Privacy Policy / Πολιτική Απορρήτου
OK ITHAKI PRIVACY POLICY — PUBLICATION DRAFT 2026-08-02
1. Operator and contact
OK ITHAKI is operated by Vasileios Karatzas, Greece. Contact for privacy, data-subject rights, security and legal requests: okithaki@gmail.com. Before commercial public release, complete business or legal address and any registration details must be added and reviewed by legal counsel.
2. Scope
This policy covers the Android app, the web app at ok-ithaki.gr, the public website at www.ok-ithaki.gr and OK ITHAKI server services. The service is nickname-first and does not require an email address or phone number for basic use.
3. Age
The current app states a 16+ limit. Because it includes user communication and user-generated content, the final age rating, minor-safety controls and app-store distribution must be approved before public release. The service is not intended for children below the stated limit.
4. Data kept mainly on the device
Name or nickname, avatar or initial, short description, language, settings, policy choices and the private account file are stored locally first. The account file is created only when requested by the member and should be kept by the member on a computer, USB drive or another private secure location.
5. Data the server may process
Depending on the feature used, the server may process: app or device identifier, nickname and basic profile, language, presence/last activity, posts, comments, reactions, messages, contact relations and requests, content reports, metadata and files uploaded by the member, notification token when enabled, call-signalling data, technical counters, usage limits and security logs. An IP-address hash may be used for abuse prevention instead of the full address where the feature permits.
6. Purposes and legal bases
Data is used to provide requested features, deliver messages and content, operate contacts and calls, provide support, protect security, prevent spam and abuse, review reports, comply with lawful requests and establish or defend legal claims. Legal bases may include performance of the service, consent where required, legitimate interests in security and abuse prevention, and compliance with legal obligations.
7. Messages, content, files and calls
Messages and posts sent to the server are available to intended recipients and, when required for safety or reports, authorised administration. The availability of an encryption option must not by itself be understood as a guarantee of end-to-end encryption for every channel. Calls use WebRTC and the server handles necessary signalling and call-state data; permanent recording is not enabled by default. Files uploaded by a member are stored so they can be delivered or displayed.
8. Notifications and external providers
Notifications may use Firebase Cloud Messaging only when enabled in the production release. Hosting, DNS/TLS and any notification provider act as technical recipients or processors under their terms. Personal data is not sold. Before release, final providers, processing locations, data-processing agreements and international-transfer safeguards must be documented where required.
9. Retention
The server has a default operational TTL of 72 hours for message, feed and media-metadata rows, configurable from one hour to 30 days. Security events may be kept for about 14 days and mood check-ins for up to 30 days. Profile, contact, report, legal-request and actual media files may have different life cycles and are deleted when no longer needed, when a deletion function is used, or when required by law. Closed legal requests are scheduled for deletion after 180 days unless longer retention is needed for a legal obligation or claim.
10. Rights
Where applicable, members may request information, access, correction, deletion, restriction, portability, objection or withdrawal of consent. They may also complain to the competent supervisory authority. Reasonable verification may be required to protect other members and confirm that a request relates to the relevant device or identity.
11. Account deletion
The app provides controls for deleting the local identity and requesting deletion of server-side data. The public website provides a separate request page. Deletion does not remove information that must temporarily be retained for legal obligations, security, abuse prevention or third-party rights.
12. Security
Measures include HTTPS/TLS, access restrictions, hashing or encoding where applicable, request limits, reporting and blocking tools. No service can guarantee absolute security. Vulnerabilities may be responsibly reported to okithaki@gmail.com without publicly disclosing active secrets or personal data.
13. Changes
This policy may be updated when features, providers or legal requirements change. The active version and date are published in the app and on the website.
IMPORTANT: This is a technically adapted publication draft, not legal advice or a certification of compliance. Final legal review and completion of operator details are required before commercial release.