Privacy Policy
This policy describes, as accurately as the current Kogoto app and backend actually behave, what personal data Kogoto processes, why, and what choices and rights you have. It is written to match the real implementation — not a generic template. Where a legal conclusion has not yet been confirmed by a lawyer, this document says so rather than asserting compliance it cannot yet prove.
Status: draft, prepared for legal review. This policy has been written to describe Kogoto's real, current technical behaviour, but it has not yet been reviewed or approved by a qualified data-protection lawyer, and it is not offered as a certified compliance statement. It is the same text shown inside the Kogoto app under Settings → Privacy & safety → Privacy Policy.
1.Who operates Kogoto
Kogoto is currently operated by a private individual based in Austria, not a registered company. Contact for any privacy question, request, or concern: kogoto2026@gmail.com.
The operator's full legal name and a publication-safe postal address are not published in this document. This section is therefore not yet sufficient for a formally complete Austrian provider-information (Impressum) statement; that is tracked as an open item for a broader public release. It does not affect your ability to reach Kogoto at the contact address above, exercise your rights under Section 9, or delete your account under Section 10.
2.Data-protection contact
For any question about this policy or your data: kogoto2026@gmail.com. Kogoto has not appointed a Data Protection Officer; none is required for processing at Kogoto's current scale, and this document does not claim one exists.
3.What personal data Kogoto processes
Kogoto is a proximity-based social app: you create an account, build a profile, discover nearby Kogoto users over Bluetooth, connect with people you choose to, message your connections, and optionally post short-lived "Stories." The data below reflects what the current app and backend collect to make that work.
Account & identity
- First name, email address, password (stored only as an Argon2 hash — Kogoto never stores or can recover your actual password), date of birth (used to compute and verify your age; only your age, never your exact birth date, is ever shown to another user), and country.
- Email verification status and the timestamp it was verified.
- The Terms of Service / Privacy Policy version and timestamp you accepted at registration.
- If you sign in with Google or Apple (optional): the account identifier that provider assigns you (a stable opaque id), the email address the provider asserts (for Apple this may be a private-relay forwarding address), and your name if the provider supplies it. These come from the provider's signed identity token, which Kogoto's backend verifies; Kogoto keeps no Google or Apple access tokens and stores only the link between your Kogoto account and that provider identifier. Using a provider sign-in is never required — email and password remain available, and you can add a password later.
Profile
- Your bio, interests, profile picture, and any additional gallery photos you choose to upload (up to six).
Stories
- Photos and optional captions you post as Stories, visible only to your accepted connections, and automatically removed after 24 hours unless you choose to keep a copy in "Saved" / "Old Stories" (which then stays private to you only).
- Who has viewed one of your Stories, and when — visible only to you, the person who posted it. Viewing your own Story is never recorded.
- Who has liked one of your Stories, and when — visible only to you. If you like someone else's Story you can see your own like on it, but not whether anyone else liked it.
Proximity ("Nearby")
- Whether you have Nearby discovery turned on, and for how long (each activation lasts up to 30 minutes and switches off automatically).
- A short-lived, randomly generated, rotating Bluetooth identifier your phone broadcasts while Nearby is on. It does not contain your name, email, or any other identifying information by itself; Kogoto's backend is what maps it back to your account when another Kogoto user who also has Nearby on discovers it.
- Kogoto does not use GPS and does not collect or store your device's geographic coordinates. Proximity to another user is only ever shown as an approximate label (for example "very close"), never an exact distance. On Android versions before 12, the operating system itself requires the location permission in order to scan for Bluetooth devices at all — Kogoto requests it only for that reason and never uses it to determine or record where you are.
Events
- If you join a temporary "Event" (an optional feature — for a festival, conference, party, or any other gathering), Kogoto stores which Event you belong to and for how long (up to 24 hours, capped to the Event's own lifetime, and ended immediately if you leave the Event).
- Joining an Event does not, by itself, make you discoverable to anyone. It only helps Kogoto also show you to other members of the same Event while Nearby discovery is separately turned on for both of you. There is no way for anyone to see who else is in an Event, and Kogoto keeps no history of which Events you have joined.
- An official Event (created ahead of time by an organiser and joined via a QR code or code) may show an organiser name, short description, and logo to its members.
Kogoto Spots
- If you join a Kogoto Spot (a persistent real-world place — a café, bar, club, university, gym, or venue — that you join via its QR code or code), Kogoto stores that you are currently present there and until when (you choose a duration, capped at 24 hours), and, if you follow a Spot, that follow.
- Other people only ever see an aggregate count of how many people are currently at a Spot, unless they are also currently checked in at that same Spot at the same time. Kogoto keeps no public attendance list and no history of Spots you have visited once your session there ends; a follow is removed when you unfollow or when you delete your account.
- A Spot has no location coordinate stored anywhere — its real-world location is implicit in its name and description only.
Connections & messages
- Connection requests you send or receive, their status (pending, accepted, declined, cancelled, expired, or blocked), and any short "Ask" question and reply exchanged before accepting. An accepted connection is what Kogoto calls a "Meetup."
- The messages you send in a conversation with an accepted connection — text, and any photo you choose to send directly into the chat (including a "Meetup Souvenir" selfie) — and when each message was sent and read.
- Any emoji reaction you add to a message, and whether a message is sent as a reply to an earlier one.
Blocking & reporting (safety)
- Who you have blocked (kept private — the blocked person is never told who blocked them).
- Reports you file against another user, a message, a connection request, or a Story, including the category and any description you provide, plus a snapshot of the reported content taken at the time of the report as evidence. Reports are confidential: only Kogoto's operator can read report content, through a command-line tool with no public or in-app access. The person you report is never told who reported them.
Notifications
- Your device's push-notification token (if you allow notifications), and your per-category notification preferences.
Product analytics
Kogoto records a small, fixed set of product-usage events tied to your account, so the operator can understand how the app is used in aggregate. The events are: opening the app; turning Nearby on or off; joining or leaving an Event; joining, leaving, following, or unfollowing a Kogoto Spot; the Meetup (connection) request / accept / decline / confirm / cancel steps; and whether a push notification to your device succeeded or failed.
- These events are stored only in Kogoto's own database. No third-party analytics service, SDK, or advertising tracker is used, and there is no generic event-tracking sink — only the closed list above.
- They contain no message or Story content, no location, no email address, and no raw Bluetooth, push, or advertising identifier.
- They are only ever read as aggregates — total active users, retention rates, Meetup acceptance rate, feature-usage counts — never to build an individual profile of you or to target you.
- They are deleted when you delete your account.
Security & technical
- Standard request and error logs kept by Kogoto's hosting provider and backend framework for operating and securing the service. Kogoto's own application code does not log passwords, tokens, verification or reset codes, or message content.
- Abuse-prevention counters (for example, failed-login counts keyed to an email address or an action keyed to a user id) used only for rate limiting.
- App crash and error diagnostics — see Section 6 (Firebase Crashlytics). These carry a stack trace plus device, OS, and app-version information only, and never a user identifier, email, or other personal data.
Kogoto does not collect: your GPS or geographic location, your phone number (no phone-number field exists anywhere in the app), your contacts, your SMS or call logs, or microphone audio.
4.Why Kogoto processes this data, and whether it is required
Most of the data above is required to create an account and use Kogoto's core features at all (email, password, date of birth, first name, country, and — for anyone using Nearby, messaging, or Stories — the data those features inherently need to function). Bio, interests, extra gallery photos, and Stories are optional. Push notifications are optional and controlled by you. The product-analytics events in Section 3 are recorded automatically for signed-in use and are not individually optional, but they are minimised and aggregate-only as described there.
5.Legal basis (candidate — pending legal review)
This section states the legal-basis candidates the operator currently understands to apply under the EU General Data Protection Regulation (GDPR). It has not yet been confirmed by a lawyer and is not a legal certification.
- Performance of a contract (Art. 6(1)(b) GDPR): account data, profile data, Nearby, Events, Spots, connections, and messaging — all directly necessary to provide the Kogoto service you signed up for.
- Legitimate interest (Art. 6(1)(f) GDPR): security logging, fraud and abuse prevention, rate limiting, the reporting / blocking / moderation system, crash diagnostics, and the aggregate product analytics in Section 3 — necessary to keep Kogoto and its users safe and to operate and improve the service.
- Consent (Art. 6(1)(a) GDPR): push notifications (an operating-system permission you grant or deny, plus app-level category toggles you control), and any future optional feature that is not necessary for the core service.
- Legal obligation (Art. 6(1)(c) GDPR): retaining specific records where the operator becomes subject to a legal retention requirement.
6.Who receives your data (processors)
Kogoto uses the following external infrastructure providers to operate the service. Each acts as Kogoto's data processor for the data described. Kogoto does not sell your data, and does not share it with any advertiser or data broker.
| Provider | Used for | What it processes |
|---|---|---|
| Render | Backend application hosting (Frankfurt, Germany) | All data that passes through Kogoto's backend, in transit and in process memory |
| Supabase | Database and private file storage | Account, profile, message, analytics, and media data at rest |
| Google Firebase | Push notifications; app crash / error diagnostics (Crashlytics) | Device push token and notification content (deliberately generic — no message text); for crash diagnostics, a stack trace and device / OS / app-version information only, never a user identifier or email |
| Brevo (Sendinblue SAS) | Transactional email (verification codes, password-reset codes) | Your email address and the one-time code being sent |
| Google — Sign in with Google | Identity provider for the optional "Continue with Google" sign-in | The Google account identifier, email, and name inside the identity token you authorise Google to issue to Kogoto. Used only to create or sign you in to your Kogoto account. No Google access token is retained. |
| Apple — Sign in with Apple | Identity provider for the optional "Sign in with Apple" sign-in | The Apple account identifier and, on first authorisation only, the email (possibly a private-relay address) and name inside the identity token. Used only to create or sign you in to your Kogoto account. No Apple token is retained. |
The product-analytics events in Section 3 are first-party: they are stored only in Kogoto's own database (hosted by Supabase, listed above) and are not sent to any analytics provider. Kogoto does not currently use any advertising SDK, third-party analytics SDK, or data broker.
7.International data transfers
Kogoto's backend runs in Frankfurt, Germany (EU). Supabase, Firebase, and Brevo are each used as configured for this deployment. Whether any of them processes data outside the European Economic Area as part of its own infrastructure has not yet been independently verified by the operator against each provider's current data-processing agreement and sub-processor list. This section will state a final position once that verification is complete; in the meantime, treat Firebase and the Google / Apple sign-in infrastructure as potentially global.
8.How long Kogoto keeps your data
Most of your data is kept for as long as your account exists and is deleted when you delete your account (see Section 10), including your profile, media, Stories, connections, messages, Nearby and Event/Spot state, notification settings, and the product-analytics events in Section 3.
Narrow exceptions, retained after deletion because they no longer contain identifying data or are needed for safety:
- Reports filed against your account (as the reported person) are retained as moderation history. Such a report never stored your personal data beyond an internal id reference, which becomes a dangling reference on deletion.
- Abuse-prevention counters (rate-limit events) are retained. These are opaque strings with no direct link to your account that could be used to selectively remove them.
Stories have their own 24-hour visibility window as a product behaviour. Whether Kogoto's hosting and database providers retain a point-in-time backup copy for a period after deletion (standard for managed database backups) has not yet been confirmed with those providers; this section will be updated when it is.
9.Your rights
Subject to the conditions and exceptions set out in the GDPR, you may have the right to:
- Access a copy of the personal data Kogoto holds about you (see Section 11 for the in-app self-service option).
- Rectification of inaccurate data — most profile fields can be edited directly in the app.
- Erasure ("right to be forgotten") — see Section 10.
- Restriction of processing, in the circumstances the GDPR provides for.
- Data portability, for data you provided and that is processed by automated means under a contract or consent basis — see Section 11.
- Object to processing based on legitimate interest.
- Withdraw consent at any time, for any processing based on consent (for example, push notifications), without affecting the lawfulness of processing before the withdrawal.
To exercise any of these rights, contact kogoto2026@gmail.com. Kogoto will respond as required by applicable law. Some requests may require verifying that you are the account holder before Kogoto can act on them, to protect your data from being accessed or deleted by someone else.
You also have the right to lodge a complaint with a supervisory authority. In Austria this is the Österreichische Datenschutzbehörde (Austrian Data Protection Authority) — www.dsb.gv.at. You may also contact the authority in your own EU member state.
10.Delete your account
You can permanently delete your Kogoto account at any time from Settings → Delete account, after confirming your password (or re-authenticating with Google or Apple if your account has no Kogoto password). This immediately: signs you out everywhere (every active session is revoked); stops Nearby discovery and Bluetooth advertising; removes your device from receiving further push notifications; and deletes your profile, gallery photos, Stories, connections, messages, Nearby and Event/Spot state, notification preferences, blocks you set, reports you filed, and product-analytics events, in a single database transaction. Deletion cannot be undone.
If you no longer have the app or cannot sign in, email kogoto2026@gmail.com from the address associated with your account, with the subject line "Delete my Kogoto account." Kogoto will verify you control that email address before deleting the account, and will not confirm or deny whether an address has a Kogoto account to anyone other than that verified request. See the exceptions in Section 8 for the narrow categories not erased immediately.
11.Export your data
You can request a machine-readable (JSON) copy of your own Kogoto data from Settings → My Data & Privacy → Download my data. The export contains your own profile, gallery and Stories metadata, connections, messages you sent, blocks and reports you filed, and notification preferences. It never includes your password hash, any access, refresh, verification, or reset token, another user's private data, or any information about who reported you.
12.Children and minimum age
Kogoto requires every account holder to be at least 16 years old, enforced both when you enter your date of birth during sign-up and independently by the backend (a client cannot bypass this check). Kogoto does not knowingly collect personal data from anyone under 16. Kogoto's separate Child Safety Standards describe how Kogoto approaches child-safety concerns more broadly, including for users aged 16–17.
13.Security measures
Passwords are hashed with Argon2 and are never stored or logged in plaintext. Refresh tokens, email-verification codes, and password-reset codes are stored only as a cryptographic hash. All communication between the Kogoto app and its backend uses HTTPS. Private media (profile pictures, gallery and Story photos) is stored in a private bucket and served only through an authenticated route, never a public URL.
Kogoto's hosting and database/storage providers apply their own
infrastructure-level security controls; the operator has not independently
audited or certified those providers' specific technical safeguards, and
this policy does not claim "all data is encrypted" as a blanket statement.
If you believe you have found a security issue, see SECURITY.md
in the Kogoto repository or email the contact address above.
14.Changes to this policy
If this policy changes in a way that materially affects how your data is processed, Kogoto will update the "Last updated" date above and make reasonable efforts to notify active users (for example, via an in-app notice). Continuing to use Kogoto after a change takes effect means you accept the updated policy; you can always delete your account if you do not.
3 September 2026: added a dedicated disclosure of Kogoto's first-party product analytics (Section 3); added Kogoto Spots to Section 3; expanded the messaging description to cover in-chat photos, emoji reactions, and replies; aligned Section 10 with the in-app "Delete account" wording. This is an effective-date update only — there is no separate "accept the Privacy Policy" step in the app, so it triggers no re-acceptance.
30 August 2026: added the "Continue with Google" and "Sign in with Apple" disclosures.
Questions about this policy: kogoto2026@gmail.com. See also the Terms of Service and the Support page.