Who is responsible
Doppi, Inc. operates Kimari and is responsible for the personal information described here. For access, correction, deletion, consent withdrawal or a privacy concern, email support@kimari.ai. We may need to verify your identity before acting on a request.
Account and profile information
We use your phone number and authentication records to sign you in using SMS verification. We collect your community, name, date of birth, gender, selected Coffee Date areas, occupation, consent records and source photo to provide introductions, arrange meetings in a shared selected area and operate your account. Previously supplied postal codes remain private and may be used to assign an initial date area that you can change. Height, education and whether you have children are optional. Community choices can reveal religious or cultural information; choose and share them deliberately. We do not provide a public member directory.
Conversations, safety and payments
We process your answers to proposals, relationship feedback, concierge and Coffee group messages, reports and blocks to arrange meetings and support safety. We also keep purchase amounts, payment status, transaction references, First Coffee records and operational billing notes. Stripe handles payment credentials; Kimari does not collect full card numbers. Device notification tokens and technical request records support notifications, security and troubleshooting.
AI photo processing
With your explicit permission before upload, we send your selected source photo to fal.ai and its model provider, Google or OpenAI, to generate your Coffee Portrait. The photo and generation instructions are processed to create the illustration. Private means your source photo is not shown to other members; it does not mean that no service provider processes it. You review the result before approving it for your profile.
Who can see your information
Other members receive the approved portrait and relevant profile details in their private introductions. Concierge staff can access profiles, feedback and conversations to operate the service. Your individual responses are not shown as individual answers to the other member; mutual decisions allow the concierge to arrange the next step. Coffee group messages are visible to the group and concierge. Direct concierge conversations and safety reports are not shared as group messages.
Service providers and international processing
Clerk handles authentication; Supabase and Cloudflare support data storage, hosting and delivery; fal.ai and its model providers, Google and OpenAI, process portraits; Stripe handles payments. Apple, Google or your browser's push service delivers notifications when enabled. These providers may process information outside your country, including in the United States, where laws may differ. We may disclose information where legally required or necessary to investigate fraud and protect safety.
Human concierge
A concierge reviews profiles, writes matching memos from your proposal feedback, creates proposals and coordinates Coffee Dates.
Website analytics
We use Google Analytics and PostHog (United States), plus Meta Pixel for public advertising and Web registration measurement, to count page visits, app-store link clicks, completed registration and search activation. On our Canada landing pages, including the homepage, measurement starts automatically unless you previously declined. Other public pages ask you to allow measurement. You can decline or change your public-site measurement choice on this Privacy page without losing access to store links. On Member Web, continuing from the phone-number form permits analytics and advertising measurement as disclosed there; an earlier refusal remains in effect. You can change this choice in Account. After permission, Meta receives a registration-completed event from a fixed measurement document, with browser/ad-click identifiers, but no phone number, profile, photograph or community values. PostHog also receives event names for authentication, profile-save and photo-upload progress and failures, without the entered values or error messages. On Member Web, Google Analytics and Meta Pixel run in a separate measurement document. When measurement is allowed, Google Analytics may share first-party cookies across kimari.ai and app.kimari.ai for journey and advertising attribution. PostHog uses browser and session identifiers for production journeys; sessions expire after 30 minutes without a measured action or 24 hours from their start, and browser identifiers last six months. We disable geographic enrichment, session recording, automatic interaction capture and person profiles. We send only fixed page categories and a small allowlist of advertising attribution values; we never send account IDs, profile fields, messages, arbitrary query strings or recordings. Your browser connects to these processors, which receive network information. Retention follows each analytics project's settings. Contact support about retention or deletion requests.
Mobile app analytics
The production iOS and Android apps use Google Firebase Analytics once the app initializes. It collects an app-instance identifier, launches, sessions, engagement, screen names, device and operating-system information, language and the approximate region Google derives from your network connection. It also receives event names for authentication, profile-save and photo-upload progress and failures, portrait selection, completed registration and search activation, without entered values or error messages. We do not send profile fields, photos, messages or Kimari account IDs to analytics. Firebase advertising storage, advertising user data and personalization are disabled. Firebase also receives confirmed purchase amounts, currency and a hashed order identifier. AppsFlyer measures installs and launches and resolves our app links, including the public community entry code associated with a link. It receives app-install identifiers, device and operating-system information and network information such as IP address. We disable advertising identifiers, Android ID, App Set ID and iOS IDFV collection and iOS AppsFlyer sharing with advertising partners. Android may share install and conversion data with advertising partners enabled in our AppsFlyer configuration. We do not display an iOS tracking permission prompt or enable individual partner sharing on iOS. AppsFlyer also receives completed registration, search activation, confirmed purchases, with amount, currency and a hashed order identifier. We do not send member identifiers, profile fields or community attributes in these conversion events. The app stores pending events locally for up to 30 days to retry failures. Once both SDKs accept an event or that period expires, its payload is erased and a hashed duplicate-prevention receipt remains for up to 365 days. Signing out clears local events and receipts. The native apps do not currently offer an analytics opt-out; their collection is separate from website measurement. Analytics data follows the Google Analytics and AppsFlyer projects' retention settings. Contact support about access or deletion requests.
Retention and deletion
Profile information, photos and conversations remain in use while your account is active so we can provide the service. Stopping search alone does not erase them. Account deletion includes removal of the Clerk identity and stored account images, clearing identifying profile fields and replacing your sent message text with a deletion marker. Related conversations close. Payment, Ticket, deletion and operational records can remain where needed for accounting, disputes, security and legal obligations; deletion does not mean every transaction record is erased. Retention depends on those purposes and applicable requirements. Contact us for details about a particular record or provider. Copies already seen or saved by other participants cannot be recalled.
Your controls
You may correct profile information, stop search, block or report a member, and request account deletion from Profile → Account settings. You can manage notification permission in device settings. Withdraw permission for future AI photo processing by not uploading another photo; contact support@kimari.ai about an existing photo or generated portrait. Withdrawing information needed for introductions may prevent us from providing that part of the service. We will explain any legal reason we cannot complete a data request.
Updates and contact
This notice describes the current service. We will explain material changes to data use and seek additional consent when required. For questions or complaints, contact support@kimari.ai. Kimari is for adults aged 18 and over; contact us if you believe a child's information has been provided.