Skip to content
KyMo

Privacy Policy

Last updated August 27, 2026

This policy describes how KyMo collects, uses, and retains information when you use the iPhone app and this website at kymodev.app. If you have questions, write support@kymodev.app.

Last updated August 27, 2026.

Who we are

KyMo is a private friend-group utility published at kymodev.app. Published support contact: support@kymodev.app.

What KyMo is

KyMo is a native iPhone app for invite-only groups. A group is the unit of work. The top of the app is a group switcher. It is not a public network, not a messenger, and not a web app clone of the product. Groups already talk in other apps. KyMo holds shared utilities those chats cannot: receipts, trips, links, hours, and scoreboards.

You create a group or join with a join code. Knowledge of the code is the invite. There is no public discovery and no explore tab.

Account data

Sign-in uses Email and Password through Firebase Authentication. We also store a display name and an optional avatar. We do not offer Sign in with Apple or Google Sign-In on the current product.

Group data

Group records live in Cloud Firestore. Depending on what members use, that can include:

  • Group name, membership, and roles.
  • Ledger receipts, line items, and splits.
  • Expedition itineraries (times stored in UTC and shown in the destination timezone).
  • Vault metadata for saved links and photos.
  • Schedule hours and overlap state.
  • Rankings, seasons, and scores.
  • Reports submitted by members.

Files we store

Avatar images and Vault JPEG uploads are stored in Google Cloud Storage. Photos in Vault are member uploads, not titles scraped from Safari.

Vault link previews

If you paste a URL into Vault, a Cloud Function may request that URL from Google infrastructure to read Open Graph tags. The request uses User-Agent KyMoVaultBot/1.0. Do not paste secret, credentialed, or private URLs. We do not want scrape URLs pasted into support tickets as a log dump.

Join codes

The join code is the Firestore group id. It is high-entropy, not a 6-digit PIN. A signed-in person who has the code can preview the group name and the membership list needed to join. Forwarded codes are not private. You are responsible for who you share a code with.

Push notifications

The native app can store an Expo push token on the user document when the device registers. The field is empty when unset. Notification preferences exist for ledger and schedule mutes. This marketing site does not send web push and does not register a browser push token.

This marketing site

kymodev.app hosts product information and the legal pages the App Store requires, including this policy at https://kymodev.app/privacy. We do not run a third-party analytics SDK or advertising pixel on this site. Native App Privacy: we collect account data and user content in the app. Tracking is no unless the product later adds analytics.

How long we keep data

Account and group data stay while the account or group exists, unless you delete as described below. We do not run a separate marketing profile on this website.

How to delete your account

In the iPhone app, open Settings and choose Delete account. That deletes the Firebase Auth user, profile, avatar, memberships, and personal schedule hours.

If you are the last member or the sole Admin, the group is removed with you. If the group continues with other members, shared receipts, vault saves, and trip plans stay as group history. Rankings rows keyed by an old user id may remain as historical scores. Personal hours leave. We do not claim that every receipt you ever split is erased from groups that keep going.

If you cannot open the app, write support@kymodev.app and we will help you complete deletion. Copy the address if your mail app does not open.

User content and safety

Vault can hold member-pasted links and JPEGs. Members can report content. Hide is device-local. An Admin can remove content from the group or kick a member. Users agree to the Terms of Service at sign-up.

Children

KyMo is not directed at children under 13, or under 16 where that higher age is required. The age rating reflects user-generated photos and links.

Processors

We use Google Firebase and Google Cloud for Authentication, Firestore, Cloud Storage, and Cloud Functions (including Open Graph fetches and account deletion).

Selling and sharing

We do not sell personal information. We do not run a “do not sell” browser tool on this site because we are not selling data through it. If you want a copy or a deletion, use in-app Delete account or write support@kymodev.app. Where GDPR or similar laws apply, that contact is how you exercise access and erasure. We have not appointed a separate public DPO or EU representative.

Changes

If this policy changes in a material way, we will update the date above and post the new text at this URL. Keep using the app after a change means you have read the current policy.

Contact

support@kymodev.app