Privacy Policy

Last updated: 10 September 2026

This privacy policy explains how Krinio (operated by Davide Maiolo, Kirchbühlstrasse 37a, 8712 Stäfa, Switzerland; contact@krinio.com) collects and processes personal data when you use krinio.com.
Data We Collect

Email address

Collected when you join the waitlist. After double opt-in confirmation, it is used for Krinio launch information and limited Ambassador membership release updates. Legal basis: consent (Art. 6(1)(a) GDPR). Stored until you unsubscribe, withdraw consent, or request deletion. We also record which of those announcements have already been sent to you, so a repeated send cannot reach you twice; that record is deleted together with your waitlist entry.

IP address

Stored at signup to prevent abuse (e.g. mass fake signups). A separate short-lived rate-limit event records the IP address for up to two hours to enforce five valid waitlist actions per hour. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). The signup IP address is retained for 90 days, then deleted. We also use the approximate country supplied by our hosting provider from the request IP address to display membership prices in an appropriate currency (Art. 6(1)(f) GDPR, legitimate interest in localized pricing). This value is processed for the request and is not saved to your profile or a pricing cookie.

Confirmation token

A random UUID generated at signup, used solely to verify your email address via a confirmation link.

Google sign-in data

If you choose Sign in with Google, Krinio receives your Google account identifier, email address, name, profile image, and authentication and session data through Google OAuth and Supabase Auth. We use this information to create and authenticate your Krinio account and prefill its profile. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The account data is retained until you delete your Krinio account; session and authorization data is retained until it expires, you sign out, or the account is deleted.

Connected YouTube channel data

If a creator explicitly connects a YouTube channel, Krinio uses the YouTube Data API with the read-only youtube.readonly scope to retrieve only the authenticated channel's ID, title, handle or custom URL, thumbnail, and public subscriber count. We store these values and an access-restricted server-side refresh token to link and display the channel, refresh the connection and public subscriber count, and optionally copy the selected channel image into the Krinio avatar. Krinio does not upload, edit, or delete YouTube content. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The channel record and refresh token are retained until the channel is replaced or the Krinio account is deleted. Revoking Krinio's access in your Google Account ends future access. It does not automatically delete metadata already stored by Krinio; contact contact@krinio.com if you want that data deleted earlier.

Saved ideas

When you are signed in and save an idea, we store the link between your account and that idea to provide your private Saved list. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Retained until you remove the idea or delete your account.

Community feedback, votes, and content reports

When you submit feedback or report an idea or feedback post, we store the feedback fields, report target, selected reason, optional explanation, moderation status, and the link to your account. Approved feedback and its author profile are visible to signed-in members; report reasons, explanations, voter identities, and reporter identities are not public. We process this to provide the feature (Art. 6(1)(b) GDPR) and for moderation, abuse prevention, and product improvement (Art. 6(1)(f) GDPR). Reports are retained while needed to review and document moderation decisions, then deleted or anonymized when no longer necessary.

In-app notifications

We store notification type, relevant resource identifiers, limited event details, creation time, and read time so we can notify you about important account, feedback, and support events. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Creators also receive an email when one of their ideas receives a support payment.

Language preference

We store the language you use in the app on your profile so we can send transactional email in that language, and the language you were reading in when you joined the waitlist so waitlist email reaches you in it. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for the profile value, consent (Art. 6(1)(a) GDPR) for the waitlist value. Retained until you delete your account or unsubscribe from the waitlist.

Requested payout country

If payouts are not yet available in your country, we store the country code you select together with your account to measure demand and prioritize new payout countries. Legal basis: legitimate interest in product and market planning (Art. 6(1)(f) GDPR). Retained until you choose another country or delete your account.

Support payment and payout records

We store the amount and status of a support payment; its links to the idea, supporter and creator; the anonymity choice; Krinio commission, Stripe fee and creator net amount; and Stripe account, Checkout Session and PaymentIntent identifiers. We receive and validate the currency during payment processing but do not store it in Krinio's database. We process this to perform the payment service (Art. 6(1)(b) GDPR), prevent fraud and handle claims (Art. 6(1)(f) GDPR), and meet financial recordkeeping duties (Art. 6(1)(c) GDPR).

Creator payout onboarding

Krinio stores the connected Stripe account identifier and checks payout readiness directly with Stripe when needed to enable creator payments. Stripe collects identity, contact, business, bank, tax and verification information directly during onboarding under its own privacy terms. Krinio does not receive raw bank details or identity documents. Legal bases: performance of a contract (Art. 6(1)(b) GDPR), compliance obligations (Art. 6(1)(c) GDPR), and fraud prevention (Art. 6(1)(f) GDPR).

Membership purchases and billing

For a creator membership or lifetime license, Krinio stores the selected offer, entitlement and purchase status; Stripe Customer, Checkout Session, Price, Subscription, PaymentIntent and invoice identifiers where applicable; currency, subtotal, tax and total; billing period, cancellation and refund status; and the connected-account country used for eligibility. Stripe collects the billing address, payment method and any business tax ID directly. Krinio does not store complete card details or the raw tax ID. Legal bases: contract performance (Art. 6(1)(b) GDPR), financial and tax obligations (Art. 6(1)(c) GDPR), and fraud and claims prevention (Art. 6(1)(f) GDPR). In the signed-in membership overview, Krinio retrieves the payment-method type, card brand and last four digits from Stripe for display. These masked details are not stored in Krinio's database. For an active Ambassador lifetime membership, we derive a public avatar decoration from the entitlement record and display it wherever your account avatar appears (Art. 6(1)(b) GDPR, contract performance). This decoration indicates Ambassador membership; the release, price and billing details remain private. Anonymous support payments display no membership decoration. The decoration is removed when the membership is revoked or otherwise ceases to be active.

Membership codes and granted memberships

For the waitlist launch offer, Krinio stores a single-use redemption code linked to your waitlist entry, when it was emailed, and when and by which account it was redeemed. Redeeming it creates a record of the granted plan with its start and end date, kept after the grant expires so the same offer cannot be issued twice. A grant has no purchase behind it, so no payment data is involved. Legal bases: performance of a contract (Art. 6(1)(b) GDPR) and prevention of abuse of the offer (Art. 6(1)(f) GDPR).

Manual verification requests

When an eligible paid creator requests the reviewed verification mark, Krinio stores the request status, submission and review times, and an internal reviewer note. Payment does not guarantee approval. The data is used to provide and document the review process (Art. 6(1)(b) GDPR) and to prevent impersonation, abuse and disputes (Art. 6(1)(f) GDPR).

Service Providers and Data Processors
We use the following third-party services. They act as processors under GDPR Art. 28 where applicable and may act as independent controllers for activities they determine themselves:

Supabase (Supabase Inc.)

Database and backend hosting. Production data stored in EU-region (Stockholm). Privacy policy: supabase.com/privacy

Google (Google Ireland Limited and Google LLC)

Google Sign-In and the YouTube Data API. Google processes the account, authorization, network, and device data needed to authenticate you, present the consent screen, and grant the selected read-only scope, and provides the authorized channel data to Krinio. Google may act as an independent controller for activities it determines itself. Transfers outside Switzerland, the EEA, or the UK are governed by Google's applicable data-protection terms and safeguards, including Standard Contractual Clauses where applicable. Krinio's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Privacy policy: policies.google.com/privacy. Google API Services User Data Policy: developers.google.com/terms/api-services-user-data-policy

Stripe (Stripe Payments Europe Limited and Stripe group companies)

Payment processing, creator identity and business verification, fraud prevention, connected accounts, payouts, creator membership billing, Stripe Tax, tax-ID validation, invoices and subscription management. Stripe receives payment, billing, contact, identity, business, bank, tax, device, and transaction data as needed for those services. Transfers outside Switzerland, the EEA, or the UK are governed by Stripe's Data Processing Agreement and safeguards including Standard Contractual Clauses where applicable. Privacy policy: stripe.com/privacy. Data Processing Agreement: stripe.com/legal/dpa

Resend (Resend Inc.)

Transactional email delivery. Used for double opt-in confirmations, secure waitlist unsubscribe links, consented launch and limited Ambassador release updates and, once the app is live, creator notifications about received support payments. Privacy policy: resend.com/legal/privacy-policy

Vercel (Vercel Inc.)

Web hosting and edge infrastructure. Also provides Vercel Web Analytics (aggregate, cookieless usage statistics) and Vercel Speed Insights (anonymous Core Web Vitals measurement, stored without an IP address). Privacy policy: vercel.com/legal/privacy-policy

Telegram (Telegram Messenger Inc.)

Delivery of privacy-minimized operational alerts about new feedback and idea reports to the Krinio operator. Feedback alerts contain only the deployment environment, category, and aggregate moderation counts. Idea report alerts contain the deployment environment, public idea title and identifier, selected report reason, and optional explanation. Reporter identity is never sent. Telegram receives the operator's chat identifier and these limited operational details. Telegram states that EEA user data is stored in the Netherlands and that transfers to group companies outside the EEA use Standard Contractual Clauses. Privacy policy: telegram.org/privacy

Analytics
We use Vercel Web Analytics to understand aggregate website usage (for example page views and basic device metadata) and Vercel Speed Insights to measure real page performance (Core Web Vitals such as loading speed, responsiveness and visual stability). According to Vercel documentation, both are cookieless and do not use local storage for tracking, and each Speed Insights measurement is stored anonymously with the route and URL, connection speed, browser, device type and operating system, and country, without an IP address and without linking page views into a session. We use this processing under legitimate interest (Art. 6(1)(f) GDPR) to improve site performance and usability.
Cookies and Local Storage
During the waitlist phase, Krinio sets only strictly necessary cookies: a functional cookie that remembers your language preference and, once you sign in, a session cookie used for authentication. These are required for the site to function and do not need consent. We do not use advertising or cross-site tracking cookies, and our analytics and performance measurement (Vercel Web Analytics and Vercel Speed Insights) are cookieless. If we ever introduce non-essential cookies, we will ask for your consent first through a cookie banner. Krinio also stores two values in your browser's local storage: your light or dark theme choice, and the fact that you closed the open-beta countdown banner. Both are strictly functional, remain on your device, are never transmitted to our servers, and identify nobody.
Legal Basis
Processing is based on your consent (Art. 6(1)(a) GDPR) when you submit your email address, on our legitimate interest (Art. 6(1)(f) GDPR) for abuse prevention, moderation, platform safety, fraud prevention, and legal claims, on performance of a contract or steps requested by you (Art. 6(1)(b) GDPR) when you use account, support, and payout features, and on legal obligations (Art. 6(1)(c) GDPR) for required financial and compliance records.
Applicable Data Protection Law
Krinio is operated from Switzerland, so data processing is primarily governed by the revised Swiss Federal Act on Data Protection (revFADP, nDSG), overseen by the Federal Data Protection and Information Commissioner (FDPIC, EDÖB). Because Krinio also addresses users in the European Union, the EU General Data Protection Regulation (GDPR) applies in addition under Art. 3(2) GDPR, and the legal bases and rights described in this policy are given with reference to it.
Your Rights
Under GDPR you have the right to access, rectify, or delete your personal data, the right to restrict or object to processing, and the right to data portability. To exercise any of these rights, contact us at contact@krinio.com. You also have the right to lodge a complaint with your national data protection authority.
Data Retention
Confirmed waitlist email addresses are retained until you unsubscribe, withdraw consent, or request deletion so Krinio can send launch and limited Ambassador release updates. IP addresses are deleted after 90 days. Short-lived waitlist rate-limit events are retained for up to two hours. If you do not confirm your email within 30 days, your entry is deleted automatically. Google sign-in account data is retained until you delete your Krinio account. Connected YouTube channel metadata and its server-side refresh token are retained until you replace the channel or delete your Krinio account; revoking access in Google ends future API access but does not by itself delete metadata already stored by Krinio. Saved-idea links are retained until you remove the idea or delete your account. Community feedback, moderation records, votes, and reports are retained while needed to operate the public feedback history and protect platform integrity, normally until account deletion, except where continued retention is required for abuse prevention, legal claims, or an anonymized product record. In-app notifications are retained until account deletion or an earlier cleanup period is introduced. A requested payout country is retained until you replace it or delete your account. Verification requests are retained until account deletion, except where a limited record is needed for impersonation prevention, abuse handling or legal claims. Support, membership, commission, fee, tax, invoice, refund and payout records are retained for applicable accounting, tax, anti-fraud, and claims periods, generally up to ten years where Swiss law requires it; Stripe retains the verification and payment data it controls under its own retention rules.
Contact
For any privacy-related requests, please contact: contact@krinio.com