Privacy Policy
KiriBook, LLC ("KiriBook," "we," "us," or "our") operates the KiriBook household address book application at kiribook.app and the related marketing website (together, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices and rights you have.
By creating an account or using the Service, you agree to the collection and use of information as described in this Policy. If you do not agree, do not use the Service.
1. A note on the two kinds of people in KiriBook
KiriBook is an address book. That means the information in it is about two different groups of people, and your rights differ depending on which group you are in:
- Account holders and users. People who create or are invited into a KiriBook account, log in, and use the app. This Policy describes how we handle your personal information directly.
- Contacts. People whose information an account holder stores in KiriBook (the households, people, addresses, and relationships you keep track of). Contacts are usually not KiriBook users. For contact information, the account holder decides what to store and is responsible for it; KiriBook processes it on the account holder's behalf. See Section 11.
2. Information we collect
2.1 Information you provide when you use the Service
Account and profile data. Your name, email address, and password (stored only as a salted hash, never in plain text). If you enable two-factor authentication, what we store depends on the method you choose:
- Authenticator app. An authentication secret, held encrypted.
- Email codes. A short-lived hash of the code we send you, erased once it is used or expires.
- Passkey. A public key, a credential identifier, a label you choose for the device, and the dates the passkey was added and last used. A passkey's private key is created on your own device and never leaves it, so it is never transmitted to us and we store nothing capable of signing in as you.
Any backup codes you generate are stored only as hashes.
Billing data. If you subscribe to a paid plan, our payment processor (Stripe) collects and processes your payment card and billing details. KiriBook does not store your full card number. We store a Stripe customer identifier, your subscription status, and renewal dates.
Contact and household data you enter. This is the core of the Service. It can include, for the people and households you track:
- Names, display names, and sort names
- Mailing addresses, including address history (we keep prior addresses by marking them no longer current rather than deleting them)
- Phone numbers, email addresses, and social media handles
- Birthdates or birth years, anniversaries, and other important dates
- Relationships between people (family trees, household membership)
- Tags and mailing lists
- Free-text notes
- Events, guest lists, and RSVP responses
Uploaded images. If you use photo import, you can upload a photo of an envelope, label, or card. We send that image to our AI vision provider (Anthropic) to read the address text from it. See Section 4.
Requests and messages. Content you submit through address-update requests, intake forms, referrals, feedback, saved reports, and support communications.
2.2 Information we collect automatically
Usage and product analytics. We use PostHog in the application, and Ghost analytics on the marketing website, to understand how the Service is used (pages and features viewed, actions taken, session and device information, approximate location derived from IP address). This helps us improve the product.
Log and device data. IP address, browser type, device and operating system information, timestamps, and error diagnostics.
Cookies and similar technologies. We and our analytics providers use cookies and similar technologies. See Section 6.
Email delivery data. We send transactional and notification emails through Resend, which records delivery outcomes (whether a message was delivered, bounced, or was reported as spam) so we can operate and troubleshoot email. We do not track whether you open our emails, and we do not use click-tracking links that identify individual recipients. Some links in our emails carry campaign tags (UTM parameters) that tell our product analytics which message a visit came from; those tags identify the message, not you.
2.3 Information from third parties
Contact sync. If you connect a Google or Microsoft account, we access and synchronize contacts between that account and KiriBook, using the permissions you grant. See Section 5.
Address validation. When you enter or import an address, we send it to our address validation and geocoding service (Smarty) to standardize and locate it, and we store the standardized result.
Payment status. Stripe sends us updates about your subscription (for example, successful renewals, failed payments, cancellations).
3. How we use information
We use information to:
- Provide, operate, and maintain the Service (store and display your address book, sync contacts, validate addresses, generate mailing labels and exports, send event invitations).
- Process payments, manage subscriptions, and prevent billing fraud.
- Send transactional and service messages (account verification, password resets, address-update requests, renewal notices, and important-date reminders).
- Read address text from images you upload for import.
- Provide customer support and respond to your requests.
- Understand usage and improve the Service, including product analytics and feature development.
- Secure the Service, detect and prevent abuse, and enforce our Terms of Service.
- Comply with legal obligations and enforce our legal rights.
We do not sell your personal information, and we do not use the contents of your address book to target you with third-party advertising.
4. Uploaded photos and AI address reading
When you upload a photo to import an address, KiriBook sends that image to Anthropic (the provider of the Claude AI models) solely to extract the address text. We use this only to help you enter data faster. Per Anthropic's commercial terms, inputs submitted through its API are not used to train its models. KiriBook does not store the uploaded image. It is held in memory only long enough to extract the address text and to show it to you during review, and it is discarded when you finish. If you would rather not use AI-assisted import, do not use the photo-import feature and enter addresses manually.
5. Contact sync (Google and Microsoft)
If you connect a Google or Microsoft account, KiriBook will, according to the scopes you approve, read contacts from that account into KiriBook and/or write KiriBook contacts back to it. We store encrypted access tokens to perform this sync and a record of which KiriBook records are linked to which external contacts. You can pause or disconnect sync at any time in Settings, which stops future syncing and clears the stored tokens. Disconnecting does not delete data already synced in either direction. KiriBook's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
6. Cookies and tracking technologies
We use cookies and similar technologies for:
- Essential functions (keeping you logged in, security, remembering preferences). These are required for the Service to work.
- Analytics (PostHog in the app; Ghost on the marketing site) to measure and improve usage.
You can control cookies through your browser settings. Blocking essential cookies will break core functionality. Where required by law, we will present a cookie or consent notice and honor your choices, including Global Privacy Control (GPC) signals.
7. How we share information
We share information only as described here. We do not sell personal information.
Service providers (subprocessors). We share information with vendors that operate parts of the Service under contract and on our instructions:
| Provider | Purpose |
|---|---|
| Hetzner Online (Germany) | Hosting and infrastructure |
| Stripe | Payment processing |
| Resend | Email delivery (delivery outcomes only) |
| Anthropic | AI reading of uploaded address images |
| Smarty | Address validation and geocoding |
| Google; Microsoft | Contact synchronization (only if you connect them) |
| Google Fonts | Web font delivery |
| PostHog; Ghost | Product and website analytics |
Legal and safety. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of KiriBook, our users, or others.
Business transfers. If KiriBook is involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction. We will notify you of any change in ownership or use of your personal information.
With your direction. When you export data, send an invitation, share an event, or connect an integration, information is shared as you direct.
8. Data retention
We keep your information for as long as your account is active and as needed to provide the Service. Specific retention periods:
- Address history is retained by design: when an address changes, the prior address is marked no longer current rather than deleted, so you keep an accurate historical record. It persists for the life of your account.
- Account and contact data are kept while your account is active. When you delete your account, the deletion is held for a 14-day grace period during which you can cancel it; after that, we remove your personal information and your stored contact data from our live systems, and from backups within 90 days as they are overwritten.
- Activity and audit logs are retained for 2 years, then automatically purged.
- Imported file data (the reviewable contents of files you import) is purged 90 days after the import is completed or cancelled.
- Server and application logs are retained for approximately 30 days.
- Product analytics are retained according to our analytics providers' default retention periods.
We may retain limited records longer where we must do so to comply with legal, tax, accounting, or dispute-resolution obligations.
9. How we protect information
We use technical and organizational safeguards including encryption in transit (HTTPS), encryption at rest for our database and backups, hashed passwords, optional two-factor authentication (including passkeys, where the private key stays on your device and we store only the public half, so our servers hold no shared secret that could be used to sign in as you), strict account isolation (every user's data is scoped to their own account), role-based access controls, and audit logging of sensitive actions. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your password confidential.
If we experience a breach of security compromising your personal information, we will notify affected individuals and any required regulators as required by applicable law, including South Dakota's data breach notification law (SDCL 22-40-19 to 22-40-26).
10. Your rights and choices
All users can, within the app:
- Access and export your data (CSV and other export formats).
- Correct any information by editing it directly.
- Delete individual records. Deleting the entire account is available to account administrators, or to any user by request as described below.
- Enable two-factor authentication for stronger account security, using a passkey (Face ID, Touch ID, Windows Hello, or a security key), an authenticator app, or emailed codes.
- Control integrations, pausing or disconnecting contact sync at any time.
- Manage email preferences for non-essential notifications.
To request deletion of your account and associated data, or to exercise any right described in this Policy, use the in-app controls or contact us at support@kiribook.app. We will verify your identity before acting on a request. We will respond within 45 days, and will let you know if we need additional time as permitted by law.
11. Information about other people that you add
Most information in KiriBook is about your contacts, who are typically not KiriBook users. When you add and manage this information:
- You are responsible for having a lawful basis and any necessary permission to store and use other people's information in KiriBook, and for using it only for legitimate personal or organizational purposes consistent with our Terms of Service.
- We act on your behalf. For the contact information you store, KiriBook acts as a processor/service provider handling that data on your instructions. You control what is collected, corrected, and deleted.
- Data subject requests. If one of your contacts asks KiriBook to access, correct, or delete their information, we will generally direct that request to you as the account holder, or work with you to fulfill it, because you control that data.
- Self-service updates. KiriBook offers address-update and intake features that let you send a secure link to a contact so they can review or submit their own current information. Information a contact submits this way is added to your account under your control.
- Sensitive details. Some information you may record about a contact (for example, health information, religious affiliation, or other sensitive facts in free-text notes) is treated as sensitive personal information under some privacy laws. You are responsible for having any consent or lawful basis those laws require before storing such details.
- Emails we send to your contacts. When you use address-update requests, invitations, or event messages, KiriBook sends emails to your contacts on your behalf. Our email provider (Resend) records delivery outcomes for those messages (delivered, bounced, or reported as spam), as described in Section 2.2, so we can operate and troubleshoot these features. We do not track whether your contacts open those emails.
- Analytics on the pages we show your contacts. The address-update and intake pages we host for your contacts use our product analytics provider (PostHog), as described in Section 2.2. This records that a page was viewed and that a submission was made, together with device information and approximate location derived from IP address. It does not record the contents of what your contact submits.
12. Children's privacy
The Service is intended for adults. As stated in our Terms of Service, you must be at least 18 years old to create an account. The Service is not directed to children under 13, and we do not knowingly allow children under 13 to create accounts. If you believe a child under 13 has created an account, contact us and we will delete it. You may store contact information about minors (for example, children in a household you track) as the account holder responsible for that data; do so only in a manner consistent with applicable law and any necessary parental permission.
13. Where your data is stored and international transfers
The Service is intended for residents of the United States. We do not offer or market the Service to individuals in the European Union or the United Kingdom.
KiriBook is operated from the United States. Our primary production data is hosted in the European Union (Hetzner, Germany), and some of our service providers process information in the United States or other countries. This means your information moves between the United States and the European Union, and among our service providers, as needed to operate the Service. Wherever data is processed, we require appropriate contractual and technical protections. By using the Service, you consent to this storage, transfer, and processing of your information as described in this Policy.
14. U.S. state privacy rights
Depending on your state of residence (for example, California under the CCPA/CPRA, and similar laws in states such as Colorado, Connecticut, Virginia, and others), you may have the right to:
- Know and access the personal information we collect about you.
- Request correction of inaccurate personal information.
- Request deletion of your personal information.
- Obtain a portable copy of your information.
- Opt out of any "sale" or "sharing" of personal information and of targeted advertising.
We do not sell personal information and do not share it for cross-context behavioral advertising. We do not discriminate against you for exercising these rights. To exercise a right, contact us at support@kiribook.app. You may use an authorized agent where the law permits, and you may appeal a decision by replying to our response. We honor Global Privacy Control (GPC) browser signals where required.
Categories of personal information we collect map to the sections above: identifiers (name, email), account credentials, commercial/billing information, internet and usage activity, approximate geolocation, and the contact and relationship information you enter. We collect these for the purposes described in Section 3.
15. Do Not Track
Some browsers offer a "Do Not Track" signal. There is no common industry standard for responding to it, so we do not respond to Do Not Track signals, but we do honor Global Privacy Control where legally required.
16. Third-party links
The Service may link to third-party websites or services (for example, a connected Google account or an external map). We are not responsible for their privacy practices. Review their policies separately.
17. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or through the Service and update the "Last updated" date above. Your continued use of the Service after changes take effect means you accept the revised Policy.
18. Contact us
KiriBook, LLC 7401 S Bitterroot Pl, Sioux Falls, SD 57108 Email: support@kiribook.app Phone: (605) 368-1723