Privacy Policy

Last updated: 2026-09-25

This policy explains what Kutla does with your information. It covers the Kutla mobile app and this website, both published by Better Life With Apps.

The short version

1. Your account

Kutla has no email-and-password signup. We do not collect an email address in order to let you use the app. An account is created anonymously from a hash derived from your installation of the app.

Against that account we store:

2. What stays on your device and what you send us

Your kit and your posts stay on your device. Your business logo (and the copy of it the app cleans up on your phone), your contact line, the photos you save in the app, and the posts you finish and export are kept only in the app’s storage on your phone or tablet. The headline, your name, your logo, the contact line, the flag and the “Made with Kutla” signature are placed on the scene on your device. None of this is sent to our servers, so we cannot see it and cannot restore it. When you share a post, it goes through your device’s share sheet to the app and the people you choose.

What a post sends. When you start a post, the app sends us the day, the country, the style and the kind of post, and:

Photos come from your camera or your photo library, only when you pick them. A photo may show you, your family or your child. Uploads are private by default. They are never publicly listed, never used for analytics, and served only through short-lived signed links that expire.

Reminders. If you turn reminders on, we store a reminder profile: your country and the calendar region it belongs to, your time zone, whether your posts are personal or for a business, your sector, the days you muted, and the wording of the notification, which the app writes on your device. We use it to send one reminder three days and one day before a day that applies to you, between 10:00 and 21:00 in your time zone, and we record which reminders were sent so none is sent twice. The country is the one you choose in the app; the app does not ask for location permission and never reads your precise location.

Reports. If you report a post in the app, we keep your reason and any note you add with the post’s record, so that we can review it.

3. AI processing

To make a post, what it sends (section 2) goes to OpenAI, which acts as a processor on our instructions. OpenAI’s image model draws the scene, from your photo when you sent one, and a text-free emblem for the logo-mark tool. OpenAI’s language model writes three captions from the day, its hashtags and the name you gave; your name is never part of the image request. Before anything is sent, the app asks for your permission and names OpenAI; nothing is sent until you allow it. You can withdraw that permission at any time under Settings → Privacy → AI processing.

Under OpenAI’s API terms, data sent through the API is not used to train its models. OpenAI keeps abuse-monitoring logs of image requests for up to 30 days, unless the law requires it to keep them longer, and the captions are requested without asking OpenAI to store them (OpenAI: your data).

The scenes and emblems are stored on our servers for 30 days (section 8), so that the app can fetch them again. The captions are stored with the post’s record. The app keeps its own copy of your posts on your device.

4. Purchases

Kutla sells subscriptions (weekly for personal posts, monthly or yearly for businesses) and one-time credit top-ups through the Apple App Store and Google Play. Purchases are verified through RevenueCat. We store a billing identifier for your account, the state of your subscription, a record of each top-up you bought, your credit balance and the history of credits added and spent.

We never see or store your card number.

5. Diagnostics and analytics

To find crashes, fix problems, deliver notifications and understand how the app is used, we use:

While analytics is on, the app also gives RevenueCat its Firebase Analytics instance ID, so that purchases can be matched to app usage in our own reports. When analytics is off, that link is cleared. Your analytics choice is stored only on your device.

In-app feedback (Wiredash)

The feedback form in the app is provided by Wiredash. Each time the app starts, at most once every 30 minutes, it checks in with Wiredash, whether or not you ever send feedback. The check-in carries a random identifier that Wiredash’s code creates on your device, the app’s version, build number and build commit, its bundle ID, whether it is a production or development build, your device’s language setting, and your operating system and its version. The first time it runs, it also sends a one-off first-launch event. None of this includes your user ID, your photos or anything you have written. For this data, Wiredash’s documentation says it works out your country from the connection’s IP address and does not store the address (Wiredash: analytics privacy). We rely on our legitimate interest in operating the feedback form (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).

When you choose Send feedback in the app’s settings, the app sends Wiredash your message, your email address if you enter one, and a screenshot if you add one. You can draw on the screenshot before sending it; it shows whatever is on the screen at that moment, including a photo, a post or your business details if they are on screen. With your feedback go device and app details (platform, operating-system version, device model, screen size, language setting, and the app’s version and build) and details we add so that we can follow up: your user ID, the app’s name, whether it is the production or development version, your subscription status and, when the app has already loaded it, your credit balance. We read your feedback in Wiredash to answer it and to fix the app. We do this at your request and in our legitimate interest in improving the app (GDPR Art. 6(1)(b) and (f); KVKK Art. 5(2)(c) and (f)).

6. Where your data is stored

Our backend runs on a server we rent from Hetzner in Helsinki, Finland, inside the EU. The PostgreSQL database, the Redis queue and the private MinIO object storage that holds the photos you sent and the scenes made for you all run on that server. Your logo, contact line, saved photos and finished posts are not stored there; they stay on your device.

Feedback you send from the app, and the feedback form’s check-ins, are kept by Wiredash, not on our servers. Wiredash GmbH is based in Germany, but its privacy policy says that data may be transferred to the United States, processed there and stored on Google Cloud servers (Wiredash: privacy policy).

7. Who your data reaches

Besides the infrastructure above, your data reaches only the service providers we need to run Kutla:

ProviderWhat it is used for
OpenAIDrawing the scene of a post, from your photo when you choose to put its people in the scene; drawing logo emblems; writing captions from the day and the name you gave
HetznerHosting our servers, database, queue and object storage in Finland (EU)
Apple App Store, Google PlaySelling and billing subscriptions and credit top-ups; delivering notifications to your device
RevenueCatVerifying purchases and subscription state, reporting them to our servers, and handling store refunds
Google FirebaseAnalytics, crash reporting, post and reminder notifications through Firebase Cloud Messaging, remote configuration, and App Check device attestation that keeps the backend reachable only from a genuine copy of the app
WiredashThe in-app feedback form: its check-ins and the feedback you send (Wiredash GmbH, based in Germany; according to its privacy policy, data is stored on Google Cloud and may be transferred to the United States)
SentryError reports from our servers

We do not sell personal information, we show no ads, and we do not share personal information for cross-context behavioural advertising.

8. How long we keep things

9. Deleting your account

You can delete your account at any time in the app, under Settings → Your data → Delete my data. This also clears your logo, contact line, saved photos and posts that the app keeps on your device, and erases your reminder profile. If you can no longer open the app, write to privacy@blwapps.com; the deletion page explains what to include. Deleting revokes your access immediately and queues a deletion request. After a short safety delay, the stored photos and scenes, the inputs and captions of your posts, push tokens, consent records and billing identity attached to your account are removed. What remains is a non-identifying tombstone record, the audit evidence that the deletion happened, records of your posts and files without the inputs, the captions or the files themselves, your purchase and credit records, and database backups for about two weeks. A documented legal hold can pause a deletion.

Full instructions, including what to do if you have already uninstalled the app, are on the account and data deletion page.

10. Your rights

Under the GDPR and the Turkish personal data protection law (KVKK), you can ask us to give you access to your personal data, correct it, erase it, restrict how we process it, hand it over in a portable form, or stop processing it altogether. Under the CCPA, we do not sell or share personal information.

To exercise any of these, write to privacy@blwapps.com. Because we do not ask for your email address when you use the app, please read the deletion page first — it explains what we need in order to find your record.

11. Children and photos of other people

Kutla is meant for adults and is not directed at children. We do not knowingly create accounts for children under 13, or under 16 in the European Economic Area.

A parent may add a photo of their own child, or a family photo, to make a post for a special day. Such a photo is handled like any other photo you send: it is used only to make that post, sent to OpenAI only when you choose to put the people in it into the scene, never used for analytics or to train AI models, and deleted from our servers within 30 days (section 8). Only add a photo of a child if you are their parent or guardian, and only add photos of other people who agree to it. If you believe a photo of your child was sent without your agreement, write to privacy@blwapps.com and we will help delete it.

12. This website

This website is a set of static pages. It sets no cookies, runs no analytics or tracking scripts, and loads nothing from other websites. It is served from the same server in Helsinki as our backend.

When someone shares the app from its settings, the link they send opens this website’s /get page and carries a ref tag naming where the link came from, such as app_share. The page sends you on to the App Store, Google Play or this website’s home page and passes the tag along. When /get is opened, our server records only the time, the website, the page address with its tag, and whether the page loaded: no IP address, no cookies, no device identifiers. We use these records to count how many visits share links bring. The App Store and Google Play may count installs that came through the tag in the statistics they give us.

13. Changes to this policy

When the app changes in a way that affects this policy, we update this page and change the date at the top.

14. Contact

Privacy questions and requests: privacy@blwapps.com
Everything else: support@blwapps.com