Privacy
What Kintso processes — and what it does not.
This policy describes what the app actually does. It was written against the source code, not against a template.
Last updated: 24 August 2026 · Version 1.0
1 · Who is responsible
The controller for processing within the meaning of the General Data Protection Regulation is:
Europaring 90
53757 Sankt Augustin
Germany Email:
matthias@laffalu.com
Questions about the app: hello@kintso.care
A data protection officer has [[ not been appointed / been appointed: name, contact ]].
2 · In short
So you do not have to read to the end to know the important parts:
- We sell nothing on and run no advertising. Kintso is funded by a subscription.
- Your words stay between you. What you write goes to nobody outside your couple — not to the AI companion, not to usage statistics, not to advertising networks.
- The main store sits in the European Union. Four services outside the EU receive precisely bounded parts; which ones is in sections 5 and 6.
- There is no end-to-end encryption. We write that down because other apps make the opposite claim in this spot. What there is instead is in section 14.
- Error reports run independently of consent, because the app could not otherwise be kept stable. What travels with them is in section 8 — unsoftened.
3 · What data arises
Account
Email address and password — or, if you sign in with Apple or Google, the identifier that service returns to us. Plus a first name (freely chosen, a nickname is fine), an optional profile picture, your time zone and your settings.
The connection between two people
An invite code and, once you are connected, the pairing of your two accounts. From then on you both see the same shared content.
What you do in the app
Daily check-in values (two sliders and an optional keyword), answers to questions, contributions to a guided conversation with an optional feeling mark, voice messages, entries in the solo journal, reflections after a pause, essence answers, planted practices, shared evenings and anniversaries.
This content is the heart of the app. Some of it is personal and sensitive — statements about mood, closeness and conflict can allow inferences about health and sex life. We treat it accordingly: it does not leave your couple.
Crisis features
When one of you starts a shared pause, an entry with time, duration and status is created so that both devices show the same state. The reflections afterwards belong to the content above.
Purchase
Whether a subscription is active and until when. Payment itself runs through the App Store or Google Play — we see neither your payment details nor your billing address.
Technical
Device identifier for notifications, app version, timestamps, error data. We keep no access log with IP addresses for profiling.
4 · On what legal basis
- Contract (Art. 6(1)(b) GDPR) — for everything the app cannot work without: account, pairing, your content, notifications about events in your couple, subscription status.
- Consent (Art. 6(1)(a) GDPR) — for the AI companion Kumo and for every additional category it may see. Both require a yes from both partners and can be withdrawn at any time.
- Legitimate interest (Art. 6(1)(f) GDPR) — for error reports and operation. Our interest is an app that does not crash; we balance it against yours by keeping content out of error reports.
- Special categories (Art. 9 GDPR) — insofar as your entries contain information about health or sex life, we process it on the basis of your explicit consent under Art. 9(2)(a) GDPR, which you give by using the relevant feature. The intimate question areas additionally open only once both partners explicitly agree.
5 · Who else receives something
This list is exhaustive. Everyone named is contractually bound and may not use the data for their own purposes.
| Service | What goes there | Where | Basis |
|---|---|---|---|
| Supabase | The main store: account, pairing, all content, voice messages, profile pictures. Also the sending of sign-in and password emails. | EU | Contract |
| Expo | The delivery service for notifications: the device identifier and the text of the message. See section 10 — it also says what such a message can contain. | USA | Contract |
| Apple · Google | The last stretch of every notification runs through the operating system's push service. In addition, depending on your choice: signing in with Apple or Google, and handling the subscription. | USA | Contract |
| Anthropic | Only with the AI companion switched on: a handful of monthly figures, no names and no text. The full list is in section 7. | USA | Consent |
| Sentry | Error and crash reports including technical identifiers. See section 8. | see section 6 | Legitimate interest |
| RevenueCat | Subscription management: a device identifier, from sign-in your user identifier, plus purchase and expiry data. No payment details. | USA | Contract |
| PostHog | Usage statistics. The app currently sends nothing there — see section 9. | EU | Consent |
Authorities receive data only where we are legally obliged. There is no disclosure to advertising networks, data brokers or analytics providers beyond this list.
6 · Transfers outside the EU
Four of the services named are based in the United States. For those transfers we rely on the European Commission's Standard Contractual Clauses under Art. 46(2)(c) GDPR, insofar as the provider is not already certified under the EU-US Data Privacy Framework.
US law permits authorities access to data held by providers there under certain conditions. A level of protection fully equivalent to the European one therefore cannot be guaranteed. That is precisely why we keep the amount that leaves at all small: no text goes to the AI companion, and error reports contain no content.
7 · The AI companion Kumo
Kumo is optional and off by default. Once a month it writes a short companion text for your shared chronicle.
The following paragraph matches the wording in the app:
If you both explicitly consent, Kintso creates a short companion text once a month (a "monthly chapter") for your shared chronicle. For this we transmit only aggregated monthly values of your couple to our processor Anthropic PBC (USA): month and year, the number and average values of your check-ins, the number of your echo dialogues, the smoothed monthly reading of your chronicle and the kind of anniversaries falling in that month. Never transmitted: your words and messages, the solo journal, your essence answers, crisis and timeout data, or your names. The legal basis is your consent (Art. 6(1)(a) GDPR); it is voluntary and can be withdrawn in the app at any time — after withdrawal no new chapters are created; chapters already created remain part of your shared chronicle. The transfer to the USA takes place on the basis of the EU Standard Contractual Clauses.
Anthropic does not store the transmitted data permanently, except where legally required or for misuse review; otherwise it is deleted within 30 days and is not used to train AI models.
Further categories (such as the emotional colouring of your echo moments) are transmitted only if you both release them individually in the app; a withdrawal takes effect from the next chapter — chapters already created remain part of your chronicle.
No automated decision-making within the meaning of Art. 22 GDPR takes place. Kumo is a companion and does not replace therapy or professional advice.
Two additions that the app leaves out for space:
- Where the text above says "average values", what we actually transmit are rounded classes ("quiet", "in flow", "full") rather than numbers. In months that asked a lot of you, they are omitted entirely.
- Withdrawal takes effect from the next chapter. Chapters already written stay in your chronicle because they belong to you — you can remove them by deleting your account or on request.
8 · Error reports
When the app hits an error, it sends a report to our processor Sentry. Without such reports, an app running on thousands of different devices could not be kept stable.
These reports run independently of consent. We base them on our legitimate interest in operating the service. You can object under Art. 21 GDPR — write to us and we will arrange it.
A report contains: the error message, the point in the program where it occurred, information about the device and app version, and technical identifiers. In individual cases that includes your user identifier — a random string that leads us to your account.
Your content is not part of it. Words, messages, journal entries, check-in values and voice messages are not placed into error reports; the app maintains a dedicated filter for that.
No measurement of program run times takes place: the corresponding sampling rate is set to zero.
9 · Usage statistics
The app currently sends no usage events. The feature is built and switched off — no connection is opened and no device identifier is created for it.
If we switch it on, it will be like this: through the provider PostHog with processing in the European Union, only with your prior consent, and only with the information that something happened — never what. So, for example, "a check-in was submitted", but never the values inside it. We will ask you first and change this policy first.
Separately from that, our server monitoring reports technical operating states to the same provider — with no reference to any person, only information about the state of our own systems.
10 · Notifications on your phone
You receive notifications only if you have allowed them in your operating system. The route runs through Expo and from there through Apple's or Google's push service.
Please be clear about one thing when you decide: a notification is not confidential on this route. It appears on your lock screen and passes the services named on its way. What it contains:
- your partner's first name in the heading, as entered in the app;
- a fixed text block — never your own words. Some of these blocks do say something about the situation, though: that a shared pause is running, that a conversation sheet for couples therapy has been requested, or that a more intimate question area is awaiting release.
If that is too much, there are two routes: switch notifications off entirely in the operating system, or set your phone so that previews appear only when the device is unlocked.
You can set quiet hours in the app. One exception is deliberate: the notification about a shared pause reaches you even then — it is the case quiet hours are not meant for.
11 · How long we keep things
- Account and content — as long as your account exists.
- After a separation, a relationship archive stays reachable for the remaining partner for 30 days, after which access falls away.
- For the AI companion, Anthropic deletes the transmitted values within 30 days under contract.
- Error reports are deleted after the retention period configured at the provider.
- Billing-relevant records are kept as long as commercial and tax law requires.
12 · Deleting — and what it means
You can delete your account in the app. Here is what happens, described precisely, because "delete" does not mean the same thing everywhere:
- Your account is removed, your profile anonymised, your profile picture and your voice messages deleted.
- Your pairing is dissolved. Your partner keeps access to the shared archive for 30 days.
- What you wrote together remains — contributions to a guided conversation, answers to shared questions, the monthly chapters. Those entries are also your partner's data, and their conversation would become incomplete if they were removed. If you want those gone as well, write to us; we will weigh it case by case against the other person's rights.
- At RevenueCat a subscription record with your identifier remains — today we do not trigger a deletion there. If you want that, write to us and we will do it by hand until the route is automatic.
- The farewell note your partner sees carries your first name. Otherwise it would read "Deleted user", and that is a hard ending for someone who has just been left.
13 · Your rights
Under the GDPR you can ask us for:
- Access (Art. 15) to everything we process about you. The app includes a self-export that produces your data as a file.
- Rectification (Art. 16) of inaccurate details.
- Erasure (Art. 17) — see section 12.
- Restriction (Art. 18) of processing.
- Portability (Art. 20) in a common format.
- Objection (Art. 21) to processing based on legitimate interest — in particular to error reports.
- Withdrawal of consent (Art. 7(3)) at any time, with effect for the future.
Write to the address in the legal notice. You also have the right to lodge a complaint with a data protection supervisory authority — either the one where you live or the one responsible for our registered office.
14 · Security
What we do:
- Every connection between app and server is encrypted in transit (TLS).
- On your device, data is stored encrypted (AES-256); the key is generated once on the device and kept in the operating system's keychain.
- On the server, every row is bound to your couple. The database enforces this itself, not the app — another couple cannot technically retrieve your rows.
- Voice messages sit in protected storage that requires a valid sign-in.
What we do not do, so that you do not assume it:
- There is no end-to-end encryption. Your content sits readable on the server. We do not look at it in normal operation — but technically we could, which is why we say so.
- Profile pictures and uploaded files sit in non-public storage. They are served only through short-lived signed addresses valid for one hour; without a sign-in, and without belonging to the couple in question, the storage hands out nothing.
15 · Age
Kintso is intended for adults. Use requires a minimum age of 18. We do not actively collect age; if we learn that an account belongs to a minor, we delete it.
16 · Changes
When what we process changes, this policy changes with it. The date above tells you which version you are reading. For changes that concern consent, we ask you in the app beforehand — silence does not count as agreement with us.
A word on the honesty of this text. It was written against the app's source code: for every sentence above there is a place in the program that carries it. Where something works differently from what you might assume — with error reports, with notifications, with deletion — it is stated here rather than left out. If you find a discrepancy, write to us and we will correct it.