← Back to Cora
Legal

Privacy Policy

Last updated: 1 August 2026

1. Who we are

Cora is operated by Lumospark LLC, a limited liability company registered in Wyoming, USA (“Lumospark”, “we”, “us”). Lumospark is the data controller for the personal data described here.

Contact and data requests: hello@coramap.com

Cora is a taste-personalised venue-discovery service for restaurants, bars, and cafes in London and Copenhagen, available on iOS.

2. What we collect

You give us:

We collect automatically:

3. Location

With your permission, Cora uses your device’s precise (GPS-level) location while you are using the app, to show nearby venues and sort results by distance. When you run a search, your coordinates are sent to our backend to produce location-relevant results and are stored with the search record.

Background location — only if you book. If you tap through to book a table, Cora asks separately for “Always” location permission and sets a geofence around that one venue, so it can notice when you have been and offer to ask how it was. This is the only background use of your location: we do not follow you the rest of the time, and we do not detect visits to venues you have not booked. You can decline it, or revoke it later in iOS Settings, and every other part of the app keeps working.

You can decline or revoke location permission at any time in iOS Settings; Cora still works with manual city selection.

4. How we use your data and why

We do not sell your personal data, and we do not use it for third-party advertising.

5. What other people can see

Cora has social features. Please be aware:

6. Who we share data with

We use the following service providers, who process data on our behalf under contract:

7. International transfers

Our database is EU-hosted. Some providers above (OpenAI, Anthropic, Google, Vercel) are US-based, so some data is transferred to the United States. Where data is transferred outside the UK/EU, we rely on appropriate safeguards such as Standard Contractual Clauses.

8. Analytics and cookies

This app does not run third-party product-analytics SDKs or session recording on your device. We record usage and interaction data (§2) on our own servers to improve the service. Our marketing website uses only essential and functional cookies.

9. Storage, security, and retention

Data is stored in Supabase (PostgreSQL) in the EU with row-level security. Authentication uses OAuth 2.0 with PKCE. Avatars are stored with access controls and EXIF/GPS metadata is stripped on upload. All connections use HTTPS/TLS.

Retention:

10. Your rights

Depending on where you live (UK/EU GDPR and others), you may have the right to access, correct, export, delete, or object to the processing of your personal data, to withdraw consent, and to complain to a supervisory authority (in the UK, the ICO; in Denmark, Datatilsynet).

11. Children

Cora is not directed at children under 13, and we do not knowingly collect data from them.

12. Changes

We may update this policy. Material changes will be communicated in the app, and the “last updated” date will change.

13. Contact

Lumospark LLC — hello@coramap.com