Privacy Policy
Last updated: 2026-09-25
This policy explains what Kutla does with your information. It covers the Kutla mobile app and this website, both published by Better Life With Apps.
The short version
- There is no signup. We do not ask for your email address, and a name is only ever the one you choose to put in a post’s captions.
- Your logo, your contact line, the photos saved in the app and your finished posts stay on your phone or tablet. They are never sent to our servers.
- A photo of people, including a photo of your child, leaves your device only when you ask for the people in it to be put into the scene. It is sent to OpenAI, which makes the image on our instructions and does not use it to train its models, and it is deleted from our servers within 30 days.
- For reminders we keep your country and time zone, never your precise location.
- Everything we store sits on a server we rent from Hetzner in Helsinki, Finland, inside the EU.
- You can have your account and your data deleted at any time — see how to delete your account.
1. Your account
Kutla has no email-and-password signup. We do not collect an email address in order to let you use the app. An account is created anonymously from a hash derived from your installation of the app.
Against that account we store:
- a randomly generated user identifier (UUID);
- the installation hash the account was created from;
- your platform (iOS or Android), the app version, and your device’s language and region setting (for example
en-US); - session tokens that keep you signed in on that installation;
- if you allow notifications, the push token that lets us tell you when a post is ready and remind you before a special day.
2. What stays on your device and what you send us
Your kit and your posts stay on your device. Your business logo (and the copy of it the app cleans up on your phone), your contact line, the photos you save in the app, and the posts you finish and export are kept only in the app’s storage on your phone or tablet. The headline, your name, your logo, the contact line, the flag and the “Made with Kutla” signature are placed on the scene on your device. None of this is sent to our servers, so we cannot see it and cannot restore it. When you share a post, it goes through your device’s share sheet to the app and the people you choose.
What a post sends. When you start a post, the app sends us the day, the country, the style and the kind of post, and:
- for a personal post, who is in it (you, a child, your family or a couple), the name you want in the captions if you gave one, and, only when you choose to put the people in your photo into the scene, that photo. If you keep your photo as it is, the app frames it on your device and does not upload it;
- for a business post, your sector, one to three brand colours and, if you gave one, your business name for the captions;
- for the logo-mark tool, your sector, your brand colours and the mark style you picked.
Photos come from your camera or your photo library, only when you pick them. A photo may show you, your family or your child. Uploads are private by default. They are never publicly listed, never used for analytics, and served only through short-lived signed links that expire.
Reminders. If you turn reminders on, we store a reminder profile: your country and the calendar region it belongs to, your time zone, whether your posts are personal or for a business, your sector, the days you muted, and the wording of the notification, which the app writes on your device. We use it to send one reminder three days and one day before a day that applies to you, between 10:00 and 21:00 in your time zone, and we record which reminders were sent so none is sent twice. The country is the one you choose in the app; the app does not ask for location permission and never reads your precise location.
Reports. If you report a post in the app, we keep your reason and any note you add with the post’s record, so that we can review it.
3. AI processing
To make a post, what it sends (section 2) goes to OpenAI, which acts as a processor on our instructions. OpenAI’s image model draws the scene, from your photo when you sent one, and a text-free emblem for the logo-mark tool. OpenAI’s language model writes three captions from the day, its hashtags and the name you gave; your name is never part of the image request. Before anything is sent, the app asks for your permission and names OpenAI; nothing is sent until you allow it. You can withdraw that permission at any time under Settings → Privacy → AI processing.
Under OpenAI’s API terms, data sent through the API is not used to train its models. OpenAI keeps abuse-monitoring logs of image requests for up to 30 days, unless the law requires it to keep them longer, and the captions are requested without asking OpenAI to store them (OpenAI: your data).
The scenes and emblems are stored on our servers for 30 days (section 8), so that the app can fetch them again. The captions are stored with the post’s record. The app keeps its own copy of your posts on your device.
4. Purchases
Kutla sells subscriptions (weekly for personal posts, monthly or yearly for businesses) and one-time credit top-ups through the Apple App Store and Google Play. Purchases are verified through RevenueCat. We store a billing identifier for your account, the state of your subscription, a record of each top-up you bought, your credit balance and the history of credits added and spent.
We never see or store your card number.
5. Diagnostics and analytics
To find crashes, fix problems, deliver notifications and understand how the app is used, we use:
- Firebase Analytics — how the app is used: screens, onboarding steps, whether your posts are personal or for a business, purchases and a few properties such as which of our apps you are using. The events carry no names, no text you type and none of your photos. Analytics is switched on by default outside the EEA and the UK. In the EEA and the UK it stays off until you allow it; you can change your answer under Settings → Privacy. On Android, while analytics is on, Firebase Analytics also reads the device’s advertising ID. On iPhone it does not, and the app never asks for App Tracking Transparency permission. Google Analytics works out an approximate region and city from the connection’s IP address; the app never asks for your location;
- Firebase Crashlytics — crash reports, without your user ID;
- Firebase Cloud Messaging — delivering the notification that a post is ready and the special-day reminders, if you allow notifications. The push token it issues is stored with your account (section 1);
- Firebase Remote Config — remote configuration of the app;
- Firebase App Check — checks that requests to our servers come from a genuine copy of the app on a genuine device;
- Sentry — error reports from our servers, without your photos, names or post details.
While analytics is on, the app also gives RevenueCat its Firebase Analytics instance ID, so that purchases can be matched to app usage in our own reports. When analytics is off, that link is cleared. Your analytics choice is stored only on your device.
In-app feedback (Wiredash)
The feedback form in the app is provided by Wiredash. Each time the app starts, at most once every 30 minutes, it checks in with Wiredash, whether or not you ever send feedback. The check-in carries a random identifier that Wiredash’s code creates on your device, the app’s version, build number and build commit, its bundle ID, whether it is a production or development build, your device’s language setting, and your operating system and its version. The first time it runs, it also sends a one-off first-launch event. None of this includes your user ID, your photos or anything you have written. For this data, Wiredash’s documentation says it works out your country from the connection’s IP address and does not store the address (Wiredash: analytics privacy). We rely on our legitimate interest in operating the feedback form (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
When you choose Send feedback in the app’s settings, the app sends Wiredash your message, your email address if you enter one, and a screenshot if you add one. You can draw on the screenshot before sending it; it shows whatever is on the screen at that moment, including a photo, a post or your business details if they are on screen. With your feedback go device and app details (platform, operating-system version, device model, screen size, language setting, and the app’s version and build) and details we add so that we can follow up: your user ID, the app’s name, whether it is the production or development version, your subscription status and, when the app has already loaded it, your credit balance. We read your feedback in Wiredash to answer it and to fix the app. We do this at your request and in our legitimate interest in improving the app (GDPR Art. 6(1)(b) and (f); KVKK Art. 5(2)(c) and (f)).
6. Where your data is stored
Our backend runs on a server we rent from Hetzner in Helsinki, Finland, inside the EU. The PostgreSQL database, the Redis queue and the private MinIO object storage that holds the photos you sent and the scenes made for you all run on that server. Your logo, contact line, saved photos and finished posts are not stored there; they stay on your device.
Feedback you send from the app, and the feedback form’s check-ins, are kept by Wiredash, not on our servers. Wiredash GmbH is based in Germany, but its privacy policy says that data may be transferred to the United States, processed there and stored on Google Cloud servers (Wiredash: privacy policy).
7. Who your data reaches
Besides the infrastructure above, your data reaches only the service providers we need to run Kutla:
| Provider | What it is used for |
|---|---|
| OpenAI | Drawing the scene of a post, from your photo when you choose to put its people in the scene; drawing logo emblems; writing captions from the day and the name you gave |
| Hetzner | Hosting our servers, database, queue and object storage in Finland (EU) |
| Apple App Store, Google Play | Selling and billing subscriptions and credit top-ups; delivering notifications to your device |
| RevenueCat | Verifying purchases and subscription state, reporting them to our servers, and handling store refunds |
| Google Firebase | Analytics, crash reporting, post and reminder notifications through Firebase Cloud Messaging, remote configuration, and App Check device attestation that keeps the backend reachable only from a genuine copy of the app |
| Wiredash | The in-app feedback form: its check-ins and the feedback you send (Wiredash GmbH, based in Germany; according to its privacy policy, data is stored on Google Cloud and may be transferred to the United States) |
| Sentry | Error reports from our servers |
We do not sell personal information, we show no ads, and we do not share personal information for cross-context behavioural advertising.
8. How long we keep things
- A photo you sent is kept until the newest post that uses it expires, 30 days after that post was started, and is then deleted from our storage. A photo that no post uses is deleted after 24 hours.
- The scenes and emblems made for you are kept for 30 days after the post was started, and are then deleted from our storage. The posts the app saved stay on your device.
- The choices behind a post (day, country, style, who is in it, sector, brand colours, mark style), the name you gave for the captions and the captions themselves stay in the record of that post for as long as your account exists. They are removed when you delete your account.
- Your reminder profile is kept while reminders are on. Turning reminders off or deleting your account erases it, together with the record of reminders sent.
- Your push token is kept until you turn notifications off, the token stops working, or you delete your account.
- A report you make is kept with the reported post’s record.
- Your account record is kept for as long as the account exists.
- Purchase and credit records are kept after you delete your account, so that refunds and store disputes can still be settled. RevenueCat keeps its own record of your purchases.
- Your logo, contact line, saved photos and finished posts are never on our servers. They stay on your device until you remove them, clear the app’s data, uninstall the app or use Delete my data.
- Crash reports are kept by Firebase Crashlytics for 90 days.
- Feedback you send stays at Wiredash until it is deleted there. Deleting your account does not remove it; write to us if you want it removed.
- Records of visits to this website’s
/getpage contain no IP address or identifier; the oldest file is deleted as the record grows.
9. Deleting your account
You can delete your account at any time in the app, under Settings → Your data → Delete my data. This also clears your logo, contact line, saved photos and posts that the app keeps on your device, and erases your reminder profile. If you can no longer open the app, write to privacy@blwapps.com; the deletion page explains what to include. Deleting revokes your access immediately and queues a deletion request. After a short safety delay, the stored photos and scenes, the inputs and captions of your posts, push tokens, consent records and billing identity attached to your account are removed. What remains is a non-identifying tombstone record, the audit evidence that the deletion happened, records of your posts and files without the inputs, the captions or the files themselves, your purchase and credit records, and database backups for about two weeks. A documented legal hold can pause a deletion.
Full instructions, including what to do if you have already uninstalled the app, are on the account and data deletion page.
10. Your rights
Under the GDPR and the Turkish personal data protection law (KVKK), you can ask us to give you access to your personal data, correct it, erase it, restrict how we process it, hand it over in a portable form, or stop processing it altogether. Under the CCPA, we do not sell or share personal information.
To exercise any of these, write to privacy@blwapps.com. Because we do not ask for your email address when you use the app, please read the deletion page first — it explains what we need in order to find your record.
11. Children and photos of other people
Kutla is meant for adults and is not directed at children. We do not knowingly create accounts for children under 13, or under 16 in the European Economic Area.
A parent may add a photo of their own child, or a family photo, to make a post for a special day. Such a photo is handled like any other photo you send: it is used only to make that post, sent to OpenAI only when you choose to put the people in it into the scene, never used for analytics or to train AI models, and deleted from our servers within 30 days (section 8). Only add a photo of a child if you are their parent or guardian, and only add photos of other people who agree to it. If you believe a photo of your child was sent without your agreement, write to privacy@blwapps.com and we will help delete it.
12. This website
This website is a set of static pages. It sets no cookies, runs no analytics or tracking scripts, and loads nothing from other websites. It is served from the same server in Helsinki as our backend.
When someone shares the app from its settings, the link they send opens this website’s /get page and carries a ref tag naming where the link came from, such as app_share. The page sends you on to the App Store, Google Play or this website’s home page and passes the tag along. When /get is opened, our server records only the time, the website, the page address with its tag, and whether the page loaded: no IP address, no cookies, no device identifiers. We use these records to count how many visits share links bring. The App Store and Google Play may count installs that came through the tag in the statistics they give us.
13. Changes to this policy
When the app changes in a way that affects this policy, we update this page and change the date at the top.
14. Contact
Privacy questions and requests: privacy@blwapps.com
Everything else: support@blwapps.com