Last updated: August 9, 2026
Overview
Kiwi Car AI (“Kiwi”, “we”, “our”) is a voice-first iPhone and CarPlay app for AI-assisted driving questions. Kiwi uses a backend service for session management, entitlement checks, request routing, operational diagnostics, usage metering, and privacy-safe product analytics. Kiwi does not sell your personal data, does not use advertising tracking, and does not run server-side conversation or memory sync by default.
Data Controller
Robert OberdorferAsternweg 49
32676 Lügde
Germany
Email: kiwicarai@posteo.com
What Stays on Your iPhone
Kiwi keeps the following information locally on your device by default:
- Conversations: Your conversation history is stored in the app's local storage on your iPhone.
- Memories: Notes that you save with Kiwi Memory stay on your iPhone.
- Install-bound Kiwi service session: Kiwi stores an install-bound Kiwi service session in the iPhone Keychain so the service can recognize this installation, refresh access when needed, and check entitlement state.
- App preferences: Settings such as your location-sharing preference, onboarding completion, and debug preferences are stored locally on your device.
- Activation delivery markers: Kiwi stores which fixed activation milestones have already been queued or delivered so the app normally sends each milestone only once per installation. These markers stay in the app's local preferences.
How Kiwi Processes Requests
When you ask Kiwi a question, Kiwi sends the current request and the conversation context needed to answer it through Kiwi's backend service for model and voice processing. Kiwi uses the backend service to authenticate the request, apply entitlement checks, meter completed turns, and return the response and audio to your iPhone.
- OpenAI acts as Kiwi's model provider for AI request processing.
- xAI may process answer text and fixed voice-cue text for text-to-speech when configured as Kiwi's voice provider.
- OpenAI's privacy policy applies to model-processing data: https://openai.com/policies/privacy-policy/
- xAI's privacy policy may apply to text-to-speech processing data: https://x.ai/legal/privacy-policy
- Kiwi does not provide a normal mode that asks you to paste your own OpenAI API key.
- Kiwi does not sync your full conversation history or memory notes to Kiwi's backend by default.
What Kiwi's Backend Stores
Kiwi's backend stores the minimum server-side information needed to operate the service. This includes:
- Session, identifier, and entitlement data: Pseudonymous service-user, installation, and session records; App Attest verification data; entitlement, preview, purchase, subscription, and billing-period status. Kiwi does not require a name or email account for normal app use.
- Network and security data: Cloudflare, Kiwi's hosting stack, and short-lived rate limiting may process IP addresses, request timestamps, routes, request IDs, and similar network metadata to deliver and protect the service.
- Metadata-only usage analytics: Request type, provider, model, request profile, token counts when available, text-to-speech character counts, cost metadata, durations, web-search usage, and related operational metadata.
- Aggregate rollups: Longer-lived user and global usage summaries derived from metadata-only events.
- Privacy-safe activation analytics: Kiwi may send fixed milestone names such as onboarding completed, the first voice-permission outcome, first core action started or completed, and paywall presented. The request is authenticated to prevent abuse, but the activation analytics table stores only a UTC date, the fixed milestone name, and a global count. It contains no user, installation, request, locale, app-version, location, prompt, answer, or audio field. Preview-start and active-subscription milestones are generated only by verified server-side transitions. Counts are approximate because a retry after a lost server response can count the same milestone again.
- Temporary TTS authorization: When Kiwi prepares an answer for linked text-to-speech, the backend temporarily stores the answer text with a one-time authorization. It is deleted after successful use; unused authorizations expire after 30 minutes and are removed by expiry cleanup.
- Short-lived replay protection: Kiwi keeps replayable request and response payloads for up to 24 hours to safely handle retries and idempotent request replays.
Kiwi's metadata-only usage analytics intentionally exclude prompt text, answer text, and audio payloads. Kiwi does not sell this data or use it for advertising.
App Privacy Data Categories
In Apple's App Privacy terminology, Kiwi may collect the following categories. “Linked” means linked to a pseudonymous Kiwi service user, installation, or device record; it does not mean that Kiwi knows your civil identity.
- Identifiers: Pseudonymous user and device or installation identifiers, used for app functionality.
- Purchases: Purchase and subscription history, used for entitlement and app functionality.
- Usage Data: Product interaction and other usage data, used for app functionality and analytics.
- User Content: Questions and conversation context sent to service a request, used for app functionality.
- Search History: Questions that invoke Kiwi's optional web-search capability, used for app functionality.
- Location: Depending on the installed app version and iOS accuracy setting, optional location context can be precise or coarse and is used only for app functionality. Precise Location applies to the currently available version because it can send rounded coordinates. The pending privacy-hardening build sends only a city or region and will allow that disclosure to be removed after release.
- Diagnostics: Crash, performance, and other diagnostic data, used for app functionality, reliability, and analytics. Backend performance and diagnostic records can be linked to a pseudonymous service user or installation; Sentry crash records are not intentionally linked to that service identity.
None of these categories is used to track you across apps or websites owned by other companies.
Siri Integration
Kiwi integrates with Siri and App Shortcuts for hands-free use. When you use Siri commands:
- Apple processes your voice according to Apple's privacy practices.
- The transcribed text is passed to Kiwi and then through Kiwi's backend service for model processing. Spoken responses may also be processed for text-to-speech.
Optional Location
Kiwi offers an optional “Share Location” feature that you can enable in Settings. When enabled:
- The currently available app version can derive a place name and rounded coordinates. Apple's App Privacy terminology therefore treats this as Precise Location even when Kiwi describes the feature as approximate.
- A pending privacy-hardening build removes coordinates before transmission and sends only a reverse-geocoded city or region. Until that build is available, location context must be treated as precise.
- The location context is included in the first message of each conversation sent through Kiwi's backend service to OpenAI.
- Kiwi does not use the location feature when it is turned off.
- You can disable the feature at any time in Settings.
When the feature is disabled, Kiwi does not access or send your location.
Crash, Performance, and Diagnostic Data
Kiwi uses Sentry to receive crash data, performance data, and other diagnostic data that help us keep the app working reliably. Diagnostic events may include technical context such as app version, device model, operating-system version, request status, and error details. Kiwi does not intentionally attach screenshots, prompts, answers, or audio to Sentry events. Kiwi uses diagnostic data for app functionality and debugging, not for tracking or advertising.
Service Providers and International Processing
Kiwi uses service providers only where needed to operate the app:
- Apple: App distribution, StoreKit purchases, subscription status, App Attest, Siri, and Apple-provided app analytics.
- Hetzner: Hosting of Kiwi's backend service in the European Union.
- Cloudflare: Network delivery, TLS termination, availability, and abuse protection.
- OpenAI: AI request processing. Kiwi sends Responses API requests with provider-side application-state storage disabled. Under OpenAI's standard controls, abuse-monitoring logs can still contain prompts, responses, and derived metadata and can be retained for up to 30 days, or longer when legally required, unless approved account-level controls apply. See OpenAI's API data controls.
- xAI: Text-to-speech processing when configured as Kiwi's voice provider.
- Sentry (Functional Software, Inc.): Crash, performance, and diagnostic processing.
Some providers may process data outside the European Economic Area. Where required, such transfers rely on an applicable adequacy decision, the EU-US Data Privacy Framework, Standard Contractual Clauses, or another lawful transfer safeguard.
Legal Bases for EEA and UK Users
- Contract and requested services: App functionality, request processing, entitlement checks, purchases, and subscription access are processed to provide the service you request.
- Legitimate interests: Security, abuse prevention, reliability diagnostics, cost control, metadata-only usage measurement, and aggregate product analytics support the safe and sustainable operation of Kiwi.
- Consent: Optional location processing begins only after you enable the feature and grant the iOS permission. You can withdraw this choice in Kiwi Settings or iOS Settings.
- Legal obligations: Limited records may be retained where required for accounting, tax, dispute, or other legal obligations.
Retention
- Conversations, memories, preferences, and activation delivery markers remain on your iPhone until you delete them, reset the app, or uninstall it, subject to iOS Keychain behavior.
- Replayable request and response payloads expire after no more than 24 hours.
- Linked TTS authorization text is deleted after successful use. Unused authorizations expire after 30 minutes and are removed by expiry cleanup.
- Raw authentication and metadata-only usage events are retained for up to 30 days.
- Network and rate-limit data is retained only for the applicable security window or the infrastructure provider's configured operational-log period.
- Pseudonymous installation, session, purchase, subscription, entitlement, billing, user-level rollup, and security records are retained for as long as needed to operate and protect the service, honor purchases, resolve disputes, or meet legal obligations.
- Global daily activation counts and other aggregate rollups may be retained longer for trend, cost, reliability, and product analysis.
- Diagnostic data is retained according to Kiwi's configured Sentry project retention and deleted when it is no longer needed.
What Kiwi Does Not Do
- Kiwi does not sell your personal data.
- Kiwi does not use third-party advertising SDKs or cross-app tracking.
- Kiwi does not offer server-side chat history or memory sync by default.
Data Deletion
You can delete conversations and memories from within the app. Uninstalling the app removes app-sandbox data on your iPhone. Keychain-based service credentials are managed separately by iOS and may persist across reinstall until they are rotated or replaced. To request deletion of pseudonymous server-side service records associated with your Kiwi installation, contact kiwicarai@posteo.com.
Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a copy of personal data, and to object to or withdraw consent for certain processing. Contact kiwicarai@posteo.com to exercise these rights. EEA users may also lodge a complaint with a data-protection authority. The competent authority for the controller is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
Children's Privacy
Kiwi is not directed at children under 13, and we do not knowingly collect personal data from children.
Changes to This Policy
We may update this policy from time to time. When we do, we will update the date at the top of this page.
Contact
If you have questions about this privacy policy, contact us at kiwicarai@posteo.com.