# Kogoto Privacy Policy **Status: DRAFT — prepared for legal review. Not yet confirmed by a qualified legal professional. Effective date: 2026-08-13. Version: 2026-09-23.** This document describes, as accurately as the current Kogoto app and backend actually behave, what personal data Kogoto processes, why, and what choices and rights you have. It is written to match the real, current implementation — not a generic template. Where a legal conclusion (e.g. the correct legal basis for a specific processing activity) has not yet been confirmed by a lawyer, this document says so explicitly rather than asserting compliance it cannot yet prove. ## 1. Who operates Kogoto Kogoto is currently operated by a private individual based in Austria, not a registered company. Contact for any privacy question, request, or concern: **kogoto2026@gmail.com**. The operator's full legal name and a publication-safe postal address are not published in this document. This section is therefore not yet sufficient for a formally complete Austrian provider-information (Impressum) statement — see `docs/OWNER_LEGAL_INPUTS_REQUIRED.md` in the Kogoto repository, which tracks this as an open item for public Production release. It does not affect your ability to reach Kogoto at the contact address above, exercise your rights under Section 9, or delete your account under Section 10. ## 2. Data protection contact For any question about this policy or your data: **kogoto2026@gmail.com**. ## 3. What personal data Kogoto processes Kogoto is a proximity-based social app: you create an account, build a profile, discover nearby Kogoto users over Bluetooth, connect with people you choose to, message your connections, and optionally post short-lived "Stories." The data below reflects exactly what the current app and backend collect to make that work — see `docs/DATA_INVENTORY.md` in the Kogoto repository for the complete, itemized technical inventory this section summarizes. **Account & identity** - First name, email address, password (stored only as an Argon2 hash — Kogoto never stores or can recover your actual password), date of birth (used to compute and verify your age; only your age, never your exact birth date, is ever shown to another user), country. - Email verification status and the timestamp it was verified. - The Terms of Service/Privacy Policy version and timestamp you accepted at registration. - **If you sign in with Google or Apple (optional):** the account identifier that provider assigns you (a stable opaque id), the email address the provider asserts (for Apple this may be a private-relay forwarding address), and your name if the provider supplies it. These come from the provider's signed identity token, which Kogoto's backend verifies; Kogoto keeps **no** Google or Apple access tokens and stores only the link between your Kogoto account and that provider identifier (`auth_identities`). Using a provider sign-in is never required — email and password remain available, and you can add a password later. **Profile** - Bio, interests, your profile picture, and any additional gallery photos you choose to upload (up to 6). - Your gallery photos are visible to the same people who can already see your profile picture: your accepted connections and people with a pending connection request between you, people who find you in Nearby while your Nearby is on, and people checked in at the same Kogoto Spot at the same time. Never to anyone you blocked or who blocked you, and not while your account is suspended. A photo you delete is no longer shown to anyone. **Stories** - Photos and optional captions you post as Stories, visible only to your accepted connections, and automatically removed after 24 hours unless you choose to keep a copy in "Saved"/"Old Stories" (which then stays private to you only). - Who has viewed one of your Stories, and when — visible only to you, the person who posted it. Viewing your own Story is never recorded. - Who has liked one of your Stories, and when — visible only to you. If you like someone else's Story, you can see your own like on it, but not whether anyone else liked it. **Proximity ("Nearby")** - Whether you have Nearby discovery turned on, and for how long. You choose each session's length (30 minutes, 1 hour, 2 hours or 4 hours). It always switches off automatically at the end, and you can turn it off or change the length at any time. There is no "always on" option. - A short-lived, randomly-generated, rotating Bluetooth identifier your phone broadcasts while Nearby is on — it does not contain your name, email, or any other identifying information by itself; the Kogoto backend is what maps it back to your account when another Kogoto user who also has Nearby on discovers it. - Kogoto does **not** use GPS and does not collect or store your device's exact geographic coordinates. Proximity to another user is only ever shown as an approximate label (e.g. "very close"), never an exact distance. **Event Mode** - If you choose to join a temporary "Event" (an optional feature you can turn on in Settings — for a festival, conference, party, or any other gathering), Kogoto stores which event you belong to and for how long (up to 24 hours, capped to the event's own lifetime, and ended immediately if you turn Event Mode off). - Joining an event does **not**, by itself, make you discoverable to anyone. It only helps Kogoto also show you to other members of the same event *while Nearby discovery is separately turned on for both of you* — the same Nearby session rule above still applies in full. There is no way for anyone to see who else is in an event, and Kogoto keeps no history of which events you've joined in the past. - If you create or join an event using a name you type yourself ("Quick Event"), that name is stored and shown to other members of that specific event. An official event (created ahead of time by an organizer and joined via a QR code) may also show an organizer name, short description, and logo to its members. **Kogoto Spots** - If you join a Kogoto Spot (a persistent real-world place — a café, bar, club, university, gym, or venue — that you join via its QR code or a short code), Kogoto stores that you are currently present there and until when (you choose a duration, capped at 24 hours), and, if you follow a Spot, that follow. - Other people only ever see an aggregate count of how many people are currently at a Spot, unless they are also currently checked in at that same Spot at the same time. Kogoto keeps no public attendance list and no history of Spots you have visited once your session there ends; a follow is removed when you unfollow or delete your account. A Spot has no location coordinate stored anywhere — its real-world location is implicit in its name and description only. - Two people who are both checked in at the same Spot at the same time can send each other a normal connection request without turning Nearby on. This doesn't create any Bluetooth/proximity record and doesn't reveal any distance. **Announcements from Spots you joined or follow, and Events you joined** - The organizer of a Spot or Event (Kogoto itself, or an approved independent Creator — see below) can send operational announcements through Kogoto. This isn't carrier SMS. - For a **Spot**, the organizer chooses the audience for each announcement: the people **currently joined** to the Spot, the Spot's **followers**, or **both** (someone who is joined *and* follows gets it only once). **Following a Spot therefore can subscribe you to its announcements.** For an **Event**, only people who currently joined it can receive them (Events have no followers). - The organizer can also send an announcement to only a set number of the eligible people instead of all of them. Kogoto then picks that many recipients at random; the organizer can't choose, and never learns, who they are. - You stop receiving a Spot's announcements when you leave (or your visit ends) **and** don't follow it — unfollow to stop follower announcements. You stop receiving an Event's announcements when you leave it or it ends. You receive none from someone you blocked or who blocked you, or while your account is suspended. - **Opt out:** turning off "Spot & Event announcements" in the app's notification settings stops all announcements to you — you then get neither a push notification nor an inbox copy. Eligibility, including this setting, is checked when each announcement is sent. - Kogoto calculates who receives an announcement. The organizer only sees how many people were eligible and how many it was sent to, never who they are or their contact details. - Kogoto stores each announcement (organizer, Spot/Event, audience chosen, text, time, number of eligible people and of recipients) and your copy of it (and whether you've read it), so it can show it in your in-app inbox. Announcements are deleted after 90 days. **Spot Feed posts and likes** - A Spot's organizer (Kogoto, or the Spot's Creator) can publish posts ("updates") with text and images on the Spot page. Kogoto stores each post, its images (re-encoded, with metadata such as location removed), which Event it links, who wrote it, and its status. Publishing a post doesn't notify anyone; an organizer can separately send it as an announcement (see above). - If you **like** a post, Kogoto stores that you liked it and when. Other users, the organizer and Kogoto's admin tools only ever see the total number of likes, never who liked. Unliking deletes the like, and your likes are deleted with your account or when the post is deleted. Liking a post never follows or joins the Spot and never subscribes you to announcements. - You can report a post in the app. Kogoto can hide or delete any post. **Creators** - Kogoto may approve independent organizers, businesses or people as **Creators**, who manage their own Spots/Events in the Creator portal. Creators are not Kogoto. If you apply, Kogoto stores your Creator status (pending/approved/rejected/suspended) and when it changed, which version of the Kogoto Creator Terms you accepted and when, the Spots/Events and images you submit, and an audit record of your Creator actions (for example creating, editing or submitting content and sending announcements) and of Kogoto's moderation decisions about them (approval, or rejection with its reason). - **Creator application.** To apply you give Kogoto your last name and/or organization name, a **phone number** and a short description of the Spots/Events you want to run. You can create the Kogoto account for this in the Creator portal: it's the same kind of account as in the app (verified by an emailed code, with the same profile details) and works in the app too. The phone number is **not verified**; it's used only by the Kogoto team to contact you about your application or your Creator content, is visible only to Kogoto's admins, and is never shown to other users or published. These details are kept while your account exists and deleted with it. `LEGAL_REVIEW_REQUIRED`: legal basis for the Creator application data (pre-contractual steps vs. legitimate interest). - Creator Spots and Events are reviewed by Kogoto before they appear in the app, and their QR code and join code only work once approved. An important change to approved content (for example its name, description, type, times, logo or links) sends it back to review, and it is hidden until approved again. Content published by Kogoto itself isn't part of this review. - Creators only ever see aggregate statistics for their own content (followers, people currently present, total joins, participants). They never see who followed or joined, or anyone's email, phone number or other contact details. **Connections & messages** - Connection requests you send or receive, their status (pending, accepted, declined, cancelled, expired, or blocked), and any short "Ask" question/reply exchanged before accepting. An accepted connection is what Kogoto calls a "Meetup." - The messages you send in a conversation with an accepted connection — text, and any photo you choose to send directly into the chat (including a "Meetup Souvenir" selfie) — and when each message was sent and read. - Any emoji reaction you add to a message, and whether a message is sent as a reply to an earlier one. **Blocking & reporting (safety)** - Who you have blocked (kept private — the blocked person is never told who blocked them). - Reports you file against another user, a message, a connection request, or a story, including the category and any description you provide. Reports are confidential — see the "How reporting works" page in the app and `docs/DATA_INVENTORY.md` for exactly who can see report content (only Kogoto's own operator, via the private admin tools — the reported person is never told who reported them). - Kogoto's administrators may review, publish, unpublish, reject or remove Spot/Event content, and keep an audit record of those moderation and admin actions. **Notifications** - Your device's push-notification token (if you allow notifications), and your per-category notification preferences. **Product analytics** - Kogoto records a small, fixed set of product-usage events tied to your account: opening the app; turning Nearby on or off; joining or leaving an Event; joining, leaving, following, or unfollowing a Kogoto Spot; the Meetup (connection) request / accept / decline / confirm / cancel steps; and whether a push notification to your device succeeded or failed (`user_events` — see `docs/DATA_INVENTORY.md`). - These events are stored only in Kogoto's own database. **No third-party analytics service, SDK, or advertising tracker is used**, and there is no generic event-tracking sink — only the closed list above. They contain no message or Story content, no location, no email address, and no raw Bluetooth, push, or advertising identifier. - They are only ever read as aggregates — total active users, retention, Meetup acceptance rate, feature-usage counts — never to build an individual profile or to target you, and they are deleted when you delete your account. **Security & technical** - Standard request/error logs kept by Kogoto's hosting provider and backend framework for operating and securing the service (see `docs/DATA_PROCESSORS_AND_TRANSFERS.md`). Kogoto's own application code does not log passwords, tokens, verification/reset codes, or message content. Kogoto does **not** collect: your exact GPS location, your phone number (no phone number field exists anywhere in the app -- the only exception is a Creator application, see "Creators" above), your contacts, SMS/call logs, or microphone audio. ## 4. Why Kogoto processes this data, and whether it's required Most of the data above is required to create an account and use Kogoto's core features at all (email, password, date of birth, first name, country, and, for anyone using Nearby/messaging/Stories, the data those features inherently need to function). Bio, interests, extra gallery photos, and Stories are optional. See `docs/DATA_INVENTORY.md` for a per-field required/optional breakdown. ## 5. Legal basis (candidate — pending legal review) This section states the legal-basis candidates the Kogoto operator currently understands to apply, under the EU General Data Protection Regulation (GDPR). **This has not yet been confirmed by a lawyer** and is not a legal certification. - **Performance of a contract (Art. 6(1)(b) GDPR)**: account data, profile data, Nearby, Events, Kogoto Spots, connections, and messaging — all directly necessary to provide the Kogoto service you signed up for. - **Legitimate interest (Art. 6(1)(f) GDPR)**: security logging, fraud and abuse prevention, rate limiting, the reporting/blocking/moderation system, crash diagnostics, and the aggregate first-party product analytics described in Section 3 — necessary to keep Kogoto and its users safe and to operate and improve the service. - **Consent (Art. 6(1)(a) GDPR)**: push notifications (an OS-level permission you grant or deny, and app-level category toggles you control), and any future optional feature that isn't necessary for the core service. - **Legal obligation (Art. 6(1)(c) GDPR)**: retaining specific records where the operator becomes subject to a legal retention requirement (see `docs/DATA_RETENTION_POLICY.md`). ## 6. Who receives your data (processors) Kogoto uses the following external infrastructure providers to operate the service. Each acts as Kogoto's data processor for the data described — Kogoto does not sell your data to anyone, and does not share it with any advertiser or data broker. See `docs/DATA_PROCESSORS_AND_ TRANSFERS.md` for the full technical detail behind this table. | Provider | What it's used for | What it processes | |---|---|---| | Render | Backend application hosting (Frankfurt, Germany) | All data that passes through Kogoto's backend | | Supabase | Database and private file storage | Account, profile, message, and media data at rest | | Google Firebase | Push notifications; app crash/error diagnostics (Crashlytics) | Device push token, notification content (no message text — see `docs/DATA_INVENTORY.md`); for crash diagnostics, a stack trace and device/OS/app-version info only — never a user identifier, email, or other personal data | | Brevo | Transactional email (verification codes, password reset codes) | Your email address, and the one-time code being sent | | Google (Sign in with Google) | Identity provider for the optional "Continue with Google" sign-in | The Google account identifier, email, and name inside the identity token you authorize Google to issue to Kogoto. Used only to create or sign you in to your Kogoto account. Kogoto retains no Google access token. | | Apple (Sign in with Apple) | Identity provider for the optional "Sign in with Apple" sign-in (iOS) | The Apple account identifier and, on first authorization only, the email (possibly a private-relay address) and name inside the identity token. Used only to create or sign you in to your Kogoto account. Kogoto retains no Apple token. | The product-analytics events in Section 3 are first-party: they are stored only in Kogoto's own database (hosted by Supabase, listed above) and are not sent to any analytics provider. Kogoto does not currently use any advertising SDK, third-party analytics SDK, or data broker. ## 7. International data transfers Kogoto's backend runs in Frankfurt, Germany (EU). Supabase, Firebase, and Brevo are each used as configured for this deployment; whether any of them processes data outside the European Economic Area as part of their own infrastructure has not yet been independently verified by the Kogoto operator against each provider's current data-processing agreement and sub-processor list — see `docs/DATA_PROCESSORS_AND_ TRANSFERS.md`, which flags this explicitly as requiring confirmation before this section can state a final position. ## 8. How long Kogoto keeps your data See `docs/DATA_RETENTION_POLICY.md` for the full, per-category retention breakdown. In summary: most of your data — including your profile, media, messages, Nearby/Event/Spot state, and the product-analytics events in Section 3 — is kept for as long as your account exists (Creator announcements and your copies of them: 90 days), and is deleted when you delete your account (see Section 10 below) — with narrow exceptions for data Kogoto's operator believes may need to be retained briefly for security, abuse-prevention, or legal reasons even after deletion, each specifically listed in that document. ## 9. Your rights Subject to the conditions and exceptions set out in the GDPR, you may have the right to: - **Access** a copy of the personal data Kogoto holds about you (see Section 11, "Export your data," below, for the in-app self-service option). - **Rectification** of inaccurate data — most profile fields can be edited directly in the app. - **Erasure** ("right to be forgotten") — see Section 10, "Delete your account." - **Restriction of processing**, in the specific circumstances the GDPR provides for. - **Data portability**, for data you provided and that is processed by automated means under a contract or consent basis — see Section 11. - **Object** to processing based on legitimate interest. - **Withdraw consent** at any time, for any processing based on consent (e.g. push notifications), without affecting the lawfulness of processing before the withdrawal. To exercise any of these rights, contact kogoto2026@gmail.com. Kogoto will respond as required by applicable law; some requests may require verifying you are the account holder before Kogoto can act on them, to protect your data from being accessed or deleted by someone else. You also have the right to lodge a complaint with a supervisory authority. In Austria, this is the **Österreichische Datenschutzbehörde (Austrian Data Protection Authority)** — https://www.dsb.gv.at. ## 10. Delete your account You can permanently delete your Kogoto account at any time from **Settings → Delete account**, after confirming your password (or re-authenticating with Google or Apple if your account has no Kogoto password). This immediately: signs you out everywhere (every active session is revoked), stops Nearby discovery and Bluetooth advertising, removes your device from receiving further push notifications, and deletes your profile, gallery photos, Stories, connections, messages, Nearby and Event/Spot state, blocks you set, reports you filed, and product-analytics events, in a single database transaction and according to `docs/DATA_RETENTION_POLICY.md`. Deletion cannot be undone. ## 11. Export your data You can request a machine-readable (JSON) copy of your own Kogoto data from **Settings → My Data & Privacy → Download my data**. The export contains your own profile, gallery/Stories metadata, connections, messages you sent, blocks and reports you filed, and notification preferences. It never includes your password hash, any access/refresh/ verification/reset token, another user's private data, or any information about who reported you (see Section 3 above and `docs/ DATA_INVENTORY.md` for exactly what is and isn't included, and why). ## 12. Children and minimum age Kogoto requires every account holder to be at least **16 years old**, enforced both when you enter your date of birth during sign-up and independently by the backend (a client cannot bypass this check). Kogoto does not knowingly collect personal data from anyone under 16. See `docs/GOOGLE_PLAY_AGE_CLASSIFICATION_REVIEW.md` and the Child Safety Standards document for how Kogoto approaches child-safety concerns more broadly, including for users aged 16–17. ## 13. Security measures Passwords are hashed with Argon2 (never stored or logged in plaintext). Refresh tokens, email-verification codes, and password-reset codes are never stored in plaintext — only a cryptographic hash of each is kept. All communication between the Kogoto app and its backend uses HTTPS. Kogoto's hosting and database/storage providers (Render, Supabase) apply their own infrastructure-level security controls; the Kogoto operator has not independently audited or certified those providers' specific technical safeguards, and this policy does not claim "all data is encrypted" as a blanket statement — see `docs/DATA_PROCESSORS_AND_ TRANSFERS.md` for exactly what has and hasn't been verified. If you believe you've found a security issue, see `SECURITY.md` in the Kogoto repository. ## 14. Changes to this policy If this policy changes in a way that materially affects how your data is processed, Kogoto will update the effective date above and make reasonable efforts to notify active users (e.g. via an in-app notice). Continuing to use Kogoto after a change takes effect means you accept the updated policy; you can always delete your account if you do not. **2026-09-23:** Nearby sessions are now chosen by you (30 minutes to 4 hours); your gallery is visible to people who can already see your profile picture; people checked in at the same Spot can send connection requests without Nearby; new disclosures for announcements from Spots/ Events you joined or Spots you follow (joiners, followers or both, all or a randomly chosen number of eligible people, with an opt-out that stops push and inbox copies), the Creator program (including the Creator application's unverified phone number) and review of Creator content before publication, Spot Feed posts and aggregate-only post likes, admin moderation/audit records, and the 90-day announcement retention. This is an effective-date update only; there is no separate "accept the Privacy Policy" step, so no re-acceptance is triggered. `LEGAL_REVIEW_REQUIRED`: legal basis for Creator announcements to joiners and to followers (contract vs. legitimate interest vs. consent; whether following is sufficient notice, and whether e-privacy / direct-marketing rules apply to follower announcements) and for admin audit records. **2026-09-03:** added a dedicated disclosure of Kogoto's first-party product analytics (`user_events`) in Section 3, with its legal basis in Section 5 and a first-party clarification in Section 6; added Kogoto Spots to Section 3 and Section 5; expanded the messaging description in Section 3 to cover in-chat photos ("Meetup Souvenir"), emoji reactions, and replies; aligned Section 10 with the in-app "Delete account" label and the actual deletion cascade. Effective-date update only — there is no separate "accept the Privacy Policy" step in the app, so no re-acceptance is triggered. **2026-08-30:** added the "Continue with Google" / "Sign in with Apple" disclosures (Sections 3 and 6). This is an effective-date update; there is no separate "accept the Privacy Policy" step in the app, so no re-acceptance is triggered by it. The optional provider sign-ins ship disabled until the operator supplies the required provider client IDs. ## 15. This is a draft This Privacy Policy has been prepared to accurately describe Kogoto's real, current technical behavior, but it has **not** yet been reviewed or approved by a qualified data-protection lawyer, and Kogoto does not claim it is complete or legally sufficient for every jurisdiction. It must not be relied upon as a certified compliance statement until that review has taken place — see `docs/OWNER_LEGAL_INPUTS_REQUIRED.md` and `docs/PLAY_STORE_PRIVACY_SAFETY_READINESS.md` for exactly what remains outstanding.