Privacy Policy
Privacy Policy
Last updated: 2026-07-20
Hosted at: usekempt.com/privacy
Contact: hello@usekempt.com
1. Who we are
Kempt is a home-maintenance app for first-time homeowners. The app is operated by Brian Garland (sole proprietor; entity formation pending). “We,” “us,” and “Kempt” refer to the same operator throughout this document. Mailing address: Kempt, 4050 Pennsylvania Ave, Ste 115 #667, Kansas City, MO 64111.
2. What this policy covers
This policy applies to the Kempt iOS app, the website at usekempt.com, and any data we hold about you that originated from either. It does not cover third-party services we link to. Once you leave Kempt for another site or app, that service’s privacy policy applies.
3. Data we collect
We collect only what we need to make the app work for you. Categories below map to Apple’s privacy nutrition labels.
3.1 — Contact info
- Email address. Required for sign-in (Apple, Google, or email magic link). Used to authenticate you and to send transactional notices (security alerts, account-deletion confirmation). We do not send marketing email.
3.2 — User content
- Your home’s address (street, ZIP). Required to fetch home attributes and a Street View image during onboarding. Stored at rest.
- Appliances, tasks, notes, completion history, money-saved entries, weekly briefs. The product is a home-maintenance log. All of this is content you create.
- Memory facts the agent extracts from your turns (“Your furnace is a Lennox SLP99V”) — visible and editable on the in-app Memory screen.
- Photos of appliances you upload to identify make/model. The photo is processed by our AI inference provider to identify make, model, and serial number (see §4).
3.3 — Photos
See §3.2 — appliance photos. We do not access your camera roll without your explicit picker action.
3.4 — Climate zone
Derived from the ZIP in the address you provide during onboarding. We map it to a climate zone to drive seasonal task generation. We do not collect GPS or any device location, and your ZIP is not sent to our analytics provider.
3.5 — Usage data
Which screens you open and which actions you take in the app. Once you’ve signed in, each event is tied to an account identifier that does not contain your name or email. Before you sign in, events are not associated with any account. Used to understand how the app is used and to improve it.
3.6 — Diagnostics
Crash reports and exception traces, with personal identifiers stripped. Used to find and fix bugs.
3.7 — Push tokens
Your device’s push token, so we can send you weekly briefs and severe-weather alerts. You can revoke push permission in iOS Settings at any time.
3.8 — Subscription status
Whether your subscription is active, when it renews or lapsed, and whether you have used a free trial. This comes to us from Apple via RevenueCat (see §4). We do not receive or store your payment card details.
3.9 — What we do not collect
- Your phone number.
- Your precise GPS location.
- Your contacts.
- Your social-graph data.
- Your other apps’ data.
- Advertising identifiers (IDFA). Kempt does not show ads and does not track you across other apps or websites.
4. Third-party processors
We use the following categories of service providers to operate the app. Each processes a slice of your data on our behalf under a Data Processing Agreement with us.
- AI inference (Anthropic, PBC). Your turns with the agent, your home address, appliance metadata, and relevant memory facts are processed to generate task suggestions, weekly briefs, appliance identifications, and chat responses. Anthropic is named here per Apple’s 2025 AI third-party-disclosure requirement. Anthropic does not train on API traffic by default.
- Database, storage, auth, and server infrastructure. All app data — your account, home, appliances, tasks, photos, memory, and briefs — is stored and processed by a US-based cloud infrastructure provider.
- Sign-in and push-notification delivery. Your sign-in identifiers and push tokens are processed by the sign-in providers you choose (Apple or Google) and Apple’s push notification service.
- Address enrichment. Your home address is used in a one-time lookup at onboarding to retrieve property attributes (year built, square footage, bedroom/bathroom count).
- Street View imagery (Google LLC). Your home’s street address is sent to Google’s Street View Static API in a separate, one-time lookup at onboarding, to retrieve and store a street-view image of your home shown in the app. Google receives your address only for this lookup.
- Appliance manual lookup (ManualsLib). To find the instruction manual for one of your appliances, its brand and model are sent as a search query to ManualsLib, a third-party online manuals directory. Only the appliance brand and model are sent. No account identifier, name, email, or address is included.
- Email delivery (Resend, Inc.). Weekly briefs and other transactional emails are sent through Resend, a US-based email delivery service, which receives the recipient’s email address and the content of the email.
- Bot and fraud prevention (hCaptcha / Intuition Machines, Inc.). During sign-in, a challenge service verifies you’re not an automated bot. It receives your IP address and device/behavioral signals. It does not receive your name, email, or anything you put into the app.
- Usage analytics. Event-level app-usage data, tied to an account identifier that does not contain your name or email, is processed by a US-based analytics service. That service is configured not to derive your location from your IP address.
- Error monitoring. Crash reports and exception traces (personal identifiers stripped) are processed by a US-based error monitoring service.
- Subscription management (RevenueCat, Inc.). When you subscribe, Apple processes the payment and sends a transaction receipt to RevenueCat, a US-based subscription-management service, which tracks whether your subscription is active and tells our servers. RevenueCat receives an account identifier that does not contain your name or email, your subscription and purchase history, and the country of your App Store account. It does not receive your name, email, home address, photos, or anything you put into the app. We never receive or store your payment card details — Apple handles payment end to end.
No advertising networks. No data brokers. We do not sell, rent, or share your data with anyone outside these categories.
5. How we use your data
- To run the app: store your home, generate tasks, compose briefs, deliver pushes, support your turns with the agent.
- To debug and improve the app: usage analytics and crash reports.
- To comply with the law: respond to valid legal requests (subpoena, court order). We will notify you if we receive a request targeting your data, unless legally barred from doing so.
We do not use your data for advertising. We do not profile you for purposes outside the app’s stated function.
6. Data retention
- Active accounts: retained while your account exists.
- Deleted accounts: see §7. Cascade-deleted within 7 days; backups age out within 30 days.
- Usage analytics: retained up to 7 years under our analytics provider’s current default configuration. We have not configured a shorter automatic deletion schedule.
- Crash reports: retained 30 days, then aged out.
- Auth logs: retained 90 days for security-incident investigation.
- Subscription records: entitlement state is retained while your account exists and is deleted with it. Apple and RevenueCat keep their own transaction records under their retention policies, which we do not control.
7. Your rights
You have the right to:
- Access the data we hold about you. In-app: Settings → Data → Export. If you can’t sign in, email
hello@usekempt.comwith subject “Access request” — we’ll send an export within 30 days. - Delete your account and all associated data. In-app: Settings → Account → Delete account. Everything you created in the app — your home, appliances, tasks, photos, and memory — is cascade-deleted, and backups age out within 30 days. Some usage-analytics events tied to a de-identified account marker may persist for up to 7 years per §6, and RevenueCat and Apple retain their own subscription records under their own retention policies (see §4) — both outside our direct control.
- Correct any data — directly in the app for everything you authored, or via email for account-level data.
- Export your data — Settings → Data → Export provides a portable copy of your home, appliances, tasks, and memory.
- Withdraw consent at any time by deleting your account.
For California residents (CCPA/CPRA): you have the same rights above. We do not sell or share personal information.
8. Data security
All data in transit is TLS 1.2+ encrypted. All data at rest is encrypted at the disk level. Access controls ensure you can only read your own home’s data. Operator accounts are protected with hardware-key two-factor authentication.
We will notify affected users promptly after confirming a personal-data breach.
9. Children
Kempt is not directed at children under 13 and does not knowingly collect data from them. If you believe a child has created an account, email hello@usekempt.com and we will delete the account.
10. Changes to this policy
We will email you at the address on file before any material change takes effect. Non-material changes (typos, clarifications) will be noted in the change log below. The current version of this policy lives at usekempt.com/privacy.
11. Contact
- Email:
hello@usekempt.com - Mailing address: Kempt, 4050 Pennsylvania Ave, Ste 115 #667, Kansas City, MO 64111
12. Change log
- 2026-07-22 — v1.5 (Phase-12 Workstream B, RF-673). Added ManualsLib to §4 as a disclosed sub-processor. The appliance-manual lookup (
lookup_manual) sends the user-authored appliance brand and model as a search query to ManualsLib, a third-party manuals directory (supabase/functions/_shared/handlers/lookup-manual.ts). This recipient was missed by the v1.3 sub-processor enumeration (RF-665) and left §4 inaccurate against its own closing affirmation that we share data with no one outside the listed categories. No account identifier is sent, only the appliance brand and model. Paired in the same change with a code fix (RF-674) removing that same brand/model text from the handler’s log lines, so the one place the app logged user-authored content is closed at the same time it is disclosed. - 2026-07-20 — v1.4 (Phase-12 Workstream B, RF-665(ii) follow-up). §6’s “usage analytics retained 12 months, then discarded” was itself a false claim — checked against actual PostHog config (project 397473), which showed
event_retention_months: 84,events_retention_enforced: false. v1.3 (below) documented this and proposed bringing the config down to 12 months; that turned out not to be self-serve configurable on the current plan (no dashboard control found, no PostHog API/MCP field exists for it, and event retention appears to be plan-tier-bucketed rather than an arbitrary settable value). Rather than leave the false promise live while waiting on a PostHog support ticket, §6 and §7 now state the actual current retention (up to 7 years, PostHog’s platform default, not enforced down). This affects RF-655’s “Decision 2” from the App Privacy label session — the call to let the 34 historical$geoip_*person-profile properties “expire under the 12-month retention clock” rather than manually purge them assumed the clock this entry now shows didn’t exist. That decision needs revisiting; not resolved by this entry. - 2026-07-20 — v1.3 (Phase-12 Workstream B, RF-665). Three undisclosed sub-processors added to §4: Google LLC (Street View imagery, a separate transmission from the existing property-attribute “Address enrichment” lookup), Resend, Inc. (email delivery — recipient address + email content), and hCaptcha / Intuition Machines, Inc. (bot/fraud prevention at sign-in — IP + device signals). None of the three were named anywhere in this document, which contradicted §4’s affirmative “we do not sell, rent, or share your data with anyone outside these categories.” Four accuracy fixes surfaced by the same review: §3.5 now states plainly that pre-sign-in events are not associated with any account (the prior wording implied every event carried an account identifier). §7’s account-deletion bullet no longer promises “all personal data” is cascade-deleted without qualification — it now names what actually survives deletion (analytics events under §6’s retention window; RevenueCat/Apple’s own subscription records) so the claim matches
purge_user()’s actual scope (home, home_member, and account rows — verified againstdelete-account.ts, which makes no PostHog or RevenueCat calls). Removed the “Opt out of analytics — toggle in Settings → Privacy” bullet from §7 — verified againstapps/mobile/srcthat no such screen exists anywhere in the app; the claim was false. Building an actual in-app opt-out is tracked as a new RF, separate from this accuracy pass. §6’s “usage analytics retained 12 months” claim was checked against the actual PostHog project config and found to be false as written —event_retention_monthsis 84 (the platform default),events_retention_enforced: false. Decision: bring the config to 12 months to match this document’s existing promise, rather than soften the promise to match the config. That setting change is not exposed through the PostHog API/MCP and requires a manual change in the PostHog dashboard (Settings → Data management) — tracked as an open operator action, not yet done as of this entry. - 2026-04-26 — v0.1 draft (Chunk 9.9.F). Beta-banner copy in place. Final version pending legal review (Phase 11, ~$500 one-time consult).
- 2026-04-30 — v0.1.1 (Chunk 9.95.D): contact emails consolidated to
hello@usekempt.com. §8 Access bullet updated to lead with in-app export path. - 2026-07-20 — v1.2 (Phase-12 Workstream B, RF-664). §3.4 retitled from “Coarse location” to “Climate zone”, and its body now states that your ZIP is not sent to our analytics provider. A Gate-1 review found the app had been transmitting the ZIP to PostHog as an
address_enteredevent property; that property was removed from the code, so the app now collects no location data at all and a section carrying Apple’s “Coarse location” category name was inaccurate. The code changed first — retitling ahead of the payload fix would have hidden the collision rather than removed it. - 2026-07-20 — v1.1 (Phase-12 Workstream B, RF-655). Removed five inaccurate “anonymous” / “aggregated” analytics claims. Verified against the code rather than intent: PostHog’s
distinct_idbecomes the user’s account uuid at sign-in (apps/mobile/src/lib/analytics.ts), and RevenueCat’s App User ID is that same account uuid (SubscriptionProvider.tsx), so neither is anonymous, and analytics is event-level, not aggregated. Reworded §3.5, §4 (both the analytics bullet and the RevenueCat bullet), §5, and §6 to “an account identifier that does not contain your name or email” — accurate without leaning on “anonymous” as a term of art. §4’s analytics bullet also now states that IP-based location derivation is disabled, which is what makes the App Store “Location: not collected” declaration honest. Note: the v1.0 entry below describes RevenueCat as receiving “an anonymous account identifier” — that was this document’s wording at the time and is left as the historical record; the body no longer says it. Motivated by the RF-655 App Privacy label refresh, which declares User ID as linked to identity and would otherwise have contradicted this policy on the same page. - 2026-07-20 — v1.0 (Phase-12 Workstream B, RF-651). Paid-subscription rewrite for public launch. §4 replaced the placeholder “Subscription management (not active during the free beta)” bullet with RevenueCat, Inc. named as an active processor, including what it does and does not receive (an anonymous account identifier, subscription and purchase history, and App Store country — never name, email, address, photos, or app content) and an explicit statement that we never receive payment card details. New §3.8 discloses subscription status as a collected data category (former §3.8 renumbered to §3.9). §6 retention extended to subscription records, noting Apple’s and RevenueCat’s own retention is outside our control. Beta framing removed throughout. Mailing address published inline (4050 Pennsylvania Ave, Ste 115 #667, Kansas City, MO 64111) now that it is a registered CMRA private mailbox rather than the founder’s home — closes RF-649. §2’s contractor-website example removed (feature never built — same verification as the Terms’ §8 removal). Feeds the App Privacy nutrition-label refresh (RF-655), where Purchases was an entirely missing category. Reconciles a 2026-05-08 fork of these docs that lived only in the website repo — see RF-661.
- 2026-05-02 — v0.2: §4 sub-processor table replaced with category-based list (Anthropic named per Apple AI disclosure rule; other vendors described by function only). §3.5/3.6 trimmed — removed named event list and internal technical detail. §6 GDPR framing removed (US-only app). §7 (now §8) security section simplified — implementation details removed. §8 (now §7) Your rights — DB table names removed, export bullet simplified. Sections renumbered.
- 2026-05-04 — v0.3 (Chunk 11.F): §3.2 appliance-photo paragraph updated — removed on-device OCR claim (KemptVision native module retired Chunk 11.B; photos now processed by AI inference provider). Beta banner simplified — removed “legal language will be tightened by counsel.” RF-351 TODO comment added to §1.