Skip to content

Privacy Policy

Effective Last updated

In short

  • We collect what the app needs to work: your account details, the gatherings you create or join, your messages, and — while the app is open — your approximate location.
  • Your position on Kaif Radar is deliberately blurred on our server before it is stored, and the raw GPS coordinates your device sends are never written to disk. Radar data lives in memory with a timer, not in our database.
  • We do not sell personal data, and we do not use it for third-party advertising.
  • You can access, correct, export or delete your data from within the app, or by writing to privacy@kaif.app.
  • This policy covers both Russian Federal Law 152-FZ and the GDPR. Where they differ, we apply the stricter standard to everyone.

The summary is a convenience and has no legal effect. Where it and the full text differ, the full text governs.

This policy explains how Kaif Technologies LLC handles personal data in the Kaif applications and on this website.

1. Who is responsible for your data

The operator of your personal data under Federal Law No. 152-FZ, and the controller under Article 4(7) GDPR, is:

Legal entityKaif Technologies LLC
Registered address350000, Russia, Krasnodar Krai, Krasnodar, [street, building, office]
OGRN0000000000000
INN0000000000
Personal-data operator registry entrynot yet assigned
Privacy contactprivacy@kaif.app
Data protection officerdpo@kaif.app
EU representative (Art. 27 GDPR)to be appointed

If you are in the European Economic Area or the United Kingdom, you may contact our EU representative instead of us for any matter relating to the processing of your personal data.

2. What we collect

You give us

  • Account data: name or display name, email address and/or phone number, password (stored only as a bcrypt hash — we never hold the password itself), and date of birth where needed to confirm you meet the minimum age.
  • Profile data: photograph, bio, interests, city, and the languages you speak.
  • Content: gatherings you create, messages you send, photographs you upload, ratings and reviews you write, and your Radar status text.
  • Verification data: where you choose to verify your identity as a Host, the identity document you submit and the details it contains.
  • Payment data: where you buy or sell through the Service, the billing details needed to complete the transaction, and for Hosts receiving payouts, the bank or account details and tax identifiers required. Full card numbers are handled by our payment provider and never reach our servers.
  • Correspondence: what you write to our support, safety and privacy addresses.

We collect automatically

  • Location data, while the app is open and in the foreground only. See section 4.
  • Device and technical data: device model, operating system version, app version, language, and a device identifier used for push notifications.
  • Log data: IP address, timestamps, and the requests your app makes to our API. Used for security, abuse prevention and debugging.
  • Usage data: which screens you open and which features you use, in aggregate form, to understand what to improve.

We receive from others

  • If you sign in with Google or Apple: your identifier with that provider, your email address, and your name where the provider supplies it. Apple's Private Relay addresses are supported — we do not require your real address.
  • If another user reports you, the content of that report.

We do not collect special categories of personal data under Article 9 GDPR — data revealing racial or ethnic origin, political opinions, religious beliefs, trade-union membership, genetic or biometric data, health data, or data about sexual orientation. If you volunteer such information in free-text fields such as your bio or a gathering description, you do so on your own initiative and it is processed as ordinary Content.

3. Why we process it, and on what legal basis

PurposeData usedLegal basis (GDPR)Basis (152-FZ)
Create and operate your accountAccount, profileArt. 6(1)(b) — performance of a contractArt. 6(1)(5) — performance of a contract
Show nearby gatherings and peopleApproximate location, interestsArt. 6(1)(b) and Art. 6(1)(a) — consent for locationArt. 6(1)(1) — consent
Deliver messages and notificationsContent, device tokenArt. 6(1)(b)Art. 6(1)(5)
Take payment and pay out to HostsPayment, verificationArt. 6(1)(b) and Art. 6(1)(c) — legal obligationArt. 6(1)(5) and Art. 6(1)(2)
Verify Host identityIdentity documentArt. 6(1)(a) — consentArt. 6(1)(1) — consent
Keep the Service safe; investigate abuseLog, report, account dataArt. 6(1)(f) — legitimate interestsArt. 6(1)(5)
Prevent fraud and comply with lawPayment, log dataArt. 6(1)(c) and 6(1)(f)Art. 6(1)(2)
Improve the productAggregated usage dataArt. 6(1)(f) — legitimate interestsArt. 6(1)(5)
Send you service emailsEmail addressArt. 6(1)(b)Art. 6(1)(5)
Send you marketing, if you asked for itEmail addressArt. 6(1)(a) — consentArt. 6(1)(1) — consent

Where we rely on legitimate interests, we have carried out a balancing assessment and concluded that the processing is necessary, proportionate, and within your reasonable expectations. You may object to it at any time — see section 8.

Where we rely on consent, you may withdraw it at any time, without affecting the lawfulness of processing before withdrawal. Withdrawing consent to location processing turns off Radar and nearby discovery; the rest of the Service continues to work.

4. Location data — how Kaif Radar works

This section describes the most sensitive processing we carry out, in the detail it deserves.

  • Location is read only while the app is open and in the foreground. Kaif does not request or use background location, and does not build a location history.
  • When you are visible on Radar, your device sends its coordinates to our server. The server immediately reduces their precision: the position is snapped to a coarse geohash cell, and then offset by a deterministic amount derived from your user identifier. Only this transformed position is stored.
  • The raw coordinates your device sends are not written to persistent storage. They exist in memory for the duration of the request.
  • Because the offset is per-user, two people standing in the same place do not resolve to the same displayed point, and the displayed point cannot be used to identify a building or an address.
  • Radar presence is stored in an in-memory store with a time-to-live of 180 seconds, and your Radar status with a time-to-live of two hours. Neither is written to our database. When the TTL elapses, the record is removed by the store itself.
  • Turning on invisible mode removes you from Radar entirely. Blocking is applied in both directions before any Radar result is returned.
  • For discovering gatherings rather than people, we use a coarser city- or area-level position, and you can set your city manually instead of granting location permission at all.

Location processing is based on your consent, given through your device's permission prompt. You can withdraw it at any time in your device settings or by using invisible mode.

5. Who we share data with

We do not sell personal data. We do not share it with third-party advertising networks or data brokers. We share it only as follows.

With other users

Your display name, photograph, bio and interests are visible to other users. Gatherings you host are visible according to the visibility you choose. When you join a gathering, your participation is visible to the Host and other Participants. Your approximate Radar position and status are visible to nearby users while you are visible.

With processors acting on our instructions

ProcessorPurposeLocation
Payment provider (YooMoney)Processing payments and payoutsRussian Federation
Google (Firebase Cloud Messaging)Delivering push notificationsEU / United States
LocationIQConverting coordinates and text into place namesEuropean Union
Google Firebase CrashlyticsCrash and error reportingEU / United States
SMTP email providerSending transactional emailSee current sub-processor list

Each processor is bound by a written agreement meeting the requirements of Article 28 GDPR and Article 6 of 152-FZ, may act only on our documented instructions, and may not use your data for its own purposes. Our database, file storage, real-time layer and operations console are operated by us and not by a third-party platform.

For legal reasons

We disclose data to authorities where we are legally required to. We assess each request against the legal basis it claims, decline requests that are informal or overbroad, and — unless prohibited by law or where notice would create a risk to someone's safety — we tell the affected user.

On a business transfer

If the business is sold or merged, data may transfer to the acquirer, who will remain bound by this policy until it is lawfully replaced. We will notify you before your data becomes subject to a different policy.

6. Storage location and international transfers

In accordance with Article 18(5) of Federal Law 152-FZ, the personal data of citizens of the Russian Federation is recorded, systematised, accumulated, stored, amended and retrieved using databases located in the Russian Federation. Where data is subsequently transferred abroad, that transfer takes place only after the primary processing in Russian databases.

Transfers outside the Russian Federation, where they occur, are made to countries providing adequate protection of the rights of data subjects, or on the basis of your consent, or as necessary to perform a contract to which you are a party, in accordance with Article 12 of 152-FZ.

Transfers of data from the EEA to a third country are made under one of the mechanisms in Chapter V GDPR — an adequacy decision where one applies, or Standard Contractual Clauses adopted by the European Commission, supplemented where necessary by additional technical measures. You may request a copy of the safeguards in place by writing to privacy@kaif.app.

7. How long we keep it

DataRetention
Account and profileWhile your account is active; deleted within 30 days of account deletion
Radar presence180 seconds (technical TTL)
Radar status2 hours (technical TTL)
MessagesWhile the chat exists; removed when the gathering and its chat are deleted
Gatherings24 months after the gathering ends, then anonymised for statistics
Identity verification documentsDeleted within 90 days of a decision; only the outcome and decision date are retained
Payment and payout recordsAs required by tax and accounting law — generally 5 years in the Russian Federation
Moderation reports and enforcement records3 years, so that repeat behaviour can be identified
Server logs90 days
BackupsRolling 30 days, after which deleted data is gone from backups too

When you delete your account, we delete or irreversibly anonymise your personal data within 30 days, except where we must keep something to comply with a legal obligation, to establish or defend a legal claim, or to enforce a ban on a user who was removed for serious misconduct — in which case we keep the minimum necessary and nothing more.

Messages you have already sent to other people remain visible to those people. This is a property of conversation, not a retention decision: we cannot recall a message from someone else's device or memory.

8. Your rights

Under both regimes you have the right to:

  • Know whether we process your personal data, and obtain a copy of it (Art. 15 GDPR; Art. 14 of 152-FZ).
  • Have inaccurate data corrected (Art. 16 GDPR; Art. 14 of 152-FZ).
  • Have your data deleted, where we no longer need it or where processing was unlawful (Art. 17 GDPR; Art. 14 of 152-FZ).
  • Have processing restricted while a dispute about accuracy or lawfulness is resolved (Art. 18 GDPR).
  • Receive the data you gave us in a structured, machine-readable format, and have it transmitted to another controller where technically feasible (Art. 20 GDPR).
  • Object to processing based on legitimate interests, including profiling (Art. 21 GDPR).
  • Withdraw consent at any time, without affecting past processing (Art. 7(3) GDPR; Art. 9 of 152-FZ).
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Art. 22 GDPR). We do not make such decisions; enforcement decisions that affect your account are reviewed by a person.

Most of these can be exercised directly in the app: your profile is editable, your data is exportable from settings, and account deletion is a single action. For anything else, write to privacy@kaif.app. We reply within 30 days. Where a request is complex we may extend this by a further two months and will tell you why within the first 30 days. We do not charge for this, unless a request is manifestly unfounded or excessive.

We may ask you to confirm your identity before acting on a request — not to obstruct it, but because disclosing your data to someone impersonating you would be a worse outcome than a short delay.

Complaints

If you are unhappy with how we have handled your data, tell us first — we would rather fix it. You also have the right to complain to a supervisory authority: in the Russian Federation, the Federal Service for Supervision of Communications, Information Technology and Mass Media (Roskomnadzor); in the EEA, the data protection authority of your country of residence, place of work, or the place of the alleged infringement.

9. How we protect your data

  • All traffic between your device and our servers is encrypted in transit with TLS.
  • Passwords are stored only as bcrypt hashes. We cannot read them, and we will never ask you for yours.
  • Access tokens are short-lived and can be revoked immediately; logging out adds the token to a revocation list that is checked on every request.
  • Identity documents are uploaded directly to a private storage bucket using short-lived pre-signed URLs. We store only the object key, and reviewers read documents through time-limited links. The documents are never publicly addressable.
  • Access to production data is limited to staff who need it, is authenticated individually, and every administrative action is written to an append-only audit log.
  • We run our own database, storage and infrastructure rather than delegating them to a third-party platform.

No system is perfectly secure. If a breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority within 72 hours as required by Article 33 GDPR, and notify you directly without undue delay where the risk is high.

10. Children

The Service is not for people under 16, and we do not knowingly process their personal data. If you believe a child has created an account, write to safety@kaif.app and we will investigate and remove it.

11. Changes to this policy

We will update this policy when our processing changes. For material changes we will notify you in the app or by email at least 14 days before they take effect. The "last updated" date above always reflects the current version, and previous versions are available on request.

12. Contact

For any question about this policy or about your data, write to privacy@kaif.app. For our data protection officer, write to dpo@kaif.app. Postal correspondence can be sent to 350000, Russia, Krasnodar Krai, Krasnodar, [street, building, office].