Last updated: September 24, 2026
Overview
Kiwi Car AI (“Kiwi”, “we”, “our”) is a voice-first iPhone and CarPlay app for AI-assisted driving questions. Kiwi uses a backend service for session management, entitlement checks, request routing, operational diagnostics, usage metering, and privacy-safe product analytics. Kiwi does not sell your personal data, does not use advertising tracking, and does not run server-side conversation or memory sync by default.
Data Controller
Robert OberdorferAsternweg 49
32676 Lügde
Germany
Email: [email protected]
What Stays on Your iPhone
Kiwi keeps the following information locally on your device by default:
- Conversations: Your conversation history is stored in the app's local storage on your iPhone.
- Memories: Notes that you save with Kiwi Memory stay on your iPhone.
- Install-bound Kiwi service session: Kiwi stores an install-bound Kiwi service session in the iPhone Keychain so the service can recognize this installation, refresh access when needed, and check entitlement state.
- App preferences: Settings such as your location-sharing preference, onboarding completion, and debug preferences are stored locally on your device.
- Optional analytics markers: Only after you allow Usage Analytics, Kiwi stores a random event ID, event time, app version, and build number with each queued fixed activation milestone or usage-attempt event so retries can be delivered once. Declining or withdrawing consent clears this local queue and its one-time markers.
How Kiwi Processes Requests
When you ask Kiwi a question, Kiwi sends the current request and the conversation context needed to answer it through Kiwi's backend service for model and voice processing. Kiwi uses the backend service to authenticate the request, apply entitlement checks, meter completed turns, and return the response and audio to your iPhone.
- OpenAI acts as Kiwi's model provider for AI request processing.
- xAI may process answer text and fixed voice-cue text for text-to-speech when configured as Kiwi's voice provider.
- OpenAI's privacy policy applies to model-processing data: https://openai.com/policies/privacy-policy/
- xAI's privacy policy may apply to text-to-speech processing data: https://x.ai/legal/privacy-policy
- Kiwi does not provide a normal mode that asks you to paste your own OpenAI API key.
- Kiwi does not sync your full conversation history or memory notes to Kiwi's backend by default.
What Kiwi's Backend Stores
Kiwi's backend stores the minimum server-side information needed to operate the service. This includes:
- Session, identifier, and entitlement data: Pseudonymous service-user, installation, and session records; App Attest verification data; entitlement, preview, purchase, subscription, and billing-period status. Kiwi does not require a name or email account for normal app use.
- Network and security data: Cloudflare, Kiwi's hosting stack, and short-lived rate limiting may process IP addresses, request timestamps, routes, request IDs, and similar network metadata to deliver and protect the service.
- Metadata-only usage analytics: Request type, provider, model, request profile, token counts when available, text-to-speech character counts, cost metadata, durations, web-search usage, and related operational metadata.
- Aggregate rollups: Longer-lived user and global usage summaries derived from metadata-only events.
- Optional activation analytics: If you choose “Allow Analytics” for the expanded analysis, Kiwi collects fixed setup and usage events for 30 days from your first consent to this version. Existing users are asked again; an earlier consent is not silently expanded. Events describe onboarding screens and deliberate navigation, permission requests and outcomes, preview selection and access results, purchase selection and outcomes, Siri or CarPlay usage attempts, capture and recognition milestones, backend processing, and actual playback start and completion. Each event is retained for up to 90 days from its occurrence. Records contain a random event ID, a random attempt ID where relevant, fixed allowlisted categories (entry channel, feature, step, outcome and technical failure phase or code), event time, app version/build, source, and the existing pseudonymous installation or service-user reference. No questions, answers, transcripts, audio, memory contents, location coordinates, advertising identifiers or free-form error messages are included. Client retries are deduplicated; backend processing and verified purchase transitions are server-owned. You can decline without losing app functionality and withdraw consent in Settings. Withdrawal stops collection and clears pending local events immediately. The backend deletes this installation's linked funnel events when it receives the withdrawal; if you are offline or your session has expired, the app sends it at the next authenticated connection. A minimal first-consent timestamp remains with the installation to enforce the original deadline; switching analytics off and on does not restart the 30 days. Offline events created within the collection window may arrive later within their 90-day retention period while consent remains active. Bounded local storage and daily upload limits can leave measurement gaps. Older app versions can continue the previously disclosed, narrower analytics under their original consent until upgraded or revoked. Apple download and acquisition reports remain aggregate-only and cannot be joined to an installation. Unlinked global daily counts may be retained longer.
- Temporary TTS authorization: When Kiwi prepares an answer for linked text-to-speech, the backend temporarily stores the answer text with a one-time authorization. It is deleted after successful use; unused authorizations expire after 30 minutes and are removed by expiry cleanup.
- Short-lived replay protection: Kiwi keeps replayable request and response payloads for up to one hour to safely handle retries and idempotent request replays.
Kiwi's metadata-only usage analytics intentionally exclude prompt text, answer text, and audio payloads. Kiwi does not sell this data or use it for advertising.
App Privacy Data Categories
In Apple's App Privacy terminology, Kiwi may collect the following categories. “Linked” means linked to a pseudonymous Kiwi service user, installation, or device record; it does not mean that Kiwi knows your civil identity.
- Identifiers: Pseudonymous user and device or installation identifiers, used for app functionality and, with optional consent, analytics.
- Purchases: Purchase and subscription history, used for entitlement, app functionality, and analytics.
- Usage Data: Product interaction and other usage data, used for app functionality and analytics.
- User Content: Questions and conversation context sent to service a request, used for app functionality.
- Search History: Questions that invoke Kiwi's optional web-search capability, used for app functionality.
- Location: Depending on the installed app version and iOS accuracy setting, optional location context can be precise or coarse and is used only for app functionality. Precise Location applies to the currently available version because it can send rounded coordinates. The pending privacy-hardening build sends only a city or region and will allow that disclosure to be removed after release.
- Diagnostics: Crash, performance, and other diagnostic data, used for app functionality, reliability, and analytics. Backend performance and diagnostic records can be linked to a pseudonymous service user or installation; Sentry crash records are not intentionally linked to that service identity.
None of these categories is used to track you across apps or websites owned by other companies.
Siri Integration
Kiwi integrates with Siri and App Shortcuts for hands-free use. When you use Siri commands:
- Apple processes your voice according to Apple's privacy practices.
- The transcribed text is passed to Kiwi and then through Kiwi's backend service for model processing. Spoken responses may also be processed for text-to-speech.
Optional Location
Kiwi offers an optional “Share Location” feature that you can enable in Settings. When enabled:
- The currently available app version can derive a place name and rounded coordinates. Apple's App Privacy terminology therefore treats this as Precise Location even when Kiwi describes the feature as approximate.
- A pending privacy-hardening build removes coordinates before transmission and sends only a reverse-geocoded city or region. Until that build is available, location context must be treated as precise.
- The location context is included in the first message of each conversation sent through Kiwi's backend service to OpenAI.
- Kiwi does not use the location feature when it is turned off.
- You can disable the feature at any time in Settings.
When the feature is disabled, Kiwi does not access or send your location.
Necessary Backend Failure Diagnostics
To investigate failed or interrupted answers, Kiwi keeps limited technical failure records on its existing EU-hosted backend. These include the failure stage and time, error class and recognized error code, HTTP status, technical source-file locations, provider and model, processing durations, counts of received text and audio segments, and request or operation identifiers. Those identifiers can link the record to a pseudonymous service user or installation; the records are not anonymous. Full conversations, transcripts, audio, memories, location, and authentication credentials are not intentionally attached to these failure records. Filtered error descriptions may contain fragments of request or response content; filtering cannot guarantee that every fragment is removed.
This necessary service diagnosis is separate from optional activation analytics and voluntary Sentry reporting. It operates independently of those consent switches, is restricted to technical investigation and service reliability, and is not used for an individual product funnel, advertising, or model training. The legal basis is our legitimate interest in diagnosing and resolving service failures, subject to necessity, data minimization, and your right to object.
Crash, Performance, and Diagnostic Data
Kiwi uses Sentry for technical error and crash diagnostics. Versions before 3.3 can also send performance samples, automatic session measurements, and a separate pseudonymous Sentry installation identifier. Version 3.3 disables those performance samples and automatic session measurements and removes the Sentry user identifier from outgoing error events. Starting with version 3.3, Sentry starts only after a separate, voluntary error-reporting consent in Settings; this is off by default and is not enabled by activation-analytics consent. You can use every Kiwi feature without agreeing. Turning it off cancels the SDK transport, stops new reporting and clears pending local diagnostic files. Data already received by Sentry cannot be recalled by cancelling an upload and remains subject to the retention period and your applicable rights. Separate local cache directories prevent an earlier consent period's pending reports from being sent after you opt in again. Diagnostic events may include app version, device model, operating-system version, request status, and error details. Kiwi does not intentionally attach screenshots, prompts, answers, or audio. The Sentry project is configured to discard client IP addresses from newly processed events. Error diagnostics are separate from optional activation analytics and are not used for advertising.
Service Providers and International Processing
Kiwi uses service providers only where needed to operate the app:
- Apple: App distribution, StoreKit purchases, subscription status, App Attest, Siri, and Apple-provided app analytics.
- Hetzner: Hosting of Kiwi's backend service in the European Union.
- Cloudflare: Network delivery, TLS termination, availability, and abuse protection. Production and staging API traffic passes through Cloudflare Proxy and Tunnel; the public website is delivered through Pages. The Self-Serve Agreement incorporates Cloudflare's Data Processing Addendum.
- OpenAI: AI request processing. Kiwi sends Responses API requests with provider-side application-state storage disabled. The current project uses Global processing; an EU-only processing region or approved Zero Data Retention is not configured. Under OpenAI's standard controls, abuse-monitoring logs can still contain prompts, responses, and derived metadata and can be retained for up to 30 days, or longer when legally required, unless approved account-level controls apply. See OpenAI's API data controls.
- xAI: The API provider is identified as SpaceXAI LLC in its current Data Processing Addendum. Text-to-speech processing when configured as Kiwi's voice provider. The current account uses standard retention, not Zero Data Retention. According to xAI's API security documentation, requests and responses are encrypted and retained for 30 days for potential abuse investigation, then automatically deleted. API data is not used for training without permission. See xAI API data controls.
- Sentry (Functional Software, Inc.): Crash, performance, and diagnostic processing.
Some providers may process data outside the European Economic Area. Where required, such transfers rely on an applicable adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, or another lawful transfer safeguard.
Legal Bases for EEA and UK Users
- Contract and requested services: App functionality, request processing, entitlement checks, purchases, and subscription access are processed to provide the service you request.
- Legitimate interests: Security, abuse prevention, investigation of service failures, and operational cost control support the safe operation of Kiwi. These purposes do not authorize an individual product funnel without consent.
- Consent: Optional activation analytics and, starting with version 3.3, Sentry error reporting each require their own express consent. Neither is required to use Kiwi. Location processing begins only after you enable the feature and grant the iOS permission. You can withdraw either analytics or diagnostic consent independently in Kiwi Settings, and location permission in Kiwi Settings or iOS Settings.
- Legal obligations: Limited records may be retained where required for accounting, tax, dispute, or other legal obligations.
Retention
- Conversations, memories, and preferences remain on your iPhone until you delete them, reset the app, or uninstall it, subject to iOS Keychain behavior. Optional activation-delivery markers are cleared when consent is withdrawn. The minimal first-consent timestamp remains locally and with the installation to enforce the original 30-day deadline.
- Replayable request and response payloads expire after no more than one hour.
- Linked TTS authorization text is deleted after successful use. Unused authorizations expire after 30 minutes and are removed by expiry cleanup.
- Raw authentication events are retained for up to 30 days. Pseudonymous activation events, metadata-only usage events, and user-level usage rollups are retained for up to 90 days.
- Dedicated backend answer-failure database records have a retention limit of seven days and are removed by the scheduled cleanup described below. General backend log copies follow size-based rotation and do not share that fixed seven-day deadline; copies in stopped deployment containers remain until those containers are retired. Hosting backups have the separate rotation and restore rules described below.
- Backend expiry cleanup runs every minute independently of app usage. Expired replay and authorization payloads cannot be used after their validity deadline; physical deletion follows in the next successful cleanup run. Service outages can delay cleanup, which resumes when the service becomes available.
- Network and rate-limit data is retained only for the applicable security window or the infrastructure provider's configured operational-log period.
- Pseudonymous installation, session, purchase, subscription, entitlement, billing, user-level rollup, and security records are retained for as long as needed to operate and protect the service, honor purchases, resolve disputes, or meet legal obligations. This does not extend the 90-day limit for user-level analytics rollups.
- Hosting backups rotate through seven daily server-backup slots. This is not a guaranteed seven-day deletion period if backups stop. A restored database must remain isolated until deletion checks complete. Optional funnel history is discarded and measurement is closed for restored installations before analytics can resume; such a recovery creates a measurement gap.
- Global daily activation counts and other aggregate rollups may be retained longer for trend, cost, reliability, and product analysis.
- Sentry error events in Kiwi's current Developer plan are retained for up to 30 days. Sentry documents backup retention of 30 or 90 days depending on data type; this is separate from active event storage. Legacy events already sent by older app versions are subject to the applicable retention and deletion process.
What Kiwi Does Not Do
- Kiwi does not sell your personal data.
- Kiwi does not use third-party advertising SDKs or cross-app tracking.
- Kiwi does not offer server-side chat history or memory sync by default.
Data Deletion
You can delete conversations and memories from within the app. Turning off “Share Usage Analytics” in Settings immediately stops new optional funnel collection and clears its local queue and markers. Kiwi's backend deletes this installation's linked funnel events when the withdrawal reaches it; an offline withdrawal is retried at the next authenticated connection. Uninstalling the app removes app-sandbox data on your iPhone. Keychain-based service credentials are managed separately by iOS and may persist across reinstall until they are rotated or replaced. To request deletion of other pseudonymous server-side service records associated with your Kiwi installation, contact [email protected].
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal data, and to object to or withdraw consent for certain processing. Contact [email protected] to exercise these rights. EEA users may also lodge a complaint with a data-protection authority. The competent authority for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Children's Privacy
Kiwi is not directed at children under 13, and we do not knowingly collect personal data from children.
Changes to This Policy
We may update this policy from time to time. When we do, we will update the date at the top of this page.
Contact
If you have questions about this privacy policy, contact us at [email protected].