Teamur

Privacy Policy

This page is a translation provided for convenience. The legally binding text is the Russian version; in case of any discrepancy, it prevails.

The inventory below was verified against the database schema, not written from memory. If the app collects something, it is named here.

Version 1.0, effective September 1, 2026.

In short

1. Who is responsible for the data

The data controller is ИП TEAMUR, IIN 080619553955, address: г. Алматы, проспект Аль-Фараби, дом 9, the Republic of Kazakhstan.

For any question about data: help@teamurapp.com.

2. What we collect

2.1. Required at registration

Without these an account cannot be created.

DataWhy
First and last nameclassmates need to recognise you; Teamur has no anonymous profiles
Email addresssigning in, password recovery, school verification
Date of birthto confirm you are at least 14; it is not shown on your profile
School and gradefinding people nearby and verifying the school by email domain
Citysearch and project matching
Passwordstored as an irreversible hash, never in clear text

2.2. Optional - added by you

The app works without any of this.

About exam scores. We accept only the number itself and, optionally, a link to the official result page. The app does not accept or store certificate files - an IELTS test report form contains a photograph, date of birth and document number, which amounts to a child's identity document. We deliberately declined to store that for the sake of a line in a profile.

2.3. Generated as you use the app

You do not enter these, but they are recorded - which is why they are named here.

DataWhy
Your messages, connection requests, project applications and invitationsthere would be no way to deliver them
Projects you created and your membership in others' projectsthis is the substance of the app
Comments on feed poststhey are public to signed-in users
Last-activity marker (updated at most once an hour)the "active recently" label and clean-up of abandoned accounts
Which feed posts you opened and which you likedso read posts are not shown twice, and to count likes
Which users you blockedso the two of you stop seeing each other
Reports you submittedmoderation could not review them otherwise
Consents at registration: type, date and document version numberrequired by the personal data law: consent must be verifiable
Moderation decisions about your accountso they can be appealed and reviewed

2.4. Your legal guardian's data

A minor's account is created with the consent of a parent or other legal guardian, and we must be able to prove that consent was given. So at registration you provide their email address, and on the consent page they identify themselves.

Guardian's dataWhy
Email addressto send the link to the consent page and the confirmation letter
Full namewithout it, the consent record does not say who gave it
Relationship to the childmother, father, guardian, custodian or other legal representative
Date, time and method of confirmationthe law requires that receipt of consent can be confirmed
Version number and checksum of each documentproves which text the consent was given to
IP address and brief device detailsfurther evidence of the same
Withdrawal of consent, if any: date and methodthe record must show both the giving and the withdrawal

This data is used only to obtain and evidence consent. It is never shown to other users, never used for mailings, and never used for advertising - we have no advertising at all.

The mechanism is described in full in two separate documents for the guardian, available in Russian: consent to the agreement and consent to data processing.

2.5. Technical records of the authentication service

The sign-in service the app runs on (Supabase Auth) keeps its own log: time of sign-in, IP address, device and browser type. This is standard protection against password-guessing and account takeover.

We do not use these records for anything else - not for profiling, not for advertising, not for determining location. They are named here because saying "we do not collect IP addresses" would be untrue.

The same applies to crash reports: the place in the code, the app version, the device model and the OS version. They appear only when the app breaks, and serve one purpose - fixing it. Details, including what is not in them, are in section 3.

2.6. What we deliberately do not collect

Each item is a decision, not an oversight.

3. What we do not have at all

Where the app does reach out, besides our own database

There are three such requests, and only the last one relates to what happens in the app.

Checking for updates. On launch, the app asks Expo's servers whether a newer version exists. The request carries the app version, the platform and the device language. Not your name, not your account, not what you opened.

Why: so we can fix bugs without asking everyone to reinstall the app.

Crash reports. If the app crashes, a report goes to Sentry. It contains the place in the code that broke, the app version, the device model and the operating system version.

What it does not contain: your messages, your profile, the contents of your screens. We separately disabled user data collection, screen recording, and everything written to the app's internal log — because server responses could end up there. Storing IP addresses is switched off on Sentry's side.

Push notifications. To deliver a notification we pass it to Expo's servers, and they pass it to Apple or Google, depending on your phone. There is no other route: this is how both systems work.

What is passed: the device token — a string issued by the phone, which is how a notification finds your device — and the text of the notification itself.

And here is the part that matters. If the notification is about a new message, its text contains the sender's name and the beginning of the message — meaning a fragment of the conversation travels through other companies' servers. Every messenger works this way, but we think this should be stated plainly rather than buried in a table.

You can turn this off. Settings → Notifications → "Show message text". Then only the name arrives: "New message from Asel". The same screen lets you turn off message notifications entirely.

Worth knowing separately: a notification is visible on the lock screen, to anyone holding the phone. If the phone is not only yours, turn the text off.

The first two requests happen even when you are not signed in: they are about the app, not about a person. The third does not happen at all until you allow notifications.

We do not sell personal data and do not share it for advertising or marketing - neither for money nor for free.

4. Why we process data

For these purposes and no others:

  1. to let you sign in and recover access if you forget your password;
  2. to show your profile to people looking for project participants;
  3. to match projects and people by school, city, grade and skills;
  4. to deliver messages, applications and notifications;
  5. to verify your school by email address;
  6. to keep people safe: moderation, blocking, report review, protection against password-guessing;
  7. to comply with legal requirements.

5. Legal basis

The basis is consent, and it is twofold. At registration you confirm that you have read this document and the Terms of Use. Your legal guardian separately confirms consent to the processing of your data, on their own page, via a link sent by email.

The law of the Republic of Kazakhstan on Personal Data and its Protection (Article 8) permits consent to be given "in writing, through a state service, a non-state service, or by any other method allowing confirmation that consent was received". We rely on the third method: every consent is recorded with its date and the version number of the document you accepted - otherwise there would be nothing to confirm.

On parents specifically. Article 22 of the Civil Code of the Republic of Kazakhstan provides that minors aged fourteen to eighteen enter into transactions with the consent of their legal guardians. Registration is such a transaction, and it does not rest on a checkbox ticked by the young person themselves.

Therefore: until the guardian confirms consent via the link sent by email, the account is not active. You can fill in your profile; you cannot write to other people. After thirty days without confirmation the account is deleted.

The guardian may withdraw consent at any time, using the link in the confirmation letter or by writing to help@teamurapp.com. Access ends immediately; the data is deleted after seven days.

You withdraw your own consent by deleting your account in the app or writing to us.

6. Who can see your data

6.1. Other users

WhatVisible to
Name, photograph, school, grade, city, "about me", skills, interests, languages, achievements, statuseveryone signed in to the app
Projects you created and your comments in the feedeveryone signed in
Instagram and Telegramonly on an accepted connection, and only if you have not hidden them
Date of birth, email address, password, your guardian's datano user, ever
Private messagesonly the participants of that chat

A visitor who is not signed in sees only the news feed - not profiles, not projects, not messages.

One clarification about the photo. It is stored in file storage and has a direct link that opens without signing in. The link itself cannot be guessed and is only visible to those who can see the profile. But once someone has obtained and saved it, that link keeps working until the photo is replaced or the account is deleted: replacing it erases the previous file, and so does deleting the account.

6.2. Services the app runs on

They process data on our instructions and may not use it for their own purposes.

ServiceWhat it handles
Supabasedatabase, authentication, photograph storage
Resenddelivery of app emails: address confirmation, password recovery, letters to the legal guardian
Zohosupport mailboxes
Cloudflareserving this website
Expo (EAS)building the app and delivering updates - see §3
Sentrycrash reports from the app - see §3
Expo (push)delivering notifications to your phone - see §3
Apple, Googledelivering notifications to your phone: without them a notification cannot reach the device

The list changes with the app; changes are reflected here.

6.3. Public authorities

Only on a lawful request and only to the extent of that request.

7. Where data is stored

Data is stored in Supabase cloud infrastructure, whose servers are located outside the Republic of Kazakhstan.

We are obliged to say this plainly. The law of the Republic of Kazakhstan on Personal Data and its Protection (Article 12) requires that a database containing the personal data of citizens be located within Kazakhstan. That condition is not currently met.

The app is prepared for the move: first name, last name, date of birth and contacts are held in separate tables accessible only through a dedicated layer, and can be relocated without rewriting the application. The decision to relocate, and its timing, rests with the owner of the app.

We write this in the policy rather than omitting it: a gap between what is written and what is true is worse than the gap itself.

8. How long we keep data

DataRetention
Profile, achievements, projects, photographwhile the account exists
Private messageswhile the chat exists; after account deletion see below
Feed view and like recordswhile the account exists
Consent log, including the guardian's datawhile the account exists and a reasonable period after - otherwise there is nothing to prove the processing was lawful
Account that never received guardian's consent30 days, then deleted automatically
Account with consent withdrawnaccess ends immediately, deletion after 7 days
Moderation decisions and reportsuntil the case is closed, and a reasonable period after, in anonymised form
Authentication technical logper the authentication service's own retention, for a limited time

When an account is deleted, personal data is deleted immediately. A detailed and honest account of what remains and why is on the account deletion page.

9. Your rights

You may:

For anything without a button: write to help@teamurapp.com from your account's email address. A matching address is the confirmation that the account is yours - we ask for no other documents.

We respond within 15 business days at most, usually sooner. The law allows the same period for ceasing processing after consent is withdrawn.

10. How we protect data

Absolute security does not exist, and promising it would be a lie. If a breach affecting your data occurs, we will tell you.

11. Children

The app is intended for teenagers aged 14 to 18, meaning our entire audience is under 18. The product is built accordingly:

Registration below the age of 14 is not possible. If we learn that a younger child has nonetheless created an account, we will delete it.

12. Changes to this policy

We update this document as the app changes. Material changes will be announced inside the app at least 14 days in advance.

The version number and effective date are shown beneath the page title.

13. Contact

help@teamurapp.com - questions about data, deletion requests, complaints.

Reports of violations are answered within 24 hours; other enquiries within 15 business days.