1. Introduction & Legal Basis
1.1 Who We Are
Thiskrit Ltd is a private company registered in England and Wales under the Companies House. We are the data controller for all personal data processed through the Thiskrit App.
Company Details
- Name
- Thiskrit Ltd
- Registration Number
- 16760043
- Registered Address
- Oxford, United Kingdom
- support@thiskrit.com
- Data Protection Officer
- privacy@thiskrit.com
1.2 Legal Framework
This Privacy Policy is compliant with:
- UK General Data Protection Regulation (UK GDPR)
- Data Protection Act 2018 (DPA 2018)
- Privacy and Electronic Communications (EC Directive) Regulations 2003
- Online Safety Act 2023 (where applicable)
- Children's Online Privacy Code (Ofcom)
- Apple App Store Privacy Policy Guidelines
- Google Play Store Developer Policy
1.3 Age Requirement & Parental Consent
Thiskrit is designed for users aged 16 and above. By using the App, you confirm that you are at least 16 years old. If you are aged 13–15 in the United Kingdom, you may only use Thiskrit with the express written consent of a parent or legal guardian. Parents who provide consent agree to be responsible for monitoring and supervising their child's use of the App and agree to this entire Privacy Policy on the child's behalf.
We do not knowingly collect or retain personal data from anyone under the age of 13. If we become aware that we have collected data from a user under 13, we will immediately delete such data and terminate the account.
2. Data We Collect
We collect only the minimum personal data necessary to provide the Thiskrit Service. Below is a comprehensive list of all data we collect, organized by collection method.
2.1 Data You Provide Directly
Account Registration & Authentication
- Email address (for account creation and email verification)
- Username (chosen by you, used for unique identification)
- Password (encrypted and securely stored)
- Phone number (optional, for two-factor authentication if enabled)
- Date of birth (for age verification at signup)
- Profile photo (optional, uploaded by you)
- Bio or profile description (optional, entered by you)
User-Generated Content
- Posts (text, images, videos, and Stories you create)
- Messages (chat conversations between connected users)
- Connections (list of mutual connections and connection requests)
- Spaces (audience groups you create and their membership)
- Comments and reactions on other users' content
- Any other content you voluntarily upload or create within the App
All user-generated content is encrypted and stored securely. Content shared within Spaces is only visible to members of those Spaces.
2.2 Data Collected Automatically
Device & App Usage Data
- Device type, model, and operating system
- App version and features used
- Session start and end times
- Crash reports and error logs (via Firebase Crashlytics)
- Device identifier (IDFA on iOS, AAID on Android) — used only for crash reporting
- Approximate location (country/region only, based on IP address)
This data is collected to maintain app stability, identify and fix bugs, and understand which features are most used. We do NOT track precise geolocation or send any tracking data to third parties.
Network & Connection Data
- IP address (for security and abuse prevention)
- Connection timestamps
- Data transmitted to/from the App (encrypted in transit via TLS 1.2+)
2.3 Data from Third-Party Services
Firebase (Google)
We use Firebase for the following purposes:
- Authentication (email and phone-based login)
- Real-time messaging infrastructure (Firestore)
- Push notifications (Firebase Cloud Messaging)
- Crash reporting (Firebase Crashlytics)
- Performance monitoring (Firebase Performance Monitoring)
Firebase processes data on our behalf as a data processor. Thiskrit Ltd remains the data controller. Data is encrypted in transit and at rest. Full details are available in Google's Privacy Policy.
Amazon Web Services (AWS)
We use AWS for the following purposes:
- Media storage (S3 buckets for images, videos, and files)
- Server infrastructure (EC2, VPC)
- Database backups (AWS)
All data stored on AWS is encrypted at rest and in transit. AWS acts as a data processor on our behalf. Full details are in AWS's Privacy Policy.
3. How We Use Your Data
We use your personal data only for the following legitimate purposes:
3.1 To Provide the Service
- Creating and managing your account
- Enabling you to create Spaces and share content
- Delivering messages between connected users (end-to-end encrypted)
- Storing and retrieving your posts, Stories, and media
- Sending password reset and verification emails
3.2 To Maintain Security & Safety
- Detecting and preventing fraud, abuse, and unauthorized access
- Investigating suspicious account activity
- Enforcing Terms of Service and legal agreements
- Protecting the rights, privacy, and safety of users
- Complying with legal obligations and law enforcement requests
3.3 To Improve the App
- Analyzing usage patterns (anonymized data only)
- Identifying bugs and technical issues (via Crashlytics)
- Testing new features and functionality
- Improving app performance and user experience
All analysis is performed on aggregated, anonymized data. We do NOT profile individual users or create usage patterns tied to personal identity.
3.4 To Comply with Legal Obligations
- Responding to valid legal requests from authorities
- Complying with child protection regulations
- Meeting age verification requirements under UK law
4. Data We Explicitly Do Not Collect
In keeping with our privacy-first philosophy, Thiskrit does NOT:
- Collect or track precise geolocation data
- Build behavioral profiles or user interest categories
- Use algorithmic tracking or analytics cookies
- Sell user data to third parties
- Share data with advertisers or marketing companies
- Retain browsing history or app usage patterns linked to your identity
- Use cross-app or cross-device tracking
- Integrate with social media platforms for tracking purposes
- Collect data for profiling, targeting, or surveillance
5. Encryption & Data Security
5.1 End-to-End Encryption (E2EE)
All personal messages on Thiskrit are protected by end-to-end encryption. This means:
- Messages are encrypted on your device before being sent
- Only you and the recipient can decrypt and read your messages
- Thiskrit servers cannot decrypt or read your messages
- Even if Thiskrit infrastructure is compromised, message content remains protected
Technical Details
Messages are encrypted using AES-256 encryption. The encryption key is derived from a unique chat identifier using SHA-256 hashing. Each message is encrypted with a randomly generated initialization vector (IV), which is prepended to the ciphertext.
5.2 Data in Transit
All communication between your device and Thiskrit servers is protected by TLS 1.2 or higher encryption. This applies to:
- Login and authentication
- Image and video uploads
- API calls and data synchronization
- Push notifications
5.3 Data at Rest
User data stored on Thiskrit servers is encrypted at rest using industry-standard encryption protocols:
- Firebase Firestore data is encrypted at rest
- AWS S3 media files are encrypted using AES-256
- Database backups are encrypted and stored securely
5.4 Credential Handling
Passwords are:
- Never stored in plaintext
- Hashed using bcrypt with salt
- Never transmitted over unencrypted connections
- Never logged or monitored by our staff
5.5 Access Controls
Thiskrit staff access to production data is:
- Strictly limited to essential personnel only
- Logged and audited
- Protected by multi-factor authentication
- Subject to non-disclosure agreements
6. Data Sharing & Disclosure
6.1 When We Share Data
Thiskrit shares your personal data only in the following limited circumstances:
With Service Providers (Data Processors)
We use third-party service providers who process data on our behalf:
- Google Firebase (authentication, messaging, crash reporting) — subject to Data Processing Agreement
- Amazon Web Services (infrastructure and storage) — subject to Data Processing Agreement
- Wise (international payment processing) — for salary/compensation only, subject to Data Processing Agreement
All service providers are required to implement appropriate data protection measures and are contractually bound to process data only as instructed by Thiskrit.
With Connected Users (Within Spaces)
Content you share within a Space is visible only to members of that Space. This includes:
- Posts and Stories (visible to chosen Space members only)
- Messages (visible only to the recipient)
- Profile information (visible based on Space membership)
For Legal Compliance & Law Enforcement
Thiskrit may disclose personal data if legally required:
- In response to valid legal requests (court orders, warrants, subpoenas)
- To comply with child protection laws
- To prevent imminent harm or illegal activity
- To enforce Terms of Service
We will attempt to notify users of legal requests unless legally prohibited from doing so. We never voluntarily provide data to law enforcement without a valid legal order.
Business Transfers
If Thiskrit is acquired, merged, or undergoes bankruptcy, user data may be transferred as part of the transaction. Users will be notified of any such change and given the opportunity to delete their account if they do not consent.
6.2 Data We Do NOT Share
Thiskrit does NOT:
- Share data with advertisers or marketing companies
- Sell user data for any purpose
- Share data with data brokers
- Share behavioral profiles with third parties
- Use your data for targeted advertising
7. Your Rights Under UK Data Protection Law
Under UK GDPR and the Data Protection Act 2018, you have the following rights regarding your personal data:
7.1 Right of Access (Subject Access Request)
You have the right to request a copy of all personal data we hold about you. We will provide this information within 30 calendar days of receiving a valid request. To make a Subject Access Request, email privacy@thiskrit.comwith the subject line “SAR”.
7.2 Right to Rectification
You have the right to correct inaccurate or incomplete personal data. You can update your profile information directly within the App. For data we control that you cannot edit, contact privacy@thiskrit.com.
7.3 Right to Erasure (‘Right to be Forgotten’)
You have the right to request deletion of your personal data, subject to certain exceptions. When you delete your account:
- Your account and associated profile data are deleted
- Your posts and Stories are deleted
- Messages remain encrypted and are deleted from our servers
- Backups may retain data for up to 30 days before permanent deletion
To request account deletion, go to App Settings → Account → Delete Account. You will be prompted to confirm. After confirmation, your account cannot be recovered.
7.4 Right to Restrict Processing
You can ask us to restrict processing of your data in certain circumstances (e.g. while you contest accuracy). We will retain the data but limit how we use it. Contact privacy@thiskrit.com to request restriction.
7.5 Right to Data Portability
You have the right to receive your personal data in a commonly used, machine-readable format (e.g. JSON, CSV). To request a data export, contact privacy@thiskrit.com. We will provide this within 30 days.
7.6 Right to Object
You have the right to object to processing of your data for specific purposes. This does not apply to processing necessary to provide the Service, but you can opt out of non-essential processing. Contact privacy@thiskrit.com to object.
7.7 Rights Related to Automated Decision-Making
Thiskrit does not use automated decision-making, profiling, or algorithmic processing that produces significant legal effects on you.
7.8 How to Exercise Your Rights
To exercise any of the above rights:
- privacy@thiskrit.com
- Include
- Your email address, account username, and a clear description of your request
- Timeline
- We will respond within 30 calendar days
- No fees
- We do not charge for exercising your rights (except in cases of manifestly unfounded requests)
8. Children & Minors
8.1 Age Restrictions
Thiskrit is not intended for children under 16. We do not knowingly collect data from children under 16. If we discover we have done so, we will immediately delete such data and terminate the account.
8.2 Users Aged 13–15 (UK)
Under UK law, users aged 13–15 may use Thiskrit only with parental or guardian consent. By creating an account for a child aged 13–15, the parent/guardian:
- Confirms they are the child's parent or legal guardian
- Gives explicit consent for the child to use Thiskrit
- Accepts full responsibility for the child's use of the App
- Agrees to supervise and monitor the child's activity
- Confirms they have read and understood this entire Privacy Policy
Parents can request deletion of a child's account at any time by contacting privacy@thiskrit.com and providing proof of parental authority.
8.3 Safeguards for Minors
For all users under 18, Thiskrit implements additional safeguards:
- No algorithmic recommendation feeds (chronological only)
- No targeted advertising or data profiling
- No integration with third-party tracking services
- Regular safety reviews and content moderation
9. Firebase & Google Services
9.1 Firebase Data Processing
Thiskrit uses Google Firebase to provide core functionality. As a Firebase user, your data may be processed according to Google's Privacy Policy.
What Firebase Accesses
- Authentication data (email, phone number, hashed password)
- Real-time messaging data (Firestore)
- Push notification data (FCM)
- Crash reports and error logs (Crashlytics)
- Performance metrics (Performance Monitoring)
Data Residency
Firebase data is stored in Google data centers, which may be located in various regions. For EU/UK users, data is typically stored in EU data centers, but may be replicated globally for redundancy.
11. Amazon Web Services (AWS) & Data Storage
11.1 AWS Usage
Thiskrit uses AWS for:
- Server infrastructure (EC2, VPC)
- Media storage (S3 buckets)
- Database hosting (MongoDB)
- Backup and disaster recovery
AWS acts as a data processor on our behalf. AWS does not have access to unencrypted content or user data beyond what is necessary to provide hosting services.
11.2 Data Security on AWS
- All S3 buckets are encrypted with AES-256
- Database backups are encrypted at rest
- All data in transit to/from AWS is encrypted via TLS
- AWS infrastructure is GDPR-compliant
Full AWS security details are available in AWS's Privacy Policy and DPA.
12. Data Retention & Deletion
12.1 How Long We Keep Your Data
Active Account Data
While your account is active, we retain:
- Account information (email, username, profile)
- For as long as the account exists
- Posts and Stories
- Until you delete them
- Messages
- Until you delete them or delete your account
- Connections list
- While connections are active
After Account Deletion
- Account data is deleted immediately from live systems
- Database backups may retain data for up to 30 days (for disaster recovery)
- After 30 days, all copies of your data are permanently deleted
- Encrypted messages remain encrypted and are deleted
Log Data & Technical Records
- IP logs
- Retained for 90 days (for security purposes)
- Crash reports
- Retained for 180 days (for debugging)
- Server logs
- Retained for 30 days
After the retention period, logs are deleted. Logs do not contain content; they contain only metadata (timestamps, IP addresses, error messages).
12.2 User-Initiated Deletion
You can delete individual posts, messages, or entire accounts at any time:
- Delete a post: Tap → Delete
- Delete a message: Swipe → Delete
- Delete account: Settings → Account → Delete Account (irreversible)
13. International Data Transfers
Thiskrit is based in the United Kingdom and operates under UK GDPR. However, your data may be processed in other countries:
- Firebase (Google) — US, EU, and other regions
- AWS — US and EU data centers
- Wise (payments) — global processing
For transfers outside the UK/EU, Thiskrit relies on:
- Standard Contractual Clauses (SCCs) for transfers to the US and other countries
- Recipient adequacy decisions (where applicable)
- Your explicit consent (where necessary)
By using Thiskrit, you consent to the transfer of your data to countries outside the UK/EU as necessary to provide the Service. We take steps to ensure data is protected at the same level regardless of location.
14. Security Measures & Breach Notification
14.1 Security Measures
Thiskrit implements comprehensive security measures:
- End-to-end encryption for messages
- TLS 1.2+ for all data in transit
- AES-256 encryption for data at rest
- Secure password hashing
- Regular security audits and penetration testing
- Access controls and role-based permissions
- Intrusion detection and prevention systems
- DDoS protection and rate limiting
14.2 Data Breach Notification
In the unlikely event of a confirmed data breach:
- We will notify affected users within 72 hours (as required by UK GDPR)
- Notification will include details of the breach and impact
- Guidance on protective steps will be provided
- We will notify the ICO (Information Commissioner's Office) if the breach involves significant risk
You will be notified via the email address on your account. Do not rely on second-hand reports of breaches; check official Thiskrit announcements.
15. Third-Party Links & Integrations
The Thiskrit App may contain links to third-party websites or services. Thiskrit is not responsible for the privacy practices of third-party sites. We encourage you to review their privacy policies before providing any data.
Thiskrit does not intentionally integrate with social media platforms for tracking, login, or data collection. If you choose to log in via third-party authentication (if available), you are subject to both this Privacy Policy and the third-party provider's terms.
16. Contact & Complaints
16.1 Privacy Inquiries
If you have questions about this Privacy Policy or how your data is handled:
- privacy@thiskrit.com
- Thiskrit Ltd, Oxford, United Kingdom
- Response time
- Within 10 business days
16.2 Data Protection Officer
For data protection-specific inquiries: support@thiskrit.com
16.3 Data Protection Complaints
If you believe Thiskrit has violated your data protection rights, you have the right to file a complaint with the Information Commissioner's Office (ICO):
- Website
- ico.org.uk
- Phone
- 0303 123 1113
- casework@ico.org.uk
17. Policy Updates & Changes
Thiskrit may update this Privacy Policy from time to time. Material changes will be announced via:
- In-app notification
- Email to your registered address
- Updated policy on this page (with new ‘Last Updated’ date)
Continued use of the App after changes constitutes acceptance of the updated policy. We recommend reviewing this policy periodically for updates.
18. UK GDPR Special Provisions
18.1 Legal Basis for Processing
We process your personal data based on the following legal grounds under UK GDPR:
- Consent
- You consent to account creation and use of the App
- Contract
- Processing is necessary to provide the Service you requested
- Legal obligation
- Processing required by law (e.g. child protection)
- Legitimate interests
- Preventing fraud, improving the App, and protecting rights
18.2 Lawful Basis for Each Data Type
- Account data (email, username)
- Contract
- User-generated content (posts, messages)
- Contract & User Control
- Crash reports
- Legitimate interest (improving app stability)
- IP logs
- Legitimate interest (security and fraud prevention)
18.3 Privacy Impact Assessment
Thiskrit conducts Data Protection Impact Assessments (DPIA) for high-risk processing. A summary is available upon request.
19. Compliance with App Store Policies
19.1 Apple App Store Privacy Requirements
This Privacy Policy complies with Apple's App Store Review Guidelines:
- Data collection is limited to essential functions
- All collection methods are disclosed
- Users have control over their data (delete account, delete content)
- Data is not shared with third-party advertisers
- No tracking for advertising purposes
- Age restrictions are enforced (16+)
19.2 Google Play Store Privacy Requirements
This Privacy Policy complies with Google Play's Developer Policy:
- Clear disclosure of data collection
- User consent for sensitive data
- Commitment to data security
- Commitment not to sell personal data
- Respect for device permissions
- Age-appropriate content policies
20. Acknowledgment & Acceptance
By downloading, installing, and using the Thiskrit App, you:
- Acknowledge that you have read this entire Privacy Policy
- Confirm you understand how your data is collected and used
- Consent to the processing of your personal data as described
- Accept the terms and conditions of this Policy
- Confirm you are at least 16 years old (or have parental consent if 13–15)
If you do not agree to this Policy, do not use the App.
This Privacy Policy is effective from 14 August 2026. Thiskrit Ltd — Protecting Your Privacy by Design. Questions? Contact manthan@thiskrit.com.