Privacy Policy

Effective and last updated: August 5, 2026

Who Operates Coreification

Coreification operates this fashion discovery and social platform. Privacy, data, and security requests may be sent to contact@coreification.com. If a different legal entity begins operating the service, this policy will be updated before that change takes effect.

1. Information We Collect

  • Account data: Google or Apple account identifier, email address when the provider supplies it, display name, handle, age and policy confirmations, account role, and authentication records.
  • Profile, content, and communications data: Profile images, preferences, posts, items, source links, text comments, private direct messages, votes, reports, follows, blocks, and saved boards.
  • Legacy data: Voice memos created before Coreification became text-only may remain in protected storage until the account owner deletes the account or requests deletion.
  • Advertiser and commerce data: Creator or Brand application details, legal or business contact information, website and verified domain email, billing contact, countries served, organization and team roles, campaign targeting, aggregate campaign events, reports, and Stripe or Apple transaction identifiers. Coreification does not receive full payment-card numbers or Apple payment credentials.
  • Technical and usage data: Requested pages, timestamps, browser/device details, approximate network information, performance measurements, security events, and error reports. The iOS crash boundary sends a one-way error fingerprint and fixed platform route, not a stack trace, message content, token, or user identifier.
  • Local device and notification data: Authentication session data protected by the iOS Keychain, an app-install identifier, Expo push token when you opt in, cached media, upload and draft state, notification state, theme, active handle, and privacy choices. Photos or camera images enter the app only when you select or capture them; selected media is uploaded when you choose to publish it.

2. How We Use Information

We use information to operate accounts and sessions, publish content you choose to share, personalize discovery, provide social and saved-content features, verify advertisers, process and review sponsorships, enforce frequency limits, produce aggregate campaign reports, moderate abuse, secure and troubleshoot the service, measure reliability, comply with law, and enforce our Terms.

3. Public Information

Your handle, display name, profile images, public posts, submitted items, and public interactions may be visible to anyone. Do not upload private information or content you do not want publicly accessible. Email addresses, authentication identifiers, direct messages, private moderation records, blocks, and payment identifiers are not intentionally displayed publicly.

Direct messages are visible to the participants. If a participant reports a message or conversation, authorized moderators may review the reported message and limited surrounding context needed to investigate the report, preserve evidence, and enforce our rules.

Approved Brand name, category, website, social profiles, countries served, Brand profile handle, and verification date may be public. Legal contact, domain email, billing contact, team membership, application review records, and campaign-event identifiers are not intentionally displayed publicly.

4. Service Providers and Affiliate Technology

We disclose only the information needed for providers to perform services for Coreification:

  • Supabase: authentication, database hosting, and file storage.
  • Google and Apple: account authentication. Apple also processes iOS creator-boost purchases and sends signed transaction, refund, and revocation records that Coreification verifies and uses to activate or stop the corresponding campaign. For Apple accounts, Coreification stores an encrypted server-side refresh credential only so it can revoke the Apple authorization when the account is deleted. Coreification verifies Apple-signed account-status notifications, stores a restricted replay record without the signed payload or relay email address, and uses those events to update relay status, remove revoked Apple credentials, or begin deletion.
  • Expo: opt-in iOS push-notification routing and delivery. Notification payloads use generic direct-message text and never include a private message body.
  • Stripe: sponsored-campaign payment processing, fraud prevention, refunds, and disputes.
  • Vercel: hosting, application logs, web analytics, and performance measurement.
  • Skimlinks: optional affiliate-link recognition and commission attribution. Its script loads only after you select “Allow affiliate technology.”

Coreification may also disclose information when required by law, to investigate abuse or fraud, to protect users, or as part of a business transaction subject to appropriate safeguards. We do not sell account profile data.

5. Cookies, Local Storage, and Your Choices

  • Supabase uses authentication cookies needed to keep you signed in.
  • Coreification uses browser storage and native device storage for functional preferences, drafts, cached media, install state, and your affiliate-technology choice. The iOS app protects session data in the Keychain and clears a retained session when it detects a fresh reinstall.
  • Vercel provides privacy-oriented traffic and performance measurements used to operate the service.
  • Skimlinks may use cookies or similar identifiers only after you opt in through the privacy-choice panel.

You can change the Skimlinks choice at any time with the Privacy choices control shown on the site. Browser controls can also clear cookies and local storage, although clearing essential authentication data will sign you out.

6. Retention and Account Deletion

  • Active account and content data is retained while needed to provide the service.
  • Account deletion starts a 30-day recovery period. Signing in does not cancel it; you must explicitly recover the account. After that period, the account, direct messages, user-owned content, saved boards, social relationships, legacy voice messages, unpaid campaign drafts, and user-uploaded files are deleted by the account-purge process. An auth-only signup can be deleted immediately in the app.
  • Coreification attempts to revoke Apple authorization during deletion. If Apple is temporarily unavailable, user data deletion still proceeds and only the encrypted revocation credential is retained in a server-only retry queue for no more than 30 additional days, then deleted.
  • Limited security, paid-campaign lifecycle, payment, dispute, tax, backup, and moderation evidence may be retained in de-identified or access-restricted form when legally required or necessary for accounting, reconciliation, abuse prevention, or resolving a report. A reported direct-message snapshot is moderator-only, pseudonymized if an involved account is deleted, and expires no later than 180 days after capture. Backups expire on their normal protected retention schedule.
  • Aggregated or de-identified measurements that no longer identify an account may be retained.

7. Your Rights and Controls

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to certain processing. The app lets you edit profile information, delete individual content, manage follows and blocks, control push notifications, delete an incomplete signup, and schedule account deletion. You may also contact us to request deletion of legacy data or make another privacy request. We may need to verify account ownership before completing a request.

To make a request, email contact@coreification.com with the subject Privacy request, identify the Coreification handle involved, and describe the access, correction, export, deletion, restriction, objection, or appeal you are requesting. Do not email passwords, payment-card numbers, or copies of identity documents unless we specifically request an appropriate verification method. We will respond within the period required by applicable law.

Coreification does not sell account profile data for money. You can decline or withdraw permission for optional affiliate technology through Privacy choices. If applicable law gives you additional rights concerning sale, sharing, targeted advertising, or an appeal, include that request in your email.

8. Safety, Security, and International Processing

We use access controls, row-level database policies, transport encryption, scoped service credentials, monitoring, and abuse controls designed to protect information. No system is perfectly secure. Providers may process data in the United States and other locations where they operate, subject to their contractual and legal safeguards.

Where required, our grounds for processing include providing the service you request, consent for optional affiliate technology, legitimate interests such as security, reliability, moderation, and service improvement, and compliance with legal obligations. You may complain to the data-protection authority available where you live. Learn more about our safeguards and reporting channel in the Security Overview.

9. Children

Coreification is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has created an account, contact us so we can investigate and remove it.

Reports should include the account handle or content URL and why you believe the account belongs to a child under 13. Do not send additional personal information about the child unless requested. See the Safety Center for reporting options.

10. Changes and Contact

We may update this policy as the service changes. Material changes will be identified by a new effective date and, when appropriate, an in-product notice.

Privacy, data, and security requests: contact@coreification.com.