Kratic LLC operates Kratic for adults aged 18 and over. This policy covers our Android app, iOS app and website, including account, recovery, health, connected-service and support data.
We are committed to protecting your privacy and ensuring the security of your personal data.
We collect the following types of information to provide and improve our service:
If you choose Apple sign-in, Apple sends us a stable account identifier and a verified email address. That address may be a private relay address. Apple may also send your name when you first authorize Kratic. We use this information to create, find or link your Kratic account and to keep your sign-in secure. Apple sign-in does not give Kratic access to your calendar, tasks or health data. Those connections need separate permission.
We encrypt the Apple refresh token on our server so we can revoke it when you delete your Kratic account. If Apple is temporarily unavailable, local account deletion continues and token revocation is retried. If you use a private relay address, Apple controls forwarding to your personal inbox. Messages from Kratic may not reach you if you turn forwarding off.
When you connect your Google account, we access the following data based on your approved permissions:
How we use Google data:
We do NOT use Google API data to:
Google Data Retention:
Kratic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
We access Fitbit User Data only via Fitbit's OAuth flow and the scopes you grant. We do not scrape, circumvent, or use alternative authentication methods.
What we may access (scope-dependent):
How we use Fitbit data:
Storage, retention, and deletion:
Research and marketing:
Before you use the recovery profile, check-ins or AI features in the Android or iOS app, Kratic shows a versioned notice and asks you to agree. The notice explains that check-ins, recovery profile, chat and relevant connected-service data can go to the AI processors listed below for personalized replies and Recovery Briefs. We save each platform's notice version, acceptance time and changes to your choice. You can withdraw in Profile > Privacy. This revokes sessions for that platform and signs you out there. Your web account, stored data and existing connected-service sync remain. Disconnect those services to stop their sync, or use the account deletion options below to remove your account and associated data.
Kratic stores account data and uses service providers for the functions below. A processor receives the data needed for that function. Processing can take place outside your country, including in the US.
To ensure reliable service delivery and continuous improvement, we maintain logs of your interactions with the AI assistant. This helps us:
Our logging system captures the following information for each conversation:
We take steps to protect your privacy in our logs:
This logging is essential for maintaining a reliable, high-quality AI assistant service. All data is stored securely and used only for the purposes described above.
We use your information solely for the purpose of providing the AI Assistant service, including:
We use essential cookies to operate the service. If you allow optional measurement, we also use Google Analytics and Google Ads to measure website visits and campaign results. We store random browser and session identifiers and campaign identifiers in local browser storage.
These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you, such as logging in.
Purpose: Maintains your authentication session so you stay logged in.
Duration: Up to 30 days, or until you sign out or the session is revoked.
Type: Essential / Functional
Purpose: Tracks your multi-factor authentication status to ensure secure access.
Duration: Up to 30 days, or until you sign out or the session is revoked.
Type: Essential / Functional
Purpose: Match Apple's sign-in response to the request you started and, if you choose to link Apple, finish that link in your existing Kratic session.
Duration: Up to 10 minutes for the sign-in request and 2 minutes for an account link.
Type: Essential / Functional
Google measurement loads only after you select Allow measurement. It uses page categories, campaign identifiers and confirmed trial or purchase events. It does not receive check-in answers, chat text, account names or connected-service data. Ad personalization and automatic user-provided data are disabled in our tag setup. We do not load Meta Pixel. Your measurement choice and random browser identifier are stored for up to 180 days. Google manages Analytics sessions. Campaign identifiers are kept for up to 30 days. You can change or withdraw your choice at any time with the Cookie choices button at the end of this page. Withdrawal stops the tag and removes local measurement data and its accessible first-party cookies; it does not erase data already sent to Google. Connected services and pages you choose to open have their own privacy policies.
We use Twilio to deliver text messages. They process your phone number solely for message delivery and are bound by our data processing agreement.
We use Resend to deliver emails. They process your email address solely for delivery and are bound by our data processing agreement.
Kratic uses HTTPS for network transport, access controls for server data, and encryption for stored integration credentials. Account and health records are stored in server databases; this is not end-to-end encryption. Authorized staff may access records when needed for support, security, deletion or a legal obligation.
Under GDPR and other privacy regulations, you have the right to:
You can manage your data and exercise these rights through the application settings or by contacting us. You may revoke Fitbit access at any time from your Fitbit or Google Account settings; revocation stops data access and removes stored Fitbit tokens on our side.
In the iOS or Android app, open Profile, Privacy, then Delete My Account. If you cannot use the app, email support@kratic.com with the subject "Kratic account deletion". Use your account email when possible. You do not need to reinstall the app or have paid access. This address also accepts account-support and data requests.
We verify account ownership before deletion. Never send your password, sign-in code or payment-card details. We will explain any further verification and the request status by email.
Account deletion removes account and profile records, check-ins, conversations, saved reports, connected-service credentials and caches, push registrations, and uploaded files controlled by Kratic. File cleanup and interrupted deletion can finish in background work. Sessions are revoked, and recurring website billing is canceled as part of the deletion process. Uninstalling either mobile app does not delete your account or cancel a subscription. Deletion does not itself issue a refund.
Restricted records needed to prevent repeat trial abuse, preserve deletion after a restore, settle payments, meet legal duties or resolve disputes can remain. These records must not restore product access. Backup copies and provider records have separate retention and removal processes; deletion is not an immediate erasure of every backup or a deletion of your account at a connected service. Contact us for the records and retention periods that apply to your request.
For data access, correction, deletion, or Fitbit-specific removal requests, email support@kratic.com. You can also email developer@kratic.com for privacy requests.
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.
Last updated: September 25, 2026
See also: Terms of Service · Support