Privacy Notice
This Privacy Notice (the “Notice”) explains how KeyPort International OÜ collects, uses, shares, and protects the personal data of consumers (“Consumer”, “You”, “Your”) when You interact with the website https://iamapp.io/ (the “Site”) and the IAM mobile application (the “Application”; together, the “Service”).
We process personal data in accordance with Regulation (EU) 2016/679 (the “GDPR”), the United Kingdom General Data Protection Regulation and the UK Data Protection Act 2018 (together, the “UK GDPR”), the Estonian Personal Data Protection Act, the ePrivacy rules applicable to cookies and similar technologies, and other applicable data protection laws. Unless stated otherwise, references in this Notice to the GDPR, the EU, or the EEA shall be read as including the UK GDPR and the United Kingdom, and all rights described in this Notice are equally available to Consumers in the United Kingdom. Residents of certain U.S. states have additional rights described in Section 14.
The Service provides AI-generated content for personal development purposes only. Recommendations provided by the Service do not constitute medical diagnosis, clinical opinion, or a substitute for professional medical advice. Always consult a qualified physician or other healthcare professional before making decisions regarding Your health.
1. DATA CONTROLLER
Company name: KeyPort International OÜ (the “Company”, “We”, “Us”, “Our”)
Registered address: Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärava tn 50-201, 10152, Estonia
Email: support@iamapp.io
The Company is the controller of Your personal data within the meaning of Article 4(7) GDPR.
2. PERSONAL DATA WE COLLECT
We collect the following categories of personal data:
| Category | Examples | Source |
|---|---|---|
| Identity data | Name, date of birth, age, profile picture | Directly from You |
| Contact data | Email address | Directly from You |
| Registration data | Sign-in identifiers received when You register via Apple ID (email, name) | You; Apple |
| Onboarding & goal data | Selected areas of life, goals, development priorities, level of ambition, thematic interests | Directly from You |
| Consumer content | Text messages and prompts submitted to the AI functionality, responses to questions, and information about Your emotional or psychological state that You voluntarily disclose | Directly from You |
| Health data (special category) | Information about Your well-being, physical activity, and health transmitted via Apple Health, subject to Your separate explicit consent; health-related information You voluntarily provide | You; Apple Health |
| Technical & device data | Device and application identifiers, operating system, app version, language, approximate location (country/region), crash logs | Automatically |
| Usage data | Features used, content viewed, session activity, interaction events | Automatically, subject to consent where required |
| Transaction data | Subscription status, plan, purchase and renewal events, billing country, and payment status (We do not receive or store Your payment card details; payments are collected and processed by Apple as merchant of record) | Apple; automatically |
| Support data | Contents of Your inquiries and related contact details | Directly from You |
You may choose not to provide certain data, but this may prevent the use of some features of the Service.
3. PURPOSES AND LEGAL BASES OF PROCESSING
Under the GDPR, We must have a legal basis for each processing purpose. We rely on the following:
| Purpose | Data used | Legal basis (GDPR) |
|---|---|---|
| Creating and managing Your Account; authentication | Identity, contact, registration data | Art. 6(1)(b) – performance of a contract |
| Providing the core Service, including AI-generated personalized content and audio sessions | Onboarding & goal data, Consumer content, usage data | Art. 6(1)(b) – performance of a contract |
| Processing information about Your emotional or psychological state and Apple Health data to personalize sessions | Health data, Consumer content | Art. 9(2)(a) – Your explicit consent, in conjunction with Art. 6(1)(a) |
| Managing Subscriptions and entitlements | Transaction data | Art. 6(1)(b) – performance of a contract |
| Customer support | Support data, identity, contact data | Art. 6(1)(b); Art. 6(1)(f) – legitimate interest in resolving inquiries |
| Product analytics and Service improvement | Usage data, technical data | Art. 6(1)(a) – consent (where collected via tracking technologies); Art. 6(1)(f) – legitimate interest for aggregated, privacy-preserving analytics |
| Marketing communications (email) | Contact data | Art. 6(1)(a) – consent; You may withdraw at any time |
| Advertising measurement and personalized advertising | Device identifiers, usage data | Art. 6(1)(a) – consent (via the in-app consent screen and, on iOS, App Tracking Transparency) |
| Security, fraud prevention, and abuse detection | Technical data, usage data | Art. 6(1)(f) – legitimate interest in protecting the Service and its users |
| Compliance with legal obligations (tax, accounting, lawful requests) | Transaction data, identity data | Art. 6(1)(c) – legal obligation |
| Establishing, exercising, or defending legal claims | Data relevant to the claim | Art. 6(1)(f) – legitimate interest |
Where We rely on legitimate interests, We have carried out a balancing assessment and concluded that Our interests are not overridden by Your interests or fundamental rights. You may object to processing based on legitimate interests as described in Section 10.
4. SPECIAL CATEGORIES OF PERSONAL DATA (HEALTH AND WELL-BEING DATA)
Some of the data processed by the Service — including information about Your emotional, psychological, or mental state that You submit to the AI functionality, and data received from Apple Health — constitutes special category data concerning health within the meaning of Article 9 GDPR.
We process such data only on the basis of Your explicit consent (Article 9(2)(a) GDPR), which We request separately within the Application before such processing begins. You may withdraw this consent at any time in the Application settings or by contacting Us; withdrawal does not affect the lawfulness of processing carried out before withdrawal, but certain personalization features will no longer be available.
We do not use special category data for advertising or marketing purposes, and We do not sell such data.
5. CONSENT AND HOW TO WITHDRAW IT
Where processing is based on consent, We obtain it through a clear affirmative action — for example, the in-app consent screen presented before optional analytics or advertising technologies are activated, the separate explicit consent request for health and well-being data, and the opt-in for marketing emails. Use of the Service alone does not constitute consent.
You may withdraw any consent at any time, free of charge, with effect for the future, via the Application settings (Privacy / Consent preferences) or by contacting Us at the address in Section 16. On iOS, You can additionally manage tracking permissions in Your device settings (Settings → Privacy → Tracking).
6. AUTOMATED PROCESSING AND AI
The Service uses artificial intelligence to generate personalized content, recommendations, and audio sessions based on the information You provide. This constitutes automated processing, including profiling, for the purpose of personalizing Your experience. It does not produce legal effects concerning You or similarly significantly affect You within the meaning of Article 22 GDPR: the outputs are informational content that You are free to use or disregard, and no automated decisions are made about Your access to the Service, pricing, or rights.
Content provided through the Service is AI-generated. AI outputs may be inaccurate or incomplete, and should not be relied upon as professional advice.
7. RECIPIENTS AND PROCESSORS
We share personal data only to the extent necessary and with the following categories of recipients, each bound by a data processing agreement under Article 28 GDPR where they act as Our processor:
- AI service providers. To process text inputs and generate content, We engage OpenAI and Anthropic. They receive Consumer content strictly to the extent necessary to provide the relevant feature.
- Voice technology providers. For speech synthesis and audio generation, We use ElevenLabs, which processes text submitted for audio generation.
- Cloud infrastructure and analytics providers. For hosting, data storage, email delivery, and product analytics, We use providers such as Google and Amplitude.
- Platform. Apple processes Your purchases as merchant of record and provides sign-in and, where You consent, Apple Health integration, acting under its own privacy terms.
- Professional advisers and authorities. We may disclose data to professional advisers and to public authorities where required by applicable law or to protect Our legal rights.
We do not sell Your personal data and do not share it with third parties for their own independent marketing purposes.
8. INTERNATIONAL DATA TRANSFERS
Some of Our processors are located in the United States or other countries outside the European Economic Area. Where personal data is transferred outside the EEA, We ensure an adequate level of protection through one of the following safeguards:
- EU–U.S. Data Privacy Framework (DPF): transfers to recipients certified under the DPF, which the European Commission has recognized as providing adequate protection;
- Standard Contractual Clauses (SCCs): the European Commission’s standard contractual clauses (Decision (EU) 2021/914), supplemented where necessary by additional technical and organizational measures.
- UK transfers: for personal data originating from the United Kingdom, We rely on the UK Addendum to the EU Standard Contractual Clauses or the UK International Data Transfer Agreement (IDTA) issued by the Information Commissioner’s Office, and, where applicable, the UK Extension to the EU–U.S. Data Privacy Framework.
Our current transfer mechanisms per provider: OpenAI (SCCs / DPF certification), Anthropic (SCCs / DPF certification), ElevenLabs (SCCs), Google (SCCs / DPF certification), Amplitude (SCCs / DPF certification). You may request a copy of the relevant safeguards by contacting Us at the address in Section 16.
9. RETENTION PERIODS
We retain personal data only for as long as necessary for the purposes for which it was collected, and We apply the following retention periods:
| Data category | Retention period |
|---|---|
| Account, identity, and onboarding data | For the life of Your Account; deleted or anonymized within 30 days of Account deletion |
| Consumer content and generated audio sessions | For the life of Your Account or until You use the “Start Over” feature; deleted within 30 days of Account deletion |
| Health and well-being data (special category) | Until You withdraw consent or delete Your Account, whichever occurs first; deleted within 30 days |
| Usage and analytics data | Up to 24 months from collection, after which it is deleted or aggregated |
| Transaction records | Up to 7 years, to the extent required by Estonian accounting and tax law |
| Support correspondence | Up to 3 years from the closure of the inquiry |
| Consent records | For the duration of processing and up to 3 years thereafter, to demonstrate compliance |
Where deletion is requested, We may retain limited data where required by law or necessary for the establishment, exercise, or defense of legal claims.
10. YOUR RIGHTS UNDER THE GDPR
You have the following rights in relation to Your personal data:
- Right of access (Art. 15): obtain confirmation of whether We process Your data and receive a copy of it;
- Right to rectification (Art. 16): have inaccurate or incomplete data corrected;
- Right to erasure (Art. 17): have Your data deleted, including by deleting Your Account in the Application;
- Right to restriction of processing (Art. 18);
- Right to data portability (Art. 20): receive the data You provided in a structured, commonly used, machine-readable format;
- Right to object (Art. 21): object to processing based on legitimate interests, and to direct marketing at any time;
- Right to withdraw consent (Art. 7(3)): at any time, without affecting the lawfulness of prior processing;
- Right not to be subject to solely automated decisions producing legal or similarly significant effects (Art. 22).
To exercise Your rights, contact Us at support@iamapp.io or use the tools in the Application (including in-app Account deletion). We will respond within one month, extendable by two further months for complex requests, in which case We will inform You. We may request information necessary to verify Your identity.
Right to lodge a complaint: You have the right to lodge a complaint with a supervisory authority, in particular in the EU Member State of Your habitual residence or place of the alleged infringement. Our lead supervisory authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, Estonia, www.aki.ee, info@aki.ee. If You are in the United Kingdom, You may lodge a complaint with the Information Commissioner’s Office (ICO), Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF, www.ico.org.uk.
11. COOKIES AND SIMILAR TECHNOLOGIES
The Site and the Application use cookies, software development kits (SDKs), and similar technologies. These fall into the following categories:
- Strictly necessary technologies – required for the operation of the Service (e.g., session management, security, remembering Your consent choices). These are used without consent on the basis of Our legitimate interest in operating the Service.
- Functional technologies – remember Your choices, such as language. Used with Your consent where required.
- Analytics technologies – help Us understand how the Service is used (e.g., Amplitude, Google Analytics). Activated only after You give consent via the consent banner (Site) or consent screen (Application).
- Advertising and measurement technologies – used to measure and personalize advertising (e.g., Google Ads, Meta (Facebook/Instagram) advertising tools, YouTube advertising). These identify Your device and are activated only after You give consent. On iOS, tracking across apps additionally requires Your permission via the App Tracking Transparency prompt.
Analytics and advertising technologies process data that may identify Your device and are therefore not anonymous; they are used only with Your prior consent, which You may withdraw at any time via the consent settings on the Site or in the Application. You may also configure Your browser to refuse cookies; strictly necessary functions may be affected.
12. MARKETING
We send marketing emails only with Your prior consent. Every marketing email contains an unsubscribe link, and You may also opt out in Your Account settings or by contacting Us. Opt-out requests are processed without undue delay, at the latest within 7 business days. Transactional and service messages (e.g., purchase confirmations, material changes to terms) are not marketing and may be sent without consent.
13. CHILDREN
The Service is intended for individuals aged 18 and over. We do not knowingly collect personal data from individuals under 18. If We become aware that personal data of a person under 18 has been collected, We will delete it. If You are a parent or guardian and believe Your child has provided Us with personal data, please contact Us using the details in Section 16.
14. ADDITIONAL RIGHTS OF U.S. STATE RESIDENTS
14.1. Consumer health data (Washington, Nevada, and similar laws)
Some information We collect — including information about Your emotional, psychological, or mental state that You submit to the Service and data received from Apple Health — may constitute “consumer health data” under the Washington My Health My Data Act, Nevada SB 370, and similar U.S. state laws. We collect and process such data only with Your consent and only for the purposes of providing and personalizing the Service, as described in this Notice. We do not sell consumer health data, We do not use it for advertising, and We do not share it with third parties except with the processors identified in Section 7 acting on Our behalf. You have the right to: confirm whether We collect, share, or sell Your consumer health data; access such data, including a list of third parties with whom it has been shared; withdraw Your consent; and request deletion of Your consumer health data. To exercise these rights, contact Us at support@iamapp.io with the subject line “Consumer Health Data Request”. If Your request is denied, You may appeal by replying to Our decision, and, if the appeal is unsuccessful, You may contact the attorney general of Your state.
14.2. State privacy rights
If You reside in California, Virginia, Colorado, Connecticut, Utah, Nevada, or another U.S. state with an applicable comprehensive privacy law, You may have additional rights, including the right to know, access, correct, and delete personal information, the right to opt out of the sale or sharing of personal information and of targeted advertising, and the right to non-discrimination for exercising these rights.
We do not sell personal information as defined under the California Consumer Privacy Act. To exercise any of these rights, contact Us at support@iamapp.io with the subject line “Privacy Request” and an indication of Your state of residence. We will verify Your identity and respond within the time limits established by applicable law (in California, generally within 45 days). You may designate an authorized agent to submit requests on Your behalf.
15. OTHER JURISDICTIONS (CANADA, AUSTRALIA, NEW ZEALAND, UKRAINE)
We extend the rights described in Section 10 (access, correction, deletion, portability, objection, withdrawal of consent) to all Consumers, regardless of location. In addition: if You are in Canada, We process personal data in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial laws, and You may contact the Office of the Privacy Commissioner of Canada (www.priv.gc.ca); if You are in Australia, We handle personal information consistently with the Australian Privacy Principles under the Privacy Act 1988, and You may contact the Office of the Australian Information Commissioner (www.oaic.gov.au); if You are in New Zealand, the Privacy Act 2020 applies, and You may contact the Office of the Privacy Commissioner (www.privacy.org.nz); if You are in Ukraine, We process personal data consistently with the Law of Ukraine “On Personal Data Protection”. Marketing emails are sent only with Your express consent, consistent with Canada’s Anti-Spam Legislation (CASL) and the Australian Spam Act 2003.
Canada. Your personal data may be stored and processed outside Canada, including in the European Economic Area and the United States, and may be accessible to the authorities of those jurisdictions under their laws. We obtain meaningful consent for the collection, use, and disclosure of personal information as described in this Notice. Questions or complaints regarding Our privacy practices may be addressed to Our privacy contact at support@iamapp.io. Every marketing email We send includes a functioning unsubscribe mechanism, consistent with CASL.
Australia. Personal information may be disclosed to overseas recipients located in the European Economic Area and the United States; We take reasonable steps to ensure that such recipients handle it in a manner consistent with the Australian Privacy Principles. If You have a complaint about Our handling of Your personal information, please contact Us first using the details in Section 16, and We will investigate and respond within 30 days. If You are not satisfied with Our response, You may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
New Zealand. Our contact person for privacy matters can be reached at support@iamapp.io. Where personal information is disclosed to recipients outside New Zealand, We ensure comparable safeguards through the transfer mechanisms described in Section 8. You may complain to the Office of the Privacy Commissioner if You believe Your privacy has been interfered with.
Ukraine. We process Your personal data on the basis of Your consent or another lawful ground under the Law of Ukraine “On Personal Data Protection”. You may withdraw Your consent and exercise the rights described in Section 10 at any time, free of charge. Nothing in this Notice limits Your mandatory rights as a consumer of digital services under Ukrainian law.
16. SECURITY, CHANGES, AND CONTACT
16.1. Security
We implement appropriate technical and organizational measures within the meaning of Article 32 GDPR, including encryption of data in transit, access controls on a need-to-know basis, staff confidentiality obligations, and vendor due diligence. No method of transmission or storage is completely secure; if You believe Your interaction with Us is no longer secure, please notify Us immediately.
16.2. Changes to this Notice
We may update this Notice from time to time. If We make material changes, We will notify You in advance through the Application or by email. The “Last updated” date above indicates when this Notice was last revised.
16.3. Contact
KeyPort International OÜ
Harju maakond, Tallinn, Kesklinna linnaosa, Vesivärava tn 50-201, 10152, Estonia
Email: support@iamapp.io
When You send Us a request, We may ask You to provide information necessary to verify Your identity.