logo

Privacy Policy

How Kaarma collects, uses and protects your personal data

Last updated: July 8, 2026

This policy explains how Kaarma collects and processes your personal data. It applies to all users of the application; the specific law that applies varies depending on your location (see §2).

1. Who is responsible for your data

ItemInformation
Data controllerKaarma SA, c/o Optimize Conseils Sàrl — Route de Saint-Julien 184, 1228 Plan-les-Ouates (Switzerland)
EU representative (Art. 27 GDPR)EDPO (European Data Protection Office), Avenue Huart Hamoir 71, 1030 Brussels (Belgium) — contact form: https://edpo.com/gdpr-data-request/
Data protection contact pointSarah Nanzer — sarah@kaarma.ai

2. Which law applies to you

Kaarma is established in Switzerland. Depending on where you are when you use the application, one or more data protection laws apply. Your rights are equivalent in spirit; the competent authority changes.

Your situationApplicable lawSupervisory authority
Users in SwitzerlandSwiss Federal Act on Data Protection (FADP)FDPIC (Federal Commissioner)
Users in the European UnionGDPRCompetent national authority (CNIL, CNPD…)
Other territoriesLocal laws where applicableLocal authority

3. The data we collect

CategoryExamplesSource
Account & identityIdentifier, phone number, age declaration (18 or over) collected when accepting the Terms of UseYou
Declared preferencesAffinity tags (vibe, format, culture)You
Relationships and circlesMutual friends, groups, accepted or declined invitationsYou / Usage
In-app activityEvents joined/created, availability, browsing, interactionsUsage
Content and messagesDirect messages (between mutual friends), published content, reportsYou / Other users
LocationPosition (proximity, presence), if you enable itDevice
Personalized suggestionsRelevance indicator computed from your activityDerived
Technical dataDevice identifiers, notification tokens, access logsDevice

Kaarma does not access your address book. Sharing an event to another application (for example WhatsApp) is done through your device’s share sheet, without your contacts being transmitted to Kaarma.

4. Why we process your data

Each purpose relies on its own legal basis. We do not bundle several purposes under a single acceptance.

#PurposeLegal basisConsequence of refusal
F1Operating the service (account, basic suggestion feed, connecting friends, service-related notifications)Performance of the contractThe service cannot operate
F2Location (proximity, presence confirmation)ConsentApp usable without location
F3Personalizing your suggestions (behavioral analysis)ConsentNon-personalized suggestions
F4Improving and developing our services and modelsConsentYour data is not used for this
F5Security, moderation and compliance with our legal obligations (review of reports, prevention of abuse and fraud, reports to competent bodies)Legitimate interest (community safety) and legal obligationProcessing necessary to protect users and the Service (right to object under applicable law)

5. Location

Location is never enabled by default and relies on your consent. It is used only while the application is open (never in the background) and around events: no collection more than two hours before an event, one session as the event approaches and during it, then it stops when the event ends. You can disable it at any time, both in your phone settings and in Settings › Privacy. Your location is never traded for a reward.

6. Personalization, behavioral analysis and automated decisions

With your consent, Kaarma analyzes your in-app activity to suggest the right opportunities at the right time. Without this consent, the application works with non-personalized suggestions.

Our transparency commitment. We do not produce or store any explicit assessment of your emotional or psychological state. We compute a relevance indicator from your activity, and our architecture stores the actions you take rather than conclusions about you.

Personalization relies on automated analysis of your activity (the events you join, your availability, your browsing) to compute the relevance of the suggestions shown to you. These suggestions do not constitute decisions producing legal or similarly significant effects on you: you remain free to act on them or not. You may object to this analysis or withdraw your consent at any time (§8), without losing access to the Service.

7. Minors

Kaarma is restricted to persons aged 18 and over. Your age (18 or over) is declared when accepting the Terms of Use, and the application is rated 18+ on the app stores. Direct messaging is restricted to mutual friends, and any account reported as belonging to a minor is deleted after verification. Data relating to children benefits from enhanced protection.

8. Your consent and its withdrawal

Where processing relies on your consent (location, personalization, service improvement), that consent is:

  • Granular: you accept each use separately; there is no bundled “accept all”.
  • Revocable: you can withdraw it at any time in Settings › Privacy, as easily as you gave it.
  • Without effect on the past: withdrawal stops the processing going forward; it does not call into question what was lawfully done before.

Withdrawing consent to personalization switches your feed to non-personalized mode; it does not block access to the application. Withdrawal does not erase data already collected: for that, you can exercise your right to erasure by contacting us (see §13 and §16).

9. Retention periods

We keep your data for as long as necessary for the purposes described, according to the following rules:

  • As long as your account is active and your consent remains valid.
  • After you delete your account: your account can be restored for 30 days in the event of an error or a change of mind; after that period, deletion or anonymization is initiated and completed within approximately 30 days.
  • After prolonged inactivity (around 3 years): we notify you, then delete your account.
  • Detailed activity data: kept at a fine-grained level for 12 to 24 months, then reduced to aggregated indicators.

These periods apply subject to legal retention obligations (for example in the event of a report, a dispute or accounting obligations).

10. Who we share your data with

We do not sell your data. We use service providers (processors) who act on our instructions; other recipients receive data only in the cases described below:

ProviderRoleSafeguards
AWSHosting (Paris, EU)Data processing agreement
Google FirebaseFirst-party analytics (with consent)Data processing agreement
AppsFlyerDeep linking and install attributionData processing agreement
Technical & development partnersPlatform development and maintenanceContracts + transfer clauses
OrganizersEvent publication; aggregated statistics onlyAggregated / anonymized data
Authorities and competent bodiesReports required or justified by law (in particular child protection)Legal obligation or safeguarding of essential interests

11. International transfers

Some of our providers are located outside your country, including outside Switzerland and the European Union (in particular in Vietnam for development). Where these countries do not offer a recognized equivalent level of protection, these transfers are governed by appropriate safeguards:

  • United States (Google — Firebase, BigQuery, Maps): transfers covered by Google’s certification under the EU-US and Swiss-US Data Privacy Frameworks, supplemented by standard contractual clauses as a fallback safeguard.
  • Vietnam: standard contractual clauses (Swiss and/or European version depending on the applicable regime).
  • AppsFlyer: processing on our behalf only; transfers governed by the adequacy decision benefiting Israel (EU and Switzerland) and by standard contractual clauses for processing in the United States.
  • Reports: where the law requires or justifies it, certain reports (in particular child protection) may be sent to competent bodies located in the United States, on the basis of a legal obligation or the safeguarding of essential interests.
  • Technical segregation of access and logging, in order to limit access to only the data that is necessary.

You can obtain a copy of the applicable safeguards by contacting us (§16).

12. Security

We implement appropriate technical and organizational measures to protect your data, including access control and logging and the segregation of environments. However, no transmission over the Internet and no information system can be guaranteed to be absolutely secure; we cannot rule out all risk of unauthorized access.

13. Your rights

Depending on the applicable law, you have the following rights, which you can exercise by contacting us. We respond within one month of receiving your request, extendable by two months for complex requests (in which case we will inform you):

  • Access your data and obtain a copy of it.
  • Rectify inaccurate data.
  • Request the erasure of your data.
  • Restrict or object to certain processing.
  • Receive your data in a portable format.
  • Withdraw your consent at any time.
  • Lodge a complaint with the competent supervisory authority (see §2).

Erasure and withdrawal. When you withdraw your consent to personalization or request erasure, we stop the processing concerned and delete the derived indicators relating to you, subject to legal retention obligations.

14. Trackers and SDKs

The application integrates tools provided by third parties:

  • Google Firebase (first-party analytics): collection is enabled only after your consent. No advertising identifier is collected (no IDFA, IDFV or AdID); no advertising SDK is used. Google acts as a processor; data may be processed in the United States (see §11).
  • AppsFlyer (deep linking and install attribution): opens the right content when you follow an invitation link and measures where installs come from, on our behalf only and with no advertising purpose. AppsFlyer acts as a processor; transfers are subject to safeguards (see §11).
  • Google Maps (map display and place search): when a map is displayed, Google collects certain technical data (IP address, device data, interactions with the map) as a separate data controller, in accordance with the Google Privacy Policy (policies.google.com/privacy). Displaying a map does not require enabling your location (see §5).

On iOS, any cross-app tracking would be subject to a separate request (App Tracking Transparency), independent of the consents above.

15. Changes to this policy

We may update this policy. In the event of a significant change, we will inform you before it takes effect. The date of the last update appears at the top of this document.

16. Contact us

For any question or to exercise your rights: sam@kaarma.ai or sarah@kaarma.ai. The contact details of the EU representative (EDPO) are set out in Section 1.