1. Who We Are
West Ridge Tech LLC, an Ohio limited liability company doing business as Koromia Apps ("Koromia," "we," "us," or "our"), publishes the mobile applications listed in Section 3.
We are the data controller for personal information processed through our applications.
Contact: West Ridge Tech LLC d/b/a Koromia Apps
Privacy inquiries: privacy@koromia.app General support: support@koromia.app Security reports: security@koromia.app
2. Our Approach
We build applications that collect as little as possible. Two of our four applications require no account and transmit no data to us at all. Where we do process information, we do so for a stated purpose and no other.
We do not sell personal information. We do not share it for cross-context behavioral advertising. We do not embed advertising SDKs. We do not use your content to train artificial intelligence models, and we contract with our AI provider on terms that prohibit them from doing so.
We do not collect or verify your identity. Where an application has accounts, we ask for an email address so you can sign back in and recover access — nothing more. We do not ask for your legal name, we do not verify the name you choose, and we do not check anything you tell us against any record. You are welcome to use our applications pseudonymously, with a display name and email address that are not connected to your real identity, and doing so will not limit any feature. Where an application has no account at all, we could not identify you even if we wanted to.
This is a deliberate design choice, not an oversight. The less we know about who you are, the less there is to lose.
3. How This Policy Works
This document sets out the practices common to all Koromia applications. Each application also has its own Privacy Notice describing exactly what that application collects. Our applications differ substantially — read the notice for the application you use.
| Application | Privacy Notice | Account? | Data sent to servers? |
|---|---|---|---|
| Kadi | /kadi/privacy | Anonymous — no sign-up | Yes |
| Clinic Questions | /clinic-questions/privacy | No | Yes — AI processing only, not stored |
| Lift Logic | /lift-logic/privacy | Yes | Yes |
| Holy Rosary | /holy-rosary/privacy | No | No — video download only |
Where an application's Privacy Notice conflicts with this document, the Notice controls for that application.
Two applications process health-related information. Those practices are described in our separate Consumer Health Data Policy, which is required by Washington's My Health My Data Act and comparable laws.
4. Categories of Information
Across our applications we may process the following. No single application processes all of these — see the applicable Notice.
Information you provide:
- Account credentials — email address, display name
- Google account profile data, where you choose Google Sign-In
- Age and body weight (Lift Logic only)
- Free-text health context you choose to enter (Clinic Questions only)
- Support correspondence
Information collected automatically:
- IP address and network request metadata, received by our infrastructure providers
- Device model, operating system version, application version
- Crash and stability diagnostics
- Aggregate performance telemetry (Lift Logic only)
We do not collect: precise geolocation, contacts, photos, camera or microphone input, calendar data, SMS or call logs, biometric identifiers, government identifiers, or payment card data. We do not use advertising identifiers.
5. Google Sign-In
Where an application offers Google Sign-In, we receive only the basic profile information Google provides for that purpose: your name, email address, Google profile identifier, and public avatar image.
We never receive, see, or store your Google password. Authentication occurs entirely on Google's systems; we receive a token confirming success.
You may revoke our access at any time from your Google Account permissions page. Revoking access does not delete your Koromia account — see Section 11.
6. Purposes and Legal Bases
| Purpose | Information used | Legal basis (GDPR) |
|---|---|---|
| Create and secure accounts | Email, display name, Google profile ID | Contract |
| Authenticate sign-in | Credentials, tokens | Contract |
| Deliver requested app functionality | As described in each Notice | Contract |
| Generate AI suggestions you request | Prompt content you submit | Contract; explicit consent for health data |
| Operate leaderboards and multiplayer | Display name, avatar, results | Contract |
| Route private rooms and matchmaking | IP address, device identifier | Contract |
| Detect cheating, bots, fraud, abuse | Server logs, telemetry | Legitimate interests |
| Diagnose faults, improve stability | Crash and performance data | Legitimate interests |
| Respond to support requests | Contact details, message content | Legitimate interests |
| Comply with law, enforce our Terms | As necessary | Legal obligation; legitimate interests |
Where we rely on legitimate interests, we have assessed that our interests do not override your rights and freedoms. Where we rely on consent, you may withdraw it at any time.
We do not use your information for automated decision-making producing legal or similarly significant effects.
7. Artificial Intelligence
Two applications include AI-generated content, powered by Google's Gemini models accessed through Firebase AI Logic.
Our commitments:
- Content you submit to an AI feature is transmitted to Google for processing and returned to your device.
- If specifically stated, We use the Agent Platform Gemini API (Google's Gemini Enterprise Agent Platform, formerly branded Vertex AI) as our Firebase AI Logic backend, under terms in which Google acts as our data processor and does not use prompts or responses to improve its products. If not specifically stated, we may use Google Gemini Developer API which may provide prompts and output by Google for AI training or improvments.
- We do not train, tune, or refine any model on your content.
- We do not retain prompt content on our own servers except as stated in an application's Notice.
AI output may be inaccurate or incomplete. It is informational only. See our Terms of Service and the disclaimers in each application.
You may report offensive, unsafe, or inaccurate AI output using the in-app reporting control or by writing to support@koromia.app.
8. Disclosure
We disclose personal information only to:
- Processors and service providers acting on our documented instructions under written contract, listed in Section 12
- Other users, limited to what you choose to make visible — display name, avatar, leaderboard standing (Kadi only)
- Legal and safety recipients, where we reasonably believe disclosure is required by law or valid legal process, or is necessary to protect the rights, safety, or property of Koromia, our users, or the public
- A successor, in a merger, acquisition, or asset sale, subject to this policy
We publish a transparency note if we receive a government demand, where legally permitted.
9. Children
Our applications are not directed to children under 18, and we do not knowingly collect personal information from them. Where an application asks for age, users below the minimum are not permitted to create an account.
If we learn we have collected personal information from a child in violation of this section, we will delete it promptly. Parents and guardians may write to privacy@koromia.app.
10. Retention
| Category | Retention |
|---|---|
| Account records | Until you delete your account, then purged within 30 days |
| AI prompt content | Not retained by us; see each Notice for provider handling |
| Server logs (IP, request metadata) | 30 days, then deleted |
| Crash and diagnostic data | 90 days |
| Aggregate performance metrics | 14 months, in aggregated form only |
| Support correspondence | 24 months |
| Records required by law or needed for dispute resolution | As long as reasonably necessary |
Backups follow our ordinary rolling schedule and may lag these periods by up to 30 days.
11. Your Rights
Depending on your jurisdiction, you may have the right to access, correct, delete, port, restrict or object to processing of your personal information; to withdraw consent; to opt out of sale or sharing (we do neither); to non-discrimination for exercising a right; and to appeal a denial.
To exercise a right:
- Email privacy@koromia.app with the subject "Privacy Request," identifying the application and the right you are exercising.
- In-app, where the application has accounts: Settings → Account → Delete Account.
- On the web: https://koromia.app/account-deletion
We verify identity by confirming control of the account email address. Where an application holds no account and no stored data, we may have nothing to retrieve or delete — we will tell you so plainly rather than requesting identifying information we do not need.
Response times: within 45 days (US state laws) or one month (GDPR/UK GDPR), extendable once with notice.
Authorized agents may act on your behalf with written proof of authorization.
Appeals: reply to our decision with "Appeal" in the subject line. We respond within 45 days in writing. You may also complain to your state attorney general or, in the EEA/UK, your supervisory authority.
12. Processors and Service Providers
Per our Google Play Data Safety declarations:
| Provider | Role | Applications | Information |
|---|---|---|---|
| Google LLC — Firebase Authentication | Account authentication | Kadi, Lift Logic | Anonymous account identifiers (Kadi); email (Lift Logic) |
| Google LLC — Cloud Firestore / Realtime Database | Data storage | Kadi, Lift Logic | Account and application data |
| Google LLC — Firebase AI Logic / Agent Platform Gemini API (formerly Vertex AI) | AI inference | Clinic Questions, Lift Logic | Prompt content, transiently |
| Google LLC — Firebase Crashlytics | Crash reporting | Lift Logic | Crash logs, device information |
| Google LLC — Firebase Analytics | Performance analytics | Lift Logic | Aggregate usage events |
| Google LLC — Firebase Hosting / Cloud Storage | Video delivery | Holy Rosary | IP address, request metadata |
| Google LLC / Apple Inc. — app stores | Distribution | All | Governed by their own policies |
| Cloudflare, Inc. | DNS, website security, cookieless web analytics | Website only | IP address, request metadata |
13. International Transfers
We operate from the United States and process data there. If you use our applications from outside the United States, your information is transferred to and processed in the United States.
For transfers from the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses as incorporated into our providers' data processing terms.
14. Security
We apply safeguards proportionate to the sensitivity of the information, including TLS encryption in transit, encryption at rest for stored account data, delegated authentication so that we never handle third-party passwords, least-privilege internal access, and Firebase App Check to restrict backend access to our genuine applications.
No system is perfectly secure and we cannot guarantee absolute security. Report suspected vulnerabilities to security@koromia.app. We will acknowledge within 15 business days and will not pursue legal action against good-faith researchers who follow responsible disclosure.
15. Do Not Track and Global Privacy Control
We do not respond to browser Do Not Track signals, as no common standard exists. We honor Global Privacy Control signals on our website where required by law. Our applications contain no advertising or cross-site tracking technologies.
16. Changes
We may update this policy. We will revise the Effective Date and, for material changes, give at least 14 days' notice in-app or by email before the change takes effect.
17. Contact
privacy@koromia.app — privacy questions and rights requests support@koromia.app — general support security@koromia.app — vulnerability reports
West Ridge Tech LLC d/b/a Koromia Apps, an Ohio limited liability company.
Our mailing address is provided in the copy of this policy inside each application.
Related documents: Terms of Service · Consumer Health Data Policy · Application Privacy Notices linked in Section 3