Skip to main content

Legal & Privacy

Privacy Policy

How KF.Social collects, uses, and protects your personal data

Effective

12 July 2026

Version

Version 3.0

Platform

KF.Social

Controller

KaneFilous Limited

This Privacy Policy explains how KaneFilous Limited, as the data controller, collects, uses, shares, and protects your personal data when you use KF.Social. KF.Social is a social app for making friends and meeting people, with a feed, private messaging, interest communities, and in-person meetups. This policy is written to comply with the EU General Data Protection Regulation (GDPR).

1. About This Policy

This Privacy Policy applies to the website kf.social and the KF.Social apps for iOS, Android, and the web (together, the "Service"). It describes what personal data we collect, why we collect it, the lawful basis on which we process it, who we share it with, and your rights.

KaneFilous Limited is the data controller responsible for your personal data. If you have any questions about this policy or our data practices, you can contact us at privacy@kf.social.

2. Data Controller

The data controller for your personal data is KaneFilous Limited, a company registered in Ireland, which operates KF.Social. You can reach our privacy team at privacy@kf.social. Live location sharing, identity verification, and dietary information involve more sensitive data and are covered separately in Sections 4 and 5.

3. What Data We Collect and Why

We collect different types of personal data depending on how you use the Service. Each category below sets out what we collect, the purpose, and our lawful basis for processing under GDPR. Special category data, meaning biometric identity-verification data and the dietary and allergy information you can provide for Dinners, is covered separately in Section 5, and live location sharing in Section 4.

Account and identity

We collect your name or display name, email address, and profile details such as your photo and bio. When you sign up, you confirm you are at least 16. Lawful basis: performance of our contract with you to provide your account, and our legitimate interests in operating a safe service.

Sign-in providers

You can sign in with an email one-time passcode, Sign in with Apple (including Hide My Email, where Apple gives us a private relay address rather than your real email), Google Sign-In, or a passkey. We process the identifiers these methods return so we can authenticate you. Some links we send include a secure magic-link token that signs you in. Lawful basis: performance of our contract with you.

Content you create

We process the posts, comments, reactions, hashtags, mentions, and stories you share on the feed, and your direct messages, including text, voice notes, photos and video, and disappearing messages. We handle metadata for voice and video calls (such as who called whom and call duration) to connect and deliver calls; call audio and video are not recorded by us. We also process media you upload and the visibility level you choose for your content. Lawful basis: performance of our contract with you.

Gems communities

When you join or are invited to a Gem (an interest community), we process your membership, community posts, and community chat, and, where you use them, short-code invite links. Lawful basis: performance of our contract with you.

Dinners and in-person events

When you host or join a Dinner, we process your event participation, join and cancellation status, and the venue details shared with confirmed guests. If you provide dietary or allergy information for a Dinner, it is special category data and is handled as described in Section 5. Lawful basis: performance of our contract with you.

Bookings and payments

When you book a seat at a Dinner we record the booking and the Matching Fee. Payment is processed by Stripe: your card details are entered directly into Stripe's payment interface on your device and never touch our systems. We store only the Stripe payment reference, the amounts and currency, and the refund status. We do not create a Stripe customer profile for you and we do not store your billing address. Lawful basis: performance of our contract with you, and our legal obligations to keep financial records.

Device, notifications, and technical data

We process device and push notification tokens, app version, and basic technical logs needed to deliver notifications, keep the Service secure, and diagnose problems. Lawful basis: performance of our contract with you and our legitimate interests in security and reliability.

Usage and analytics

We use PostHog (EU-hosted) for product analytics to understand how the Service is used and to improve it. IP addresses are anonymised and we scrub personal identifiers on the client before events are sent. We do not sell your personal data. This is described in Section 7. Lawful basis: our legitimate interests in maintaining and improving the Service, and, for cookie storage and marketing pixels on the web, your consent.

Communications

We send transactional emails and push notifications (such as sign-in codes, reminders, and safety messages) and, if you opt in, optional marketing. Lawful basis: performance of our contract for transactional messages, and your consent for marketing.

Safety and reports

If you report content or a person, or block someone, we process that report, block, and moderation data to keep the Service safe. Lawful basis: our legitimate interests in running a safe service and complying with our legal obligations, including under the Digital Services Act.

4. Live Location Sharing in Chat

You can choose to share your live, precise location inside a direct message. This is always started by you: it is off by default, you pick who you share with, and you can stop sharing at any time. We process your precise location only while a sharing session is active, to show it to the people you chose in that chat.

Lawful basis: your consent, which you give by starting a location share and can withdraw at any time by stopping it. Live location data is retained only for as long as needed to deliver the active share and is not used to build a location history or for advertising.

5. Special Category Data: Identity Verification and Dietary Information

Two kinds of data we process are special category data under GDPR Article 9: the biometric data used for optional identity verification, and the dietary and allergy information you can provide for Dinners, which can reveal health or religious details. We process both only with your explicit consent (Article 9(2)(a)).

5.1 Identity verification (biometric data)

Identity verification is optional. If you opt in, we process:

  • Your government identity document and the data read from it, including its machine-readable zone (MRZ), such as your name, date of birth, document number, and expiry date
  • A selfie with a liveness check, from which biometric features are derived to confirm that the document belongs to you

We use this data only to verify your identity and, if successful, to add a verified badge to your profile. We run checks for uniqueness (to prevent one identity being used for multiple accounts) and name-binding and expiry (to confirm the document is valid and matches your account). Some verifications are handled through a manual review lane by trained KF staff.

Retention. Once a verification decision is made, we delete the identity document image and the biometric data derived from your selfie. We keep only the minimal record needed to show that your account is verified and to support the uniqueness check. You can withdraw consent at any time; withdrawing does not affect processing carried out before withdrawal.

Lawful basis: your explicit consent (Article 9(2)(a)) for the biometric processing, and our legitimate interests in preventing fraud and duplicate accounts for the underlying identity check.

5.2 Dietary and allergy information for Dinners

Providing dietary or allergy information for a Dinner is entirely optional. Because it can reveal details about your health or religious beliefs, we treat it as special category data and process it only with your explicit consent.

  • The information you provide is stored as a snapshot on the booking it relates to and is used only to plan that dinner.
  • It is never shared with venues or with other guests. At the venue, everyone orders for themselves.
  • You can view, edit, or delete this information, and you can withdraw your consent at any time. Withdrawing consent does not affect processing carried out before withdrawal, but it may mean we are less able to plan around a specific requirement.

Lawful basis: your explicit consent (Article 9(2)(a)).

6. Cookies and Similar Technologies

On the web we use cookies and similar technologies, grouped into the categories offered by our cookie banner:

  • Strictly necessary: these keep you signed in, remember your preferences, and record your cookie choices. They are always on because the site cannot work properly without them, and they do not require consent.
  • Analytics: product analytics through PostHog. By default, analytics runs in a cookieless baseline mode that does not store an identifier on your device. Only if you accept optional cookies does analytics switch to a persistent mode that stores an identifier for cross-visit measurement.
  • Marketing: where we run marketing pixels on our website (currently Meta, TikTok, and Reddit), they load only after you accept optional cookies, and share limited event data with those platforms so we can measure our own campaigns. See Section 7.

Only strictly necessary cookies are set without your consent. Analytics persistence and marketing pixels load only after you accept them in the cookie banner, and you can decline or withdraw your consent at any time through the banner or your browser settings. The mobile apps store session tokens securely on your device (for example, in the iOS Keychain or the Android Keystore) and cache some content for performance; the marketing pixels described in Section 7 run on our website only and are not part of the in-app experience.

7. Analytics and Marketing Measurement

We use PostHog for product analytics, hosted in the EU at eu.posthog.com. IP addresses are anonymised, and we scrub personal identifiers on the client before events are sent. A cookieless baseline mode runs without storing an identifier on your device; a persistent mode that stores an identifier is used only after you accept optional cookies on the web. We do not show advertising inside KF.Social, and we do not sell your personal data.

On our website, and with your consent, we may run marketing pixels from advertising platforms (currently Meta, TikTok, and Reddit) to measure conversions from our own marketing campaigns, such as visits and sign-ups. These set cookies and send limited event data to those platforms. They load only after you accept optional cookies via the cookie banner, and you can decline or withdraw consent at any time.

Lawful basis: our legitimate interests in understanding and improving the Service for baseline analytics, and your consent under GDPR Article 6(1)(a) and EU ePrivacy rules for cookie storage and marketing pixels.

8. Communications

We send transactional emails and push notifications that are necessary to provide the Service, such as sign-in codes, activity you have asked to be notified about, and safety messages. You can control push notifications in your device settings.

With your consent, we also send optional marketing from our kf.social domain about KF.Social. You can withdraw that consent at any time using the unsubscribe link in any marketing email or in Settings. We do not sell or share your contact details for third-party marketing.

9. Who We Share Data With

We share personal data only with the processors and partners we need to run the Service, and only for the purposes described. We do not sell your personal data.

Recipient Purpose
Amazon Web Services (AWS) Cloud hosting, data storage, and content delivery. Data is hosted in the EU (Frankfurt, eu-central-1).
Stripe Processing Matching Fee payments for Dinner bookings. Card details are entered directly into Stripe's payment interface and never touch our systems; we store only the payment reference, amounts, currency, and refund status.
PostHog (EU) Product analytics, EU-hosted, with IP anonymisation and client-side scrubbing of identifiers.
Apple and Google Sign-in (Sign in with Apple, Google Sign-In), push notification delivery, and app subscriptions and in-app purchases (Premium and Super Waves).
Sentry Error and crash monitoring to keep the Service reliable. Personal data is scrubbed before events are sent.
Meta, TikTok, and Reddit Website marketing pixels that, with your consent, share limited event data so we can measure conversions from our own campaigns. See Section 7.

We may also disclose personal data where required by law, to enforce our terms, or to protect the rights, safety, and security of our users, the public, or KaneFilous Limited.

10. International Data Transfers

Your personal data is primarily stored and processed in the European Union. Some providers, such as Stripe (payments), Apple and Google (sign-in, push, and in-app purchases), and the marketing-pixel partners described above, may process data outside the European Economic Area (for example, in the United States). Where personal data is transferred outside the EEA, we rely on appropriate safeguards, including the EU Standard Contractual Clauses (SCCs) and, where applicable, an adequacy decision or certification under the EU-US Data Privacy Framework.

11. Data Retention and Account Deletion

We keep your personal data only for as long as necessary for the purposes set out in this policy, or as required by law. In general:

  • Account and content data is kept while your account is active.
  • Identity-verification documents and biometric data are deleted after a verification decision, as described in Section 5.
  • Live location data is kept only for the duration of an active sharing session (Section 4).
  • Dietary and allergy information is stored as a snapshot on the booking it relates to, can be deleted by you at any time, and is deleted with your account (Section 5).
  • Payment and purchase records, including Stripe payment references for Matching Fees and Premium or Super Waves purchases, are retained as required to meet our financial, tax, and legal obligations.
  • Analytics data is retained in line with our provider settings and our minimisation practices.

Account deletion. You can delete your account at any time from within the app. Deletion is carried out by a scheduled deletion pipeline: your request is queued and your personal data is deleted or anonymised, normally within 30 days, except where we are required to retain certain records by law. Content you shared with other people may remain visible to them, and residual copies in backups age out over our normal backup cycle.

12. Your Rights

Under GDPR, you have the following rights regarding your personal data:

  • Right of access: request a copy of the personal data we hold about you
  • Right to rectification: request correction of inaccurate or incomplete data
  • Right to erasure: request deletion of your personal data
  • Right to data portability: request your data in a structured, commonly used, machine-readable format
  • Right to restriction: request that we limit how we process your data
  • Right to object: object to processing based on our legitimate interests
  • Right to withdraw consent: where processing is based on consent (including identity verification, dietary information, live location, marketing, and cookies), withdraw it at any time without affecting prior processing

You can exercise many of these rights directly in Settings, including editing your profile and deleting your account. For anything else, contact us at privacy@kf.social.

Complaints

You can complain to our lead supervisory authority, the Irish Data Protection Commission (DPC), at www.dataprotection.ie, if you are unhappy with how we handle your data. If you are elsewhere in the EU, you may also complain to your local data protection authority. We would welcome the chance to address your concerns first, so please consider contacting us before you do.

13. Profiles, Search and Content Visibility

KF.Social includes social features such as profiles, posts, and communities. Some profile information, such as your display name and photo, is visible to other people so they can recognise you.

To help people find each other, profiles are indexed for profile discovery and search within the Service. You control the visibility of your posts using the visibility level you set for each one:

  • Public: visible to other people on the Service
  • Friends: visible only to people you are connected with
  • Private: visible only to you

Reports, blocks, identity-verification data, and dietary information are never shown to other people.

14. Security

We use appropriate technical and organisational measures to protect your personal data, including encryption in transit, secure storage of credentials on your device (the iOS Keychain and Android Keystore), restricted internal access, error monitoring with personal data scrubbed, and payment handling by Stripe so that card details never touch our systems. No system can be guaranteed completely secure, but we work to protect your data and to respond promptly to any incident.

15. Children

You must be at least 16 to use KF.Social, and you must be at least 18 to host or attend an in-person Dinner. The Service is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has provided us with personal data, please contact us at privacy@kf.social and we will take steps to delete it.

16. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will let you know by email or through the Service. The effective date shown at the top of this page tells you when the current version took effect.


17. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, you can reach us through the following channels:

  • Privacy enquiries: privacy@kf.social
  • Data controller: KaneFilous Limited, 71 Lower Baggot Street, Dublin, D02 P593, Ireland
  • Lead supervisory authority: Irish Data Protection Commission, www.dataprotection.ie

Version 3.0. Effective 12 July 2026. KF.Social is operated by KaneFilous Limited, a company registered in Ireland.

KF.Social
Go for dinner. Leave with friends.
Get the app