Legal · LEG·01
Privacy Policy.
Privacy Policy for the Kitalon Labs Android apps (PayRadar, PixelPro AI, Quick Convert, and ScanLite) and browser extensions (JobSafe, OneReply, POA Architect, and QuoteSweep).
Last updated: 5 September 2026
Table of Contents
Introduction
Kitalon Labs LLC ("Kitalon Labs", "we", "our", "us") operates the following Android applications and browser extensions: PayRadar, PixelPro AI, Quick Convert, ScanLite, JobSafe, OneReply, POA Architect, and QuoteSweep (collectively, the "Apps"). This Privacy Policy explains what information we collect, how we use it, with whom we share it, and what rights you have with respect to your information.
By installing or using any of the Apps, you agree to the practices described in this Privacy Policy and these Terms. If you do not agree, please uninstall the App or remove the extension and discontinue use.
This Policy applies globally. Where we refer to additional obligations under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), or other applicable law, those provisions apply only to residents of the relevant jurisdiction.
Data Controller
For the purposes of the GDPR and equivalent data protection laws, the data controller is:
Kitalon Labs LLC
Dhaka, Bangladesh
Email: [email protected]
Information We Collect
Information you provide directly
PayRadar (Subscription Tracker): Subscription names, amounts, billing cycles, and renewal dates that you manually enter into the App. This data is stored exclusively on your device using local device storage. We do not transmit this data to our servers.
PixelPro AI (AI Photo Editor): Photos and images you select for editing, including images taken with your device camera. Editing instructions and parameters you configure within the App. When cloud-based AI processing is elected by you, image data is transmitted to our processing servers solely for the duration of the operation and deleted immediately upon completion. We do not retain, index, or use your images for model training.
Quick Convert (File Converter): Files you upload or select for conversion (documents, images, audio, video). Files are processed locally on your device where technically feasible. Where server-side conversion is required, files are transmitted over TLS, processed, returned to you, and permanently deleted from our servers within 24 hours. We do not store, index, or analyse your file contents.
ScanLite (Document Scanner): Images captured using your device camera for document scanning. All scanned document data is stored locally on your device. ScanLite does not upload scanned documents to any server. You may voluntarily export documents to third-party storage services (for example, Google Drive), in which case the relevant third party's privacy policy governs that data.
Browser extensions
JobSafe (job scam detector): When you view a job listing on LinkedIn, Indeed, or Glassdoor, JobSafe sends that listing's text and metadata (title, company, description, location, salary, posting date, and URL) to our servers to generate a scam-risk classification. We retain short excerpts of that text together with the classification result for up to 7 days for quality monitoring, then delete them. If you report a listing as a scam or mark one as safe, we store a hash of the listing's identifying details plus the short text you submit, to improve detection over time. If you submit an appeal against a classification, we store your business email address, the listing URL, and your note.
OneReply (Gmail reply assistant): OneReply integrates with Gmail entirely through the page itself, using InboxSDK. It does not use the Gmail API and does not request access to your Google account. When you ask OneReply to draft or polish a reply, the visible content of that email thread is sent through our proxy to Anthropic and/or OpenAI to generate the response.
POA Architect (Amazon reinstatement appeals): You provide details about your Amazon seller account suspension, including the suspension reason, your business information, and a description of the issue. This information is sent to Anthropic, OpenAI, and/or Google (Gemini) to draft a Plan of Action, and is stored on our servers so you can review, edit, and resubmit your case.
QuoteSweep (insurance quoting assistant): QuoteSweep is in development; this section describes the planned design and will be verified against the shipped product before launch. You provide a commercial risk profile, including your business's legal name, NAICS classification, address, payroll, gross receipts, square footage, prior loss history, business description, and Federal Employer Identification Number (FEIN). We store this profile on our servers; your FEIN is encrypted at rest. QuoteSweep uses this profile to pre-fill quote forms on supported carrier portals (currently planned: Travelers, The Hartford, Liberty Mutual, The Hanover, and AmTrust) directly in your browser. QuoteSweep never submits a quote application on your behalf — you review and submit each carrier form yourself.
Information collected automatically
We use the following third-party SDKs in one or more Apps. Each SDK may collect certain data as described:
| SDK / Service | Apps | Data Collected | Purpose |
|---|---|---|---|
| Firebase Analytics | All Apps | Anonymised usage events, device model, OS version, app version, country (not precise location) | Product analytics, crash-free rate |
| Firebase Crashlytics | All Apps | Crash stack traces, device state at time of crash, anonymised installation ID | Bug fixing |
| Google Play Billing | PayRadar, PixelPro AI, ScanLite | Purchase token, order ID (provided by Google, not by us) | Processing in-app purchases |
| RevenueCat | PixelPro AI | Purchase history, entitlement status | Subscription management |
| Google ML Kit (on-device) | PixelPro AI, ScanLite | Processed locally; no data leaves the device via this SDK | On-device AI features |
| TensorFlow Lite / ONNX Runtime (on-device) | PixelPro AI | Processed locally; no data leaves the device via these libraries | On-device AI inference |
| Transformers.js / ONNX Runtime (on-device) | JobSafe | Processed locally as a first pass; no data leaves the device via these libraries | On-device scam-signal pre-screening |
| Cloudflare Workers / KV | JobSafe, OneReply, QuoteSweep | JobSafe: job listing text and metadata, cached excerpts and classification results (up to 7 days), report/appeal data. OneReply: proxied request metadata. QuoteSweep: your stored risk profile. | Scam classification, request routing, profile storage |
| Anthropic API, OpenAI API | OneReply, POA Architect | Content you submit (email thread text for OneReply; suspension and business details for POA Architect) | Generating AI-drafted replies and appeals |
| Google Gemini API | POA Architect | Content you submit (suspension and business details) | Generating AI-drafted appeals |
| Lemon Squeezy | OneReply | Payment details (processed by Lemon Squeezy, not stored by us) | Subscription billing |
| Stripe | POA Architect, QuoteSweep | Payment details (processed by Stripe, not stored by us) | Payment processing |
We do not use advertising SDKs. We do not sell advertising placements in the Apps. No data collected through the Apps is sold to advertisers or data brokers.
Device permissions
The Apps request the following permissions, used strictly for stated purposes:
| Permission | App(s) | Purpose |
|---|---|---|
| CAMERA | PixelPro AI, ScanLite | Capture photos for editing / scanning |
| READ_MEDIA_IMAGES, READ_EXTERNAL_STORAGE | PixelPro AI, Quick Convert | Access photos/files you select |
| WRITE_EXTERNAL_STORAGE (Android < 10) | Quick Convert, ScanLite | Save output files |
| INTERNET | All Apps | SDK telemetry, cloud features (where applicable) |
| BILLING | PayRadar, PixelPro AI, ScanLite | In-app purchase processing via Google Play |
| POST_NOTIFICATIONS (Android 13+) | PayRadar | Renewal reminder notifications |
We never request CONTACTS, LOCATION, MICROPHONE (except where you explicitly grant it for a specific feature), SMS, or CALL_LOG permissions.
Browser extension permissions
Our browser extensions request the following permissions, used strictly for stated purposes:
| Permission | Extension(s) | Purpose |
|---|---|---|
| storage, alarms, scripting | OneReply | Save your settings locally, run scheduled tasks, and inject reply suggestions into the Gmail page |
| Host access: mail.google.com | OneReply | Detect Gmail compose windows and read the open thread via InboxSDK. OneReply does not request the Gmail API or Google account access. |
| activeTab, storage | JobSafe | Read the job listing page you have open; save your settings |
| Host access: linkedin.com, indeed.com, glassdoor.com | JobSafe | Detect and scan job listings on these sites |
| activeTab, storage | POA Architect | Read the Amazon Seller Central page you have open; save your case data |
| Host access: sellercentral.amazon.com | POA Architect | Detect suspension notices and appeal forms |
| storage | QuoteSweep | Save your risk profile locally between sessions |
| Host access: travelers.com, thehartford.com, libertymutual.com, hanover.com, amtrust.com | QuoteSweep | Pre-fill your risk profile into supported carrier quote forms |
None of our extensions request the Gmail API, Google account sign-in, browsing history, or access to sites beyond those listed above.
How We Use Your Information
We use the information collected to:
- (a) Provide and maintain the features of the Apps;
- (b) Process in-app purchases and validate entitlements;
- (c) Diagnose crashes and fix bugs;
- (d) Understand aggregate usage patterns to improve the Apps;
- (e) Send you renewal reminders (PayRadar only, opt-out available in Settings);
- (f) Classify job listings for scam risk (JobSafe);
- (g) Generate AI-drafted content you request (email replies in OneReply, appeal drafts in POA Architect);
- (h) Pre-fill supported insurance carrier quote forms with your risk profile (QuoteSweep);
- (i) Comply with legal obligations.
We do not use your information to build advertising profiles, engage in targeted advertising, or sell your data to any third party.
Legal bases for processing (GDPR Article 6): Performance of a contract: processing necessary to deliver the App functionality you requested. Legitimate interests: crash analytics and aggregate product analytics (you may object; see Section 8). Consent: where we have explicitly asked for your consent (for example, optional cloud processing in PixelPro AI). Legal obligation: where processing is required by applicable law.
Data Sharing and Disclosure
We share your information only in the following limited circumstances:
- Service providers: Firebase (Google LLC) and RevenueCat, Inc. act as data processors on our behalf under data processing agreements. They process data only as directed by us and for the purposes described in this Policy.
- Cloudflare, Inc.: Cloudflare Workers and KV host the backend infrastructure for JobSafe, OneReply, and QuoteSweep, and process data only as directed by us.
- AI processing providers: When you use OneReply or POA Architect, the content you submit is sent to Anthropic, OpenAI, and/or Google (Gemini) solely to generate the reply or appeal draft you requested.
- Payment processors: Stripe (POA Architect, QuoteSweep) and Lemon Squeezy (OneReply) process your payment details under their own privacy policies. We never receive your full payment card details.
- Google Play: When you make a purchase, Google LLC processes payment data under Google's own privacy policy. We receive only a purchase token and order ID; we never receive your payment card details.
- Legal requirements: We may disclose information if required by applicable law, court order, or governmental authority, or to protect the rights, property, or safety of Kitalon Labs, our users, or the public.
- Business transfers: If Kitalon Labs undergoes a merger, acquisition, or asset sale, your information may be transferred. We will provide notice before your information is transferred and becomes subject to a different privacy policy.
We do not sell, rent, or trade your personal information to third parties for their marketing purposes.
Data Retention
| Data Type | Retention Period |
|---|---|
| Locally stored app data (PayRadar, ScanLite) | Retained on device until you uninstall the App or delete the data |
| Firebase Analytics events | 14 months (Google's default; we have not extended this) |
| Firebase Crashlytics reports | 90 days |
| Cloud-processed images (PixelPro AI) | Deleted immediately upon operation completion; maximum 1 hour |
| Server-converted files (Quick Convert) | Deleted within 24 hours of conversion completion |
| JobSafe classification cache (job text excerpts and results) | Up to 7 days, then deleted |
| JobSafe scam reports and safe-marks (hash plus short text) | Retained indefinitely to improve detection |
| JobSafe appeals (business email, listing URL, note) | Until the appeal is resolved, then deleted within 12 months |
| OneReply email thread content sent for reply generation | Not retained beyond generating the response |
| POA Architect case data | 1 year after your case is resolved, then deleted |
| QuoteSweep risk profile data | Until you delete your account or request deletion |
| Purchase records | 7 years (legal/accounting obligation) |
Security
We implement industry-standard technical and organisational measures to protect information from unauthorised access, alteration, disclosure, or destruction. These include TLS encryption for all data in transit, access controls, and regular security reviews. However, no method of transmission over the internet or electronic storage is 100% secure. We encourage you to use the latest version of the App.
Your Rights
Depending on your jurisdiction, you may have the following rights:
All users:
- Access: Request a copy of the personal data we hold about you.
- Deletion: Request deletion of your personal data. Note that locally stored data can be deleted by uninstalling the App. For server-held data, contact us.
- Opt-out of analytics: You may disable Firebase Analytics by turning off "Usage Analytics" in the App's Settings screen (where available) or by enabling "Limit Ad Tracking" / "Opt out of Ads Personalization" in your device settings.
EEA / UK residents (GDPR): Rectification: correct inaccurate personal data. Restriction: request restriction of processing in certain circumstances. Portability: receive your data in a structured, machine-readable format. Object: object to processing based on legitimate interests. Withdraw consent: where processing is based on consent, withdraw it at any time. Complaint: lodge a complaint with your local supervisory authority.
California residents (CCPA/CPRA): You have the right to know, delete, correct, and opt out of the sale or sharing of personal information. We do not sell or share personal information as defined under the CCPA. We do not discriminate against you for exercising your rights.
To exercise any right, contact us at [email protected]. We will respond within 30 days (or such shorter period as required by law).
Children's Privacy
The Apps are not directed to children under the age of 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children under these ages. If you believe a child has provided us with personal information, please contact us at [email protected] and we will delete it promptly.
International Data Transfers
Kitalon Labs is based in Bangladesh. When you use the Apps, your data may be processed in countries outside your own, including the United States (where Google LLC, RevenueCat, Anthropic, OpenAI, Cloudflare, Stripe, and Lemon Squeezy operate infrastructure). These countries may have different data protection laws than your home country. We rely on these providers' Standard Contractual Clauses and other adequate transfer mechanisms to protect your data.
Third-Party Links and Services
The Apps may allow you to export or share content to third-party services (for example, Google Drive). This Policy does not apply to those third-party services, and we are not responsible for their privacy practices.
Changes to This Policy
We may update this Policy periodically. We will notify you of material changes by updating the "Last Updated" date at the top of this page and, where required by law, by in-app notification. Your continued use of the Apps after any change constitutes your acceptance of the updated Policy.
Contact Us
For privacy-related questions, requests, or complaints:
Kitalon Labs LLC
Email: [email protected]
Website: https://kitalonlabs.com
