Skip to content
Last updated 14 August 2026

Privacy Policy

How Thiskrit Ltd collects, uses, discloses and safeguards your personal data when you use the Thiskrit App for iOS and Android, and related services.

This Privacy Policy (“Policy”) explains how Thiskrit Ltd (“Company”, “we”, “us”, “our”) collects, uses, discloses, and safeguards your personal data when you use our mobile application, “Thiskrit” (“App”), available on iOS and Android platforms, and related services (collectively, “Services”). We are committed to protecting your privacy and ensuring complete transparency about how we handle your information.

This Policy applies to all users of the Thiskrit App, including beta testers, and describes your rights under UK data protection law.

PLEASE READ THIS POLICY CAREFULLY. By accessing or using Thiskrit, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with our practices, please do not use the App.

1. Introduction & Legal Basis

1.1 Who We Are

Thiskrit Ltd is a private company registered in England and Wales under the Companies House. We are the data controller for all personal data processed through the Thiskrit App.

Company Details

Name
Thiskrit Ltd
Registration Number
16760043
Registered Address
Oxford, United Kingdom
Data Protection Officer
privacy@thiskrit.com

1.2 Legal Framework

This Privacy Policy is compliant with:

  • UK General Data Protection Regulation (UK GDPR)
  • Data Protection Act 2018 (DPA 2018)
  • Privacy and Electronic Communications (EC Directive) Regulations 2003
  • Online Safety Act 2023 (where applicable)
  • Children's Online Privacy Code (Ofcom)
  • Apple App Store Privacy Policy Guidelines
  • Google Play Store Developer Policy

1.3 Age Requirement & Parental Consent

Thiskrit is designed for users aged 16 and above. By using the App, you confirm that you are at least 16 years old. If you are aged 13–15 in the United Kingdom, you may only use Thiskrit with the express written consent of a parent or legal guardian. Parents who provide consent agree to be responsible for monitoring and supervising their child's use of the App and agree to this entire Privacy Policy on the child's behalf.

We do not knowingly collect or retain personal data from anyone under the age of 13. If we become aware that we have collected data from a user under 13, we will immediately delete such data and terminate the account.

2. Data We Collect

We collect only the minimum personal data necessary to provide the Thiskrit Service. Below is a comprehensive list of all data we collect, organized by collection method.

2.1 Data You Provide Directly

Account Registration & Authentication

  • Email address (for account creation and email verification)
  • Username (chosen by you, used for unique identification)
  • Password (encrypted and securely stored)
  • Phone number (optional, for two-factor authentication if enabled)
  • Date of birth (for age verification at signup)
  • Profile photo (optional, uploaded by you)
  • Bio or profile description (optional, entered by you)

User-Generated Content

  • Posts (text, images, videos, and Stories you create)
  • Messages (chat conversations between connected users)
  • Connections (list of mutual connections and connection requests)
  • Spaces (audience groups you create and their membership)
  • Comments and reactions on other users' content
  • Any other content you voluntarily upload or create within the App

All user-generated content is encrypted and stored securely. Content shared within Spaces is only visible to members of those Spaces.

2.2 Data Collected Automatically

Device & App Usage Data

  • Device type, model, and operating system
  • App version and features used
  • Session start and end times
  • Crash reports and error logs (via Firebase Crashlytics)
  • Device identifier (IDFA on iOS, AAID on Android) — used only for crash reporting
  • Approximate location (country/region only, based on IP address)

This data is collected to maintain app stability, identify and fix bugs, and understand which features are most used. We do NOT track precise geolocation or send any tracking data to third parties.

Network & Connection Data

  • IP address (for security and abuse prevention)
  • Connection timestamps
  • Data transmitted to/from the App (encrypted in transit via TLS 1.2+)

2.3 Data from Third-Party Services

Firebase (Google)

We use Firebase for the following purposes:

  • Authentication (email and phone-based login)
  • Real-time messaging infrastructure (Firestore)
  • Push notifications (Firebase Cloud Messaging)
  • Crash reporting (Firebase Crashlytics)
  • Performance monitoring (Firebase Performance Monitoring)

Firebase processes data on our behalf as a data processor. Thiskrit Ltd remains the data controller. Data is encrypted in transit and at rest. Full details are available in Google's Privacy Policy.

Amazon Web Services (AWS)

We use AWS for the following purposes:

  • Media storage (S3 buckets for images, videos, and files)
  • Server infrastructure (EC2, VPC)
  • Database backups (AWS)

All data stored on AWS is encrypted at rest and in transit. AWS acts as a data processor on our behalf. Full details are in AWS's Privacy Policy.

3. How We Use Your Data

We use your personal data only for the following legitimate purposes:

3.1 To Provide the Service

  • Creating and managing your account
  • Enabling you to create Spaces and share content
  • Delivering messages between connected users (end-to-end encrypted)
  • Storing and retrieving your posts, Stories, and media
  • Sending password reset and verification emails

3.2 To Maintain Security & Safety

  • Detecting and preventing fraud, abuse, and unauthorized access
  • Investigating suspicious account activity
  • Enforcing Terms of Service and legal agreements
  • Protecting the rights, privacy, and safety of users
  • Complying with legal obligations and law enforcement requests

3.3 To Improve the App

  • Analyzing usage patterns (anonymized data only)
  • Identifying bugs and technical issues (via Crashlytics)
  • Testing new features and functionality
  • Improving app performance and user experience

All analysis is performed on aggregated, anonymized data. We do NOT profile individual users or create usage patterns tied to personal identity.

3.4 To Comply with Legal Obligations

  • Responding to valid legal requests from authorities
  • Complying with child protection regulations
  • Meeting age verification requirements under UK law

4. Data We Explicitly Do Not Collect

In keeping with our privacy-first philosophy, Thiskrit does NOT:

  • Collect or track precise geolocation data
  • Build behavioral profiles or user interest categories
  • Use algorithmic tracking or analytics cookies
  • Sell user data to third parties
  • Share data with advertisers or marketing companies
  • Retain browsing history or app usage patterns linked to your identity
  • Use cross-app or cross-device tracking
  • Integrate with social media platforms for tracking purposes
  • Collect data for profiling, targeting, or surveillance

5. Encryption & Data Security

5.1 End-to-End Encryption (E2EE)

All personal messages on Thiskrit are protected by end-to-end encryption. This means:

  • Messages are encrypted on your device before being sent
  • Only you and the recipient can decrypt and read your messages
  • Thiskrit servers cannot decrypt or read your messages
  • Even if Thiskrit infrastructure is compromised, message content remains protected

Technical Details

Messages are encrypted using AES-256 encryption. The encryption key is derived from a unique chat identifier using SHA-256 hashing. Each message is encrypted with a randomly generated initialization vector (IV), which is prepended to the ciphertext.

5.2 Data in Transit

All communication between your device and Thiskrit servers is protected by TLS 1.2 or higher encryption. This applies to:

  • Login and authentication
  • Image and video uploads
  • API calls and data synchronization
  • Push notifications

5.3 Data at Rest

User data stored on Thiskrit servers is encrypted at rest using industry-standard encryption protocols:

  • Firebase Firestore data is encrypted at rest
  • AWS S3 media files are encrypted using AES-256
  • Database backups are encrypted and stored securely

5.4 Credential Handling

Passwords are:

  • Never stored in plaintext
  • Hashed using bcrypt with salt
  • Never transmitted over unencrypted connections
  • Never logged or monitored by our staff

5.5 Access Controls

Thiskrit staff access to production data is:

  • Strictly limited to essential personnel only
  • Logged and audited
  • Protected by multi-factor authentication
  • Subject to non-disclosure agreements

6. Data Sharing & Disclosure

6.1 When We Share Data

Thiskrit shares your personal data only in the following limited circumstances:

With Service Providers (Data Processors)

We use third-party service providers who process data on our behalf:

  • Google Firebase (authentication, messaging, crash reporting) — subject to Data Processing Agreement
  • Amazon Web Services (infrastructure and storage) — subject to Data Processing Agreement
  • Wise (international payment processing) — for salary/compensation only, subject to Data Processing Agreement

All service providers are required to implement appropriate data protection measures and are contractually bound to process data only as instructed by Thiskrit.

With Connected Users (Within Spaces)

Content you share within a Space is visible only to members of that Space. This includes:

  • Posts and Stories (visible to chosen Space members only)
  • Messages (visible only to the recipient)
  • Profile information (visible based on Space membership)

For Legal Compliance & Law Enforcement

Thiskrit may disclose personal data if legally required:

  • In response to valid legal requests (court orders, warrants, subpoenas)
  • To comply with child protection laws
  • To prevent imminent harm or illegal activity
  • To enforce Terms of Service

We will attempt to notify users of legal requests unless legally prohibited from doing so. We never voluntarily provide data to law enforcement without a valid legal order.

Business Transfers

If Thiskrit is acquired, merged, or undergoes bankruptcy, user data may be transferred as part of the transaction. Users will be notified of any such change and given the opportunity to delete their account if they do not consent.

6.2 Data We Do NOT Share

Thiskrit does NOT:

  • Share data with advertisers or marketing companies
  • Sell user data for any purpose
  • Share data with data brokers
  • Share behavioral profiles with third parties
  • Use your data for targeted advertising

7. Your Rights Under UK Data Protection Law

Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:

7.1 Right of Access (Subject Access Request)

You have the right to request a copy of all personal data we hold about you. We will provide this information within 30 calendar days of receiving a valid request. To make a Subject Access Request, email privacy@thiskrit.comwith the subject line “SAR”.

7.2 Right to Rectification

You have the right to correct inaccurate or incomplete personal data. You can update your profile information directly within the App. For data we control that you cannot edit, contact privacy@thiskrit.com.

7.3 Right to Erasure (‘Right to be Forgotten’)

You have the right to request deletion of your personal data, subject to certain exceptions. When you delete your account:

  • Your account and associated profile data are deleted
  • Your posts and Stories are deleted
  • Messages remain encrypted and are deleted from our servers
  • Backups may retain data for up to 30 days before permanent deletion

To request account deletion, go to App Settings → Account → Delete Account. You will be prompted to confirm. After confirmation, your account cannot be recovered.

7.4 Right to Restrict Processing

You can ask us to restrict processing of your data in certain circumstances (e.g. while you contest accuracy). We will retain the data but limit how we use it. Contact privacy@thiskrit.com to request restriction.

7.5 Right to Data Portability

You have the right to receive your personal data in a commonly used, machine-readable format (e.g. JSON, CSV). To request a data export, contact privacy@thiskrit.com. We will provide this within 30 days.

7.6 Right to Object

You have the right to object to processing of your data for specific purposes. This does not apply to processing necessary to provide the Service, but you can opt out of non-essential processing. Contact privacy@thiskrit.com to object.

7.7 Rights Related to Automated Decision-Making

Thiskrit does not use automated decision-making, profiling, or algorithmic processing that produces significant legal effects on you.

7.8 How to Exercise Your Rights

To exercise any of the above rights:

Include
Your email address, account username, and a clear description of your request
Timeline
We will respond within 30 calendar days
No fees
We do not charge for exercising your rights (except in cases of manifestly unfounded requests)

8. Children & Minors

8.1 Age Restrictions

Thiskrit is not intended for children under 16. We do not knowingly collect data from children under 16. If we discover we have done so, we will immediately delete such data and terminate the account.

8.2 Users Aged 13–15 (UK)

Under UK law, users aged 13–15 may use Thiskrit only with parental or guardian consent. By creating an account for a child aged 13–15, the parent/guardian:

  • Confirms they are the child's parent or legal guardian
  • Gives explicit consent for the child to use Thiskrit
  • Accepts full responsibility for the child's use of the App
  • Agrees to supervise and monitor the child's activity
  • Confirms they have read and understood this entire Privacy Policy

Parents can request deletion of a child's account at any time by contacting privacy@thiskrit.com and providing proof of parental authority.

8.3 Safeguards for Minors

For all users under 18, Thiskrit implements additional safeguards:

  • No algorithmic recommendation feeds (chronological only)
  • No targeted advertising or data profiling
  • No integration with third-party tracking services
  • Regular safety reviews and content moderation

9. Firebase & Google Services

9.1 Firebase Data Processing

Thiskrit uses Google Firebase to provide core functionality. As a Firebase user, your data may be processed according to Google's Privacy Policy.

What Firebase Accesses

  • Authentication data (email, phone number, hashed password)
  • Real-time messaging data (Firestore)
  • Push notification data (FCM)
  • Crash reports and error logs (Crashlytics)
  • Performance metrics (Performance Monitoring)

Data Residency

Firebase data is stored in Google data centers, which may be located in various regions. For EU/UK users, data is typically stored in EU data centers, but may be replicated globally for redundancy.

10. Cookies & Tracking Technologies

10.1 Mobile App Policy

As a native mobile application, Thiskrit does not use cookies in the traditional sense (HTTP cookies are web-based). However, the App may store local data for the following purposes:

  • Session tokens (to keep you logged in)
  • Encryption keys (for end-to-end encryption)
  • Cache (to speed up app performance)

This local data is stored on your device only and is not transmitted to tracking services.

10.2 No Third-Party Tracking

Thiskrit does not use:

  • Third-party cookies or tracking pixels
  • Cross-app tracking identifiers
  • Cross-device tracking
  • Advertising networks or tracking SDKs
  • Behavioural retargeting services

11. Amazon Web Services (AWS) & Data Storage

11.1 AWS Usage

Thiskrit uses AWS for:

  • Server infrastructure (EC2, VPC)
  • Media storage (S3 buckets)
  • Database hosting (MongoDB)
  • Backup and disaster recovery

AWS acts as a data processor on our behalf. AWS does not have access to unencrypted content or user data beyond what is necessary to provide hosting services.

11.2 Data Security on AWS

  • All S3 buckets are encrypted with AES-256
  • Database backups are encrypted at rest
  • All data in transit to/from AWS is encrypted via TLS
  • AWS infrastructure is GDPR-compliant

Full AWS security details are available in AWS's Privacy Policy and DPA.

12. Data Retention & Deletion

12.1 How Long We Keep Your Data

Active Account Data

While your account is active, we retain:

Account information (email, username, profile)
For as long as the account exists
Posts and Stories
Until you delete them
Messages
Until you delete them or delete your account
Connections list
While connections are active

After Account Deletion

  • Account data is deleted immediately from live systems
  • Database backups may retain data for up to 30 days (for disaster recovery)
  • After 30 days, all copies of your data are permanently deleted
  • Encrypted messages remain encrypted and are deleted

Log Data & Technical Records

IP logs
Retained for 90 days (for security purposes)
Crash reports
Retained for 180 days (for debugging)
Server logs
Retained for 30 days

After the retention period, logs are deleted. Logs do not contain content; they contain only metadata (timestamps, IP addresses, error messages).

12.2 User-Initiated Deletion

You can delete individual posts, messages, or entire accounts at any time:

  • Delete a post: Tap → Delete
  • Delete a message: Swipe → Delete
  • Delete account: Settings → Account → Delete Account (irreversible)

13. International Data Transfers

Thiskrit is based in the United Kingdom and operates under UK GDPR. However, your data may be processed in other countries:

  • Firebase (Google) — US, EU, and other regions
  • AWS — US and EU data centers
  • Wise (payments) — global processing

For transfers outside the UK/EU, Thiskrit relies on:

  • Standard Contractual Clauses (SCCs) for transfers to the US and other countries
  • Recipient adequacy decisions (where applicable)
  • Your explicit consent (where necessary)

By using Thiskrit, you consent to the transfer of your data to countries outside the UK/EU as necessary to provide the Service. We take steps to ensure data is protected at the same level regardless of location.

14. Security Measures & Breach Notification

14.1 Security Measures

Thiskrit implements comprehensive security measures:

  • End-to-end encryption for messages
  • TLS 1.2+ for all data in transit
  • AES-256 encryption for data at rest
  • Secure password hashing
  • Regular security audits and penetration testing
  • Access controls and role-based permissions
  • Intrusion detection and prevention systems
  • DDoS protection and rate limiting

14.2 Data Breach Notification

In the unlikely event of a confirmed data breach:

  • We will notify affected users within 72 hours (as required by UK GDPR)
  • Notification will include details of the breach and impact
  • Guidance on protective steps will be provided
  • We will notify the ICO (Information Commissioner's Office) if the breach involves significant risk

You will be notified via the email address on your account. Do not rely on second-hand reports of breaches; check official Thiskrit announcements.

16. Contact & Complaints

16.1 Privacy Inquiries

If you have questions about this Privacy Policy or how your data is handled:

Mail
Thiskrit Ltd, Oxford, United Kingdom
Response time
Within 10 business days

16.2 Data Protection Officer

For data protection-specific inquiries: support@thiskrit.com

16.3 Data Protection Complaints

If you believe Thiskrit has violated your data protection rights, you have the right to file a complaint with the Information Commissioner's Office (ICO):

Website
ico.org.uk
Phone
0303 123 1113

17. Policy Updates & Changes

Thiskrit may update this Privacy Policy from time to time. Material changes will be announced via:

  • In-app notification
  • Email to your registered address
  • Updated policy on this page (with new ‘Last Updated’ date)

Continued use of the App after changes constitutes acceptance of the updated policy. We recommend reviewing this policy periodically for updates.

18. UK GDPR Special Provisions

18.1 Legal Basis for Processing

We process your personal data based on the following legal grounds under UK GDPR:

Consent
You consent to account creation and use of the App
Contract
Processing is necessary to provide the Service you requested
Legal obligation
Processing required by law (e.g. child protection)
Legitimate interests
Preventing fraud, improving the App, and protecting rights

18.2 Lawful Basis for Each Data Type

Account data (email, username)
Contract
User-generated content (posts, messages)
Contract & User Control
Crash reports
Legitimate interest (improving app stability)
IP logs
Legitimate interest (security and fraud prevention)

18.3 Privacy Impact Assessment

Thiskrit conducts Data Protection Impact Assessments (DPIA) for high-risk processing. A summary is available upon request.

19. Compliance with App Store Policies

19.1 Apple App Store Privacy Requirements

This Privacy Policy complies with Apple's App Store Review Guidelines:

  • Data collection is limited to essential functions
  • All collection methods are disclosed
  • Users have control over their data (delete account, delete content)
  • Data is not shared with third-party advertisers
  • No tracking for advertising purposes
  • Age restrictions are enforced (16+)

19.2 Google Play Store Privacy Requirements

This Privacy Policy complies with Google Play's Developer Policy:

  • Clear disclosure of data collection
  • User consent for sensitive data
  • Commitment to data security
  • Commitment not to sell personal data
  • Respect for device permissions
  • Age-appropriate content policies

20. Acknowledgment & Acceptance

By downloading, installing, and using the Thiskrit App, you:

  • Acknowledge that you have read this entire Privacy Policy
  • Confirm you understand how your data is collected and used
  • Consent to the processing of your personal data as described
  • Accept the terms and conditions of this Policy
  • Confirm you are at least 16 years old (or have parental consent if 13–15)

If you do not agree to this Policy, do not use the App.

This Privacy Policy is effective from 14 August 2026. Thiskrit Ltd — Protecting Your Privacy by Design. Questions? Contact manthan@thiskrit.com.