Privacy Policy
This page is a translation provided for convenience. The legally binding text is the Russian version; in case of any discrepancy, it prevails.
The inventory below was verified against the database schema, not written from memory. If the app collects something, it is named here.
Version 1.0, effective September 1, 2026.
In short
- We collect what you put into your profile, plus the minimum technical records the app cannot work without.
- We have no advertising, no trackers and no third-party analytics - none at all.
- We deliberately do not collect phone numbers, location, or scans of documents.
- Data is not sold and is not shared with anyone beyond the services the app runs on.
- Your account and data can be deleted from inside the app at any time.
1. Who is responsible for the data
The data controller is ИП TEAMUR, IIN 080619553955, address: г. Алматы, проспект Аль-Фараби, дом 9, the Republic of Kazakhstan.
For any question about data: help@teamurapp.com.
2. What we collect
2.1. Required at registration
Without these an account cannot be created.
| Data | Why |
|---|---|
| First and last name | classmates need to recognise you; Teamur has no anonymous profiles |
| Email address | signing in, password recovery, school verification |
| Date of birth | to confirm you are at least 14; it is not shown on your profile |
| School and grade | finding people nearby and verifying the school by email domain |
| City | search and project matching |
| Password | stored as an irreversible hash, never in clear text |
2.2. Optional - added by you
The app works without any of this.
- profile photograph;
- "about me" text, skills and notes on them, interests, languages;
- achievements: exam scores (IELTS, TOEFL, SAT, Duolingo) with the date taken and, if you wish, a link to official verification; olympiads with subject, level, year and placement; experience and projects with description, role, period and a link;
- Instagram and Telegram links - visible only to people you have an accepted connection with, and each can be hidden separately.
About exam scores. We accept only the number itself and, optionally, a link to the official result page. The app does not accept or store certificate files - an IELTS test report form contains a photograph, date of birth and document number, which amounts to a child's identity document. We deliberately declined to store that for the sake of a line in a profile.
2.3. Generated as you use the app
You do not enter these, but they are recorded - which is why they are named here.
| Data | Why |
|---|---|
| Your messages, connection requests, project applications and invitations | there would be no way to deliver them |
| Projects you created and your membership in others' projects | this is the substance of the app |
| Comments on feed posts | they are public to signed-in users |
| Last-activity marker (updated at most once an hour) | the "active recently" label and clean-up of abandoned accounts |
| Which feed posts you opened and which you liked | so read posts are not shown twice, and to count likes |
| Which users you blocked | so the two of you stop seeing each other |
| Reports you submitted | moderation could not review them otherwise |
| Consents at registration: type, date and document version number | required by the personal data law: consent must be verifiable |
| Moderation decisions about your account | so they can be appealed and reviewed |
2.4. Your legal guardian's data
A minor's account is created with the consent of a parent or other legal guardian, and we must be able to prove that consent was given. So at registration you provide their email address, and on the consent page they identify themselves.
| Guardian's data | Why |
|---|---|
| Email address | to send the link to the consent page and the confirmation letter |
| Full name | without it, the consent record does not say who gave it |
| Relationship to the child | mother, father, guardian, custodian or other legal representative |
| Date, time and method of confirmation | the law requires that receipt of consent can be confirmed |
| Version number and checksum of each document | proves which text the consent was given to |
| IP address and brief device details | further evidence of the same |
| Withdrawal of consent, if any: date and method | the record must show both the giving and the withdrawal |
This data is used only to obtain and evidence consent. It is never shown to other users, never used for mailings, and never used for advertising - we have no advertising at all.
The mechanism is described in full in two separate documents for the guardian, available in Russian: consent to the agreement and consent to data processing.
2.5. Technical records of the authentication service
The sign-in service the app runs on (Supabase Auth) keeps its own log: time of sign-in, IP address, device and browser type. This is standard protection against password-guessing and account takeover.
We do not use these records for anything else - not for profiling, not for advertising, not for determining location. They are named here because saying "we do not collect IP addresses" would be untrue.
The same applies to crash reports: the place in the code, the app version, the device model and the OS version. They appear only when the app breaks, and serve one purpose - fixing it. Details, including what is not in them, are in section 3.
2.6. What we deliberately do not collect
Each item is a decision, not an oversight.
- phone number - the riskiest field on a platform for minors and the least useful for the purpose;
- location - the city is enough; the app never requests location permission;
- advertising device identifier - we have no advertising;
- scans and photographs of documents - certificates, school letters, identity papers;
- address book contacts, calendar, microphone, files on your device.
3. What we do not have at all
- No advertising and no ad networks.
- No third-party analytics: no Google Analytics, no Firebase, nothing of the kind.
- No trackers and no pixels.
- Fonts are bundled into the app and are not fetched over the network.
- This website contains no scripts and no cookies. You can read these pages without leaving a trace.
Where the app does reach out, besides our own database
There are three such requests, and only the last one relates to what happens in the app.
Checking for updates. On launch, the app asks Expo's servers whether a newer version exists. The request carries the app version, the platform and the device language. Not your name, not your account, not what you opened.
Why: so we can fix bugs without asking everyone to reinstall the app.
Crash reports. If the app crashes, a report goes to Sentry. It contains the place in the code that broke, the app version, the device model and the operating system version.
What it does not contain: your messages, your profile, the contents of your screens. We separately disabled user data collection, screen recording, and everything written to the app's internal log — because server responses could end up there. Storing IP addresses is switched off on Sentry's side.
Push notifications. To deliver a notification we pass it to Expo's servers, and they pass it to Apple or Google, depending on your phone. There is no other route: this is how both systems work.
What is passed: the device token — a string issued by the phone, which is how a notification finds your device — and the text of the notification itself.
And here is the part that matters. If the notification is about a new message, its text contains the sender's name and the beginning of the message — meaning a fragment of the conversation travels through other companies' servers. Every messenger works this way, but we think this should be stated plainly rather than buried in a table.
You can turn this off. Settings → Notifications → "Show message text". Then only the name arrives: "New message from Asel". The same screen lets you turn off message notifications entirely.
Worth knowing separately: a notification is visible on the lock screen, to anyone holding the phone. If the phone is not only yours, turn the text off.
The first two requests happen even when you are not signed in: they are about the app, not about a person. The third does not happen at all until you allow notifications.
We do not sell personal data and do not share it for advertising or marketing - neither for money nor for free.
4. Why we process data
For these purposes and no others:
- to let you sign in and recover access if you forget your password;
- to show your profile to people looking for project participants;
- to match projects and people by school, city, grade and skills;
- to deliver messages, applications and notifications;
- to verify your school by email address;
- to keep people safe: moderation, blocking, report review, protection against password-guessing;
- to comply with legal requirements.
5. Legal basis
The basis is consent, and it is twofold. At registration you confirm that you have read this document and the Terms of Use. Your legal guardian separately confirms consent to the processing of your data, on their own page, via a link sent by email.
The law of the Republic of Kazakhstan on Personal Data and its Protection (Article 8) permits consent to be given "in writing, through a state service, a non-state service, or by any other method allowing confirmation that consent was received". We rely on the third method: every consent is recorded with its date and the version number of the document you accepted - otherwise there would be nothing to confirm.
On parents specifically. Article 22 of the Civil Code of the Republic of Kazakhstan provides that minors aged fourteen to eighteen enter into transactions with the consent of their legal guardians. Registration is such a transaction, and it does not rest on a checkbox ticked by the young person themselves.
Therefore: until the guardian confirms consent via the link sent by email, the account is not active. You can fill in your profile; you cannot write to other people. After thirty days without confirmation the account is deleted.
The guardian may withdraw consent at any time, using the link in the confirmation letter or by writing to help@teamurapp.com. Access ends immediately; the data is deleted after seven days.
You withdraw your own consent by deleting your account in the app or writing to us.
6. Who can see your data
6.1. Other users
| What | Visible to |
|---|---|
| Name, photograph, school, grade, city, "about me", skills, interests, languages, achievements, status | everyone signed in to the app |
| Projects you created and your comments in the feed | everyone signed in |
| Instagram and Telegram | only on an accepted connection, and only if you have not hidden them |
| Date of birth, email address, password, your guardian's data | no user, ever |
| Private messages | only the participants of that chat |
A visitor who is not signed in sees only the news feed - not profiles, not projects, not messages.
One clarification about the photo. It is stored in file storage and has a direct link that opens without signing in. The link itself cannot be guessed and is only visible to those who can see the profile. But once someone has obtained and saved it, that link keeps working until the photo is replaced or the account is deleted: replacing it erases the previous file, and so does deleting the account.
6.2. Services the app runs on
They process data on our instructions and may not use it for their own purposes.
| Service | What it handles |
|---|---|
| Supabase | database, authentication, photograph storage |
| Resend | delivery of app emails: address confirmation, password recovery, letters to the legal guardian |
| Zoho | support mailboxes |
| Cloudflare | serving this website |
| Expo (EAS) | building the app and delivering updates - see §3 |
| Sentry | crash reports from the app - see §3 |
| Expo (push) | delivering notifications to your phone - see §3 |
| Apple, Google | delivering notifications to your phone: without them a notification cannot reach the device |
The list changes with the app; changes are reflected here.
6.3. Public authorities
Only on a lawful request and only to the extent of that request.
7. Where data is stored
Data is stored in Supabase cloud infrastructure, whose servers are located outside the Republic of Kazakhstan.
We are obliged to say this plainly. The law of the Republic of Kazakhstan on Personal Data and its Protection (Article 12) requires that a database containing the personal data of citizens be located within Kazakhstan. That condition is not currently met.
The app is prepared for the move: first name, last name, date of birth and contacts are held in separate tables accessible only through a dedicated layer, and can be relocated without rewriting the application. The decision to relocate, and its timing, rests with the owner of the app.
We write this in the policy rather than omitting it: a gap between what is written and what is true is worse than the gap itself.
8. How long we keep data
| Data | Retention |
|---|---|
| Profile, achievements, projects, photograph | while the account exists |
| Private messages | while the chat exists; after account deletion see below |
| Feed view and like records | while the account exists |
| Consent log, including the guardian's data | while the account exists and a reasonable period after - otherwise there is nothing to prove the processing was lawful |
| Account that never received guardian's consent | 30 days, then deleted automatically |
| Account with consent withdrawn | access ends immediately, deletion after 7 days |
| Moderation decisions and reports | until the case is closed, and a reasonable period after, in anonymised form |
| Authentication technical log | per the authentication service's own retention, for a limited time |
When an account is deleted, personal data is deleted immediately. A detailed and honest account of what remains and why is on the account deletion page.
9. Your rights
You may:
- see what data we hold about you - most of it is visible in your profile and settings;
- correct it - the profile is editable in the app;
- delete your account and data - in settings, in a few taps, without contacting us;
- withdraw consent to processing;
- complain about how we handle your data.
For anything without a button: write to help@teamurapp.com from your account's email address. A matching address is the confirmation that the account is yours - we ask for no other documents.
We respond within 15 business days at most, usually sooner. The law allows the same period for ceasing processing after consent is withdrawn.
10. How we protect data
- The connection to the server is always encrypted (HTTPS/TLS).
- Passwords are stored as irreversible hashes - we do not know them and cannot recover them, only reset them.
- Access to every row of data is restricted at the database level, not only in the app: even a request bypassing the interface will not reveal another person's data.
- Service fields (role, verification status, suspension period) are separately write-protected - a user cannot change them on their own record.
- Permissions are checked by an automated test suite before every change to the database.
Absolute security does not exist, and promising it would be a lie. If a breach affecting your data occurs, we will tell you.
11. Children
The app is intended for teenagers aged 14 to 18, meaning our entire audience is under 18. The product is built accordingly:
- the account does not work until a legal guardian has confirmed consent;
- private messaging is possible only after mutual consent from both sides;
- there are no random or anonymous chats: name and school are always visible;
- profiles are not visible to anyone who is not signed in;
- contacts outside the app are revealed only on an accepted connection;
- child sexual abuse and exploitation are prohibited by a separate document, and it is the only violation for which an account is removed without review.
Registration below the age of 14 is not possible. If we learn that a younger child has nonetheless created an account, we will delete it.
12. Changes to this policy
We update this document as the app changes. Material changes will be announced inside the app at least 14 days in advance.
The version number and effective date are shown beneath the page title.
13. Contact
help@teamurapp.com - questions about data, deletion requests, complaints.
Reports of violations are answered within 24 hours; other enquiries within 15 business days.