Privacy Policy
Kairoscope is designed with privacy-first principles. Your journal entries — the moments you capture and the words you write about them — are for your eyes only, unless you explicitly choose to share anonymized summaries.
This Privacy Policy explains what data stays on your device, what data we hold on your behalf if you sign in, what we send to third parties to make the app work, and the controls you have over all of it.
1. Privacy-First Promise
Kairoscope does not sell data, does not show ads, and does not read or share your journal text. We do not run third-party advertising or marketing SDKs. The only data that ever leaves your device is what you sign in with, what we need to sync your private journal to your account, (only if you opt in) anonymized aggregate numbers used for global comparisons, and (only if you choose) an optional tip processed by Apple or Google.
Kairoscope is free to download and use. Optional consumable tips — Buy me a coffee ($0.99), Support the mission ($4.99), and Champion ($9.99) — do not unlock features or entitlements. Purchases are processed by Apple In-App Purchase or Google Play Billing; we do not receive your payment card details.
2. What Stays On Your Device
By default, the following are stored only on your device, in app-private local storage (an embedded Isar database) and are never uploaded:
- Raw journal text (the
rawTextfield of each moment) - Any media you attach (the
mediaPathsfield of each moment) - Any other free-form notes you write
If you never sign in, your journal stays on your device. An optional tip you choose to purchase is processed by Apple or Google and does not require an account.
3. What We Hold If You Sign In (Private Cloud Sync)
If you choose to create an account and enable cloud sync, the following is stored in Firebase under your user account so you can access your journal across devices and recover it if you reinstall the app:
- Your authentication identifier (email address, or the opaque user identifier returned by Google Sign-In or Apple Sign-In)
- For each moment: tags, classification (phenomenon, impact, elements), numeric scores (significance, coincidence, intuition), and timestamps
- Reports and Kairoscope readings you generate
We do not sync your raw journal text or attached media. These remain on the originating device only. Synced data is stored in your private user document and is not accessible to other users; access is enforced by Firebase Security Rules.
4. Opt-In Anonymized Insights (Global Comparison)
If — and only if — you explicitly tap "Share insights" in the Reports screen, Kairoscope uploads numerical aggregate summaries (for example: "5 moments logged this week, average significance 80") to a public research_data collection. This powers the Global Comparison feature, which shows you how your activity compares to the community.
- These uploads contain no raw text, no media, no email address, no user identifier, and no other personally identifying information.
- You can stop sharing at any time. New uploads will stop immediately. Aggregated counts that have already contributed to community averages are by design not linked to your identity and cannot be individually removed.
5. AI-Generated Kairoscope Readings
When you tap "Generate Kairoscope" in the Reports screen, Kairoscope sends an anonymized aggregate summary of your recent activity (counts and scores grouped by category — never your raw text) to our AI provider so it can return a short narrative reflection.
- Provider: OpenAI, L.L.C. (or, depending on our deployment, Microsoft Azure OpenAI Service). The request is initiated from our Cloud Function on your behalf; your device does not contact the provider directly.
- Data sent: the validated aggregate summary only. Tags and numeric scores. No raw journal text. No email or user identifier.
- Retention by the provider: subject to OpenAI's (or Azure's) API data-handling policy. As of this writing, OpenAI does not use API inputs to train its models and retains API requests for abuse-monitoring for a limited period. See openai.com/policies or Azure OpenAI data privacy.
- This step happens only when you request a Kairoscope reading. It does not run in the background.
6. Third-Party Services We Use
| Service | Purpose | Data sent |
|---|---|---|
| Firebase Authentication (Google LLC) | Sign-in and account management | Email and/or social-provider identifier |
| Cloud Firestore (Google LLC) | Private sync and opt-in shared insights | See sections 3 and 4 |
| Cloud Functions for Firebase (Google LLC) | Server-side Kairoscope generation, rate limiting | See section 5 |
| Firebase App Check (Google LLC) | Abuse prevention (verifies requests come from a genuine app install) | A device-attestation token (App Attest on iOS, Play Integrity on Android) |
| Firebase Hosting (Google LLC) | Hosts this policy and the Terms of Service | Standard web server logs (IP address, user agent) when you visit those pages |
| Sign in with Google (Google LLC) | Optional sign-in method | Per Google's privacy policy: policies.google.com/privacy |
| Sign in with Apple (Apple Inc.) | Optional sign-in method | Per Apple's privacy policy: apple.com/legal/privacy |
| OpenAI API (OpenAI, L.L.C.) or Azure OpenAI Service (Microsoft Corporation) | AI Kairoscope readings | Anonymized aggregate summary only — see section 5 |
| Apple In-App Purchase (Apple Inc.) | Optional tip-jar purchases on iOS | Purchase transaction processed by Apple; we do not receive payment card details |
| Google Play Billing (Google LLC) | Optional tip-jar purchases on Android | Purchase transaction processed by Google; we do not receive payment card details |
We do not currently use third-party analytics, crash reporting, advertising, or marketing SDKs. If we add any in the future, this policy will be updated and (where required) we will request your consent.
7. Your Rights and Controls
- Keep everything local. Don't sign in. Your journal stays on your device. Optional tips, if you choose them, are processed by Apple or Google and do not require an account.
- Export. You can read all of your locally-stored moments at any time within the app.
- Delete an individual moment. Deleting locally also removes the synced metadata if you were signed in.
- Delete your account. Use Settings → About → Delete account in the app. This deletes your Firebase Auth account and the private synced data we hold on your behalf (moments, reports, Kairoscope requests, and Kairoscope readings). Request account deletion on the web (no app required).
- Anonymized aggregates that you previously opted to share cannot be linked back to your identity and remain part of the global averages after deletion, by design.
If you cannot reach the delete option for any reason (for example, you no longer have access to the device), email privacy@kairoscope.app from the address associated with your account and we will process the deletion manually.
8. Children's Privacy
Kairoscope is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact privacy@kairoscope.app and we will delete it.
9. International Users and Data Transfers
Firebase services and our AI provider operate from data centers in the United States and other regions. By using Kairoscope, you understand that your synced data and the anonymized summaries you choose to share may be processed in countries other than your own, including the United States, under the data-protection laws of those jurisdictions.
10. Security
Data in transit between your device, Firebase, and our AI provider is encrypted with HTTPS/TLS. Data at rest in Firebase and at our AI provider is encrypted by those providers per their published practices. The on-device Isar database is stored in app-private storage — other apps on your device cannot read it. You are responsible for the security of the device itself (passcode, biometric lock, OS updates).
11. Changes to This Policy
If we make material changes to this policy, we will update the Effective date above and (for material changes affecting data already collected) make a reasonable effort to notify you in the app before the change takes effect.
12. Contact
Questions, deletion requests, or concerns: privacy@kairoscope.app.
By using Kairoscope, you agree to this Privacy Policy.