Thousands are already on board.

Join the movement
Skip to content

Legal

Privacy Policy

Last updated: 21 September 2026

This Privacy Policy is the single privacy notice for Civicore. It describes how we collect, use, store, share, and otherwise process personal data when you use:

  • the marketing website at civicore.co.ke (the "Marketing Site");
  • the web application at app.civicore.co.ke (the "Application"); and
  • the mobile applications published as Civicore: Kenya Campaigns on Google Play and the Apple App Store (application ID ke.co.civicore.app) (the "Mobile Apps").

Together, those surfaces and related APIs, public profiles, documentation, in-app browsers, and support channels are the "Platform". There is no separate privacy notice for the Application or the Mobile Apps. Sign-up, sign-in, billing, and onboarding screens, including those opened from a Mobile App in an in-app browser, are covered here.

This policy is intended to align with the Kenya Data Protection Act, 2019 ("KDPA") and the Data Protection (General) Regulations, 2021. It should be read with the Terms of Service, the Cookie Policy, and the Child Safety Standards.

Contents

  1. Who we are
  2. Scope: the three surfaces this policy covers
  3. Lawful bases under the KDPA
  4. Categories of personal data we collect
  5. How we use personal data
  6. Mobile Apps: permissions and device data
  7. Cookies and similar technologies
  8. Sharing and processors
  9. International transfers
  10. Retention
  11. Security
  12. Children
  13. Public profiles, pledges, and manifesto records
  14. Automated processing and AI
  15. Your rights under the KDPA
  16. Account deletion
  17. Complaints
  18. Changes
  19. Contact

1. Who we are

Civicore ("we", "us", or "our") is an independent civic-tech platform operating in the Republic of Kenya. For the purposes of the KDPA, Civicore is the data controller of personal data processed through the Platform. We are not affiliated with any political party, the Independent Electoral and Boundaries Commission, or any government body.

Privacy enquiries: privacy@civicore.co.ke. Security: security@civicore.co.ke. General: hello@civicore.co.ke.

2. Scope: the three surfaces this policy covers

This policy applies whenever personal data is processed in connection with:

  • Marketing Site. Browsing, contact and demo forms, donations initiated from Civicore pages, documentation, and legal pages.
  • Application. Account creation and Clerk sign-in (email, Google, or Apple), role onboarding, public and private profiles, manifesto publishing, campaign operations, volunteer tools, internal messaging, live sessions, billing, and analytics dashboards.
  • Mobile Apps. Guest browsing of the aspirant directory; signed-in feeds, posts, stories, comments, reporting, live audio/video, optional push notifications, crash diagnostics, and any in-app browser opened onto the Application or Marketing Site for registration, billing, or legal documents.

A Civicore account is shared across the Application and the Mobile Apps. Data collected on one surface may be used on another to provide the same account, content, and security controls. Guest use of a Mobile App without an account is still processing under this policy, typically limited to device, diagnostics, and content you choose to view.

This policy does not govern websites, apps, or payment pages of third parties that we link to (for example a Paystack checkout page). Their notices apply once you leave the Platform.

3. Lawful bases under the KDPA

We process personal data only where a lawful basis in the KDPA applies. Depending on the activity, that is one or more of:

  • Consent — for optional marketing messages, optional push notifications, optional device permissions (camera, microphone, photos), and non-essential analytics where we ask.
  • Performance of a contract — to create and run your account, provide Platform features you request, process billing, and perform the Terms of Service, including Aspirant Public Commitments.
  • Legitimate interests — to secure the Platform, prevent abuse, keep audit logs, measure aggregate use, and operate a civic-information service, where those interests are not overridden by your rights.
  • Legal obligation — tax, accounting, child-safety reporting, responding to lawful requests, and other duties under Kenyan law.
  • Public interest / journalistic and civic archiving — where the KDPA permits processing of information the data subject has made public, or processing for journalism, research, or public-interest archiving of Official Public Commitment Records, as described in the Terms of Service, Section 8.

Political opinions, party affiliation, and related campaign records can be sensitive personal data under section 2 of the KDPA. We process that data because it is necessary for Civicore's civic-tech service, because you (or your organisation) have provided it in connection with an account or a public profile, and, for published aspirant and party material, because you have made it public. We do not use sensitive political data to sell advertising.

4. Categories of personal data we collect

We practise data minimisation. What we collect depends on the surface and the role. We do not require an account to read the Marketing Site or, in the Mobile Apps, to browse public aspirant directory content as a guest.

4.1 All surfaces

  • Technical and security data — IP address, user agent or app version, device type, request metadata, approximate network location (not precise GPS), timestamps, and diagnostic logs. Used to deliver, secure, and debug the Platform.
  • Identifiers — account IDs, session tokens, and similar identifiers needed for authentication and abuse prevention.

4.2 Marketing Site

  • Contact-form submissions — full name, email, organisation, role, Kenyan phone number, message, and stated intent (for example a demo or partnership request).
  • Privacy-safe analytics — aggregate page views and Web Vitals via Vercel Analytics; no advertising cookies.
  • Donation records — if you donate via a Paystack link we publish, Paystack processes payment details as an independent controller or processor according to its notice. We may receive your name, email, amount, and payment status so we can acknowledge the gift.

4.3 Application (app.civicore.co.ke)

  • Account and authentication — name, email, phone where provided, profile photo, authentication credentials handled by Clerk, and Sign in with Google or Sign in with Apple identifiers those providers share with us.
  • Role and organisation data — role (aspirant, party administrator, campaign manager, coordinator, volunteer, civic organisation, citizen), party or campaign affiliation, and the electoral scope of that role (national, county, constituency, ward).
  • Aspirant and party public profiles — biography, office sought, region, manifesto, media gallery, social links, verification status, and peace-pledge acceptance.
  • Campaign operations — tasks, events, volunteer assignments, internal messages, broadcasts, and related audit events.
  • User-generated content — posts, stories, comments, reports, live-session questions and chat, and media you upload.
  • Billing — plan, payment status, and related invoices processed through Paystack. We do not store full card numbers on Civicore systems.
  • Product usage — feature use needed to operate dashboards (for example profile views and manifesto reads shown to an aspirant).

4.4 Mobile Apps

  • Everything in 4.3 that the Mobile Apps display or submit through the same Civicore account and APIs.
  • Photos you choose — when composing a post or story.
  • Camera and microphone — only when you join or host a live session, and only while the app is in the foreground for that session.
  • Push token — if you enable notifications (Firebase Cloud Messaging).
  • Diagnostics — crash and stability reports (Firebase Crashlytics), app version, and device model, used to keep the apps working.

We do not collect your contacts, precise background GPS, or advertising identifiers for third-party advertising. Electoral "near me" views use the county, constituency, or ward saved on a Civicore profile or in content, not covert location tracking.

4.5 Data we do not collect as a rule

  • Voter-register or IEBC register data.
  • Ballot choices.
  • Payment card PAN/CVV on our servers.
  • Data for sale to data brokers or political advertisers outside the Platform.

5. How we use personal data

We use personal data to:

  • provide, maintain, and improve the Platform across all three surfaces;
  • create and authenticate accounts, including via an in-app browser from a Mobile App;
  • show you public campaign information and, if you sign in, role-appropriate tools;
  • publish and archive profiles, pledges, and manifestos you choose to make public;
  • operate live sessions, comments, reports, and notifications you enable;
  • process fees and donations through Paystack;
  • respond to contact-form and support enquiries;
  • secure the Platform, rate-limit abuse, investigate reports, and keep audit logs;
  • comply with law, including child-safety reporting described in our Child Safety Standards;
  • measure aggregate performance (for example Web Vitals on the Marketing Site); and
  • communicate service notices, security alerts, and — only with consent — optional updates.

We do not sell personal data. We do not use personal data to train external foundation models. We do not serve third-party behavioural advertising on the Platform.

6. Mobile Apps: permissions and device data

The Mobile Apps are native clients of the same Platform. They are not a separate product with a separate privacy regime. In addition to Section 4.4:

  • Guest mode. You may open the Aspirants tab without an account. We still process technical, security, and diagnostics data, and any content you choose to view.
  • Registration. New accounts are created on the Application. The Mobile Apps may open app.civicore.co.ke in an in-app browser (Safari View Controller / Chrome Custom Tab). That session is Application processing under this policy, not a third party's site in the ordinary sense.
  • Permissions. Camera and microphone are requested for live sessions only. Photos are requested when you attach media. Notifications are optional. You can deny or later revoke a permission in system settings.
  • Background. The apps use remote-notification background mode for push delivery. Live audio/video runs in the foreground. We do not run background location tracking.
  • Store listings. Google Play Data safety and Apple Privacy Nutrition Labels must match this policy. If a given build disables Crashlytics or a similar SDK, the store labels will be updated for that build.

7. Cookies and similar technologies

See the Cookie Policy for the current list. In summary:

  • Marketing Site — theme preference in local storage; Vercel Analytics without advertising cookies.
  • Application — essential session, authentication, and security cookies or local storage required for Clerk sign-in and to keep you logged in.
  • Mobile Apps — local caches, auth tokens, optional push tokens, and diagnostics identifiers; not used to track you across third-party apps for advertising.

8. Sharing and processors

We do not sell personal data. We share it only with:

  • Service providers who process data on our instructions to operate the Platform, currently including Clerk (authentication), Supabase (database, file storage, realtime), Vercel (hosting and privacy-safe analytics), Resend (transactional email), Paystack (payments and donations), LiveKit Cloud (live audio/video transport), and Google Firebase (Cloud Messaging and Crashlytics for Mobile Apps). Sign in with Google and Sign in with Apple are operated by those providers when you choose them.
  • The public — when you publish a profile, manifesto, post, story, comment, or live session as public or follower-visible content. That is the nature of a civic campaign platform.
  • Your organisation — party administrators, campaign managers, and other Agents with scoped access may see data within their role, as described in the Terms. Party administrators can also see aggregate Civicore citizen registration counts by electoral area (county, constituency, and ward) for campaign planning. Those analytics are counts only and do not include names, contact details, or other personal identifiers of citizens.
  • Competent authorities — where we reasonably believe disclosure is required or permitted by law, including child-safety reporting, electoral-offence reports, or response to a lawful request. See also Terms of Service, Section 23.
  • Successors — if Civicore is transferred, personal data may transfer to the successor under this policy.

Processors are engaged under data-processing terms where the KDPA requires them. They may only use the data to provide their service to us, except where they are independent controllers (for example a store or a sign-in provider acting on their own notice when you use their button).

9. International transfers

Civicore is operated for Kenya. Some processors listed in Section 8 may store or access personal data outside Kenya (including in the United States or the European Union). Where that is a transfer under the KDPA, we rely on a lawful transfer mechanism, which may include the data subject's consent, performance of a contract, or appropriate safeguards such as contractual clauses and vendor security reviews. We do not transfer personal data to a country solely because it is convenient for advertising.

LiveKit transports audio and video for the duration of a session. Civicore keeps comments, questions, and moderation history on our own systems, not in the media vendor, except as needed to deliver the live stream.

10. Retention

We keep personal data only as long as needed for the purposes in this policy, including:

  • Contact-form submissions — 24 months after the last meaningful interaction, unless you ask us to delete sooner and no legal hold applies.
  • Server and security logs — typically 30 days, longer if needed to investigate an incident or abuse.
  • Account data — for the life of the account, then as needed to complete deletion, resolve disputes, or meet legal holds.
  • Billing and donation records — for the statutory accounting period in Kenya.
  • Audit logs of sensitive operations — for the relevant election cycle and a reasonable period afterward, so the Platform remains auditable.
  • Public profiles, Peace Pledges, and Manifesto Versions — in accordance with the Terms of Service, Section 8, including archival display after account closure where the KDPA allows journalism, research, legal claims, or public-interest archiving.
  • Crash diagnostics — for a short operational period needed to fix defects.

When we no longer need personal data, we delete or irreversibly anonymise it, except where the law requires or permits longer retention.

11. Security

We use administrative, technical, and organisational measures appropriate to a civic-tech platform, including TLS in transit, encryption at rest for primary datastores, scoped role-based access control, backend-enforced authorisation, and append-only audit events for sensitive operations. No method of transmission or storage is perfectly secure. Report suspected vulnerabilities to security@civicore.co.ke. Our public security posture is at Security & Trust.

If a personal-data breach is likely to affect your rights, we will notify you and the Office of the Data Protection Commissioner as the KDPA requires, aiming to inform affected customers within 72 hours of a confirmed incident where that timeline applies.

12. Children

The Platform is intended for persons 18 years or older and is not directed at children. We do not knowingly create accounts for children. If we learn that we have collected personal data from a child, we will delete the account data except where we must retain it for law enforcement or child-safety reporting. CSAE and CSAM are prohibited. See the Child Safety Standards. Report concerns to safety@civicore.co.ke and do not attach CSAM.

13. Public profiles, pledges, and manifesto records

If you publish an aspirant or party profile, a Peace Pledge, a manifesto, a post, or other public content, you are making that information public. Other users, journalists, and civic organisations may read, cite, and rely on it. The Terms of Service, Section 8, describe the Official Public Commitment Record, version history, and the limited interaction with the right to erasure. A request to erase an account does not automatically retract a manifesto version that was lawfully published, except as that section and the KDPA require.

14. Automated processing and AI

Civicore may use automated tools to summarise, surface, or flag content for human review. We do not use solely automated processing to produce a legal or similarly significant decision about you without a route to human review. We do not train external models on customer content. During the election-week protocol described in the Terms, generative and amplification features are restricted. You can read the public stance at Compliance.

15. Your rights under the KDPA

Subject to the KDPA and its exemptions, you have the right to:

  • be informed about the processing of your personal data;
  • access your personal data;
  • rectify inaccurate or incomplete personal data;
  • erase personal data in the circumstances the Act allows;
  • restrict processing;
  • data portability, where applicable;
  • object to processing based on legitimate interests; and
  • withdraw consent where processing is based on consent, without affecting prior lawful processing.

To exercise these rights, email privacy@civicore.co.ke from the address on your account where possible, and describe the request. We may need to verify your identity. We will respond within the time the KDPA requires. Some rights are limited where we must keep data for legal claims, security, child safety, journalism, or the public archival of Official Public Commitment Records.

16. Account deletion

You may delete a Civicore account from a Mobile App (Menu → Delete account, confirmed twice) or by writing to privacy@civicore.co.ke. Deletion calls our API to remove the Clerk user and to soft-delete the Civicore account. You do not need to email support first if the in-app flow completes.

Deletion ends access to private account features across the Application and the Mobile Apps. It does not by itself erase public Official Public Commitment Records already published, billing records we must keep, security logs still in cycle, or data we are required to retain. Guest device data is not an account; clearing the app or site data on your device removes local caches.

17. Complaints

Please contact privacy@civicore.co.ke first so we can try to resolve the issue. You also have the right to lodge a complaint with the Office of the Data Protection Commissioner in Kenya.

18. Changes

We may update this policy for the Marketing Site, the Application, and the Mobile Apps together. The "Last updated" date above is the current version. For a material change, we will take reasonable steps to notify registered users (for example by email or in-product notice). Continued use of any surface after the effective date is acceptance of the updated policy.

19. Contact

Privacy: privacy@civicore.co.ke. Security: security@civicore.co.ke. Child safety: safety@civicore.co.ke. Legal: legal@civicore.co.ke. General: hello@civicore.co.ke or the contact form.

Related documents