Privacy policy
This Privacy Policy explains what personal data Karv collects, how we use it, and how we protect it when you use the Karv application (“the App”).
We comply with the General Data Protection Regulation (EU 2016/679) (“GDPR”) and applicable laws of Poland.
1. Who we are
Karv is developed and operated by Karv Labs.
If you have a privacy question, contact privacy@karv.today.
2. What data we collect
a. Account and profile data
- Email address
- Authentication data handled through Supabase Auth
- Profile information you provide, such as your display name and timezone
b. Usage data
- Time-tracking sessions, notes, timestamps, item titles, and related metadata you create in the App
- Basic service logs we use for diagnostics, security, and abuse prevention
We do not collect unnecessary personal data, and we do not track your activity outside the App.
3. How we use your data
We use your data to:
- Operate and maintain the App
- Sync and display your sessions and notes
- Provide customer support
- Improve performance and reliability
- Detect and prevent abuse or technical issues
We do not sell your data or use it for advertising.
4. Legal basis for processing
We process your data under the following GDPR bases:
- Performance of a contract: to provide the App and its features.
- Legitimate interest: to keep the service secure and reliable.
- Consent: where consent is required by law, we will ask for it.
5. Data storage and third-party services
We use Supabase for authentication and backend services, including storing account, profile, and app data.
We also use Amazon Web Services (AWS) to help run and deliver the App.
If we add other services that process personal data, we will update this policy.
6. Data retention
We keep your data for as long as we need it to provide the App and support your account.
If you ask us to delete your account or personal data, we will handle that request within the timeframe required by law, subject to any legal, security, or backup retention needs.
We may keep limited diagnostic logs for security, fraud prevention, and service reliability.
7. Your rights
Under the GDPR, you have the right to:
- Access your personal data
- Rectify inaccurate data
- Delete your data (“right to be forgotten”)
- Restrict or object to processing
- Receive a copy of your data in a portable format
To exercise any of these rights, email privacy@karv.today.
We will respond within the timelines required by law.
8. Security
We use encryption in transit, such as HTTPS, and other technical safeguards appropriate to the services we use.
Access to personal data is limited to authorized personnel and protected by authentication controls.
No system is perfectly secure, but we continually review and update our safeguards.
9. International transfers
If your data is transferred outside the European Economic Area, we will do so only under lawful safeguards, such as Standard Contractual Clauses (SCCs) or similar approved mechanisms.
10. Cookies and analytics
Karv does not use advertising cookies or invasive cross-site tracking.
If we introduce analytics or additional cookies in the future, we will update this policy first.
11. Children’s privacy
Karv is not directed to children under 16.
If you believe a child has given us personal data without the required consent, contact privacy@karv.today so we can delete it.
12. Changes to this policy
We may update this Privacy Policy from time to time.
The latest version will always be available at https://karv.today/privacy.
If a change is material, we’ll let you know in the App or by email before it takes effect.
13. Contact
For privacy-related questions, requests, or complaints, email privacy@karv.today.