Who we are and when this policy applies
Kulaya is a family organization service operated from New Jersey, United States. This Privacy Policy applies to the Kulaya website, web app, and mobile apps, together called the Service. It explains how we handle personal information when you visit the public website, create or join a family space, connect another service, contact us, or use Kulaya.
This policy does not govern a website or service Kulaya links to but does not control. That service's own terms and privacy policy apply. Feature-specific notices can supplement this policy and control for the information or processing they specifically address.
For information received from Google APIs, including information derived from it, the stricter restrictions in Google Sign-In, Calendar, and Gmail take precedence over any broader use, sharing, retention, or business-transfer language elsewhere in this policy or our supplemental notices. A provider's general terms do not authorize a use that Google's Limited Use requirements prohibit.
The Kulaya privacy notice set
This policy should be read with the notices that apply to your family:
- Children's Privacy Notice
- Consumer Health Data Privacy Policy
- U.S. State Privacy Addendum
- Service Provider and Connected Services List
A just-in-time notice shown when you choose a feature can provide more detail about the information selected for that action. A separate consent must be requested before processing when applicable law requires one; accepting the general policy is not a substitute for that choice.
Information we collect
Depending on the features a family chooses, we collect:
- Account and authentication information. Email address, authentication identifier, password verifier maintained by the authentication provider, session and security information, and basic Google profile information if you choose Google Sign-In. At public email signup, we record the current Terms and Privacy Policy versions, an affirmative 18-or-older declaration, the signup source, and the database time of submission. Before a signed-in adult requests access through a household code, link, or targeted invitation, we require another unchecked affirmation and verify that the account has a current recorded acceptance. If it does not, we record the current versions, an affirmative 18-or-older declaration, the authenticated household-join source, and the database time. We do not duplicate an existing current acceptance. Starting a new family also records a distinct family-creator authority declaration. General acceptance by an adult requesting to join does not establish creator or administrator authority and is not parental, consumer-health, or AI consent. Creating an invitation or an administrator-managed child or teen profile does not create another adult's acceptance.
- Supervised child or teen access information. When an owner or parent administrator creates or reactivates a supervised credential during controlled testing, Kulaya records the authenticated owner or parent actor, the exact family, profile and supervised login involved, the derived child or teen role, the children's-notice version, authorization status, and server-recorded authorization, revocation, and update times. Ages 6–12 additionally require verified parental consent. AI is unavailable to anyone under 18. Earlier versioned AI choices and verification records may remain as historical evidence; they do not enable AI access. Eligible adults make their own separate AI choice.
- Family profiles and access information. Family name, member names, relationships, role, age or date of birth, school and grade, avatar or profile photo, email, phone number, color, dietary preferences, allergies, parent relationships, invitation status, and sharing settings.
- Family organization content. Manually recorded allowance, spending, savings goals, money-learning progress, calendar events, internet calendar subscriptions, activities, school information and grades, tasks, chores, lists, habits, grocery items, meals, recipes, nutrition records, family preferences, notifications, change history, and parenting notes.
- Consumer health and wellness information. Allergies, dietary preferences, vaccines, clinicians, appointments, lab values, height, weight, sex, family health history, nutrition goals, meals, exercise, sleep, device-health summaries, and related inferences. See the Consumer Health Data Privacy Policy.
- Files and communications. Photos, documents, text, voice transcripts, pasted or forwarded email, Calendar or internet calendar content, and support messages you submit.
- Connected-service information. Google account email and identifiers, authorized scopes, Calendar events, Gmail headers, snippets, selected message content, connection and sync state, processing outcome, and audit information needed to connect or disconnect the service.
- AI request information. Prompts, selected files or images, confirmations, AI output, and family context supplied to perform the request.
- Product-interaction information. Limited records showing that an onboarding, invitation, school review, task action, notification, or AI request occurred or succeeded. These events use a controlled set of properties and are not intended to contain free-form family content.
- Technical information. IP address, browser or device type, operating system, app version, request timing, route, error details, cookie or local-storage identifiers, sync state, and security records.
Where information comes from
- you, the person the information concerns, or another authorized family member;
- your browser, device, operating system, or installed Kulaya app;
- Google Sign-In, Calendar, or Gmail when you separately authorize that connection;
- an internet calendar feed or forwarded email address you configure;
- a photo, file, document, voice transcript, or health export you select;
- an AI-generated classification, extraction, estimate, summary, or suggestion; and
- our hosting, authentication, database, security, and support providers.
How we use information
We use personal information to:
- create accounts and family spaces, authenticate users, and apply family roles and access settings;
- save, organize, synchronize, display, and back up the content a family asks Kulaya to manage;
- provide optional Calendar, Gmail, email-extraction, voice, camera, device-health, Health, Nutrition, and AI features when an eligible user chooses to use them;
- personalize views and provide the classifications, suggestions, meal guidance, and other features requested;
- measure whether important product flows work, allocate AI usage, and improve reliability without creating advertising profiles;
- protect accounts, enforce access controls, prevent abuse, troubleshoot errors, and maintain the Service;
- respond to support, privacy, safety, and legal requests; and
- comply with law and enforce our Terms of Use.
Sensitive information, including consumer health information and information about children, is used only for the requested family-facing feature, security, support, legal compliance, and the other purposes specifically described in the applicable notice.
How sharing works inside a family
Kulaya is built around a shared family space. Core roster information can be visible to people who have access to that family, including names, relationships, role, age or grade, contact fields, avatar, dietary preferences, and allergies when those fields have been added. Feature-specific information and actions can have additional role or member restrictions.
The family owner or a parent administrator can invite adults, connect profiles to logins, assign roles, create or reactivate a supervised child or teen credential through the parent-managed flow, and remove access through the normal product controls. A supervised child or teen login is limited to the applicable personal and shared-family views and actions for that role. All AI, including the Learning helper, is unavailable to anyone under 18. Gmail, Google connection, invitation, family-administration, and other adult-only features remain unavailable to that login. An adult's ability to administer the household does not by itself establish legal authority over every other adult's health, school, or private information.
Review the people in the family space and add only information you are authorized to share. If another person adds information about you, contact the family owner or parent administrator or email us for help.
Google Sign-In, Calendar, and Gmail
Google features are optional and separated by purpose:
- Google Sign-In. If enabled and selected, Kulaya receives basic account information Google provides for authentication, such as email address and profile details. Kulaya never receives the Google password.
- Google Calendar. If separately connected, Kulaya requests read-only access to the Google account email and Calendar events. Completing the connection or an import and later eligible manual or app-open syncs import event content under your access settings. Automatic OpenAI classification is currently disabled. Proposals wait in the review queue unless the user approves them. OAuth tokens are encrypted and kept server-side.
- Gmail. If an eligible adult separately connects Gmail, Kulaya uses read-only access for message search and requested event extraction. Search first reads headers and snippets from saved approved senders. With separate email-summary AI permission, Kulaya fetches selected matching bodies for manual analysis or newly arriving matching messages after a separate background opt-in, about every ten minutes. DeepInfra processes that content using DeepSeek V4 Flash for a private summary, importance assessment, action list, and suggested dates requiring review. Approved senders may send school, work, household, or other topics; sender approval is not a school-only filter. Google grants mailbox-wide read capability; Kulaya enforces the approved-sender restriction before processing. Kulaya does not retain the selected body after processing, but can retain the Gmail message identifier, subject, sender, and processing status or outcome to prevent duplicate imports and track the result.
Calendar or Gmail can be disconnected in Settings. Disconnecting removes the connection and encrypted credentials. Imported or approved family events, edited information, and limited connection or security audit records can remain as explained by the confirmation and this policy.
Google Limited Use commitment. Kulaya's use and transfer of information received from Google APIs, including raw data and aggregated, anonymized, or otherwise derived data, adheres to the Google API Services User Data Policy and the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
We use Google user data only to provide or improve the user-facing features you choose, such as connecting your account, importing Calendar events, and summarizing approved email or proposing dates for your review. We do not sell Google user data, use it for advertising, or use or transfer it to create, train, fine-tune, or improve foundational or generalized AI or machine-learning models. This prohibition also covers derived summaries, extracted events, embeddings, and anonymized or aggregated information. Consent to a feature does not authorize prohibited model training. We do not submit Google user data as model-training feedback or evaluation datasets to AI providers.
Transfers are limited to providing or improving these visible features with your consent, security purposes, compliance with applicable law, or a merger, acquisition, or sale of assets after your explicit prior consent, as allowed by Google's Limited Use requirements. Our processors may use Google user data only for these permitted purposes, not their own unrelated purposes or generalized model training. The same restrictions continue to apply to retained copies and derived information. Human access is limited to your affirmative permission to view specific data, security investigations, legal requirements, or aggregated and anonymized data used for internal operations in accordance with Google's policy.
AI processing is inference, not training. With your separate email-summary permission, Kulaya sends the necessary message content to DeepInfra's hosted DeepSeek V4 Flash inference API. This is a hosted third-party service, not a model self-hosted or operated offline by Kulaya. The dedicated email-processing route does not send Gmail messages to OpenAI or fall back to another AI provider. DeepInfra's no-training terms and disclosed retention exceptions are linked in our provider list. Connecting Gmail alone does not send message content to AI; the eligible adult must separately authorize email-summary processing and manual or background analysis. Supervised child and teen logins cannot connect or use Google Calendar or Gmail.
Internet calendars and forwarded email
An authorized user can add an internet calendar feed URL or forward an email to an address configured for Kulaya. For an internet calendar, Kulaya stores the feed URL, label, connection owner, sync status, error details, refresh information, and events retrieved from the feed. The server fetches the URL when the feed is added, when an authorized user requests a refresh, and on eligible authenticated app loads, subject to a minimum refresh interval.
Adding the feed and later eligible manual or app-open syncs retrieve new or changed events. Automatic OpenAI classification is currently disabled. The resulting proposals still wait for review rather than being added to the family calendar automatically.
If an eligible adult configures email forwarding, Kulaya can process the sender, recipient, subject, headers, identifiers, and message text needed to extract proposed calendar items. The same separate email-summary AI permission is required for pasted or forwarded messages, including school, work, household, and other topics you are authorized to share. Relevant subject and text are sent to DeepInfra, not OpenAI; attachments are not analyzed and links are not opened. The result enters a review queue rather than being added automatically. Approved events remain until deleted, and limited security and outcome records can remain as described in this policy.
AI features and automated processing
Kulaya offers two separately authorized AI purposes for eligible adults aged 18 or older. All AI features, including the Learning helper, are unavailable to anyone under 18. Parental approval does not override that restriction. Guest accounts cannot use AI. Non-AI family features retain their separate age and access rules.
Reduced general assistant: OpenAI. GPT-5.6 Terra processes only the adult's current typed or dictated question and its answer. We do not attach earlier chat messages, stored family records, school-email content, files, or images. This mode cannot read or change app data, browse the web, or execute tools. Do not submit children's information, private family details, contact information, or sensitive health information. Local screening reduces accidental disclosure but cannot reliably identify every kind of personal information in free text.
Existing Gemini permissions do not authorize OpenAI processing. Earlier full-assistant permissions do not authorize either new limited purpose. Each requires its own current notice and choice.
OpenAI also performs input and output safety moderation. We send an opaque safety identifier, not a raw email or account ID. API content is not used for model training by default. Kulaya's OpenAI Zero Data Retention request is pending, not approved: standard provider safety retention can apply. Disabling response storage is not ZDR. The full family-data assistant, uploads, and automatic OpenAI calendar classification remain disabled pending their separate privacy and readiness checks. See OpenAI's API data controls.
Email summaries: DeepInfra. With a separate adult permission, DeepInfra processes message text and subjects using DeepSeek V4 Flash to produce private summaries, importance assessments, action lists, and suggested calendar dates. Messages can concern school, work, household, or other topics; an approved sender is not a school-only filter. We do not send the stored family roster or email attachments, follow links, or automatically approve calendar changes. Email content is not sent to OpenAI. Only use this feature for information you are authorized to share, including any child information in an email.
Connecting Gmail alone does not authorize AI processing. You must save approved senders and select matching messages for manual analysis, or separately opt into checks about every ten minutes for newly arriving messages. Pasted or forwarded email also requires the separate email-summary AI permission. There is no automatic historical backfill. Empty checks do not call AI. The current pilot limits attempts and shares the household AI allowance; frequency is not a delivery guarantee or an emergency service.
Kulaya does not retain raw email bodies after processing. Private summaries, message identifiers, subjects, senders, proposed dates, and processing outcomes can remain until deleted. DeepInfra's terms prohibit training on customer content and limit content retention, with support, security, and legal exceptions. Technical prompt caching may apply; Kulaya does not request extended cache retention. It is not a promise that no data is ever retained, or a claim of U.S.-only processing. See DeepInfra's terms and the provider list.
Review or withdraw each permission separately in Settings → AI & family permissions. Background email checks can also be paused in Gmail settings. Withdrawal blocks future requests, but a transmission already sent cannot be recalled. General chat can remain in the current device's local history until cleared; it is not forwarded as conversation context. Permission, usage, and security records are retained as described in this policy. None of these choices authorizes another person's account.
AI is not a person, therapist, emergency service, or professional adviser. Safeguards cannot guarantee every answer is safe or correct. Check original messages and review proposed dates before accepting them. Do not rely on AI output for diagnosis, treatment, or medical, legal, financial, or high-impact decisions. In the U.S., call 911 for immediate danger or call/text 988 for a suicide or mental-health crisis.
Device permissions, photos, voice, and health imports
Kulaya asks for device access when you choose a feature that needs it. Camera and photo access can be used for avatars, meal photos, document extraction, or another selected upload. Microphone and speech access can turn speech into text. The browser, operating system, Apple, Google, or a device speech service can process audio under its own policies.
Raw Apple Health, Garmin, and Samsung Health export files selected for device import are designed to be parsed on the device and are not uploaded as raw export files. Daily summaries the user chooses to save can be stored in the family space and synchronized with Kulaya. Eligible users can also add person-linked Health and Nutrition information, meal logs, profiles, and imports during prelaunch testing. These features are optional; review family visibility and add another person's information only when authorized.
Kulaya does not create or use a faceprint, voiceprint, or other biometric identifier from an ordinary family photo or voice transcript for identification or authentication.
Cookies, local storage, and browser privacy signals
Kulaya uses cookies, local storage, session storage, and comparable native-app storage for sign-in, security, offline operation, synchronization, preferences, and feature state. We do not use them to build an advertising profile or track people across unaffiliated websites for advertising.
A browser “Do Not Track” signal does not change our current practices because Kulaya does not conduct cross-site advertising tracking. Because Kulaya does not currently sell data or process it for targeted advertising, a Global Privacy Control signal does not change the Service's current processing.
Kulaya currently requests Google Fonts automatically when a web page loads. That request gives Google the IP address and browser information needed to deliver the font. Google operates services across other websites and handles that request under its own privacy policy; Kulaya does not authorize Google to use the request for Kulaya advertising. Other than automatic infrastructure delivery and a service a user deliberately connects or invokes, Kulaya does not knowingly permit a third party to collect information through Kulaya over time and across unaffiliated services for advertising.
Retention
Current retention depends on the record and why it exists:
- Account and family content is generally kept while the account or family uses the feature, until an authorized user deletes it, or until the relevant account or family space is deleted.
- Connected-service credentials are kept while the connection remains active and are removed when the connection is successfully disconnected, subject to limited security and audit records.
- Selected Gmail bodies and raw device-health exports are not retained by Kulaya as source files after the transient processing described above. Limited Gmail metadata, including the message identifier, subject, sender, and processing status or outcome, can remain to prevent duplicate imports and track the result.
- Approved or imported events and edited content remain as family content until deleted, even when the source connection is removed.
- Product-interaction, AI-usage, notification, change-history, support, and security records are kept while needed for reliability, abuse prevention, account coordination, dispute handling, or legal compliance. Some records can be retained after a user identifier is removed.
- Backups can remain until the applicable provider restoration or rotation cycle. They are not used for ordinary product operation and are handled under the deletion rules that apply to the information.
The categories above describe current retention behavior, not a promise that every record has an automated expiration date. Product-interaction, change-history, audit, support, security, deletion-tombstone, and backup records may remain longer for the purposes described above. Kulaya must adopt and enforce category-specific child and health retention schedules before public launch where applicable law requires those schedules. Additional information appears in the applicable supplemental notice.
Security and incident notice
We use safeguards designed for the sensitivity of family information, including encrypted network connections, authenticated access, database access controls, private file storage, encrypted Google OAuth tokens, rate limits, and Keychain or Keystore-backed encrypted storage for important native-app data. Provider and personnel access uses authenticated administrative controls. Family-member visibility is described separately above. No system is perfectly secure.
If we discover an incident requiring notice under the FTC Health Breach Notification Rule, a state breach law, or another applicable law, we will notify affected people, regulators, and others in the manner and time required by law.
Your choices and privacy rights
U.S. users may ask Kulaya to confirm processing; access, correct, delete, or obtain a portable copy of eligible personal information; withdraw consent; and appeal a denied request. Applicable law can provide additional rights or exceptions. Kulaya will not discriminate against a person for exercising a privacy right.
Email support@kulaya.app with the subject “Privacy request.” Include the Kulaya account email, state of residence, right requested, and enough detail to locate the information. We verify identity and authority over the relevant person or family space. An authorized agent may submit a request where permitted by law.
We respond within the time required by law. If we deny the request, you may appeal by emailing the same address with the subject “Privacy appeal.” See the U.S. State Privacy Addendum and Consumer Health Data Privacy Policy for details.
Account and data deletion
To request permanent account deletion, sign in, open the Account page (or Settings when available to your role), choose Delete account, and confirm. Treat the deletion as complete only after Kulaya displays a successful confirmation. If the request fails or you cannot sign in, email support@kulaya.app from the account address with the subject “Delete my Kulaya account.”
A successful account deletion removes the authentication account and initiates removal of the user's connected credentials, user-linked records, and avatar files from active Kulaya systems. After the server confirms deletion, the device completing the request attempts to clear Kulaya browser storage and the encrypted native-app mirror. Browser or operating-system caches and data on another device may require separate clearing. Limited product, security, support, legal, deidentified, or backup records can remain as described in the Retention section.
Shared family data needs special care. Deleting a family owner can delete the family space and shared information for everyone. Deleting a person who joined another family removes that login, but can also remove records authored by that account while other family information remains. Content another family member added, copied, or continues to control may remain. Review the confirmation carefully and contact support before deleting if ownership should be transferred or records preserved.
Signing out, disconnecting Google, removing a family member, deleting an account, and making a verified privacy deletion request are different operations. Signing out or disconnecting a service does not delete the account or all information already added to the shared family space.
Children and teens
- Ages 0–5 - young children: parent-managed profiles only. No direct sign-in or AI.
- Ages 6–12 - children: direct sign-in requires verified parental consent. AI is unavailable to this age group, including the Learning helper. A checkbox or pending verification request alone never enables direct sign-in.
- Ages 13–17 - teens: a parent or legal guardian must authorize supervised sign-in. AI is unavailable to this age group, including accounts with earlier parental AI approval or teen assent.
- Ages 18 and older - adults: public signup and adult permissions. Each eligible adult makes their own AI choice for the exact account and family, after age and provider readiness checks.
Age is derived from date of birth, not a user-selected label. Missing or inconsistent minor age information blocks direct access. Permission is checked again when the age band, family, account, or controlling notice changes; it is not silently carried into a new category. An existing supervised account does not automatically become an adult account at 18.
AI permission is separate from permission to use the core app. Children and teens cannot use any AI, including the Learning helper, AI file or voice uploads, AI actions, connected external accounts, or adult health and nutrition AI features. Guest accounts cannot use AI. These restrictions also apply during testing.
Parents can manage profiles without enabling direct access or AI. Providing a child's information does not authorize every family member to use or disclose it. Read the Children's Privacy Notice for verification, data categories, choices, and retention.
Family-entered school information
Kulaya is currently offered directly to families, not by or on behalf of a school. Grades, deadlines, and school information entered or forwarded by a family are family-provided information, not an official school record maintained by Kulaya for the school. A separate school agreement and privacy notice would be required before Kulaya accepts school-provided records as a school service provider.
U.S. processing and policy changes
Kulaya is operated from the United States. Information can be processed in the United States and other locations where providers operate. Those locations can have different data-protection rules.
We can update this policy as Kulaya, providers, or law changes. We will update the date and provide direct or prominent notice when a change is material or law requires it. We will not rely only on continued use when applicable law requires fresh affirmative permission for a materially different use or disclosure.
Contact us
For privacy questions, requests, appeals, or complaints, contact:
KulayaNew Jersey, United States
support@kulaya.app