English
1. Scope and operator
Shoorkum is responsible for the processing described here when it determines why and how personal information is used. This Notice covers the apps, website, community, support, and related services.
Shoorkum’s privacy contact is reachable through shoorkum.com/support or in-app Help & Safety. We may verify control of the account before acting.
2. Information we process
- Account and authentication: email, Supabase user ID, authentication method, confirmation state, session tokens, account creation or last-sign-in information, and the minimal identity metadata supplied to Supabase Auth by a chosen provider. Google normally supplies a provider subject, name, and profile-photo URL with its required basic profile scope; Shoorkum does not use that name or photo as your public community identity. Email and provider profile metadata are not displayed on posts, comments, profiles, or leaderboards.
- Profile and preferences: nickname, avatar seed, language, followed categories, notification choices, voice, theme, app-lock preference, automatic-story-translation choice, privacy settings, and outcome-reminder preference.
- Age and country assurance: declared country and birth date, derived age band, assurance status and expiry, guardian-consent status where applicable, and a one-way reference. In private-beta self-declaration, raw birth date is transmitted once to derive the band and is not stored in Shoorkum’s database.
- Content and activity: posts, tags, polls, comments, replies, debate sides, votes, helpful reactions, saves, outcomes, reports, blocks, moderation status, reputation, levels, leaderboard results, and timestamps.
- Safety and support: report reasons, appeals, support messages, moderation decisions, limited audit events, deletion requests, abuse evidence, and valid legal-preservation records.
- Technical and operational: IP and network metadata received by hosting or security providers, app/browser/device type, operating system, request time, error and security logs, rate-limit counters, notification tokens, and usage counts. Shoorkum does not request precise GPS location for country context.
- Device-local: drafts, saved/feed caches, generated narration cache, app-lock or PIN material, and session material. Native sessions use secure device storage where supported; other offline content may use ordinary app storage. Browser storage is controlled by the browser.
3. How information is collected
Information comes from you, your Service interactions, automated safety and security systems, other users who report or interact, authentication and infrastructure providers, and age/country or guardian-assurance providers if enabled.
Do not submit another person’s personal information unless necessary, lawful, and appropriately anonymized. Public posts must not contain contact details or readily identifying facts.
4. Why we use it and legal grounds
- Create, authenticate, recover, secure, and administer accounts.
- Provide feeds, posts, comments, debates, voting, reputation, leaderboards, saves, notifications, outcomes, translation, narration, privacy tools, and country-context indicators.
- Apply age-appropriate and country-aware access rules and guardian controls.
- Detect contact sharing, abuse, exploitation, self-harm risk, threats, unlawful material, manipulation, spam, fraud, and attacks.
- Review reports and appeals, enforce rules, correct reputation, and preserve evidence lawfully.
- Measure reliability, control provider costs, diagnose errors, prevent duplicate operations, and improve accessibility and performance.
- Send service, security, policy, account, and support communications.
- Meet valid legal obligations and protect users, Shoorkum, and the public.
Depending on applicable law, processing relies on performance of the user agreement, legitimate interests in operating and protecting the Service, consent where required, vital interests in a genuine emergency, and legal obligations. Required consent may be withdrawn prospectively; prior lawful processing or another legal basis may continue.
5. Public visibility and anonymity
Dilemma aliases conceal the ordinary profile from the community; adviser nicknames and reputation are persistent. The backend associates activity with an internal account for safety, integrity, deletion, and legal compliance. Readers may infer identity from writing style, facts, screenshots, quotations, or information the author supplies.
“From your country” is a viewer-specific match signal. It does not display or make the country searchable or include the author’s jurisdiction in the post response, and is omitted when the applicable privacy mode disables it.
6. Automated processing and AI-enabled services
Posts, comments, replies, debate arguments, tags, and poll labels may be screened by automated rules and Supabase built-in AI safety signals. Microsoft Azure Content Safety may also be used when enabled. Systems may assign an audience, stop publication, reduce distribution, or flag material. Automation can be wrong; eligible decisions may be appealed.
Automatic story translation is on by default. When it is on and a community story differs from the selected app language, the story title, body, and poll labels needed for display may be sent to Microsoft Azure Translator. Shoorkum does not add the public alias, adviser name, tags, or hashtags to that automatic request; a name written inside the story text still travels as part of that text. Turning the setting off stops automatic provider requests and keeps the original text available. Comments, replies, and debate arguments are translated only when you press their Translate control. Fixed Shoorkum editorial prompts use bundled translations on the device and remain bilingual even when automatic translation is off. A manual Translate request sends the selected content to Azure Translator.
If you request a named cloud voice, selected text may go to ElevenLabs to generate audio. Generated audio may remain in a private shared cache for up to 30 days so identical narration does not repeatedly consume provider resources; its index contains a one-way content hash rather than source text. Privacy scanning and rewriting may process submitted text inside Shoorkum’s server environment. Usage counters keep counts and character totals, not source text or translations.
Automated systems do not issue fatwas, decide religious correctness, or replace qualified professional review. Shoorkum does not use sensitive public dilemmas to train a general-purpose model controlled by Shoorkum. Provider handling remains subject to provider terms and configured retention controls.
7. Providers and disclosures
- Supabase: authentication, database, realtime, server functions, backend security, and built-in AI safety signals.
- Vercel: website hosting, delivery, and technical logs.
- Resend: account/service email and delivery status.
- Microsoft Azure: content-safety screening and translation when enabled.
- ElevenLabs: cloud narration when a named cloud voice is selected.
- Apple and Google: optional account authentication and the minimal identity metadata their sign-in systems supply. Shoorkum asks Apple only for the email scope; Google requires basic email and profile scopes.
- Device systems and notification infrastructure: app distribution, device capability, and delivery where used.
Providers may process data outside your country and are instructed or configured for service delivery and security. Shoorkum may disclose information to competent authorities, courts, emergency services, or safety organizations when valid law requires it, or when a good-faith assessment finds disclosure legally permitted and necessary for an imminent threat, child exploitation, or serious abuse.
Shoorkum does not sell personal information or use it for cross-context behavioral advertising. If that changes, this Notice will be updated and legally required choice provided first.
8. International transfers
Providers may operate globally, so information can be processed outside your country. If applicable law requires a transfer mechanism, assessment, contractual safeguards, local hosting, or regulator approval, Shoorkum will use the required measure before relying on that transfer. This Notice does not override mandatory localization or transfer restrictions.
9. Retention periods
- Active account, authentication, profile, preferences, and current compliance records: while active; deletion from active systems within 30 days after a completed deletion request unless an exception below applies.
- Private-beta raw birth date: used in request memory for no more than 10 minutes and not stored in Shoorkum’s database. A Google/Apple preflight stores only keyed token, network, and birth-date references plus derived country and age band; the token expires after 10 minutes and expired preflights are regularly deleted. Derived account band, country, one-way assurance reference, and history: current assurance no more than 31 days; associated safety/audit records up to 24 months.
- Published posts and comments: until withdrawn, auto-hidden, removed, or account deletion. Withdrawn/auto-hidden source and account link up to 90 days for recovery, integrity, and abuse investigation. Content tied to a report, appeal, suspension, threat, exploitation concern, or dispute up to 24 months after closure.
- Votes, reactions, blocks, outcomes, reputation, and server saves: while needed for an active account or community integrity; removed or de-linked within 30 days after completed deletion unless tied to a retained safety matter.
- Notifications: up to 180 days. Daily translation/narration counters: up to 35 days. Rate-limit and routine operational logs: up to 12 months.
- Private shared generated-narration audio: up to 30 days after the most recent access, unless removed earlier for storage, safety, deletion, or provider reasons.
- Reports, moderation audits, appeals, fraud and security evidence: up to 24 months after closure. Policy acceptance and completed deletion records: up to 7 years where reasonably needed to show compliance or resolve claims.
- Backups: inaccessible deleted data may remain in rotating encrypted or provider-controlled backups for up to 30 additional days before overwrite.
- Legal hold: specific information may remain only while a valid obligation, order, unresolved claim, or protection need requires it, with restricted access and deletion or anonymization afterward.
- Device caches and drafts: until removed in the app, cleared by the system/browser or user, or the app is uninstalled. Narration cache is designed to be bounded and purgeable, but device/browser behavior controls final removal.
10. Children and teenagers
Shoorkum applies country-aware age bands and feature limits. A young person may use an account only when the Service says the age/country combination is eligible and required guardian steps are complete. Users below the permitted minimum must not create an account.
Teen safeguards may restrict public profiles, mentions, contact sharing, mature content, purchases, payouts, visibility, or other features. Basic safety cannot be removed by payment or guardian choice. A guardian may contact support about an eligible minor, but Shoorkum must verify authority and consider the young person’s rights before disclosure.
11. Your privacy rights
Depending on law, you may request access, correction, deletion, restriction, objection, portability, withdrawal of consent, or review of a significant automated decision, and complain to a competent privacy or consumer authority. Rights are not absolute; Shoorkum may preserve information or decline a request under a lawful exception and explain where permitted.
Submit requests through support or Help & Safety with the account nickname and enough detail, but never a password, one-time code, unnecessary identity document, or another person’s private information. We may verify account control. We aim to respond in the legally required period or, if none is specified, within 30 days.
12. Choices, storage, and controls
- Use generated aliases and remove identifying facts.
- Disable country context where the posting control is available.
- Use app lock, discreet notifications, privacy scanning, auto-hide, block, report, and deletion.
- Change voice, language, notifications, reminders, theme, and available preferences.
- Turn off automatic story translation to keep community stories in their original language. Do not press a manual Translate control or request cloud narration if you do not want the selected text sent to the applicable provider. The Original control returns a translated item to its source text.
The website and apps may use essential session storage, secure tokens, local storage, and similar technologies to sign you in, remember choices, prevent abuse, and provide requested functions. Shoorkum does not currently use advertising cookies or cross-service behavioral trackers. Browser or device controls may clear local data, but disabling essential storage can prevent account features from working.
13. Security
Shoorkum uses access controls, restricted database permissions, server-held provider secrets, secure transport, session protection, rate limits, moderation controls, and device secure storage where supported. No system is absolutely secure. Public content can be copied, compromised devices can expose local data, and providers or networks can fail.
Report suspected security or privacy incidents through Help & Safety. Do not publish another person’s data or exploit a vulnerability to access data that is not yours.
14. Changes and contact
Material changes will be presented in the Service and may require renewed acknowledgment or consent where legally required. The dates above identify this version.
Privacy contact and rights requests: https://www.shoorkum.com/support or in-app Help & Safety.