Pinchly.

Privacy Policy

Version 3.1 · Effective 2026-08-03 (planned App Store launch) · Last updated 2026-07-18 · Published by KuhlApps, LLC

Summary — what this policy says in plain English

1. What this policy covers

This Privacy Policy explains what personal data Pinchly collects, why, how long we keep it, the categories of service providers we share it with, and the choices you have. It applies to the Pinchly mobile application and to the pinchly.app website that links to this policy.

Questions: support@kuhlapps.com.

2. Who we are

Pinchly is operated by KuhlApps, LLC (the "Company"), a Delaware limited liability company. For GDPR, KuhlApps, LLC is the data controller; for CCPA, it is the business that determines the purposes and means of processing.

Contact: support@kuhlapps.com. A postal address for formal notices is available on request to the same email. Users in the EEA or UK may request the details of our representative where one is appointed.

3. Who can use Pinchly

You must be at least 16 years old to create a Pinchly account. We do not knowingly collect personal data from anyone under 16, and we will delete the account and associated data promptly if we learn otherwise. Pinchly is not directed to children and has no features designed for children. For users in the EEA or UK, the digital-consent age we apply is 16 (Article 8 GDPR).

If you are a parent or guardian and believe a child has created an account, contact support@kuhlapps.com.

4. What data we collect

4.1 Data you give us directly

CategoryPurpose
Account identifiers — your email address, and a self-attested date of birth used once at signup to confirm you are 16+ and to derive a coarse age band (see §4.5), after which the birth year is discardedAccount creation, sign-in, age verification, and a single demographic dimension for the de-identified statistics in §4.6
Profile and preference content — your display name and optional profile details; the people you add and the preferences, notes, and groupings you save about them; your connections with other usersProviding the core service: remembering and retrieving what people like, and — only when you explicitly choose to share — showing selected content to people you connect with
Optional birthday — your birth month and day only (never the year), stored only if you turn on birthday visibilityLetting your accepted connections be reminded of your birthday. Off by default; turning it off deletes it (see §4.5)
Subscription statusEnforcing free-tier limits and unlocking paid features
Support correspondenceResponding to you

Your entries about other people are private to you. Preferences you add about someone else are visible only to you unless you take an explicit action to share them.

4.2 Data we collect automatically

CategoryPurpose
Product analytics — de-identified records of which features you use (e.g., that a preference was created in a given category). These never contain your notes, the names of people you add, your email, or any free-text content.Understanding usage to improve the product
Crash and error reports — stack traces and device/OS/app metadata, with personal content scrubbed before sendingDiagnosing and fixing problems
Subscription receipts — the app-store subscription identifier, plan tier, and renewal statusManaging your subscription
AI processing of the content you capture and retrieve — the text you type or speak when saving a preference, and your search questions, are processed by third-party AI service providers to structure your entries and answer your searches. Searches are scoped to your own data. No audio, no email, no account identifier is sent; the request is never used to train AI models and is deleted after at most a short abuse-monitoring period; we keep no copy.Turning what you capture into usable entries and answering your searches
Place search — the text you type into a place search field, and (only if you opt in) your approximate location as a search bias, sent to a third-party mapping providerReturning place suggestions
Standard server logs — transient IP address, request timestampsOperating and securing the service

4.3 What we do not collect, sell, or expose

4.4 Voice, places, and location

4.5 Birthday visibility and age band

4.6 How aggregated statistics may improve Pinchly

When this applies. The aggregated-statistics layer and any related suggestion features roll out only as Pinchly's community grows large enough for patterns to be meaningful and genuinely anonymous, and may not be active at launch. Until they are active, no patterns are built from your data and there is nothing to opt out of. We describe them here so your consent is fully informed from the start.

As Pinchly grows, we may combine the structured labels in many people's saved preferences (the category, whether something is a favorite or an "avoid," and a coarse age band) into de-identified, aggregated statistics — facts about a population, not records about you. These may power in-app suggestions, help us improve the product, and may be shared or sold as aggregate trend reports containing only statistics — never your preferences, your identity, or anyone you've added.

The limits we hold — these are firm:

  1. De-identified. Data enters this layer only under non-reversible keys; there is no path back to you or anyone you added.
  2. Aggregate only leaves the building, subject to a minimum group size — we never release user-level records or statistics from too few people to be anonymous.
  3. No free-text notes and no minors ever enter this layer.
  4. Your visibility choices are never overridden. A suggestion about a specific person uses only anonymous population statistics plus what you are already allowed to see about that person — never anything they kept private.
  5. You are never sold. De-identified, aggregated statistics are not personal information.

Your choices. You can turn off contribution to this layer and turn off personalized suggestions in Settings → Privacy & data at any time (these controls arrive with the feature). Where your jurisdiction gives you a right to opt out of "profiling," "targeted advertising," or "sharing," this control is how you exercise it. Because aggregated statistics never identified you, they are not un-computed when you delete your account (see §9).

5. How we use your data

We use the data in §4 only to: provide and secure Pinchly and sync your data; enforce your visibility choices on every request through database-level access rules; send transactional email (login codes, account notices, invites); structure and retrieve the content you capture (§4.2); return place suggestions; improve the product and, where active, build the de-identified aggregated statistics in §4.6; let your connections celebrate your birthday if you opt in; enforce our Terms and prevent abuse; and comply with law.

We do not use your data for third-party advertising, cross-context behavioral tracking, or automated decisions that produce legal or similarly significant effects about you.

6. Legal bases for processing (GDPR / UK GDPR)

PurposeLegal basis
Providing the app (including AI processing of content you capture and place suggestions you request)Contract — Art. 6(1)(b)
Security, fraud prevention, abuse response; de-identified product analytics; building the de-identified aggregated statistics in §4.6 (backed by a Data Protection Impact Assessment); retaining a coarse age band; crash reportingLegitimate interests — Art. 6(1)(f). You may object to the §4.6 processing and optional analytics at any time in Settings → Privacy & data
Optional location bias, optional birthday visibility, any future marketing emailConsent — Art. 6(1)(a)
Legal complianceLegal obligation — Art. 6(1)(c)

We do not intentionally process special-category data, and the §4.6 layer excludes free-text notes for that reason. Please do not put health, religious, political, sexual-orientation, or other special-category information into your notes.

7. Who we share data with

We share personal data only with the categories of service providers below, each bound by a Data Processing Agreement or equivalent, none of whom uses your data for their own marketing or to train AI models on your content. A current list of our specific sub-processors is available on request to support@kuhlapps.com.

Category of service providerData shared
Cloud hosting, backend, database, authentication, and email delivery (our primary processor; we are the controller)All data in §4, to operate the service
AI service providers (capture structuring and search retrieval)The text you capture or search, for the duration of the request plus a short vendor abuse-monitoring period; never used for training; no audio, no email, no account identifier
Mapping / place-search providerPlace search text; if you opted in, approximate location; no account identifier, no email, no preference content
Product analytics providerDe-identified event records (no notes, names, or emails)
Crash and error-monitoring providerStack traces and device metadata, personal content scrubbed
Subscription management providerApp-store subscription identifier, plan tier, renewal status
Build and push-notification infrastructureDevice push tokens and notification payloads (no preference content)
App store and in-app-purchase providerStore-provided account identifiers and purchase receipts

We share personal data outside these categories only when required by law or to prevent imminent harm, and we notify you where permitted. Business recipients of aggregate trend reports (§4.6) receive no personal data.

8. International data transfers

Pinchly's infrastructure is hosted in the United States. For users in the EEA, UK, or Switzerland, transfers rely on Standard Contractual Clauses and our processors' supplementary measures. Copies are available on request via support@kuhlapps.com.

9. How long we keep your data

DataRetention
Account data (email, profile, people, preferences)For the lifetime of your account
Birth yearNot retained — used once, then discarded
Age bandLifetime of your account, or until you opt out of §4.6; coarse and non-identifying
Birthday (month + day), if enabledUntil you turn it off or delete your account
De-identified, aggregated statistics (§4.6)Retained indefinitely as population statistics; not linked to you and not deleted on account deletion because they contain nothing that identifies you
Archived (recoverable) entriesUntil permanently deleted or your account is deleted
Account deletion requestCompleted within 30 days of a verified request, except records we must keep by law
Server logs30 days
Crash reports90 days
Analytics events13 months (rolling)
AI capture/retrieval requestsNot kept by us; held briefly by the AI provider for abuse monitoring, then deleted; never used for training
AudioNever collected
Place search queriesNot retained beyond a short in-memory cache
Subscription receiptsDuration of the subscription plus 7 years for financial recordkeeping

Deleting your account deletes your data; the only thing that persists is de-identified population statistics that never identified you.

10. Your rights

Subject to applicable law and applied to all users worldwide: access a copy of your data; correct inaccurate data (most is editable in the app); delete your account and personal data in Settings → Privacy → Delete my data, or by email; export a machine-readable copy (in-app export in development; available on request meanwhile); object / opt out of the §4.6 aggregated-statistics layer and personalized suggestions in Settings → Privacy & data; restrict or object to processing based on legitimate interests; withdraw consent where we rely on it; and lodge a complaint with your data protection authority. De-identified population statistics (§4.6) are not personal data and cannot be selectively deleted, but you can stop future contribution at any time.

To exercise any right, email support@kuhlapps.com. We verify identity before acting and do not charge for reasonable requests.

California (CCPA/CPRA). California residents have the rights above. Pinchly does not sell personal information and does not share personal information for cross-context behavioral advertising. The de-identified, aggregated statistics in §4.6 are not "personal information" and their creation or sharing is not a "sale" or "share"; we keep them de-identified, do not re-identify them, and require recipients not to. We do not discriminate against users who exercise their rights.

Other US states (Virginia, Colorado, Connecticut, Utah, Oregon, Texas, and others). Residents have analogous rights, including opt-out of targeted advertising, sale, and certain profiling. Pinchly does not engage in targeted advertising and does not sell personal information; the §4.6 opt-out honors profiling/sharing opt-outs. We are not a data broker.

11. Cookies, SDK identifiers, and tracking

The app does not use browser cookies. It uses scoped, single-purpose identifiers (an auth session token, an anonymous analytics identifier not linked to any advertising ID, an error-monitoring session identifier, a subscription identifier, a push token, and a per-search place-service session token). Pinchly does not use Apple's advertising identifier (IDFA), does not request App Tracking Transparency permission, and includes no advertising or attribution SDK.

12. Security

Report a vulnerability: support@kuhlapps.com.

13. Children's privacy (COPPA and equivalents)

Pinchly is for users 16 and older. We do not knowingly collect personal information from anyone under 16 and delete it promptly if discovered. When an adult adds a private record about another person who is a child, that is the adult's private record; no data about anyone we can identify as a minor is ever included in the §4.6 statistics, and a non-user's birthday is used only for the adult's reminders. Parents or guardians: email support@kuhlapps.com.

14. Changes to this policy

We update this policy when we change how we collect or use data; the "Last updated" date reflects the most recent change. For material changes (a new category of data or a new category of recipient) we notify you in-app and by email at least 14 days before the change takes effect. For non-material changes (corrections, clarifications, formatting) we update the date. Prior versions are archived and available on request.

15. Contact

Email: support@kuhlapps.com — for privacy questions, rights requests, and to request our postal address or current sub-processor list.

We aim to respond within 5 business days to general inquiries and within 30 days to formal rights requests.