What we hold.
To operate Kythen, we hold the following:
Account information
- Your email address, received from your Apple or Google account when you sign in, used for transactional communications. Not used for authentication directly; Apple and Google handle authentication. Not shared with third parties for marketing.
- The display name you chose. This is visible to other users.
- Your age, stored as a whole number, not a date of birth.
- Photos you added to your profile, stored until you remove them or delete your account.
- Profile content you created, such as your bio and other profile details.
- A user identifier assigned to your account. Used internally to associate your data; not visible to other users in raw form.
- Authentication records and session tokens required to keep you signed in. Kythen uses Apple Sign-In and Google Sign-In for account creation. We do not collect or store account passwords.
- A verified / not verified pointer. The actual identity verification documents are held by our verification provider, not by Kythen (see third parties below).
Activity and events
- Your active sessions at verified venues while you are there. This data is session-scoped; detailed records purge on a short schedule.
- The Wi-Fi network name your device is connected to, and the IP address of the network, used only at check-in to verify your presence at a venue. On iOS and Android, reading the Wi-Fi network name requires a location permission from the operating system; your GPS coordinates are not collected or transmitted to Kythen. The Wi-Fi network name is not stored as visit history. Your IP address may be retained in security and compliance audit logs per Kythen's data retention policy.
- Events you attended, stored as event metadata plus your attendance record.
- Connections you made with other users, while the connection is active.
- Messages you exchanged with your connections, stored under the retention schedule below.
- Product interaction data: which features you used, how often, in aggregate. Used to understand platform usage, not to build a behavioral profile of you individually.
Product operation data
- Moderation reports you filed or that were filed about you.
- Audit logs of platform operations (your logins, account changes, administrative actions we took on your account). These support security and legal obligations.
- Subscription and payment records, if you have a paid account. The actual payment details are with our payment provider.
- Basic device and connection information required to operate the app, such as device type and IP address, retained briefly for security and service reliability.
Diagnostic data
- Crash data: information about app crashes, collected via our error tracking tool (Sentry). Personal identifiers are stripped before this data leaves your device. Crash reports are not linked to your user identity in our systems.
- Performance data: response times and error rates, collected at the system level. Not linked to individual users.
- Other diagnostic data: device type, operating system version, and app version, used to reproduce and fix technical issues.