Privacy Policy
Last updated: July 12, 2026
KSHMR LLC ("we," "our," or "us") operates the Kairos application at yourkairos.io (the "Services"). This Privacy Policy describes how we collect, use, and protect your information.
1. Information We Collect
Account information. When you create an account, we collect a username, an email address, and a password. You may optionally enable two-factor authentication.
User-entered data. Morning ratings (energy, mood, focus on a 1–5 scale), notes, and contact records (people you track, interactions you log, close-friends selections) that you create within Kairos.
Health and fitness data.If you connect Apple Health (via the iOS app's HealthKit integration), we receive the daily rollups you authorize — typically sleep, heart-rate variability, recovery, steps, workouts, and respiratory data. WHOOP, Oura, Garmin, Fitbit, and Apple Watch users all route through the same Apple HealthKit pipeline. If you connect Strava, we receive your activity history (runs, rides, walks, swims). We do not sell, share, or use any of this data for advertising.
Calendar data. If you connect Google Calendar, we receive event metadata (titles, times, durations, locations, and conference links) for the calendars you authorize.
Financial data. If you connect a bank account via Plaid, we receive transactions, balances, account metadata, and recurring-subscription detections for the accounts you authorize. We do not sell or share this data, and we do not use it for credit decisions or advertising.
Device-sync data. If you use the optional Mac-only iPhone Sync feature, we receive metadata extracted from your local iPhone backup (such as messages, call history, photo metadata, and contacts) and store it in your account. This feature runs only on your own computer over a USB connection; the backup is not uploaded anywhere except to your own Kairos instance.
Device information. Basic technical information such as device type and operating system, used for diagnostics.
Diagnostic and security data. We record IP addresses on authentication events and admin actions for rate-limiting and audit-trail purposes.
AI-generated narratives (opt-in).If you opt into the Prose surface, aggregated summaries of your data and — for the Excerpt tile only — verbatim excerpts of your own past messages are sent to Anthropic (the makers of Claude) for narrative generation. Recap and Discover tiles send only aggregated numbers; Excerpt sends message text. Prose is off by default; you can enable or disable it at any time in Settings → Preferences → Prose. Anthropic's data-handling terms apply to any content sent while Prose is enabled.
2. How We Use Information
- To provide and improve the Services
- To authenticate you and secure your account
- To compute your personal analytics (mode characterization, change-point detection, pattern coupling) on your data alone, per-user
- To respond to your support requests
- To comply with legal obligations
3. Third-Party Integrations
Kairos integrates with third-party services that you explicitly authorize: Apple HealthKit, Strava, Google Calendar, Plaid (financial accounts), and Anthropic (Claude, for the opt-in Prose surface). Each integration is governed by the terms and privacy policy of the respective provider. You may revoke access at any time, both from within Kairos and from the provider's own settings.
Service providers. We also rely on passive service providers to operate the Services:
- Resend — transactional email (verification, password reset).
- Cloudflare Turnstile — CAPTCHA on the signup page.
- Better Stack — server-side log aggregation.
- Sentry — application error monitoring; personally identifying fields are scrubbed from error reports before submission.
- Nominatim / OpenStreetMap — reverse-geocodes GPS coordinates from your photo metadata into city / state / country.
- Open-Meteo — returns historical weather for GPS coordinates your photos were taken at.
4. Data Storage and Security
Your data is stored in a managed Postgres database operated on our behalf by a cloud infrastructure provider. We protect it with the following measures:
- All data is transmitted over TLS.
- Passwords are hashed using a memory-hard algorithm; session tokens are hashed before storage.
- Third-party integration tokens (bank connections, wearable and calendar OAuth refresh tokens, etc.) are encrypted at rest using AES-256-GCM authenticated encryption.
- Sensitive user-generated text — the message bodies and sender names from iPhone Sync, photo filenames, personal notes, transaction notes, and per-interaction notes on people you track — is also encrypted at rest with AES-256-GCM. Numeric metrics (sleep, heart rate, activity totals) and provider catalog data (song titles, artist names, merchant categories) are stored plaintext because they need to be aggregated for your personal analytics.
- Optional two-factor authentication is available for every account.
- Each user's data is isolated by a per-row tenant identifier; every query is scoped to the session user.
We use industry-standard practices to protect data, but no method of transmission or storage is 100% secure.
5. Data Sharing
We do not sell your personal information. We do not share your personal data with third parties except: (a) with service providers who help us operate the Services, (b) to comply with legal obligations, or (c) with your explicit consent.
6. Your Rights
You may access, export, correct, or delete your data at any time through the application or by contacting us. An export includes every table your account has written to, including all synced integration data, delivered as a single JSON file. Depending on your jurisdiction, you may have additional rights under GDPR, CCPA, or other applicable laws.
Retention. We retain your data until you delete your account, except for security-audit records, which are retained for up to two years.
7. Children's Privacy
The Services are not directed to children under 13, and we do not knowingly collect personal information from children under 13.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised "Last updated" date.
9. Contact
Questions about this Privacy Policy: [email protected]
KSHMR LLC, 28 Cinnamon Dr, Upper Saddle River, NJ 07458