Privacy Policy & Cookie Information

Privacy Policy

Kratic LLC operates Kratic for adults aged 18 and over. This policy covers our Android app, iOS app and website, including account, recovery, health, connected-service and support data.

We are committed to protecting your privacy and ensuring the security of your personal data.

Information We Collect

We collect the following types of information to provide and improve our service:

  • Authentication credentials stored securely. If you add an optional login password, we store a salted password hash. Removing password login or deleting your account removes that credential
  • Session information to maintain your login state
  • Credentials for integrations you enable, such as Google, Notion, Microsoft, Fitbit, WHOOP, RescueTime and YNAB
  • Connected-service data you explicitly request, such as calendar events, tasks, Notion pages, and Fitbit data (e.g., activity, sleep, heart-rate metrics, profile) limited to the scopes you approve
  • Recovery answers, sobriety dates, mood, sleep, activity, nutrition, hydration and other health records you enter or connect
  • Budget and transaction data, calendars, tasks and documents from services you connect
  • Conversation content, uploaded files, generated output and tool results
  • Support contacts you enter, location used for weather, and notification preferences and device tokens
  • Account and billing identifiers, phone verification, consent history, support reports and technical records

Sign in with Apple

If you choose Apple sign-in, Apple sends us a stable account identifier and a verified email address. That address may be a private relay address. Apple may also send your name when you first authorize Kratic. We use this information to create, find or link your Kratic account and to keep your sign-in secure. Apple sign-in does not give Kratic access to your calendar, tasks or health data. Those connections need separate permission.

We encrypt the Apple refresh token on our server so we can revoke it when you delete your Kratic account. If Apple is temporarily unavailable, local account deletion continues and token revocation is retried. If you use a private relay address, Apple controls forwarding to your personal inbox. Messages from Kratic may not reach you if you turn forwarding off.

Google User Data

When you connect your Google account, we access the following data based on your approved permissions:

Google Calendar

  • Calendar events (titles, times, descriptions, attendees)
  • Calendar metadata and settings

Google Tasks

  • Task lists and individual tasks
  • Task details (titles, due dates, notes, completion status)

How we use Google data:

  • Display your calendar and tasks within the app interface
  • Enable the AI assistant to help manage your schedule through conversation
  • Create, update, or delete calendar events and tasks at your request

We do NOT use Google API data to:

  • Train, improve, or develop AI/ML models
  • Serve advertisements or sell to third parties
  • Any purpose not explicitly disclosed in this policy

Google Data Retention:

  • OAuth tokens are encrypted and stored only while your account is connected
  • Google Calendar and Tasks data can be fetched or synced for app features and may appear in saved conversations and outputs
  • Disconnecting Google removes its stored credentials and connection caches. Saved conversations and outputs are separate; you can request their deletion

Google API Services Compliance

Kratic's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Fitbit Data & Permissions

We access Fitbit User Data only via Fitbit's OAuth flow and the scopes you grant. We do not scrape, circumvent, or use alternative authentication methods.

What we may access (scope-dependent):

  • Activity, steps, exercises, sleep, readiness, and basic profile details
  • Heart-rate and related wellness metrics where you have granted permission
  • Any additional Fitbit datasets only if you explicitly authorize them for a feature

How we use Fitbit data:

  • To answer your prompts, summarize trends, or combine Fitbit data with other tools you enable
  • To troubleshoot and secure the integration (limited technical logs only)
  • Never for ads, resale or public display. Relevant data can be sent to the AI processors described below to produce the features you use

Storage, retention, and deletion:

  • Fitbit OAuth tokens are encrypted at rest; we request the minimum scopes needed
  • Fitbit data can be synced in the background, cached on the server and used in dashboards, conversations and recovery summaries while the integration is connected
  • You can disconnect Fitbit in settings or revoke access from your Fitbit/Google Account; we then stop all Fitbit API calls and delete stored Fitbit tokens
  • If you request removal of Fitbit-derived content from conversation history, contact us and we will delete associated Fitbit data and tokens

Research and marketing:

  • We do not use Fitbit data for advertising or sell Fitbit data
  • We do not use Fitbit data for research without your explicit consent; any future research use would be de-identified and consented

Mobile data-use choice

Before you use the recovery profile, check-ins or AI features in the Android or iOS app, Kratic shows a versioned notice and asks you to agree. The notice explains that check-ins, recovery profile, chat and relevant connected-service data can go to the AI processors listed below for personalized replies and Recovery Briefs. We save each platform's notice version, acceptance time and changes to your choice. You can withdraw in Profile > Privacy. This revokes sessions for that platform and signs you out there. Your web account, stored data and existing connected-service sync remain. Disconnect those services to stop their sync, or use the account deletion options below to remove your account and associated data.

Services that process data

Kratic stores account data and uses service providers for the functions below. A processor receives the data needed for that function. Processing can take place outside your country, including in the US.

  • Weather: Open-Meteo receives the location you select to return a forecast.
  • AI: OpenRouter and the model providers it routes to, or direct Anthropic and Cerebras services, receive relevant messages, uploaded content, recovery answers and connected data for chat, Agents, summaries and conversation titles. Fallback providers can process the same request.
  • Connected services: Google, Microsoft, Notion, Fitbit, WHOOP, RescueTime and YNAB receive authorized requests for the integrations you enable. Disconnecting stops future sync once revocation is applied; it does not erase records you keep with those services.
  • Payments: Stripe processes website payments and billing details. Kratic stores purchase and subscription identifiers and status. Android has no checkout.
  • Messages: Twilio processes phone verification and opted-in SMS delivery; Resend processes email delivery; Google Firebase Cloud Messaging delivers Android push notifications.
  • Reports: Kratic stores the explanation you submit, your account, report type, source and time. A report does not attach your conversation automatically. Authorized staff can review reports to address safety problems. There is no in-app reply inbox.

Conversation Logging & Service Improvement

To ensure reliable service delivery and continuous improvement, we maintain logs of your interactions with the AI assistant. This helps us:

  • Debug issues and resolve technical problems quickly
  • Understand how the service is used to enhance functionality
  • Improve AI response quality and accuracy over time
  • Maintain service reliability and performance

What We Log

Our logging system captures the following information for each conversation:

  • Conversation content: Your messages and the AI assistant's responses to maintain conversation context and improve responses
  • System configuration: Which AI model and tools were used, along with system prompts, to understand service behavior
  • Tool usage: Information about tools called (like calendar or task management) and their results, to ensure integrations work correctly
  • Performance metrics: Response times and token usage to optimize service speed and efficiency
  • Error information: Technical errors and their context to quickly identify and fix issues
  • Attachment metadata: Information about files you share (file names, types, sizes) while omitting the actual file content from logs

Data Protection in Logging

We take steps to protect your privacy in our logs:

  • Access to account content and technical logs is restricted to authorized operations and support
  • Server records use access controls. Integration credentials are encrypted; conversation and health records are not end-to-end encrypted
  • Logs support reliability, security and requested troubleshooting
  • Relevant conversation and connected-service content is sent to AI processors to produce responses

This logging is essential for maintaining a reliable, high-quality AI assistant service. All data is stored securely and used only for the purposes described above.

How We Use Your Information

We use your information solely for the purpose of providing the AI Assistant service, including:

  • Authenticating and maintaining your session
  • Integrating with Google Calendar, Google Tasks, Notion, and Fitbit (permitted scopes only)
  • Providing AI-powered assistance based on your connected services and conversation context
  • Ensuring the security, reliability, and functionality of the application

Cookie Policy

We use essential cookies to operate the service. If you allow optional measurement, we also use Google Analytics and Google Ads to measure website visits and campaign results. We store random browser and session identifiers and campaign identifiers in local browser storage.

Essential Cookies

These cookies are necessary for the website to function and cannot be switched off. They are usually only set in response to actions made by you, such as logging in.

auth_session

Purpose: Maintains your authentication session so you stay logged in.

Duration: Up to 30 days, or until you sign out or the session is revoked.

Type: Essential / Functional

auth_mfa

Purpose: Tracks your multi-factor authentication status to ensure secure access.

Duration: Up to 30 days, or until you sign out or the session is revoked.

Type: Essential / Functional

apple_web_oauth and apple_web_link_ticket

Purpose: Match Apple's sign-in response to the request you started and, if you choose to link Apple, finish that link in your existing Kratic session.

Duration: Up to 10 minutes for the sign-in request and 2 minutes for an account link.

Type: Essential / Functional

Google measurement loads only after you select Allow measurement. It uses page categories, campaign identifiers and confirmed trial or purchase events. It does not receive check-in answers, chat text, account names or connected-service data. Ad personalization and automatic user-provided data are disabled in our tag setup. We do not load Meta Pixel. Your measurement choice and random browser identifier are stored for up to 180 days. Google manages Analytics sessions. Campaign identifiers are kept for up to 30 days. You can change or withdraw your choice at any time with the Cookie choices button at the end of this page. Withdrawal stops the tag and removes local measurement data and its accessible first-party cookies; it does not erase data already sent to Google. Connected services and pages you choose to open have their own privacy policies.

SMS Text Message Communications

What We Send

  • Daily or weekly check-in reminder text messages at your configured time
  • Messages are sent from our toll-free number +1 (888) 218-0760
  • Message frequency varies based on your settings (up to 1 per day or 1 per week)
  • Message and data rates may apply

Your Rights

  • Consent: SMS requires explicit opt-in. Consent is not a condition of purchase or use of our service
  • Opt-out: Reply STOP to any message, or disable SMS reminders in Settings
  • Help: Reply HELP to any message, or contact support@kratic.com
  • Access: View your consent history in Settings

Data We Store

  • Phone number and verification status
  • Consent records with timestamps and IP addresses (for audit compliance)
  • SMS preferences (time, frequency)
  • Date of last SMS sent

We use Twilio to deliver text messages. They process your phone number solely for message delivery and are bound by our data processing agreement.

Email Communications

What We Send

  • Daily or weekly check-in reminder emails at your configured time

Your Rights

  • Consent: Grant or revoke consent anytime in Settings
  • Unsubscribe: Every email includes a one-click unsubscribe link
  • Access: View your consent history in Settings

Data We Store

  • Consent records with timestamps and IP addresses (for audit compliance)
  • Email preferences (time, frequency)
  • Date of last email sent

We use Resend to deliver emails. They process your email address solely for delivery and are bound by our data processing agreement.

Data Security

Kratic uses HTTPS for network transport, access controls for server data, and encryption for stored integration credentials. Account and health records are stored in server databases; this is not end-to-end encryption. Authorized staff may access records when needed for support, security, deletion or a legal obligation.

Your Rights

Under GDPR and other privacy regulations, you have the right to:

  • Access your personal data, including conversation logs
  • Request correction of inaccurate data
  • Request deletion of your data, including conversation history
  • Withdraw consent at any time
  • Export your data in a portable format

You can manage your data and exercise these rights through the application settings or by contacting us. You may revoke Fitbit access at any time from your Fitbit or Google Account settings; revocation stops data access and removes stored Fitbit tokens on our side.

Delete your Kratic account

In the iOS or Android app, open Profile, Privacy, then Delete My Account. If you cannot use the app, email support@kratic.com with the subject "Kratic account deletion". Use your account email when possible. You do not need to reinstall the app or have paid access. This address also accepts account-support and data requests.

We verify account ownership before deletion. Never send your password, sign-in code or payment-card details. We will explain any further verification and the request status by email.

Account deletion removes account and profile records, check-ins, conversations, saved reports, connected-service credentials and caches, push registrations, and uploaded files controlled by Kratic. File cleanup and interrupted deletion can finish in background work. Sessions are revoked, and recurring website billing is canceled as part of the deletion process. Uninstalling either mobile app does not delete your account or cancel a subscription. Deletion does not itself issue a refund.

Restricted records needed to prevent repeat trial abuse, preserve deletion after a restore, settle payments, meet legal duties or resolve disputes can remain. These records must not restore product access. Backup copies and provider records have separate retention and removal processes; deletion is not an immediate erasure of every backup or a deletion of your account at a connected service. Contact us for the records and retention periods that apply to your request.

Contact & Requests

For data access, correction, deletion, or Fitbit-specific removal requests, email support@kratic.com. You can also email developer@kratic.com for privacy requests.

Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new policy on this page and updating the "Last updated" date.

Last updated: September 25, 2026