nockda Privacy Policy
Last updated: 27 July 2026
This policy has not been reviewed by a lawyer. It is published now so that nockda can operate transparently during early access, and will be reviewed by qualified counsel before nockda exits beta. If anything here needs to change as a result of that review, we will update this page and notify users of material changes (see §11).
At a glance
The full policy below is authoritative, but here's the short version:
- We don't collect your real name, email address, or phone number. You sign up with Apple or Google, and we only receive that account's unique ID. You choose your own nickname.
- No ads, no selling your data, no ad tracking. Our only revenue is subscriptions.
- We only use location at city level (and only for the marketplace feature). We don't store precise GPS coordinates, and we automatically strip location data (EXIF GPS) from photos you upload.
- Posts are automatically screened by AI before they go live. If a post is rejected, you'll be notified, and you can contact us to request a human review of that decision.
- If you delete your account, your personal identifiers are erased after a 30-day grace period. Posts and messages you wrote stay visible under a "deleted user" label, so that conversations and threads other people were part of still make sense.
- Your data is stored in the UK/EU, and you can download or request deletion of your data from the app at any time.
1. Who we are
nockda ("we," "us," "the service") is a UK-launched, location-based social network and local marketplace app. This policy applies to the nockda app (iOS/Android) and related services. It explains what personal data we collect, why, how we handle it, and the rights you can exercise.
We process personal data in accordance with the UK GDPR and the Data Protection Act 2018.
- Data controller: Hyun Suk Lee, operating nockda as an individual pending formal business registration. We will update this section with full company details once incorporation is complete.
- Registered address: not yet published — we operate as an individual at this stage. Please contact us by email for any correspondence.
- Contact: help@nockda.com
- ICO registration: we are reviewing whether registration with the UK Information Commissioner's Office is required for our current scale and will register if so.
2. What we collect — and what we don't
What we don't collect
- Your real name — we only use nicknames. There is no identity verification step.
- Email address or phone number — your login provider (Apple/Google) holds these; they are not shared with us.
- Precise location — we don't store GPS coordinates. When the marketplace feature needs to determine your city, we use your coordinates momentarily and store only the resulting city name.
- Payment details — card numbers and similar are handled entirely by Apple/Google and never reach our servers.
- Contacts, photo library, or other device data — beyond the photos you choose to attach, we don't access your device's data.
- Advertising identifiers or behavioural tracking data — we don't run ads, so we have no reason to collect this.
What you give us directly
| Item | Details | When |
|---|---|---|
| Account identifier | The unique user ID from Apple/Google Sign-In (not your name or email) | At sign-up |
| Profile | Nickname, country of residence, languages you use | During onboarding |
| Content | Posts, replies, marketplace listings, chat messages, attached images | While using the app |
| Reports | Reason for a report, and a snapshot of the reported content | When you report something |
What we collect automatically
| Item | Details | Purpose |
|---|---|---|
| Push token | Your device's push-notification address (Expo Push Token) and platform (iOS/Android) | Sending notifications |
| Session activity | Timestamps of session/token refresh | Security (detecting session hijacking), aggregate usage stats (see §4) |
| Approximate city | The city inferred from coordinates when you create a marketplace listing — only the city name is stored | Matching local listings |
| Error diagnostics | Technical information when the app crashes or errors (no personal identifiers) | Fixing bugs |
What we receive from third parties
| Item | Source | Details |
|---|---|---|
| Subscription status | Apple/Google, via RevenueCat | Whether you're subscribed and when it expires (no payment details) |
3. How we use it (purpose and legal basis, UK GDPR Art. 6)
| What we do | Data used | Legal basis |
|---|---|---|
| Create your account, sign you in | Account identifier, profile | Performance of a contract |
| Show your feed, search results, marketplace listings | Content, language, country, city | Performance of a contract |
| Chat | Messages, participants | Performance of a contract |
| Automatically screen posts, handle reports | Content, report details | Legitimate interests (platform safety, compliance with app store UGC requirements) |
| Manage your subscription | Subscription status | Performance of a contract |
| Send notifications (likes, replies, messages, etc.) | Push token | Performance of a contract |
| Fix bugs | Error diagnostics | Legitimate interests (service quality) |
| Aggregate usage stats (e.g. weekly active users) | Sign-up date, session timestamps, post timestamps | Legitimate interests (improving the service) — computed entirely on our own servers, never sent to a third-party analytics provider |
We do not use your data for advertising, and we do not sell it to third parties.
4. Who we share it with
We use the following companies as processors to run our servers. They may only process data on our instructions, not for their own purposes (e.g. marketing).
| Company | Role | Data involved | Location |
|---|---|---|---|
| Neon | Database | All account and content data | EU |
| Upstash | Cache/queue | Short-lived session-related data | EU |
| Cloudflare (R2) | Image storage | Attached images | Global CDN infrastructure |
| RevenueCat | Subscription management | Subscription status, app user ID | US-based |
| Sentry | Error tracking | Technical diagnostics only (PII filtered out) | US-based |
| Anthropic (Claude) | AI post screening | Post text | US |
| Apple / Google | Sign-in, in-app payments | Login tokens, payment processing | Per their own policies |
We may also disclose data where legally required (e.g. a valid court order or law-enforcement request).
International transfers: data may be transferred to processors outside the UK/EEA (e.g. Anthropic, RevenueCat, Sentry). Where this happens, we rely on safeguards recognised under the UK GDPR, such as the UK's International Data Transfer Addendum to the EU Standard Contractual Clauses.
5. How long we keep it
- While your account is active: we retain the data described in §2.
- When you delete your account: there is a 30-day grace period. Logging back in during this window cancels the deletion and restores your account.
- After 30 days: personally identifying information (nickname, login identifier, push token, language/country settings) is deleted or replaced with randomised values, and all uploaded images are deleted.
- What stays: posts and chat messages you wrote are not deleted — they remain under a "deleted user" label, so conversations and threads other users were part of aren't broken. All information that could identify you is removed, so this content is no longer linked to you. You can delete individual posts or messages yourself at any time before account deletion.
- Original images: only the resized version is kept after upload; the original file (including any EXIF GPS location data) is deleted immediately.
- Report records: kept for 2 years for dispute handling and platform-safety purposes.
6. Children and teenagers
nockda is available to users aged 17 and over. We check age during sign-up, and accounts confirmed to belong to someone under 17 are not permitted. We do not knowingly collect personal data from anyone under 17, and we delete such accounts if we discover them. If you believe a child under 17 has created an account, please let us know at help@nockda.com.
7. Automated decision-making (AI post review)
Posts are automatically screened by Claude (Anthropic), an AI system, before they go live. If a post is judged to violate our policies, it may be rejected without human review, and you'll be notified of the outcome.
If you disagree with a rejection, you can contact us at help@nockda.com to request that a human reviews the decision. We plan to add an in-app appeal button in a future update; this page will be updated once that's available.
8. Your rights (UK GDPR Ch. 3)
Things you can do directly in the app:
| Right | How |
|---|---|
| Access your data / data portability | Settings → Export my data — download your posts, listings, messages, and profile as JSON (download link valid for 72 hours) |
| Rectification | Change your nickname, language, or country directly in Settings |
| Erasure | Settings → Delete account (see §5 for the process) |
| Delete individual content | Delete any post or listing directly from it |
Things you need to contact us for: restriction of processing, objection, or any other request — email help@nockda.com and we'll respond within one month.
Complaints: if you're unhappy with how we've handled your data, you can complain to the UK Information Commissioner's Office (ICO, ico.org.uk). We'd appreciate the chance to resolve it directly first.
9. Security
- All communication is encrypted (HTTPS/TLS).
- We have no password of our own to leak — sign-in is Apple/Google only, so there's no password database at risk.
- Login session tokens are stored as hashes, not in plain text. If a token is stolen or reused, all sessions on that account are terminated immediately.
- Admin functions are protected by two-factor authentication.
10. Cookies
The nockda app does not use web cookies. Usage statistics are computed entirely on our own servers, without any third-party analytics tool, and are never transmitted externally in a personally identifiable form.
11. Changes to this policy
We may update this policy as the service changes. We'll give advance notice of material changes through an in-app announcement or notification. Last updated: 27 July 2026.
12. Contact us
For anything related to your personal data: help@nockda.com