Privacy Policy for Corporal
Last Updated: February 22, 2026
1. Introduction
Welcome to Corporal. This privacy policy explains how we collect, use, and protect your information when you use our mobile application. Corporal is designed to help users find clothing, food, and shelter resources in their community.
2. Information We Collect
2.1 Account Information
- Email Address: Used for account creation, authentication, and important notifications
- Password: Encrypted and securely stored using industry-standard encryption
2.2 Location Data
- Device Location: We request access to your device's location to show nearby resources and enable you to submit new resource locations. Location data is only accessed when you use the app and is not tracked in the background.
- Submitted Locations: When you submit a resource location, we store the address, coordinates, and category information you provide
2.3 User-Generated Content
- Location Submissions: Resource name, address, category (clothing/food/shelter), description, and optional photos
- Photos: Images you optionally upload when submitting a resource location
2.4 Usage Information
- App activity logs for debugging and improving service quality
- Device information (OS version, device model) for compatibility purposes
3. How We Use Your Information
We use the collected information for the following purposes:
- Provide Services: Display resource locations on the map, manage user accounts
- Content Moderation: Review and approve user-submitted locations to ensure accuracy and appropriateness
- Communication: Send account verification emails and important service updates
- Improve the App: Analyze usage patterns to enhance functionality and user experience
- Security: Protect against fraud, abuse, and unauthorized access
4. Information Sharing and Disclosure
4.1 Public Information
- Approved Locations: Resource locations you submit and we approve are visible to all app users (authenticated and anonymous)
- Display Names: Your display name is associated with locations you submit and visible to administrators
4.2 Third-Party Services
We use the following trusted third-party services:
- Supabase: Database, authentication, and file storage services. Data is stored securely on Supabase servers. See Supabase Privacy Policy
- Railway: Server hosting for administrative operations
4.3 We Do NOT Sell Your Data
We never sell, rent, or trade your personal information to third parties for marketing purposes.
5. Data Security
We implement industry-standard security measures:
- Passwords are encrypted using bcrypt hashing
- Data transmission uses HTTPS encryption
- Row-Level Security (RLS) policies protect database access
- Authentication tokens are securely stored on your device
- Regular security audits and updates
6. Your Rights and Choices
6.1 Access and Update
You can view and update your profile information within the app's Profile screen.
6.2 Delete Your Account
You may request account deletion by contacting us. Upon deletion:
- Your account credentials and personal information will be permanently deleted
- Resource locations you submitted may be retained (anonymized) to maintain service integrity
6.3 Location Permissions
You can revoke location access at any time through your device settings. This will limit your ability to submit new locations but you can still browse existing resources.
7. Children's Privacy
Corporal is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
8. Data Retention
- Account Data: Retained while your account is active
- Location Data: Retained indefinitely to maintain service quality unless you request deletion
- Authentication Logs: Retained for 90 days for security purposes
9. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of significant changes by:
- Updating the "Last Updated" date at the top of this policy
- Sending an email notification to your registered email address
- Displaying a notice in the app
10. International Users
Corporal is operated in the United States. If you are located outside the U.S., please be aware that information we collect will be transferred to and processed in the United States. By using Corporal, you consent to this transfer.
11. Contact Us
If you have questions about this privacy policy or our data practices, please contact us:
- Email: bleu@corporalapp.org
- Support: bleu@corporalapp.org
12. California Privacy Rights
California residents have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected
- Right to delete personal information
- Right to opt-out of personal information sales (we do not sell data)
- Right to non-discrimination for exercising privacy rights
© 2026 Corporal. All rights reserved.