KrewU

Privacy policy

Version 2026-08-24.1 · in force since 24 August 2026

In short. KrewU collects the minimum it needs to work: name, age and location. We don't sell data, we don't profile, we don't show advertising. A young person's location isn't archived: only the last known one exists, and it gets overwritten. Messages are kept for twelve months, so that a report can be assessed. Everything is on servers in the European Union.

Who we are

Data controller

ElleMultiverse S.R.L., Via Dante 13/15, 20056 Trezzo sull'Adda (MI), Italy. VAT and tax code 14184620962.
For anything to do with data: privacy@krewu.it.

What we collect

The data, one by one

Data Why For how long
Parent's email and password Creating the account and allowing sign-in As long as the account exists
Young person's name and date of birth Recognising them in the app and setting the level of supervision, which depends on age As long as the profile exists
Location during an SOS Letting people reach whoever asked for help 30 days, then deleted automatically
Shared location Showing where they are to parents and to the people the young person has chosen No history: only the last location exists, overwritten
Messages, photos, videos and voice notes Letting young people communicate inside a closed network 12 months, then deleted automatically
Subscription status Knowing whether the family has KrewU Plus. Only our server writes it, after asking Apple or Google: we never receive or keep card details As long as the account exists
Notification tokens Delivering alarms and alerts As long as the device stays linked
Consent log Proving what was consented to and when: it's a legal obligation and a protection for the user 10 years from the closure of the account

We don't ask for the young person's surname, address, school or phone number. We don't use advertising identifiers and we don't integrate advertising trackers or behavioural analytics tools.

This website has no forms, no profiling cookies and no measurement tools: the pages are static and collect nothing. Until 7 September 2026 there was a waiting-list form protected by Google reCAPTCHA Enterprise; when the app was released that form was removed, and reCAPTCHA with it.

Why we're allowed to

Legal basis

For the data the service needs, performance of the contract (Art. 6(1)(b) GDPR).

Location has to be split into three different things, because they rest on different bases. The one parents see is performance of the contract (Art. 6(1)(b)): it's the function KrewU is installed for, it can't be turned off while keeping the service, and that's why we don't present it as a choice that wouldn't really be one. The young person knows: a notification stays on their phone, and the app says so plainly. Sharing with friends is consent (Art. 6(1)(a)): the parent authorises it, it can be withdrawn at any time, and the young person can turn it off themselves. Location during an SOS is consent, and in the case of an alarm vital interests also apply (Art. 6(1)(d)).

For notifications and for keeping messages for moderation purposes, consent (Art. 6(1)(a)), which can be withdrawn at any time from the app's settings.

For children under 14 processing rests on the authorisation of the holder of parental responsibility (Art. 8 GDPR; in Italy the age of digital consent is 14). It is the parent who creates the profile, gives consent and can withdraw it.

Where they end up

Where they're stored

The database and the server functions are in Germany (europe-west3), the attached files in Belgium (europe-west1). The infrastructure provider is Google Cloud EMEA Limited, acting as processor.

Push notifications pass through Apple's and Google's services, which by their nature also operate outside the European Union. The content of a notification is kept to the bare minimum.

Who processes them for us

The providers that process content

Some KrewU features couldn't exist without external services: the automatic checking of images, the reading of voice notes for moderation, the generation of backgrounds. They are all Google Cloud EMEA Limited services, which carries them out as processor on our instructions and not for its own purposes. None of this content is used to train models, for advertising or for profiling.

What is sent To which service Why
Photos and videos exchanged in chat Google Cloud Vision Detecting unsuitable content before it's delivered
Profile photo Google Cloud Vision Preventing an unsuitable photo from becoming a minor's picture
Photos and videos in statuses Google Cloud Vision The same check, before the status is visible to the crew
Voice notes Google Cloud Speech-to-Text Transcribing them into text on request, of someone in the conversation or of the parent supervising it. It doesn't happen to every voice note: until someone asks, that content goes through no check at all
The sentence the young person writes for the background Google Gemini Generating the chat background image
Texts to translate Google Cloud Translation Showing a message in the reader's language

Nobody at ElleMultiverse reads the conversations. These checks are automatic, and they produce an outcome — accepted, rejected, to be reported — not a copy we can read.

Who sees them

Who they're disclosed to

To nobody, outside the closed network the family has chosen. Inside the app, a young person's data is visible to their parents, to the trusted adults the parent has approved, and to the friends both parents have approved.

The location follows a stricter rule than everything else: on the map it's seen only by parents and siblings. A trusted adult — a grandparent, an uncle, a coach — receives it only inside an SOS, that is the location at that moment, and has no way of consulting it at other times. Sharing with friends requires an explicit permission from the parent on top of that, and the young person can turn it off whenever they like.

We don't sell data, we don't pass it to advertisers, we don't profile and we don't take automated decisions producing legal effects on people.

Child safety

Moderation

Images and videos exchanged in the app go through an automatic content check before being delivered, and voice notes are transcribed into text so they can go through the same check. Messages can be reported by whoever receives them: a report makes that single message visible to the parents, even when the conversation wouldn't be.

Where child sexual abuse material is found, we preserve the evidence, block the accounts involved and report to the competent authorities, as required by law.

Your rights

What you can ask for, and how

Access, rectification, erasure, restriction, objection and portability (Arts. 15-22 GDPR). In the app you'll already find, without having to write to anyone:

For everything else: privacy@krewu.it. If you've already uninstalled the app, deletion can be requested here: delete the account, where there's also the full list of what gets removed and of the three things that stay. We reply within thirty days. You also have the right to lodge a complaint with the Italian data protection authority (garanteprivacy.it).

If something changes

Changes to this policy

Every substantial change means a new version and a new request for consent when the app is opened. Previous versions remain available on request.

This is a courtesy translation. The Italian version is the binding one: in case of discrepancy, the Italian text prevails.