Kinly Privacy Policy
Effective Date: July 2026 • FlashSoft OU
1. Introduction and Scope
This Privacy Policy explains how FlashSoft OÜ, a private limited company (osaühing) incorporated under the laws of the Republic of Estonia ("Company", "we", "us" or "our"), processes information in connection with the mobile application Kinly (the "App").
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, the Company is the controller of Personal Data processed through the App, except where a Third-Party Service or an App Store Provider acts as an independent controller, as described in this Privacy Policy.
This Privacy Policy applies only to the App. It does not apply to any Third-Party Services, websites or apps, even if they are accessible through the App.
By downloading, installing, accessing or using the App, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Privacy Policy, you must not use the App and must delete it from your Device.
This Privacy Policy forms part of, and should be read together with, our End User License Agreement (Terms of Use) available at https://flashsoftapps.com/kinly-eula.html.
2. Definitions
- "Personal Data" means any information relating to an identified or identifiable natural person.
- "Processing" means any operation performed on Personal Data, such as collection, storage, use, disclosure or deletion.
- "Device" means the smartphone, tablet or other device on which the App is installed.
- "Third-Party Services" means services, software development kits (SDKs), platforms and content provided by persons other than the Company.
- "App Store Provider" means Apple Inc. (App Store) or Google LLC (Google Play), as applicable.
3. Information We Collect
3.1 Information You Provide to Us
We do not require you to create an account or to provide your name, email address or other contact details to use the core features of the App, unless stated otherwise below.
If you contact us, for example by email, we process the information you choose to provide, such as your email address, name and the content of your message, in order to respond to you.
Health Information You Log. The App lets you record health and wellness information, such as blood pressure, heart rate, blood sugar, blood oxygen, body weight, body temperature, cholesterol, sleep, water intake, steps and calories, together with notes, the circumstances of a measurement, medications and the doses you mark as taken, photos you attach to a reading, and profile details such as a name, year of birth and height. This information may concern your health and is a special category of Personal Data. It is stored on your Device and, where you use iCloud, in your private iCloud account as described in this Section. It is not transmitted to us and is not shared with any of the Third-Party Services listed in Section 4; analytics events sent by the App describe which features are used, never the values you record. Reports, summaries and files that you export or share leave the App only when you choose to send them. If you add a profile for another person, such as a family member, you are responsible for having that person's consent, or the consent of their legal representative, to record their information. If you are located in the EEA, the UK or Switzerland, this processing is based on your explicit consent (Art. 9(2)(a) GDPR), which you give by entering the information and can withdraw at any time by deleting it in the App.
Sync via Your iCloud Account. If you are signed in to iCloud, the App may use Apple's iCloud service to sync your readings, medications and doses, reminders, target ranges and profiles, including photos attached to readings (data read from Apple Health is excluded) across your own Devices. This information is stored in your private iCloud account, governed by Apple's privacy policy, and is not transmitted to our servers and not accessible to us. You can control this at any time in your Device's iCloud settings, including by disabling iCloud for the App or deleting the data from iCloud.
3.2 Information Collected Automatically
When you use the App, certain information is collected automatically by the App and by the Third-Party Services integrated into it, including:
- Device information: Device model, manufacturer, operating system and version, language, time zone, screen parameters, and technical information about the Device such as memory and storage.
- Identifiers: app instance identifiers, installation identifiers, app user identifiers, the vendor identifier (IDFV) on iOS, the app set ID on Android and, only where you have permitted access, the advertising identifier (IDFA on iOS or Android Advertising ID on Android).
- Usage data: the date and time of your use of the App, first launch, sessions, screens viewed, features used, taps and other in-app events.
- Diagnostic data: crash reports, error logs, performance data and related technical information.
- Approximate location: country, region and city derived from your IP address. We do not collect your precise GPS location unless stated in Section 3.4.
- Purchase information: information about Subscriptions and in-app purchases, such as product identifier, transaction identifier, purchase date, renewal status, price and currency, and trial status.
3.3 Information from App Store Providers
When you make a purchase in the App, the App Store Provider processes your payment and provides us, directly or through Apphud, with transaction information necessary to validate and manage the purchase. We do not receive or store your payment card details, billing address or App Store Provider account password.
3.4 Device Permissions
The App may request permission to access certain features of your Device. You decide whether to grant each permission and can change your decision at any time in your Device settings. If you decline or revoke a permission, some features of the App may not be available or may not work properly, and the Company is not responsible for any resulting limitation.
Camera. The App may request access to your Device camera to read the numbers on the display of a blood pressure monitor, glucose meter or other measuring device, so you do not have to type them. Camera access is used only when you actively use the related feature. Unless stated otherwise in this Privacy Policy, images and video captured through the App are processed on your Device and are not transmitted to us. You can grant or revoke camera access at any time in your Device settings.
Photo Library. The App may request access to your photo library to attach a photo, such as a monitor display or a lab printout, to a reading. The App accesses only the photos and videos you select or, where applicable, the items you allow in your Device settings. Unless stated otherwise in this Privacy Policy, selected media is processed on your Device and is not transmitted to us. The App may save content you create to your photo library when you instruct it to do so.
Notifications. The App may ask for permission to send you notifications, such as reminders and information about features or offers. You can disable notifications at any time in your Device settings.
Files and Documents. The App may access files and documents that you select to import readings from a CSV file, restore a backup, and create CSV exports, PDF reports and backup files that you choose to save or share. The App accesses only the files you choose. Unless stated otherwise in this Privacy Policy, files are processed on your Device and are not transmitted to us.
Apple Health (iOS). With your permission, the App may read the following data from Apple Health: steps, body weight, heart rate and sleep, and may write the following data that you log in the App to Apple Health: blood pressure, heart rate, body weight, body temperature, blood glucose, blood oxygen, water intake, active energy and sleep. Data read from Apple Health is used only to show readings you already record in other apps alongside the ones you log in the App, in its charts, insights and reports. It is stored only on your Device, in a separate local database that is never synced to iCloud. It is not transmitted to us, is not shared with any of the Third-Party Services listed in Section 4, is not used for advertising, marketing or data mining, and is not sold. It leaves the App only if you include it in a report or file that you choose to export or share. You choose which data types to share on the iOS permission screen and can change your choice at any time in the Health app or in Settings > Privacy & Security > Health. If you are located in the EEA, the UK or Switzerland, this processing is based on your explicit consent (Art. 9(2)(a) GDPR), which you give and can withdraw through the iOS Health permissions.
Face ID and Touch ID. If you turn on the app lock, the App asks iOS to confirm your identity with Face ID, Touch ID or your Device passcode before your information can be viewed. The check is performed by iOS; the App receives only whether it succeeded and never has access to your biometric data.
3.5 Information We Do Not Intentionally Collect
Unless expressly stated in this Privacy Policy, we do not intentionally collect your name, postal address, phone number, precise location, contacts, photos, files, or any special categories of Personal Data (such as data concerning health, biometric data, racial or ethnic origin, political opinions, religious beliefs or sexual orientation). Please do not send us such information.
4. Third-Party Services We Use
The App uses the Third-Party Services listed below. These providers collect and process information directly from your Device in accordance with their own privacy policies. Some of them process data on our behalf as processors, and some act as independent controllers. We do not control, and are not responsible for, the data practices of Third-Party Services. We encourage you to read their privacy policies.
| Service | Provider | Purpose | Data Processed | Privacy Policy |
|---|---|---|---|---|
| Apphud | Apphud Inc. (USA) | Subscription and purchase management | Purchase and transaction history, device identifiers (IDFV, IDFA or Android Advertising ID where permitted), app user ID, country, language, locale, time zone, IP address, device model, OS version, app version, last activity date | https://legal.apphud.com/privacy |
| Firebase Analytics | Google LLC / Google Ireland Limited | Usage analytics | App instance ID, advertising identifier where permitted, device model, OS version, app version, language, country and approximate region derived from IP address, first launch, sessions, screens viewed, in-app events and purchases | https://policies.google.com/privacy |
| Firebase Crashlytics | Google LLC / Google Ireland Limited | Crash reporting and diagnostics | Crash installation UUID, Firebase installation ID, crash stack traces and logs, device model, CPU architecture, RAM and disk space, OS name and version, app version, device orientation, jailbreak or root status, timestamps | https://firebase.google.com/support/privacy |
| AppsFlyer | AppsFlyer Ltd. (Israel) | Attribution and marketing analytics | IP address (which may indicate general location), user agent, advertising identifier (IDFA or Android Advertising ID) where permitted, device type, operating system version, system language, and engagement data such as clicks, impressions, installations and in-app events | https://www.appsflyer.com/legal/services-privacy-policy/ |
Apphud. We use Apphud, provided by Apphud Inc. (USA), to manage Subscriptions and in-app purchases, validate purchase receipts, restore purchases and analyze subscription performance. Apphud processes purchase and transaction history, device identifiers (such as IDFV, and IDFA or Android Advertising ID where you have permitted access), an app user identifier, country, language, locale, time zone, IP address, device model, operating system version, app version and the date of your last activity in the App. Apphud does not receive your payment card details. Apphud's privacy policy is available at https://legal.apphud.com/privacy.
Firebase Analytics. We use Google Analytics for Firebase, provided by Google, to understand how the App is used and to improve it. Firebase Analytics automatically collects an app instance identifier, the advertising identifier where you have permitted access, device model, operating system and app version, language, country and approximate region, first launch, session information, screens viewed, and in-app events and purchases. Your approximate location is derived from your IP address; according to Google, IP addresses are not logged or stored in Google Analytics. More information is available at https://firebase.google.com/support/privacy and in Google's Privacy Policy at https://policies.google.com/privacy.
Firebase Crashlytics. We use Firebase Crashlytics, provided by Google, to receive crash reports and diagnose errors. When the App crashes or experiences an error, Crashlytics may collect a crash installation identifier, a Firebase installation ID, crash stack traces and logs, device model, processor architecture, memory and disk space, operating system name and version, app version, device state (such as orientation and jailbreak or root status) and timestamps. According to Google, this data is retained for ninety (90) days. More information is available at https://firebase.google.com/support/privacy.
AppsFlyer. We use AppsFlyer, provided by AppsFlyer Ltd. (Israel), for mobile attribution and marketing analytics: to understand which campaign or channel led you to install the App, to measure the performance of our marketing and to detect advertising fraud. AppsFlyer may collect your IP address (which may indicate your general location), user agent, the advertising identifier (IDFA on iOS or Android Advertising ID on Android) where you have permitted access, device type, operating system version and system language, and engagement data such as clicks, impressions, installations and in-app events. AppsFlyer's services privacy policy is available at https://www.appsflyer.com/legal/services-privacy-policy/.
Apple and Google. Purchases and Subscriptions are processed by the App Store Provider through which you downloaded the App: Apple Inc. (https://www.apple.com/legal/privacy/) or Google LLC (https://policies.google.com/privacy). The App Store Provider acts as an independent controller of your account and payment information. We do not receive or store your payment card details, billing address or App Store account password.
5. How We Use Information
We and our Third-Party Services use the information described in this Privacy Policy for the following purposes:
- to provide, operate and maintain the App and its features;
- to process, validate, manage and restore Subscriptions and in-app purchases;
- to monitor the stability and performance of the App and to diagnose and fix errors and crashes;
- to analyze how the App is used and to develop, test and improve the App, its features, content and user experience;
- to measure the effectiveness of our marketing and promotional activities;
- to store, chart and summarize the health information you record, and to prepare the reports and summaries you choose to export or share;
- to sync your settings and content across your own Devices through your iCloud account;
- to detect, prevent and address fraud, abuse, security incidents and technical issues;
- to respond to your requests and communicate with you;
- to comply with legal obligations and to establish, exercise or defend legal claims;
- for any other purpose with your consent.
6. Legal Bases for Processing (EEA, UK and Switzerland)
If you are located in the European Economic Area, the United Kingdom or Switzerland, we rely on the following legal bases:
- Performance of a contract (Art. 6(1)(b) GDPR): to provide the App and to process and manage your Subscriptions and purchases.
- Legitimate interests (Art. 6(1)(f) GDPR): to keep the App secure and stable, to diagnose errors, to analyze and improve the App, to prevent fraud, and to establish, exercise or defend legal claims. Our legitimate interests are not overridden by your interests or fundamental rights, taking into account the pseudonymous nature of most of the data.
- Consent (Art. 6(1)(a) GDPR): where required by applicable law, including for personalized advertising, for access to the advertising identifier and for storing or accessing information on your Device. You may withdraw your consent at any time as described in Section 13. Withdrawal does not affect the lawfulness of processing before withdrawal.
- Legal obligation (Art. 6(1)(c) GDPR): where processing is necessary to comply with the law, such as accounting and tax obligations.
7. Advertising and Tracking
The App does not currently display third-party advertisements and does not use your advertising identifier to display personalized advertisements. If we introduce advertising, we will update this Privacy Policy and, where required by law, request your consent. On iOS, you can control tracking permissions at any time in Settings > Privacy & Security > Tracking.
8. How We Share Information
We do not sell your Personal Data for money. We may share information only as follows:
- Third-Party Services listed in Section 4, which process data to provide their services to us or as independent controllers.
- App Store Providers, which process purchases and Subscriptions.
- Legal requirements: where we believe in good faith that disclosure is required by law, regulation, legal process or a governmental request, or is necessary to protect the rights, property or safety of the Company, our users or others.
- Business transfers: in connection with a merger, acquisition, reorganization, financing, sale of assets or similar transaction, in which case information may be transferred to the acquirer or successor.
- With your consent or at your direction.
- Aggregated or de-identified information that cannot reasonably be used to identify you may be shared for any lawful purpose.
9. International Data Transfers
The Company is established in the European Union. Our Third-Party Services are located in, or transfer data to, countries outside the European Economic Area, including the United States, which may not provide the same level of data protection as your country. Where required, such transfers are based on the European Commission's adequacy decisions (including the EU-U.S. Data Privacy Framework, for certified recipients), Standard Contractual Clauses approved by the European Commission, or other lawful transfer mechanisms. By using the App, you acknowledge that your information will be transferred to and processed in such countries.
10. Data Retention
We retain Personal Data only for as long as necessary for the purposes described in this Privacy Policy, unless a longer retention period is required or permitted by law. Information processed by Third-Party Services is retained in accordance with their retention policies, as summarized in Section 4. Correspondence with us is retained for as long as needed to handle your request and for a reasonable period afterwards to defend potential claims. When information is no longer needed, it is deleted or anonymized.
11. Data Security
We and our Third-Party Services use technical and organizational measures designed to protect information against unauthorized access, loss, misuse or alteration, including encryption in transit. However, no method of transmission over the internet or of electronic storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your Device secure, including using a passcode, installing operating system updates and not using the App on a jailbroken or rooted Device. Where required by applicable law, we will notify you and/or the competent authorities of a personal data breach.
12. Your Rights
12.1 EEA, UK and Switzerland
Subject to the conditions and exceptions set out in applicable law, you have the right to:
- request access to your Personal Data;
- request rectification of inaccurate Personal Data;
- request erasure of your Personal Data;
- request restriction of processing;
- receive your Personal Data in a portable format;
- object to processing based on legitimate interests, including profiling;
- withdraw your consent at any time;
- lodge a complaint with a supervisory authority. The lead supervisory authority for the Company is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), https://www.aki.ee. You may also contact the authority in your country of residence.
12.2 United States
Depending on your state of residence (for example, California, Virginia, Colorado, Connecticut, Utah, Texas or Oregon), you may have the right to know what Personal Data we process, to access and receive a copy of it, to correct it, to delete it, and to opt out of "targeted advertising", "sale" or "sharing" of Personal Data as defined by applicable state law. We do not sell Personal Data for money. The use of advertising and analytics Third-Party Services may be considered "sharing" or "targeted advertising" under some state laws; you can opt out as described in Section 7 and Section 13. We will not discriminate against you for exercising your rights. You may designate an authorized agent to make a request on your behalf, subject to verification.
12.3 How to Exercise Your Rights
To exercise your rights, contact us at contact@flashsoftapps.com. We may need to verify your identity before responding. We respond within the time limits required by applicable law.
Most information processed through the App is pseudonymous and linked to Device or app identifiers rather than to your name or email address. To help us locate your data, please include in your request the App name, your Device platform and, if available, the identifiers shown in the App's settings or the transaction ID of your purchase. If we cannot reasonably identify the data relating to you, we may be unable to fulfill your request, as permitted by applicable law. Some requests may also be exercised directly with the relevant Third-Party Service or App Store Provider.
13. Your Choices and Controls
- Device permissions: manage or revoke permissions at any time in your Device settings.
- Advertising identifier and tracking: control as described in Section 7.
- Consent choices: where the App displays a consent message, you may review or change your choices in the App's settings, where available.
- Subscriptions: manage or cancel through your App Store Provider account settings.
- Stop all collection: you can stop all collection of information by the App at any time by uninstalling the App from your Device.
14. Children's Privacy
The App is not directed to children under the age of 13, or under the higher minimum age required for consent to data processing in your country (for example, 16 in some EEA countries). We do not knowingly collect Personal Data from such children. If you are a parent or guardian and believe that your child has provided Personal Data through the App, contact us at contact@flashsoftapps.com, and we will take steps to delete such information. Parents and guardians are responsible for supervising their children's use of Devices and apps.
15. Third-Party Links and Content
The App may contain links to, or content from, third-party websites, apps and services, including advertisements. We are not responsible for the content, privacy practices or security of any third party. Your interactions with third parties are governed by their own terms and privacy policies.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time at our sole discretion. The updated version will be published at https://flashsoftapps.com/kinly-privacy-policy.html and will be effective from the "Last Updated" date shown above. Where required by applicable law, we will inform you of material changes through the App or by other appropriate means. Your continued use of the App after the "Last Updated" date means that you acknowledge the updated Privacy Policy. We encourage you to review this Privacy Policy periodically.
17. Language
This Privacy Policy is written in English. If it is translated into another language, the English version prevails in the event of any inconsistency, to the extent permitted by applicable law.
18. Contact Us
If you have any questions about this Privacy Policy or our data practices, contact us:
- Company: FlashSoft OÜ
- Email:contact@flashsoftapps.com
- Website:https://flashsoftapps.com