What we hold.
To operate Kythen, we hold the following:
Account information
- Your email address, used for authentication and transactional email. Not shared with third parties for marketing.
- The display name you chose. This is visible to other users.
- Your age, stored as a whole number, not a date of birth.
- Photos you added to your profile, stored until you remove them or delete your account.
- Profile content you created, such as your bio and other profile details.
- A user identifier assigned to your account. Used internally to associate your data; not visible to other users in raw form.
- Authentication records and session tokens required to keep you signed in. Kythen uses Apple Sign-In and Google Sign-In for account creation. We do not collect or store account passwords.
- A verified / not verified pointer. The actual identity verification documents are held by our verification provider, not by Kythen (see third parties below).
Activity and events
- Your active sessions at verified venues while you are there. This data is session-scoped; detailed records purge on a short schedule.
- Precise location, used only while you are actively using the app to verify your presence at a venue. Not collected in the background. Not stored beyond the session window.
- Events you attended, stored as event metadata plus your attendance record.
- Connections you made with other users, while the connection is active.
- Messages you exchanged with your connections, stored under the retention schedule below.
- Product interaction data: which features you used, how often, in aggregate. Used to understand platform usage, not to build a behavioral profile of you individually.
Product operation data
- Moderation reports you filed or that were filed about you.
- Audit logs of platform operations (your logins, account changes, administrative actions we took on your account). These support security and legal obligations.
- Subscription and payment records, if you have a paid account. The actual payment details are with our payment provider.
- Basic device and connection information required to operate the app, such as device type and IP address, retained briefly for security and service reliability.
Diagnostic data
- Crash data: information about app crashes, collected via our error tracking tool (Sentry). Personal identifiers are stripped before this data leaves your device. Crash reports are not linked to your user identity in our systems.
- Performance data: response times and error rates, collected at the system level. Not linked to individual users.
- Other diagnostic data: device type, operating system version, and app version, used to reproduce and fix technical issues.