Privacy Policy

Effective 2026-09-04. This is the formal Privacy Policy for Krewva's iOS (iPhone), macOS, and Windows applications. The formal Privacy Policy controls if this page differs from the Trust Charter. It explains what Krewva sees, what can stay on a device, what selected context may reach Krewva or a third-party AI service, and how long records are kept.

iPhone clarification — September 5, 2026. This is an iPhone clarification only. It explains the iPhone keyboard, personalization, Voice Input, permissions, and retention. It does not change the 2026-09-04 policy or record a new consent.

Existing users accept the 2026-09-04 Terms and Privacy version through Krewva's normal acceptance gate.

Who Krewva is

Krewva is made by Wuvov Inc., a Delaware corporation. “Krewva” means the product; “you” means the person whose accounts, device, or content Krewva uses under your instructions.

What Krewva collects and why

Krewva collects the smallest set of information needed for an enabled feature and the records needed to show its work. Depending on what you use, this can include:

  • Account and contact identifiers, including sign-in identifiers and email addresses, plus consent, permission, and feature settings.
  • iPhone request context, including an image of the current conversation on your screen, which may show other people's data; selected reply history, writing samples, contact memory, contact objectives, AI impressions, and current-life context; and the drafts and review records produced from that context.
  • Spoken intent and transcripts when you use a voice feature. Voice audio follows the separate path described below.
  • On macOS and Windows, content from connected accounts and local context that you authorize, such as messages, threads, contacts, and selected files, plus bounded drafts, plans, outcomes, and audit facts.
  • Payment and subscription records, usage information, and content-free diagnostics such as platform, readiness, request ID, timing, failure code, dimensions, byte size, and candidate count.

We use this information to provide personalized drafts, transcription, account and billing functions, support, security, and reliable product operations. Krewva does not collect connected-account content for advertising or track you across the web.

iPhone product analytics

Core app and keyboard-quality analytics are enabled by default during this beta after account onboarding. AI processing, keyboard Full Access and microphone permissions remain separate. Analytics does not change your subscription. Deletion requests remain protected across sign-in.

Core analytics records fixed page and button identifiers, foreground time, feature attempts, explicit reply choices, insertion calls, fixed failure codes, and app and iOS versions. Verified subscription facts may include a start date before analytics collection began; earlier clicks are not reconstructed. Events use a random account-linked identifier, not an anonymous identity. This beta does not request age, occupation or relationship research questionnaires. Krewva does not scan installed apps or infer demographic answers from conversations or contacts.

This analytics path excludes conversation and reply text, prompts, screen images, audio, keystrokes, clipboard contents, contact identifiers, names, email addresses, advertising identifiers, and device fingerprints. It uses no session replay or automatic location enrichment and does not forward your client IP to the analytics provider. AI requests remain a separate path and may process the screen image described below.

The selected analytics provider is PostHog Cloud in the US (Virginia). During this beta, we do not set an event expiry date; vendor retention limits may apply. Inactive research profiles and analytics identities are scheduled for deletion after 12 months without permitted activity. Product and engineering maintainers may inspect these records. Keyboard activity is used only to improve the keyboard. Marketing receives only reviewed non-keyboard summaries, with small groups withheld; it receives no platform account or individual advertising audience. This does not make the underlying records anonymous.

Contact privacy@krewva.com to request analytics deletion. Deletion stops collection and requests removal of the provider profile and events, separately from necessary billing records. Requests already in flight may finish. We verify completion, with a target of 30 days.

iPhone local storage and selected context

Some iPhone personalization records are stored in local app storage, including selected reply history, writing samples, source-scoped contact memory, contact objectives, AI impressions, and current-life context. Local storage does not mean that every related item stays on the device. For a permitted draft, Krewva may send the request-scoped image and the smallest selected context needed to Krewva and a third-party AI service. Krewva does not promise automatic cloud sync of local contacts.

iPhone drafts, screen images, and Voice Input

Screen access, feature enablement, AI-processing consent, and voice permission are separate decisions. An iPhone keyboard permission does not by itself grant AI-processing consent, microphone permission, or authority to send a message.

  • Draft replies. After explicit AI-processing consent, the keyboard may send a fresh image of the current conversation on your screen and selected personalization context through Krewva to a third-party AI service. Krewva returns three drafts for review. Choosing one inserts it into the text field; Krewva never sends it for you. ABC mode sends no conversation data to an AI service.
  • Request-scoped images. A fresh image of the current conversation on your screen is captured for the current request only. It is distinct from derived records such as a selected draft, review evidence, or a contact-memory update. Raw image pixels are not ordinary account history, logs, Sentry data, or support-bundle data.
  • Voice Input. Voice Input is subject to the current Terms and Privacy disclosures and requires microphone permission. Audio goes directly from the iPhone to a transcription service, not to the Krewva backend. A resulting transcript can be used by the selected feature. Ordinary Voice Input is dictation. The updated iPhone Intent preview combines an image of the current conversation on your screen and transcribed meaning to generate one message for insertion into the active app’s text box, then returns to Voice / Intent. It is one-off, not a global or Contact instruction, and separate from three-suggestion Drafts. The user reviews, edits, and sends. Availability depends on the build; this is a preview reference, not a shipped-feature claim. Existing consent and retention terms still apply.

Desktop screen use: three separate flows

On macOS and Windows, screen access, feature enablement, AI-processing consent, Task acceptance, Step approval, and outbound action authority are separate. Krewva does not treat an operating-system screen permission as feature enablement or AI consent.

  • Draft a Reply. A user trigger requests one fresh image of the active top-level window. Only when the feature is enabled and AI processing is consented to may that image travel through Krewva to a third-party AI service for reviewable reply suggestions. The capture itself never sends.
  • Do a Task local OCR. Krewva tries semantic text first. If a bounded semantic gap remains, bounded local OCR can process active-window pixels. Raw pixels stay on the device. Selected derived text may support a Task after the user's choice, not before.
  • Do a Task visual discovery. This is a separate enabled and AI-consented upload path. A fresh image of the active window may travel through Krewva to a third-party AI service to propose Task candidates only. A candidate grants no execution authority. Task acceptance and Step approval remain separate.

Desktop capture is user-triggered and limited to the active top-level window. It is not continuous monitoring and never falls back to a full-desktop capture. Denied, revoked, protected, or changed targets fail closed. Windows may request borderless-capture access during explicit setup or Settings; a normal trigger does not open that prompt. The platform permission mechanisms differ while the product meaning stays the same. You are responsible for lawful access and any notice or consent required for other people visible in a window.

Third-party AI processing and other providers

Krewva uses third-party AI services for selected drafts and other features, and a third-party transcription service for Voice Input. Krewva sends only the selected context needed for the feature, which can include text, a request-scoped image, or audio sent directly to the transcription service. The current recipient categories and identities are shown in the in-app consent disclosures. For recipient details or questions, contact founders@krewva.com. Other provider categories include hosting, storage, rate limiting, payments, monitoring, and connected-account services.

Default abuse-monitoring logs at a third-party AI service may be kept for up to 30 days unless longer retention is required by law or is reasonably necessary to protect that service or any third party from harm. “Up to 30 days” is not an absolute maximum. Krewva does not promise zero provider retention.

Images, diagnostics, and permitted derivatives

Raw image pixels are request-scoped. Krewva excludes them from account history, ordinary logs, Sentry, and support bundles. Krewva may retain permitted derivatives under the relevant feature rules, including generated drafts, review evidence, selected Task evidence, plans, outcomes, audit facts, and a one-way fingerprint. Those derivatives are not raw image history.

Diagnostics are designed to remain content-free. They may record platform, readiness, request ID, image dimensions, byte size, whether a fingerprint exists, timing, failure code, or candidate count, but not raw image pixels.

Retention and local controls

On iPhone, Reply History can be retained for 7, 30, or 90 days, or Forever. The local writing-sample window is bounded to up to 20 recent samples and can be deleted or cleared. You can pause learning, delete one contact or memory item, or clear all local personalization. Pausing learning does not erase existing records. Contact profiles and objectives are not automatically age-pruned; they remain until you delete them. AI impressions can also be cleared when you change an Objective or its pace. Clearing local personalization is not account deletion.

On macOS and Windows, message bodies, cards, and voice samples use the current plan-based inactivity windows: 30 days, 90 days, or 365 days. Those windows do not apply to raw images or local iPhone contact records. Consent-gated redacted improvement records and audit records have separate lifecycles and are not raw message history.

Account deletion has a 30-day cancelable grace period before the implemented purge. Third-party access revocation is best effort. Separate billing or legally required records may remain for their stated lifecycle. Krewva does not promise that a provider or connected account will delete data on the same schedule.

How Krewva protects information

Krewva authenticates account requests and encrypts connected-account credentials at rest with keys managed by AWS KMS. Access is bounded by the feature, consent, Task, Step, and destination authority that apply to the request. When a required permission or consent is denied, revoked, or stale, the relevant operation fails closed.

Your choices and requests

You can review or withdraw iPhone permissions in iPhone Settings, disable a feature, revoke a connected-account permission, or use the app's Privacy controls where they are available. You can request access, correction, deletion, or an export of the information Krewva keeps, subject to identity checks, product availability, and any applicable legal or separately governed record requirement.

Children and other people's content

Krewva is not designed for children to use independently. Do not connect or capture another person's content unless you have lawful authority and provide any notice or obtain any consent that is required.

Changes to this notice

If this notice changes materially, Krewva will update the version date and use its normal acceptance gate before the revised policy applies to existing users where required.

How to reach Krewva

For help with access, correction, export, deletion, or an iPhone support question, write to founders@krewva.com. For a privacy-specific request, you can also write to privacy@krewva.com.

See Your data. Your choices. for practical request options, and the sub-processors list for formal provider identities.