Privacy
What we know about you.
KalaBond holds your address book, which is about as personal as software gets. This page says exactly what we collect, where it sits, who else touches it, and what we will never do with it.
Last updated 16 September 2026
Who we are
KalaBond is made by Kala-X Technology Pty Ltd, a company based in Perth, Western Australia. In this policy "we", "us" and "our" mean that company. It is the entity responsible for — in GDPR terms, the controller of — the personal information described here.
For anything about privacy, write to support@kalabond.com.
What this covers
This policy covers the KalaBond website at kalabond.com, the KalaBond mobile apps for iOS and Android, the KalaBond web app, and the shared voting links people open in a browser without an account. It does not cover other Kala-X products, or anywhere else a link might take you.
What the website collects
The marketing pages you're reading now collect nothing on their own. There are no analytics, no advertising trackers and no cookies. Two forms collect something, and only when you choose to fill one in:
- The waitlist — your email address, plus which form you used and which page you were on. Only so we can tell you once when KalaBond opens up.
- The contact form — your name, email, the topic you picked and your message. Only so we can reply. The message is emailed to our support mailbox and a copy is kept in our database.
Our host, Vercel, keeps standard server logs (IP address, browser type, the page requested) for its own security and operational purposes, as essentially every web host does.
One thing worth naming: these pages load two typefaces, Playfair Display and Manrope, from Google Fonts. That means your browser makes a request to Google when a page loads, and Google sees your IP address as a result. We don't send them anything else, and nothing you type on this site goes anywhere near them.
What the app collects
What you give us
To have an account, we need:
- Your email address and a password, held by our authentication provider (the password is hashed — we never see it).
- Your name, if you set one.
To do what the app is for, we store what you put into it:
- People you're keeping in touch with — name, nickname, phone number, birthday, the groups you've put them in, how often you want to be in touch, a preferred language for messages to them, whether you've muted or archived them, and the dates you've marked as caught up. Whether you typed a person in or picked them from your phone's contacts, these are the only fields we hold.
- Plans — the title, description, address or place, links and bring-list you've added, the names of the people you invited, the times and venues you proposed, and everyone's votes, RSVPs and comments.
- Your preferences — your default catch-up rhythm, default language, and a short writing sample if you've given one to steer the tone of drafted messages.
- An area for venue suggestions — a city, postcode, country and search radius, if you type them into Settings. Typed by you, never read from your phone's location.
- What you write to us — if you contact support, your message and the address you sent it from.
What the app records as it runs
- Account identifiers — an internal account id, and a separate opaque billing identifier. The billing identifier can be created as soon as you're signed in — you don't have to open the subscription screen — and on iOS and Android it is the name our subscription provider knows you by (see Subscriptions and purchases). Neither is your email address.
- AI usage — for each drafted message or venue search: which feature, when, and the amount of text processed. This is how the monthly allowance and the daily limit are counted. It is not the content of the message.
- Subscription state — whether you have KalaBond Plus and until when. Detail in Subscriptions and purchases.
- Update checks — the app asks our update service, Expo, whether there is newer app code to download. That request carries which platform it is on, which version of the app it is running and which release channel it is on, plus a random identifier generated for that installation of the app so the service can tell requests apart. Like any request over the internet, it also exposes your IP address to the service. The installation identifier is not an advertising identifier; we don't link it to your account, and it isn't used to track you.
- Ordinary server logs — the providers that run our database and functions keep standard request logs (IP address, time, request) for security and operations, as any server does.
If you send us feedback
There is a “Send feedback” option in Settings, and a “Report” link on the banner that appears when something fails to save. Both are entirely up to you — nothing is sent unless you write something and press send. When you do, we store:
- What you chose from the list (stuck, broken, an improvement, a question, or anything else) and what you typed.
-
Which kind of screen you were on, not which record.
We store
/contact/[id], never the id itself — so we know you were looking at a contact card, and not whose. The same for the last few screens before it. - Your app version, your platform and operating system version, whether you're on the free plan or KalaBond Plus, and how many contacts, groups and plans you have — the numbers, never the contents.
- If a save or load had just failed, the database's short error code — five characters such as
42501. Never the error message, which can name tables and values.
No screenshot is taken, ever. A picture of a KalaBond screen would contain other people's names and phone numbers, and those people did not choose to send us anything. What we collect instead is the shape of the situation, which is enough to find most faults.
The reminder switch, the calendar events the app has added, and whether you're recognised on a voting link you've opened before are stored on your device only. There is no analytics or crash-reporting software in the app, and no advertising identifier is read — the feedback above is the only diagnostic information we ever receive, and only when you choose to send it.
The people in your address book
This is the part most privacy policies skate over, so we'll be direct: when you add someone to KalaBond, you are giving us information about a person who has not agreed to anything. We take that seriously and it shapes what we do with it.
Their details are used only to make your app work for you. We do not build a profile of them, do not use their details to market anything to them, do not try to work out whether they're also a KalaBond user, and do not combine what you tell us about someone with what anyone else tells us about them. A contact you add is a private note in your account, not an entry in a directory.
If someone asks us to remove their details, we'll help — see your rights below. In practice their information sits inside your account, so this usually means asking you to delete the contact; we'll tell them that plainly, and act ourselves where we're required to.
If someone sent you a voting link
You don't need an account to vote on a KalaBond plan, and we don't create one for you. When you open a share link we collect only:
- The name you type in, so the organiser knows whose vote is whose.
- Your votes, your RSVP, any comment you add, and any bring-list item you claim.
That's it. No email, no phone number, no account, no password. Your browser stores a small identifier so you're recognised if you come back to the same link and don't have to re-enter your name — that stays on your device.
What you submit is visible to the organiser and to other people invited to that plan. It isn't used for anything else.
The AI features
KalaBond can draft a message for you, and can suggest places to meet. Both are optional, and both work by sending a small amount of context to Anthropic, which runs the model that writes the text. We think you should know exactly what goes, so this list is taken from the code that sends it:
- For a drafted message — whether it's for a plan or a one-to-one nudge; the first name or nickname of the person it's for, or the first names or nicknames of everyone invited to the plan (including a name a guest typed in themselves); the plan title, and, once a plan is locked in, its time and the name of the venue; for a nudge, whether it's been a while since you caught up; the language you've chosen; the kind of message you asked for (a check-in, a birthday wish, and so on); anything you typed for it to include; and your writing-tone sample if you've set one.
- For place suggestions — the plan title, roughly how many people are coming, the time of day, the city, postcode and country you typed in, the search radius you set, and your language.
What is not sent: your contact list, anyone's phone number, email address or birthday, your check-in history, your other plans, and your account details. Each request is separate and is answered by a general-purpose model. We don't train a model of our own on anything you write, and we keep a record of the request having happened (see AI usage), not of what was written. Anthropic processes the request under its own commercial terms and privacy policy, which we don't restate here.
Both features produce a draft you have to read and approve. KalaBond never sends a message on your behalf.
Subscriptions and purchases
KalaBond Plus is a subscription bought through the Apple App Store or Google Play. The store takes the payment.
- Apple or Google handle your payment details. Your card or payment method is held by them under their own terms. KalaBond never receives it — not the number, not the billing address.
- RevenueCat processes the subscription for us. It is the service that talks to both stores on our behalf, and it tells us when a subscription starts, renews, lapses, is refunded or is restored on a new phone. RevenueCat knows you as an opaque billing identifier we generate — we don't give it your email address or your name — along with the product you bought, the store, the dates, and the store's own purchase records, including the price and currency in the store's currency. Because its software runs inside the app on iOS and Android, it also receives the technical information any such service needs in order to work: things like the app version, the device's platform and operating system, and your IP address. We do not use RevenueCat for advertising, or to track you across other apps.
- What we keep is the minimum needed to give you what you paid for and to handle the subscription's lifecycle: your billing identifier, whether Plus is active and until when, which product and store it came through, and a log of the events the store sent us about it, with the store's purchase details as they arrived.
Some of this survives deleting your account, and the subscription itself is not cancelled by deleting it — both are explained in how long we keep things.
Permissions on your phone
Every one of these is optional and asked for only when you use the feature it belongs to:
- Contacts — read only, and only when you choose to import. The app reads the names and phone numbers in your address book so it can show you a list to pick from; that list is built on your phone and never uploaded. Only the people you tick are saved to your account, and for each of them only the name and number. On iOS you can share a selection of contacts rather than the whole book, and the app works with that. We never write to your address book or change it.
- Calendar — used to add an event once you've locked in a plan, and to remove one it added if the plan is cancelled. To know where to put the event it reads the list of calendars on your device — their names, not their contents. It does not read your appointments, and nothing from your calendar is sent to us.
- Notifications — to remind you about check-ins and birthdays. These are local reminders: the app schedules them on your phone, from the contacts already on it. They don't pass through our servers or through a push-notification service, and we don't hold a push token for your device.
KalaBond does not use your location. There is no GPS access, no background location, and no location permission in the app at all. Place suggestions work from a city, postcode, country and radius you type in yourself.
KalaBond asks for access to Contacts, Calendar and Notifications when those features need it. It never writes to your address book — a write contacts permission that was never exercised has been removed.
Where your data is stored
Your account and everything in it is held in a PostgreSQL database run by Supabase on Amazon Web Services infrastructure in the ap-southeast-2 region — Sydney, Australia. Waitlist and contact form submissions from this website go to the same database.
That was a deliberate choice: the database originally sat in Tokyo, and it was moved to Sydney before the product took on any real users, both to keep data closer to the people it belongs to and because it's meaningfully faster from here.
Sending data overseas
We're an Australian company storing data in Australia. If you're in Australia, your information generally stays here — with the exception of the specific things sent to the providers below, some of which operate in the United States: the context for an AI request, subscription records, and email.
If you're in the UK or the EEA, using KalaBond means your information is transferred to Australia, and to the other providers listed in who else touches it. Australia is not covered by a UK or EU adequacy decision, so those transfers rely on appropriate safeguards, in our case the European Commission's Standard Contractual Clauses (and the UK Addendum) together with the protections described in security.
If you'd like the detail of the safeguards that apply to a particular provider, ask us at support@kalabond.com and we'll tell you.
Who else touches it
We use a small number of service providers. They process data on our instructions to make the product work — none of them are given it to use for their own purposes, and none of them sells it:
- Supabase (on AWS, Sydney) — the database, accounts and sign-in, and the small server functions that run the AI features, the contact form and subscription updates.
- Vercel — hosting for this website and the web app.
- Resend (which sends via Amazon SES) — the account emails we send you, such as confirming sign-up or resetting a password, and delivery of contact-form messages to us.
- Microsoft 365 — our support mailbox. Anything you email to support@kalabond.com, or send through the contact form, is read and answered there.
- Anthropic — the model behind drafted messages and place suggestions, limited to what's listed in the AI features.
- RevenueCat — subscription processing across both app stores, as described in subscriptions and purchases.
- Apple and Google — app distribution through their stores, and payment for subscriptions bought there.
- Expo — building the app and delivering updates to it.
Who at KalaBond can see it
A small number of authorised people at Kala-X can look up an account when there's a reason to: answering a support request, sorting out a subscription that didn't activate, investigating abuse or a security problem, or meeting a legal obligation. What they can see is your email address, your name, when you joined, and your subscription status and history. They cannot browse your contacts, your plans or your messages — the tool they use doesn't show them. Every time an account is looked up, or anything is changed on it, that action is logged with who did it and why.
What we never do
These aren't aspirations. There is no part of KalaBond built to do any of them:
- We do not sell, rent or trade your personal information, or anyone's in your contact list. Not now, not as a later revenue idea.
- We do not run advertising, and we do not share anything for ad targeting or measurement. There is no advertising identifier read anywhere in the app, and nothing is used to track you across other apps or websites.
- We do not have data-broking or analytics-for-sale infrastructure, even stubbed in for later. There is no analytics or usage-tracking software in the app at all.
- We do not read your WhatsApp, SMS or any other messages. There is no technical means by which we could, and we haven't tried to build one. KalaBond can open a chat with a message ready for you to send — that is the entire extent of it.
- We do not sell or promote venues. Suggested places are generated on request and are not paid placements.
- We do not send anything to anyone on your behalf without you reading it first.
- We do not make decisions about you by automated means that have a legal or similarly significant effect.
How long we keep things, and deleting your account
Your account and everything in it is kept while your account exists. You can delete it yourself at any time, from Settings → Privacy & account → Delete account in the app. If you can't get into the app, ask us and we'll do it — the steps are on our delete your account page.
Deleting your account does four different things, and we'd rather spell them out:
- Deleted — your sign-in, your name and settings, every contact and group, every plan you created with all of its invitees, times, venues, votes and comments, and your AI usage record. This happens immediately and cannot be undone.
- Anonymised — if someone else invited you to their plan, your place on it isn't deleted. Your name is replaced with "Deleted participant" and any comment you left is removed, leaving an anonymous record that someone was invited and how they answered. That is deliberate: removing it would retract an RSVP the organiser had already counted and change another person's plan as a side effect of yours going. Once the name and comment are gone, what remains identifies nobody. The same applies to any feedback or problem report you sent us from inside the app: the report is kept, but the link to your account and whatever you wrote are both removed, leaving only which screen, which version and which error — so a fault we are still fixing does not vanish with the account that reported it.
- Retained — if you ever bought KalaBond Plus, the subscription records described in subscriptions and purchases are kept, unlinked from any person: your opaque billing identifier, the subscription's state, product, store and dates, and the events the store sent us. We keep them because the store subscription continues after the account is gone, and a later renewal, refund, chargeback, reconciliation or dispute has to be recorded against something. RevenueCat and the store keep their own corresponding records under their own policies. The log of any support or administrative action on your account is also kept, holding an opaque identifier rather than your name.
- Backups — deleted information may remain for a time in our database provider's encrypted backups, as part of its normal backup lifecycle. Backups exist to recover the service from a failure, not to restore a deleted KalaBond account.
Deleting your KalaBond account does not cancel a KalaBond Plus subscription. Store subscriptions are managed through the store account that bought them, not through KalaBond. If you delete your account without cancelling first, the subscription can keep renewing — so cancel it in your store account before you delete your KalaBond account.
Other things we hold, and how long for:
- Support messages — whether you emailed us or used the contact form, the message in our support mailbox is kept for 12 months after we've answered you, so we have the thread if you come back to us, then deleted. It lives in our mailbox, not in your account. A contact-form message also creates the copy in our database described in what the website collects. That copy has no fixed deletion period yet; you can ask us to remove it at any time.
- Waitlist addresses — kept until KalaBond opens to the public and we've told you, then deleted. Ask sooner and we'll remove you straight away.
- Guest voting details — the name and votes you gave on a shared link live with that plan, and go when the organiser deletes it or deletes their account.
We may keep something longer where the law requires it, but we won't keep it "just in case".
Why we're allowed to hold it
Under Australian privacy law we collect only what we reasonably need to run the service. If the UK or EU GDPR applies to you, our lawful bases are:
- Performance of a contract — your account, your contacts, your plans, the emails needed to sign in, and the subscription records needed to provide KalaBond Plus. Without these there is no product to provide.
- Legitimate interests — keeping the service secure and working, answering you when you write to us, and keeping the record of a subscription after an account is deleted so refunds and disputes can be handled. We've weighed this against your interests and kept the data involved to a minimum.
- Legal obligation — where accounting, tax or consumer law requires us to keep a record of a purchase.
- Consent — the waitlist, the optional AI features, and each phone permission. You can withdraw consent at any time; for the waitlist, tell us and you're off it.
Your rights
Wherever you are, you can ask us to:
- Show you what personal information we hold about you.
- Correct it if it's wrong.
- Delete it, including closing your account entirely — yourself, in the app, or by asking us.
- Send you a copy of what you've put in, in a form you can take elsewhere. You can do this yourself too, from Settings → Privacy & account → Download my data.
If the UK or EU GDPR applies to you, you can also ask us to:
- Restrict what we do with your information while a question about it is sorted out.
- Object to processing we've based on legitimate interests.
- Withdraw consent you previously gave, without affecting what we did before you withdrew it.
Write to support@kalabond.com. We'll respond within 30 days and won't charge you for it. We may need to confirm who you are first, so we don't hand your information to somebody else.
Security
Accounts are protected by email and password, with passwords hashed by our authentication provider — we never see or store the plain text. Data is encrypted in transit.
Access to your data is enforced at the database itself, not just in the app: rules on every table restrict rows to the account that owns them. Guest voting links reach the database only through a few narrowly-scoped functions tied to that one plan's link — an anonymous visitor never gets general access to any table. Subscription records can be written only by our own server, from what the store tells it, never by the app.
No system is perfectly secure, and we won't pretend otherwise. If a breach affects you, we'll tell you and the relevant regulator as required — under the Notifiable Data Breaches scheme in Australia, and within 72 hours where the UK or EU GDPR applies.
Children
KalaBond is made for adults and isn't directed at children. We don't knowingly create accounts for under-16s. If you believe a child has an account, tell us and we'll remove it.
Changes to this policy
If we change this policy we'll update the date at the top. If a change materially affects what we do with your information, we'll tell you in the app or by email rather than quietly editing the page.
Complaints
Raise it with us first at support@kalabond.com — we'd rather fix it directly.
If you're not satisfied with how we've handled it, you can complain to your regulator: the Office of the Australian Information Commissioner in Australia, the Information Commissioner's Office in the UK, or your national data protection authority in the EEA.