California Privacy Addendum
Effective Date: April 26, 2026 Last Updated: July 21, 2026
This Addendum supplements the ConKarma Privacy Policy for residents of California, in line with the California Consumer Privacy Act of 2018, as amended by the California Privacy Rights Act ("CCPA/CPRA"). Capitalised terms not defined here have the meaning given in the main Policy.
1. Categories We Collect, Sources, and Purposes
In the past 12 months we have collected the following CCPA categories of personal information:
| CCPA category | Examples | Sources | Business purposes |
|---|---|---|---|
| A — Identifiers | Email, account ID, device ID, IP address | You, your device | Account creation, authentication, fraud prevention, security |
| B — Customer records (Civ. Code 1798.80(e)) | Name, contact details | You | Account, support |
| C — Protected classifications | Birthday (used to compute age tier) | You | Age-gating adult features, COPPA compliance |
| D — Commercial information | In-app purchase records | Apple/Google billing, you | Service delivery, billing reconciliation |
| F — Internet / network activity | App usage events, request logs | Your device | Analytics, debugging, abuse prevention |
| G — Geolocation (coarse) | Country code derived from IP | Your device | Region-specific compliance, fraud detection |
| G — Precise geolocation (opt-in) | Latitude / longitude attached to a specific emergency check-in only when you (or a verified parent on a child's behalf) have turned on Emergency location sharing AND toggle "Share my location with this alert" before sending. We do not collect location in the background. | Your device, at the moment you send a check-in | Letting the rest of your cell know where you are during an emergency check-in. CCPA §1798.140(ae) sensitive-PI; see §3 for limited-use scope. |
| I — Professional / employment | None | — | — |
| J — Education | None | — | — |
| K — Inferences | Engagement signals used to populate suggestions / recommendations | Derived | Service personalisation |
| L — Sensitive personal information | Account credentials (limited use category — see §3); opt-in Health & Fitness data (HealthKit / Google Fit / Health Connect — steps, distance, active minutes, sleep, mindfulness; CMIA-adjacent fitness data, see §3) | You | Authentication only; auto-completing fitness-tagged tasks against the threshold you set |
2. Categories We Disclose for Business Purposes
We disclose the following categories to the categories of recipients shown:
| Category disclosed | Recipients |
|---|---|
| Identifiers, Internet/network activity, Geolocation (coarse) | Backend platform (Supabase, Inc., with AWS as its downstream sub-processor), error monitoring (Firebase Crashlytics — Google LLC), email delivery (a standard SMTP relay service used for transactional email), GeoIP resolution (freeipapi.com, based in Germany — receives only your IP address to return a coarse country / region for security and legal-compliance gating) |
| Identifiers, Commercial information | Apple App Store, Google Play (independent controllers for billing) |
We do not "sell" personal information as defined by the CCPA. We do not "share" personal information for cross-context behavioural advertising. We do not knowingly collect, sell, or share the personal information of consumers under 16 without affirmative authorisation (Civ. Code §1798.120(c)); ads are never served to known child accounts (under 13). For children's data, ConKarma applies purpose-bound, child-specific data minimisation per the canonical COPPA Data Retention Policy.
3. Sensitive Personal Information — Limited Use
Account credentials (passwords, in hashed form) are the only sensitive personal information we collect by default, and we use them only for the limited purposes Civ. Code §1798.121(b) permits without an opt-out: providing the Service you requested, security, and fraud prevention. We do not infer characteristics from sensitive PI.
Precise geolocation (opt-in only). When you turn on Emergency location sharing AND toggle "Share my location with this alert" on a specific emergency check-in, we collect latitude and longitude at that moment and attach it to that check-in. We do not track location in the background, do not infer characteristics from it, and do not use it for advertising. Coordinates are visible only to other members of your cell. Retention horizon: 14 days for California users (shorter than the standard CCPA-acceptable horizon by design); after 14 days the coordinates are deleted while the "safe" / "need help" record itself stays without location. Revoking consent in Settings → Emergency location sharing deletes any coordinates we still hold within minutes.
Health & Fitness data (opt-in only). When you grant Apple HealthKit / Google Fit / Health Connect permission for specific categories (steps, distance, active minutes, sleep, mindfulness), the app reads only those categories' daily totals while in the foreground, performs the threshold check locally on your device, and sends only the resulting boolean ("did the threshold cross today, yes/no") to our servers attached to the relevant mission/duty/experience. Raw health values are never written to our servers. This data falls within the CCPA's sensitive-PI category and, for fitness data sourced from Apple HealthKit, may also be subject to California's Confidentiality of Medical Information Act (CMIA); we treat it under the limited-use scope of Civ. Code §1798.121(b) and apply the same "no advertising / no inference" guardrail as the rest of the SPI in this section. Apple HealthKit's terms of service forbid sharing health data with third parties for advertising or any unrelated commercial purpose, and we honour that across both iOS and Android. Revoking any health permission in your device's system Settings stops the auto-complete flow for that category immediately; we never push a re-prompt without an explicit user action.
4. Retention
We retain each category for as long as needed for the disclosed purposes:
- Account data: while your account is active, plus 30 days for recovery.
- In-app purchase records / financial logs: 7 years (tax, audit).
- Request logs / debugging: 90 days.
- Coarse geolocation: stored as a derived country code on the request log; same 90 days.
5. Your California Rights
You have the right to:
- Know what personal information we have collected, the sources, the purposes, and the categories of recipients.
- Access a copy of the personal information we have about you (Settings → Export my data).
- Delete your personal information (Settings → Delete account).
- Correct inaccurate personal information.
- Opt out of sale/sharing — not applicable, see §2.
- Limit use of sensitive personal information — not applicable, see §3.
- Non-discrimination for exercising your rights.
To exercise rights, email legal@conkarma.app with the subject "California rights request" and include the email associated with your account so we can verify.
6. "Shine the Light" (Civ. Code §1798.83)
California residents may request, once per year, a list of personal information disclosed to third parties for those third parties' direct marketing purposes during the preceding calendar year. We do not disclose personal information to third parties for their direct marketing purposes. Email legal@conkarma.app with the subject "Shine the Light request" to receive a written confirmation.
7. Authorised Agents
You may designate an authorised agent to make a request on your behalf. We will require written authorisation signed by you, and we may require you to verify your identity directly with us before processing.
8. Adult-zone (Ember) — Sensitive PI consent & retention
For California residents, adult-zone (Ember) content is "sensitive personal information" under the CCPA/CPRA (Cal. Civ. Code §1798.140(ae)), as it includes data about a consumer's sex life; where that content is health-derived, it is also protected as "medical information" under California's Confidentiality of Medical Information Act (CMIA, Cal. Civ. Code §56 et seq.). It is processed only on your explicit opt-in, and you may limit the use of this sensitive PI at any time (Settings → Ember privacy).
- Default 3-year retention. Configurable in Settings → Ember privacy from 90 days to 10 years; you control the duration. Hard-deleted on window close.
- Per-device enable. Adult-zone access is OFF by default on every non-primary device; you opt in per device. The audit log of changes is retained alongside the user record for the same period as the account.
- Relationship-data limit. Adult-zone entities are visible only to the cell-mate(s) you explicitly authorised via a trusted-cell relationship; ConKarma operators do not read them outside of two-eye admin emergencies.
- Backup-exclusion toggle (Settings → Ember privacy) keeps the Ember subset out of iCloud / Drive backups when on.
- Export-inclusion toggle lets you opt adult-zone rows into your portability export (default OFF — exports stay sharing-safe).
- Withdrawing consent. If you withdraw your adult-zone consent (off-toggle in Settings → Ember privacy), we hard-delete every adult-zone row attributable to you within 30 days; the relevant rows are also excluded from any pending portability export.
- No automated processing without consent (ADR-120). No automated content model processes Ember content without your explicit consent — AI assistance and moderation of Ember content happen only under that consent, never by default.
- Adult-zone usage analytics (separate opt-in, default OFF). Only if you give the separate adult-analytics consent do we send anonymised, surface-level Ember usage metadata to Google Analytics 4 — which feature was used and a coarse action verb, under a pseudonymous client identifier only, with no PII and no content-level detail (never which specific act, scene, or content). We do not use or disclose this sensitive PI for advertising or to infer characteristics about you; Google Signals, ads-personalisation, and Google data-sharing are OFF for this stream. You may limit the use of, or withdraw, this at any time (Settings → Ember privacy).
9. Governing Law & Non-Waivable Consumer Rights
Nothing in this Addendum or the main Policy limits the non-waivable rights California consumers hold under California law. The arbitration and class-action waiver in the Terms of Service §17 does not apply where California mandatory consumer-protection law would render it unenforceable, and the Limitation of Liability in the Terms of Service §15 is subject to its own statutory carve-outs.
10. Changes
We will update the Last Updated date above when we change this Addendum and publish material changes via in-app notice.