Privacy Policy

Last updated: September 10, 2026
Effective date: September 10, 2026

This Privacy Policy explains how Korka (“we”, “our”, “the app”) handles information when you use the Korka iOS application and related services at korka.app. The Korka service is provided “AS IS”.

We built Korka with privacy as a default. We do not sell your data. We do not run ads. We do not track you across other apps. We do not send marketing emails. Your saved places are yours.

1. Who we are

Korka is operated by Astrid as a sole proprietor based in Sweden. For all matters relating to this Privacy Policy, including data access requests, corrections, deletions, or questions, you can reach us at:

Email: hello@korka.app

We are the data controller for personal information processed through Korka.

2. Age requirement

Korka is intended for users aged 16 and over. We do not knowingly collect information from anyone under 16. If you are under 16, please do not use Korka or provide any information to us. If we learn that we have collected information from a person under 16, we will delete it.

3. Information we collect

3.1 Information you provide directly

Account information. When you create an account, we collect your email address (if you sign up with email) or the identifier provided by Apple (if you use Sign in with Apple). Sign in with Apple lets you use a private relay email if you prefer.

Your first name. If you sign up with email, you can give us your first name. If you use Sign in with Apple, Apple may share your name with us the first time you sign in, if you choose to. We use your first name to greet you in the app, and to show who sent a collection or city when you share it with someone (see “Shared codes” below).

Content you save. When you share a social media post with Korka, or paste a URL into the app, we receive the URL of that post. We then process the public content of the post (see Section 4) to identify the venue and save a reference to that venue on your personal map. The saved reference includes the venue’s name, address, city, coordinates, and a link back to the original post. You can delete any saved venue at any time from within the app.

Text you paste. If you paste text into Korka to import places from it (for example, a list of restaurants from your notes), we send that text to our AI processing partner to find the venue names in it. We save the venues found, not the text itself.

Collections and notes. If you organize venues into collections, we store the collection name and the venues it contains. If you add status markers (“To try” / “Been”) or ratings to venues you’ve visited, we store those.

Shared codes. If you share a collection or city with another Korka user via a share code, we store the code and the association between the code and the content being shared, so the recipient can redeem it. When someone opens your share, the app shows them your first name (or “A friend” if we don’t have one) together with the shared content. We never show them your email address.

3.2 Information collected automatically

Usage data. When you use the app, we collect analytics events (for example: “spot saved”, “map viewed”, “paywall shown”). These events help us understand which features are used and where users drop off. Events are linked to a random account ID, together with your sign-up date and whether you have premium, but not to your name or email. Our analytics provider also receives your IP address, which it uses to estimate your approximate location (city and country). Analytics data is stored in the EU.

This data is pseudonymous rather than anonymous: it doesn’t contain your name or email, but because it uses the same random ID as your account, we could connect it to your account if we looked it up. We use it only in aggregate to improve the app.

Crash data. If the app crashes or encounters an error, technical information about the device state at that moment is sent to our error reporting service. Crash reports from the app are not linked to your account and do not include your saved content. In the rare case that a server error concerns your account specifically (for example, a purchase that failed to activate premium), the error report may include your account ID or email so we can fix the problem.

Push notifications. If you allow notifications, we store a push token for your device so we can notify you, for example when an import finishes in the background. The token is deleted when you delete your account, and you can turn notifications off at any time in iOS Settings.

Device information. Standard information about your device (model, operating system version, app version) is collected for compatibility and debugging.

3.3 Location information

While you use the app. With your permission, Korka uses your location to:

Proximity alerts (optional). If you turn on a proximity alert for a saved spot, iOS notifies Korka when you come within about 150 metres of that spot, even when the app is closed. This needs the “Always” location permission, which we only ask for when you turn on your first alert. You can have alerts on up to 20 spots. The locations of those spots are stored on your device, iOS does the checking on your device, and the notification is created on your device.

In both cases, your location stays on your device. We never send it to our servers and we don’t keep a location history. You can turn off individual alerts in the app, or change or revoke location permission at any time in iOS Settings.

4. How we use your information

We use the information described above to:

We do not use your data for advertising. We do not sell your data to anyone.

5. Third-party services we use

Korka relies on a set of third-party service providers to function. Each receives only the data needed for its specific role. We describe each category below; where we name a specific provider, it is because they are a visible part of the user experience.

CategoryPurposeWhat data it receives
Apple (Sign in with Apple, App Store)Authentication and payment processingApple ID identifier, your name and email if you choose to share them, purchase receipts
Cloud database, servers and hostingStores your account, saved venues, collections, and ratings; runs the import serviceEmail address, first name, account identifier, saved content, preferences
AI processing partnerIdentifies venues from the posts you share and from text you paste into the app; generates trip-planning suggestions and community-note summariesThe public content of posts you share, text you paste into the notes import, and the venues you select for trip planning. We do not send your name, email, or account ID
Content retrieval partnerRetrieves the public content of the posts you shareThe URL of the post you chose to share
Google Places APIEnriches venue data (address, photos, rating, opening hours)The venue name and city being looked up
Google Maps SDKRenders the map inside the appStandard map tile requests (Google receives IP address and approximate location for tile rendering, per Google's own policies)
Push notification serviceDelivers notifications, for example when an import finishes in the backgroundYour device's push token and the text of the notification
Payment platformManages the one-time premium unlockYour account ID and Apple purchase receipt
Product analyticsHelps us understand which features are usedUsage events, a random account ID, sign-up date and plan, device and app version, and your IP address (used to estimate your city and country). Stored in the EU. No name, no email, no advertising identifier
Crash and error reportingHelps us identify and fix bugsTechnical error information and device state at the time of the error (no saved content). Not linked to your account, except for server errors that concern your account specifically (see Section 3.2)

We do not share your data with any third party outside these service providers. None of these providers are authorized to use your data for purposes beyond providing their service to Korka. If you need the identity of a specific provider for a regulatory request (for example, a data subject access request under GDPR), email hello@korka.app and we will provide it.

6. Legal basis for processing (GDPR)

If you are in the European Economic Area or the United Kingdom, we process your personal data under the following legal bases:

7. Data retention

We keep your data for as long as your account exists. If you delete your account from within the app, we permanently delete:

Proximity alerts on your device are switched off. Our internal records of which venues an import found are kept to monitor quality, but they are disconnected from your account.

Analytics events linked to your random account ID may remain with our analytics provider after you delete your account. Once your account is deleted, that ID is no longer connected to your email or anything else we hold. If you want those events deleted as well, email hello@korka.app and we will do it. Crash reports are kept by our error reporting provider for a limited period and then deleted automatically.

Backup systems may retain residual copies of data for up to 30 days after deletion as part of standard operational recovery procedures. After 30 days, the data is fully gone.

8. Your rights

8.1 Everyone

You can:

8.2 If you are in the EEA, UK, or Switzerland (GDPR rights)

In addition to the above, you have the right to:

To exercise any of these rights, email hello@korka.app. We will respond within 30 days.

8.3 If you are in California (CCPA / CPRA)

California residents have the right to know what personal information we collect, to delete it, and to not be discriminated against for exercising these rights. We do not sell personal information. To exercise your rights, email hello@korka.app.

9. International data transfers

Korka is operated from Sweden, but the third-party services we rely on may process data in other countries, including the United States. Our analytics data is stored in the EU. When personal data is transferred outside the EEA, we rely on the safeguards that each service provider has in place, such as Standard Contractual Clauses approved by the European Commission.

10. Security

We take reasonable technical and organizational measures to protect your data:

No system is perfectly secure. If we become aware of a security breach that affects your personal data, we will notify you without undue delay, as required by law.

11. Children’s privacy

As stated in Section 2, Korka is not intended for anyone under 16. We do not knowingly collect information from anyone under 16.

If you are a parent or guardian and you believe your child has provided information to us, please contact us at hello@korka.app and we will delete the information promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will change the “Last updated” date at the top and, for significant changes, notify you inside the app or by email before they take effect.

13. Opting out and withdrawing consent

You can withdraw your consent or stop the processing of your data in several ways:

Uninstalling the app does not automatically delete your account data from our servers. To delete your account data, use the Delete Account flow inside the app or email us.

14. Contact

For any question about this Privacy Policy, or to exercise any of your rights:

Email: hello@korka.app