Who this policy applies to
Kipa is a private, local-first document vault operated from Luxembourg. This policy explains how the mobile app handles your vault and how this website handles support requests.
Data the mobile app stores
Kipa stores information you enter or scan, including document images, titles, dates, reminder settings, notes, folders, preferences, and encrypted backup or transfer packages you create. This information remains on your device unless you intentionally export or share a file.
Encryption and device storage
The Kipa database uses SQLCipher encryption. Document attachments use authenticated AES-GCM encryption. Encryption keys are held in the operating system's secure key storage. Durable attachments are saved inside Kipa's private app directory, organised by date and an internal item identifier.
Camera, photos, biometrics, and notifications
Kipa requests camera or photo-library access only when you choose to scan or attach a document. OCR runs on the device using Apple Vision or Google ML Kit.
If you enable app lock, biometric verification is performed by iOS or Android. Kipa does not receive or store your fingerprint or face data. If you create reminders, Kipa asks the operating system to schedule local notifications and does not use push-notification tokens.
Purchases
If you buy Kipa Plus, Apple, Google, and RevenueCat process the purchase and provide Kipa with entitlement status and purchase metadata. Kipa does not receive your full payment-card details. Their privacy policies apply to information they process.
Backup, transfer, and export
Kipa can create password-protected .kipa backup files and encrypted .kipasync transfer files. Kipa does not upload these files. You select where they are saved or which system sharing service carries them. Anyone who has both a file and its passphrase may be able to restore its contents.
Website contact requests
If you submit the contact form, this website processes the name, email address, topic, and message you provide so Kipa can reply. The configured email-delivery provider processes that message on Kipa's behalf. Do not attach private vault documents or include backup passphrases.
Analytics, advertising, and tracking
The Kipa mobile app does not include advertising, behavioral analytics, or cross-app tracking. This website is built without advertising, behavioral analytics, or tracking cookies. Kipa does not sell personal information.
Deleting data
You can delete individual documents inside Kipa. Deleting the app removes its local database and files according to the behavior of your operating system. Copies you exported remain wherever you saved or shared them. For a website contact request, ask Kipa support to delete the message where legally permitted.
Children
Kipa is not directed to children and does not knowingly collect children's information through an online service.
Changes
Material changes will be included with an app or website update and reflected by a new effective date.
Contact
For questions, privacy requests, or complaints, use the Kipa support form. The operator's final legal name and postal contact must be added before public App Store release.
Contact support with a description of the request, but never send a document image or backup passphrase.