Privacy Policy — Local Plus

Last updated: 7 September 2026 · Made by KiraVerse · support@kirazone.xyz

This policy is written to be read by a merchant, not by a lawyer. Where a sentence could be read two ways, the narrower reading is the one we mean.

The short version

Your sales stay on your phone. Everything the till does — recording sales, counting stock, working out your profit, refunds, expenses, reports — happens on your device and is stored there. We cannot see any of it. There is no server holding your takings.

Five things leave your phone, and only when you choose them:

  1. A report or backup you export and share. It goes wherever you send it, and nowhere else.
  2. An AI menu photo. If you ask for a picture to be made, the dish name goes to the image provider. If you ask for a photo you took to be fixed, that photograph goes to the image provider along with what you asked for. The result comes back and is stored in your account.
  3. A credit purchase. Google Play handles the payment; we are told only that a purchase happened.
  4. Connecting a second phone. If you link phones so an owner can see what staff are selling, a short summary of each sale is sent so the owner's phone can show it. This keeps sending after you set it up, so it has its own section below.
  5. Publishing a Local+ storefront. If you switch your shop on in Local+, your shop's name, its position on the map, and your menu — item names, selling prices and their photos — are put where customers can see them. That is the point of publishing, and it too has its own section below.

If you never use AI photos, never export, never connect a second phone and never publish a storefront, Local Plus sends nothing anywhere.

What we store, and where

On your phone only

WhatNotes
Products, prices, costs, recipes Costs and recipes never leave the device. Item names, selling prices and menu photos leave it in exactly one case: you publish a Local+ storefront, which puts your menu where customers can see it. See "Publishing a storefront".
Every sale, refund, void and expense Stays on the device, with two exceptions you choose. On a shop with connected phones, a short summary of each sale — amount, count, seller, time — is also sent so the owner can see it; refunds, voids and expenses are never sent. And if you are logged in, a copy of your whole shop is saved to your own account so you can get it back on a new phone — see "A copy in your account". Nobody but you can read it.
Stock levels and movementsNever leaves the device
Your settings — currency, exchange rate, language, business-day start Never leaves the device
Where your shop is Read once, only when you tap "Use my location" on the Local+ storefront screen, and stored on the device. If you publish your storefront, that stored position is part of what is published — a customer finds your shop by where it is. Unpublish and it is no longer served. Never read in the background, and never while you are not looking at that screen.
Photos you take with the camera Stay on the device — unless you ask for one to be fixed with AI, which sends that photo. See below.
The menu boards you design Never leave the device. The finished picture goes wherever you send it, and nothing else does — the dish names and prices on a board are never sent anywhere, even when the background under them was bought.

A note on location, because it is the one permission that sounds like tracking: this app asks for it at the moment you press the button that needs it, uses it to record a single point — where your shop is — and never asks again. There is no background location permission in the app at all, so it cannot follow you anywhere even if something went wrong. If you never set up a Local+ storefront, it is never asked for.

Android's automatic backup is switched off for this app, deliberately. Your trading history is not copied to the Google Drive of whoever owns the phone.

On our servers — only if you use AI photos or buy a board background

WhatWhy
An account identifierTo know whose credits are whose
Your email address Only if you create an account with one, sign in with Google, or sign in with Apple without hiding it. Used to sign you in and to send a password reset. Never used to advertise to you.
Your credit balance, when each pack was bought and when it expires Because a balance the phone controls is a balance anyone can edit
The AI photos you generatedSo you keep them if you change phone
The name of the dish each photo was for To generate the photo, and so you can find it again
A record of each generationSo you can see where a credit went
A photo you asked to have fixed It is sent to the image provider to be worked on, and the result is saved in place of it. The original is not kept on our servers as a separate copy.
The background you bought for a menu board So you keep it if you change phone. One per board: buying another replaces it.
What you asked that background to look like Either which of the ready-made ones you picked, or the words you typed. Nothing else about the board is sent — not your dish names, not your prices, not the layout.

On our servers — only if you publish a Local+ storefront or take orders

WhatWhy
Your published storefront: shop name, description, logo, position, and your menu — item names, selling prices, photos, availability So customers can find your shop and see what it sells. This is public — anyone using Local+ can read it. Unpublishing takes the shop out of discovery.
Each order a customer places: what they ordered, the amounts, and the name, phone number and address they typed So the order can reach you and you can fulfil it. Held on our servers, shown to you in the app. Your costs and margins are not part of an order — a customer never sees what anything cost you.

That is the complete list. Not your sales, not your profit, not your costs. Your selling prices are on our servers in exactly one case — a storefront you chose to publish, where they are the menu. What you paid, what you made, and your book of sales are in neither list, ever.

Your account

You can use the entire till with no account at all.

An account is needed only for credits, and for letting a second phone join the same shop. Local Plus can create an anonymous account — no name, no email, no phone number, just an identifier that says "this device's credits".

If you want those credits to survive a lost phone, you can turn that anonymous account into a real one, three ways:

Either way, your sales, prices, costs and customers stay on the phone. An account carries credits, not books.

Messages, reviews and reports on Local+

These three exist only on the Local+ side — the marketplace, where a customer orders from a shop. None of them touches the till. A phone that only sells, and never publishes a storefront, produces none of it.

It is also the one part of this policy written for the customer as much as for the merchant, because on Local+ each of them writes things the other one reads.

The conversation on an order

Once an order is placed, the customer and the shop can write to each other about it — "no ice", "I am at the door". Those messages are stored on our servers, because a server is the only way the other phone can read them. Both already have each other's name and phone number from the order itself, so the thread tells neither of them anything the order had not already.

A message cannot be edited or deleted once it is sent — not by either side, and not by us. It is the record of what was agreed about an order, and a record either side could rewrite would be worth less than no record at all.

Reviews

When an order is finished, the customer can rate the shop out of five and write a comment. The rating and the comment are stored on our servers and shown to that shop. The shop is never told who wrote them: no name, no phone number and no account identifier reaches the merchant. That is deliberate — a merchant who can see who complained is a merchant nobody complains to.

We do not write reviews and we do not edit them.

Reporting something

Either side can report a shop, a person, an order, or the conversation on one.

A report carries the account identifier of whoever sent it, what the report is about, the reason they picked from a fixed list, and anything they chose to type in their own words. It is read by one person: the owner of KiraVerse. The reported party is never told who reported them, and there is no reply — the app says so before the report is sent rather than after.

Blocking

Blocking a shop, or blocking a customer, is kept on that phone only and is never sent anywhere. Nobody is told they have been blocked, because there is nothing to tell: no list of who avoids whom exists on our side to be read, handed over, or lost. That has a cost and it is fair that you know it — a block does not travel to your other phone, and reinstalling the app clears it.

Delivery-order notifications

Not available in the current release. The description below is how the feature is built for when it ships, and it is kept here because a policy that appears after a feature does is a policy nobody re-reads. Today, the switch it describes does not exist on your phone, and nothing of the kind runs.

If you turn this on, Local Plus can see that a delivery app has posted a notification.

It reads which app posted it, and at what time. Nothing else. Not the title, not the message, not the customer's name, not the order, not the amount. This is enforced by how the feature is built, not by a promise: the notification's contents are never read, so there is nothing to store, send or lose.

That information stays on your phone and is used for one thing: showing you "an order arrived at 14:32 — record it?".

The feature is off until you switch it on in your phone's own settings, and you can switch it off there at any time.

Publishing a storefront

Nothing here happens unless you switch your shop on in Local+. An unpublished shop serves nothing, and that is how the app arrives.

Published means public. Your shop's name, description, logo, its position on the map, and your menu — item names, selling prices, photos, what is available — can be read by anyone using Local+. That is what a storefront is for, and it is why this section exists: everywhere else in this policy, prices staying private is the rule.

What is never part of it: your costs, your margins, your recipes, your stock levels, your sales history, your expenses, your staff. A customer sees a menu, not a book.

Orders. When a customer orders, they type a name, a phone number and — for delivery — an address. That reaches our servers and your phone, because you have to fulfil the order. It is theirs: if they delete their account, their name, number and address are stripped out of the order while your record of the sale itself stays.

Turning it off. Unpublish from the storefront screen. The shop leaves discovery immediately. Deleting your account removes the storefront and its orders entirely.

Connecting a second phone

This section exists because it is the only part of Local Plus that keeps sending after you set it up, and because the rest of this policy would be misleading without it.

Nothing here happens unless you connect phones. An unlinked shop sends nothing, and that is how the app arrives.

What is sent when phones are linked

WhatWhen
Your shop's nameOnce, when you create the link
A staff member's name and role When you make an invite code for them
For each sale: the amount, the currency, how many items, who sold it, and the timeAs it happens

What is not sent, ever

What you sold. Your costs, your margins or your profit. Your stock. Your expenses. Your reports. Your photos. Anything about your customers. The owner's phone shows a running feed of sales — an amount, a seller and a time — and nothing underneath it.

Turning it off. Disconnect the phone, or revoke it from the owner's Connected phones list. Sales stop being sent immediately. What was already sent stays until it is deleted; ask us and we will delete it.

One deliberate behaviour worth naming: if the owner revokes a phone while it is mid-shift, that phone keeps selling normally and its sales simply stop appearing in the owner's feed. The till never refuses a customer because of something the owner did an hour ago, and the sale is still recorded in full on the phone that made it.

Verifying a store

Before a shop is shown to customers on Local Plus, a person at KiraVerse checks who is behind it. This is optional in exactly the sense that publishing is: you only meet it if you ask for your store to be verified.

What you send. Four photographs and a few details: the front of a government ID, a photo of your face holding that ID, your shopfront, the inside of your shop; your full name as on the ID, a phone number, the shop's address, the pin you already placed on the map, and — if you have one — a business registration number.

Who sees it. The photographs and details go to our servers and are shown to one person: the owner of KiraVerse, who reviews them by eye. No automated face matching is performed, and nothing is sent to any third-party identity service. Customers never see any of it; they see a "verified" mark on your shop, and nothing else.

What we do not keep. We do not store your ID number as text — the photograph is the record. We keep the photographs and details for as long as your store is verified, so a later question about the shop can be answered.

Turning it off. Deleting your account deletes the photographs, the details and the verification record with it. Ask by email if you want a verification withdrawn without deleting the account.

Who else receives anything

WhoWhat they getWhen
Google Firebase Your account identifier, your email address if you gave one, your credit records, your generated photos Only if you make an account or use AI photos
Google Firebase Your shop's name, your staff members' names and roles, and a summary of each sale — amount, count, seller, time Only if you connect a second phone
Google Firebase Your published storefront — shop name, position, menu with prices and photos — and each order's contents, with the name, phone number and address the customer typed Only if you publish a Local+ storefront / take orders through it
Google Firebase Your store verification — the four photographs and the details you typed Only if you ask for your store to be verified
Anyone using Local+ Your published storefront, exactly as above. It is public by design Only while your shop is published
The other phones on your shop The owner sees the sale summaries above. A staff phone sees only its own shop name and role Only if you connect a second phone
The person on the other end of an order What you write in the thread on that order Only while an order is open between you
A shop you ordered from Your rating out of five and any comment you wrote, with nothing that says who you are Only after you review a finished order
The owner of KiraVerse A report: who sent it, what it is about, the reason, and anything they typed. Nobody else can read one Only when somebody reports something
The AI image provider (fal.ai) The name of the dish you asked for a picture of, or — if you are fixing a photo — that photo Only when you press generate or fix
Google (sign-in) That you signed in to Local Plus, and your email address Only if you choose to sign in with Google
Apple (sign-in) That you signed in to Local Plus Only if you choose Sign in with Apple
Google Play The purchase itself. We never see your card Only when you buy credits
Whoever you send an export to Whatever is in that file Only when you export and share it

We do not sell your data. We do not share it for advertising. There is no analytics or tracking SDK in this app.

Children

Local Plus is a tool for running a business and is not directed at children.

Your choices

Changes

If this policy changes in a way that affects what leaves your phone, the app will tell you in the app before the change takes effect — not only here.

A note on what "we cannot see it" means

It is the ordinary meaning. Your sales are written to a database file inside the app's private storage on your own device. No copy of that file is sent anywhere, no key is held by us, and there is no mechanism by which we could request one.

One precision, because a policy that is nearly true is worse than one that is plain: if you have connected a second phone, the sale summaries described above do reach Firebase, because that is the only way the owner's phone can show them. That is a few numbers per sale and a seller's name. Your book — what you sold, what it cost you, what you made, your stock, your expenses — is still only on your device, and is still not something we can read. If your phone is lost, we still cannot help you — there is nothing on our side to restore from. That is the trade this design makes on purpose, and it is why the backup exists and why it is yours to keep: the file is the only copy there will ever be, and where it lives is your decision rather than ours.