Effective date: 11 September 2026
This Privacy Policy explains how Bright Minds Hub Marketing Management LLC ('Bright Minds Hub', 'KMSTRY', 'we', 'our', 'us') processes personal data for the KMSTRY mobile applications, associated APIs, Venue Partner dashboard, and KMSTRY legal, support and invite websites, including staging.kmstry.net during the external beta. We do not sell personal data.
Reading or acknowledging this Policy is not blanket consent to every use of personal data. Where consent is required, we request it separately. Different features collect different information: a venue-only account does not create personal check-in or discovery activity merely by managing its venue.
1. Data Controller
| Item | Details |
|---|---|
| Controller | Bright Minds Hub Marketing Management LLC, Dubai, United Arab Emirates |
| Postal address | Office 2703, Concord Tower, Dubai Media City, Dubai, United Arab Emirates |
| Privacy and support contact | adops@brightmindshub.net |
| Telephone | +971 4 494 1211 |
| Company website | https://brightmindshub.net |
Bright Minds Hub determines the purposes and means of processing for KMSTRY accounts and platform services. Venue businesses are responsible for their own use of information they lawfully receive through the platform. Any separate processing on a venue's behalf must be governed by the applicable agreement; managing a venue account does not give the venue access to all KMSTRY user data.
2. Applicable Law and Processing Grounds
We process personal data subject to applicable data-protection law, including UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data where it applies. GDPR, UK GDPR or other local laws apply when their territorial and material scope covers the processing. A user's location alone does not make every foreign data-protection regime applicable.
Under the UAE PDPL, we rely on consent unless a permitted exception applies, including processing necessary to perform a contract with you, comply with applicable legal obligations, or establish, exercise or defend legal claims. We assess the ground for each purpose under the applicable law. Where another applicable law permits legitimate-interest processing, it requires an assessment of necessity and your rights; it is not a blanket ground for all UAE processing.
Account authentication, requested messaging, check-in and venue-management operations involve information needed to provide those services. Optional account-linked venue discovery analytics and marketing choices are managed separately. Device permission controls access to resources such as location, camera and microphone; permission does not authorise unrelated uses. We use date of birth to enforce KMSTRY's 18+ eligibility rule, without claiming that every requested profile field is required by law.
3. Information We Collect
3.1 Information you provide
| Category | Examples and purpose |
|---|---|
| Account and profiles | Name, username, email, phone where provided, date of birth, gender, interests, bio, profile photos, account type and preferences; used to maintain your account, enforce eligibility and provide profile and discovery features. |
| Authentication | Password hashes, authentication-provider identifiers and returned profile/contact details, verified status, sessions and consent records; used for sign-in, account security and recording your choices. |
| Messages and social activity | Message text, photo/file attachments, replies, reactions, conversation identifiers, shared venue cards, connection requests, matches, blocks and chat visibility/deletion choices; used to deliver and manage conversations. |
| Check-ins and stories | Venue, check-in time, vibe and intent selections, photos, videos, captions/text overlays and profile-display choices; used to show presence and shared content. |
| Venue and event activity | Venue follows, event RSVPs, venue profiles, staff memberships and permissions, event posts and venue stories; used for the features you use. |
| Verification and venue claims | Submitted verification photographs, trade licences, ownership videos, business/contact information and claim decisions; used to assess identity or venue ownership and prevent abuse. |
| Reports and support | Reported content, complaint details, evidence, correspondence and moderation actions; used to investigate reports, enforce rules and respond to requests. |
3.2 Information generated through use
| Category | Examples and purpose |
|---|---|
| Location | Device coordinates, reported accuracy and capture time where supplied, last known location, check-in coordinates and distance from a venue; used for discovery, check-in validation and abuse prevention. |
| Device and security information | IP address, user agent, app version/build, platform, OS version, App Check/integrity results and security events; used for compatibility, minimum-build checks, rate limiting, fraud prevention and diagnostics. |
| Delivery and interaction records | Push token and permissions, notification preferences and delivery results, message delivery/read status, story views, timestamps and venue search events; used for delivery, feature state and the reporting explained below. |
| Legal and access requests | Accepted document versions, acceptance time/source, IP and user agent where available, export selections/status and identity-verification results; used for accountability and handling requests. |
We do not receive your device's Face ID or fingerprint templates. A photograph or video you submit for verification is still personal data and is covered by this Policy. We do not import your address book or calendar. External-beta services do not request payment credentials or charge for subscriptions. KMSTRY is for adults aged 18 and over; see Section 11.
4. How We Use Information and Your Choices
- Provide account, personal-profile and venue-management services, discovery, check-in, messages, stories, event activity and notifications.
- Investigate reported content, enforce our Terms, prevent fraud and unauthorised access, and maintain service reliability.
- Record legal acknowledgements and handle access, export, correction, deletion and other privacy requests.
4.1 Venue discovery analytics
Optional account-linked venue discovery analytics is disabled by default. Where the personal-profile discovery controls are available, you can change Settings → Privacy choices → Share venue discovery analytics. The preference is associated with your KMSTRY account; venue management does not itself generate personal venue-search activity.
When enabled, venue search/discovery events may be associated with your user identifier to improve search and trending insights. When disabled, new search events are recorded without that identifier and identifiers are removed from retained venue search events for your account. Unlinked event information and aggregate counts may remain. Removing an identifier does not, by itself, guarantee that every remaining record is irreversibly anonymous.
This choice does not switch off essential security or delivery records, active check-in visibility, intentionally shared stories, or venue statistics derived from check-ins. Aggregate statistics and the venue's active-guest display are different features: the latter can identify non-anonymous guests as explained in Section 5.
4.2 Communications
We send account verification, password-reset, security, legal and export-status communications as needed to provide the service. Push delivery depends on device permissions and in-app preferences. Marketing communications require the applicable opt-in; you can change the marketing preference in settings or use an unsubscribe option where provided. Declining marketing does not stop essential account notices.
4.3 Future advertising
Paid subscriptions and targeted advertising campaigns are not offered during the external beta. Before introducing additional advertising processing, we will explain the data, recipients, controls and applicable consent requirements and update this Policy. No audience threshold, anonymisation guarantee or advertising transfer mechanism is claimed for an unlaunched feature.
5. Who Can Receive or See Information
5.1 Other users and venue personnel
Your profile, active check-in, photos, vibe and intents may appear to eligible users through venue presence, profile and discovery features. Personal stories may also appear to matched connections, including when those people are not at the same venue. Venue stories and event/business content are displayed through their associated venue and feed features. Visibility depends on the feature, active/expiry state, account settings, blocking rules and access checks.
Message recipients can see the content, attachments, replies, reactions and venue cards you send, together with relevant sender and delivery information. Story authors may see viewer information under the feature's visibility rules. Other people may save, copy, photograph or forward information they can access; deleting it from KMSTRY cannot erase copies they independently made.
Authorised venue owners and staff can see the venue's non-anonymous active guests, including name/username, profile or check-in photo, gender and active stories. They may access this dashboard remotely. Anonymous Mode excludes your identity from that active-guest list, but may still contribute to aggregate counts. It does not make you anonymous to KMSTRY or hide messages you intentionally send.
Profile and discovery features share profile information, including age-related information; the current service also returns date-of-birth information to eligible viewers through these features. Your login email, phone and credentials are not ordinary public-profile fields. Content you choose to send or publish may itself reveal personal information. Venue business/contact information you publish is intended to be visible.
5.2 Providers
| Provider | Function and information involved |
|---|---|
| DigitalOcean | Application hosting, managed database, object storage and export storage; processes the data stored by those services in the configured deployment regions. |
| Google Firebase: FCM and App Check | Push tokens and delivery payloads; app/device integrity signals and verification results. Apple push services participate in iOS notification delivery. |
| Google Maps and Places | Map display, venue details, search queries and relevant location context for mapping and nearby search. |
| Google and Apple sign-in | Authentication identifiers, tokens and profile/contact information returned by the provider. Apple may supply a private relay email. |
| Resend | Email recipient, message content and delivery information for transactional communications. |
| Sentry, when enabled | Technical errors, performance and diagnostic metadata according to the deployed monitoring configuration. |
Some providers process information on our instructions; sign-in and mapping providers may also process data under their own terms and privacy notices. Provider processing locations and subprocessors may vary. International-transfer requirements are explained in Section 13.
Push notifications and email can be displayed by operating systems and delivery providers. Message previews may reveal content on a lock screen depending on your settings. Export-status notifications do not include the archive or its contents.
5.3 Safety, legal requests and business changes
Authorised personnel may access information needed for support, verification, moderation, security and privacy requests. This can include reported messages and media. We may disclose information when required by applicable law or lawful orders, or where legally permitted to protect rights and safety. We provide notice where required and legally permitted.
If the business is reorganised, acquired or transferred, relevant information may pass to the successor subject to applicable data-protection requirements and required notice. We do not sell personal data to advertisers or data brokers.
6. Location
With location permission, KMSTRY may obtain location while you use location-based features, including opening discovery, searching nearby venues and creating or updating a check-in. We do not operate continuous background location tracking.
We retain the last known location and check-in location records, including coordinates, time and distance used to validate presence. Check-in expiry removes active presence; it does not itself erase the historical check-in record. These records support requested history/discovery features and security. Selected location history can be requested through data export, and you may request deletion using app controls or the privacy contact.
Exact device coordinates are not shown to ordinary users or venue staff as dashboard fields. Mapping/nearby services and infrastructure providers may process location as explained in Section 5. You can revoke permission in device settings; check-in and nearby discovery are limited without it, while messaging and other features that do not require location remain available.
7. Temporary Media and Access
A new check-in currently expires after 3 hours unless you check out earlier. A renewed check-in has its own expiry. Personal stories linked to a check-in use the associated expiry; venue stories follow their separately assigned expiry. The expiry displayed for a particular item governs its availability.
Check-in media and linked stories are removed from active display on checkout or expiry and are normally removed from live storage during cleanup. Where content has been reported, a restricted copy or snapshot may be retained as moderation evidence for safety, abuse prevention, dispute handling or legal compliance. Report evidence is not available to ordinary users and is retained only for as long as reasonably necessary for those purposes. Scheduled cleanup and technical failures can delay physical deletion. Expiry of media does not erase the separate historical check-in record. Residual backup copies, where present, follow the backup retention described below.
Private media is served through access checks and time-limited URLs. Such URLs can remain usable until their short expiry, and a recipient can retain a copy already obtained. This protection is not end-to-end encryption: KMSTRY systems process stored messages and media to deliver the service and authorised support, safety and legal functions.
Profile photos, message attachments, venue content and verification documents have different purposes and retention rules. Do not rely on temporary content as your only copy.
8. Retention and Deletion
| Information | Retention rule or criteria |
|---|---|
| Account and profile data | Kept while the account/profile is in use, until deletion, with only applicable legal, security or dispute-related exceptions. |
| Check-in location and history | May remain after active check-in expiry until removed through applicable history/account controls or a fulfilled privacy request; media expiry is separate. |
| Last known location | Updated when the service receives a newer location; not an automatically erased record when you close the app. Subject to account deletion and privacy requests. |
| Check-in media and personal stories | Active until checkout or the relevant expiry, followed by live-storage cleanup as described in Section 7. Reported content may be retained with restricted access under the Security, delivery, support and legal records criteria. |
| Messages and attachments | Kept to provide conversation history until deletion or applicable cleanup. Soft-deleted messages and fully hidden conversations have 30-day cleanup rules; hiding a conversation for yourself does not immediately remove it for the other participant. |
| Venue, event and verification records | Kept for the relevant venue/event, membership, claim or verification purpose and any necessary dispute or legal requirement. Closing a personal profile does not necessarily delete a business record shared with other venue members. |
| Security, delivery, support and legal records | Kept as needed for authentication, delivery investigation, abuse prevention, requests and documented legal/dispute needs. Retention depends on the record and purpose; we do not represent a universal 12-month automatic deletion rule. |
| Discovery analytics | Account identifiers are removed from retained search events when you disable the optional choice. Unlinked event data and aggregate counts may remain for search/trend reporting. |
| Export archives | Normally 96 hours after completion, or 48 hours when precise location history is included; may be removed earlier after cancellation or account deletion. |
| Export request audit | Up to 24 months after a terminal request status; the audit does not retain the archive contents. Account deletion can remove the associated record earlier. |
| Backups | Residual copies may remain until overwritten or expired under the configured disaster-recovery schedule. Contact us for information about a specific deletion request and applicable exceptions. |
A confirmed full-account deletion removes associated personal data from live systems and initiates storage cleanup, subject to applicable lawful retention. Deleting only a personal profile or leaving a venue is different from deleting the whole KMSTRY account. Shared business records, another participant's independently supplied content, and records required for legal claims may require separate treatment. We explain any applicable exception when handling a request.
Where information must be retained for a legal or security purpose, its use must be limited to that purpose. A recovery from backup must not return previously deleted data to ordinary use without reapplying the deletion. We do not promise recovery of deleted content.
9. Your Rights and Data Export
Depending on applicable law, you may request access, correction, deletion, restriction, portability, withdrawal of consent and objection to applicable processing, including direct marketing. Rights can be subject to lawful exceptions and the rights of others. You can ask for human review of an automated decision affecting you.
Use Settings → Account Center → Download your data for available personal or venue export scopes. Available scopes depend on your profiles and venue permissions. The export is a ZIP archive with JSON and, where selected, human-readable HTML. Available media and categories depend on your selection and the records held for the selected scope. The archive can be downloaded and shared separately.
Self-service message exports include your sent messages and reactions, with third-party references minimised. They exclude received-message contents, other users' private contact/profile information, reporter identities, credentials and internal security/moderation material. These are self-service limits, not a blanket rejection of legal access rights: contact us if you need information omitted from an export, including received messages. We assess the request individually and may redact information to protect other people's rights or explain a lawful refusal.
Sensitive requests, including precise-location exports, may require recent identity verification. When ready, an archive may trigger an in-app, push or email status notice. Download access expires as described in Section 8; making an export does not delete your account.
You can request full account deletion in settings or use the account-deletion page linked on the KMSTRY website (/delete-account). You can also contact adops@brightmindshub.net for access, correction, deletion or other requests, including when you cannot sign in. Do not email passwords or one-time codes. We may request proportionate identity or authority verification through an appropriate method.
Our service target is to respond within 30 days, and we comply with any shorter applicable legal deadline. If a lawful extension or exception applies, we explain it and the next steps. Requests are normally free; any fee or refusal must be permitted by applicable law and explained. You may ask us to review a response and complain to the UAE Data Office or another competent authority for your case.
10. Cookies and Local Storage
KMSTRY's public legal, support and invite pages currently do not intentionally set analytics or marketing cookies, so they do not display a non-essential-cookie consent banner. Hosting and request logs can still process IP addresses and technical request information. Non-essential cookies introduced later will require updated information and any legally required consent before activation.
The native app uses secure storage for authentication tokens and local preferences/caches for its interface and media. FCM tokens support notifications. External sign-in pages and websites opened from the app may use their own cookies. The no-marketing-cookie statement applies to KMSTRY's public pages, not the separate Bright Minds Hub corporate website or third-party sites.
11. Children
KMSTRY is intended only for people aged 18 or older. We do not knowingly collect children's information. If we learn an account belongs to someone under 18, we restrict access and handle deletion, retaining only information where lawfully necessary for safety or legal obligations. Report an underage account to adops@brightmindshub.net.
12. Security and Incidents
Security controls include password hashing, authenticated access, private export storage, time-limited media access, input validation, rate limiting, app-integrity checks and security logging. Their configuration is assessed for each deployment. Public release connections use HTTPS; no system can guarantee absolute security. Messages are not end-to-end encrypted.
If a personal-data breach requires notification, we notify the competent authority and affected individuals in the circumstances and within the periods required by the applicable law. This is not an unconditional 72-hour promise for every incident.
13. International Processing
Bright Minds Hub is based in Dubai, UAE. Hosting and database/storage infrastructure includes configured EU regions; Google, Apple, Resend and other providers may process relevant information in the United States and other countries used by their infrastructure and subprocessors.
A transfer must satisfy the applicable legal requirements. Depending on the jurisdiction and transfer, this can involve a recognised adequate destination, an enforceable contractual safeguard meeting the relevant law, or a specifically permitted exception. A provider DPA or encryption alone is not proof that every transfer is lawful. We do not claim signed EU standard contractual clauses or a particular certification without evidence that it applies. Contact the privacy address for information about relevant destinations and safeguards.
14. Venue Accounts
Venue-only accounts process business, staff, event, story, support and security information relevant to managing the venue. A mixed account can also have personal-profile activity. Export and profile-deletion scopes reflect that distinction, while full-account privacy rights remain available.
Venue personnel must use active-guest information only for authorised venue operations, respect Anonymous Mode and visibility settings, and not scrape profiles, identify anonymous visitors or reuse guest details for unsolicited marketing. Business owners must provide their own notices where required for independent processing. Future targeted campaigns are subject to Section 4.3.
15. Automated Processing
Proximity/search ranking, integrity checks, rate limits and minimum-build controls use automated rules and can affect feature availability. These controls are not a guarantee of physical presence or a person's identity. Contact support to question an access restriction or seek human review where applicable. We do not describe unlaunched advertising profiling as an active beta feature.
16. Policy Changes
We publish an effective date and retain document versions. Material changes are notified through the app or other appropriate communication. The app can ask you to acknowledge the current Privacy Policy and accept updated Terms. An acknowledgement does not replace separate consent where required. New optional processing requiring consent is not authorised merely by continued use.
17. Contact
Send privacy enquiries to adops@brightmindshub.net or the postal address in Section 1. Include enough information to identify your account and request, but do not send passwords, one-time codes or unnecessary identity documents. This Policy applies to KMSTRY; the corporate website and other linked services may have separate notices.