Your data, kept honest.
Effective 4 July 2026 · Last updated 4 July 2026
The short version
talks. is an anonymous campus forum. You post under a random alias and a penguin, not your name. We ask for your student email so we can keep the community to real students, but we hold that email separately and we never attach it to your posts for anyone to see. We only connect the two if the law forces us to, or to stop a serious threat to someone's safety. We collect what we need to run and improve the app, and we are building an in-app switch that puts behavioural analytics fully in your hands. We do not sell your personal data.
1. Who we are
talks. is operated by its founder, Samer Roz, from Madrid, Spain, who acts as the data controller under the EU GDPR and the Spanish Data Protection Act (LOPDGDD) while the talks. company is being incorporated. Once the company is formed, it will take over as controller and this page will be updated. We run talks. at IE University (Madrid and Segovia) from Spain, so Spanish law and GDPR apply.
Contact and all data requests: tellus@thetalksapp.com. We are not required to appoint a Data Protection Officer; all data matters are handled through this address.
2. Who can use talks.
talks. is for university students, and you must be at least 16. Some features, including Talks Match, are for users 18 and over only. We do not knowingly collect data from anyone under 16, and we will delete such accounts if we find them.
3. The anonymity model, honestly
- You post under a random alias and a penguin avatar. Your real name is never shown, because we never ask for it.
- Your email is stored separately from your content. There is no button, anywhere, that reveals who is behind an alias.
- talks. is pseudonymous, not untraceable. Your account has an internal ID that authored your content. We do not expose it, and we would only connect an alias to a person where we are legally required to, or where it is necessary to prevent a serious and imminent threat to someone's safety.
- This matches what we promise in the app and on our site: we verify emails to keep the community real, but never link them to your posts publicly, and we only step in on a serious legal or safety threat.
- One honest caveat: Whisper is a private one-to-one thread, so the two people in it can see each other's aliases. We never list who whispered on a post, and unsaved whispers are deleted automatically.
4. What we collect
Account and identity
Your student email, your password (handled by Firebase, never readable to us), a one-time verification code (stored hashed, then deleted), your internal account ID, and your signup position.
Your pseudonymous identity
Your current alias, alias history, penguin avatar and cosmetics, culture score, role, badges, and streaks.
Community profile
Campus, school(s), degree(s), graduation year, notification preferences, and blocked users.
Content you create
Posts, comments, polls and votes, GIFs, redactions, quotes and reposts, chat and whisper messages, Daily Discussion answers, confessions, feedback, and reports, all under your alias.
Media you upload
Images and video attached to posts. Uploads are scanned automatically for unsafe content before they appear, and we strip image location/EXIF metadata on upload.
Device and technical
Push notification tokens, your platform (iOS/Android) and app version, and crash diagnostics. We do not collect your IP address, advertising ID, or a device UUID for tracking.
Usage and analytics
We measure how you use talks.: screen views, session length and return frequency, time spent viewing posts, scroll depth, what you tap, what you post and comment on, how you move through features, and how you respond to notifications. Today this runs on our legitimate interest in understanding and improving a brand-new product. We are building an in-app analytics switch; once it ships, behavioural analytics will run on your consent and you will control it in Settings. Until then, you can object at any time by emailing tellus@thetalksapp.com and we will turn analytics off for your account.
Upcoming features
Talks Match (from September 2026, 18+) will process your date of birth, questionnaire answers, and a real profile with photos, on your consent. We do not collect phone numbers. The Frame is a campus photo feature moderated like other media.
5. Why we use it, and our legal basis
| What we do | Legal basis (GDPR Art. 6) |
|---|---|
| Run your account, verify your email, host your content | Contract |
| Moderate content, scan media, handle reports, prevent ban-evasion | Legitimate interests; legal obligation |
| Security, rate limiting, abuse and fraud prevention | Legitimate interests |
| Push notifications | Consent |
| Behavioural analytics | Legitimate interests today; consent once the in-app switch ships |
| Talks Match (date of birth, questionnaire) | Consent |
| Respond to legal requests; report illegal content | Legal obligation; vital interests |
| Aggregated, anonymized statistics | Legitimate interests (outside GDPR once truly anonymized) |
6. Who we share data with
We do not sell your personal data. We use trusted providers who process data on our instructions: Google / Firebase (auth, database, storage, functions, messaging, analytics, crash reporting), Postmark (email), Google Cloud Vision and Video Intelligence (media safety scanning), Cloudflare (web hosting), Algolia (search), GIF providers such as Tenor/Klipy (your GIF search text), and Apple and Google (app stores and push transport). We also disclose data to authorities when legally compelled or to prevent a serious safety threat.
7. International transfers
Some providers are US-based or global, so data may leave the European Economic Area. Those transfers are protected by GDPR-recognised mechanisms, mainly the EU Standard Contractual Clauses and, where applicable, an adequacy decision. Our core database and functions stay in the EU.
8. How long we keep it
- Account and profile: until you delete your account.
- Posts and comments: kept, but re-labelled "Deleted user" if you delete your account.
- Whispers: unsaved deleted after 5 days; saved kept until you delete them.
- Verification codes: deleted on use, within about 10 minutes.
- Unverified signups: deleted after about 48 hours.
- Deletion tombstone: a hashed form of your email is kept indefinitely, only to enforce bans and stop banned users re-signing up. It cannot be reversed.
- Analytics: retained by Firebase Analytics as event-level data for 2 months and user-level data for 14 months, then deleted or kept only in aggregated form.
9. Your rights
Under GDPR you can access, correct, delete, restrict, object, withdraw consent, and port your data. Delete your account any time in Settings > Delete Account. For anything else, email tellus@thetalksapp.com and we will respond within one month. Because accounts are pseudonymous, we may need to confirm a request comes from the account holder before acting.
You can also complain to the Spanish authority, the Agencia Española de Protección de Datos (AEPD), at www.aepd.es. We would appreciate the chance to fix it first.
10. How we protect your data
Content is separated from identity by design. Access is restricted, security rules govern what any account can read or write, sensitive actions run only on our servers, and passwords and codes are never stored in readable form. No system is perfectly secure, but talks. is built so that being anonymous in public is the default.
11. Changes
If we change how we use your data, we will update this page, and for anything material (especially a new purpose) we will ask for fresh consent rather than quietly reusing what we hold.
12. Contact
Questions, requests, or complaints: tellus@thetalksapp.com.