c rnr
How Cornr Works For businesses About Us Contribute Contact Us
Ask for my country
Privacy

Privacy Policy

Last updated 16 September 2026 · Effective 16 September 2026 · Version 3.0

North Axis Holdings, Inc. ("Cornr", "we", "us", or "our") is committed to protecting your personal information in accordance with British Columbia's Personal Information Protection Act (PIPA) and, where it applies to our cross-border activities, the federal Personal Information Protection and Electronic Documents Act (PIPEDA). This policy explains what we collect, why, who we share it with, how long we keep it, and what you can make us do about it.

The short version. We keep the cornr you are in, not an address. We do not sell anything about you, we do not run targeted advertising, and we do not use your content to train AI models. We do not infer anything from your behaviour. Your interests are ones you picked, and your light is one you turned on. We do keep a record of your devices and of moderation, because an app where neighbours meet in person cannot let a banned account walk back in. You can delete your account from inside the app, and that deletes your content with it.

1. Who we are and how to reach us

Cornr is a hyperlocal neighbourhood application operated by North Axis Holdings, Inc., a company based in British Columbia, Canada. We have designated a Privacy Officer who is accountable for our compliance with this policy and applicable privacy law.

Privacy Officer
North Axis Holdings, Inc.
British Columbia, Canada
founder@northaxis.holdings

2. What personal information we collect

2.1 Information you give us

  • Account information: your email address and password (stored only as a hash) when you create an account. If you use Sign in with Apple, we receive an Apple identifier and whatever address you chose to share, including Apple's private relay address if you chose to hide your email, in which case we never see your real one.
  • Profile: a display name, and optionally an age, a short bio, a profile photograph, and a banner image. When you crop a photograph we also keep the original privately, so that you can move the frame later without uploading it again, and the position of the frame.
  • Approximate location: to place you on a neighbourhood cornr ("cornr"), your device converts your position into a coarse geographic cell roughly a ten-minute walk across, and sends us the cell. We do not store your precise GPS coordinates for this purpose, and we do not collect location while the app is in the background. A precise position is used momentarily, on your device, when you and another person meet in person and scan each other's code; it is not stored.
  • Content you post: posts, talk, comments, private messages, photos and video, questions to hosts, and reviews of local businesses. Reviews are shown to other neighbours and to the business, under your display name unless you post anonymously.
  • Interests you choose: optional tags from a fixed list. Visible only to people who share your cornr, and only while you keep them. The list deliberately excludes religion, health, political affiliation, sexual orientation, and gender identity, and we do not infer interests from your behaviour.
  • Your mute and block lists, which are visible only to you and are used to keep people out of each other's way.
  • Camera: the app uses the camera only to scan a Cornr code. Images from the camera are processed on your device and are not sent to us or stored.
  • Cornr Cubes: if you play the daily puzzle we keep your scores, streak, and the times you answered. Your display name and score appear on leaderboards visible to other neighbours in your cornr and city. You can stop playing at any time, which stops new scores being recorded.
  • Business information (business accounts): business name, street address, the name of a responsible person, category, opening hours, links, a perk or profile description, card imagery, and subscription and payment status.
  • Support communications: whatever you send us when you write to us or use the contact form on this website.

2.2 Information collected automatically

  • Device records. For each device you sign in from we keep a device identifier generated by the app and stored in your device's keychain, Apple's vendor identifier for our apps, the platform, device model, operating system version, app version, the first and most recent times we saw it, how many times we have seen it, and the first and most recent IP addresses, together with the country, city, and cornr those addresses resolved to. We use this to keep your account secure, to recognise a returning device, and to enforce suspensions and closures. See section 2.4.
  • Usage data: app version, basic interaction logs, and error reports, used to operate, secure, and troubleshoot the service.
  • Push notification tokens: if you allow notifications, we store the token Apple issues for your device so we can send them. Revoking the permission, or deleting the app, ends this. If you use a Live Activity, iOS shares a separate token for that activity, which we use only to update it and which expires with it.
  • Your time zone and a coarse activity timestamp, so that a daily allowance resets at midnight where you actually are, and a record of when you were last seen, so neighbours can tell whether you are around.
  • A record that you accepted these terms, and which version.
  • Cookies: our website uses essential cookies to keep you signed in to the business and moderation areas. See section 9.

2.3 Moderation information

Reporting is central to how Cornr stays usable, and it creates personal information of its own. When a report is filed we record who filed it, what it was about, the reason chosen, anything written in the box, the cornr each party was in, the reporter's IP address, and the time. Where the report is about a photograph or a banner, we also keep the address of the image as it stood at the moment of the report, so that a moderator judges the picture that was actually complained about rather than whatever replaced it. When a moderator acts we record who acted, what they did, why, and a copy of the content as it stood at the moment it was removed. We also record warnings, strikes, suspensions, and account closures.

This is visible only to administrators. We keep it because a moderation system with no record cannot answer an appeal, cannot recognise a pattern of behaviour across several reports, and cannot show a regulator what it did. If you were reported and nothing came of it, the report is still on file as handled and dismissed.

We do not tell a person who reported them, and an access request under section 12 will not reveal a reporter's identity.

2.4 Device restrictions

When we close or suspend an account for a serious breach we may also record a restriction against the device identifier and IP address it was used from, so that the same person cannot simply make a new account and carry on. A restriction records the device identifier, the IP address, the reason, the account it came from, and when it was applied and lifted. We use it only to enforce our Terms. Because IP addresses are shared and reassigned, we review restrictions on request, and a restriction can be lifted.

2.5 Payment information

Purchases made inside the iOS app go through Apple's In-App Purchase. Apple is the merchant of record; we receive a receipt identifier and what you are entitled to, never your payment details. Host sponsorships and Presence subscriptions are processed by Stripe, which handles card data under its own terms and PCI-DSS obligations; we receive a confirmation and limited transaction metadata, never a full card number.

3. Why we collect it

Under PIPA we may only collect, use, and disclose personal information for purposes a reasonable person would consider appropriate. We use yours to:

  • create and secure your account and authenticate you;
  • place you on the correct cornr and show you nearby activity;
  • deliver posts, talk, messages, questions, and perks between neighbours and hosts;
  • send the notifications you have asked for, and service and safety notices;
  • run Cornr Cubes and its leaderboards;
  • process host payments, subscriptions, and refunds;
  • receive and act on reports, keep the service safe, and enforce our Terms, including by recognising a device that a closed account was used from;
  • operate, maintain, troubleshoot, and improve the service;
  • detect, prevent, and respond to fraud, abuse, and security incidents;
  • comply with legal obligations and respond to lawful requests.

We do not sell personal information, we do not run behavioural advertising, we do not build advertising profiles, and we do not use your content to train machine-learning models. Our AI provider is contractually prohibited from training on what we send it.

3.1 Automated processing

We use automated systems, including a third-party artificial intelligence service, to help classify posts, sort the report queue, and power Ember, the optional guide. What is sent for this purpose is the content being classified or the question you asked, along with the minimum context needed to answer it. It is processed on our behalf and is not used to train the provider's models. No automated system alone closes an account: a decision that materially affects your account is reviewed by a person, and you may appeal it. You can avoid Ember entirely by not using it.

4. Consent

We collect, use, and disclose your personal information with your consent, except where PIPA permits or requires otherwise, including where collection is necessary to investigate a breach of an agreement or a contravention of law, or where it is in someone's interests and consent cannot be obtained in a timely way. By creating an account and using Cornr you give express consent for the purposes described here. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice, by contacting our Privacy Officer; withdrawing consent may mean we can no longer provide some or all of the service. Withdrawing consent does not require us to delete information we are obliged to keep, including a moderation record or a device restriction relating to a safety matter.

5. When we disclose personal information

  • Service providers: Supabase (database, authentication, and file storage), Apple (sign-in, in-app purchase, and push notification delivery), Anthropic (the artificial intelligence service behind Ember and post classification, called only from our servers and never given your payment details), Stripe (payments), and Netlify (website hosting and contact-form delivery). They process personal information only on our instructions and under contractual obligations to protect it, and none of them is permitted to use it for their own purposes.
  • Other users, by your choice: what you post in a cornr, your profile, your profile photograph and banner, your chosen interests, your Cubes score on a leaderboard, your reviews, and a host's public card are visible to others as an intended function of the service.
  • A business you review, which sees the review and, unless you posted anonymously, the display name attached to it.
  • Legal and safety reasons: where required or permitted by law, to respond to a lawful request from a court, regulator, or law enforcement agency, to investigate a breach of our Terms, or to protect the rights, safety, or property of you, us, or others. Content that sexually exploits a minor is reported to the authorities without exception.
  • Business transactions: in connection with a merger, acquisition, financing, or sale of assets, in accordance with PIPA's rules for such transactions.

We do not tell a person who reported them. A report is between you and the moderator.

6. Storage outside Canada

Our service providers, including Supabase, Apple, Anthropic, Stripe, and Netlify, store and process personal information on servers located in the United States. Your personal information may therefore be stored or processed outside Canada and may be accessible to courts, law enforcement, and regulatory authorities in those jurisdictions under their laws. We require our providers to protect personal information with safeguards comparable to those required under PIPA. By using Cornr you acknowledge this cross-border storage and processing. If you have questions about where your information is stored, contact our Privacy Officer.

7. How we protect your information

We make reasonable security arrangements to protect personal information against unauthorized access, collection, use, disclosure, copying, modification, or disposal. These include hashed passwords, encryption in transit, row-level security policies on every table in our database so that a query can only ever return what the person asking is entitled to see, moderation tables that nothing outside our server functions can read, and limiting administrative access to the people who need it. No system can be guaranteed perfectly secure, and you share information with other users at your own risk, but we work to protect your information in proportion to its sensitivity.

Breach response: if a privacy breach occurs that creates a real risk of significant harm to you, we will notify you and, where required, the applicable Privacy Commissioner, without unreasonable delay, and we keep records of breaches as required by law.

8. Children

Cornr is intended only for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18. If we learn that we have, we delete it and close the account. If you believe a child is using Cornr, report the account in the app or write to our Privacy Officer.

9. Cookies and analytics

The Cornr app contains no third-party analytics or advertising software development kits. This website uses essential cookies, set by Supabase, to keep you signed in to the business portal and the moderation area. These cannot be turned off through our site because they are what signing in means. We do not currently set advertising cookies. If that ever changes we will ask for your consent first, and declining will not cost you access to anything that matters. Because we do not track you across sites, there is nothing for a Do Not Track or Global Privacy Control signal to switch off.

The Ko-fi support widget on this site is loaded from Ko-fi and is subject to their privacy policy.

10. How long we keep your information

We keep personal information only as long as necessary for the purposes it was collected for, or as required by law.

  • Talk clears itself 24 hours after the last reply.
  • Posts expire after a day, or seven days for a bulletin notice.
  • Private messages and reviews stay until you or the other party delete them, or until your account is deleted.
  • Device records are kept while the account is active and for a reasonable period afterwards, so that a closed account cannot immediately return.
  • Moderation records, including a copy of removed content and the address of a reported image, are kept while they remain useful for handling an appeal or recognising repeat behaviour, and then destroyed.
  • Device restrictions are kept until they are lifted, or until the reason for them no longer applies.
  • Transaction records are kept as long as tax and accounting law requires.
  • PIPA requires us to keep personal information used to make a decision about you for at least one year after that decision, so you have time to ask for it.

When retention is no longer required, we securely destroy or de-identify the information.

11. Deleting your account

You can delete your account from inside the app. Profile, then Settings, then Delete my account. You do not need to email us and there is no waiting period. Deleting your account removes your profile, your photographs, your posts and comments, your talk, your private messages, your interests, your Cubes scores, your reviews, and your device tokens.

Four things survive, and it is fair that you know which: content other people have already received a copy of, transaction records we are legally obliged to keep, any moderation record relating to a safety matter, and any device restriction. The last two are kept so that an account closed for harming somebody cannot be reopened by deleting it and starting again.

12. Your rights

Under PIPA, you have the right to:

  • Access the personal information we hold about you, and receive an account of how it has been used and to whom it has been disclosed;
  • Correct personal information that is inaccurate or incomplete;
  • Withdraw consent, subject to legal or contractual limits;
  • Ask questions or make a complaint about our handling of your information.

To exercise any of these, contact our Privacy Officer at founder@northaxis.holdings. We respond within the time PIPA requires, generally 30 days. We may need to verify your identity first. There is generally no fee to access your own information, though PIPA permits a minimal fee for certain requests, of which we would notify you in advance. An access request will not reveal the identity of somebody who reported you, and we may withhold information where PIPA allows or requires us to, including where disclosing it would reveal personal information about someone else or would compromise an investigation.

13. Changes to this policy

We may update this policy from time to time. When we make material changes we will update the "Last updated" date above and notify you in the app before they take effect. Your continued use after a change takes effect means you accept the updated policy.

14. How to make a complaint

If you have a privacy concern, contact our Privacy Officer first so we can try to resolve it. If you are not satisfied with our response, you may contact the Office of the Information and Privacy Commissioner for British Columbia, or, for matters under federal jurisdiction, the Office of the Privacy Commissioner of Canada:

Office of the Information and Privacy Commissioner
for British Columbia

PO Box 9038, Stn. Prov. Govt.
Victoria, B.C. V8W 9A4
oipc.bc.ca

Office of the Privacy Commissioner of Canada
30 Victoria Street
Gatineau, Quebec K1A 1H3
priv.gc.ca

How Cornr Works For businesses About Us Contribute Contact Us Privacy Terms

Cornr™ © 2026. All Rights Reserved.
A product of North Axis Holdings, Inc.