Back to home

Legal

Kepton — Privacy Policy

How Kepton collects, uses, and protects your information (GDPR / UK GDPR, CCPA/CPRA, India DPDP Act, and APAC-aware)

Effective date: [PLACEHOLDER: insert publish date]Last updated: [PLACEHOLDER: insert date]

This Privacy Policy explains how Kepton ("we," "us," "our") collects, uses, discloses, and protects information when you use the Kepton mobile application and the kepton.app website (together, the "Service"). It applies to users worldwide, with specific sections for the European Union / United Kingdom, the United States, India, and other Asia-Pacific jurisdictions.

1. Who Is Responsible for Your Data

Kepton is currently operated by an individual trading as "2 Bros," based in Pune, Maharashtra, India, who acts as the data controller (or "data fiduciary" under India's Digital Personal Data Protection Act, 2023) for the personal data described in this Policy.

ACTION NEEDED BEFORE PUBLISHING: Update this controller identity, and re-issue this Policy, if and when the operating entity is incorporated.

Privacy contact: support@kepton.app

ACTION NEEDED BEFORE PUBLISHING: India's DPDP Act requires a visible Grievance Officer contact once you have meaningful user volume. For now, support@kepton.app can serve this role, but note it here explicitly and update it if you appoint a dedicated Grievance Officer.

2. What Information We Collect

2.1 Account information

  • Email address, used for authentication and account recovery.
  • Trial and subscription status (trial end date, subscription tier).

2.2 Usage and productivity data

  • Tasks you create, including title, priority, and chosen timer duration.
  • Completed focus sessions and the resulting in-app "trees" and streaks.
  • Responses to onboarding and in-app preference questions about your energy levels and working style, used only to select a planning template.

ACTION NEEDED BEFORE PUBLISHING: Confirm the exact wording of your onboarding questions. They must ask about general working preferences, energy, and focus style, not about an ADHD diagnosis or symptom severity. If any question asks a user to self-report a diagnosis or medical symptom, that answer becomes "special category" health data under GDPR Article 9 and "sensitive personal data" under India's DPDP framework, which requires explicit, separate consent and additional safeguards. This Policy is drafted on the assumption that the current survey does not do this.

2.3 Device and technical data

  • Device type, operating system version, and app version, collected automatically for compatibility and support.
  • Crash and error diagnostic data, collected through Sentry.

2.4 Payment data

Subscription payments are processed entirely by the Apple App Store or Google Play Store. Kepton does not receive or store your full card number or billing address; we receive only confirmation of subscription status from Apple/Google.

3. Legal Bases for Processing (EU / UK Users)

  • Performance of a contract: to create your account, run the timer and forest features, and manage your subscription.
  • Legitimate interests: to maintain security, prevent abuse, and improve the Service, balanced against your rights.
  • Consent: for any analytics or marketing communications where consent is legally required, and for cookies as described in Section 6.

4. How We Use Your Information

  • To provide, operate, and maintain the Service.
  • To process your subscription and communicate about billing.
  • To respond to support requests.
  • To diagnose and fix crashes and bugs.
  • To comply with legal obligations.

We do not sell your personal information, and we do not use your task or planning content to train third-party AI models.

5. Cookies and Similar Technologies

The kepton.app website uses cookies and similar technologies. The mobile app uses equivalent on-device identifiers and SDK-level analytics rather than browser cookies.

  • Strictly necessary: required for login sessions and security; cannot be disabled.
  • Functional: remember your preferences, such as display settings.
  • Analytics: help us understand aggregate usage patterns.

ACTION NEEDED BEFORE PUBLISHING: You have not listed a specific web analytics tool. If kepton.app uses any analytics or advertising script (Google Analytics, Meta Pixel, etc.), name it here and add a cookie-consent banner with granular accept/reject controls for EU/UK visitors before launch. Without a named tool, this section currently assumes strictly necessary cookies only.

Where required by EU/UK law (ePrivacy Directive and GDPR), we obtain your consent before setting non-essential cookies, through a consent banner on first visit. You can withdraw consent at any time through your browser settings or the cookie preference link in the website footer.

6. Third Parties We Share Data With (Subprocessors)

  • Supabase — database hosting and user authentication.
  • Vercel — hosting for the website and backend API routes.
  • Sentry — crash and error diagnostic reporting.
  • Apple Inc. and Google LLC — app distribution and subscription billing.
  • RevenueCat — subscription status tracking and analytics, where enabled.

ACTION NEEDED BEFORE PUBLISHING: Confirm the exact hosting region for your Supabase project (the schema notes suggest this has not been finalized). If any subprocessor stores data outside the EU/UK for EU/UK users, you need a valid international transfer mechanism, most commonly the EU Standard Contractual Clauses, referenced here once the region is confirmed.

7. International Data Transfers

Where your data is transferred to a country outside your own, including to India where Kepton is operated, we rely on appropriate safeguards required by applicable law, such as Standard Contractual Clauses for EU/UK users, or your explicit consent where applicable.

8. Data Retention

We retain your account and usage data for as long as your account is active. If you delete your account, we delete or anonymize your personal data within 30 days, except where we are required to retain limited records for legal, tax, or fraud-prevention purposes.

ACTION NEEDED BEFORE PUBLISHING: Confirm this 30-day figure matches what Sahil can actually implement in Supabase (a deletion job or manual process). Do not publish a retention commitment the system cannot currently fulfil.

9. Your Rights

9.1 European Union and United Kingdom (GDPR / UK GDPR)

You have the right to access, correct, delete, restrict, or port your data, to object to certain processing, and to withdraw consent at any time. You also have the right to lodge a complaint with your local data protection authority.

9.2 United States (California CCPA/CPRA and similar state laws)

California residents have the right to know what personal information is collected, to request deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information. Kepton does not sell personal information. Residents of other US states with comparable privacy laws (for example Virginia, Colorado, Connecticut) have similar rights under their respective statutes.

9.3 India (Digital Personal Data Protection Act, 2023)

You have the right to access a summary of your personal data and the processing activities involved, to correction and erasure, to grievance redressal through our Grievance Officer, and to nominate another individual to exercise your rights in the event of death or incapacity.

9.4 Other Asia-Pacific jurisdictions

Depending on your location, you may have additional rights under laws such as Australia's Privacy Act 1988, Singapore's Personal Data Protection Act, or similar regional frameworks. We will honor valid requests under the law applicable to you.

To exercise any of these rights, email support@kepton.app. We will respond within the timeframe required by the applicable law (generally 30 days).

10. Children's Privacy

Kepton requires all users to self-declare that they are at least 16 years old at signup. The Service is not directed at children, and we do not knowingly collect personal data from anyone under 16. If we learn that a user under 16 has provided personal data, we will delete it.

11. Security

We apply reasonable technical and organizational measures to protect your data, including encrypted connections (HTTPS/TLS), access controls on our database, and dependency and secrets-management hygiene as part of our standard build process. No system is completely secure, and we cannot guarantee absolute security.

12. Data Breach Notification

In the event of a data breach affecting your personal data, we will notify affected users and, where legally required, the relevant supervisory authority, without undue delay and in line with applicable law (for example within 72 hours of becoming aware, where GDPR's notification timeline applies).

13. Changes to This Policy

We may update this Privacy Policy from time to time. Material changes will be notified through the app or by email at least 14 days before they take effect.

14. Contact Us

For any privacy question, request, or complaint, contact support@kepton.app.