Kurozu

Privacy Policy

Effective date: June 29, 2026
Last updated: July 9, 2026

This Privacy Policy describes how kurozu ("we," "us," or "our") collects, uses, and shares information when you use the kurozu mobile application for iOS (the "App").

By using the App, creating a cloud account, or using cloud-connected features, you acknowledge this Policy. The App is local-first: you can build and use timelines on your device without signing in.

Contact: support@kurozu.app


1. Summary


2. Scope

This Policy applies to the iOS App. It does not cover third-party websites, AI tools, or apps you paste exported text into, or services we do not operate.

The App may be distributed under a display name configured at build time (for example, "Timeline" or "kurozu"). References to "the App" mean the kurozu iOS application regardless of icon label.


3. Information you provide

3.1 Timeline and fact content

You may create timelines and facts, including titles, descriptions, tags, time expressions, and fact-type labels.

Mode Where it is stored Transmitted to us
Local-only On your device (SQLite) No, unless you use cloud features or copy/export it elsewhere
Cloud-synced On your device (cache) and our servers Yes — when you create, edit, sync, or delete cloud timelines

You choose what to enter. Content may include health-related or other sensitive information if you type it.

3.2 Account and authentication

Cloud accounts use Google Sign-In or Sign in with Apple. If you sign in, we process:

Sign in with Apple may provide a private relay email address. That address may represent a separate cloud account from the same person using Google Sign-In.

3.3 AI features

The initial iOS release does not enable in-app cloud AI features such as AI Add. Coming-soon labels or disabled AI controls in the App do not send your timeline content, prompts, or Apple Health data to an AI provider.

If we enable in-app cloud AI features in a future release, we will update this Policy before collecting or sharing data for those features.

3.4 Export

Export to AI builds plain text on your device and copies it to your clipboard. We do not receive export payloads on our servers.

If you choose to include selected Apple Health summaries in an export, the App shows an inline notice near that choice before copying. Once you paste exported text into another app, website, AI service, or message, that third party's terms and privacy practices apply.

3.5 Support and feedback

If you email us, we receive whatever you include in your message.


4. Information collected automatically

4.1 Crash and error reporting

We use Firebase Crashlytics to collect crash reports and technical errors, such as:

We configure crash reporting not to include timeline content, fact text, authentication tokens, email addresses, or Apple Health data in crash reports.

4.2 Product analytics

We use Google Firebase Analytics to understand how the App is used. Events may include, for example:

We do not send timeline titles, fact descriptions, health data, or email addresses to Firebase Analytics.

Firebase Analytics may collect standard device and app identifiers as described in Google's privacy documentation. We do not use the App for cross-app advertising or sell analytics data.

4.3 Network and session data

When you use cloud features, our API receives:

We do not intentionally log full timeline descriptions, export payloads, or complete AI prompts in server logs.

4.4 Local device data (not transmitted)

The App stores on your device:

We use connectivity checks locally to show online/offline state. We do not transmit a history of your network status.


5. Apple Health (preview feature)

On supported iPhones, the App includes a preview panel that can read Apple Health data only after you grant HealthKit permission. The App may request access to:

This feature is not a medical device and is not intended to diagnose or treat any condition.


6. How we use information

We use information to:

We do not use your timeline content to train machine-learning models.


7. How we share information

We share information only as follows:

Recipient Purpose Data shared
Supabase Authentication Email, OAuth tokens/IDs, session data
Google Sign in with Google OAuth profile data, such as email, name, profile image, and provider identifiers
Apple Sign in with Apple; HealthKit (on device) OAuth data via Apple; health metrics stay on device unless you type them elsewhere or include selected summaries in a user-directed export
Our hosting provider Cloud API and database Cloud timelines, facts, account metadata
Firebase Crashlytics Crash reporting Technical diagnostics (no timeline content)
Google (Firebase) Product analytics Event names and non-content properties

We may disclose information if required by law or to protect safety, rights, or property.

We do not sell personal information.

Third-party providers are expected to protect user data consistently with this Policy and applicable App Store requirements.


8. Data retention

Data Retention
Local-only timelines On your device until you delete them or uninstall the App
Cloud timelines and facts Until you delete them, delete your account, or we terminate the service; limited backups and operational logs may persist for a short period where necessary
Account record Until you request account deletion, subject to limited records we must keep for legal, security, or operational reasons
Firebase Crashlytics / Analytics Per Firebase retention settings; we configure minimal retention where possible

9. Account deletion

You can delete your cloud account from Settings in the App.

When you confirm deletion:

  1. We delete your cloud timelines, facts, and related server data from active systems.
  2. We delete or disable your Supabase authentication user as part of that process.
  3. The App purges cached cloud data on your device and signs you out.

Local-only timelines on your device are not deleted by account deletion. To remove local data, delete those timelines in the App or uninstall the App.

Sign-out removes cloud data from your device cache but does not delete server-side cloud data.

If deletion fails due to a technical error, contact us at support@kurozu.app.

Some copies may remain temporarily in backups, provider logs, or fraud/security records where necessary, and are handled according to our retention settings and legal obligations.


10. Security

We use industry-standard measures including HTTPS for API traffic, authenticated access to cloud data, and separation of local and cloud account namespaces on device.

No method of transmission or storage is completely secure. You are responsible for securing access to your device.


11. Children

The App is not directed to children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. Contact us if you believe a child has provided us information.


12. International transfers

We and our service providers may process information in countries other than where you live. Those countries may have different data-protection laws. Where required, we rely on applicable safeguards, such as adequacy decisions, standard contractual clauses, provider data-processing terms, or other lawful transfer mechanisms.


13. Your choices and rights

Depending on where you live, you may have rights to access, correct, delete, or port personal information, or to object to or restrict certain processing.

To exercise rights or ask questions, contact support@kurozu.app.


14. Changes to this Policy

We may update this Policy. We will post the revised version at this URL and update the effective date. Material changes may be communicated in the App or by email where appropriate. Continued use after changes take effect constitutes acknowledgment.


15. Contact

kurozu
Email: support@kurozu.app

For App Store privacy nutrition labels, our practices should match the disclosures in this Policy. Third-party SDKs, including Firebase, may publish their own privacy manifests bundled with the App.