guest@kroma:~$ read privacy.txt
PRIVACY_
PROTOCOL.
Effective 28 August 2026. This notice covers KROMA phone for iOS and kromaphone.com.
01 / THE SHORT VERSION
KROMA phone is local-first. Its handset, menus, utilities and bundled games run on your device. We use limited measurement data to understand reliability and improve the app and website; we do not sell personal information or use it for personalized advertising.
02 / DATA WE PROCESS
- App and website analytics: app or page activity, app version, broad device/browser characteristics, approximate region and diagnostic context through Firebase Analytics / Google Analytics.
- Server records: request time, requested path, response status and network/security metadata used to deliver and protect the website.
- Device permissions: contacts, camera/flashlight and photo-library access are requested only when you invoke a feature that needs them. Core phone data stays on your device unless you deliberately use an online feature.
- Optional KROMA Cloud: if you choose KROMA cloud, the service stores a random account identifier, a one-way hash of the access key held in your iOS Keychain, any phone backup you submit, and files you upload. A backup can contain general, phone and profile settings, reminders and Composer tunes. Your PIN, security code and lock state are never included.
03 / ADVERTISING CONTROLS
Personalized-ad signals, advertising storage and advertising user-data consent are disabled for the website. Website Analytics is optional: the Firebase Analytics module is not loaded until you choose Allow analytics, and you can change that choice through Analytics settings in the homepage footer. In the iOS app, Analytics runs without IDFA access; personalized advertising signals and Apple ad-network attribution registration are disabled.
04 / SERVICE PROVIDERS
We use Firebase and Google Analytics to measure usage, and Cloudflare plus dedicated KROMA origin infrastructure to deliver the website, online game catalog and optional KROMA Cloud service. These providers process relevant data under their own terms and privacy commitments. Learn more in the Firebase privacy documentation and Google Privacy Policy.
05 / RETENTION & CHOICES
Measurement and server records are retained only for operational, security and product-improvement needs according to the configured provider retention periods. KROMA Cloud keeps submitted backups and uploaded files until you replace or delete them; deleting the KROMA ID removes its server-side backup and files. You can deny or withdraw optional website Analytics from the homepage footer, use device controls for the app, or remove the app to erase its local container. The prerelease feedback page does not currently collect submissions; a direct support and privacy-request channel will be published before the public App Store release.
06 / UPDATES
We may update this notice as KROMA phone evolves. The effective date above will change when a material revision is published.