PRIVACY POLICY
(United Kingdom)
This version, drafted with reference to the UK GDPR and the Data Protection Act 2018, applies to users who select the United Kingdom as their country of residence in the App. A separate French version applies to users who select France.
Draft updated: 24 July 2026
1. Who We Are and the Scope of this Policy
1.1 This Privacy Policy explains how KARIDO SAS, a French société par actions simplifiée with a share capital of €6,800, whose registered office is at 8 rue de Saint-Pétersbourg, 75008 Paris, France, registered with the Paris Trade and Companies Register under number 107 620 007 R.C.S. Paris ("KARIDO", "we", "us" or "our"), processes personal data when you use the KARIDO mobile application (the "App"), its contact form or newsletter services.
1.2 KARIDO SAS is the controller for the processing described in this Policy. You can contact us at contact@karido.io. We have not appointed a Data Protection Officer because we are not currently required to do so; that address is our privacy contact point.
1.3 This Policy should be read with the applicable Terms and Conditions. A third party's own privacy policy or terms may also apply when you use Apple, Google, a third-party merchant or a Brevo-hosted form.
2. Personal Data We Collect
2.1 Guest data and installation preferences stored locally. In guest mode, friends, events and gift ideas are stored locally on your device. The App also stores language, currency and shopping-market preferences, notification settings, versioned legal acceptance evidence, Analytics and Crashlytics choices, and the guest AI trial status and failed-attempt count for the day. This local data is not synchronised to your Firestore space unless you sign in. The first AI request nevertheless creates or restores an anonymous Firebase Authentication identifier and a temporary Firestore record for the job and its private context; this does not make your guest data available on another device. Relevant information is also transmitted when you use the contact form.
2.2 Account and authentication data. If you create an Account, Firebase Authentication processes a user identifier, email address, sign-in provider, email-verification status and identity information that Apple or Google may provide. For password authentication, Firebase processes and stores a hashed password; Karido cannot access the plain-text password. Karido does not ask for your own date of birth during Account creation.
2.3 Friend, event and gift data. Depending on what you enter, this may include a friend's first and last name, date of birth or other event dates, optional gender, relationship, interests, taste and style, things to avoid, an event-specific gift hint, minimum or maximum budget, and gift ideas with their status, estimated price, note or link. Reminders are scheduled locally on the device.
2.4 Legal evidence. We process the selected legal region, the Terms and Privacy Policy versions, displayed language, acceptance source, and client and server timestamps. Evidence is local for a guest and is also recorded in Firestore after sign-in.
2.5 Data processed for artificial intelligence and offer search. When you request a generation, the App prepares a request containing relevant information you entered: the friend's name, relationship, interests, style, things to avoid, inferred age where a birth year is known, event name, type and date, up to thirty existing gift-idea titles, budgets, shopping market, currency, and generation and search languages. Optional gender and the event-specific gift hint are not sent in the current version. Generated suggestions are displayed in the App; only suggestions you choose to save become persistent gift ideas. For eligible Accounts, the backend then uses product queries, the France or United Kingdom market and, when compatible, the budget to find offers; it does not send the friend's name to the product catalogue.
2.6 Optional Analytics data. Only if enabled, Google Analytics for Firebase receives a random app-instance identifier, technical device and App data, and a limited set of generic events: onboarding completion, access mode, creation of a friend or event, reminder coverage, generic AI-generation progress or outcome, guest-trial consumption, revealing more ideas, saving a gift idea, generic product-link opening, Account creation and newsletter status. Karido does not send Analytics your Firebase UID, names, email addresses, dates, relationships, budgets, gift-context text, prompts, gift titles or product links.
2.7 Optional crash reports. Only if enabled, Firebase Crashlytics may receive crash traces, App and operating-system versions, device model, technical installation identifiers and data needed for diagnosis. Karido does not configure Crashlytics with your Firebase UID and does not intentionally attach names, email addresses, prompts or gift data.
2.8 Contact form. If you contact us through the App, we process the message, optional subject, optional or prefilled reply email, locale, session mode, sign-in provider, authentication status and timestamp. The message is delivered to our Google Workspace mailbox and is not stored in Firestore. App Check also processes technical material needed to verify the App installation.
2.9 Newsletter. For in-App subscription, we use the authenticated Account's email address, locale, consent source and version, subscription status and timestamps. Brevo sends a double opt-in email and treats the subscription as active only after confirmation. If you use a Brevo form from the Karido website, Brevo also processes the information submitted under the notices presented with that form.
2.10 Optional selection-ready notifications. If you enable this setting, Firebase Cloud Messaging processes an installation-specific token, your Firebase identifier, platform, locale, App version and last-active date. The notification contains only an opaque job identifier and generic wording; it does not contain a friend's name, gift idea, product, search terms or merchant link.
2.11 Security data. Firebase, Google and attestation providers may process IP addresses, authentication logs, installation identifiers, App Check tokens and attestation material to secure services and prevent abuse.
2.12 We do not ask for special category data such as health, religion, ethnicity, sexual orientation or political opinions. You must not enter such information about yourself or another person.
3. Data About Other People
3.1 The App lets you record information about friends or family members who are not themselves Karido users. You must limit this to what is necessary for reminders and gift planning, have a legitimate reason for entering it, and ensure that the person would reasonably expect or has been informed of the use.
3.2 Karido does not use that information to contact those people, profile them for its own benefit or send them advertising. It is processed to provide the functions requested by the Account holder or guest user.
3.3 A person whose data has been entered may contact us to exercise their rights. We may need additional information to identify the relevant data without disclosing another User's information.
4. Purposes and Legal Bases
4.1 Providing the App, including guest mode, Account management, synchronisation, friends, events, gifts and reminders: performance of the Terms agreed with you (Article 6(1)(b) UK GDPR).
4.2 Generating AI gift suggestions and finding product offers, including the guest trial: performance of the Terms. Relevant data is processed to answer the request, search offers for the selected market, secure the service and apply its usage rules.
4.3 Keeping evidence of the Terms and privacy information presented: performance of the Terms, compliance with legal obligations and our legitimate interest in demonstrating applicable choices in the event of a dispute.
4.4 Measuring App usage with Analytics: your consent, requested as an optional choice from Home and changeable in Settings. Analytics remains disabled before a positive choice.
4.5 Receiving crash reports with Crashlytics: your separate consent, requested optionally and changeable in Settings. Crashlytics remains disabled before a positive choice.
4.6 Managing the newsletter: your voluntary consent confirmed through double opt-in. Refusal does not affect Account creation or use of the App.
4.7 Responding to support messages: our legitimate interest in handling enquiries, or taking steps at your request depending on the message.
4.8 Notifying you when an AI selection is ready: your optional consent, separate from event reminders, Analytics and marketing communications. You may withdraw it at any time in Settings.
4.9 Securing the App, preventing fraud and abuse, and enforcing the Terms: our legitimate interests and, where relevant, legal obligations.
4.10 Complying with law and valid authority requests: compliance with legal obligations.
4.11 We do not sell or rent personal data and do not use it for third-party targeted advertising.
5. Recipients and Service Providers
5.1 We disclose data only to providers needed for the purposes described:
(a) Google Cloud and Firebase for authentication, Cloud Firestore, backend functions, App Check, Remote Config, Firebase Cloud Messaging, Analytics and Crashlytics according to your choices;
(b) Google through the Gemini Developer API called by our backend to produce gift suggestions and protect the service against abuse;
(c) Apple and Google when you choose their authentication services, and Apple for APNs delivery if you enable selection-ready notifications;
(d) Brevo for newsletter double opt-in, delivery and management;
(e) Google Workspace to receive and handle contact-form messages; and
(f) affiliate networks, marketplace providers and participating merchants, including Awin, to provide product offers and attribute purchases when you follow an affiliate link; and
(g) professional advisers or competent authorities where required by law or needed to establish, exercise or defend legal claims.
5.2 App stores, authentication providers and third-party merchants may process data for their own purposes under their own policies. Karido is not responsible for processing independently determined by those third parties.
5.3 Under Google's current terms, the Paid Services data treatment applies to Gemini Developer API use made available to users in the United Kingdom. Under that treatment, prompts and responses are not used to improve Google's products or train its general-purpose models. Google nevertheless logs prompts and responses for a limited period solely to detect and prevent prohibited uses, maintain service safety, and make required legal or regulatory disclosures. We will update this Policy if the service configuration or applicable terms change.
6. Artificial Intelligence Processing
6.1 Gift suggestions are generated using the relevant information described in clause 2.5. The App does not make any decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you.
6.2 Karido does not use friend information to train its own general-purpose model and does not ask Google to add it to a shared dataset for general model improvement.
6.3 Under the Gemini Developer API terms currently applicable to Paid Services, Google logs prompts and responses for a limited period to detect and prevent policy violations, maintain service safety, and make required legal or regulatory disclosures. The current public terms do not specify a numerical duration for this logging. Under the conditions described in clause 5.3, this content is not used to improve Google's products.
6.4 You must avoid entering sensitive, confidential or unnecessary data. The "things to avoid" field is intended to guide gift recommendations and must not be used for medical, religious or other special-category information.
6.5 Suggestions are stored persistently in Karido only if you choose to save them. Unselected results remain subject to the temporary processing necessary for display and the AI provider's rules.
7. Locations and International Transfers
7.1 Synced application data in Cloud Firestore is hosted in the European eur3 multi-region, relying in particular on regions in Belgium and the Netherlands. Guest data primarily remains on the device, subject to AI requests, the contact form and any telemetry you enable.
7.2 Firebase Authentication is operated from data centres in the United States. Other Firebase services, Gemini, Google Workspace, Brevo, Apple and Google may process data outside the United Kingdom or European Economic Area.
7.3 Where required, transfers rely on adequacy regulations, the UK International Data Transfer Addendum, approved contractual clauses or another safeguard recognised by applicable law. Further information is available from contact@karido.io.
8. How Long We Keep Your Data
8.1 Guest data and local preferences: until deleted in the App, successfully transferred to an Account, erased following confirmed Account deletion, the App's data is cleared or the App is uninstalled, subject to operating-system device backups. After a successful import, or after Account deletion is confirmed, the App erases friends, events and gift ideas from the previous guest database. Local legal evidence and installation-level preferences follow their respective reset mechanisms and may remain.
8.2 Account, friend, event, gift and synchronised consent data: while the Account remains open. Active deletion is initiated through the App after a recent sign-in. Once deletion is confirmed, the App also erases any application data in the previous local guest database and retries that erasure on a later launch if it fails technically. To prevent work already in progress from recreating data after deletion, Karido retains a technical deletion lock linked to the Firebase identifier, without friend, event or gift content, for no more than ninety (90) days. Firebase also states that certain authentication data and backup copies may take up to one hundred and eighty (180) days to be removed from live and backup systems.
8.3 AI jobs and Gemini requests and responses: the job and its private context are temporary in Firestore. An active job is configured to expire within two days and a completed job within twenty-four hours; Firestore TTL deletion is asynchronous. Google may log prompts and responses for the limited period, not numerically specified in its current public terms, needed for abuse monitoring and the purposes described in clause 6.3. Gift ideas you save follow the retention period for Account gift data.
8.4 User-level and event-level Analytics data: no more than fourteen (14) months where Analytics is enabled. Aggregated statistical reports that no longer reasonably identify an installation may be kept longer.
8.5 Crashlytics reports and associated identifiers: ninety (90) days before Firebase begins removing them from live and backup systems.
8.6 Newsletter data: until unsubscribe. When the Account is deleted, the address may remain in a protected technical queue for no more than seven (7) days, solely while Karido performs or retries the Brevo unsubscribe; the queue entry is deleted as soon as that operation succeeds. Brevo may then retain the email address on a suppression list for as long as needed to honour the opt-out and prevent unsolicited resubscription. Firestore consent evidence is deleted with the Account.
8.7 Support messages: for as long as needed to respond and manage the enquiry, and subsequently where justified by a legal obligation or legal claim.
8.8 Selection-ready notifications: the installation token is removed when you disable the setting, sign out, delete your Account or Firebase reports it as invalid. An inactive installation is removed within ninety (90) days. The opaque job identifier and technical delivery state are retained for no more than seven (7) days.
8.9 Security logs and provider technical data: according to the relevant service's own period. For example, Firebase Authentication retains logged IP addresses for a few weeks, and App Check retains certain replay-protection tokens for no more than thirty (30) days.
9. Your Rights and Choices
9.1 Subject to applicable conditions, you have rights to access, rectify or erase personal data, restrict or object to processing, receive data in a portable format and withdraw consent at any time without affecting earlier processing.
9.2 You may manage selection-ready notifications, Analytics and Crashlytics, the newsletter and Account deletion in Settings. Withdrawing notifications removes Karido's registration of the installation token. Withdrawing Analytics consent disables collection and resets local Analytics data. Withdrawing Crashlytics consent disables collection and removes unsent reports; reports already sent remain subject to clause 8.5.
9.3 To exercise a right or report data relating to a friend, contact contact@karido.io. We may request information needed to verify identity or locate the data without requesting more than necessary. We generally respond within one month, subject to extensions allowed by law.
9.4 You may complain to the Information Commissioner's Office at ico.org.uk. We would appreciate the opportunity to review your concern first.
10. Children
10.1 The App is not intended for children under 13. If we learn that a child under 13 has provided personal data through the App, we will take appropriate steps to delete it. [AGE THRESHOLD AND WORDING TO BE CONFIRMED BY UK COUNSEL]
11. Security
11.1 We use proportionate technical and organisational safeguards, including encryption in transit, password hashing by Firebase Authentication, App Check, Firestore access rules limited to the Account holder, backend request validation and data minimisation for Analytics.
11.2 No system can guarantee absolute security. If a personal-data breach occurs, we will assess the risk and notify the ICO and affected individuals where required by law.
12. Changes to this Policy
12.1 We may update this Policy to reflect changes to the App, our providers or applicable law. The date and applicable version are identified in the App.
12.2 A material change may result in the Policy being presented again and, where necessary, a new acceptance of the Terms or a new consent choice. We will provide appropriate notice before the change takes effect where required by law.
13. Contact
13.1 For any question, request or complaint about this Policy or personal data:
By email: contact@karido.io
By post: KARIDO SAS, 8 rue de Saint-Pétersbourg, 75008 Paris, France
Read the Terms and Conditions →
This is the app's Privacy Policy. Looking for the website's privacy policy instead? Privacy.