When this version applies to you. If you create your Kera account on or after 26 September 2026, this policy applies from the day you create it. If your account existed before 26 September 2026, it applies to you from 26 October 2026, giving you 30 days’ notice; until then version 1.1 continues to apply to you. Child profiles (section 13) are covered by this version and the Children’s Privacy Notice from the day they are created.
Updated 29 September 2026. We added section 6.5 on connecting an AI app such as ChatGPT or Claude to Kera, an optional feature you turn on yourself, with matching rows in sections 3.3, 4, 8.6, 10, 11, 12 and 13. The connected-app parts change nothing for you unless you connect an AI app. We also added the in-app notification list, which keeps the notifications Kera sends you for 90 days, to sections 10 and 11. Nothing else changed. The text as first published on 26 September 2026 is at aikera.io/privacy/v1.2.
At a glance
- Who we are: Kera is run by SPIN LLC, a company registered in Georgia. We’re responsible (the “controller”) for your personal data.
- What Kera is: a household shopping app. Members of a household add what they need, approve requests, record purchases and track budgets. There’s also an AI assistant, Kera, that you can type or talk to. You’re talking to an AI system, not a person, whenever you use the assistant, and its voice is computer-generated.
- What we collect: your account details, what you and your household put into the app, and technical data needed to run it. Some features need permissions you can refuse (camera, microphone, contacts, location, notifications).
- Children: Kera accounts are for adults. A parent or guardian can add their child to the household as a child profile, after giving verifiable consent. Children can’t use the AI assistant, voice or search. See section 13 and the Children’s Privacy Notice.
- Who else sees it: the other members of your household, and service providers who run parts of Kera for us, including AI providers (OpenAI, Anthropic, Google, Replicate) and search providers (Brave, Shopify). Several of them are in the United States. If you connect an AI app such as ChatGPT or Claude to Kera, that app receives the household information you allow (section 6.5).
- What we don’t do: we don’t sell your data, we don’t share it for advertising, we don’t show ads, and the assistant never buys anything or spends money for you.
- Deleting your account: Settings → Privacy & data → Delete my data. You’re signed out at once, and your personal data is erased automatically after 30 days unless you sign back in to cancel.
- Your rights: you can ask for a copy of your data, correct it, delete it, object to some uses and withdraw consent. Email hello@spin.ge.
1. Who we are
Kera is operated by SPIN LLC (“we”, “us”), the controller of your personal data.
| Legal entity | SPIN LLC (Georgian: შპს სპინ), a limited liability company registered in Georgia, company ID 405173191 |
| Registered address | Ana Politkovskaia Street 22a, Floor 10, Apt 140, Vake District, Tbilisi 0186, Georgia |
| Privacy contact | hello@spin.ge (use this for any privacy question or rights request) |
| Product support | support@aikera.io |
| Data protection officer | We have not appointed a data protection officer. Contact hello@spin.ge for any data protection matter. |
2. What this policy covers
This policy covers:
- the Kera mobile app (Android; an iOS version is in preparation). A link to this policy is shown when you create an account,
- the Kera web app at
aikera.app, - public gift pages that Kera users share with people outside their household (section 14),
- the Kera website at
aikera.io, including its contact and early-access sign-up forms (section 3.1).
It doesn’t cover the websites and apps of shops you visit from Kera.
The admin console that SPIN LLC staff use to run Kera isn’t available to you, but section 8.4 explains what our staff can see.
3. The personal data we collect
3.1 Data you give us
| Category | Examples | Required? |
|---|---|---|
| Account | Email address, display name, password (we store only a salted hash, never the password itself) | Required to create an account |
| Household | Household name and type, currency, time zone, total budget, your role (Admin, Buyer or Requester), invite codes you create or redeem | Required to use a household |
| Child profiles (if you add your child) | Your child’s first name or nickname and age band (never a date of birth), the features you allow, and a record of your consent (section 13) | Optional |
| Shopping | Requests and list items (name, quantity, note, store, brand, size, expected price), recurring essentials, shopping trips, templates, pantry staples, return and warranty dates, price watches | Required for the core features |
| Comments and reactions | Comments and emoji reactions on items | Optional |
| Photos and voice notes | Photos and voice notes you attach to an item; pictures you upload as an item’s image | Optional |
| Money you track | Recorded purchases and prices, budgets, income and expense entries, bills, reimbursements, receipt splits, settle-up entries, savings targets | Optional; per feature |
| Bank statement files | A CSV or OFX file you import. We read it on our servers without AI and keep only each transaction’s date, description (usually the shop name) and amount. We don’t keep the file or any account number in it. | Optional; Admins and Buyers only |
| Receipt photos | A photo of a receipt you scan. It’s read by an AI provider (section 6) and not stored; only the parsed lines (shop, date, items, prices) are kept | Optional; adults only |
| Wishlists and gift occasions | Wishes (name, note, image, target price, who it’s visible to), who has claimed a gift, occasions (a name such as “Mum’s birthday”, a date, and who it’s for, which may be a person who doesn’t use Kera, such as “Grandma Nino”) | Optional |
| Shopping preferences | Brand, store, “avoid”, dietary and allergy notes, optionally linked to a specific household member. Allergy and dietary notes can reveal health information; see section 5. | Optional |
| Assistant conversations | What you type or say to the assistant and its replies, including transcripts of voice calls | Optional |
| Approximate location | A city and country you type, or your device’s approximate position (see section 7) | Optional; Admins and Buyers only |
| Messages to us | Emails you send us and our replies, and records of any privacy request you make | Optional |
| Website forms | The name, email address and message you send through a form on aikera.io. If you sign up for early access, your name and email address are also stored as a contact with our email provider (Resend) so we can send you updates about Kera. | Optional |
3.2 Data other people give us about you
Kera is shared, so other people can enter data about you:
- another member may invite you, record a purchase you made, add a preference about you (for example an allergy), or create a gift occasion for you;
- a guest on a public gift page may leave their first name when they claim a gift (section 14).
If you put information about someone else into Kera (for example a family member’s allergy or a friend’s birthday), please make sure they’re happy for you to do so.
3.3 Data we collect automatically
| Category | What it is | Why |
|---|---|---|
| Sign-in data | A session token (valid 7 days), stored on your device; password-reset and email-change links (single-use, short-lived); for a child profile, one-time sign-in codes (10 minutes) and, for each device the child signs in on, a random device token and the device’s name | Keeping you signed in; account recovery |
| Age check at sign-up | The birth month and year you enter (used once, then discarded); the time you confirmed you’re an adult; if your Google or Apple account reports an age, only that it said you’re an adult and which store | Making sure accounts are for adults (section 13) |
| Device and delivery data | Push-notification token, device platform, app version; app-update checks | Delivering notifications and app updates |
| Usage data | Which features you use and when; the days you’re active; when you were last active; the domain of your email address (for example “gmail.com”, never the full address); the amount and shop of purchases you record; a session identifier | Understanding which features work and improving Kera (section 4) |
| Error reports | When the app or our server hits an error: what went wrong, your user ID (not your name or email), app and device version, and on our server the address of the request that failed (with any query details removed) | Finding and fixing bugs |
| IP address | Used for a few seconds to limit how many requests one connection can make; not stored in our database. Our hosting providers may log it (section 10) | Security and abuse prevention |
| AI usage records | Which AI feature ran for your household, the model, how many tokens it used, its cost and whether it failed. No message content. | Controlling cost and quality |
| Connected AI apps (only if you connect one) | Which app you connected, to which household, the permissions you allowed, and when you connected and last used it; the app’s sign-in keys, stored only in scrambled, one-way form; a log of each request the app makes (which action, which household, success or failure, how long it took; never what was asked or answered) | Running the connection, keeping it secure and preventing abuse (section 6.5) |
3.4 Data we don’t collect
- Payment details: Kera doesn’t take payments and has no card or bank-login details.
- Bank connections: Kera doesn’t connect to your bank.
- Government ID.
- Precise location: we never store a precise GPS position.
- Your address book: see section 7.
- Date of birth: when you sign up we ask for your birth month and year to check you’re an adult, and then discard them. For a child profile we ask only for an age band.
4. How we use your data, and our legal bases
The table lists each purpose. The “legal basis” column applies under the EU and UK GDPR, the Law of Georgia on Personal Data Protection, and similar laws (see the supplements for other countries).
| Purpose | Data used | Legal basis |
|---|---|---|
| Running your account and household: sign-in, requests, approvals, purchases, budgets, recurring items, wishlists, notifications you’ve allowed | Account, household, shopping, money, wishlist data | Contract: we need it to provide the service you signed up for |
| AI features you choose to use: the assistant, voice, receipt and photo reading, link and recipe reading, search, gift research | What you send to that feature, plus the household context it needs (section 6) | Contract |
| Connected AI apps you choose to connect: sending the app the household information it asks for, and making the changes it asks for, within the permissions you allowed (section 6.5) | Your household’s list and, depending on the permissions, budgets, spending, past prices and requests waiting for you | Contract: you ask us to do it |
| Automatic AI helpers: suggesting a category, spotting a duplicate item, generating a picture for an item with none | Item names | Legitimate interests (see below) |
| Health-related preferences (allergy and dietary notes) | Those notes | Your explicit consent (section 5) |
| Child profiles: creating a child’s profile and running it (requests, wishes, comments, photos and voice memos the parent allows, notifications, parent controls) | The child’s data (section 13) | Consent of the child’s parent or guardian (GDPR Art. 6(1)(a) and Art. 8); explicit consent for health notes about the child (Art. 9(2)(a)) |
| Proving parental consent and handling a parent’s requests | Consent records; requests | Legal obligation |
| Age check at sign-up | Birth month and year (not kept); store age signal | Legal obligation where the law requires age assurance; otherwise legitimate interests in keeping accounts for adults |
| Approximate location for nearby-shop suggestions | City/country or rounded position | Consent |
| Contacts, camera, microphone, photo library, notifications | See section 7 | Consent (the device permission) together with contract for the feature |
| Security and abuse prevention: rate limits, fraud and misuse checks, protecting accounts | Sign-in data, IP address (briefly), usage data, connected-app activity log | Legitimate interests |
| Fixing errors | Error reports | Legitimate interests |
| Improving Kera from usage data | Usage data | Legitimate interests; you can object (section 12) |
| Service emails (password reset, email change) | Email address | Contract |
| Replying to website messages and sending early-access updates you signed up for | Name, email address, message | Consent; you can unsubscribe from updates at any time |
| Handling your privacy requests and keeping records of them | Your request and our reply | Legal obligation |
| Complying with the law, responding to lawful requests, defending legal claims | As needed | Legal obligation; legitimate interests |
Our legitimate interests, in plain terms:
- Automatic AI helpers: keeping lists tidy and easy to scan. We only send the item name, not who added it.
- Security: keeping Kera and your account safe.
- Fixing errors: making the app work. Error reports carry a user ID, not your name or email.
- Improving Kera: learning which features people use. We look at this internally, don’t share it with advertisers, and don’t use it to make decisions about you.
We’ve weighed these interests against your rights and believe the processing is expected and low-impact. You can object at any time (section 12).
Do you have to give us your data? You need an email address, display name and password to create an account, and a household to use most features. Everything else is optional; if you don’t provide it, only the related feature won’t work.
What we don’t do: we don’t sell your personal data, share it for cross-context behavioural advertising, give it to data brokers, show ads, or use it for advertising profiles.
5. Allergy and dietary notes (health information)
Allergy and dietary notes (“no peanuts”, “gluten-free”, “Nino is lactose intolerant”) can reveal health information, which the law gives extra protection. We use them only so that Kera doesn’t suggest something unsafe and can respect your household’s needs.
- Consent: before you save your first allergy or dietary note, Kera asks for your explicit consent and explains that the note will be shared with the household and with our AI providers when the assistant is used.
- Notes about someone else: a note can be linked to another household member. Only add one if that person agrees. A note about a child with a child profile can be added only after the child’s parent or guardian has given separate consent (section 13).
- Who sees them: members of your household, and the AI provider running the assistant when any household member uses it (section 6).
- Withdrawing consent: in Settings → Privacy & data → Health notes consent, withdraw the consent; the notes it covered are deleted. You can also delete a single note: its author or a household Admin can delete it. Once a note is deleted we stop using it.
- When your account is erased: notes you wrote, and notes about you, are deleted.
6. AI features
6.1 You’re talking to an AI
The assistant, Kera, is an AI system, not a person. Its replies are generated by AI models and can be wrong, so check anything important (especially prices and allergens) before relying on it. Kera’s voice is synthetic (AI-generated), not a recording of a real person. The app labels the assistant as AI in the chat and during voice calls.
6.2 What the assistant can and can’t do
The assistant can suggest items, answer questions about your list and budget, look things up on the web, and find product prices. It is advisory only:
- it never buys anything and never spends or moves money;
- anything it proposes (an item, a wish, a saved preference) is added only after a person taps to confirm;
- approvals, purchases and budget changes are always made by a household member.
Kera makes no decision based solely on automated processing that has legal or similarly significant effects on you. Budget warnings are simple arithmetic. Household “auto-approve” rules are set by your household’s Admin, not by AI.
6.3 What we send to which AI provider
| When you… | What’s sent | To |
|---|---|---|
| Chat with the assistant | Your message and conversation so far, plus household context it looks up: list items, household name, budget and spending figures (which can include members’ display names next to what they spent), saved preferences including allergy and dietary notes | OpenAI (main); Anthropic (if OpenAI fails) |
| Talk to the assistant (voice) | Your voice audio, to turn it into text; the reply text, to turn it into speech | OpenAI and/or Google (whichever is configured, with the other as backup) |
| Make a live voice call with Kera | Your voice audio, streamed directly from your device, plus the same household context as a chat. A written transcript of the call is saved to your conversation history. | Google or OpenAI |
| Use the microphone button when adding an item | Your voice, turned into text by your phone’s or browser’s own speech recognition (Google on Android and Chrome, Apple on iOS and Safari), under their terms; the text then goes to Anthropic to be split into items | Google or Apple (device service); Anthropic |
| Photograph a product (snap-to-add) or a receipt | The photo | Anthropic only |
| Paste a product link or recipe | The web address; the page’s text | We fetch the page from our servers; Anthropic reads the text |
| Add an item | The item name, to suggest a category and check for duplicates | Anthropic |
| Add an item with no matching picture | The item name, as a picture prompt | Replicate |
| Ask for spending insights, restock or setup suggestions | Spending and list figures for your household | Anthropic |
| Ask the assistant to search the web, “find options” for an item, or research a gift | A search query written by the assistant. We instruct it never to include your name, email or household details, but that is an instruction to the AI, not a technical filter. | Brave Search; Shopify (catalog search: the search text only); shop websites we fetch from our servers; Anthropic (gift research summaries) |
Children: children can’t use any of these features. A child’s name, household handle and account ID are never sent to an AI, search or image provider, and neither is anything a child writes (request notes, comments, wish notes, their own preferences). When an adult uses the assistant, the names of things a child asked for and allergy or diet notes about a child can be part of the household context, labelled “a child in the household”. Items a child adds never get an AI-generated picture. See section 13.
We don’t send photos or voice audio to any AI provider other than those listed for that row.
How the AI providers may use your data. They act as our processors: they process the data to return a result to us. Under our agreements with them, they may not use it to train their models. Providers may keep data for a short period for abuse monitoring (OpenAI says up to 30 days). We ask OpenAI not to store assistant responses beyond that.
6.4 Your choices
- Most AI features run only when you use them. You can avoid them by not using the assistant, voice, or photo and link reading.
- Automatic AI helpers (category suggestions, duplicate checks, item pictures) run on item names when an item is added. To turn off AI processing for your household, email hello@spin.ge and we’ll switch it off.
- You can delete any assistant conversation from its history. To stop conversations being kept at all, email us and we’ll turn off conversation history for your household.
6.5 Connected AI apps (ChatGPT, Claude)
You can connect Kera to an AI app you already use, such as ChatGPT or Claude, and ask it about your household’s list and budgets there. This is optional and off until you set it up. You start it from the AI app; Kera then asks you to sign in, choose one household and review what the app may do. Nothing is connected until you tap Allow. If you never connect an AI app, this section doesn’t apply to you.
What the app can see or do. Only what the permission screen lists, only for the household you chose, and only while the connection is active:
- See your household’s shopping list: the items on the list (name, status, category and quantity) and the names of recently bought items.
- See your budgets, spending and past prices: the “safe to buy” figure, the budget left for a category, spending totals by category, shop, member (by display name) and item, and what your household paid for an item before.
- Add items to your shopping list and add items to your wishlists: they’re added under your household’s normal rules, as if you had added them in Kera.
- See requests waiting for your approval and approve or decline requests, where Kera offers these: each request’s name, quantity and category and the first name of the member who asked, and approving or declining it as you would in the app.
Because Kera is shared, what the app sees includes things other members added, the first names of members who asked for something and, with the budgets permission, what each adult member spent under their display name. If you’re a Requester in that household, the app gets no budgets, spending, prices or approvals, just as in the Kera app.
What the app never gets. Your password, your other households, members’ email addresses, and anything about children in the household. An item a child asked for is shown to the app only as “an item a child asked for”, with no name or details; a child’s name is removed from everything the app receives, and a child’s spending is merged into one unnamed row. A child’s requests can’t be seen in detail or answered from the app, a wish can’t be saved for a child’s occasion, and a child profile can’t connect an AI app.
A connected app can’t buy anything. It can’t make a purchase, spend or move money, or change budgets through Kera, and Kera has no card or bank details to give it.
Who is responsible for what. Connecting is your choice, and we send the information to the app at your request, only when it asks and only while the connection is active. This is different from section 6.3, where OpenAI and Anthropic work for us as processors: when you connect ChatGPT, Claude or another AI app, the company behind that app receives the information for you, under the terms and privacy policy you agreed with it (for example OpenAI’s for ChatGPT, Anthropic’s for Claude), and decides itself how to use and keep it, which may include processing it in the United States. What that company does with the information after it receives it is covered by its privacy policy, not this one.
How to disconnect. In Kera, go to Settings → Privacy → Connected apps and tap Disconnect; the app loses access at once. Changing or resetting your password, changing your email address, leaving the household or deleting your account also ends every connection. Removing Kera inside the AI app stops that app using it; to be sure the connection is closed on our side too, disconnect it in Kera. Disconnecting doesn’t delete what the AI app already received: use the AI app’s own settings, or contact the company behind it, for that.
7. Device permissions
Every permission is optional, and you can turn it off at any time in your device settings. Turning one off only stops the related feature.
| Permission | What it’s for | What happens to the data |
|---|---|---|
| Camera | Snap-to-add, receipt scanning, barcode scanning, item photos, scanning the code that signs a child in on their device | Product and receipt photos go to Anthropic to be read and aren’t stored unless you keep one as an item picture or attachment. Barcodes are looked up by number only (section 8.2). |
| Photo library | Choosing an existing picture | Only the pictures you pick are read |
| Microphone | Voice notes, talking to the assistant, voice calls | Voice notes are stored with the item. Voice sent to the assistant isn’t stored by us (section 6.3). |
| Notifications | Approvals, budget alerts, price drops, reminders | Kera asks after you first sign in; you can say no. On a child’s device, Kera sends notifications only if the parent left them on; from the next app update, the child’s device also asks for permission only then. Manage categories and quiet hours in Settings → Notifications. |
| Contacts | Showing your contacts when you add household members during setup | The app reads your contacts on your device to show the list. Nothing from your address book is sent to us or stored. Invites are codes that you share yourself; Kera never contacts anyone in your address book. |
| Location (approximate) | Suggesting shops near you | Off until you turn it on. Your device’s approximate position is sent to our server, which rounds it to about 1 km before storing it; the unrounded value isn’t kept. You can type a city instead. Remove it any time in the app. |
8. Who we share your data with
8.1 Inside your household
Kera is built for sharing. Members of your household can see what you add to it: your display name, requests, comments, reactions, photos and voice notes, purchases, wishes that you’ve made visible to the household, and preferences. What each member sees depends on their role; for example, children can’t see household money (section 13).
If a parent adds a child to the household, a child profile’s requests, comments, reactions, photos, voice memos and wishes are visible to every household member, like everyone else’s.
Household Admins and Buyers can export the household’s data, including every member’s display name, email address and role.
8.2 Service providers (processors)
These providers process personal data on our behalf, under contracts that require them to protect it and use it only to provide their service to us.
| Provider | What they do for us | Personal data they receive | Location |
|---|---|---|---|
| Neon | Database | All data stored in Kera | EU (Frankfurt) |
| Fly.io | Runs our servers | All data passing through our servers; server logs, which include user and household IDs and purchase amounts and shops recorded as usage data | EU (Frankfurt) |
| Cloudflare (R2) | File storage | Photos, voice notes, item pictures | Global network |
| Vercel | Hosts the web app and the aikera.io website | Technical request data (such as IP address and browser) | Global network |
| OpenAI | Assistant, speech-to-text, text-to-speech, live voice | See section 6.3 | United States |
| Anthropic | Assistant (backup) and the AI helpers in section 6.3; reading photos and receipts | See section 6.3 | United States |
| Google (Gemini) | Speech-to-text, text-to-speech, live voice | Voice audio; the assistant’s context during live calls | United States / global |
| Replicate | Generating item pictures | Item names | United States |
| Brave Search | Web and product search | Search queries | United States |
| Shopify | Product catalog search | The search text only | Canada / United States |
| Resend | Service emails; early-access mailing list | Your email address and the reset, change or email-confirmation link; emails to a parent about their child’s profile (consent, confirmation, reminders), which include the child’s first name; the name and email address of early-access sign-ups | United States |
| Expo | Delivering push notifications; app updates | Push token, device platform, and the notification text, which can include members’ names, item names and prices | United States |
| Sentry | Error reports | See section 3.3 | EU (app); EU or United States (server) |
Notifications are handed by Expo to Apple (APNs) or Google (Firebase Cloud Messaging) to reach your device, including the notification text.
8.3 Other services our servers contact
These receive no personal data about you from us, or only what you asked us to look up:
- Barcode databases (Open Food Facts, Open Beauty Facts, Open Products Facts, Open Pet Food Facts, Open Library, UPCitemdb): the barcode number only.
- OpenStreetMap Nominatim and Overpass: the city and country you typed, or your rounded (~1 km) position, to find nearby shops.
- Exchange-rate services (Frankfurter/European Central Bank, Fawaz currency API): currency codes and dates only.
- Google favicon service: shop web addresses, to show shop logos.
- Shop websites: when you paste a link or watch a price, our servers visit that page. If the web address you pasted contains personal information, the shop’s site receives it.
Some features we’ve built aren’t active: we don’t currently use Amazon’s product API or any affiliate network, and we earn no affiliate commissions. If that changes, we’ll update this policy first and label affiliate links in the app.
8.4 Our staff
A small number of SPIN LLC staff can access Kera’s data through an admin console, to provide support, keep Kera running and handle privacy requests. Every staff action is logged. Children’s names and emails are hidden from staff by default; revealing them requires a senior role and is logged.
8.5 Other disclosures
We may disclose data if the law requires it, to respond to a valid legal request, to protect the rights, safety or property of our users, the public or us, or as part of a merger, acquisition or sale of assets. In that case, the buyer would have to honour this policy, and we would tell you where the law requires.
8.6 AI apps you connect
If you connect an AI app to Kera, such as ChatGPT (OpenAI) or Claude (Anthropic), we send it the household information described in section 6.5, at your direction. The company behind the app receives it on its own account, under its own terms and privacy policy, not as our service provider.
9. Where your data is processed
Our database and servers are in the European Union (Frankfurt). SPIN LLC is based in Georgia and staff access the data from there. Several providers in section 8.2 are in the United States or operate globally, so your data is also processed there.
Georgia and the United States don’t have the same data protection laws as the EU or UK, and Georgia does not have an EU adequacy decision. Where the law requires, we protect transfers with:
- the European Commission’s Standard Contractual Clauses (with the UK Addendum or Swiss amendments where relevant);
- an adequacy decision, where one applies, such as the EU–US Data Privacy Framework for US providers certified under it;
- safeguards required by Georgian law for transfers out of Georgia.
You can ask for a copy of these safeguards at hello@spin.ge.
10. How long we keep your data
| Data | How long |
|---|---|
| Your account | Until it’s erased (section 11). After erasure an anonymous placeholder remains so shared household records still add up; it contains nothing that identifies you. |
| Household and its content (list items, purchases, budgets, money tracking, recurring items, shared wishes) | While the household exists. A household Admin can delete the household; when no active members remain, we delete the household and its content within 30 days. |
| Photos, voice notes, item pictures | Until deleted by you or your household, or until your account is erased. When an item is deleted, its files are deleted too. |
| Comments and reactions | Until deleted, or until your account is erased. |
| Allergy, dietary and other preferences | Until deleted, or until the author’s or subject’s account is erased. |
| Assistant conversations (including call transcripts) | Until you delete them, or until your account is erased |
| Approximate location | Until someone in your household removes it |
| Voice sent to the assistant, receipt and snap-to-add photos, bank statement files | Not stored by us (processed and discarded). AI providers may keep them briefly (section 6.3). |
| Session token on your device | Up to 7 days, or until you sign out |
| Password-reset link | 1 hour, single use |
| Push token | Until you sign out, the token stops working, or your account is erased |
| Usage data | 13 months, then deleted. |
| AI usage records (no content) | 12 months. |
| Assistant quality records (no content) | 90 or 180 days depending on type |
| In-app notification list (the notifications Kera sent you, including their text) | 90 days, then deleted. |
| Connected AI apps (which app, which household, the permissions, when you connected and last used it) | While the connection is active. After you disconnect, kept with your account’s history until your account is erased or the household is deleted. |
| Connected-app sign-in keys (stored only in scrambled, one-way form) | Until 30 days after they expire or the connection ends, then deleted. |
| Connected-app activity log (which action, which household, success or failure, how long it took; never what was asked or answered) | 180 days, then deleted. |
| Error reports | Up to 90 days |
| Gift-page guest names | 90 days after the occasion date, or sooner if the wish is removed. |
| Website messages and early-access sign-ups | Until you ask us to delete them. If you unsubscribe, we stop sending updates. |
| Records of privacy requests | 24 months after the request is closed. |
| Children’s data | See the Children’s Data Retention Policy in the Children’s Privacy Notice. In short: a child’s photos go 30 days after the request closes (180 days at most; voice memos 90 days at most), comments and reactions 90 days after the request closes, usage data after 90 days, and an unused profile after 12 months. |
| Parental consent records | While the child’s profile exists, then 3 years after consent is withdrawn or the profile is erased, to show we obtained consent. They never contain the child’s name. |
| Requests to add a child that weren’t confirmed | 7 days |
| Age check at sign-up | Your birth month and year aren’t kept. The time you confirmed you’re an adult, and any store age signal result, are kept with your account. |
| Health-notes consent records | 3 years after you withdraw consent, the household is deleted, or the person the notes were about is erased, to show we obtained consent. |
| Staff audit log | 365 days. Your name and email are removed from it when your account is erased. |
| Backups | Kept by our database provider for up to 30 days, then overwritten. Erased data may remain in a backup until then, and we don’t restore it. |
| Hosting and email provider logs | Per each provider’s own retention |
We may keep specific data longer if we have to for legal reasons, for example to handle a dispute or comply with a legal order.
11. Deleting your account
How to delete: in the app, go to Settings → Privacy & data → Delete my data. You can also ask at https://aikera.io/account-deletion or email hello@spin.ge from your account’s email address.
What happens:
- Straight away: your account is deactivated, you’re signed out on every device, and any AI app you connected loses access.
- 30-day grace period: if you change your mind, sign back in within 30 days and the deletion is cancelled.
- After 30 days: your personal data is erased automatically. We:
- replace your email address, display name and password with meaningless placeholders, so the account can’t be used or linked to you;
- delete your push tokens, notification settings, in-app notification list, password-reset and email-change links, and assistant conversations;
- delete your connected AI apps and their sign-in keys;
- delete your photos, voice notes and item pictures you uploaded (including the stored files);
- delete your comments and reactions;
- delete preferences you wrote and preferences about you;
- delete the wishes you created;
- remove your user ID from usage data;
- remove your name and email from our staff audit log.
What stays, and why: records your household relies on, such as list items, purchases, budgets and settle-up entries, stay with the household so the other members’ history and totals are still correct. After erasure they show as added or bought by ”Removed member” and aren’t linked to you.
If you’re the only Admin of a household, Kera asks you to hand the Admin role to another member or delete the household before your account is deleted.
If you’re a parent of a child profile: if no other parent or guardian of the child keeps their account, deleting your account also withdraws consent for your child and erases the child’s profile when your erasure takes place. The app tells you before you confirm. Signing back in within 30 days cancels both.
Data may remain in backups for the period in section 10.
12. Your rights
Depending on where you live, you have some or all of these rights:
| Right | What it means |
|---|---|
| Access | Get a copy of your personal data and information about how we use it |
| Portability | Get your data in a machine-readable format, or have us send it to another service where feasible |
| Correction | Fix data that’s wrong or incomplete |
| Deletion | Have your data erased (section 11) |
| Restriction | Ask us to pause using your data in some situations |
| Objection | Object to uses based on our legitimate interests, such as usage analytics; we’ll stop unless we have compelling grounds |
| Withdraw consent | Where we rely on consent (health notes, location, device permissions), withdraw it any time. This doesn’t affect what we did before. |
| Complain | Complain to a data protection authority (see the supplements) |
In the app you can:
- export your household’s core data (Settings → Privacy & data → Export my data; Admins and Buyers). The export includes your account, household members, items, purchases, budgets, recurring items and your connected AI apps (never their sign-in keys). For a complete copy of everything we hold about you, email us.
- change your email address, display name, items and preferences;
- turn usage analytics and crash reports on or off (Settings → Privacy & data);
- manage notifications, remove your location, delete conversations, disconnect AI apps you’ve connected, and delete your account.
To exercise any right, email hello@spin.ge. We may ask you to confirm the request from your account’s email address or to answer questions to verify your identity; we won’t ask for more information than we need. You can use an authorised agent where your law allows; we’ll ask them for proof of authority. We reply within one month (sooner where local law requires, see the supplements), and tell you if we need more time and why. It’s free unless a request is clearly unfounded or excessive.
Parents can exercise these rights for their child in the app (House tab → Children → your child → Privacy & controls) or as section 13 describes.
If we refuse a request, we’ll explain why and how to appeal or complain.
We won’t treat you differently (for example by charging more or offering a worse service) because you used your rights.
13. Children
Kera accounts are for adults: nobody under 18 may create their own account. When you sign up, we ask for your birth month and year without saying which answer is needed, and we may check the age on your Google or Apple account. If we learn that someone under 18 has created their own account, we’ll delete it.
Children can take part in a household only through a child profile set up by their parent or guardian, after the parent gives verifiable consent. This section summarises how we treat children’s data; the Kera Children’s Privacy Notice gives the full detail, including the notice to parents required by the US Children’s Online Privacy Protection Act (COPPA) and our written children’s data retention policy.
- Only a parent or guardian can add a child. An adult household member who confirms they’re the child’s parent or legal guardian, and whose email address is confirmed, asks to add the child. We email that address; the parent opens the link while signed in and gives consent on a form. We create the profile only then, and send a second email 24 hours later so the account holder can undo it. A child profile has no email address, phone number or password: the parent signs the child in on their device with a one-time code, and the child uses a PIN.
- What a child profile collects: a first name or nickname and an age band (from the parent); the requests, comments, reactions, preferences and wishes the child adds; photos and voice memos (on unless the parent switches them off); a notification token (if notifications are on); sign-in details (a hashed PIN and a token and name for each device); usage data (IDs and counts only) and error reports. Adults can add allergy and diet notes about the child only with the parent’s separate consent.
- What the parent controls: photos, voice memos, notifications and the wishlist can each be switched off at any time. The parent can see, download or delete the child’s data, pause the profile, sign out the child’s devices, reset the PIN and withdraw consent.
- What children can’t do: buy, approve requests, invite people, share gift pages, create or join a household, scan receipts or products, import statements, use location, web or product search, the assistant, voice features or other AI features, or export data. They don’t see household money unless an Admin chooses to let them see budgets.
- Children’s data and AI: the name of an item a child adds goes to Anthropic for category and duplicate checks, with nothing that identifies the child. Items a child adds never get an AI-generated picture, and links a child pastes are read without AI. When an adult uses the assistant, the names of things a child asked for and allergy or diet notes about the child can be sent, labelled “a child in the household”, never with the child’s name. A child’s photos, voice memos and anything they write are never sent to an AI provider. These providers act as our processors and may not use the data for their own purposes. An AI app an adult connects to Kera (section 6.5) never receives a child’s name or the details of anything a child asked for.
- No ads, no profiling: we never show ads to children, use their data for behavioural advertising, sell it, or build marketing profiles.
- Children’s files: photos and voice memos are stored privately and open only through short-lived links given to signed-in members of the household (section 16).
- Public gift pages: a child’s wishes, an occasion for a child and a child’s name are never shown on a public gift page (section 14).
- Parents’ rights: in the app (House tab → Children → your child → Privacy & controls), by email to hello@spin.ge, or by phone on +1 908 742 4951. Withdrawing consent signs the child out at once and erases the profile within 30 days.
If you think a child has given us data without their parent’s consent, email hello@spin.ge and we’ll delete it.
14. Public gift pages and guests
An Admin or Buyer can create a public link to a gift occasion so friends and family outside Kera can see the wish list and claim a gift.
What the page shows: the occasion’s name, its next date and how many days away it is, the first name of the person who shared it, the wishes’ names and pictures, and (if the sharer chose) prices. It doesn’t show members’ emails, other household data, or who has claimed what. It never shows a child’s wishes, an occasion for a child, or a child’s name, and an occasion for a child can’t be shared.
What we collect from guests: if you claim a gift, just the first name you type. We don’t ask guests to create an account, and don’t set cookies. We use your name so the household knows the gift is taken (legitimate interests in making gift-giving work). We keep it for the time in section 10. To have it removed sooner, email hello@spin.ge. The page links to this policy.
Links expire after 90 days at most (30 by default) and can be turned off any time by the household.
15. Cookies and browser storage
The Kera web app doesn’t use cookies, advertising trackers or third-party analytics. It uses your browser’s local storage to:
- keep you signed in (your session token);
- remember your settings and dismissed tips;
- queue actions made offline until you’re back online.
These are needed for the features you ask for, so we don’t ask for consent. You can clear them in your browser at any time, which signs you out.
The mobile app stores your session token in your device’s secure storage.
16. Security
We protect your data with measures appropriate to the risk, including:
- encryption in transit (HTTPS/TLS) for all traffic;
- passwords stored only as salted bcrypt hashes;
- sessions that expire, and that we can end on all devices at once (for example after a password reset or deletion request);
- checks that you belong to a household, and your role, on every request;
- rate limits to slow down abuse;
- protections against our servers being tricked into fetching internal addresses, and checks on uploaded files;
- logging of every staff action in the admin console, and two-factor sign-in required for every staff account;
- for a child’s profile: a PIN locked for 15 minutes after 5 wrong tries, and one-time sign-in codes that expire after 10 minutes;
- encryption at rest provided by our database and storage providers.
Photos, voice notes and your household’s own item pictures are stored privately. The app opens them through short-lived links that only signed-in members of your household receive (a public gift page also receives such links for the wishes it shows). Our shared picture catalog, shop logos and product photos from public barcode databases stay public, because they contain no personal data.
No system is completely secure. If a breach puts your data at risk, we’ll notify the relevant authorities and you where the law requires (for example, within 72 hours under the GDPR and Georgian law).
17. Changes to this policy
We’ll update this policy as Kera changes. We’ll post the new version with its effective date. For important changes we’ll tell you in the app or by email before they take effect and, where the law requires, ask for your consent again. The previous version is at aikera.io/privacy/v1.1 and version 1.0 at aikera.io/privacy/v1.0; older versions are available on request.
18. Contact
SPIN LLC · Ana Politkovskaia Street 22a, Floor 10, Apt 140, Vake District, Tbilisi 0186, Georgia Privacy: hello@spin.ge · Support: support@aikera.io
Regional supplements
These supplements add to the policy above for people in the listed places. If a supplement conflicts with the main policy, the supplement applies to you.
A. European Economic Area, United Kingdom and Switzerland
- Controller: SPIN LLC (section 1).
- Legal bases: section 4. Health information: explicit consent (GDPR Art. 9(2)(a)), section 5.
- Automated decisions: none with legal or similarly significant effects (GDPR Art. 22), section 6.2.
- Transfers: section 9.
- Rights: section 12, under GDPR Arts. 15–21. We reply within one month, extendable by two months for complex requests.
- Complaints: you can complain to the data protection authority where you live or work, or where the issue happened (in the EU, list at edpb.europa.eu). UK: Information Commissioner’s Office (ico.org.uk). You can also complain to us first and we’ll acknowledge it within 30 days. Switzerland: Federal Data Protection and Information Commissioner (FDPIC).
- AI transparency (EU AI Act Art. 50): section 6.1.
- Children: section 13 and the Children’s Privacy Notice. We ask for the consent of the holder of parental responsibility for every child under 18, including where a younger age of digital consent applies in your country (GDPR Art. 8), and for explicit consent for health notes about a child.
B. Georgia
The Law of Georgia on Personal Data Protection (2023, in force since 1 March 2024) applies to our processing.
- Rights: to be informed, access, correction, update and completion, deletion or destruction, blocking (restriction), portability, withdraw consent, and to object to automated decisions.
- Response time: we reply within 10 working days, extendable where the law allows.
- Complaints: Personal Data Protection Service of Georgia (personaldata.ge).
- Minors: a child under 18 can use Kera only through a child profile created by their parent or legal representative, with the parent’s consent, confirmed as described in section 13. Health notes about a child need the parent’s separate consent.
- Transfers out of Georgia: section 9.
- Breach notification: we notify the Personal Data Protection Service where required, within 72 hours.
C. United States
C.1 Children (COPPA)
Kera is a general-audience service. A child under 13 can use Kera only through a child profile their parent creates after giving verifiable parental consent by email (“email plus”). Our Children’s Privacy Notice is the notice COPPA requires: it lists what we collect from children, how we use it, the service providers that handle it, our written retention policy, and parents’ rights. We don’t disclose children’s personal information to third parties other than service providers that support our internal operations. If we learn that we’ve collected personal information from a child under 13 without a parent’s consent, we’ll delete it. A parent or guardian can review or delete their child’s data, or refuse further collection, in the app, by email to hello@spin.ge, or by phone on +1 908 742 4951.
C.2 Your US state privacy rights
This part applies to residents of California, Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws, to the extent those laws apply to us.
Personal information we collected in the past 12 months:
| Category (California terms) | Examples | Source | Purpose | Disclosed for a business purpose to |
|---|---|---|---|---|
| Identifiers | Email, display name, user ID, push token, IP address (briefly) | You; your device | Accounts, security, notifications | Hosting and database providers, Resend, Expo, Sentry |
| Customer records | Name, email | You | Accounts | Hosting and database providers |
| Commercial information | Items, purchases, prices, budgets, wishes | You; household members | Core service | Hosting providers; AI providers (section 6.3) |
| Internet or other network activity | Feature use, error reports | Your device | Analytics, fixing errors | Sentry, hosting providers |
| Geolocation | City/country, or position rounded to ~1 km | You | Nearby shops | OpenStreetMap services |
| Audio and visual | Voice audio, voice notes, photos | You | Voice, photo features | Cloudflare, OpenAI, Google, Anthropic |
| Sensitive personal information | Account login (email and password); health information (allergy and dietary notes) | You; household members | Sign-in; safe suggestions | Hosting providers; AI providers |
| Inferences | None used to build profiles | — | — | — |
We don’t sell or share personal information (including for cross-context behavioural advertising), and haven’t in the past 12 months. We don’t knowingly sell or share the personal information of consumers under 16. We use sensitive personal information only for purposes the law permits without a right to limit (providing the service you asked for, security and integrity), so we don’t offer a “limit the use” option.
Your rights: to know what we collect and disclose, access, correction, deletion, portability, and to opt out of sale, sharing, targeted advertising and profiling (which we don’t do). Where your state requires consent for sensitive data, we ask for it (section 5). Exercise them by emailing hello@spin.ge. We’ll verify your identity (section 12) and reply within 45 days, extendable once by 45 days. An authorised agent may act for you with written permission. If we deny your request, you can appeal by replying to our decision; we’ll respond within the time your state law sets and, if we deny the appeal, tell you how to contact your state Attorney General.
No discrimination: we won’t treat you differently for using your rights.
Retention: section 10.
C.3 Consumer health data (Washington, Nevada and similar laws)
Allergy and dietary notes can be “consumer health data” under Washington’s My Health My Data Act and similar laws. We collect them only with your consent (section 5), use them only to make Kera’s suggestions safe and relevant, share them only with household members and our processors (the AI providers in section 6.3), never sell them, and delete them when you ask. You can ask to access, delete or withdraw consent at hello@spin.ge.
D. Other countries
| Country | What applies to you |
|---|---|
| Canada (PIPEDA; Quebec Law 25) | Rights to access and correct your data and withdraw consent. Kera’s privacy-invasive features (location) are off by default. You can reach the person in charge of personal information at hello@spin.ge. Your data is processed outside Canada and Quebec (section 9). Complaints: Office of the Privacy Commissioner of Canada; in Quebec, the Commission d’accès à l’information. |
| Brazil (LGPD) | Legal bases as in section 4 (contract, legitimate interests, consent, legal obligation; health notes on specific, highlighted consent). Rights under LGPD Art. 18, including confirmation of processing, anonymisation, information about sharing and revoking consent. We reply to a full request within 15 days. You can reach our contact for data subjects (encarregado) at hello@spin.ge. Complaints: ANPD (Autoridade Nacional de Proteção de Dados). Children’s data is processed in their best interest with a parent’s specific consent (LGPD Art. 14). |
| Australia (Privacy Act, APPs) | You can access and correct your data and complain to us; if unhappy with our response, to the Office of the Australian Information Commissioner (oaic.gov.au). We disclose data to providers in the United States and the EU (sections 8–9). |
| India (DPDP Act 2023) | We process your data with your consent as described in this notice, which you can withdraw as easily as you gave it. Rights: access to a summary of your data, correction, completion, erasure, grievance redressal, and nominating someone to act for you. Contact our grievance officer at hello@spin.ge. If unresolved, you can complain to the Data Protection Board of India. Under Indian law, anyone under 18 is a child; a child can use Kera only through a child profile created with a parent’s verifiable consent (section 13). |
| Japan (APPI) | You can ask us to disclose, correct, stop using or delete your retained personal data. We provide data to providers in the United States and other countries (sections 8–9). On request, we’ll tell you about those countries’ data protection systems and the measures the providers take. Complaints: Personal Information Protection Commission. |
| South Korea (PIPA) | Rights to access, correct, delete and suspend processing; we reply within 10 days. We transfer data overseas to the providers, countries and for the purposes and periods in sections 8–10, via network transmission when you use the relevant feature. You can refuse the transfer by not using that feature or by deleting your account. Children under 14 need a legal guardian’s consent. Complaints: Personal Information Protection Commission, or the KISA Privacy Call Center (118). |
| Türkiye (KVKK) | Rights under KVKK Art. 11; we reply within 30 days. Transfers abroad rely on the safeguards in section 9. Complaints: Personal Data Protection Authority (KVKK). |
| Switzerland (revFADP) | See supplement A. Complaints: FDPIC. |