Privacy

Kotavo Privacy Policy

Last updated: October 2026

This policy describes how the Kotavo city companion app handles information. Kotavo is operated by Kwovira Technologies.

Who operates Kotavo

Kotavo is built and operated by Kwovira Technologies. For any privacy question or request about Kotavo, contact support@kwovira.com.

Scope of this policy

This policy governs the Kotavo mobile app, which is currently offered as a controlled beta. It does not govern the Kwovira corporate website, which has its own separate website privacy notice. If Kotavo's data practices change materially, this policy will be updated before the new practices take effect.

Information Kotavo accesses or collects

Kotavo is designed to work without an account and to keep personal decision-making data on your device. In summary:

Kotavo has no advertising SDKs, no analytics or tracking SDKs, and no crash-reporting SDKs. Your information is never sold.

Location information

The app declares the Android location permissions (ACCESS_FINE_LOCATION and ACCESS_COARSE_LOCATION) so that two optional, explicit features can work:

  1. Nearby ranking — when you explicitly turn on location personalisation in the visitor experience, the app reads your current position once to rank nearby places already shown in the app.
  2. Journey origin — when planning a journey in Getting Around, you may optionally use your current position as the starting point. Typing the start manually always works without location.

The following protections always apply to location:

How information is used

Information is used only for these purposes:

Beta feedback

The in-app beta feedback form sends the category you pick (problem, suggestion, data issue, or other), the message you write (up to 2,000 characters), the app surface you sent it from, and basic app metadata (app version, build number, platform such as Android). Feedback works without signing in: the form does not ask for your name or email, and no account or location is attached.

Submitted feedback is stored by Kwovira with a reference ID, a status, and timestamps so the team can review and act on it during the beta. Because the message is free text, please do not include passwords, identity numbers, or other sensitive personal details in feedback.

Device and local information

The following stays on your device and is not sent to Kwovira:

If you sign in, a session token is kept in your device's secure storage so the app can recognise you until you sign out or the session expires.

Technical and service information

When the app talks to the Kotavo API, connections use HTTPS. Operating the service necessarily processes standard technical information, such as request timestamps, the requested route or feature, status codes, request identifiers, and network information such as IP addresses as seen through forwarding headers. This is used to deliver, secure, and debug the service — for example, to investigate failures or abuse. Authentication credentials are redacted from logs and are never stored in readable form.

Service providers and sharing

Kwovira shares data only as needed to operate Kotavo:

There is no advertising, analytics, or crash-reporting provider. Data is never sold, and peer users in Kotavo Connect never see your raw account identifiers or email address.

Accounts and Kotavo Connect

Using Kotavo as a guest — without an account — keeps every city companion module available. Signing in with Google is optional. If you sign in, Kwovira stores a provider-neutral account record, the verified provider reference, and your email address for minimal account display only.

Kotavo Connect (meeting people in your city) is optional and off by default. Signing in alone never turns Connect on and never publishes anything. If you choose to use Connect, you decide what goes into your profile (such as a nickname, languages, interests, or a short intro), who can discover you, and whom to connect with; messages are plain text shared only with accepted connections, and safety reports are append-only and never shown to the reported person. Blocking stops further contact from the blocked account.

Data retention

Kwovira does not publish fixed numeric retention periods. Information is retained only as long as reasonably necessary for the purpose described in this policy:

Data deletion and privacy requests

To request access, correction, or deletion of information associated with you, email support@kwovira.com from an address we can reply to, describing your request. Signing out revokes your app session on the server. Feedback reference IDs you receive after submitting can help us locate a specific report.

Data security

Kwovira uses reasonable technical and organisational safeguards, including HTTPS for app traffic, one-way hashing of stored session tokens, redaction of credentials from logs, and restricted access to production infrastructure. No method of transmission or storage is completely secure, so absolute security cannot be guaranteed.

Children's privacy

Kotavo is not directed at children under 13, and the beta does not knowingly collect personal information from children. If you believe a child has provided personal information through Kotavo, contact support@kwovira.com so it can be reviewed and removed where appropriate.

Changes to this policy

Material changes to how Kotavo handles information will be reflected in an updated policy here before they take effect. The date at the top shows when this policy was last updated.

Contact

For privacy questions or requests about Kotavo, contact support@kwovira.com.

Corporate website notice