Kasstek

Privacy Policy

Effective Date: April 11, 2026
Last Updated: February 1, 2026
Applies To: All Kasstek mobile (iOS, iPadOS) and desktop (macOS) applications, and the kasstek.com website.

1. Introduction

Kasstek ("Kasstek," "we," "us," or "our") develops and publishes software applications for Apple platforms, including iPhone, iPad, and Mac. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights and choices available to you.

This Policy is written to comply with privacy laws in the United States (including the California Consumer Privacy Act as amended by the California Privacy Rights Act, "CCPA/CPRA"), the European Union (the General Data Protection Regulation, "GDPR"), the United Kingdom ("UK GDPR"), Canada (the Personal Information Protection and Electronic Documents Act, "PIPEDA"), Brazil (Lei Geral de Proteção de Dados, "LGPD"), Australia (the Privacy Act 1988), and other applicable jurisdictions.

By downloading, installing, or using any Kasstek application, or by visiting kasstek.com, you acknowledge that you have read and understood this Privacy Policy.

2. Scope & Definitions

This Policy applies to all Kasstek products and services ("Services"), including but not limited to:

"Personal Information" (also called "personal data") means any information that relates to an identified or identifiable natural person. "Processing" means any operation performed on personal information, such as collection, storage, use, or disclosure.

3. Information We Collect

We collect information in the following categories. Not every Kasstek app collects every category — consult the App Store privacy label for each specific app for details.

3.1 Information You Provide Directly

3.2 Information Collected Automatically

3.3 Information from Device Permissions

Some Kasstek apps request permission to access device features. Access is only granted with your explicit consent, which you can revoke at any time through your device settings.

Permission Purpose Data Used
Microphone Voice capture, audio recording, voice memos Audio processed locally on device; not uploaded unless you explicitly share it
Camera Scanning, photo capture (where applicable) Images processed locally; not uploaded unless you save or share
Photo Library Selecting images to use in-app Only photos you explicitly select
Location Location-aware features (where applicable) Used in-session; not retained unless you save it
Notifications Alerts, reminders, engagement prompts Device push token; no message content stored on our servers
Speech Recognition Voice-to-text transcription Processed by Apple on-device where supported; see Apple's privacy policy otherwise

3.4 Information We Do Not Collect

4. How We Use Information

We use the information we collect for the following purposes:

We do not use your personal information for purposes incompatible with those stated above without providing you notice and, where required, obtaining your consent.

6. Sharing & Disclosure

We do not sell or rent your personal information. We share information only in the limited circumstances described below:

6.1 Service Providers

We engage third-party service providers ("processors" under GDPR, "service providers" under CCPA) who process information on our behalf under strict contractual obligations. These include:

A current list of processors is available on request (see Contact Us).

6.2 Legal Requirements

We may disclose information if required to do so by law or in response to valid legal requests, including subpoenas, court orders, or government demands. We will challenge requests that we believe are overbroad or unlawful.

6.3 Business Transfers

If Kasstek is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or a prominent notice on our website and in-app before your information becomes subject to a different privacy policy.

6.4 With Your Consent

We may share information for any other purpose with your explicit consent.

We do not sell personal information.

Kasstek does not sell personal information as "sale" is defined under the CCPA/CPRA or any other applicable law. We do not share personal information for cross-context behavioral advertising.

7. Third-Party Services

Our apps may integrate with the following categories of third-party services. Each operates under its own privacy policy, which we encourage you to review:

We do not control, and are not responsible for, the privacy practices of third parties. Any information collected by third parties is governed by their own privacy policies.

8. International Data Transfers

Kasstek is based in the United States. If you access our Services from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate.

For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on one or more of the following safeguards:

You may request a copy of the relevant transfer mechanism by contacting us at the address below.

9. Data Retention

We retain personal information only as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods vary by data category:

Data Category Retention Period
Account data Until account deletion, plus up to 30 days in backups
User-generated content Stored on your device; we do not retain copies unless you explicitly sync or back up
Crash reports and diagnostics Up to 90 days
Usage analytics Up to 14 months, aggregated thereafter
Support communications Up to 2 years after resolution
Purchase records As required by tax and consumer protection laws (typically 7 years)

When we no longer need personal information, we delete it or anonymize it so that it can no longer be associated with you.

10. Security

We implement technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:

No security measure is perfect. While we strive to protect your information, we cannot guarantee absolute security. If we become aware of a security breach that affects your personal information, we will notify you and appropriate authorities as required by law.

11. Your Rights

Depending on your location, you have certain rights regarding your personal information. We honor these rights regardless of where you live, to the extent it is technically and legally feasible.

Right to Access

Request a copy of the personal information we hold about you.

Right to Rectification

Correct inaccurate or incomplete information.

Right to Erasure

Request deletion of your personal information ("right to be forgotten").

Right to Restrict Processing

Limit how we use your information in certain circumstances.

Right to Data Portability

Receive your information in a structured, machine-readable format.

Right to Object

Object to processing based on legitimate interests or for direct marketing.

Right to Withdraw Consent

Withdraw previously given consent at any time.

Right to Non-Discrimination

We will not discriminate against you for exercising your privacy rights.

To exercise any of these rights, contact us using the details in the Contact Us section. We will verify your identity before responding. We will respond within the timeframes required by applicable law (typically 30–45 days).

12. U.S. State Privacy Rights

12.1 California (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides you with the following rights:

Categories of personal information collected in the preceding 12 months: identifiers (device IDs), commercial information (purchase history), internet activity (app usage), geolocation (approximate, from IP), and inferences drawn from the above. We do not collect the categories of sensitive personal information requiring opt-out under CPRA.

Sources: directly from you, from your device, and from our service providers.

Purposes: as described in Section 4.

Shared with: service providers as described in Section 6.

To submit a CCPA/CPRA request, email admim@kasstek.com with the subject line "California Privacy Request." You may also designate an authorized agent to submit a request on your behalf.

12.2 Other U.S. States

Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, and other states with comprehensive privacy laws have substantially similar rights (access, delete, correct, opt out of targeted advertising, opt out of sale, opt out of profiling for significant decisions). To exercise these rights, contact us using the same procedure described above.

12.3 "Shine the Light" (California Civil Code § 1798.83)

California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information for third-party direct marketing.

13. European Union & United Kingdom Rights (GDPR / UK GDPR)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 11, as well as:

Data Controller: Kasstek is the data controller for personal information collected through our Services. Our contact details are in Section 23.

EU/UK Representative: If we are required to appoint a representative under GDPR Article 27 or UK GDPR, we will publish their contact details here.

14. Other Regions

14.1 Canada (PIPEDA)

Canadian residents have the right to access their personal information and challenge its accuracy. You may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca. Quebec residents also have rights under Law 25.

14.2 Brazil (LGPD)

Brazilian residents have rights similar to those under GDPR, including access, correction, anonymization, portability, deletion, information about data sharing, and revocation of consent. You may contact the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.

14.3 Australia (Privacy Act 1988)

Australian residents may request access to and correction of personal information we hold about them and may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

14.4 Japan (APPI)

Japanese residents have rights under the Act on the Protection of Personal Information, including disclosure, correction, and cessation of use. Contact the Personal Information Protection Commission at ppc.go.jp.

14.5 South Korea (PIPA)

Korean residents have rights under the Personal Information Protection Act, including access, correction, deletion, and suspension of processing.

14.6 China (PIPL)

If you are in the People's Republic of China, you have rights under the Personal Information Protection Law, including access, correction, deletion, and portability. You may withdraw consent and object to automated decision-making.

14.7 Other Jurisdictions

If you are located in a jurisdiction with a data protection law not specifically addressed above (including India's DPDPA, South Africa's POPIA, and others), we will honor the rights afforded to you under that law to the extent it is technically and legally feasible.

15. Children's Privacy

Our Services are not directed to children under the age of 13 (or under 16 in the EEA and UK), and we do not knowingly collect personal information from children. We comply with the U.S. Children's Online Privacy Protection Act ("COPPA") and the GDPR's provisions regarding children's consent.

If a Kasstek app is designed for children, it will be listed in the Apple Kids Category and will comply with the additional requirements of that category, including:

If you believe a child under 13 has provided us with personal information, please contact us immediately at admin@kasstek.com, and we will delete the information.

16. Apple Platform Disclosures

16.1 App Tracking Transparency (ATT)

On iOS 14.5 and later, Apple requires apps to obtain explicit permission before tracking users across other companies' apps and websites. Kasstek apps display the ATT prompt only when tracking is genuinely required (such as for third-party advertising). If you decline, no tracking identifier (IDFA) will be shared. You may change your choice at any time in Settings → Privacy & Security → Tracking.

16.2 App Store Privacy Labels

Each Kasstek app on the App Store displays a "Privacy Nutrition Label" summarizing the categories of data collected and how they are used. These labels are kept accurate and current.

16.3 Privacy Manifest

As required by Apple, each Kasstek app includes a PrivacyInfo.xcprivacy manifest declaring:

16.4 Sign in with Apple

Where supported, we offer Sign in with Apple as a privacy-preserving authentication option. When you use Sign in with Apple, you may choose to hide your email address from us. Apple will provide a relay email that forwards to your real address — we never see your real email unless you choose to share it.

16.5 iCloud Sync

If an app offers iCloud sync, your data is stored in your personal iCloud account and is not accessible to Kasstek. iCloud storage is governed by Apple's privacy policy.

16.6 On-Device Processing

Where possible, we process data on your device rather than on our servers. This includes speech recognition, image analysis, and machine learning features that use Apple's on-device frameworks.

17. Cookies & Similar Technologies

Our mobile and desktop applications do not use browser cookies. Our website (kasstek.com) uses only strictly necessary cookies required for the site to function. We do not set tracking or advertising cookies without your consent.

If we add optional cookies in the future (for analytics or marketing), we will display a consent banner in accordance with the EU ePrivacy Directive and the UK's PECR, and will not set those cookies until you opt in.

18. Analytics & Telemetry

We collect anonymous usage analytics to understand how our apps are used and to identify bugs. Analytics data is aggregated and does not identify individual users. Where Apple's App Tracking Transparency applies, we honor your choice.

You may opt out of analytics within the app settings of each Kasstek app, or by disabling "Share App Analytics with App Developers" in Settings → Privacy & Security → Analytics & Improvements on your device.

19. Advertising

Some Kasstek apps may display advertising. Where ads are shown:

Ads are never shown in apps designed for children.

20. Do Not Track & Global Privacy Control

Some browsers offer a "Do Not Track" (DNT) setting or support Global Privacy Control (GPC) signals. Kasstek treats GPC signals as a valid opt-out of sale and sharing of personal information, as required by California law and recognized by other state privacy laws.

21. Automated Decision-Making & Profiling

We do not use automated decision-making or profiling to make decisions that have legal or similarly significant effects on you. If this changes, we will update this Policy and obtain appropriate consent where required.

22. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:

We encourage you to review this Policy periodically. Your continued use of the Services after a revised Policy becomes effective constitutes acceptance of the updated terms.

23. Contact Us

If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

We will respond to your inquiry within the timeframes required by applicable law. For GDPR-related inquiries, please include "GDPR Request" in your subject line. For California CCPA/CPRA requests, include "California Privacy Request."

Before deploying this document

Replace the bracketed postal address, confirm the email addresses are monitored, and have this document reviewed by qualified legal counsel in the jurisdictions where you operate. Privacy law is fact-specific and varies by product — treat this as a strong starting point, not final legal advice.