Privacy Policy
Last updated: August 2026
1. Who is responsible
Kipa is jointly operated by Pavel Mikhailau and Kateryna Igelskaya (the "Controllers"). For privacy requests, contact us at privacy@kipaapp.com. We will respond using that inbox; a postal address can be provided on request for formal correspondence.
2. Information We Collect
We collect information you provide when you create an account (email address, display name, profile photo if you add one) and the content you save (links, notes, categories, cover images). If you use photo scan / OCR features, we process text and images you select to help fill item fields. When you enable notifications, we store a push token. We also collect subscription and entitlement status via our payment partner, diagnostic data when the App crashes or is slow, and product usage events (associated with your account id, not your email). Onboarding answers (for example how you heard about us) may be stored locally and used in aggregate product analytics.
3. How We Use Your Information
We use your information to provide, maintain, and improve the App: syncing your saves across devices, processing subscriptions, sending transactional email (verification, password reset, trial reminders), measuring product usage and stability, and—where you allow tracking on Apple devices—understanding how marketing campaigns lead to installs. We do not sell your personal information.
4. Public wishlists
If you choose to publish a collection, a public copy may include the collection title, your display name (or part of your email local-part if no name is set), intro text, and each item's title, description, link URL, and image. Anyone with the link can view that page. Unpublishing or deleting your account deactivates those public pages; copies already opened or cached elsewhere may persist outside our control.
5. Data Storage and Security
Primary user content is stored in Google Cloud Firestore in the European Union (eur3). Some Cloud Functions and related processing run in the United States (us-central1). We use encryption in transit and at rest where provided by our vendors. No method of transmission over the Internet is 100% secure.
6. Third-Party Services
We use the following processors / services:
- Firebase Authentication, Cloud Firestore, Cloud Storage, Analytics, Crashlytics, and Performance Monitoring (Google)
- Tenjin for install and campaign attribution on mobile
- RevenueCat for subscription management and purchase validation
- Apple Sign In and Google Sign-In for authentication
- Expo (push notifications and app updates)
- Resend for transactional email
- Microlink to fetch link previews (title, description, image) for URLs you save
- Anthropic (via our servers) and Rork LLM toolkit to help extract product fields from screenshots / OCR text when you use those features
These services have their own privacy policies. Some are located outside the EEA; where required we rely on appropriate transfer mechanisms offered by those providers (such as Standard Contractual Clauses).
7. Analytics, Diagnostics, and Attribution
We use Firebase Analytics to understand feature usage. For signed-in users we may associate events with a stable app user identifier (your account id). We do not set your email address as an analytics user property.
We use Firebase Crashlytics and Performance Monitoring to diagnose crashes and latency.
On Apple devices we use App Tracking Transparency. If you allow tracking, Tenjin may use the IDFA and related signals for campaign measurement. If you do not allow tracking, we instruct Tenjin to opt out of that tracking flow and we turn off advertising-related Google Analytics consent flags while continuing product analytics where appropriate.
8. Push Notifications and Email
If you grant notification permission, we may send push messages about the App (for example reminders related to your saves). You can disable them in device settings. We send transactional email for account security and subscription lifecycle (for example trial ending). Marketing emails, if any, will be sent only where permitted and with an unsubscribe option.
9. Your Rights
Depending on where you live (including the EEA/UK), you may have rights to access, rectify, erase, restrict, or port your personal data, and to object to certain processing or withdraw consent. You can delete your account from Account → Delete Account, or email privacy@kipaapp.com. You may also lodge a complaint with your local supervisory authority.
10. Data Retention and Deletion
We retain your data while your account is active. When you delete your account we remove your profile, saved items and categories, uploaded files under your account, and deactivate your public wishlists, typically within 30 days. Some records may remain for a limited time where legally required (for example payment or security logs). Analytics, crash, attribution, and subscription vendors may retain residual data according to their own retention policies after we delete our copy or log out your subscription profile.
11. Children's Privacy
The App is not intended for children under 13. We do not knowingly collect personal information from children under 13. If we learn that we have, we will delete it.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy in the App and on kipaapp.com and change the "Last updated" date. For material changes we will provide additional notice in the App or by email when appropriate.
13. Contact Us
Controllers: Pavel Mikhailau and Kateryna Igelskaya
Email: privacy@kipaapp.com