Privacy Policy
Effective date: April 22, 2026. Kyarafit (“we,” “us,” or “our”) operates a cosplay wardrobe, build-tracking, and convention-planning service (“Service”). This Privacy Policy describes how we collect, use, disclose, and safeguard information when you use our websites, mobile apps, and related features.
Summary
We collect data needed to run your account and sync your content. We do not sell your personal information or use cross-app ad tracking for targeted ads.
Scope
This policy applies to personal information processed in connection with the Service. If you do not agree with this policy, please do not use the Service.
Information we collect
- Account and authentication. Email address, display name, username, password hash (stored securely by our auth provider), session tokens, and similar identifiers needed to create and secure your account. If you use Google or Apple sign-in, we receive profile identifiers from those providers according to your permission choices.
- Content you create. Cosplay builds, wardrobe items, convention plans, packing lists, notes, and other planning data you enter or upload while using the Service.
- Images. Photos or files you explicitly choose to upload for items, builds, avatars, or progress tracking.
- Device and local storage. To support offline use and session persistence, the app may store limited data on your device (for example cached content or tokens). Web browsers may store auth-related data locally so you remain signed in across visits.
- Communications. Messages you send to us (such as support email) and transactional emails we send (verification, password reset).
- Billing (if enabled). If paid features are offered, payment status and subscription metadata may be processed by our payment provider; we do not store full payment card numbers on our servers.
Information we do not collect by default
- Precise GPS location (convention “location” fields are text you type).
- Contacts or address books.
- Health, fitness, or medical data.
- Advertising identifiers for cross-app ad targeting.
- Photos or files from your device unless you explicitly select them for upload.
How we use information
We use personal information to:
- Provide, maintain, and improve the Service;
- Authenticate users and protect accounts;
- Sync your content across devices when you are signed in;
- Store and display images and user-created content;
- Send transactional emails (verification, password reset, service-related notices);
- Operate optional subscription or billing features if enabled;
- Detect abuse, fraud, and security incidents;
- Comply with law and enforce our Terms of Service.
Legal bases (EEA, UK, Switzerland)
Where applicable, we rely on: (1) performance of a contract with you; (2) our legitimate interests in operating and securing the Service (balanced against your rights); (3) consent where required (for example optional marketing, if offered); and (4) legal obligations.
Sharing and subprocessors
We share information with service providers who assist us in hosting, authentication, database and file storage, email delivery, payments, and analytics infrastructure necessary to run the Service. Depending on features you use, providers may include Convex, Better Auth, Google or Apple (for social sign-in), Resend (transactional email), Stripe (billing, if enabled), and hosting vendors for our web application.
We may disclose information if required by law, legal process, or governmental request, or to protect the rights, safety, and security of users, Kyarafit, or others.
International transfers
Our infrastructure may process data in the United States and other countries where our providers operate. Where required, we use appropriate safeguards (such as standard contractual clauses) for transfers from the EEA, UK, or Switzerland.
Retention
We retain personal information as long as your account is active or as needed to provide the Service. After account deletion, we delete or anonymize cloud-synced profile data and user content associated with your account within a reasonable period, except where retention is required for legal, security, or billing dispute purposes.
Your rights
Depending on your location, you may have rights to access, correct, delete, or export your personal information, and to object to or restrict certain processing. You may exercise deletion through in-app account settings where available, or contact us using the email below. You may lodge a complaint with your local data protection authority.
California residents
California residents may have additional rights under the CCPA/CPRA, including to know, delete, and correct personal information, and to opt out of certain sharing (we do not “sell” personal information or share it for cross-context behavioral advertising as defined under California law). To submit a request, email us at the address below.
Children's privacy
The Service is not directed to children under 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, contact us and we will take appropriate steps.
Security
We implement technical and organizational measures designed to protect personal information. No method of transmission or storage is completely secure; use the Service at your own risk.
Changes to this policy
We may update this Privacy Policy from time to time. We will post the revised policy on this page and update the effective date. Continued use of the Service after changes become effective constitutes acceptance of the revised policy, where permitted by law.
No sale of personal data
Kyarafit does not sell your personal information and does not use third-party ad-tech for cross-app tracking to deliver targeted advertising.
Contact
For privacy or data requests, contact kyarafit@kyarafit.com.