App Usage Policy
A practical guide to accounts, permissions, posting, messages, live features, and responsible use of Kronop.
This policy follows the user-facing flows present in Kronop's application: sign-in, profiles, social content, messaging, permissions, reporting, and account controls. Availability and behavior can vary by app build; the current in-app screens govern feature-specific steps.
Scope and product availability
This guide applies when you access Kronop through a supported application build or an officially provided web experience. It explains current user-facing flows, not a guarantee that every listed function is available to every account.
The application contains modules for photos, video, Reels, Stories, live, music, notes, questions and answers, groups, marketplace, profiles, search, notifications, chat, and an AI assistant. Use only the controls displayed and enabled in your current version.
- Do not bypass feature restrictions, access controls, or account security checks.
- Feature names and locations may change between releases.
- Do not assume a feature is active merely because a package or source module exists.
Create and access an account
The app includes email one-time-code and password sign-in flows and a Google OAuth path. An Apple-branded sign-in screen is present, but the complete Apple provider exchange must be verified before the service is described as active.
Provide information you are authorized to use, keep recovery channels current, and use only one account unless the product's rules permit otherwise. A birth-date field appears in onboarding; the code review does not establish an age-eligibility check.
- Do not share passwords, one-time codes, access tokens, or recovery links.
- Use account recovery through the app's official sign-in flow.
- Report suspected unauthorized access promptly through the verified support route.
Complete and manage a profile
Profile functionality includes a username, display name, biography, profile and cover media, optional social links, and relationship or post counts. Onboarding asks for additional fields including phone number, date of birth, gender, address, country, and an optional profile image flow.
Some onboarding values are submitted to a profile endpoint, but the reviewed request path does not prove that every field is stored successfully in production. Only provide optional details when you understand why the current screen requests them.
- Choose a username and profile details that do not impersonate another person.
- Do not place private credentials or sensitive personal information in a public biography.
- Use profile controls to update or limit visible details where the current build offers them.
Permissions and device controls
The app permission screen requests camera, microphone, photos/media, foreground location, and notifications. The app explains that camera and microphone support capture or live features, photo access supports selecting uploads, location supports location features, and notifications provide app or chat notices.
Permission status is checked and, for signed-in accounts, written to a device-permissions record. The operating system controls the actual grant; Kronop cannot revoke a permission from its own interface and directs users to device settings.
- Grant only the access needed for features you choose to use.
- You can deny optional permissions and continue using other app features where available.
- Change or revoke permission in Android or iOS settings; the app may update its recorded status when reopened.
Location use
The onboarding form can request foreground location, read a current position, reverse-geocode it into an address, and populate address and country fields. Some upload forms separately accept a location label entered by the user.
The code review does not establish continuous background location tracking. A location field or label can still reveal where a person lives, works, or created content, so inspect it before submitting.
- Use the location permission only when you want to use an associated feature.
- Remove or edit a location label before posting if it is not appropriate for the audience.
- Revoke device location access through system settings when you no longer want to grant it.
Create, upload, and share content
Creation flows include selecting or capturing images, video, audio, stories, live content, notes, questions, group material, and marketplace listings. Uploads can include text, a title or caption, category, tags, media, and a user-supplied location depending on the feature.
Media uploads use authenticated signing requests to obtain time-limited storage URLs. A successful post may also create a database record referencing the uploaded media. Access, removal, and expiration behavior depend on the feature and production storage configuration.
- Check the media, caption, tags, audience, and location before publishing.
- Upload content you own or have permission to share.
- Do not assume deleting a database record immediately removes every stored media object or copy.
Stories, Reels, video, and live
Stories include viewing, reactions, comments, views, and an expiry field in the current code. Reels and videos include feeds, playback, comments, and interaction paths. A stored expiry timestamp does not establish complete cleanup of files or copies.
Live flows request a session from a configured API and use a meeting identifier and participant token with a Cloudflare RealtimeKit/WebRTC integration. Live session metadata can include title, category, audience, optional location, and interaction preferences.
- Use camera and microphone controls intentionally before beginning a live session.
- Do not show other people or private surroundings without appropriate permission.
- Review the current audience and live controls before sharing sensitive material.
Chat and social interactions
Direct chat supports text and media message types and stores message identifiers, sender and receiver identifiers, message content, type, delivery status, and timestamps in the configured data service. Realtime subscriptions support message and presence updates.
Chat preferences include online status, last-seen visibility, read receipts, typing indicator, message preview, auto-delete, screenshot alert, and ghost mode. A visible preference does not prove that all clients enforce it or that it prevents screenshots or recipient copies.
- Send messages only to intended recipients and do not transmit credentials or high-risk secrets.
- Respect blocks and privacy choices; do not use alternate accounts to evade them.
- The reviewed message service does not demonstrate end-to-end encryption; do not assume messages are inaccessible to service infrastructure.
AI and voice tools
The AI assistant uses a local on-device model runtime for text completion. The model file is downloaded to app storage from a model-hosting endpoint; conversation text in the reviewed service is passed to local inference rather than a Kronop AI server.
Voice input can invoke operating-system speech recognition and spoken output can use the device speech API. System speech services may process voice according to device settings and provider terms.
- Do not use AI output as professional, emergency, medical, legal, or financial advice.
- Avoid entering sensitive personal information into an assistant conversation.
- Delete the app or its stored files using device controls if you no longer want a downloaded model on that device.
Reports, blocking, and privacy controls
User and content reporting can include a reason, description, content location, and optional screenshots. The report record starts with a pending status. Blocking and private-account screens provide controls for limiting interactions and audience.
A report is not a promise of a specific decision or review time. Privacy switches and blocking can affect intended app behavior but cannot prevent all off-platform contact, saved copies, or device-level captures.
- Report a specific account or content through the relevant in-app option.
- Use blocking and privacy settings to reduce unwanted interaction.
- For immediate danger, contact local emergency services rather than relying on an in-app report.
Notifications and account security
In-app notifications can contain a title, message body, type, status, route, content identifier, and timestamp. The app has code to register push identifiers, while delivery can depend on configured provider services and the production build.
Notification previews can expose message text on a locked screen. Use app and operating-system settings to choose whether previews and notifications appear.
- Protect your device and sign out on shared devices.
- Review notification privacy settings before enabling message previews.
- Treat unsolicited requests for codes, credentials, or payment as suspicious.
Respectful and lawful use
Use Kronop lawfully, respect intellectual property and privacy, and follow the Terms of Service and Content Policy. Do not automate scraping, manipulate engagement, interfere with app availability, or access another user's account or data.
The reviewed code does not define a complete product availability, moderation, or appeal service level. Follow notices presented in the app and use official support for account-specific issues.
- Do not upload malware, scams, unlawful material, or deceptive listings.
- Do not attempt to bypass signed-media access or API authorization.
- Do not misrepresent a feature's availability or imply that Kronop guarantees outcomes.
Account deletion and unresolved behavior
The app includes a Delete Account action that invokes a function to delete the authenticated Supabase user and then attempts to sign out. The reviewed function does not visibly clean every related profile, content, chat, report, notification, database, or object-storage record.
Use the Account Deletion Policy for the precise limitation. BALYX must test and document all deletion paths before promising full erasure or a completion deadline.
- Uninstalling the app is not equivalent to submitting an account deletion request.
- A feature-level deletion may have a different result from account deletion.
- Request scope information through the verified privacy contact.
Support and policy updates
Use the in-app controls for supported settings and reports. For support, privacy, or security questions, use only a contact channel verified by Kronop and linked from the Trust Center.
This guide is an implementation-based draft. Production providers, feature availability, user age requirements, geographic coverage, and operational response commitments must be verified before final publication.
- Keep the app updated and review policy notices when they change.
- Provide only the minimum information needed to resolve a support request.
- Report suspected security issues responsibly through the verified route.
What you can do
- Use only accounts and permissions you are authorized to use.
- Review audience and location choices before publishing.
- Keep your credentials private and report suspected account misuse.
Need help?
If this page does not answer your question, visit the Help Center or contact Support. For a safety concern, use the reporting route that best matches the issue.