Skip to content
Bini
Features Security Safety Get the app
Features Security Safety Privacy Get the app
Legal

Privacy Policy

Effective Date: October 3, 2026 · RevuFlex LTD

Bini, previously named KissApp ("the App," "our App"), is developed and operated by RevuFlex LTD ("RevuFlex," "we," "us," "our"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use Bini. We are committed to protecting your privacy and ensuring that your personal data is handled responsibly. Please read this policy carefully. By using the App, you agree to the collection and use of information in accordance with this policy.

Contents

  1. Information We Collect
  2. How We Use Your Information
  3. End-to-End Encryption
  4. Information Sharing Between Partners
  5. Analytics and Crash Reporting
  6. Third-Party Services
  7. Device Permissions
  8. Data Storage and Security
  9. Data Retention
  10. Your Rights and Choices
  11. Children's Privacy
  12. International Data Transfers
  13. Changes to This Policy
  14. Contact Us

01

Information We Collect

We collect information you provide directly, information generated through your use of the App, and information from third-party services integrated into the App.

Information You Provide

  • Account Information. When you register, we collect your phone number (verified by a one-time code we text you), date of birth, and gender selection. You may optionally upload a profile picture; it is served from a public web address, so anyone who has its link can view it — do not use a private or sensitive image. Your date of birth is used to confirm that you meet our minimum age requirement.
  • Partner Pairing. To connect with your partner, we process invitation codes, an optional relationship date for anniversary tracking, and your device's time zone (used to determine when your shared day ends for streak purposes).
  • Messages and Media. The content of messages you send, including text, images, videos, voice messages, documents, stickers, and other files. All message content is end-to-end encrypted on your device before transmission (see Section 3).
  • Memories. Photos and videos you save to your shared Memories album, together with their captions and place names. The media, captions, and place names are end-to-end encrypted. The geographic coordinates and capture date attached to a memory are stored so the shared memory map can place them.
  • Question of the Day. The answers you and your partner write to the daily shared question. Answers are end-to-end encrypted in the same way as messages, so we cannot read what either of you wrote. Stored alongside the encrypted answer are the identifier of the question your pair was served and the date you answered it.
  • Sticky Notes. Notes you and your partner pin to the shared board on your home screen, and the cross-offs, stamps and replies you add to them. The text and these additions are end-to-end encrypted in the same way as your messages, so we cannot read them. Stored alongside each encrypted note are which of you wrote it, its colour, its tilt and place on the board, and when it was written and last changed.
  • Stickers. Stickers you create from your own photos or import as sticker packs are stored in your personal library in encrypted form, using a key derived from your own private key. Your partner cannot read your library; only stickers you actually send are re-encrypted for the two of you. Stored next to each encrypted sticker is technical metadata: a SHA-256 fingerprint of the sticker image (used so the same sticker is not saved twice and so a sticker you already own can be recognised), the name of the pack it came from, its file size, and whether it is animated. A fingerprint is not the image and cannot be turned back into one, but the same sticker file always produces the same fingerprint.
  • Calendar Events. Entries and categories you create in the shared Pair Calendar. From version 2.0.4 of the App, the title, notes and place of each entry, and the names of your categories, are end-to-end encrypted in the same way as your messages, so we cannot read them. Encryption begins for a couple once both of you have opened version 2.0.4 or later; the App then also encrypts the entries you created earlier, the next time either of you opens it, and anything written later from a device that still runs an older version is encrypted as soon as one of your updated devices sees it. Stored alongside the encrypted text is what the App needs to put entries in order and remind you of them: the date and time, whether an entry lasts all day, how it repeats, its reminder times, whether it is marked as important, the colour and icon of its category, which of you added it, whether it is an automatically created birthday or anniversary, and — if you linked a calendar on your phone — a reference to the matching entry there.
  • Saved Locations. Names, addresses, and coordinates of locations you save to shared Map Lists.
  • Safety Reports. If you report a safety concern from inside the App, we receive the reason you selected, anything you chose to write in the description box (up to 2,000 characters), your account identifier, the identifiers of the pairing and of the person you are reporting, your time zone, and the app version and platform you reported from. Because a report asks us to act, it is addressed to our safety team, who read it. If you choose to attach messages — a choice you make yourself, by ticking a box that is never ticked for you — your device also sends the messages, photos, stickers and voice notes from that conversation within the range you picked, or the single message you reported, from both you and the other person; your device encrypts them before they leave it, so that only our safety team can open them, and our servers and our storage provider cannot. Videos are sent as a single still frame. Documents are not sent at all, and neither is view-once media, whether or not it was opened. We also record technical details of recent messages in that conversation — message identifiers, who sent them, when, the kind of item, the storage path of any attached file, and the exact encrypted length — so that we can confirm attached items really were part of it; we cannot read those messages. You can follow your report in the App, and we store the updates our safety team sends you and any replies you add. See our Child Safety Standards for how reports are handled.
  • If Someone Reports You. A person you exchange messages with can include messages and media from your conversation in a safety report, in the same way they could show them to anyone else. We use that material only to review the report, to protect users, and to meet legal obligations, including reporting apparent child sexual abuse material to the authorities. We do not tell a reported person that a report was made, or by whom.
  • Settings and Preferences. Your language preference, theme color selection, notification preferences, and widget configuration choices. Partner nicknames you set are stored only on your own device and are never uploaded to our servers.
  • Contacts (on your device only). With your permission, the App looks up your partner's phone number in your address book so they appear under the name you saved for them. This matching happens entirely on your device: your contacts are never uploaded, stored on our servers, or shared with us or anyone else, and you can decline or revoke the permission at any time without losing any feature except the automatic name.

Information Collected Automatically

  • Device Information. Device type, model, operating system version, app version, and platform (iOS or Android) to ensure the App functions correctly on your device and to diagnose faults.
  • Location Data. Location sharing is off until you turn it on, and pairing does not start it. Nothing is collected until you switch sharing on yourself from the map screen inside the App; when you do, the App first shows a short notice explaining the choice your phone is about to offer, and only then is location access requested. Once sharing is on, the App collects your GPS coordinates (latitude and longitude) and shares them with your partner, and you can switch it off again at any time from the same screen. While location sharing is off, the App does not store your live position or share it with your partner — including when your partner asks for a refresh (see Section 4). If you have allowed location access, two things still use it: when you open the App’s own camera from Memories, the App reads where you are at that moment so the photo or video you take is pinned there; and while the map screen is open, the App shows where you are and sends your position with any place search you type there, so nearby results come first (see Mapbox in Section 6).
  • Usage Data. Kiss events and streak counters between you and your partner, call metadata (participants, call type, start and end times, duration, and connection records needed to place the call), online and typing indicators, message delivery and read timestamps, and a flag recording that a screenshot was taken while a photo, video or file in your chat was being viewed.
  • Message Reactions. The emoji you tap onto a message is stored on our servers next to the encrypted message it belongs to, together with which of you reacted.
  • Message Metadata. Alongside each encrypted message we store what is needed to deliver and display it: which pair it belongs to, who sent it, when it was sent, what kind of item it is (text, photo, video, voice message, file, GIF, or sticker), whether it replies to another message, and whether it was sent as view-once. The content it describes is end-to-end encrypted.
  • Push Notification Tokens. Device tokens for Firebase Cloud Messaging (FCM) and, on iOS, VoIP push tokens, used to deliver notifications and incoming call alerts.
  • Encryption Keys. We store your public encryption key, which your phone creates together with your private key, and — if you create a recovery key — an encrypted backup of your private key that only that recovery key can open, plus the date it was created. When you move to a new phone by scanning the code it shows with your old one, the key travels between your two devices as ciphertext relayed briefly through our servers, sealed to a one-time key that never leaves your new phone. In every case we only ever hold ciphertext we cannot open (see Section 3).
  • Diagnostics and Product Analytics. Crash reports and a small, fixed set of product milestone events, described in full in Section 5.

Subscription Information

  • Purchase Data. When you subscribe to Bini Premium, we receive subscription status, product identifier, store of purchase (Apple App Store or Google Play Store), expiration date, and original purchase date from our subscription processor, RevenueCat. We do not receive or store your payment card details, billing address, or other financial information.
↑ Back to top

02

How We Use Your Information

We use the information we collect for the following purposes:

  • Providing and Operating the App. To create and maintain your account, pair you with your partner, deliver messages and stickers, enable voice and video calls, share locations, synchronize calendars, store your Memories, and provide all core features of the App.
  • Security and Encryption. To encrypt and decrypt your messages and call data, verify your identity, lock the App with your device’s biometrics if you turn that on, restore your encryption keys when you sign in on a new device, and protect the integrity of your account.
  • Notifications. To send you push notifications for incoming messages, calls, kiss events, streak reminders, and calendar event reminders.
  • Subscription Management. To verify your premium subscription status, grant access to premium features, and synchronize subscription status between paired users.
  • Stability and Product Improvement. To receive crash reports so we can fix faults, and to count a small number of product milestones so we can understand which parts of the App work and which do not. This is described in detail in Section 5.
  • Safety and Legal Compliance. To review and act on safety reports, to keep reporters informed of what is happening with their report, and to meet our legal obligations, including reporting child sexual abuse material to the National Center for Missing & Exploited Children, the Internet Watch Foundation, the National Crime Agency and other competent authorities.
  • Legal Compliance. To comply with applicable laws, regulations, legal processes, or enforceable governmental requests.
We do not sell your personal information. We do not display advertisements. We do not use your data for ad targeting or profiling. We do not track you across other apps or websites, and the App is built so that it does not collect an advertising identifier on either platform. Bini is funded through optional premium subscriptions.
↑ Back to top

03

End-to-End Encryption

Your privacy is fundamental to Bini. Your private conversations and the media inside them are protected with end-to-end encryption (E2EE).

  • How It Works. The App establishes a shared secret between you and your partner using elliptic-curve cryptography. Content is encrypted on your device before leaving it, and only your and your partner’s devices can decrypt it.
  • What Is End-to-End Encrypted. Chat text, photos, videos, voice messages, documents and other files, stickers you send, your Memories media together with their captions and place names, your Question of the Day answers, the notes you pin to your shared board together with the cross-offs, stamps and replies added to them, the titles, notes and places of your calendar entries and the names of your calendar categories (from the point described in Section 1), and the signalling data used to set up calls. When you send a GIF, we store only an encrypted reference to it rather than the image itself.
  • What This Means. Neither RevuFlex, nor our infrastructure providers, nor any third party can read the content of your messages or listen to your calls. Encrypted data stored on our servers is indecipherable without your private keys, which only you and your partner hold — on your own devices, and in encrypted backups that only you can unlock. The only exception is content that one of the two people in a conversation deliberately chooses to send to our safety team in a report; that content is encrypted by their device so that only our safety team can open it, and it never gives us a key to the rest of your conversation.
  • Notifications Carry No Readable Content. A push notification tells your partner's device that something arrived and what kind of item it is — for example "Photo", "Video", "Voice message", "File", "GIF", or "Sticker". It never carries your words in readable form: for a text message it may carry a short excerpt sealed with a preview key that only your and your partner's devices hold, so that their phone can show a preview if its own notification settings allow one; the captions you add to photos and videos, voice messages, file contents, stickers, and daily-question answers are never passed to the notification service in any form. A notice that your partner added a calendar entry or pinned a note uses a fixed phrase; a calendar notice sent from version 2.0.4 or later may also carry the entry’s title as the same kind of sealed excerpt. See Section 6 for the full description of what a notification contains.
  • Your Keys on Your Devices. Your private key is generated on your phone and kept in its secure storage. So that it can return when you restore or replace your phone, a copy may also be kept in your platform’s own keychain backup — iCloud Keychain on iPhone, and on Android Google’s Block Store, which is included in a cloud backup only where that backup is end-to-end encrypted. Neither we nor your partner can read that copy. You can also move the key straight to a new phone: the new phone shows a code, your old phone scans it, and the key travels between them sealed so that we cannot open it.
  • Recovery Key. The App also asks you to create a recovery key: a 24-character code generated on your device and shown to you once. It locks a second encrypted copy of the same private key, which lets you restore your history on a new phone even when no signed-in phone is at hand. The recovery key itself is never sent to us — we only ever store the locked copy it produces, which we cannot open. If you lose your recovery key and no signed-in device or keychain backup remains, your previously shared content cannot be recovered by anyone, including us.
  • Voice and Video Calls. Calls are established using WebRTC peer-to-peer connections. Call signalling data is encrypted before traversing our servers, and the audio/video stream flows directly between devices over an encrypted connection. When a direct connection is not possible, the encrypted stream is relayed through a TURN server that cannot decrypt it.
↑ Back to top

04

Information Sharing Between Partners

Bini is designed for two people in a relationship. When you pair with a partner, certain information is shared between you by design:

  • Always Shared. Your phone number, profile picture, online and typing status, message delivery and read receipts, the emoji reactions you place on messages, kiss events and streak counts, Memories you add, the notes on your shared board, your Question of the Day answer once you have both answered, and shared calendar events and categories. Your date of birth and gender are also readable by your paired account, although the App does not display them to your partner anywhere.
  • Shared When Enabled. Your real-time location (only while location sharing is switched on — it starts off; see below), saved Map Lists, and call history.
  • Subscription Status. If either partner holds a Premium subscription, both partners receive access to premium features. Each partner can see whether premium access is active for the pair.
  • Screenshots of Photos and Videos. If you take a screenshot while viewing any photo or video your partner sent — not only view-once media — your partner is told that a screenshot was taken.

Location sharing is off until you turn it on. Pairing does not start it: no location is collected or shared until you switch sharing on yourself from the map screen inside the App. When you do, the App first shows a short notice explaining what your phone is about to ask — choosing "Always" lets sharing keep working when the App is closed, while "While Using the App" limits it to the times the App is open on your screen — and sharing begins only once you have acknowledged that notice and answered the system prompt. You can switch it off again at any time from the same screen, and off means off — while the toggle is off the App does not store your live position or share it with your partner (apart from the Memories camera and the map screen, as described in Section 1), and it will not do so even if your partner sends a refresh request or you simply reopen the App. One thing to be aware of: the last position you shared before switching off remains stored and stays visible to your partner, clearly marked as a last-known position with the time it was recorded, until you share again or delete your account. We keep only that single most recent position — we do not build a location history.

Answers to the Question of the Day are revealed only once you have both answered; until then your partner cannot read yours, and you cannot read theirs.

Any nickname you give your partner is stored only on your own device and is never shared with them or uploaded to our servers. Messages and media you send are delivered exclusively to your paired partner. No other users can access your pair's data.

↑ Back to top

05

Analytics and Crash Reporting

The App includes two Google Firebase components: Crashlytics, which reports crashes, and Google Analytics for Firebase, which counts a small number of product milestones. Both are limited on purpose, and neither can be connected to the content of your messages.

Crash Reporting (Firebase Crashlytics)

When the App crashes or hits an unexpected error, we receive a technical report containing the stack trace, the device model, the operating system version, and the App version. We use these reports only to find and fix faults. We do not attach your name, phone number, user identifier, or any message content to crash reports.

Product Analytics (Google Analytics for Firebase)

We record a small, fixed list of milestone events so we can see where the App is working and where people get stuck. These are the only events we write ourselves, and Firebase additionally records its own standard app-lifecycle events (such as first opening the App and the start of a session):

  • An account was created.
  • An invitation was sent.
  • A pair was created.
  • The first kiss was sent from this installation.
  • The first chat message was sent from this installation.
  • The premium screen was shown, and which feature led to it (chosen from a fixed list, such as calendar or map lists).
  • A free trial began.
  • A subscription became active.
  • The daily question was answered.

These events record only that a step happened. They carry no free-form text at all: the App is built so that message content, daily-question answers, nicknames, names, phone numbers, invitation codes, and coordinates cannot be passed into an analytics event. We do not set a user identifier or any user properties, so these events cannot be joined back to you, to your partner, or to your encrypted content. Analytics and crash collection are switched off in development builds.

None of this is used for advertising. We do not run ads, we do not build advertising profiles, and we do not track you across other apps or websites. The App is configured to disable advertising-identifier collection and ad-personalization signals, and it removes the advertising-ID permission that the analytics library would otherwise add on Android. Google processes this data on our behalf as our service provider; Firebase's own handling of it is described in Google's privacy documentation, linked in Section 6.

Where we rely on legitimate interests to keep the App stable and to improve it (see Section 10), you may object to this processing by contacting us at privacy@thekissapp.com.

↑ Back to top

06

Third-Party Services

We integrate the following third-party services to operate the App. Each service receives only the minimum data necessary for its function and cannot access your end-to-end encrypted content. The last entry in this section is not a service provider working for us, but a category of recipient you should know about.

Supabase

Purpose: Backend infrastructure, user authentication, database, and real-time data synchronization.

Data Shared: Account information, pair relationships, encrypted message records, Memories, sticky notes and daily-question answers (their content end-to-end encrypted as described in Section 1), calendar events (their titles, notes and places end-to-end encrypted as described in Section 1), Map Lists, location data, and safety reports.

Privacy Policy: supabase.com/privacy

Cloudflare

Purpose: Encrypted storage of media and files, and relay connectivity for voice and video calls (TURN).

Data Shared: Encrypted media blobs (which Cloudflare cannot decrypt) and call relay traffic. Messages and media you choose to attach to a safety report are held in a separate private store, encrypted by your device so that Cloudflare cannot decrypt them either. Your profile picture is stored on Cloudflare's public avatar storage.

Bot protection at sign-in (Cloudflare Turnstile): when you ask for a sign-in code, the App may run an automated check provided by Cloudflare that tells people apart from automated abuse. For that check Cloudflare receives your network address and technical signals about your device and its browser environment; we and our authentication provider receive only a single-use token saying that the check passed. The check is not used for advertising. It is covered by Cloudflare’s privacy policy and its Turnstile Privacy Addendum.

Privacy Policy: cloudflare.com/privacypolicy

Google Firebase — Cloud Messaging, Crashlytics, and Analytics

Purpose: Delivering push notifications for messages, calls, and reminders; crash reporting; and the limited product analytics described in Section 5.

Data Shared: Device push notification tokens and notification metadata; crash reports with device model, operating system version, and App version; and the fixed milestone events listed in Section 5, together with the automatic parameters Firebase collects with any event, such as an app-instance identifier, device model, operating system, and an approximate region derived from the network address.

What a notification contains: notifications identify the sender by the name saved on your own device (the name in your address book, or a nickname you set); as transmitted, they carry only your partner's phone number as a fallback label, and describe what arrived using a generic indicator — for example "Photo", "Video", "Voice message", "File", "GIF", or "Sticker" — rather than anything you wrote. No user-authored text is ever included in readable form: a text message may travel only as a short excerpt encrypted on the sender's phone with a key that only the two of you hold, which your partner's phone decrypts to show a preview if its own settings allow one, and which the notification service and we cannot read; the caption on a photo or video, voice messages, files, stickers, and daily-question answers all stay encrypted and never reach the notification service at all. A notice that your partner added a calendar entry, pinned a note or created a Map List uses a fixed phrase. A calendar notice sent from version 2.0.4 or later may also carry the entry’s title as a short encrypted excerpt, in the same way as a text message; the text of a note and the name of a Map List are not included at all. The contact name or nickname is substituted for that fallback on your own device, after the notification arrives — the name itself never travels through the notification service. A notice about a safety report you made never says so: it reads only "You have a new account notice," carries no identifiers, and is held back between 22:00 and 07:00 in your own time zone.

Privacy Policy: policies.google.com/privacy · firebase.google.com/support/privacy

RevenueCat

Purpose: Managing in-app subscriptions and premium entitlements across Apple App Store and Google Play Store.

Data Shared: Your account identifier — the same identifier your account carries in our own database, not an anonymous or randomly generated one — together with subscription status, product identifiers, and purchase metadata. It contains no name or phone number, but it is stable and can be linked back to your account by us and by RevenueCat. No payment card or billing details are shared by us.

Privacy Policy: revenuecat.com/privacy

Mapbox

Purpose: Rendering interactive maps, displaying partner locations, and geocoding addresses.

Data Shared: Map viewport coordinates; location search queries — when you search on the map screen, together with your current position so that nearby places come first; and the coordinates the App asks Mapbox to turn into a place name: a point you tap on the map, and the location of a Memory — the one saved in the photo or video or, when you open the camera from Memories, your position at that moment. Apart from these, your precise location is sent to Mapbox only when rendering the map view.

Privacy Policy: mapbox.com/legal/privacy

SMS Delivery (Sign-In Codes)

Providers: Twilio Inc. (worldwide) and D7 Networks (selected countries), with Telegram Gateway as a fallback.

Purpose: Delivering the one-time codes that verify your phone number and sign you in.

Data Shared: Your phone number and the fact that a sign-in code was requested. These providers never see your messages or any other content.

Privacy Policy: twilio.com/legal/privacy · d7networks.com/privacy · telegram.org/privacy

KLIPY

Purpose: GIF search and delivery in chat.

Data Shared: The words you type into the GIF search box, the GIFs you view or pick, your device's country, and basic technical data such as your network address. GIFs are fetched by your device directly from KLIPY's network. We send KLIPY no account identifier, and nothing we send ties a search or a GIF to your account, your partner, or your conversation. KLIPY does see requests coming from your device and may handle them using its own identifiers and your network address, as described in its privacy policy. We never send your messages to KLIPY.

Privacy Policy: KLIPY Privacy Policy

Previously GIPHY: GIF search was provided by GIPHY until September 16, 2026. GIFs sent before that date are still displayed from GIPHY's public content network when you open that part of your conversation, which shares your network address with GIPHY and nothing else (GIPHY Privacy Policy).

Apple and Google Platform Services

Purpose: App distribution, in-app purchase processing, VoIP call delivery (Apple CallKit and PushKit), and device calendar synchronization.

Data Shared: As required by each platform for app operation, purchase processing, and system integration.

Child-Protection Authorities and Law Enforcement

These are not service providers acting for us, but they are recipients you should know about. Where the law requires or permits, material from safety reports — including content a reporter chose to attach — and the associated account data may be disclosed to the National Center for Missing & Exploited Children (United States), the Internet Watch Foundation and the National Crime Agency (United Kingdom), and to police or child-protection authorities, including ones outside your own country.

↑ Back to top

07

Device Permissions

Bini requests the following device permissions. Each is requested when the feature that needs it first runs, and you may revoke any permission at any time through your device settings. Because location sharing is off until you turn it on, the location permission is requested only when you switch sharing on from the map screen — not at sign-in — and the App explains what your phone is about to ask before that prompt appears. Declining it, or leaving sharing switched off, means no location is collected.

  • Camera. To capture photos and videos to send to your partner in chat and to save to Memories.
  • Microphone. To record voice messages and to enable audio during voice and video calls.
  • Photo Library. To select existing photos, videos, and files from your device to share in chat or add to Memories, to create stickers from your own photos, and to save received media to your device.
  • Media Location (Android). To read the location that your camera saved inside a photo, so a Memory can be placed on your shared map. This is read on your device from the photo you chose; we do not scan your photo library.
  • Location (When In Use and Always/Background). To share your location with your partner on the map. Background or "Always" access allows sharing to continue, and to resume after your phone restarts, while the feature is switched on; "While Using the App" limits sharing to the times the App is open on your screen. Location sharing is off until you switch it on from the map screen, and this permission is requested only at that point. You can turn sharing off again at any time, and you can revoke the permission itself in your device settings.
  • Notifications. To deliver push notifications for messages, calls, kisses, streak reminders, and calendar reminders.
  • Calendar. To synchronize shared Pair Calendar events with your device's native calendar application. If you link a calendar on your phone or export to one, the App writes the titles, notes and places of your entries into that calendar, where they are kept by your phone and by that calendar’s provider (for example iCloud or Google) under its own terms.
  • Face ID / Biometrics. To let you lock the App with Face ID, Touch ID or your device’s biometrics. Biometric data is processed entirely on your device by the operating system and is never transmitted to our servers.
  • Bluetooth and Audio Settings. To route call audio to a connected headset or speaker. We do not use Bluetooth to discover nearby people or devices for any other purpose.
  • Display Over Other Apps (Android). To show the full-screen incoming call screen on top of whatever is on your display, and over the lock screen, when your partner calls you. It is used only to present incoming and ongoing calls.
  • Battery Optimization Exemption (Android, optional). To ask Android not to suspend the App while you are actively sharing your location, so sharing is not silently interrupted. You can decline this and location sharing will still work while the App is running.
↑ Back to top

08

Data Storage and Security

We take the security of your data seriously and implement multiple layers of protection:

  • Encryption in Transit. All data transmitted between the App and our servers is encrypted using TLS (Transport Layer Security), and the App refuses unencrypted connections. Voice and video calls use encrypted WebRTC peer-to-peer connections.
  • Encryption at Rest. Message content, chat and Memories media together with their captions and place names, stickers, daily-question answers, the notes on your shared board, and the titles, notes and places of calendar entries and the names of calendar categories (from the point described in Section 1) are stored in end-to-end encrypted form. If you created a recovery key, the backup of your private key that it protects is encrypted on your device before it is stored. Our database and storage providers additionally encrypt the data they store at rest.
  • Row-Level Security. Our database enforces row-level security policies ensuring that each user can only access data belonging to their own pair. No user can access another pair's data through our API.
  • Column-Level Protection of Key Backups. Your encrypted private key backups are additionally restricted at the database level so that they can be read only by your own account, through a dedicated owner-only interface. Your partner cannot fetch them.
  • Restricted Access to Reported Material. Anything you attach to a safety report is encrypted on your own device to keys held only by our safety team, and photos, stickers and voice notes are encrypted to a stricter key than the text of the conversation, so that only the team members holding that key can open them. Each time such an item is retrieved for viewing, that retrieval is recorded.
  • Secure Local Storage. Your encryption keys and your sign-in session are kept on your device in platform-specific secure storage (iOS Keychain / Android Keystore-backed storage).
  • Sign-In Security. You sign in with a one-time code sent to your phone number; the App has no password. Before an irreversible action such as deleting your account, the App asks you to confirm with a fresh code.
  • Bot Protection at Sign-In. Requests for a sign-in code are rate-limited, and may be checked by Cloudflare Turnstile (see Section 6), so that automated abuse cannot be used to send codes.
  • Screenshot Protection. The App asks the operating system to block screenshots and screen recording of the chat and of calls. Other screens, such as the home board and the map, can be captured. It is a deterrent, not a guarantee — another device can always photograph a screen — so treat anything you send as something your partner can keep.

While we implement robust security measures, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to protecting your data using commercially reasonable measures.

↑ Back to top

09

Data Retention

We retain your information for as long as necessary to provide the App's services and fulfill the purposes described in this policy:

  • Account Data. Retained for as long as your account is active. When you delete your account, your profile data, encryption keys and key backups, notification tokens, and subscription records are permanently deleted.
  • Messages, Media, Memories, Sticky Notes, Stickers, and Daily Answers. Their content is stored in encrypted form for as long as both paired accounts exist. When a pair is dissolved, the associated records are deleted; when an account is deleted, the records and stored media files of its current pair are deleted as well. Media files left from a pair that was dissolved earlier remain in storage in encrypted form until we remove them; you can ask us to remove them at any time at privacy@thekissapp.com.
  • Location Data. If you never switch location sharing on, we hold no live position for you. If you do, we store only your single most recent position, which is overwritten each time a new one is recorded — we do not keep a location history. That last position remains stored, and visible to your partner as a last-known position, until you share a newer one or delete your account. Deleting your account removes it. The places attached to your Memories and saved to your Map Lists are kept with them, as described in Section 1.
  • Calendar Events and Map Lists. Retained for as long as the pair exists; the titles, notes and places of calendar entries and the names of calendar categories are kept in encrypted form from the point described in Section 1. They are deleted when the pair is dissolved or the accounts are deleted.
  • Safety Reports. Retained separately from your account, for as long as we may need them to act on the report, to answer an appeal, or to meet a legal or child-protection obligation — including after the pairing is dissolved or an account involved is deleted. Messages and media attached to a report are deleted 90 days after a report is closed without action, and one year after a report is closed with action, unless they are subject to a legal hold or relate to child safety; deletion destroys the keys as well as the files, so what remains cannot be opened by anyone. Material we report to the National Center for Missing & Exploited Children is kept for at least one year from that report and is then destroyed, unless a legal hold or a law-enforcement request requires us to keep it longer. Deleting your account removes your name from a report you filed but does not withdraw the report itself; a reporting system that could be erased by the person reported, or by the reporter under pressure, would not protect anyone.
  • Call Records. Call metadata is retained with your chat history. The technical connection data used to set up a call is deleted automatically on a short cycle after the call ends.
  • Subscription Data. Purchase metadata is retained for the duration of your subscription and a reasonable period thereafter for accounting and dispute resolution purposes.
  • Invitation Codes. A pending invitation code is retained until it is accepted, cancelled by you, or replaced by a new one.
  • Crash Reports and Analytics Events. Held by Google as our processor and deleted automatically at the end of Firebase's retention period for that data.
↑ Back to top

10

Your Rights and Choices

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access. You may request a copy of the personal data we hold about you. Please note that we cannot provide the content of your end-to-end encrypted messages, because we cannot read it — that content is available to you in the App on a device holding your key. The exception is material someone attached to a safety report, of which we may hold a copy. Where answering a request would reveal a safety report about you, the identity of a reporter, or an ongoing investigation, we may withhold that information as the law allows.
  • Correction. You may update your profile information, your phone number (by verifying a new number with a one-time code), date of birth, and other personal details directly within the App's settings.
  • Deletion. You may delete your account at any time from the menu on the App's home screen (or on the pairing screen, if you are not paired), or ask us to delete it for you — see Delete Your Account for the steps. Account deletion permanently removes from our servers your profile, messages, Memories, sticky notes, daily-question answers, stickers, calendar events, saved locations and key backups, together with the stored media files of your current pair; Section 9 explains what is kept and how to ask us to remove media left from an earlier pair.
  • Location Sharing. Location sharing is off unless you turn it on. You may enable it — or disable it again — at any time from the map screen within the App. While it is off, your live position is not stored or shared with your partner, apart from the Memories camera and the map screen described in Section 1; the last position you shared, if any, remains until you share again or delete your account.
  • Recovery Key. You may create a recovery key, or replace an existing one, at any time in the App's settings. Creating a new one immediately invalidates the previous one.
  • Notifications. You may manage or disable push notifications through your device's settings at any time.
  • Permissions. You may revoke any device permission (camera, microphone, location, calendar, photos) through your device's settings. Some features may not function without their required permissions.
  • Subscription. You may manage or cancel your Premium subscription through the Apple App Store or Google Play Store at any time.

To exercise any of these rights, you may use the in-app settings or contact us at the address provided in Section 14.

European Economic Area, United Kingdom, and Switzerland

If you reside in the EEA, UK, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR), including the right to data portability, the right to restrict processing, and the right to object to certain processing activities. Our legal bases for processing your data are: performance of our contract with you (providing the App's services, including messaging, pairing, and subscriptions); your consent (for the device permissions you grant, such as location, camera, photos, notifications, and calendar, and for optional features you switch on); our legitimate interests (keeping the App secure and stable, preventing abuse, and the limited analytics described in Section 5); and compliance with legal obligations. Where we rely on consent, you may withdraw it at any time by turning the feature off or revoking the permission. You also have the right to lodge a complaint with your local data protection authority.

California

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect and how it is used, the right to request deletion of your personal information, and the right not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioral advertising. To exercise your CCPA rights, contact us at the address provided in Section 14.

↑ Back to top

11

Children's Privacy

Bini is intended for users aged 16 and older. We do not knowingly collect personal information from anyone under the age of 16. If you are a parent or guardian and believe that a child under 16 has provided us with personal information, please contact us immediately at the address provided in Section 14, and we will take steps to delete such information from our servers.

In jurisdictions where the applicable minimum age for using this type of service is higher than 16, the App is not intended for use by anyone below that age. The App is not directed to children, and it must never be used to share sexual or intimate content involving anyone under the age of 18.

We explicitly prohibit child sexual abuse and exploitation (CSAE) and child sexual abuse material (CSAM). Our Child Safety Standards set out what is forbidden, how to report it from inside the App or by email, how we respond, and who our child safety point of contact is. Anyone can report a child safety concern to abuse@thekissapp.com.

↑ Back to top

12

International Data Transfers

Your information may be transferred to, stored, and processed in countries other than your country of residence. Our infrastructure providers (Supabase, Cloudflare, Google Firebase, Mapbox, RevenueCat, KLIPY) and our sign-in code providers (Twilio, D7 Networks, Telegram Gateway) operate servers in multiple regions. By using the App, you consent to the transfer of your information to these facilities.

Where required by applicable law, we ensure that appropriate safeguards are in place for international data transfers, including Standard Contractual Clauses approved by the European Commission or other legally recognized transfer mechanisms.

↑ Back to top

13

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you through the App or by other appropriate means before the changes take effect. The "Effective Date" at the top of this policy indicates when it was last revised.

Your continued use of the App after the effective date of a revised policy constitutes your acceptance of the updated terms. We encourage you to review this policy periodically.

↑ Back to top

14

Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

RevuFlex LTD
Email: privacy@thekissapp.com
Report abuse: abuse@thekissapp.com

We will respond to your inquiry as soon as practicable and within the timeframe required by applicable law.

Bini

A private app for one couple. Nobody else can join it. Bini is Latin for “a pair”.

Privacy Policy Terms of Service Child Safety Delete Account Contact

Bini is operated by RevuFlex LTD.

© 2026 RevuFlex LTD. All rights reserved.