Privacy policy
Last updated:
KOHVRA is designed around minimum collection, private-by-default sharing, and controls that work on the server as well as in the interface. This policy says what we hold, why, and what you can do about it.
What we collect
- Account data: email, display name, self-declared birth date, home country and city.
- Duplicate-account check: the type of identity document you choose (Israeli ID or passport and its issuing country) and a keyed cryptographic fingerprint of its number. The number itself is never stored and cannot be read back from the fingerprint.
- Private-beta review signals: invitation provenance, a required face photo, optional Instagram username, and the administrator decision.
- Trip data: destinations, accommodation area and dates you choose to enter.
- Social data: invitations, friend requests, friendships, blocks, attendance responses and saved content.
- Location coordinates only after you actively share them, together with your selected precision and audience.
- Safety data: reports, moderation decisions and minimal audit records.
- Preferences: your language and accessibility settings, which stay in your browser and are never sent to us.
Verification availability
KOHVRA does not currently use a government-ID, selfie, email one-time-code, phone or SMS verification provider. Birth date is self-declared and is not proof of identity. The identity-document number is checked only for its format and to make sure it has not opened another account; it is not checked against any government register. Private-beta access requires a traceable invitation, a face photo, a birth date showing you are 18 or over, a document not already in use, and explicit administrator approval. The administrator sees your age, not your full birth date. The application does not claim stronger verification than this.
Location data
Location sharing is off by default. You choose exact, street or area precision and an audience of only you, your friends, selected approved members or all approved members. Approximate responses are coarsened on the server. Stale locations are excluded. Stopping sharing deletes the stored location and revokes grants; KOHVRA does not keep a location history.
Place information from Google
Opening hours, photos and ratings for places come from Google Maps Platform. Requests are made by our server, never by your browser, so Google does not receive your identity or device details from KOHVRA. Only the Google place identifier is stored; the rest is held in memory for at most fifteen minutes.
Sharing and blocking
Approved members can see the public profile and trip-presence information exposed by the member features. Friendship does not grant location access by itself; sharing with friends is a separate choice you make. Joining through someone’s invitation makes you friends once your account is approved. A hidden profile is left out of discovery, trip overlaps, search and the map for everyone who is not already a friend. Blocking removes the friendship, pending requests, location grants and related social notifications in both directions, and blocked members are excluded from discovery and social context.
What we do not do
- We do not sell personal data or operate advertising trackers.
- We do not collect scans or photos of passports or identity documents, and we do not store identity-document numbers.
- We do not send precise GPS coordinates to product analytics.
- We do not expose account email or birth date through member search.
Retention and deletion
Account deletion removes profile and location data and the identity-document fingerprint, invalidates sessions, anonymizes the account identifier and retains only minimal safety and audit records where needed. Open reports may be retained for member protection. Profile photos are currently stored as validated, compressed image data in our database for the limited private beta.
Your rights and contact
- Correct profile information in the application.
- Delete the account from your profile.
- Request access, correction, restriction, portability or additional deletion at talm13124@gmail.com.
- Contact the relevant data-protection authority if a concern is not resolved. For residents of Israel this is the Privacy Protection Authority.
Children
The private beta is for adults aged 18 and over. Registration requires a birth date and rejects one below 18, and an administrator reviews each applicant’s photo and age, but no external age-verification provider is currently connected.
Languages
This policy is published in English and Hebrew. Both versions are intended to say the same thing. If a difference in wording ever matters, the English version governs.
Write to talm13124@gmail.com. A person reads every message.
This document is also available in Hebrew.