Privacy policy

This policy explains how KitKit handles information in the mobile app, website, and waitlist.

App account and profile

KitKit may store your name, email address, username, birthday, gender, optional profile photo, time zone, availability settings, and authentication records. We use your birthday to enforce KitKit's minimum age requirement. KitKit also stores the friend connections, requests, and invite links needed to provide the service.

Age information and younger users

KitKit is for people age 13 and older. We ask for a birthday to check eligibility. If a person enters a birthday showing they are under 13, we block access and delete the newly created account and associated information. We use birthdays for age checks and to apply age-appropriate ad protections. We may use age groups and gender to understand our users in aggregate, not to select interests or personalize advertising. The profile asks for a gender selection and includes an Other option. Users age 13 to 17 receive the minor ad protections described below.

Friends and calls

Your Circle is made up of friends you choose in KitKit. The current app does not ask for phone numbers or access your phone's address book. Older friend records may still contain an optional phone number from a previous version. Friend records can also include a name, avatar, and interaction history you add. KitKit stores call-session metadata such as the two participants, call status, and timestamps. Live microphone audio is transmitted to provide a call; KitKit does not currently create or store call recordings.

Permissions and device data

The app asks for microphone access to make calls and notification access to ring your device. It asks for camera or photo-library access only when you choose to take or select a profile picture. It stores push notification tokens and may receive basic device, network, and diagnostic information.

Website and waitlist

The website waitlist stores your email address, phone platform (iOS or Android), the time you consented, and the source of the sign-up. We use that information for KitKit waitlist and launch updates. We do not sell your email.

How we use information

We use information to create and secure accounts, connect friends, schedule and deliver calls, send service and account emails, deliver call notifications, provide support, and improve reliability. We do not sell your personal information.

Product analytics

When PostHog is configured, KitKit sends a pseudonymous account identifier after sign-in, an app-installation identifier, country code, onboarding status, normalized screen names, and limited feature activity such as call type, outcome, and duration, availability summaries, purchase and ad outcomes, and app, build, and device information. We use this information to understand product use and reliability. KitKit does not send names, email addresses, phone numbers, birthdays, profile photos, availability schedule contents, feedback text, call audio, message content, raw errors, or precise location to PostHog. Session replay and automatic touch capture are disabled.

Optional rewarded ads

If you choose to watch a rewarded ad, Google Mobile Ads may process device identifiers, network information, consent choices, ad interactions, app performance and diagnostic information, and approximate location inferred from your IP address to deliver ads, limit repeat ads, measure results, prevent fraud, and meet legal requirements. KitKit requests non-personalized ads and offers a way to continue without watching an ad. Non-personalized ads may still use device identifiers for frequency capping and aggregated reporting. For users under 18, KitKit also marks the request for under-age-of-consent treatment and limits ads to Google's general-audience content rating. KitKit does not mark the service as directed to children under 13 because those users may not use the service.

Profile photo checks

If you choose to add or replace a profile photo and agree to the check in the app, KitKit sends the photo to OpenAI's moderation service to check for explicit or harmful content. We do not send your name, email address, or birthday with the photo. If the check is temporarily unavailable, the new photo may be shared with friends while KitKit retries it. If a later check rejects the photo, KitKit removes it.

Service providers

KitKit uses Convex for authentication, storage, and app data; LiveKit for real-time call transport; RevenueCat for optional purchases and rewarded-ad measurement and verification; PostHog for product analytics when configured; OneSignal and Resend for waitlist and account email; Apple, Google, Firebase, and Expo services for app delivery and notifications; and Sentry for diagnostics when configured. The website may be hosted on Vercel. These providers process only the information needed to perform their services under their own terms and privacy commitments. Google Mobile Ads and its consent tools may process data when you choose a rewarded ad or open Privacy Choices.

Diagnostics

When Sentry is configured, KitKit may send crash and error details, a limited app-start performance transaction, and the KitKit account ID associated with signed-in users. The current app disables default personal data, screenshots, view hierarchy, session replay, and automatic performance tracing in Sentry.

Retention, choices, and deletion

We keep account data while your account is active. When you delete an account, KitKit deletes the profile, friendships, requests, call history, notification tokens, and authentication records tied to it, except for limited records that law, fraud prevention, or security requires us to retain. We keep waitlist data until launch communications end or you ask us to delete it. Historical analytics, diagnostic, purchase, and ad-measurement records held by PostHog, Sentry, RevenueCat, Apple, or Google do not automatically disappear at the same time as your active KitKit account. They may remain until the provider deletion process or configured retention period is complete, or as required for transaction records, fraud prevention, tax, security, or other legal obligations. After verifying a request, we apply provider deletion controls to linked records where applicable. You can delete an app account from the app or use the account deletion page. To access, correct, or remove waitlist data, email hi@usekitkit.com. Limited records may be retained when reasonably necessary for security or legal obligations.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of your personal information, and to object to or withdraw consent for some processing. You can change ad choices from the app's Privacy Choices control when available. Email hi@usekitkit.com to make another request. We may need to verify your identity before completing it. You may also complain to your local data-protection authority.

Security and international processing

We use reasonable technical and organizational safeguards, but no online service can guarantee absolute security. KitKit and its providers may process information in countries other than yours. Where required, we use legally recognized safeguards for those transfers.

Changes and contact

We will post revisions and update the date below when KitKit's data practices change. If a change materially affects your privacy rights, we will provide additional notice when required. Questions can be sent to hi@usekitkit.com.

Last updated September 27, 2026.