LEGAL

Privacy Policy

Kairo is privacy-first by construction, not just by policy. Your raw health data never leaves your iPhone.

Last updated: June 28, 2026

The short version

Kairo reads your health and calendar data on your device to estimate your circadian rhythm and suggest better timing for your day. Raw biometric data (sleep, heart rate, HRV) is processed on-device and is never uploaded to our servers, sold, or used for advertising. The cloud is never in the loop for a recommendation.

Data Kairo accesses

  • Apple Health (HealthKit) — sleep timing, heart rate, heart-rate variability and related signals, read only with your explicit permission and used to estimate your circadian phase.
  • Calendar (EventKit) — read for free/busy times only, to plan around your existing events. Kairo writes a proposed block only after you confirm it, and never moves or deletes events you already have.
  • Approximate location — optional, used coarsely for sunrise/sunset and time-zone (jet-lag) so light timing matches your day. Precise location is not required.
  • Account & subscription — if you create an account or subscribe, we process an identifier and your subscription status (via Apple) so your settings sync and Pro features unlock.

How your data is processed

The circadian engine and personalization run locally on your iPhone. Raw HealthKit samples are reduced on-device to small summaries that feed the engine and are not transmitted. If you enable cross-device sync, only an encrypted blob of model parameters and preferences is stored — never raw biometric streams. We cannot read it.

What we do not do

  • We do not sell your data, ever.
  • We do not use health data for advertising.
  • We do not upload raw sleep, heart-rate or HRV data.

Third parties

We rely on Apple for app distribution, in-app purchases and (optionally) Sign in with Apple. Apple processes your purchase and account data under its own privacy policy. We do not share your data with advertisers or data brokers.

Cookies & tracking

This website sets no cookies and uses no third-party analytics or advertising trackers. Fonts are self-hosted and nothing here profiles you — so there is no cookie banner to click through. If we ever add privacy-friendly, cookieless analytics, we will note it here.

Your rights

You can revoke Health, Calendar or Location permissions at any time in iOS Settings. You can request access to, export of, or deletion of any account data we hold by emailing ab@digitalflow.agency. Deleting the app removes on-device data from your phone.

Children

Kairo is not directed to children under 13, and we do not knowingly collect their data.

Changes

We may update this policy as the product evolves. Material changes will be reflected here with a new “last updated” date.

Who we are & contact

Kairo is operated by Digital Flow Pte. Ltd. (UEN 202350828Z), 68 Circular Road, #02-01, Singapore 049422. We are the data controller for the limited account data described above. Questions about privacy? Email ab@digitalflow.agency.

Not medical advice. Kairo estimates circadian timing; it does not diagnose or treat sleep disorders.