Legal

Privacy policy

This policy covers the Panko: AI Fitness Coach mobile app (com.pankobyte.fitness) and this website. It is written by PankoByte, the studio that makes Panko.

Last updated 11 August 2026

The short version

  • Your training and food logs are stored under your account and are readable only by you.
  • Progress photos never leave your phone. There is no server copy.
  • There are no ads, no advertising identifiers, and nothing is sold or shared with data brokers.
  • You can delete your account, and everything in it, from inside the app.

What the app stores about you

Panko keeps your data in Google Firebase (Firebase Authentication and Cloud Firestore), under your own user ID. The security rules on that database are written so that only the signed-in owner can read or write their own records.

Your account

Your email address and display name, held by Firebase Authentication. If you sign up with email and password, we also keep the first and last name you type so the app can greet you properly. If you sign in with Google, we receive your email address, name and profile picture URL from Google. We never see your Google password.

Your profile

Height, current weight, sex, age, activity level, training goal, unit preference, weekly training target, and your calorie and macro targets. Panko needs these to compute your energy targets and your calorie burn. The onboarding answers you gave (what usually trips you up, how long you pledged to train, how you found the app, and the time of day you train) are stored on the same profile.

What you log

Workouts you build, sessions you complete with their sets, reps and weights, meals with their calories and macros, saved meals, and your weigh-ins. Panko also keeps lifetime counters and personal records so the charts and the "beat last time" prompts work.

AI usage counters

A per-day count of how many AI actions you have used. This is how the fair-use caps on each tier are enforced. It holds numbers and dates, not the content of what you asked.

Cached coach notes

The written weekly review is generated once and cached for that week, so opening it again does not re-run the model. The cached text is stored under your user ID and survives a reinstall.

What stays on your phone

Progress photos are local-only. They are written to the app's private directory on your device and are never uploaded. There is no Firestore collection and no Cloud Storage bucket behind that feature. Body photos are the most sensitive thing the app touches, and uploading them buys you nothing, so we do not. If you switch progress photos to your device gallery, they become ordinary photos on your phone, subject to whatever backup you have configured for your gallery.

Android's app auto-backup is switched off for Panko, so your photos and local settings are not copied to Google Drive behind your back. Workout reminders and home-screen widget snapshots are also local to the device.

The AI coach, and what gets sent

Coach Panko runs on Google's Gemini models, reached through Firebase AI Logic. When you use an AI feature, the relevant content is sent to Google to generate the answer, and comes back into the app:

  • Chat and voice: what you typed or said, plus recent turns of the same conversation.
  • Photo meal scan: the photo of your food.
  • Meal estimates: the description of the meal.
  • Weekly review: a summary of your targets, food log and training from the week, so the note is about your own progress.

Your body photos are never part of any of this. Google processes this content to return a response under the Firebase AI Logic terms and does not use it to train its models.

Crash reports

Release builds send crash reports to Firebase Crashlytics: the stack trace, the device model, the OS version and the app version. This tells us that something broke and where. Debug builds do not report. There is no analytics SDK in the app. Panko does not track what screens you visit or how long you spend on them.

Payments

Panko is sold through Google Play and the App Store. Your payment details go to the store, never to us, and we never see a card number. We use RevenueCat to tell the app whether your subscription is active; it receives an anonymous purchase identifier and the store's receipt data for that purpose.

Permissions the app asks for

  • Camera: to scan a meal or take a progress photo.
  • Microphone: to talk to the coach or log a meal by voice.
  • Photo library: to import a progress photo, or save one to your gallery.
  • Notifications and exact alarms: to fire the workout reminders you asked for, at the time you asked for them.

Every one of these is optional. Decline any of them and the rest of the app still works.

Sharing a workout

If you share a workout link, that workout becomes readable by anyone who holds the link. Nothing else about you travels with it: not your sessions, your food log, your weight or your photos. Workouts you do not share stay private and are not listed or searchable.

Who else touches your data

Only the services the app runs on: Google Firebase (authentication, database, AI, crash reporting and app-integrity checks), Google Play or the App Store for purchases, and RevenueCat for subscription status. Panko contains no advertising SDK, requests no advertising identifier, and your data is never sold, rented or handed to a data broker.

How long it is kept, and deleting it

Your data stays for as long as your account does. You can delete your account from Settings → Delete account inside the app; that wipes your profile, workouts, sessions, meals, weigh-ins, saved meals and cached coach notes, and removes the sign-in itself. Progress photos go with the app when you uninstall it, because they were only ever on your phone. Deletion is not reversible and we do not keep a shadow copy.

If you would rather we did it for you, email support@pankobyte.com from the address on your account.

Step-by-step instructions, and the short list of things that outlive the account, are on the delete your account page.

Your rights

You can see everything Panko holds about you inside the app, correct it there, and delete it there. If you are in a region with data protection law that grants you a formal right of access, portability, correction, erasure or objection, write to support@pankobyte.com and we will handle it within 30 days.

Children

Panko is not intended for children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, email support@pankobyte.com and we will remove it.

Not medical advice

Panko is a training and nutrition tracker with a coaching assistant attached. It is not a doctor, a dietitian or a medical device, and nothing it says is medical advice. Talk to a qualified professional before starting a new training or eating plan, especially if you have a health condition.

This website

fitness.pankobyte.com is a static site on Firebase Hosting. It sets no cookies, runs no analytics and no ad scripts. It loads fonts from Google Fonts, which means your browser makes a request to Google when you open a page. Firebase Hosting keeps ordinary server request logs.

Changes

If this policy changes in a way that matters, the date at the top moves and the app tells you. Small clarifications are made in place.

Contact

PankoByte · support@pankobyte.com
Pune, Maharashtra, India 411045