Privacy Policy
Summary — what this policy says in plain English
- What we collect: what you give us (your email, the names of people you add, and the preferences you save about them) and minimal telemetry (which features you use, crash reports). When you capture a preference — typed or spoken — the text is processed by third-party AI service providers to turn it into a structured entry and to make it findable later. If you speak, your phone turns your speech into text, the same as keyboard dictation; Pinchly never records or stores the audio — only the text. We keep no copy of that request, it is never used to train anyone's AI models, and our providers delete it after at most a short abuse-monitoring period.
- How your data may improve Pinchly for everyone: As Pinchly grows, we may combine everyone's saved preferences into de-identified, aggregated patterns — statistics across many people that cannot be tied back to you or anyone you've added. These may power in-app suggestions, help us improve the product, and may be shared as aggregate trend reports. Your individual preferences are never sold or shared — only anonymous patterns, and your free-text notes are never used.
- The hard line we draw: Pinchly is 16+. We never sell your personal information, and we never share information that identifies you or anyone you've added. Any suggestion about a specific person uses only what you're already allowed to see about them — never anything they kept private. Your birthday is off by default. Location is used only to improve place search. Voice is optional — typing does everything voice does.
1. What this policy covers
This Privacy Policy explains what personal data Pinchly collects, why, how long we keep it, the categories of service providers we share it with, and the choices you have. It applies to the Pinchly mobile application and to the pinchly.app website that links to this policy.
Questions: support@kuhlapps.com.
2. Who we are
Pinchly is operated by KuhlApps, LLC (the "Company"), a Delaware limited liability company. For GDPR, KuhlApps, LLC is the data controller; for CCPA, it is the business that determines the purposes and means of processing.
Contact: support@kuhlapps.com. A postal address for formal notices is available on request to the same email. Users in the EEA or UK may request the details of our representative where one is appointed.
3. Who can use Pinchly
You must be at least 16 years old to create a Pinchly account. We do not knowingly collect personal data from anyone under 16, and we will delete the account and associated data promptly if we learn otherwise. Pinchly is not directed to children and has no features designed for children. For users in the EEA or UK, the digital-consent age we apply is 16 (Article 8 GDPR).
If you are a parent or guardian and believe a child has created an account, contact support@kuhlapps.com.
4. What data we collect
4.1 Data you give us directly
| Category | Purpose |
|---|---|
| Account identifiers — your email address, and a self-attested date of birth used once at signup to confirm you are 16+ and to derive a coarse age band (see §4.5), after which the birth year is discarded | Account creation, sign-in, age verification, and a single demographic dimension for the de-identified statistics in §4.6 |
| Profile and preference content — your display name and optional profile details; the people you add and the preferences, notes, and groupings you save about them; your connections with other users | Providing the core service: remembering and retrieving what people like, and — only when you explicitly choose to share — showing selected content to people you connect with |
| Optional birthday — your birth month and day only (never the year), stored only if you turn on birthday visibility | Letting your accepted connections be reminded of your birthday. Off by default; turning it off deletes it (see §4.5) |
| Subscription status | Enforcing free-tier limits and unlocking paid features |
| Support correspondence | Responding to you |
Your entries about other people are private to you. Preferences you add about someone else are visible only to you unless you take an explicit action to share them.
4.2 Data we collect automatically
| Category | Purpose |
|---|---|
| Product analytics — de-identified records of which features you use (e.g., that a preference was created in a given category). These never contain your notes, the names of people you add, your email, or any free-text content. | Understanding usage to improve the product |
| Crash and error reports — stack traces and device/OS/app metadata, with personal content scrubbed before sending | Diagnosing and fixing problems |
| Subscription receipts — the app-store subscription identifier, plan tier, and renewal status | Managing your subscription |
| AI processing of the content you capture and retrieve — the text you type or speak when saving a preference, and your search questions, are processed by third-party AI service providers to structure your entries and answer your searches. Searches are scoped to your own data. No audio, no email, no account identifier is sent; the request is never used to train AI models and is deleted after at most a short abuse-monitoring period; we keep no copy. | Turning what you capture into usable entries and answering your searches |
| Place search — the text you type into a place search field, and (only if you opt in) your approximate location as a search bias, sent to a third-party mapping provider | Returning place suggestions |
| Standard server logs — transient IP address, request timestamps | Operating and securing the service |
4.3 What we do not collect, sell, or expose
- We do not sell your personal information, and we do not share information that identifies you or anyone you've added for anyone's advertising. We have no advertising SDKs and show no ads. What we may share externally is limited to de-identified, aggregated statistics that identify no one (see §4.6).
- We do not include your free-text notes, or any data about anyone we can identify as a minor, in the aggregated statistics of §4.6.
- We do not store your device location on our servers, and we do not use background location.
- We do not upload your contacts. If you use "Add from your contacts," the names are read on your device only to build a picker; only the people you pick are saved.
- We do not record, receive, or store audio. When you speak, your phone turns speech into text (on-device when possible, otherwise via your phone's built-in dictation service, the same as any dictation); Pinchly receives only text.
- We do not collect photos or camera-roll media, and we do not use Apple's advertising identifier (IDFA).
- We do not send the content you capture or retrieve to any third party to train that third party's AI models.
4.4 Voice, places, and location
- Voice capture (optional). Typing does everything voice does. If you speak a preference, your phone converts speech to text the same way keyboard dictation does; Pinchly never records, receives, or stores audio — only the resulting text, which is processed as described in §4.2 and stored only if you save the entry.
- Contacts (optional). "Add from your contacts" reads names on your device only, to show you a picker. Contacts are never uploaded, and we do not read phone numbers, emails, or other contact fields. You can turn the permission off at any time and the rest of the app keeps working.
- Places and location. Place search text is sent to a third-party mapping provider to return suggestions and is not retained beyond a short in-memory cache. If you grant location permission and turn on the in-app location switch, your approximate location (used only while you are actively searching, foreground only) is sent as a search bias and is not stored on our servers. Public information about a place you attach may be cached so others don't re-query it; that cache never records who searched for or attached a place.
4.5 Birthday visibility and age band
- Your birth year is used once at signup — to confirm you are 16+ and to derive a coarse age band (e.g., "25–34") — and is then discarded. We do not store your birth year or exact age; the age band is used only as a single demographic dimension for the de-identified statistics in §4.6 and is never shown to other users.
- Your birth month and day are not stored unless you turn on "Make my birthday visible." This is off by default (Settings → Privacy). When on, we store month and day only (never the year) and show them to your accepted connections; when off, we delete them.
- These features are never available to an account flagged as under 16, which contributes nothing to §4.6.
4.6 How aggregated statistics may improve Pinchly
When this applies. The aggregated-statistics layer and any related suggestion features roll out only as Pinchly's community grows large enough for patterns to be meaningful and genuinely anonymous, and may not be active at launch. Until they are active, no patterns are built from your data and there is nothing to opt out of. We describe them here so your consent is fully informed from the start.
As Pinchly grows, we may combine the structured labels in many people's saved preferences (the category, whether something is a favorite or an "avoid," and a coarse age band) into de-identified, aggregated statistics — facts about a population, not records about you. These may power in-app suggestions, help us improve the product, and may be shared or sold as aggregate trend reports containing only statistics — never your preferences, your identity, or anyone you've added.
The limits we hold — these are firm:
- De-identified. Data enters this layer only under non-reversible keys; there is no path back to you or anyone you added.
- Aggregate only leaves the building, subject to a minimum group size — we never release user-level records or statistics from too few people to be anonymous.
- No free-text notes and no minors ever enter this layer.
- Your visibility choices are never overridden. A suggestion about a specific person uses only anonymous population statistics plus what you are already allowed to see about that person — never anything they kept private.
- You are never sold. De-identified, aggregated statistics are not personal information.
Your choices. You can turn off contribution to this layer and turn off personalized suggestions in Settings → Privacy & data at any time (these controls arrive with the feature). Where your jurisdiction gives you a right to opt out of "profiling," "targeted advertising," or "sharing," this control is how you exercise it. Because aggregated statistics never identified you, they are not un-computed when you delete your account (see §9).
5. How we use your data
We use the data in §4 only to: provide and secure Pinchly and sync your data; enforce your visibility choices on every request through database-level access rules; send transactional email (login codes, account notices, invites); structure and retrieve the content you capture (§4.2); return place suggestions; improve the product and, where active, build the de-identified aggregated statistics in §4.6; let your connections celebrate your birthday if you opt in; enforce our Terms and prevent abuse; and comply with law.
We do not use your data for third-party advertising, cross-context behavioral tracking, or automated decisions that produce legal or similarly significant effects about you.
6. Legal bases for processing (GDPR / UK GDPR)
| Purpose | Legal basis |
|---|---|
| Providing the app (including AI processing of content you capture and place suggestions you request) | Contract — Art. 6(1)(b) |
| Security, fraud prevention, abuse response; de-identified product analytics; building the de-identified aggregated statistics in §4.6 (backed by a Data Protection Impact Assessment); retaining a coarse age band; crash reporting | Legitimate interests — Art. 6(1)(f). You may object to the §4.6 processing and optional analytics at any time in Settings → Privacy & data |
| Optional location bias, optional birthday visibility, any future marketing email | Consent — Art. 6(1)(a) |
| Legal compliance | Legal obligation — Art. 6(1)(c) |
We do not intentionally process special-category data, and the §4.6 layer excludes free-text notes for that reason. Please do not put health, religious, political, sexual-orientation, or other special-category information into your notes.
7. Who we share data with
We share personal data only with the categories of service providers below, each bound by a Data Processing Agreement or equivalent, none of whom uses your data for their own marketing or to train AI models on your content. A current list of our specific sub-processors is available on request to support@kuhlapps.com.
| Category of service provider | Data shared |
|---|---|
| Cloud hosting, backend, database, authentication, and email delivery (our primary processor; we are the controller) | All data in §4, to operate the service |
| AI service providers (capture structuring and search retrieval) | The text you capture or search, for the duration of the request plus a short vendor abuse-monitoring period; never used for training; no audio, no email, no account identifier |
| Mapping / place-search provider | Place search text; if you opted in, approximate location; no account identifier, no email, no preference content |
| Product analytics provider | De-identified event records (no notes, names, or emails) |
| Crash and error-monitoring provider | Stack traces and device metadata, personal content scrubbed |
| Subscription management provider | App-store subscription identifier, plan tier, renewal status |
| Build and push-notification infrastructure | Device push tokens and notification payloads (no preference content) |
| App store and in-app-purchase provider | Store-provided account identifiers and purchase receipts |
We share personal data outside these categories only when required by law or to prevent imminent harm, and we notify you where permitted. Business recipients of aggregate trend reports (§4.6) receive no personal data.
8. International data transfers
Pinchly's infrastructure is hosted in the United States. For users in the EEA, UK, or Switzerland, transfers rely on Standard Contractual Clauses and our processors' supplementary measures. Copies are available on request via support@kuhlapps.com.
9. How long we keep your data
| Data | Retention |
|---|---|
| Account data (email, profile, people, preferences) | For the lifetime of your account |
| Birth year | Not retained — used once, then discarded |
| Age band | Lifetime of your account, or until you opt out of §4.6; coarse and non-identifying |
| Birthday (month + day), if enabled | Until you turn it off or delete your account |
| De-identified, aggregated statistics (§4.6) | Retained indefinitely as population statistics; not linked to you and not deleted on account deletion because they contain nothing that identifies you |
| Archived (recoverable) entries | Until permanently deleted or your account is deleted |
| Account deletion request | Completed within 30 days of a verified request, except records we must keep by law |
| Server logs | 30 days |
| Crash reports | 90 days |
| Analytics events | 13 months (rolling) |
| AI capture/retrieval requests | Not kept by us; held briefly by the AI provider for abuse monitoring, then deleted; never used for training |
| Audio | Never collected |
| Place search queries | Not retained beyond a short in-memory cache |
| Subscription receipts | Duration of the subscription plus 7 years for financial recordkeeping |
Deleting your account deletes your data; the only thing that persists is de-identified population statistics that never identified you.
10. Your rights
Subject to applicable law and applied to all users worldwide: access a copy of your data; correct inaccurate data (most is editable in the app); delete your account and personal data in Settings → Privacy → Delete my data, or by email; export a machine-readable copy (in-app export in development; available on request meanwhile); object / opt out of the §4.6 aggregated-statistics layer and personalized suggestions in Settings → Privacy & data; restrict or object to processing based on legitimate interests; withdraw consent where we rely on it; and lodge a complaint with your data protection authority. De-identified population statistics (§4.6) are not personal data and cannot be selectively deleted, but you can stop future contribution at any time.
To exercise any right, email support@kuhlapps.com. We verify identity before acting and do not charge for reasonable requests.
California (CCPA/CPRA). California residents have the rights above. Pinchly does not sell personal information and does not share personal information for cross-context behavioral advertising. The de-identified, aggregated statistics in §4.6 are not "personal information" and their creation or sharing is not a "sale" or "share"; we keep them de-identified, do not re-identify them, and require recipients not to. We do not discriminate against users who exercise their rights.
Other US states (Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and others). Residents have analogous rights, including opt-out of targeted advertising, sale, and certain profiling. Pinchly does not engage in targeted advertising and does not sell personal information; the §4.6 opt-out honors profiling/sharing opt-outs. We are not a data broker.
11. Cookies, SDK identifiers, and tracking
The app does not use browser cookies. It uses scoped, single-purpose identifiers (an auth session token, an anonymous analytics identifier not linked to any advertising ID, an error-monitoring session identifier, a subscription identifier, a push token, and a per-search place-service session token). Pinchly does not use Apple's advertising identifier (IDFA), does not request App Tracking Transparency permission, and includes no advertising or attribution SDK.
12. Security
- Data is encrypted in transit (TLS) and at rest (AES-256).
- Database access is enforced on every request; no personal data is readable by another user except through a path you explicitly authorized.
- The aggregated-statistics process (§4.6) reads production data one way to produce de-identified aggregates and retains no re-identification key.
- Vendor access is limited to what each vendor needs.
- We will notify affected users without undue delay of a personal-data breach likely to risk your rights.
Report a vulnerability: support@kuhlapps.com.
13. Children's privacy (COPPA and equivalents)
Pinchly is for users 16 and older. We do not knowingly collect personal information from anyone under 16 and delete it promptly if discovered. When an adult adds a private record about another person who is a child, that is the adult's private record; no data about anyone we can identify as a minor is ever included in the §4.6 statistics, and a non-user's birthday is used only for the adult's reminders. Parents or guardians: email support@kuhlapps.com.
14. Changes to this policy
We update this policy when we change how we collect or use data; the "Last updated" date reflects the most recent change. For material changes (a new category of data or a new category of recipient) we notify you in-app and by email at least 14 days before the change takes effect. For non-material changes (corrections, clarifications, formatting) we update the date. Prior versions are archived and available on request.
15. Contact
Email: support@kuhlapps.com — for privacy questions, rights requests, and to request our postal address or current sub-processor list.
We aim to respond within 5 business days to general inquiries and within 30 days to formal rights requests.