Legal

Privacy Policy

Last updated: August 20, 2026.

§Our approach to privacy

Intentions is a quiet space for the parts of yourself you don't share casually — your hopes for the day, a difficult conversation you're working through, a thought you needed to put somewhere. We treat that material as private by default.

KuickTech LLC operates Intentions and is the controller or business responsible for the personal data described in this policy.

We collect the smallest amount of data we need to run the service. We don't sell your data, we don't rent it, and we don't use it to build advertising profiles. We do not include third-party advertising trackers; the service and analytics providers we do use are described below.

This page explains, in plain language, what we collect, why, who touches it, how long we keep it, and the rights you have over it. If anything here is unclear, write to us — the address is at the bottom.

§What we collect

We group what we collect into four categories, from least to most sensitive.

  • Account data. Your email address, an optional display name, and the auth identifiers returned by Sign in with Apple or Google sign-in. We don't store your Apple or Google password — we only see the token those services hand us.
  • Subscription data. Your plan tier, renewal status, trial state, purchase history, and Apple transaction identifiers. We never see or store your card number — that lives with Apple.
  • App content (most sensitive). The intentions you set, your daily check-ins (mood, energy, focus values), journal entries, conversations with the AI coach, text transcribed from voice input, and cards you save. This is the content of your practice, and we treat it with the most care.
  • Usage and diagnostics data. Feature interactions such as screen views and taps, purchase events, network request and response-code metadata, crash and performance diagnostics, app and OS version, device model, device or installation identifiers, and the account identity used by our analytics service. Kixo may also collect a reference screenshot when a screen in a particular app release has not yet been catalogued. These records may be linked to your account. We use them to operate the service, fix bugs, and understand which features are working.

No precise location data. Intentions does not currently ask for or store your precise location.

No advertising or cross-app tracking. Intentions uses Kixo for product analytics, but does not embed advertising SDKs or use your activity for cross-context behavioral advertising.

§How we use your data

Everything we collect serves one of a small number of clear purposes:

  • to deliver the core service — sign you in, sync your intentions and journal across devices, generate the daily ritual;
  • to personalize the AI coach so its responses reflect the intentions you've set and the check-ins you've shared, instead of starting cold every session;
  • to adapt prompts and recommendations to your current mood, energy, focus, and intention;
  • to keep the app reliable — diagnose crashes, fix bugs, monitor performance;
  • to send essential service emails (receipts, important changes, security notices) — never marketing without your consent;
  • to process payments through the Apple App Store.

§AI Coach data handling

If you enable AI data sharing and use an AI feature, the text you submit and the relevant account context are sent to our configured model provider — currently OpenAI — to generate the response that comes back to you.

Those requests are handled under the provider's terms for our account. We use the response to provide the requested feature and retain the conversation in your Intentions account as described below. You can turn AI data sharing off in your profile; AI features that need a model provider will then be unavailable.

Voice input is handled through Apple's Speech framework. Depending on your device and Apple's service, Apple may process the audio under Apple's privacy terms. Intentions does not upload or retain the raw audio on its backend. If you send the resulting transcript, it is stored and processed as text.

For users in jurisdictions that require it (the EU, the UK, and similar), here is the lawful basis we rely on under the GDPR:

  • Performance of a contract. Most of what we do — running your account, syncing your content, and delivering core non-AI features — is necessary to provide the service you've subscribed to.
  • Legitimate interest. Crash reporting, basic feature analytics, and security monitoring rest on our legitimate interest in keeping the app reliable and safe.
  • Consent. Optional things — voice input, AI data sharing and the model requests it enables, marketing emails, and any optional permissions — run only after you've chosen to enable them. You can withdraw consent at any time.
  • Legal obligation. A small set of data is kept where the law requires (tax records tied to subscription billing, for example).

§Who we share with

We work with a short list of vendors. Each one is used for a specific operational purpose and receives the data needed for that role.

  • Hosting and infrastructure — our infrastructure providers host the application, databases, backups, and uploaded assets.
  • AI model provider — OpenAI processes model requests for enabled AI features.
  • Analytics — Kixo handles product interaction, network metadata, crash, push, and diagnostics data, including account identifiers used to connect activity to a user. Kixo's continuous visual session replay is disabled in Intentions. Separately, its screen-catalog feature may upload a one-time reference screenshot for a screen and app release that Kixo has not seen before. The SDK applies automatic redaction, but the image can contain other content visible on that screen. We do not use third-party advertising analytics.
  • Payment platform — Apple handles the transaction and provides subscription and purchase status to us.
  • Email and customer support — when you email us, your message and the address you wrote from are processed by the email and mailbox providers we use so we can reply.

We do not sell personal data or share it for cross-context behavioral advertising. We may disclose data to the recipients needed to operate Intentions, when you ask us to, as part of a corporate transaction, or when legally required.

§How long we keep things

While your account is active, we keep content needed to provide the features you use. Some product areas apply shorter retention periods; where they do, the app or feature explains them.

  • Account deletion — deletion prevents further use of the account and starts removal from active systems. If part of the cleanup is temporarily unavailable, automated reconciliation continues it.
  • Coach conversation history — retained with your account until you delete it or a documented feature-specific retention rule applies.
  • Voice input — raw audio is not stored by the Intentions backend. A transcript you submit is retained as text with the relevant feature.
  • Limited retained records — Apple transaction audit records, security records, a one-way account-deletion tombstone, backups, and data held by recipients may remain where needed for legal, fraud-prevention, security, or recovery purposes and follow their applicable retention schedules.

Email [email protected] if you need the retention details that apply to a specific record or request.

§Security

We use technical and organizational measures designed to protect personal data. Those measures include:

  • Encryption in transit — every connection between the app and our servers uses TLS.
  • Authentication controls — signed tokens, short-lived verification codes, and rate limits protect account and administrative access.
  • Restricted access — production and administrative access is limited to people who need it to operate and support the service.
  • Maintenance and review — we update dependencies, review security-sensitive changes, and monitor service health.

If a personal-data breach occurs, we will notify affected people and authorities when and as required by applicable law.

§Your rights

Wherever you live, you have rights over the data we hold about you. Under the GDPR and the CCPA — and as a baseline for everyone — those rights include:

  • Access — see what we have on you.
  • Export — receive a copy of your content in a portable format.
  • Correction — fix anything that's inaccurate.
  • Deletion — ask us to remove your account and content.
  • Portability — move your data to another service.
  • Objection or restriction — ask us to stop or limit certain processing where applicable.

To use any of these rights, email [email protected]. We may need to verify that the request concerns your account. We'll respond within the period required by applicable law, and we won't charge for a reasonable request.

§Children’s privacy

Intentions is not designed for, or directed at, anyone under the age of 13. Our Terms require users to be at least 13 and may require a parent or guardian where local law says so.

If we learn that we've collected information from a child under 13 without verified parental consent, we'll delete it. If you believe a child has signed up, please write to us at [email protected] and we'll act quickly.

§International data transfers

Intentions is a global service. To deliver it, your data may move between jurisdictions, including the United States and countries in the European Economic Area, depending on where our infrastructure and vendors operate at any given time.

Where the law requires a transfer mechanism, we rely on the European Commission's Standard Contractual Clauses, plus supplementary measures where appropriate, to give your data the protection your home jurisdiction expects.

§Cookies and tracking

This marketing site uses no third-party tracking cookies. There's no Google Analytics, no Meta pixel, no retargeting. The only cookies set here are the strictly necessary ones the site needs to function.

If we ever add a privacy-respecting analytics cookie in the future, it will be opt-in — nothing will load until you tell us yes — and we'll explain what it does in plain language before asking.

§Changes to this policy

Privacy practices evolve as the app evolves. When we change something material — what we collect, how we use it, or who we share it with — we'll let you know in advance through an in-app notice and, where appropriate, by email.

The “last updated” date at the top of this page is the simplest signal that something has changed. Minor edits (clarifying language, fixing a typo) may not get a separate notice, but the date will always tell the truth.

§How to reach us

For privacy-specific questions — a data request, a concern about how something is handled, a worry about an account — write to [email protected].

For everything else, the general inbox is [email protected]. We read every message and try to reply within a few working days.