Kasstek ("Kasstek," "we," "us," or "our") develops and publishes software applications for Apple platforms, including iPhone, iPad, and Mac. We respect your privacy and are committed to protecting your personal information. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights and choices available to you.
This Policy is written to comply with privacy laws in the United States (including the California Consumer Privacy Act as amended by the California Privacy Rights Act, "CCPA/CPRA"), the European Union (the General Data Protection Regulation, "GDPR"), the United Kingdom ("UK GDPR"), Canada (the Personal Information Protection and Electronic Documents Act, "PIPEDA"), Brazil (Lei Geral de Proteção de Dados, "LGPD"), Australia (the Privacy Act 1988), and other applicable jurisdictions.
By downloading, installing, or using any Kasstek application, or by visiting kasstek.com, you acknowledge that you have read and understood this Privacy Policy.
This Policy applies to all Kasstek products and services ("Services"), including but not limited to:
"Personal Information" (also called "personal data") means any information that relates to an identified or identifiable natural person. "Processing" means any operation performed on personal information, such as collection, storage, use, or disclosure.
We collect information in the following categories. Not every Kasstek app collects every category — consult the App Store privacy label for each specific app for details.
Some Kasstek apps request permission to access device features. Access is only granted with your explicit consent, which you can revoke at any time through your device settings.
| Permission | Purpose | Data Used |
|---|---|---|
| Microphone | Voice capture, audio recording, voice memos | Audio processed locally on device; not uploaded unless you explicitly share it |
| Camera | Scanning, photo capture (where applicable) | Images processed locally; not uploaded unless you save or share |
| Photo Library | Selecting images to use in-app | Only photos you explicitly select |
| Location | Location-aware features (where applicable) | Used in-session; not retained unless you save it |
| Notifications | Alerts, reminders, engagement prompts | Device push token; no message content stored on our servers |
| Speech Recognition | Voice-to-text transcription | Processed by Apple on-device where supported; see Apple's privacy policy otherwise |
We use the information we collect for the following purposes:
We do not use your personal information for purposes incompatible with those stated above without providing you notice and, where required, obtaining your consent.
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, our legal basis for processing your personal data depends on the specific purpose:
| Purpose | Legal Basis (GDPR Art. 6) |
|---|---|
| Operating the app and delivering features you requested | Performance of a contract — Art. 6(1)(b) |
| Crash reporting and diagnostics | Legitimate interests — Art. 6(1)(f) |
| Analytics and product improvement | Consent — Art. 6(1)(a), opt-in via App Tracking Transparency |
| Responding to support inquiries | Performance of a contract and legitimate interests |
| Complying with legal obligations | Legal obligation — Art. 6(1)(c) |
| Security and fraud prevention | Legitimate interests — Art. 6(1)(f) |
Where we rely on consent, you can withdraw that consent at any time without affecting the lawfulness of processing performed before withdrawal.
Our apps may integrate with the following categories of third-party services. Each operates under its own privacy policy, which we encourage you to review:
We do not control, and are not responsible for, the privacy practices of third parties. Any information collected by third parties is governed by their own privacy policies.
Kasstek is based in the United States. If you access our Services from outside the United States, your information may be transferred to, stored in, and processed in the United States or other countries where we or our service providers operate.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on one or more of the following safeguards:
You may request a copy of the relevant transfer mechanism by contacting us at the address below.
We retain personal information only as long as necessary to fulfill the purposes for which it was collected, including satisfying legal, accounting, or reporting requirements. Retention periods vary by data category:
| Data Category | Retention Period |
|---|---|
| Account data | Until account deletion, plus up to 30 days in backups |
| User-generated content | Stored on your device; we do not retain copies unless you explicitly sync or back up |
| Crash reports and diagnostics | Up to 90 days |
| Usage analytics | Up to 14 months, aggregated thereafter |
| Support communications | Up to 2 years after resolution |
| Purchase records | As required by tax and consumer protection laws (typically 7 years) |
When we no longer need personal information, we delete it or anonymize it so that it can no longer be associated with you.
We implement technical and organizational measures designed to protect your personal information against unauthorized access, alteration, disclosure, or destruction. These measures include:
PrivacyInfo.xcprivacy) declaring all data collection and third-party SDK use, as required by AppleNo security measure is perfect. While we strive to protect your information, we cannot guarantee absolute security. If we become aware of a security breach that affects your personal information, we will notify you and appropriate authorities as required by law.
Depending on your location, you have certain rights regarding your personal information. We honor these rights regardless of where you live, to the extent it is technically and legally feasible.
Request a copy of the personal information we hold about you.
Correct inaccurate or incomplete information.
Request deletion of your personal information ("right to be forgotten").
Limit how we use your information in certain circumstances.
Receive your information in a structured, machine-readable format.
Object to processing based on legitimate interests or for direct marketing.
Withdraw previously given consent at any time.
We will not discriminate against you for exercising your privacy rights.
To exercise any of these rights, contact us using the details in the Contact Us section. We will verify your identity before responding. We will respond within the timeframes required by applicable law (typically 30–45 days).
If you are a California resident, the California Consumer Privacy Act (as amended by the California Privacy Rights Act) provides you with the following rights:
Categories of personal information collected in the preceding 12 months: identifiers (device IDs), commercial information (purchase history), internet activity (app usage), geolocation (approximate, from IP), and inferences drawn from the above. We do not collect the categories of sensitive personal information requiring opt-out under CPRA.
Sources: directly from you, from your device, and from our service providers.
Purposes: as described in Section 4.
Shared with: service providers as described in Section 6.
To submit a CCPA/CPRA request, email admim@kasstek.com with the subject line "California Privacy Request." You may also designate an authorized agent to submit a request on your behalf.
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Iowa, Delaware, New Hampshire, New Jersey, Tennessee, and other states with comprehensive privacy laws have substantially similar rights (access, delete, correct, opt out of targeted advertising, opt out of sale, opt out of profiling for significant decisions). To exercise these rights, contact us using the same procedure described above.
California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes. We do not disclose personal information for third-party direct marketing.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the rights described in Section 11, as well as:
Data Controller: Kasstek is the data controller for personal information collected through our Services. Our contact details are in Section 23.
EU/UK Representative: If we are required to appoint a representative under GDPR Article 27 or UK GDPR, we will publish their contact details here.
Canadian residents have the right to access their personal information and challenge its accuracy. You may file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca. Quebec residents also have rights under Law 25.
Brazilian residents have rights similar to those under GDPR, including access, correction, anonymization, portability, deletion, information about data sharing, and revocation of consent. You may contact the Autoridade Nacional de Proteção de Dados (ANPD) at gov.br/anpd.
Australian residents may request access to and correction of personal information we hold about them and may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Japanese residents have rights under the Act on the Protection of Personal Information, including disclosure, correction, and cessation of use. Contact the Personal Information Protection Commission at ppc.go.jp.
Korean residents have rights under the Personal Information Protection Act, including access, correction, deletion, and suspension of processing.
If you are in the People's Republic of China, you have rights under the Personal Information Protection Law, including access, correction, deletion, and portability. You may withdraw consent and object to automated decision-making.
If you are located in a jurisdiction with a data protection law not specifically addressed above (including India's DPDPA, South Africa's POPIA, and others), we will honor the rights afforded to you under that law to the extent it is technically and legally feasible.
Our Services are not directed to children under the age of 13 (or under 16 in the EEA and UK), and we do not knowingly collect personal information from children. We comply with the U.S. Children's Online Privacy Protection Act ("COPPA") and the GDPR's provisions regarding children's consent.
If a Kasstek app is designed for children, it will be listed in the Apple Kids Category and will comply with the additional requirements of that category, including:
If you believe a child under 13 has provided us with personal information, please contact us immediately at admin@kasstek.com, and we will delete the information.
On iOS 14.5 and later, Apple requires apps to obtain explicit permission before tracking users across other companies' apps and websites. Kasstek apps display the ATT prompt only when tracking is genuinely required (such as for third-party advertising). If you decline, no tracking identifier (IDFA) will be shared. You may change your choice at any time in Settings → Privacy & Security → Tracking.
Each Kasstek app on the App Store displays a "Privacy Nutrition Label" summarizing the categories of data collected and how they are used. These labels are kept accurate and current.
As required by Apple, each Kasstek app includes a PrivacyInfo.xcprivacy manifest declaring:
Where supported, we offer Sign in with Apple as a privacy-preserving authentication option. When you use Sign in with Apple, you may choose to hide your email address from us. Apple will provide a relay email that forwards to your real address — we never see your real email unless you choose to share it.
If an app offers iCloud sync, your data is stored in your personal iCloud account and is not accessible to Kasstek. iCloud storage is governed by Apple's privacy policy.
Where possible, we process data on your device rather than on our servers. This includes speech recognition, image analysis, and machine learning features that use Apple's on-device frameworks.
We collect anonymous usage analytics to understand how our apps are used and to identify bugs. Analytics data is aggregated and does not identify individual users. Where Apple's App Tracking Transparency applies, we honor your choice.
You may opt out of analytics within the app settings of each Kasstek app, or by disabling "Share App Analytics with App Developers" in Settings → Privacy & Security → Analytics & Improvements on your device.
Some Kasstek apps may display advertising. Where ads are shown:
Ads are never shown in apps designed for children.
Some browsers offer a "Do Not Track" (DNT) setting or support Global Privacy Control (GPC) signals. Kasstek treats GPC signals as a valid opt-out of sale and sharing of personal information, as required by California law and recognized by other state privacy laws.
We do not use automated decision-making or profiling to make decisions that have legal or similarly significant effects on you. If this changes, we will update this Policy and obtain appropriate consent where required.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will:
We encourage you to review this Policy periodically. Your continued use of the Services after a revised Policy becomes effective constitutes acceptance of the updated terms.
If you have questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:
We will respond to your inquiry within the timeframes required by applicable law. For GDPR-related inquiries, please include "GDPR Request" in your subject line. For California CCPA/CPRA requests, include "California Privacy Request."
Replace the bracketed postal address, confirm the email addresses are monitored, and have this document reviewed by qualified legal counsel in the jurisdictions where you operate. Privacy law is fact-specific and varies by product — treat this as a strong starting point, not final legal advice.