Home

Privacy policy

Koriva is a family safety app, and by its nature it handles sensitive data: location, events on a child’s phone, sometimes messages. So we started by deciding what we would not collect. This policy describes what the app actually does today.

Last updated:

In short

  • No ads, no selling of data, no analytics or tracking tools.
  • Adults turn their own location and usage sharing on themselves; a child’s sharing is managed by the family, and the child sees this on their phone.
  • Shared message content is end-to-end encrypted with the family guardians’ keys; we cannot read it.
  • The web filter and link check never read or record the pages you visit.
  • Most data is kept for a limited time: live location 24 hours, events at most 90 days; the day’s movements stay only on the child’s phone, for 7 days.
  • The daily brief is written by rules; your data is never sent to any AI model.
  • You can delete your account from the app at any time.

Who is responsible

The controller of the personal data in this policy is Koriva – Family Tracking & Safety (“Koriva”, “we”). For any privacy question or request: azadbilek34@gmail.com.

Whose data is processed

  • Family guardians: the adults who create the account and manage the family.
  • Family members: children, older relatives and other adults who join the family by invitation.
  • Others, indirectly: the numbers of people who call or message a child’s phone and (at the level the guardian chooses) the message text; phone numbers reported as scams.
  • Visitors to this website (see “This website” below).

What we process and why

Each item says what the data is, why it is needed and the legal basis. The bases are: contract (to provide the app), consent (optional sharing) and legitimate interest (keeping the service secure and preventing abuse).

Account and family

  • Email address and password (the password is held only by Firebase Authentication, in a form that cannot be reversed), display name, role in the family (guardian, child, older relative, adult) and family memberships. Basis: contract.
  • Optional profile photo: shrunk on the phone to 192 pixels, with its location and device information (EXIF) removed. Only a family guardian can set a child’s photo; nobody can set another adult’s.
  • Optionally a child’s birth year only, to suggest age-appropriate settings. The birthday is never asked.

Location

  • The latest location of a person who turned sharing on (deleted after 24 hours). A child’s movements during the day are not sent to the server: they are kept only on the child’s phone for 7 days. When a family guardian asks for a day, it is sent encrypted with the guardians’ keys; the server cannot read it and this encrypted copy is deleted after 24 hours. An adult’s movement history can never be asked for.
  • Safe zones (areas such as home or school that the family draws) and records of arriving at and leaving them (7 days).
  • Journeys: destination, estimated arrival and arrival alert (30 days).
  • Basis: for adults, consent; the person starts sharing and can stop it at any time. For children, the parent’s (family guardian’s) consent; once sharing is on the child cannot turn it off, and a guardian can stop it by removing the child from the family.

Devices and notifications

  • Battery level (7 days), whether protections are on (30 days), phone type and language.
  • The device’s notification token, to send notifications (renewed while in use, deleted after 30 days without use).
  • Firebase App Check tokens that confirm the app is the genuine Koriva app. Basis: legitimate interest (preventing abuse of the service).

Screen time and rules

  • The rules the family sets (daily time, school hours and bedtime, app limits) and which version of the rules the phone applied.
  • App usage (minutes per app): for children, always visible to the family guardian; for adults, only if they turn it on on their own phone. What happens inside apps is never read. Kept for 35 days; deleted immediately when an adult turns sharing off. Basis: for children, parental consent; for adults, consent.

A child’s calls and messages (Android only)

  • The family guardian chooses how much is shared from a child’s phone: nothing, only who and when, or including content.
  • Calls: number, time, duration and call type. SMS and WhatsApp, Telegram, Instagram and Messenger notifications: sender, time and (if chosen) text. Message text is encrypted with the family guardians’ keys; our server only sees it encrypted.
  • Links in messages are checked on the phone; if one is suspicious, the family receives a “suspicious link” alert.
  • For calls from a number not in the contacts, the guardian receives a notification with the number and time.
  • Kept for 30 days. Who changed the sharing level and when is kept for 90 days.
  • Adults’ calls and SMS (including older relatives’) are never shared. An adult can turn on message protection only for themselves, and with the recommended option neither the sender nor the text is shared.

Safety events

  • Emergency help (SOS) requests (30 days), “I’m OK” check-ins (30 days), Incident Center entries (90 days; the type and time of the event, not its content) and daily brief records (35 days).
  • Blocked calls and protection-related events (30 days).

Scam number reports

  • When you report a number as a scam, it is stored as a keyed hash, not in plain form. If a number is reported by three separate accounts it joins the public block list; the list never says who reported it.
  • Basis: legitimate interest (collective protection against fraud).

Link check and web filter

  • For a link check, the server receives not the address but a short fingerprint shared by thousands of addresses; the phone does the matching. Queries are not recorded.
  • The web filter runs on the phone and only looks at address lookups (DNS). Block lists are downloaded to the phone. Pages visited are never read, recorded or sent to us. Only a short list of blocked addresses stays on the phone.

Subscription

  • Payment is taken by the App Store or Google Play; your card details never reach us. To confirm the subscription, your account ID and purchase information go to RevenueCat; no location or family data does. Basis: contract.

Error reports

  • Only if you turn them on: the type of error and the line of code where it happened. No error message or personal information is sent, and reports are not linked to a person. Kept for 90 days.

What we don’t do

  • We don’t show ads, use data for advertising or sell your data to anyone.
  • There is no analytics, advertising or tracking SDK in the app.
  • We don’t send your data to AI or language models.
  • We don’t profile people with automated decisions that have legal effects.

Children’s data

Koriva is a tool used by parents and guardians. A family guardian account can only be created by someone aged 18 or over. A child joins Koriva only through the guardian’s invitation and the setup the guardian does on the phone; that setup is the parent’s consent to processing the child’s data. The guardian confirms they have legal authority over the child.

Koriva does not hide on a child’s phone: the app, its persistent notifications and system permissions are visible. As a parent you can always ask for a child’s data to be deleted.

Who we share data with

Your family: sharing is the purpose of the app and is limited by the permissions described above.

Service providers (they work only on our behalf and on our instructions):

  • Google (Firebase): authentication, database, server functions, file storage, notification delivery and App Check. App data is stored in data centres in the European Union (europe-west1, Belgium); authentication and notification delivery run on Google’s global infrastructure.
  • Apple and Google notification services (APNs, FCM): to deliver notifications to your phone. Notifications shown on the lock screen are written to leave out sensitive details.
  • RevenueCat (USA): subscription verification.
  • Google Maps: the map is shown in the app with the Google Maps SDK. To show the map and run its service, Google processes the phone’s IP address, the map area viewed and technical usage information, also under Google’s privacy policy. Koriva does not send your family’s locations to Google; the markers are drawn over the map on the phone.
  • FOSSGIS e.V. (Germany), routing.openstreetmap.de: start and end points are sent only when you ask for a route for a journey.

Authorities: only when the applicable law requires it and only as far as necessary.

International transfers

Although app data is stored in the EU, some data may be processed in the USA for authentication, notification delivery, showing the map and subscription verification. These transfers rely on safeguards offered by the providers and recognised by the applicable law (for example the European Commission’s standard contractual clauses and the EU-US Data Privacy Framework).

How long we keep data

DataKept for
Live location24 hours
Movement historyOnly on the child’s phone, 7 days
Encrypted copy of a movement summary24 hours
Zone arrival and departure records7 days
Battery level7 days
Journeys, SOS, I’m OK, call and message records30 days
App usage, daily brief records35 days
Incident Center, error reports, sharing-change records90 days
Account, family, rules, zones, profile photoUntil the account is deleted
Record of a deletion7 days after the deletion completes

Expired records are deleted automatically. If a legal retention duty applies, the data is kept only for that period and purpose.

Security

All connections are encrypted (HTTPS). Database access is restricted by rules that open each record only to the family members who need to see it. Message content is end-to-end encrypted. Only verified Koriva apps can reach the server. No system is perfect; if a data breach occurs we will inform you and the relevant authority as the law requires.

Your rights

Depending on the law where you live (for example the EU General Data Protection Regulation, KVKK in Türkiye, the UK GDPR or US state laws) you may have the right to access, correct and delete your data, to restrict or object to processing, to receive your data in a portable form and to withdraw consent at any time.

  • Most of these you can use straight away in the app: turn sharing off, remove your photo, turn usage sharing off (records are deleted), delete your account.
  • For anything else, write to azadbilek34@gmail.com. We reply within 30 days at the latest and may ask you to write from your registered email address to confirm it is you.
  • You have the right to complain to a data protection authority (in the EU, the authority in your country; in the UK, the ICO; in Türkiye, the Personal Data Protection Authority).
  • For California and similar laws: we do not sell your personal information or share it for targeted advertising.

This website

korivafamily.com uses no cookies, analytics or advertising and loads nothing from other sites; even the fonts come from the site itself. The site is served by Firebase Hosting (Google), which processes technical information such as your IP address to deliver pages and prevent abuse. The language you choose is remembered only in your browser for your next visit.

Changes

We update this policy as the app changes and refresh the date above. For an important change (for example a new kind of data or a new service provider) we will tell you in the app in advance, and ask for your consent again where processing is based on consent.

Contact

Koriva – Family Tracking & Safety · azadbilek34@gmail.com