Privacy Policy
Effective date: April 26, 2026
Last updated: September 29, 2026 · Version 1.3
This Privacy Policy explains how KipFire ("we," "us," or "our") collects, uses, stores, and shares information when you use our mobile application and related services.
1. Information we collect
1.1 Account and authentication
When you sign in or create an account, we process data through our authentication provider and our backend:
- Email address (when you sign in with email, Google, or Apple and the provider shares an email).
- Username you choose in the app, if you set one.
- Display name (when your sign-in provider, such as Apple or Google, shares a name with the app).
- Firebase user identifier (UID) and an internal application user ID used to tie your profile, tasks, and subscription state together on our servers.
1.2 How you use the app (service data)
To run the product, our servers may store and process:
- Language and region-related preferences used to generate tasks in the right language.
- Task-related data, including selected categories, AI-generated task text, metadata about prompts (for example model or style fields where applicable), and records needed for daily limits and premium access.
- Subscription and purchase status synchronized between the app, Apple billing, our subscription partner, and our backend so we can unlock premium features.
- Push notification token if you opt in, so we can deliver notifications through the platform push service.
1.3 Optional context for premium tasks
If you use features that generate tasks from your situation, you may provide optional labels or free text (for example mood, a place type you pick, or a short description). That content is sent to our API and may be included in prompts sent to our AI provider to generate a task. It may be stored on our servers as needed to provide the feature (for example to avoid repeats or to improve reliability).
1.4 Technical and security data
- IP address, timestamps, and diagnostic information in server logs for security, abuse prevention, and operations.
- Basic device or client information your HTTP client sends with API requests (for example user-agent strings), where applicable.
1.5 Information we do not collect
- We do not collect or store your payment card numbers. In-app purchases are processed by Apple.
- We do not use Apple's App Tracking Transparency (IDFA-based cross-app advertising tracking) in KipFire.
- We do not collect your phone number.
- We do not collect precise GPS coordinates from your device sensors. Optional context you type or select is not the same as location tracking.
- We do not store your videos or photos. Media you record is processed on your device and saved to your photo library when you choose to save it. It is never uploaded to our servers.
- We do not sell your personal information.
2. How we use your information
- Provide the service: authenticate you, generate and deliver tasks, enforce free-tier limits, and enable premium features.
- Operate subscriptions: verify purchases, restore access, and prevent abuse.
- Communicate: send push notifications when you allow them, and transactional messages where we offer them (for example about your account or subscription).
- Secure and maintain: monitor for fraud, protect accounts, debug outages, and improve the reliability and performance of our infrastructure.
We do not use your data for third-party advertising, and we do not use it for tracking as defined in Apple's App Privacy documentation.
3. Video and media
Video recording, placing the task text on your video, and saving to your photo library all happen on your phone. KipFire does not upload or store your videos.
- Media you save is stored in your device's gallery under your control.
- Microphone audio is captured as part of video recording on your device. We do not receive your audio.
4. Third-party services
We rely on service providers to operate KipFire. They process data on our behalf according to their own policies.
4.1 Google Firebase
- Purpose: authentication, and optional reads from Cloud Firestore for in-app configuration (for example categories or prompts).
- Typical data: authentication identifiers, email when applicable, and client requests to Firestore.
- Privacy: Firebase Privacy and Google Privacy Policy
4.2 RevenueCat
- Purpose: in-app subscription management, entitlements, and purchase restoration.
- Typical data: app user identifiers (for example your Firebase UID), purchase metadata from Apple, and device or app-instance identifiers as described in RevenueCat's documentation.
- Privacy: RevenueCat Privacy Policy
4.3 Apple and Google
- Purpose: app distribution through the App Store, Apple In-App Purchase, Sign in with Apple, Google sign-in, and push notification delivery.
- Typical data: purchase receipts, subscription status, and account identifiers held by the platform.
- Privacy: Apple Privacy Policy; Google Privacy Policy
4.4 xAI
- Purpose: AI generation of the task text you see in the app.
- Typical data: category, language, and the prompt fields needed to generate a task. Optional text you type for a task may be included. We never send your videos.
- Privacy: xAI Privacy Policy
4.5 Our application database (MongoDB)
- Purpose: primary storage for application data such as user records, tasks, quotas, and subscription sync fields.
- Typical data: the categories described in Section 1, stored on servers we control or host (for example MongoDB Atlas or equivalent).
- Privacy: MongoDB Privacy Policy
4.6 Email delivery (if used)
- Purpose: transactional email (for example welcome or subscription messages) when we enable that feature.
- Typical data: email address.
- Privacy: depends on the provider (for example Google when using Gmail SMTP).
4.7 Expo push infrastructure
- Purpose: delivery of push notifications through Expo's tooling where configured.
- Typical data: push tokens and related metadata needed to deliver notifications.
- Privacy: Expo Privacy Policy
5. Data security
We use reasonable technical and organizational measures, including encrypted transmission (HTTPS), access controls on backend systems, and secure authentication flows. No online service is completely secure, and we cannot guarantee absolute security.
6. Your rights and choices
6.1 Access and control
Depending on where you live, you may have rights to access, correct, delete, or export your personal data, or to object to certain processing. Contact us at support@kipfire.com to make a request.
6.2 Delete your account
You can delete your account from the in-app menu. This deletes the data we hold for your account, subject to legal retention requirements.
6.3 Push notifications
You can allow or deny notifications when prompted, and change this later in your device Settings.
7. Data retention
We keep information for as long as needed to provide the service, comply with law, resolve disputes, and enforce agreements. When you delete your account, we delete or anonymize associated personal data within 30 days unless a longer period is required by law.
8. Children's privacy
KipFire is not intended for children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children below that age. If you believe we have, contact support@kipfire.com and we will delete it.
9. International data transfers
We may process and store information in the United States and other countries where we or our service providers operate. These countries may have different data protection laws than yours.
10. European users (GDPR)
If you are in the European Economic Area, the UK, or Switzerland, you may have rights to access, rectify, erase, restrict, or port your data, and to lodge a complaint with a supervisory authority. Our legal bases include performance of a contract with you and our legitimate interests in operating and securing the service, where permitted.
11. California users (CCPA / CPRA)
California residents may have the right to know what personal information we collect, to request deletion, and to opt out of certain types of sharing. We do not sell personal information as defined under the CCPA. We will not discriminate against you for exercising your privacy rights.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version on this page and change the "Last updated" date. For material changes, we may provide additional notice.
13. Contact us
Email: support@kipfire.com
For deletion or access requests, include the email address linked to your account so we can verify your identity.