Privacy Policy
What changed in this version
- Added new features: Going (event attendance), chat read state, last message in the chat list, kor start time and friend marker, user-added venues, Appearance (day/night) and language settings.
- Rewrote the location section to match the app exactly: the 300 m, 1 km and 5 km rules and the coordinates stored when you light a kor.
- Updated the retention table; records with no fixed retention period are now stated as such. Corrected the waitlist retention statement.
- Added a section for users in the United States (California and other state rights, “Do Not Sell or Share” statement).
- Updated event sources, event images delivered through our server, and the list of service providers; Google Places and Google Geocoding were removed from the list because we no longer use them.
This policy explains how your personal information is handled when you use the Kor mobile app and the getkor.app website. It is the notice at collection for users in the United States (see section 12), the information notice under the GDPR for users in the European Economic Area/United Kingdom, and, for users in Türkiye, the notice under Law No. 6698 on the Protection of Personal Data (“KVKK”).
1. Who we are
The controller is [COMPANY LEGAL NAME] (“Kor”, “we”), address: [ADDRESS]. For any question, request or complaint about this policy, contact support@getkor.app. We respond within 30 days, or within 45 days where US state law applies.
2. In short
- We do not sell your personal information, we do not use it for advertising and we do not share it with ad networks. There are no ads in the app.
- Your location is not tracked continuously: it is read once, only while the app is open, when you open a screen or take an action. It is never read in the background.
- Other people see the venue you are at, not your exact coordinates.
- Chats close when the kor goes out, and messages are later deleted from our systems (see section 6).
- You can delete your account from the app at any time; deletion is immediate.
3. Information we collect
- Account and identity: first and last name, username, age (only your calculated age is stored, not your date of birth), gender, bio, your ID at your Google/Apple sign-in provider and your email address if the provider shares it, your phone's operating system (iOS/Android), your invite code and who invited you.
- Photos: profile photo and gallery photos (others see at most 3 on a free account and at most 9 on Premium; extra photos are hidden, not deleted).
- Location: see section 4.
- Kors: the venue where you light a kor, your GPS coordinates at that moment, your note, the occasions you pick, group size, the “open to something new” marker, start and end time, and your feedback after the kor. We record who opened your kor card and on which day; you are only shown the total.
- Messages: the first message you send when you write to a kor and your distance to the venue (not your coordinates), chat messages, and a record created when you take a screenshot of a chat on iPhone.
- Chat read state: for each chat we store a “last read” timestamp on our server, used only to calculate your own unread count. The other person is never shown a “seen” status. The last message of each chat in your chat list is shown only to you.
- Friends and evening plans: your mutual friendships, the friend groups you create (name and members), and your friend code, valid for 72 hours. When you say “I'm going out tonight”: the time, the venue (if you choose one), your arrival time and the groups you show it to. When you mark your arrival, your location is used only for the proximity check and is not stored.
- Going (event attendance): when you tap “Going” on an event, we store your account, the event and the time. Other users only see the total count; your first name and photo are shown only to your friends (at most 3 people per event, plus a count of friends). People you have blocked, or who have blocked you, do not see you.
- Venue marks and venue photos: the music/entry/line information you mark at a venue and photos you take there. These are shown to others in aggregate and without showing who posted them; they are kept with your identity for abuse review. Photos go through automated content screening before they are published, and the screening labels are stored.
- Venues you add: when you add a venue we store its name, type and your current GPS position (as the venue's location), and mark your account as the one who added it. Until it is approved the venue is visible only to you; once approved it is visible to everyone, without showing who added it.
- Venues you follow: a private list; venues cannot see who follows them.
- Badges and kor power: derived from your kor history, meet confirmations, invites, friendships and venues you added. Visible to others by default; you can hide them in Settings.
- Notifications: your push token (FCM) and the title and text of notifications sent to you.
- Settings: your “Show my location on the map” consent and its date, and badge visibility. Language, Appearance (day/night/auto), maps app preference and saved events are stored only on your phone and are not sent to us. Distance units (km/miles) and clock format follow your phone's region settings.
- Support, reports and blocks: your support messages, reports you make or that are made about you, and blocks.
- Subscription: Premium status, end date and environment (Apple/Google). Your card or bank details never reach us (see section 10).
- Kor Nokta interactions: the day you saw and tapped sponsored venue pins on the map (one record per person per day). Venues only receive totals.
- Usage and device data: in-app usage statistics (screens opened and events such as lighting a kor or sending a message; Firebase Analytics) and crash reports (device model, OS version, error log; Firebase Crashlytics). We do not collect advertising identifiers (IDFA/AAID) and the app does not track you across other companies' apps and websites.
- Website: if you join the waitlist, only your email address; on application forms, what you enter (with a separate notice); analytics cookies only if you accept them (see the Cookie Policy).
Sensitive data: we do not process health, religious, sex-life or biometric data. Automated selfie/face verification was removed from the product on August 8, 2026. Gender is never used for filtering, matching or visibility; it may only be shown as an aggregate ratio not linked to anyone (the share of women/men among all users).
4. Location
- When it is read: only while the app is open; once each time you open the map, the feed or a venue, and when you take an action such as lighting a kor, adding a venue or making an evening plan. We never ask for background location and never read it in the background.
- Why it is sent: so we can show nearby venues, kors and events, your location is included in that request to our server; it is not stored for those requests.
- What is stored: when you light a kor, your coordinates at that moment are stored with the kor (for safety and abuse review); when you write to a kor, only your distance is stored; when you add a venue, your position becomes the venue's location.
- The 300 m rule: to light a kor, add a venue mark or photo, or mark your arrival for an evening plan, you must be within 300 meters of the venue (with GPS accuracy of 100 m or better).
- What others see: your kor is visible to users within 5 km of the venue. The identifying details on a kor card (first name, age, photo, note, badges, when the kor started and whether you are friends) are shown only to people closer than 1 km to the venue; people farther away see a masked card: only the venue, group size, the “open to something new” marker and end time. Start time and the friend marker are never sent on masked cards. Your exact coordinates are never shown to any user.
- Location display consent: before you light a kor we separately ask for your consent to show the venue you are at on the map. Without it you cannot light a kor but you can still use the map. You can withdraw it in Settings > “Show my location on the map”.
- Location-based notifications: you may get a notification when someone lights a kor at a venue where you have lit one before (at most once every 6 hours) and in the evening about activity in the district of your last kor. You can turn notifications off in Settings.
5. Purposes and legal bases
- Providing the service (account, map, kors, messaging, friends, evening plans, Going, adding venues, Premium): performance of a contract (GDPR Art. 6(1)(b); KVKK Art. 5(2)(c)).
- Safety and abuse prevention (reports/blocks, content screening, fighting fake accounts and fake locations, keeping kor coordinates): legitimate interests (GDPR Art. 6(1)(f); KVKK Art. 5(2)(f)).
- Product improvement and statistics (Firebase Analytics, Crashlytics, aggregate reports): legitimate interests. Never used for advertising.
- Legal obligations (lawful requests from authorities, billing records): GDPR Art. 6(1)(c); KVKK Art. 5(2)(ç).
- Consent: website analytics cookies and application forms. Showing your venue on the map also requires your consent (section 4).
We collect your information electronically and automatically through the app and the website.
6. How long we keep it
| Chat messages | A chat closes the moment the kor goes out and neither side can view it again. Messages are deleted from our systems 48 hours after the kor's scheduled end. Chats that were reported, or marked “uncomfortable” after the kor, are kept for 30 days for review, then deleted. |
| Chat read state | Deleted with the chat. |
| Kors (including coordinates), the first message you sent to a kor, kor card view records | Until your account is deleted. |
| Evening plans | Deleted at the end of the night (06:00 Turkey time, which is 11 PM US Eastern / 8 PM US Pacific the previous evening during daylight saving time); never archived. |
| Venue marks and venue photos | Record and file deleted at the end of the night they belong to (06:00 Turkey time); never archived. |
| Going records | Until you remove it or delete your account. |
| Friendships and groups | Until you or the other person removes them, or the account is deleted. |
| Friend code | Valid for 72 hours; unusable after it expires and replaced when you generate a new one. |
| Notification history | 90 days. |
| Reports and blocks | Until either person deletes their account. |
| Venues you added | The venue stays on the map; when you delete your account the link to you is removed. |
| Kor Nokta view/tap records, badges, support messages | Until your account is deleted. |
| Other account and profile data, photos | Until your account is deleted; deletion is immediate. |
| Application forms (website/app) | 1 year after the application is decided, or after submission if it is never reviewed; then deleted automatically. |
| Waitlist email (website) | No automatic deletion period; deleted when you ask. |
| Previously verified school domain (removed campus badge) | Until you ask for deletion or the account is deleted. |
| Analytics and crash data | According to Firebase retention settings; aggregate reports not linked to anyone may be kept indefinitely. |
“End of the night” and daily limits are currently calculated in Turkey time (UTC+3) for all countries.
7. What others see
- Kor card: under the rules in section 4; only your first name (not your last name), age, profile photo, note, occasions, group size, whether you are Premium, your badges (unless hidden), when the kor started and whether you are friends with the viewer.
- When you write to a kor: the kor's owner sees your first name, photo, age, message and your distance to the venue.
- In a chat: at first only your first name, age and photo; once you agree to open your profile, the other person also sees your full name, username, bio and gallery.
- Your friends: your first name and photo; your evening plan (time, venue, arrival) if you share it with their group; that you are “Going” to an event.
- Venues (Kor Nokta partners): totals only; no venue is ever told who lit a kor, who came or who marked what.
- Website: names of districts with at least 2 live kors may be shown in aggregate.
8. Service providers and transfers
These providers process your information only on our behalf and under our instructions; none of them uses it for its own commercial purposes:
- Google Firebase (Authentication, Cloud Storage, Cloud Messaging, Firestore, Analytics, Crashlytics): sign-in sessions, photo hosting, push notifications, content-free “something changed” markers, usage statistics and crash reports.
- Sign in with Google and Sign in with Apple: account sign-in.
- Railway: server hosting.
- Supabase: database hosting (United Kingdom, London region).
- Cloudflare: map tile delivery; your IP address and the tile coordinates you view pass through Cloudflare.
- RevenueCat: managing App Store/Google Play subscription status (your user ID and purchase records).
- Amazon Web Services (Rekognition, Frankfurt region): automated content screening of venue photos. A photo that cannot be screened is not published.
- Resend: only transactional alert emails to our own team (for example, a report notice).
- Google Analytics: only on the getkor.app website and only if you accept cookies.
Event and venue data sources: events come from sources such as Ticketmaster, SeatGeek, Bandsintown, Fever, etkinlik.io, Bugece and Xceed; venues come from the Overture Maps Foundation, OpenStreetMap and venues added by users. We send no information about you to these sources. Event images are delivered through our server and held only in temporary memory; if an image is loaded directly from the source's server, your IP address reaches that server. Details and licenses: Data Licenses.
International transfers: our providers' infrastructure is located mainly in the United States, the European Union and the United Kingdom, and Kor is operated from Türkiye. Transfers rely on appropriate safeguards such as adequacy decisions or standard contractual clauses (GDPR Chapter V; KVKK Art. 9).
Authorities: we share information with public authorities when legally required and in response to a valid request.
9. Your rights
Depending on where you live, you may have the right to access, correct, delete or receive a copy of your information, to restrict or object to processing, and to complain to a data protection authority. In Türkiye you also have the rights in KVKK Art. 11. US state rights are in section 12.
You can delete your account in Profile > Settings > “Delete account” (Account and Data Deletion). For anything else, write to support@getkor.app.
10. Payments and subscriptions
Premium is purchased through the App Store (Apple) or Google Play. Your card and bank details are never seen, processed or stored by Kor or RevenueCat. Subscription status (active/inactive, end date) is reported to us through RevenueCat. Terms: Subscription Terms.
11. Security
All data in transit is encrypted with HTTPS/TLS. Row-level security is enabled on our database tables, your session key is kept in secure storage on your phone, and access is limited to the minimum needed to provide the service. No system is perfect; if a data breach occurs we will notify affected people and authorities within the legal deadlines.
12. Additional information for users in the United States
This section applies to residents of California (CCPA as amended by the CPRA) and of other states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Texas, Oregon and others).
- Categories we collected in the past 12 months: identifiers (name, username, email, account ID); protected characteristics (age, gender); commercial information (subscription status); internet or device activity (usage and crash data); geolocation, including precise geolocation; visual information (photos); inferences (badges, kor power). Sources: you and your device. Purposes: those in section 5. Recipients: the service providers in section 8, for business purposes only.
- Sensitive personal information: precise geolocation and account log-in credentials. We use it only to provide the service and keep it safe, as permitted by law, and never to infer characteristics about you.
- Do Not Sell or Share: we do not sell your personal information and we do not share it for cross-context behavioral (targeted) advertising, and we have not done so in the past 12 months. We do not knowingly sell or share the information of anyone under 16; Kor is for adults 18 and over. Because we do not sell or share, a Global Privacy Control signal requires no further action, but we treat it as a valid opt-out request.
- Your rights: to know and access the personal information we hold, to delete it, to correct it, to get a portable copy, to opt out of sale/sharing and to limit the use of sensitive information (we do neither), and not to be discriminated against for using these rights.
- How to exercise them: email support@getkor.app or delete your account in the app. We verify your identity through the email on your account or from inside the app. An authorized agent may submit a request with your written permission. We respond within 45 days. If your state provides an appeal process and we deny your request, you can appeal by emailing support@getkor.app with the subject “Appeal”.
- Retention: as described in section 6.
- Shine the Light / Nevada: we do not disclose personal information to third parties for their own direct marketing and we do not sell covered information.
13. Children
Kor is for people aged 18 and over. If we learn that a user is under 18, we close the account and delete its data. Details: Child Safety Standards.
14. Changes
We may update this policy; each version starts with its date and a summary of changes. We will notify you in the app about significant changes.
15. Contact
Questions and requests: support@getkor.app