Privacy Policy

This describes exactly what Kleos collects, why, and how you can delete it - written to match what the app actually does, not a generic template.

Account and profile data

When you sign up, we collect your email and password (handled by our authentication provider, Supabase Auth - we never see or store your password in plain text). During profile setup and afterward, you provide a username, display name, and optional bio, avatar photo, and cover photo. All of this is visible to other signed-in Kleos users - that visibility is the point of a social profile - and you can edit or remove any of it at any time from Edit Profile.

Achievement completions and posts

Completing an achievement requires a photo as proof, which becomes a post visible in the feed and on your profile. Posts can include an optional caption and an optional free-text location name you type yourself (e.g. "Galata Tower") - we do not collect GPS coordinates or use any location or mapping service.

Likes, comments, and follows

Liking a post, commenting, and following another user are all visible actions tied to your account - they power the counts and lists shown throughout the app (follower/following counts, like counts, comment threads). You can delete your own comments and posts at any time, and unfollow whenever you'd like.

Reports and blocks

If you report a post, comment, or user, we record who reported what and why, so it can be reviewed - this record is visible only to you and the Kleos team, never to the person you reported. Blocking another user is a private action: only you can see who you've blocked, and blocking automatically removes any existing follow between you and prevents future interaction.

Notifications

We store a record when someone follows you, likes your post, or comments on it, so we can show you an in-app notification list and, if you enable it, a real push notification.

Push notification tokens and device information

If you turn on push notifications, we store a device push token (an identifier issued by Apple or Google, via Expo's push service - not your device's advertising ID or any hardware identifier), along with which platform it's for (iOS or Android) and when it was last used. This exists solely to deliver the three notification types above to your device, and is deleted automatically if you turn notifications off, sign out, or delete your account.

Analytics and third-party services

Kleos does not use any third-party analytics, advertising, or crash-reporting SDK. The only external services involved in running the app are Supabase (our database, authentication, and file storage provider) and Expo's push notification relay (which forwards a notification's title/body/navigation data to Apple/Google on our behalf - it does not see your account data beyond what's needed to deliver that one message). If that ever changes, this section will be updated before it happens, not after.

Storage and security

All data is stored with Supabase, using industry-standard database and file-storage security. Access is restricted by row-level security rules tied to your own account - enforced by the database itself, not just app-side checks - so another user's client can never read or write data that isn't theirs to touch.

Account deletion

You can permanently delete your account at any time from Settings → Delete Account inside the app. This removes your profile, posts, comments, likes, follows, notifications, push tokens, reports you've filed, and uploaded photos (avatar, cover, and completion photos). It is permanent and cannot be undone. See our Account Deletion page for the exact steps and what to do if you can't access the app.

Data retention

We keep your data for as long as your account exists. Deleting your account removes it immediately, with one narrow exception: a photo file that failed to be cleaned up due to a transient storage error may briefly remain orphaned in storage with no account attached to it - this is a known, low-risk edge case, not a deliberate retention policy, and such files are never associated with your identity once your account is gone.

Contact us

For any privacy questions, data requests, or concerns, email supportkleos@gmail.com.