Privacy Policy
Last updated: 6 September 2026
This policy explains how we process personal data across everything KREISO offers. It is written to meet Articles 13 and 14 GDPR.
Also available in German.
It covers three places:
| Where | What it is |
|---|---|
| kreiso.app | Our website: the waitlist, /apply, the vibe test and paid events under /specials |
| app.kreiso.app | The web version of KREISO: sign-up, your profile, tickets and payment in a browser |
| The KREISO app | Our mobile app for iOS and Android |
Where a section applies to only one of them, it says so.
1. Controller
Nikita Konstantinovskiy Görresstraße 11 80798 Munich, Germany support@kreiso.app
We have not appointed a Data Protection Officer. See section 16.
2. Where your data is stored
Your account, your profile, your messages and your photos are stored inside the European Union. Our primary database is Cloud SQL for PostgreSQL in europe-west1 (Belgium). Files, including every photo, live in Cloud Storage in the EU multi-region. Our application services and our chat server run in europe-west1. The older parts of the website use Firestore in the eur3 multi-region (Belgium and the Netherlands).
Some of the companies that help us run KREISO are based outside the EU. Those transfers are covered in section 12.
3. The website (kreiso.app)
3.1 Waitlist
Data: name, email address and/or phone number. Purpose: to tell you when we launch or when a place opens. Legal basis: Art. 6(1)(b) GDPR, delivering the notification service you signed up for.
3.2 Event applications (/apply)
Data: name, email, phone, age, gender, country of origin, languages spoken, life stage, city, time in the city, the events you select, and a campaign identifier if you arrived through a tracked link. Purpose: to review applications, decide which events to invite you to, and contact you about them. Legal basis: Art. 6(1)(b) GDPR, steps taken at your request before a possible contract. The demographic details, which we also use for statistics, rest on Art. 6(1)(f), our legitimate interest in understanding who applies and building balanced groups.
3.3 Paid events (/specials)
Data: name, email, phone, age, gender, country of origin, number of seats, any note you write, and payment status. Purpose: to review your booking, allocate places, and run the event. Legal basis: Art. 6(1)(b) GDPR for the booking and the contract. Payment records: Art. 6(1)(c), legal retention obligations.
Card details are entered on Stripe's own checkout page. We never see or store your card number.
3.4 Vibe test and card decks (/vibe-test, /cards)
Data: your answers, a generated result, and a name if you enter one. Purpose: to produce and display your result, and to let you compare with friends who have a share link. Legal basis: Art. 6(1)(b), providing the feature you asked for.
4. Your KREISO account
This section covers app.kreiso.app and the mobile app, which are two ways into the same account.
4.1 Signing in
Data: your phone number, or your Google or Apple account, depending on how you sign in. Signing in with Apple may give us a relay address rather than your real one, and that is fine. We also hold an internal account identifier and, if you gave one, your email address and whether it has been verified. Purpose: to create and secure your account, and to let you back in on a new device. Legal basis: Art. 6(1)(b) GDPR.
Sign-in is handled for us by Firebase Authentication (Google). Verification codes are sent by SMS through the same service. We do not send marketing SMS. Ever.
4.2 Your profile
Data: your name, date of birth, gender, country of origin, the languages you speak, a short description of yourself, your city, your profile photo, the event categories you pick, and your answers to our questionnaire. We also store the language we should write to you in and your time zone, both read from your device.
Purpose: to build your profile, to put you into groups, and to show you to the other people in a group you join.
What other participants can see: your first name, your photo, your age in whole years, your country of origin, and the questionnaire answers we have marked as shown on profiles. They do not see your date of birth, your gender, your phone number, your email address, or your questionnaire answers that are not marked as shown.
Legal basis: Art. 6(1)(b) GDPR. Country of origin is covered separately in section 8.
4.3 Group chat
When a group is confirmed, we open a conversation for it.
Data:
- Messages you write. Stored on our servers so the conversation exists at all.
- Photos you send, up to ten per message. Your device shrinks and re-encodes every photo before it is uploaded, so the camera and location metadata of the original file is not carried across. On Android we also do not ask for the permission that would let us read a photo's location at all. Photos are stored in our private EU bucket and are served only to the people in that conversation, through short-lived links that expire after about fifteen minutes.
- A location, if you choose to share one. This is the one place KREISO reads your device's position, and only while the sharing screen is open. What we store and send to the group is the point you chose on the map, its coordinates, an optional label, and a small picture of the map. We never read your location in the background, and you can pan the map and send a different point instead of where you are.
- A read marker, so your unread count is right across your devices. We do not tell the other participants whether you have read a message, and we do not show anyone that you are typing.
- Reports and blocks. See section 4.6.
Boris is part of every group conversation. What he says is written by us in advance. See section 9.
Legal basis: Art. 6(1)(b) GDPR, running the conversation that belongs to the group you joined. Sharing a location rests on your decision to share it in that moment.
Who can read a conversation: the people currently in that group, and nobody else. If you leave a group or move to another one, you lose access to that history at the same moment. Our staff can access a conversation where it is necessary to look into a report, to keep people safe, or where the law requires it. We do not read conversations otherwise.
4.4 Push notifications and email preferences
Data: a push token issued by Apple or Google for each of your devices, the platform, and your notification preferences. Purpose: to send you the notifications you have turned on. When your app draws a message notification, it fetches the sender's picture, which means your device makes a request to us at that moment. Legal basis: Art. 6(1)(b) GDPR for notifications about your groups, your events and your account. See section 6 for anything promotional.
You can turn the push categories on or off in the app, and unsubscribe from any email using the link it carries.
4.5 Tickets and payment
Data: what you bought, what you paid, when, the tickets it created, which ones you spent, and a payment reference from Stripe. Purpose: to sell you tickets, to hold your place at an event, and to keep the accounts. Legal basis: Art. 6(1)(b) GDPR for the purchase and Art. 6(1)(c) for the accounting records.
Payment is processed by Stripe. You enter card or wallet details with Stripe directly. We never receive or store your card number.
4.6 Reports, blocks and safety
Data: when you report a message or a person, we record who reported, who was reported, which message, the reason you picked, and when. When you block someone, we record that too. Purpose: to look into what happened, to keep people safe, to enforce our terms and our Community Guidelines, and to stop somebody who has been removed from coming back. Legal basis: Art. 6(1)(f) GDPR. Our legitimate interest, and that of everyone else using KREISO, in a service where people are safe. Where a matter is serious, also Art. 6(1)(f) for establishing, exercising or defending legal claims, and Art. 6(1)(d) where somebody's vital interests are at stake.
We do not tell the person you reported or blocked that it was you. If you were reported, you may ask what was said about you, but we will not give you the reporter's identity: their rights are engaged too, and Art. 15(4) and Art. 14(2)(f) GDPR let us protect them.
4.7 After an evening: your review
After a group has met, we ask three things: how it was, who you would meet again, and anything else you want to say. The second question also lets you record that somebody did not turn up.
Purpose: to understand how well our matching works, to build better groups next time, and to notice people who repeatedly do not show up. Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in a service that gets better at what it does, and in evenings where people actually arrive.
Nothing you write here is ever shown to the people it is about. It is not a rating anyone can see, it is not published, and it does not appear on anybody's profile. What it does do is influence who you are matched with in future, and that works in both directions: what other people say affects your matches, and what you say affects theirs. You can ask us what we hold about you and have it corrected under section 14.
4.8 Invitations
If you invite somebody, we handle a signed invitation link and, once they accept, the fact that the two of you are connected to that event. If somebody invited you, we learned your details from them at that moment. That is the source, and Art. 14 GDPR is why this sentence is here.
5. Making KREISO work and making it better
Across all three surfaces we also process your data to:
- keep the service running, diagnose faults and restore it after one;
- prevent, detect and investigate abuse, spam, fraud, fake accounts and duplicate sign-ups;
- understand how KREISO is used and improve it, including improving how we match people and how we build groups;
- develop, test and evaluate the models and rules our matching uses, wherever possible on data that no longer identifies anyone;
- enforce our terms and Community Guidelines; and
- establish, exercise or defend legal claims.
Legal basis: Art. 6(1)(f) GDPR. We have weighed our interest against yours in each case, and we can explain that assessment on request. You may object under Art. 21 GDPR on grounds relating to your particular situation. Where we rely on legitimate interest to improve the service, an objection is honoured without you giving any reason at all.
6. Messages we send you
We send four different kinds of message, and they rest on different bases:
| Kind | Example | Legal basis |
|---|---|---|
| Transactional | Your group is confirmed, your evening is tomorrow, here is the address, a new message arrived, your payment went through, your account needs attention | Art. 6(1)(b) GDPR, performing our agreement with you |
| Service notifications | Events open in your city, a place has come free, we have launched where you are | Art. 6(1)(b) GDPR. Telling you about evenings you could join is the service you signed up for, not advertising. You can still switch these off. |
| Similar events, to people who have bought | If you have bought tickets, news about comparable future events | Art. 6(1)(f) GDPR together with § 7(3) UWG. You may object at any time, free of charge, using the link in every message. |
| General promotional email | Anything not covered above | Art. 6(1)(a) GDPR, your separate consent |
We do not send marketing SMS. Text messages are only ever sign-in codes and details for an event you applied for or booked.
Every message carries a one-click way to stop receiving that kind of message, and the app has a settings screen for the same thing. Opting out of promotional messages does not stop transactional ones about an event you have booked: you will still get the address and the reminder.
7. Analytics, diagnostics and storage on your device
7.1 On the website and at app.kreiso.app
We use Google Analytics 4 to understand how the site is used and where people drop out, and, at app.kreiso.app, the Meta pixel and the TikTok pixel to measure our advertising.
Nothing is measured until you accept it. No analytics or advertising cookie is set, no pixel is loaded, and nothing is sent to Google, Meta or TikTok until you click Accept on our cookie banner. Reject is offered with the same weight as Accept, and ignoring the banner counts as reject. You can change your mind at any time.
Legal basis: § 25(1) TDDDG and Art. 6(1)(a) GDPR, consent.
7.2 In the mobile app
The app uses two Google services that report back to us:
| What | Purpose |
|---|---|
| Firebase Crashlytics | Records crashes and handled errors so we can fix them. Without it we cannot keep the app working. |
| Firebase Analytics | Counts screens and actions, so we can see where the app is confusing. Never message content, never what you write. |
The app carries no advertising SDK, no third-party tracker and nothing that follows you into other apps. On Android, if you installed after clicking an advertisement, Google Play passes us the campaign that sent you.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in an app that works and in knowing which parts of it do not. You may object at any time by writing to support@kreiso.app, and we will stop collecting it for you.
7.3 What is stored on your device
Website and app.kreiso.app:
| What | Purpose | Consent needed? |
|---|---|---|
| Flow and session identifiers | Lets you return and carry on without re-entering everything | No, strictly necessary |
| Language preference | Remembers whether you chose English or German | No, strictly necessary |
| Sign-in token | Keeps you signed in | No, strictly necessary |
| App Check token | Security, see section 11 | No, strictly necessary |
| Your cookie choice | Remembers what you decided | No, strictly necessary |
| Stripe's fraud checks, on the payment screen only | Stripe loads its own payment form there and uses it to spot fraudulent payments | No, strictly necessary |
| Google Analytics cookies, Meta and TikTok pixel cookies | Analytics and advertising measurement | Yes |
In the mobile app, everything stored on your device is there so the app works. Nothing on this list is used for advertising:
| What | Purpose |
|---|---|
| Sign-in token | Keeps you signed in, held in the device keychain |
| A copy of what you have already loaded | Your profile, your groups, your events, and up to 30 days of your message history, so the app opens instantly and works with no signal |
| Downloaded photos | Profile pictures, event pictures and photos from your conversations, so they do not download twice |
| Your unfinished sign-up | Your answers so far, so closing the app does not lose them |
| Messages you sent while offline | Held until they can be delivered |
| Push token and notification settings | So notifications reach the right device |
All of it is removed when you sign out or delete your account, and all of it goes when you delete the app.
8. Country of origin, languages, and Article 9 GDPR
We ask where you are from and which languages you speak. Languages are how we make sure everybody in a group can talk to each other. Your country of origin is shown on your profile to the other people in your group, and is one of the things considered when groups are built.
Neither is a special category of data under Art. 9 GDPR. Nationality and the languages you speak are not on that list, and we do not use them to infer, record or match on ethnic or cultural background.
Should we ever introduce matching that weighs a shared cultural background, we would ask for your explicit consent under Art. 9(2)(a) GDPR separately and in advance, and you would be able to decline and still use KREISO.
We do not process data about your health, religion, political opinions, trade union membership, sexual orientation or sex life, and we do not try to work any of them out. If a free-text field invites you to describe yourself, or you are writing in a group conversation, please keep in mind that anything you choose to put there is stored the way you wrote it. We do not analyse it for sensitive characteristics and we would rather you did not include them.
9. Boris, and artificial intelligence
Boris is not an artificial intelligence, and today nothing you write is sent to an AI provider. He is our host. Everything he says in the app is written by us in advance and stored as text; a message from Boris is us talking to you through a character, not a model generating a reply. Your messages, your profile and your questionnaire answers are not sent to any AI company.
Groups are built by our own software running on our own servers, using the rules described in section 10.
Looking ahead. We may in future use artificial intelligence for a limited set of purposes: helping Boris answer questions, suggesting how groups might be composed, translating, and finding harmful content faster. If we do, then:
- the provider will act as our processor under Art. 28 GDPR, under a contract that forbids using your data to train their models;
- processing will take place in the EU, or under an adequacy decision or Standard Contractual Clauses;
- the legal basis will be Art. 6(1)(b) where it delivers the service and Art. 6(1)(f) where it protects it, and you may object under Art. 21;
- a decision that matters will never be left to a model alone; and
- where you are talking to an AI rather than reading something we wrote, we will say so plainly, and anything generated will be marked as such.
We will update this section, with the provider named, before that starts.
10. How matching works, and Article 22 GDPR
KREISO's whole point is deciding who should meet whom. Our software does that, and it does it automatically.
It reads your questionnaire answers, your languages, your event categories, your city, your age, the availability you have shown, and, where you have consented, your country of origin. It also reads the signals described in section 4.7: who people said they would meet again, and who did not turn up. From that it forms small groups. A person can review, adjust or override the result, and does so when a group needs it.
This is not a decision that produces legal effects or similarly significant effects on you within the meaning of Art. 22 GDPR. Being placed in one group of strangers rather than another does not change your legal position, your money, your work or your access to anything you are entitled to. There is no entitlement to a particular group in the first place.
We are telling you this anyway, because it is your data and you should know what it does. If you are unhappy with how you have been matched, write to support@kreiso.app and a person will look at it.
11. Security and abuse prevention
We use Firebase App Check to verify that requests come from our genuine website and our genuine app, rather than from automated tooling. On the website this uses reCAPTCHA Enterprise, which reads technical characteristics of your device and browser; in the app it uses App Attest on iOS and Play Integrity on Android. Our servers reject requests without a valid token, so the service cannot function without it.
Legal basis: Art. 6(1)(f) GDPR, our legitimate interest in preventing abuse, spam and fraud. Because this is strictly necessary to deliver the service you requested, it falls within the exemption in § 25(2) no. 2 TDDDG and is not subject to consent.
reCAPTCHA Enterprise is provided by Google as our processor under the Google Cloud Data Processing Addendum. It is not the free consumer reCAPTCHA product, and your data is not used for Google's own purposes.
Beyond that we protect data with encryption in transit and at rest, authenticated access controls, private storage that no client can read directly, image links that expire, and access limited to what operations require.
No system is perfectly secure. If you find a vulnerability, please report it to support@kreiso.app.
12. Who we share data with, and international transfers
We do not sell, rent or trade personal data. We use the following processors, each under a data processing agreement pursuant to Art. 28 GDPR:
| Processor | Purpose | Location |
|---|---|---|
| Google Cloud (Cloud SQL, Cloud Storage, Cloud Run, Firebase Authentication, App Check, Firestore, Hosting, Cloud Functions) | Database, file storage, hosting, sign-in, security | EU (europe-west1, EU, eur3) |
| Firebase Cloud Messaging, Apple Push Notification service | Delivering push notifications | EU/US |
| Firebase Analytics, Crashlytics | App diagnostics and usage measurement | EU/US |
| Google Ireland Ltd., Google Analytics 4 | Website analytics, only with your consent | EU/US |
| Meta, TikTok | Advertising measurement at app.kreiso.app, only with your consent | US |
| Stripe Payments Europe Ltd. | Payment processing | EU/US |
| Resend | Transactional and promotional email, and the contact list it is sent from | US |
Image resizing runs on our own servers in the EU rather than through any image service. Chat runs on our own server in the EU. Neither involves a third party.
Stripe acts as an independent controller for parts of the payment process under its own privacy policy. Apple and Google act as independent controllers for their own sign-in and push infrastructure.
We may also disclose data where required by law, or to establish, exercise or defend legal claims.
Where a processor handles data outside the EU or EEA, the transfer is protected by an adequacy decision of the European Commission, which covers transfers to organisations in the United States certified under the EU-U.S. Data Privacy Framework, or by the European Commission's Standard Contractual Clauses together with technical measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards by writing to support@kreiso.app.
13. How long we keep data
| Data | Retention |
|---|---|
| Your account and profile | For as long as your account exists |
| After you delete your account: a safety window | 3 months. We keep enough to look into anything that comes to light about conduct before you left, and to defend a claim |
| After an account is banned | 12 months, and for as long as necessary the minimum needed to stop that person opening a new account |
| Messages and photos in a conversation | For as long as the conversation exists. Messages you sent stay in the conversation for the other participants, shown as coming from a deleted account, because the conversation is theirs too |
| Reports, blocks and safety records | 6 years, so that a pattern of behaviour is still visible and a claim can still be defended |
| Reviews and matching signals | For as long as your account exists, then anonymised and kept as statistics |
| Payment and accounting records | Up to 10 years, as required by § 147 AO and § 257 HGB |
| Contract data, for legal claims | 3 years from the end of the year in which the contract was concluded (§§ 195, 199 BGB) |
| Consent and acceptance records | 3 years from the end of the year in which consent was withdrawn, as evidence under Art. 7(1) GDPR |
| Waitlist entries and website applications | Until you unsubscribe or ask us to delete them, or 36 months without any interaction from you |
| Analytics data | 14 months, the maximum Google Analytics permits |
| Crash and diagnostic reports | 90 days |
| Server and error logs | 90 days |
Where a period runs from inactivity, the clock restarts each time you interact with us. After these periods data is deleted or irreversibly anonymised.
14. Your rights
You have the right to access your data, to have it rectified or erased, to restrict or object to processing, to data portability, and to withdraw consent at any time with effect for the future.
Where we rely on legitimate interest, you may object under Art. 21 GDPR on grounds relating to your particular situation. Where the legitimate interest is improving the service, we honour an objection without asking why.
Deleting your account. You can delete your account yourself, in the app, under Settings, or at kreiso.app/delete-account. Deletion removes your profile, your photo, your tickets, your devices and your reviews. Two things survive it, and both are deliberate: messages you sent stay in the conversations they belong to, shown as coming from a deleted account, because those conversations belong to the other participants as well; and safety, payment and accounting records are kept for the periods in section 13.
To exercise any other right, write to support@kreiso.app. We respond within one month; if a request is complex we may extend this by two further months and will tell you why.
You may also lodge a complaint with a supervisory authority. The one responsible for us is:
Bayerisches Landesamt für Datenschutzaufsicht (BayLDA) Promenade 27, 91522 Ansbach, Germany https://www.lda.bayern.de
You may also complain to the authority where you live or work.
15. Age
KREISO is for people aged 16 and over, and we do not knowingly collect data from anyone younger. Some events have an 18+ requirement, stated in the event description. If you believe a child has given us personal data, write to support@kreiso.app and we will delete it.
16. Data Protection Officer
We have not appointed a Data Protection Officer. Under § 38(1) sentence 2 BDSG, one becomes mandatory regardless of headcount if our processing requires a Data Protection Impact Assessment under Art. 35 GDPR. We are assessing this, and will appoint and publish a DPO if it applies.
17. Changes
We may update this policy. If changes are material we will tell you by email, or by a prominent notice in the app or on the site, before they take effect. The date at the top always reflects the current version.
18. Contact
Nikita Konstantinovskiy Görresstraße 11 80798 Munich, Germany support@kreiso.app