Privacy Policy

Last updated: September 16, 2026

This Privacy Policy explains how Corzo ("we," "us," "our," or the "App") collects, uses, shares, and protects information when you use our mobile application, our website at corzo.app, and related services (together, the "Service"). By creating an account, submitting your email on our website, or otherwise using the Service, you acknowledge that your information will be handled as described here.

If you do not agree with this policy, please do not use the Service.


1. Who we are (data controller)

Corzo is operated by Silvester Šikula - doklezz, a sole trader established in Slovakia, located at Podhrádok 471/7, 059 34 Spišská Teplica, Slovakia. For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, we are the data controller of the personal data described in this policy. You can reach us at corzo@corzo.app with any question about this policy or your data.

We have not appointed a Data Protection Officer because we are not required to under Article 37 GDPR. Privacy questions go to the address above.

2. Information we collect

2.1 Information you give us directly

Category Examples Why we collect it
Account information Email address, password (stored only as a salted hash), nickname/username, profile photo, bio To create and secure your account, identify you to other users, and let you sign in
Sign in with Apple / Google The unique identifier Apple or Google gives us for your account, and, only on your very first sign-in, the name/email that provider chooses to share To let you sign in without a separate password, and to link that sign-in method to your account
Two-factor authentication Whether you have email codes or Face ID confirmation turned on, and the one-time codes we email you. Face ID itself runs entirely on your device through Apple's system; we never receive any biometric data, only a yes/no result To protect your account from unauthorized sign-ins
Profile & vehicle details Car make/model, horsepower, modifications, photos To power the profile and car-listing features you choose to fill in
Purchase & subscription information Whether you have an active Premium subscription, your subscription tier, and renewal date, as provided to us by Apple or Google after a purchase, never your payment card details To give you access to Premium features and manage your subscription
Content you post Photos, videos, captions, comments, likes, saves, and stories (which expire after 24 hours) To operate the media feed and let other users see and interact with what you post
Messages Text, photos, voice notes, video, and reactions you send in direct chat, group chat, or car meet chat To deliver your messages to the people you're messaging, and to operate the moderation, support, and safety functions described below
Cruise Radio voice Your voice while you hold the talk button during a group cruise Relayed live to the other participants of that cruise only. We do not record or store Cruise Radio audio.
Car meet information Meets you create or attend, invitations, announcements, meet chat messages To organize and display car meets you participate in
Clan information Clans you create, join, or apply to, your role in them, and your contribution to clan points and clan wars To operate the clan features
Music connection If you connect Spotify or Apple Music: the access token that provider issues to us, and the track/artist/artwork you're currently playing To show what you're listening to to friends, in chat, and during drives and group cruises, for as long as you keep the connection on
Support requests The subject, message, and any screenshot/photo you attach to a support ticket To respond to and resolve your issue
Content reports The reason you give when reporting a post, and the report itself To review reported content and take action if needed
Launch waitlist email The email address you voluntarily submit on our website (corzo.app) to be notified when the App launches To send you a one-time email when the App becomes available. We don't use this address for anything else, and submitting it doesn't create an account

2.2 Information collected automatically

Category Examples Why we collect it
Location data (precise) Your device's GPS coordinates while you have live location sharing turned on; the full GPS route, speed, and distance of a drive you choose to record; your live position during a group cruise you've joined; and the position of a traffic alert you submit To show your live location to friends you've allowed to see it, to place you on the map, to power drive recording, group cruises, leaderboards and the explored map, and to place traffic alerts on the map. Drive recording requires "Always" location access if you want it to keep working while your screen is locked or the app is in the background. You control this in your device's Settings at any time
Explored map (derived) Which cells of a coarse map grid your recorded drives passed through, and a running count of them To power the "scratch map" and explored leaderboard, if you leave that feature on in Settings. Only the count and the cells you have cleared are kept, not the drive that cleared them
Country (derived) A country code (currently only Czechia, Slovakia, or Poland are recognized) classified on our server from your published location, using an offline border check rather than any external geocoding service To power the country-specific leaderboards. Only the resulting country is shown to other users, never your coordinates
Motion activity Whether your phone thinks you're in a vehicle or on foot, read from your device's motion sensors while a drive is being recorded To pause or end a drive automatically when you leave the car. This is processed only on your device and is never sent to us
Push notification token The device token Apple assigns to your installation of the App To deliver push notifications you've allowed, through Apple Push Notification service
Usage & device information App version, device type, general performance data, and one record per day of whether your account made any request (no details of what you did) To keep the Service working, debug problems, understand how many people use the App, and improve it
IP address & server logs Your device's IP address, the request path, timestamp, and user agent, recorded automatically on every request our servers receive To help keep the Service secure, detect and prevent abuse, and enforce fair-use limits. Your IP address is not stored as part of your profile or linked to your account; it exists only in short-lived server logs and security tooling and is deleted on a rolling basis
Follows, likes, blocks, and social graph Who you follow, who follows you, who your friends are, who you've blocked To power the social and messaging features and to honor blocks
Progression data Points, level, daily challenges, streaks, and awards earned in the App, plus an audit trail of awards taken back To operate the progression features and to detect farming or abuse of them
Moderation records Reports about you, restrictions applied to your account (for example a temporary comment or posting hold), and the reason To enforce our Terms and to give you a statement of reasons and an appeal, as the law requires

We do not use any third-party analytics or advertising SDKs in the App, and we do not use cookies or tracking technologies on corzo.app beyond what is strictly necessary to serve the page. The admin area of our website uses a session cookie that applies only to our own staff.

2.3 Information from other users

Other users may upload content about you (for example, tag you in a car meet, mention you, or post a photo or video you appear in) or provide your nickname to send you a friend request. We are not responsible for information other users share about you outside the Service's intended features. If content posted by someone else violates your rights, report it in the App or contact us (see §6 and the notice channel in our Terms of Service).

2.4 Sensitive information

Precise location is treated as sensitive personal information under several laws, including the California Privacy Rights Act and other US state privacy laws. We collect it only with the permission you grant in your device's Settings and for the purposes listed above, and you can withdraw that permission at any time. We do not intentionally collect health data, biometric identifiers, government ID numbers, or other special categories of data, and we ask you not to share them through the Service. Photos, videos, and messages you choose to post may reveal such information about you or others; that content is processed only to provide the features you use and for the moderation described below.

2.5 Automated content moderation (AI)

We use an automated, AI-based tool to screen photos and videos you upload, including posts, stories, avatars, chat attachments, car meet chat attachments, and support ticket attachments, before they're stored or shown to anyone else. This tool analyzes the image (or a frame taken from the video) to detect content that violates our content policies, such as explicit/nudity content, and automatically rejects uploads that are flagged.

3. How we use your information, and our legal bases

We use the information we collect for the purposes below. Where the GDPR or UK GDPR applies, the legal basis for each purpose is listed alongside it.

Purpose Legal basis (GDPR Art. 6)
Create, maintain, and secure your account; provide the core features of the App (profiles, chat, media feed, stories, drive recording and leaderboards, group cruises, car meets, clans, progression, support tickets) Performance of a contract (Art. 6(1)(b))
Show your live location to friends you've chosen to share it with, and to other participants of a group cruise you joined; record drives; place traffic alerts you submit Your consent (Art. 6(1)(a)), given through the location permission and the in-App switches, which you can withdraw at any time
Show what you're listening to, if you connect a music service Your consent (Art. 6(1)(a)), withdrawn by disconnecting the service in Settings
Send push notifications Your consent (Art. 6(1)(a)), given through the system notification permission
Send you a one-time launch email from the waitlist Your consent (Art. 6(1)(a))
Derive your country for leaderboards; derive explored map cells from your drives Performance of a contract (Art. 6(1)(b)); you can turn the explored map off in Settings
Automatically screen uploads for policy violations; review reports; apply and record account restrictions Our legitimate interest in keeping the Service safe and lawful (Art. 6(1)(f)), and compliance with our legal obligations under the EU Digital Services Act (Art. 6(1)(c))
Process and manage your Premium subscription Performance of a contract (Art. 6(1)(b)) and legal obligations (tax and accounting records) (Art. 6(1)(c))
Communicate with you about your account, support requests, security, or changes to our policies Performance of a contract (Art. 6(1)(b)) and legitimate interests (Art. 6(1)(f))
Keep server logs; detect, investigate, and prevent fraud, abuse, spam, cheating in progression features, and violations of our Terms Our legitimate interest in the security and integrity of the Service (Art. 6(1)(f))
Comply with legal obligations, respond to lawful requests, and establish, exercise, or defend legal claims Legal obligation (Art. 6(1)(c)) and legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we have balanced those interests against your rights and concluded they are not overridden; you can object at any time (see §6).

We do not sell your personal information, we do not share it for cross-context behavioral advertising, we do not show third-party ads, and we do not use your data for profiling that produces legal or similarly significant effects on you.

4. How we share your information

We never share your password with anyone, including our own staff.

Direct messages between two users, and group and car meet chat, are encrypted at rest in our database with a separate key per conversation. This is not end-to-end encryption: unlike your password, we hold what's needed to decrypt message content, for example to investigate a report, respond to a support request, or comply with a legal obligation, subject to the internal access restrictions described below. Access is limited to what's needed for those purposes; we don't monitor messages as a matter of routine.

5. How we protect your information

We use a combination of technical, administrative, and organizational safeguards designed to protect your information against unauthorized access, disclosure, alteration, and loss. These include, among others, encryption of data in transit, encryption of message content at rest, hashing of passwords and of security tokens, controls that limit who and what can access your data, hardware-key (passkey) protected access to our admin tools, and internal restrictions on who at Corzo can access production systems. We don't publish the specifics of our security measures, as doing so could undermine their effectiveness.

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. If we become aware of a personal data breach that is likely to result in a high risk to you, we will notify you and, where required, the competent supervisory authority, within the time limits set by applicable law. If you believe you've found a security vulnerability in the Service, please report it to us at corzo@corzo.app rather than disclosing it publicly.

6. Your choices and rights

6.1 Controls in the App

6.2 Your rights under the GDPR and UK GDPR

If you're in the European Economic Area, Switzerland, or the United Kingdom, you have the right to:

To exercise any of these rights, contact corzo@corzo.app. We'll respond within one month, extendable by two further months for complex requests, and we'll tell you if that happens. We may need to verify your identity, usually by asking you to write from the email address on your account. Exercising your rights is free unless a request is manifestly unfounded or excessive.

6.3 Your rights under US state privacy laws

Depending on where you live in the United States (including California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, and other states with comprehensive privacy laws), you may have the right to:

To exercise these rights, contact corzo@corzo.app or use the in-App controls above. We'll respond within 45 days, extendable once by another 45 days where reasonably necessary, and we'll tell you if that happens. You may designate an authorized agent to make a request on your behalf; we'll ask for proof of that authorization and may still need to verify your identity directly. If we deny your request, we'll tell you why, and you may appeal by replying to our decision or writing to corzo@corzo.app with "Privacy appeal" in the subject; we'll respond to the appeal within 45 days and, if we deny it, tell you how to contact your state attorney general.

California disclosures. In the preceding 12 months we have collected the categories of personal information listed in §2 (identifiers, account and profile information, commercial information about subscriptions, precise geolocation, audio/visual content you upload, internet activity in the form of server logs, and inferences limited to the derived country and explored cells) from you and your device, and disclosed them for business purposes only to the service providers listed in §4. We have not sold or shared personal information, and we have no actual knowledge that we sell or share the personal information of consumers under 16.

7. Data retention

We keep your information for as long as your account is active, or as needed to provide the Service, and then delete or anonymize it. Specific rules:

8. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under that age. If the minimum age in your country is higher than 16, that higher age applies to you. We do not knowingly collect personal information from children under 13 in the United States, in line with COPPA. If you believe a child has provided us with personal information, contact us at corzo@corzo.app and we will delete it and terminate the account.

9. International data transfers

Your information may be processed and stored in countries other than the one you live in. Where we or our service providers (see §10) transfer personal data of EU/EEA, Swiss, or UK users outside those areas, for example to the United States, we rely on a safeguard recognized under GDPR Chapter V, such as an adequacy decision (for example, the EU-US Data Privacy Framework, for providers certified under it) or the European Commission's Standard Contractual Clauses (and the UK International Data Transfer Addendum where relevant), rather than relying on your consent alone. Contact us at corzo@corzo.app for more information about the safeguard used for a specific transfer.

10. Third-party services

The App integrates with, or relies on, the following third parties:

Your use of these providers' own services is subject to their own terms and privacy policies, which we don't control.

11. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we'll notify you through the App or by other reasonable means before the change takes effect, and where a change requires your consent under applicable law, we'll ask for it. The "Last updated" date at the top of this policy indicates when it was last revised.

12. Contact us

If you have questions about this Privacy Policy or how we handle your data, contact us at:

Silvester Šikula - doklezz corzo@corzo.app Podhrádok 471/7, 059 34 Spišská Teplica, Slovakia

This address is also our single point of contact for users and for authorities under Articles 11 and 12 of the EU Digital Services Act. Please write in English or Slovak.