Last updated on July 22, 2026

Privacy policy

This Privacy Policy explains what personal data Karv collects, how we use it, and how we protect it when you use the Karv application (“the App”).

We comply with the General Data Protection Regulation (EU 2016/679) (“GDPR”) and applicable laws of Poland.

1. Who we are

Karv is developed and operated by Karv Labs.

If you have a privacy question, contact privacy@karv.today.

2. What data we collect

a. Account and profile data

  • Email address
  • Authentication data handled through Supabase Auth
  • Profile information you provide, such as your display name and timezone

b. Usage data

  • Time-tracking sessions, notes, timestamps, item titles, and related metadata you create in the App
  • Basic service logs we use for diagnostics, security, and abuse prevention

We do not collect unnecessary personal data, and we do not track your activity outside the App.

3. How we use your data

We use your data to:

  • Operate and maintain the App
  • Sync and display your sessions and notes
  • Provide customer support
  • Improve performance and reliability
  • Detect and prevent abuse or technical issues

We do not sell your data or use it for advertising.

4. Legal basis for processing

We process your data under the following GDPR bases:

  • Performance of a contract: to provide the App and its features.
  • Legitimate interest: to keep the service secure and reliable.
  • Consent: where consent is required by law, we will ask for it.

5. Data storage and third-party services

We use Supabase for authentication and backend services, including storing account, profile, and app data.

We also use Amazon Web Services (AWS) to help run and deliver the App.

If we add other services that process personal data, we will update this policy.

6. Data retention

We keep your data for as long as we need it to provide the App and support your account.

If you ask us to delete your account or personal data, we will handle that request within the timeframe required by law, subject to any legal, security, or backup retention needs.

We may keep limited diagnostic logs for security, fraud prevention, and service reliability.

7. Your rights

Under the GDPR, you have the right to:

  • Access your personal data
  • Rectify inaccurate data
  • Delete your data (“right to be forgotten”)
  • Restrict or object to processing
  • Receive a copy of your data in a portable format

To exercise any of these rights, email privacy@karv.today.

We will respond within the timelines required by law.

8. Security

We use encryption in transit, such as HTTPS, and other technical safeguards appropriate to the services we use.

Access to personal data is limited to authorized personnel and protected by authentication controls.

No system is perfectly secure, but we continually review and update our safeguards.

9. International transfers

If your data is transferred outside the European Economic Area, we will do so only under lawful safeguards, such as Standard Contractual Clauses (SCCs) or similar approved mechanisms.

10. Cookies and analytics

Karv does not use advertising cookies or invasive cross-site tracking.

If we introduce analytics or additional cookies in the future, we will update this policy first.

11. Children’s privacy

Karv is not directed to children under 16.

If you believe a child has given us personal data without the required consent, contact privacy@karv.today so we can delete it.

12. Changes to this policy

We may update this Privacy Policy from time to time.

The latest version will always be available at https://karv.today/privacy.

If a change is material, we’ll let you know in the App or by email before it takes effect.

13. Contact

For privacy-related questions, requests, or complaints, email privacy@karv.today.