Effective Date: 23 March 2026 | Last Updated: 23 March 2026
SOKI ("we", "us", or "our") operates a venue-based anonymous social chat platform accessible via the SOKI mobile application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, disclose, retain, and protect your personal information when you use our Service, and describes the rights available to you under applicable law.
This Policy applies to all users globally, with specific provisions for users in the Republic of Kenya (Kenya Data Protection Act, 2019), the European Economic Area and United Kingdom (General Data Protection Regulation — GDPR / UK GDPR), and the United States (including the California Consumer Privacy Act — CCPA/CPRA, and the Children's Online Privacy Protection Act — COPPA).
By using the Service you confirm that you have read, understood, and agree to this Privacy Policy. If you do not agree, please discontinue use of the Service.
SOKI is the data controller responsible for your personal information.
For EEA/UK users: if you are dissatisfied with our response to a privacy complaint, you have the right to lodge a complaint with your local supervisory authority. For Kenyan users, complaints may be directed to the Office of the Data Protection Commissioner (ODPC).
To enforce our Community Guidelines, we collect and process:
We process your personal data on the following legal bases:
| Processing Activity | Legal Basis |
|---|---|
| Providing the Service (account creation, messaging, RealMoments) | Performance of contract / Legitimate interests |
| Automated content moderation (AI scanning of messages, images, videos, profiles) | Legitimate interests — protecting users from harmful content; legal obligation (CSAM reporting) |
| Strike and ban enforcement | Legitimate interests — platform safety and integrity |
| Sending transactional emails (verification, account notices) | Performance of contract |
| Retaining ban history to prevent evasion | Legitimate interests — preventing circumvention of safety measures |
| Complying with CSAM reporting obligations | Legal obligation |
| Analytics and service improvement | Legitimate interests |
| Responding to legal requests | Legal obligation |
| Push notifications (with consent) | Consent |
| Location data for venue context | Performance of contract / Consent |
For Kenyan users: processing is conducted in accordance with the Kenya Data Protection Act, 2019 (DPA 2019) and associated regulations. For EEA/UK users: processing is conducted under GDPR Article 6 and, where applicable, Article 9.
RealMoments are dual-camera photo and video posts that you submit in response to venue-triggered moments. By posting a RealMoment, you acknowledge and agree to the following:
Important: If you believe a venue operator has used your RealMoment content unlawfully or in violation of these terms, please contact us immediately at privacy@soki.co.ke. We will investigate and, where appropriate, take action against the venue's access to our platform.
We do not sell your personal information. We share information only in the following circumstances:
Your username, profile emoji or photo, bio, interests, and messages are visible to other users within the same venue. Your email address is never visible to other users.
Venue operators can view RealMoments, chat activity (in aggregate), and moderation-related information relevant to their venue. They cannot access your email address, device identifiers, or payment information.
We share data with third-party processors who assist us in operating the Service, including:
All processors are bound by data processing agreements requiring them to handle your data only as directed by us and in accordance with applicable law.
We may disclose your information where required by law, court order, or governmental authority, or where we believe disclosure is necessary to:
In the event of a merger, acquisition, reorganisation, or sale of assets, your information may be transferred as part of that transaction. We will notify you via email or prominent in-app notice before your information is transferred and becomes subject to a different privacy policy.
SOKI operates a multi-layer automated content moderation system to protect users from harmful, illegal, and policy-violating content. You acknowledge and agree that:
Our automated systems classify content into severity tiers and apply proportionate enforcement actions including content removal, account muting, temporary suspension, and permanent account termination. All automated decisions are subject to appeal (see Section 10.6). We maintain human oversight at the account level — individual content decisions are automated, but account-level enforcement actions that result in muting or banning are reviewed by our moderation team.
Any content detected as child sexual abuse material (CSAM) is immediately removed, the associated account is permanently suspended, and the content and account information are reported to the relevant national authority and/or NCMEC as required by applicable law. We do not delete CSAM evidence — it is preserved for law enforcement purposes. This obligation overrides any contractual or privacy considerations.
While we invest significantly in content moderation, no automated system is perfect. We do not guarantee that all harmful content will be detected or removed. Users are encouraged to use the in-app report feature to flag content that our systems may have missed.
| Data Category | Retention Period | Reason |
|---|---|---|
| Active profile data | Until account deletion | Service provision |
| Soft-deleted profile (post-deletion) | 30 days | Compliance and dispute resolution |
| Archived deleted profile | 7 years from deletion | Legal obligation / audit trail |
| Chat messages | Rolling 90-day cleanup (group chats) | Service provision; storage management |
| Private chat messages | Until account deletion or manual deletion | Service provision |
| RealMoments content | Until deleted by user or account deletion | Service provision |
| Moderation violation records | Until account deletion, then anonymised | Platform safety |
| Email ban records (hard strikes) | Until manually lifted by admin | Preventing ban evasion |
| CSAM-related records | Indefinitely or as required by law | Legal obligation — mandatory reporting |
| Payment records (venue operators) | 7 years | Tax and accounting obligations |
| Server logs | 90 days | Security and debugging |
When you delete your account, your personal information is immediately stripped from your profile, your Firebase Authentication account is permanently deleted, and your username is released. A soft-deleted shell of your profile is retained for 30 days (without any personal data) to maintain chat history integrity for other users, after which it is archived.
SOKI is based in Kenya and uses infrastructure providers (Google Firebase, OpenAI) whose servers are located primarily in the United States. By using our Service, you acknowledge that your data may be transferred to, stored in, and processed in countries outside your country of residence, including countries that may not have the same level of data protection as your home country.
For EEA/UK users: transfers to the United States are made pursuant to appropriate safeguards including Standard Contractual Clauses (SCCs) as provided by our infrastructure partners. For Kenyan users: transfers are conducted in accordance with the requirements of the Kenya Data Protection Act, 2019, and applicable regulations on cross-border data transfers.
To exercise any of the above rights, contact us at privacy@soki.co.ke. We will respond within 30 days (or within any shorter period required by applicable law). We may require identity verification before processing your request. Requests are free of charge; we reserve the right to charge a reasonable fee for manifestly unfounded or excessive requests.
If your content was removed or your account was actioned by our automated moderation system and you believe this was in error, you may submit an appeal using the in-app "Appeal" button on the flagged content, or by contacting support@soki.co.ke. Appeals are reviewed by our human moderation team. Decisions on appeals are final.
The Service is intended for users aged 16 and over (or such higher age as required by applicable law in your jurisdiction). We do not knowingly collect personal information from children under 16. If you are under 16, please do not use the Service or provide any personal information.
For US users: the Service is not directed to children under 13 within the meaning of COPPA. If we become aware that we have collected personal information from a child under 13, we will delete it immediately.
If you believe a child under the applicable minimum age has created an account, please contact us at privacy@soki.co.ke with the subject line "Minor Account".
We implement appropriate technical and organisational measures to protect your personal information including:
No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security. In the event of a data breach that is likely to result in a risk to your rights and freedoms, we will notify you and relevant authorities as required by applicable law (within 72 hours for EEA/UK users under GDPR; within the timeframes required under Kenyan law).
The SOKI mobile application does not use browser cookies. We use device-local storage (MMKV) to cache certain preferences and session data on your device. This data does not leave your device except as part of normal Service operation. Our website (soki.co.ke) may use cookies for analytics and functionality; a separate cookie notice is provided on the website.
Some browsers offer a "Do Not Track" (DNT) feature. Our mobile application does not respond to DNT signals, as there is no industry-standard interpretation of DNT for mobile apps.
The Service may contain links to third-party websites or services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through our Service.
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:
Your continued use of the Service after the effective date of the updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must discontinue use of the Service and may delete your account.
For any privacy-related enquiries, requests, or complaints:
EEA/UK users may also contact our EU/UK representative at legal@soki.co.ke. Kenyan users may contact the Office of the Data Protection Commissioner (ODPC) at www.odpc.go.ke.
© 2026 SOKI. All rights reserved. | Effective: 23 March 2026 | Version 2.0