English · العربية
Privacy policy
Khaili is an offline-first horse and stable operations application operated by Zayed Albloushi. This policy applies to the complimentary, operations-only TestFlight pilot for an unspecified number of stables, their authorized users, and private horse owners selected and invited by Zayed Albloushi.
Data we handle
Khaili handles email address, account profile, workspace membership and permissions; basic horse profile data such as name, breed, sex, birth date and stable location; stable-care schedules and events; tasks, programs, workouts, rides and reminders; support requests; account exports and deletion requests; device and synchronization security records; and minimal operational audit events. A user-initiated ride may include precise or approximate GPS route, timestamps, distance, speed and device-motion measurements.
Excluded pilot data
The pilot does not collect or permit medical, medication, vaccination or veterinary notes; clinical-readiness evidence; passport, microchip or registry identifiers or documents; Advisor generation; raw research collection or upload; SMS signup; or Apple and Stripe billing. Do not enter excluded data in names, notes, tasks, support messages or uploads.
Why we use data
We use permitted data to authenticate users by email, provide authorized stable operations, support offline work, record a ride when requested, synchronize approved devices, enforce access and the 40-active-horse limit, deliver reminders, create exports, process deletion requests, respond to support and investigate reliability or security incidents.
Sharing, hosting and processors
Records are available only to people authorized for the relevant stable workspace or horse. Supabase provides authentication, PostgreSQL, private storage and required server functions, with the pilot project hosted in Mumbai, India. Resend delivers email sign-in codes and privacy-safe service alerts. Cloudflare hosts the public policies, support pages, admin web application and five-minute scheduler. Apple provides TestFlight distribution and device services. These processors may handle network and service metadata under their own terms. Khaili does not sell data, use advertising, perform cross-app tracking or enable mobile telemetry.
Ride location and motion
Ride recording starts only after an explicit user action. Location may continue while that active ride is in the background and the operating system displays its location indicator. A user may deny permission and manually log a ride. Research mode and raw research upload are disabled.
Offline storage
Authorized records may be cached on your device so core work can continue offline. Credentials use platform-protected storage. Encrypted ride batches are processed on the device; the operational route and summary can synchronize to the authorized workspace. The app revalidates access, applies an offline authorization time limit, locks expired caches, and purges data after logout, account switching, deletion, or detected access revocation. Offline devices cannot learn about revocation until they reconnect or the authorization lease expires.
Backups, retention and deletion
The hosted pilot uses daily backups with a seven-day provider retention window. The operational backup objective is no more than 24 hours of data loss and the recovery target is four hours after the operator confirms a recoverable incident; these are targets, not guarantees. A deleted ride is recoverable for 30 days before route data is purged. Account holders can initiate deletion inside Khaili under More → Privacy and account. Direct identifiers, credentials, device registrations, memberships and private exports are removed when deletion completes. Deletions may remain in encrypted backups until those backups rotate out. Shared operational records may require transfer, workspace deletion review or pseudonymized retention for other authorized users and security audit.
Your controls
The app provides account-data export, account-deletion initiation, language and notification controls, and support access. Export links are private and short-lived. Contact info@khaili.ae for privacy or support.
Security and limits
Khaili uses row-level authorization, protected server functions, private storage, short-lived links, local purge controls, and encrypted platform credential storage. No system is risk-free. Horse-care information is an operational aid and does not replace a veterinarian or emergency service.
Children and changes
Khaili is intended for authorized stable professionals and adult account holders, not children. Material changes will be dated and published at https://khaili.ae/privacy.
Khaili