Privacy Policy
Effective date: August 20, 2026
Last updated: September 7, 2026
This Privacy Policy describes how Kurozu ("we," "us," or "our") collects, uses, and shares information when you use the Kurozu mobile application for iOS (the "App").
By using the App, creating a cloud account, or using cloud-connected features, you acknowledge this Policy. The App is local-first: you can build and use timelines on your device without signing in.
Contact: support@kurozu.app
1. Summary
- Local-first by default. Core timeline features work offline without an account. Local-only data stays on your device unless you move it to the cloud, use a cloud feature, or copy/export it elsewhere.
- Cloud is optional. Signing in with Google, Apple, or email and password enables cloud timelines, Premium, and account features.
- AI requires permission. Before enabling AI, we ask for affirmative permission to send the data described in Section 3.3 to OpenAI, Google Cloud Vertex AI, and, when web search is used, Perplexity. You may decline and continue using non-AI features.
- No sale or advertising tracking. We do not sell personal information or use it for cross-app advertising.
- No model training by Kurozu. We do not train our own AI models on your content. We use business/API services whose applicable terms state that customer content is not used to train their models without customer authorization, and we do not opt in to such training.
- Diagnostics and analytics. The iOS App uses Firebase Crashlytics for crash reporting and Firebase Analytics (Google) for privacy-conscious product analytics. These tools are configured not to receive your timeline text, health records from Apple Health, or similar sensitive content.
- Account deletion lets you request deletion of the cloud content described below from our active systems. Local timelines on your device are not deleted by that action. Some anonymized account, purchase, usage, security, and accounting records are retained where necessary.
2. Scope
This Policy applies to the iOS App and the cloud services used by that App. It does not govern third-party websites you open, apps or services into which you paste exported text, or services we do not operate. Our use of service providers to operate the App is described in Section 7.
The App may be distributed under a display name configured at build time (for example, "Timeline" or "Kurozu"). References to "the App" mean the Kurozu iOS application regardless of icon label.
3. Information you provide
3.1 Timeline and fact content
You may create timelines and facts, including titles, descriptions, tags, time expressions, and fact-type labels.
| Mode | Where it is stored | Transmitted to us |
|---|---|---|
| Local-only | On your device (SQLite) | No, unless you use cloud features or copy/export it elsewhere |
| Cloud-synced | On your device (cache) and our servers | Yes — when you create, edit, sync, or delete cloud timelines |
You choose what to enter. Content may include health-related or other sensitive information if you type it.
3.2 Account and authentication
Cloud accounts use Google Sign-In, Sign in with Apple, or email and password. If you sign in, we process:
- Email address, including an Apple private-relay address if selected
- Authentication identifiers, including Supabase user ID and sign-in provider metadata
- Display name or profile information made available by Google or Apple
- Session and security information needed to authenticate requests
Sign in with Apple may provide a private-relay email address. That address may represent a separate Kurozu account from the same person using Google Sign-In.
3.3 AI and web-search features
After you affirmatively accept the AI disclosure during onboarding, the App may provide:
- Ask AI, which generates an answer and may use web search;
- Suggest, which proposes facts or follow-up questions and may use web search; and
- AI Add Facts, which extracts proposed facts from text you provide for your review.
These features require a signed-in account, a cloud timeline, network access, an eligible Premium entitlement, and available AI allowance. AI features may process:
- Your prompt, message, question, or interview response
- Timeline identifiers and titles
- Relevant fact types and fact summaries, including descriptions, time text, and tags
- A selected or focused fact
- Bounded recent assistant history, including prior questions, answers, interview rounds, and source metadata
- Date, language, and request metadata needed to perform the request
Who receives what:
- Kurozu receives the request and context needed to perform it.
- OpenAI and Google Cloud Vertex AI may each process prompts, selected timeline context, bounded history, and search-source text. Routing may depend on the feature, model availability, reliability, and operational requirements.
- Perplexity receives a derived search query and search parameters such as domain, country, or language filters when Ask or Suggest uses web search. Perplexity does not receive the raw timeline as a search request.
Public-page reading: Where available, when you use Ask, the assistant may read text from public webpages using Tavily or Firecrawl. This can include URLs you supply and URLs discovered during research. We select the page-reading service as part of the AI feature; there is no separate in-app page-reading switch or permission prompt.
The page-reading service receives the webpage URL and extraction options, not your timeline or conversation context. A URL can itself reveal sensitive information. Do not submit private, account-specific or signed links. Extracted page text is included in the context sent to the AI provider used to answer your question. We do not create a stored archive of fetched page bodies: intermediate extracted text stays in the active server workflow's memory. Answers and source metadata, including extraction status and retrieval time, follow the assistant-history and temporary-workflow storage practices below. Page-reading providers may retain requests and content under their applicable service agreements, settings and legal obligations; we do not promise zero retention.
Assistant conversations are stored on your device. Bounded portions may be sent again when needed for a later AI turn. Temporary server workflow records may contain request and result data until acknowledged or until their configured expiry, currently approximately 12 hours.
We do not use AI inputs or outputs to train our own models. Under the business/API services selected for launch, OpenAI, Google Cloud Vertex AI, and Perplexity state that customer content is not used to train their models without customer authorization. We do not opt in to provider training. Providers may retain or process data for service delivery, abuse prevention, security, or legal compliance under their applicable agreements and configured settings.
Apple Health samples are not automatically included in AI requests. Health-related information you manually type into a cloud timeline, prompt, or conversation may be included.
3.4 Purchases, Premium, and AI usage
Purchases are processed by Apple through the App Store. We use RevenueCat to validate transaction information, associate an entitlement with your signed-in Kurozu account, and synchronize subscription status. We may process:
- Kurozu account identifier
- App Store product, transaction, and receipt information
- Subscription status, including purchase, renewal, cancellation, expiration, billing issue, and refund state
- Premium entitlement and applicable subscription period
- AI allowance grants, reservations, deductions, remaining percentage, and expiration
- Usage measurements such as feature type, token counts, search-request counts, and allowance consumed; these billing measurements do not contain full prompt text
We do not receive your full payment-card number or Apple ID payment credentials.
3.4 Export
Export to AI builds plain text on your device and copies it to your clipboard. We do not receive export payloads on our servers.
If you choose to include selected Apple Health summaries in an export, the App shows an inline notice near that choice before copying. Once you paste exported text into another app, website, AI service, or message, that third party's terms and privacy practices apply.
3.6 Support and feedback
If you email us, we receive whatever you include in your message.
4. Information collected automatically
4.1 Crash and error reporting
We use Firebase Crashlytics to collect crash reports and technical errors, such as:
- Stack traces and error messages
- App version, build number, and OS version
- Device model and locale
- Anonymous session or crash identifiers
We configure crash reporting not to include timeline content, fact text, authentication tokens, email addresses, or Apple Health data in crash reports.
4.2 Product analytics
We use Google Firebase Analytics to understand how the App is used. Events may include, for example:
- Onboarding completion
- Authentication started / succeeded / failed (provider type only, not credentials)
- Move-to-cloud started / succeeded / failed
We do not send timeline titles, fact descriptions, health data, or email addresses to Firebase Analytics.
Firebase Analytics may collect standard device and app identifiers as described in Google's privacy documentation. We do not use the App for cross-app advertising or sell analytics data.
4.3 Network and session data
When you use cloud features, our API receives:
- Your Supabase access token for authentication
- Request metadata such as timestamps, endpoint, HTTP status, latency, app version, IP address, and other network information customarily sent with an internet request
We configure application logs to exclude full timeline descriptions, AI prompts, answers, search results, authentication tokens, and export payloads. Temporary AI workflow storage described in Section 3.3 is not an application log and may contain request or result content until it expires or is deleted.
4.4 Local device data (not transmitted)
The App stores on your device:
- A device-generated local account ID that is not sent to our servers
- App preferences (for example, language choice, last-opened timeline)
- Cached cloud timelines when signed in (purged on sign-out or account deletion)
- Assistant conversation history; bounded portions are transmitted when you make a later AI request
We use connectivity checks locally to show online/offline state. We do not transmit a history of your network status.
5. Apple Health
On supported iPhones, the App includes a preview panel that can read Apple Health data only after you grant HealthKit permission. The App may request access to:
Steps
Heart rate
Resting heart rate
Respiratory rate
Heart rate variability (HRV)
Sleep, including asleep, awake, deep sleep, light sleep, REM sleep, and in-bed intervals
Data is processed on your device to produce summary text.
Apple Health data is ephemeral and local: it is not saved to the App's database and is not uploaded to Kurozu, Firebase, or an AI provider.
The preview does not write data to Apple Health.
Selected summaries may be included in a user-directed clipboard export after an inline warning.
We do not use Apple Health data for advertising, marketing, use-based data mining, or profiling.
Health information you manually enter as a fact or AI prompt is user-provided content rather than a direct Apple Health read and may be cloud-synced or processed as described above.
This feature is not a medical device and is not intended to diagnose or treat any condition.
6. How we use information
We use information to:
- Provide local and cloud timeline functionality
- Authenticate you and secure your account
- Perform AI Add, Ask, Suggest, and related web search at your request
- Generate, display, and retain local assistant history
- Process App Store purchases, entitlements, AI allowance, renewals, cancellations, and refunds
- Diagnose crashes and improve stability after consent
- Understand feature usage and improve the App after consent
- Respond to support requests
- Detect abuse, fraud, or security incidents
- Comply with legal obligations and protect rights, safety, and property
We do not sell personal information, use it for cross-context behavioral advertising, or train our own AI models on your content.
7. How we disclose information
We use the following recipients and processors:
- Supabase: authentication, session management, cloud database, and account operations
- Google: Google Sign-In, Firebase Analytics, Firebase Crashlytics, Google Cloud hosting, and Vertex AI
- Apple: Sign in with Apple, Apple Health on device, App Store purchases, payment processing, subscription management, and refunds
- OpenAI: generation for AI features
- Perplexity: web search
- Tavily or Firecrawl: public-webpage text extraction for Ask, where available
- RevenueCat: transaction validation, subscription and entitlement synchronization, and billing webhooks
- Cloud infrastructure providers: API hosting, temporary workflow execution, security, and operational services
We may also disclose information:
- When required by law or valid legal process
- To protect users, the public, our rights, or our property
- In connection with a merger, financing, acquisition, or transfer of the service, subject to appropriate protections
We do not sell or share personal information for cross-context behavioral advertising. We require service providers to process data only for authorized purposes and to provide protections consistent with this Policy and applicable law.
8. Retention
We retain information according to its purpose and legal requirements:
- Local-only timelines and local-only assistant threads: remain on your device until you delete them or uninstall the App
- Cloud timelines and facts: remain until you delete them, delete your account, or the service ends, subject to temporary backups and necessary security records
- Cloud-account assistant threads: are stored on your device and purged from the device on sign-out or account deletion; bounded history may already have been processed in earlier AI requests
- Temporary AI workflow data: is removed when acknowledged or after the configured expiry, currently approximately 12 hours, unless longer retention is required for security or law
- AI and search provider data: is retained according to the applicable business/API contract, configured retention setting, and legitimate security or legal requirements
- Account record after deletion: may remain as an anonymized or de-identified tombstone without the account email where needed to prevent reactivation errors, reconcile billing, or maintain system integrity
- Purchase, entitlement, ledger, usage, refund, fraud, tax, and accounting records: remain for as long as reasonably necessary for the relevant legal, accounting, security, dispute, and audit purposes; we de-link or minimize these records where feasible
- Firebase Analytics and Crashlytics data: remains according to our configured Firebase retention periods and Google's processor terms
Retention is based on the nature and sensitivity of the information, the reason it was collected, security and fraud needs, contractual requirements, limitation periods, and applicable tax, accounting, consumer, and privacy laws.
9. Account deletion
You may delete your cloud account from Settings in the App.
If an Apple subscription may still be active, the App warns you and provides access to Apple's subscription-management page. Deleting your Kurozu account does not cancel the subscription. You may continue with deletion after confirming that you understand this.
When deletion is confirmed:
- We delete cloud timelines, facts, fact types, temporary AI mailbox data, AI request logs, and active entitlements.
- We delete or disable the Supabase authentication user.
- We remove the email from the retained account tombstone and de-link retained usage records where feasible.
- The App purges cached cloud data and cloud-account assistant conversations from the device and signs you out.
We retain the limited billing, transaction, ledger, usage, fraud, tax, accounting, and security records described in Section 8. Apple and RevenueCat may retain purchase records under their own legal and contractual obligations.
Local-only timelines and local-only assistant threads are not deleted by cloud-account deletion. Delete them in the App or uninstall the App to remove them.
Because Premium recovery is tied to the original Kurozu account, deleting that account may prevent you from using the remaining subscription entitlement in Kurozu even if Apple continues billing until cancellation. Cancel the Apple subscription before deleting the account if you do not want it to renew.
Sign-out removes cached cloud data and cloud-account conversations from the device but does not delete server-side cloud data.
If deletion fails due to a technical error, contact support@kurozu.app.
10. Security
We use industry-standard measures including HTTPS for API traffic, authenticated access to cloud data, and separation of local and cloud account namespaces on device.
No method of transmission or storage is completely secure. You are responsible for securing access to your device.
11. Children
The App is not directed to children under 13. You must be at least 13, or the minimum age required where you live, to use the App. If you are under the age of majority, a parent or guardian must authorize your use and accept the Terms of Service. We do not knowingly collect personal information from a child in violation of applicable law.
12. International transfers
We and our service providers may process information in countries other than where you live. Those countries may have different data-protection laws. Where required, we rely on applicable safeguards, such as adequacy decisions, standard contractual clauses, provider data-processing terms, or other lawful transfer mechanisms.
13. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive personal information, and to object to, restrict, or withdraw consent to certain processing.
- Local data: manage it in the App or remove it by uninstalling.
- Cloud data: edit or delete it in the App; use account deletion for the account-level process described above.
- AI: decline or withdraw AI permission; this disables new AI requests.
- Analytics and diagnostics: withdraw consent in the App's settings; collection stops prospectively.
- HealthKit: revoke permission in iOS Settings → Privacy & Security → Health.
- Apple subscription: manage or cancel it through your Apple account's subscription settings.
To exercise a right or ask a question, contact support@kurozu.app. We may need to verify your identity.
14. Changes to this Policy
We may update this Policy. We will post the revised version at this URL and update the effective date. Material changes may be communicated in the App or by email where appropriate. Continued use after changes take effect constitutes acknowledgment.
15. Contact
Kurozu
Email: support@kurozu.app