Legal
Privacy Policy
Last updated: September 2, 2026
Effective date: September 2, 2026.
Kwilt Labs LLC ("Kwilt", "we", "us", or "our") provides the Kwilt mobile app (the App), our websites, and related cloud services, including kwilt.app, go.kwilt.app, and other Kwilt-operated domains (together, the Service). This Privacy Policy explains what information the Service handles, why it is used, when it leaves your device, who may process it, and the choices available to you.
This Policy is part of our Terms of Service.
At a glance
- A Kwilt account is required for ordinary use of the current App.
- Some device state remains local, but Kwilt is not device-only. Sign-in, sync, sharing, Money, Explore, Meals, remote Games, durable Chat, AI, providers, analytics, subscriptions, and support use network services.
- Your capability data is private by default. It becomes visible to another person or service only through an action such as sharing, joining a Household or game room, connecting a provider, or publishing.
- We do not sell personal information or use it for cross-context behavioral advertising.
- Apple Family Controls app/category tokens, Face ID or Touch ID results, and source records in Apple Health stay under Apple's or your device's control unless this Policy says a derived summary is synced.
1. Scope and key terms
- Kwilt account: the identity used to sign in to and sync with Kwilt.
- Household: a Kwilt roster with roles, memberships, invitations, and capability-specific permissions. Household membership does not give blanket access to another person's private data.
- Dependent profile: a profile created and managed by an adult for bounded Household participation. It is not permission for a child under 13 to create or control a Kwilt account.
- Connected provider: a third-party service you authorize or open from Kwilt, such as a bank-data, calendar, retailer, AI, or connected-tool provider.
- AI service: Kwilt's AI endpoints and the model providers they call to process a request.
2. On-device, Kwilt cloud, and provider processing
Kwilt keeps some drafts, caches, settings, permission state, notifications, Focus state, and other working data on your device. The current App also requires an account and uses Kwilt cloud services for core identity and for many synchronization and service features.
An optional feature may send data only after you use that feature, grant a device permission, connect a provider, choose content, or approve a share. Other operational data—such as account identifiers, security records, app/version information, and service diagnostics—may be processed whenever needed to authenticate, secure, deliver, or maintain the Service.
3. Information we collect and process
The information Kwilt handles depends on the capabilities and providers you use.
- Account, contact, and profile. User and person IDs, email address, display name, avatar, authentication provider, account status, preferences, coaching context, and profile summaries.
- Planning, Focus, Chapters, and Chat. Arcs, Goals, Activities and To-dos, notes, steps, tags, schedules, reminders, Focus sessions, Chapters, messages, check-ins, replies, reactions, AI proposals, approvals, action receipts, and related history.
- Attachments, images, documents, and audio. Photos, videos, files, scans, audio recordings, filenames, types, sizes, timestamps, storage locations, and sharing settings that you choose to upload or use with a feature.
- AI and voice. Prompts, selected Kwilt context, images, audio, transcripts, model output, tool calls, approved actions, usage, latency, and status information.
- Money. Plaid connection and institution identifiers; account name, type, mask, and balances; transaction dates, amounts, merchants, descriptions, and categories; budgets, allocations, rules, forecasts, corrections, receipts, and related Screen Time rule intent. Kwilt does not receive your bank login credentials from Plaid Link and does not receive payment-card details for App Store purchases.
- Explore and Places. Approximate or precise coordinates, timestamps, accuracy, speed, course, recorded paths, visits, places, placemarks, explored areas, recaps, search requests, and recording preferences when you use those features.
- Recipes, cooking, Meals, and dietary needs. Recipe titles, ingredients, instructions, notes, source URLs and credits, provenance, photos, scans, text or voice imports, cook sessions, meal plans, diners, choices, reactions, ingredient avoidances, and dietary labels you provide.
- Groceries and retailer connections. Grocery lists and corrections, product and store searches, ZIP code or location used for a search, prices and offers, selected products and quantities, retailer account and OAuth information, cart handoff state, and user-reported checkout or receipt state. Retailers control final products, substitutions, delivery or pickup, payment, and checkout.
- Games. Player names and profiles, local guest seats, room and invitation state, moves, scores, personal bests, submissions, votes, game content, and nearby private-table discovery state.
- Household, dependents, and Screen Time. Household name, people and display names, adult/dependent kind, roles, memberships, invitations, capability grants, requests, operations, audit events, enrolled-device state, and rule intent. Apple Family Controls application and category tokens stay on the configured device and are not collected by Kwilt.
- Calendar and reminders. Connected account ID or email, provider tokens, calendar IDs and names, availability, event IDs, times, and event details selected for scheduling, plus content included in an
.icsexport. Apple Calendar and Reminders access may remain on-device; Google or Microsoft connections use their cloud services. - Apple Health. Permission state and authorized summaries such as movement, workouts, sleep, mindfulness, steps, active days, and active minutes. Source records remain in Apple Health. Kwilt does not use Health information for advertising, marketing, or data mining.
- Phone Agent and communications. Phone number, verification and link state, inbound and outbound SMS, prompts, message and delivery state, action history, relationship or memory records used by that feature, support messages, and email preferences and delivery events.
- Subscriptions. RevenueCat customer or app-user ID, product, entitlement, purchase, restore, trial, renewal, expiration, and refund state. Apple processes App Store payment information.
- Identifiers, usage, and diagnostics. Supabase user/person/Household IDs, install ID, analytics distinct ID, push token, app/build/device metadata, coarse feature and notification events, provider status, timestamps, latency, errors, logs, and security or abuse-prevention records.
- Website, search, and link data. Search terms sent to an image, GIF, recipe, retailer, map, or geocoding provider; invite, referral, or affiliate codes; IP address; user agent; timestamps; and requested URLs in website or provider logs.
- Connected AI tools. OAuth consent, scopes, tokens, connection state, action history, object IDs, idempotency hashes, compact Kwilt summaries, and changes you explicitly authorize a connected tool to make.
4. Why we use information
We use information to:
- authenticate accounts, sync state, and provide the capabilities you choose;
- personalize planning, summaries, suggestions, and AI responses;
- operate private sharing, Households, invitations, multiplayer rooms, and connected tools;
- connect to authorized financial, calendar, retailer, communication, and other providers;
- process subscription entitlement and purchase lifecycle state;
- deliver notifications, transactional messages, opted-in product communications, and support;
- measure product performance and reliability with bounded analytics and diagnostics;
- secure the Service, enforce quotas, prevent abuse and fraud, and investigate incidents; and
- comply with law, enforce our Terms, and protect Kwilt, our users, and others.
5. Providers and other services
Depending on the feature, Kwilt uses the following processors or connects you to an independent service. A provider may independently handle information under its own terms when you sign in to, authorize, or leave Kwilt for that provider.
- Supabase for authentication, database, storage, Realtime, Edge Functions, and operational logs.
- OpenAI for selected text, image, audio, transcription, speech, and Realtime AI processing.
- Plaid for bank-data connection and Transactions information.
- PostHog for privacy-minimized product analytics and feature configuration.
- RevenueCat for subscription entitlement and purchase lifecycle management; Apple processes App Store purchases.
- Apple for Sign in with Apple, push delivery, HealthKit, Calendar/Reminders, maps or geocoding, and Family Controls; Google for sign-in and optional Calendar; and Microsoft for optional Outlook/Calendar connections.
- Kroger/Smith's for authorized store, product, and cart features; Instacart for an optional shopping handoff when enabled; and Amazon or other retailers for user-selected external or affiliate shopping links.
- Resend for transactional and opted-in product email; Twilio for optional Phone Agent verification and SMS; and Expo and Apple push services for push delivery.
- Unsplash for optional image search and GIPHY for optional celebration GIF search.
- OpenStreetMap/Nominatim, OpenStreetMap.de, and Wikimedia Maps for selected geocoding, static-map images, or map tiles.
6. AI, voice, and connected-tool processing
When you use an AI feature, Kwilt sends the prompt or media you submit and the bounded context needed for that request to a Kwilt AI endpoint, which normally uses Supabase infrastructure to call OpenAI. Context may include selected planning records, profile summaries, financial/category evidence, recipe content, an attachment, or other information identified by the feature before you act.
Live conversation may use a short-lived credential to create a direct encrypted connection between your device and OpenAI's Realtime service. Durable Chat messages, approved actions, and receipts may remain in Kwilt's systems even when provider audio or request processing is transient.
Kwilt does not use your content to train its own general-purpose models. When a business/API provider offers a control preventing training on submitted content, Kwilt configures that provider not to train on it. We may retain bounded usage, status, safety, and reliability information as described in this Policy.
A connected AI tool receives only the scopes and information authorized for that connection. A write-capable tool may create, update, complete, or delete supported Kwilt records after the required user review. You can revoke a connected tool from Kwilt's connection settings where supported.
7. Location and Explore
Explore can use foreground location for a place search, map, or recording you start. If you turn on Automatic Exploring and grant background access, the App may continue recording walks, drives, errands, or trips while the App is not open. Location history is private by default and does not automatically become a family-location feed.
You can stop a recording, turn off Automatic Exploring, or change location access in device Settings. Location may be sent to Kwilt for signed-in synchronization and to Apple or selected map/geocoding providers to render or identify places.
8. Money and connected financial accounts
When you choose to connect an account, Plaid Link handles your financial-institution authentication. Kwilt receives the resulting connection, account, balance, and transaction information needed to provide Money. Financial information is not visible to Household members by default.
A Money privacy-lock preference and the result of Face ID or Touch ID authentication stay on the device. Display-safe widget summaries may be placed in an Apple app group for Kwilt's widgets. Apple Family Controls selections used by a Screen Time rule remain on the configured device.
9. Sharing, Households, Games, and publication
Kwilt capability data is private by default. Another person can see data only when the product's sharing or authority rules allow it—for example, after an explicit Goal or attachment share, a Household role and capability grant, participation in a meal plan or game room, or a recipe publication.
Household membership does not provide blanket access to another member's Money, Explore history, Chat, Recipes, Calendar, Health, or other private capability data. Local game guests are not automatically turned into Kwilt accounts or Household members.
Shared or published records may remain available to other authorized participants after you leave or delete your account when needed to preserve their legitimate experience. Where appropriate, Kwilt removes or de-identifies your personal association with retained shared records.
10. Analytics and diagnostics
Kwilt uses PostHog and operational logs to understand feature use, performance, delivery, and reliability. Analytics may begin when the App opens and may use an install-scoped identifier. After sign-in, selected events may be associated with your Kwilt user ID.
Kwilt's analytics policy excludes intentionally sending user-entered free-form text, financial transaction content or amounts, precise location or paths, Health data, Apple Family Controls tokens, calendar event content, recipe or grocery text, Chat content, and game submissions. We do not use analytics for personalized advertising or cross-context tracking.
If your App version offers an analytics choice in Settings, that control applies to future optional product analytics. You may also contact support@kwilt.app to object to analytics processing or request deletion of analytics-linked information where applicable. Security, fraud-prevention, transactional, and essential service records may still be processed when needed to operate and protect the Service.
11. How we disclose information
We do not sell personal information. We disclose information only in these circumstances:
- At your direction. To a person, Household, room, provider, retailer, connected tool, or public audience you choose.
- Service providers. To the processors above as needed to provide, secure, and support the Service under applicable contractual protections.
- Legal and safety. When required by law or reasonably necessary to protect rights, safety, security, prevent fraud, or investigate abuse.
- Business changes. As part of a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable law and appropriate safeguards.
12. Retention and deletion
We retain information only while reasonably needed to provide the feature, maintain shared records, administer subscriptions, meet legal obligations, resolve disputes, protect security, and prevent abuse. Retention varies by the kind of record and the provider involved.
- Device data. Account-scoped caches are cleared where the App supports it. Uninstalling the App removes its ordinary local storage, but does not delete cloud records or data controlled by another provider.
- Account and private content. The App provides an account-deletion action in Settings. A successful request removes the Kwilt authentication identity and Kwilt-controlled private records that are not required to be retained. If the request fails, the App reports the failure and the account remains until deletion succeeds.
- Connected providers. You can use the disconnect or revoke controls available in Kwilt or through the provider. Deleting a Kwilt account does not guarantee deletion of provider-controlled records such as bank, calendar, retailer order, App Store purchase, email/SMS delivery, or security records. Contact or disconnect directly with the provider when needed.
- Shared records. Content needed by another authorized participant may remain in de-identified form or under transferred adult stewardship. A dependent does not become a Household owner merely because an adult deletes an account.
- Logs, fraud/security records, and backups. Limited operational records may remain for legal, security, delivery, and fraud-prevention purposes. Deleted data may persist temporarily in protected backups until those backups are overwritten under normal schedules.
- Subscriptions. Deleting a Kwilt account does not cancel an Apple-managed subscription. Manage or cancel it through Apple.
13. Your privacy choices and controls
- Device permissions. Control photos, camera, microphone, location, Calendar, Reminders, Apple Health, local network, notifications, Face ID/Touch ID, and Family Controls through the relevant feature and device Settings.
- Optional features. Avoid optional AI, voice, Explore recording, Health, Calendar, retailer, Phone Agent, or connected-tool processing by not enabling or using that feature.
- Connections and sharing. Disconnect supported providers, revoke connected tools and invitations, leave shared experiences where allowed, and change sharing settings in the App or provider.
- Account deletion. Use Settings > Account settings > Delete account. Apple subscription cancellation remains separate.
- Privacy requests. Contact
support@kwilt.appto request access, correction, deletion, portability, or another applicable privacy right. We may verify your identity before acting.
14. Children and dependent profiles
A person under 13 may not create or control a Kwilt account. An adult account holder may create a parent-managed dependent profile and enable bounded Household capabilities for that dependent. A person between 13 and the age of majority where they live may use a Kwilt account only with parent or guardian consent.
Adults are responsible for the dependent information they provide, capability grants, invitations, device setup, and appropriate supervision. If you believe a child's information was collected contrary to this Policy, contact support@kwilt.app.
15. Regional disclosures and rights
Depending on where you live, you may have rights to access, correct, delete, port, restrict, or object to processing of personal information and to withdraw consent where processing relies on consent. Kwilt may process information to perform a contract, with consent, to comply with law, or for legitimate interests such as security and service reliability, as permitted where you live.
We do not sell personal information or share it for cross-context behavioral advertising. California residents and authorized agents may submit applicable requests through support@kwilt.app.
16. Security
Kwilt uses safeguards designed to protect information, including encrypted network transport, authentication, authorization rules, scoped provider credentials, and access controls. No transmission or storage system is perfectly secure, and we cannot guarantee absolute security.
17. International processing
Kwilt is operated from the United States. Information may be processed in the United States and other places where Kwilt or its providers operate. Where required, we use safeguards intended to support lawful international transfers.
18. Changes and contact
We may update this Policy as Kwilt, our providers, or legal requirements change. We will update the date above and provide additional notice when required.
Questions or privacy requests: support@kwilt.app.