Effective date: 16 July 2026 · Last updated: 16 July 2026
This Privacy Policy explains how Krooko (the website and social platform available at this address, operated by Alexandros Roussos) collects, uses, discloses and protects your personal data when you use it. Krooko is a free social platform that helps people find business and creative partners: members post "cards", share posts and stories, follow each other, chat and sign collab agreements.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), Greek Law 4624/2019, and other applicable Greek and EU law.
For all privacy questions, requests and support, contact alexroussossm@gmail.com or write to the postal address above. Given Krooko's size and the nature of its processing, a Data Protection Officer is not required and has not been appointed; the controller handles all privacy matters directly.
We do not collect gender, phone numbers, postal addresses, government ID or verification documents, or payment details — Krooko is free and has no payments.
Our own code does not record your IP address. However, the infrastructure we run on (Supabase) and the content-delivery networks that serve fonts and scripts necessarily see your IP address and standard request data in their server logs, as every website's infrastructure does. We do not use these logs to profile you.
We do not collect GPS or precise location, and we do not derive or store location from your IP.
There are no third-party logins (no Google/Apple sign-in), no analytics trackers and no advertising technologies on Krooko.
| Purpose | Legal basis |
|---|---|
| Creating and operating your account, showing your content, delivering messages and notifications | Performance of a contract (Art. 6(1)(b)) |
| Enforcing fair-use limits, preventing spam and abuse, blocks, moderation of reports | Legitimate interests (Art. 6(1)(f)) — keeping the platform safe and usable |
| Security of accounts and sessions (device list, hashed passwords, access rules) | Legitimate interests (Art. 6(1)(f)) |
| Responding when you contact or report | Legitimate interests / performance of a contract |
| Complying with valid legal requests | Legal obligation (Art. 6(1)(c)) |
| Optional visibility features (e.g. showing your collab track record) | Consent (Art. 6(1)(a)) — you can switch them off any time |
We do not use your data for advertising, we do not build marketing profiles, and we never sell your personal data.
Two things on Krooko happen automatically. You always have the right to a human review of either (GDPR Art. 22(3)), and the Report a problem form reaches a person who can overturn the result.
Everything else is not automated: the feed is chronological with no ranking algorithm or engagement profiling, and "Suggested for you" is simply ordered by follower count. Fair-use limits (2 cards a day, one post per 5 minutes, 2 username changes a month) apply equally to everyone. We do not use facial recognition, age estimation, or any biometric processing.
We never sell your data. We share it only with the service providers needed to run Krooko (section 17), with other users according to your audience choices, and with competent authorities where the law requires it (based on a valid legal request). We have no advertising partners, no data brokers and no "business partners" receiving personal data.
Our database, files and authentication are hosted by Supabase in a data centre located within the European Union — so your account data and content stay in the EEA. Limited exceptions exist for auxiliary services: contact and report emails are delivered via FormSubmit (a US-based service), and fonts/scripts are served by global content-delivery networks. Where such a provider processes data outside the EEA, the transfer is protected by appropriate safeguards under GDPR Chapter V — in particular the EU Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework.
| Data | Kept for |
|---|---|
| Account, profile & content | Until you delete it or delete your account |
| Stories | 24 hours, then no longer served |
| Feed posts | Automatically deleted 7 days after posting — or earlier if you delete them |
| Messages & conversations | Automatically deleted 7 days after sending — or earlier if you delete them (deletion removes them for all participants) |
| Device list ("where you're logged in") | Until you remove a device or delete your account |
| Fair-use records (card/repost/username timestamps) | Only as long as needed to enforce the limits |
| Reports | As long as needed to review and act, and to evidence enforcement |
| Files you attach to a complaint | Deleted the moment your complaint is decided. They are shown to one moderator and then removed automatically |
| Provider backups | Deleted data may persist in encrypted infrastructure backups for a limited period (typically up to 30 days) before being purged |
| Browser storage on your device | Until you log out / clear it — see the Cookie Policy |
No system is perfectly secure — please use a strong, unique password.
Krooko is for people aged 16 or older. This is above the digital-consent age applicable in Greece (15 under Law 4624/2019), so no parental-consent mechanism is operated. You confirm your age at sign-up. We do not knowingly collect data from anyone under 16; accounts reported or found to belong to under-16 users are removed together with their data. Anyone can flag a suspected under-16 account with the report tool ("Under-16 user"). See the 16+ Policy.
You can exercise most rights directly in Settings (download your data, edit profile, delete posts/cards/messages, manage devices, privacy toggles, delete account). For anything else, email alexroussossm@gmail.com — we respond within one month as GDPR requires.
Settings → "Delete account" permanently deletes your account after a typed confirmation. This removes your profile, cards, posts, stories, comments, likes, messages, group memberships, collab records, favourites, blocks, devices and notifications — the deletion cascades through the whole database. Nothing is retained except: (a) copies that may persist briefly in encrypted backups (see retention), and (b) records we must keep to comply with law or evidence enforcement. Content you sent to others that they saved outside Krooko (e.g. screenshots) is outside our control.
Krooko sets no tracking, analytics or advertising cookies. We use only essential browser storage (localStorage) to keep you logged in and remember your theme — details, durations and how to clear it are in the Cookie Policy. Because only strictly necessary storage is used, no cookie-consent banner is required.
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Authentication, database, file storage, realtime delivery of messages/notifications; sends service emails (sign-up confirmation, password reset, email change) | All account and content data described above, as our processor; infrastructure logs (incl. IP) |
| FormSubmit | Delivers contact-form messages and reports to our email | Only what you type in those forms (name, email, message / report details) |
| Fontshare (CDN) | Serves the Satoshi font | Your IP address and user-agent when the font loads |
| goQR (api.qrserver.com) | Generates the QR code of your profile link in Settings | Your public profile URL, when you open that Settings section |
We use no analytics service (no Google Analytics), no payment processor, no Firebase, no social-login providers.
We send no marketing emails, newsletters, promotional push notifications or SMS. The only emails you receive are transactional (account confirmation, password reset, email-change confirmation). Notifications inside Krooko (likes, follows, replies, invites) exist only in the app's inbox. While a Krooko tab is open, new activity may play a short alert sound and show a red dot on the tab icon — this happens entirely in your browser, involves no browser push-notification permission and no additional data collection, and the sound can be switched off in Settings.
To keep Krooko safe we may: review reports, remove content that breaks the Community Guidelines or the law, suspend or ban accounts, and remove under-16 accounts. Moderation decisions are made by a human; there are no automated moderation tools. Every card, post, story, comment, profile and message can be reported via its three-dot menu, and reports are anonymous to the reported user.
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours as required by GDPR Art. 33, and inform affected users without undue delay where Art. 34 requires it.
We may update this policy as Krooko evolves. The "Last updated" date above always reflects the current version, and material changes will be announced on the platform. Continued use after an update constitutes acceptance where legally appropriate; where a change requires consent, we will ask for it.
We'd appreciate the chance to resolve any concern first — email alexroussossm@gmail.com. You also have the right to lodge a complaint with the Greek supervisory authority:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifissias Ave 1–3, 115 23 Athens, Greece · www.dpa.gr
Related documents: Terms of Service · Community Guidelines · Cookie Policy · 16+ Policy · Safety Center