Last updated: 7 October 2026 (revised)
Kairos is a self-guided ERP (Exposure and Response Prevention) companion for OCD. What you record in it is about your own mental health, so the short version matters: what you write is stored on your device and in your own account, read by nobody else, and never sold, shared, or used to advertise to you.
Kairos records only what you enter:
Kairos does not ask for your name, date of birth, address, phone number, location, contacts, photos, or health data from other apps. It does not access your camera, microphone, or HealthKit.
On your device. Everything you enter is written to your phone first, and the app works offline. Deleting the app removes that copy.
In your account. Kairos requires an account, so the records listed above are also stored in our database and sync to your other devices. Each row is bound to your account and protected by row-level security, so no other user can read your data. The database is operated by Supabase, who act as our data processor and host it in the European Union.
On your device only. Your safety screening answers, your weekly notes and your settings never leave your phone. Because they are not in your account, they do not follow you to a new phone, and deleting the app removes them.
Your records belong to your account, not to the phone. The phone keeps a working copy so the app opens quickly and works without a connection, and that copy is removed when it should no longer be there:
If you sign out with no internet connection, entries made since the last sync cannot be uploaded first and are lost with the local copy. Crash reports and usage data stop when the phone changes hands, and the next person is asked for their own choice.
Kairos requires an account. It is what lets your history survive a lost or replaced phone, and it is the boundary that keeps your records yours. You can sign in with an email address and password, or with Google. If you use Google sign-in we receive only your email address and basic profile information — Google does not give us access to your Gmail, Drive, contacts, or anything else, and we do not request it.
We use your email address solely to identify your account and to send account-related messages such as confirmation and password resets. We do not send marketing email.
The app sends two kinds of technical data, and it is worth being exact about what each one can and cannot contain.
Crash reports. When the app crashes, we receive the technical details of the failure — which screen, which version of the app and operating system, and the programming error itself. This is how we find out something is broken for people who would otherwise just delete the app.
Usage events. We record that certain things happened: an exercise was started, an exercise was completed, an urge was logged, the quiz was finished. This tells us where the app is confusing or where people give up, which is the only way to improve it without guessing.
Durations are rounded to the nearest 30 seconds rather than recorded exactly, because a precise timing is closer to an identifier than it looks.
Crash reports go to Sentry and usage events to PostHog, both acting as our processors. If you would rather send neither, you can turn both off in the app under Profile, and the app works exactly the same without them.
Information about your mental health is special category data under the UK GDPR, which means it needs a stronger justification than ordinary personal data. Being specific about that matters more than a general promise to be careful.
| What | Why we process it | Our basis |
|---|---|---|
| Your account email and password | To create your account, sign you in, and send password resets | Necessary to provide the service you asked for (contract) |
| Quiz results, exercise logs, urge logs, exposures you write | To show your own history back to you and sync it between your devices. Nobody else reads it. | Your explicit consent, given by choosing to use the app and enter it |
| Crash reports | To find out the app is broken for people who would otherwise just delete it | Your consent. Off unless you turn it on. |
| Usage events | To see where the app is confusing or where people give up | Your consent, asked for separately from crash reports. Off unless you turn it on. |
Crash reports and usage data are off until you switch them on, and they are two separate switches — agreeing to one is not agreeing to the other. You will not be asked twice, and the app behaves identically either way. Turning either off in Profile stops it immediately rather than at the next launch.
You can withdraw consent for everything else by deleting your account, which removes the records rather than hiding them.
We use three processors. All three store this data in the European Union, so it does not leave the UK/EU for these purposes.
| Who | What for | What they get | Where |
|---|---|---|---|
| Supabase | Account and sync | Your email and the records above | EU |
| Sentry | Crash reports | Device model, OS, app version, the error itself, and an app install identifier. Not your name, email or IP. | EU |
| PostHog | Usage events | That an event happened, a rounded duration, device model. No content, no location. | EU |
If you sign in with Google, Google processes that sign-in under its own policy.
Every notification Kairos shows is created by the app on your own phone. We do not send them from a server, we are not told when one is shown or tapped, and we do not hold a push-notification address for your device. There are three kinds, and the second and third exist only if you switch them on.
The times you choose are held only in your phone's own notification schedule. They are not stored in your account or sent to us. Removing a check-in, turning the reminder off, signing out, or deleting your account cancels them.
If you have turned usage data on, switching the daily practice reminder on or off is recorded as an event, with no time attached. Check-ins are not recorded at all.
There are no promotional or streak notifications. You can decline or revoke notification permission at any time in your phone's Settings, and the rest of the app works without it.
Kairos offers optional home-screen widgets, and on iPhone a live timer on the lock screen while an exercise is running. If you add them, they show the number of exercises you have completed this week and in total, a small trend line drawn from your starting distress ratings, and — while an exercise is running — its title and timer.
To make this possible the app copies those few figures to a shared area on your phone that the widget can read. They do not leave your device. They are, however, visible to anyone who can see your home screen or lock screen, and an exercise title can say more than you might want it to. The widgets are entirely optional, and removing them removes the display.
The crisis screen lists helplines and links to outside organisations. Tapping a phone number places a call using your phone, and tapping a link opens that organisation's website. Kairos does not tell those organisations anything about you, and we are not told that you tapped anything.
If you are in the UK or EU, the UK GDPR and GDPR give you rights of access, rectification, erasure, restriction, portability, and objection. Our lawful basis for processing is your consent, which you can withdraw at any time by deleting your account.
Kairos is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Synced data is kept until you delete your account. Local data is kept until you sign out or delete the app. We do not keep backups of deleted accounts beyond our provider's standard retention window.
If this policy changes in a way that materially affects how your data is handled, we will update the date at the top and note the change in the app.
Questions, data requests, or account deletion: kairosocd@proton.me