Privacy Policy

Last updated: July 05, 2026 · Version 2026-07-05

1. Introduction

Kaify Ai ("Kaify", "we", "us") operates https://kaifyai.org and the Kaify mobile web application. This Privacy Policy explains what personal data we collect, why we use it, who we share it with, and your rights under GDPR, UK GDPR, and KVKK (Turkey).

2. Data We Collect

  • Account: email address, profile name, locale, timezone, country
  • Health & fitness: steps, streaks, workout notes, body metrics, optional injury notes, photo analysis results (not stored as public images)
  • AI chat: messages you send to coaches, coaching memory summaries
  • Usage: gem balance, market purchases, referral activity, analytics aggregates
  • Technical: IP address (security/rate limits), device/browser type, session cookies
  • Payments: processed by Paddle (Merchant of Record) — we receive subscription status and billing email, not card numbers

3. Lawful Basis (GDPR Art. 6 & 9)

We process account and service data under contract (providing the app) and legitimate interests (security, fraud prevention).

Health-related data, photos for AI analysis, and automated coaching require your explicit consent (GDPR Art. 9). You can withdraw consent in Settings; withdrawal may limit AI features.

4. AI & Automated Processing

Kaify uses third-party AI providers (Google Gemini, DeepSeek) to generate coaching responses and analyze photos. Prompts are sanitized; images are processed transiently for analysis. Outputs are not medical advice. See our Terms of Service for disclaimers.

5. Subprocessors & Sharing

We share data only with service providers needed to run Kaify:

  • Supabase (database, auth, storage) — EU (Frankfurt)
  • Vercel (hosting)
  • Google Gemini / DeepSeek (AI inference)
  • Sentry (error monitoring)
  • Paddle (payments)
  • Google reCAPTCHA (bot protection on waitlist)

We do not sell your personal data. See Cookie Policy for cookie details.

6. International Transfers

Some providers process data in the United States or other countries. Where required, we rely on Standard Contractual Clauses (SCCs) or equivalent safeguards. AI API calls may route through US or other regions depending on provider infrastructure.

7. Retention

We keep your data while your account is active. After account deletion, core profile and associated records are removed via cascade delete. Some anonymized analytics or legal logs may be retained longer where required by law. Target: delete or anonymize within 6 months after account termination unless law requires longer storage.

8. Your Rights

You may have the right to:

  • Access your data (export JSON in Settings → Security)
  • Rectify inaccurate profile data
  • Delete your account (right to erasure)
  • Restrict or object to certain processing
  • Withdraw consent for AI/health processing
  • Lodge a complaint with your supervisory authority

Contact: privacy@kaifyai.org — we respond within 30 days where GDPR/KVKK applies.

9. Children

Kaify is for users aged 16 and over. We do not knowingly collect data from children under 16. Contact us to request deletion if you believe a minor registered.

10. Security

We use encryption in transit (HTTPS), row-level security in the database, MFA support, rate limiting, and access controls. No method is 100% secure; report concerns to support@kaifyai.org.

11. Changes & Contact

We may update this policy. Material changes will be notified in-app or by email. Version: 2026-07-05 · Last updated: July 05, 2026.

Kaify Ai · Toros Mah., Çukurova, Adana 01150, Turkey · privacy@kaifyai.org

Privacy Policy — Kaify