Coryo
Privacy Policy
Effective September 10, 2026. This policy separates server data, account backup, local device data, and information you send directly to another provider.
1Who we are
Coryo ("we", "us") operates the Coryo iOS application and coryo.dance. Contact [email protected] for access, correction, deletion, listing correction, or takedown requests.
2Server data and public catalog data
The table below describes data stored on Coryo servers. Public professional catalog data is listed because a teacher, studio, or organizer may still want to know what evidence we keep and how to correct it.
| Category | What is stored | Source | Purpose |
|---|---|---|---|
| Public catalog and evidence | Published class and event facts, public professional teacher and studio facts, source URLs and quotes, fetch receipts, review decisions, and permitted or credited catalog media. | Studios, organizers, public professional sources, booking platforms, event directories, and organizer submissions | To publish an auditable class and event catalog and correct it when a source changes |
| Account identifiers | Email address, a Coryo account id and public id, and a Google Firebase subject when Google sign-in is used. | You and the identity provider you choose | To authenticate the account and keep account records separate |
| Account profile | Display name, dance styles, level, and home neighborhood. These fields are optional. | You | To identify your account and personalize the class feed |
| Account backup | Class records and teacher and studio follows, including deletions, versions, and conflict receipts. | You, after signing in or accepting a guest import | To restore the supported record on another signed-in device without silently overwriting newer changes |
| Connections and safety choices | Friend requests, accepted friends, and accounts you block. | You, if you use connection features | To maintain mutual connections and enforce blocks |
| Social profile and discovery | An optional username, display name and avatar, adult social-access confirmation, and whether you opted into discovery. | You | To let eligible dancers find and recognize one another without publishing accounts that opted out |
| Private social content | Direct messages and server-authored class previews, read markers, and friends-only studio memories including an optional note and visit date. | You and the friends you choose to interact with | To deliver conversations, shared classes, read state, and the friends memory map |
| Safety reports | Reports you file, opaque account and content identifiers, the reason and optional details, and a minimum snapshot of the reported account, message, or memory. | You, when you report social content | To investigate abuse even if an account or reported item is later deleted |
| Waitlist | Email address and an optional short source label. | You, on the website | To hold your place on the prelaunch waitlist |
| Event submission contact | An optional email address stored separately from the public event. | You, on the event submission form | So a reviewer can ask about the submitted event |
| Catalog gap requests | A request id, the missing studio or teacher name, optional location and public links, an optional note, moderation status, and an account association when you are signed in. | You, when you request a studio or teacher | To research a missing catalog entry without publishing the request itself |
| Event requests | A request id, event name, optional California location or area, optional public source link, moderation status, and an account association when you are signed in. | You, when you request an event | To research a possible event without treating the request as a public event fact |
| Feature requests | A request id, the feature description, app and iOS versions, moderation status, and your account association. | You, when you request a feature while signed in | To review and prioritize product improvements without publishing your request |
| Organizer-created events | A request id, event details, host and attendance details, an optional account association, and optional cover rights, hash, size, dimensions, credit, upload token hash, and private object evidence. | You, when you create an event | To review the event before publication and verify that an optional cover is the file you declared |
| Earlier cloud Coryo history, when that pilot was enabled | Private conversation text, verified source references, action proposal receipts, configured allowance counters, and a rounded coarse location only when nearby ranking is requested. | You and the product records Coryo is allowed to read | To answer a signed-in request, sync private history, prevent duplicate paid turns, and enforce configured trial limits |
| Security receipts | A hashed sign-in code, email address, request network key, attempt count, timestamps, rate-limit receipts, and account-sync idempotency receipts. | You and the network request | Authentication, replay safety, and abuse prevention |
The v2 account backup synchronizes exactly three record kinds: class records, teacher follows, and studio follows. A class record includes its Going or Took state, the saved class snapshot, your note, your song, and the time you said you booked it. The saved snapshot can include the studio's public coordinates. It does not include a coordinate measured from your phone.
3What stays on this device
Growth Plans, plan archives, capture choices, baseline and final clips, profile media, and diary photos stay in the active personal scope on this device. Local profile name, bio, and Instagram handle also stay there. Coryo account sync does not include any of these fields or files. Recommendation impressions and tuning choices also stay in that personal scope and are not included in account sync.
Plan clips are limited to 60 seconds and 100 MB, are excluded from device backup, and are not uploaded by Coryo. The app makes a poster frame locally. It does not score or analyze movement.
Diary notes and songs are different from diary photos. A signed-in class record backs up its note and song; the attached photo remains local.
Calendar conflict checking is optional. When enabled, the app reads busy time ranges in memory to avoid overlaps. It does not retain event names, notes, attendees, or calendar identifiers. Busy ranges are held only in memory while calendar checking is on; they are not persisted or uploaded.
We do not collect: precise or background location, address-book contacts, plan clips, profile or diary media, payment-card details, or studio credentials on Coryo servers. The user-media exception is an optional organizer event cover that you deliberately submit for review; section 2 explains the information retained with it.
We keep daily totals of teacher and agency-roster profile opens to prioritize public profile updates. These totals contain no viewer account, device identifier, or viewing history. Requests also pass through our short-lived network rate limits. Playing a public Instagram video connects your device directly to Instagram's media servers.
4How information is shared
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we do not disclose it for cross-context behavioral advertising. The services below receive information for the named purpose.
| Service provider | What it processes | Purpose |
|---|---|---|
| Google Cloud Platform | Server data described in section 2 | Hosting, database, and secret storage in the United States |
| Google and Firebase | The Google credential and Firebase identity used when you choose Google sign-in | Authenticating Google sign-in before Coryo issues its own session |
| Gmail | The email address and one-time code requested for email sign-in | Delivering the code |
| Studio and booking providers | The page request, website data, and anything you enter on their page | Providing their independent sign-in, booking, and payment flow directly to you |
Providers that process personal information for Coryo may use it only to deliver the named service and must protect it consistently with this policy, their agreements with us, and applicable law. Studio and booking providers are independent: you send information directly to their page, and their own privacy terms apply.
Email and Google are available in the current build. Sign in with Apple appears only when the signed app and the live service confirm the same Apple identity and a complete release configuration. Coryo and note polishing use Apple’s on-device model on supported phones. Catalog searches go to our server; the model processes the retrieved results and your local context on your phone, and Coryo is not offered on a phone that cannot run it.
Your Coryo prompts and your notes are not sent to any model provider. The older cloud assistant was removed on 10 September 2026, along with its provider code, so there is no longer a route that could send them, enabled or otherwise.
Friend requests and accepted connections are visible to the two accounts involved. A block ends the friendship, removes the conversation from both inboxes and closes its history to both accounts, so a blocked account will notice. We never say who blocked them or that a block is the reason. We do not publish friend counts.
We may also disclose information if required by law, to respond to lawful requests from public authorities, or to protect the rights, property or safety of any person. If Coryo is involved in a merger or acquisition, information may transfer as part of that transaction, and this policy will continue to apply until you are notified otherwise.
5Automatic attendance
Automatic logging is optional. When it is On and location permission allows it, Coryo arms regions only for eligible future classes marked Going. A region entry can start visit monitoring only during the class window, from 15 minutes before the start through 45 minutes after the scheduled end. Up to 15 of the soonest eligible regions may be armed.
iOS visit detection is global while it is armed and may observe visits beyond the studio during that bounded period. Coryo compares an iOS visit or one-time location fix with the public studio location. The raw coordinate is held only long enough to calculate distance from the studio; it is not persisted or uploaded.
The device may temporarily store the class id, time, distance, and accuracy needed to decide one class. Those samples are removed after a decision, denial, unmark, cancellation, expiry, permission downgrade, departure, or Off. Attendance provenance and any measured minutes remain local. If attendance changes the class from Going to Took, that class record can be included in signed-in account backup.
Turning automatic logging Off asks iOS to stop every Coryo region and visit monitor, cancels scheduled work, and removes active samples. Sign-out, account switching, guest import, and account deletion await that same teardown and clear the app-local booking website store before another personal scope is activated.
6Sign-in and booking providers
Google sign-in uses Google's sign-in software and Firebase authentication, then exchanges the verified Firebase token for a Coryo session. Email sign-in sends a one-time code through Gmail.
Booking pages use Coryo’s persistent, app-local WebKit website-data store. The studio or booking provider receives the page request and anything you type there, including its own account or payment information. Coryo does not receive those credentials or card details. Coryo does not treat a URL, page close, or payment-provider return as proof that you booked. After the page closes, only your explicit answer can save a booking time in your class record.
You can remove every booking-site cookie, sign-in, and other WebKit item saved by this app under Me, Storage, Clear booking website data. This does not clear Safari, the class catalog, marks, or the Coryo account.
7Where catalog information comes from
Class information comes from public studio schedules, official studio pages, public booking widgets, structured data, documented partner interfaces, and deliberate manual review. Public retrieval never authorizes automating a dancer's login, account, payment, or authenticated booking flow.
Event information can come from organizer sites, public event directories, public professional posts, and organizer submissions. Only approved, future, placed events reach the public event feed. Public professional data is not a dancer's private account data, but it remains correctable.
The current release publishes stored studio and event catalog fields, and teacher portraits, that Coryo's owner authorized for publication. A teacher biography read from a studio's own public schedule page is published with a link to that page and the date we read it, and it stops being shown once that reading is no longer refreshed. Teacher social links and direct media publish only when they are tied to a current teacher-profile grant and pass the applicable verification, freshness, integrity, and revocation checks. A teacher who wants a biography changed or removed can write to us and we will correct it.
Where a studio has published no biography for a teacher, we may show the biography from the teacher's own public Instagram account instead. It is shown whole and exactly as the account had it, never edited and never combined with anything else, with a link to that account and the date we read it. The page says which of the two you are reading. A studio biography always takes precedence, so if one is published later it replaces the Instagram one. We show an Instagram biography only for an account we have already confirmed belongs to that teacher, and the same correction and removal request applies to it.
We retain source URLs, source quotes, fetch receipts, and short-lived raw schedule payloads so a listing can be audited and corrected. A mirrored event flyer is served only with credit and a link to its source, and a takedown stops the artwork from being served while leaving factual event information intact.
Catalog tooling has used Meta Business Discovery for public professional accounts. It can retain post identifiers, captions, delivery URLs, thumbnails, and other candidate metadata needed for review. Catalog tools can also make downloaded and stored copies of public profile pictures or event flyer images, together with source and credit records and a correction and removal process. This catalog processing is separate from Facebook sign-in, which is not available in the current release.
A teacher who chooses Connect with Instagram authorizes a separate Instagram login. We use the one-time result to compare the Instagram username with the exact Coryo teacher listing and to read public professional profile details such as display name, biography, follower and media counts, website, and whether a profile picture is available. We retain the stable Instagram-scoped identifier, verification time, and the profile receipt needed to audit or refresh the connection. We do not receive the Instagram password or retain the Instagram access token. A provider profile-picture URL is not published directly; an image must pass the moderated Coryo storage path first.
Teachers, studios, organizers, and dancers can request a correction or takedown at[email protected]. We do not access private accounts, direct messages, follower lists, or authenticated member schedules to build the catalog.
8Retention
- Account, provider-link, friend, and synchronized-record data remains while the account exists. Account-sync tombstones also remain for the account lifetime so an old device cannot recreate a deletion.
- A sign-in code works for 10 minutes. Expired and used code rows become eligible for removal within 24 hours after expiry or use.
- Rate-limit receipts become eligible for removal after 48 hours.
- Account-sync retry receipts become eligible for removal after 180 days.
- An event submission contact becomes eligible for removal 30 days after a final review decision or 90 days after submission, whichever comes first. Every current final review path records that decision time.
- An organizer cover upload policy and completion token expire after 15 minutes. An unfinished private upload is abandoned after a 24-hour grace period. A verified cover can remain in the private review queue for up to 90 days. Rejected private cover bytes are deleted when possible and otherwise remain quarantined for deletion retry. Approval copies the verified cover to public event storage and removes the private copy.
- Studio, teacher, and event requests remain as private catalog operations records. Deleting an associated account removes the account link from the request. A request sent while signed out has no account link. No automatic request expiry is implemented.
- Milestone progress (opened gems, unlocked stones and the featured stone) is one row per account, kept while the account exists and deleted with it.
- Keyed hashes of your sign-in identities and verified email address are kept after account deletion to prevent repeat trials. Apple DeviceCheck stores whether this device has used a trial. An unverified device can sign in but does not receive a new trial.
- Feature requests are tied to the signed-in account that sent them. Deleting that account deletes its feature requests and their review state.
- Problem reports and catalog corrections sent from Help & feedback are tied to the signed-in account that sent them, with the app and iOS version. Deleting that account deletes them and their review state.
- A teacher listing photo (the public copy and the private original) is deleted when the claim is revoked or the account is deleted. A copy that a storage error left behind is deleted by the private-retention job on its next run.
- A crash or hang diagnostic the app reports while signed in (the call stack, the app and OS versions, and the device model, never message text or location) is kept for 90 days and then removed by the private-retention job. Deleting the account deletes its diagnostics at once.
- An application kit (the details, headshot and resume a dancer types once to apply to agencies) and the record of each application we carried remain while the account exists. The kit is sent to an agency only after the dancer turns on permission and taps Apply for that agency; a form or email door delivers the kit to that agency, and a packet door sends it back to the dancer only. Deleting the account deletes the kit row, every application record, and the headshot, resume and receipt screenshots in private storage in the same operation.
- Messages and their class previews remain while their direct conversation exists. Deleting either participant account deletes the conversation, its messages, and the realtime replay copies of those messages in the same transaction, so the other participant cannot replay a deleted account’s messages afterwards.
- An authored studio memory remains until its author deletes it or deletes the account. Unfriending or either-direction blocking removes it from that friend’s surfaces immediately.
- A safety report keeps its minimum moderation snapshot for 24 months from submission even if the reporter, subject, message, or memory is deleted. It is then removed by the private-retention job. No legal hold is implemented in this release.
- Realtime replay events normally expire after 7 days and one-use realtime tickets after no more than 60 seconds; expired rows are removed by the private-retention job. Account deletion removes every replay event that account could read or was the other party to immediately, without waiting for expiry.
- Unchanged raw class-schedule payloads are deduplicated. Raw schedule-fetch rows become eligible after 14 days and are removed by the next full schedule cleanup.
- Waitlist addresses remain until they are removed in response to a request. No automatic waitlist expiry is implemented.
- Local data remains until its feature-specific delete control, scope cleanup, or app removal deletes it. Plan clips are excluded from device backup.
- Coryo conversation text remains until the direct history delete control or account deletion removes it. A deletion tombstone retains only the conversation id, account boundary, and deletion time needed to clear another device.
- The application does not enforce or verify a duration for cloud runtime logs or database backups. Provider and operator settings must be reviewed before release, so this policy does not invent a duration.
- The guarded cleanup code supports an hourly schedule, but this policy does not claim that cadence until the production job and scheduler are independently verified.
9Your rights, deletion, and choices
Depending on where you live, you may have the rights below. We honor these requests from everyone, regardless of location, and we will not discriminate against you for exercising them.
- Know and access: ask what personal information we hold about you.
- Delete: under Me, Account, delete the server account and choose whether this phone keeps the record as a private guest profile or erases its account-scoped local data too. You can also ask for help by email.
- Correct: fix information that is inaccurate. Profile fields are editable in the app.
- Portability: receive a copy of your information in a portable format.
- Opt out of sale or sharing: we do not sell or share personal information, so there is nothing to opt out of.
- Local controls: remove selected profile or diary media, delete plan clips, clear recommendation tuning, turn automatic logging Off, or clear booking website data.
- AI controls, when enabled: delete a Coryo conversation directly.
A successful account request removes managed Firebase identity data used by this app first, then deletes the Coryo account and its linked server rows. Independent Google, Apple, studio, and booking-provider accounts are not deleted.
Before the server request, the app journals your local choice. It waits for location and booking teardown, then either rekeys the closed account store and local media to a fresh guest scope or erases the closed scope. A lost response or interrupted local operation stays pending and can be retried without activating another profile early. The dedicated data deletion page explains that boundary. Signing in remains optional, and the public catalog works without an account.
To make a request, email [email protected]. We may need to verify control of the account email or another relevant identifier. You may use an authorized agent. We respond within the period required by applicable law.
10Security
Server data is encrypted in transit. Sign-in codes are stored as hashes, not as the six digits that were emailed. Application secrets are configuration values rather than source code. Coryo does not store a Coryo password.
No transmission or storage method is completely secure. Do not enter a studio password or payment detail anywhere except the booking provider's own page, whose current host is shown in the booking browser.
11Children
Coryo is intended for people aged 13 and over. We do not knowingly create an account for a child under 13. Contact [email protected] if you believe a child provided account information.
Social features are separately opt-in and limited to accounts that explicitly confirm they are at least 18. The general 13-and-over app audience does not grant social access.
12International users
Coryo operates in the United States, and server information is processed there. If you use the service elsewhere, information sent to our servers is transferred to the United States.
13Changes to this policy
If the implementation changes what leaves the device, this page must change with it. Material changes will be communicated before they take effect.
14Contact
Questions, privacy requests, corrections, and takedowns: [email protected].