Privacy Policy

Last updated: 7 October 2026 (revised)

Kairos is a self-guided ERP (Exposure and Response Prevention) companion for OCD. What you record in it is about your own mental health, so the short version matters: what you write is stored on your device and in your own account, read by nobody else, and never sold, shared, or used to advertise to you.

The short version

What Kairos stores

Kairos records only what you enter:

Kairos does not ask for your name, date of birth, address, phone number, location, contacts, photos, or health data from other apps. It does not access your camera, microphone, or HealthKit.

Where it is stored

On your device. Everything you enter is written to your phone first, and the app works offline. Deleting the app removes that copy.

In your account. Kairos requires an account, so the records listed above are also stored in our database and sync to your other devices. Each row is bound to your account and protected by row-level security, so no other user can read your data. The database is operated by Supabase, who act as our data processor and host it in the European Union.

On your device only. Your safety screening answers, your weekly notes and your settings never leave your phone. Because they are not in your account, they do not follow you to a new phone, and deleting the app removes them.

Signing out, and sharing a phone

Your records belong to your account, not to the phone. The phone keeps a working copy so the app opens quickly and works without a connection, and that copy is removed when it should no longer be there:

If you sign out with no internet connection, entries made since the last sync cannot be uploaded first and are lost with the local copy. Crash reports and usage data stop when the phone changes hands, and the next person is asked for their own choice.

Accounts and sign-in

Kairos requires an account. It is what lets your history survive a lost or replaced phone, and it is the boundary that keeps your records yours. You can sign in with an email address and password, or with Google. If you use Google sign-in we receive only your email address and basic profile information — Google does not give us access to your Gmail, Drive, contacts, or anything else, and we do not request it.

We use your email address solely to identify your account and to send account-related messages such as confirmation and password resets. We do not send marketing email.

Crash reports and usage data

The app sends two kinds of technical data, and it is worth being exact about what each one can and cannot contain.

Crash reports. When the app crashes, we receive the technical details of the failure — which screen, which version of the app and operating system, and the programming error itself. This is how we find out something is broken for people who would otherwise just delete the app.

Usage events. We record that certain things happened: an exercise was started, an exercise was completed, an urge was logged, the quiz was finished. This tells us where the app is confusing or where people give up, which is the only way to improve it without guessing.

What these can never contain. Usage events record that something happened, never what it was about. They cannot carry which OCD themes you matched, the text of anything you wrote, your distress ratings, the names of exercises you did, or your email address. This is enforced in the code by a fixed list of permitted events and properties — anything outside it is refused and the event is discarded, rather than sent with the sensitive part removed.

Durations are rounded to the nearest 30 seconds rather than recorded exactly, because a precise timing is closer to an identifier than it looks.

Crash reports go to Sentry and usage events to PostHog, both acting as our processors. If you would rather send neither, you can turn both off in the app under Profile, and the app works exactly the same without them.

Why we are allowed to hold this

Information about your mental health is special category data under the UK GDPR, which means it needs a stronger justification than ordinary personal data. Being specific about that matters more than a general promise to be careful.

WhatWhy we process itOur basis
Your account email and password To create your account, sign you in, and send password resets Necessary to provide the service you asked for (contract)
Quiz results, exercise logs, urge logs, exposures you write To show your own history back to you and sync it between your devices. Nobody else reads it. Your explicit consent, given by choosing to use the app and enter it
Crash reports To find out the app is broken for people who would otherwise just delete it Your consent. Off unless you turn it on.
Usage events To see where the app is confusing or where people give up Your consent, asked for separately from crash reports. Off unless you turn it on.

Crash reports and usage data are off until you switch them on, and they are two separate switches — agreeing to one is not agreeing to the other. You will not be asked twice, and the app behaves identically either way. Turning either off in Profile stops it immediately rather than at the next launch.

You can withdraw consent for everything else by deleting your account, which removes the records rather than hiding them.

Where your data goes

We use three processors. All three store this data in the European Union, so it does not leave the UK/EU for these purposes.

WhoWhat forWhat they getWhere
SupabaseAccount and syncYour email and the records aboveEU
SentryCrash reportsDevice model, OS, app version, the error itself, and an app install identifier. Not your name, email or IP.EU
PostHogUsage eventsThat an event happened, a rounded duration, device model. No content, no location.EU

If you sign in with Google, Google processes that sign-in under its own policy.

What we never do

Notifications

Every notification Kairos shows is created by the app on your own phone. We do not send them from a server, we are not told when one is shown or tapped, and we do not hold a push-notification address for your device. There are three kinds, and the second and third exist only if you switch them on.

The times you choose are held only in your phone's own notification schedule. They are not stored in your account or sent to us. Removing a check-in, turning the reminder off, signing out, or deleting your account cancels them.

If you have turned usage data on, switching the daily practice reminder on or off is recorded as an event, with no time attached. Check-ins are not recorded at all.

There are no promotional or streak notifications. You can decline or revoke notification permission at any time in your phone's Settings, and the rest of the app works without it.

Home-screen widgets and the lock screen

Kairos offers optional home-screen widgets, and on iPhone a live timer on the lock screen while an exercise is running. If you add them, they show the number of exercises you have completed this week and in total, a small trend line drawn from your starting distress ratings, and — while an exercise is running — its title and timer.

To make this possible the app copies those few figures to a shared area on your phone that the widget can read. They do not leave your device. They are, however, visible to anyone who can see your home screen or lock screen, and an exercise title can say more than you might want it to. The widgets are entirely optional, and removing them removes the display.

Crisis resources

The crisis screen lists helplines and links to outside organisations. Tapping a phone number places a call using your phone, and tapping a link opens that organisation's website. Kairos does not tell those organisations anything about you, and we are not told that you tapped anything.

Your control over your data

If you are in the UK or EU, the UK GDPR and GDPR give you rights of access, rectification, erasure, restriction, portability, and objection. Our lawful basis for processing is your consent, which you can withdraw at any time by deleting your account.

Children

Kairos is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.

Retention

Synced data is kept until you delete your account. Local data is kept until you sign out or delete the app. We do not keep backups of deleted accounts beyond our provider's standard retention window.

Changes

If this policy changes in a way that materially affects how your data is handled, we will update the date at the top and note the change in the app.

Contact

Questions, data requests, or account deletion: kairosocd@proton.me

Kairos is not a medical device and not a substitute for professional care. It does not diagnose or treat OCD. If you are in crisis, contact emergency services — 999 in the UK, 911 in the US — or a helpline listed in the app's Crisis Support screen.