1. Controller and contact
KRON Sports Network (“KRON”) is independently operated by an individual based in Türkiye. KRON services are provided through kron.social and related web/PWA applications. The sole public legal and privacy contact channel is kron@kron.social.
2. Data we collect
- Account data: email address, username, display name, profile image, profile banner, bio and favourite sport.
- User content: reactions, replies, media, polls, hashtags and reports.
- Direct messages: the content and timestamps of private messages you send between mutually following users, together with the conversation record itself (which two users it belongs to, when it started and when the last message was sent).
- Interaction data: likes, follows, echoes, views, reports and notification activity.
- Technical data: IP address, device/browser type, operating system, logs and security records. IP addresses are processed solely for security and abuse prevention; they are not used to derive or store location.
- Session and preference data: authentication session, language, theme, cookie and advertising preferences.
- Push data: device/browser subscription token if you enable notifications.
3. Purposes and legal bases
We process data to create and secure your account, provide platform features, publish content, send notifications, prevent abuse, enforce rules, improve performance, respond to lawful requests and, only where permitted, display or measure advertising. Processing may rely on performance of a contract, legal obligations, legitimate interests and consent where required. For direct messaging, delivering your message to the other participant is based on performance of the contract, while retaining reported content as moderation evidence and preventing abuse are based on legitimate interests.
4. Visibility of your content
KRON is a social platform. Your username, profile and content may be visible on the platform and on public sharing pages. You should not post personal or sensitive information in public areas.
5. Service providers and transfers
KRON may use the following categories of providers to operate the service:
- Supabase — database, storage and authentication
- Vercel — hosting, delivery and technical logs
- Google / Firebase — Google sign-in, app configuration, advertising and related technical services
- Resend — email delivery (welcome and system emails)
- Cloudflare — bot and abuse protection (sign-in verification)
- Browser, operating system and push providers — notification delivery
These providers may use infrastructure in different countries. Transfers are handled under applicable data-protection rules and provider agreements.
6. Retention
We keep account data while your account is active and retain security, transaction and legal records for a reasonable period required for their purpose. After an account-deletion request, profile and personal data are deleted or anonymised except for technical or legal exceptions. Removal from backups may take additional time.
Direct messages are ephemeral: they are deleted automatically from our active systems about 48 hours after they are sent. Copies of deleted messages remain for a further period in our daily technical backups; because only a limited number of backups is kept, those copies fall away as the backup cycle completes — at most about two weeks from sending. Separately from the messages, the conversation record itself (which two users it belongs to, when it started and when the last message was sent) is kept for as long as the conversation still contains messages, and is removed in the same automated run as the last remaining message. A conversation start date can therefore be older than 48 hours even when its messages are not.
If you report a message, a copy of that message is retained beyond this period as moderation evidence. Deleting a conversation hides it from your own view only: the other participant’s copy is unaffected, and the messages themselves are not removed any earlier than the automatic schedule described above. This is deliberate — otherwise an abusive sender could destroy the evidence the other person needs in order to report them. You can turn direct messages off entirely in Settings. Your data is encrypted in transit (HTTPS).
When someone who mutually follows a user tries to message that user while their direct messages are switched off, we keep a single content-free record of the attempt: who tried to reach whom, and when. The message text is neither delivered nor stored. Repeat attempts by the same person toward the same user do not create additional records, so the number of attempts is not held anywhere. The recipient is only shown that someone tried to reach them — not who, not how many times, and not exactly when. These records are deleted after 30 days, a separate and independent retention period from the direct-message periods described above. Legal basis: our legitimate interest in letting users with messaging switched off learn that someone wanted to reach them, and in preventing abuse.
7. Your rights
Depending on applicable law, you may have rights to learn whether your data is processed, request information or a copy, correct data, request deletion or restriction, object to certain processing, withdraw consent and complain to a competent authority.
Send your request from the email associated with your account, with sufficient detail, to kron@kron.social. We may request additional information to verify your identity.
8. Account deletion
You can delete your account through Settings. If you cannot access the account, email kron@kron.social and include your username.
9. Children
KRON is not directed to children under 13. Users under 18 should use KRON with parent or guardian permission where required by local law. If we learn that data belongs to a child under 13, we will take steps to remove the account and data.
10. Security and incident notices
We apply reasonable technical and organisational safeguards, but no online system can guarantee absolute security. Report suspected account or security issues promptly to kron@kron.social.
11. Changes
We may update this policy as the service or law changes. Material updates will be communicated through the platform or another appropriate channel. The date above identifies the current version.