Privacy Policy for Kantara
Effective 26 May 2025 · Last updated 25 June 2026
This Privacy Policy explains how Kantara Limited ("Kantara", "we", "our", or "us") collects, uses, discloses, and protects your personal data when you use Simone, our AI parenting guide on WhatsApp or other channels, in compliance with the Personal Data (Privacy) Ordinance (Cap. 486) ("PDPO") of Hong Kong.
By using Simone or our related services, you acknowledge that you have read and understand this Privacy Policy. Questions, comments, or concerns? Please reach out: info@kantara.life
Our Privacy Commitments
- Your conversations with Simone are private. The content of your conversations is not shared with third parties, except to provide our Services, improve our Services, or as required by law.
- We never sell your personal data. We do not sell, rent, or trade your personal data to advertisers or any third parties.
- You control your personal data. Request to access it, correct it, or delete it whenever you want.
- We collect personal data only for specific purposes, and we are transparent about why we need each type of data.
- We are upfront about who can see your data and why. Some technical service providers process data to help make Simone work.
1. Scope of this Privacy Policy
This Privacy Policy applies to all interactions with Simone across WhatsApp, our website (www.kantara.life), and other official channels operated by Kantara Limited. It covers personal data collected through text messages, images, and user interactions associated with Simone's AI services.
You decide how much or how little you are comfortable sharing. If you do not provide us with certain personal data, some of the Services may not work as intended.
2. Key Definitions
- Personal Data — information relating to you as a living individual from which you can be identified.
- Data Subject — you, the individual whose personal data we collect and process.
- Data User — Kantara Limited, which controls the collection, holding, processing, and use of your personal data.
- Data Processor — third-party service providers who process personal data on our behalf (such as cloud service providers and AI processing services).
3. Personal Data We Collect
3.1 Account Data. Your WhatsApp number (stored as an anonymized salted SHA-256 hash only); optional details such as your name, email address, or child's age range; time zone; what you'd like Simone to call you; and any personal identifiers you voluntarily provide. Used to provide and improve our Services, for identification and authentication, to address malicious use, and to uphold your preferences.
3.2 Conversational Data. Your interactions with Simone, message timestamps and frequency, and language patterns (spam detection only). Technical data includes message content cached temporarily in Redis (15 minutes), spam detection logs (60 seconds), and message processing queues (5 minutes). Used to deliver personalized guidance, improve our Services, and maintain conversation continuity.
Medical Information (Optional). If you voluntarily share medical information (such as allergies, medications, special needs, or disabilities), we store it encrypted in your profile, include it in conversations transmitted to our AI chat provider (via the DeepSeek API using the DeepSeek v4 model), and use it for more personalized responses. Sharing it is entirely optional; by sharing it, you explicitly consent to this processing. Please note that, as described in Section 14.1, content sent through the DeepSeek API may be received by the AI model provider to provide and improve its services.
3.3 Images You Upload. Photos you send for informational suggestions and basic technical metadata. EXIF metadata (including location) is removed wherever technically feasible. See Section 5.
3.4 Communications with Us. Email address (if you contact us), platform and OS version, any personal data in support requests, and attachments. Used to provide support, respond to inquiries, improve our Services, and (with consent) invite you to user research.
3.5 Hardware Diagnostic and System Information. OS, hardware, and browser version, crash reports and error logs, and device identifiers required for functionality.
3.6 Usage Data. Internal analytics, usage patterns, log files, device and browser type, language, IP address, and (website only) cookies, pixel tags, and web beacons.
3.7 Feedback and Survey Data (Optional). Ratings, preferences, and survey responses.
We do not require or encourage submission of sensitive personal information. If you voluntarily provide it, it is protected as described here, but Simone does not provide professional medical, legal, or financial advice.
4. Purpose and Lawfulness of Collection (DPP1)
Personal data is collected only for lawful purposes directly related to Simone's functions — necessary, adequate, but not excessive — for:
- Service Delivery — to deliver, personalize, and improve AI-driven parenting guidance.
- Communication Management — to manage communications and respond to inquiries.
- Security and Abuse Prevention — to detect and prevent misuse, spam, or threats.
- System Maintenance — to maintain and improve our technical systems.
- Legal Compliance — to comply with lawful requests or regulatory obligations.
- Research and Improvement — using only aggregated, non-identifiable data.
- Direct Marketing — only with your prior express and voluntary consent (see Section 8).
4.1 How Collection Works. Conversations happen naturally; there is no sign-up. You control what you share, and Simone will never pressure you, require personal details to function, or penalize you for keeping things private.
4.2 What We Collect Through Simone. Your messages (encrypted); images you send (stored up to 30 days for conversational context); your hashed phone number; and technical data. We do not collect your WhatsApp profile information, contact list, location (unless you mention it), or anything beyond what you voluntarily share.
5. Image Data and Processing
5.1 Consent and Purpose. By sending an image, you consent to its temporary collection and processing solely to generate automated, non-medical informational responses. Simone does not provide professional medical advice.
5.2 Processing and Transmission. When you send an image, it is temporarily transmitted to the Google Gemini API over encrypted connections (HTTPS/TLS). Gemini both analyzes the image and generates the informational response directly — the image and its contents are never forwarded to our chat provider (DeepSeek), and no second AI model receives the image. We receive only Gemini's text-based result, not copies of your images.
5.3 How Long We Keep Images. In our systems: held in memory only during analysis (1–5 minutes) then deleted; we store image metadata but not the images; image URLs are purged after 7 days; deletions are logged. On Twilio's servers: stored up to 7 days then auto-deleted. With Google: processed to generate results, not used to improve models without permission, with logs typically retained up to 30 days for debugging.
5.4 Maximum Retention Guarantee. In no case will images be accessible by or through Simone's systems after seven (7) days from upload. Enforced via a daily deletion job (3:00 AM UTC), a daily compliance audit (6:00 AM UTC), automatic alerts, and manual deletion on request.
5.5 What We Cannot Control. Google's internal retention, WhatsApp's transmission handling, and images stored on your own device.
5.6 Security and Metadata Handling. Secure transmission (HTTPS/TLS), EXIF metadata removed where feasible, processing tied to your hashed identifier only, and restricted access.
5.7 Your Rights for Image Data. Request immediate deletion by messaging Simone ("Delete my images") or emailing info@kantara.life. We delete URLs from our database immediately and from Twilio within 24 hours. We cannot delete images already processed by Google/WhatsApp under their own terms, or images on your device.
5.8 Third-Party Service Disclosure. Twilio (message delivery; images 7 days, auto-deleted); Google Gemini API (image analysis and response generation; deleted after processing, logs up to 30 days); WhatsApp/Meta (messaging; per WhatsApp's policy).
5.9 Technical Constraints. Deletion may occasionally be delayed by network issues, processing failures (retried automatically), database replication lag, or third-party timelines; we investigate failures within 24 hours.
5.10 Transparency Commitment. We log all deletions, monitor compliance with the 7-day policy, alert on any overage, resolve violations within 48 hours, and provide deletion confirmation on request.
5.11 User-Requested Deletion. Request via message ("delete my images") or email (subject "Delete My Images"). We cannot delete images on your device or those already processed by Google or WhatsApp under their policies.
6. Data Accuracy and Retention (DPP2)
6.1 Accuracy. We take all practicable steps to keep personal data accurate and up to date. You may request correction (see Section 11).
6.2 Retention Periods. Encrypted message data: while you use our Services, up to 30 days after account deletion. Spam detection logs: 60 seconds. Conversation context cache (Redis): 15 minutes. Message processing queues: 5 minutes. Image files (in-memory): 1–5 minutes. Image files (Twilio): max 7 days. Image URLs (database): max 7 days. Account data: while you maintain an account. Anonymized/aggregated data: may be retained indefinitely. Legal/regulatory data: as required by law.
6.3 Deletion Requirements. Once data is no longer required, we securely delete or anonymize it unless erasure is prohibited by law or not in the public interest, consistent with Section 26 of the PDPO.
6.4 Your Deletion Rights. You may request deletion at any time (see Section 11); we comply unless retention is legally required or necessary to protect important interests.
7. Use of Personal Data (DPP3)
7.1 Permitted Uses. We use your data only for the purposes in Section 4, or purposes directly related to them.
7.2 New or Unrelated Uses Prohibited. We will not use your data for any new, unrelated purpose without your express and voluntary consent beforehand.
7.3 Withdrawal of Consent. You may withdraw consent at any time in writing (see Section 20). We will cease the relevant use, though this may affect some services. Withdrawal does not affect prior lawful processing.
8. Direct Marketing (Part 6A of PDPO)
8.1 No Marketing Without Consent. We will not use your data for direct marketing without your prior express consent.
8.2 Information Provided Before Seeking Consent. We will inform you of our intention, that we cannot proceed without consent, the kinds of data used, the classes of products/subjects marketed, your right to opt out free of charge, and how to exercise it.
8.3 Transfer to Third Parties for Direct Marketing. We do not provide personal data to third parties for their direct marketing. If we ever intend to, we will seek separate explicit consent and disclose recipients, subjects, and any gain.
8.4 Your Opt-Out Rights. You may opt out anytime, free of charge, via email unsubscribe links, text instructions, device notification settings, or by contacting info@kantara.life. We action opt-outs within 10 working days.
8.5 Important Service Communications. Transactional messages (policy updates, security alerts, support responses, service announcements) are not direct marketing and are necessary for service delivery.
9. Data Security (DPP4)
We take all practicable steps to protect personal data against unauthorized or accidental access, processing, erasure, loss, or use.
9.1 Technical Safeguards. Stored messages encrypted with Fernet (AES-128 + HMAC); Redis cache (15 min) stored unencrypted for fast retrieval; transit always encrypted (HTTPS/TLS). Phone numbers replaced with irreversible salted SHA-256 hashes; we never store your actual number. Secure infrastructure with segregation and access control, multi-factor authentication, and automated spam detection and vulnerability scanning.
9.2 Organizational Safeguards. Staff training, vendor security assessments, penetration testing and code reviews, and incident response with business continuity, breach notification, and recovery plans.
9.3 Risk Assessment. We assess measures based on data sensitivity, potential harm, storage location, personnel integrity, and current threats.
9.4 Limitation of Liability. No system is completely secure. To the fullest extent permitted by law, we do not accept liability for unauthorized access, use, disclosure, or loss that occurs despite our reasonable security measures.
9.5 Your Role in Security. You also play an important role; see Section 18.
10. Openness and Transparency (DPP5)
This Privacy Policy is our primary means of being open about our data practices. We inform you of the kinds of data we hold, our purposes, our practices, how to exercise rights, and who to contact. It is available at https://www.kantara.life/privacy/, on request, and through Simone, and is updated periodically. We use clear, plain language and may seek renewed consent for significant changes where required by law.
11. Your Rights: Access and Correction (DPP6)
You control your personal data. Under the PDPO you have comprehensive rights, which we honor regardless of where you live.
11.1 Right to Access. Confirm whether we hold data about you; receive a copy (including transcripts and images if retained, account info, and other data); and be informed of purposes and disclosure recipients.
11.2 Right to Correction. Correct inaccurate data, add information where incomplete and misleading, and update outdated information.
11.3 Right to Deletion/Erasure. We honor deletion requests where data is no longer necessary, consent is withdrawn, or data was unlawfully processed, unless prohibited by law. To delete your complete chat history, message Simone: "delete chat history". Warning: this erases all personalization and is irreversible.
11.4 How to Submit Requests. Easy access (transcripts): email info@kantara.life from your address. Formal requests: write to the Data Protection Officer, Kantara Limited, info@kantara.life, with subject "Data Access / Correction / Deletion Request – Simone".
11.5 Our Response Timeline. Acknowledgment within 10 working days; full response to valid access/correction requests within 40 days per the PDPO; extensions for complex requests with notice.
11.6 Information Required. Sufficient information to locate your data, the specific data concerned, and proof of identity.
11.7 Fees. A reasonable fee may apply to access requests (notified in advance); no fee for correction or deletion requests.
11.8 Circumstances for Refusal. We may refuse where the request is frivolous/vexatious, would prejudice legal proceedings, would reveal confidential commercial information, is subject to legal privilege, or where PDPO exemptions apply (see Section 12).
12. Exemptions
Under the PDPO, certain exemptions may apply to the disclosure, use, or retention of personal data. We will only rely on such exemptions where legally permitted and necessary.
13. Disclosure of Personal Data
13.1 No Sale or Trading. We do not sell, rent, or trade your personal data.
13.2 Permitted Disclosures. To service providers/data processors (cloud hosting such as Neon Postgres; AI chat processing via DeepSeek; AI image processing via Google Gemini; messaging such as WhatsApp and Twilio; analytics/monitoring); for legal obligations; for corporate transactions (with equivalent protection and notice); and otherwise only with your express consent.
13.3 De-identified and Aggregated Data. We may create and share non-identifiable statistics, trend analysis, performance metrics, and demographic summaries. We will never share your conversation transcripts with third parties, even de-identified, without your explicit consent.
13.4 What We Do NOT Share. Conversation transcripts (except as needed for AI processing), images (except for temporary processing), identifiable data with advertisers, or data with partner programs (none currently operate).
13.5 Future Partner Programs (Not Currently Active). Any future programs would be optional, require separate agreement, be transparent, never share transcripts without explicit consent, and be governed by the partner's own terms.
14. Third-Party Services and Data Processors
14.1 DeepSeek API and DeepSeek v4 (Chat Processing). Your text conversations are processed by DeepSeek's v4 language models, which we access through the DeepSeek API operated by Hangzhou DeepSeek Artificial Intelligence Co., Ltd. This involves one sub-processor:
- DeepSeek (China) — receives your message text and relevant conversation context, generates responses using DeepSeek v4 models, and returns those responses to us.
Data minimization. Before transmission we replace your phone number with an irreversible salted hash, and we do not transmit your name, email address, or other DeepSeek account identifiers with your messages. Stored chat data is encrypted (Fernet) and all transmission uses encrypted connections (HTTPS/TLS).
How your content may be used. Under DeepSeek's Privacy Policy and Open Platform Terms, DeepSeek may receive the contents of your text interactions in order to provide the API service. DeepSeek's policies describe how inputs and outputs may be processed, retained, and used. Because Simone reaches DeepSeek v4 through the DeepSeek API, the precise training and retention treatment of your content is governed by DeepSeek's applicable terms and API agreements. For this reason we do not represent that your content will never be used to train or improve DeepSeek's models. What we can control, we do: we minimize the data we send, share no account identifiers, encrypt stored data, and honor deletion of the data we hold at any time.
Medical information. Any medical information you choose to share is transmitted to DeepSeek (China) with the relevant conversation and is stored encrypted in your profile. Sharing it is optional and, by sharing it, you explicitly consent to this processing. Because content sent through the DeepSeek API may be used by the model provider as described above, please avoid sharing sensitive information you do not wish to disclose.
Provider policies (please review before sharing sensitive information): DeepSeek Privacy Policy (https://cdn.deepseek.com/policies/en-US/deepseek-privacy-policy.html) and DeepSeek Open Platform Terms of Service (https://cdn.deepseek.com/policies/en-US/deepseek-open-platform-terms-of-service.html).
14.2 Google Gemini API (Image Processing). When you send an image, it is processed by the Google Gemini API over encrypted connections. Gemini analyzes the image and generates the informational response directly; the image and its contents are not forwarded to DeepSeek, and no second AI model receives the image. We receive only Gemini's text output. Images are deleted as soon as processing completes, and metadata is stripped where feasible. Policies: ai.google.dev/gemini-api/terms, cloud.google.com/terms/service-terms, policies.google.com/privacy.
14.3 WhatsApp (Message Delivery). Owned by Meta; messages are end-to-end encrypted in transit between you and our service. WhatsApp's own practices are governed by its terms and privacy policy.
14.4 Twilio (WhatsApp Messaging Infrastructure). Processes message content, hashed phone number, and metadata; may temporarily store content (including images) up to 7 days then auto-delete. Twilio does not use your content for its own purposes and maintains SOC 2 Type II and ISO 27001 programs; infrastructure spans the US, Europe, and Asia-Pacific. Policies: twilio.com/legal/privacy, /tos, /data-protection-addendum.
14.5 Neon Postgres (Database Hosting). Hosts your encrypted conversation data, hashed phone numbers, metadata, and logs. Data is encrypted at rest (Fernet) before storage, connections use SSL/TLS, and Neon (SOC 2 Type II) cannot read your conversation content due to our encryption. Our database is hosted in Singapore. Policies: neon.tech/privacy-policy, /terms-of-service, /security, /dpa.
14.6 Your Acknowledgment and Control. By using Simone you acknowledge these processors may process your data, that we cannot fully control their independent handling, that you may review their policies, and that you may stop using Simone at any time.
14.7 Limitation of Liability. We cannot guarantee third-party compliance in all circumstances and are not liable for their independent actions outside our contractual relationship or occurring despite reasonable oversight.
14.8 Changes to Third-Party Services. We may change or add providers and will update this policy to reflect material changes.
15. Cookies and Tracking (Website Visitors Only)
15.1 Use of Cookies. Our website uses cookies and similar technologies. We do not use cookies within the Simone WhatsApp service.
15.2 Types of Cookies. Essential (required for functionality), Analytics (e.g., Google Analytics; aggregated and anonymous), Preference (settings and language), and Marketing (only with your explicit consent).
15.3 Your Control Over Cookies. Manage via browser settings (Chrome, Firefox, Safari, Edge). Disabling some cookies may affect functionality.
15.4 Third-Party Cookies. Our site may include third-party cookies (e.g., Wix Analytics or embedded content); we do not control these — review their policies.
15.5 Cookie Policy Updates. Material changes will be reflected here and via our cookie consent banner.
16. Children's Privacy
16.1 Age Restriction. Simone is designed for adults; our Services are not directed to children under 18 (or another age required by local law), and we do not knowingly collect children's data without parental consent. Our providers also restrict use by children; for example, DeepSeek states that its Services are not directed to, and it does not knowingly collect data from, children under 18.
16.2 Parental Awareness. Supervise your child's device usage, be aware of the apps they access, and discuss online privacy and safety.
16.3 If We Learn of Child Data Collection. Contact us immediately; we will verify the report, delete the child's data promptly (unless legally required to keep it), close any associated account, and implement preventive measures.
16.4 No Knowing Collection. If we learn we have collected a child's data in violation of law, we will delete it immediately.
17. International Data Transfers
17.1 Cross-Border Transfers. Your data may be processed outside Hong Kong, including where our cloud infrastructure is located (e.g., Singapore) and where our AI providers operate (including China in the case of DeepSeek, and primarily the United States in the case of Google). These countries may have different data protection laws.
17.2 PDPO Section 33 (Not Yet in Force). Section 33 regulating cross-border transfers is not yet in force, but we proactively protect international transfers.
17.3 Safeguards We Implement. Encryption in transit and at rest, anonymization of identifiers, secure protocols, and selecting processors with strong certifications (e.g., ISO 27001, SOC 2) and appropriate data protection policies.
18. Your Responsibilities
18.1 Safeguard Your Personal Data. Protect your device (strong locks, updates, security software, find-my-device), protect your account (strong unique passwords, no credential sharing, log out of shared devices, beware phishing), and be mindful of sensitive information you share with Simone.
18.2 Report Security Issues. Contact us immediately, change passwords if applicable, and document suspicious activity.
18.3 Review Privacy Practices Regularly. Re-read this policy periodically and review the policies of any third-party sites or apps before sharing data with them.
18.4 Protect Children's Information. Monitor and educate your children, know Simone is for adults, and contact us if your child has used Simone (see Section 16).
18.5 Use Services Appropriately. Do not use Simone for illegal purposes, hack or disrupt it, violate others' privacy, impersonate others, or upload malicious code. Misuse may result in suspension, reporting, or legal action.
18.6 Keep Your Information Current. Update changed information promptly and contact us for help (see Section 11).
18.7 Understand Limitations. Simone provides general information only and is not a substitute for professional medical, legal, or financial advice; in emergencies contact emergency services. We are not responsible for decisions made on Simone's information, third-party content, or losses from failing to safeguard your device or credentials.
19. Contact Us
19.1 Questions, Comments, or Concerns. Data Protection Officer, Kantara Limited, info@kantara.life, subject "Privacy Question – Simone" or "Data Request – Simone".
19.2 Response Timeline. Acknowledgment within 10 working days; general questions within 10–15 working days; formal data requests within 40 days per the PDPO (see Section 11).
19.3 What to Include. Your name, contact information, a clear description of your request, relevant details, and identity verification information for data requests.
19.4 Security Concerns. Mark urgent security emails "URGENT – Security Issue" with as much detail as possible; we prioritize these.
19.5 Feedback Welcome. We welcome suggestions on improving transparency and protecting your privacy.
20. Updates to This Policy
We may update this policy to reflect changes in practices, law, technology, feedback, new features, or third-party services. For material changes we update the "Last Updated" date and notify you via Simone, email, prominent website notice, or push notification, and may seek renewed consent where required. Changes typically take effect with at least 14 days' notice for material changes; non-material changes may take effect on posting. The current version is always available at https://www.kantara.life/privacy/. Continued use after changes constitutes acceptance; if you disagree, you may stop using Simone and request deletion. Archived versions are available on request.
21. Summary of Our Privacy Commitment
Your privacy and trust are fundamental to Simone. We are committed to: Transparency — clear explanation of what we collect and why; Purpose Limitation — using data only for stated, legitimate purposes; Data Minimization — collecting only what is necessary; Security — strong encryption (AES-128 for stored data), anonymization, access controls, and regular testing; Retention Limits — keeping data only as long as needed with secure, automatic deletion; Your Rights — honoring access, correction, and deletion, free of charge for most requests; No Sale of Data — never selling your data or sharing it with advertisers; Control and Consent — you decide what to share, with clear consent and easy opt-outs; and Accountability — investigating complaints and continuously improving.
By using Simone, you acknowledge that you have read and understood this Privacy Policy. Questions or concerns? Contact us at info@kantara.life.