Legal

Privacy Policy

Last updated: September 24, 2026

Overview

Kiwi Car AI (“Kiwi”, “we”, “our”) is a voice-first iPhone and CarPlay app for AI-assisted driving questions. Kiwi uses a backend service for session management, entitlement checks, request routing, operational diagnostics, usage metering, and privacy-safe product analytics. Kiwi does not sell your personal data, does not use advertising tracking, and does not run server-side conversation or memory sync by default.

Data Controller

Robert Oberdorfer
Asternweg 49
32676 Lügde
Germany
Email: [email protected]

What Stays on Your iPhone

Kiwi keeps the following information locally on your device by default:

How Kiwi Processes Requests

When you ask Kiwi a question, Kiwi sends the current request and the conversation context needed to answer it through Kiwi's backend service for model and voice processing. Kiwi uses the backend service to authenticate the request, apply entitlement checks, meter completed turns, and return the response and audio to your iPhone.

What Kiwi's Backend Stores

Kiwi's backend stores the minimum server-side information needed to operate the service. This includes:

Kiwi's metadata-only usage analytics intentionally exclude prompt text, answer text, and audio payloads. Kiwi does not sell this data or use it for advertising.

App Privacy Data Categories

In Apple's App Privacy terminology, Kiwi may collect the following categories. “Linked” means linked to a pseudonymous Kiwi service user, installation, or device record; it does not mean that Kiwi knows your civil identity.

None of these categories is used to track you across apps or websites owned by other companies.

Siri Integration

Kiwi integrates with Siri and App Shortcuts for hands-free use. When you use Siri commands:

Optional Location

Kiwi offers an optional “Share Location” feature that you can enable in Settings. When enabled:

When the feature is disabled, Kiwi does not access or send your location.

Necessary Backend Failure Diagnostics

To investigate failed or interrupted answers, Kiwi keeps limited technical failure records on its existing EU-hosted backend. These include the failure stage and time, error class and recognized error code, HTTP status, technical source-file locations, provider and model, processing durations, counts of received text and audio segments, and request or operation identifiers. Those identifiers can link the record to a pseudonymous service user or installation; the records are not anonymous. Full conversations, transcripts, audio, memories, location, and authentication credentials are not intentionally attached to these failure records. Filtered error descriptions may contain fragments of request or response content; filtering cannot guarantee that every fragment is removed.

This necessary service diagnosis is separate from optional activation analytics and voluntary Sentry reporting. It operates independently of those consent switches, is restricted to technical investigation and service reliability, and is not used for an individual product funnel, advertising, or model training. The legal basis is our legitimate interest in diagnosing and resolving service failures, subject to necessity, data minimization, and your right to object.

Crash, Performance, and Diagnostic Data

Kiwi uses Sentry for technical error and crash diagnostics. Versions before 3.3 can also send performance samples, automatic session measurements, and a separate pseudonymous Sentry installation identifier. Version 3.3 disables those performance samples and automatic session measurements and removes the Sentry user identifier from outgoing error events. Starting with version 3.3, Sentry starts only after a separate, voluntary error-reporting consent in Settings; this is off by default and is not enabled by activation-analytics consent. You can use every Kiwi feature without agreeing. Turning it off cancels the SDK transport, stops new reporting and clears pending local diagnostic files. Data already received by Sentry cannot be recalled by cancelling an upload and remains subject to the retention period and your applicable rights. Separate local cache directories prevent an earlier consent period's pending reports from being sent after you opt in again. Diagnostic events may include app version, device model, operating-system version, request status, and error details. Kiwi does not intentionally attach screenshots, prompts, answers, or audio. The Sentry project is configured to discard client IP addresses from newly processed events. Error diagnostics are separate from optional activation analytics and are not used for advertising.

Service Providers and International Processing

Kiwi uses service providers only where needed to operate the app:

Some providers may process data outside the European Economic Area. Where required, such transfers rely on an applicable adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, or another lawful transfer safeguard.

Legal Bases for EEA and UK Users

Retention

What Kiwi Does Not Do

Data Deletion

You can delete conversations and memories from within the app. Turning off “Share Usage Analytics” in Settings immediately stops new optional funnel collection and clears its local queue and markers. Kiwi's backend deletes this installation's linked funnel events when the withdrawal reaches it; an offline withdrawal is retried at the next authenticated connection. Uninstalling the app removes app-sandbox data on your iPhone. Keychain-based service credentials are managed separately by iOS and may persist across reinstall until they are rotated or replaced. To request deletion of other pseudonymous server-side service records associated with your Kiwi installation, contact [email protected].

Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal data, and to object to or withdraw consent for certain processing. Contact [email protected] to exercise these rights. EEA users may also lodge a complaint with a data-protection authority. The competent authority for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.

Children's Privacy

Kiwi is not directed at children under 13, and we do not knowingly collect personal data from children.

Changes to This Policy

We may update this policy from time to time. When we do, we will update the date at the top of this page.

Contact

If you have questions about this privacy policy, contact us at [email protected].