Privacy Policy
Effective Date: August 24, 2026
1. Introduction and Scope
Korrelated, LLC ("Korrelated," "we," "us," or "our") is a California limited liability company and the developer of Kanvio. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Kanvio mobile application ("Kanvio" or the "App") and the kanv.io website (the "Website"), collectively referred to as the "Service."
By using the Service, you agree to the collection and use of information as described in this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account and Authentication Data
When you create an account, we collect:
- Authentication credentials through Sign in with Apple or Sign in with Google via Firebase Authentication. On Android, Sign in with Google is the only available provider
- Provider identifiers (opaque identifiers assigned by Apple or Google — not your Apple ID or Google account credentials)
- Email address (as provided by your authentication provider)
- Your age range or date of birth, used solely for age verification (see Section 7). On iOS 26 and later we request only an age range through Apple's Declared Age Range API — you never enter a birthday; we collect an exact date of birth only as a fallback on earlier versions, if you decline to share your range, or on Android, which has no equivalent age-range API
2.2 Profile Data
- Display name (your chosen username)
- Avatar image (up to 512x512 pixels)
- Optional social media links (Instagram, TikTok, X/Twitter, YouTube, personal website)
For users aged 13–17, social media links are hidden from public view by default.
2.3 Location Data
Kanvio is a location-based augmented reality platform. Location data is central to how the Service works:
- Precise GPS coordinates (latitude and longitude) are collected when you use the map view or AR camera. Location is collected only while the App is in the foreground and actively in use — we do not collect location data in the background
- Content location: When you place digital art ("graffiti") in the world, the GPS coordinates of that content are stored and visible to other users. This is core to Kanvio's functionality
- Your real-time location is never shared with other users. Only the locations of content you create are visible
- Privacy Zones: You can define circular protected areas (100m–2,000m radius) where your content is hidden from all users except your trusted friends
- Location precision: coordinates are stored to 6 decimal places (~0.1 meter) for AR anchoring accuracy, and rounded to 4 decimal places (~11 meters) for display purposes
- Coarse location for feed ranking: When you open Discover, an approximate coordinate rounded to 3 decimal places (~110 meters) is sent with the request so nearby art can rank higher. It is used to order that response and is not stored against your account. Nothing is sent while you are inside one of your own Privacy Zones, and nothing is sent if location permission is refused — in both cases the feed simply ranks without it
Location permission is requested through your device's standard system prompt (iOS or Android). You can revoke location access at any time in your device's Settings.
2.4 User-Created Content
- Drawings and artwork (PNG format, up to 2 MB)
- Imported and edited photos
- Scene preview images (JPEG format)
- Text descriptions (up to 280 characters)
- Content category assignments (Tag, Art, Life, Humor, Love, Voice, Tribute)
- AR Cloud Anchor identifiers (for persistent AR positioning; these have a 365-day time-to-live set by Google)
2.5 Interaction and Activity Data
- Likes on content
- Comments (up to 500 characters, which may include @mentions of other users)
- Content reports you submit
- View events and timestamps
- Share events, including which platform you share to (e.g., Instagram, Messages). When you share content externally, a preview page is generated containing the creator's display name, description, and a preview image — this metadata may be cached or indexed by the receiving platform
- Dwell time (how long you view a piece of content)
- In-app activity notifications (e.g., comments on your content, @mentions, likes, challenge reminders). These notifications are auto-deleted after 30 days. That applies to the notifications themselves; view counts and raw interaction history are kept longer, as set out in Section 6 (Data Retention)
- An opaque push-notification token issued to your device through Firebase Cloud Messaging (and, on iOS, Apple Push Notification service) so we can keep your unread activity count up to date. On iOS this also updates the app icon badge; Android has no equivalent launcher badge, so the count is shown inside the app. The token does not contain personal information. It is deleted when you sign out, when you delete your account, or when the platform invalidates it
2.6 Challenge Data
- Challenges you create (title, description, theme image, date range, optional location)
- Challenge participation and submissions
- Leaderboard data (entry counts and likes received)
2.7 Social and Safety Data
- Trusted friends list (one-directional friend relationships you create), including whether a relationship is awaiting a parent's approval
- Saved People list (people you have privately bookmarked). This list is visible only to you — the person saved is not notified, and no counts are shown to anyone
- Block and restrict actions you take against other users
- Privacy Zone definitions (zone name, center coordinates, and radius — visible only to you)
- Parent-child account links and parental control settings (if a parent or guardian links to your account)
- Account recovery requests (if you use the trusted friend verification process to recover your account, a temporary recovery request is stored linking your account to the verifying trusted friend. These requests expire automatically)
2.8 Device and Technical Data
- Device model and operating system version (iOS or Android)
- Aggregated engagement statistics
2.9 Website Submissions
If you submit a form on the kanv.io website, we collect the information you provide:
- Waitlist: Email address and preferred platform.
- Support: Email address, subject category, message text, and an optional handle. If provided, the handle is normalized to lowercase before transmission. Because users may enter a public identifier here (for example, a social-media username), the handle may identify you to a wider audience than your email alone — providing it is optional and at your discretion.
Website submissions are transmitted to and processed by Formspree (see Section 4).
2.10 Website Analytics and Cookies
The kanv.io website uses Google Analytics 4 to understand how visitors use the site (for example, which pages are viewed, approximate location derived from IP address, device and browser type, and referring sources). Google Analytics sets cookies to measure this activity. We use Google Consent Mode, and analytics cookies are not set unless you accept them via the consent banner shown when you first visit the site. If you reject or do not accept, no analytics cookies are stored. You can change your choice at any time by clearing the site's cookies and the "kanvio_consent" entry in your browser's local storage, or by managing cookies through your browser settings. This applies to the website only; the Kanvio mobile app does not use Google Analytics.
2.11 Biometric and App Lock Data
The Kanvio app offers an optional App Lock that requires biometric authentication — Face ID or Touch ID on iOS, fingerprint or face unlock on Android — with your device passcode, PIN, or pattern as a fallback, to open the app. This feature is off by default. When you enable it, authentication is performed entirely by your device's operating system (for example, Apple Face ID / Touch ID via the Secure Enclave, or Android's BiometricPrompt). Kanvio does not collect, store, access, or transmit your biometric data or device passcode. We store only a single on/off setting on your device indicating whether App Lock is enabled.
3. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the Kanvio service, including AR content creation, discovery, and social features
- Authenticate your identity and manage your account
- Verify your age and apply appropriate safety restrictions
- Display your content to other users at the locations where you place it
- Personalize your content feed (see Section 10)
- Moderate content for safety and policy compliance (see Section 8)
- Respond to reports and enforce our Community Guidelines and Terms of Service
- Analyze usage patterns to improve the Service
- Send service-related communications
- Comply with legal obligations
4. How We Share Your Information
Publicly Visible Data
The following information is visible to other Kanvio users by design:
- Your display name and avatar
- Content you place (drawings, photos, descriptions) and its location
- Your likes and comments
- Your challenge participation and leaderboard standings
- Your profile statistics (pieces created, likes received, likes given)
Content placed within a Privacy Zone is visible only to you and your trusted friends.
Third-Party Service Providers
We share data with the following third-party service providers, solely to operate the Service. Because this policy covers both the kanv.io website and the Kanvio app, we have grouped providers by where they apply:
App (Kanvio mobile applications for iOS and Android)
- Google Cloud Platform (GCP): The Kanvio app backend is hosted entirely on GCP. All user data described in Section 2 (account, profile, content, interactions, challenges, and social data) is stored and processed on GCP infrastructure. Specific GCP services that process your data in notable ways include:
- Firebase Authentication: Processes authentication tokens and provider identifiers for sign-in
- Cloud Vision API: Images you upload are scanned for automated content safety (see Section 8)
- Cloud Natural Language API: Text content you submit is scanned for toxicity (see Section 8)
- ARCore Cloud Anchors: AR positioning data (Cloud Anchor identifiers and spatial mapping data) is sent to enable persistent AR content placement. Raw camera frames are not transmitted
Certain platform frameworks used by the App process data locally on your device and do not transmit it to Apple, Google, or any third party for Kanvio's purposes. On iOS these are ARKit, Vision, PencilKit, MapKit, and Core Image; on Android they are ARCore, ML Kit subject segmentation (which runs on-device), and the Maps SDK.
Website (kanv.io)
- Amazon Web Services (AWS): The kanv.io website is hosted via Amazon S3 and CloudFront. AWS may collect server logs including IP addresses and access timestamps. AWS's privacy policy is available at aws.amazon.com/privacy.
- Formspree: Processes support form submissions on the kanv.io website, and holds the Android launch waitlist signups collected before August 2026. Formspree's privacy policy is available at formspree.io/legal/privacy-policy.
- Google Analytics: Provides website usage analytics (pages viewed, approximate location, device and browser information, and referring sources) when you consent to analytics cookies on the website. Google's privacy policy is available at policies.google.com/privacy, and how Google uses data from sites that use its services is described at policies.google.com/technologies/partner-sites.
Other Disclosures
- Legal Requirements: When required by law, regulation, subpoena, court order, or other legal process
- Safety: When we believe disclosure is necessary to protect our rights, your safety, or the safety of others
- Business Transfers: In connection with a merger, acquisition, or sale of assets, in which case you will be notified of any change in ownership
What We Do Not Do
- We do not sell your personal information
- We do not share your personal information for cross-context behavioral advertising
- We do not track you across other apps or websites. App Tracking Transparency (ATT) is not required because Kanvio does not engage in cross-app tracking
5. Location Data — Special Disclosures
Because Kanvio collects precise location data, we want to be especially transparent about how this data is handled:
- Location is collected only in the foreground while you are actively using the map or AR features. Kanvio does not use background location services
- Location permission is requested through your device's standard system prompt. You can change or revoke this permission at any time in your device's Settings
- The location where you place content is stored and visible to other users — this is the core functionality of Kanvio
- Your real-time position is never exposed to other users
- Privacy Zones allow you to define protected areas where your content is hidden from everyone except your trusted friends
- For users aged 13–17, location sharing defaults to OFF and may be further restricted by parental controls
- Precise location data (geolocation) is classified as "sensitive personal information" under the CPRA. We use it solely to provide the core AR functionality of the Service, not for profiling or advertising
6. Data Retention
We retain your data for the following periods:
| Data Type | Retention Period |
|---|---|
| Account data (provider IDs, email, DOB flag) | Until account deletion |
| Profile data (display name, avatar) | Until account deletion |
| Content (graffiti, drawings, photos) | Until you delete the content or your account |
| Comments you write | Until you delete the comment or your account. A comment you leave on someone else’s piece is kept if that piece or that account is deleted, or if that piece’s creator removes it — in each case it stops being visible to anyone, and remains yours to delete |
| AR Cloud Anchor IDs | Until content deletion (365-day max TTL per Google) |
| Device model / OS version | 90 days |
| Activity notifications (comments, @mentions, likes, challenge reminders) | Auto-deleted after 30 days |
| View counts shown on a piece | Kept for the life of the piece |
| Raw interaction history (individual view and share events, dwell time) | Pruned on a 90-day window, in monthly batches (so up to about 120 days) |
| Offline drafts (on-device only) | Auto-purged after 7 days |
| Trusted friends, saved people, blocks, restricts | Until you remove them or delete your account |
| Privacy Zone definitions | Until you remove them or delete your account |
| Parent-child links and parental controls | Until either account is deleted or the link is removed |
| Engagement analytics | Retained in aggregated/anonymized form for service improvement |
| Deleted-account safety archive | About 90 days after account deletion, then permanently erased. Longer only where a legal preservation obligation applies (see below) |
Account Deletion: When you delete your account, everything on it stops being visible immediately and is permanently destroyed from the live service within 48 hours. This includes your profile, all content, the comments you wrote, your likes, challenge data, and Cloud Anchor identifiers. Comments other people wrote on your artwork are not destroyed — see below. Some anonymized, aggregated analytics (e.g., total view counts) may persist, but nothing identifying you remains in the app.
Safety and legal archive (90 days): Before that data is destroyed, we copy the account and its content into a separate, access-restricted archive and keep it for 90 days. The archive is not part of the service: it cannot be viewed, searched, restored or browsed, and it is never used for personalization, analytics, advertising, recommendations or any product purpose. Its sole use is to answer a child-safety report, an abuse or harassment investigation, or a lawful request from law enforcement that arrives after an account has already gone — which is when evidence of serious harm is most often lost. After 90 days the archived copy is erased; erasure begins at the 90-day mark and completes within about a week of it.
The one exception to the 90 days is a specific legal obligation: material reported to the National Center for Missing & Exploited Children, or a preservation request or legal hold from law enforcement. Where one applies, the relevant items are retained until that matter is resolved, and no longer.
Content by other people on your content. A comment is attached both to its author and to the artwork it sits on. If someone deletes their account, the archive of their artwork includes its whole comment thread, including comments written by other people. This means a comment you left on somebody else’s piece may be archived because they deleted, independently of anything you do. We tell you this because it is not obvious, and because your own deletion does not remove that copy — it was made at the time of their deletion.
Your comment outlives the artwork it sits on. Since August 2026, deleting a piece of artwork — or the account that made it — no longer destroys the comments other people left on it. Those comments stop being visible to everyone at that moment, and they stay that way; nobody can read them in the app. We keep them because a comment is its author’s own words, and deleting somebody else’s artwork should not erase what other people said about it — including a complaint about that artwork. Your own comments remain yours to delete at any time, and deleting your account deletes every comment you wrote.
Other people named in a deleted account’s archive. The archive of a deleted account contains that account’s records — and many of those records describe a relationship with somebody else, so they name that person too. If you interacted with an account that is later deleted, you may appear in its archive: a comment you left, whether either of you saved, blocked, restricted or trusted-friended the other, a report either of you made about the other, a challenge of theirs you joined, a parent-child link, or an activity notification that mentions you. You are there because of something that happened between you and that account, not because of anything you did at the time of their deletion — and, as above, your own deletion does not remove that copy. The archive is access-restricted, is never used for any product purpose, and is erased on the same 90-day terms.
Legal basis and your rights. This retention is an exception to erasure, not a refusal of it, and it is permitted under Article 17(3) of the UK GDPR and equivalent provisions elsewhere — for compliance with a legal obligation, and for the establishment, exercise or defence of legal claims. You may still exercise your rights over archived data by contacting contact@kanv.io; where we cannot erase an item because a legal obligation requires us to keep it, we will tell you so and tell you why.
7. Children's Privacy and Parental Controls
Children Under 13
Kanvio does not permit account creation by children under the age of 13 in compliance with the Children's Online Privacy Protection Act (COPPA). Age verification is performed at signup: on iOS 26 and later we use Apple's Declared Age Range API, which tells us only an age range (never a birthday); on earlier versions, if you decline to share your age range, or on Android, we ask for your date of birth instead. Users determined to be under 13 are blocked from creating an account, and this restriction is backed by secure on-device storage — the iOS Keychain or Android's encrypted app storage — to prevent re-attempts on the same device.
We do not knowingly collect personal information from children under 13. If we become aware that such data was collected, it will be deleted promptly.
Minors (Ages 13–17)
Users between 13 and 17 are flagged as minors and receive automatic safety restrictions, including:
- Screen time limits (60-minute daily session limit with cooldown)
- Content sensitivity filter enabled by default (sensitive content hidden)
- Location sharing defaults to OFF
- Content creation rate limits
- Social media links hidden from public profile (a linked parent can allow them)
- @mention notification filtering (only trusted friends' mentions reach the minor, unless a linked parent widens it)
Parental Controls
Parents and guardians can link to their child's account and configure additional restrictions, including:
- Custom screen time limits and curfew hours
- Feed and content sensitivity settings
- Trusted-friends-only mode (limits feed and map to friends' content)
- Friend approval — a new trusted friend grants no access at all until the parent approves it. Relationships that already existed when the setting is turned on are unaffected, and remain visible and removable by the parent
- Control over who can send the child an @mention notification, and whether they may show social links
- Reminders before the child posts a photo containing a face, or a piece with its location shared
- Remote account lock (pause the child's account entirely)
- Weekly activity digests showing aggregated statistics only — parents cannot read the child's actual comments, messages, or content
To exercise parental rights regarding your child's data (access, correction, or deletion), please contact us at privacy@kanv.io with the subject line "Parental Rights Request."
8. Content Moderation and AI Processing
To maintain a safe environment, Kanvio uses automated content moderation:
- Image Scanning: All images uploaded to Kanvio (graffiti, challenge theme images, avatars) are automatically scanned via Google Cloud Platform (Cloud Vision SafeSearch) for inappropriate content including nudity, violence, and other unsafe material. This scanning occurs asynchronously after upload
- Text Scanning: Text content is scanned via Google Cloud Platform (Cloud Natural Language) for toxicity before it is posted. This includes: display names, graffiti descriptions, challenge titles and descriptions, comments, and social media link usernames. Content exceeding toxicity thresholds is rejected with an explanation
- Sensitivity Tiers: Content is assigned a sensitivity level: safe (shown to everyone), sensitive (hidden from minors), or blocked (held for manual review, visible only to creator)
- Community Reporting: Users can report content. Content receiving 3 or more reports from unique users is automatically hidden pending review
- Enforcement: Violations are addressed through an enforcement ladder: warning, 7-day ban, suspension, and permanent ban
- Comments on your artwork: The creator of a piece can remove a comment left on it. The comment stops being visible to everyone immediately and is kept, not destroyed, so that it remains available to moderation and to a lawful request — a comment is often the evidence in a harassment or child-safety report. Its author can still delete their own comment at any time. See Section 6 (Data Retention)
No human review of content occurs unless triggered by user reports or automated safety flags.
9. AR Data and Camera Privacy
- Kanvio uses the device camera for augmented reality functionality — via Apple ARKit on iOS, and Google ARCore on Android
- Camera frames are processed entirely on your device and are never transmitted to Korrelated's servers or third parties
- No video is recorded from AR sessions
- Spatial mapping data used for AR anchoring is processed via Google ARCore Cloud Anchors — Cloud Anchor identifiers are transmitted, but raw camera frames are not
- Camera permission is requested through your device's standard system prompt and can be revoked at any time
10. Algorithms and Personalization
Kanvio personalizes your content feed using the following factors:
- Quality: Content engagement metrics (likes, comments, dwell time)
- Freshness: Newer content is weighted more heavily, with an exponential decay function
- Proximity: Content closer to your current location is prioritized
- Category Affinity: Based on your viewing history over the past 30 days, content in categories you engage with more frequently may be prioritized
- Trusted Friend Boost: Content from your trusted friends receives a priority boost
- Saved People Boost: Content from people you have saved receives a smaller boost. This affects only your own feed and is not visible to the person saved
- Feed engagement: We record when a piece is shown to you in Discover, separately from when you open it, so that ranking can reflect what people actually choose to look at
- Diversity: Anti-flooding and anti-domination rules prevent any single category or creator from overwhelming your feed
Challenge recommendations use similar factors: freshness, urgency, popularity, and proximity.
All personalization is computed at the time of each request. No persistent user interest profile or model is built or stored. There is no cross-app profiling or behavioral advertising.
11. Your Privacy Rights
11.1 California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights:
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected
- Right to Delete: Request deletion of your personal information (you can also delete your account yourself, in the App or at kanv.io/delete-account.html)
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt Out: Opt out of the sale or sharing of personal information. We do not sell or share personal information
- Right to Limit Use of Sensitive Personal Information: Precise geolocation is classified as sensitive personal information under CPRA. We use it solely for the core AR functionality of the Service
- Right to Non-Discrimination: We will not discriminate against you for exercising your rights
Categories of Information Collected:
| Category | Examples | Business Purpose | Sold or Shared |
|---|---|---|---|
| Identifiers | Display name, email, provider IDs | Account management, authentication | No |
| Precise Geolocation | GPS coordinates for AR content placement | Core AR functionality | No |
| Internet or Network Activity | In-app browsing, view history, engagement metrics | Feed personalization, service improvement | No |
| Audio, Electronic, or Visual Information | Photos, artwork, avatar image | Content display, content moderation | No |
| Inferences | Category affinity scores from viewing history (not stored persistently) | Feed personalization | No |
| Sensitive Personal Information | Precise geolocation | Core AR functionality only | No |
How to Exercise Your Rights: Email privacy@kanv.io with your request. We will verify your identity using information associated with your account and respond within 45 days. You may also designate an authorized agent with written authorization.
11.2 European Economic Area and United Kingdom (GDPR)
If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation:
- The right to access, rectify, erase, restrict processing of, or port your personal data
- The right to object to processing based on legitimate interests
- The right to withdraw consent at any time
- The right to lodge a complaint with your local data protection supervisory authority
Lawful Bases for Processing:
- Consent: Location access, camera access
- Contract Performance: Account management, content storage and display, social features
- Legitimate Interest: Security, content moderation, analytics, service improvement
Automated content moderation (Section 8) does not produce decisions with legal effects. Users may appeal moderation decisions by contacting us.
12. Account Deletion
You can delete your account at any time, either through the App's settings (Profile → Settings → Account → Delete Account) or from the web at kanv.io/delete-account.html, which does not require the App to be installed. Upon deletion:
- Everything on the account stops being visible immediately and is permanently destroyed from the live service within 48 hours, including your profile, all content, the comments you wrote, your likes, challenge data, and Cloud Anchor identifiers
- Comments other people wrote on your artwork are not destroyed — they stop being visible to everyone, and remain their authors’ to delete. See Section 6 (Data Retention)
- Some anonymized, aggregated analytics may persist (e.g., total view counts), but nothing identifying you remains in the app
- A separate, access-restricted copy is retained for about 90 days for safety and legal purposes only, then erased — see Section 6 (Data Retention) for what this is, what it is never used for, and the single legal exception that can extend it
Both routes are identical in effect, and both require you to be signed in: deletion is authorized only by authenticating to the account itself through Sign in with Apple or Sign in with Google. The web page uses Firebase Authentication for that sole purpose and sets no analytics or advertising cookies. We do not act on deletion requests that merely identify an account by handle, email address, or other detail, because such a request is not proof that the account belongs to the person asking.
This account deletion mechanism satisfies Apple's App Store and Google Play requirements for in-app account deletion, and Google Play's requirement for a web-based account deletion request channel.
13. Data Security
We implement reasonable security measures to protect your information, including:
- TLS/HTTPS encryption for all data in transit
- Row-level security (RLS) policies enforced at the database level
- Secure authentication via Firebase Authentication
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. In the event of a data breach affecting your personal information, we will notify you and applicable authorities as required by law.
14. International Data Transfers
Your data is processed and stored in the United States via Google Cloud and AWS infrastructure. If you use the Service from outside the United States, your information will be transferred to, stored, and processed in the United States. Our service providers maintain appropriate safeguards for international data transfers, including standard contractual clauses where applicable.
15. Do Not Track
Kanvio does not track users across third-party apps or websites for advertising purposes. The App does not use App Tracking Transparency (ATT) because no cross-app tracking occurs. The kanv.io website uses Google Analytics, with your consent, to measure usage of the site. Because there is no industry-standard for how to respond to browser "Do Not Track" signals, we do not currently respond to them; however, website analytics are enabled only if you accept the consent banner, and you can decline at any time.
16. Third-Party Links
The Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing personal information.
17. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. The updated version will be indicated by the "Effective Date" at the top of this page. For material changes, we will provide notice through the App. Your continued use of the Service after changes constitutes acceptance of the updated policy.
18. Contact Us
If you have questions about this Privacy Policy, our data practices, or wish to exercise your privacy rights, please contact us at:
Korrelated, LLC
Email: privacy@kanv.io
Mailing Address: 2520 Venture Oaks Way, Suite 120, Sacramento, CA 95833
For parental rights requests, please email privacy@kanv.io with the subject line "Parental Rights Request."