Privacy
Privacy Policy
What this app collects, why it collects it, and what you can ask us to delete.
Kinorvia - Family Locator ("Kinorvia", "we") is a private location-sharing app for families, couples and friend groups. It lets people you choose see where you are, only when you decide, only for as long as you decide, and it keeps a record of every change so you can check. This policy says what Kinorvia collects, why, who receives it, how long it is kept and how to delete it. For any privacy question or request, write to us through the support page. The rules for using Kinorvia that go with the Terms of Use are in Community rules and reports, below. Kinorvia is published by the publisher named on its App Store and Google Play listings.
The short version
- You must be 13 or older. We keep only an age range, never a birth date.
- Location sharing is off until you turn it on, in each circle, for a time you choose. You can stop it everywhere with one tap.
- We keep only your latest position and overwrite it. We never keep a trail of where you have been.
- We show no ads and we do not sell your data or your location.
- AI helpers are off until you agree, and only ever see what a helper needs.
- You can export your data in the app and delete your account in the app or on the web, without a subscription.
- We have zero tolerance for stalking, harassment and abusive content. You can report people, check-ins, circles and AI answers in the app, privately and without a subscription (see Community rules and reports).
Age, teens and children
- At first launch Kinorvia asks for your birth month and year. Under 13, Kinorvia is not available to you, and we do not save what you entered. Otherwise we keep only an age range: 13 to 15, 16 to 17, or 18 and over.
- Teens (13 to 17): sharing starts off in every circle until you turn it on yourself, and the AI helpers stay off until you agree to them. If a teen age range is set on an account that is already sharing, all of its sharing is switched off.
- An age range can only move up. If you chose it wrongly, tell us through the support page.
- Kinorvia is not aimed at children and is not a parental-control or hidden-monitoring tool. There is no guardian role. A person is shared only when they turn their own sharing on.
- If you believe someone under 13 is using Kinorvia, report that person in the app or tell us through the support page.
What we collect and why
We use this information to run the features you ask for: circles, sharing, place alerts, check-ins, safety tools, notifications, your subscription, support and account safety.
Account. A guest account is created when you start using the app, and you can protect it with an email address and password. Firebase Authentication (Google) processes the sign-in; the password never reaches our servers except for the one-off web deletion described below. We also keep your display name, avatar, age range and an account identifier.
Devices. For each phone we keep an install identifier, a public signing key (its private key stays inside the phone's secure hardware), platform, app version, system version and device model. Requests carry a Firebase App Check token that proves the request comes from the real app. If you allow notifications, we keep the device's notification token.
Location, only while sharing is on. Your latest position, its accuracy, speed, movement state, battery level, charging state and time. If you also allow location "all the time" on your phone, the phone updates it in the background too; the app explains this before it asks for that permission. If you share approximately with every circle, your phone rounds each point to a grid about 1 km wide before it is uploaded. If you share exactly with any circle, the exact point is uploaded and Kinorvia rounds what an approximate viewer receives. Kinorvia collects your location, including in the background, only to share it with the circle members you choose and to send arrival and departure alerts for saved places, and never for ads.
Sharing health. Per device we keep the latest permission state, whether location services and background use are available, battery and low-power state, last upload time, queue size and an error code. It only powers the checklist that explains why a location looks old or is missing.
Circles and content. Circle names and membership, invitations and join requests, saved places (label, coordinates, size and type), your per-place alert choices, place arrival and departure events, check-ins (a preset and an optional note of up to 140 characters), location requests, safety timers, help alerts, sharing agreements, activity items, and your hides, blocks, mutes and reports.
Transparency records. The privacy ledger, revocation receipts and who-looked counters, described below. The optional sample circle is simulated: its people are not real accounts and cannot see your location.
Purchases. Apple or Google takes your payment; Kinorvia never receives a card number. We receive the store's transaction reference, product, status and expiry, check them with the store, and keep an encrypted store reference and status so we can restore access and stop one purchase being reused.
Notifications and settings. Your notification categories, quiet hours, and the choice of whether alerts show names and places.
Voice check-ins. If you hold the microphone button, your phone records a short voice note, which is sent for transcription (see AI helpers) and shown to you to confirm before anything is sent. We never store the audio.
Support and web deletion. A support message stores the name, address, subject and message you type. The web deletion page checks that the account is yours with your email and password, which are used once in memory and never stored or logged, or with a recovery code that we store only as a one-way hash.
Technical data. Your IP address and request details are used to deliver the service, limit abuse and secure requests. Short-lived request and rate-limit records expire on their own.
What we do not collect. Your contacts or address book, photos, health data, advertising identifiers, or anything for advertising or cross-app tracking.
Sharing your location
- Nothing is shared until you turn sharing on in a circle. Modes are off, live, paused, or until a time you choose, and precision is exact or approximate.
- Joining a circle never turns your sharing on. You can hide yourself from one person, pause, stop in one circle, or stop everywhere.
- The people in your circle see what you share with them. Someone who sees it can make their own copy; we cannot erase copies made outside Kinorvia.
- When you or the people who can see you change something, it is written to your privacy ledger.
- Location freshness and accuracy vary with your phone. Kinorvia is not an emergency service. If you or someone else is in immediate danger, call your local emergency number.
Ledger, who looked and receipts
- The privacy ledger lists who could see you, what changed and when, including when another member's AI request used facts about you. Only you can see your own ledger.
- Who-looked counters count how often other members' map or person views showed your position, per person, in 10-minute steps. You can see them in the Privacy and safety area of the app. Your own views are never counted.
- A revocation receipt is proof that access ended: when, and what remains. You get one when you turn sharing off, pause, narrow precision, hide someone, stop everywhere, revoke a place alert, leave or are removed from a circle, or withdraw AI consent.
Optional AI helpers
- AI helpers are off until you agree, with one separate AI consent for all of them. Turning it off is always available and also deletes your saved AI results. Teens need to agree too.
- Each helper is sent only what it needs: the text you type, place names, check-in notes you may already see, rough distance bands, your sharing settings, or a voice recording. People are sent as letters, not names. Exact locations, street addresses, email addresses, account and device identifiers and payment details are never sent.
- Our servers send the request to Kinorvia's own AI gateway (the Gowalk AI gateway), which passes it to an AI model provider working for us as a service provider. We do not control that provider's own retention or training. We do not promise that it deletes requests or does not use them to improve its models, and where it processes them is not specified. Avoid putting sensitive information in free text.
- AI answers are labelled as AI-generated, can be wrong, and never establish anyone's location or safety. You can report any AI answer in the app.
- Results are saved for 30 days, visible only to you, and deleted when you withdraw consent or delete your account. Voice recordings live only inside the one request and are deleted right after transcription.
Notifications
Notifications use Firebase Cloud Messaging with Apple and Google push services. Payloads carry no coordinates or addresses. Names and place labels appear only if you chose "Show who and where in alerts"; otherwise the text is generic. You can turn categories and quiet hours on or off. Safety alerts ignore quiet hours. Nothing in Kinorvia depends on notifications: the activity feed shows every event.
Optional diagnostics
Analytics and crash diagnostics are off unless you turn on "Share diagnostics" in Settings. When on, Firebase Analytics and Crashlytics receive app and device details, coarse feature events such as opening a screen or starting a purchase, and crash traces that contain only Kinorvia code locations. The SDK also uses an app-instance identifier and a coarse region derived from network information. They never receive your location, names, messages, AI text, passwords or purchase tokens, and no advertising identifier is used. Turning the setting off stops future collection, resets local analytics data and discards unsent crash reports. Firebase keeps data it has already received under its own retention settings, and we cannot promise its removal.
Maps and address search
- Your phone loads map tiles directly from OpenFreeMap using OpenStreetMap data. Those requests show your IP address and the map area you are viewing to OpenFreeMap, without your account details.
- When you save a place, your phone's own geocoder (Apple or Google) may receive the address text you type, or the map position you pick, to find or name it. If it finds nothing, and only when you submit, our servers send the text you typed to Photon or Nominatim (OpenStreetMap-based search services) with a nearby area rounded to about 10 km and never with your identity. Results are cached for 24 hours under a hash of the query, without the query text.
Who receives information
- Circle members receive what you share with them, which is what the sharing settings, hides, blocks and privacy ledger describe.
- Service providers process data to run Kinorvia: Firebase (Google) for sign-in, app verification, notifications and, only if you opt in, diagnostics; Apple and Google for purchases and push delivery; hosting and network providers for our servers; OpenFreeMap; the geocoding services above; and the AI gateway and provider above. They may process data in other countries.
- Onboarding and paywall screens are web pages served from our own domain. Loading them sends your language, platform, the app's identifier and your IP address, as any web request does.
- We do not sell your data or your location, and we show no ads. We disclose information only to the recipients above, or when the law requires it.
How long we keep information
- Position: only your latest position is kept, and each new one overwrites it. There is no history. It is deleted when your sharing ends or you stop everywhere, and deleted anyway if it has not been updated for 30 days.
- Place events and check-ins: 30 days.
- Privacy ledger entries and revocation receipts: 12 months.
- Who-looked counters: 30 days.
- AI results: 30 days, and removed at once when you withdraw AI consent. AI usage counters last 3 days. Voice audio is not stored.
- Reports of people, check-ins, circles and AI answers: 12 months.
- Deletion records: 12 months (a hashed account identifier and the install identifiers of its phones).
- Inactive accounts: accounts without an email address that have not been opened for 90 days and hold no active subscription are deleted automatically.
- Shorter items: activity feed items 30 days; check-ins you hid from your own feed 30 days; finished safety timers and help alerts 30 days, with the position in a help alert removed after 24 hours; invitations, join requests and location requests 30 days after they are decided or expire; ended sharing agreements 12 months; trip circles 7 days after they end; the simulated sample circle 30 days after you last use the app; notification delivery records 7 days; notification tokens not refreshed for 270 days; address search cache 24 hours; revoked devices 30 days.
- Purchase records: kept while they give anyone access. Once a purchase gives no one access, for example after the account is deleted or the subscription has ended, its encrypted store reference is removed 12 months later.
- Sign-in and diagnostics: your Firebase sign-in record stays until you delete your account. Firebase holds optional diagnostics under its own settings.
- Support messages are kept while we handle the request and as needed to record how it was resolved.
Data past its retention period is excluded from the app straight away and removed by daily cleanup jobs.
Your choices and rights
- Stop, pause or narrow sharing at any time, hide from a person, block, mute, leave a circle or turn notifications, diagnostics and AI helpers off.
- Withdraw AI consent, which deletes your saved AI results and gives you a receipt.
- Export your data as one JSON file from Settings, Account. It works without a subscription.
- Delete your account, as described next.
- For access, correction, objection or any other privacy request, write to us through the support page. Use the export and deletion tools where they fit, because they are how we can be sure the account is yours.
Deleting your account
- In the app: open Settings, then Account, then Delete my account. It works without a subscription and shows what is deleted first.
- On the web: use the account deletion page with your email and password, or with the recovery code you can create in Settings, Account. An account without an email can only use the code, so create one in the app while you can. If you never do, an unused account without an email is deleted automatically after 90 days of inactivity.
- What is deleted at once: your profile, circle memberships, sharing settings, latest position, check-ins, saved-place consents, safety timers and help alerts, the activity items about you, your own privacy ledger and receipts, notification tokens and devices, AI consent and results, and your recovery code. Circles you own pass to another member, or are deleted when you are the only member. Some records of other people that mention you are not yours to delete: they are listed below under What stays.
- Your sign-in: straight after your data is gone we ask our sign-in provider (Firebase Authentication) to delete your sign-in. Deleting in the app, or on the web with your email and password, uses your own sign-in to do it. Deleting with a recovery code (any account can create one, with or without an email), and the automatic deletion of an inactive account, have no sign-in of yours to use. When a removal cannot be done straight away it is retried automatically for up to 7 days where our systems allow it. If it still does not finish, the sign-in record stays with the provider: for a guest account it holds only an identifier, with no name or email; for an account you protected with an email and password it holds that email address and its password sign-in. The web deletion page says when the removal did not finish, and in any case you can ask us to remove it through the support page.
- What stays, your deletion record: for 12 months, so a repeated or replayed request cannot bring a deleted account back, we keep a one-way hash of your account identifier and, in plain form, the install identifiers of the phones you used Kinorvia on. An install identifier is derived from the app's public key on that phone; it is not your name, your email, a hardware serial number or an advertising identifier. While a sign-in removal is being retried, a retry job also holds the plain account identifier for at most 8 days.
- What stays, your name in other people's records: the records of other people are theirs, so they are not removed with your account. Your display name, as it was when the record was written, stays in the circle activity item that says you left (30 days) and in the privacy ledgers of the other members of your circles, in entries such as that you joined or left a circle, that they hid themselves from you or that they blocked you (12 months). Only the person whose ledger it is can see those entries.
- What stays, saved places you created: in a circle that carries on, they stay with that circle, no longer linked to you, until the circle ends or its owner or an admin removes them.
- What stays, reports and purchases: moderation reports for up to 12 months (a report you made loses its link to you, while a report about you or your content keeps what was reported, such as the name, note text and account identifier, so that we can act on it); and the encrypted store reference of a purchase, without any link to you, up to 12 months after it stops giving anyone access.
- Your subscription is not cancelled when you delete your account. Manage or cancel it in your Apple or Google Play subscription settings.
Community rules and reports
These rules go with the Terms of Use, and by using Kinorvia you agree to follow them. They apply to everything you put into Kinorvia: display names, circle names, place labels, check-in notes, sharing agreements, AI text, reports and support messages.
You must not:
- follow, track or locate anyone without their agreement, or use Kinorvia to stalk, harass, bully, threaten or intimidate anyone;
- pressure or trick someone into sharing, or secretly use Kinorvia on someone else's phone to watch them;
- pretend to be another person, or use a name meant to mislead;
- put abusive, hateful, sexual, violent or illegal content, or anything that endangers or sexualises a child, into names, notes, labels or agreements;
- send spam, scams or links and contact details meant to take a conversation out of the app.
We have zero tolerance for objectionable content and abusive behaviour.
- Report in the app: open a person and choose "Report" followed by their name; choose "Report" under a check-in, which opens "Report this check-in"; open a circle and choose "Report this circle"; choose "Report" under an AI answer, which opens "Report this AI result"; or, if someone is following your location without your agreement, open Privacy and safety, choose "Worried someone is tracking you?" and then "Report a concern", which opens "Report unwanted location access". Reasons include harassment, impersonation, unsafe content, spam and tracking without consent. For an abusive place name or note, report the circle or the person who wrote it. Reporting never needs a subscription.
- Reports are private. The person you report is never told it was you. A reported check-in disappears from your feed straight away. You can also block or hide from that person, mute them, leave the circle, or stop sharing everywhere.
- What we do. A person reviews reports. We may remove content, and we may restrict, suspend or close accounts that break these rules. A report is not an emergency call and is not watched in real time.
- Names, check-in notes, circle names, place labels and agreement text pass an automatic filter that refuses links, contact details and blocked words. The filter does not replace reporting.
Security
Requests travel over encrypted connections. Each request carries your Firebase sign-in, an App Check token and a signature made with a key that never leaves your phone's secure hardware, and the server checks all three. No service is perfectly secure, so keep your device, password and recovery code safe.
Changes to this policy
The current policy is always published at this address. If a change affects what the AI helpers send or how long their results are kept, the app asks for your AI choice again before using them.