arrow_back

Privacy Policy

28 August 2026

1. Controller and contact

The data controller is Vojtěch Jaroš, OSVČ, IČO 01535013, Rybalkova 375/59, 101 00 Praha, e-mail: techvo@gmail.com — a self-employed individual (OSVČ) registered in Prague, Czech Republic; “IČO” is the Czech company identification number. Please direct all privacy requests and complaints to this e-mail address; it also serves as the contact point (grievance officer) for users from countries where this is legally required.

This Policy is provided in Czech, German, English, Ukrainian and Russian. The Czech version prevails; the other language versions are informative translations.

2. Data we process

Account and profile: e-mail address, display name, password (stored only in secured form), an optional profile photo (avatar) and the contact e-mail address you optionally choose to display on your profile.

Age: date of birth entered at registration to verify the age limit (18+).

Content: posts (requests, events and information pins) you create, accept or join, including their location, description and photos; chat messages and direct messages; ratings you give and receive; reactions and comments; notifications.

Relationships and communities: your friends list, community memberships and roles, invitations, and the list of users you have blocked.

Reports: the content of reports you submit and records of how they were handled.

Approximate location: the last map view you saw (center and zoom), so we can reopen the map where you left off. We do not store your device's precise location.

Notifications and devices: if you enable notifications, we store your device or browser identifier used to deliver them (push token) and the list of devices registered for notifications.

Consent records: version of accepted documents and timestamp.

Technical data necessary for operation: a sign-in session (a session cookie in the web application, a securely stored sign-in token in the mobile app) and your saved language preference. We use no analytics or marketing tools.

Operational logs: accessing the service creates short-lived technical records (IP address, time and target of the request) on our servers and those of our hosting providers, used for security and troubleshooting; they are automatically deleted after a short time.

3. Location

Karuno is a map service — a post's location is its essence. You provide it yourself and it is visible on the map to users according to the visibility you choose for the post (public, friends only, or members of a community only). Consider which place you enter; it does not have to be your home address.

We do not process or store your device's precise location. The “my location” button uses it only temporarily on your device to center the map. We store only the last map view (approximate location, see section 2).

4. Purpose and legal basis

We process data to provide the Karuno service (Art. 6(1)(b) GDPR — performance of contract), to comply with legal obligations including age verification and protection of minors (point (c)) and for our legitimate interests, in particular security and abuse prevention (point (f)).

Optional features — push notifications and the public display of your contact e-mail address on your profile — are based on your consent (Art. 6(1)(a) GDPR). You may withdraw consent at any time in the settings; this does not affect the lawfulness of prior processing.

Providing your data is voluntary. However, without the data required at registration (e-mail address, display name, password, date of birth) we cannot provide the service; you provide other data only if you use the respective feature.

We do not carry out automated decision-making or profiling within the meaning of Art. 22 GDPR.

5. Recipients, processors and international transfers

Data is stored with Supabase (database, file storage, authentication) in the European Union region. The web application runs on Vercel; the API and the mobile app backend run on our own server in Germany (Hetzner). E-mail notifications are delivered by Resend. Data processing agreements are in place with these providers.

Push notifications to the mobile app are delivered by Google (Firebase Cloud Messaging) on Android devices and Apple (Apple Push Notification service) on iOS devices; browser notifications are delivered by your browser's push service. We pass them your device push token and the notification content — for a chat message this is the sender's name and the beginning of the message (at most 80 characters). You can turn notifications off at any time; then nothing is passed on.

Base map tiles are provided by OpenFreeMap. Tiles are loaded directly from its servers, which therefore see your device's IP address and the coordinates of the map view. We do not pass on any account data.

Google (Firebase Cloud Messaging), Apple (Apple Push Notification service), Vercel and Resend may process data outside the European Economic Area, in particular in the USA. Transfers are safeguarded by a European Commission adequacy decision (the EU–U.S. Data Privacy Framework) where the provider is certified, and otherwise by the EU Standard Contractual Clauses (SCC) or another instrument under Chapter V GDPR; you can obtain information about these safeguards, including a copy where applicable, via the e-mail in section 1.

We never sell your data, share it for marketing purposes, or use it for targeted advertising.

6. Retention

We keep your data for as long as your account exists. Completed post history is automatically deleted 3 years after completion. Chat messages attached to a post are deleted at most 12 months after the post is closed; direct messages outside posts are kept until one of the participants deletes their account. After account deletion your data is erased as described in section 7; data we must retain under legal obligations, or need to establish, exercise or defend legal claims, is kept only for the necessary period.

7. Your rights

You have the right of access, rectification, erasure, restriction of processing, data portability and objection. Directly in your profile you can: edit your name, export your data (JSON) and delete your account. The export includes your profile, consents, posts including history, events and participations, communities and memberships, friendships, blocks, ratings given and received, reactions, messages, reports, photos, notifications and registered devices; it does not include access credentials (push tokens and keys), and other users appear in it only by their identifier.

You can delete your account in your profile; the steps and an e-mail alternative are described on the Delete account page (/delete-account). Deleting your account cascade-deletes your profile, sign-in data, photos, messages, notifications and other records tied to your account; content other users interacted with (for example completed posts or messages in group conversations) remains in anonymised form with no link to you.

You may lodge a complaint with the Czech Data Protection Authority (Úřad pro ochranu osobních údajů, uoou.gov.cz). If you are outside the Czech Republic, you may also contact your local supervisory authority.

8. Age limit

The service is intended exclusively for persons aged 18 or over. You provide your date of birth at registration; we do not allow younger persons to register. If we learn that an account belongs to a person under 18, we will delete it.

9. International users

Karuno applies the GDPR standard of data protection to all users regardless of country. In addition, you have the rights granted by the law of your country of residence; you can exercise them via the e-mail in section 1.

If you are in Israel, you have in particular the rights of access and rectification under the Israeli Privacy Protection Law, 5741-1981; you may also lodge a complaint with the Israeli Privacy Protection Authority.

If you use Karuno from Ukraine, your personal data is transferred outside Ukraine and processed in the European Union (and, in the cases described in section 5, outside it) with the GDPR standard of protection; you may also contact the Ukrainian Parliament Commissioner for Human Rights with a complaint.

10. Changes to this Policy

We may update this Policy. We will announce a material change (in particular a new data category, a new purpose, a new recipient or a longer retention period) at least 30 days before it takes effect by a notice in the app and on the website; from the effective date the app will ask you to confirm the new version. If you do not agree with the new version, you may delete your account before the effective date without any penalty.

Minor changes (correcting typos, clarifying wording, replacing a subprocessor with an equivalent level of protection, changes required by law) take effect upon announcement.

Each version of this Policy states its issue date and effective date; previous versions are available on request at the e-mail in section 1.