Privacy
Kotavo Privacy Policy
Last updated: October 2026
This policy describes how the Kotavo city companion app handles information. Kotavo is operated by Kwovira Technologies.
Who operates Kotavo
Kotavo is built and operated by Kwovira Technologies. For any privacy question or request about Kotavo, contact support@kwovira.com.
Scope of this policy
This policy governs the Kotavo mobile app, which is currently offered as a controlled beta. It does not govern the Kwovira corporate website, which has its own separate website privacy notice. If Kotavo's data practices change materially, this policy will be updated before the new practices take effect.
Information Kotavo accesses or collects
Kotavo is designed to work without an account and to keep personal decision-making data on your device. In summary:
- Stays on your device only: your precise location when you explicitly request a nearby feature (used once, never stored or sent anywhere), and your settings and preferences such as visitor or local mode, mobility profile, and map layer choices.
- Sent to Kwovira only when you choose: beta feedback you submit, sign-in information if you sign in with Google, and Kotavo Connect content if you turn Connect on and publish or message.
- Always sent for technical operation: the standard technical information every app sends with network requests, such as the requested page or feature, described below.
Kotavo has no advertising SDKs, no analytics or tracking SDKs, and no crash-reporting SDKs. Your information is never sold.
Location information
The app declares the Android location permissions
(ACCESS_FINE_LOCATION and
ACCESS_COARSE_LOCATION) so that two optional, explicit
features can work:
- Nearby ranking — when you explicitly turn on location personalisation in the visitor experience, the app reads your current position once to rank nearby places already shown in the app.
- Journey origin — when planning a journey in Getting Around, you may optionally use your current position as the starting point. Typing the start manually always works without location.
The following protections always apply to location:
- Location is foreground-only — the app never requests background location and never tracks you continuously.
- Location is read once per explicit action at medium (reduced) accuracy, which is sufficient everywhere in the app.
- Your coordinates stay on your device: they are never sent to the Kotavo API, never stored on Kwovira servers, and never saved on the device (only the on/off preference is remembered).
- Location is never given to any third-party SDK or service and is never used for advertising or analytics.
- If you tap an external directions or map link, your chosen destination (a place from Kotavo's city data, not your live position) is opened in the map app you choose — only ever on your explicit tap.
How information is used
Information is used only for these purposes:
- Showing city information, places, events, and mobility content you request.
- Ranking nearby places or setting a journey start, on-device, when you explicitly ask.
- Operating optional sign-in, Kotavo Connect, and beta feedback when you choose to use them.
- Operating, securing, and improving the service, including reviewing beta feedback and investigating faults or abuse.
Beta feedback
The in-app beta feedback form sends the category you pick (problem, suggestion, data issue, or other), the message you write (up to 2,000 characters), the app surface you sent it from, and basic app metadata (app version, build number, platform such as Android). Feedback works without signing in: the form does not ask for your name or email, and no account or location is attached.
Submitted feedback is stored by Kwovira with a reference ID, a status, and timestamps so the team can review and act on it during the beta. Because the message is free text, please do not include passwords, identity numbers, or other sensitive personal details in feedback.
Device and local information
The following stays on your device and is not sent to Kwovira:
- Visitor or local mode choice and related preferences.
- Mobility profile (your travel modes and primary mode).
- Map layer and display choices.
- Your precise location, whenever location features are used (never saved).
If you sign in, a session token is kept in your device's secure storage so the app can recognise you until you sign out or the session expires.
Technical and service information
When the app talks to the Kotavo API, connections use HTTPS. Operating the service necessarily processes standard technical information, such as request timestamps, the requested route or feature, status codes, request identifiers, and network information such as IP addresses as seen through forwarding headers. This is used to deliver, secure, and debug the service — for example, to investigate failures or abuse. Authentication credentials are redacted from logs and are never stored in readable form.
Service providers and sharing
Kwovira shares data only as needed to operate Kotavo:
- Google sign-in (only if you sign in): Google verifies your identity and the app exchanges the resulting identity token with the Kotavo API for a revocable, opaque session. Only a hash of the session token is stored server-side.
- Map tiles: the in-app map loads map image tiles from the OpenStreetMap tile service, which necessarily receives the tile areas your map view requests.
- Hosting and network infrastructure: the servers and network systems that deliver and protect the Kotavo API necessarily handle request traffic described above.
- Email: if you write to support@kwovira.com, we receive what you include so we can respond.
There is no advertising, analytics, or crash-reporting provider. Data is never sold, and peer users in Kotavo Connect never see your raw account identifiers or email address.
Accounts and Kotavo Connect
Using Kotavo as a guest — without an account — keeps every city companion module available. Signing in with Google is optional. If you sign in, Kwovira stores a provider-neutral account record, the verified provider reference, and your email address for minimal account display only.
Kotavo Connect (meeting people in your city) is optional and off by default. Signing in alone never turns Connect on and never publishes anything. If you choose to use Connect, you decide what goes into your profile (such as a nickname, languages, interests, or a short intro), who can discover you, and whom to connect with; messages are plain text shared only with accepted connections, and safety reports are append-only and never shown to the reported person. Blocking stops further contact from the blocked account.
Data retention
Kwovira does not publish fixed numeric retention periods. Information is retained only as long as reasonably necessary for the purpose described in this policy:
- Beta feedback is kept while needed to evaluate and improve the beta.
- Account and Connect records are kept while your account or profile is active.
- Operational and security logs are kept for limited service and security purposes.
- Session tokens expire and can be revoked by signing out.
Data deletion and privacy requests
To request access, correction, or deletion of information associated with you, email support@kwovira.com from an address we can reply to, describing your request. Signing out revokes your app session on the server. Feedback reference IDs you receive after submitting can help us locate a specific report.
Data security
Kwovira uses reasonable technical and organisational safeguards, including HTTPS for app traffic, one-way hashing of stored session tokens, redaction of credentials from logs, and restricted access to production infrastructure. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.
Children's privacy
Kotavo is not directed at children under 13, and the beta does not knowingly collect personal information from children. If you believe a child has provided personal information through Kotavo, contact support@kwovira.com so it can be reviewed and removed where appropriate.
Changes to this policy
Material changes to how Kotavo handles information will be reflected in an updated policy here before they take effect. The date at the top shows when this policy was last updated.
Contact
For privacy questions or requests about Kotavo, contact support@kwovira.com.