Plain-language summary
- Kalamooo works fully offline — you can use it with just a device PIN, no account, and no data ever leaves your phone.
- If you sign in with Google or Apple, your store's data (products, sales, customer credit records) syncs to our database so you can reach it from another device.
- Asking the AI chat a question while online sends that question, plus the store data needed to answer it, to our AI provider (Groq). Offline, it runs entirely on your phone instead.
- Uploading a document to "My Documents" sends its text to Google's AI (Gemini) to make it searchable.
- We never sell your data, and there are no ad or tracking SDKs in this app.
1. What we collect
Kalamooo is a point-of-sale and credit-ledger app for small shop owners. Almost everything it stores is data you enter about your own business — we collect only what the app needs to run, sync, and answer your questions about your own store.
Account data (only if you sign in): The app works with no account at all, unlocked by a local PIN. If you choose "Continue Online" and sign in with Google or Apple, we receive your email address (via Supabase Authentication), and may also receive your name if your sign-in provider shares it, to create and secure your account.
Store & business data you enter:
- Store name, owner name, business phone number, and address (all optional at setup)
- Products and inventory: names, prices, stock levels, photos you add
- Sales transactions: amounts, payment type, timestamps
- Customer credit records: a customer's name, optional phone number, running balance, and payment history — entered by you, the store owner, about your own customers
- Staff/seller accounts you invite, and their sale activity under your store
Documents you choose to upload: The optional "My Documents" feature lets you upload PDFs or spreadsheets so the AI chat can reference them. We process the text inside files you actively choose to upload — nothing is scanned automatically.
Diagnostics: On Android, crash and error reports are collected via Firebase Crashlytics to help us fix bugs — this is off by default in development builds and never includes your store's financial data, only technical error details. Not collected on iOS.
Device permissions: Camera and photo library access are used only when you choose to scan or attach a product/receipt photo. Face ID / fingerprint (where supported) unlocks the app locally on your device — this biometric data never leaves your phone or reaches us.
2. Who we share it with
We don't sell data, and we don't use advertising or tracking SDKs. Data is shared only with the service providers below, and only for the specific purpose listed.
| Provider | Receives | Purpose | When |
|---|---|---|---|
| Supabase | Account email, store/product/sales/customer data you've synced | Backend database, authentication, cross-device sync | Only if you sign in/sync |
| Groq | Your typed question, plus the store data (e.g. sales totals, customer names and balances, stock levels) needed to answer it | Generates the AI chat's answer | Only when using AI chat while online — offline mode sends nothing |
| Google Gemini | Text extracted from documents you upload to "My Documents" | Creates searchable embeddings so AI chat can reference your documents | Only when you upload a document (paid add-on feature) |
| Firebase Crashlytics | Crash logs and technical diagnostics (device model, stack traces) | Bug fixing and stability | Android only, automatically |
| Google Sign-In | Email address, and name if you allow it to be shared | Account authentication | Only if you choose to sign in with Google |
| Apple Sign-In | Email address (or a private relay address if you choose "Hide My Email"), and name if you allow it to be shared | Account authentication | Only if you choose to sign in with Apple, on iOS |
Note on customer names and balances reaching Groq: if you ask the AI chat something like "who owes me the most?" while signed in online, the relevant customer names and balances are sent to Groq so it can phrase the answer — the same way a query to any database needs the matching records to respond. This never happens in offline/PIN mode.
3. How the AI features work
Kalamooo's "Chat with Store" assistant answers questions about your own store's data — it never invents numbers. Every money figure it shows is pulled directly from your real records and formatted by the app itself, not guessed by the AI.
- Offline/PIN mode: a small AI model runs entirely on your phone. Nothing about your question or your data is sent anywhere.
- Signed in online: your question and the specific store data needed to answer it are sent to Groq's cloud AI for that one exchange, and are not used to train Groq's models on our plan.
- Uploaded documents: processed by Google Gemini solely to make them searchable within your own chat.
4. Storage & security
- Your local database is encrypted at rest (SQLCipher/AES). The encryption key lives in your device's own secure keystore (Android Keystore/iOS Keychain) and is never transmitted or synced anywhere.
- All network traffic to Supabase, Groq, and Gemini is encrypted in transit (HTTPS/TLS).
- Data you haven't chosen to sync never leaves your device.
5. Retention & deletion
Synced data is retained for as long as your account is active. You can request deletion of your account and all associated store data at any time by contacting us (see below) — we'll remove it from our systems within a reasonable timeframe, except where we're required to retain records by law.
6. Your choices
- Use the app entirely offline with a local PIN and no account, if you'd rather nothing leave your device.
- Choose per-question whether to scope AI chat to specific topics, narrowing what data it can even consider.
- Request a copy or deletion of your synced data at any time (contact below).
- Decline camera/photo/biometric permissions — the app still works, just without those specific conveniences.
7. Children's privacy
Kalamooo is a business tool for shop owners and is not directed at children. We do not knowingly collect data from anyone under 18.
8. Changes to this policy
If this policy changes materially, we'll update the effective date above. Continued use of the app after a change means you accept the updated policy.
9. Contact
Questions, data requests, or deletion requests can be sent to: datuudann@gmail.com
Kalamooo — offline-first POS & credit ledger for small shop owners.
