Privacy Policy — Kiyaye
1) What Kiyaye does
Kiyaye lets members of a private, invitation-only circle share who currently holds responsibility for one person, record named claims about agreed duty windows, hand the watch to another member, and preserve visible disagreements without silently replacing either person's claim.
Scope: Kiyaye does not provide medical, care, emergency, dosage, treatment, or safety advice. Members decide their own duties and record only what they say happened.
2) Data we collect
- Account information: email address, display name, an internal user identifier, password-verification data, session records, and account status.
- Private-circle content: circle and central-person names, membership and escalation order, invitations, accepted watches and handover offers, duty titles and time windows, attributed done or not-done claims, optional notes, named explanations, acknowledgements, reports, blocks, and server timestamps.
- Optional health-related content: members may choose to put health-related details in a duty title or note. Kiyaye does not require, infer, diagnose, or recommend any health information.
- Notification data: an app-scoped Firebase Cloud Messaging registration token so the service can deliver watch and shared-record updates.
- Reliability data: idempotency identifiers, logical clocks, watch epochs, bounded clock offsets, and event sequence numbers used to merge retries without duplicating claims.
Kiyaye does not collect location, contacts, photos, files, audio, advertising identifiers, payment information, or analytics. The optional invite scanner is provided by Google Play services; it returns the selected QR value to Kiyaye without giving the app broad camera access.
3) Passwords and local protection
Passwords travel only over HTTPS. The service stores a salted PBKDF2-SHA-256 password hash, not the plain password. Session tokens, the authorized circle cache, and queued claims are encrypted on the device with Android Keystore-backed AES-GCM.
The optional Kiyaye App PIN stays on the device as a salted one-way value. Optional fingerprint or face unlock is handled by Android; Kiyaye does not receive biometric data. Neither device unlock method is enabled automatically.
4) How we use data
- Authenticate accounts and enforce membership on every private-circle request.
- Synchronize the accepted watch, claims, explanations, acknowledgements, reports, and membership controls across authorized devices.
- Detect six narrowly defined disagreement conditions while keeping every accepted claim attributable and visible.
- Suppress duplicate retries, order changes consistently when device clocks differ, and escalate an expired watch from the server even when an app is closed.
- Deliver generic push notifications and process reports of shared content or members.
5) Who can see data
Circle content is not public. Only signed-in active members of that exact circle can read it; invitations must be shared by a member, and server authorization is checked for every request. A signed-in outsider cannot read circle data. Reports may be reviewed by the developer to investigate abuse or child-safety concerns.
Members can see the names attached to claims, handovers, and explanations because attribution is the core function. Blocking another member hides supported optional text for the blocker without rewriting the shared factual record.
6) Service providers and transfers
- Cloudflare Workers and D1: authenticated API processing, encrypted transport, server state, scheduled escalation, and ordinary security/network metadata needed to operate and protect the service.
- Firebase Cloud Messaging / Google Play services: app-scoped notification delivery and the optional system QR scanner.
These companies process data for app functionality. We do not sell data, share it with advertisers, create advertising profiles, or use it for cross-app tracking. Global infrastructure may process data outside your country.
7) Data retention, export, and deletion
How long we keep your data. Kiyaye keeps data only for as long as the account or the private circle it belongs to exists, plus the limited periods below. We do not keep data for advertising, profiling, or sale, and we do not keep analytics profiles, advertising identifiers, location history, or contact lists, because the app never collects them.
- Account record (email address, display name, password-verification data): kept while the account exists. When you delete the account these fields are overwritten immediately — the email address is replaced with a non-working placeholder, the name becomes “Former member”, and the password data is destroyed — so that claims other members already relied on keep their place in the shared record without identifying you.
- Sign-in sessions: expire automatically 90 days after sign-in, and are deleted immediately when you sign out or delete your account.
- Notification registration tokens: kept while that device stays signed in; deleted when you sign out, delete your account, or uninstall the app.
- Private-circle content (circle and central-person names, memberships, watches, handover offers, duty titles and time windows, claims, explanations, acknowledgements, reports, blocks, and server timestamps): kept for as long as that circle exists, because the other members depend on the shared record. It is erased when the circle owner deletes the circle, and a circle left without an active member is deleted.
- Reliability data (idempotency identifiers, logical clocks, watch epochs, event sequence numbers): kept with the circle it belongs to and erased with it.
- Data stored on your phone (authorized circle cache, queued claims, app PIN): stays on the device until you delete the account or circle, sign out, clear the app’s storage, or uninstall Kiyaye.
- Backups: our database host keeps automatic point-in-time restore points for up to 30 days. Deleted data disappears from those restore points as they expire; it is not used to bring deleted content back.
What you can do at any time.
- Export: an active member can export the currently authorized circle record from Settings.
- Leave a circle: membership becomes inactive. Earlier claims remain in the circle because other members rely on the shared sequence.
- Delete account: Settings → Delete account removes sessions, notification tokens, active memberships, email address, display name, and password-verification data. Earlier shared claims remain only under a non-identifying “Former member” label. If the deleted account owns a circle, ownership transfers to another active member; a circle with no successor is deleted.
- Delete circle: the owner can permanently delete the circle and its server-side watches, offers, duties, claims, explanations, acknowledgements, reports, blocks, events, and memberships.
- Local copies: deleting an account or circle through Kiyaye clears its local authorized cache and queued data. Android also removes app-private data when the app is uninstalled or its storage is cleared.
If you cannot access the app, use the public Kiyaye account and data deletion page to send a deletion request.
8) Reports, blocking, and child safety
Every other member and every other member's shared claim has an in-app Report action. Members can also block another member, leave a circle, or remove a member when they own the circle. Kiyaye's separate Child Safety Standards explicitly prohibit child sexual abuse and exploitation (CSAE), child sexual abuse material (CSAM), grooming, sextortion, trafficking, and conduct that endangers a child.
9) Permissions and choices
- Internet and network state: required for authenticated synchronization and reliable retry status.
- Notifications: requested only on Android versions that require runtime approval and can be denied or disabled in Android Settings.
- Biometric use: used only if the member turns on Kiyaye's optional biometric App Lock.
The app does not declare broad camera, storage, microphone, contact, location, advertising-ID, or payment permissions.
10) Children
Kiyaye is intended for adults coordinating a private family watch and is not directed to children under 13 or the equivalent minimum age in their jurisdiction. If you believe a child has provided personal information or is at risk, use the in-app report path or contact the child-safety address below.
11) Security and changes
Kiyaye uses HTTPS, hashed opaque server sessions, encrypted local state, server-enforced circle authorization, deterministic duplicate suppression, and generic lock-screen notification text. No networked service can promise absolute security. We may update this policy when actual practices or legal requirements change; the effective date will change with it.
12) Contact
Saifullah Ahad
Email: www.saifullah.ai@gmail.com
Website: https://saifullah.ai
Location: Dhaka, Bangladesh