Version: 2026-09-19-v1. Effective date: September 19, 2026.
Who we are and what this policy covers
Kaxon AI LLC operates the service under the assumed name Partner Finder and is the controller of the personal information described here. This policy covers the Partner Finder app, the Partner Finder website and the services behind them, in every version in which it is presented. New processing needs the notice or consent that applies to it.
We do not sell personal information, share it for behavioral advertising, or include an advertising network. There is no public people directory. We do not use location or Find activity for marketing, profiling or automated decisions with legal effect.
Information we collect
| Information | Purpose and recipients |
|---|---|
| Email, display name, sign-in and account status | Setup, support and security; Firebase Authentication and our account service |
| Age range, how it was determined, consent version and time | Eligibility and the controls that apply; restricted account records |
| Guardian link, confirmations, revocations and approvals | Family Access; relevant status is visible to the linked parties |
| App-generated device identity, public keys, active or retired device state and replacement events | Connect the right phones, replace an active phone after account sign-in, and stop a removed phone from silently returning |
| Find participants, time, transport, outcome and delivery status | Deliver a Find and show your own recent activity |
| Encrypted coordinates, accuracy and capture time | Guide an authorized finder; relayed encrypted to the chosen recipient only |
| Purchase and entitlement status | Paid access; Google Play and RevenueCat |
| Optional analytics and crash information | Reliability, only with your separate choice; Firebase services |
| Privacy and deletion case records: case reference, dates, state and audit events | Fulfil and prove your request; kept apart from account data and stripped of identifiers when done |
| Messages you send during a Find, and when they were sent and delivered | Deliver your message to the people in that Find; relayed to the chosen recipients only |
| Blocks you set, reports you make or that are made about you, and the review outcome | Let you refuse contact, review safety reports, and act on accounts that break the Terms |
| Support and website submissions, and abuse-prevention metadata | Answer you and prevent abuse; restricted support mailbox and hosting providers |
We collect this information from you, from your phone as you use the app, from the people you connect with (for example their approvals), and from the providers named below (for example a purchase confirmation).
How we use information
We use personal information to provide the service you ask for, to keep it secure, to answer you, to meet legal obligations, and, with your separate choice, to improve reliability through analytics and crash reports. Where a law requires a legal basis, we rely on the agreement you accepted, on our legitimate interest in running a safe service, on your consent for optional processing, and on legal obligations for records we must keep.
Age and Family Access
Adults use independent accounts. Users aged 13 to 17 set up with a parent or legal guardian and keep their own privacy choices where the law gives them. Guardian agreement does not consent to all optional processing. Enrollment under 13 is not available. If we learn that a child under 13 supplied personal information, we stop further processing and delete it, subject to the narrow exceptions the law allows. Report any such case to privacy@kaxon-ai.com.
A neutral age check comes before any avoidable account processing. The person chooses an age range; the app does not ask for or store a birth date. We use the range for eligibility and controls, not for marketing or analytics. Where available, Google Play may supply age or supervision signals, and mandatory regional verification must be completed where a law requires it. Self-declaration and email do not prove age or guardianship.
If a person signs in to an existing account, Firebase processes the sign-in identity needed to find that account's current age and consent records, so we do not ask for a new age declaration on every phone change. If no eligible account exists, the app returns to the age check before creating one.
Both parties confirm Family Access. A guardian sees relevant link and approval status, not unrestricted messages, contacts or Find history. Teen location sharing needs the teen's permission; a non-guardian recipient also needs guardian approval. Age review and adult acceptance can end the managed relationship. Linking a family member, joining a saved group or paying for access does not by itself give anyone location access; permission is specific to each recipient and direction.
Location, nearby use and maps
Remote location needs a valid directional grant to one exact trusted person. An adult's explicit acceptance of the remote-location disclosure during new pairing creates that grant until location access is turned off or either person removes trust. It never silently widens previously saved nearby trust. A separate control may offer a shorter duration. No approval is needed for each Find while the grant is valid. Teen and guardian approvals are separate; adult acceptance cannot replace them. Android location and background permissions are still required. Sharing is visible and can be stopped. Each 15-minute Find allows up to six attempts; failures count, and a Bluetooth connection stops the remaining attempts. There is no continuous location diary and no operator live-location view.
The responder's phone encrypts coordinates for the finder's phone before Cloudflare relays them. Only the recipient phone can decrypt them; the relay holds no session decryption key. Push notifications contain no coordinates. Timing, participant and ordinary IP and network metadata remain service data. Encryption cannot protect a compromised phone or recall a screenshot. Removing trust invalidates future access on both sides: the removing phone blocks locally and the service rejects revoked access once the removal reaches it. The other phone removes its local access when it receives the revocation; an offline phone cannot receive that until it reconnects, so do not assume an offline copy is instantly erased. Stop acts on that phone.
Nearby messages and radio measurements stay on the participating phones and are not uploaded to the account service. The finder's own position supports local direction and is not sent to the responder. MapLibre renders maps supplied through OpenFreeMap when you choose online maps or downloads; those providers may receive your IP address, the viewed area, timing and technical metadata, and centering a map can reveal the area you are viewing. Downloaded regions stay on your phone until removed and never fetch another person's location.
A group Find is handled as separate Finds that happen to run together: each person has their own permission, session and records, and no one in a group receives another member's location because they are in the same group. Where a watch is paired to your phone, the phone sends it only what it needs to show the current direction and distance; the watch holds no separate account and keeps nothing after the Find.
Optional diagnostics and our providers
Analytics and crash reporting are separate choices, off by default. Declining does not disable finding. Teens give their own specific consent to optional processing, with any additional consent a local law requires. App events exclude names, email, codes, messages, coordinates and radio measurements; the SDKs may process instance identifiers and technical session, device and crash information. Withdrawing consent stops future collection; records already sent follow the provider's retention and our verified deletion procedure.
Our providers are Cloudflare (hosting, relay, storage, security and the website), Google Firebase (authentication, push notifications and chosen telemetry), Google Play and RevenueCat (billing and purchase validation), Google Workspace (our support and privacy mailboxes), and OpenFreeMap and MapLibre (maps you choose to load). Each processes information only for the stated service, security, support or legal purpose under contracts that restrict other use. Information is processed in the United States and may be processed in other countries where those providers operate; where a law requires transfer safeguards, we rely on the provider's approved mechanisms.
How we protect information
Connections between the app, the website and our services use TLS. Our providers encrypt stored data at rest. Location points are encrypted end to end between the two phones, and the relay cannot read them. Each phone's identity keys are generated and kept in the phone's secure keystore, backed by hardware where the phone supports it. Privacy case records that name a person are sealed with a separate key and are stripped of identifiers when a case closes. Access to production systems is limited to the people who run the service and is protected by multi-factor sign-in. No method is perfectly secure: protect your phone with a screen lock, keep it updated and do not share codes. If a security incident affects your information, we notify you and the authorities as the law requires.
Retention
| Category | Limit or trigger |
|---|---|
| Active account, device and trust records, current family consent | While needed, until removal or verified deletion |
| Provisional teen setup | Removed automatically about seven days after the last setup step if Family Access was never completed; privacy and deletion requests remain available at any time |
| Family invitation | Redeemable for ten minutes |
| Find activity metadata | Up to 30 days from the event and at most 1,000 events; no location trail |
| Latest encrypted point | Retrievable only during the authorized session; removed by cleanup normally within about 24 hours of session expiry |
| Deletion request in the waiting period | 14 days from the request, unless you keep the account earlier |
| After account deletion: hashed device and account identifiers | Up to 12 months, only to stop a removed phone or account from silently returning; they identify no one on their own |
| After account deletion: write-blocking markers on the account service | Up to 30 days |
| After account deletion: case audit record without identifiers | Up to 12 months; not an archive of your data |
| Case emails to you and to us | Content is removed from our systems once sent; the copy in your mailbox is yours |
| Temporary privacy exports | Up to ten days; documented legal holds are separate |
| Routine privacy correspondence | Up to 90 days after closure when necessary |
| Ordinary support messages | Normally within 90 days after resolution |
| Testing interest | Until the phase ends, you withdraw, or 12 months, whichever comes first |
| Local contacts, maps and messages on your phone | Until you remove them or cleanup reaches the phone |
Expiry blocks authorized access as soon as it applies; physical deletion runs in bounded jobs and can be delayed by an outage. Provider backups and records follow their own schedules. We do not promise instant removal from every backup or from a disconnected phone. A legal hold needs a documented reason, scope and review date; deletion never creates a blanket archive.
Messages sent during a Find are kept only as long as needed to deliver them and to let the people in that Find read them, and are removed with your account. Records of a block, a report, or the action we took on a report are kept while they remain needed for safety and to show a decision was made, and they can outlive the reported account where safety or law requires it.
Deleting your account
From Account in the app, choose Delete my account. After a fresh sign-in check, the request is accepted and your account is locked immediately: your phones lose cloud access and no new connections, Finds or purchases can be made. We email you an acknowledgement with a case reference, and we email ourselves the same reference. A 14-day waiting period follows. During it you can sign in and choose Keep my account, which closes the request and unlocks the account with nothing deleted. When the waiting period ends, we erase your billing profile at RevenueCat, your account, phone, contact and activity records on our account service, and your sign-in at Firebase, then email you that it is done. If a step fails, the account stays locked until we complete it; we do not report a deletion that did not happen.
What remains afterwards is listed in the retention table: hashed identifiers and a case record without identifiers, each for up to 12 months, and short-lived write-blocking markers. Google Play keeps its own purchase records under Google's policies. Information another person already received on their phone, such as a screenshot, is outside our control. Local data on a phone that stays offline cannot be erased remotely; use the app's reset when the phone is available.
You can also request deletion at privacy@kaxon-ai.com or through the website form without Plus, completed setup, a reinstall or new Terms acceptance. We verify identity and authority before changing account data; a display name, device name or case number alone is not proof. A guardian may request deletion of a linked teen account through the same verified process. Deleting an account does not cancel a Google Play subscription.
Your rights and choices
Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct it, to delete it, to restrict or object to some processing, to withdraw a consent you gave, to appeal a decision we make about a request, and to complain to a data protection or consumer authority. We answer verified requests within the time the law allows, normally within 30 days, and we do not treat you differently for exercising a right.
For residents of US states with consumer privacy laws that apply to us: we do not sell or share personal information, we do not process it for targeted advertising, and we use precise geolocation only to provide the Find you or your trusted person requested. Browser opt-out signals such as Global Privacy Control therefore change nothing, but we honor them where a law requires it. You can exercise any right by emailing privacy@kaxon-ai.com; an authorized agent may act for you with proof of authority.
You can withdraw analytics or crash-reporting consent in the app at any time, remove a trusted person, stop a session, turn off location access, or delete your account. Notices about security, consent, purchases and privacy requests are service messages, not marketing. We send no marketing email; if that ever changes, it will need your separate choice and carry an opt-out.
Requests from authorities and safety reports
Requests from law enforcement, courts or other authorities are checked for scope, jurisdiction and authority. We may narrow, challenge or reject them, and we notify affected users when the law allows. Preserving information is not disclosing it. We cannot supply plaintext location history because we do not hold it, and an informal request does not grant access.
Reports of coercion, unauthorized access or misuse can be sent to support@kaxon-ai.com or privacy@kaxon-ai.com. Send only what is needed for review, never passwords or illegal imagery. What you choose to disclose in a report becomes restricted case information. A report does not give us access to decrypt anyone's private communications. These channels are not emergency services.
We also receive reports from users about other users. We look at what the report says, and at the limited account and Find records needed to judge it. We do not read the messages of people who have not been reported in order to look for problems, and there is no general monitoring of message content.
Website, cookies and communications
The website sets no advertising or analytics cookies. Cloudflare, which hosts and protects it, may set a security cookie when bot protection or a challenge applies; the contact and deletion forms use Cloudflare Turnstile to keep automated abuse out. Contact forms process what you type plus abuse-prevention metadata such as your IP address, and deliver it to our restricted support or privacy mailbox. The checkbox on a form lets us reply; it is not consent to tracking or marketing. Avoid sending credentials, precise home locations or unnecessary sensitive documents.
Changes and contact
We post the version identifier and effective date of every change and give notice or seek renewed consent for material changes as the law requires. Questions, requests and complaints: privacy@kaxon-ai.com. Product questions: support@kaxon-ai.com. Kaxon AI LLC, doing business as Partner Finder.
Help and privacy requests
These documents apply when this version is presented in your app. Request account deletion or contact privacy@kaxon-ai.com. You do not need Plus or new Terms acceptance to make a privacy request.