Privacy Policy

Your privacy is fundamental to our mission

Effective Date: September 1, 2025

🔒

End-to-End Encrypted

Your data is encrypted at all times

🚫

Never Sold

We never sell your personal data

🗑️

Delete Anytime

Remove all your data instantly

At Kaivo, we understand that quitting vaping is a personal journey, and protecting your privacy is essential to building trust. This Privacy Policy explains how we collect, use, protect, and handle your personal information.

Information We Collect

Information You Provide Directly

  • Account Information: Email address, username, and password for secure access to your account
  • Profile Data: Avatar selection and any optional profile details you choose to share
  • Health & Habit Data: Vaping frequency, nicotine levels, device types, quit goals, and progress tracking information
  • Community Content: Posts, replies, and reactions you share in community features
  • AI Chat Conversations: When you use our AI chat feature, your messages are processed by Google's Gemini API to provide personalized responses and support. Chat conversations are encrypted in transit and at rest. Your conversation data is not used to train AI models and is automatically deleted after 30 days. Google's privacy policy for Gemini is available at https://ai.google.dev/gemini-api/terms.
  • Support Communications: Messages and feedback sent to our support team for assistance

Information Collected Automatically

  • Usage Data: Features used, screens viewed, actions taken, and session duration to improve your experience
  • Device Information: Device model, operating system, app version, and unique device identifiers for technical support
  • Performance Data: Crash reports, error logs, and app performance metrics to maintain service quality
  • Analytics Data: Aggregated usage patterns and feature engagement to enhance our services
  • Push Notification Data: We use OneSignal to deliver push notifications about your progress, reminders, and app updates. This service collects your device's push token, notification preferences, and basic device information (operating system, app version). You can disable push notifications at any time through your device settings or within the app. OneSignal's privacy policy is available at https://onesignal.com/privacy_policy.

Information We Don't Collect

  • Precise location data - We don't track your location
  • Contacts or address book - We don't access your contacts
  • Photos or media - We don't access your photos unless you explicitly share them
  • Biometric data - We don't collect fingerprints, face scans, or other biometric information

How We Use Your Information

To Provide Core Services

  • Create and maintain your account - Secure authentication and profile management
  • Generate personalized quit plans - Based on your habits and goals for maximum effectiveness
  • Provide AI-powered support - Using Google's Gemini API for personalized conversations and guidance
  • Track your progress and health improvements - Monitor your journey and celebrate milestones
  • Enable community features and connections - Connect with others on similar quit journeys

To Improve Kaivo

  • Analyze usage patterns - To enhance features and improve user experience
  • Debug technical issues - To improve app performance and stability
  • Develop new tools and content - To provide more effective quit support
  • Conduct research on quitting patterns - Using anonymized data to help more people succeed

To Communicate With You

  • Send important account and security updates - Keep you informed about your account and security
  • Provide progress milestones and encouragement - Celebrate your achievements (if you've enabled notifications)
  • Respond to support requests - Help you with any questions or issues you encounter
  • Send promotional updates - Share new features and content (only with your explicit consent)

Legal Basis for Processing (GDPR)

We process your data based on

We process your data based on:

  • Consent: For optional features like marketing emails and push notifications that you can disable anytime
  • Contract: To provide the core services you've requested, like account creation, progress tracking, and AI chat support
  • Legitimate Interests: For security, fraud prevention, service improvement, and app functionality that benefits all users
  • Legal Obligation: When required by law, such as responding to valid legal requests or court orders

Data Sharing and Third Parties

We Never Sell Your Data

We will never sell, rent, or trade your personal information to third parties.

Third-Party Service Providers

We integrate with the following trusted third-party services to provide our app functionality:

These services operate under their own privacy policies and security standards. We carefully select partners who meet our high standards for data protection and user privacy.

Legal Disclosure

We may disclose information if required by law, court order, or government request. We'll notify you unless legally prohibited.

Business Transfers

If Kaivo is acquired or merged, your data may be transferred. We'll notify you before any transfer and ensure continued protection.

Data Security

Technical Safeguards

  • Encryption: TLS 1.3 for data in transit, AES-256 for data at rest
  • Access Controls: Role-based access with multi-factor authentication
  • Regular Testing: Security audits and penetration testing
  • Secure Infrastructure: SOC 2 compliant hosting providers

Organizational Measures

  • Limited access on need-to-know basis
  • Employee confidentiality agreements
  • Regular security training
  • Incident response procedures

Your Privacy Rights

Universal Rights

  • Access: Request a copy of your personal data
  • Correction: Update inaccurate information
  • Deletion: Delete your account and associated data
  • Portability: Export your data in machine-readable format
  • Opt-Out: Disable non-essential data collection

California Residents (CCPA)

  • Right to know what personal information we collect
  • Right to delete personal information
  • Right to opt-out of data "sales" (we don't sell data)
  • Right to non-discrimination for exercising rights

EU/UK Residents (GDPR)

  • Right to object to processing
  • Right to restrict processing
  • Right to lodge complaints with supervisory authorities
  • Right to withdraw consent

Exercising Your Rights

  • Through app settings
  • Email: privacy@kaivo.app
  • We'll respond within 30 days

Data Retention

Retention Policy

  • Account and usage data: Retained while your account is active and for up to 12 months after deletion
  • AI chat conversations: Automatically deleted after 30 days
  • Analytics data: Anonymized and retained for up to 24 months for service improvement
  • You can request immediate deletion of all your data by contacting us at privacy@kaivo.app
  • Backups: May persist up to 90 days in secure backups
  • Legal Holds: Extended retention if required by law

Data Safety Summary

Google Play Data Safety Compliance

The following data types are collected and shared:

  • Personal identifiers (email address, username) - shared with Supabase for authentication
  • Health and fitness data (vaping tracking, progress metrics) - stored securely, not shared with third parties
  • App activity (features used, preferences) - used internally for service improvement
  • Device identifiers (for push notifications) - shared with OneSignal
  • Subscription and purchase history - shared with RevenueCat for payment processing

All data is encrypted in transit and at rest. No data is sold to third parties.

Children's Privacy

Age Requirements

Kaivo is intended for users 13 and older. We do not knowingly collect information from children under 13 without parental consent. If we learn we've collected such data, we'll delete it immediately. Parents who believe we've collected their child's information should contact us at privacy@kaivo.app.

International Data Transfers

Cross-Border Data Processing

We're based in the United States. By using Kaivo, you consent to data transfer to the US. We ensure appropriate safeguards for international transfers through: • Standard contractual clauses • Data processing agreements • Privacy Shield principles (where applicable)

Cookies and Tracking

Tracking Technologies

Kaivo's mobile app doesn't use cookies. Our website uses minimal, essential cookies for: • Security and authentication • Basic analytics (if you consent) You can control cookies through your browser settings.

Changes to This Policy

Policy Updates

We may update this policy to reflect changes in our practices or legal requirements. We'll notify you of material changes via: • In-app notifications • Email to your registered address • Prominent notice in the app Continued use after changes constitutes acceptance.

Contact Us

Privacy Questions

Email: privacy@kaivo.app

General Support

Email: support@kaivo.app

Mailing Address

Kaivo Inc.
3040 78th Ave SE
Mercer Island, WA 98040
United States

Data Protection Officer

If you're in the EU, you can contact our DPO at: dpo@kaivo.app

This Privacy Policy is part of our Terms of Service. By using Kaivo, you agree to both documents.

Last Updated: September 1, 2025