MyCampus

MyCampus Privacy Policy

Effective Date: April 5, 2026 Last Updated: April 5, 2026 Version: 1.0


This Privacy Policy ("Policy") describes in detail how Krtuworks LLC ("Krtuworks," "Company," "we," "us," "our"), a Wyoming Limited Liability Company (Entity ID: 2022-001108715), collects, receives, uses, processes, stores, shares, transfers, retains, protects, and deletes your personal information and data when you access, use, or interact with the MyCampus platform, including all mobile applications (iOS and Android), web-based interfaces, application programming interfaces ("APIs"), WebSocket connections, push notification delivery systems, AI-assisted features, background services, and all related services, features, content, and functionality (collectively, the "Service" or "Platform").

This Policy also covers: our use of cookies and similar technologies; our data retention and deletion practices; your rights under applicable privacy and data protection laws; our international data transfer practices; our use of artificial intelligence and machine learning; and the privacy practices applicable to specific features such as messaging, marketplace, matching, clubs, company accounts, and academic schedule features.

This Policy should be read together with our Terms of Service. If there is a conflict between this Policy and the Terms of Service regarding data processing practices, this Policy governs. If you do not agree with the practices described in this Policy, do not use the Service.


TABLE OF CONTENTS

Part I -- Core Privacy

  1. Data Controller and Contact Information
  2. Scope of This Policy
  3. Information We Collect
  4. How We Collect Information
  5. How We Use Your Information
  6. How We Share Your Information

Part II -- Legal Bases and International Compliance

  1. Legal Bases for Processing (GDPR)
  2. Turkish Data Protection (KVKK)
  3. United States Privacy Laws

Part III -- Third-Party Services and Data Transfers

  1. Third-Party Service Providers
  2. International Data Transfers

Part IV -- Cookies and Tracking Technologies

  1. Cookies, Local Storage, and Similar Technologies

Part V -- Data Retention and Deletion

  1. Data Retention Schedule
  2. Account Deletion and Data Erasure

Part VI -- Your Rights and Security

  1. Your Privacy Rights
  2. Automated Decision-Making and Profiling
  3. Security Measures
  4. Data Breach Notification

Part VII -- Feature-Specific Privacy

  1. AI Features, Gossi, and Machine Learning
  2. Messaging and Communication Privacy
  3. Voice and Video Call Privacy
  4. Location Data
  5. Marketplace and Financial Data
  6. Matching and Discovery (Quickmatch) Privacy
  7. Company and Business Account Data
  8. Club and Organization Data
  9. Academic Schedule and Notification Data
  10. Notification Preferences
  11. Feed Algorithm and Personalization Data
  12. Telemetry and Analytics
  13. Media Upload and Processing
  14. Children and Minors

Part VIII -- General

  1. Do Not Track and Global Privacy Control
  2. Changes to This Policy
  3. Contact Information

PART I -- CORE PRIVACY


1. Data Controller and Contact Information

1.1 Data Controller

The data controller responsible for the processing of your personal data is:

Krtuworks LLC Wyoming Limited Liability Company (USA) Entity ID: 2022-001108715 30 N Gould St, Ste R, Sheridan, WY 82801, United States of America Phone: +1 (307) 429-3359

1.2 Privacy Contact

For all privacy-related inquiries, data protection requests, rights exercises, complaints, or questions about this Policy:

Purpose Contact
Privacy, data rights, GDPR, KVKK, CCPA requests [email protected]
General support, account issues [email protected]
Physical mail Krtuworks LLC, Attn: Privacy/Legal, 30 N Gould St, Ste R, Sheridan, WY 82801, USA

1.3 Data Protection Inquiries

Krtuworks does not currently maintain a formally designated Data Protection Officer (DPO). All data protection inquiries are handled by our legal and compliance team at [email protected]. If appointment of a DPO becomes required under applicable law, we will update this section accordingly.


2. Scope of This Policy

2.1 What This Policy Covers

This Policy applies to all personal data processed in connection with:

(a) The MyCampus mobile applications (iOS and Android);

(b) The MyCampus web-based interfaces;

(c) The MyCampus APIs and real-time connections;

(d) The Krtuworks admin panel and moderation tools;

(e) The Krtuworks business panel for company account management;

(f) Push notification delivery systems (push notification services);

(g) AI-assisted features (Gossi conversational agent, media analysis);

(h) Voice and video call features (facilitated through third-party infrastructure);

(i) Email communications between you and Krtuworks (verification, password reset, notifications, security alerts);

(j) Background services and scheduled tasks (academic reminders, content cleanup, analytics aggregation);

(k) Any other service, feature, or communication operated by Krtuworks in connection with MyCampus.

2.2 What This Policy Does NOT Cover

This Policy does not apply to:

(a) Third-party websites, applications, platforms, or services that are linked from, integrated with, or referenced by the Service -- they have their own privacy policies, and we encourage you to read them before providing information;

(b) Information that other users collect about you through the Service, including screenshots, copies, recordings, or redistributions of your content by other users outside the Service;

(c) Data that has been permanently and irreversibly anonymized, de-identified, or aggregated such that it can no longer reasonably be used to identify you, either alone or in combination with other data;

(d) Publicly available information about universities and educational institutions obtained from public sources (such as public encyclopedia) and used for informational enrichment of the Service.

2.3 Users Outside Our Primary Jurisdictions

MyCampus is a global service available to university communities worldwide. While our servers are located in the European Union (Germany) and our company is registered in the United States, users from many jurisdictions use the Service. We endeavor to comply with applicable data protection laws in all jurisdictions where we operate. If your jurisdiction has specific privacy requirements not addressed in this Policy, please contact us at [email protected].


3. Information We Collect

We collect different categories and types of information depending on how you use the Service, which features you access, and what information you choose to provide. Not all data described below is collected from every user. This section provides a comprehensive inventory of all personal data we may collect.

3.1 Account and Identity Data

Data Purpose Required/Optional
Email address (university domain) Account creation, verification (6-digit OTP), communications, account recovery Required
Username Unique public identifier (reserved for 90 days after deletion) Required
Password (stored exclusively as a secure one-way hash, never in plaintext) Authentication Required
University affiliation (university ID, domain) Eligibility verification, community assignment, content scoping Required
Department Profile display, community features, AI context Required at registration
Year (enrollment year) Profile display, community features, AI context Required at registration
Account status (active, suspended, frozen, banned, deleted) Service operation, moderation enforcement System-generated
Account roles (USER, ADMIN; CompanyRole: OWNER, ADMIN, POSTER) Access control, permission management System-generated
Platform ToS acceptance timestamp and version Legal compliance, consent records System-generated
Account creation timestamp Service operation, retention scheduling System-generated
Last active timestamp Online status, session management, account lifecycle System-generated
Recovery email (personal email, for graduates) Account recovery after university email loss Optional

3.2 Profile and Preferences

Data Purpose Required/Optional
Bio (up to 500 characters) Profile display, AI context for Gossi Optional
Avatar / profile picture URL Profile display Optional
Banner image URL Profile display Optional
Gender (male, female, non_binary) Matching features, profile display Optional
Birth date Age verification (minimum 16), matching features Optional
Feed preference (algorithmic / chronological) Personalization Optional (default: algorithmic)
Privacy setting (public / private profile) Access control, content visibility Optional (default: public)
Online status visibility toggle Privacy control Optional (default: visible)
Location sharing toggle Privacy control for matching Optional (default: off)
Social media links (Instagram, Twitter/X, LinkedIn, etc.) Profile display Optional
Gossi memory toggle (enabled / disabled) Controls whether Gossi AI stores contextual notes about you Optional (default: enabled)
Company DM preference (ALL / VERIFIED_ONLY / NONE) Company account messaging control Optional (default: ALL)

3.3 Content and Activity Data

Data Purpose
Posts (text, title, media URLs, location tags, poll data) Core features, content delivery
Comments and threaded replies Core features, discussion
Poll votes and poll responses Polling features
Mentions (users you mention and mentions of you) Social features, notifications
Reactions (upvotes, downvotes on posts and comments) Engagement features, content ranking
Saves (bookmarked posts) Personal content management
Shares (posts shared in messages) Social features
Community memberships, roles, and activity Group features, access control
Confession post authorship (hidden from other users, retained by Krtuworks) Safety, moderation, legal compliance
Content deduplication identifiers Content deduplication, integrity
Engagement metrics (upvote/downvote counts, comment counts, share counts, view counts) Content ranking, feed algorithm
Quality scores and engagement rates Feed personalization
Post settings (comments enabled, Gossi enabled, pinned, locked, archived) User content control
Ratings (course ratings, professor ratings, club ratings, company ratings: 0.5-5.0 scale) Review features, community insights

3.4 Messaging and Communication Data

Data Purpose
Direct messages (one-on-one text, attachments, reactions, replies) Private communication
Group messages (text, attachments, reactions, replies, group name, avatar) Group communication
Message metadata (sender, recipient(s), timestamp, delivery status, read status) Message delivery, read receipts
Message reactions (emoji reactions on individual messages) Communication features
Starred/bookmarked messages Personal message management
Shared posts within messages Content sharing
Voice notes and audio messages Communication features
Typing indicators (real-time, not stored) Communication experience
Group membership changes (additions, removals, role assignments, ownership transfers) Group management, notifications
Conversation settings (mute status, notification preferences per conversation) User preferences

3.5 Voice and Video Call Data

Data Purpose
Call metadata (duration, participants, timestamps, call type: audio/video) Service quality, feature operation
Call status (ringing, accepted, rejected, ended, missed, cancelled) Call management
call infrastructure provider UID (unique per-user identifier for call infrastructure) Call routing
Call channel identifiers Session management

We do NOT record, store, or have access to the audio or video content of your calls. Call media is processed in real-time by third-party call infrastructure for routing and delivery only.

3.6 Marketplace and Commerce Data

Data Purpose
Marketplace listings (title, description, price, currency, category, images, condition) Commerce features
Marketplace type (buy/sell or housing) Listing categorization
Listing status (active, sold) Inventory management
QR verification codes (cryptographically signed verification data) In-person transaction verification
Transaction records (buyer, seller, amount, currency, status, timestamps) Transaction management
Seller ratings and review text (0.5-5.0 scale) Trust and safety
Marketplace rating aggregates (average rating, rating count per user) Reputation system
Target gender preference for listings Listing filtering
FindRoom housing data (contract type, house features, tenant preferences, location, rent amount, room details, amenities, photos) Housing search features

3.7 Matching and Discovery Data

Data Purpose
Match profile (age, gender, interests, bio, photos, "looking for" preferences) Matching algorithm
Maximum distance preference Location-based matching
Precise location (latitude/longitude) -- only when you opt in Proximity matching
Swipe history (likes, passes, super-likes with timestamps) Matching algorithm, connection management
Match records (mutual matches between users) Connection management
Daily swipe limit tracking Fair usage enforcement

3.8 Club and Organization Data

Data Purpose
Club memberships, roles, and permissions Club features, access control
Club governance data (term records, president assignments, board snapshots) Club management, accountability
Club event participation and attendance Event management
Club join requests and application status Membership workflows
Committee memberships and leadership assignments Internal club organization
Club ratings (0.5-5.0 scale) Community feedback
Club announcements (read status, priority level) Communication features

3.9 Company and Business Account Data

Data Purpose
Company name, path name, industry type Company identification
Company contact information (phone, website, address, company email) Business communication
Company verification documents (business licenses, certificates -- deleted after review) Trust and safety verification
Verification tier (None, Verified, Official, Enterprise) and status Access control, trust signals
Sub-account relationships (parent user ID linking Owner to Admin/Poster accounts) Account hierarchy management
Company ratings (0.5-5.0 scale, aggregate and individual) Reputation system
Cross-university post targeting (which universities a company post targets) Content distribution

3.10 Notification and Schedule Data

Data Purpose
Device push tokens (platform-specific push tokens) Push notification delivery
Device platform (iOS, Android) and locale Notification formatting, localization
Notification preferences (42 dismissable types, each with push and history toggles) User preference management
Disabled push notification types (list) Push delivery filtering
Disabled history notification types (list) History storage filtering
Academic schedule (course entries: codes, names, time slots, classrooms, exam dates) Schedule features, academic reminders
Schedule timezone and locale Timezone-aware notification delivery
Schedule sharing relationships (who you share your schedule with) Social schedule features

3.11 Safety and Moderation Data

Data Purpose
Reports you submit (report reason, additional context, content snapshots at time of report) Content moderation
Reports about your content or account (reporter identity confidential) Enforcement
Moderation actions (warnings with count, suspensions with duration and reason, bans with reason, freezes with source) Enforcement tracking
Disciplinary action history (action type, reason, duration, issuing moderator, appeal status) Enforcement accountability
Appeal submissions and outcomes Appeals process
Content snapshots preserved at time of report (post/comment content, metadata, media URLs) Evidence preservation
Ban evidence records (email, IP address, device info -- for permanent bans to prevent re-registration) Safety, re-registration prevention
Freeze source tracking (records how and why the account was frozen) Account lifecycle management

3.12 Security and Authentication Data

Data Purpose
Session tokens (stored securely, never in plaintext) Authentication
Session metadata (device name, device type, OS version, app version, build number) Device identification, security monitoring
IP address at login and during sessions Security, approximate geolocation, abuse prevention
User agent string Device and browser identification
Approximate location from IP (city, country via a third-party geolocation service) Session context, login alerts
2FA method type (TOTP, email, passkey) and enrollment status Account security
2FA authentication secrets (encrypted) TOTP verification
2FA backup codes (securely hashed) Emergency account recovery
2FA challenge records (challenge token, attempt count, state, device context, expiration) Security verification
Passkey/WebAuthn credentials (credential ID, public key, counter, device type, transports, AAGUID, name) Passwordless authentication
Password reset tokens (short-lived, ~15 minutes) Password recovery
Recovery request details (type, status, verification documents for graduate recovery) Account recovery
Email verification challenges (verification challenge records) Email verification
Last password change timestamp Security monitoring

3.13 Device and Technical Data

Data Purpose
Device type (iOS, Android, Web) Compatibility, feature availability
Device name (e.g., "iPhone 15 Pro", "Samsung Galaxy S24") Session identification, login alerts
Operating system and version Compatibility, debugging
App version and build number Version management, feature flags
Network type Service quality optimization
Push notification tokens (platform-specific push tokens) and platform Notification delivery
Device locale and language preference Localization

3.14 Logs, Analytics, and Telemetry Data

Data Purpose
Access logs (timestamp, HTTP method, URL path, status code, response time, user ID) Operation, debugging, security monitoring
Error logs (stack traces, error messages, context) Debugging, service reliability
Telemetry events (content viewing patterns, navigation, interactions, sharing, and app usage) Analytics, personalization, service improvement
Telemetry event metadata (event identifiers, session context, timestamps, and interaction details) Event context and deduplication
Daily aggregated telemetry (total screen time, session count, posts viewed, average dwell time, interaction breakdowns, hourly activity distribution, content type preferences) Trend analysis, personalization
Feed interaction data (engagement scores, quality scores, interaction weights) Feed personalization
User interaction scores (weighted affinity scores between users based on engagement patterns) Social graph, content recommendations
"Not interested" signals (post-level, author-level, topic-level) Content filtering, feed personalization
Vote metrics (processing times, internal operation durations) Performance monitoring

3.15 AI Processing Data

Data Purpose
Content submitted to Gossi AI (post text, comment text, community metadata, category-specific data, thread context, engagement metrics) AI reply generation
Gossi memory (AI-generated single paragraph per user summarizing observed characteristics, communication style, interests, and interaction patterns) Contextual AI responses
Gossi vote decisions (AI-determined upvote/downvote/neutral on content) AI engagement behavior
Media URLs submitted for AI analysis Automated media understanding
AI media analysis results (scene summaries, identified objects, extracted text, ambient descriptions) Content enrichment, AI context
Gossi rate limit tracking (usage counters and rate tracking) Fair usage enforcement

3.16 Location Data

Data Source Purpose Your Control
Precise GPS coordinates (latitude/longitude) Your device (opt-in only) Quickmatch proximity matching, post location tagging Disable in device settings or app
Approximate location (city, country) IP address via a third-party geolocation service Session context, login alerts, content localization Automatic
User-provided location (addresses, location names) You (FindRoom listings, post location tags) Housing search, location context You choose what to enter
Last known coordinates and update timestamp Quickmatch location sharing Location-based discovery Disable in device settings or app

3.17 Information from Third Parties and Other Users

Data Source Purpose
Mentions, messages, and tags referencing you Other users Social features, notifications
Reports about your content or account Other users Content moderation
Ratings and reviews about you (marketplace seller ratings) Other users Trust and safety, reputation
University content enrichment (names, locations, founding dates, descriptions -- not personal data) public encyclopedia API Informational content
Email deliverability status (bounce information) Email infrastructure Communication reliability
Push notification delivery status push notification services Notification reliability

4. How We Collect Information

4.1 Information You Provide Directly

We collect information that you voluntarily provide when you:

(a) Register for an account (email, username, password, university affiliation, department, year, optional birth date and gender);

(b) Create or edit your profile (bio, avatar, banner, social links, preferences);

(c) Create content (posts, comments, polls, ratings, reviews);

(d) Send messages (text, media, voice notes, reactions);

(e) Create marketplace listings or housing listings;

(f) Set up matching profiles (interests, preferences, photos, bio);

(g) Create or manage clubs (events, announcements, roles, committees);

(h) Register a Company Account (company details, contact information, verification documents);

(i) Enable two-factor authentication (2FA method selection, device registration);

(j) Configure notification preferences (push and history toggles for individual notification types);

(k) Enter academic schedule data (courses, times, classrooms, exam dates);

(l) Share your schedule with other users;

(m) Submit reports about content or users;

(n) Submit appeals against moderation decisions;

(o) Contact us through support or legal channels;

(p) Respond to surveys, promotions, or research requests;

(q) Interact with Gossi AI (by mentioning @gossi, which triggers AI processing of your content and context);

(r) Provide feedback, suggestions, or bug reports.

4.2 Information Collected Automatically

When you access or use the Service, we automatically collect:

(a) Device and session data: Device type, name, operating system, app version, build number, user agent string, IP address, and device tokens for push notifications;

(b) Usage and interaction data: Pages viewed, features used, actions taken (posts, comments, votes, messages, follows, blocks, saves, shares), timestamps of actions, and navigation patterns;

(c) Telemetry data: Engagement events (dwell time on posts, photo expansions, video watch duration, scroll depth, link clicks, share actions, save actions, follow conversions, session duration, screen views, app foreground/background transitions);

(d) Performance data: Service response times, error rates, and system health metrics;

(e) Location data: Approximate location derived from your IP address (city and country level, via a third-party geolocation service). Precise GPS location is collected only when you explicitly enable location sharing for matching features;

(f) Communication metadata: Message delivery and read receipt timestamps, call duration and participant information, typing indicator events (real-time only, not stored);

(g) Security data: Login timestamps, session creation and expiration events, 2FA challenge attempts and outcomes, password change events;

(h) AI interaction data: When you mention @gossi, contextual data about the post, comments, community, and your previous interactions is compiled and processed through our AI infrastructure.

4.3 Information from Other Users

We receive information about you from other users when they:

(a) Mention you in posts or comments (creating mention references linked to your account);

(b) Send you messages (creating message records with your user ID as recipient);

(c) Report your content or account (creating report records referencing your content or user ID);

(d) Rate you as a marketplace seller (creating rating records linked to your account);

(e) Follow, block, or interact with your account (creating relationship records);

(f) Share your posts in messages (creating share references);

(g) Add you to group conversations (creating participant records);

(h) Share their academic schedule with you (creating schedule sharing relationships).

4.4 Information from Third-Party Services

We receive limited information from third-party services:

(a) Email infrastructure: Delivery status, bounce information, and deliverability signals for emails we send to you;

(b) Push notification services (push notification services): Delivery receipts, token validity status, and error responses;

(c) IP geolocation (third-party geolocation service): Approximate city and country based on your IP address;

(d) AI media analysis: Our proprietary AI systems generate analysis results (scene descriptions, identified objects, extracted text, ambient descriptions) for media you upload to the Service;

(e) Voice/video call infrastructure (call infrastructure provider): Call quality metrics, connection status, and participant metadata (no audio/video content);

(f) public encyclopedia API: Publicly available university information used for content enrichment (not personal data).


5. How We Use Your Information

We use the information we collect for the following purposes. Each purpose is linked to one or more legal bases described in Part II.

5.1 Providing and Operating the Service

Account creation, authentication, and session management; core feature delivery (communities, posts, messaging, calls, marketplace, housing, matching, clubs, company accounts); content storage, processing, delivery, and display; media upload, processing, optimization, and delivery through CDN; push notification delivery, in-app notifications, and email communications; academic schedule management and reminder delivery; real-time features (WebSocket updates, typing indicators, online status); search, discovery, and content indexing; and all other functionality necessary to operate the Service as described in our Terms of Service.

5.2 Personalization and Recommendations

Algorithmic feed ranking based on engagement signals, recency, relevance, social graph proximity, and user interaction history; content recommendations based on community memberships, topic affinity, and content type preferences; matching suggestions based on profile compatibility, interests, and proximity; trending content identification based on engagement velocity; "not interested" signal processing for content filtering; and learning user preferences over time through telemetry and interaction data.

5.3 AI Features

Generating Gossi AI replies to user mentions using contextual information (post content, comments, community data, category-specific metadata, Gossi memory); processing Gossi votes (AI-determined upvotes/downvotes) on content; maintaining and updating Gossi per-user memory (AI-generated contextual notes about users who interact with Gossi); automated media analysis (generating scene descriptions, object identification, text extraction, and contextual metadata for uploaded images and videos); university content enrichment using publicly available data sources and language model processing; content safety screening and spam detection.

5.4 Safety, Security, and Integrity

Account security (two-factor authentication, session management, new login alerts, credential protection); content moderation (automated scanning for policy violations, human review of reported content); abuse prevention (rate limiting, behavioral pattern detection, multi-account detection); file validation and malware scanning; report processing and disciplinary action enforcement; re-registration prevention for banned accounts; email deliverability monitoring; and protecting the rights, property, and safety of Krtuworks, our users, and the public.

5.5 Communications

Transactional emails (account verification OTP codes, password reset codes, 2FA verification codes, security alerts, moderation notifications, account status changes); service announcements and platform updates; push notifications for real-time events (messages, comments, votes, mentions, calls, schedule reminders, moderation actions); in-app notification history; and administrative broadcast notifications.

5.6 Analytics and Service Improvement

Usage analytics and telemetry processing (engagement patterns, feature usage, session metrics); aggregated analytics (activity summaries, content performance metrics); performance monitoring and optimization; aggregated and anonymized insights for feature development, product decisions, and service quality improvement; and data integrity verification.

Complying with applicable laws, regulations, and legal processes; responding to lawful requests from law enforcement, regulatory authorities, and courts of competent jurisdiction; enforcing our Terms of Service, Community Guidelines, and other policies; establishing, exercising, or defending legal claims; and maintaining records required by applicable tax, financial, and regulatory requirements.


6. How We Share Your Information

6.1 With Other Users

As part of normal Service operation, certain information is shared with other users:

(a) Public profile information: Username, avatar, banner, bio, department, year, university affiliation, social links, online status (if enabled), and public/private designation;

(b) Content you post: Posts, comments, ratings, reviews, and media shared in public or semi-public communities are visible to other community members;

(c) Messages: Message content is shared with message recipients (individual and group);

(d) Matching profiles: Your matching profile information is visible to other users in the matching pool;

(e) Marketplace listings: Listing details (title, description, price, images, seller rating) are visible to eligible users;

(f) Club information: Your club membership, roles, and public club activities are visible to club members and, for certain information, to all university community members;

(g) Company information: Company profile, posts, ratings, and verification status are publicly visible;

(h) Schedule sharing: If you choose to share your schedule, the recipient can view your course entries and times;

(i) Reactions and engagement: Your votes, comments, mentions, and other interactions are reflected in content engagement metrics (individual votes are not publicly attributed);

(j) Confession posts: When you comment on confession posts, if you are the original post author, your comments appear as "Anonymous" to other users.

6.2 With Service Providers

We share data with third-party service providers who assist in operating the Service. Each provider receives only the data necessary for their specific function and is contractually obligated to use data solely for the specified purposes. Our current service providers are listed in Section 10.

We may disclose personal data when we believe in good faith that disclosure is necessary to:

(a) Comply with applicable law, regulation, legal process, or governmental request (including subpoenas, court orders, search warrants, and national security letters);

(b) Enforce our Terms of Service, Community Guidelines, and other policies;

(c) Detect, investigate, prevent, or address fraud, security issues, technical problems, or violations of our policies;

(d) Protect the rights, property, safety, or security of Krtuworks, our users, or the public, as required or permitted by law;

(e) Respond to emergency situations involving imminent danger of death or serious physical injury to any person;

(f) Cooperate with law enforcement investigations, including providing preserved data in response to valid legal process;

(g) Report suspected child sexual abuse material (CSAM) to the National Center for Missing & Exploited Children (NCMEC) and/or the International Centre for Missing & Exploited Children (ICMEC) and relevant law enforcement authorities (mandatory under applicable law);

(h) Report terrorist or violent extremist content to relevant authorities as required by law.

6.4 In Connection with Business Transfers

In the event of a merger, acquisition, reorganization, bankruptcy, receivership, dissolution, sale of all or substantially all assets, or other similar corporate transaction, your personal data may be transferred to the acquiring entity or successor. In such event:

(a) We will notify you through available channels (email, in-app notification, or prominent notice on the Service) before your personal data is transferred and becomes subject to a different privacy policy;

(b) Where required by law, we will seek your consent before completing the transfer;

(c) The acquiring entity will assume the obligations under this Policy with respect to your previously collected data.

We may share your personal data with third parties when you have given your explicit consent for a specific sharing purpose. You may withdraw consent at any time, though withdrawal does not affect the lawfulness of processing performed prior to withdrawal.

6.6 Aggregated and De-Identified Data

We may share data that has been aggregated, de-identified, or anonymized such that it can no longer reasonably be used to identify you. Such data is not subject to the restrictions of this Policy. Examples include: aggregate usage statistics, anonymized engagement metrics, trend reports, and platform health indicators.

6.7 What We Do NOT Do

Krtuworks makes the following commitments regarding your data:

(a) We do NOT sell your personal information to data brokers, advertisers, analytics companies, or any third party for monetary or other valuable consideration;

(b) We do NOT share your personal data for cross-context behavioral advertising, targeted advertising by third parties, or ad-tech profiling;

(c) We do NOT share private message content with anyone other than the intended participants, except for safety/moderation purposes (reported messages) or valid legal process;

(d) We do NOT reveal the identity of confession/anonymous post authors to other users under any circumstances through the Service interface;

(e) We do NOT share your precise GPS location with other users without your explicit opt-in consent (matching feature location sharing);

(f) We do NOT share your IP address or approximate IP-based location with other users;

(g) We do NOT use your personal data to train general-purpose AI models, large language models, or image generation models;

(h) We do NOT provide third-party advertisers with access to your personal data for their own marketing purposes;

(i) We do NOT create advertising profiles, interest-based marketing segments, or behavioral tracking dossiers about our users for sale or distribution to third parties.


PART II -- LEGAL BASES AND INTERNATIONAL COMPLIANCE


Where the General Data Protection Regulation (EU) 2016/679 ("GDPR") or the UK General Data Protection Regulation ("UK GDPR") applies to our processing of your personal data, we rely on the following legal bases. Each processing activity may rely on one or more bases as appropriate.

7.1 Performance of Contract (Article 6(1)(b))

Processing necessary for the performance of our contract with you (these Terms of Service), including:

Account creation, authentication, and session management; core feature delivery (communities, posts, comments, messaging, voice/video calls, marketplace, housing listings, matching, clubs, company accounts, schedule features); content hosting, storage, processing, and delivery; media upload, optimization, and CDN delivery; push notification delivery for Service-related events; real-time features (WebSocket updates, typing indicators, online status); academic schedule reminders and notifications; Gossi AI reply generation when you mention @gossi; marketplace transaction management and QR verification; search, discovery, and content indexing; account recovery and password reset; and two-factor authentication services.

7.2 Legitimate Interests (Article 6(1)(f))

Processing necessary for our legitimate interests or those of a third party, where those interests are not overridden by your fundamental rights and freedoms:

Processing Activity Legitimate Interest Safeguard
Content moderation (automated + human) Safe, trustworthy platform Users can appeal all decisions; human review for significant actions
Abuse and fraud prevention (rate limiting, multi-account detection, IP monitoring) Platform integrity, user protection Proportionate measures; automated flags reviewed by humans
Usage analytics and telemetry Service improvement, performance optimization Aggregated where possible; limited retention for raw events
Feed personalization and algorithmic ranking Relevant, engaging user experience Users can choose chronological feed; "not interested" controls available
AI features (Gossi replies, media analysis) Enhanced user experience, content enrichment User controls (disable Gossi per post, disable memory); data not used for model training
Security logging (IP addresses, sessions, login events) Unauthorized access prevention, incident response Limited retention; access restricted to authorized personnel
IP geolocation (approximate city/country) Session context, login security alerts Approximate only; not shared with other users
Interaction scoring and social graph analysis Content relevance, meaningful connections Automated; used only for internal ranking; not disclosed to third parties
Gossi per-user memory Improved conversational continuity User can view, delete, or disable memory entirely at any time
Email deliverability monitoring Reliable communication Automated; used only for delivery optimization
Bug reporting and error logging Service reliability, debugging Limited retention; minimized personal data in logs

You have the right to object to processing based on legitimate interests at any time (see Section 15). We will cease processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing is necessary for the establishment, exercise, or defense of legal claims.

7.3 Consent (Article 6(1)(a))

Processing based on your freely given, specific, informed, and unambiguous consent:

Processing Activity How to Withdraw Consent
Precise GPS location sharing (Quickmatch matching) Disable location sharing in device settings or app preferences
Gossi memory storage (AI contextual notes about you) Disable through in-app Gossi settings
Optional profile data (bio, gender, birth date, social links) Remove or modify in profile settings

Withdrawing consent does not affect the lawfulness of processing performed before withdrawal. Withdrawal may affect the availability or functionality of features that rely on the withdrawn consent.

7.4 Legal Obligation (Article 6(1)(c))

Processing necessary to comply with a legal obligation to which we are subject:

Law enforcement requests and court orders; mandatory reporting of child sexual abuse material (CSAM) to NCMEC/ICMEC; tax and financial record-keeping requirements for marketplace transactions; data breach notification obligations under GDPR, KVKK, and applicable US state laws; age verification requirements under applicable child protection laws; content removal obligations under applicable laws (e.g., EU Digital Services Act, national court orders); and preservation of data subject to legal holds or litigation preservation obligations.

7.5 Vital Interests (Article 6(1)(d))

In exceptional circumstances, we may process personal data to protect the vital interests of you or another person, including: responding to imminent threats of self-harm or harm to others identified on the Platform; cooperating with emergency services in life-threatening situations; and preserving evidence related to credible, imminent threats of violence.

7.6 Special Categories of Data (Article 9)

We do not intentionally collect special category data (data revealing racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic data, biometric data for identification, health data, or data concerning sex life or sexual orientation). However:

(a) Gender and orientation data in matching profiles: Processed based on your explicit consent when you create a matching profile. You may remove this data at any time by deleting your matching profile;

(b) Recovery documents (transcripts, diplomas): May contain education-related data. Processed based on your explicit consent when you submit a recovery request. Documents are reviewed and permanently deleted within 24-48 hours;

(c) Health-related content in user posts: If you voluntarily share health information in posts, comments, or messages, such sharing is your choice and is not systematically collected or processed by us for health-related purposes.


8. Turkish Data Protection (KVKK)

Where the Turkish Personal Data Protection Law (Kisisel Verilerin Korunmasi Kanunu, Law No. 6698, "KVKK") applies to our processing of your personal data:

8.1 Processing Principles (Article 4)

We adhere to the following principles in all processing of personal data of Turkish data subjects:

(a) Lawfulness and fairness: Data is processed in accordance with law and principles of good faith;

(b) Accuracy and currency: We take reasonable measures to ensure personal data is accurate and up-to-date, and provide mechanisms for you to correct inaccurate data;

(c) Purpose limitation: Data is collected for specified, explicit, and legitimate purposes and not further processed in a manner incompatible with those purposes;

(d) Data minimization: Data collected is adequate, relevant, and limited to what is necessary for the purposes of processing;

(e) Limited retention: Data is retained only for as long as necessary for the purposes for which it was collected or as required by applicable law;

(f) Integrity and confidentiality: Appropriate technical and organizational measures are implemented to ensure data security.

8.2 Legal Bases (Article 5)

We process personal data of Turkish data subjects on the following legal bases:

(a) Explicit consent (Article 5(1)): For optional features requiring opt-in (precise location sharing, Gossi memory, optional profile data);

(b) Necessity for contract performance (Article 5(2)(c)): For processing necessary to provide the Service under our Terms;

(c) Legal obligation (Article 5(2)(c)): For processing required by Turkish law or regulation;

(d) Establishment, exercise, or protection of a right (Article 5(2)(e)): For processing necessary to establish, exercise, or protect legal claims;

(e) Legitimate interests (Article 5(2)(f)): For processing necessary for our legitimate interests, provided that the fundamental rights and freedoms of the data subject are not harmed. This includes security measures, analytics, content moderation, and service improvement.

8.3 Sensitive Data (Article 6)

Sensitive personal data (as defined under KVKK Article 6, including data relating to race, ethnicity, political opinions, philosophical beliefs, religion, sect, appearance, membership of associations/foundations/trade unions, health, sexual life, criminal convictions, and biometric/genetic data) is processed only with explicit consent or where permitted by law. We do not systematically collect sensitive data categories as defined under KVKK.

8.4 Your KVKK Rights (Article 11)

As a data subject under KVKK, you have the right to:

(a) Learn whether your personal data is being processed;

(b) Request information about the processing if your data has been processed;

(c) Learn the purpose of processing and whether your data is used in accordance with that purpose;

(d) Know the third parties to whom your data has been disclosed, domestically or internationally;

(e) Request correction of incomplete or inaccurate personal data;

(f) Request deletion or destruction of your personal data under the conditions set forth in KVKK Article 7;

(g) Request that corrections, deletions, or destruction be notified to third parties to whom your data has been transferred;

(h) Object to any result produced against you by automated processing of your personal data;

(i) Claim compensation for damages arising from unlawful processing of your personal data.

How to exercise: Send your request to [email protected] with the subject line "KVKK Request." We will verify your identity and respond within thirty (30) days.

8.5 Data Transfer Outside Turkey (Article 9)

Transfers of personal data of Turkish data subjects outside Turkey comply with KVKK Article 9 requirements, including: explicit consent of the data subject; adequate protection in the receiving country; or binding commitments providing adequate protection where the receiving country lacks an adequacy determination from the Turkish Personal Data Protection Board.


9. United States Privacy Laws

9.1 California (CCPA/CPRA)

If you are a California resident, you have rights under the California Consumer Privacy Act, as amended by the California Privacy Rights Act ("CCPA/CPRA," Cal. Civ. Code Section 1798.100 et seq.):

Categories of Personal Information Collected:

CCPA Category MyCampus Examples
Identifiers (Section 1798.140(v)(1)(A)) Email address, username, user ID, IP address, device identifiers, push tokens
Personal records (Cal. Civ. Code Section 1798.80(e)) Account credentials, university affiliation, department, year
Protected classifications Age (birth date), gender (optional)
Commercial information Marketplace listings, orders, transactions, purchase history, ratings
Internet/electronic network activity Usage logs, telemetry events, interactions, feed activity, session data, browsing history within the Service
Geolocation data Precise GPS coordinates (optional), IP-based approximate location (city/country)
Sensory data Uploaded images, videos, audio/voice notes
Education information University affiliation, department, year, academic schedule, course codes, recovery documents
Professional/employment information Company account data, company role (OWNER/ADMIN/POSTER)
Inferences drawn Engagement scores, feed ranking scores, interaction affinity scores, content quality scores, topic/content type preferences
Sensitive personal information Account credentials, precise geolocation (when opted in), private message content, education records, recovery documents

Sale and Sharing: We do NOT sell personal information to third parties for monetary or other valuable consideration. We do NOT share personal information for cross-context behavioral advertising. We do not engage in targeted advertising or data brokerage.

Sensitive Personal Information: Used only for providing the Service, ensuring security, and as otherwise permitted by CPRA Section 1798.121. We do not use sensitive personal information for profiling purposes or for inferring characteristics about you for advertising.

Your California Rights:

(a) Right to Know: Request the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purpose for collection, and the categories of third parties to whom we have disclosed your information;

(b) Right to Delete: Request deletion of your personal information, subject to legal exceptions (ongoing transactions, legal obligations, security, internal uses consistent with expectations, compliance with law);

(c) Right to Correct: Request correction of inaccurate personal information;

(d) Right to Opt-Out of Sale/Sharing: Not applicable as we do not sell or share personal information, but we honor such requests;

(e) Right to Limit Sensitive Data Use: Request that we limit our use of sensitive personal information to uses necessary for providing the Service;

(f) Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights, including by denying services, charging different prices, providing a different level of service, or suggesting any of the foregoing.

How to Exercise California Rights:

Financial Incentives: We do not offer financial incentives, price differences, or service-level differences in exchange for the retention or sale of personal information.

9.2 Other US State Privacy Laws

We comply with applicable state privacy laws, including but not limited to:

(a) Virginia Consumer Data Protection Act (VCDPA): Rights to access, correct, delete, obtain a copy, and opt out of targeted advertising and sale;

(b) Colorado Privacy Act (CPA): Similar rights with universal opt-out mechanism recognition;

(c) Connecticut Data Privacy Act (CTDPA): Rights to access, correct, delete, obtain, and opt out;

(d) Utah Consumer Privacy Act (UCPA): Rights to access, delete, and opt out;

(e) Other enacted state privacy laws: We monitor and comply with new state privacy legislation as it takes effect.

For all US state privacy rights requests, contact [email protected]. We will process your request in accordance with the applicable state law and respond within the timeframes required by that law.

9.3 Global Privacy Control (GPC)

We acknowledge Global Privacy Control (GPC) signals as valid expressions of user privacy preferences where required by applicable law (including California, Colorado, and Connecticut). Since we do not sell or share personal information for advertising or cross-context behavioral purposes, our existing data practices already comply with the opt-out preferences expressed by GPC signals without requiring additional technical action.

9.4 Shine the Light (California Civil Code Section 1798.83)

California residents may request information about any disclosures of personal information to third parties for their direct marketing purposes. Since we do not disclose personal information to third parties for their direct marketing purposes, this requirement is satisfied by this disclosure. For inquiries, contact [email protected].


PART III -- THIRD-PARTY SERVICES AND DATA TRANSFERS


10. Third-Party Service Providers

We use the following categories of third-party service providers to operate the Service. Each provider receives only the minimum data necessary for their specific function. We enter into data processing agreements with providers where required by applicable law.

10.1 Hosting and Infrastructure

Provider Function Data Processed Location
EU-based hosting provider Primary server hosting and compute (dedicated server) All Service data (database, application, cache, media processing) Germany (EU)

10.2 Content Storage and Delivery

Provider Function Data Processed Location
Global cloud storage and CDN provider Media file storage (images, videos, documents), backups, CDN delivery Uploaded media files, file metadata (size, type, dimensions) Global (global infrastructure)

10.3 Push Notifications

Provider Function Data Processed Location
Push notification routing provider Push notification routing and delivery to iOS and Android devices Push tokens, notification payload (title, body, badge count, deep link, category), device platform USA
iOS push notification service iOS push notification delivery (via push notification routing) Push tokens, notification payload USA (Apple infrastructure)
Android push notification service Android push notification delivery (via push notification routing) Push tokens, notification payload USA (Google infrastructure)

10.4 Voice and Video Communication

Provider Function Data Processed Location
Voice and video call provider Real-time voice and video call infrastructure (media routing, not recording) Call media streams (audio/video, processed in real-time only, not stored), participant UIDs, channel identifiers, call quality metrics Global (call provider infrastructure)

We do NOT record call audio or video content. The call provider processes call media solely for real-time routing and delivery.

10.5 AI and Machine Learning

AI and machine learning features (including the Gossi conversational agent, automated media analysis, content safety systems, and university content enrichment) are powered by Krtuworks's proprietary AI infrastructure. Our AI systems are developed, operated, and maintained by Krtuworks and run on our own infrastructure hosted within the European Union. AI processing details, data flows, and user controls are described in detail in Section 19 of this Policy. We do not use your personal data to train general-purpose AI models.

10.6 Geolocation

Provider Function Data Processed Location
third-party geolocation service Approximate location lookup from IP address (city, country) IP address (queried), returned city/country string Germany

Results are cached temporarily in our infrastructure to minimize external lookups.

10.7 Content Enrichment

Provider Function Data Processed Location
Public encyclopedia API University information enrichment (names, descriptions, coordinates, history) University names and search queries (no personal data) USA (encyclopedia API infrastructure)
UI-Avatars Default avatar generation from username initials First letter of username (no other personal data) Global

10.8 Security

Provider Function Data Processed Location
Automated certificate authority TLS/SSL certificate issuance and renewal for encrypted connections Server domain names (no personal data) USA
DNS and DDoS protection provider DNS resolution, DDoS protection, traffic proxying IP addresses (in transit), HTTP request metadata Global

10.9 Email

Provider Function Data Processed Location
Self-hosted email service Transactional email delivery (verification codes, password resets, security alerts, moderation notifications) Recipient email address, email content, delivery status Self-hosted, Germany (EU) -- data does not leave our servers

10.10 Subprocessor Management

We conduct due diligence on all third-party service providers before engagement, including review of their security practices, data protection policies, and compliance certifications. We enter into data processing agreements (DPAs) with providers where required by GDPR, KVKK, or other applicable law. We periodically review provider compliance and security posture. Material changes to our subprocessor list are communicated in updates to this Policy.


11. International Data Transfers

11.1 Where Your Data Is Processed

MyCampus primary infrastructure is hosted in the European Union (Germany (EU)). Your data may also be processed in the following locations as part of Service operation:

Location Services Data Types
European Union (Germany) Primary server, database, in-memory cache, self-hosted AI, self-hosted email All Service data (primary processing location)
United States Krtuworks corporate operations, push notification services, call infrastructure provider (call infrastructure), CDN provider (CDN/storage), Let's Encrypt (certificates), public encyclopedia API Push tokens, notification payloads, call media streams, cached content, university search queries
Global (distributed) CDN edge nodes, call routing servers Cached media content, real-time call media streams

11.2 EEA/UK Transfer Safeguards

For transfers of personal data from the European Economic Area (EEA) or United Kingdom to countries that have not received an adequacy decision from the European Commission or UK Secretary of State:

(a) Standard Contractual Clauses (SCCs): We use the European Commission-approved Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) as the primary transfer mechanism for transfers to the United States and other non-adequate countries;

(b) UK International Data Transfer Agreement (IDTA) / UK Addendum: For transfers from the United Kingdom, we use the UK IDTA or the UK Addendum to the EU SCCs, as approved by the UK Information Commissioner's Office;

(c) Supplementary measures: In addition to contractual safeguards, we implement supplementary technical and organizational measures including: encryption of data in transit (industry-standard TLS) and at rest where applicable; access controls limiting data access to authorized personnel; data minimization (transferring only the minimum data necessary for the specific purpose); pseudonymization where practicable; and contractual restrictions on provider data use;

(d) Transfer impact assessments: We conduct transfer impact assessments (TIAs) for transfers to jurisdictions without adequacy decisions, evaluating the legal framework of the receiving country, the nature of the data transferred, the specific circumstances of the transfer, and the effectiveness of supplementary measures.

11.3 Turkey Transfer Safeguards (KVKK Article 9)

Transfers of personal data of Turkish data subjects outside Turkey comply with KVKK Article 9:

(a) Explicit consent of the data subject for transfers to countries without adequate protection;

(b) Where the receiving country has been determined to have adequate protection by the Turkish Personal Data Protection Board;

(c) Where the data controller in the receiving country provides a written undertaking of adequate protection and the Turkish Board grants authorization.

11.4 Your Acknowledgment

By using the Service, you acknowledge that your data may be processed in the jurisdictions identified above and that we employ the transfer safeguards described in this Section to protect your data during international transfers.


PART IV -- COOKIES AND TRACKING TECHNOLOGIES


12. Cookies, Local Storage, and Similar Technologies

12.1 Our Approach

The Service primarily uses token-based authentication (secure authorization headers with encrypted tokens) rather than browser cookies for most functionality. Our cookie usage is minimal and limited to strictly necessary operational purposes.

12.2 Technologies We Use

Cookies (browser-based access only):

Name Type Duration Purpose Necessity
mc_admin_token HTTP-only, first-party, secure 24 hours Admin panel authentication (Krtuworks staff only) Strictly necessary
mc_company_token HTTP-only, first-party, secure 24 hours Business panel authentication (Company account holders) Strictly necessary
mc_company_act_as First-party Session Tracks which sub-account role (Owner/Admin/Poster) is currently active in the business panel Strictly necessary
mc_company_locale First-party Persistent Stores business panel language/locale preference Strictly necessary

We do not use third-party analytics cookies, advertising cookies, social media tracking cookies, or any form of cross-site tracking cookies.

Device-Local Storage (mobile applications):

Data Purpose Storage Method
Authentication token Persistent login across app sessions Secure device storage (iOS Keychain, Android Keystore)
User preferences and settings UI configuration, notification preferences, feed mode Local application storage
Cached content (posts, profiles, media thumbnails) Offline access, faster loading, reduced data usage Local application cache
Push notification tokens Notification delivery registration Local application storage
Draft content (unsent messages, post drafts) Content preservation Local application storage

This data is stored locally on your device, managed by the operating system's security framework, and is not transmitted to third parties. You can clear application data through your device settings.

Server-Side Technologies (not visible to you):

Technology Purpose Retention
Server-side temporary data Session management, rate limiting, real-time features (online status, live updates), authentication verification, and performance optimization Temporary; automatically expires (minutes to hours depending on data type)

12.3 Third-Party Components

The mobile applications include third-party components for core functionality: push notification delivery, voice and video calls, and application framework support. These components are used exclusively for core Service functionality, not for advertising, tracking, or behavioral profiling. We do not include any advertising, analytics tracking, or social media integration components in our applications.

Since we use only strictly necessary technologies for authentication, security, and core functionality, consent is not required under EU/UK ePrivacy rules (ePrivacy Directive Article 5(3) exemption for strictly necessary storage), KVKK, or equivalent regulations. If we introduce non-essential cookies or tracking technologies in the future, we will update this section and implement appropriate consent mechanisms before deploying them.

12.5 Managing Technologies

You can manage technologies used by the Service as follows:

(a) Browser cookies: Manage through your browser settings (Settings > Privacy > Cookies). Blocking the mc_admin_token cookie prevents admin panel access (does not affect regular user access);

(b) Mobile app storage: Clear application data through your device settings (Settings > Apps > MyCampus > Storage > Clear Data). Note: this will log you out and clear cached content;

(c) Push notifications: Disable in your device notification settings (Settings > Notifications > MyCampus) or through in-app notification preferences;

(d) Location permissions: Disable GPS access in your device settings (Settings > Privacy > Location Services > MyCampus);

(e) Camera and microphone: Disable in your device settings to prevent use of call features and media capture.


PART V -- DATA RETENTION AND DELETION


13. Data Retention Schedule

We retain personal data only as long as necessary for the purposes for which it was collected, to comply with legal obligations, to resolve disputes, to enforce our agreements, and to protect the safety and security of our users and the Service. The following table describes our retention periods for different categories of data.

13.1 Retention Periods

Data Category Retention Period Deletion Method
Active user accounts Retained while account is active; deletion available on request Account deletion process (Section 14)
Posts and comments (user-deleted) Soft-deleted immediately upon user action; hard-deleted after 30 days Automated daily cleanup job
Posts and comments (moderation-removed) Content removed from display immediately; content snapshot retained up to 1 year for approved reports Automated maintenance; manual cleanup for report snapshots
Direct and group messages (user-deleted) Soft-deleted immediately; hard-deleted (including media) after 30 days Automated daily cleanup job
Message metadata (sender, recipient, timestamp) Retained for operational purposes during account lifecycle; deleted with account Account deletion cascade
Notifications (in-app history) Automatically deleted after 30 days Automated daily cleanup job (runs at 03:00 UTC)
Sessions Until expiry (configurable per session) or manual revocation Automatic expiry; manual revocation via account settings
Password reset tokens ~15 minutes from issuance Automatic expiry
Email verification challenges (OTP) Progressive cooldown: 10min, 30min, 6hr, 12hr, 24hr; challenge locked after 5 failed attempts Automatic expiry and cleanup
2FA challenge data (TOTP, email, passkey) 5-10 minutes Automatic expiry
2FA backup codes Until used (single-use) or regenerated (all previous codes invalidated) Consumed on use; batch invalidation on regeneration
Passkey/WebAuthn credentials Until user removes them or account deletion User action; account deletion cascade
Recovery requests (2FA/graduate) Processed within 24-48 hours; documents deleted immediately after decision Manual review + automated document deletion
Recovery documents (transcripts, diplomas) Reviewed and permanently deleted within 24-48 hours of submission Manual deletion after review decision
Reports and content snapshots Report records: retained for moderation history; content snapshots: up to 1 year if report approved, cleared immediately if report dismissed Automated maintenance service
Disciplinary actions Until expiry date (for temporary actions); permanent actions retained for account history System-managed expiry; account deletion
Appeal records Retained with associated disciplinary action record Same as disciplinary actions
IP geolocation cache Temporary Automatic cache expiry
Session cache Short-lived Automatic cache expiry
Access and error logs Per server log rotation policy (typically 7-30 days) Log rotation
Raw telemetry events Retained for up to 30 days, then automatically deleted Aggregation worker processes daily; cleanup removes events older than 30 days
Daily aggregated telemetry Retained while account is active; deleted on account deletion Account deletion cascade
"Not interested" signals Indefinitely while account is active (user can remove at any time) User action (DELETE endpoint); account deletion
Marketplace transaction records Retained for legal/tax compliance (period varies by jurisdiction) Manual retention per applicable requirements
QR verification codes Retained with transaction record Same as transaction records
Marketplace ratings Retained while rated user's account is active Account deletion cascade
Gossi AI memory Retained until user deletes, disables memory, or deletes account User action (delete or disable in settings); account deletion cascade
Gossi rate limit counters Temporary; resets daily Automatic cache expiry
Media analysis results (AI) Cached temporarily; not permanently stored Automatic cache expiry
Feed algorithm data Recalculated periodically; individual scores refreshed on 30-day rolling window Automated recalculation; account deletion
Device tokens Updated on device change; removed on logout (session-linked); removed on account deletion Session cleanup; account deletion cascade
Ban evidence (permanent bans) Retained indefinitely for re-registration prevention and law enforcement cooperation Manual; not automatically deleted
Ban evidence (deliverability issues) Temporary; auto-expires Automatic expiry
Academic schedule data Retained while account is active Account deletion cascade
Schedule sharing relationships Retained while both accounts are active User action (unshare); account deletion
Club governance records (terms, board snapshots) Retained for club history and accountability Club dissolution; manual cleanup
Company verification requests Request records: retained for audit trail; documents: deleted after review decision Document deletion post-review; record retained
Email delivery logs Retained for bounce monitoring and deliverability tracking Log rotation

13.2 Retention Principles

When determining retention periods, we consider:

(a) The purpose for which the data was collected and whether that purpose has been fulfilled;

(b) The sensitivity and nature of the data;

(c) The potential risk of harm from unauthorized use or disclosure;

(d) Applicable legal, regulatory, and contractual requirements;

(e) Whether the data is necessary for the establishment, exercise, or defense of legal claims;

(f) The legitimate interests of Krtuworks and the reasonable expectations of users;

(g) The cost and feasibility of continued storage versus deletion.

13.3 Data Minimization in Practice

We implement data minimization through:

(a) Collecting only data necessary for specified purposes (not collecting data "just in case");

(b) Automated deletion schedules that purge data when retention periods expire;

(c) Aggregation of analytics data (replacing individual records with aggregate statistics);

(d) Pseudonymization where full identification is not required for the processing purpose;

(e) Regular review of data inventory to identify and eliminate unnecessary data collection.


14. Account Deletion and Data Erasure

14.1 Initiating Account Deletion

You may request deletion of your account at any time through:

(a) The in-app account deletion feature in your account settings;

(b) Contacting [email protected] with your account deletion request.

14.2 Soft Delete Phase (Grace Period)

Upon initiating deletion:

(a) Your account enters a "soft-deleted" state: your profile, content, and activity are removed from active display and search results;

(b) A grace period of ninety (90) days begins, during which you may cancel the deletion by logging back into your account;

(c) During the grace period, your data remains in our systems but is not accessible to other users;

(d) If you log in during the grace period, your account is automatically restored to active status and the deletion is cancelled;

(e) You will not receive notifications, appear in matching, or be discoverable by other users during the soft-delete phase.

14.3 Hard Delete Phase (Permanent Erasure)

After the grace period expires without cancellation, your account enters the irreversible hard-delete process:

Data permanently deleted: (a) All personally identifiable information from your user record (email, username, credentials, bio, birth date, gender, department, year, profile images, social links, recovery email, and all preference fields);

(b) All posts you created (content text, titles, media references, location data, poll data);

(c) All comments and replies you created;

(d) All direct and group messages you sent (including text content and media attachments);

(e) All notifications associated with your account;

(f) All session records and device tokens;

(g) All Gossi AI memory about you (cascade deletion);

(h) All matching profiles, swipe history, and match records;

(i) All marketplace ratings you gave and received;

(j) All schedule data and schedule sharing relationships;

(k) All follow and block relationships;

(l) All community memberships and role assignments;

(m) All saved posts and bookmarks;

(n) All "not interested" signals;

(o) All telemetry events associated with your account;

(p) All uploaded media files from cloud storage;

(q) All cached data associated with your account (sessions, vote states, feed snapshots, rate limits, online status);

Data anonymized (for referential integrity): (r) A "ghost user" placeholder is created with no personally identifiable information, solely to maintain referential integrity in the database (so that replies to your comments, reports referencing your content, and other database relationships do not break);

(s) Content that was quoted, replied to, or incorporated into other users' content may persist in anonymized form (attributed to the ghost user);

Data preserved (legal exceptions): (t) Legal obligations: Transaction records and financial data retained as required by applicable tax, accounting, and financial regulations;

(u) Active legal proceedings: Data subject to ongoing legal proceedings, government investigations, or preservation orders retained until the matter is resolved;

(v) Safety records: For accounts terminated due to severe violations (permanent bans for CSAM, terrorism, credible threats), ban evidence records (email, IP address, device information) are retained indefinitely to prevent re-registration and to cooperate with law enforcement;

(w) Backup copies: Data in backup copies may persist temporarily until overwritten by the normal backup rotation cycle;

(x) Aggregated/anonymous data: De-identified, anonymized, and aggregated statistical data that can no longer identify you may be retained indefinitely;

(y) Content shared by others: Content that other users independently saved, screenshotted, copied, forwarded, or otherwise captured before your deletion cannot be recalled from those users.

14.4 Hard Delete Process

The hard-delete process is fully automated with built-in safeguards to ensure completeness, prevent duplicate processing, and handle failures gracefully. Company sub-accounts are processed before parent accounts to ensure all associated data is properly removed.

14.5 Account Deletion by Krtuworks

Krtuworks may delete accounts pursuant to enforcement actions described in our Terms of Service. For accounts terminated for policy violations, the same deletion process applies, subject to the retention exceptions described in Section 14.3(t)-(y) and any additional retention required for safety and law enforcement cooperation.

14.6 Company Account Closure

When a Company Account is closed:

(a) All sub-accounts (Admin, Poster) linked to the company are simultaneously affected;

(b) Non-owner sub-account users cannot independently recover their accounts -- the Owner must reactivate the company first;

(c) If the Company Account proceeds to hard delete, all associated sub-accounts follow the same hard-delete process;

(d) Company verification documents that have already been deleted post-review are not affected (already gone);

(e) Company ratings, reviews, and public content follow the standard deletion/anonymization process.

14.7 Data Portability Before Deletion

Before deleting your account, you may exercise your right to data portability (where applicable under GDPR Article 20, CCPA, or equivalent laws) by requesting a copy of your personal data in a structured, commonly used, machine-readable format. Contact [email protected] to request data export before initiating account deletion.


PART VI -- YOUR RIGHTS AND SECURITY


15. Your Privacy Rights

15.1 Rights Summary

Depending on your location and applicable law, you may have some or all of the following rights regarding your personal data:

Right Description Applicable Jurisdictions
Access Request a copy of the personal data we hold about you GDPR, KVKK, CCPA, VCDPA, CPA, CTDPA, UCPA, and others
Correction / Rectification Request correction of inaccurate or incomplete personal data GDPR, KVKK, CCPA, VCDPA, CPA, CTDPA
Deletion / Erasure Request deletion of your personal data (subject to legal exceptions) GDPR ("right to be forgotten"), KVKK, CCPA, VCDPA, CPA, CTDPA, UCPA
Portability Receive your personal data in a structured, commonly used, machine-readable format, and transmit it to another controller GDPR, KVKK, VCDPA, CPA, CTDPA
Restriction of Processing Request that we limit processing of your data in certain circumstances GDPR, KVKK
Objection Object to processing based on legitimate interests or for direct marketing purposes GDPR, KVKK
Withdraw Consent Withdraw previously given consent for consent-based processing GDPR, KVKK, CCPA (sensitive data)
Automated Decision-Making Not be subject to solely automated decisions producing legal or similarly significant effects, with right to human intervention GDPR (Article 22), KVKK (Article 11(h))
Non-Discrimination Not be discriminated against for exercising privacy rights CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA
Opt-Out of Sale/Sharing Opt out of the sale of personal information or sharing for behavioral advertising CCPA/CPRA, VCDPA, CPA, CTDPA, UCPA (not applicable -- we do not sell/share)
Appeal Appeal a denial of your privacy rights request VCDPA, CPA, CTDPA
Complaint File a complaint with a supervisory authority GDPR, KVKK, UK GDPR
Compensation Claim compensation for damages from unlawful processing KVKK (Article 11(i)), GDPR (Article 82)

15.2 How to Exercise Your Rights

Primary contact:

In-app controls (available without contacting us):

Physical mail:

15.3 Identity Verification

Before processing your privacy rights request, we may need to verify your identity to prevent unauthorized access to your data. Verification methods may include:

(a) Confirming your registered email address (sending a verification code);

(b) Confirming account-specific information known only to the account holder;

(c) For authorized agent requests: written authorization from the account holder and verification of the agent's identity;

(d) For high-sensitivity requests (bulk data export, account deletion): enhanced verification may be required.

We will not request more information than necessary to verify your identity.

15.4 Response Times

Jurisdiction Initial Response Extension
GDPR (EU/EEA) 1 month from receipt +2 months for complex or voluminous requests (with notification and explanation)
UK GDPR 1 month from receipt +2 months for complex requests (with notification)
KVKK (Turkey) 30 days from receipt With notification to the data subject
CCPA/CPRA (California) 45 days from receipt +45 days with notification and explanation of reason
VCDPA, CPA, CTDPA, UCPA 45 days from receipt +45 days with notification

15.5 Appeals

If we deny or partially deny your privacy rights request, we will explain the reason for denial and provide information about your appeal options:

(a) Internal appeal: Reply to our response with additional information or clarification;

(b) Supervisory authority complaint: You may file a complaint with the applicable data protection authority (see Section 15.6);

(c) US state appeals: For requests under VCDPA, CPA, or CTDPA, you may appeal using the process described in our response.

15.6 Supervisory Authorities

You have the right to lodge a complaint with the data protection supervisory authority in your jurisdiction:

Jurisdiction Authority Contact
EU/EEA Your national Data Protection Authority (full list: edpb.europa.eu/about-edpb/about-edpb/members_en) Varies by country
United Kingdom Information Commissioner's Office (ICO) ico.org.uk
Turkey Personal Data Protection Board (KVKK Kurulu) kvkk.gov.tr
California Attorney General oag.ca.gov
Virginia Attorney General oag.state.va.us
Colorado Attorney General coag.gov
Connecticut Attorney General portal.ct.gov/ag
Other jurisdictions Your applicable data protection or consumer protection authority Varies

16. Automated Decision-Making and Profiling

16.1 Automated Processing We Perform

The Service uses automated systems and algorithms for the following purposes:

(a) Feed ranking and personalization: Algorithms analyze engagement signals, user interaction history, content attributes, recency, community relevance, and social graph data to order and prioritize content in your feed. This processing determines which content you see first and affects content visibility, but does not restrict your access to content (you can switch to chronological mode);

(b) Matching suggestions (Quickmatch): Algorithms generate match suggestions based on profile compatibility, stated preferences, shared interests, proximity (when location is shared), and university affiliation. Matching determines which profiles are presented to you but does not make decisions about you with legal or similarly significant effects;

(c) Content moderation (automated screening): Automated systems screen content for potential policy violations including spam patterns, known harmful content signatures, and other automated indicators. Automated systems may hold content for human review or immediately remove content matching known CSAM hashes. Account-level enforcement actions (warnings, suspensions, bans) are not imposed solely by automated systems -- human review is involved in all significant enforcement decisions;

(d) Trending content identification: Algorithms identify trending content based on engagement velocity (rate of interactions relative to time and community baseline). Trending designation is algorithmic, not editorial;

(e) Rate limiting: Automated systems monitor request patterns and enforce rate limits to prevent abuse. Excessive requests may be temporarily throttled or blocked;

(f) Spam and abuse detection: Automated systems analyze behavioral patterns to identify potential spam, coordinated manipulation, multi-account abuse, and other platform integrity threats;

(g) Gossi AI responses and voting: Automated AI systems generate conversational replies and cast votes (upvotes/downvotes) on content when triggered by user mentions. Gossi's behavior is fully automated once triggered;

(h) Interaction scoring: Automated systems calculate weighted affinity scores between users based on their engagement patterns, used solely for internal feed ranking and content recommendations;

(i) Engagement and quality scoring: Automated systems calculate engagement rates, quality scores, and influence scores for content and users, used for feed ranking and trending identification.

16.2 Decisions with Significant Effects

We do not make decisions based solely on automated processing (including profiling) that produce legal effects concerning you or similarly significantly affect you, except:

(a) Where such processing is necessary for the performance of our contract with you (e.g., automated transaction processing in marketplace);

(b) Where authorized by applicable law;

(c) Where based on your explicit consent.

16.3 Your Rights Regarding Automated Decisions

Where applicable law provides (including GDPR Article 22 and KVKK Article 11(h)):

(a) You may request information about the logic involved in automated decisions that significantly affect you;

(b) You may request human intervention in decisions that were made solely by automated systems;

(c) You may express your point of view and contest automated decisions;

(d) You may opt out of purely algorithmic feed ranking by choosing the chronological feed mode.

To exercise these rights, contact [email protected].


17. Security Measures

17.1 Technical Measures

We implement the following technical security measures to protect your personal data:

(a) Encryption in transit: All data transmitted between your device and our servers is encrypted using current industry-standard TLS encryption. WebSocket connections are secured with encrypted WebSocket connections;

(b) Password security: Passwords are processed using industry-standard, computationally intensive one-way hashing algorithms before storage. We never store, log, or transmit passwords in plaintext. Krtuworks employees cannot view or retrieve your password;

(c) Session token security: Session tokens are stored using industry-standard security measures. Raw tokens are never stored on our servers;

(d) Two-factor authentication: Multiple 2FA methods available (TOTP, email codes, passkeys/WebAuthn) providing layered authentication security;

(e) 2FA secret encryption: TOTP shared secrets are encrypted at rest using industry-standard encryption before storage;

(f) Passkey/WebAuthn security: Passkey credentials use public-key cryptography with counter-based replay attack prevention and origin/relying party verification;

(g) Rate limiting: Comprehensive rate limiting across all endpoints to prevent brute force attacks, credential stuffing, API abuse, and denial-of-service attacks;

(h) File upload validation: Server-side MIME type verification and content validation to prevent malicious file uploads; file size limits enforced;

(i) HTTP security headers: Content Security Policy (CSP), X-Frame-Options (SAMEORIGIN), X-Content-Type-Options (nosniff), X-XSS-Protection, Strict-Transport-Security (HSTS), Referrer-Policy (no-referrer), X-DNS-Prefetch-Control, X-Download-Options, X-Permitted-Cross-Domain-Policies, and Cross-Origin-Opener-Policy headers;

(j) CORS restrictions: Cross-Origin Resource Sharing configured to accept requests only from authorized origins;

(k) Input validation: Server-side validation on all user inputs using parameterized database queries (Prisma ORM), preventing SQL injection, XSS, and other injection attacks;

(l) Role-based access control (RBAC): Administrative functions restricted to authorized personnel with defined roles and permission levels;

(m) Distributed locking: Distributed locking mechanisms prevent race conditions in critical operations (vote processing, account deletion, scheduled tasks);

(n) Content deduplication: SHA-based content hashing for media deduplication, preventing storage of duplicate files;

(o) Atomic operations: Server-side atomic operations ensuring consistency of vote counting, rate limiting, and other critical real-time operations.

17.2 Organizational Measures

(a) Access controls: Administrative access to production systems, databases, and infrastructure is restricted to authorized Krtuworks personnel with defined roles and responsibilities;

(b) Principle of least privilege: Access rights are granted based on the minimum level necessary for each role's function;

(c) Incident response: We maintain incident response procedures for identifying, containing, investigating, and remediating security incidents;

(d) Vendor management: Third-party service providers undergo security review before engagement and are bound by data processing agreements;

(e) Secure development practices: Code review, input validation, parameterized queries, and security-conscious development methodology.

17.3 Your Role in Security

You play an important role in protecting your account and data:

(a) Use a strong, unique password not used for any other service;

(b) Enable at least one two-factor authentication method (we strongly recommend passkeys or TOTP);

(c) Securely store your 2FA backup codes in a separate location from your primary device;

(d) Keep your device operating system and the MyCampus app updated;

(e) Be cautious of phishing attempts -- Krtuworks will never ask for your password;

(f) Review your active sessions regularly and revoke any unrecognized sessions;

(g) Report suspicious activity to [email protected] immediately;

(h) Log out on shared or public devices.

17.4 No Absolute Guarantee

While we implement commercially reasonable security measures consistent with industry standards, no method of transmission over the Internet and no method of electronic storage is 100% secure. We cannot guarantee the absolute security of your personal data. In the event of a security breach affecting your data, we will notify you as described in Section 18.


18. Data Breach Notification

18.1 Our Obligations

In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, Krtuworks will:

(a) Notify supervisory authorities within the timeframes required by applicable law:

(b) Notify affected individuals without undue delay when the breach is likely to result in a high risk to your rights and freedoms, providing:

(c) Maintain breach records documenting all personal data breaches, including facts, effects, and remedial actions taken, regardless of whether the breach triggers notification obligations.

18.2 Notification Channels

Breach notifications to affected individuals will be communicated through one or more of the following channels: email to your registered email address, in-app notification, push notification, or prominent notice on the Service. Where individual notification is not feasible (e.g., contact information unavailable), we will use public communication channels as required by applicable law.

18.3 Cooperation

In the event of a breach, we will cooperate fully with relevant supervisory authorities, law enforcement agencies, and affected individuals to investigate the incident, mitigate harm, and prevent recurrence.


PART VII -- FEATURE-SPECIFIC PRIVACY


19. AI Features, Gossi, and Machine Learning

19.1 Overview

The Service incorporates artificial intelligence and machine learning technologies. This section describes in detail what data is processed, how it is processed, where it is processed, and what controls you have over AI processing of your data.

19.2 Gossi Conversational AI -- Data Processed

When a user mentions @gossi in a post or comment, the following data is compiled into a context prompt and sent to our AI infrastructure for response generation:

Post data included in AI context:

Category-specific data included (varies by community type):

Comment and thread data:

User-specific data:

Data NOT included in AI context:

19.3 Gossi Memory -- Data Storage and Controls

Gossi maintains a per-user contextual memory to improve response relevance:

What is stored:

What is NOT stored:

How memory is generated and updated:

Your controls:

Automatic deletion: Gossi memory is automatically and permanently deleted when your account is deleted (database cascade deletion).

19.4 Gossi Voting -- Data and Behavior

Gossi may automatically cast votes (upvotes or downvotes) on content it responds to:

19.5 Gossi Rate Limiting and Usage Tracking

Each user has daily and per-minute usage limits for Gossi interactions:

19.6 Gossi Post Toggle

Post authors can disable Gossi replies on their posts:

19.7 Automated Media Analysis

When you upload images or videos to the Service, they may be processed by our AI media analysis pipeline:

Data sent for analysis:

Analysis output generated:

Processing details:

Data NOT used for model training: Your media is not used by Krtuworks to train, fine-tune, or improve AI models.

19.8 University Content Enrichment

We use AI to generate informational content about universities:


20. Messaging and Communication Privacy

20.1 Message Storage and Access

Messages (direct and group) are stored on Krtuworks servers hosted in the EU (Germany). You acknowledge that:

(a) Messages are stored in our database for delivery, synchronization across devices, and Service operation;

(b) Messages are not end-to-end encrypted by default. All data is encrypted in transit (TLS) between your device and our servers, and our database infrastructure provides encryption at rest, but Krtuworks has the technical ability to access message content;

(c) Message content is accessible to Krtuworks personnel and systems only under the following circumstances:

20.2 Message Metadata

In addition to message content, we collect and process message metadata:

20.3 Message Deletion and Retention

20.4 Group Chat Privacy

20.5 Recipients May Redistribute

Recipients of your messages may save, copy, screenshot, forward, or otherwise share your message content outside the conversation and outside the Service. Krtuworks cannot prevent or control such redistribution. Exercise caution when sharing sensitive information through messages.


21. Voice and Video Call Privacy

21.1 Call Processing

Voice and video calls are facilitated through Voice and video call provider's real-time communication infrastructure:

(a) Call media (audio and video streams) is processed by call infrastructure provider's servers for real-time routing and delivery only;

(b) Call audio and video content is NOT recorded, stored, or accessible to Krtuworks or call infrastructure provider after the call ends;

(c) Call media transits through call infrastructure provider's global server infrastructure, which may include servers in various jurisdictions;

(d) All call media is encrypted in transit.

21.2 Call Metadata Collected

We collect the following call metadata:

21.3 Call Metadata Retention

Call metadata is retained as part of your account activity data and is subject to the same retention policies as other account data. Call metadata is deleted when your account is permanently deleted.

21.4 Call Notifications

When you receive an incoming call, push notifications are sent to your registered devices. Call notifications may repeat at intervals (approximately every 5 seconds for up to 30 seconds) to ensure you are alerted. If you do not answer, the call is marked as missed.


22. Location Data

22.1 Types of Location Data

Type Collection Method Precision Your Control Retention
Precise GPS Device GPS sensor (explicit opt-in via location permission + in-app toggle) Latitude/longitude coordinates Disable in device settings or app; revoke at any time Updated when you actively use matching; cleared on account deletion
Approximate IP-based Automatic lookup via a third-party geolocation service when you create a session City and country level Cannot be disabled (collected automatically for security) Cached temporarily; session record retained per session lifecycle
User-provided You manually enter locations (post location tags, FindRoom listing addresses) As specific as you choose to provide You decide what to enter; can edit or remove Retained with associated content; deleted when content is deleted

22.2 How Location Data Is Used

(a) Precise GPS: Used exclusively for Quickmatch proximity-based matching. Other users see your approximate distance (e.g., "5 km away") but never your exact coordinates. Location sharing is required for Quickmatch discovery -- disabling it removes you from the matching pool;

(b) Approximate IP-based: Used for session context (displayed in your active sessions list as "City, Country"), new login security alerts (notifying you of logins from unfamiliar locations), and content localization. IP-based location is NOT shared with other users;

(c) User-provided: Displayed as part of the content you create (e.g., post location tag, FindRoom listing address). Visible to users who can view the associated content.

22.3 Location Data Sharing

(a) With other users: Only when you explicitly opt in to location sharing in Quickmatch. Other users see approximate distance, never exact coordinates. User-provided locations (post tags, listings) are visible as part of content;

(b) With service providers: IP addresses are sent to third-party geolocation service for geolocation lookup (returns city/country, no further processing by third-party geolocation service);

(c) With law enforcement: May be disclosed in response to valid legal process;

(d) Not shared for advertising: Location data is never shared with advertisers or used for location-based advertising.

22.4 Disabling Location Features


23. Marketplace and Financial Data

23.1 Marketplace Data Collection

When you use marketplace features (buy/sell or FindRoom housing), we collect:

Seller data:

Buyer data:

Transaction data:

23.2 QR Verification Data

The QR-based verification system generates unique, cryptographically secured codes that identify the transaction. QR codes do not contain financial account details, payment card information, or sensitive personal data.

QR codes are generated when a purchase request is initiated and stored with the transaction record. QR data does not contain financial account details, payment card information, or sensitive personal data.

23.3 Financial Data

As of the effective date of this Policy, the Service does not implement integrated payment processing. Marketplace transactions are conducted between buyers and sellers through their own payment methods outside the Platform. Krtuworks does not collect, process, or store payment card numbers, bank account details, or other financial instrument data.

When integrated payment processing is introduced in the future (e.g., through Stripe Connect), this Policy will be updated to describe the additional financial data collected, how it is processed, and the payment processor's data handling practices.

23.4 Housing Listing Data (FindRoom)

FindRoom housing listings may include detailed property information:

This information is provided voluntarily by the listing creator and displayed publicly to eligible users. Listing creators are responsible for ensuring their listings comply with applicable fair housing laws and do not include discriminatory preferences based on protected characteristics.


24. Matching and Discovery (Quickmatch) Privacy

24.1 Matching Profile Data

When you create a Quickmatch matching profile, the following data is collected and used:

24.2 Matching Algorithm Data

The matching algorithm processes:

24.3 Data Visibility to Other Users

When you participate in Quickmatch:

(a) Your matching profile (age, gender, bio, interests, photos, university) is visible to other users in the matching pool;

(b) Your approximate distance is visible when both you and the other user have location sharing enabled (exact coordinates are never shown);

(c) Your swipe decisions (like, pass) are NOT visible to the other user unless a mutual match occurs;

(d) When a match occurs, both users are notified and can begin messaging;

(e) Your matching activity (how many people you swiped, when you were last active in matching) is not publicly disclosed.

24.4 Matching Data Deletion


25. Company and Business Account Data

25.1 Additional Data Collected

Company Accounts involve additional data processing beyond standard individual accounts:

Company profile data:

Verification data:

Sub-account data:

Cross-posting data:

25.2 Company Account Data Sharing

25.3 Company Account Closure

When a Company Account is closed, frozen, or deleted:


26. Club and Organization Data

26.1 Club-Specific Data Processing

The Clubs feature involves processing of the following additional data categories:

Governance data:

Membership data:

Club activity data:

26.2 Club Data Visibility

26.3 Club Data Retention


27. Academic Schedule and Notification Data

27.1 Schedule Data Collection

When you use the academic schedule feature, we collect:

27.2 Schedule Notification Processing

Your schedule data is used to generate the following automated notifications:

(a) Daily schedule reminder: At approximately 21:00 in your local timezone, a summary of the next day's classes (or a notification that you have no classes). Processing: our server calculates your local time from your stored timezone and queries your schedule entries for the next day;

(b) Class reminders: Approximately 1 hour before each scheduled class, including course code and classroom (if provided). Processing: hourly cron job checks for classes starting within the next hour in each user's local timezone;

(c) Exam reminders: At 1 week, 3 days, 1 day, and 1 hour before each exam. Processing: hourly cron job compares exam dates against current time in user's timezone;

(d) Class conflict alerts: When two or more classes overlap in the same time slot, a conflict notification is sent. Processing: overlap detection runs as part of the class reminder job;

(e) Schedule sharing notifications: When someone shares or unshares their schedule with you.

27.3 Schedule Data Sharing

27.4 Schedule Data Retention

Schedule data is retained while your account is active and is permanently deleted when your account is deleted (cascade deletion). Schedule sharing relationships are deleted when either party's account is deleted or when the sharing is manually revoked.


28. Notification Preferences

28.1 Granular Notification Control

The Service provides granular control over notifications through a per-type preference system:

Two independent toggles per notification type:

(a) Push toggle: Controls whether push notifications (phone alerts) are delivered for that type;

(b) History toggle: Controls whether the notification is recorded in your in-app notification history.

You can independently control push and history for each dismissable notification type. For example, you can receive push notifications for new messages but not store them in history, or store comment notifications in history without receiving push alerts.

28.2 Dismissable vs. Non-Dismissable Notifications

28.3 Preference Data Storage

Your notification preferences are stored on your account and take effect immediately when changed. By default, all notifications are enabled. Changes to your preferences apply instantly to future notifications. Preference data is deleted when your account is deleted.

28.4 Push-Only Notifications

Some notification types are inherently push-only (they do not save to notification history regardless of your preferences). These include: new message alerts, incoming call alerts, group chat actions, message reactions, course chat join notifications, and all academic schedule reminders. For these types, only the push toggle is meaningful; the history toggle has no effect because these events were never stored in history by design.


29. Feed Algorithm and Personalization Data

29.1 Data Inputs for Feed Personalization

The algorithmic feed uses the following data categories to rank and personalize content for you:

Engagement signals (per-content):

User interaction data:

Content attributes:

User preferences:

Negative signals:

29.2 Algorithm Data Storage

29.3 "Not Interested" Data

When you mark content as "not interested":

29.4 Your Controls


30. Telemetry and Analytics

30.1 What We Collect

The Service collects usage telemetry to understand how features are used, identify issues, and improve the user experience. The types of usage data we collect include:

Engagement data: How long you view posts and comments, when you expand photos or videos, and when you tap links in content.

Action data: When you share, save, or bookmark content; when you mark content as "not interested"; and when you follow users from the feed.

Interaction data: Voting actions on comments, viewing and expanding reply threads.

Navigation data: Which screens you visit, how far you scroll in feeds, and when you navigate to user profiles or communities.

App usage data: When you open and close the app, and when the app moves between active and background states.

Each event includes basic context such as timestamps and references to the content involved. This data is collected in the background during normal app usage.

30.2 How Telemetry Is Processed

(a) Personalization: Certain usage signals are used in real-time to improve feed relevance and content recommendations;

(b) Daily summaries: Raw usage data is periodically summarized into aggregated activity reports (such as total screen time, posts viewed, and interaction patterns);

(c) Anonymized insights: Individual telemetry data is aggregated into anonymized platform-level statistics used for product decisions, feature prioritization, and service quality monitoring;

(d) Content quality: Engagement patterns are used to identify trending content and assess content quality for feed ranking.

30.3 Telemetry Data Retention

30.4 Your Acknowledgment

By using the Service, you acknowledge and consent to the collection and processing of telemetry data as described in this Section. The Service does not currently provide a general opt-out mechanism for core telemetry collection, as this data is integral to operating, maintaining, improving, and securing the Service. Where applicable law requires consent or provides an opt-out right for analytics tracking beyond what is strictly necessary, we will comply with such requirements.


31. Media Upload and Processing

31.1 Media Metadata Collected

When you upload media files (images, videos, documents) to the Service, we collect and store:

31.2 Media Processing

Uploaded media undergoes the following processing:

(a) Content validation: Server-side MIME type verification ensures the file content matches its declared format and does not contain malicious payloads;

(b) Image optimization: Images may be resized, compressed, and reformatted (e.g., generating multiple resolution variants and thumbnails) for optimal delivery across different devices and network conditions;

(c) Deduplication: Content-hash-based detection identifies previously uploaded identical files. Duplicate uploads reference existing stored copies rather than creating new ones, reducing storage requirements while maintaining your ownership reference;

(d) AI media analysis: Media may be processed by our AI analysis pipeline (see Section 19.7) for scene description, object identification, text extraction, and contextual understanding. This analysis enhances Gossi AI context and may support content moderation.

31.3 Media Storage and Delivery

31.4 Media and Third Parties


32. Children and Minors

32.1 Minimum Age

The Service requires a minimum age of sixteen (16) years. We do not knowingly collect, solicit, or process personal data from anyone under the age of sixteen. Registration requires a valid university email address; since university enrollment typically begins at age 16-18, this requirement serves as a practical indicator that users meet the minimum age. Additionally, we collect birth date during registration and validate that users are at least sixteen (16) years of age. We rely on users to provide truthful information during registration, and creating an account with a false birth date constitutes a violation of our Terms of Service.

32.2 Higher Minimum Ages

In jurisdictions where the minimum age for:

(a) consenting to personal data processing;

(b) entering into binding contracts;

(c) using social networking services is higher than sixteen, users must meet the locally applicable minimum age. Users between sixteen and the age of legal majority must have parental or guardian consent as described in our Terms of Service.

32.3 Discovery and Deletion

If we become aware that we have collected personal data from a person under the applicable minimum age without proper consent:

(a) We will take prompt steps to verify the situation;

(b) We will delete all identifiable personal data associated with that person as quickly as practicable;

(c) We will terminate the associated account;

(d) We will notify the minor's parent or guardian if contact information is available and notification is required by law.

32.4 Parental and Guardian Notification

If you are a parent or legal guardian and believe your child has created an account or provided personal data to the Service without your consent, please contact us immediately at [email protected]. We will verify the report and, if confirmed, promptly delete the data and terminate the account.

32.5 COPPA Compliance

We comply with the U.S. Children's Online Privacy Protection Act (COPPA) by not knowingly collecting personal information from children under thirteen (13) years of age. The Service is not directed to children under 13.

32.6 Additional Protections for Minors

For users who are between sixteen and eighteen years of age:

(a) We encourage the use of privacy settings to limit profile visibility;

(b) We apply the same content moderation and safety protections as for adult users;

(c) Matching features (Quickmatch) are available but users are encouraged to exercise caution;

(d) Parents and guardians may contact us to discuss additional safeguards for minor users.


PART VIII -- GENERAL


33. Do Not Track and Global Privacy Control

33.1 Do Not Track (DNT)

We do not currently respond to "Do Not Track" browser signals because there is no universally accepted standard for how websites should respond to DNT signals. As the Service does not engage in cross-site tracking, behavioral advertising, or third-party data sharing for advertising purposes, DNT signals do not change our data practices.

33.2 Global Privacy Control (GPC)

We acknowledge Global Privacy Control (GPC) signals as valid expressions of user privacy preferences where required by applicable law, including the California Consumer Privacy Act, the Colorado Privacy Act, and the Connecticut Data Privacy Act. Since we do not sell, share, or disclose personal information for advertising, cross-context behavioral targeting, or data brokerage purposes, our existing data practices already comply with the opt-out preferences expressed by GPC signals without requiring additional technical processing. Should our data practices change in the future to include activities covered by GPC opt-out requirements, we will implement technical GPC signal detection and compliance mechanisms before initiating such activities.


34. Changes to This Policy

34.1 How We Update This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make changes:

(a) Material changes: We will update the "Effective Date" and "Last Updated" fields, increment the version number, and provide notice through one or more of the following: in-app notification, push notification, email to your registered email address, or a prominent banner within the Service. Material changes include modifications to data collection categories, new third-party data sharing, changes to retention periods, new processing purposes, or changes that materially affect your rights;

(b) Non-material changes: Minor corrections, clarifications, formatting, or updates reflecting existing practices may be made without advance notice, though the "Last Updated" date will be updated;

(c) Consent for material changes: Where required by applicable law (including GDPR, KVKK, or other mandatory data protection frameworks), we will seek your affirmative consent before material changes take effect;

(d) Effective date: Unless otherwise specified or required by law, material changes take effect thirty (30) days after notice is provided;

(e) Continued use: Your continued use of the Service after the effective date of any change constitutes acceptance of the updated Policy. If you disagree with changes, stop using the Service and delete your account;

(f) Prior versions: Previous versions of this Policy are available upon request at [email protected].


35. Contact Information

35.1 How to Reach Us

If you have any questions, concerns, complaints, or requests regarding this Privacy Policy, your personal data, or our data practices, you may contact us through the following channels:

Krtuworks LLC 30 N Gould St, Ste R, Sheridan, WY 82801, USA Phone: +1 (307) 429-3359

Purpose Contact
Privacy rights requests, GDPR, KVKK, CCPA inquiries [email protected]
Data protection questions and complaints [email protected]
DMCA and copyright claims [email protected] (Subject: "DMCA Notice")
General support and account issues [email protected]
Security vulnerabilities and responsible disclosure [email protected] (Subject: "Security")

35.2 Response Commitment

We aim to acknowledge all privacy-related inquiries within five (5) business days and provide substantive responses within the timeframes required by applicable law (see Section 15.4 for jurisdiction-specific response times).

35.3 Supervisory Authority Complaints

If you are not satisfied with our response to your privacy inquiry, you have the right to lodge a complaint with your local data protection supervisory authority (see Section 15.6 for a list of relevant authorities by jurisdiction).


Last updated: April 5, 2026. Version 1.0. Copyright 2022-2026 Krtuworks LLC. All rights reserved.