Privacy Policy

KindaOkay — Effective date: December 22, 2025

This Privacy Policy explains how KindaOkay ("we", "us", "our") collects, uses, stores, and shares information when you use the KindaOkay mobile application and its related services (the "Service"). By using the Service, you agree to the practices described in this Privacy Policy.

1. What the Service Does (Informational Only)

KindaOkay is an informational food analysis and decision-support tool. It lets you scan product barcodes or search for products and receive insights about product composition and characteristics.

The Service may display nutritional values (e.g., sugar, fat, salt), ingredient-related flags (e.g., allergens, additives, palm oil), and processing indicators (e.g., ultra-processed food index). It may also calculate an internal informational score based on the goals you select.

Important disclaimer:

  • The Service does not provide medical advice, diagnoses, or treatment recommendations.
  • Outputs are informational only and may be incomplete or inaccurate due to limitations of third-party data sources.
  • You remain responsible for your food choices and decisions.

2. Interpretation and Definitions

Account

A profile created to access the Service.

Application

The mobile application titled "KindaOkay".

Service

The Application and related backend services operated by the Owner.

Owner / We / Us / Our

An individual operator located in the Czech Republic.

Device

Any device used to access the Service.

Personal Data

Information that identifies or can reasonably be linked to an individual (e.g., email).

Usage Data

Data collected automatically through use of the Service (e.g., logs, diagnostics).

Food Data

Product and nutrition information retrieved from public third-party databases.

Goals / Preferences

User-selected settings used to present information and compute an informational score.

3. Information We Collect

3.1 Information you provide

  • Email address
  • Name (as provided by your sign-in provider)
  • Goals and preferences (e.g., skin health, digestion, general awareness)

3.2 Barcode scans and history

  • Barcodes you scan
  • Scan history and timestamps
  • Internally calculated informational scores and explanations

3.3 Information collected automatically (limited)

We do not currently use third-party analytics tools (e.g., Google Analytics) for the mobile app. However, standard server and platform logs may collect limited technical data necessary to operate and secure the Service (e.g., IP address in server logs, request metadata, error logs).

3.4 Device permissions

  • Camera: used to scan barcodes. We do not store your camera roll or photos because the current MVP does not upload product photos.
  • We do not request location, contacts, or microphone access.

3.5 Food data from third-party databases

After you scan a barcode or search for an item, we retrieve publicly available product information from third-party databases. Food data may be cached in our backend to improve performance and availability.

4. How We Use Information

We use collected information to:

  • Create and manage your account and sign-in
  • Store your goals/preferences and scan history
  • Retrieve and display Food Data from public databases
  • Compute and display informational scores, positives, negatives, and explanations
  • Maintain, secure, debug, and improve the Service

AI-generated notes (coach notes)

The Service may generate short explanatory "coach notes" using AI (e.g., OpenAI) to summarize why certain attributes are highlighted. These notes are informational summaries and may be simplified for clarity.

5. Legal Bases for Processing (GDPR)

If you are in the European Economic Area (EEA) or where GDPR applies, we process Personal Data under one or more of the following legal bases:

  • Performance of a contract: to provide the Service you request.
  • Legitimate interests: to operate, secure, and improve the Service.
  • Consent: where required (for example, if we introduce optional marketing).
  • Legal obligation: where we must comply with applicable law.

6. How We Share Information

We do not sell your Personal Data. We may share information only as needed to operate the Service:

6.1 Third-party services

We use the following third-party services that may collect information:

RevenueCat

Supabase

  • Purpose: Backend database for storing onboarding responses and feedback
  • Data shared: All onboarding information listed above, associated with your RevenueCat user ID
  • Privacy policy: https://supabase.com/privacy

Sentry

  • Purpose: Error tracking and performance monitoring
  • Data shared: Error logs, device information, IP address, and user context
  • Privacy policy: https://sentry.io/privacy/

PostHog

  • Purpose: Product analytics and session recording
  • Data shared: Usage patterns, user interactions, session replays, device information
  • Privacy policy: https://posthog.com/privacy

Apple App Store / Google Play Store

  • Purpose: Payment processing for subscriptions
  • Data shared: Payment information, purchase history (handled directly by Apple/Google)

TikTok Pixel

  • Purpose: Conversion tracking and advertising measurement
  • Data shared: Device identifiers (IDFA on iOS when granted permission), app events (such as app installs, purchases, and custom events)
  • Privacy policy: https://www.tiktok.com/legal/privacy-policy
  • Opt-out: You can opt out of TikTok tracking through iOS App Tracking Transparency (ATT) settings by denying tracking permission when prompted or by going to Settings > Privacy & Security > Tracking on your iOS device

We share only the data necessary to provide the relevant functionality. For AI-generated notes, we aim to send de-identified inputs (e.g., product attributes and goal context) and avoid sending direct identifiers.

6.2 Legal compliance and protection

  • We may disclose information if required by law or to protect rights, safety, and security.

6.3 Business transfers

  • If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as permitted by law.

7. Third-Party Data Sources and Accuracy

The Service retrieves Food Data from public databases such as:

Food data is provided by third parties and may be incomplete, incorrect, or outdated. We do not modify Food Data at the source.

8. Data Retention

We retain Personal Data for as long as your Account is active and as necessary to provide the Service.

  • Account data (email/name): retained while your account is active
  • Goals/preferences and scan history: retained while your account is active, unless you delete it
  • Cached Food Data: retained as needed for performance and availability

We may retain limited information longer if required for legal compliance, security, fraud prevention, or dispute resolution.

9. Your Privacy Rights

Depending on your jurisdiction (including GDPR in the EU and certain US state laws like CCPA/CPRA), you may have rights to:

  • Access your personal information
  • Correct inaccurate information
  • Delete your information
  • Export your information (data portability, where applicable)
  • Object to or restrict certain processing (where applicable)
  • Withdraw consent where processing is based on consent

You can exercise many of these rights through in-app controls. You can also contact us at jaroslabs@gmail.com.

10. Deleting Your Account and Data

You can delete your account and associated data from within the app. When you request deletion, we delete or anonymize personal data within a reasonable time, unless we must retain some information for legal or security purposes.

11. International Transfers

We currently host the Service in the EU only (Supabase). If we later use processors outside your country or the EU/EEA, we will implement appropriate safeguards (such as Standard Contractual Clauses where required) and update this Privacy Policy.

12. Security

We use reasonable administrative, technical, and organizational measures to protect information. No system is perfectly secure; you use the Service at your own risk.

13. Children's Privacy

The Service is not intended for children under 13 and is not designed for clinical or professional use. We do not knowingly collect personal information from children under 13.

14. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version in the app and update the effective date above. For material changes, we may provide additional notice within the app.

15. Contact

If you have questions, requests, or complaints related to privacy, contact: