Privacy Policy
Last updated: 10 September 2026
Email address
Collected when you join the waitlist. After double opt-in confirmation, it is used for Krinio launch information and limited Ambassador membership release updates. Legal basis: consent (Art. 6(1)(a) GDPR). Stored until you unsubscribe, withdraw consent, or request deletion. We also record which of those announcements have already been sent to you, so a repeated send cannot reach you twice; that record is deleted together with your waitlist entry.
IP address
Stored at signup to prevent abuse (e.g. mass fake signups). A separate short-lived rate-limit event records the IP address for up to two hours to enforce five valid waitlist actions per hour. Legal basis: legitimate interest (Art. 6(1)(f) GDPR). The signup IP address is retained for 90 days, then deleted. We also use the approximate country supplied by our hosting provider from the request IP address to display membership prices in an appropriate currency (Art. 6(1)(f) GDPR, legitimate interest in localized pricing). This value is processed for the request and is not saved to your profile or a pricing cookie.
Confirmation token
A random UUID generated at signup, used solely to verify your email address via a confirmation link.
Google sign-in data
If you choose Sign in with Google, Krinio receives your Google account identifier, email address, name, profile image, and authentication and session data through Google OAuth and Supabase Auth. We use this information to create and authenticate your Krinio account and prefill its profile. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The account data is retained until you delete your Krinio account; session and authorization data is retained until it expires, you sign out, or the account is deleted.
Connected YouTube channel data
If a creator explicitly connects a YouTube channel, Krinio uses the YouTube Data API with the read-only youtube.readonly scope to retrieve only the authenticated channel's ID, title, handle or custom URL, thumbnail, and public subscriber count. We store these values and an access-restricted server-side refresh token to link and display the channel, refresh the connection and public subscriber count, and optionally copy the selected channel image into the Krinio avatar. Krinio does not upload, edit, or delete YouTube content. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). The channel record and refresh token are retained until the channel is replaced or the Krinio account is deleted. Revoking Krinio's access in your Google Account ends future access. It does not automatically delete metadata already stored by Krinio; contact contact@krinio.com if you want that data deleted earlier.
Saved ideas
When you are signed in and save an idea, we store the link between your account and that idea to provide your private Saved list. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Retained until you remove the idea or delete your account.
Community feedback, votes, and content reports
When you submit feedback or report an idea or feedback post, we store the feedback fields, report target, selected reason, optional explanation, moderation status, and the link to your account. Approved feedback and its author profile are visible to signed-in members; report reasons, explanations, voter identities, and reporter identities are not public. We process this to provide the feature (Art. 6(1)(b) GDPR) and for moderation, abuse prevention, and product improvement (Art. 6(1)(f) GDPR). Reports are retained while needed to review and document moderation decisions, then deleted or anonymized when no longer necessary.
In-app notifications
We store notification type, relevant resource identifiers, limited event details, creation time, and read time so we can notify you about important account, feedback, and support events. Legal basis: performance of a contract (Art. 6(1)(b) GDPR). Creators also receive an email when one of their ideas receives a support payment.
Language preference
We store the language you use in the app on your profile so we can send transactional email in that language, and the language you were reading in when you joined the waitlist so waitlist email reaches you in it. Legal basis: performance of a contract (Art. 6(1)(b) GDPR) for the profile value, consent (Art. 6(1)(a) GDPR) for the waitlist value. Retained until you delete your account or unsubscribe from the waitlist.
Requested payout country
If payouts are not yet available in your country, we store the country code you select together with your account to measure demand and prioritize new payout countries. Legal basis: legitimate interest in product and market planning (Art. 6(1)(f) GDPR). Retained until you choose another country or delete your account.
Support payment and payout records
We store the amount and status of a support payment; its links to the idea, supporter and creator; the anonymity choice; Krinio commission, Stripe fee and creator net amount; and Stripe account, Checkout Session and PaymentIntent identifiers. We receive and validate the currency during payment processing but do not store it in Krinio's database. We process this to perform the payment service (Art. 6(1)(b) GDPR), prevent fraud and handle claims (Art. 6(1)(f) GDPR), and meet financial recordkeeping duties (Art. 6(1)(c) GDPR).
Creator payout onboarding
Krinio stores the connected Stripe account identifier and checks payout readiness directly with Stripe when needed to enable creator payments. Stripe collects identity, contact, business, bank, tax and verification information directly during onboarding under its own privacy terms. Krinio does not receive raw bank details or identity documents. Legal bases: performance of a contract (Art. 6(1)(b) GDPR), compliance obligations (Art. 6(1)(c) GDPR), and fraud prevention (Art. 6(1)(f) GDPR).
Membership purchases and billing
For a creator membership or lifetime license, Krinio stores the selected offer, entitlement and purchase status; Stripe Customer, Checkout Session, Price, Subscription, PaymentIntent and invoice identifiers where applicable; currency, subtotal, tax and total; billing period, cancellation and refund status; and the connected-account country used for eligibility. Stripe collects the billing address, payment method and any business tax ID directly. Krinio does not store complete card details or the raw tax ID. Legal bases: contract performance (Art. 6(1)(b) GDPR), financial and tax obligations (Art. 6(1)(c) GDPR), and fraud and claims prevention (Art. 6(1)(f) GDPR). In the signed-in membership overview, Krinio retrieves the payment-method type, card brand and last four digits from Stripe for display. These masked details are not stored in Krinio's database. For an active Ambassador lifetime membership, we derive a public avatar decoration from the entitlement record and display it wherever your account avatar appears (Art. 6(1)(b) GDPR, contract performance). This decoration indicates Ambassador membership; the release, price and billing details remain private. Anonymous support payments display no membership decoration. The decoration is removed when the membership is revoked or otherwise ceases to be active.
Membership codes and granted memberships
For the waitlist launch offer, Krinio stores a single-use redemption code linked to your waitlist entry, when it was emailed, and when and by which account it was redeemed. Redeeming it creates a record of the granted plan with its start and end date, kept after the grant expires so the same offer cannot be issued twice. A grant has no purchase behind it, so no payment data is involved. Legal bases: performance of a contract (Art. 6(1)(b) GDPR) and prevention of abuse of the offer (Art. 6(1)(f) GDPR).
Manual verification requests
When an eligible paid creator requests the reviewed verification mark, Krinio stores the request status, submission and review times, and an internal reviewer note. Payment does not guarantee approval. The data is used to provide and document the review process (Art. 6(1)(b) GDPR) and to prevent impersonation, abuse and disputes (Art. 6(1)(f) GDPR).
Supabase (Supabase Inc.)
Database and backend hosting. Production data stored in EU-region (Stockholm). Privacy policy: supabase.com/privacy
Google (Google Ireland Limited and Google LLC)
Google Sign-In and the YouTube Data API. Google processes the account, authorization, network, and device data needed to authenticate you, present the consent screen, and grant the selected read-only scope, and provides the authorized channel data to Krinio. Google may act as an independent controller for activities it determines itself. Transfers outside Switzerland, the EEA, or the UK are governed by Google's applicable data-protection terms and safeguards, including Standard Contractual Clauses where applicable. Krinio's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Privacy policy: policies.google.com/privacy. Google API Services User Data Policy: developers.google.com/terms/api-services-user-data-policy
Stripe (Stripe Payments Europe Limited and Stripe group companies)
Payment processing, creator identity and business verification, fraud prevention, connected accounts, payouts, creator membership billing, Stripe Tax, tax-ID validation, invoices and subscription management. Stripe receives payment, billing, contact, identity, business, bank, tax, device, and transaction data as needed for those services. Transfers outside Switzerland, the EEA, or the UK are governed by Stripe's Data Processing Agreement and safeguards including Standard Contractual Clauses where applicable. Privacy policy: stripe.com/privacy. Data Processing Agreement: stripe.com/legal/dpa
Resend (Resend Inc.)
Transactional email delivery. Used for double opt-in confirmations, secure waitlist unsubscribe links, consented launch and limited Ambassador release updates and, once the app is live, creator notifications about received support payments. Privacy policy: resend.com/legal/privacy-policy
Vercel (Vercel Inc.)
Web hosting and edge infrastructure. Also provides Vercel Web Analytics (aggregate, cookieless usage statistics) and Vercel Speed Insights (anonymous Core Web Vitals measurement, stored without an IP address). Privacy policy: vercel.com/legal/privacy-policy
Telegram (Telegram Messenger Inc.)
Delivery of privacy-minimized operational alerts about new feedback and idea reports to the Krinio operator. Feedback alerts contain only the deployment environment, category, and aggregate moderation counts. Idea report alerts contain the deployment environment, public idea title and identifier, selected report reason, and optional explanation. Reporter identity is never sent. Telegram receives the operator's chat identifier and these limited operational details. Telegram states that EEA user data is stored in the Netherlands and that transfers to group companies outside the EEA use Standard Contractual Clauses. Privacy policy: telegram.org/privacy