Nekuvo · iPhone · Private beta
Nekuvo app privacy
This page explains the information used by the current Nekuvo private beta and the choices available to you.
Controller
Nekuvo is published by Jonathan Benay, a French sole trader operating as Hangeul Studio, SIREN 993 713 460, 61 rue de Lyon, 75012 Paris, France.
General questions: support@nekuvo.com
Privacy questions: privacy@nekuvo.com
Information used
- Account and profile: technical Sign in with Apple identity, internal ID, username, chosen name, kitten, preferences and account state.
- Conversations: participants, sent text, expressions, scenes and snapshots needed for the mini-comic, timestamps, Sent, Delivered and Read receipts, replies and reactions.
- Connections and safety: invitations and contact requests, blocks, evidence you choose to report, related decisions and appeals.
- Device and service: session, random installation ID per account and environment, generic device model, iOS/app versions, last technical activity, notification token and preference.
- 13+ access: the design provides for an age range, territory policy and, where required, limited parental evidence. No provider or public territory is active yet.
- Support: your email address and the information you choose to provide when contacting us.
Depending on how Sign in with Apple works for your account, Apple may provide a real or relay email address to the authentication service. We are still confirming which fields are retained before public launch.
The current app does not upload your address book, location, message photos or voice recordings to Nekuvo.
Dictation, exports and kittens
Dictation is optional. Nekuvo only accepts it when speech recognition runs on the device: the app does not record that audio or send it to Nekuvo or Runway. Text becomes a message only when you send it.
Comic images are created locally. They leave the app only when you choose to share them; the receiving app then applies its own rules. Kitten packs contain artistic assets and no conversations. Downloading them requires authorized access. Downloading them may generate technical network data at the hosting provider.
Purposes and recipients
We use this information to authenticate your account, deliver and display conversations, synchronize devices and receipts, apply settings, distribute kittens, prevent abuse, handle reports and respond to your requests. Precise lawful bases will be approved per purpose and territory before public launch.
Your correspondent sees information needed for your exchange. Supabase provides authentication, database, realtime and artistic asset storage. Apple provides Sign in with Apple, APNs and TestFlight/App Store distribution. Cloudflare routes Nekuvo email; Google hosts the Hangeul Studio mailbox. Runway is used only to create artistic assets in the studio: your conversations are not sent to it.
The Supabase development project is located in eu-west-1. That region does not establish that all logs, functions, support access and subprocessors remain in the European Union. Contracts and transfer safeguards for the future production environment still require approval.
Protection and current limits
TLS protects data in transit, tokens are stored in the iOS Keychain, and server access rules restrict each conversation’s data. The current beta does not provide end-to-end encryption. The backend can therefore technically read message content. Nekuvo will only be described as end-to-end encrypted after complete implementation and verification.
No advertising or marketing analytics SDK is active, and we do not use conversations to train AI. Hangeul Studio personnel must only access data when an operational purpose requires it.
Your settings
Notifications are generic and say “New message.” without a text preview. Both iOS authorization and the in-app preference control them. Read receipts are off by default for minors. You can block or unblock someone and report an accessible message. Nekuvo does not show a public last-seen status.
Retention and deletion
Messages currently have no automatic expiry. They remain linked to the account until they are deleted under the service’s rules. Evidence selected for a report normally expires after 30 days; Apple revocation events after 40 days; push requests after 24 hours and their terminal states after 7 days. Moderation metadata and audits are designed for longer retention. These technical periods and actual purge operation will be reviewed before public launch.
Support correspondence is deleted no later than 90 days after closure, unless a legal duty or dispute justifies limited retention. Production periods for other logs, inactive accounts and backups are not yet finalized.
You can request deletion under Profile → Privacy → Delete my account. Access closes, then that account’s profile and messages are erased. The other participant’s messages remain; your identity is removed from retained scenes and the conversation becomes read-only. A server process continues Apple revocation and technical deletion. A copy already exported or held by someone else cannot be recalled remotely. Uninstalling the app does not delete the account.
Your rights
Depending on your circumstances, you may request access, correction, erasure, restriction, objection and portability, and withdraw consent where processing relies on it. A proportionate identity check may protect a request made outside your session. Never send a password, sign-in code or private key.
Email privacy@nekuvo.com or write to the postal address above. You may also contact the CNIL or your competent supervisory authority.