Privacy Policy
Last updated: September 2026
1. Who We Are
Khema is an AI-based chat app for smoking cessation. The app guides you through structured sessions to help you quit smoking.
Data Controller:
Khema (in formation), operated by its founders Julian Laue, Gabriel Zerbe and Vanessa Kropp
c/o Online-Impressum.de #4533
Europaring 90
53757 Sankt Augustin
Germany
Contact for privacy matters: datenschutz@khema.ai
2. Overview
This Privacy Policy explains what personal data we collect, why we process it, and what rights you have. It applies to the Khema mobile app (iOS and Android) and the Khema website.
Khema processes health data — specifically data related to your smoking behavior, nicotine dependence, and cessation progress. Health data is a special category of personal data under Art. 9 GDPR and receives additional protection. We will never process your health data without your explicit consent.
Because Khema is a smoking cessation service, we recognize that even operational data — such as your account existence, session activity, and program progress — reveals health-related information in context. The fact that you have a Khema account inherently indicates that you are seeking support for smoking cessation. All personal data processed within Khema is therefore treated as health data under Art. 9 GDPR.
Consent before account creation: Before you can create a Khema account, we ask for your explicit consent to the processing of your health data under Art. 9(2)(a) GDPR. This consent covers all processing activities described in this policy that involve data linked to your account. Without this consent, we cannot create your account or provide the service, because the service inherently requires the processing of health data — this is not an artificial restriction but reflects the nature of a smoking cessation service.
Unless stated otherwise, all processing activities described below that involve data linked to your account rely on Art. 9(2)(a) GDPR (explicit consent for health data) in conjunction with the applicable Art. 6 basis specified in each section. Technical data that is not linked to your account or health/session content is treated separately under Section 3.4; where technical or audit logs are linked to your account, we apply the same health-context safeguards.
We do not sell your data. We do not share your data with advertisers. The core processing of the Khema service takes place within the European Union; limited exceptions are described in Section 5.1.
3. What Data We Collect
3.1 Account Data
When you create or use a Khema account, we process account and profile data needed for registration, sign-in, account management, age verification and access security. This includes in particular:
- Email address and sign-in data — including hashed and salted password data, email verification and password resets
- Profile information — such as first name, last name, date of birth and optional profile picture
- Account status and security data — such as account IDs, sign-in status, session and security events
- Consent records — such as when you accepted the Terms, Privacy Policy, health-data processing or optional emails
- Additional authentication methods — such as phone number or authentication data if you use SMS-2FA, TOTP, WebAuthn or passwordless sign-in
If you sign up using a social login provider (Google, Apple, or Microsoft), we receive limited account and profile information from that provider through our authentication system (see Section 6).
Legal basis: Explicit consent, Art. 9(2)(a) GDPR, in conjunction with contract performance, Art. 6(1)(b) GDPR. As described in Section 2, your account existence in a smoking cessation service constitutes health-related information.
3.2 Health Data
To provide our smoking cessation service, we process health data that you share with the app. This includes:
- Session conversation content — the messages you send and the AI responses you receive during sessions
- Nicotine dependence assessments — your responses to standardized questionnaires used to personalize the program
- Craving tracking data — information you log about your cravings, such as intensity, context, and how you responded
- Smoking cessation progress — your smoke-free status, quit attempts, and related milestones
- AI-generated session summaries — recaps of your sessions, shown to you in the app
We only process the health data you choose to share with the app.
Legal basis: Explicit consent, Art. 9(2)(a) GDPR, in conjunction with contract performance, Art. 6(1)(b) GDPR.
3.3 Usage and Behavioral Data
To operate the service and understand how the app is used, we collect:
- Session data — session start and end times, duration, session type (regular or craving-support), completion reason
- Program progress — which stage of the program you are in
- Last active timestamp — when you last used the app
- Account creation time
Legal basis: Explicit consent, Art. 9(2)(a) GDPR, in conjunction with contract performance, Art. 6(1)(b) GDPR. This data is necessary to deliver the structured session program and inherently reveals information about your smoking cessation journey.
3.4 Technical Data
When you use the app, our servers automatically collect:
- IP address and technical request metadata — processed for security, routing, abuse prevention and error diagnosis; not used for location tracking
- Application logs — technical telemetry for monitoring system health and diagnosing errors
- Device and app integrity proof — once a day the app checks that it is an unmodified build from the App Store or Google Play running on a device that has not been tampered with (Apple App Attest on iOS, Google Play Integrity on Android). To do this, technical information is read from your device. No content and no health data are processed in this check. For this access to your device we rely on Section 25(2) no. 2 TDDDG, because the proof is necessary to provide the service to you securely. What we store, how long we keep it and what is sent to Google are set out in Sections 5 and 7.1, and the consequences of a negative result in Section 8.
General technical logs do not contain session content and are kept separate from account data where possible. Technical operational and security-detection logs, including request, error, crash, rate-limit, brute-force, blocked-access and infrastructure security alerts, are kept for 30 days. Separate audit and accountability logs may be linked to your account where this is necessary to evidence account access, access control, consents, deletion, exports, data-rights handling or administrative actions; these audit logs are kept for up to 3 years. Access and event logs are deleted when you delete your account; records evidencing account deletion, data reset and automatically detected relapses are kept immutably for 3 years (details in Section 7.2); administrative events are kept for 360 days. They are stored on our own EU-based infrastructure.
Legal basis: Legitimate interest, Art. 6(1)(f) GDPR. Our legitimate interest is ensuring the security and stability of the service.
3.5 AI-Generated and AI-Related Data
Operating the AI-led sessions produces additional data that we store. This includes:
- Internal summaries — structured summaries used primarily by the AI to maintain context across sessions, and by our quality assurance team for quality review (not visible to you)
- Personalization data — key themes, milestones, or motivational insights extracted from your conversations, used to improve future sessions
- AI monitoring logs — records of your AI interactions from our self-hosted AI monitoring system. They comprise the full prompt sent to the AI including conversation history and the full AI response (both contain health data), plus request metadata such as user identifiers and timestamps, and operational metrics such as response performance and resource usage. Unlike the general technical logs in Section 3.4, these logs contain session content.
- Evaluation results — scores and flags from the automated safety evaluations (e.g., "safety score: pass"). They are not new conversation content and do not themselves contain health data.
- Quality assurance notes — derived summaries from human quality review
The session summaries shown to you in the app are already listed in Section 3.2. You can always review and correct any AI-derived data shown in the app. If you believe any information is incorrect, you have the right to rectification under Art. 16 GDPR (see Section 9.2).
Sections 4.1, 4.8 and 4.9 describe how and why this data is produced.
Legal basis: For internal summaries and personalization data, explicit consent, Art. 9(2)(a) GDPR, in conjunction with contract performance, Art. 6(1)(b) GDPR; internal summaries are additionally covered by the consent described in Section 4.9. For AI monitoring logs, evaluation results and quality assurance notes, explicit consent, Art. 9(2)(a) GDPR, in conjunction with consent, Art. 6(1)(a) GDPR (see Section 4.9).
4. How and Why We Process Your Data
4.1 To Provide the Smoking Cessation Service Safely
We process your account data, health data, and session data to deliver the core Khema experience: guided sessions for smoking cessation, craving tracking, visualisation, and progress monitoring.
The sessions are delivered by a large language model (LLM). So that the AI can provide personalized, contextually appropriate responses, your profile information (such as your name), your smoking cessation progress and history, the current session's conversation history, and summaries and context from previous sessions are included in the prompt sent to the LLM during a session. AI chat responses are generated with the model Claude Opus 5. We reach this model through Cortecs, a routing service provider that we have configured so that inference runs only on providers established in the European Union. Cortecs performs the inference for this model at Amazon Web Services in Ireland or France, or at Google. Amazon Web Services (AWS), also operating in the EU, provides the failover path for chat responses and runs supporting AI tasks such as session summaries. All of these providers process your data solely for inference, meaning to generate a response to the prompt, and none of them use your data to train their models.
Based on your sessions, the AI generates additional outputs. These include the session summaries shown to you in the app (Section 3.2), as well as the internal summaries and personalization data (Section 3.5) that maintain context across sessions and improve future sessions.
This includes delivering that service in a technically safe and reliable way. Khema supports you in a health-sensitive situation, and a fault in the app or an inappropriate AI response can reach you in a vulnerable moment. We therefore also process your data to detect and fix faults and security issues, to review the quality and safety of the AI guidance, and to develop the session structure and the instructions given to the AI so that the service stays safe for you. Section 4.9 describes how that review works in detail.
For this work we rely on service providers that support us in delivering the service safely. These include hosting and infrastructure providers, providers of AI and speech recognition features, and tools our team uses to document faults and track changes. All of these providers are named in Section 5 and are contractually bound as processors. We do not process your data for advertising purposes and do not share it with advertisers.
Legal basis: Contract performance, Art. 6(1)(b) GDPR; explicit consent, Art. 9(2)(a) GDPR, for health data. Where the processing serves AI quality and safety review, it relies on the separate consent described in Section 4.9.
4.2 To Send You Transactional Emails
We use Google Workspace to send essential emails such as password reset requests and account verification. Only your email address is shared with Google for this purpose — no health data or session content is included in these transmissions.
Legal basis: Explicit consent, Art. 9(2)(a) GDPR, in conjunction with contract performance, Art. 6(1)(b) GDPR. Although the email content itself does not contain health data, your email address is processed in the context of a smoking cessation service.
4.3 To Request Feedback
If you opt in during registration by checking the box reading *"Yes, I'd like to receive occasional emails from Khema, such as tips to help me quit and feedback requests. Optional"*, we will send you occasional requests for feedback about the app. In particular, this includes invitations to a short video call in which you can give us qualitative feedback about your experience with Khema. We do not currently send a regular newsletter.
To decide whom to invite for feedback and to personalise these emails, we use session metadata such as the number of sessions you have completed and the number of messages, and your age from your account data. We do not use session content for this. This data is used internally by us only and is not shared with Google; the emails themselves do not contain health data or session content.
These emails are sent via Google Workspace. You can unsubscribe at any time by contacting us at datenschutz@khema.ai or by clicking the unsubscribe link in any such email. Unsubscribing does not affect your health data consent or your ability to use the service.
Legal basis: Consent, Art. 6(1)(a) GDPR. The decision to receive feedback requests is separate from your health data consent. You can unsubscribe without affecting your account or health data processing.
4.4 To Conduct Research
We share anonymized, aggregated usage statistics with selected research partners to support scientific research into smoking cessation. This data is fully anonymized and can no longer be linked to individual users. It includes only aggregate figures such as overall quit rates, average session counts, or usage patterns across the user base — never individual conversation content or personal details.
Because this data is anonymized in accordance with Recital 26 GDPR, it is no longer considered personal data and GDPR does not apply to its use.
4.5 To Convert Voice Messages to Text (Dictation)
You can optionally dictate chat messages using the microphone instead of typing them. When you use this feature, your audio recording is streamed over TLS through the Khema backend to Microsoft Azure Cognitive Services Speech (Fast Transcription) in the EU. The audio is only passed through and is never stored on Khema infrastructure. The transcript returned to you is shown in the app and is not stored either.
We store only usage metadata for each transcription, such as the audio duration, the character count of the text, timestamps, and error codes. We keep this metadata until you delete your account, to enforce usage limits and for accountability. If you submit the transcript as a chat message, it is then processed like a normal chat message (see Sections 3.2 and 4.1).
Legal basis: Contract performance, Art. 6(1)(b) GDPR; explicit consent, Art. 9(2)(a) GDPR, for health data.
4.6 To Send Push and In-App Notifications
We send you notifications about relevant in-app events, for example a new reply in your session, a gentle reminder about your craving tracking, or reaching a milestone. To do this, the app registers a device push token with our backend. The content of the push messages is deliberately generic and contains no health details, meaning no wording about smoking or cravings. However, the mere visibility of a Khema notification on your lockscreen can already reveal that you use the app, and thereby disclose a health context.
On Android, delivery is handled through Firebase Cloud Messaging (Google, a processor under the Google Cloud Data Processing Addendum; possible processing in the US is covered by the EU-US Data Privacy Framework with Standard Contractual Clauses as a fallback). On iOS, delivery is handled through the Apple Push Notification service (Apple acts here as an independent controller; transfers of EEA personal data to the US are governed by Standard Contractual Clauses according to Apple's privacy policy). We store the in-app notifications in your inbox until you delete your account. Push tokens are deleted on logout, when the provider reports an invalid token, or on account deletion. You can disable notifications at any time in your operating system settings.
Legal basis: Contract performance, Art. 6(1)(b) GDPR; explicit consent, Art. 9(2)(a) GDPR, for health data.
4.7 To Show Your Progress (Metrics Dashboard)
When you open the progress screen in the app, we compute an overview from data you have already provided, such as your smoke-free status, your consumption profile, and your craving entries. It shows, for example, how long you have been smoke-free, your estimated money saved, a statistical estimate of the life-time you have regained (cigarette users only), a body-recovery timeline, and your craving patterns.
These figures are population-level statistical illustrations to support motivation and are not individual medical advice. The displayed values are recomputed each time you open the screen and are not persisted. No new personal data is stored for this feature.
Legal basis: Contract performance, Art. 6(1)(b) GDPR; explicit consent, Art. 9(2)(a) GDPR, for health data.
4.8 To Update Your Progress Automatically (Automated Decision-Making)
Khema uses automated decision-making as defined by Art. 22 GDPR in limited cases. The AI may evaluate session conversations to detect whether certain milestones or status changes occurred — for example, whether you relapsed and agreed to start a new quit attempt. This can trigger automated updates to your progress tracking (such as resetting your smoke-free timer) without human review.
- Significance and consequences: Automated decisions may update your cessation progress data. Your previous progress is recorded in your history.
- Your rights: You have the right to contest any automated decision. If your progress was updated incorrectly, contact us at datenschutz@khema.ai and we will manually review and correct it.
Legal basis: Explicit consent, Art. 9(2)(a) GDPR, in conjunction with contract performance, Art. 6(1)(b) GDPR. Transparency disclosure provided under Art. 13(2)(f) GDPR; substantive rights under Art. 22 GDPR.
4.9 To Monitor AI Quality and Safety
Khema is an AI-driven smoking cessation app. Unlike traditional apps, we must be able to review what the AI said to users and why. Only in this way can we detect harmful, inappropriate, or incorrect AI responses, verify that the AI follows the session structure we designed, ensure the safety and quality of the user experience, and improve the AI's instructions and behavior over time.
To do this, a self-hosted AI monitoring system running on our EU-based infrastructure logs your AI interactions (the AI monitoring logs described in Section 3.5). We use these logs for automated safety evaluations and for human review by our quality assurance team.
Automated safety evaluations. A separate AI model assesses conversations for signs that a user may be in distress or at risk of harm, for inappropriate, harmful, or off-topic AI responses, and for whether the AI followed the intended session structure for each session. These evaluations require processing your session conversations (which contain health data) as input. The evaluation results are scores and flags (see Section 3.5) and do not themselves contain your health data.
Human review by our quality assurance team. A trained member of our team reviews session conversations (both your messages and the AI's responses) for quality assurance, to identify conversations where the AI may have responded inappropriately, and to refine the instructions and prompts that guide the AI's behavior. The conversations selected for review may be chosen based on, among other things, the automated safety evaluations or engagement and disengagement signals. This means that a human will read what you write in your sessions. This team member is bound by confidentiality obligations and a data processing agreement governing access to your health data.
We record notes from this quality review as derived summaries and store them in an access-restricted private repository with GitHub, Inc. Details on the provider and the transfer basis can be found in Section 5.
Retention: AI monitoring logs are retained for as long as the underlying session conversations, meaning until you delete your account. When you delete your account or withdraw your consent to AI quality and safety monitoring, all AI monitoring logs linked to your account are permanently deleted within 30 days. The same deadline applies to the quality assurance notes from human review. We remove them from the GitHub repository within 30 days and also clean up the version history, so that the notes are not retained in earlier states. If you use the "reset my data" feature (see Section 7.2), AI monitoring logs are not deleted; they are only removed by a full account deletion or by withdrawal of consent.
Legal basis: Explicit consent, Art. 9(2)(a) GDPR, in conjunction with consent, Art. 6(1)(a) GDPR. This processing is covered by the explicit consent you provide before account creation, which includes consent to AI quality and safety monitoring.
5. Data Sharing, Third-Party Processors and International Data Transfers
We do not sell your data. We share personal data only with the service providers listed below, who process data on our behalf under data processing agreements in accordance with Art. 28 GDPR.
| Service Provider | Purpose | Data Shared | Location |
|---|---|---|---|
| Microsoft Azure | Infrastructure hosting and speech-to-text (Azure Cognitive Services Speech, EU) | Personal data where required to operate the service; audio in transit for transcription (audio not stored) | EU |
| Cortecs | Routing of LLM inference for AI chat responses (model Claude Opus 5; inference at Amazon Web Services Ireland/France or Google) | Session and context data required to generate AI responses (inference only, no training on your data) | EU (configured to EU data centres only) |
| Amazon Web Services (AWS) | LLM inference (chat failover and supporting AI tasks such as session summaries) | Session and context data required to generate AI responses and summaries | EU |
| Firebase Cloud Messaging (Google) | Push delivery of notifications on Android | Device push token and generic notification payload (no health details) | EU data processing; possible access by Google LLC in the US under the EU-US Data Privacy Framework |
| Google Play Integrity API (Google) | Verification of the app integrity proof on Android | Integrity token issued by Google with the device and app verdict plus a check value derived from the session-key reference and a one-time challenge (no account or health data) | EU data processing; possible access by Google LLC in the US under the EU-US Data Privacy Framework |
| Google Workspace | Transactional and feedback emails | Email address | EU data processing; Google LLC is certified under the EU-US Data Privacy Framework |
| Twilio | Delivery of SMS one-time codes if you enable SMS two-factor authentication | Phone number and SMS delivery metadata. The message body contains the one-time code, its validity period and the name Khema; it contains no information about smoking, cravings or cessation progress | Processing by Twilio Inc. in the US, covered by the EU-US Data Privacy Framework with the Standard Contractual Clauses incorporated in the Twilio Data Protection Addendum as a fallback |
| GitHub, Inc. | Storage of internal quality assurance notes on sessions (Section 4.9) | Derived notes and summaries from quality review | USA; EU-US Data Privacy Framework (European Commission adequacy decision), supplemented by Standard Contractual Clauses under the GitHub Data Protection Agreement |
Self-hosted services (running on our EU-based server cluster, not shared with third parties):
- Authentication system — self-hosted user identity and access management
- AI monitoring system — logging and reviewing AI interactions for safety and quality
- Application logging system — technical monitoring and error diagnosis
Research Partners
We share anonymized, aggregated statistics with selected research partners (see Section 4.4). Because this data is fully anonymized and cannot be linked to individual users, it does not constitute a data transfer of personal data under GDPR.
5.1 International Data Transfers
All personal data is generally stored and processed within the European Union. Our infrastructure runs in the EU.
Limited data may be processed outside the EU in the following cases:
- Google Workspace (email delivery): Your email address may be processed by Google LLC for sending transactional and feedback emails.
- Twilio (SMS two-factor authentication): If you enable SMS two-factor authentication, we process your phone number and the delivery metadata of the one-time code SMS through Twilio. This processing takes place at Twilio Inc. in the United States. Twilio Inc. is certified under the EU-US Data Privacy Framework; the Standard Contractual Clauses incorporated in the Twilio Data Protection Addendum apply in addition. The message body states the one-time code, its validity period and the name Khema, but no information about smoking, cravings or cessation progress. For the connection and billing metadata of the message transmission, Twilio acts as an independent controller and not on our behalf.
- Social login providers (authentication exchange): If you use social login, profile data (email, name, profile picture) may be processed by Google LLC, Apple Inc., or Microsoft Corporation during the authentication exchange (see Section 6.4).
- Firebase Cloud Messaging (push delivery on Android): To deliver push notifications, a device push token and a generic notification payload may be processed by Google LLC in the US. No session content is transferred. Google LLC is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses additionally apply as a fallback under the Google Cloud Data Processing Addendum.
- Apple Push Notification service (push delivery on iOS): Apple Inc. acts as an independent controller for push delivery. Only a device push token and a generic notification payload are transferred, no session content. Transfers of EEA personal data to the US are governed by Standard Contractual Clauses according to Apple's privacy policy.
- Google Play Integrity API (app integrity proof on Android): To verify that the app is an unmodified build from Google Play, the integrity token issued by Google is sent back to Google; it contains no account or health data. Google LLC is certified under the EU-US Data Privacy Framework; Standard Contractual Clauses additionally apply as a fallback under the Google Cloud Data Processing Addendum.
- Apple App Attest (app integrity proof on iOS): The proof is generated on your device by Apple's attestation service; our servers send no data to Apple for this and verify the proof themselves. Apple's privacy policy applies to the on-device service.
- GitHub (internal quality assurance notes): We store derived notes and summaries from human quality review (Section 4.9) in an access-restricted private repository with GitHub, Inc. in the United States (a processor under the GitHub Data Protection Agreement). Full conversation transcripts are not stored there. The transfer is based on the European Commission's adequacy decision of 10 July 2023 on the EU-US Data Privacy Framework, under which GitHub, Inc. is certified; Standard Contractual Clauses apply in addition.
Google LLC, Microsoft Corporation, GitHub, Inc. and Twilio Inc. are certified under the EU-US Data Privacy Framework, providing an adequate level of data protection as recognized by the European Commission under Art. 45 GDPR. Apple international transfers of EEA personal data are governed by Standard Contractual Clauses according to Apple's privacy policy.
The day-to-day operation of the service takes place within the European Union. Your session conversations, your voice recordings when using dictation, and the persistent storage of your data do not leave the EU. Outside the EU, health-related data is processed only when the derived quality assurance notes are stored with GitHub (Section 4.9); limited account and profile data is processed only for optional social login and, if you enable it, for SMS two-factor authentication.
6. Social Login (SSO)
You may create a Khema account using your existing Google, Apple, or Microsoft account. If you choose to do so, the following applies:
6.1 How Social Login Works
All social logins are brokered through our self-hosted authentication system. Khema never communicates directly with Google, Apple, or Microsoft — the authentication system handles the connection.
When you use social login, we receive limited account and profile data from the provider where needed to create, sign in to and manage your account. We do not share session content or smoking cessation information with your social login provider. How the provider processes your authentication request is governed by the provider's own privacy policy (see Section 6.5).
6.2 What Data We Receive and Store
We store only the social-login data needed to create, sign in to and manage your account. What we receive depends on the provider:
- Google: Email address, name, provider identifier and profile picture, where available. Your date of birth may also be processed where used for account features such as age verification.
- Apple: Email address, name and provider identifier. Apple allows you to hide your real email address — if you choose this option, we receive and store an Apple-generated private relay address instead. Apple usually provides your name only on your first sign-in. No profile picture is provided.
- Microsoft: Email address, name, provider identifier and profile picture, where available.
If a provider shares a profile picture, we store it as your account profile picture. You can change or remove it at any time in your account settings.
6.3 Your Choices
It is your choice whether to use social login. You can always sign up with an email address and password instead. You can disconnect your social login at any time by setting a password in your account settings, after which your account will use email and password authentication instead.
6.4 International Data Transfers
The authentication exchange may involve the transfer of profile data (email address, name, profile picture) to servers outside the EU. No session content or smoking cessation information is transferred during this exchange. Google LLC and Microsoft Corporation are certified under the EU-US Data Privacy Framework, providing an adequate level of data protection as recognized by the European Commission under Art. 45 GDPR. Apple international transfers of EEA personal data are governed by Standard Contractual Clauses according to Apple's privacy policy.
6.5 Provider Privacy Policies
The social login providers process your data according to their own privacy policies:
- Google: https://policies.google.com/privacy
- Apple: https://www.apple.com/legal/privacy/
- Microsoft: https://privacy.microsoft.com/privacystatement
Legal basis: Contract performance, Art. 6(1)(b) GDPR, for social-login data needed to create, sign in to and manage your account. Consent, Art. 6(1)(a) GDPR, for optional profile data that is not necessary for the service. Once stored in your Khema account, this data is subject to the legal bases described in Section 3.1, including explicit consent under Art. 9(2)(a) GDPR for health data.
7. Data Retention and Deletion
7.1 Retention Periods
| Data Category | Retention Period |
|---|---|
| Account data (email, name, birth date) | Until you delete your account |
| Health data (conversations, craving data, cessation progress, assessments) | Until you delete your account or reset your data |
| AI-generated outputs (summaries, personalization data) | Until you delete your account or reset your data |
| AI monitoring logs | Until you delete your account or withdraw your consent to AI monitoring (whichever is sooner); deletion completes within 30 days |
| Quality assurance notes from human review (stored with GitHub, see Sections 4.9 and 5.1) | Until you delete your account or withdraw your consent to AI monitoring (whichever is sooner); deletion completes within 30 days, including clean-up of the version history |
| Usage and behavioral data | Until you delete your account |
| Social login link (provider connection) | Until you delete your account or disconnect social login |
| Technical operational and security-detection logs (server, request, error, diagnostic, rate-limit, blocked-access and security-control alert metadata) | 30 days |
| Audit and accountability logs (account-access, access-control, consent, deletion, export, data-rights and admin-action event metadata) | Up to 3 years; access and event logs are deleted on account deletion, immutable records of account deletion, data reset and automatically detected relapses are kept for 3 years, administrative events for 360 days |
| Voice recordings (dictation) | Not stored; streamed transiently only |
| Transcript text | Not stored |
| Transcription usage metadata (audio duration, character count, timestamps, error codes) | Until you delete your account |
| Device push tokens | Until logout, provider bounce for an invalid token, or account deletion, whichever comes first |
| App integrity proof (session-key reference, result, timestamps; on iOS additionally the device's public attestation key) | Valid for 24 hours; deleted 7 days after expiry; not linked to your account |
| In-app notification inbox | Until you delete your account |
| Anonymized aggregated technical metrics | Indefinitely, if they can no longer be linked to an identifiable person |
| Consent record for optional feedback emails | Until you withdraw consent or delete your account |
7.2 Deleting Your Data
Account deletion: You can delete your account in the app settings. This permanently deletes all your data, including your account information, session conversations, health data, AI-generated outputs, and AI monitoring logs. Deletion completes within 30 days. Since 25 July 2026 we no longer place your health or session data in an archive after deletion. For accounts deleted or reset before that date, a segregated remainder of previously archived records still exists. It is no longer used for the service, and its full deletion is being prepared. For information or deletion, contact datenschutz@khema.ai.
Accountability records: Excepted from deletion are records evidencing that your account was deleted and your data was reset, and a record evidencing that an automatically detected relapse led to a new smoke-free status. These records are stored immutably for the duration of the retention period. They contain no session content, but they do contain the event, its timestamp, your user identifier, the IP address of the triggering request and technical correlation attributes such as resource type and correlation ID; by its very existence the relapse record allows an inference about your cessation history. In addition, our authentication system keeps ordinary sign-in and account events, for example account creation and changes to your email address; these expire automatically after 3 years. We keep them for 3 years so that we can demonstrate to supervisory authorities that we acted on your deletion request (Art. 5(2) GDPR).
Reset my data: You can reset your data in the app settings. This deletes all your session conversations, health data, and AI-generated outputs, but keeps your account active so you can start fresh. Please note that AI monitoring logs are not deleted when you reset your data; they are only deleted when you fully delete your account or withdraw your consent to AI monitoring.
8. Data Security
We implement technical and organizational measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS (Transport Layer Security).
- Encryption at rest: All data stored on our servers is encrypted.
- Access control: Access to personal data is restricted to authorized team members with a legitimate need.
- Self-hosted infrastructure: Our authentication system, AI monitoring, and application logging are all hosted on our own EU-based infrastructure — your session content and the AI monitoring logs are not stored on third-party monitoring platforms.
- Password security: Your password is stored using one-way encryption with hashing and salting. No one at Khema can read your password.
- Device and app integrity proof: The app proves that it is an unmodified store build running on a device that has not been tampered with (Apple App Attest / Google Play Integrity). The proof is bound to your device's session key, so a stolen access token alone is not enough. Since 8 September 2026, without a valid proof we refuse access to your health and session data and stop renewing your sign-in, so you have to sign in again. The app renews the proof automatically beforehand and retries several times if it fails. If this locks you out for good, datenschutz@khema.ai will help you.
9. Your Rights
Under the GDPR, you have the following rights regarding your personal data. You can exercise these rights by contacting us at datenschutz@khema.ai or by using the relevant features in the app.
9.1 Right of Access (Art. 15 GDPR)
You have the right to request confirmation of whether we process your personal data and, if so, to receive a copy of that data along with supplementary information about the processing, including the purposes, categories of data, recipients, and retention periods. You can request a data export by emailing datenschutz@khema.ai. We will provide your data in a structured, machine-readable format (JSON).
9.2 Right to Rectification (Art. 16 GDPR)
You have the right to correct inaccurate personal data and to have incomplete personal data completed. In the app you can edit your profile information and assessment responses. For other corrections or to provide supplementary information, contact us at datenschutz@khema.ai.
9.3 Right to Erasure (Art. 17 GDPR)
You have the right to request deletion of your personal data. You can delete your account directly in the app (see Section 7.2). Deletion completes within 30 days. The data retained are the accountability records described in Section 7.2.
9.4 Right to Restriction of Processing (Art. 18 GDPR)
You have the right to request restriction of processing if you contest the accuracy of your data, if the processing is unlawful, if we no longer need the data but you need it for legal claims, or if you have objected to processing pending verification.
9.5 Right to Data Portability (Art. 20 GDPR)
Where processing is based on your consent or our contract with you and is carried out by automated means, you have the right to receive the personal data you have provided to us in a structured, commonly used, machine-readable format (JSON) and to transmit it to another controller. Where technically feasible, you may also request that we transmit the data directly to another controller. Contact us at datenschutz@khema.ai.
9.6 Right to Object (Art. 21 GDPR)
You have the right to object to processing based on legitimate interest (Art. 6(1)(f) GDPR) on grounds relating to your particular situation. We will stop processing unless we demonstrate compelling legitimate grounds that override your interests, or the processing is necessary for the establishment, exercise, or defence of legal claims.
9.7 Right to Withdraw Consent (Art. 7(3) GDPR)
Where processing is based on your consent (particularly for health data processing), you may withdraw your consent at any time. You can do this by deleting your account in the app or by contacting us at datenschutz@khema.ai. Withdrawal of consent does not affect the lawfulness of processing carried out before the withdrawal.
Please note that withdrawing your consent for health data processing will result in the termination of your account and the deletion of your data, as the smoking cessation service cannot be provided without processing health data. This is not an artificial restriction — it reflects the inherent nature of the service. A smoking cessation app cannot function without processing information related to your smoking behavior and cessation journey.
9.8 Right Regarding Automated Decision-Making (Art. 22 GDPR)
You have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. The automated progress updates described in Section 4.8 are the only automated decision-making in Khema. You have the right to obtain human intervention, to express your point of view, and to contest any automated decision by contacting us at datenschutz@khema.ai.
9.9 Right to Lodge a Complaint (Art. 77 GDPR)
If you believe that our processing of your personal data violates the GDPR, you have the right to lodge a complaint with a supervisory authority, in particular in the Member State of your habitual residence, place of work, or place of the alleged infringement. The competent authority for Khema is:
Der Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection Lower Saxony)
Prinzenstraße 5
30159 Hannover
Germany
Phone: +49 (0) 511 120-4500
Email: poststelle@lfd.niedersachsen.de
Website: https://www.lfd.niedersachsen.de
9.10 Response Time (Art. 12(3) GDPR)
We will respond to your requests within one month. If your request is particularly complex or we receive a large number of requests, we may extend this period by up to two additional months, in which case we will inform you of the extension and the reasons for the delay within the initial one-month period.
10. Young Users
Khema is intended exclusively for users aged 16 and older. Art. 8(1) GDPR sets 16 as the default age for information society services, and Germany has not lowered that threshold. We have decided not to offer a route via parental or legal guardian consent for anyone under 16, and to open the service only from the age of 16.
How we check age: During onboarding we ask for your date of birth. This is a self-declaration; we do not verify it against an identity document. The date you provide is evaluated on our servers. If you are under 16, we block access to the therapeutic features, that is sessions, chat, craving tracking, dictation and progress figures. Account management, notification settings and profile functions remain available so that you can delete your account. Answers you entered during onboarding before this evaluation may already have been stored; we delete them on request at datenschutz@khema.ai. We process your date of birth for this purpose as part of your account data (Section 3.1); it is stored in your user profile, in your questionnaire responses and in our authentication system.
If you are a parent and believe your child is using Khema nonetheless, please contact us at datenschutz@khema.ai and we will delete the account.
11. Website
The Khema website (khema.ai) is a landing page that provides information about the app. The website does not use cookies, does not use analytics tools, and does not collect personal data beyond what is necessary to serve the webpage (see Section 3.4 regarding server logs).
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our service, or legal requirements. If we make material changes, we will notify you through the app before the changes take effect.
The date of the most recent update is shown at the top of this document. We encourage you to review this policy periodically.
13. Contact
If you have any questions about this Privacy Policy or about how we handle your data, please contact us:
Email: datenschutz@khema.ai
Postal address:
Khema (in formation)
c/o Online-Impressum.de #4533
Europaring 90
53757 Sankt Augustin
Germany