Karira

Privacy Policy

Last updated: 2026-08-10  ·  Version: 2026-08-10

This Privacy Policy explains how Karira LLC ("we," "us," or "our") collects, uses, discloses, and protects information in connection with the Karira mobile application and any related services (collectively, the "Service"). We are the controller of the personal data described in this Policy.

By downloading, accessing, or using the Service, you acknowledge that you have read and understood this Policy. If you do not agree, please do not use the Service.


1. Who we are

The Service is provided by Karira LLC, a limited liability company organized under the laws of the State of Rhode Island, with its principal place of business at 700 Narragansett Park Dr, Ste 100, Pawtucket, RI 02861. You can contact us at privacy@karira.app for any privacy-related question or request.

The Service is not offered to users in the European Economic Area (EEA), the United Kingdom, or Switzerland. We do not target or make the app available in those territories, and accordingly we have not appointed a representative under Article 27 of the GDPR or the UK GDPR. If you are located in one of those regions, please do not use the Service. Should we offer it there in future, we will update this Policy and appoint a representative before doing so.

2. A note on how Karira works

Karira is a personal meditation and relaxation companion. You have a private, ongoing conversation with an AI companion, and you can turn moments from that conversation into personalized guided audio meditations. Making the Service work requires processing the words you type or speak and the meditations we generate for you. This Policy describes exactly what that involves.

Karira is a wellness product, not a medical or healthcare service. See our Terms of Service for the full disclaimer.

3. Information we collect

We aim to collect only what is needed to provide the Service. Depending on how you use Karira, we process the following categories:

a. Content you provide.

b. App preferences and technical data.

c. Account information. Using Karira requires an account. You sign in with Sign in with Apple or Google, and we receive from that provider a stable account identifier and, unless you choose to hide it, an email address. We never receive or store your Apple or Google password. You may also optionally give a display name during setup, which is used only to address you inside the app.

We do not currently sell subscriptions in the app. If and when we do, purchases will be processed by the Apple App Store, and we will receive a subscription status from Apple — never your card details.

d. Analytics. We use PostHog to understand how the app is used in aggregate — for example, how many people finish setup, or where they stop. Events are a fixed list we chose, not a blanket capture of everything you touch, and they carry no message text, meditation scripts, feedback bodies, names, or email addresses. Analytics events are associated with your account identifier, which means they are linked to you rather than anonymous.

Specifically, in PostHog we disable session replay (screen recording), autocapture of taps, and automatic error capture, because chat messages and meditation scripts appear on screen and do not belong in a third party.

What we do NOT collect. We do not use advertising identifiers; we do not include advertising or social-media SDKs in the app; we do not build advertising profiles; and we do not track you across other apps or websites. We do not show ads.

We do not knowingly collect precise geolocation, contacts, photos, camera data, or health-record data. The app requests only microphone access (for voice features, with your permission) and uses background audio so meditations can keep playing.

4. How we use information

We use the information above to:

We do not use your conversation content or voice recordings to serve you advertising, and we do not use them to train or improve AI models — ours or a vendor's. If that ever changes, we will say so here explicitly and, where required, ask for your consent first.

5. How information is processed and shared

We share information only as described here. We do not sell your personal information, and we do not share it for cross-context behavioral advertising.

a. Service providers / sub-processors. To deliver core functionality, content you provide is transmitted to the following providers, which act on our behalf:

ProviderPurposeWhat is sent
Anthropic, PBC (Claude AI models)Powers the companion's replies, meditation scripts, and in-app reflectionsThe relevant conversation text and context
ElevenLabs Inc.Speech-to-text (transcribing your voice) and text-to-speech (voicing meditations and voice samples)Your voice recordings (for transcription) and the text to be spoken
Supabase, Inc.Hosts our database, file storage, authentication, and server functionsAll stored Service data — your account, conversations, meditations, and settings
PostHog, Inc.Product analytics (see §3d)A fixed list of usage events and your account identifier. No message text, scripts, feedback bodies, names, or email addresses.
Apple Inc. / Google LLCSign-in, when you choose that providerHandled by the provider. We receive an account identifier and, unless you hide it, an email address

These providers process the data to perform their service and are subject to their own terms and privacy commitments. Please review:

b. Hosting. Our backend, database, and file storage run on Supabase, and our meditation-rendering worker runs on managed container hosting. Both are located in the United States. Our analytics provider, PostHog, also processes data in the United States. See Section 9 on international transfers.

c. Legal and safety. We may disclose information if required by law, subpoena, or legal process, or where we believe in good faith it is necessary to protect the rights, property, or safety of our users, the public, or us, or to investigate fraud or security issues.

d. Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.

6. Data retention

We retain your content for as long as needed to provide the Service and for the limited additional period described here. Your conversations and generated meditations are stored so you can return to them; you can delete them from within the app, and doing so removes the associated messages. Voice recordings used for transcription are transient and are not retained by us after processing beyond what is necessary to complete the request.

Our concrete retention periods are:

Data categoryRetention after its trigger
A conversation (and its messages) you deleteheld in a soft-deleted state for 30 days, then permanently deleted
Generated meditations detached from a deleted conversation90 days, then the audio and record are deleted
Failed/incomplete meditation renders7 days
Operational usage/rate-limit records (no message content)7–90 days
Security event logs (metadata only; see §7)180 days (up to 400 days for account-deletion and high-severity records, for security and legal compliance)
A data-export file you request7 days, then deleted
Your account and all associated data, when you delete your accountdeleted immediately on request

Note that deleted data may persist for a short additional window in our encrypted backups before those backups rotate out.

7. Security

We use reasonable administrative, technical, and organizational measures designed to protect information, including encryption in transit (HTTPS/TLS on every network connection) and encryption at rest (our database and file storage are encrypted on disk by our hosting provider, and your login session is stored in your device's secure keychain). We also apply row-level access controls so each user can reach only their own data, least-privilege service credentials, server-side secret management, and monitoring for suspicious activity such as repeated failed sign-ins. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your device secure.

8. Children's privacy

The Service is not directed to children. You must be at least 16 years old (or the age of digital consent in your country, if higher) to use it. We do not knowingly collect personal information from children under that age. If you believe a child has provided us information, contact privacy@karira.app and we will delete it.

9. International data transfers

We and our sub-processors may process information in the United States and other countries whose data-protection laws differ from yours. Where we transfer personal data out of the EEA/UK/Switzerland, we rely on appropriate safeguards such as the Standard Contractual Clauses and equivalent mechanisms.

10. Your rights (EEA / UK — GDPR)

If you are in the EEA or UK, you have the right to access, rectify, erase, restrict or object to processing of your personal data, portability, and to withdraw consent where processing is based on consent. You may also lodge a complaint with your local supervisory authority. You can exercise several of these directly in the app: Settings → Download my data exports your data (access/portability) as a machine-readable file, and the deletion controls in the app let you delete individual conversations, your entire chat history, or your whole account (erasure).

Legal bases we rely on: performance of a contract (to provide features you request), our legitimate interests (to operate, secure, and improve the Service), consent (e.g. microphone access for voice features), and legal obligation where applicable. To exercise your rights, contact privacy@karira.app.

11. Your rights (California — CCPA/CPRA)

If you are a California resident, you have the right to know what personal information we collect and how we use and disclose it, to access and delete it, to correct inaccurate information, and to limit the use of sensitive personal information. We do not "sell" or "share" personal information as those terms are defined under the CCPA/CPRA, and we do not use it for cross-context behavioral advertising. We will not discriminate against you for exercising these rights. To make a request, contact privacy@karira.app from the email address associated with your account, so we can verify the request belongs to you.

12. How the Service is delivered

The Karira app distributed through the App Store is a hosted service: your conversations, generated meditations, and settings are stored on our infrastructure as described in Section 5, and are processed by the providers listed there. There is no configuration of the distributed app in which your data stays only on your own device.

13. Apple App Store disclosures

Where the Service is distributed through the Apple App Store, our "App Privacy" data disclosures on the store listing are intended to be consistent with this Policy. As built, the app is designed not to use tracking or advertising and requests only microphone access and background audio. [Keep your App Store privacy "nutrition label" in sync with this Policy and re-verify before each submission.]

14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, provide additional notice within the Service. Your continued use after an update means you accept the revised Policy.

15. Contact us

Questions or requests about this Policy or your personal data:

Karira LLC 700 Narragansett Park Dr, Ste 100, Pawtucket, RI 02861 privacy@karira.app