Privacy Policy

1. Introduction and Scope

Korrelated, LLC ("Korrelated," "we," "us," or "our") is a California limited liability company and the developer of Kanvio. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Kanvio mobile application ("Kanvio" or the "App") and the kanv.io website (the "Website"), collectively referred to as the "Service."

By using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account and Authentication Data

When you create an account, we collect:

2.2 Profile Data

For users aged 13–17, social media links are hidden from public view by default.

2.3 Location Data

Kanvio is a location-based augmented reality platform. Location data is central to how the Service works:

Location permission is requested through your device's standard system prompt (iOS or Android). You can revoke location access at any time in your device's Settings.

2.4 User-Created Content

2.5 Interaction and Activity Data

2.6 Challenge Data

2.7 Social and Safety Data

2.8 Device and Technical Data

2.9 Website Submissions

If you submit a form on the kanv.io website, we collect the information you provide:

Website submissions are transmitted to and processed by Formspree (see Section 4).

2.10 Website Analytics and Cookies

The kanv.io website uses Google Analytics 4 to understand how visitors use the site (for example, which pages are viewed, approximate location derived from IP address, device and browser type, and referring sources). Google Analytics sets cookies to measure this activity. We use Google Consent Mode, and analytics cookies are not set unless you accept them via the consent banner shown when you first visit the site. If you reject or do not accept, no analytics cookies are stored. You can change your choice at any time by clearing the site's cookies and the "kanvio_consent" entry in your browser's local storage, or by managing cookies through your browser settings. This applies to the website only; the Kanvio mobile app does not use Google Analytics.

2.11 Biometric and App Lock Data

The Kanvio app offers an optional App Lock that requires biometric authentication — Face ID or Touch ID on iOS, fingerprint or face unlock on Android — with your device passcode, PIN, or pattern as a fallback, to open the app. This feature is off by default. When you enable it, authentication is performed entirely by your device's operating system (for example, Apple Face ID / Touch ID via the Secure Enclave, or Android's BiometricPrompt). Kanvio does not collect, store, access, or transmit your biometric data or device passcode. We store only a single on/off setting on your device indicating whether App Lock is enabled.

3. How We Use Your Information

We use the information we collect to:

4. How We Share Your Information

Publicly Visible Data

The following information is visible to other Kanvio users by design:

Content placed within a Privacy Zone is visible only to you and your trusted friends.

Third-Party Service Providers

We share data with the following third-party service providers, solely to operate the Service. Because this policy covers both the kanv.io website and the Kanvio app, we have grouped providers by where they apply:

App (Kanvio mobile applications for iOS and Android)

Certain platform frameworks used by the App process data locally on your device and do not transmit it to Apple, Google, or any third party for Kanvio's purposes. On iOS these are ARKit, Vision, PencilKit, MapKit, and Core Image; on Android they are ARCore, ML Kit subject segmentation (which runs on-device), and the Maps SDK.

Website (kanv.io)

Other Disclosures

What We Do Not Do

5. Location Data — Special Disclosures

Because Kanvio collects precise location data, we want to be especially transparent about how this data is handled:

6. Data Retention

We retain your data for the following periods:

Data Type Retention Period
Account data (provider IDs, email, DOB flag) Until account deletion
Profile data (display name, avatar) Until account deletion
Content (graffiti, drawings, photos) Until you delete the content or your account
Comments you write Until you delete the comment or your account. A comment you leave on someone else’s piece is kept if that piece or that account is deleted, or if that piece’s creator removes it — in each case it stops being visible to anyone, and remains yours to delete
AR Cloud Anchor IDs Until content deletion (365-day max TTL per Google)
Device model / OS version 90 days
Activity notifications (comments, @mentions, likes, challenge reminders) Auto-deleted after 30 days
View counts shown on a piece Kept for the life of the piece
Raw interaction history (individual view and share events, dwell time) Pruned on a 90-day window, in monthly batches (so up to about 120 days)
Offline drafts (on-device only) Auto-purged after 7 days
Trusted friends, saved people, blocks, restricts Until you remove them or delete your account
Privacy Zone definitions Until you remove them or delete your account
Parent-child links and parental controls Until either account is deleted or the link is removed
Engagement analytics Retained in aggregated/anonymized form for service improvement
Deleted-account safety archive About 90 days after account deletion, then permanently erased. Longer only where a legal preservation obligation applies (see below)

Account Deletion: When you delete your account, everything on it stops being visible immediately and is permanently destroyed from the live service within 48 hours. This includes your profile, all content, the comments you wrote, your likes, challenge data, and Cloud Anchor identifiers. Comments other people wrote on your artwork are not destroyed — see below. Some anonymized, aggregated analytics (e.g., total view counts) may persist, but nothing identifying you remains in the app.

Safety and legal archive (90 days): Before that data is destroyed, we copy the account and its content into a separate, access-restricted archive and keep it for 90 days. The archive is not part of the service: it cannot be viewed, searched, restored or browsed, and it is never used for personalization, analytics, advertising, recommendations or any product purpose. Its sole use is to answer a child-safety report, an abuse or harassment investigation, or a lawful request from law enforcement that arrives after an account has already gone — which is when evidence of serious harm is most often lost. After 90 days the archived copy is erased; erasure begins at the 90-day mark and completes within about a week of it.

The one exception to the 90 days is a specific legal obligation: material reported to the National Center for Missing & Exploited Children, or a preservation request or legal hold from law enforcement. Where one applies, the relevant items are retained until that matter is resolved, and no longer.

Content by other people on your content. A comment is attached both to its author and to the artwork it sits on. If someone deletes their account, the archive of their artwork includes its whole comment thread, including comments written by other people. This means a comment you left on somebody else’s piece may be archived because they deleted, independently of anything you do. We tell you this because it is not obvious, and because your own deletion does not remove that copy — it was made at the time of their deletion.

Your comment outlives the artwork it sits on. Since August 2026, deleting a piece of artwork — or the account that made it — no longer destroys the comments other people left on it. Those comments stop being visible to everyone at that moment, and they stay that way; nobody can read them in the app. We keep them because a comment is its author’s own words, and deleting somebody else’s artwork should not erase what other people said about it — including a complaint about that artwork. Your own comments remain yours to delete at any time, and deleting your account deletes every comment you wrote.

Other people named in a deleted account’s archive. The archive of a deleted account contains that account’s records — and many of those records describe a relationship with somebody else, so they name that person too. If you interacted with an account that is later deleted, you may appear in its archive: a comment you left, whether either of you saved, blocked, restricted or trusted-friended the other, a report either of you made about the other, a challenge of theirs you joined, a parent-child link, or an activity notification that mentions you. You are there because of something that happened between you and that account, not because of anything you did at the time of their deletion — and, as above, your own deletion does not remove that copy. The archive is access-restricted, is never used for any product purpose, and is erased on the same 90-day terms.

Legal basis and your rights. This retention is an exception to erasure, not a refusal of it, and it is permitted under Article 17(3) of the UK GDPR and equivalent provisions elsewhere — for compliance with a legal obligation, and for the establishment, exercise or defence of legal claims. You may still exercise your rights over archived data by contacting contact@kanv.io; where we cannot erase an item because a legal obligation requires us to keep it, we will tell you so and tell you why.

7. Children's Privacy and Parental Controls

Children Under 13

Kanvio does not permit account creation by children under the age of 13 in compliance with the Children's Online Privacy Protection Act (COPPA). Age verification is performed at signup: on iOS 26 and later we use Apple's Declared Age Range API, which tells us only an age range (never a birthday); on earlier versions, if you decline to share your age range, or on Android, we ask for your date of birth instead. Users determined to be under 13 are blocked from creating an account, and this restriction is backed by secure on-device storage — the iOS Keychain or Android's encrypted app storage — to prevent re-attempts on the same device.

We do not knowingly collect personal information from children under 13. If we become aware that such data was collected, it will be deleted promptly.

Minors (Ages 13–17)

Users between 13 and 17 are flagged as minors and receive automatic safety restrictions, including:

Parental Controls

Parents and guardians can link to their child's account and configure additional restrictions, including:

To exercise parental rights regarding your child's data (access, correction, or deletion), please contact us at privacy@kanv.io with the subject line "Parental Rights Request."

8. Content Moderation and AI Processing

To maintain a safe environment, Kanvio uses automated content moderation:

No human review of content occurs unless triggered by user reports or automated safety flags.

9. AR Data and Camera Privacy

10. Algorithms and Personalization

Kanvio personalizes your content feed using the following factors:

Challenge recommendations use similar factors: freshness, urgency, popularity, and proximity.

All personalization is computed at the time of each request. No persistent user interest profile or model is built or stored. There is no cross-app profiling or behavioral advertising.

11. Your Privacy Rights

11.1 California Residents (CCPA/CPRA)

If you are a California resident, you have the following rights:

Categories of Information Collected:

Category Examples Business Purpose Sold or Shared
Identifiers Display name, email, provider IDs Account management, authentication No
Precise Geolocation GPS coordinates for AR content placement Core AR functionality No
Internet or Network Activity In-app browsing, view history, engagement metrics Feed personalization, service improvement No
Audio, Electronic, or Visual Information Photos, artwork, avatar image Content display, content moderation No
Inferences Category affinity scores from viewing history (not stored persistently) Feed personalization No
Sensitive Personal Information Precise geolocation Core AR functionality only No

How to Exercise Your Rights: Email privacy@kanv.io with your request. We will verify your identity using information associated with your account and respond within 45 days. You may also designate an authorized agent with written authorization.

11.2 European Economic Area and United Kingdom (GDPR)

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation:

Lawful Bases for Processing:

Automated content moderation (Section 8) does not produce decisions with legal effects. Users may appeal moderation decisions by contacting us.

12. Account Deletion

You can delete your account at any time, either through the App's settings (Profile → Settings → Account → Delete Account) or from the web at kanv.io/delete-account.html, which does not require the App to be installed. Upon deletion:

Both routes are identical in effect, and both require you to be signed in: deletion is authorized only by authenticating to the account itself through Sign in with Apple or Sign in with Google. The web page uses Firebase Authentication for that sole purpose and sets no analytics or advertising cookies. We do not act on deletion requests that merely identify an account by handle, email address, or other detail, because such a request is not proof that the account belongs to the person asking.

This account deletion mechanism satisfies Apple's App Store and Google Play requirements for in-app account deletion, and Google Play's requirement for a web-based account deletion request channel.

13. Data Security

We implement reasonable security measures to protect your information, including:

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.

14. International Data Transfers

Your data is processed and stored in the United States via Google Cloud and AWS infrastructure. If you use the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Our service providers maintain appropriate safeguards for international data transfers, including standard contractual clauses where applicable.

15. Do Not Track

Kanvio does not track users across third-party apps or websites for advertising purposes. The App does not use App Tracking Transparency (ATT) because no cross-app tracking occurs. The kanv.io website uses Google Analytics, with your consent, to measure usage of the site. Because there is no industry-standard for how to respond to browser "Do Not Track" signals, we do not currently respond to them; however, website analytics are enabled only if you accept the consent banner, and you can decline at any time.

16. Third-Party Links

The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal information.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. The updated version will be indicated by the "Effective Date" at the top of this page. For material changes, we will provide notice through the App. Your continued use of the Service after changes constitutes acceptance of the updated policy.

18. Contact Us

If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us at:

Korrelated, LLC
Email: privacy@kanv.io
Mailing Address: 2520 Venture Oaks Way, Suite 120, Sacramento, CA 95833

For parental rights requests, please email privacy@kanv.io with the subject line "Parental Rights Request."