Kairoscope Privacy Policy

Last updated: 21 August 2026.

In short

  • Who. Your data is processed by Yevhen Orestov — an individual in Ukraine, who runs Kairoscope (§1).
  • What we keep. Your account, calendar, tasks, friends and shares. Separately: the emotion diary, medication reminders and energy markers — this is health data (Art. 9 GDPR), processed on your explicit consent, and neither the diary nor the medication reminders do anything until you start them yourself (§2, §4).
  • Where. The database, attachments and backups live on a Hetzner server in Germany (EU); the free-text diary note, the medication name and AI chat messages are encrypted at field level on top of that. Some processing happens at providers in the USA (§6, §7, §14).
  • AI features. Off until you turn them on in your profile. Diary entries reach AI only under the separate "mood AI" consent. No AI action is applied without your confirmation (§5).
  • Advertising. No advertising cookies or pixel trackers on the web; analytics in the mobile app requires consent, in version 1.0.2 and newer (§13). We do not sell data (§8).
  • Your rights. Exporting all your data as JSON and deleting your account are in your Profile, without writing to us; the diary exports and erases separately. We answer requests within one month (§12).

This is a summary, not the document. The full text below is what binds; where the two differ, it governs.

1. Data controller

Data is processed by Yevhen Orestov (an individual, operating Kairoscope), Ukraine. Contact for data questions: kairoscope.contact@gmail.com.

2. What we store

CategoryWhat
AccountEmail, hashed password, display name, timezone, language, theme, clock format, phone (optional), avatar (if you upload one)
CalendarEvents, tasks, categories, day templates, notes, time goals, attachments (if you add any)
SocialFriends, groups, event/task sharing, messages in shared sessions
PushPush subscription (browser, FCM, APNs via Expo), log of reminders already sent
Emotion diary
(health data, Art. 9)
State entries: two wellbeing scales, emotion labels, body map (marked body areas), triggers, free-text note (encrypted), time, optional link to an event; "moments" (timestamp only); morning and evening mood and fatigue check-ins
Medication
(health data, Art. 9)
Medication names and labels (encrypted), dosing schedule, the status of each dose (taken or missed) and its time
Wellbeing
(health data, Art. 9)
Hourly energy markers, energy-budget settings — including your own lists of what drains and what restores you
AI chatAssistant conversation history (contents encrypted), AI usage counters
Voice (transient)Audio for speech recognition — sent to Groq (whisper-large-v3-turbo), with OpenAI Whisper as fallback; not stored after transcription
SyncExternal calendar OAuth token (encrypted) and imported events — only if you connected Google/Microsoft yourself
Location (premium)Precise GPS coordinates and addresses (home, events, saved places) — processed by Google Maps Platform for geo-reminders, address autocomplete and travel time; only when you use those features
Calendar link (ICS)A unique subscription token, if you enable the feature — stored hashed and encrypted (see §10)
SubscriptionYour account identifier in the purchase system, subscription status, promo codes you redeemed
Analytics (mobile app)Anonymous app-instance identifier, device model, OS version, language, approximate country from IP, "sign up" and "login" events (see §13)
Technical dataIP address (rate limiting and abuse protection), crash reports (app version, device, screen sequence, account identifier)
FeedbackEmail, name and message text, if you write to us through the form
Booking guestThe name and email of a person who booked a slot through a user's public booking link. Stored in dedicated fields on the event itself; the name is also part of the event's title. That person has no Kairoscope account — see the separate paragraph in §3

3. Why we process it, and on what legal basis

PurposeData categoriesLegal basis
Creating and running your account, sign-in, password resetAccountArt. 6(1)(b), performance of a contract
Showing your calendar: events, tasks, categories, templates, attachmentsCalendarArt. 6(1)(b)
Reminders (push, email)Push, event timesArt. 6(1)(b)
Sharing with friends and groupsSocialArt. 6(1)(b)
External calendar sync (read-only)SyncArt. 6(1)(a), consent — you connect it yourself and can disconnect it
Emotion diary, body map, triggers, notes, check-insHealth dataArt. 9(2)(a), explicit consent, together with Art. 6(1)(a) — see §4
Medication reminders and dose historyHealth dataArt. 9(2)(a), explicit consent, together with Art. 6(1)(a) — see §4
Energy budget and hourly energy markersHealth dataArt. 9(2)(a), explicit consent, together with Art. 6(1)(a) — see §4
AI features over text: chat, categorisation, suggestions, day planning, the day's fatigue hint, the recovery suggestionEvent and task titles, times, free slots; for the day's fatigue hint, the recovery suggestion and day planning also your lists of what drains and what restores youArt. 6(1)(a), consent — the "AI features" switch in Settings. For the drains/restores lists this is at the same time a special category (Art. 9(2)(a)) — see the caveat in §4
AI over the diary: voice to labels, weekly reviewAudio, diary aggregatesArt. 9(2)(a), separate explicit consent — the "mood AI" switch
Geo reminders, leave-on-time, address suggestionsLocationArt. 6(1)(a), consent
Subscription and paymentsSubscriptionArt. 6(1)(b), performance of a contract
Abuse protection, rate limiting, crash reportsTechnical dataArt. 6(1)(f), legitimate interest in the security and availability of the service
Answering messages sent through the feedback formFeedbackArt. 6(1)(f), legitimate interest in handling your enquiry
Measuring app advertising performanceAnalyticsConsent (Art. 6(1)(a)); without consent analytics does not run, switch in Settings. Applies from app version 1.0.2 onwards — see §13
Booking a slot through a public linkBooking guestArt. 6(1)(f), the legitimate interest of both parties in holding the agreed meeting

If you book a slot through someone else's link. When someone shares a Kairoscope booking link and you pick a slot, we store the name and email you provide so that the calendar owner knows who the meeting is with. The legal basis is the legitimate interest of both parties in holding the agreed meeting (Art. 6(1)(f)). Your name becomes part of the event's title in the owner's calendar, so anyone the owner shows that calendar to, or shares the event with, can read it; your email is visible to the owner alone. Your email stays on our server in Germany and goes nowhere else. Your name is a different matter, which is why it is called out separately here: it is part of the event's title, and an event's title leaves our server through the owner's ordinary use of the app — into the text of a push reminder if the owner sets one on that event (Expo, Apple, Google, USA), to OpenAI (USA) if they use an AI feature for that day, to their external calendar provider if they subscribed their feed there, and into a push to a friend they share the event with. Those recipients, their countries and the transfer mechanisms are listed in §7 and §8. This data is kept for as long as the event itself exists. You can ask us to delete it — write to kairoscope.contact@gmail.com: we remove the name from the event's title and erase the name and the email, while the event itself stays in the owner's calendar. You have the same rights as those described in §12, even though you have no account here.

"Helper": when a friend can fill your schedule. You can let a friend — only a friend with whom you already have an accepted friendship — suggest events for your free time and edit the events they added themselves that you have already accepted. For the days they look at, the helper sees the title, time, category and your note on each event — the widest disclosure anywhere in this feature, and a deliberate one: to suggest a time around "pick up my test results," a helper needs the note itself, not just a title. An event from a connected Google or Microsoft calendar is shown to them without its note: that text is somebody else's words, not yours. A helper can never see or set anything about how you are feeling — no mood, no energy level, no medication data: none of those fields exist in any request a helper can make.

Kairoscope marks every event with who added it — you or the helper — and does not erase the grant record itself even once it is revoked: both are part of your data export (§12) and remain proof of who had access and when, even after that access has ended (retention period — §11). You can revoke access at any time — either you or the helper can do it — and the right to write into your schedule ends with the next request to the server, not the next time the app is opened. Events you have already accepted from a helper stay in your calendar and keep reminding you like any other event of yours, precisely because you accepted them. If you end the friendship with that person, access is revoked automatically.

4. Health data

Special category of data (Article 9 GDPR). The emotion diary, body map, triggers, state notes, mood and fatigue check-ins, hourly energy markers, and your medication schedule and dose history are health data. We process them on the basis of your explicit consent (Art. 9(2)(a) together with Art. 6(1)(a)) and only to show you your own entries, reminders and trends.

Today that consent is expressed by you turning these features on and writing the entries yourself. A dedicated confirmation that records the date and the version of this text is being added — this page will be updated with it.

Neither feature does anything until you start it yourself: a diary entry exists only when you create it, and medication reminders exist only when you add a schedule.

This data is never used for advertising and never shown to friends. Diary entries and medication data are not sent to AI providers without the separate "mood AI" consent (§5). One exception we name plainly: as soon as you turn on the general "AI features" switch, your lists of what drains and what restores you go to OpenAI along with the day's schedule — in the day's fatigue hint and in day planning; the recovery suggestion sends the restores list. You do not have to open the fatigue hint for this: using any of those features is enough. That happens under the general AI consent, not under "mood AI". The hourly energy markers themselves, and the mood and fatigue check-ins, are not sent there. The free-text diary note, the medication name and AI chat messages are encrypted at field level; the remaining diary signals (emotion labels, body areas, triggers, scales) are stored without field-level encryption, because they are what your own trends are computed from.

Medication reminders and what the notification says. A medication name can reveal a diagnosis, which is why it is encrypted at field level in our database — and, for the same reason, why by default it is not part of the notification text. The push says only "Time to take your medication"; the app fetches the actual name from our own API and renders it on the device. The reason is plain: a notification reaches you through intermediaries — Expo (650 Industries, USA), then Apple APNs or Google FCM — and they read the notification text. In Settings → "Medication" there is a switch, "Show the medication name in notifications", off by default; if you turn it on, the name goes to those services and onto your phone's lock screen. What the switch cannot hide in either state: the fact that you receive medication reminders, and when — the notification is tagged as a medication one so that the "Taken" button works and so that Android does not mute it along with ordinary reminders. Hiding that too would mean giving up server-side medication reminders altogether. Web push is encrypted end-to-end (VAPID), so there not even the delivery service reads the text; the switch still governs it, because "show the name in notifications" is one promise, not two.

You can export the diary as a separate JSON file or erase it entirely without deleting your account: Settings → "Emotion diary", in the mobile app and in the web version alike. It is also part of the full account export (§12) and is erased together with the account. Medication schedules are deleted one by one in the "Medication" section, together with that schedule's dose history; a copy of your medication data comes from the account export. For the mood and fatigue check-ins and the hourly energy markers there is no standalone erase control at all — §11 spells this out.

5. AI processing

AI features (voice transcription, chat, categorization, suggestions) only activate after you opt in in your profile, and send AI providers the minimum context needed — event titles, times, free slots, and, for the day's fatigue hint, the recovery suggestion and day planning, your drains/restores lists (§4). Text features (chat, categorization, suggestions) are processed by OpenAI; speech recognition (voice→text) is processed by Groq (whisper-large-v3-turbo), with OpenAI Whisper as fallback. Emotion diary entries go to AI only under the separate "mood AI" consent plus a 16+ confirmation; for the weekly review the server computes aggregates and does not send the notes themselves. Facts are computed deterministically on our server; the AI never acts without your confirmation.

Automated decisions (Article 22 GDPR). Kairoscope makes no decisions about you based solely on automated processing, and carries out no profiling with legal or similarly significant effects. The AI only proposes: create an event, suggest an emotion label, find a free slot. Every proposal is applied only after you confirm it in the interface, and the server discards proposals that refer to events or contacts that do not exist. Facts (overlaps, free slots, statistics) are computed deterministically on our server, not by a language model. The crisis support card is triggered by deterministic phrase matching on your device; it is never sent anywhere, never notifies anyone, and never blocks an entry from being saved.

6. Where data lives

PostgreSQL, attachment files and backups live on a Hetzner Online GmbH server in Germany (EU). Backups are encrypted.

7. International transfers

Primary storage is in the EU, but some processing takes place at providers based in the United States: OpenAI, Groq Inc., RevenueCat Inc., Expo (650 Industries, Inc.), Google LLC (Firebase, FCM, Maps, SMTP), Apple Inc. (APNs), Microsoft Corp. (calendar sync). What exactly each of them receives is listed in §8. Emotion diary data is transferred to the United States only if you have separately enabled "mood AI"; otherwise it does not leave the EU.

The operator of Kairoscope is based in Ukraine — a country for which the European Commission has not adopted an adequacy decision — so the operator's own access to the data is also a transfer outside the EEA.

The Article 46 mechanisms for such transfers are the European Commission's Standard Contractual Clauses, as part of the data processing agreements with the providers, and, where it applies, the recipient's certification under the EU-US Data Privacy Framework. We are currently completing those agreements with each provider; you can ask for the current status and a copy of the safeguards in force at kairoscope.contact@gmail.com. This page will be updated as soon as that is done.

8. Who we share data with

RecipientWhat we sendWhyCountry
Hetzner Online GmbHAll service data (hosting)Hosting the database, files and backupsGermany
OpenAIEvent and task titles, times, free slots, chat messages, your drains/restores lists (for the day's fatigue hint, the recovery suggestion and day planning); audio as fallbackText AI features, fallback speech recognitionUSA
Groq Inc.Voice input audioSpeech recognition, primary providerUSA
Google / MicrosoftOAuth token, reading your calendarSync, only if you connected itUSA
Google Maps PlatformCoordinates and addressesGeo reminders, travel time, address suggestionsUSA
Google FCM, Apple APNs, Expo (650 Industries)Push token and the notification text, including event titles. Not the medication name: by default a medication reminder says only that a dose is due, and the app renders the name itself (see §4). If you switch on "Show the medication name in notifications" yourself, the name goes here tooDelivering reminders to your deviceUSA
Google (Gmail SMTP)Email addresses and message contentsVerification, password reset, email remindersUSA
RevenueCat Inc.Your Kairoscope account identifier, purchase identifier, subscription statusVerifying subscription statusUSA
Firebase Analytics (Google)Anonymous app-instance identifier, device model, OS and app version, language, approximate location from IP; sign-up and sign-in events plus Firebase's standard automatic set (app opens, session starts, engagement time, app and OS updates)Measuring app advertising performance (§13)USA
Apple, GoogleTransaction dataPayment processing in the app storesUSA
GlitchTipApp version, device, screen sequence, account identifierCrash reports; this is our own server, not a third partyEU

In addition, if you turn on the weather for the day, your device itself calls the Open-Meteo forecast service with coordinates rounded to about a kilometre. Those coordinates do not pass through our server and we do not store them.

The Google and Apple sign-in buttons in the web version work the same way — around our server. When you open the login or sign-up page, your browser loads the button scripts from accounts.google.com (Google Identity Services) and appleid.cdn-apple.com (Sign in with Apple). This happens as the page opens, before you press anything, so your IP address and the address of that page become known to Google and Apple even if you end up signing in with a password or simply close the tab. Those requests go from your device; we neither see nor store anything from them, and what the provider does with them is decided by the provider, not by us. The mobile app does not do this: its sign-in screen loads nothing, and signing in with Google or Apple starts only when you tap the corresponding button.

We do not sell data. We announce a new recipient in the app.

9. Location

Kairoscope accesses your device's precise location only when you turn on a feature that needs it (geo-reminders, "leave on time", address suggestions). We collect GPS coordinates and the addresses (home/events) you enter, and use them to trigger geo-reminders (when you arrive at or leave a place), compute travel time and departure nudges, and autocomplete addresses. For geo-reminders the app accesses location in the background — only to match it against places you set up yourself; that matching happens on your device, and those background coordinates are not sent anywhere. The coordinates and addresses you save, and your current position when an event shows the "leave on time" estimate, are sent to Google Maps Platform to compute routes, travel time and address suggestions. If the day's weather is enabled, coordinates rounded to about a kilometre go from your device to the Open-Meteo forecast service. You can remove the geo condition from a reminder, delete saved places, and revoke the location permission in your system settings at any time. Location is never used for advertising or sold.

10. Calendar link (ICS)

If you enable calendar subscription, we create a unique link that serves your calendar without a password: anyone who obtains the link sees all of your events — and not only the title and time, but also each event's note text and location, for your whole history, not just today. The note is the same free text that §14 calls the most sensitive thing you write, so treat this link as a key to the entire calendar, not as a list of titles. We store the token itself hashed and encrypted, so it cannot be read out of the database. Do not publish the link. There is no revoke button yet: if the link ended up somewhere it should not have, write to kairoscope.contact@gmail.com and we will replace it.

11. Retention

CategoryRetention
Account, calendar, tasks, categories, templates, attachments, and everything else you create in the app: saved places, booking links, time goals, if-then follow-ups, hidden imported eventsFor as long as the account exists. Deleting the account in your Profile erases them immediately, together with the attachment files
The name and email of a guest who booked a slot through your linkFor as long as the event itself exists in the owner's calendar. They go with the event, with the deletion of the owner's account, or earlier at the guest's own request (see the booking paragraph in §3)
Emotion diary: state entries and "moments"For as long as the account exists, or until you erase them yourself — a single entry from its card, the whole diary with the button in Settings → "Emotion diary" (app or web). We set no automatic expiry: this is your personal archive, and how old it gets is your decision
Medication: schedules and dose historyFor as long as the account exists, or until you delete the schedule yourself in the "Medication" section — deleting a schedule takes its dose history with it
Mood and fatigue check-ins, hourly energy markersFor as long as the account exists. There is currently no button in the app that erases these records: a day's check-in can be overwritten with a new value, erasing the diary does not touch them, and they go when the account goes. To have them removed sooner, ask us by email (§12). We set no automatic expiry
Voice input audioNot stored: sent to the transcription provider and discarded as soon as the text comes back
Assistant chat historyFor as long as the account exists. We set no automatic expiry: it is your conversation, and the app shows it back to you
Live-session event chat90 days
Unsaved event draft30 days after the last change. This is what you started typing into the form and did not save; a saved event is the row above
Calendar sync OAuth tokensFor as long as sync is connected; disconnecting it in your Profile deletes them
Session refresh tokensUntil expiry; expired ones are deleted by a daily job
Email-verification and password-reset tokensUntil expiry (a link lives for hours); expired ones are deleted by a daily job, used ones the moment they are used
Device push tokensWhile the device is active. A token whose app has not opened in over 180 days is deleted; the next launch registers it again
AI usage counters (free-tier quotas)24 months
Schedule proposals from a helper90 days after the decision (accepted or declined); ones still awaiting a decision have no expiry — that is one you have not answered yet
"Helper" grants — who was allowed to fill your schedule, and whenFor as long as the account exists, including an already-revoked grant: a revoked row is proof of who had access and when, so we do not erase that either
Sent-reminder log2 days
Snoozed ("10 more minutes") reminders1 day
In-app notificationsRead ones are deleted after 30 days; unread ones stay for as long as the account exists
Encrypted backups7 days (attachment archives 3 days), then deleted. Deleted data can survive in a backup copy for the same period
Server technical logsKept no longer than needed for diagnostics and abuse protection
Crash reportsKept while needed to fix the bug in question
Messages sent through the feedback form24 months, or sooner at your request. If you sent it from your account's address and that address is verified, deleting the account erases the message too, along with the name and the address. Messages sent from a different address cannot be attributed to the account and are not erased with it: the form works without an account. The same holds for an address we cannot tie to exactly one account (for instance, when two accounts differ in it only by letter case): we have no basis for attributing such a message to either of them, and it goes at the general period above. The email code for that form lives 10 minutes, a used one disappears at once, and unused ones are removed by a daily job
Subscription recordsFor as long as the account exists. The transaction data itself is kept by Apple, Google and RevenueCat under their own retention
Consent records: what you agreed to, when, and which revision of the textFor as long as the account exists. This is the evidence that consent existed (Art. 7(1)), so it lives as long as the account and goes with it. Withdrawing does not erase the record; it adds a withdrawal row

12. Your rights

Your rights. You have the right to: access your data and receive a copy in a machine-readable JSON format (Art. 15, 20); rectify inaccurate data (Art. 16); erase it, the "right to be forgotten" (Art. 17); restrict processing (Art. 18); object to processing we carry out on the basis of legitimate interest (Art. 21); withdraw any consent.

How to exercise them. Exporting all your data as JSON and deleting your account are in your Profile, in both the web version and the mobile app, without contacting us. A separate export and erasure of the emotion diary is in Settings → "Emotion diary", in both versions. The health-data consent (and its withdrawal), the AI features switch, the separate "mood AI" consent and the 16+ confirmation are also in both versions, under Settings. Everything else, including changing your email, restriction of processing and objection, by email to kairoscope.contact@gmail.com. We respond within one month of the request; in complex cases the period may be extended by a further two months, and we will tell you within the first month (Art. 12(3)). We may ask you to confirm your identity by writing from the account's own address if we have reasonable doubts.

Withdrawing consent takes effect for the future and does not make processing that took place before withdrawal unlawful (Art. 7(3)). Data already sent to OpenAI or Groq to fulfil your request cannot be recalled from their systems by us.

Complaints. If you believe we are processing your data unlawfully, you have the right to lodge a complaint with a data protection supervisory authority in the country of your residence, your place of work, or the place of the alleged infringement. The list of EU member-state authorities: edpb.europa.eu/about-edpb/about-edpb/members_en. In Ukraine the supervisory authority is the Ukrainian Parliament Commissioner for Human Rights: ombudsman.gov.ua. You do not have to contact us first, though we usually resolve matters faster.

13. Cookies, local storage and analytics

Cookies and local storage. On the web: an HttpOnly cookie for the authentication refresh token, localStorage for theme, language and session cache; two keys holding personal data (rounded coordinates for the weather, and your own recovery notes) are wiped when you sign out. In the mobile app the refresh token lives in the OS secure store (Keychain / Android Keystore), and the offline change queue and recovery notes live in a separate encrypted local store whose key is held by the same OS store; signing out wipes them along with any downloaded attachments. Appearance settings (theme, language) stay — they are not personal data. We use no advertising cookies and no pixel trackers on the web.

Analytics. With your consent we use Firebase Analytics (Google Ireland Ltd. and Google LLC) to measure the performance of our app advertising. The app itself sends two events, sign-up and sign-in. On top of those, Firebase collects its own standard usage events: app opens, session starts, engagement time, app and OS updates. They carry an anonymous app-instance identifier, your device model, OS and app version, language, and an approximate location derived from your IP address. Those automatic events cannot be switched off one by one — consent covers the whole set. We have turned off automatic screen-view reporting, no content from your calendar, tasks or diary is sent, and we do not collect the device advertising identifier. Without consent, analytics does not run at all. Consent is given separately on each device and does not carry over between them; you can change your mind at any time in Settings. This applies to app version 1.0.2 and later. The switch lives in the app's own code, so on earlier versions still installed on a device analytics keeps collecting without it; updating the app turns the gate on. The web version has no third-party analytics at all, but the login page does load the Google and Apple sign-in button scripts (§8), and that alone reveals your IP address to them.

14. Security

Transport: HTTPS (TLS 1.2 and 1.3, HSTS). Authentication: JWT together with a refresh token in an HttpOnly cookie, passwords protected with bcrypt. Special-category data, namely the free-text emotion diary note, medication names and AI chat messages, is additionally encrypted at field level with AES-256-GCM using a key held separately from the database; without that key the server refuses to start in production. Structured diary signals (emotion labels, body areas, triggers, scales) are stored without field-level encryption because they are needed to compute your own trends; the server has no disk-level encryption at present, which is why the most sensitive element — the free text — is protected at field level instead. Calendar sync OAuth tokens are encrypted, and the calendar subscription token is stored both hashed and encrypted. Backups are encrypted with AES-256 before being written to disk, and the script refuses to make a backup without a key. Crash reports pass through a filter that strips the content of your entries, access tokens, your email and your IP address — only the account identifier remains. In the mobile app the diary can additionally be locked with a PIN held in the OS secure store.

15. Children

Kairoscope is intended for people aged 16 and over. In EU member states that have set a lower digital consent age (from 13), the service may be used from that age. At registration we ask you to confirm that you meet the age threshold; the one exception is an account created by a first sign-in with Google or Apple from the sign-in screen (Terms, §1). We do not knowingly collect data from anyone below the applicable threshold. AI features over the emotion diary additionally require a separate confirmation that you are 16 or older; that confirmation can be withdrawn at any time in Settings, and withdrawing it switches "mood AI" off with it. If you are a parent and believe your child has created an account, write to kairoscope.contact@gmail.com and we will delete the account and all data within 30 days.

16. Google user data & Limited Use

When you connect Google Calendar sync, Kairoscope requests read-only access to your Google Calendar (the Google Calendar "calendar.readonly" scope). We use this access solely to read your existing calendar events and show them alongside your Kairoscope events, so you can see your whole day and avoid scheduling conflicts. We never create, edit, or delete anything in your Google Calendar.

Kairoscope's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, Google Calendar data:

The encrypted OAuth token is stored only while sync is connected; disconnecting sync in your Profile deletes it and revokes access. You can also revoke access anytime at myaccount.google.com/permissions.

17. Changes to this policy

Material changes are announced in the app.

This policy is published in Ukrainian, English, Spanish and French. The Ukrainian version is the authoritative one; the others are translations provided for convenience, and in case of any discrepancy the Ukrainian text prevails. This does not limit any of the rights described in §12, which you can exercise in any of these languages.

18. Contact

kairoscope.contact@gmail.com