CardsFeedHow it worksAbout
Legal

Privacy Policy

Effective date: 16 July 2026 · Last updated: 16 July 2026

1. Introduction

This Privacy Policy explains how Krooko (the website and social platform available at this address, operated by Alexandros Roussos) collects, uses, discloses and protects your personal data when you use it. Krooko is a free social platform that helps people find business and creative partners: members post "cards", share posts and stories, follow each other, chat and sign collab agreements.

We process personal data in accordance with the EU General Data Protection Regulation (GDPR), Greek Law 4624/2019, and other applicable Greek and EU law.

2. Data controller

  • Controller: Alexandros Roussos, operating Krooko as a private individual (no registered company)
  • Address: Mitropolitou Zerba 9, Kymi, Euboia, Greece
  • Country: Greece
  • Email: alexroussossm@gmail.com
  • Phone: +30 698 570 8063

3. Contact & Data Protection Officer

For all privacy questions, requests and support, contact alexroussossm@gmail.com or write to the postal address above. Given Krooko's size and the nature of its processing, a Data Protection Officer is not required and has not been appointed; the controller handles all privacy matters directly.

4. What personal data we collect

Account information

  • Email address and password (the password is stored only in hashed form — we never see or store it in plain text)
  • Username, display name, bio, profile picture
  • Your confirmation that you are 16 or older (we do not collect your date of birth)
  • Account settings: private-account status, theme choices, whether your collab track record is shown

We do not collect gender, phone numbers, postal addresses, government ID or verification documents, or payment details — Krooko is free and has no payments.

Content you create

  • Cards (title, description, category, tags, optional cover image)
  • Posts: text, photos, GIFs and video clips (max 10 seconds)
  • Stories (photo or text; they expire after 24 hours)
  • Comments, replies and likes (on posts, cards and comments)
  • Direct messages and group-chat messages, including photo messages
  • Collab agreements: their title and who signed, with timestamps

Social & activity data

  • Who you follow and who follows you
  • Users you block (visible only to you), chats you pin, cards you favourite (strictly private to you)
  • Group memberships and invitations
  • Notifications generated by activity (follows, likes, comments, replies, invites, friends' posts)
  • Reports you submit (type, reason, details)
  • Fair-use records: timestamps of card posts, reposts and username changes, used only to enforce the platform limits

Presence & device information

  • A "last seen" timestamp, refreshed roughly every minute while you have Krooko open, powering the online/last-seen indicator in chat
  • For each browser you sign in from: a random device identifier we generate, your browser's user-agent string (e.g. "Chrome · Windows"), and when it was last active — shown to you in Settings → "Where you're logged in"

Technical data

Our own code does not record your IP address. However, the infrastructure we run on (Supabase) and the content-delivery networks that serve fonts and scripts necessarily see your IP address and standard request data in their server logs, as every website's infrastructure does. We do not use these logs to profile you.

Location

We do not collect GPS or precise location, and we do not derive or store location from your IP.

5. How we collect data

  • Directly from you: registration, editing your profile, posting content, messaging, reporting, contacting us
  • Automatically while you use Krooko: presence heartbeat, device registration, notification generation
  • Via the contact/report forms (delivered to our email through FormSubmit — see section 17)

There are no third-party logins (no Google/Apple sign-in), no analytics trackers and no advertising technologies on Krooko.

6. Legal bases (GDPR Art. 6)

PurposeLegal basis
Creating and operating your account, showing your content, delivering messages and notificationsPerformance of a contract (Art. 6(1)(b))
Enforcing fair-use limits, preventing spam and abuse, blocks, moderation of reportsLegitimate interests (Art. 6(1)(f)) — keeping the platform safe and usable
Security of accounts and sessions (device list, hashed passwords, access rules)Legitimate interests (Art. 6(1)(f))
Responding when you contact or reportLegitimate interests / performance of a contract
Complying with valid legal requestsLegal obligation (Art. 6(1)(c))
Optional visibility features (e.g. showing your collab track record)Consent (Art. 6(1)(a)) — you can switch them off any time

7. Why we use your data

  • Create and authenticate your account and keep you signed in
  • Show your cards, posts, stories and profile to the audiences you chose
  • Deliver direct messages, group chats, typing/online indicators and read receipts
  • Power follows, friends (mutual follows), likes, comments and notifications
  • Run collab agreements and display your public collab track record (unless you hide it)
  • Enforce audience choices (Public / Friends) and privacy settings at the database level
  • Detect and limit spam through posting limits; review reports; enforce blocks
  • Provide support when you contact us

We do not use your data for advertising, we do not build marketing profiles, and we never sell your personal data.

8. Automated decision-making

Two things on Krooko happen automatically. You always have the right to a human review of either (GDPR Art. 22(3)), and the Report a problem form reaches a person who can overturn the result.

  • Photo moderation. Images you upload are checked automatically before they are published. If one is refused, your account is suspended for 24 hours. You can appeal once, and a moderator reviews it.
  • Language filtering. Some words are refused automatically in posts, comments, cards, hashtags, usernames and display names.

Everything else is not automated: the feed is chronological with no ranking algorithm or engagement profiling, and "Suggested for you" is simply ordered by follower count. Fair-use limits (2 cards a day, one post per 5 minutes, 2 username changes a month) apply equally to everyone. We do not use facial recognition, age estimation, or any biometric processing.

9. Who we share data with

We never sell your data. We share it only with the service providers needed to run Krooko (section 17), with other users according to your audience choices, and with competent authorities where the law requires it (based on a valid legal request). We have no advertising partners, no data brokers and no "business partners" receiving personal data.

10. International transfers

Our database, files and authentication are hosted by Supabase in a data centre located within the European Union — so your account data and content stay in the EEA. Limited exceptions exist for auxiliary services: contact and report emails are delivered via FormSubmit (a US-based service), and fonts/scripts are served by global content-delivery networks. Where such a provider processes data outside the EEA, the transfer is protected by appropriate safeguards under GDPR Chapter V — in particular the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.

11. Data retention

DataKept for
Account, profile & contentUntil you delete it or delete your account
Stories24 hours, then no longer served
Feed postsAutomatically deleted 7 days after posting — or earlier if you delete them
Messages & conversationsAutomatically deleted 7 days after sending — or earlier if you delete them (deletion removes them for all participants)
Device list ("where you're logged in")Until you remove a device or delete your account
Fair-use records (card/repost/username timestamps)Only as long as needed to enforce the limits
ReportsAs long as needed to review and act, and to evidence enforcement
Files you attach to a complaintDeleted the moment your complaint is decided. They are shown to one moderator and then removed automatically
Provider backupsDeleted data may persist in encrypted infrastructure backups for a limited period (typically up to 30 days) before being purged
Browser storage on your deviceUntil you log out / clear it — see the Cookie Policy

12. Security

  • All traffic is encrypted in transit (HTTPS/TLS)
  • Passwords are stored only as salted hashes (bcrypt, via Supabase Auth) — never in plain text
  • Row-Level Security on every database table: private messages, blocks, favourites, friends-only content and message requests are enforced by the database itself, not just hidden by the interface
  • File storage is scoped so users can only write to their own folders
  • Rate limits enforced server-side to prevent abuse
  • Session controls: you can see every logged-in device and log out of all other devices in Settings
  • Data at rest is encrypted by our hosting provider

No system is perfectly secure — please use a strong, unique password.

13. Children's privacy

Krooko is for people aged 16 or older. This is above the digital-consent age applicable in Greece (15 under Law 4624/2019), so no parental-consent mechanism is operated. You confirm your age at sign-up. We do not knowingly collect data from anyone under 16; accounts reported or found to belong to under-16 users are removed together with their data. Anyone can flag a suspected under-16 account with the report tool ("Under-16 user"). See the 16+ Policy.

14. Your GDPR rights

  • Access and data portabilitySettings → Your data → Download my data gives you everything we hold, immediately, as a JSON file
  • Rectification — correct inaccurate data (most of it you can edit yourself in Settings)
  • Erasure ("right to be forgotten") — delete content or your whole account
  • Restriction of processing, and objection to processing based on legitimate interests
  • Human review of any automated decision — including automatic photo moderation (section 8)
  • Withdraw consent at any time where processing is based on consent
  • Complain to the supervisory authority (section 23)

You can exercise most rights directly in Settings (download your data, edit profile, delete posts/cards/messages, manage devices, privacy toggles, delete account). For anything else, email alexroussossm@gmail.com — we respond within one month as GDPR requires.

15. Account deletion

Settings → "Delete account" permanently deletes your account after a typed confirmation. This removes your profile, cards, posts, stories, comments, likes, messages, group memberships, collab records, favourites, blocks, devices and notifications — the deletion cascades through the whole database. Nothing is retained except: (a) copies that may persist briefly in encrypted backups (see retention), and (b) records we must keep to comply with law or evidence enforcement. Content you sent to others that they saved outside Krooko (e.g. screenshots) is outside our control.

16. Cookies & local storage

Krooko sets no tracking, analytics or advertising cookies. We use only essential browser storage (localStorage) to keep you logged in and remember your theme — details, durations and how to clear it are in the Cookie Policy. Because only strictly necessary storage is used, no cookie-consent banner is required.

17. Third-party services

ServiceWhat it doesWhat it receives
SupabaseAuthentication, database, file storage, realtime delivery of messages/notifications; sends service emails (sign-up confirmation, password reset, email change)All account and content data described above, as our processor; infrastructure logs (incl. IP)
FormSubmitDelivers contact-form messages and reports to our emailOnly what you type in those forms (name, email, message / report details)
Fontshare (CDN)Serves the Satoshi fontYour IP address and user-agent when the font loads
goQR (api.qrserver.com)Generates the QR code of your profile link in SettingsYour public profile URL, when you open that Settings section

We use no analytics service (no Google Analytics), no payment processor, no Firebase, no social-login providers.

18. Marketing communications

We send no marketing emails, newsletters, promotional push notifications or SMS. The only emails you receive are transactional (account confirmation, password reset, email-change confirmation). Notifications inside Krooko (likes, follows, replies, invites) exist only in the app's inbox. While a Krooko tab is open, new activity may play a short alert sound and show a red dot on the tab icon — this happens entirely in your browser, involves no browser push-notification permission and no additional data collection, and the sound can be switched off in Settings.

19. Your content & visibility

  • Public cards, posts and stories are visible to anyone; your public profile shows your username, name, avatar, bio, follower counts and (unless you hide it) your collab track record
  • "Friends" posts and stories are visible only to mutual follows — enforced by the database
  • Private accounts don't appear in suggestions, and strangers may send only one message request until you reply
  • Deleted content may remain in encrypted backups for a limited period before being purged
  • You are responsible for the content you publish; others may screenshot or copy what you have shared with them

20. Community moderation

To keep Krooko safe we may: review reports, remove content that breaks the Community Guidelines or the law, suspend or ban accounts, and remove under-16 accounts. Moderation decisions are made by a human; there are no automated moderation tools. Every card, post, story, comment, profile and message can be reported via its three-dot menu, and reports are anonymous to the reported user.

21. Data breaches

If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours as required by GDPR Art. 33, and inform affected users without undue delay where Art. 34 requires it.

22. Changes to this policy

We may update this policy as Krooko evolves. The "Last updated" date above always reflects the current version, and material changes will be announced on the platform. Continued use after an update constitutes acceptance where legally appropriate; where a change requires consent, we will ask for it.

23. Complaints

We'd appreciate the chance to resolve any concern first — email alexroussossm@gmail.com. You also have the right to lodge a complaint with the Greek supervisory authority:

Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifissias Ave 1–3, 115 23 Athens, Greece · www.dpa.gr

24. Contact

Related documents: Terms of Service · Community Guidelines · Cookie Policy · 16+ Policy · Safety Center