination (the Homestead Planet first). Logging meals or workouts can advance season progress and unlock seasonal residents and world objects. We store season progress numbers, which seasons are available, and unlock-presentation receipts on your device so the Planet can grow and replay ceremonies.
When account sync is available, we may also save those progress and presentation values to your Luko account so the Planet can follow you across devices. That sync is progress state only — not HealthKit samples, body-weather details, or location.
Planet visuals (scene, weather look, daylight, dialogue presentation) are computed and stored on your device.
G. Apple Health / HealthKit (optional, iOS)
If you allow Apple Health access, Luko may read these HealthKit types so your Planet’s decorative “body weather” can reflect recent patterns:
- sleep;
- steps;
- active energy;
- workouts already stored in Apple Health;
- heart rate;
- heart rate variability (HRV).
We request read access only. Luko does not add, change, or delete data in Apple Health.
HealthKit samples, sync receipts, and the derived weather state are processed and stored on your device. We do not upload HealthKit samples, time series, or inferred weather causes to our servers, to analytics, to advertising measurement, or to other third parties. Android does not use HealthKit in this version.
After you grant access, iOS may wake the app in the background when those Health types update so Planet weather can stay current. We may show an optional local weather notice on your device. Those notices are generated on the device; they are not a remote push of health data.
Allowing HealthKit is optional. Declining it does not block Adventure, meal logging, or workouts. Planet weather then uses a permission-free fallback.
H. Approximate location (optional)
The first time you open Adventure, Luko may ask for approximate (coarse) location while using the app so Planet daylight can follow local sunrise and sunset. We do not request precise GPS, always-on location, or background location.
Location is used only to compute a sunrise/sunset window for that device-local day. It is not stored beyond what that computation needs and is not sent to our servers, analytics, or advertising partners. It is not used for maps, fitness tracking, or ads.
Declining location does not reduce features. Planet uses a fixed daylight window (6:00–20:00) instead.
I. Device & technical data
Device type, OS/app version, diagnostics needed to operate and secure the Service, push notification tokens (if enabled), and local preferences on device.
J. Analytics (PostHog)
We send product-usage events to PostHog (for example: app opens, onboarding steps, meal-log funnel, workout and toolbox funnels, Home briefing readiness, Planet / Adventure presentation events, which settings were changed — not their values). We also store categorical onboarding answers as PostHog person properties: main goal, secondary goals, goal pace, activity level, sex, and self-reported install source. We may use PostHog to run in-app experiments (feature flags) that choose among complete product experiences; flags do not add extra personal data beyond the events and properties described here.
We do not send to analytics: your name, age, height, weight, target weight, message/chat content, meal photos, voice transcripts, Luko’s note free-text, workout prescription details (sets, reps, loads), HealthKit samples, body-weather details, location, or feedback-board post text. Session replay (screen recording) is disabled.
PostHog may receive a technical identifier and, by default, IP address used to infer an approximate region (not precise GPS).
K. Advertising measurement (AppsFlyer)
AppsFlyer measures which ads or campaigns led to your install and a small set of campaign events (registration completed, onboarding completed, and a meal logged). Meal-log events sent to AppsFlyer do not include meal photos, descriptions, or nutrition values. Workout session events, HealthKit data, Planet weather, and location are not sent to AppsFlyer in this version. That measurement is “tracking” under Apple’s rules: it can link data from Luko with data from other companies’ apps or sites for ad measurement.
On iOS we show Apple’s App Tracking Transparency prompt. If you allow it, AppsFlyer may use the advertising identifier (IDFA). If you decline, the app works the same; attribution falls back to Apple’s SKAdNetwork (delayed, aggregate, no user-level IDFA). We may still set an AppsFlyer customer user ID after you sign in (your account ID) for attribution matching. SKAdNetwork postbacks may be received via our measurement partner’s endpoints configured for the app.
We do not show third-party ads in the app in this version.
L. Feedback portal (UserJot)
From Home (top-right chip) you can open an in-app feedback board hosted by UserJot. Submissions may include idea or bug text and, if you type one, an email address. Boards in this version are private: a post is visible only to you (as the author) and the Luko team — not a public feed. Image uploads are off. We do not pass your Luko/Clerk account identity into UserJot. Guest posting does not require a UserJot account. An email you type there is stored by UserJot and is not sent to PostHog or AppsFlyer.
M. Permissions (iOS)
| Permission | Purpose |
|---|---|
| Camera | Scan meals |
| Photo Library | Choose meal photos |
| Microphone | Voice meal descriptions (optional). Speech is on-device when the device supports it; otherwise it may use Apple’s speech service |
| Speech Recognition | Turn speech into a meal description you can edit before sending |
| Notifications | Optional habit reminders, and optional on-device Planet weather notices |
| Motion | Optional: make Meal tokens tumble when you tilt or shake your phone. Motion stays on device and is not used to track workouts or count steps |
| Location (When In Use, Approximate) | Optional: match Planet daylight to local sunrise and sunset. Declining uses a fixed daylight window and does not change how the rest of the app works |
| Apple Health / HealthKit | Optional: read sleep, steps, active energy, workouts, heart rate, and HRV so Planet weather can reflect recent body patterns. Data stays on device. Luko does not write to Apple Health. Declining does not block Adventure |
| Tracking | Optional: measure which ads brought you to Luko (AppsFlyer). Declining does not change how the app works |
You can change permissions in iOS Settings.
N. Children
We do not knowingly collect personal information from children under 13 (or the minimum age required in your country). Contact us to request deletion if needed.
3. How we use information
We use information to:
- provide the Service (account, plan targets, meal logging, recipe ideas, Workout with Luko plans and sessions, Home briefing, Homestead Planet progress, history, settings, optional feedback);
- analyze meals with AI to estimate nutrition and, after a log, generate a short spoken/text note;
- generate and update workout preferences, daily plans, coach lines, estimated burn, and Home briefing copy with AI and/or our servers;
- grow Planet season progress from meal and workout logs, and (if you allow it) derive on-device Planet weather from HealthKit and daylight from approximate location;
- authenticate and secure accounts;
- send optional push reminders or on-device weather notices you opt into;
- understand product usage, run in-app experiments, and improve reliability (PostHog);
- measure advertising campaigns (AppsFlyer);
- host optional private product feedback (UserJot);
- comply with law and enforce our Terms.
We do not sell your personal information. We do not use HealthKit data for advertising, marketing, or data mining. This version does not process payments or subscription data.
4. AI processing
When you log food by photo, text, or voice, relevant content may be sent to our servers and/or subprocessors so we can return nutrition estimates. After you confirm a log, we may generate a short AI note (text and, on iOS, spoken audio). Recipe-idea requests are also processed by AI.
For workouts, Luko’s note, plan generation, coach lines, estimated burn, Ask Luko to update, and Home briefing may be processed on our servers and/or by AI subprocessors using the preferences and session data described above.
Planet weather is computed on your device from HealthKit (if allowed). It is not sent to an AI provider.
Outputs are estimates and may be inaccurate. Do not rely on them for medical decisions or as a substitute for professional training advice.
5. How we share information
We may share information with:
- Service providers under contracts that limit use to serving us: hosting, Clerk (authentication), AI providers (meal analysis, honest summary, recipe ideas, workout planning / briefing), content delivery for exercise media, PostHog (product analytics and experiments), AppsFlyer (install and campaign measurement), UserJot (feedback board hosting), support;
- Apple for Sign in, speech recognition (if used), HealthKit (if you allow it — Apple already holds that health data), App Store operations, and SKAdNetwork attribution;
- legal/safety recipients when required by law or to protect rights, or in a merger/acquisition (with notice where required).
We do not share meal photos, health profile data, HealthKit samples, body-weather details, location, or workout prescription details for third-party advertising. AppsFlyer receives account identifiers and campaign events (including that a meal was logged) for ad measurement, not meal photos, meal descriptions, body metrics, workout logs, or HealthKit data. Feedback text and any email typed in the portal are processed by UserJot as described in section 2.L; we do not send that content to PostHog or AppsFlyer.
6. Retention
We keep information while your account is active and as needed to provide the Service, resolve disputes, and meet legal obligations. Delete your account in-app (Settings → Accounts → Delete My Account) or by emailing us; we will delete or anonymize personal data except where law requires retention. Analytics and attribution vendors retain data under their own retention settings.
On-device HealthKit copies, Planet weather, location-derived daylight, and local Adventure presentation are removed when you delete the app or account data on the device. Account-synced Planet progress, if any, is deleted with your account.
Guest feedback posts are not tied to your Luko account. Deleting your Luko account does not automatically delete UserJot submissions. Email us from the address you used on the board (or describe the post) to request removal. UserJot retains data under its own settings.
7. Security
We use reasonable administrative, technical, and organizational measures (including encrypted transit and access controls). No method of transmission or storage is 100% secure.
8. Your choices & rights
Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing, and to withdraw consent.
- Account deletion: Settings → Accounts → Delete My Account, or email us from your account email.
- Feedback posts: email hu@zentarilabsinc.com to request deletion of UserJot submissions (especially guest posts).
- Apple Health: iOS Settings → Health → Data Access & Devices → Luko, or decline the in-app HealthKit sheet.
- Location: iOS Settings → Privacy & Security → Location Services → Luko.
- Tracking: decline Apple’s tracking prompt, or later iOS Settings → Privacy & Security → Tracking.
- Notifications, camera, photos, microphone, motion: iOS Settings.
- Sign out: Settings → Accounts.
9. International transfers
We may process data in the United States and other countries where we or our providers operate. Where required, we use appropriate transfer safeguards.
10. Changes
We may update this Policy when features or data practices change. We will post a new last-updated date. Continued use after changes means you accept the updated Policy where permitted by law.
11. Contact
hu@zentarilabsinc.com
Zentari Labs Inc.
650 California St, Fl 7
San Francisco, CA 94108