Privacy Policy
KindaOkay — Effective date: December 22, 2025
This Privacy Policy explains how KindaOkay ("we", "us", "our") collects, uses, stores, and shares information when you use the KindaOkay mobile application and its related services (the "Service"). By using the Service, you agree to the practices described in this Privacy Policy.
1. What the Service Does (Informational Only)
KindaOkay is an informational food analysis and decision-support tool. It lets you scan product barcodes or search for products and receive insights about product composition and characteristics.
The Service may display nutritional values (e.g., sugar, fat, salt), ingredient-related flags (e.g., allergens, additives, palm oil), and processing indicators (e.g., ultra-processed food index). It may also calculate an internal informational score based on the goals you select.
Important disclaimer:
- The Service does not provide medical advice, diagnoses, or treatment recommendations.
- Outputs are informational only and may be incomplete or inaccurate due to limitations of third-party data sources.
- You remain responsible for your food choices and decisions.
2. Interpretation and Definitions
Account
A profile created to access the Service.
Application
The mobile application titled "KindaOkay".
Service
The Application and related backend services operated by the Owner.
Owner / We / Us / Our
An individual operator located in the Czech Republic.
Device
Any device used to access the Service.
Personal Data
Information that identifies or can reasonably be linked to an individual (e.g., email).
Usage Data
Data collected automatically through use of the Service (e.g., logs, diagnostics).
Food Data
Product and nutrition information retrieved from public third-party databases.
Goals / Preferences
User-selected settings used to present information and compute an informational score.
3. Information We Collect
3.1 Information you provide
- Email address
- Name (as provided by your sign-in provider)
- Goals and preferences (e.g., skin health, digestion, general awareness)
3.2 Barcode scans and history
- Barcodes you scan
- Scan history and timestamps
- Internally calculated informational scores and explanations
3.3 Information collected automatically (limited)
We do not currently use third-party analytics tools (e.g., Google Analytics) for the mobile app. However, standard server and platform logs may collect limited technical data necessary to operate and secure the Service (e.g., IP address in server logs, request metadata, error logs).
3.4 Device permissions
- Camera: used to scan barcodes. We do not store your camera roll or photos because the current MVP does not upload product photos.
- We do not request location, contacts, or microphone access.
3.5 Food data from third-party databases
After you scan a barcode or search for an item, we retrieve publicly available product information from third-party databases. Food data may be cached in our backend to improve performance and availability.
4. How We Use Information
We use collected information to:
- Create and manage your account and sign-in
- Store your goals/preferences and scan history
- Retrieve and display Food Data from public databases
- Compute and display informational scores, positives, negatives, and explanations
- Maintain, secure, debug, and improve the Service
AI-generated notes (coach notes)
The Service may generate short explanatory "coach notes" using AI (e.g., OpenAI) to summarize why certain attributes are highlighted. These notes are informational summaries and may be simplified for clarity.
5. Legal Bases for Processing (GDPR)
If you are in the European Economic Area (EEA) or where GDPR applies, we process Personal Data under one or more of the following legal bases:
- Performance of a contract: to provide the Service you request.
- Legitimate interests: to operate, secure, and improve the Service.
- Consent: where required (for example, if we introduce optional marketing).
- Legal obligation: where we must comply with applicable law.
6. How We Share Information
We do not sell your Personal Data. We may share information only as needed to operate the Service:
6.1 Third-party services
We use the following third-party services that may collect information:
RevenueCat
- Purpose: Subscription and payment processing
- Data shared: User identifier, purchase information, subscription status
- Privacy policy: https://www.revenuecat.com/privacy
Supabase
- Purpose: Backend database for storing onboarding responses and feedback
- Data shared: All onboarding information listed above, associated with your RevenueCat user ID
- Privacy policy: https://supabase.com/privacy
Sentry
- Purpose: Error tracking and performance monitoring
- Data shared: Error logs, device information, IP address, and user context
- Privacy policy: https://sentry.io/privacy/
PostHog
- Purpose: Product analytics and session recording
- Data shared: Usage patterns, user interactions, session replays, device information
- Privacy policy: https://posthog.com/privacy
Apple App Store / Google Play Store
- Purpose: Payment processing for subscriptions
- Data shared: Payment information, purchase history (handled directly by Apple/Google)
TikTok Pixel
- Purpose: Conversion tracking and advertising measurement
- Data shared: Device identifiers (IDFA on iOS when granted permission), app events (such as app installs, purchases, and custom events)
- Privacy policy: https://www.tiktok.com/legal/privacy-policy
- Opt-out: You can opt out of TikTok tracking through iOS App Tracking Transparency (ATT) settings by denying tracking permission when prompted or by going to Settings > Privacy & Security > Tracking on your iOS device
We share only the data necessary to provide the relevant functionality. For AI-generated notes, we aim to send de-identified inputs (e.g., product attributes and goal context) and avoid sending direct identifiers.
6.2 Legal compliance and protection
- We may disclose information if required by law or to protect rights, safety, and security.
6.3 Business transfers
- If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as permitted by law.
7. Third-Party Data Sources and Accuracy
The Service retrieves Food Data from public databases such as:
- OpenFoodFacts: https://world.openfoodfacts.org/
- USDA: https://www.usda.gov/
- DTU Food: https://www.food.dtu.dk/english/
- Public Health Agency of Canada: https://www.canada.ca/en/public-health.html
Food data is provided by third parties and may be incomplete, incorrect, or outdated. We do not modify Food Data at the source.
8. Data Retention
We retain Personal Data for as long as your Account is active and as necessary to provide the Service.
- Account data (email/name): retained while your account is active
- Goals/preferences and scan history: retained while your account is active, unless you delete it
- Cached Food Data: retained as needed for performance and availability
We may retain limited information longer if required for legal compliance, security, fraud prevention, or dispute resolution.
9. Your Privacy Rights
Depending on your jurisdiction (including GDPR in the EU and certain US state laws like CCPA/CPRA), you may have rights to:
- Access your personal information
- Correct inaccurate information
- Delete your information
- Export your information (data portability, where applicable)
- Object to or restrict certain processing (where applicable)
- Withdraw consent where processing is based on consent
You can exercise many of these rights through in-app controls. You can also contact us at jaroslabs@gmail.com.
10. Deleting Your Account and Data
You can delete your account and associated data from within the app. When you request deletion, we delete or anonymize personal data within a reasonable time, unless we must retain some information for legal or security purposes.
11. International Transfers
We currently host the Service in the EU only (Supabase). If we later use processors outside your country or the EU/EEA, we will implement appropriate safeguards (such as Standard Contractual Clauses where required) and update this Privacy Policy.
12. Security
We use reasonable administrative, technical, and organizational measures to protect information. No system is perfectly secure; you use the Service at your own risk.
13. Children's Privacy
The Service is not intended for children under 13 and is not designed for clinical or professional use. We do not knowingly collect personal information from children under 13.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated version in the app and update the effective date above. For material changes, we may provide additional notice within the app.
15. Contact
If you have questions, requests, or complaints related to privacy, contact:
- Email: jaroslabs@gmail.com