Pinchly Privacy Policy
Effective date: 2026-08-09
Last updated: 2026-08-02
Version: 3.2 — CEO-approved launch data-use boundary under D195/D196. PUBLISHED at the canonical URL on 2026-08-09 (CEO authorization, D224).
Canonical URL: https://pinchly.app/privacy
Publisher: KuhlApps, LLC (“Pinchly,” “we,” “us,” “our”)
Summary
- Pinchly is a private memory utility. We collect the account information, people, preferences, notes, and settings you choose to save so the app can remember and retrieve them for you.
- Typed or dictated text may be processed by business/API artificial-intelligence providers to structure a Pinch or answer your search. Pinchly does not record or store audio; your device's dictation service supplies text.
- At launch, we do not combine private preference content across users to build commercial patterns, demographic preference reports, buyer-facing outputs, or cross-user personalized suggestions.
- Product analytics is limited to consented structural events and excludes names, notes, preference or item text, contact data, precise location, and raw voice.
- We do not sell personal information, share it for cross-context behavioral advertising, use advertising SDKs, or use Apple's advertising identifier.
- “You Added” entries stay private to their creator unless that creator explicitly shares through an available visibility control. Official content and private content never overwrite one another.
Questions or privacy requests: support@kuhlapps.com. Never send a password, one-time code, full payment-card number, or more private Pinch content than is needed to explain a request.
1. Scope and controller
This policy applies to the Pinchly mobile application and Pinchly websites that link to it. KuhlApps, LLC determines why and how personal data is processed and is the controller or business for applicable privacy law. A formal-notice address and current sub-processor list are available through the contact address above.
2. Eligibility and children
You must be at least 16 years old to create an account. We do not knowingly permit accounts for anyone under 16. If we learn that an under-16 account exists, we suspend and delete it through the verified deletion process, subject only to records lawfully required to be kept.
An adult may privately record a memory about another person, including a family member. That does not create an account for the other person. Do not record sensitive information about a child or other third party that you do not have a lawful reason to keep. At launch, private preference content is not used for cross-user or commercial preference analysis.
3. Data we collect and why
3.1 Information you provide
| Data | Why we process it |
|---|---|
| Email address and authentication records | Create and secure your account and deliver sign-in links or account notices |
| Self-attested birth information | Confirm the 16+ rule; an exact birth year is discarded after the age check, while a coarse age band may be retained for age-safety and feature eligibility but is not used for cross-user/commercial preference analysis at launch |
| Display name and profile settings | Present your account and apply your choices |
| People, connections, Circles, Pinches, preference options, notes, reminders, and visibility choices | Provide the private-memory, retrieval, reminder, and user-directed sharing service |
| Optional birthday month and day | Provide birthday visibility/reminders only when you turn that feature on; the year is not stored for this feature |
| Support messages and attachments | Investigate and answer your request |
“You Added” content is private to the account that created it unless the creator explicitly chooses an available sharing scope. Another person's Official content remains controlled by that person. Linking an offline person to an Official Profile is viewer-local and does not merge ownership.
3.2 Information generated when you use Pinchly
| Data | Why we process it |
|---|---|
| Consent records, plan tier, limits, and subscription status | Apply the versioned choices and product access that govern your account |
| A content-free first-successful-retrieval timestamp and coarse account-age/Pinch-count buckets | Decide when the App Store introductory offer may be presented and measure the D221 funnel without storing the question, answer, person, Pinch, or place |
| Structural product events, only when analytics consent is valid | Understand whether screens and workflows work; event payloads exclude names, notes, preference/item text, contact data, precise location, and raw voice |
| Crash/error records and device/app metadata | Diagnose reliability and security problems; private content must be scrubbed before transfer |
| Standard security logs such as IP address, time, route, and status | Operate, protect, rate-limit, and investigate abuse of the service |
| Push token and delivery state, when notifications are enabled | Deliver content-minimized transactional notifications |
| App Store transaction and entitlement records | Confirm paid access, restore purchases, and keep required financial records |
3.3 AI-assisted capture and retrieval
When you ask Pinchly to structure or retrieve a memory, the minimum text needed for that request may be sent to a contracted business/API provider. Pinchly does not send audio, your password, or a one-time authentication code. We configure and contract for business processing rather than consumer-model training; the current provider, purpose, transfer mechanism, and exact retention term are maintained in our sub-processor record.
Pinchly stores the structured Pinch you choose to save and the data needed to retrieve it. It does not intentionally keep a separate raw AI request transcript beyond operational logs or a short failure/recovery record needed to complete or diagnose the request. Publication of this promise remains blocked until executed provider terms and configured retention evidence match it.
3.4 Voice, contacts, places, and location
- Voice is optional. Your device turns speech into text; Pinchly does not record, receive, or store audio. Typing provides the same capture and retrieval paths.
- Contacts are optional. The app reads contact names on your device to show a picker. It does not upload your address book, phone numbers, or contact emails. Only a person you choose is saved.
- Place search is optional. Search text is sent to a place provider. If you separately allow location bias while actively searching, an approximate foreground location may be sent for that search. Pinchly does not store device location or use background location. Public place details may be cached without recording who searched for the place.
- Birthday visibility is optional and off by default. When on, month and day—not year—may be shown to accepted connections. Turning it off removes the stored birthday month/day used by that feature.
4. Launch data-use boundary
At launch, Pinchly uses preference content only to provide, secure, support, structure, and retrieve the service requested by the user. It does not use private preference content to create:
- cross-user preference patterns or demographic preference slices;
- external trend reports or buyer-facing outputs;
- advertising, targeted-advertising, or data-broker products;
- cross-user personalized suggestions; or
- commercial models trained on users' Pinches, notes, contacts, or people.
A future proposal to do any of these things requires a new policy and Terms version, a separate prospective opt-in that is not bundled with ordinary service acceptance, a new CEO decision, and the D195 identity, sensitive-data, minor, output, withdrawal, testing, and platform gates. Until those conditions pass, the processing remains disabled.
5. Data we do not collect or use
- We do not sell personal information or share it for cross-context behavioral advertising.
- We do not use advertising or attribution SDKs and do not request Apple's advertising identifier or App Tracking Transparency permission.
- We do not record or store voice audio.
- We do not upload your address book.
- We do not store background or precise device-location history.
- We do not collect payment-card credentials; Apple handles App Store payments.
- We do not intentionally use private content to make decisions that produce legal or similarly significant effects about a person.
- We do not intentionally ask users to store government identifiers, account credentials, payment data, health records, or other highly sensitive data in notes.
6. Legal bases for EEA/UK processing
| Purpose | Legal basis |
|---|---|
| Account, private-memory, retrieval, sharing chosen by the user, subscription access, and requested support | Contract — GDPR/UK GDPR Article 6(1)(b) |
| Security, fraud/abuse prevention, content-free reliability measurement, and required records | Legitimate interests — Article 6(1)(f), balanced against user rights |
| Optional location bias, optional birthday visibility, optional analytics, and future marketing | Consent — Article 6(1)(a), withdrawable at any time |
| Tax, accounting, lawful process, and regulatory duties | Legal obligation — Article 6(1)(c) |
The launch legal bases do not authorize cross-user or commercial preference processing. We do not intentionally infer or analyze special-category data from private content. Do not place health, religion, politics, sexuality, biometric data, credentials, or other sensitive information in free-text notes.
7. Service providers and disclosures
We use providers only for the contracted functions needed to operate Pinchly. The categories may include:
| Provider category | Data involved |
|---|---|
| Hosting, database, authentication, storage, and transactional email | Account and service data needed to operate Pinchly |
| Business/API AI processing | Minimum capture or retrieval text needed for the request |
| Place search | Search text and optional approximate foreground location bias |
| Product analytics | Consented structural events without private content |
| Crash/error monitoring | Scrubbed technical diagnostics |
| Subscription management and Apple | Store identifiers, receipts, plan, and entitlement state |
| Build and push infrastructure | Build inputs, device push token, and content-minimized delivery payloads |
Before a provider processes launch user data, its current terms, privacy role, purpose, data categories, retention, deletion path, security/transfer mechanism, and training posture must match this policy and be filed in the processing register. We may disclose data when lawfully required or to address an imminent safety/security threat, and we notify affected users where law permits.
8. International transfers
Pinchly is operated from the United States and may use providers in the United States or other countries. Where required, transfers from the EEA, UK, or Switzerland rely on an adequacy mechanism, Standard Contractual Clauses, UK addendum, or another lawful transfer method plus appropriate safeguards. Current transfer details are available on request.
9. Retention and deletion
| Data | Retention rule |
|---|---|
| Account, people, Pinches, notes, Circles, reminders, and settings | Until deleted by the user or the account is deleted, subject to recoverable/archive behavior shown in the product |
| Exact birth year | Used for the age check and then discarded |
| Coarse age band | Until account deletion or an earlier approved deletion path; not used for launch cross-user/commercial preference analysis |
| Optional birthday month/day | Until the setting is turned off or the account is deleted |
| Consent ledger | As needed to prove which version and choice governed processing, subject to legal retention |
| Security logs | Normally 30 days unless needed for a documented incident, abuse investigation, or legal obligation |
| Crash reports | Normally 90 days |
| Product analytics | Normally 13 months, rolling, when consented |
| AI request content | No separate Pinchly transcript is intentionally retained beyond the request and short operational failure/recovery needs; provider retention follows the filed contracted term |
| Place search | No user-linked query history; a short cache may be used to return results |
| Content-free AI and Places cost/operations records | AI account/entry linkage is removed at verified account deletion or within 90 days. AI and Places per-call detail is then reduced to anonymous daily totals and deleted; those daily totals are kept for no more than 13 months from the source day. These records never contain prompts, answers, voice, preference text, names, place queries or identity, precise location, or contact data. |
| Subscription/financial records | Subscription duration plus the period required for accounting, tax, disputes, and law |
| Support cases | Only as long as needed for the request, security, legal deadlines, and defensible records, with unnecessary attachments removed |
A verified account-deletion request is targeted for completion within 30 days unless a shorter law applies. We delete or de-identify account data and send required processor requests. A narrow record may be retained when law requires it, to prevent fraud/abuse, or to prove completion; it is isolated and not used for product or marketing purposes. D195 authorizes no launch cross-user preference aggregate that survives deletion.
10. Your choices and rights
Subject to applicable law, users may request access, correction, export, deletion, restriction, objection, or withdrawal of consent and may complain to a privacy regulator. California and other US-state residents may also exercise applicable rights concerning sale, sharing, targeted advertising, and profiling. Pinchly does not sell personal information, share it for cross-context behavioral advertising, or operate the D195-disabled commercial preference layer at launch.
Use in-app controls where available or email support@kuhlapps.com. We verify identity before disclosing, changing, exporting, or deleting account data. We do not ask for a password or one-time code and do not discriminate against a person for exercising a privacy right.
11. Security
Pinchly uses encrypted network connections, managed encryption at rest, server-enforced database access rules, least-privilege service access, content-minimized analytics and notification payloads, and incident/deletion procedures. No security program eliminates all risk. Report a suspected vulnerability to support@kuhlapps.com without including unnecessary personal data or exploit details in an ordinary message.
If a personal-data breach is likely to risk individuals' rights, we notify affected people and regulators as required by applicable law.
12. Cookies and identifiers
The mobile app does not use browser cookies. It uses limited identifiers for authentication, consent, analytics when allowed, diagnostics, subscriptions, push delivery, and place-search sessions. Pinchly does not use those identifiers for third-party advertising or cross-context behavioral tracking.
13. Changes and prior versions
We version this policy. Before a material change takes effect, we provide notice and request new consent where law or the changed purpose requires it. A future cross-user or commercial preference use requires a new version and prospective opt-in under D195; continued ordinary app use alone is not consent to that different purpose.
Approved prior versions and their effective periods are archived through versioned publication records.
14. Contact
KuhlApps, LLC
Email: support@kuhlapps.com
Use this address for general privacy questions, rights requests, a current sub-processor list, transfer safeguards, or the formal-notice address. The publication pipeline must not claim a monitored response time until receipt, reply, backup-owner, and escalation evidence is filed.
Version 3.2 was approved in content direction by the CEO on 2026-08-02 under D195/D196 and amended on 2026-08-07 under D221 to disclose the content-free post-value offer milestone. It is not effective or public merely because this source exists; publication, provider-contract, consent-version, support, and live-alias gates remain binding.