Privacy Policy — Local Plus
Last updated: 7 September 2026 · Made by KiraVerse · support@kirazone.xyz
This policy is written to be read by a merchant, not by a lawyer. Where a sentence could be read two ways, the narrower reading is the one we mean.
The short version
Your sales stay on your phone. Everything the till does — recording sales, counting stock, working out your profit, refunds, expenses, reports — happens on your device and is stored there. We cannot see any of it. There is no server holding your takings.
Five things leave your phone, and only when you choose them:
- A report or backup you export and share. It goes wherever you send it, and nowhere else.
- An AI menu photo. If you ask for a picture to be made, the dish name goes to the image provider. If you ask for a photo you took to be fixed, that photograph goes to the image provider along with what you asked for. The result comes back and is stored in your account.
- A credit purchase. Google Play handles the payment; we are told only that a purchase happened.
- Connecting a second phone. If you link phones so an owner can see what staff are selling, a short summary of each sale is sent so the owner's phone can show it. This keeps sending after you set it up, so it has its own section below.
- Publishing a Local+ storefront. If you switch your shop on in Local+, your shop's name, its position on the map, and your menu — item names, selling prices and their photos — are put where customers can see them. That is the point of publishing, and it too has its own section below.
If you never use AI photos, never export, never connect a second phone and never publish a storefront, Local Plus sends nothing anywhere.
What we store, and where
On your phone only
| What | Notes |
|---|---|
| Products, prices, costs, recipes | Costs and recipes never leave the device. Item names, selling prices and menu photos leave it in exactly one case: you publish a Local+ storefront, which puts your menu where customers can see it. See "Publishing a storefront". |
| Every sale, refund, void and expense | Stays on the device, with two exceptions you choose. On a shop with connected phones, a short summary of each sale — amount, count, seller, time — is also sent so the owner can see it; refunds, voids and expenses are never sent. And if you are logged in, a copy of your whole shop is saved to your own account so you can get it back on a new phone — see "A copy in your account". Nobody but you can read it. |
| Stock levels and movements | Never leaves the device |
| Your settings — currency, exchange rate, language, business-day start | Never leaves the device |
| Where your shop is | Read once, only when you tap "Use my location" on the Local+ storefront screen, and stored on the device. If you publish your storefront, that stored position is part of what is published — a customer finds your shop by where it is. Unpublish and it is no longer served. Never read in the background, and never while you are not looking at that screen. |
| Photos you take with the camera | Stay on the device — unless you ask for one to be fixed with AI, which sends that photo. See below. |
| The menu boards you design | Never leave the device. The finished picture goes wherever you send it, and nothing else does — the dish names and prices on a board are never sent anywhere, even when the background under them was bought. |
A note on location, because it is the one permission that sounds like tracking: this app asks for it at the moment you press the button that needs it, uses it to record a single point — where your shop is — and never asks again. There is no background location permission in the app at all, so it cannot follow you anywhere even if something went wrong. If you never set up a Local+ storefront, it is never asked for.
Android's automatic backup is switched off for this app, deliberately. Your trading history is not copied to the Google Drive of whoever owns the phone.
On our servers — only if you use AI photos or buy a board background
| What | Why |
|---|---|
| An account identifier | To know whose credits are whose |
| Your email address | Only if you create an account with one, sign in with Google, or sign in with Apple without hiding it. Used to sign you in and to send a password reset. Never used to advertise to you. |
| Your credit balance, when each pack was bought and when it expires | Because a balance the phone controls is a balance anyone can edit |
| The AI photos you generated | So you keep them if you change phone |
| The name of the dish each photo was for | To generate the photo, and so you can find it again |
| A record of each generation | So you can see where a credit went |
| A photo you asked to have fixed | It is sent to the image provider to be worked on, and the result is saved in place of it. The original is not kept on our servers as a separate copy. |
| The background you bought for a menu board | So you keep it if you change phone. One per board: buying another replaces it. |
| What you asked that background to look like | Either which of the ready-made ones you picked, or the words you typed. Nothing else about the board is sent — not your dish names, not your prices, not the layout. |
On our servers — only if you publish a Local+ storefront or take orders
| What | Why |
|---|---|
| Your published storefront: shop name, description, logo, position, and your menu — item names, selling prices, photos, availability | So customers can find your shop and see what it sells. This is public — anyone using Local+ can read it. Unpublishing takes the shop out of discovery. |
| Each order a customer places: what they ordered, the amounts, and the name, phone number and address they typed | So the order can reach you and you can fulfil it. Held on our servers, shown to you in the app. Your costs and margins are not part of an order — a customer never sees what anything cost you. |
That is the complete list. Not your sales, not your profit, not your costs. Your selling prices are on our servers in exactly one case — a storefront you chose to publish, where they are the menu. What you paid, what you made, and your book of sales are in neither list, ever.
Your account
You can use the entire till with no account at all.
An account is needed only for credits, and for letting a second phone join the same shop. Local Plus can create an anonymous account — no name, no email, no phone number, just an identifier that says "this device's credits".
If you want those credits to survive a lost phone, you can turn that anonymous account into a real one, three ways:
- With an email address and a password. We then hold your email address, so we can send you a password-reset link if you ask for one.
- With your Google account. Google tells us your email address and an identifier, and Google knows you signed in to Local Plus. We ask for nothing else from your Google account — not your contacts, not your files, not your Drive.
- With Sign in with Apple. We then receive whatever Apple chooses to pass on — an identifier, and an email address unless you ask Apple to hide it.
Either way, your sales, prices, costs and customers stay on the phone. An account carries credits, not books.
Messages, reviews and reports on Local+
These three exist only on the Local+ side — the marketplace, where a customer orders from a shop. None of them touches the till. A phone that only sells, and never publishes a storefront, produces none of it.
It is also the one part of this policy written for the customer as much as for the merchant, because on Local+ each of them writes things the other one reads.
The conversation on an order
Once an order is placed, the customer and the shop can write to each other about it — "no ice", "I am at the door". Those messages are stored on our servers, because a server is the only way the other phone can read them. Both already have each other's name and phone number from the order itself, so the thread tells neither of them anything the order had not already.
A message cannot be edited or deleted once it is sent — not by either side, and not by us. It is the record of what was agreed about an order, and a record either side could rewrite would be worth less than no record at all.
Reviews
When an order is finished, the customer can rate the shop out of five and write a comment. The rating and the comment are stored on our servers and shown to that shop. The shop is never told who wrote them: no name, no phone number and no account identifier reaches the merchant. That is deliberate — a merchant who can see who complained is a merchant nobody complains to.
We do not write reviews and we do not edit them.
Reporting something
Either side can report a shop, a person, an order, or the conversation on one.
A report carries the account identifier of whoever sent it, what the report is about, the reason they picked from a fixed list, and anything they chose to type in their own words. It is read by one person: the owner of KiraVerse. The reported party is never told who reported them, and there is no reply — the app says so before the report is sent rather than after.
Blocking
Blocking a shop, or blocking a customer, is kept on that phone only and is never sent anywhere. Nobody is told they have been blocked, because there is nothing to tell: no list of who avoids whom exists on our side to be read, handed over, or lost. That has a cost and it is fair that you know it — a block does not travel to your other phone, and reinstalling the app clears it.
Delivery-order notifications
Not available in the current release. The description below is how the feature is built for when it ships, and it is kept here because a policy that appears after a feature does is a policy nobody re-reads. Today, the switch it describes does not exist on your phone, and nothing of the kind runs.
If you turn this on, Local Plus can see that a delivery app has posted a notification.
It reads which app posted it, and at what time. Nothing else. Not the title, not the message, not the customer's name, not the order, not the amount. This is enforced by how the feature is built, not by a promise: the notification's contents are never read, so there is nothing to store, send or lose.
That information stays on your phone and is used for one thing: showing you "an order arrived at 14:32 — record it?".
The feature is off until you switch it on in your phone's own settings, and you can switch it off there at any time.
Publishing a storefront
Nothing here happens unless you switch your shop on in Local+. An unpublished shop serves nothing, and that is how the app arrives.
Published means public. Your shop's name, description, logo, its position on the map, and your menu — item names, selling prices, photos, what is available — can be read by anyone using Local+. That is what a storefront is for, and it is why this section exists: everywhere else in this policy, prices staying private is the rule.
What is never part of it: your costs, your margins, your recipes, your stock levels, your sales history, your expenses, your staff. A customer sees a menu, not a book.
Orders. When a customer orders, they type a name, a phone number and — for delivery — an address. That reaches our servers and your phone, because you have to fulfil the order. It is theirs: if they delete their account, their name, number and address are stripped out of the order while your record of the sale itself stays.
Turning it off. Unpublish from the storefront screen. The shop leaves discovery immediately. Deleting your account removes the storefront and its orders entirely.
Connecting a second phone
This section exists because it is the only part of Local Plus that keeps sending after you set it up, and because the rest of this policy would be misleading without it.
Nothing here happens unless you connect phones. An unlinked shop sends nothing, and that is how the app arrives.
What is sent when phones are linked
| What | When |
|---|---|
| Your shop's name | Once, when you create the link |
| A staff member's name and role | When you make an invite code for them |
| For each sale: the amount, the currency, how many items, who sold it, and the time | As it happens |
What is not sent, ever
What you sold. Your costs, your margins or your profit. Your stock. Your expenses. Your reports. Your photos. Anything about your customers. The owner's phone shows a running feed of sales — an amount, a seller and a time — and nothing underneath it.
Turning it off. Disconnect the phone, or revoke it from the owner's Connected phones list. Sales stop being sent immediately. What was already sent stays until it is deleted; ask us and we will delete it.
One deliberate behaviour worth naming: if the owner revokes a phone while it is mid-shift, that phone keeps selling normally and its sales simply stop appearing in the owner's feed. The till never refuses a customer because of something the owner did an hour ago, and the sale is still recorded in full on the phone that made it.
Verifying a store
Before a shop is shown to customers on Local Plus, a person at KiraVerse checks who is behind it. This is optional in exactly the sense that publishing is: you only meet it if you ask for your store to be verified.
What you send. Four photographs and a few details: the front of a government ID, a photo of your face holding that ID, your shopfront, the inside of your shop; your full name as on the ID, a phone number, the shop's address, the pin you already placed on the map, and — if you have one — a business registration number.
Who sees it. The photographs and details go to our servers and are shown to one person: the owner of KiraVerse, who reviews them by eye. No automated face matching is performed, and nothing is sent to any third-party identity service. Customers never see any of it; they see a "verified" mark on your shop, and nothing else.
What we do not keep. We do not store your ID number as text — the photograph is the record. We keep the photographs and details for as long as your store is verified, so a later question about the shop can be answered.
Turning it off. Deleting your account deletes the photographs, the details and the verification record with it. Ask by email if you want a verification withdrawn without deleting the account.
Who else receives anything
| Who | What they get | When |
|---|---|---|
| Google Firebase | Your account identifier, your email address if you gave one, your credit records, your generated photos | Only if you make an account or use AI photos |
| Google Firebase | Your shop's name, your staff members' names and roles, and a summary of each sale — amount, count, seller, time | Only if you connect a second phone |
| Google Firebase | Your published storefront — shop name, position, menu with prices and photos — and each order's contents, with the name, phone number and address the customer typed | Only if you publish a Local+ storefront / take orders through it |
| Google Firebase | Your store verification — the four photographs and the details you typed | Only if you ask for your store to be verified |
| Anyone using Local+ | Your published storefront, exactly as above. It is public by design | Only while your shop is published |
| The other phones on your shop | The owner sees the sale summaries above. A staff phone sees only its own shop name and role | Only if you connect a second phone |
| The person on the other end of an order | What you write in the thread on that order | Only while an order is open between you |
| A shop you ordered from | Your rating out of five and any comment you wrote, with nothing that says who you are | Only after you review a finished order |
| The owner of KiraVerse | A report: who sent it, what it is about, the reason, and anything they typed. Nobody else can read one | Only when somebody reports something |
| The AI image provider (fal.ai) | The name of the dish you asked for a picture of, or — if you are fixing a photo — that photo | Only when you press generate or fix |
| Google (sign-in) | That you signed in to Local Plus, and your email address | Only if you choose to sign in with Google |
| Apple (sign-in) | That you signed in to Local Plus | Only if you choose Sign in with Apple |
| Google Play | The purchase itself. We never see your card | Only when you buy credits |
| Whoever you send an export to | Whatever is in that file | Only when you export and share it |
We do not sell your data. We do not share it for advertising. There is no analytics or tracking SDK in this app.
Children
Local Plus is a tool for running a business and is not directed at children.
Your choices
- Use the till without an account. Everything except AI photos works.
- Delete your data on the phone by uninstalling, or by clearing the app's storage in Android settings. This is immediate and total; we cannot recover it for you, because we never had it.
- Delete your account and its data, from inside the app.
More → Account → Delete account. It removes your account, any credits you
have not spent, every photo the app generated for you, any storefront you
published, and any phones linked to your shop. It happens immediately and
cannot be undone, so spend your credits first if you have any.
Your shop stays on this phone. Your products, sales, costs, stock and staff are not part of your account, have never left the phone, and deleting the account does not touch them.
Orders you placed as a customer are the one thing that is changed rather than removed: the merchant keeps their record of the sale, and your name, phone number and address are stripped out of it. Destroying somebody else's sales record is not something your account deletion gets to do — and leaving your phone number behind is not something we get to do either.
If you would rather we did it, the address at the top still works.
- Save a backup. Reports → Safe keeping → Save a backup writes your whole shop to one file that this app can read back: items, sales, costs, stock, staff and hours. It is a plain, open, documented format. It never leaves the phone on its own — it goes only where you send it, and it carries no PINs in it, because those live in the phone's keystore and not in your records.
- A copy in your account. If you are logged in, the app
keeps one copy of your shop in your own account so a lost,
stolen or broken phone does not cost you your records. This is the only
thing in this app that sends your sales anywhere, and it happens
only while you are logged in — signing in is how you ask
for it. A guest account does not count and nothing is sent.
It is the same file "Save a backup" writes: items, sales, costs, stock, staff and hours, and no PINs. It carries no photographs. It is stored under your account and the rules on the server allow only that account to read it, write it or delete it — not another merchant, not somebody who is not logged in.
It is saved when you come back to the app, at most once every six hours, and only when something has changed. Reports → Safe keeping shows when it was last actually saved — never when it was last attempted.
To stop it: Remove the copy on that same screen takes it out of your account, and logging out stops anything further being sent. Deleting your account removes it with everything else.
- Export everything. The export produces a plain CSV of your own records. It is your data and the format is open. It is a report, not a backup — the app cannot read a CSV back in.
Changes
If this policy changes in a way that affects what leaves your phone, the app will tell you in the app before the change takes effect — not only here.
A note on what "we cannot see it" means
It is the ordinary meaning. Your sales are written to a database file inside the app's private storage on your own device. No copy of that file is sent anywhere, no key is held by us, and there is no mechanism by which we could request one.
One precision, because a policy that is nearly true is worse than one that is plain: if you have connected a second phone, the sale summaries described above do reach Firebase, because that is the only way the owner's phone can show them. That is a few numbers per sale and a seller's name. Your book — what you sold, what it cost you, what you made, your stock, your expenses — is still only on your device, and is still not something we can read. If your phone is lost, we still cannot help you — there is nothing on our side to restore from. That is the trade this design makes on purpose, and it is why the backup exists and why it is yours to keep: the file is the only copy there will ever be, and where it lives is your decision rather than ours.