Kiki eSIM · Spicy Kiwi

Privacy Policy

Effective · Version ·

1. What this covers

This policy explains how handles information in the Kiki eSIM app, its account and order service, and these legal pages. Kiki helps crew plan and buy travel data around real roster duties.

2. Information Kiki handles

If you choose a custom profile photo, a copy is kept on your device for your profile. This version does not upload it or sync it to another device. Choosing a crew portrait removes that local custom-photo selection.

3. How a roster image is handled

A roster screenshot or camera image you choose to upload is sent to and processed on our servers to extract your schedule (duty dates, flight numbers, routes and off days). The image itself is deleted right after it has been read; it is not kept, and it is not shared with Zetexa or any other third party. The extracted duty data is kept on our servers while your Crew Plan is active, and is deleted no later than 90 days after your Crew Plan ends. If you later buy or prepare coverage for a duty, the minimum duty and destination details needed for that order may be used or sent to the Kiki backend.

4. Location and motion

With foreground permission, Kiki uses device location to choose a local greeting and centre travel features. It saves only the resolved country code and country/city label for this purpose, not a location history. You can refuse or revoke permission and use the app with device locale and time zone instead.

Device-motion readings create subtle parallax effects. They are used moment-to-moment, are not saved, and are not sent to Spicy Kiwi. Reduce Motion or an unavailable sensor produces a static fallback.

5. Notifications, iOS search and Shortcuts

Kiki can schedule local check-in and coverage notifications from roster data. Boarding-card notification art is bundled with the app. Apple delivers notifications under your device settings.

On iOS, Kiki can index duty, roster and pack titles in Core Spotlight and can mirror a minimal snapshot—next duty, check-in state and eSIM data remaining—to the app's private App Group for App Intents and Shortcuts. These features are on-device and can be controlled through iOS. Apple may process interactions under its own privacy terms.

6. Auto check-in consent

Auto check-in is off until you make an explicit choice. Kiki keeps an append-only on-device record of that choice, including whether it was enabled, when, and where in the app the choice was made. A matching authenticated server consent endpoint is prepared but is not yet connected in this app build. Kiki's check-in state is an app workflow; it is not a claim that an airline has checked you in.

7. Why information is used

Information is used to verify account/crew status, save preferences and rosters, display relevant destinations, calculate truthful prices, process orders and payments, provision and manage eSIM data, show usage, provide check-in/coverage reminders, prevent duplicate or abusive transactions, handle support/refund requests, keep security and consent records, and meet legal obligations.

8. Service providers

Kiki uses service providers only where needed to operate the service:

Kiki does not include an advertising SDK and does not sell personal information.

9. Storage, retention and security

Some information remains only in app storage. Backend records are retained for the periods below, or while needed to provide the service, secure and reconcile transactions, handle disputes, and satisfy applicable obligations, whichever is longer for legal/financial records. Stripe, Zetexa and infrastructure providers may retain their own records under their policies and legal duties.

DataRetention
Account identity (name, email, anything identifying) after you delete your accountDeleted 90 days after the deletion request; anonymised order lines (country, date, price — no person) are kept indefinitely
eSIM orders and usage linked to you24 months, then anonymised and the order line kept indefinitely
Payment records (Stripe identifiers, amount, date, last 4 digits)7 years, for US tax and accounting requirements
Crash and device logs90 days
Stay/location data (explicit opt-in only)24 months, then deleted; you can delete it sooner from Settings
Roster image (screenshot or photo)Deleted immediately after it is read for schedule extraction
Extracted roster/duty dataKept while your Crew Plan is active; deleted no later than 90 days after it ends

Kiki uses platform and service safeguards appropriate to the data, but no storage or transmission method is perfectly secure.

10. Your choices and deletion

You can change app permissions in device Settings, turn off notifications or auto check-in, and remove local roster/account data through available app controls. The current “Reset local account” action signs you out and clears the local profile only; it does not delete other local data or server/provider records.

An authenticated server account-deletion endpoint has been prepared to remove app-owned account, order, payment/refund, eSIM-profile/ICCID, duty/check-in, wallet, consent, subscription, OTP and idempotency records, leaving only a one-way subject digest and aggregate deletion receipt. It is not yet wired into this app build or deployed for user use. Stripe financial records, Zetexa records and raw security/webhook records require separate provider-retention and deletion handling before the feature can be represented as complete.

11. Contact and changes

Questions or privacy requests will use the support contact once it is approved: . Material policy changes will update the effective date and be surfaced through an appropriate app or website notice.

This operational draft intentionally flags unresolved contact and provider-deletion details; it must be reviewed before public launch.