Kymber

Privacy Policy

Location when it matters.

Effective date: May 30, 2026  ·  Last updated: July 16, 2026

The short version

Kymber is built to share your location only when you decide to — never silently, never in the background. We don't track your movements or keep a continuous trail of where you've been.

When you share live, your location streams to your chosen contacts only while that session is active, and that live stream is deleted when the session ends. The individual points you choose to send — a one-time location ping, the final point of a share, or a point attached to a letter — are kept for a limited time so they stay viewable in your history, then deleted automatically.

Kymber also lets you send short letters and meet-up plans to your trusted contacts. We store that content only to deliver it, and it is removed when it self-destructs, expires, is deleted, or after a short backstop period — whichever comes first.

We use anonymous sign-in, so you don't create an account or password. (You can optionally turn on backup with Google Sign-In so your account can be recovered on a new phone — nothing is backed up unless you explicitly choose otherwise.) We don't sell your data, we don't show ads, and we don't track you over time. This page explains exactly what Kymber collects, why, and how to delete it.

Who we are

This Privacy Policy describes how the Kymber mobile application ("Kymber," "we," "us") handles your information. Kymber is a privacy-first location-sharing and safety app that lets you share your live location with trusted contacts you choose — triggered by you calling a trusted contact from within Kymber, an in-app request, an SOS broadcast, a meet-up you arrange, or a short letter you send.

Kymber is operated by Todd Eastland. If you have questions about this policy or your data, contact us at theast.qa@gmail.com.

What we collect

Information you provide

Location data

Information collected automatically

How location works Privacy-first

Location is the heart of Kymber, so we want to be precise about it:

Letters, meet-ups & user content You're in control

Beyond location, Kymber lets you send a few kinds of short, optional content to the trusted contacts you choose. This content is sent only to the specific people you select — Kymber has no public feeds, profiles, or strangers, and any groups are private and limited to the trusted contacts you choose.

Acceptable use. Because letters and meet-up notes are content you write, you are responsible for what you send, and you agree not to use Kymber to send unlawful, abusive, harassing, or otherwise objectionable content.

Staying in control. Kymber gives you quiet, in-app ways to manage who can reach you — none of which notify the other person:

You can manage blocked people, and this setting, on the Privacy screen. You can also reach us about a safety concern at theast.qa@gmail.com.

How we use information

We do not use your information for advertising, and we do not sell or rent it.

Who we share information with

App permissions

Kymber requests only the permissions it needs for the features above:

Precise & approximate location (while in use only)
Used to share your location during an active session, SOS, or meet-up, and to capture a point when you send a ping or attach your location to a letter. Kymber does not request background location.
Notifications
To show share requests, shared locations, meet-up activity, letters, SOS alerts, and the persistent "sharing now" notification.
Foreground service (location)
Keeps a sharing session alive while you're sharing, with a visible ongoing notification.

Optional backup & account recovery Opt-in only

By default, Kymber keeps no way to recover your account: if you lose your phone or uninstall the app, your notes, history, and contacts are gone for good. If you prefer a safety net, you can optionally turn on backup — during setup or later from the Privacy screen. Nothing described in this section happens unless you explicitly choose it.

Data retention & deletion

Deleting your data. You can delete your Kymber data at any time from within the app, on the Privacy screen, using the two-step delete option. This permanently removes your profile, contacts, sharing sessions, requests, pings, stored location points, meet-ups, letters, activity status, reachability timestamp, and SOS records from our systems. Permanent We may retain reports about possible abuse or safety violations, and limited related information, for as long as we need to review them and keep people safe. Because Kymber uses anonymous sign-in, this in-app action is the way to delete your data; there is no separate account to look up. If you enabled backup, deleting your data also deletes your backup and unlinks your Google account. If you no longer have the app installed: reinstall and recover your account (if you enabled backup), then delete from the Privacy screen — or email us at theast.qa@gmail.com from your linked Google address and we will delete your account and data for you.

Security

Data is encrypted in transit using industry-standard TLS. Access to your data is governed by server-side security rules so that only you and the contacts you share with can see a session's location or a letter you sent. Kymber never has a password of its own to be stolen or leaked: sign-in is anonymous by default, and if you enable backup, authentication is handled by Google Sign-In — your Google password is never seen or stored by Kymber. No method of transmission or storage is ever completely secure, but we work to protect your information.

Payments SOS is free forever

SOS and the core safety features are free forever, regardless of any purchase, and they always will be. Nothing in this section applies to them.

Beyond those, Kymber offers two optional purchases:

Purchases are processed by Google Play Billing. Kymber does not receive or store your card or payment details — Google handles payment processing under Google's Privacy Policy. We receive only your purchase and entitlement status, so the app can unlock the right features for you.

Refunds are handled by Google Play under Google Play's refund policy — because Google takes the payment, they issue the refund. If something has gone wrong, write to us at theast.qa@gmail.com anyway and we'll help where we can.

Children

Kymber is not directed to children under 13 and is intended for users aged 13 and older. We do not knowingly collect information from children under 13. If you believe a child has provided us information, contact us at theast.qa@gmail.com and we will delete it.

Where your data is processed

Kymber's backend runs on Google Firebase infrastructure, with data processed and stored on servers located in the United States. By using Kymber, you understand your information may be processed in the United States, which may have data-protection laws different from those in your country.

If you are in the UK or the European Economic Area (EEA), moving your data to the United States is covered by recognized legal safeguards. Our backend provider, Google LLC, is certified under the EU-US Data Privacy Framework and the UK Extension to it (the "UK-US data bridge") — arrangements approved by the European Commission and the UK government that allow personal data to flow to certified US companies. Where those frameworks do not apply, Google's data-processing terms also incorporate the European Commission's Standard Contractual Clauses and the UK's International Data Transfer Addendum, which provide a separate legal safeguard for the transfer. You can ask us for more detail at theast.qa@gmail.com.

Your rights in the UK & Europe UK & EU GDPR

If you are in the United Kingdom or the European Economic Area (EEA), the UK GDPR and EU GDPR give you specific rights over your personal data. This section explains them and how Kymber meets them. These rights apply alongside everything described above — they don't replace it.

Who is responsible for your data

Kymber is operated by Todd Eastland, who is the "data controller" for the information described in this policy. You can reach us about any data question at theast.qa@gmail.com.

The legal bases we rely on

The UK and EU GDPR require us to have a "lawful basis" for using your personal data. Depending on what you do in the app, we rely on:

Your rights

You have the right to:

You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Kymber does not make any such automated decisions about you.

How to use your rights

Many of these are built right into the app: you can delete your data or edit your name on the Privacy screen, and turn any share or setting off whenever you like. For anything else, email us at theast.qa@gmail.com. We will respond free of charge and within one month. Because Kymber uses anonymous sign-in, we may need to ask you for details only you would know so we can locate the right data and confirm it's really you.

Complaints

If you have a concern about how we handle your data, please contact us first at theast.qa@gmail.com — we will acknowledge your complaint within 30 days and work to put it right. You also have the right to complain to a data-protection regulator. In the UK that is the Information Commissioner's Office (ICO)ico.org.uk, helpline 0303 123 1113. In the EEA you may contact the supervisory authority in your country. We'd appreciate the chance to help before you do.

Changes to this policy

We may update this Privacy Policy from time to time. When we do, we'll revise the "Last updated" date above, and significant changes may be communicated in the app. Continued use of Kymber after an update means you accept the revised policy.

Contact

Questions about this policy or your data? Reach us at theast.qa@gmail.com.