Privacy · Kroma
What stays on your device.
This policy explains what Kroma and NexaraTech handle, why they handle it, where it goes, and what controls you have. Kroma is built around local creator work. This draft reflects the current app source.
01 · Operator
Know who handles your information.
NexaraTech is the brand used for this website and Kroma. The legal entity name, business address, privacy contact, and governing location are not confirmed in the reviewed source. They must be inserted before this policy is published as final legal notice.
Replace the missing operator details with registered business details. Do not publish this draft as final notice until that review is complete.
02 · Information handled
Data depends on what you choose.
Kroma can handle these categories for the purposes below:
- Local creator content: videos, images, files, URLs, captions, notes, tags, OCR text, transcripts, publishing records, platform selections, and related metadata. These support saving, organizing, searching, reviewing, exporting, and publishing.
- Connection data: platform account authorization, access or refresh data, and requested publish fields. These support account connection and publishing actions you start.
- Purchase data: purchase history and entitlement status received through Apple or the subscription entitlement service. Apple processes payment details.
- Diagnostic data: limited technical events when you enable diagnostic sharing. These support crash and workflow debugging.
- Support data: your email address, message, selected topic, and device or app details you choose to send. These support replies and privacy requests.
Information comes from you, your device, Apple, connected platforms, and service providers involved in requested features. Kroma does not use advertising identifiers or cross-context behavioral advertising in the reviewed source.
This website stores your light or dark theme choice in browser local storage. Reviewed website source shows no account sign-in, cookie-based analytics, advertising tracker, or website ticket database.
03 · Local app data
Creator content is stored locally.
Kroma stores its catalog in a local SwiftData store and stores media in local CreatorVault directories. Imported media files use AES-GCM encryption. The vault key uses device-only Keychain protection. The local store can contain plaintext metadata such as titles, notes, OCR text, transcripts, source URLs, and publishing records, protected by iOS file protection.
The reviewed source shows no NexaraTech database for the local catalog or private media. Kroma does not upload that local catalog or private media as part of ordinary local use. Device backups and operating-system services can have separate handling outside Kroma’s control.
Local storage does not stop data leaving the device when you publish, share, export, connect an account, import a remote URL, or use a system feature with its own provider.
04 · Platform connections
Connections run when you start them.
Kroma supports direct publishing to YouTube and LinkedIn when account permissions, network access, credentials, and platform state allow it. Kroma also prepares assisted sharing for TikTok, Instagram, X, and Facebook. Assisted sharing hands prepared content to a platform or system share surface. Kroma cannot confirm the final post there.
Account credentials and refresh data used by reviewed flows are stored in the device Keychain. OAuth exchange routes use provider client secrets server-side. Reviewed source shows no database-backed token storage. OAuth requests may still be processed by the exchange provider while the request runs.
A publish or share action can send selected media, caption, tags, and required fields to the platform you selected. That platform then acts as its own data controller under its own policy and terms.
05 · Diagnostics
Diagnostics are optional and off by default.
Kroma has a Privacy & Security setting for diagnostic sharing. If you enable it, Kroma may send limited error and workflow events to Sentry for crashes, failed imports, publishing, OAuth, transcription, transcoding, export, deletion, payment, and known action taps.
Payloads use closed event values and approved technical fields such as app version, build, OS version, platform, provider, reason, operation, product or entitlement identifier, result, and duration bucket. The reviewed source disables screenshots, view hierarchy, session replay, automatic breadcrumbs, network breadcrumbs, default personal data, stacktraces, request data, user data, and free-form error text.
Sentry retention depends on the configured Sentry account and provider terms. The website does not promise a fixed Sentry retention period. Diagnostic sharing can be turned off in Kroma settings.
06 · Sharing and providers
Limited providers support requested features.
NexaraTech may disclose information to providers only as needed for a requested feature, support, security, legal compliance, or business administration. Reviewed providers include Apple, RevenueCat, Sentry, OAuth exchange infrastructure, and connected publishing platforms. Providers process information under their own terms and privacy notices.
NexaraTech does not sell personal information or share it for cross-context behavioral advertising in the reviewed app source. Kroma does not use an advertising analytics SDK in the reviewed source.
Providers may process information outside your country. Exact provider locations, transfer mechanisms, and regional retention settings must be confirmed before final publication. NexaraTech may also disclose information when required by law, to protect rights or safety, or during a business transfer, subject to applicable law.
07 · Retention and deletion
Keep data only as long needed.
- Local app data remains until you delete it, clear it, or remove app data.
- OAuth exchange requests are not stored in a reviewed Kroma database.
- Sentry diagnostics follow configured provider retention.
- Apple and RevenueCat purchase records follow their provider retention.
- Support correspondence is kept only as needed for support, security, legal, and recordkeeping purposes. No fixed period is currently verified.
Deleting content in Kroma does not delete copies already sent to a platform, Apple, a provider, a recipient, or a device backup. Ask the relevant provider for deletion where that provider controls the copy.
08 · Privacy rights
Ask for access or control.
Depending on where you live, you may have rights to know what personal information is handled, access it, correct it, delete it, receive a portable copy, restrict or object to processing, withdraw consent, and complain to a privacy regulator. You may also have rights against certain automated decisions. Rights vary by region and may have legal limits.
Email a request to support@nexaratech.ca. We may ask for reasonable information to verify the request. Do not send private media, credentials, tokens, or account secrets. Requests are handled within timelines required by applicable law. The reviewed source does not show a separate privacy inbox or appointed data protection officer.
09 · Your controls
Use settings to manage local access.
- Delete saved clips, collections, variants, and publishing records.
- Disconnect connected platform accounts in Settings.
- Clear thumbnail or other local caches.
- Turn diagnostic sharing off at any time.
- Manage or cancel subscriptions through Apple account settings.
- Contact support about privacy questions or data concerns.
10 · Children
Kroma is not directed to children.
Kroma and this website are intended for general audiences and are not directed to children. Do not use Kroma to submit another person’s information without authority. If you believe a child provided personal information, contact support so the request can be reviewed under the law that applies.
Questions
Ask about data handling.
Contact support@nexaratech.ca. The website support form opens your email client. It does not create a website ticket record or send an automatic receipt.