Política de Privacidad — KIVIFY

Última actualización: 28 de agosto de 2026
Tus datos viven en tu dispositivo · Sin venta de datos · Sin publicidad

KIVIFY es una app de organización personal y bienestar: hábitos, planes diarios, recordatorios, ayuno, recetas, documentos, finanzas, comunidad y un asistente con inteligencia artificial. La gran mayoría de tus datos se guarda solo en tu teléfono. No pedimos tu nombre, correo ni teléfono para usar la app.

Responsable del tratamiento: el desarrollador independiente de KIVIFY. Contacto: Rafullabs@gmail.com.

1. Datos que se guardan en tu dispositivo

Hábitos, tareas, planes, registros de ayuno, comidas, estados de ánimo, diario, finanzas personales, libros de control, mascotas, vehículos, documentos escaneados e historial de actividad se guardan localmente en tu teléfono, en el almacenamiento privado de la app: no tenemos acceso a ese almacenamiento y no podemos consultarlo. Excepción importante: cuando usas una función de IA, el contenido concreto de esa petición —incluido el texto que escribes al coach y fragmentos breves de tus entradas anteriores— sí se envía para poder responderte, como se detalla en el apartado 2.1. Puedes exportarlos y usar "Restablecer todos mis datos" desde la propia app: eso borra todo lo que KIVIFY guarda en este teléfono —el almacenamiento interno de la app, los ficheros que escribe en el disco y los recordatorios ya programados— salvo dos cosas: el identificador anónimo del dispositivo, que se conserva para que no pierdas el Premium que compraste, y, si la habías desactivado, tu preferencia de no compartir la telemetría de uso, porque borrarla la volvería a activar sin que te enteres. En total ese botón se ocupa de cuatro cosas —las mismas cuatro que su confirmación te enumera antes de tocar nada—: además de vaciar este teléfono, borra tu copia cifrada en la nube (apartado 2.10), borra tu fila de miembro de Comunidad —la que lleva tu apodo, tu ciudad y tu zona horaria— y da de baja los recordatorios que te envía el servidor, para que no te sigan llegando avisos de una app que acabas de vaciar. Cómo lo hace: antes de preguntarte nada, la app comprueba qué aplica en ese momento, y la confirmación —un solo «Borrar» y un «Cancelar»— enumera exactamente lo que va a pasar; lo de fuera del teléfono solo se toca si aplica: el borrado de la copia se pide siempre que en este teléfono haya un código de recuperación —la única llave capaz de localizarla; pedirlo cuando no conste copia es inocuo—, y si no encontramos código, no consta ninguna copia asociada a este teléfono —es todo lo que la app puede saber—; sin sesión, no hay fila de Comunidad ni recordatorios del servidor que dar de baja. Cancelar ahí significa que no se ha tocado nada. Si confirmas, el borrado corre de una vez, sin preguntas intermedias —primero lo de fuera del teléfono que aplique, después lo de dentro—, y al final un parte separa lo borrado confirmado de lo que no se pudo confirmar y de lo que no aplicaba, con un botón para reintentar solo lo pendiente: úsalo antes de cerrar la app, porque las llaves para borrar lo pendiente solo siguen a mano hasta que la cierres. Lo que ese botón no hace es barrer por su cuenta el resto de lo que pueda haber en el servidor —reportes de error, tickets de soporte, el registro interno de consumo de las APIs de pago o lo que compartiste dentro de un grupo—: para eso está la solicitud de supresión que describe el apartado 12. Y si desinstalas la app, esas dos claves se van también: en el teléfono no queda nada.

2. Datos que salen del dispositivo y por qué

2.1 Funciones de inteligencia artificial (opcionales, bajo demanda)

Cuando usas una función de IA (coach, planes, escáner de alimentos, resumen de documentos, voz), la app envía solo el contenido necesario para esa petición a nuestro servidor intermedio (proxy), que lo reenvía a proveedores que actúan como encargados del tratamiento. Puede incluir el texto que escribes o dictas, fotos que tú decides analizar y audio que tú decides grabar. Se usa únicamente para generarte la respuesta; no creamos perfiles, no se guarda un historial asociado a tu identidad y los contenidos no se usan para entrenar modelos. Puedes reportar cualquier respuesta de IA desde la propia app.

Documentos e imágenes financieras que tú decides procesar. Algunas funciones te permiten enviar a la IA fotos o archivos con información financiera para que la app los organice por ti: la foto de un ticket o recibo (para registrar el gasto), la captura de un plan de pagos (p. ej. Klarna/Affirm, para crear recordatorios de cuotas) o el PDF/CSV de un estado de cuenta bancario que tú subes manualmente (para clasificar tus movimientos). Este contenido se procesa de forma efímera con el único fin de extraer los datos que verás y confirmarás en la app: no se almacena en nuestros servidores, no se comparte con terceros distintos de los proveedores de IA que actúan como encargados, no se usa para entrenar modelos y el resultado queda guardado solo en tu dispositivo. Nunca te pedimos credenciales bancarias ni nos conectamos a tu banco.

2.2 Comunidad (opcional, anónima)

Si activas la Comunidad (pareja o grupos), lo que compartes (mensajes del tablero, ánimos, retos, planes compartidos, check-ins) se guarda en nuestra base de datos (Supabase) bajo una identidad anónima: un identificador técnico y el apodo que elijas. No se pide correo, teléfono ni nombre real. Solo los miembros de tu grupo ven lo que compartes.

Tu ciudad y tu zona horaria, si usas Comunidad. Para que tu pareja o tu grupo vean tu hora local y de dónde eres, se guarda en esa misma base de datos el nombre de tu ciudad y tu zona horaria, junto a tu identidad anónima. La ciudad puedes escribirla tú a mano; si concedes el permiso de ubicación, la app también puede deducirla de tu posición aproximada (solo el nombre de la ciudad: tus coordenadas no se guardan). A diferencia del resto de usos de la ubicación, este dato sí queda almacenado mientras pertenezcas al grupo, y lo ven sus miembros. Puedes cambiarlo o dejarlo en blanco desde la app, y se borra automáticamente al salir del grupo.

Tu dirección IP, en las llamadas a nuestro servidor. Cuando usas una función de IA, nuestro servidor intermedio apunta la dirección IP de la petición en su propia casilla, junto al identificador anónimo del dispositivo. En las demás llamadas de pago —voz, visión, escáner de alimentos, clima, lugares— esa casilla se queda vacía; pero en dos de ellas —el clima y los lugares— hay un matiz que preferimos contarte: si la petición llega sin el identificador anónimo del dispositivo, la IP ocupa su lugar como identificador de la fila, tanto en el contador de cupos como en el libro de cuentas. Se usa solo para seguridad y para impedir el abuso de las claves de pago (límites por dispositivo y detección de identificadores rotados). Cuánto se conserva: son dos apuntes distintos y con plazos distintos. En el contador antiabuso —el que corta las ráfagas, minuto a minuto—, un máximo de unas dos horas (se borra solo cada 15 minutos). Y en nuestro registro interno de consumo de las APIs de pago —el libro de cuentas, con el contador de cupos al lado, que es el que lleva cuántas veces has usado cada función—, donde cada fila apunta el servicio, la fecha, el coste y la familia de función junto a la IP o al identificador anónimo del dispositivo —nada del contenido de tu petición—, se conserva mientras necesitemos ese libro de cuentas para controlar el gasto, sin borrado automático: ninguna tarea automática lo poda, ni a él ni al contador de cupos, y hoy guarda filas desde junio de 2026. No se usa para publicidad, ni para crear perfiles, ni se vende, ni se cruza con el contenido de tus peticiones.

2.3 Notificaciones push

Para enviarte notificaciones con la app cerrada usamos Firebase Cloud Messaging (FCM) de Google: se guarda un token técnico de dispositivo que no identifica tu persona.

2.4 Suscripciones

Si te suscribes a Premium, la compra la gestiona Google Play Billing y la validación de la suscripción la realiza RevenueCat mediante un identificador anónimo de dispositivo. No vemos ni recibimos los datos de tu tarjeta (los gestiona Google).

2.5 Telemetría de uso (anónima y desactivable) y reportes de error

Reportes de error. Cuando la app falla, enviamos la traza técnica del fallo junto al identificador anónimo de tu dispositivo (sirve para no contar mil veces el mismo fallo y para saber si un arreglo funcionó). Son necesarios para mantener la app en pie y no se pueden desactivar.

Telemetría de uso. Registramos qué funciones se usan —sin ningún contenido tuyo— bajo un identificador aleatorio propio de la telemetría, distinto del anterior y sin relación con él. Esta sí puedes desactivarla desde los ajustes de la app.

2.6 Ubicación (opcional, bajo demanda)

Las funciones "cerca de ti" (clima, veterinarias, servicios) usan tus coordenadas en el momento, solo para esa búsqueda. Se envían a Google Maps Platform a través de nuestro proxy y, en la búsqueda de veterinarias, directamente a servicios de OpenStreetMap (Overpass, Nominatim y su generador de mapas estáticos) sin pasar por el proxy, porque son APIs públicas que se consultan desde la app. No guardamos historial de ubicaciones ni usamos la ubicación en segundo plano.

2.7 Catálogos públicos que consultamos por ti (opcional, bajo demanda)

Algunas búsquedas se resuelven contra catálogos públicos y gratuitos, que reciben únicamente el término que escribes o el código de barras que escaneas, sin ningún identificador tuyo: Open Food Facts y USDA FoodData Central (buscador de alimentos), Open Pet Food Facts (comida de mascotas por código de barras), TheMealDB (recetas), Apple Podcasts y Google Books (sugerencias de pódcast y libros), Openverse, Wikimedia Commons y Wikipedia (fotos de lugares y platos). Estos servicios no actúan como encargados nuestros: son terceros independientes con sus propias políticas. Otros —el BLS de EE. UU. para la inflación y los tipos de cambio de Frankfurter / ExchangeRate-API— reciben solo un identificador de serie o una divisa: ningún dato tuyo.

Bolsa. Si usas el seguimiento de acciones, Yahoo Finance (y, para cotizaciones y noticias, Twelve Data, Marketaux y Financial Modeling Prep) recibe el término que escribes en ese buscador y los símbolos que guardas en tu cartera o en tu lista de seguimiento, sin ningún identificador tuyo y sin importe alguno: nunca les llega cuántas acciones tienes ni a qué precio las compraste. También son terceros independientes con sus propias políticas, no encargados nuestros.

2.8 Contenido que tú decides publicar

Tres funciones crean un enlace público, y solo cuando tú las usas. Al compartir una reflexión en audio, la app sube a un almacenamiento público de Supabase la versión despersonalizada de esa reflexión (sin tu nombre) y guarda a su lado un fragmento de hasta 180 caracteres de su texto: el enlace resultante no caduca y cualquiera que lo tenga puede escucharla. Es una publicación que inicias tú, con el botón de compartir. Queda sin dueño: la fila publicada guarda el audio, el fragmento de texto, el idioma y la duración, y no guarda quién la subió —ni tu identificador ni ningún otro dato tuyo—. Eso significa que solo podemos retirarla si nos mandas el enlace, a Rafullabs@gmail.com: sin él no hay nada que ate esa reflexión a ti y no hay forma de encontrarla, tampoco para nosotros. Si crees que querrás retirarla, guarda el enlace, porque "Restablecer todos mis datos" borra también la lista local de lo que compartiste. Aparte, las ilustraciones de los platos que la app genera se guardan en otro almacenamiento público, identificadas por el nombre del plato y sin ningún dato tuyo, para no tener que volver a generarlas. Y si adjuntas una captura de pantalla a un ticket de soporte (adjuntarla es opcional), esa imagen se sube a un tercer almacenamiento público de Supabase para poder verla al atender tu ticket: su dirección es larga y aleatoria y no aparece en ningún índice ni buscador, pero cualquiera que tenga el enlace puede abrir la imagen. Míralo antes de enviarlo y no incluyas nada que no quieras que salga del teléfono; si quieres que borremos una captura ya enviada, escríbenos a Rafullabs@gmail.com con tu número de ticket.

2.9 Este sitio web (kivifyapp.com)

La portada de kivifyapp.com avisa a nuestro propio servidor de dos cosas: que la página se ha cargado y que alguien ha pulsado el botón de descarga. De cada aviso guardamos la ruta de la página, el sitio desde el que llegaste, la versión del archivo que se descarga, el tipo de dispositivo (móvil, tableta u ordenador, deducido del navegador) y el país, que deducimos de tu dirección IP: de ese aviso guardamos el país, no la IP. Tu dirección IP queda apuntada aparte, en el contador antiabuso de nuestro servidor —el que impide que alguien reviente la página a peticiones—, y solo durante un máximo de unas dos horas: una tarea automática borra cada 15 minutos todo lo que pase de ese plazo. Ese contador guarda tu IP, cuántas peticiones ha hecho en la ventana de un minuto en curso, cuándo fue la última y qué familia de función se está limitando —en la web es siempre la misma, la de las peticiones baratas—; nada del contenido, y no se cruza con el aviso de visita. Sin cookies, sin publicidad y sin identificarte: no hay ningún identificador que te siga entre visitas, y esta medición no se cruza con nada de la app. Sirve para saber qué explica bien la app y qué no. Estas dos páginas legales —esta y la de Términos— no envían ese aviso; lo único que guardan en tu navegador (localStorage) es el idioma que elijas arriba, para mostrártelas en él la próxima vez.

2.10 Respaldo cifrado en la nube (opcional, lo enciendes tú)

KIVIFY puede guardar una copia de seguridad cifrada de tus datos en nuestra base de datos (Supabase) para que no los pierdas si cambias de teléfono o reinstalas. Viene apagado: no se sube nada hasta que tú lo enciendes desde la pantalla de Respaldo y eliges un PIN. Si además activas el respaldo automático, la app vuelve a subir la copia al cerrarse, y como mucho una vez cada ~20 horas.

Qué sube. Lo que la app guarda en el almacenamiento interno de tu teléfono —hábitos, tareas, planes, registros de ayuno y comidas, ánimo, diario, finanzas, mascotas, vehículos, documentos, historial de actividad—, salvo dos exclusiones. La primera, una lista cerrada que se queda fuera a propósito: el PIN y los ajustes del propio respaldo, las cachés que se regeneran solas, los identificadores de las notificaciones ya programadas y el diario de intentos del escáner corporal (es diagnóstico de esa cámara, no un dato tuyo). La segunda, un tope de guardia por tamaño: si un elemento suelto supera los 5 MB, tampoco viaja en la copia —no debería ocurrir, porque las fotos se guardan como archivos y no dentro de ese almacenamiento—. El aviso de ese tope depende de quién suba: cuando subes la copia , desde la pantalla de Respaldo, la app te dice cuántos elementos dejó fuera; el respaldo automático corre en segundo plano, sin avisos, así que si ese tope dejara algo fuera en una subida automática no te lo diría en ese momento —lo verás en el aviso de tu siguiente subida manual, si el elemento sigue superando el tope—. Dentro de la copia viajan también tu identificador de cuenta y tu código de recuperación: son los que permiten que el teléfono nuevo vuelva a ser el mismo. No suben los ficheros que la app escribe en el disco: tus grabaciones de voz, los audios generados y las fotos de viajes se quedan en el teléfono.

Cifrado de extremo a extremo: no podemos leerla. La copia se cifra en tu teléfono con AES de 256 bits, con una llave derivada de tu código de recuperación + tu PIN mediante PBKDF2-SHA256 con 50.000 iteraciones. Ni el código ni el PIN salen nunca del dispositivo. En el servidor quedan cuatro cosas y nada más: el bloque cifrado, su tamaño, la fecha de la última subida y un localizador que es el hash SHA-256 de tu código de recuperación —no reversible y sin ningún dato tuyo dentro—. Sin tu código y tu PIN nadie puede descifrarla: tampoco KIVIFY. La tabla está cerrada con reglas de acceso por fila y solo se consulta pidiendo el localizador exacto, así que nadie puede volcar las copias de todo el mundo. La otra cara de esa promesa: si olvidas el PIN o pierdes el código, la copia es irrecuperable —no hay puerta trasera— y tampoco podríamos ayudarte a abrirla.

Cuánto se conserva y cómo se borra. Hay una sola copia por código de recuperación: cada subida sustituye a la anterior. No caduca ni se borra sola —ninguna tarea automática la poda—: se queda hasta que tú la borras. Para eso hay dos caminos en la app: el botón "Borrar la copia de la nube" de la pantalla de Respaldo y "Restablecer todos mis datos", que la borra antes de vaciar el teléfono. Si en ese momento no hay conexión, ese borrado queda «sin confirmar»: el parte final te lo dice y te deja reintentar solo lo pendiente — hazlo antes de cerrar la app, porque el borrado local ya se llevó del teléfono tu código y tu PIN, y la llave que permite borrar la copia —el código— solo sigue a mano, en memoria, hasta que la cierres. Después queda la vía del correo, pero con un límite que hay que decir entero: esa copia se localiza solo por el hash de tu código de recuperación, así que sin el código ni tú ni nosotros podemos encontrarla. Si conservas el código (apuntado fuera de la app), escríbenos a Rafullabs@gmail.com con él —el identificador del dispositivo no sirve para esto— y la borramos; si el código se perdió, la copia se queda en el servidor como un bloque cifrado que nadie puede abrir ni localizar.

2.11 Lista de aviso del lanzamiento (formulario de kivifyapp.com)

Si en la portada de kivifyapp.com escribes tu correo en «Avísame», guardamos ese correo, el idioma en que lo pediste y la fecha en nuestra base de datos (Supabase, EE. UU.), y nada más. Lo usamos solo para avisarte de la publicación en Google Play y de cambios importantes del servicio; nunca para publicidad, y no lo cedemos a nadie. Base legal: tu consentimiento (art. 6.1.a RGPD), que puedes retirar cuando quieras escribiendo a Rafullabs@gmail.com: borramos el correo en un plazo máximo de 30 días. La lista entera se elimina como máximo 12 meses después de la publicación.

3. Datos de salud (Health Connect) — categoría especial

Si lo autorizas, KIVIFY lee (nunca escribe) datos de salud desde Health Connect de Android, exclusivamente estos once tipos: pasos, calorías activas, calorías totales, distancia, ritmo cardíaco, sueño, ritmo cardíaco en reposo, variabilidad del ritmo cardíaco, saturación de oxígeno, sesiones de ejercicio y peso. Se usan para mostrarte tu actividad y personalizar tu plan, en tu dispositivo. No leemos tu historial anterior a los últimos 30 días ni en segundo plano. Además, la entrevista de "Mi Plan" puede recoger datos de bienestar (peso, dieta, ánimo, ciclo, cribados de seguridad).

Qué datos de salud SALEN del dispositivo. Health Connect se queda en tu teléfono. Lo que sí viaja, y solo cuando pides una función de IA, son los datos de tu perfil que esa función necesita para responderte: sexo, edad, altura, peso, peso objetivo, porcentaje de grasa corporal, estilo de dieta y restricciones alimentarias, más los cálculos derivados (calorías objetivo, macros). Se procesan para generarte la respuesta y no se usan para entrenar modelos.

Los datos de salud son una categoría especial. Su base legal es tu consentimiento explícito (RGPD art. 9.2.a), que otorgas al activar Health Connect y al completar la entrevista; puedes revocarlo en cualquier momento desde Health Connect o borrando tus datos en la app. KIVIFY no es un dispositivo médico y no diagnostica, trata, cura ni previene ninguna enfermedad; consulta siempre a un profesional de la salud.

4. Proveedores que procesan datos (encargados)

ProveedorPara qué
SupabaseBase de datos de Comunidad, telemetría y reportes de error, almacenamiento temporal (PDF/audio para resumir, con enlace firmado que caduca en minutos), el almacenamiento público del apartado 2.8 (reflexiones que tú compartes, ilustraciones de platos y la captura que adjuntes a un ticket de soporte) y el respaldo cifrado del apartado 2.10, que solo custodia: es un bloque ilegible que ni Supabase ni nosotros podemos descifrar.
Google (Gemini)IA de texto y análisis de imágenes/documentos.
Anthropic (Claude)IA del coach y análisis de comida.
ElevenLabsTexto a voz (reflexiones, pódcast).
Google Cloud (Speech/Vision/Maps)Transcripción de voz, OCR y lugares/clima.
Firebase (FCM)Notificaciones push.
RevenueCatGestión de la suscripción.
Health Connect (Google)Lectura de datos de salud del dispositivo (con tu permiso).
VercelAloja el servidor intermedio (proxy) que guarda las claves de las APIs.
ResendNos reenvía por correo los tickets de soporte y las sugerencias que tú envías (solo si tú los envías).

Los catálogos públicos del apartado 2.7 (Open Food Facts, Open Pet Food Facts, USDA, TheMealDB, Apple Podcasts, Google Books, Openverse, Wikimedia, OpenStreetMap, Yahoo Finance, Twelve Data, Marketaux y Financial Modeling Prep) no son encargados nuestros: son terceros independientes a los que solo llega tu término de búsqueda, tu código de barras, los símbolos que sigues en bolsa o —en la búsqueda de veterinarias— tus coordenadas del momento.

La conexión de correo (Gmail) y la conexión bancaria en vivo (Plaid) no están activas en esta versión. Si se habilitan en el futuro, esta política se actualizará para describir su tratamiento antes de su uso.

5. Base legal del tratamiento (RGPD)

6. Lo que NO hacemos

7. Permisos del sistema

Todos son opcionales: la app funciona sin concederlos (sin esas funciones concretas).

8. Conservación y eliminación

9. Transferencias internacionales

Nuestros proveedores pueden procesar datos en servidores fuera de tu país, principalmente en Estados Unidos. Las transferencias se amparan en los mecanismos del RGPD: Cláusulas Contractuales Tipo (SCCs) y/o la adhesión de los proveedores al EU-US Data Privacy Framework.

10. Seguridad

Comunicaciones cifradas (HTTPS/TLS). La base de datos usa reglas de acceso por fila (RLS) para que solo tu grupo lea su contenido; las claves de las APIs viven solo en el servidor, nunca en la app. El panel de administración usa autenticación de dos factores.

11. Menores

KIVIFY está dirigida y disponible solo para mayores de 18 años. No está diseñada para menores y no recopilamos conscientemente sus datos.

12. Tus derechos

Eliminación de datos. Como la app no tiene cuentas, la vía principal es local: desde la propia app puedes exportar tus datos y usar "Restablecer todos mis datos". Ese botón hace cuatro cosas, y solo cuatro: borra lo que KIVIFY guarda en este teléfono (con las dos excepciones del apartado 1), borra tu copia cifrada en la nube, borra tu fila de miembro de Comunidad y da de baja los recordatorios que te envía el servidor. Desinstalar la app elimina además esas dos claves: en el teléfono no queda nada.

Solicitud de supresión (lo que haya en el servidor). Para todo lo demás —reportes de error, tickets de soporte y sus capturas, el registro interno de consumo de las APIs de pago, o lo que compartiste dentro de un grupo— el canal es escribirnos a Rafullabs@gmail.com, y lo eliminamos en un máximo de 30 días. Qué mandarnos cambia según la cosa, porque no hay un identificador único que valga para todo:

Según tu jurisdicción puedes ejercer los derechos de acceso, rectificación, supresión, portabilidad, oposición y limitación. Para los datos locales, los ejerces directamente desde la app (exportar / restablecer; y desinstalar para eliminarlo todo). Para los datos en servidor, escríbenos a Rafullabs@gmail.com.

13. Aviso para residentes de California (CCPA/CPRA)

Si resides en California: tienes derecho a saber qué información personal se recopila, a solicitar su eliminación y a corregirla. Recogemos las categorías descritas arriba (identificadores anónimos, información de salud y de geolocalización entre la "información personal sensible", contenido que tú envías y datos de uso). No vendemos ni "compartimos" tu información personal en el sentido de la CCPA/CPRA, ni la usamos para publicidad de contexto cruzado. Puedes limitar el uso de tu información sensible y ejercer tus derechos escribiendo a Rafullabs@gmail.com; no te discriminaremos por ejercerlos.

14. Cambios

Si cambiamos esta política, actualizaremos la fecha y, si el cambio es relevante, lo avisaremos dentro de la app.

Privacy Policy — English

Last updated: August 28, 2026 — Controller: the independent developer of KIVIFY — Contact: Rafullabs@gmail.com

KIVIFY is a personal organization and wellbeing app (habits, plans, reminders, fasting, recipes, documents, finances, community and an AI assistant). The vast majority of your data is stored only on your phone. No account with your name, email or phone is required. You can export your data and use "Reset all my data" from within the app: that erases everything KIVIFY keeps on this phone —the app's internal storage, the files it writes to disk and the reminders already scheduled— except two things: the anonymous device identifier, kept so you don't lose the Premium you paid for, and, if you had turned it off, your choice not to share usage telemetry, because erasing it would switch it back on without your noticing. In total that button takes care of four things —the same four its confirmation lists for you before touching anything—: besides emptying this phone, it erases your encrypted cloud copy (see "Encrypted cloud backup" in section 2), it erases your Community membership row —the one carrying your nickname, your city and your time zone— and it cancels the reminders the server sends you, so an app you have just emptied stops pinging you. How it does it: before asking you anything, the app checks what applies at that moment, and the confirmation —a single "Erase" and a "Cancel"— lists exactly what is going to happen; what lives off the phone is only touched if it applies: the copy's deletion is requested whenever this phone holds a recovery code —the only key able to locate it; requesting it when no copy is on record is harmless—, and if we find no code, no copy is on record for this phone —that is all the app can know—; without a session, there is no Community row and no server reminders to cancel. Cancelling there means nothing has been touched. If you confirm, the erase runs in one go, with no questions in between —first whatever applies off the phone, then what's inside—, and at the end a report separates what was confirmed erased from what could not be confirmed and what did not apply, with a button to retry only what's pending: use it before closing the app, because the keys needed to erase what's pending only stay at hand until you close it. What that button does not do is sweep, on its own, everything else that may be held on the server —crash reports, support tickets, the internal usage record for the paid APIs, or what you shared inside a group—: for that there is the deletion request described in section 12. And if you uninstall, those two keys go too: nothing is left on the phone.

1. On-device data

Habits, tasks, plans, fasting and meal logs, mood, journal, personal finances, control logs, pets, vehicles, scanned documents and activity history are stored locally and we cannot access that storage. Important exception: when you use an AI feature, the specific content of that request —including the text you write to the coach and short excerpts from your earlier entries— is sent so we can answer you, as described in section 2.

2. Data that leaves the device, and why

AI features (optional, on demand): the text you type/dictate, photos you choose to analyze and audio you record are sent through our proxy to AI processors solely to generate your response; they are not used to train models, and you can report any AI response in-app. Community (optional, anonymous): content you share with your partner/group is stored in Supabase under an anonymous identifier and a nickname — and, so your partner or group can see your local time and where you are, your city name and time zone are stored there too. You can type the city yourself; if you grant location permission the app can also derive it from your approximate position (the city name only — your coordinates are not stored). Unlike every other use of location, this one is kept for as long as you belong to the group, and its members can see it; you can change it, blank it, and it is deleted automatically when you leave the group. Push: an anonymous FCM device token. Subscriptions: purchases are handled by Google Play Billing and validated via RevenueCat with an anonymous device id; we never see your card details. Crash reports: when the app fails we send the technical trace of the failure together with your anonymous device identifier (so the same failure is not counted a thousand times); they are needed to keep the app working and cannot be turned off. Usage telemetry: which features get used, with no content of yours, under a random identifier that belongs to the telemetry alone and is unrelated to the previous one — this one you can turn off in the app's settings. Location: used in the moment for "near me" searches and weather; sent to Google Maps Platform through our proxy and, for the vet search, directly to OpenStreetMap services (Overpass, Nominatim and their static-map renderer) without going through the proxy, because those are public APIs queried from the app; no background use and no server-side history.

Your IP address, on calls to our server. When you use an AI feature, our proxy writes the request's IP address into its own field, next to the anonymous device identifier. On the other paid calls —voice, vision, food scanner, weather, places— that field stays empty; but two of them —weather and places— carry a caveat we would rather tell you about: if the request arrives without the anonymous device identifier, the IP takes its place as the row's identifier, both in the quota counter and in the cost ledger. It is used only for security and to prevent abuse of the paid keys (per-device quotas and detection of rotated identifiers). How long it is kept: these are two separate records with two different lifetimes. In the anti-abuse counter —the one that cuts off bursts, minute by minute—, at most about two hours (it deletes itself every 15 minutes). And in our internal usage record for the paid APIs —the cost ledger, with the quota counter beside it, the one that tracks how many times you have used each feature—, where each row notes the service, the date, the cost and the family of feature next to the IP or the anonymous device identifier —nothing from the content of your request—, it is kept for as long as we need that cost ledger to keep spending under control, with no automatic deletion: no automatic job prunes it, nor the quota counter, and today it holds rows going back to June 2026. It is not used for advertising, not used to build profiles, never sold, and never cross-referenced with the content of your requests.

Financial documents and images you choose to process. Some features let you send the AI a photo or file with financial information so the app can organize it for you: a receipt photo (to log the expense), a screenshot of a payment plan (e.g. Klarna/Affirm, to create instalment reminders) or a bank statement PDF/CSV you upload yourself (to classify your transactions). This content is processed ephemerally, solely to extract the data you will see and confirm in the app: it is not stored on our servers, is not shared with third parties other than the AI providers acting as processors, is not used to train models, and the result is saved only on your device. We never ask for banking credentials and never connect to your bank.

Public catalogs we query for you. Some searches are answered by free public catalogs, which receive only the term you type or the barcode you scan, with no identifier of yours: Open Food Facts and USDA FoodData Central (food search), Open Pet Food Facts (pet food by barcode), TheMealDB (recipes), Apple Podcasts and Google Books (podcast and book suggestions), Openverse, Wikimedia Commons and Wikipedia (place and dish photos). These services are not our processors: they are independent third parties with their own policies. Others — the US BLS for inflation and Frankfurter / ExchangeRate-API for currency — receive only a series id or a currency code: no data of yours.

Stocks. If you use stock tracking, Yahoo Finance (and, for quotes and headlines, Twelve Data, Marketaux and Financial Modeling Prep) receives the term you type in that search box and the ticker symbols you save in your portfolio or watchlist, with no identifier of yours and no amounts: how many shares you hold and what you paid for them are not sent. They are independent third parties with their own policies too, not our processors.

Content you choose to publish. Three features create a public link, and only when you use them. When you share a spoken reflection, the app uploads the depersonalized version of it (without your name) to public Supabase storage and saves next to it an excerpt of up to 180 characters of its text: the resulting link does not expire and anyone holding it can listen. It is a publication you start, with the share button. It ends up ownerless: the published row holds the audio, the text excerpt, the language and the duration, and does not record who uploaded it —not your identifier, not any other data of yours—. That means we can only take it down if you send us the link, at Rafullabs@gmail.com: without it there is nothing tying that reflection to you and no way to find it, for us either. If you think you may want it taken down, keep the link, because "Reset all my data" also erases the local list of what you shared. Separately, the dish illustrations the app generates are kept in another public store, keyed by the dish name and with no data of yours, so they never have to be generated twice. And if you attach a screenshot to a support ticket (attaching one is optional), that image is uploaded to a third public Supabase store so we can look at it while handling your ticket: its address is long and random and appears in no index or search engine, but anyone holding the link can open the image. Check it before you send it and leave out anything you would not want off your phone; to have a screenshot you already sent deleted, email us at Rafullabs@gmail.com with your ticket number.

This website (kivifyapp.com). The home page tells our own server two things: that the page loaded and that someone hit the download button. For each of those we store the page path, the site you came from, the version of the file being downloaded, the device type (phone, tablet or desktop, derived from the browser) and the country, which we derive from your IP address: that ping stores the country, not the IP. Your IP address is written down separately, in our server's anti-abuse counter —the one that stops anyone hammering the page with requests— and only for at most about two hours: an automatic job deletes anything past that window every 15 minutes. That counter holds your IP, how many requests it has made within the current one-minute window, when the last one was, and which family of feature is being limited —on the website it is always the same one, the cheap-request family—; nothing from the content, and it is never combined with the visit ping. No cookies, no advertising and no identification: there is no identifier following you between visits, and this measurement is not combined with anything from the app. It tells us which parts of the page explain the app well and which do not. These two legal pages — this one and the Terms — do not send that ping; the only thing they keep in your browser (localStorage) is the language you pick above, so we can show them in it next time.

Encrypted cloud backup (optional, you turn it on). KIVIFY can keep an encrypted backup of your data in our database (Supabase) so you don't lose it when you change phone or reinstall. It ships switched off: nothing is uploaded until you turn it on from the Backup screen and choose a PIN. If you also enable automatic backup, the app re-uploads the copy when it closes, at most once every ~20 hours.

What it uploads. What the app keeps in your phone's internal storage —habits, tasks, plans, fasting and meal logs, mood, journal, finances, pets, vehicles, documents, activity history—, except two exclusions. The first, a closed list deliberately left out: the PIN and the backup's own settings, the caches that regenerate themselves, the identifiers of reminders already scheduled, and the body scanner's attempt log (that is a diagnostic of that camera, not data of yours). The second, a size guard: if a single item exceeds 5 MB it does not travel in the copy either —it should not happen, because photos are stored as files, not inside that storage—. Whether that guard warns you depends on who uploads: when you upload the copy from the Backup screen, the app tells you how many items were left out; automatic backup runs in the background, with no notices, so if that guard left something out of an automatic upload it would not tell you at that moment —you will see it in the notice of your next manual upload, if the item still exceeds the limit—. Your account identifier and your recovery code travel inside the copy too: they are what lets a new phone become the same one again. The files the app writes to disk are not uploaded: your voice recordings, the generated audio and travel photos stay on the phone.

End-to-end encrypted: we cannot read it. The copy is encrypted on your phone with 256-bit AES, using a key derived from your recovery code + your PIN via PBKDF2-SHA256 with 50,000 iterations. Neither the code nor the PIN ever leaves the device. Four things remain on the server and nothing else: the encrypted block, its size, the date of the last upload, and a locator that is the SHA-256 hash of your recovery code —not reversible and with no data of yours inside—. Without your code and your PIN nobody can decrypt it: not KIVIFY either. The table is closed by row-level security and can only be queried by asking for the exact locator, so nobody can dump everyone's copies. The flip side of that promise: if you forget the PIN or lose the code, the copy is unrecoverable —there is no back door— and we could not help you open it.

How long it is kept and how it is deleted. There is one copy per recovery code: each upload replaces the previous one. It does not expire and is not deleted on its own —no automatic job prunes it—: it stays until you delete it. Two ways to do that in the app: the "Delete cloud backup" button on the Backup screen, and "Reset all my data", which deletes it before emptying the phone. If there is no connection at that moment, that deletion is left "unconfirmed": the final report says so and lets you retry only what's pending — do it before closing the app, because the local wipe already took your code and your PIN off the phone, and the key that allows deleting the copy —the code— only stays at hand, in memory, until you close it. After that there is the email route, but with a limit that must be stated in full: that copy is located only by the hash of your recovery code, so without the code neither you nor we can find it. If you still have the code (written down outside the app), email us at Rafullabs@gmail.com with it —the device identifier is no use for this— and we delete it; if the code is lost, the copy stays on the server as an encrypted block nobody can open or locate.

Launch notification list (kivifyapp.com form). If you type your email into "Notify me" on the kivifyapp.com home page, we store that email, the language you asked in and the date in our database (Supabase, United States), and nothing else. We use it only to tell you when the app is on Google Play and about important service changes; never for advertising, and we never share it. Legal basis: your consent (GDPR art. 6(1)(a)), which you can withdraw at any time by writing to Rafullabs@gmail.com: we delete the email within 30 days. The whole list is deleted at most 12 months after publication.

3. Health data (Health Connect) — special category

With your permission, KIVIFY reads (never writes) these eleven types from Android Health Connect: steps, active calories, total calories, distance, heart rate, sleep, resting heart rate, heart rate variability, oxygen saturation, exercise sessions and weight, used to show your activity and personalize your plan on your device. That reading is capped at the last 30 days and does not run in the background. The "My Plan" interview may collect wellbeing data (weight, diet, mood, cycle, safety screenings). Health data is a special category; the legal basis is your explicit consent (GDPR art. 9.2.a), which you may revoke anytime via Health Connect or by deleting your data. KIVIFY is not a medical device and does not diagnose, treat, cure or prevent any condition; always consult a healthcare professional.

Which health data leaves the device. Health Connect data stays on your phone. What does travel, and only when you request an AI feature, are the profile fields that feature needs in order to answer you: sex, age, height, weight, goal weight, body fat percentage, diet style and food restrictions, plus the derived figures (calorie target, macros). They are processed to generate your answer and are not used to train models.

4. Processors

Supabase (community DB, telemetry and crash reports, temporary storage with short-lived signed links, the public storage described in section 2 for reflections you share, dish illustrations and any screenshot you attach to a support ticket, and the encrypted backup described in section 2, which it only holds: an unreadable block that neither Supabase nor we can decrypt), Google Gemini & Google Cloud Speech/Vision/Maps, Anthropic Claude, ElevenLabs, Firebase (FCM), RevenueCat (subscriptions), Health Connect (Google), Vercel (proxy host), Resend (forwards the support tickets and suggestions you send us). The public catalogs listed in section 2 (Open Food Facts, Open Pet Food Facts, USDA, TheMealDB, Apple Podcasts, Google Books, Openverse, Wikimedia, OpenStreetMap, Yahoo Finance, Twelve Data, Marketaux and Financial Modeling Prep) are not our processors: they are independent third parties that only receive your search term, your barcode, the ticker symbols you follow or —for the vet search— your coordinates at that moment. Email (Gmail) and live bank connection (Plaid) are not active in this version; if enabled later, this policy will be updated beforehand.

5. Legal bases (GDPR)

Service provision: art. 6.1.b · Health data: explicit consent, art. 9.2.a · Anonymous usage telemetry (aggregated) and crash reports (technical trace plus the anonymous device identifier): legitimate interest, art. 6.1.f · Website measurement (no cookies, no identification): legitimate interest, art. 6.1.f · Optional features/community: consent, art. 6.1.a.

6. What we do NOT do

We do not sell or share your data for advertising, show ads, train AI on your content, or access your contacts/SMS/calls. We never require your real name, email or phone: there are no accounts. The profile name and the Community nickname are optional and chosen by you; if you set one, the AI coach uses it to address you.

7. System permissions

Notifications and exact alarms — appointment, payment and habit reminders at the exact time. Camera / Photos — scanning codes and the photos you choose to analyze. Microphone — voice notes, only while you record them. Location — "near me" searches and weather, only while you use those features (no background use). Health (Health Connect) — reading activity/sleep, with your permission. All of them are optional: the app works without granting them (minus those particular features).

8. Retention & deletion

Local data: under your control — you can export it and use "Reset all my data", which erases everything stored on the phone except the anonymous device identifier and your choice not to share usage telemetry, if you had turned it off; uninstalling removes those two too, without exception. Off the phone, that same button erases your encrypted cloud copy and your Community membership row, and cancels the reminders the server sends you; for anything else that may be held on the server, the route is the deletion request in section 12. Encrypted cloud backup (section 2): one copy per recovery code —each upload replaces the previous one—; it does not expire and is not deleted on its own, no automatic job prunes it. It goes when you delete it, from the Backup screen or with "Reset all my data". Community: when you leave a group —including when "Reset all my data" does it for you— your membership row is deleted, the one carrying your nickname, your city and your time zone. The aggregates you shared and what you wrote on the board stay with the group: they are part of its history and its members see them. They go when the group is deleted. If you want them removed sooner, ask us while you are still a member (your nickname + the group code) and we do it within 30 days: once you have left, your membership row is gone, and without it nothing ties that data to you —we cannot find it either—. FCM tokens: until uninstall or ~12 months of inactivity. Crash reports: 60 days (pruned automatically every night). Usage telemetry and website measurement: 90 days; anonymous and aggregated. Your IP address: in the anti-abuse counter, at most about two hours (it deletes itself every 15 minutes); in the internal usage record for the paid APIs —in its own field only on AI calls, and as the row's identifier on the weather and places calls that arrive without the device identifier—, for as long as we keep that cost ledger, with no automatic deletion: no automatic job prunes it, nor the quota counter, so today it holds rows going back to June 2026 and they are only deleted by hand. Reflections you choose to share (section 2): the public link does not expire and the published row does not record who uploaded it; we can only take one down if you send us the link, because without it there is no way to find it. Support tickets and any screenshot you attach (section 2): they are not deleted automatically; email us with your ticket number to take one down. Deletion requests: email Rafullabs@gmail.com and we delete server data within 30 days — what to send us depends on the item, as there is no single identifier that covers everything: see the list in section 12.

9. International transfers

Providers may process data outside your country, mainly in the United States, under Standard Contractual Clauses (SCCs) and/or the EU-US Data Privacy Framework.

10. Security

Encrypted communications (HTTPS/TLS), row-level security on the database, API keys kept server-side only, two-factor authentication on the admin panel.

11. Minors

KIVIFY is intended and available for users 18 and older only; we do not knowingly collect data from minors.

12. Your rights

Access, rectification, erasure, portability, objection and restriction.

Deleting your data. Since the app has no accounts, the main route is local: in the app you can export your data and use "Reset all my data". That button does four things, and only four: it erases what KIVIFY keeps on this phone (with the two exceptions in section 1), it erases your encrypted cloud copy, it erases your Community membership row, and it cancels the reminders the server sends you. Uninstalling removes those two keys as well: nothing is left on the phone.

Deletion request (anything held on the server). For everything else —crash reports, support tickets and their screenshots, the internal usage record for the paid APIs, or what you shared inside a group— the channel is to email us at Rafullabs@gmail.com, and we delete it within 30 days. What to send us changes with the item, because there is no single identifier that covers everything:

  • Crash reports, support tickets, suggestions and the usage record: your anonymous device identifier (visible in Settings). It is the one that survives "Reset all my data", so it still works after erasing everything.
  • Community: your nickname and the group code, and while you are still a member. Your Community identity is an anonymous identifier different from the device one, it lives in the session the local wipe deletes, and leaving the group removes the row that tied it to your nickname.
  • Encrypted cloud copy: your recovery code. The device identifier is no use here: that copy is located by the hash of your code and by nothing else; without the code there is no way to find it, for us either.
  • A reflection you shared: the link, because the published row does not record who uploaded it (section 2).

13. California (CCPA/CPRA)

California residents have the right to know, delete and correct their personal information. We collect the categories described above (including health and precise geolocation as "sensitive personal information"). We do not sell or "share" your personal information as defined by the CCPA/CPRA, nor use it for cross-context behavioral advertising. To limit use of sensitive information or exercise your rights, email Rafullabs@gmail.com; we will not discriminate against you for exercising them.

14. Changes

If we change this policy we will update the date and, when the change is material, we will also tell you inside the app.