Privacy Policy

Last updated: October 1, 2026Effective: October 1, 2026

What changed in this version

  • Added new features: Going (event attendance), chat read state, last message in the chat list, kor start time and friend marker, user-added venues, Appearance (day/night) and language settings.
  • Rewrote the location section to match the app exactly: the 300 m, 1 km and 5 km rules and the coordinates stored when you light a kor.
  • Updated the retention table; records with no fixed retention period are now stated as such. Corrected the waitlist retention statement.
  • Added a section for users in the United States (California and other state rights, “Do Not Sell or Share” statement).
  • Updated event sources, event images delivered through our server, and the list of service providers; Google Places and Google Geocoding were removed from the list because we no longer use them.

This policy explains how your personal information is handled when you use the Kor mobile app and the getkor.app website. It is the notice at collection for users in the United States (see section 12), the information notice under the GDPR for users in the European Economic Area/United Kingdom, and, for users in Türkiye, the notice under Law No. 6698 on the Protection of Personal Data (“KVKK”).

1. Who we are

The controller is [COMPANY LEGAL NAME] (“Kor”, “we”), address: [ADDRESS]. For any question, request or complaint about this policy, contact support@getkor.app. We respond within 30 days, or within 45 days where US state law applies.

2. In short

3. Information we collect

Sensitive data: we do not process health, religious, sex-life or biometric data. Automated selfie/face verification was removed from the product on August 8, 2026. Gender is never used for filtering, matching or visibility; it may only be shown as an aggregate ratio not linked to anyone (the share of women/men among all users).

4. Location

5. Purposes and legal bases

We collect your information electronically and automatically through the app and the website.

6. How long we keep it

Chat messagesA chat closes the moment the kor goes out and neither side can view it again. Messages are deleted from our systems 48 hours after the kor's scheduled end. Chats that were reported, or marked “uncomfortable” after the kor, are kept for 30 days for review, then deleted.
Chat read stateDeleted with the chat.
Kors (including coordinates), the first message you sent to a kor, kor card view recordsUntil your account is deleted.
Evening plansDeleted at the end of the night (06:00 Turkey time, which is 11 PM US Eastern / 8 PM US Pacific the previous evening during daylight saving time); never archived.
Venue marks and venue photosRecord and file deleted at the end of the night they belong to (06:00 Turkey time); never archived.
Going recordsUntil you remove it or delete your account.
Friendships and groupsUntil you or the other person removes them, or the account is deleted.
Friend codeValid for 72 hours; unusable after it expires and replaced when you generate a new one.
Notification history90 days.
Reports and blocksUntil either person deletes their account.
Venues you addedThe venue stays on the map; when you delete your account the link to you is removed.
Kor Nokta view/tap records, badges, support messagesUntil your account is deleted.
Other account and profile data, photosUntil your account is deleted; deletion is immediate.
Application forms (website/app)1 year after the application is decided, or after submission if it is never reviewed; then deleted automatically.
Waitlist email (website)No automatic deletion period; deleted when you ask.
Previously verified school domain (removed campus badge)Until you ask for deletion or the account is deleted.
Analytics and crash dataAccording to Firebase retention settings; aggregate reports not linked to anyone may be kept indefinitely.

“End of the night” and daily limits are currently calculated in Turkey time (UTC+3) for all countries.

7. What others see

8. Service providers and transfers

These providers process your information only on our behalf and under our instructions; none of them uses it for its own commercial purposes:

Event and venue data sources: events come from sources such as Ticketmaster, SeatGeek, Bandsintown, Fever, etkinlik.io, Bugece and Xceed; venues come from the Overture Maps Foundation, OpenStreetMap and venues added by users. We send no information about you to these sources. Event images are delivered through our server and held only in temporary memory; if an image is loaded directly from the source's server, your IP address reaches that server. Details and licenses: Data Licenses.

International transfers: our providers' infrastructure is located mainly in the United States, the European Union and the United Kingdom, and Kor is operated from Türkiye. Transfers rely on appropriate safeguards such as adequacy decisions or standard contractual clauses (GDPR Chapter V; KVKK Art. 9).

Authorities: we share information with public authorities when legally required and in response to a valid request.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete or receive a copy of your information, to restrict or object to processing, and to complain to a data protection authority. In Türkiye you also have the rights in KVKK Art. 11. US state rights are in section 12.

You can delete your account in Profile > Settings > “Delete account” (Account and Data Deletion). For anything else, write to support@getkor.app.

10. Payments and subscriptions

Premium is purchased through the App Store (Apple) or Google Play. Your card and bank details are never seen, processed or stored by Kor or RevenueCat. Subscription status (active/inactive, end date) is reported to us through RevenueCat. Terms: Subscription Terms.

11. Security

All data in transit is encrypted with HTTPS/TLS. Row-level security is enabled on our database tables, your session key is kept in secure storage on your phone, and access is limited to the minimum needed to provide the service. No system is perfect; if a data breach occurs we will notify affected people and authorities within the legal deadlines.

12. Additional information for users in the United States

This section applies to residents of California (CCPA as amended by the CPRA) and of other states with comprehensive privacy laws (such as Colorado, Connecticut, Virginia, Texas, Oregon and others).

13. Children

Kor is for people aged 18 and over. If we learn that a user is under 18, we close the account and delete its data. Details: Child Safety Standards.

14. Changes

We may update this policy; each version starts with its date and a summary of changes. We will notify you in the app about significant changes.

15. Contact

Questions and requests: support@getkor.app