Skip to main content
Nkosoɔ Nkosoɔ
  • Home
  • Privacy
  • Delete Account
  • Crevion Commons

Nkosoɔ Privacy Policy

What we hold about you, what we cannot see, how long we keep things, and what you can do about it.

Last updated: 30 August 2026

Nkosoɔ is made by Crevion Commons LLC. This policy explains what we hold about you, what we cannot see, how long we keep things, and what you can do about it.

We have tried to write it in plain language and to state the awkward parts rather than bury them. Where something we do is more limited than you might assume, we say so.


1. The short version

Your work stays on your device. Projects, tasks, dependencies, comments, progress, retrospectives, insights, risk alerts and everything the AI assistant does live in a database on your phone — not on our servers.

When you share work with a teammate, we cannot read it. It is encrypted on your device and decrypted on theirs. The key that opens it is held only by member devices and is never sent to us.

The AI runs on your phone. Nothing you ask it, and nothing it answers, is transmitted anywhere.

There is no tracking. No analytics, no crash reporting, no advertising identifier, no ad network, no data broker. The app sends us no usage information at all. We do not sell your data and we do not share it for advertising.

Two things are less absolute than the above, and we would rather you hear them from us:

  1. Your team's name is stored on our servers in plain text. It is the one thing you type that we can read.
  2. While a change is on its way to a teammate who is offline, the sealed package rests on our servers for up to 48 hours. We cannot open it, but it does pass through and sit on infrastructure we control.

2. Who we are

Crevion Commons LLC, a Maryland limited liability company, makes Nkosoɔ and operates the relay server the app talks to. For the purposes of data-protection law we are the data controller for the information described in this policy.

  • Email: support@crevioncommons.com
  • Postal address: 2211 Saint Josephs Dr., Mitchellville, MD 20721, USA

3. What we hold about your account

Your email address and display name. These are held by Firebase Authentication, a Google service acting as our processor. Your display name is what your teammates see on the team roster.

If you sign in with Apple and use Hide My Email, we only ever receive the private relay address Apple generates. We never see your real address.

Our own relay server never receives your email address or your name. It sees only an account identifier.

Your password, if you use email sign-in, goes to Firebase Authentication and never reaches our relay. We never see it.


4. What we hold about your devices

For each device you sign in on, our relay stores:

  • your account identifier;
  • a device identifier generated by the app itself — a random value created on first run;
  • a public encryption key, so your teammates' devices can address encrypted work to yours;
  • a push notification token, so we can wake the app to fetch new work;
  • whether your subscription is active.

We do not read any identifier your operating system assigns. No advertising ID, no IDFA, no IDFV, no Android ID, no serial number. Nothing in Nkosoɔ reads them, and there is no App Tracking Transparency prompt because there is nothing to track with.


5. What we hold about your teams

  • the team's name, in plain text (see section 1);
  • who owns it, who its members are, and each member's role;
  • which devices each member uses, and their public keys;
  • when people joined.

This is what lets your teammates' devices find each other and address encrypted work to one another. It is metadata about the team, not the team's work.

Invitations are stored until used, and for at most seven days.

Removal notices — a record that a member was removed from a team, so their device knows to erase its copy — are kept for at most 30 days after the device confirms it acted on them.


6. Your project content, and the one time it touches our servers

Project content is encrypted on the device that creates it and decrypted only on your teammates' devices. The encryption key is shared between member devices and never sent to us.

While a change is on its way to a teammate who is offline, the sealed package waits on our relay and is deleted after 48 hours. We cannot open it. We disclose this because your content does rest, briefly and unreadably, on infrastructure we control.

The AI assistant is entirely on-device. Prompts, answers, and everything it reads from your projects never leave your phone. The app keeps a local record of each assistant run for your own audit — a one-way fingerprint and a short summary, stored on your device only and never transmitted.

Backups you export are encrypted with a passphrase you choose, on your device, before they are written. We never receive them, and we cannot open them. Where the file goes after you export it is your choice, made in your operating system's share sheet. If you lose the passphrase, nobody — including us — can recover the backup.


7. Subscriptions

If you subscribe, the App Store or Google Play handles the payment. We never see your card details.

We keep a record of which plan is active and when it expires, so the app can unlock the right features. We verify the store's receipt and keep only a one-way fingerprint of it — never the receipt itself, because a store receipt is a durable identifier and keeping one would put exactly the kind of cross-app identifier in our database that this product is built to avoid.


8. How long we keep things

Data retention periods
WhatHow long
Sealed content in transit48 hours
Invitations7 days
Removal notices, after they are acted on30 days
Off-app deletion requests90 days, stored as a one-way fingerprint of the address rather than the address itself
Your account, device and team recordsretention period pending product decision — for as long as your account exists, today
Subscription recordsFor as long as your account exists. If a subscription lapses or is cancelled, we keep the record for 15 additional days to resolve entitlement disputes, then delete it — sooner if you delete your account (section 11)

Server diagnostic logs expire on their own schedule and are not searchable by account.


9. Who else sees any of this

Third parties and what they receive
WhoWhat they receiveWhy
Google — Firebase Authenticationyour email address, display name and sign-in credentialsto sign you in
Google Cloudeverything in sections 4–6it hosts our relay server and database
Google — Firebase Cloud Messagingyour push notification tokento wake the app when there is new work
Google Play / Appleyour payment details, handled entirely by themsubscriptions
Google Play / Applea request to download the AI model fileson-demand delivery of the assistant

No other party receives any Nkosoɔ data. There is no data broker relationship, no ad network, and no analytics vendor.

Our servers run in the United States (Google Cloud's us-central1 region). If you use Nkosoɔ from outside the United States, the information in sections 4 and 5 is transferred there.


10. What the app asks your phone for

On Android, Nkosoɔ requests internet access and permission to show notifications, and nothing else. On iOS it requests no special permissions at all.

It does not ask for your location, contacts, camera, microphone, photo library, calendar, health data or file storage, because it does not use them.


11. Deleting your account — and what deletion cannot do

You can delete your account from inside the app: Settings → Help & support is where to find guidance, and Settings → Delete account is the control. Deletion is immediate and cannot be undone.

If you cannot open the app, write to support@crevioncommons.com from the address your account uses, or use the request form. We will send a challenge to the address your account is registered under before erasing anything — otherwise anyone who knew your email address could have your account destroyed.

What deletion does: erases your account and every record of it on our servers, deletes your sign-in identity, and wipes the device you delete from — including offline work, encryption keys and local backups. If the app is interrupted part-way through, it finishes the erasure the next time it opens.

What deletion cannot do. Nkosoɔ works offline, which means every teammate holds a full copy of your shared team's data on their own device. That is what makes the app work without a connection, and it bounds what any deletion can promise:

  • Work you contributed to a team stays with that team. Tasks you created and comments you wrote remain in your teammates' copies. We have no mechanism to reach into someone else's device and remove them, and we will not claim one.
  • If you delete a team you own, every member's device is asked to erase its copy the next time they open the app. This is a cooperative request that our servers cannot enforce.
  • Your other devices are erased only when you delete from them, or when you uninstall.
  • Your subscription is not cancelled by deleting your account. Cancel it in your App Store or Google Play settings, or you will keep being charged.
  • The downloaded AI model files are managed by Google Play or the App Store, are shared with your operating system, and contain none of your data. Remove them by uninstalling the app.

12. Your choices

  • See and export your data. Settings → Backup & restore writes an encrypted copy of your work that you control.
  • Correct it. Your display name and project content are editable in the app at any time.
  • Delete it. Section 11.
  • Ask us anything. support@crevioncommons.com.

Depending on where you live, you may have additional rights over your personal information. Write to us at the address above and we will tell you what applies and how to exercise it.


13. Children

Nkosoɔ is a tool for organising work and is not directed at children. We do not knowingly collect information from anyone under 13. If you believe a child has created an account, write to support@crevioncommons.com and we will delete it.


14. Security

Project content is encrypted end to end using established public-key cryptography, and the keys that open it are stored in your device's secure keystore and never transmitted. All traffic between the app and our servers is encrypted in transit.

No system is perfectly secure, and we will not claim otherwise. What we can say precisely is what an attacker who compromised our servers would find: team names, account and device identifiers, public keys, and sealed packages they could not open.


15. Changes to this policy

If we change what we collect or how we use it, we will update this page and the date at the top of it before the change takes effect.


16. Governing law

This policy is governed by the laws of the State of Maryland, USA, without regard to its conflict-of-laws principles. Any dispute arising from this policy will be brought in the state or federal courts located in Maryland.


Nkosoɔ is made by Crevion Commons LLC. Questions about this policy: support@crevioncommons.com

Nkosoɔ
Nkosoɔ

Offline-first, on-device AI project management. A Crevion Commons product.

Nkosoɔ

  • Home
  • Privacy Policy
  • Delete Account

Crevion Commons

  • Main site
  • support@crevioncommons.com

© 2026 Crevion Commons LLC. All rights reserved.