Your data, kept honest.
Working draft · prepared 18 July 2026 · pending legal review
The short version
talks. is an anonymous campus forum. You post under a random alias and a penguin avatar, not your real name. We ask for your student email to keep the community to real students, and we store that email separately from your posts. We only ever connect an alias to a real person if the law compels us, or to stop a serious and imminent threat to someone's safety.
We collect the data we need to run the app, keep it safe, and understand how it is used. We do not sell your personal data.
One feature, Talks Match, is different: it is an opt-in, 18+ dating feature where you build a real profile (first name, photos, age, and answers that can reveal your sexual orientation and religion). That data is sensitive and we only process it with your explicit consent. See section 11.
1. Who we are (the data controller)
talks. is operated by its founder, Samer Roz, from Madrid, Spain, who acts as the data controller under the EU General Data Protection Regulation (GDPR) and the Spanish data protection act (LOPDGDD) while the talks. company is being incorporated. Once the company is formed, it will take over as controller and this page will be updated. Our core database and Cloud Functions run in the EU region europe-west1.
Contact and all data requests: tellus@thetalksapp.com. We are not required to appoint a Data Protection Officer; all data matters are handled through this address.
2. Who can use talks. (age)
talks. is for enrolled university students. Access to the main app is gated on a valid university student email, and that student gate is how we keep the community to students. Talks Match is strictly 18+ and enforces a date-of-birth age check on our servers. We are not directed at children. If we learn that an account does not belong to an enrolled university student, we may remove it.
3. The anonymity model, explained honestly
- On the main app you post, comment, and chat under a random alias and a penguin avatar. We never ask for your real name, so it is never shown.
- Your email is stored separately from your content. There is no feature in the app that reveals, to another user, the real person behind an alias.
- When a post or comment is created, the app stores a snapshot of your alias at that moment rather than a live link to your identity. If you change your alias, the old alias is retired and permanently reserved so nobody can reuse it, and your old content keeps the old alias snapshot.
- talks. is pseudonymous, not untraceable. Your account has an internal ID that authored your content in our database. We do not expose it as an identity, and we would only ever deliberately connect an alias to a real person where we are legally required to, or where it is necessary to prevent a serious and imminent threat to someone's life or safety.
- Whisper is a private one-to-one thread anchored to a post, so the two people in it can see each other's aliases. We never list publicly who whispered on a post, and unsaved whispers delete automatically.
4. What data we collect
Account and identity
Your student email (to verify you are a real student), your password (handled entirely by Firebase Authentication, never readable to us), a one-time verification code (stored only as a salted hash and deleted on use or after 10 minutes), your internal account ID, account creation date, and a signup ordinal.
Your pseudonymous identity
Your current alias, your alias history (retired personas) and change timestamps, your penguin avatar and cosmetics, and your culture score, role, streaks, and stats.
Community profile
Your campus, school(s), degree(s), graduation year, and exchange status, your notification preferences, and your list of blocked users.
Content you create
Posts, titles, bodies, tags, polls and poll votes, comments and replies, GIFs, redactions, quotes and reposts, up/down votes, "super" reactions, global chat messages, whisper messages, Daily Discussion answers, product feedback, and reports you submit. This content is authored under your alias.
Media you upload
Images and video attached to posts. Before upload, your device re-encodes images and strips EXIF metadata including GPS/location. Uploaded media lands in a private quarantine area and is automatically scanned for unsafe content before it is shown (section 6).
Device and technical data
Push notification tokens (Firebase Cloud Messaging), your platform (iOS or Android) and app version, and crash diagnostics (Firebase Crashlytics). We do not collect your IP address, advertising identifier, or a device UUID for tracking.
Usage and analytics
If you turn it on, we measure how talks. is used so we can improve it: screen views, sessions, time spent on posts, scroll depth, what you tap, how you move through features, and how you respond to notifications. Analytics is optional and off until you turn it on. You choose at signup with a single toggle, and you can change your mind any time in Settings > Privacy & Legal. When it is off, we collect no behavioural analytics. Analytics runs through Firebase Analytics. See section 5 for the legal basis.
Special-category data in Talks Match
Talks Match (an opt-in, 18+ feature) processes sensitive data. This is set out in full in section 11. In summary, a Match profile stores your first name, date of birth, photos, voice notes, gender, who you want to be matched with (which can reveal your sexual orientation), and an optional religiousness answer, plus lifestyle answers, nationality, languages, height, and questionnaire answers.
Real names in First Week Out (FWO)
First Week Out is the one place in talks. that deliberately uses real names. When you sign up for FWO we store your real first name and an optional Instagram handle, kept entirely separate from your alias identity and never joined to it. FWO stores a first name only, not a full name.
5. Why we use your data, and our legal basis
| What we do | Why | Legal basis (GDPR Art. 6 / 9) |
|---|---|---|
| Create and run your account, verify your student email, host your content | To provide the service you signed up for | Contract 6(1)(b) |
| Send transactional emails (verification, password reset, security) | To operate the account | Contract 6(1)(b) |
| Moderate content, scan uploaded media, handle reports, block ban-evasion | To keep the community safe and lawful | Legitimate interests 6(1)(f); legal obligation 6(1)(c) |
| Security, rate limiting, abuse and fraud prevention | To protect users and the service | Legitimate interests 6(1)(f) |
| Push notifications | To keep you updated on activity you care about | Consent 6(1)(a) via device permission |
| Behavioural analytics (section 4) | To understand usage and improve the product | Consent 6(1)(a) — off until you opt in |
| Talks Match: first name, DOB, photos, voice, and matching answers | To run the matching feature you opted into | Explicit consent 9(2)(a) for special-category fields; consent 6(1)(a) for the rest |
| First Week Out real name and Instagram handle | To run the freshers feature you opted into | Consent 6(1)(a) |
| Respond to legal requests; report illegal content | Because the law requires it | Legal obligation 6(1)(c); vital interests 6(1)(d) |
| Keep a hashed-email tombstone to enforce bans | To prevent banned users re-registering | Legitimate interests 6(1)(f) |
Where we rely on legitimate interests, we have weighed our interest against your rights, and you can object at any time (section 10).
6. Media safety scanning (automated processing)
Every image or video you upload is scanned automatically before it can appear. Images are checked with Google Cloud Vision SafeSearch; videos are checked with Google Cloud Video Intelligence. If the scan is clean, the media is published. If it is flagged, the file stays in quarantine, the post stays pending, and a moderation record (the file plus the safety scores) is created for human review. Resolved review records are kept as an audit trail for 90 days and then deleted automatically. A human reviews anything that is flagged; this scanning does not produce legal or similarly significant effects about you.
7. Who we share data with (processors and recipients)
We do not sell your personal data. We use trusted service providers who handle data on our instructions.
| Processor | What they do for us | Data they see |
|---|---|---|
| Google / Firebase | Authentication, database, storage, functions, messaging, analytics, crash reporting, remote config | Most categories (core DB and functions in the EU) |
| Postmark | Verification, password-reset, and security emails | Your email address |
| Google Cloud Vision + Video Intelligence | Automated media safety scanning | Uploaded images and video |
| Algolia | In-app search | Post titles and bodies; your search queries (the index does not carry your account ID) |
| Klipy | GIF search | Your GIF search text |
| Cloudflare | Hosts our web app and admin site (Cloudflare Pages) | Web request data for the web surfaces |
| Apple / Google | App stores and push-notification transport | Device / push data |
We also disclose content or data to law enforcement, courts, or regulators when legally compelled, or to protect someone from a serious and imminent threat. If we restructure or are acquired, data may transfer to the successor under the same protections.
8. International transfers
Some processors above are US-based or operate globally, so your data may be transferred outside the European Economic Area. Where that happens the transfer is protected by mechanisms recognised under GDPR, primarily the European Commission's Standard Contractual Clauses and, where applicable, an adequacy decision such as the EU-US Data Privacy Framework for certified providers. Our core database and functions stay in the EU.
9. How long we keep it (retention)
- Account and profile data: until you delete your account (then erased or anonymized, section 12).
- Posts and comments: kept while the app runs; on account deletion the author is re-labelled "Deleted user".
- Unsaved whisper threads: 5 days (renewed on each message); saved whispers kept until you delete them.
- Notification inbox items: 60 days.
- Global chat messages: 90 days.
- Email verification codes: on use, and in any case 10 minutes.
- Unverified signups: deleted automatically after 48 hours.
- Resolved media moderation records: 90 days audit trail.
- Ban tombstone (hashed email): indefinite, to enforce bans (section 12). It cannot be reversed.
- Analytics: Firebase Analytics event data 2 months, user data 14 months, then deleted or kept only in aggregate.
10. Your rights and how to use them
Under GDPR you can, at any time, access the data we hold, correct it, delete your account and data, restrict or object to processing based on our legitimate interests, withdraw consent (for push, analytics, Talks Match, or FWO) without affecting processing done before withdrawal, and port your data in a common, machine-readable format. You can delete your account in the app under Settings, which triggers the automated erasure described in section 12. For anything else, email tellus@thetalksapp.com; we aim to respond within one month. Because accounts are pseudonymous, we may need to confirm a request comes from the account holder.
You can also complain to the Spanish authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es. We would appreciate the chance to fix it first.
11. Talks Match: sensitive data and explicit consent
Talks Match is an optional, opt-in, 18+ feature. If you never create a Match profile, none of this applies to you.
Age gate. You cannot create a Match profile without providing a date of birth, and the server rejects anyone under 18. Your date of birth cannot be changed after you first save it.
What a Match profile holds: your first name (shown on Match), date of birth (used for the 18+ gate and to show your age), photos and optional voice notes, gender and who you want to be matched with (together these can reveal your sexual orientation), an optional religiousness answer (display-only, no effect on matching, but it can reveal your religious beliefs), optional lifestyle answers, nationality, languages, height, and questionnaire answers.
Why this is treated specially. Your sexual orientation and religious beliefs are "special category" data under GDPR Article 9, which needs a stronger legal basis than ordinary data. We process it on your explicit consent (Article 9(2)(a)), which you give with a specific, unbundled consent step when you build and submit your Match profile. Your photos and voice notes are treated as sensitive in this context.
Matching. Talks Match uses your answers to compute compatibility and suggest matches. It only suggests people; a human is always in the loop through the match and chat flow.
Deletion. Deleting your Match profile, or your whole account, erases your Match data: profile, waitlist entry, photos and voice notes, pools, rankings, coupon grants, icebreaker and survey answers, and the messages you sent.
12. What happens when you delete your account
Deleting your account runs an automated cascade.
Erased outright: your user profile and its sub-data, all your alias documents (active and retired), saved posts, notification inbox, cross-device state, Daily Discussion answers, email verification record, rate-limit counters, chat suspension and presence records, up/down votes, "super" reactions, poll ballots, share receipts, product feedback, whisper threads you are in, push tokens, your entire Talks Match footprint, and your entire First Week Out footprint.
Anonymized but kept, so public threads stay coherent: your posts and comments remain but are re-labelled "Deleted user", and your global chat messages keep their text with the alias set to "Deleted user".
Retained by design: when you delete your account we keep a one-way hashed form of your email as a "tombstone". It carries no account ID and cannot be reversed into your email. It exists for one reason: to stop a banned user from simply deleting and re-registering. It is retained on our legitimate interest in keeping banned users out.
13. How we protect your data
Content is separated from identity by design. Database security rules govern what any account can read or write, sensitive actions run only on our servers, passwords and verification codes are never stored in readable form, and uploaded media is scanned before it is shown. No system is perfectly secure, but we build talks. so that being anonymous in public is the default.
14. Changes to this policy
If we change how we use your data, we will update this page. For anything material, especially a new purpose or a new category of data, we will ask for fresh consent rather than quietly reusing what we already hold.
15. Contact
Questions, requests, or complaints: tellus@thetalksapp.com.
This is a working draft prepared for legal review and is not yet in force. It must be reviewed by a qualified Spanish/EU data protection lawyer before it is published or relied upon as a statement of legal compliance.