Privacy Policy
Last updated: 23 July 2026
This Privacy Policy explains how Kintsu ("we", "us", "the app") collects, uses, and protects your personal data when you use the Kintsu mobile application and this website (kintsu.ink).
We aim to collect as little data as possible, and only what we need to run the app, keep it secure, and comply with the law. If anything in this policy is unclear, email us at privacy@kintsu.ink.
1. Who we are
Kintsu is an independent mobile application. For the purposes of the UK GDPR and EU GDPR, the data controller is Eugenio Lecci, an individual based in the United Kingdom, contactable at privacy@kintsu.ink.
We are not required to appoint a Data Protection Officer under Article 37 of the UK GDPR.
2. What data we collect and why
2.1 Account data
When you create an account, we collect:
- Email address: used to sign you in and to send essential account notifications, for example password resets.
- Username: a display name you choose. It does not have to be your real name.
If you use the app without creating an account (anonymous mode), we create an anonymous account with a randomly generated identifier on our servers. Your saved content and preferences are stored against that identifier so they follow you between sessions. It is not linked to your name, email address, or any other personal detail unless you later create an account.
2.2 App content
The app stores the following content you create inside it on our servers:
- Saved quotes: the quotes you save to your personal Temple.
- Your own quotes: any quotes you write and add yourself, including the text and any author or source you enter.
- Collections: the private collections you create and the quotes you group into them.
- Quotes already shown to you: a lightweight record of which quotes your feed has served, so it does not repeat them until you have seen everything available. This resets automatically when you have seen every quote in the deck.
- Interactions: which quotes you liked or dismissed, and how long you spent on a quote, so the feed can tune what it shows you.
- Mood check ins: when you record how you feel, we store that signal so the app can reflect fitting words back to you. This is optional and you control it.
- Oracle prompts and outputs: when you use the Oracle to generate an aphorism, the prompt you enter and the resulting text are stored against your account so you can revisit them.
- Entitlements: whether you have an active subscription or an ad unlock, so the app knows what to show you.
2.3 Diagnostic data
To keep the app working, we collect:
- Error reports: if the app crashes or hits an error, we record the error type, a short breadcrumb of recent actions, the app version, and a pseudonymous user identifier. We do not log the contents of your quotes or Oracle prompts in error reports.
- Basic app events: a small number of technical events, including app open, foreground and background transitions, ad watch outcomes (rewarded, dismissed, not ready), and Oracle generation requests, so we can tell whether core features are working. We do not record session replays or capture your screen, and we do not build detailed profiles of your reading beyond the interaction signals in section 2.2.
2.4 Advertising data
Kintsu shows occasional rewarded video ads to unlock features. When you choose to watch an ad, the Google AdMob SDK may collect:
- Your device's Advertising ID
- Device type, operating system version, and language
- IP address (used for approximate location and fraud prevention)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we ask for your consent before any personalised ads are shown, using Google's User Messaging Platform (UMP). You can withdraw or change this consent at any time from Settings, Privacy, Manage ad preferences in the app.
2.5 Purchase data
If you buy a subscription or other paid feature, the purchase is handled by Google Play Billing. We receive a purchase token from Google so we can grant you the feature you bought, but we do not see your card details, billing address, or Google account. Receipt validation is handled by RevenueCat on our behalf.
2.6 Notification data
If you turn on daily reminders, we register your device with Google Firebase Cloud Messaging so we can deliver them. We store a device notification token, your device's timezone, and your chosen schedule, so the reminder arrives at the right local time. You can turn notifications off at any time in Settings.
2.7 On-device data (not sent to our servers)
Some information stays on your device and is never sent to us:
- App preferences: your theme, font scale, and notification toggles are stored locally using Android's standard SharedPreferences store. If you uninstall the app or clear its storage, these settings are lost.
3. Who we share data with
We use the following third-party processors. Each one only receives the data it needs to do its job. We do not sell your personal data.
- Supabase (AWS eu-west, Ireland): authentication and database hosting. Receives your account data, app content, and Oracle prompts and outputs.
- Google Gemini (Google LLC, United States): AI model inference for the Oracle, and for the Mirror when it chooses a fitting quote. Receives, via our backend, the text you submit to the Oracle and the words you type into the Mirror. Your Mirror text is used only to pick a quote and is not stored by us. We use Google's paid API tier, which means Google does not use your prompts or the generated responses to train or improve its models. Gemini does not receive your email, username, or user ID.
- PostHog (United States): error reporting and basic app events. Receives diagnostic data and a pseudonymous user identifier.
- Google AdMob (global): serves rewarded ads. Receives advertising data as described in section 2.4.
- Google Firebase Cloud Messaging (global): delivers your daily notifications. Receives your device notification token.
- RevenueCat (United States): manages subscription purchases and entitlements. Receives a pseudonymous user identifier and the purchase token returned by Google Play.
- Google Play (global): distributes the app and processes in-app purchases.
- Resend (United States): our email delivery provider. It sends the account emails we send you, such as verifying your email when you sign up, resetting your password, and confirming that your account has been deleted. It receives your email address in order to deliver these messages.
- Cloudflare (global): hosts this website and routes email sent to privacy@kintsu.ink and hello@kintsu.ink.
4. Legal basis for processing (UK / EU GDPR)
- Contract: creating and running your account, storing your saved content, and processing subscription purchases.
- Legitimate interest: diagnosing errors, preventing abuse, and making sure the app works. We have weighed this against your privacy and believe the minimal data we collect is proportionate.
- Consent: personalised advertising in the EEA, UK, and Switzerland, where we ask you through the Google UMP dialog.
- Legal obligation: if you make a purchase, we may retain basic transaction records for as long as tax and accounting law requires.
5. How long we keep your data
- Account data and app content: kept until you delete your account. When you tap Settings, Delete Account Permanently, we delete your account and all of the user-linked records described in section 2.2, including your saved quotes, your own quotes, collections, already-seen quote history, interactions, mood check ins, Oracle prompts and outputs, and entitlements. Deletion is permanent.
- Anonymous accounts: kept until deleted. If you uninstall the app or clear its storage without deleting your data first (Settings, Delete Account Permanently), the identifier is removed from your device and the account can no longer be accessed.
- Notification token: kept until you turn notifications off or delete your account.
- Error reports: retained by PostHog for up to 90 days, then purged.
- Advertising data: retained by Google AdMob according to their own policy.
- Purchase records: retained for as long as UK tax and accounting law requires (currently six years).
6. Your rights
Under the UK GDPR and EU GDPR you have the right to:
- Access: ask us for a copy of the data we hold about you.
- Rectification: ask us to correct data that is wrong or out of date.
- Erasure: delete your account yourself in-app (Settings, Delete Account Permanently), email us and we will do it, or follow the steps on our account deletion page.
- Portability: ask us to export your saved content in a machine-readable format.
- Object: object to processing based on our legitimate interests.
- Withdraw consent: change your ad preferences at any time from the in-app Settings.
- Complain: if you think we have mishandled your data, you can complain to the UK Information Commissioner's Office at ico.org.uk or your national data protection authority.
To exercise any of these rights, email privacy@kintsu.ink. We will respond within one month.
7. International transfers
Your data may be transferred outside the UK and EEA, specifically to the United States (PostHog, Google Gemini, Google AdMob, RevenueCat, Resend). Where that happens, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU Standard Contractual Clauses, which are the transfer mechanisms approved by the UK Information Commissioner's Office for post-Brexit data flows to countries without an adequacy decision.
8. Age requirement
Kintsu is for adults. You must be at least 18 years old to use the app. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has created an account, email privacy@kintsu.ink and we will delete it.
9. Security
We use HTTPS for all traffic, store session tokens in your device's secure storage (Android Keystore), and rely on Supabase row-level security policies so users can only read and write their own data. No system is perfectly secure, but we take reasonable and proportionate measures to protect your information.
10. Changes to this policy
We may update this policy as the app changes. When we do, we will update the "Last updated" date at the top of this page. Material changes will be notified in-app.
11. Contact
Questions, requests, or complaints: privacy@kintsu.ink.