Effective date: 12 August 2026 · Last updated: 26 August 2026
This Privacy Policy explains how Krooko (the website and social platform available at krooko.me, operated by Alexandros Roussos) collects, uses, discloses and protects your personal data when you use it. Krooko is a free social platform that helps people find business and creative partners: members post "cards", share posts and stories, follow each other, chat and sign collab agreements.
We process personal data in accordance with the EU General Data Protection Regulation (GDPR), Greek Law 4624/2019, and other applicable Greek and EU law.
For all privacy questions, requests and support, contact alexroussossm@gmail.com or write to the postal address above. A Data Protection Officer has not been appointed. Under GDPR Article 37, a DPO is mandatory only where an organisation's core activities involve regular and systematic monitoring of individuals on a large scale, or large-scale processing of special-category or criminal-conviction data. Neither applies to Krooko: there is no behavioural tracking, profiling or ad-targeting of any kind (section 8), and Krooko does not process special-category data — health, biometric, genetic, political, religious or similar data — at all. The controller handles all privacy matters directly.
We do not collect gender, phone numbers, postal addresses, government ID or verification documents, or payment details — Krooko is free and has no payments.
Message attachments — including files, code snippets and voice messages — are stored in their own file storage, separate from photos, at an unguessable web address. That address is not listed anywhere and is not indexed, but anyone you give it to can open or download the file (or listen to the recording) without logging in — so please don't use Krooko to send confidential documents, and bear that in mind before recording a voice message too. Once a recipient downloads an attachment, listens to a voice message, or saves a code snippet, that copy is theirs, and deleting the message afterwards does not undo it. If a code snippet is marked HTML, CSS or JavaScript, either side can also run it in a sandboxed preview — that happens entirely inside your own browser and is never sent to Krooko or seen by us in any form. A voice message is never transcribed, analysed or sent to any AI provider — it is stored and played back exactly as recorded, nothing more.
If you use an AI feature — the Krooko AI assistant, AI text improve, hashtag suggestions, the AI icebreaker in messages, the bio and first card written for you during account setup, or "Describe what you need" card matching — the text involved (your message, your draft post or card, your search prompt, your setup answers, or, where relevant, a recipient's bio or card text) is sent to NVIDIA, our AI provider (based in the US), to generate a response. Per NVIDIA's own terms, it may use that text — without identifying you — to improve its own products and AI models; it never receives your password or other account data. See section 10 for the international-transfer safeguard and section 17 for the full entry.
Our own code does not record your IP address. However, the infrastructure we run on (Supabase, and our hosting provider) necessarily sees your IP address and standard request data in its server logs, as every website's infrastructure does. Our font is self-hosted rather than loaded from a third-party CDN, so no separate request goes anywhere else just to render text. We do not use these logs to profile you.
We do not collect GPS or precise location, and we do not derive or store location from your IP.
There are no third-party logins (no Google/Apple sign-in), no analytics trackers and no advertising technologies on Krooko.
| Purpose | Legal basis |
|---|---|
| Creating and operating your account, showing your content, delivering messages and notifications | Performance of a contract (Art. 6(1)(b)) |
| Fair-use limits on posting (card/post/repost/username caps) | Legitimate interests (Art. 6(1)(f)) — preventing spam and abuse from unlimited automated posting |
| Blocks, and reviewing and acting on reports | Legitimate interests (Art. 6(1)(f)) — protecting members from harassment, scams and malicious accounts |
| Automated photo moderation and language filtering | Legitimate interests (Art. 6(1)(f)) — keeping unlawful and prohibited content off the platform before it's seen by others |
| Security of accounts and sessions (device list, hashed passwords, access rules) | Legitimate interests (Art. 6(1)(f)) — detecting compromised accounts and unauthorised access |
| Responding when you contact or report | Legitimate interests (Art. 6(1)(f)) — resolving what you raised / performance of a contract |
| Complying with valid legal requests | Legal obligation (Art. 6(1)(c)) |
| Optional visibility features (e.g. showing your collab track record) | Consent (Art. 6(1)(a)) — you can switch them off any time |
Where we rely on legitimate interests above, we've weighed that interest against your rights and freedoms before relying on it. You can object at any time (section 14); we'll stop unless we can demonstrate compelling legitimate grounds that override your interests, or the processing is needed to establish, exercise or defend a legal claim.
We do not use your data for advertising, we do not build marketing profiles, and we never sell your personal data.
Two things on Krooko happen automatically:
GDPR Article 22 specifically covers decisions based solely on automated processing that produce a legal effect or similarly significantly affect you — whether the 24-hour suspension above meets that bar depends on the circumstances. Rather than relying on that threshold being met, we provide the Article 22(3) safeguards regardless of whether it's formally met: the right to obtain human intervention (a moderator reviews every appeal), the right to express your point of view (your appeal is read, not just logged), and the right to contest the decision (a moderator can overturn it). The same three apply to anything actioned through the Report a problem form.
Separately, when you create an account we offer to write your bio and your first card for you. The answers you type during setup are sent to NVIDIA for that purpose only. Nothing is published without you seeing it first — you can edit every word, or skip the card entirely — and no decision about your account is made from those answers. If you would rather not use it, write your own bio in Settings and post a card yourself.
Everything else is not automated: the feed is chronological with no ranking algorithm or engagement profiling, and "Suggested for you" is simply ordered by follower count. Fair-use limits (2 cards a day, one post per 5 minutes, 2 username changes a month) apply equally to everyone. We do not use facial recognition, age estimation, or any biometric processing.
We never sell your data. We share it only with the service providers needed to run Krooko (section 17), with other users according to your audience choices, and with competent authorities where the law requires it (based on a valid legal request). We have no advertising partners, no data brokers and no "business partners" receiving personal data.
Our database, files and authentication are hosted by Supabase in a data centre located within the European Union — so your account data and content stay in the EEA. Two auxiliary services see limited data outside the EEA: FormSubmit (contact and report emails, US-based) and NVIDIA's AI inference API (see section 8, US-based). Transfers to providers outside the EEA require a safeguard under GDPR Chapter V — typically Standard Contractual Clauses — for each provider individually; we are in the process of putting that documentation in place with both. If you would rather your report or contact message not leave the EEA at all, email us directly instead of using the form.
| Data | Kept for |
|---|---|
| Account, profile & content | Until you delete it or delete your account — kept for that long because it remains necessary to provide you the service for as long as your account is active |
| Stories | 24 hours, then no longer served |
| Feed posts | Automatically deleted 30 days after posting — or earlier if you delete them |
| Cards | Automatically deleted 30 days after they are posted or last reposted — or earlier if you delete them |
| Discover listings | Until you remove the listing or delete your account. Removing it also stops the embedded badge working |
| Card updates & applications | Deleted with the card they belong to. You can withdraw your own application at any time |
| Messages & conversations | Automatically deleted 30 days after sending. If you delete a message earlier, it's replaced with a "Message deleted" placeholder for all participants immediately, and the underlying content is permanently deleted on our standard 30-day schedule |
| Files, code, voice & video messages sent in a message | Deleted with the message that carries them — so 30 days, or sooner if you delete the message or the conversation |
| Emoji reactions | Deleted with the message or comment they're on — so at most 30 days for a message, or whenever the comment/post is deleted |
| Notifications | Automatically deleted 30 days after they are generated |
| Post views | Removed with the post itself (so at most 30 days) |
| Secret ID & PIN | Until you replace them in Settings, or delete your account |
| Device list ("where you're logged in") | Until you remove a device or delete your account |
| Fair-use records (card/repost/username timestamps) | Rolling 30 days — the longest window any limit is measured over |
| Reports | 12 months after the report is resolved, to evidence the enforcement decision if it's later disputed and to spot repeat patterns from the same account — longer only where needed to establish, exercise or defend a legal claim |
| Files you attach to a complaint | Deleted the moment your complaint is decided. They are shown to one moderator and then removed automatically |
| Provider backups | Deleted data may persist in encrypted infrastructure backups for a limited period (typically up to 30 days) before being purged |
| Browser storage on your device | Until you log out / clear it — see the Cookie Policy |
If you embed the badge on your own site, visitors to that site load the image from Krooko. As with any image served across the web, our infrastructure sees the standard request data that comes with it (IP address, user-agent, and the page that requested it) in its server logs. We do not set cookies on the badge, do not use it to build a profile of anyone, and do not track visitors across sites with it.
No system is perfectly secure — please use a strong, unique password.
Krooko is for people aged 16 or older. This is above the digital-consent age applicable in Greece (15 under Law 4624/2019), so no parental-consent mechanism is operated. You confirm your age at sign-up. We do not knowingly collect data from anyone under 16; accounts reported or found to belong to under-16 users are removed together with their data. Anyone can flag a suspected under-16 account with the report tool ("Under-16 user"). See the 16+ Policy.
You can exercise most rights directly in Settings (download your data, edit profile, delete posts/cards/messages, manage devices, privacy toggles, delete account). For anything else, email alexroussossm@gmail.com — we respond within one month as GDPR requires.
Settings → "Delete account" permanently deletes your account after a typed confirmation. This removes your profile, cards, posts, stories, comments, likes, messages, group memberships, collab records, favourites, blocks, devices and notifications — the deletion cascades through the whole database. Nothing is retained except: (a) copies that may persist briefly in encrypted backups (see retention), and (b) records we must keep to comply with law or evidence enforcement. Content you sent to others that they saved outside Krooko (e.g. screenshots) is outside our control.
Krooko sets no tracking, analytics or advertising cookies. We use only essential browser storage (localStorage) to keep you logged in and remember your theme — details, durations and how to clear it are in the Cookie Policy. Because only strictly necessary storage is used, no cookie-consent banner is required.
| Service | What it does | What it receives |
|---|---|---|
| Supabase | Authentication, database, file storage, realtime delivery of messages/notifications; sends service emails (sign-up confirmation, password reset, email change) | All account and content data described above, as our processor; infrastructure logs (incl. IP) |
| FormSubmit | Delivers contact-form messages and reports to our email | Only what you type in those forms (name, email, message / report details) |
| NVIDIA (AI inference API, US-based) | Powers the Krooko AI assistant, AI text improve, hashtag suggestions, the AI icebreaker in messages, "Describe what you need" card matching, and the bio and first card written for you during account setup | Only the text needed for that request — your message or prompt, your draft post/card, a recipient's bio/card text, or the answers you give during account setup — never your password or other account data. Per NVIDIA's terms, it may use this text, without identifying you, to improve its own products and AI models — see section 10 for the transfer safeguard |
| Sites you list or visit from Discover | Discover links out to third-party apps and websites | Nothing from us. Following a link is between you and that site, under their privacy policy — we do not pass them your data, and we do not track what you click |
| goQR (api.qrserver.com) | Generates the QR code of your profile link in Settings | Your public profile URL, when you open that Settings section |
| Google Search Console | Lets us see how Krooko appears in Google Search — indexing status, crawl errors, which search queries surface our pages — and submit our sitemap | No data about you or your visit. It reports aggregate search data Google already holds from operating Search itself (e.g. how often a query showed one of our pages); verifying our site with it adds no tracking script or cookie to any page |
We use no analytics service (no Google Analytics), no payment processor, no Firebase, no social-login providers. Google Search Console, above, is not an analytics tool — it reports on search visibility, not visitor behaviour, and it doesn't track anyone using Krooko.
We send no marketing emails, newsletters, promotional push notifications or SMS. The only emails you receive are transactional (account confirmation, password reset, email-change confirmation). Notifications inside Krooko (likes, follows, replies, invites) exist only in the app's inbox. While a Krooko tab is open, new activity may play a short alert sound and show a red dot on the tab icon — this happens entirely in your browser, involves no browser push-notification permission and no additional data collection, and the sound can be switched off in Settings.
To keep Krooko safe we may: review reports, remove content that breaks the Community Guidelines or the law, suspend or ban accounts, and remove under-16 accounts. Beyond the automated pre-publish checks described in section 8 (photo moderation and language filtering), decisions on reported content are made by a human. Every card, post, story, comment, profile and message can be reported (via its three-dot menu, or, in Community, the report link next to a post), and reports are anonymous to the reported user.
If a personal-data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the Hellenic Data Protection Authority within 72 hours as required by GDPR Art. 33, and inform affected users without undue delay where Art. 34 requires it.
We may update this policy as Krooko evolves. The "Last updated" date above always reflects the current version, and material changes will be announced on the platform. Continued use after an update constitutes acceptance where legally appropriate; where a change requires consent, we will ask for it.
We'd appreciate the chance to resolve any concern first — email alexroussossm@gmail.com. You also have the right to lodge a complaint with the Greek supervisory authority:
Hellenic Data Protection Authority (Αρχή Προστασίας Δεδομένων Προσωπικού Χαρακτήρα)
Kifissias Ave 1–3, 115 23 Athens, Greece · www.dpa.gr
Related documents: Terms of Service · Community Guidelines · Cookie Policy · 16+ Policy · Safety Center