Privacy Policy

Kaegora is operated by MENTHERIS SRL. This document is part of the Kaegora legal document set.

Privacy Policy Kaegora

Last updated: 24 July 2026

This Privacy Policy explains how MENTHERIS SRL, a company registered in Romania, ("Mentheris," "the Company," "we," "us," "our"), collects, uses, discloses, retains, and protects personal data in connection with the Kaegora mobile application (the "App," "the Service"), available globally on iOS and Android.

This Policy is designed to comply with the EU General Data Protection Regulation (Regulation (EU) 2016/679, "GDPR"), Romanian Law No. 190/2018, the UK GDPR and Data Protection Act 2018, the California Consumer Privacy Act as amended by the California Privacy Rights Act ("CCPA/CPRA") and other applicable U.S. state privacy laws, Brazil's Lei Geral de Proteção de Dados ("LGPD"), Canada's Personal Information Protection and Electronic Documents Act ("PIPEDA"), Singapore's Personal Data Protection Act ("PDPA"), Japan's Act on the Protection of Personal Information ("APPI"), India's Digital Personal Data Protection Act, and other comparable data protection frameworks applicable in the jurisdictions where our Users are located.

Because Kaegora is available globally through the Apple App Store and Google Play, this Policy applies uniformly to all Users, regardless of country of residence. Where the law of your country of residence provides specific rights or protections not otherwise described in this Policy, we will honor those rights to the extent legally required; Section 13 identifies rights that apply specifically depending on your place of residence. Where no specific local data protection law applies to you, we nonetheless apply the standards described in this Policy as our general practice.

UK Representative. Where required under Article 27 of the UK GDPR based on the scale and nature of our processing of UK residents' personal data, Mentheris will appoint a representative for UK data protection matters and will update this Policy accordingly. As of the date of this Policy, Mentheris has not appointed such a representative, as our processing does not currently meet the threshold requiring one.

This Policy is drafted in English. Where it is translated into any other language for convenience, the English-language version shall prevail in the event of any conflict or inconsistency.

If you do not agree with this Policy, you must not use the App.

1. Data Controller and Representative

1.1. Mentheris SRL is the data controller responsible for determining the purposes and means of processing personal data through the App, as defined under Article 4(7) GDPR.

1.2. Data Protection Contact. Mentheris has not appointed a statutory Data Protection Officer under Article 37 GDPR. Our core activities do not involve regular and systematic monitoring of data subjects on a large scale as our primary business purpose, nor do we process special categories of personal data at scale, the criteria that would trigger a mandatory DPO appointment. Privacy inquiries are handled by our designated privacy contact below. We will revisit this determination if the scale or nature of our processing changes.

Privacy contact:

MENTHERIS SRL

Email: [email protected]

1.3. Supervisory Authorities.

If you are located in the European Economic Area, you have the right to lodge a complaint with your local data protection supervisory authority. Our lead supervisory authority is the Romanian National Supervisory Authority for Personal Data Processing (Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal, "ANSPDCP"), B-dul G-ral. Gheorghe Magheru 28-30, Sector 1, Bucharest, Romania, www.dataprotection.ro.

If you are in the United Kingdom, you have the right to lodge a complaint with the Information Commissioner's Office ("ICO"), www.ico.org.uk.

If you are in any other jurisdiction, you may have the right to lodge a complaint with your local data protection or privacy authority, where one exists. Regardless of your location, we encourage you to contact us first at the address above so we can try to resolve your concern directly.

2. Scope and Roles

2.1. This Policy applies to personal data processed through the Kaegora mobile application. It does not apply to any third-party website, service, or application that may be linked from within the App, for example, external portfolio or social media links on a User's profile, academic resources linked in the Knowledge base, or files attached to a Call application (see Section 15).

2.2. For the data described in this Policy, Mentheris acts as the data controller. Certain service providers described in Section 9 (hosting, payment infrastructure, email delivery, push notifications) act as data processors on our behalf, under written data processing agreements compliant with Article 28 GDPR.

2.3. Where Apple and Google process payment data as merchants of record for in-app purchases, they act as independent controllers of that specific payment data, under their own privacy policies (Apple's and Google's respective privacy policies govern that processing). RevenueCat, which manages subscription lifecycle data (status, billing period, entitlements) across Apple's and Google's purchase systems on our behalf, acts as a data processor under a data processing agreement, and does not independently determine the purposes of processing your subscription data.

2.4. Where the App retrieves metadata (title, authors, abstract, year) from third-party academic databases such as CrossRef when you add a Knowledge base resource via a link or DOI, this is a one-way, non-personal metadata lookup; it does not involve the transmission of your personal data to that database.

3. Categories of Personal Data We Collect

We collect the following categories of personal data, depending on how you use the App:

3.1. Account Data

Email address, password (stored as a salted cryptographic hash, never in plain text), username, and account creation timestamp. Where you use Work Email Verification, a temporary, time-limited verification code is generated and processed solely for the duration of the verification attempt; this code is not retained after verification succeeds, fails, or expires.

3.2. Profile and Onboarding Data

Profile photo (mandatory); display name; headline; biography (up to 500 characters); professional domains and sub-domains; main and secondary focus areas; collaboration intent (e.g., "Actively seeking," "Open to ideas," "Not now"); availability level; "Looking For" and "I Can Contribute" selections; and, if provided, a verified work/company email address and its associated domain.

3.3. Contact Details (Segregated Storage)

Contact email (which may differ from your login email), phone number, personal website, and up to five additional messaging/social handles (e.g., LinkedIn, GitHub, Telegram, WhatsApp). These fields are logically and functionally segregated from your public profile record and are never displayed publicly under any circumstance, see Section 7.4 for the precise conditions under which they become visible to another specific user.

3.4. User-Generated Content and Communications

Calls and Call applications, including any attached images, documents, or links; Collaboration Workspace messages, agreements, and notes; Direct Messages exchanged between Pro-tier connected Users (a communication channel distinct from Collaboration Workspaces, see Terms, Section 13.2); appreciation messages; Community Feed posts (Thought, Question, Research, Experience) and associated structured fields (citations, co-author tags, poll data, tags, attached images or files); Knowledge base resources, reading lists, and academic notes; comments, reactions, reports, and quality flags.

3.5. Network and Relationship Data

Your connections with other Users, pending and expired connection requests, and the list of Users you have blocked. This data reflects your professional network on the platform and is treated with the same care as other sensitive profile information.

3.6. Behavioral and Derived Data

Application and connection request history; response times and response rate; the inputs to, and outputs of, the Trust Level, Compatibility Score, and Contributor Tier systems; views, saves, and shares of Calls and Knowledge resources; in-app search queries; feature usage and navigation events.

3.7. Device and Technical Data

Device identifier, push notification token, app version, operating system and version, coarse IP-derived information processed transiently for security and abuse-prevention purposes, and crash/diagnostic logs.

3.8. Subscription and Billing Data

Subscription status (e.g., trialing, active, cancel-scheduled, expired, canceled) and billing period dates, received from RevenueCat. Mentheris does not collect, transmit, or store your payment card number, expiry date, CVV, or other full payment credentials at any point, these are handled exclusively by Apple and Google as payment processors and merchants of record.

3.9. Notification Preferences

Your granular notification settings, which categories of notifications you have enabled or disabled, as described in Section 12.

3.10. Locally stored data (not transmitted to us)

Certain preferences, such as whether a specific conversation is muted, are stored only in local device storage and are never transmitted to or stored on our servers; we have no visibility into this data.

3.11. Data we do not collect

We do not request or knowingly process special categories of personal data under Article 9 GDPR (such as health data, racial or ethnic origin, religious beliefs, or biometric data for identification purposes). Any such information you voluntarily choose to include in free-text fields (e.g., a biography) is processed on the basis of your manifestly public disclosure of it (Article 9(2)(e) GDPR); we do not solicit or require such information and recommend you avoid including it.

The table below sets out each purpose for which we process personal data and the corresponding legal basis under Article 6 GDPR.

Purpose Data Involved Legal Basis
Account creation and authentication Account Data Performance of a contract (Art. 6(1)(b))
Onboarding and profile display Profile Data Performance of a contract (Art. 6(1)(b))
Matching and Compatibility Scoring Profile Data, Behavioral Data Performance of a contract (Art. 6(1)(b))
Trust Level / Contributor Tier calculation Behavioral Data Legitimate interest, platform trust and safety (Art. 6(1)(f))
Collaboration Workspace and messaging UGC, Contact Details Performance of a contract (Art. 6(1)(b))
Work Email Verification Account Data, Profile Data Consent (Art. 6(1)(a))
Content moderation, rate limiting, abuse prevention UGC, Behavioral Data, Device Data Legitimate interest, platform integrity and user safety (Art. 6(1)(f))
Subscription and billing management Subscription Data Performance of a contract (Art. 6(1)(b))
Security monitoring and fraud prevention Device Data, Account Data Legitimate interest (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c))
Push and email notifications Device Data, Account Data Performance of a contract / Consent, depending on notification category (Art. 6(1)(a)/(b))
Responding to legal requests As required Legal obligation (Art. 6(1)(c))
Retention of billing records Subscription Data Legal obligation (Art. 6(1)(c))
Connections, blocking, and network management Network and Relationship Data Performance of a contract (Art. 6(1)(b))
Direct Messages (Pro feature) UGC and Communications, Contact Details Performance of a contract (Art. 6(1)(b))
Processing intellectual property infringement notices Account Data, UGC Legal obligation, where applicable (Art. 6(1)(c)); legitimate interest, platform integrity (Art. 6(1)(f))
Responding to support and contact inquiries Account Data, contents of your inquiry Legitimate interest — providing customer support (Art. 6(1)(f))
Aggregate analytics and product improvement, including your private Profile Dashboard Behavioral and Derived Data Legitimate interest, service improvement (Art. 6(1)(f))

Where processing relies on legitimate interest, we have assessed that this interest is not overridden by your fundamental rights and freedoms, considering the context in which you provided the data and reasonable expectations of platform users. You may object to processing based on legitimate interest as described in Section 13.

Where processing relies on consent, you may withdraw that consent at any time via in-app Settings or by contacting us, without affecting the lawfulness of processing carried out before withdrawal.

5. Automated Decision-Making and Profiling

5.1. Kaegora calculates several automated signals: Trust Level (based on completed collaborations, appreciations received, and contributions), Compatibility Score (based on shared domains, focus areas, and stated collaboration preferences), Contributor Tier (based on Knowledge base contributions, saves received, and notes written), and other behavioral indicators such as a "Responsive Owner" badge (based on historical response rate) and a temporary "New" account visibility signal. These involve profiling within the meaning of Article 4(4) GDPR.

5.2. These processes influence the ranking and visibility of your profile, Calls, and content relative to other Users (for example, your position in the Discover feed or Calls Feed). They do not produce legal effects concerning you or similarly significantly affect you within the meaning of Article 22 GDPR: they do not determine your access to the Service, its price, or any outcome with comparable impact, and full core functionality of the App remains available to you regardless of your current scores or tier.

5.3. Automated screening of published content. Separately, newly published Calls are automatically screened for problematic patterns (for example, requests for payment from applicants, unrealistic promises, or spam), as described in the Terms and Conditions, Section 7.2. This screening may result in immediate publication, a temporary review period, or a block on publication. This process does not constitute a decision based solely on automated processing within the meaning of Article 22 GDPR: a temporary review period allows for human moderator intervention before any block becomes final, and you are always given the specific reason for a block and the ability to revise and resubmit your content.

5.4. You may view the specific, plain-language criteria underlying your current Trust Level, and the requirements to reach the next tier, directly within the App.

5.5. If you believe an automated ranking or screening outcome has materially misrepresented your standing on the platform or incorrectly blocked your content, you may contact us at [email protected] to: (a) obtain human review of the outcome; (b) express your point of view; and (c) contest the decision. We will respond to such requests within the timeframe described in Section 13.3.

6. Consequences of Not Providing Data

6.1. Certain data is required to use core features of the App. An email address, password, and username are required to create an account; a profile photo and completion of the full onboarding flow (identity information, professional domains and focus areas, collaboration intent, and a short biography, as described in Terms, Section 3.5) are required before your account becomes fully active. If you do not provide this data, you will not be able to create an account or access the Service.

6.2. Other data is optional, but the consequence of not providing it varies:

    (a) Contact details (email, phone, website, or other handles under Section 3.3) are not required to create an account or browse the App, but are required to complete the Contact Unlock stage of any collaboration (Terms, Section 9.7(b)). Without providing at least one contact method, you will not be able to fully activate a collaboration with another User.

    (b) Verified work email is entirely optional and affects only your company/institutional credibility badge and your ability to post under a company identity (Terms, Section 5), it does not limit any other functionality.

    (c) Biography and other profile fields are optional and primarily affect the quality of your Compatibility Score matches and how complete your profile appears to other Users.

6.3. If you disable some or all notification categories in Settings, you may not be promptly informed of time-sensitive events, such as a new Call application, a connection request, or a pending confirmation stage awaiting your response. This does not affect your ability to check for this activity manually within the App at any time.

7. Profile Visibility and Field-Level Privacy Controls

7.1. Visibility levels. You may configure your profile’s overall visibility to one of four levels:

Level Who can see your full profile
Public Any authenticated user on the platform, subject to the field-level toggles below
Network Only Only your accepted connections and active/past collaborators; other users see a limited preview only (avatar, name, domains, intent badge)
Link Only Hidden from Discover and search results, but accessible to anyone with your direct profile link
Private Completely hidden; you do not appear in Discover or search, and no one can view your profile

7.2. Mandatory minimum identification. Regardless of visibility setting, your name and headline are always shown to anyone able to reach your profile at all (Public, Network Only limited preview, and Link Only). This is an intentional platform policy, fully anonymous profiles are not permitted, to preserve a baseline of accountability across the platform. Under the Private setting, no one can reach your profile, and this baseline does not apply.

7.3. Granular field toggles. Where your profile is visible at all, you may separately control the visibility of: Highlights/badges, Appreciations, Responsiveness (a qualitative label, Fast / Average / Slow, shown to non-connected Users, who can never see the underlying numeric value regardless of your settings; a numeric value shown only to connected Users, if you enable it), and Availability status. The following fields remain visible whenever your profile is accessible at all: name, headline, biography, current focus, "Looking For," "I Can Contribute," and aggregate stats counts.

Your Collabs count (number of completed collaborations) is shown only when it is one or greater, new Users with zero completed collaborations show only their Trust Level, with no negative implication. Your Saved items (bookmarked Calls, posts, or resources) are visible exclusively to you and are never shown to any other User, regardless of visibility settings or connection status. If you hold a Work Email Verification company badge, it is displayed whenever your profile is visible at all, as an institutional trust signal, and is not subject to the granular toggles in this Section.

7.4. Contact details are never displayed on your public profile, under any visibility setting, at any visibility level, and regardless of connection status. Contact information is disclosed to a specific other user only inside a Collaboration Workspace, and only after both parties have completed the two-stage confirmation flow (agreement confirmation, followed by an explicit, separate contact-unlock confirmation by each party). When a collaboration is closed for any reason, previously shared contact records are deactivated at the database level, not merely hidden by a display/access-control rule, so that they cannot be returned to any client even in the event of an application logic error.

7.5. A live preview panel within Privacy Settings shows you exactly what a public visitor and a connected user currently see on your profile, updated in real time as you adjust settings. A separate “Preview Mode” lets you simulate your profile as seen by a public visitor, an unconnected authenticated user, or a connected user.

7.6. If another user has blocked you, or you have blocked them, your profile becomes completely inaccessible to that user (and vice versa), regardless of your visibility setting; this check takes precedence over all other visibility rules.

8. Collaboration Content, Messaging, and the Audit Trail

8.1. Messages exchanged within a Collaboration Workspace, together with system-generated messages recording key events (e.g., agreement confirmed, contacts unlocked, collaboration paused), form a permanent record associated with that collaboration and are retained as described in Section 11, even after the collaboration is closed, at which point the workspace becomes a read-only archive. Workspace notes and Knowledge base resources added within a Collaboration Workspace (Pro features) are treated the same way, visible to both participants for the duration of the collaboration, and retained as part of the same record.

8.2. Direct Messages. Where you use Direct Messages (a Pro-tier feature available between connected Users, distinct from Collaboration Workspace messaging, see Terms, Section 13.2), the content of those messages is stored to provide the conversation to both participants, but does not generate the permanent system-message audit trail described in Section 8.1, because Direct Messages are not tied to a formal collaboration record.

8.3. Message content (in both Collaboration Workspaces and Direct Messages) is indexed to support in-app message search across your own conversation history. This index exists solely to provide that functionality to you; it is not used to build advertising profiles (Mentheris does not display third-party advertising in the App, see Section 17).

8.4. Reported messages. If you or another User reports a specific message, the content of that message is shared with our moderation team as part of the review process described in Section 9 of the Terms and Conditions, regardless of which conversation type it originated in.

8.5. Certain conversation-level preferences (e.g., muting a conversation) are stored locally on your device only and are never transmitted to or stored on our servers.

9. Categories of Recipients and Sub-processors

We do not sell your personal data. We disclose personal data only to the following categories of recipients, each under an appropriate data processing agreement (for processors) or under their own privacy terms (for independent controllers):

Recipient Category Purpose Role
Apple Inc. / Google LLC Payment processing (merchant of record), platform distribution Independent controller (for payment data)
RevenueCat, Inc. Subscription lifecycle management across Apple/Google purchases Processor
Supabase Application hosting, database storage, edge function execution Processor
Push notification service (Apple Push Notification service / Firebase Cloud Messaging or equivalent) Delivery of push notifications Processor
Resend Delivery of password reset links, Work Email Verification codes, notification emails Processor
Sentry App performance monitoring, crash diagnostics, aggregate usage analytics Processor
CrossRef (or equivalent academic metadata service) One-way metadata lookup when you add a Knowledge resource via link/DOI Independent controller (limited, non-personal lookup)
Professional advisors (lawyers, accountants, auditors) Legal advice, financial auditing, regulatory compliance Processor / independent controller, as applicable, bound by confidentiality obligations
Competent public authorities Compliance with legal obligations, protection of rights and safety As required by law
Successor entity in a business transfer Continuity of service in the event of a merger, acquisition, or asset sale Controller, subject to equivalent privacy commitments

We maintain an internal, current register of sub-processors and will update this Policy if a new category of recipient is introduced that materially changes this table.

10. International Data Transfers

Because Kaegora serves a global user base, your personal data may be transferred to, and processed in, countries other than your country of residence, including the United States, where several of our infrastructure providers (including Supabase, RevenueCat, Resend, and Sentry) are based or maintain servers.

Where such transfers occur, we rely on one or more of the following safeguards, as applicable: (a) the EU-US Data Privacy Framework, where the recipient is a certified participant; (b) the European Commission's Standard Contractual Clauses (2021/914), where the recipient is not DPF-certified; (c) transfers to recipients located in a country subject to a valid European Commission adequacy decision; or (d) other appropriate safeguards recognized under Article 46 GDPR. You may request further information about the specific safeguard applicable to a given transfer, including the certification status of a specific provider, by contacting us at [email protected].

11. Data Retention

11.1. General principle. We retain personal data for no longer than necessary to fulfill the purposes described in this Policy, taking into account legal, accounting, and reporting requirements.

11.2. Active accounts. Data is retained for as long as your account remains active.

11.3. Account Deactivation is reversible: your profile is hidden from other users and activity is paused, but your data continues to be stored in full so the account can be restored upon your return.

11.4. Account Deletion is permanent and irreversible: it removes your profile, collaboration history, messages, and related personal data from our active production systems, generally within 30 days of your confirmed request, subject to the exceptions in 11.5. Only Account Deletion — not Deactivation — constitutes exercise of your right to erasure under Article 17 GDPR.

11.5. Notwithstanding deletion, we may retain limited data for the following periods and reasons: (a) Billing and tax records: retained for the period required by applicable Romanian and EU accounting/tax law (generally up to 10 years for financial records); (b) Shared collaboration records: where content you contributed forms part of another user’s own retained record (for example, an appreciation message you gave, or a system-message audit trail within a collaboration involving another user), such records may be retained in a form that pseudonymizes your identifying details while preserving the other party’s legitimate record; (c) Security and fraud-prevention logs: retained for a limited period (generally up to 12 months) to investigate and prevent abuse; (d) Backups: personal data may persist in encrypted backup systems for a limited residual period (generally up to 90 days) before being permanently purged, consistent with our disaster-recovery practices; (e) Legal holds: where retention is required to comply with a legal obligation, exercise or defend legal claims, or respond to a valid legal request.

11.6. Archived content is not deleted content. Content that expires from active visibility (e.g., time-limited Community Feed posts) or is automatically archived (e.g., Calls past their deadline, or content exceeding Free-tier limits following a subscription downgrade) remains stored and, where applicable, remains retrievable by its owner; it is not deleted as a result of expiration or archiving alone, and is only removed upon Account Deletion or a specific user-initiated deletion action.

11.7. Locally stored preferences (such as muted conversations) exist only on your device and are removed when you uninstall the App or clear its local storage; we hold no server-side copy of this data.

11.8. Prolonged account inactivity. Where an account remains inactive for an extended period (generally 24 months or more, without any login or activity), we may notify you before considering further action, which may include deactivation, in accordance with Terms, Section 18.1. We do not automatically delete inactive accounts without prior notice.

11.9. Direct Messages. Direct Messages (Section 8.2) are retained for as long as your account and the underlying connection remain active. Unlike Collaboration Workspace records, Direct Messages do not form part of a permanent audit trail tied to a formal collaboration, and are deleted upon Account Deletion without the pseudonymization exception described in Section 11.5(b), except where the other participant has independently reported a message under Section 11.5(e).

11.10. Content removed as a consequence of your own deletion. Where deleting your own content removes associated reactions, comments, or replies contributed by other Users (as described in Terms, Section 6.10), that associated content is deleted at the same time and is not separately retained by us.

11.11. Legal and moderation records. Intellectual property infringement notices and counter-notices (Terms, Sections 15.5-15.6), and records of quality flags submitted on Knowledge base resources (Terms, Section 12.2), are retained for as long as necessary to resolve the matter and for a reasonable period thereafter (generally up to 24 months) to address any recurrence or dispute, consistent with Section 11.5(e).

12. Your Communication Preferences

12.1. You can control which categories of notifications you receive via in-app Settings, organized by category (Collaboration, Network, Knowledge, and Other, including Messages, Weekly Digest, and My Alerts). A master "All Notifications" toggle disables all categories at once while preserving your individual category settings for when you re-enable it.

12.2. Notifications may be delivered as in-app push notifications or as email, depending on the category and your device settings. Disabling a category in Settings suppresses it across both channels, where applicable.

12.3. When you disable a notification category, notifications of that type are neither generated nor delivered to you, they are suppressed at the point of creation, not merely hidden from view. All notifications are generated exclusively by backend systems and cannot be triggered or fabricated by any client-side action.

12.4. My Alerts. If you configure Call alerts ("My Alerts") based on criteria such as domain, compensation type, duration, or keywords, these saved criteria are stored as part of your account data to power this feature and are treated as Behavioral and Derived Data under Section 3.6. You may pause or delete individual alerts at any time from the alerts management section of the App.

12.5. Certain system notifications relating to your own account activity (e.g., Trust Level upgrades, Knowledge milestones, profile-completion confirmation) are always enabled and are not individually configurable, other than through the master toggle. Transactional emails required for account security (e.g., password reset links, Work Email Verification codes) are not subject to notification preferences and will always be sent when requested, as they are necessary for the functioning of your account.

13. Your Data Protection Rights

13.1. If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with comparable data protection law, and subject to the conditions and exceptions under applicable law, you have the right to:

  • Access the personal data we hold about you (Art. 15 GDPR);
  • Rectify inaccurate or incomplete personal data (Art. 16 GDPR);
  • Erase your personal data (Art. 17 GDPR), noting the exceptions described in Section 11.5;
  • Restrict processing in certain circumstances (Art. 18 GDPR);
  • Data portability — to receive certain personal data you provided to us, in a structured, commonly used, machine-readable format, and to transmit it to another controller (Art. 20 GDPR);
  • Object to processing based on our legitimate interests, including profiling connected to such processing (Art. 21 GDPR);
  • Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of processing carried out before withdrawal;
  • Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects (Art. 22 GDPR) — see Section 5 regarding why our automated systems do not fall within this category;
  • Lodge a complaint with your local supervisory authority (see Section 1.3).

13.2. If you are a California resident, you may have additional rights under the CCPA/CPRA, including the right to know what personal information is collected, used, and disclosed; the right to delete personal information (subject to exceptions); the right to correct inaccurate personal information; and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information for cross-context behavioral advertising, so no opt-out mechanism for such sale/sharing is required. You may exercise applicable California rights using the contact details in Section 18.

13.3. If you are located in Canada, you have rights under PIPEDA, including the right to access and correct your personal information and to lodge a complaint with the Office of the Privacy Commissioner of Canada.

If you are located in Brazil, you have rights under the LGPD, including the rights of access, correction, deletion, portability, and objection described in Section 13.1, and the right to lodge a complaint with the Autoridade Nacional de Proteção de Dados ("ANPD").

If you are located in any other jurisdiction with a comparable data protection law not specifically listed here, you may have similar rights available under that law; we will honor such rights to the extent legally required. Regardless of your location, you may always contact us directly to exercise any of the rights described in Section 13.1, and we apply the same standard of response globally as a matter of policy.

13.4. To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before processing your request. We will respond within one month of receiving a verifiable request, extendable by a further two months for complex or numerous requests, in which case we will inform you of the extension and the reasons for the delay, as required by applicable law.

13.5. Most of these rights can also be exercised directly within the App: profile data can be corrected via Edit Profile; notification preferences via Settings; and your account can be deactivated or permanently deleted via Settings → Account.

14. Data Security

14.1. We implement technical and organizational measures designed to protect personal data against unauthorized access, alteration, disclosure, or destruction, including:

  • Server-side enforcement of all rate limits and validation rules (including, for example, the rate limits on Work Email Verification attempts described in Terms, Section 4.4), which cannot be bypassed by modifying or inspecting the client application;

  • Time-limited, single-use verification codes for Work Email Verification, generated and validated exclusively by backend functions, never by client-side logic;

  • Progressive protections against repeated failed login attempts, enforced both client-side and server-side;

  • Salted cryptographic hashing of passwords;

  • Encryption of data in transit;

  • Database-level access controls that restrict which records are returned to any client application based on the requesting User's identity and relationship to the data, for example, contact details are filtered out at the database query level once a collaboration is closed, rather than merely hidden by interface logic, as described in Section 7.4;

  • Automated error and security monitoring to detect and respond to technical issues or anomalies that could affect the security of your data;

  • Internal access limitations, under which Mentheris personnel and contractors may access personal data only to the extent necessary to perform their function (for example, our moderation process provides access to reported content, but not to unrelated account data).

14.2. No method of electronic transmission or storage is completely secure, and we cannot guarantee absolute security of your personal data.

14.3. Data breach notification. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, in accordance with Article 33 GDPR. Where the breach is likely to result in a high risk to your rights and freedoms, we will also notify you directly without undue delay, in accordance with Article 34 GDPR.

The App contains numerous points of contact with third-party content and services, including: links to academic and professional resources in the Knowledge base; contact details and external profile or portfolio links you or other Users add to your profiles (e.g., LinkedIn, GitHub, personal websites, or messaging handles); links and attachments included in Call applications; related resources and citations included in Community Feed posts; and tappable deep links to shared contact methods (e.g., WhatsApp, Telegram) once a collaboration's Contact Unlock stage is complete.

We are not responsible for the privacy practices or content of any third-party website, resource, or service accessed through the App, whether reached via a link you clicked, a link another User shared with you, or a deep link to a shared contact method. Accessing any such third-party destination is governed by that third party's own privacy policy and terms, not by this Policy. We encourage you to review the privacy policy of any third-party destination before providing personal data to it.

16. Children’s Privacy

16.1. Kaegora is intended solely for individuals aged 18 and over and is not directed at children. We do not knowingly collect personal data from individuals under the age of 18. If we become aware that we have collected personal data from a person under 18, we will take reasonable steps to promptly delete such data and, where applicable, suspend or delete the associated account. If you believe a child has provided us with personal data, please contact us at [email protected].

16.2. Consistent with the Terms and Conditions, Section 1.3, if we have reasonable grounds to suspect that an account belongs to a person under 18, whether through a report, a review process, or other indicators, we may investigate and, where appropriate, suspend or delete the account and associated data, independent of any external notification.

17. No Advertising

Mentheris does not display third-party advertising within the App, and we do not use your personal data to sell advertising space or to allow advertisers to target you within Kaegora. We do not sell your personal data to third parties for monetary or other valuable consideration.

18. Changes to This Privacy Policy

18.1. We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. Material changes will be communicated through an in-app notice and/or by updating the "Last updated" date at the top of this document, with reasonable advance notice where practicable. Your continued use of the App after changes take effect constitutes acknowledgment of the revised Policy. Where required by applicable law, we will seek your renewed consent for changes materially affecting processing based on consent.

18.2. This Policy is drafted in English. Where it is translated into any other language for convenience, the English-language version shall prevail in the event of any conflict or inconsistency, consistent with the Terms and Conditions, Section 21.7.

19. Contact Us

For any questions about this Privacy Policy, our data practices, or to exercise your data protection rights, please contact:

MENTHERIS SRL

Email: [email protected]