POV - Privacy Policy
Last Updated: August 25, 2026
1. Introduction
Kehl Group LLC ("Company," "we," "us," or "our") respects your privacy and is committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our POV mobile application ("App").
Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access or use the App.
2. Information We Collect
2.1 Personal Information
We collect information that you provide directly to us:
- Account information (name, email address, phone number, date of birth for age verification at signup)
- Profile information
- Payment and banking information
- Communications with us
- User-generated content (videos, images, descriptions)
2.2 Automatically Collected Information
When you use our App, we automatically collect:
- Location data (GPS coordinates, heading)
- Device information (device ID, model, operating system)
- Usage data (interactions with the App, bounties viewed/created)
- IP address and network information
- Session duration and timestamps
- Camera and microphone access data
- Motion and orientation sensor data
2.3 Location Information
We collect and track:
- Real-time location data while using the App
- Location history during video recording sessions
- Heading and orientation data
- Proximity to bounty locations This information is essential for the core functionality of our App.
2.4 Media Content
We collect and process:
- Video recordings
- Images
- Audio recordings
- Associated metadata (location, time, device information)
- Content descriptions and titles
2.5 Biometric and Recognition Data
We explicitly DO NOT collect or process:
- Facial recognition data
- Biometric identifiers
- Voice recognition patterns
- Behavioral biometrics
- Emotional recognition data
- Gait analysis
- Physical characteristic profiles
2.6 Special Categories of Data
We take extra precautions with:
- Health-related information
- Religious identifiers
- Cultural indicators
- Professional affiliations
- Financial status indicators
- Family-related information
- Lifestyle patterns
2.7 Third-party social and map events
The App may show third-party posts and events on the map and in live feeds (for example, public posts or news-derived events with text, a link to the original source, approximate location, and timestamp). This content is not your POV user-generated content.
- Source: Licensed or public data providers and automated workflows (for example, the GDELT Project public event feed and other news/event sources, plus geolocation enrichment such as Mapbox).
- What we show: Post text, links, timestamps, and location used to place items on the map. We apply a limited lookback in the App (approximately 10 days) for display.
- Storage: We retain rows under our data retention schedule (typically purging stale rows after 90 days unless linked to an active bounty).
- Your rights: This data is not POV account data; standard account export/delete may not remove third-party posts from our systems. Contact legal@pov.media for takedown requests where you have a legal basis.
- Platform terms: Where an original URL is stored, the App provides a View source control when available.
2.8 Third-party editorial content (blog)
We may syndicate editorial articles from our blog partner (Hashnode) into the App: title, excerpt, cover image URL, author display name, publication date, and link to the full article.
2.9 Marketplace secondary licenses
If you buy or sell a secondary license for eligible public marketplace content, we process account identifiers, payment data via Stripe, purchase amount, and license records. Commercial-use scope and platform fees are described in our Terms of Service §4.4.
3. How We Use Your Information
3.1 Core Functionality
- Matching users with nearby bounties
- Processing and delivering bounty payments
- Verifying location during content creation
- Managing user accounts and profiles
- Processing transactions
3.2 Communication
- Sending push notifications about nearby bounties
- Providing updates about bounty status
- Sending service-related messages
- Responding to your inquiries
3.3 Improvement and Analytics
- Analyzing App usage patterns
- Improving user experience
- Debugging and technical improvements
- Market research and analysis
We use PostHog (product analytics) to collect events such as feature usage, screen flows, and payment outcome metadata. We do not intentionally send full payment card numbers to PostHog. Where we send payment-related identifiers (for example, payment intent IDs) for fraud or funnel analytics, we limit fields to what is necessary for those purposes. When you are signed in, we may pass your email address to PostHog as a person property to support support and analytics correlation. See §4.1 and posthog-event-inventory.md.
3.3.1 AI-assisted bounty text (OpenAI)
When you use optional AI rewrite for bounty titles/descriptions, we send your draft title, draft description, and bounty map location to OpenAI for processing. First use shows an in-app notice; see feature-risk-ai-bounty-rewrite.md.
3.3.2 Location search and geocoding (Google, Mapbox)
We use Google Maps Platform (Places) for location search in the App and Mapbox (server-side geocoding) to resolve coordinates for map events (for example, third-party posts).
3.4 Legal and Safety
- Preventing fraud and abuse
- Ensuring compliance with our terms
- Protecting user safety
- Meeting legal requirements
3.5 Referral Program
If you participate in our Referral Program, we process referral codes, attribution, reward status, and related payout data as described in our Referral Program Terms. We share necessary information with Stripe (Connect) to pay cash rewards to eligible referrers.
4. Information Sharing and Disclosure
4.1 Service Providers
We may share your information with processors that help us operate the Service, including:
- Supabase (database, authentication, backend)
- Stripe (payments, Connect payouts, identity/tax verification for payouts)
- Bunny.net (video hosting and delivery)
- PostHog (product analytics — see §3.3)
- Sentry (error and performance monitoring, where enabled)
- OneSignal (push notifications — device tokens and delivery preferences)
- OpenAI (optional AI bounty title/description rewrite — see §3.3.1)
- Google Maps Platform and Mapbox (location search and geocoding — see §3.3.2)
- Discord (optional — internal operational alerts for trust & safety and account-deletion audit when configured; limited identifiers such as user ID and email)
- Email and other messaging providers as needed
- Other subprocessors as we update our vendor records (see
vendor-dpa-register.md)
We require processors to protect personal data under contract. GDPR data processing agreements with key vendors are maintained by the Company.
4.2 Bounty Creators
When you submit content for a bounty:
- Location data associated with the content
- Video/image content
- Submission timestamps
- Creator information as necessary
4.3 Legal Requirements
We may disclose information:
- To comply with laws
- To respond to legal requests
- To protect our rights
- To prevent fraud or abuse
5. Data Storage and Security
5.1 Storage
- User data is stored in Supabase databases
- Media content is stored on Bunny.net servers
- Data is backed up regularly
5.2 Security Measures
We protect your data with encryption in transit and at rest, row-level access controls on our database, and access limited to what each service needs. We use Sentry and PostHog for error and product monitoring. We do not currently run a formal third-party audit or penetration-testing program; if that changes we will update this policy.
5.3 Data Breach Response
In the event of a data breach:
- We will notify affected users promptly
- We will investigate and remediate the breach
- We will cooperate with law enforcement if necessary
- We will provide guidance on protecting your information
- We will take steps to prevent future breaches
5.4 Data Retention
We retain your information:
- As long as your account is active
- As needed for legitimate business purposes
- As required by law, or as necessary to establish, exercise or defend legal claims
Deleting your account does not erase everything. Two categories survive deletion, and they are not the same:
(a) Financial and transaction records. Accounting, payment and tax records — including ledger entries and withdrawal/payout history — are kept for up to seven years where we are legally required to keep them, under Article 17(3)(b) GDPR (compliance with a legal obligation). When you delete your account, these rows are de-identified: your account identifier is removed from the row, and payout/transaction evidence (amounts, timestamps, processor references) remains for the retention period. We do not represent de-identified financial rows as still identifying you. Records held by our payment processor (Stripe) are retained by Stripe under its own legal obligations — see Section 4.1.
Not retained after account deletion: linked bank account credentials (funding instruments) and withdrawal risk-control state (daily limits, device fingerprints used for fraud scoring) are deleted with your account. They are not transaction records and are not kept for the seven-year financial retention period.
(b) Identifiable contract-evidence records. A small number of records are kept in a form that still identifies you (by user ID), because their whole purpose is to prove who agreed to, or received, a particular contract document, or to evidence that we processed your deletion request. These are:
| Record | What is kept | Retained for |
|---|---|---|
| Marketplace licence PDF issuance log | The licence ID, your user ID, the time of the download, and a version marker for the document text that was served. No names, email addresses or payment details, and no copy of the PDF itself | 7 years from the download, then permanently deleted |
| Terms and policy acceptances | Which version of our Terms, Privacy Policy and related agreements you accepted, when, and your user ID as an identifier. No ongoing profile data | Life of account + applicable limitation period for contractual claims |
| Marketplace content licences | The licence record, party user IDs and roles. Contact fields for the departing party (email, contact email, display name) are redacted when you delete your account; the counterparty's contact block is untouched | Life of the licence (perpetual licences: retained indefinitely) |
| Account deletion audit | That a deletion request was made and processed, timestamps, and pipeline status; your user ID as an identifier. Request IP address and browser user-agent are redacted when deletion completes | 2 years after completion, then permanently deleted |
For these records:
- We keep them under Article 17(3)(e) GDPR — retention necessary for the establishment, exercise or defence of legal claims. That is the exemption that lets them survive an erasure request.
- A deletion or erasure request does not remove them. If you delete your account, or ask us to erase your data, these records remain for the retention period stated above. Everything else in your account is deleted as described in Section 6.1.
- They contain pseudonymous, not anonymous, data. Your user ID is retained as an identifier. We do not treat it as anonymised, and we do not claim it is.
- We do not use them for analytics, profiling, advertising or product measurement. They are used only to answer a question about a contract — for example, which text of a licence was issued to which party, and when.
- You can obtain a copy of the licence PDF issuance rows we hold about you through Profile → Download My Data (Section 6.1).
(c) Account suppression digests (repeat infringer / payout fraud). Separately from (a) and (b), when we terminate an account for repeat copyright infringement under our DMCA / 17 U.S.C. §512(i) policy, or impose a permanent payout fraud ban, we may store a one-way cryptographic digest derived from your normalised email address (HMAC-SHA256 with a server-side pepper). We do not store the plaintext email, your user ID, IP address, or device fingerprint in that table. We use the digest only to prevent the same email from immediately re-registering or re-enabling payouts to evade that decision. Rows expire three years from the decision date (renewed if a new qualifying event occurs) and are then permanently deleted. You may contest a suppression decision by contacting legal@pov.media; an admin may lift an entry after human review. Lawful basis: legitimate interests in fraud prevention and safe-harbour policy compliance (GDPR Art. 6(1)(f) / Art. 6(1)(c) where §512(i) supplies the obligation), with storage limitation under Art. 5(1)(e).
5.5 Child Sexual Abuse Material (CSAM) and Mandatory Reporting
We have zero tolerance for child sexual abuse material on the Service. When we obtain actual knowledge of apparent CSAM, we follow internal escalation procedures, preserve evidence as required by law, and report to the National Center for Missing & Exploited Children (NCMEC) via CyberTipline where required by 18 U.S.C. § 2258A. CSAM-related records may be retained longer than ordinary account data and may not be deleted through routine account-deletion requests while an investigation or legal hold applies.
6. Your Rights and Choices
6.1 Account Information
You can:
- Access your personal information
- Update or correct your data
- Delete your account in the App (Legal Center → Delete My Account); we process deletion requests via our automated pipeline (generally within 30 days). Deletion is not total: de-identified financial records (ledger and withdrawal history), a small set of records that still identify you by user ID and exist to evidence contracts you entered into or our processing of your deletion request, and (where applicable) a one-way email digest used only to enforce a prior repeat-infringer or payout-fraud decision (Section 5.4(c)), are retained. Linked bank account credentials and withdrawal risk-control state are not retained. Categories and retention periods are itemised in Section 5.4
- Download a copy of your personal data (Profile → Download My Data). The download includes key account, profile, ledger, submission, bounty, banking, withdrawal, agreement, and marketplace-license records we store as JSON. It does not include all data held about you (for example, analytics or crash data at our processors). See
personal-data-export-spec.md. You may also email legal@pov.media for a fuller access request
6.2 Location Data
You can:
- Enable/disable location services
- Control location permission settings
- Choose when to share location data
6.3 Communications
You can:
- Opt-out of promotional communications
- Manage push notification preferences
- Control email subscription settings
6.4 Privacy Settings
You can:
- Adjust privacy preferences in the App
- Control data sharing options
- Manage content visibility settings
7. Children's Privacy
The App is not intended for children under 18 years of age. We do not knowingly collect personal information from children under 18. If you are under 18, do not use the App or provide any information to us.
When you create an account, we collect your date of birth to verify that you are at least 18. We store this information in your account profile for as long as your account remains active, and we use it to enforce this age requirement. If you delete your account, your date of birth is removed along with your other account data, subject to any retention required by law.
8. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws than your country.
9. Changes to This Privacy Policy
We may update this privacy policy from time to time. The updated version will be indicated by an updated "Last Updated" date. We will notify you of any changes by posting the new privacy policy in the App.
10. Contact Us
If you have questions about this privacy policy or our privacy practices, please contact us at:
Kehl Group LLC
2761 Allied Street, 1st Floor
Green Bay, WI 54304
legal@pov.media
11. California Privacy Rights
If you are a California resident, you have specific rights regarding your personal information under the California Consumer Privacy Act (CCPA). Please contact us for more information about your rights.
12. Data Protection Rights (GDPR)
If you are in the European Economic Area (EEA), you have certain data protection rights under GDPR. These include:
- Right to access
- Right to rectification
- Right to erasure
- Right to restrict processing
- Right to data portability
- Right to object
- Rights related to automated decision-making
Limits on the right to erasure. Article 17(3) GDPR sets out cases where the right to erasure does not apply. Two apply to us:
- Art. 17(3)(b) — compliance with a legal obligation, which covers our financial and tax record-keeping.
- Art. 17(3)(e) — establishment, exercise or defence of legal claims, which covers the identifiable contract-evidence records listed in Section 5.4(b).
If you make an erasure request, we will erase what we can and tell you specifically which records we are retaining, on which of these grounds, and for how long. We will not describe records as de-identified when they are not.
13. Specific App Features and Privacy
13.1 Video Recording
- We collect video content when you submit bounties
- Videos may include location data and timestamps
- Videos are stored securely on our servers
- You control when recording starts and stops
- Video metadata is encrypted
- Access to videos is strictly controlled
- Videos are processed in secure environments
- Temporary video files are securely deleted
- Video storage follows industry best practices
13.2 Location Tracking
- Location is tracked during bounty submissions
- Periodic location updates for nearby bounty notifications
- Location history is stored for verification purposes
- Heading and orientation data is collected during recording
13.3 Push Notifications
- Notifications for nearby bounties
- Status updates for your submissions
- Account and payment notifications
- You can manage notification preferences
13.4 Payment Processing
- Payment information is processed securely
- We use third-party payment processors
- Transaction history is maintained
- Banking information is encrypted
14. Compliance with Laws
We comply with applicable data protection laws, including:
- General Data Protection Regulation (GDPR)
- California Consumer Privacy Act (CCPA)
- Other applicable state and federal laws
15. Special Privacy Protections
15.1 Workplace Privacy
- We do not encourage workplace recording
- Users must comply with workplace privacy laws
- Content revealing workplace details may be removed
- Special handling of professional environment data
15.2 Medical Privacy
- Extra protections for health-related content
- Removal of inadvertent medical information
- Strict controls on health-related metadata
- HIPAA compliance where applicable
15.3 Cultural and Religious Privacy
- Respect for cultural property rights
- Protection of religious expression
- Sensitive handling of cultural content
- Religious site privacy considerations
15.4 Professional Privacy
- Protection of business confidentiality
- Trade secret safeguards
- Professional reputation considerations
- Workplace relationship privacy
15.5 Minor Privacy Protection
- Enhanced protections for minor-related data
- Immediate removal of unauthorized minor content
- Strict parental consent requirements
- COPPA compliance measures
15.6 Location Privacy
- Anonymization of location patterns
- Protection against stalking behaviors
- Aggregation of location data
- Limited retention of movement history
15.7 Financial Privacy
- Enhanced security for payment data
- Protection of earnings information
- Secure handling of banking details
- Prevention of financial profiling
15.8 Emotional and Psychological Privacy
- Protection against emotional exploitation
- Removal of distressing content
- Mental health consideration in content moderation
- User wellbeing protections
By using the POV App, you acknowledge that you have read and understood this Privacy Policy.