What we keep, and what we do not.
Last updated 7 September 2026. This policy describes how Kiri handles your information. It is written to be read, not to be survived.
The short version
- Personal photos stay on your device unless you choose AI review.Optional catalogue contributions upload product packaging photos only after you agree. Photo transcription requires separate permission.
- We keep your chosen shopping country, email address when you have an account, products in your routine, goals, profile answers, and any corrections you save.
- We do not sell your data, and we do not run advertising.
- We do not ask for health information, and we do not diagnose, treat or monitor any medical condition.
The iPhone app and web accounts
Kiri for iPhone stores your profile, routine, preferences and history on your device. It does not create or sync a cloud account. Use Settings to export device data or reset it. A separate web account stores records with Supabase and has its own export and permanent deletion controls.
Local photos
Taking or choosing a photo does not upload it. Photos used for a private self-check or local label reference stay on the device. Temporary personal photo copies are removed when you finish or leave the review unless you chose to keep them; failed cleanup is reported. Originals in your library are unchanged. Kiri does not identify faces or add photos to your routine.
Optional AI appearance review
Before each chosen face, scalp or hair-ends photo is sent, an initially off switch asks you to allow Kiri and OpenAI via OpenRouter to review its visible appearance. Kiri resizes and re-encodes the image and removes embedded metadata on the server before forwarding pixels. Our Supabase function holds the image and draft summary in memory for the request; it does not save either to a database, file storage or application logs. We request no response storage and use provider routes that decline training data collection. Provider security and abuse-monitoring retention may still apply, and providers may process data outside your country.
You can edit the summary, dismiss observations or skip the result. Only the reviewed note and choices you save remain on your device. Only explicit profile answers and selected goals affect suggestions. Cancelling stops the app waiting but cannot undo a photo already sent or remove provider logs. A keyed hash of a random installation token and normal connection information limit abuse; these are not face identifiers. The private self-check remains available without uploading a photo.
Shared catalogue contributions
When you choose to contribute a missing product or correction, we save the barcode, country, label details and two packaging photos in Supabase. Uploaded photos are resized and decoded to remove embedded metadata. Drafts and ingredient-panel photos are private to you and catalogue reviewers. After review, the product facts and front photo may be public. A random installation token, stored as a keyed hash on the server, links submissions for abuse prevention. This is not a hardware or advertising ID.
My contributions keeps private receipts on your device so you can view statuses, continue drafts and withdraw uploads without creating an account. Withdrawal removes uploaded photos and hides the current shared record based on that contribution. Resetting a profile and routine keeps those receipts. Draft uploads expire after seven days and rejected uploads after 30 days. Accepted evidence remains while the contribution is active. Factual revision history and minimal abuse records may remain for catalogue integrity. Contact support about personal information or a lost receipt.
If available, automatic packaging transcription sends the two photos to OpenAI via OpenRouter only after a separate opt-in. We request no response storage for application history; provider security and abuse-monitoring retention may still apply. You must review the text. Personal appearance review requires its own separate permission.
When you request label reading on the web and agree to the transfer, the image is sent to our server and passed to OpenAI via OpenRouter to read the text. It is held in memory for that request and then discarded. It is never written to our database and never saved to Kiri storage. We ask OpenAI via OpenRouter not to retain the response for application history. OpenAI via OpenRouter may still temporarily process or retain API data for security and abuse monitoring under its own data controls.
We save the extracted ingredient text to your web account for review and correction. Adding the product to your routine is a separate step.
Your original photo library is controlled by you. Resetting Kiri does not delete photos from that library.
What we collect
- Your shopping country or territory, selected by you, so catalogue records and shopping searches can be relevant where you live. Apple classifies this as coarse location. We do not request GPS or precise location.
- Product search requests: selected country, submitted product search text or barcode, and requested ingredient functions derived from routine gaps. The iPhone app sends these to Kiri’s public catalogue without an account identifier or full profile/routine. Providers receive connection information such as IP addresses and may retain operational or security logs.
- Your email address, so you can sign in and reach your web account from more than one device. The iPhone app does not ask for an email or create a cloud account.
- Your routine: the products you add, their ingredient lists, and what each product is for.
- Your haircare and skincare goals and any wording you add to refine them.
- Your profile answers: things like curl pattern, porosity, how your scalp feels, and how your skin looks. These are questions about appearance. We deliberately do not ask about medical conditions.
- Corrections you make when our reading of a label is wrong. These keep your own routine accurate.
- Basic usage counts, so we can apply a daily limit on label readings and keep the service running.
What we do not collect
- Personal appearance photos or unselected photo-library images.
- Health information, diagnoses, or medical history.
- Your GPS position, precise location, or location history.
- Your contacts, calendar, or anything else on your device.
- Advertising identifiers, and we do not track you across other apps.
Who else sees it
We use a small number of services, and only for the jobs described.
- Supabase serves Kiri’s public product and ingredient catalogue, including country, search and ingredient-function queries. For separate web accounts, it also stores account records and handles sign-in. It also stores optional packaging contributions, review history and content reports. It does not receive the iPhone app’s full routine or profile.
- OpenAI via OpenRouter reads label photos and helps word explanations. On the web, we send label photos or a cosmetic preference and calculated finding only after you agree at the point of use. Personal photos from the iPhone checklist are never sent.
- Open Beauty Facts, an open database, is queried when you scan a barcode. The request includes the barcode and ordinary connection information such as your IP address. Kiri does not send your profile or routine.
- Openverse and product image hosts support product-image discovery and display. Background searches use product identity only. Image hosts receive normal connection information when images load.
- Apple and our hosting provider handle app distribution and delivery.
- Google or Bing receives the product search text and selected country when you choose one of those shopping links. Their own privacy policies apply after the link opens.
- Retailers and affiliate networks receive normal connection information when you open an approved shop link. Marked affiliate links may earn Kiri a commission. These providers may use cookies or similar technologies under their own policies after the link opens.
We do not sell your private information. Reviewed catalogue contributions are public under their stated licences. When we send you to a shop, the button identifies a search or retailer link. We do not add your Kiri account identifier, profile answers or routine to these links.
Keeping it separate
Web account records are protected by database rules tied to the account. Private catalogue submissions use receipt-based access and are reviewed through server-only tools. Public catalogue records contain product facts, not contributor names, device tokens or private ingredient photos.
How long we keep it
Account records stay until you delete individual items or delete your account. Deleting your account removes its profile, goals, routine, label readings, products and corrections. Device-only preferences stay until you reset the app, clear browser storage, or remove the app. Operational backups and security logs may remain for a limited period before they are overwritten.
Your choices
- See what we hold and export it from the account page.
- Correct anything that is wrong, in the app.
- Delete a product, reset device-only data, or permanently delete your whole account and associated records from the account page.
- Routine edits remain local unless you separately contribute them. Shared submissions can be withdrawn from My contributions. Publicly licensed photos or facts may already have been reused by others.
To ask for any of this, or to complain about how we have handled your information, email connor.si.deng@gmail.com. If you are in Australia and you are not satisfied with our answer, you can contact the Office of the Australian Information Commissioner.
Children
Kiri is not intended for children under 13, and we do not knowingly collect their information.
Where your data lives
Our hosting, database, and AI providers may process information in the regions where they operate. Reading a label sends that one image to OpenAI via OpenRouter, which may process it outside your country. Your selected country is a catalogue preference and does not control where data is hosted.
Changes
If we change what we collect, we will update this page and the date at the top. If a change is significant, such as adding photo analysis of skin or hair, we will tell you in the app before it takes effect and ask before it applies to you.
Terms and support
Read the terms of use or visit support for help.
One more thing, because it matters
Kiri gives cosmetic information about ingredients and routines. It is not medical advice, it does not diagnose anything, and it is not a substitute for a doctor, dermatologist or pharmacist. If something about your skin or scalp concerns you, please see one.