Draft — not yet in effect. This policy is under legal review.

Privacy Policy

Effective Date: [DATE] Last Updated: [DATE]

This Privacy Policy explains how NuKowd LLC ("Company," "we," "us," or "our") collects, uses, stores, discloses, and protects personal information when you use Kolekwi, including our websites, desktop applications, mobile applications, communication services, and related products and services (collectively, the "Service").

Kolekwi provides communications and collaboration features that may include direct messaging, group messaging, voice and video communications, file sharing, presence information, contacts, and organization-managed workspaces.

This Privacy Policy applies to personal accounts and, where applicable, accounts provided or managed by an organization.

QUESTION FOR LEGAL REVIEW: This Policy describes features that are not built and collect no data today. Derived from the codebase 2026-09-16: voice and video communications, call recording, channel-style conversations, telephone numbers, payments and subscriptions, push notifications, crash reports and diagnostics, error monitoring, analytics, cookies beyond the sign-in session, and organization-managed accounts and administrators — none of these exists in any form. Should each be removed until it ships, kept as a forward-looking description, or reworded to say it is not yet offered? This affects Sections 1, 2, 3, 8, 13 and 16.

1. Personal Accounts and Organization-Managed Accounts

How we handle information may depend on the type of account you use.

Personal Accounts

If you create and control your own account, NuKowd LLC generally determines how personal information associated with that account is processed and acts as the controller or business responsible for that information.

Organization-Managed Accounts

If you use the Service through an employer, business, school, or other organization ("Organization"), that Organization may control your account and the communications, files, records, and other information contained within its workspace.

For Organization-managed accounts, the Organization may determine matters such as:

In these circumstances, the Organization may be the controller of workspace content and NuKowd LLC may process that information on the Organization's behalf.

We may separately act as a controller for information we process for our own legitimate business purposes, such as account security, billing, fraud prevention, and operation of the Service.

If you have questions concerning information controlled by your Organization, you should contact your Organization's administrator.

QUESTION FOR LEGAL REVIEW: Organization-managed accounts and administrators do not exist at launch. There is no organization, workspace, administrator, or admin access of any kind in the product (derived 2026-09-16: no such code). Every account is a personal account. Should this Section be removed, held back until the feature ships, or kept with a statement that it applies only once Organization accounts are offered?

2. Information We Collect

Depending on how you use the Service, we may collect the following categories of information.

Account Information

This may include:

Passwords are stored using security measures designed to prevent us from retrieving the original password.

Communications and Content

We process information that you send, receive, upload, or otherwise provide through the Service, which may include:

Messages may contain personal information about the sender, recipient, or other individuals.

DRAFT FOR LEGAL REVIEW: Message content is end-to-end encrypted. Message bodies in direct and group conversations, message edits, the contents of attached files, an attachment's original file name, image thumbnails, and first messages sent before a contact request is accepted are encrypted on the sending device. They can be read only by the devices of the people in that conversation — which includes your own other devices, since a message you send is delivered to them as well — and by a device you later restore from your own encrypted backup. The keys that encrypt and decrypt messages are created on those devices and are never held by us in a form we can read, so we cannot read message content as it travels to those devices or as it is stored on our servers. We do hold one other kind of key: a key for each of your devices that encrypts that device's own stored copy of your messages (see Section 5), which we provide only to that device, and only while you are signed in on it. That key decrypts nothing by itself. It is useful only together with the files that device stores, which stay on the device and are not sent to us. For us to read your messages, we would need both that key and a copy of that device's stored files, which would require access to the device itself.

Some information is necessarily not encrypted, because we need it to operate the Service. This includes: your profile information, including your display name, username, and profile photograph; your contacts and the accounts you have blocked; which accounts are in which conversation; group names and records of group changes such as a rename or a member joining or leaving; the date and time each message was sent, edited, or deleted; read receipts and how far each participant has read; emoji reactions and who applied them; an attached file's type and size; and your registered devices and their names. Our hosting and infrastructure providers also receive network information such as IP addresses and request logs.

Voice and Video Communications

When you participate in a voice or video communication, we process information necessary to establish, route, maintain, and secure the communication.

If a call or meeting is recorded, participants will be informed as required by applicable law, and the resulting recording will be retained according to the applicable user or Organization retention settings.

Contacts and Invitations

If you invite another person to use the Service or provide access to contacts, we may process information necessary to send the invitation or provide the requested contact functionality.

DRAFT FOR LEGAL REVIEW (L12; drafted 2026-10-01 from L11 Phase 4, not yet reviewed): An account can be created only by accepting an invitation from someone who already uses the Service. There is no public sign-up. When you invite someone, we store the email address you enter alongside your invitation and send that address one invitation email. The email contains your display name, the name of the Service, and a link to join. The link carries a single-use code that is valid for 14 days from when the email is sent. We store only a one-way fingerprint of that code, never the code itself. Once an account is created with the code, it cannot be used again. If an invitation expires before it is used, you may send it again; this replaces the code with a new one, and the old link stops working. An invitation cannot currently be withdrawn once sent. Your invitation is deleted if your account is deleted.

DRAFT FOR LEGAL REVIEW (L12; drafted 2026-10-01 from L11 Phase 4, not yet reviewed): We send invitation emails through our email provider, Resend. Resend keeps a copy of each email it sends, including the recipient's address and the email's content, for 30 days, and stores email content in the United States. Access to our Resend account is limited to the account owner and protected by two-factor authentication.

Device and Technical Information

We may automatically collect information including:

DRAFT FOR LEGAL REVIEW (L12; drafted 2026-10-01 from L11 Phase 4, revised the same day for hashed rate-limit keys; not yet reviewed): When someone uses an invitation link to create an account, we use the IP address their request comes from to limit repeated attempts from one address. We keep the address only as a keyed one-way hash, together with a count of attempts, for up to one day, after which it is deleted automatically. The address is never stored in readable form, and we do not record it in our request logs.

Payment Information

If you purchase a paid subscription or other service, payment information may be processed by us or by our payment service provider.

We generally do not need to store complete payment-card information when payment processing is provided by a third-party payment processor.

Information Provided by Organizations

An Organization may provide us with information necessary to create or manage an account, such as your name, business email address, department, role, or account permissions.

3. How We Use Information

We may use personal information to:

Where applicable law requires a lawful basis for processing, we process personal information as necessary to perform our contract with you, comply with legal obligations, protect legitimate interests, protect users and the Service, or based on consent where consent is required.

Our legitimate interests may include operating and securing the Service, preventing abuse, improving functionality, and maintaining reliable communications between users.

4. Messages and Other Communications

Messages are communications between multiple participants. Because a message becomes part of another person's conversation history, deleting an account does not necessarily delete all messages previously sent by that account.

Recipients may retain messages they received even after the sender closes or deletes their account.

Similarly, Organizations may retain messages and other workspace records according to their retention, compliance, business, or legal requirements.

Deleting an account therefore should not be understood as retracting communications that have already been sent to other users.

5. What Happens When You Delete Your Account

When you request deletion of a personal account, we will delete, anonymize, or de-link personal information associated with the account when required and appropriate, subject to the exceptions described in this Policy and applicable law.

Deletion does not take effect immediately. When you request deletion of a personal account, the account is disabled at once, and you are signed out on every device.

DRAFT FOR LEGAL REVIEW: For 30 days following your request, you may restore the account. To do so, sign in again with your password and choose to restore the account on the screen you are shown. Signing in by itself does not restore the account, and it does not cancel the deletion.

If the account is not restored within 30 days, the deletion described in this Section is then carried out.

Account deletion may include removal or de-linking of information such as:

After an account is deleted, its username is not released and cannot be claimed by another account.

Previously Sent Messages

Messages and other communications that you previously sent to other users may remain in those users' conversation histories after your account is deleted.

Where appropriate, we may remove or de-link the account identity associated with those messages and identify the sender using a generic designation such as:

Deleted user

rather than continuing to display the deleted account's profile.

DRAFT FOR LEGAL REVIEW: Messages are also stored on the devices that received them. In the web application, each device keeps a copy of the conversations it has received, in storage belonging to that browser, encrypted on the device as described below. That copy is removed when the device is revoked or wiped, when you leave a group conversation, and, for an individual message, when the sender deletes it and the recipient's device next opens that conversation.

Signing out does not remove the copy stored on that device, but it leaves that copy unreadable. The stored copy is encrypted on the device with a key that the device does not keep: the key is specific to that device, is held by us, and is provided to the device only while you are signed in on it. Signing out on any device signs you out on all of your devices. After you sign out, the copy cannot be read on that device, including by someone with access to the browser's files, unless you sign in on it again. Its size, the number of conversations it holds and the number of messages in each remain visible. If you stop using a device without signing out, the copy remains readable there for as long as that sign-in remains valid, unless you sign out on another device or remove the device from your account. If the device stored messages before this protection was introduced on 2026-09-25, earlier unencrypted versions of some of them may remain in the browser's own storage files until the browser removes them, which we cannot control. Nor can any deletion we perform reach a device that never reopens the conversation, a screenshot, or a copy a recipient has made outside the Service.

When you request deletion of your account, you may choose to remove the copy stored on the device you are using. That choice is offered at the time you make the request and is not selected by default. Choosing it removes that device's stored messages and its encryption keys from that browser. It cannot be undone, it does not affect your other devices, and restoring the account will not return that device's stored messages to it unless you have set up a recovery key and restore from your backup. If you do not choose it, the copy remains on that device.

DRAFT FOR LEGAL REVIEW: If you set up a recovery key, an encrypted backup is stored on our infrastructure so that you can restore your history on a new device. The backup contains your message history and your device's encryption keys. Messages you set to expire are excluded from it, and image thumbnails are not included. The backup is encrypted on your device before it is uploaded and can be decrypted only with your recovery key. We cannot read it, and we cannot restore it for you if you lose that key.

The continued retention of a message does not necessarily mean that we continue to maintain the deleted user's complete account information.

For example, a message previously sent to another user may remain so that the recipient can maintain the integrity and context of their conversation history.

Organization-Managed Accounts

Deleting or disabling an Organization-managed account does not necessarily delete messages, files, meeting records, or other content associated with that user.

Such records may remain under the control of the Organization and may be subject to the Organization's own retention requirements or policies.

Information That May Be Retained

We may retain certain information following account deletion where reasonably necessary or legally permitted, including information required to:

Information contained in backups may remain for a limited period until those backups are overwritten or expire according to our backup retention procedures.

QUESTION FOR LEGAL REVIEW: This sentence covers two different things and one of them has no retention period at all. (1) A user's encrypted recovery-key backup is, today, never deleted when their account is deleted; the decided account-deletion behaviour removes it, but that is not built. (2) The "limited period" for our database provider's own backups has not been confirmed — we have not established what that retention period is. Should this sentence distinguish the two, and what period should it state once confirmed?

QUESTION FOR LEGAL REVIEW: Under the decided behaviour an account is disabled immediately on request, but an already-signed-in session may continue to work until its access token expires — up to about an hour (our authentication provider's default access-token lifetime; this project's configured lifetime has not been re-derived). Does "disabled at once" need qualifying, and is this window acceptable as described?

QUESTION FOR LEGAL REVIEW: Under the decided behaviour, a deleted account keeps a record stripped of personal fields so that messages retained in other users' conversations remain attributable to a distinct (but unnamed) former account. That record keeps a randomly generated account identifier attached to those messages. Is that pseudonymous personal information rather than anonymous information, and if so does this Policy need to say so — for example in Sections 5, 10 and 12?

6. Account Deletion and Privacy Erasure Requests Are Not Necessarily the Same

Closing or deleting an account terminates the account and begins our account-deletion process.

Applicable privacy laws may also provide separate rights concerning personal information about you.

You may therefore submit a privacy request asking us to access, correct, delete, restrict, or otherwise address personal information about you, even if you have already deleted your account.

A privacy deletion request may require us to evaluate information separately from the ordinary account-deletion process.

Where applicable law provides a right to deletion, we will evaluate the request and delete personal information that we are legally required to delete.

Deletion rights are not absolute. Information may sometimes be retained when permitted or required by law, including where retention is necessary to provide a service requested by another user, comply with law, protect security, preserve the rights of other individuals, or establish, exercise, or defend legal claims.

7. User-Controlled Message Deletion

The Service may allow users to delete individual messages they have sent.

Deleting an individual message through this feature is different from deleting an account.

Depending on the functionality of the Service, deletion may remove the message from the active conversation or replace it with an indication that a message was deleted.

Copies may temporarily remain in backups, security records, or other systems for legitimate operational or legal purposes.

An Organization may also impose retention requirements that affect whether workspace communications can be permanently deleted by individual users.

8. How We Disclose Information

We may disclose personal information to the following categories of recipients when necessary to operate the Service.

Other Users

Information you intentionally communicate to another user is disclosed to that user.

For example, recipients of a message may see your display name, profile photograph, message content, attachments, and related message information.

Organizations and Administrators

If you participate in an Organization-managed workspace, administrators may have access to information relating to that workspace according to the Organization's settings and agreement with us.

Service Providers

We may use vendors that assist us with services such as:

These providers may process information only as permitted under their agreements with us and applicable law.

QUESTION FOR LEGAL REVIEW: Should this Section name our providers? Derived from the codebase 2026-09-16, user data reaches: Supabase (database and authentication — all account data and encrypted message content), Vercel (web application hosting), Render (our API and realtime services, and the key-value store used for presence and background jobs), Cloudflare R2 (encrypted file attachments and encrypted backups), and Resend (transactional email — it receives a recipient's email address, another user's display name, and a link; no message content is ever sent by email, and the only two emails we send are an invitation and a reminder about a pending request). Derived separately: requests to Supabase pass through a Cloudflare network edge that is part of Supabase's own infrastructure rather than a provider we contract with. The list of provider categories above also includes push notifications, payment processing, customer support, error monitoring and analytics, none of which we currently use.

Legal and Safety Disclosures

We may disclose information when we reasonably believe disclosure is necessary to comply with applicable law, court orders, subpoenas, or other valid legal process.

We may also disclose information where reasonably necessary to investigate fraud, abuse, security incidents, or threats to the safety or rights of users or others.

Business Transactions

If NuKowd LLC is involved in a merger, acquisition, financing, reorganization, bankruptcy, receivership, sale of assets, or similar transaction, information may be disclosed or transferred as part of that transaction, subject to applicable law.

9. Sale of Personal Information and Targeted Advertising

We do not sell personal information.

We do not share personal information for cross-context behavioral advertising or use private message content to target third-party advertising to users.

If our practices change in a way that constitutes a sale, sharing, or targeted advertising under applicable privacy law, we will update this Policy and provide any notices and opt-out mechanisms required by applicable law before beginning that processing.

10. Data Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, including providing the Service, maintaining security, complying with legal obligations, resolving disputes, and enforcing agreements.

Retention periods may differ depending upon the type of information.

Factors we consider when determining retention periods include:

Message content may be retained for longer than the account information of the person who originally sent the message where the message remains part of another user's conversation or an Organization's records.

We periodically delete or anonymize information that is no longer reasonably necessary, subject to applicable legal and technical limitations.

11. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information against unauthorized access, disclosure, alteration, loss, or destruction.

No online service or method of electronic storage can guarantee absolute security.

Users are responsible for protecting their account credentials and should notify us promptly if they believe their account has been compromised.

DRAFT FOR LEGAL REVIEW: Message content is protected by end-to-end encryption, described in Section 2. The keys that encrypt and decrypt messages are generated on your devices. A device's keys leave it only in one circumstance: if you set up a recovery key, they are included in your encrypted backup, which is encrypted on your device before it is uploaded and which we cannot decrypt. Because we never hold those keys in a form we can read, we cannot read encrypted message content as it travels between devices or as it is stored on our servers, and we cannot recover it for you if you lose access to all of your devices and your recovery key. Separately, we generate and hold a key for each of your devices that encrypts that device's own stored copy of your messages, and we provide it only to that device while you are signed in on it. That key decrypts nothing without the files stored on that device, so reading a device's stored copy would require both that key and access to the device itself (see Section 5).

12. Your Privacy Rights

Depending on where you live and the laws that apply to you, you may have rights concerning your personal information, including the right to:

You will not be unlawfully discriminated against for exercising an applicable privacy right.

Not every right applies in every jurisdiction or circumstance.

We may need to verify your identity before processing a request. We will use information provided in connection with a privacy request only as reasonably necessary to verify and process that request.

If we decline a request, we will provide information regarding the decision and any available appeal rights when required by applicable law.

13. California Privacy Rights

California residents may have rights under the California Consumer Privacy Act, as amended ("CCPA"), including rights to know, access, correct, and delete certain personal information and to receive information regarding our collection, use, disclosure, sale, or sharing of personal information.

Where applicable, California residents may also have rights relating to sensitive personal information and the sale or sharing of personal information.

As stated above, NuKowd LLC does not sell personal information or share personal information for cross-context behavioral advertising.

During the preceding 12 months, we may have collected categories of personal information such as:

We use these categories for the purposes described in this Privacy Policy.

California residents may submit requests using the methods described in Section 18.

QUESTION FOR LEGAL REVIEW: Does the CCPA apply to NuKowd LLC at all? It applies only to businesses meeting its revenue, data-volume or data-sale thresholds. If it does not yet apply, should this Section be removed, retained voluntarily, or reworded to say we honour these rights as a matter of policy?

14. European Economic Area, United Kingdom, and Similar Jurisdictions

If the European Union General Data Protection Regulation ("GDPR"), UK GDPR, or similar law applies to our processing of your information, you may have rights including access, rectification, erasure, restriction, portability, and objection.

Where processing is based on consent, you may withdraw consent without affecting processing that occurred before withdrawal.

Where processing is based on legitimate interests, you may have a right to object to that processing.

You may also have the right to lodge a complaint with the data protection authority responsible for your jurisdiction.

If we transfer personal information internationally, we will use legally recognized safeguards where required by applicable law.

15. International Processing

NuKowd LLC is based in New Jersey, USA.

Information may be processed in countries other than the country in which you live, including countries where our service providers operate.

Privacy and data-protection laws may differ between countries.

Where applicable law requires safeguards for international transfers, we will implement legally recognized mechanisms appropriate to the transfer.

16. Cookies and Similar Technologies

Our websites and applications may use cookies, local storage, device identifiers, and similar technologies to:

Where applicable law requires consent for non-essential cookies or similar technologies, we will request that consent before using them.

Additional information may be provided in a separate Cookie Policy or cookie-management interface.

17. Children's Privacy

The Service is not intended for children under 13 to create personal accounts unless their use is authorized and handled in accordance with applicable law.

We do not knowingly collect personal information from children in violation of applicable children's privacy laws.

If you believe a child has provided us with personal information in violation of applicable law, contact us using the information below.

Important: If Kolekwi will be offered directly to schools or children, this section should be replaced with provisions specifically addressing the applicable educational and children's privacy requirements.

QUESTION FOR LEGAL REVIEW: Is 13 the right minimum age for every market the Service is offered in? Several jurisdictions set the age of consent for data processing at 16, and some permit member states to set it between 13 and 16. Should the minimum differ by market, and should the Service verify age at sign-up?

18. How to Exercise Your Privacy Rights

You may submit a privacy request by:

Email: support@kolekwi.com Web: [PRIVACY REQUEST URL]

Please describe the privacy right you wish to exercise and provide enough information for us to reasonably verify your identity and locate the relevant information.

You do not need to create a new account solely to submit a privacy request.

Where applicable law provides an appeal right, you may appeal our decision by replying to our response or contacting us at:

support@kolekwi.com

We will respond within the time required by applicable law.

QUESTION FOR LEGAL REVIEW: Is a single email address sufficient for privacy requests under every applicable law, or is a second method or a web form required? The "[PRIVACY REQUEST URL]" line above refers to a web form that does not exist — should it be removed until one is built?

19. Third-Party Services

The Service may contain links to or integrate with products and services operated by third parties.

Their privacy practices are governed by their own privacy policies and are not controlled by this Privacy Policy, except where they process information on our behalf as our service providers.

20. Changes to This Privacy Policy

We may update this Privacy Policy from time to time.

When we make material changes, we will provide notice as required by applicable law, which may include notification through the Service, email, or another appropriate method.

The "Last Updated" date at the beginning of this Policy indicates when it was most recently revised.

Material changes will apply prospectively where required by law.

21. Contact Us

If you have questions about this Privacy Policy or our privacy practices, please contact:

NuKowd LLC 5105 Hwy 33 Farmingdale, NJ 07727, USA

Privacy Email: support@kolekwi.com General Support: support@kolekwi.com