Privacy Policy

Last updated: 25 June 2026

KimatAI (“the Service”) is operated by MENTIUS LTD, a company registered in England and Wales (company no. 17122926, registered office: 60 Tottenham Court Road, Area 1/1, Suite 22, Fitzrovia, London, W1T 2EW) (“we”, “us”), which is the data controller for your personal data. This policy explains what personal data we collect when you use kimatai.com, why we collect it, and the choices you have. We keep it deliberately plain-language; if anything is unclear, email us at contact@kimatai.com.

What we collect

  • Account data — your email address and a password (stored and hashed by Google Firebase Authentication; we never see your password).
  • Trip content — the trips you create: itineraries, bookings you record, packing lists, expenses, chat messages with the trip companion, and people you invite or names you add for cost-splitting.
  • Usage counters — how many AI itineraries you have generated, used to enforce plan limits.
  • Payment data — if you subscribe or buy a Trip Pass, payments are handled entirely by Stripe. We store only your Stripe customer reference and subscription/purchase status, never card details.
  • Technical & usage data — like any website, our hosting and privacy-friendly analytics record limited technical data (e.g. IP address, browser/device type, pages viewed) to keep the Service secure, reliable and improving. We use cookieless aggregate analytics — no cross-site tracking.

We do not collect advertising identifiers, run third-party ad trackers, or sell personal data.

Our legal bases (UK GDPR)

  • Performance of a contract — to create your account, store and display your trips, and provide the AI and trip features you ask for.
  • Legitimate interests — to keep the Service secure, prevent abuse, enforce plan limits, and understand aggregate usage so we can improve.
  • Legal obligation — to keep records (e.g. for tax) and respond to lawful requests.
  • Consent — where we ever rely on it (e.g. optional communications), you can withdraw it at any time.

How your data is used

  • To provide the Service: storing and displaying your trips, syncing them across devices, and sharing them with people you invite.
  • AI processing — when you generate an itinerary, ask the companion a question, or use discovery, packing or walking-tour features, the relevant trip details and your message are sent to Google's Gemini API to produce the response. Google processes this data under its Gemini API terms.
  • Weather — day locations (coordinates only) are sent to OpenWeather to show forecasts.
  • Maps — when a map loads, your browser requests map tiles from MapTiler; place names from your itinerary are looked up against Wikipedia/Wikimedia Commons to find destination photos.
  • Email — transactional emails (e.g. account-related messages) are sent via our email provider, Brevo.
  • To enforce plan limits and prevent abuse.

Where it lives & international transfers

Your data is stored in Google Cloud Firestore and the Service is served via Vercel. Our providers act as our processors and may store or process data in data centres outside the UK/EEA (for example in the United States). Where data leaves the UK/EEA, it is protected by appropriate safeguards — such as Standard Contractual Clauses / the UK International Data Transfer Addendum — under each provider's data-processing terms.

Security

We rely on reputable infrastructure providers and apply sensible safeguards: encryption in transit (HTTPS), server-side access controls (your data is never read directly by the browser), short-lived session cookies, and passwords hashed by Firebase. No service can promise perfect security, but we take protecting your data seriously and will notify you and the ICO of any breach as required by law.

Cookies

We use a single first-party session cookie (__session) to keep you signed in. It is essential to the Service and expires after 5 days. Your theme preference is stored locally on your device. Our usage analytics (Vercel) are cookieless, and we set no advertising cookies and do no cross-site tracking.

Sharing

Trips are private to you and anyone you explicitly invite as a member. If you create a share link, anyone with that link can view (not edit) the trip until you regenerate the link. We disclose data to third-party processors only as described above — Google Firebase (authentication & database), Google Gemini (AI), Stripe (payments), Vercel (hosting & cookieless analytics), OpenWeather (forecasts), MapTiler (map tiles), Wikipedia/Wikimedia (destination images) and Brevo (email) — or where required by law. We never sell your personal data.

Retention & deletion

Your data is retained while your account exists. Deleting a trip permanently removes its content, including companion conversations. You can delete your entire account and its data yourself at any time under Account → Delete account; this is immediate and irreversible. You can also email contact@kimatai.com from your registered address and we will complete the deletion within 30 days. Some records may be retained where the law requires (e.g. payment records for tax). Backups are cycled out on a rolling basis.

Your rights

Under UK GDPR you can request access to, correction of, or deletion of your personal data, object to or restrict processing, and request portability. Contact contact@kimatai.com to exercise any of these. You also have the right to complain to the ICO (ico.org.uk).

Children

KimatAI is not directed at children. You must be at least 16 years old to create an account. If you believe a child has provided us personal data, contact us and we will delete it.

Changes

We'll post any changes to this policy on this page and update the date above. Material changes will be flagged in the app.