Privacy Policy
1. What this covers
This policy explains how handles information in the Kiki eSIM app, its account and order service, and these legal pages. Kiki helps crew plan and buy travel data around real roster duties.
2. Information Kiki handles
If you choose a custom profile photo, a copy is kept on your device for your profile. This version does not upload it or sync it to another device. Choosing a crew portrait removes that local custom-photo selection.
- Account and verification: name, account or work email, airline domain, signup and verification timestamps, OTP challenge/verification records, and a server user identifier when account services are connected.
- Roster and duty information: parsed duty dates, flight numbers, routes, leave/off-day events and check-in state. A selected duty may be sent with an order so the right destination pack can be prepared.
- eSIM and order information: chosen package, price evidence, order and payment status, data allowance and usage, activation state, install payload, and ICCID/SIM-profile identifiers supplied through Kiki's backend and connectivity provider.
- Payments and subscriptions: purchase amount, currency, Stripe payment or subscription identifiers and status. Stripe and Apple Pay handle card/payment credentials; Kiki does not receive or store full card numbers.
- Support and refunds: the purchase referenced, troubleshooting confirmations, request time, quota cycle, tier and pending-review status. The current app records refund requests locally until the authenticated server flow is connected.
- Preferences and device features: avatar, language, currency, appearance, notification choices and other app settings stored on the device.
3. How a roster image is handled
A roster screenshot or camera image you choose to upload is sent to and processed on our servers to extract your schedule (duty dates, flight numbers, routes and off days). The image itself is deleted right after it has been read; it is not kept, and it is not shared with Zetexa or any other third party. The extracted duty data is kept on our servers while your Crew Plan is active, and is deleted no later than 90 days after your Crew Plan ends. If you later buy or prepare coverage for a duty, the minimum duty and destination details needed for that order may be used or sent to the Kiki backend.
4. Location and motion
With foreground permission, Kiki uses device location to choose a local greeting and centre travel features. It saves only the resolved country code and country/city label for this purpose, not a location history. You can refuse or revoke permission and use the app with device locale and time zone instead.
Device-motion readings create subtle parallax effects. They are used moment-to-moment, are not saved, and are not sent to Spicy Kiwi. Reduce Motion or an unavailable sensor produces a static fallback.
5. Notifications, iOS search and Shortcuts
Kiki can schedule local check-in and coverage notifications from roster data. Boarding-card notification art is bundled with the app. Apple delivers notifications under your device settings.
On iOS, Kiki can index duty, roster and pack titles in Core Spotlight and can mirror a minimal snapshot—next duty, check-in state and eSIM data remaining—to the app's private App Group for App Intents and Shortcuts. These features are on-device and can be controlled through iOS. Apple may process interactions under its own privacy terms.
6. Auto check-in consent
Auto check-in is off until you make an explicit choice. Kiki keeps an append-only on-device record of that choice, including whether it was enabled, when, and where in the app the choice was made. A matching authenticated server consent endpoint is prepared but is not yet connected in this app build. Kiki's check-in state is an app workflow; it is not a claim that an airline has checked you in.
7. Why information is used
Information is used to verify account/crew status, save preferences and rosters, display relevant destinations, calculate truthful prices, process orders and payments, provision and manage eSIM data, show usage, provide check-in/coverage reminders, prevent duplicate or abusive transactions, handle support/refund requests, keep security and consent records, and meet legal obligations.
8. Service providers
Kiki uses service providers only where needed to operate the service:
- Cloudflare and Supabase for API hosting, authentication records and operational data when backend mode is connected.
- Stripe for payment and subscription processing.
- Zetexa as the eSIM/connectivity processor and supplier for package, order, profile and usage operations.
- Apple for App Store distribution and, when you opt in or invoke them, Apple Pay, notifications, location services, Core Spotlight and App Intents/Shortcuts.
Kiki does not include an advertising SDK and does not sell personal information.
9. Storage, retention and security
Some information remains only in app storage. Backend records are retained for the periods below, or while needed to provide the service, secure and reconcile transactions, handle disputes, and satisfy applicable obligations, whichever is longer for legal/financial records. Stripe, Zetexa and infrastructure providers may retain their own records under their policies and legal duties.
| Data | Retention |
|---|---|
| Account identity (name, email, anything identifying) after you delete your account | Deleted 90 days after the deletion request; anonymised order lines (country, date, price — no person) are kept indefinitely |
| eSIM orders and usage linked to you | 24 months, then anonymised and the order line kept indefinitely |
| Payment records (Stripe identifiers, amount, date, last 4 digits) | 7 years, for US tax and accounting requirements |
| Crash and device logs | 90 days |
| Stay/location data (explicit opt-in only) | 24 months, then deleted; you can delete it sooner from Settings |
| Roster image (screenshot or photo) | Deleted immediately after it is read for schedule extraction |
| Extracted roster/duty data | Kept while your Crew Plan is active; deleted no later than 90 days after it ends |
Kiki uses platform and service safeguards appropriate to the data, but no storage or transmission method is perfectly secure.
10. Your choices and deletion
You can change app permissions in device Settings, turn off notifications or auto check-in, and remove local roster/account data through available app controls. The current “Reset local account” action signs you out and clears the local profile only; it does not delete other local data or server/provider records.
An authenticated server account-deletion endpoint has been prepared to remove app-owned account, order, payment/refund, eSIM-profile/ICCID, duty/check-in, wallet, consent, subscription, OTP and idempotency records, leaving only a one-way subject digest and aggregate deletion receipt. It is not yet wired into this app build or deployed for user use. Stripe financial records, Zetexa records and raw security/webhook records require separate provider-retention and deletion handling before the feature can be represented as complete.
11. Contact and changes
Questions or privacy requests will use the support contact once it is approved: . Material policy changes will update the effective date and be surfaced through an appropriate app or website notice.
This operational draft intentionally flags unresolved contact and provider-deletion details; it must be reviewed before public launch.