Privacy Policy
KAI Solutions LLC ("KAI Solutions," "we," "us," or "our") provides this Privacy Policy to explain how we collect, use, share, and protect information across our products, including PopKit (the "Service" or "App"). This is a shared policy covering all KAI Solutions products; product-specific sections below describe how each product handles data in addition to the general practices described here.
1. Who We Are
KAI Solutions LLC is a Missouri limited liability company based in Kansas City, MO. Learn more at https://www.kai-powered.com. You can contact us regarding privacy matters at contact@kai-powered.com.
2. General Practices (All KAI Solutions Products)
2.1 Information We Collect
- Account information. When you create an account, we collect your email address. We do not require or collect a password — accounts are authenticated via a one-time code sent to your email.
- Bot and spam prevention. When you sign up, we use Cloudflare Turnstile, a CAPTCHA service, to help verify you're a real person rather than an automated script. Turnstile processes limited technical signals (such as your IP address, browser/device characteristics, and TLS fingerprint) directly with Cloudflare to make this determination; Cloudflare states these signals are not used to directly identify you. See Cloudflare's own privacy policy for details on this processing.
- Push notification token. When you sign in on a device, we automatically register a device-specific push token, provided by Apple or Google and relayed through Expo's push notification service, so we can deliver notifications to that device. This token identifies a device, not you personally. Settings > Notifications lets you turn off specific notification categories (billing, team, and usage alerts, each on by default) — turning a category off stops us from sending that type of notification, but the token itself is only deleted when you sign out.
- Payment information. Payments are processed by Stripe, Inc. We do not collect or store your full payment card details ourselves; Stripe's own privacy policy governs the payment information you provide to them directly. We receive limited information from Stripe necessary to manage your subscription (e.g., subscription status, billing period dates).
- Usage and diagnostic information. We use Sentry (a third-party error-monitoring and analytics service) to collect crash reports, error logs, and app-usage/navigation data (e.g., which screens are viewed) to help us fix bugs and understand how the app is used.
- Information you provide directly. If you contact us for support, or submit a report or feedback within the app, we collect the content of that communication, including any comments, attachments, or details you choose to include.
- Website visits. Our public websites (including kai-powered.com and vaultestudio.com) are informational and do not require an account. We do not use them to collect personal information beyond the standard server logs maintained by our hosting provider for security and operational purposes.
2.2 How We Use Information
We use the information described above to: provide and operate the Service; process payments and manage subscriptions; diagnose and fix technical problems; respond to support requests; and communicate with you about your account (e.g., sign-in codes, billing notices).
2.3 How We Share Information
We do not sell your personal information. We share information only with:
- Service providers who process information on our behalf to help us operate the Service (see the product-specific sections below for which providers are used by which product, and for what purpose).
- Legal and safety reasons, if required by law, or to protect the rights, property, or safety of KAI Solutions, our users, or others.
- In connection with a business transfer, such as a merger, acquisition, or sale of assets, subject to standard confidentiality protections.
2.4 Data Retention
We retain account information for as long as your account is active. Usage logs, diagnostic data, and similar non-essential records are automatically deleted on a rolling basis approximately 12 months after they are created. You may also request deletion of your account and associated data by contacting us at contact@kai-powered.com; we will process such requests within 30 days.
Notwithstanding the above, we may retain certain records — such as billing, subscription, and tax-related records — for longer than 12 months where required by applicable law (e.g., financial recordkeeping obligations), even after an account is closed or a deletion request is processed.
2.5 Your Rights
Depending on where you live, you have certain rights over your personal information, described below. To exercise any of these rights, contact us at contact@kai-powered.com; to protect your information, we verify requests by confirming they come from your account's registered email address before acting on them, and aim to respond within 30 days.
If you are located in the EEA, UK, or Switzerland (GDPR):
You have the right to access, rectify, erase, restrict, or object to our processing of your personal information, and to receive a copy of your data in a portable format. The legal basis we rely on for each category of processing is:
| What we process | Legal basis |
|---|---|
| Account email / sign-in | Contract (necessary to provide the Service) |
| Bot/spam-prevention signals (Cloudflare Turnstile) | Legitimate interests (preventing automated abuse) |
| Push notification token | Legitimate interests (delivering account-relevant alerts you can opt out of by category in Settings) |
| Payment and billing information | Contract, and Legal obligation (financial recordkeeping) |
| Appraisal photos sent to Google/OpenAI | Contract (this is the service you're requesting) |
| Crash/diagnostic data (Sentry) | Legitimate interests (keeping the Service working) |
If you are not satisfied with how we've handled a request, you have the right to lodge a complaint with the data protection supervisory authority in your country of residence.
If you are a California resident (CCPA/CPRA):
You have the right to know what personal information we collect about you, to request deletion or correction of that information, and to non-discrimination for exercising these rights. We do not sell or share (as those terms are defined under the CCPA) your personal information, so there is no opt-out of sale/sharing to exercise.
2.6 Children's Privacy
Our products are not directed to children under 13 (or the relevant age of digital consent in your jurisdiction), and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact us at contact@kai-powered.com and we will take steps to delete it.
2.7 International Data Transfers
Our service providers (Supabase, Google, OpenAI, Stripe, Sentry, Cloudflare, and Expo — see Section 3.7) primarily store and process data in the United States. If you are located outside the United States, including in the European Economic Area, the United Kingdom, or Switzerland, your information will be transferred to and processed in the United States.
Each of these providers has agreed to the European Commission's Standard Contractual Clauses (SCCs), and the corresponding UK Addendum, as the legal mechanism governing that transfer under their respective Data Processing Agreements. KAI Solutions LLC has executed a Data Processing Addendum directly with OpenAI to formally put this in place; Supabase, Google, Stripe, Sentry, Cloudflare, and Expo each apply their SCC-backed terms automatically as part of their standard service agreements (Cloudflare confirmed against their published DPA/SCC terms; Expo confirmed against their Terms of Service, Section 3.2 "GDPR," which commits to SCC Module Two as processor and Module One as controller — both reviewed August 2026).
2.8 Changes to This Policy
We may update this Privacy Policy from time to time. We will post the updated policy with a new "Last updated" date, and, for material changes, provide additional notice as required by law.
2.9 Contact Us
Questions about this Privacy Policy can be directed to contact@kai-powered.com.
3. PopKit-Specific Privacy Practices
This section describes how PopKit, our AI-powered luxury item identification and appraisal app, specifically handles your information, in addition to the general practices above.
3.1 What PopKit Is and Is Not
PopKit provides informational estimates only. It does not authenticate items, verify genuineness, or provide professional appraisal services. Nothing in this policy changes that — the data practices below exist to support that informational service, not any authentication or valuation guarantee.
3.2 Photos You Take
- When you photograph an item for appraisal, that photo is sent to a third-party AI provider — Google (Gemini) or OpenAI, depending on which "Search Mode" is selected — to generate the identification and appraisal result. Both providers are accessed through their paid, billing-enabled API terms, not their free consumer-product terms, which carry meaningfully different data-handling practices:
- Google (Gemini API): Google does not use prompts, responses, or files (including images) submitted through billing-enabled API projects to improve or train its models. Abuse-monitoring logs are retained for up to 55 days by default, then automatically deleted. (Source: Gemini API — Data Logging and Sharing, reviewed August 2026.)
- OpenAI (API): Data sent to the OpenAI API, including image inputs, is not used to train or improve OpenAI's models unless we explicitly opt in to share it — we do not. Abuse-monitoring logs are retained for up to 30 days by default. (Source: OpenAI — API Data Usage and Retention, reviewed August 2026.)
- Your appraisal photos and results are stored locally on your device only. PopKit does not upload or sync your appraisal history or photos to our servers for storage — this data lives in the app's local storage on your phone and is not accessible to us in the ordinary course of using the app.
- If you use the "Report This Appraisal" feature, the appraisal details and the photo itself are sent to Sentry (see Section 2.1) as part of the report, along with any comment you add, so we can review reported issues. This is the one case where a photo leaves your device to be stored by us (via our service provider).
3.3 Portfolio ("Pops") Data
If you use PopKit's portfolio-tracking feature ("Pops"), including price-paid, sold-price, and buyer information you enter, that data is also stored locally on your device only and is not synced to our servers, with one exception: if you belong to a Team account (Section 3.5), only usage counts are visible to your team admin — never your Pops content or appraisal results.
3.4 Usage and Billing Data We Do Store Server-Side
To operate free/paid usage limits and billing, we store, per appraisal request: which AI provider was used, token/duration metrics, a usage-weight value, and a timestamp. We do not store the brand, model, value, authenticity result, or photo of your appraisals server-side as part of this record — only enough to enforce your plan's usage limits and to give you an accurate usage count in Settings.
3.5 Team Accounts
If you belong to a Team/Organization account, your team's admin can see aggregate usage counts for each member (e.g., number of appraisals made in the billing period) but cannot see the content of any member's appraisals or Pops, which remain private and local to each member's device, as described above.
3.6 Currency Conversion
Currency conversion figures shown in the app are AI-generated estimates, not sourced from a live financial data feed, and should not be relied upon as accurate for accounting, tax, or transactional purposes.
3.7 Service Providers Used by PopKit
| Provider | Purpose |
|---|---|
| Supabase | Backend hosting, authentication, and database (usage/billing records; see 3.4) |
| Cloudflare | Bot/spam prevention (CAPTCHA) at signup (Section 2.1) |
| Google (Gemini API) | AI-based image identification and appraisal (Quick search) |
| OpenAI | AI-based image identification and appraisal with live web search (Deep search) |
| Stripe | Payment processing and subscription management |
| Sentry | Crash/error reporting, usage analytics, and appraisal-report review (Section 3.2) |
| Expo | Push notification delivery (Section 2.1) |
See also: Terms of Service