Privacy Policy
How Kaarma collects, uses and protects your personal data
Last updated: July 8, 2026
This policy explains how Kaarma collects and processes your personal data. It applies to all users of the application; the specific law that applies varies depending on your location (see §2).
1. Who is responsible for your data
| Item | Information |
|---|---|
| Data controller | Kaarma SA, c/o Optimize Conseils Sàrl — Route de Saint-Julien 184, 1228 Plan-les-Ouates (Switzerland) |
| EU representative (Art. 27 GDPR) | EDPO (European Data Protection Office), Avenue Huart Hamoir 71, 1030 Brussels (Belgium) — contact form: https://edpo.com/gdpr-data-request/ |
| Data protection contact point | Sarah Nanzer — sarah@kaarma.ai |
2. Which law applies to you
Kaarma is established in Switzerland. Depending on where you are when you use the application, one or more data protection laws apply. Your rights are equivalent in spirit; the competent authority changes.
| Your situation | Applicable law | Supervisory authority |
|---|---|---|
| Users in Switzerland | Swiss Federal Act on Data Protection (FADP) | FDPIC (Federal Commissioner) |
| Users in the European Union | GDPR | Competent national authority (CNIL, CNPD…) |
| Other territories | Local laws where applicable | Local authority |
3. The data we collect
| Category | Examples | Source |
|---|---|---|
| Account & identity | Identifier, phone number, age declaration (18 or over) collected when accepting the Terms of Use | You |
| Declared preferences | Affinity tags (vibe, format, culture) | You |
| Relationships and circles | Mutual friends, groups, accepted or declined invitations | You / Usage |
| In-app activity | Events joined/created, availability, browsing, interactions | Usage |
| Content and messages | Direct messages (between mutual friends), published content, reports | You / Other users |
| Location | Position (proximity, presence), if you enable it | Device |
| Personalized suggestions | Relevance indicator computed from your activity | Derived |
| Technical data | Device identifiers, notification tokens, access logs | Device |
Kaarma does not access your address book. Sharing an event to another application (for example WhatsApp) is done through your device’s share sheet, without your contacts being transmitted to Kaarma.
4. Why we process your data
Each purpose relies on its own legal basis. We do not bundle several purposes under a single acceptance.
| # | Purpose | Legal basis | Consequence of refusal |
|---|---|---|---|
| F1 | Operating the service (account, basic suggestion feed, connecting friends, service-related notifications) | Performance of the contract | The service cannot operate |
| F2 | Location (proximity, presence confirmation) | Consent | App usable without location |
| F3 | Personalizing your suggestions (behavioral analysis) | Consent | Non-personalized suggestions |
| F4 | Improving and developing our services and models | Consent | Your data is not used for this |
| F5 | Security, moderation and compliance with our legal obligations (review of reports, prevention of abuse and fraud, reports to competent bodies) | Legitimate interest (community safety) and legal obligation | Processing necessary to protect users and the Service (right to object under applicable law) |
5. Location
Location is never enabled by default and relies on your consent. It is used only while the application is open (never in the background) and around events: no collection more than two hours before an event, one session as the event approaches and during it, then it stops when the event ends. You can disable it at any time, both in your phone settings and in Settings › Privacy. Your location is never traded for a reward.
6. Personalization, behavioral analysis and automated decisions
With your consent, Kaarma analyzes your in-app activity to suggest the right opportunities at the right time. Without this consent, the application works with non-personalized suggestions.
Our transparency commitment. We do not produce or store any explicit assessment of your emotional or psychological state. We compute a relevance indicator from your activity, and our architecture stores the actions you take rather than conclusions about you.
Personalization relies on automated analysis of your activity (the events you join, your availability, your browsing) to compute the relevance of the suggestions shown to you. These suggestions do not constitute decisions producing legal or similarly significant effects on you: you remain free to act on them or not. You may object to this analysis or withdraw your consent at any time (§8), without losing access to the Service.
7. Minors
Kaarma is restricted to persons aged 18 and over. Your age (18 or over) is declared when accepting the Terms of Use, and the application is rated 18+ on the app stores. Direct messaging is restricted to mutual friends, and any account reported as belonging to a minor is deleted after verification. Data relating to children benefits from enhanced protection.
8. Your consent and its withdrawal
Where processing relies on your consent (location, personalization, service improvement), that consent is:
- Granular: you accept each use separately; there is no bundled “accept all”.
- Revocable: you can withdraw it at any time in Settings › Privacy, as easily as you gave it.
- Without effect on the past: withdrawal stops the processing going forward; it does not call into question what was lawfully done before.
Withdrawing consent to personalization switches your feed to non-personalized mode; it does not block access to the application. Withdrawal does not erase data already collected: for that, you can exercise your right to erasure by contacting us (see §13 and §16).
9. Retention periods
We keep your data for as long as necessary for the purposes described, according to the following rules:
- As long as your account is active and your consent remains valid.
- After you delete your account: your account can be restored for 30 days in the event of an error or a change of mind; after that period, deletion or anonymization is initiated and completed within approximately 30 days.
- After prolonged inactivity (around 3 years): we notify you, then delete your account.
- Detailed activity data: kept at a fine-grained level for 12 to 24 months, then reduced to aggregated indicators.
These periods apply subject to legal retention obligations (for example in the event of a report, a dispute or accounting obligations).
10. Who we share your data with
We do not sell your data. We use service providers (processors) who act on our instructions; other recipients receive data only in the cases described below:
| Provider | Role | Safeguards |
|---|---|---|
| AWS | Hosting (Paris, EU) | Data processing agreement |
| Google Firebase | First-party analytics (with consent) | Data processing agreement |
| AppsFlyer | Deep linking and install attribution | Data processing agreement |
| Technical & development partners | Platform development and maintenance | Contracts + transfer clauses |
| Organizers | Event publication; aggregated statistics only | Aggregated / anonymized data |
| Authorities and competent bodies | Reports required or justified by law (in particular child protection) | Legal obligation or safeguarding of essential interests |
11. International transfers
Some of our providers are located outside your country, including outside Switzerland and the European Union (in particular in Vietnam for development). Where these countries do not offer a recognized equivalent level of protection, these transfers are governed by appropriate safeguards:
- United States (Google — Firebase, BigQuery, Maps): transfers covered by Google’s certification under the EU-US and Swiss-US Data Privacy Frameworks, supplemented by standard contractual clauses as a fallback safeguard.
- Vietnam: standard contractual clauses (Swiss and/or European version depending on the applicable regime).
- AppsFlyer: processing on our behalf only; transfers governed by the adequacy decision benefiting Israel (EU and Switzerland) and by standard contractual clauses for processing in the United States.
- Reports: where the law requires or justifies it, certain reports (in particular child protection) may be sent to competent bodies located in the United States, on the basis of a legal obligation or the safeguarding of essential interests.
- Technical segregation of access and logging, in order to limit access to only the data that is necessary.
You can obtain a copy of the applicable safeguards by contacting us (§16).
12. Security
We implement appropriate technical and organizational measures to protect your data, including access control and logging and the segregation of environments. However, no transmission over the Internet and no information system can be guaranteed to be absolutely secure; we cannot rule out all risk of unauthorized access.
13. Your rights
Depending on the applicable law, you have the following rights, which you can exercise by contacting us. We respond within one month of receiving your request, extendable by two months for complex requests (in which case we will inform you):
- Access your data and obtain a copy of it.
- Rectify inaccurate data.
- Request the erasure of your data.
- Restrict or object to certain processing.
- Receive your data in a portable format.
- Withdraw your consent at any time.
- Lodge a complaint with the competent supervisory authority (see §2).
Erasure and withdrawal. When you withdraw your consent to personalization or request erasure, we stop the processing concerned and delete the derived indicators relating to you, subject to legal retention obligations.
14. Trackers and SDKs
The application integrates tools provided by third parties:
- Google Firebase (first-party analytics): collection is enabled only after your consent. No advertising identifier is collected (no IDFA, IDFV or AdID); no advertising SDK is used. Google acts as a processor; data may be processed in the United States (see §11).
- AppsFlyer (deep linking and install attribution): opens the right content when you follow an invitation link and measures where installs come from, on our behalf only and with no advertising purpose. AppsFlyer acts as a processor; transfers are subject to safeguards (see §11).
- Google Maps (map display and place search): when a map is displayed, Google collects certain technical data (IP address, device data, interactions with the map) as a separate data controller, in accordance with the Google Privacy Policy (policies.google.com/privacy). Displaying a map does not require enabling your location (see §5).
On iOS, any cross-app tracking would be subject to a separate request (App Tracking Transparency), independent of the consents above.
15. Changes to this policy
We may update this policy. In the event of a significant change, we will inform you before it takes effect. The date of the last update appears at the top of this document.
16. Contact us
For any question or to exercise your rights: sam@kaarma.ai or sarah@kaarma.ai. The contact details of the EU representative (EDPO) are set out in Section 1.