Privacy Policy
Kampanion — Companion App for Remote Carers
Our Privacy Commitment: Kampanion is built with privacy as a foundational design principle. We do not operate external servers, do not sell or share your data with third parties, and do not use any advertising or third-party analytics frameworks. The App contains zero third-party code.
This Privacy Policy explains what information Kampanion (the “App”) collects, how it is used, stored, and protected. Kampanion is an iPhone companion app designed for carers and support providers to communicate remotely with individuals using the Kammunicate AAC app on iPad.
Developer: Christopher Hardy
Bundle Identifier: com.sentientcaregroup.Kampanion
1. Information We Collect
The App collects and stores the following types of information to enable remote communication with a paired Kammunicate device.
1.1 Message Data
- Received messages: Drawings, communication cards, photos, stickers, and text received from the paired Kammunicate iPad
- Sent messages: Quick-response cards, drawings, photos, and stickers you send to the paired device
- Message metadata: Timestamps, message identifiers, and device identifiers associated with each message
1.2 Pairing & Identity Data
- Device identifier: A unique identifier generated locally for your device
- Paired carer identifier: A unique identifier linking your device to the paired Kammunicate iPad
- Display name and avatar: The name and avatar you choose during pairing
1.3 Connection Data
- Pairing information: Connection details established during the QR code or pairing code process
- Presence data: Heartbeat signals indicating your online status to the paired device
- Composing status: Whether you are currently composing a message
1.4 Technical Data
- App version information: Current version installed on your device
- Network status: Connectivity state monitored locally to manage message delivery
- Push notification tokens: Managed by Apple to deliver message notifications
2. How We Use Your Information
All information is used exclusively to provide the App's communication functionality. We do not use your information for advertising, profiling, or any purpose unrelated to remote carer communication.
2.1 Communication
- Sending and receiving messages between your device and the paired Kammunicate iPad
- Displaying received drawings, cards, photos, and stickers
- Showing real-time presence and composing indicators
2.2 Personalisation
- Frequently used cards: The App tracks which response cards you use most often to provide quick-access suggestions, processed entirely on your device
- Display preferences: Storing your chosen name and avatar for the communication session
2.3 Notifications
- Alerting you when a new message arrives from the paired Kammunicate device
- Providing badge counts for unread messages
3. Data Storage & Security
3.1 Local Storage
- Message cache: Recent messages are cached locally for instant display when you open the App
- Image storage: Message images are stored in the App's secure sandbox with iOS Complete File Protection
- Preferences: Pairing details and display settings stored in UserDefaults
- No external databases: The App does not maintain any external databases or server infrastructure
3.2 Encryption
On-Device Encryption
- At rest: All data benefits from iOS device-level encryption
- Keychain storage: Cryptographic keys are stored in the iOS Keychain with device-only protection (
kSecAttrAccessibleAfterFirstUnlockThisDeviceOnly) - File protection: Cached images use iOS Complete File Protection
Message Encryption
- Algorithm: AES-GCM (Advanced Encryption Standard, Galois/Counter Mode)
- Key exchange: ECDH with P256 curves, performed during the pairing process
- Key derivation: HKDF-SHA256 with deterministic salt generation
- Key lifecycle: Unique keys per pairing, permanently deleted when you disconnect
3.3 Data Retention
- Messages: The latest message from each participant is cached locally; older messages are replaced automatically
- Image cache: Stored until the App is removed or you disconnect from the paired device
- Encryption keys: Permanently deleted when you disconnect from a paired device
4. Data Sharing & Third Parties
We do not share, sell, rent, or transmit your data to any third parties. The App does not:
- Send data to external servers operated by us or any third party
- Share information with advertisers or ad networks
- Transmit data to analytics or tracking services
- Connect to social media platforms
- Use any third-party SDKs, libraries, or tracking tools
- Contain any third-party code
4.1 Apple Services
The App uses the following Apple-provided services, governed by Apple's Privacy Policy:
| Apple Service | Purpose | Data Involved |
|---|---|---|
| CloudKit | Sync encrypted messages with the paired Kammunicate iPad | Encrypted messages, carer records, presence data |
| Push Notifications | Notify you of new messages from the paired device | Push tokens managed by Apple |
| AVFoundation | Camera access for QR code scanning and photos | No camera data stored beyond user-initiated photos |
5. CloudKit & Remote Messaging
5.1 Overview
Kampanion uses Apple CloudKit to exchange messages with the paired Kammunicate iPad. This is the App's core function and the only mechanism that transmits data beyond your local device.
5.2 How Pairing Works
- A pairing invitation is created on the Kammunicate iPad, generating a QR code and a 6-character pairing code
- You scan the QR code or enter the pairing code in Kampanion
- A secure end-to-end encrypted connection is established using ECDH key exchange
- Pairing codes expire after 24 hours and are single-use
- No email addresses, phone numbers, passwords, or account creation are required
5.3 What Data Is Synced
- Encrypted message content (card selections, drawings, photos, stickers)
- Carer records (identifier, avatar, online status)
- Presence heartbeats and composing indicators
5.4 Security Measures
- End-to-end encryption: All message content encrypted with AES-GCM before storage in CloudKit
- Rate limiting: Maximum 30 messages per minute
- Key deletion: All encryption keys permanently destroyed when you disconnect
- Dual-write strategy: Messages stored in CloudKit shared zone (primary) with public database fallback, both encrypted
5.5 Disconnecting
You can disconnect from a paired device at any time. Disconnecting permanently deletes all encryption keys and clears all cached message data from your device.
6. Permissions We Request
The App requests only one device permission:
- Camera: Used to scan QR codes for pairing and to take photos for messages
This permission is optional. You can enter a pairing code manually instead of scanning a QR code. Photos can be selected from your photo library as an alternative to the camera.
Manage camera access at any time through Settings > Kampanion on your device.
7. Children's Privacy
Kampanion is designed for carers and support providers, who are typically adults. However, we take children's privacy seriously.
- No personal information collection: The App does not collect personal information requiring parental consent under COPPA
- No account creation: No email, password, or personal details are required
- Paired communication only: The App only permits communication between deliberately paired devices
8. Your Privacy Rights & Controls
Access and Review
You can view all your data directly within the App, including received messages and your pairing information.
Data Deletion
- Disconnect from a paired device to delete all synced data and encryption keys
- Remove the App to permanently delete all locally stored data
Right to Be Forgotten
Because the App does not store data on external servers (aside from encrypted CloudKit records via your own iCloud account), disconnecting and deleting the App effectively exercises your right to erasure.
9. Legal Compliance
The App's privacy-first architecture supports compliance with GDPR, UK GDPR, CCPA/CPRA, COPPA, PIPEDA, and the Australian Privacy Act. Since data processing occurs locally and CloudKit sync uses end-to-end encryption via the user's own iCloud account, many requirements related to external data processing do not apply.
10. Changes to This Policy
We may update this Privacy Policy to reflect changes in features, legal requirements, or privacy best practices. Material changes will be highlighted in App Store release notes. Your continued use of the App constitutes acceptance of the updated policy.
| Version | Date | Changes |
|---|---|---|
| 1.0 | February 21, 2026 | Initial privacy policy |
11. Contact Information
If you have questions, concerns, or requests regarding this Privacy Policy or your privacy rights, please contact us:
Developer: Christopher Hardy
Email: chriswhardy@me.com