Last Updated: April 26, 2026
Welcome to KIPFIRE. We respect your privacy and are committed to protecting your personal data. This Privacy Policy explains how KIPFIRE (“we,” “us,” or “our”) collects, uses, stores, and shares information when you use our mobile application and related services.
1. Information We Collect
1.1 Account and authentication
When you sign in or create an account, we process data through our authentication provider and our backend:
- Email address (when you use an email-based sign-in method).
- Display name (when your sign-in provider, such as Apple or Google, shares a name with the app).
- Firebase user identifier (UID) and an internal application user ID used to tie your profile, tasks, and subscription state together on our servers.
1.2 How you use the app (service data)
To run the product, our servers may store and process:
- Language and region-related preferences used to generate tasks in the right language.
- Task-related data, including selected categories, AI-generated task text, metadata about prompts (for example model or style fields where applicable), and records needed for daily limits and premium access.
- Subscription and purchase status synchronized between the app, Apple or Google billing, our subscription partner, and our backend so we can unlock premium features.
- Push notification token if you opt in, so we can deliver notifications through the platform push service.
1.3 Optional context for premium tasks
If you use features that generate tasks from your situation, you may provide optional labels or free text (for example mood, a place type you pick, or a short description). That content is sent to our API and may be included in prompts sent to our AI provider to generate a task. It may be stored on our servers as needed to provide the feature (for example to avoid repeats or to improve reliability).
1.4 Technical and security data
- IP address, timestamps, and diagnostic information in server logs for security, abuse prevention, and operations.
- Basic device or client information your HTTP client sends with API requests (for example user-agent strings), where applicable.
1.5 Information we do not collect in normal operation of the shipping app
The following describes the current KIPFIRE client behavior and our practices for the data types below:
- We do not collect or store your payment card numbers; in-app purchases are processed by Apple or Google.
- We do not use Apple’s App Tracking Transparency (IDFA-based cross-app advertising tracking) in KIPFIRE.
- We do not collect your phone number as part of the core app flows described here.
- We do not collect precise GPS coordinates from your device sensors for the features described in this policy. Optional context you type or select is not the same as continuous location tracking.
- Video and photo files you record or export are processed on your device and saved to your photo library when you choose to save them. The shipping app does not upload those media files to our servers for storage. (Separate backend capabilities may exist for other builds or future features; they are not used by the standard app flow described here.)
- We do not sell your personal information.
2. How We Use Your Information
We use the information above to:
- Provide the service: authenticate you, generate and deliver tasks, enforce free-tier limits, and enable premium features.
- Operate subscriptions: verify purchases, restore access, and prevent abuse.
- Communicate: send push notifications when you allow them; send transactional messages where we offer them (for example related to account or subscription).
- Secure and maintain: monitor for fraud, protect accounts, debug outages, and improve reliability and performance of our infrastructure.
We do not use your data for third-party advertising in KIPFIRE, and we do not use it for Apple’s “tracking” definition (cross-app advertising measurement) as described in Apple’s App Privacy documentation.
3. Video and Media
- Media you save is stored in your device’s gallery under your control.
- Microphone audio is captured as part of video recording on your device; we do not receive a separate audio file from that recording in the standard flow described above.
4. Third-Party Services
We rely on service providers to operate KIPFIRE. They process data on our behalf according to their own policies. You should read their privacy notices for details.
4.1 Google Firebase
- Purpose: Authentication; optional reads from Cloud Firestore for in-app configuration (for example categories, prompts, or related content).
- Typical data: authentication identifiers, email when applicable, and client requests to Firestore.
- Privacy: Firebase Privacy and Google Privacy Policy
4.2 RevenueCat
- Purpose: In-app subscription management, entitlements, and purchase restoration across platforms.
- Typical data: app user identifiers you configure (for example your Firebase UID), purchase history metadata from Apple or Google, and device or app-instance identifiers as described in RevenueCat’s documentation.
- Privacy: RevenueCat Privacy Policy
4.3 Apple and Google
- Purpose: App distribution, Apple In-App Purchase and Google Play Billing, Sign in with Apple / Google sign-in where enabled, and platform push notification delivery.
- Typical data: purchase receipts, subscription status, and account identifiers held by the platform.
- Privacy: Apple Privacy Policy; Google Privacy Policy
4.4 OpenAI
- Purpose: AI-powered generation of task text and related content.
- Typical data: category, language, and prompt fields needed to generate a task; for context-based generation, optional user-provided text or labels you submit may be included in the prompt sent to OpenAI.
- Privacy: OpenAI Privacy Policy
4.5 Our application database (MongoDB)
- Purpose: Primary storage for application data such as user records, tasks, quotas, subscription sync fields, and related operational data.
- Typical data: the categories described in Section 1, stored on servers we control or host (for example MongoDB Atlas or equivalent).
- Note: MongoDB Inc. supplies database software and cloud infrastructure; data processing is governed by MongoDB’s terms and privacy notice for the product you use.
- Privacy: MongoDB Privacy Policy
4.6 Email delivery (if used)
- Purpose: Transactional email (for example welcome or subscription-related messages) when we enable that feature.
- Typical data: email address.
- Privacy: Depends on the provider (for example Google when using Gmail SMTP).
4.7 Expo and push infrastructure
- Purpose: Development and delivery of push notifications through Expo’s tooling where configured.
- Typical data: push tokens and related metadata needed to deliver notifications.
- Privacy: Expo Privacy Policy
5. Data Security
We use reasonable technical and organizational measures, including encrypted transmission (HTTPS) for client-to-server communication, access controls on backend systems, and secure authentication flows. No online service is completely secure; we cannot guarantee absolute security.
6. Your Rights and Choices
6.1 Access and control
Depending on your region, you may have rights to access, correct, delete, or export personal data, or to object to certain processing. Contact us using the details below to make a request.
6.2 Delete your account
Where the app provides account deletion (for example via the in-app menu), you may use that flow to request deletion of data we hold for your account, subject to legal retention requirements.
6.3 Push notifications
You can allow or deny notifications when the operating system prompts you, and you can change notification settings later in the system Settings app.
7. Data Retention
We retain information for as long as needed to provide the service, comply with law, resolve disputes, and enforce agreements. When you delete your account (where available), we delete or anonymize associated personal data within a reasonable period unless a longer retention period is required by law.
8. Children’s Privacy
KIPFIRE is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children below that age. If you believe we have collected information from a child, contact us and we will take appropriate steps to delete it.
9. International Data Transfers
We may process and store information in the United States and other countries where we or our service providers operate. By using KIPFIRE, you understand that your information may be transferred to countries that may have different data protection laws than your own.
10. European Users (GDPR)
If you are in the European Economic Area, the UK, or Switzerland, you may have rights under applicable data protection laws, including to access, rectify, erase, restrict, or port your data, and to lodge a complaint with a supervisory authority. Our legal bases can include performance of a contract with you and legitimate interests in operating and securing the service, where permitted.
11. California Users (CCPA / CPRA)
California residents may have the right to know what personal information we collect, to request deletion, and to opt out of certain types of sharing. We do not sell personal information as “sell” is commonly defined under the CCPA. We will not discriminate against you for exercising privacy rights.
12. Changes to This Privacy Policy
We may update this policy from time to time. We will post the updated version on this page and change the “Last Updated” date. For material changes, we may provide additional notice where appropriate.
13. Contact Us
For questions, concerns, or requests about this Privacy Policy or our data practices:
Email: support@kipfire.com
App: KIPFIRE
For deletion or access requests, include the email address associated with your account so we can verify your identity.
Last Updated: April 26, 2026
Version: 1.1