Trust and choices

Partner Finder Privacy Policy

The terms and choices for this version of Partner Finder.

Version: 2026-09-19-v1. Effective date: September 19, 2026.

Who we are and what this policy covers

Kaxon AI LLC operates the service under the assumed name Partner Finder and is the controller of the personal information described here. This policy covers the Partner Finder app, the Partner Finder website and the services behind them, in every version in which it is presented. New processing needs the notice or consent that applies to it.

We do not sell personal information, share it for behavioral advertising, or include an advertising network. There is no public people directory. We do not use location or Find activity for marketing, profiling or automated decisions with legal effect.

Information we collect

InformationPurpose and recipients
Email, display name, sign-in and account statusSetup, support and security; Firebase Authentication and our account service
Age range, how it was determined, consent version and timeEligibility and the controls that apply; restricted account records
Guardian link, confirmations, revocations and approvalsFamily Access; relevant status is visible to the linked parties
App-generated device identity, public keys, active or retired device state and replacement eventsConnect the right phones, replace an active phone after account sign-in, and stop a removed phone from silently returning
Find participants, time, transport, outcome and delivery statusDeliver a Find and show your own recent activity
Encrypted coordinates, accuracy and capture timeGuide an authorized finder; relayed encrypted to the chosen recipient only
Purchase and entitlement statusPaid access; Google Play and RevenueCat
Optional analytics and crash informationReliability, only with your separate choice; Firebase services
Privacy and deletion case records: case reference, dates, state and audit eventsFulfil and prove your request; kept apart from account data and stripped of identifiers when done
Messages you send during a Find, and when they were sent and deliveredDeliver your message to the people in that Find; relayed to the chosen recipients only
Blocks you set, reports you make or that are made about you, and the review outcomeLet you refuse contact, review safety reports, and act on accounts that break the Terms
Support and website submissions, and abuse-prevention metadataAnswer you and prevent abuse; restricted support mailbox and hosting providers

We collect this information from you, from your phone as you use the app, from the people you connect with (for example their approvals), and from the providers named below (for example a purchase confirmation).

How we use information

We use personal information to provide the service you ask for, to keep it secure, to answer you, to meet legal obligations, and, with your separate choice, to improve reliability through analytics and crash reports. Where a law requires a legal basis, we rely on the agreement you accepted, on our legitimate interest in running a safe service, on your consent for optional processing, and on legal obligations for records we must keep.

Age and Family Access

Adults use independent accounts. Users aged 13 to 17 set up with a parent or legal guardian and keep their own privacy choices where the law gives them. Guardian agreement does not consent to all optional processing. Enrollment under 13 is not available. If we learn that a child under 13 supplied personal information, we stop further processing and delete it, subject to the narrow exceptions the law allows. Report any such case to privacy@kaxon-ai.com.

A neutral age check comes before any avoidable account processing. The person chooses an age range; the app does not ask for or store a birth date. We use the range for eligibility and controls, not for marketing or analytics. Where available, Google Play may supply age or supervision signals, and mandatory regional verification must be completed where a law requires it. Self-declaration and email do not prove age or guardianship.

If a person signs in to an existing account, Firebase processes the sign-in identity needed to find that account's current age and consent records, so we do not ask for a new age declaration on every phone change. If no eligible account exists, the app returns to the age check before creating one.

Both parties confirm Family Access. A guardian sees relevant link and approval status, not unrestricted messages, contacts or Find history. Teen location sharing needs the teen's permission; a non-guardian recipient also needs guardian approval. Age review and adult acceptance can end the managed relationship. Linking a family member, joining a saved group or paying for access does not by itself give anyone location access; permission is specific to each recipient and direction.

Location, nearby use and maps

Remote location needs a valid directional grant to one exact trusted person. An adult's explicit acceptance of the remote-location disclosure during new pairing creates that grant until location access is turned off or either person removes trust. It never silently widens previously saved nearby trust. A separate control may offer a shorter duration. No approval is needed for each Find while the grant is valid. Teen and guardian approvals are separate; adult acceptance cannot replace them. Android location and background permissions are still required. Sharing is visible and can be stopped. Each 15-minute Find allows up to six attempts; failures count, and a Bluetooth connection stops the remaining attempts. There is no continuous location diary and no operator live-location view.

The responder's phone encrypts coordinates for the finder's phone before Cloudflare relays them. Only the recipient phone can decrypt them; the relay holds no session decryption key. Push notifications contain no coordinates. Timing, participant and ordinary IP and network metadata remain service data. Encryption cannot protect a compromised phone or recall a screenshot. Removing trust invalidates future access on both sides: the removing phone blocks locally and the service rejects revoked access once the removal reaches it. The other phone removes its local access when it receives the revocation; an offline phone cannot receive that until it reconnects, so do not assume an offline copy is instantly erased. Stop acts on that phone.

Nearby messages and radio measurements stay on the participating phones and are not uploaded to the account service. The finder's own position supports local direction and is not sent to the responder. MapLibre renders maps supplied through OpenFreeMap when you choose online maps or downloads; those providers may receive your IP address, the viewed area, timing and technical metadata, and centering a map can reveal the area you are viewing. Downloaded regions stay on your phone until removed and never fetch another person's location.

A group Find is handled as separate Finds that happen to run together: each person has their own permission, session and records, and no one in a group receives another member's location because they are in the same group. Where a watch is paired to your phone, the phone sends it only what it needs to show the current direction and distance; the watch holds no separate account and keeps nothing after the Find.

Optional diagnostics and our providers

Analytics and crash reporting are separate choices, off by default. Declining does not disable finding. Teens give their own specific consent to optional processing, with any additional consent a local law requires. App events exclude names, email, codes, messages, coordinates and radio measurements; the SDKs may process instance identifiers and technical session, device and crash information. Withdrawing consent stops future collection; records already sent follow the provider's retention and our verified deletion procedure.

Our providers are Cloudflare (hosting, relay, storage, security and the website), Google Firebase (authentication, push notifications and chosen telemetry), Google Play and RevenueCat (billing and purchase validation), Google Workspace (our support and privacy mailboxes), and OpenFreeMap and MapLibre (maps you choose to load). Each processes information only for the stated service, security, support or legal purpose under contracts that restrict other use. Information is processed in the United States and may be processed in other countries where those providers operate; where a law requires transfer safeguards, we rely on the provider's approved mechanisms.

How we protect information

Connections between the app, the website and our services use TLS. Our providers encrypt stored data at rest. Location points are encrypted end to end between the two phones, and the relay cannot read them. Each phone's identity keys are generated and kept in the phone's secure keystore, backed by hardware where the phone supports it. Privacy case records that name a person are sealed with a separate key and are stripped of identifiers when a case closes. Access to production systems is limited to the people who run the service and is protected by multi-factor sign-in. No method is perfectly secure: protect your phone with a screen lock, keep it updated and do not share codes. If a security incident affects your information, we notify you and the authorities as the law requires.

Retention

CategoryLimit or trigger
Active account, device and trust records, current family consentWhile needed, until removal or verified deletion
Provisional teen setupRemoved automatically about seven days after the last setup step if Family Access was never completed; privacy and deletion requests remain available at any time
Family invitationRedeemable for ten minutes
Find activity metadataUp to 30 days from the event and at most 1,000 events; no location trail
Latest encrypted pointRetrievable only during the authorized session; removed by cleanup normally within about 24 hours of session expiry
Deletion request in the waiting period14 days from the request, unless you keep the account earlier
After account deletion: hashed device and account identifiersUp to 12 months, only to stop a removed phone or account from silently returning; they identify no one on their own
After account deletion: write-blocking markers on the account serviceUp to 30 days
After account deletion: case audit record without identifiersUp to 12 months; not an archive of your data
Case emails to you and to usContent is removed from our systems once sent; the copy in your mailbox is yours
Temporary privacy exportsUp to ten days; documented legal holds are separate
Routine privacy correspondenceUp to 90 days after closure when necessary
Ordinary support messagesNormally within 90 days after resolution
Testing interestUntil the phase ends, you withdraw, or 12 months, whichever comes first
Local contacts, maps and messages on your phoneUntil you remove them or cleanup reaches the phone

Expiry blocks authorized access as soon as it applies; physical deletion runs in bounded jobs and can be delayed by an outage. Provider backups and records follow their own schedules. We do not promise instant removal from every backup or from a disconnected phone. A legal hold needs a documented reason, scope and review date; deletion never creates a blanket archive.

Messages sent during a Find are kept only as long as needed to deliver them and to let the people in that Find read them, and are removed with your account. Records of a block, a report, or the action we took on a report are kept while they remain needed for safety and to show a decision was made, and they can outlive the reported account where safety or law requires it.

Deleting your account

From Account in the app, choose Delete my account. After a fresh sign-in check, the request is accepted and your account is locked immediately: your phones lose cloud access and no new connections, Finds or purchases can be made. We email you an acknowledgement with a case reference, and we email ourselves the same reference. A 14-day waiting period follows. During it you can sign in and choose Keep my account, which closes the request and unlocks the account with nothing deleted. When the waiting period ends, we erase your billing profile at RevenueCat, your account, phone, contact and activity records on our account service, and your sign-in at Firebase, then email you that it is done. If a step fails, the account stays locked until we complete it; we do not report a deletion that did not happen.

What remains afterwards is listed in the retention table: hashed identifiers and a case record without identifiers, each for up to 12 months, and short-lived write-blocking markers. Google Play keeps its own purchase records under Google's policies. Information another person already received on their phone, such as a screenshot, is outside our control. Local data on a phone that stays offline cannot be erased remotely; use the app's reset when the phone is available.

You can also request deletion at privacy@kaxon-ai.com or through the website form without Plus, completed setup, a reinstall or new Terms acceptance. We verify identity and authority before changing account data; a display name, device name or case number alone is not proof. A guardian may request deletion of a linked teen account through the same verified process. Deleting an account does not cancel a Google Play subscription.

Your rights and choices

Depending on where you live, you may have the right to know what personal information we hold about you, to receive a copy, to correct it, to delete it, to restrict or object to some processing, to withdraw a consent you gave, to appeal a decision we make about a request, and to complain to a data protection or consumer authority. We answer verified requests within the time the law allows, normally within 30 days, and we do not treat you differently for exercising a right.

For residents of US states with consumer privacy laws that apply to us: we do not sell or share personal information, we do not process it for targeted advertising, and we use precise geolocation only to provide the Find you or your trusted person requested. Browser opt-out signals such as Global Privacy Control therefore change nothing, but we honor them where a law requires it. You can exercise any right by emailing privacy@kaxon-ai.com; an authorized agent may act for you with proof of authority.

You can withdraw analytics or crash-reporting consent in the app at any time, remove a trusted person, stop a session, turn off location access, or delete your account. Notices about security, consent, purchases and privacy requests are service messages, not marketing. We send no marketing email; if that ever changes, it will need your separate choice and carry an opt-out.

Requests from authorities and safety reports

Requests from law enforcement, courts or other authorities are checked for scope, jurisdiction and authority. We may narrow, challenge or reject them, and we notify affected users when the law allows. Preserving information is not disclosing it. We cannot supply plaintext location history because we do not hold it, and an informal request does not grant access.

Reports of coercion, unauthorized access or misuse can be sent to support@kaxon-ai.com or privacy@kaxon-ai.com. Send only what is needed for review, never passwords or illegal imagery. What you choose to disclose in a report becomes restricted case information. A report does not give us access to decrypt anyone's private communications. These channels are not emergency services.

We also receive reports from users about other users. We look at what the report says, and at the limited account and Find records needed to judge it. We do not read the messages of people who have not been reported in order to look for problems, and there is no general monitoring of message content.

Website, cookies and communications

The website sets no advertising or analytics cookies. Cloudflare, which hosts and protects it, may set a security cookie when bot protection or a challenge applies; the contact and deletion forms use Cloudflare Turnstile to keep automated abuse out. Contact forms process what you type plus abuse-prevention metadata such as your IP address, and deliver it to our restricted support or privacy mailbox. The checkbox on a form lets us reply; it is not consent to tracking or marketing. Avoid sending credentials, precise home locations or unnecessary sensitive documents.

Changes and contact

We post the version identifier and effective date of every change and give notice or seek renewed consent for material changes as the law requires. Questions, requests and complaints: privacy@kaxon-ai.com. Product questions: support@kaxon-ai.com. Kaxon AI LLC, doing business as Partner Finder.

Help and privacy requests

These documents apply when this version is presented in your app. Request account deletion or contact privacy@kaxon-ai.com. You do not need Plus or new Terms acceptance to make a privacy request.

As of this update, the public website does not use advertising or website analytics cookies. Cloudflare, our hosting and security provider, may set security cookies when bot protection or a challenge applies. These help distinguish automated traffic and remember that a browser passed a challenge. Authorized staff receive a separate authentication cookie when signing in to protected administration pages; ordinary public visitors do not sign in to those pages.

You can clear or block cookies in your browser, although security checks may repeat or protected sign-in may fail. Cloudflare still receives ordinary network and security metadata when your browser requests a page, even if cookies are blocked. The contact form checkbox permits us to reply to a submitted message; it is not consent to advertising or analytics cookies.