Kairo Privacy Policy
Kairo is a privacy-first, local-first presence and memory application from Chaosphere Apps. This policy explains what Kairo processes, where information is stored, and when information may leave a device.
The Short Version
Kairo's nearby detection, trusted connection commands, and memory features work without internet. Connections, moments, notes, favorites, approximate location tags, and imported memory photos are stored in Kairo's private app storage on the device by default.
Kairo does not sell personal data. Kairo does not operate a public social feed or public location map.
Information leaves the device only when required for a supporting service or when the user chooses an action that shares it. Examples include checking Google Play for updates, sharing a generated poster, opening a saved coordinate in a map app, or enabling optional encrypted Google Drive backup.
Information Stored on the Device
Depending on the features used, Kairo may store:
- a Kairo device identity and cryptographic material;
- trusted connections and user-selected names, emojis, or avatars for them;
- display name, avatar, and mood;
- nearby moments, sessions, timestamps, estimated Bluetooth proximity, and interaction history;
- private notes, favorites, achievements, and feature unlocks;
- approximate coordinates when moment location tagging is enabled;
- photos explicitly selected through Android's system photo picker and attached to a moment; and
- app settings and operational state needed for reliable nearby detection.
This information is not uploaded to Chaosphere Apps for Kairo's core nearby or memory functionality.
Nearby Bluetooth Exchange
Kairo uses Bluetooth Low Energy, GATT, and supported device-ranging technology to detect and communicate with nearby Kairo devices. It exchanges compact rotating presence signals and encrypted commands with nearby devices.
Trusted connections receive only the protocol information required for the selected nearby feature. Around profile information, including display name, avatar, mood, and approximate Bluetooth distance, is shared only when Around visibility is enabled. GPS coordinates, timelines, notes, photos, and contact lists are not advertised in Around.
Location
Moment location tagging is optional. When enabled and Android permission is granted, Kairo stores approximate coordinates with moments in local app storage. Kairo does not provide a public live-location map.
If the user selects Open in Maps, Kairo shows a confirmation before sending the selected coordinate to an external map application. The map provider then processes that coordinate under its own terms and privacy policy. Kairo does not include connection names, notes, or photos in that map request.
Photos and Sharing
Kairo accesses only photos the user explicitly chooses through Android's system photo picker. Kairo creates an optimized private copy for the selected moment. It does not scan the photo library or automatically upload photos.
When the user shares a Memory Poster or another export, Android's share sheet sends the generated content to the app or person selected by the user. That recipient or third-party app handles the shared content under its own privacy practices.
Internet and Google Play Services
Kairo can run its core nearby and memory experience without internet. Internet may be used for:
- checking update availability and delivering optional in-app updates through Google Play;
- opening the Kairo Play Store listing;
- non-personal compatibility or app configuration in a future release; and
- optional encrypted Google Drive backup and restore, when enabled by the user.
Google Play may process technical information such as app version, device or account context, network information, and update status according to Google's privacy policy. Kairo does not send memory content to Google merely to check for an app update.
Backup and Restore
Google Drive backup is optional and off until the user enables it. Kairo uses the Google Drive appDataFolder, which is a private application-data area rather than the user's normal Drive file list. Kairo requests only the drive.appdata permission for this feature.
Before an archive leaves the phone, Kairo encrypts it with AES-256-GCM. A random backup key is protected by a user-held recovery code. Google receives and stores the encrypted archive but does not receive the recovery code from Kairo. Kairo and Google cannot recover a forgotten recovery code.
Depending on the user's backup options, the archive may contain:
- profile settings, trusted-person memory anchors, moments, sessions, notes, favorites, approximate saved locations, Memory Book selections, and earned achievements; and
- optimized private copies of moment photos when Include photos is enabled.
The archive never contains the current phone's private identity key, DeviceId, presence seed, connection shared secrets, Bluetooth addresses, active Flare or navigation sessions, or diagnostic logs. Restored timelines remain available, but nearby detection, Find, and Say hi remain paused for each person until the user refreshes that connection in person.
Kairo keeps up to three complete encrypted backup generations. Users can pause automatic backup without deleting existing copies, or delete all Kairo cloud backups from Your Kairo Data. Google account authorization and Drive processing are also subject to Google's privacy policy.
Permissions
Kairo may request Bluetooth scanning, advertising, and connection permissions; notification permission; camera access for scanning connection QR codes; approximate or precise location for optional moment tags; vibration; foreground service access; startup after reboot; and supported ranging permissions for precision finding. Permission availability does not cause Kairo to upload the associated data.
Retention and Deletion
Kairo retains local information until it is removed by the user, removed under an explained in-app retention rule, or deleted with the application. Removing a connection may remove its associated Kairo history as described by the confirmation shown in the app. Deleting an attached memory photo removes Kairo's private optimized copy; it does not delete the original gallery photo.
Encrypted Google Drive copies remain until replaced by Kairo's three-generation retention policy or deleted by the user from Your Kairo Data.
Security
Kairo uses rotating presence identifiers, trusted connection material, and encrypted command payloads to reduce Bluetooth tracking and spoofing risk. No system can guarantee absolute security, but Kairo is designed to minimize the information exposed and keep personal memory data local by default.
Children
Kairo is not designed to knowingly collect children's personal information on Chaosphere Apps servers. Families should review Bluetooth, location, sharing, and notification settings together before use.
Changes to This Policy
This policy will be updated before a material new data practice is enabled. The effective date above will change when the policy is revised.
Contact
Privacy questions can be sent to Chaosphere Apps using the developer contact listed on Kairo's Google Play Store page.