Legal
Privacy Policy
Last updated: 22 May 2026
This is a placeholder version pending legal review. By using our apps and websites you agree to these terms in their current form. Updated versions will be posted here.
This Privacy Policy explains how Kodra Holdings Limited ("Kodra Holdings", "we", "us") collects, uses, and protects information when you use our portfolio of consumer apps and websites.
1. Overview
Kodra Holdings Limited operates a portfolio of consumer apps and the marketing site at kodraholdings.com. This policy covers all apps in the portfolio unless an individual app publishes its own posted policy.
Current apps covered include:
- Haooze
- Echo
- Kodra Sal Stylist
- Angaza Smartfarm
- 75 Hard Tracker
- Future products launched under Kodra Holdings
Where a specific app posts a more detailed policy in its store listing or in-app settings, that policy controls for that app.
2. Information we collect
Account information
When you create an account: email address, display name, and (if you choose to provide it) your full name. Authentication is handled by Google Firebase Authentication.
Usage data
Anonymized events describing screens visited and features used. This is only collected when you have opted into product analytics. You can opt out at any time from in-app settings.
Device information
App version, operating system, country, and language — used for product support, crash reporting, and to roll out features safely.
Content you provide
Photos, listings, messages, fitness logs, posts, and any other content you create or upload inside one of our apps. We process this content to deliver the feature you used it for (for example, displaying a listing on Haooze or storing a workout on 75 Hard Tracker).
Payment information
Payments are handled by Apple App Store, Google Play, or Stripe. We do not store full card details. We may receive a tokenised transaction reference, a country code, and the SKU you purchased.
3. How we use information
- To operate, maintain, and improve the apps you use
- To respond to support requests and communicate about your account
- To detect, prevent, and respond to fraud or security incidents
- To comply with legal obligations
- To roll out new features safely (limited rollouts, A/B tests)
4. The cross-product data engine
Kodra Holdings runs an internal data engine across its portfolio (the "Haooze Engine" and the broader "Kodra Holdings Engine"). The engine uses anonymized, aggregated patterns of behavior across our apps to inform product decisions — for example, which features get prioritized, which markets to expand into, and where to fix friction.
We do not sell raw user data. We do not rent user lists. We do not share identifiable usage data with advertisers. Where we license insights to enterprise customers, those insights are aggregated and anonymized — never raw user records.
5. Sharing
We share information only with service providers who help us operate the apps, and only under contract that limits their use of the data to the service they provide for us. These currently include:
- Google Firebase (auth, storage, hosting, analytics)
- Anthropic (AI features in apps that use them)
- Resend (transactional email)
- Stripe / Apple / Google Play (payments)
- Railway (server hosting for some endpoints)
We do not sell personal information. We may disclose information when required by law (subpoena, court order, regulatory request) or to protect rights, safety, or property.
6. Your rights
Depending on where you live, you may have rights under the EU GDPR, the California Consumer Privacy Act (CCPA), or the Kenya Data Protection Act, including:
- Access — request a copy of the personal data we hold about you
- Correct — request correction of inaccurate data
- Delete — request deletion of your account and associated data
- Port — request a copy in a portable format
- Object / restrict — object to or restrict certain processing
To exercise these rights, email legal@kodraholdings.com from the email address associated with your account. We aim to respond within 30 days.
Account deletion (in-app): Apple App Store guidelines require account deletion to be available inside the app. Each Kodra Holdings app provides an in-app "Delete account" option under Settings > Account. If you cannot find it, email us.
7. Children
Kodra Holdings apps are not targeted at children under 13. In the European Economic Area the relevant age is 16. We honor Apple's parental gating and Google Play's Designed for Families guidelines. If you believe a child under the applicable age has provided us with information, contact us and we will delete it.
8. Security
Data in transit is protected with TLS. Data at rest in Firebase is encrypted by Google. Access to production systems is restricted to a small team using two-factor authentication. We use Firebase Security Rules and App Check to limit what each client can read and write.
No system is perfectly secure. If we become aware of an incident that affects your data, we will notify you in line with applicable law.
9. Data retention
We keep account information for as long as you have an account, and for a limited period after deletion for fraud prevention, dispute resolution, and compliance with our legal obligations. Specific retention periods vary by app and data type.
10. Changes to this policy
We may update this policy. When we do, we post the updated version here with a new "Last updated" date. Material changes will be highlighted to users in-app where reasonable.
11. Contact
Questions, requests, or complaints: legal@kodraholdings.com.
Postal: Kodra Holdings Limited, Nairobi, Kenya. A registered office address will be published here once the registration process is complete.