Privacy Policy

Last updated: May 16, 2026 · Effective worldwide

1. Who we are & controller details

Thumber ("we", "us") operates the Thumber short-video and livestream platform. We act as data controller (GDPR/UK-GDPR), business (CCPA/CPRA), responsible party (POPIA), data fiduciary (India DPDP), personal information handler (China PIPL) and equivalent for personal data we process about our users. Data Protection Officer / Information Officer / Encarregado / DPO: dpo@thumber.app.

2. What we collect

3. Legal bases (GDPR / UK-GDPR / LGPD)

4. How we use your data

To run the platform; recommend, rank and translate content; prevent abuse, CSAM, terrorism, scams and bot/fake-engagement; process payments and payouts; comply with law and government requests; conduct in-product research; and (only with your consent) send marketing.

5. Automated decision-making & AI

We use automated systems for content ranking, recommendations, language identification, AI moderation, age signals, fraud scoring, and abusive-account detection. These can result in content being deprioritised, hidden, removed, or accounts being restricted. You can request human review at appeals@thumber.app. Recommendations can be reconfigured under DSA Article 27 (Settings → Feed → Recommendations).

6. Sharing & processors

We share data only with: hosting/CDN providers (Cloudflare, Supabase/Lovable Cloud), livestream infrastructure (LiveKit), payment processors (Stripe, Paddle, Apple, Google), AI providers (limited to moderation/translation prompts), email delivery, analytics processors, KYC/AML providers for payouts, and law-enforcement when legally compelled. We do not sell or "share" personal information for cross-context behavioural advertising as defined by the CCPA/CPRA, Colorado CPA, Connecticut CTDPA, Virginia VCDPA, Utah UCPA, Texas TDPSA, Oregon OCPA, Delaware DPDPA, Iowa ICDPA, Tennessee TIPA, Indiana ICDPA, Florida FDBR, New Jersey NJDPA, New Hampshire NHPA, Minnesota MCDPA, Maryland MODPA, or Montana CDPA. We honour the Global Privacy Control (GPC) browser signal as a valid opt-out.

7. International transfers

Data may be processed in the EU, UK, USA, South Africa, Singapore and Japan. Transfers outside your jurisdiction rely on (a) EU Standard Contractual Clauses (SCCs), (b) the UK International Data Transfer Addendum, (c) Swiss FADP equivalents, (d) Japan APPI supplementary rules and Korea PIPC standard contractual clauses, (e) China PIPL standard contract / certification for outbound transfers, (f) UAE Federal Decree-Law 45/2021 adequacy, or (g) your explicit informed consent. A copy of the SCCs is available at dpo@thumber.app.

8. Retention

Account data is kept while your account is active and for up to 24 months after deletion for fraud and CSAM prevention. Payment records: 7 years for tax law. Moderation evidence: up to 5 years. Backups are rotated within 90 days. Anonymised analytics may be kept indefinitely.

9. Your rights — worldwide

We respond within 30 days (45 in CA/CPRA, 1 month GDPR, 72 hours for India urgent grievance). We may ask to verify your identity. Free of charge unless requests are manifestly unfounded or excessive.

10. Children

Thumber is not for under-13s (or under the local age of digital consent — 16 in much of the EU). We comply with COPPA (USA, verifiable parental consent where applicable), GDPR age-of-consent rules, the UK Age-Appropriate Design Code, California SB 976 (no addictive feeds to minors without parental consent), CT/Utah minor protections, and POPIA s.34. Suspected underage accounts are removed; see Safety & Age Policy.

11. Security & data breach

TLS 1.2+ in transit, AES-256 at rest, Argon2id/bcrypt password hashing, least-privilege access, RLS on all user-data tables, audit logging, regular penetration tests. If a breach is likely to result in risk to your rights and freedoms we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and you without undue delay (POPIA s.22, PIPL, LGPD, India DPDP, CCPA breach notice).

12. Cookies & similar tech

See our Cookie Policy. We honour the Global Privacy Control signal and Do Not Track where required.

13. Changes

Material changes are notified in-app and by email at least 14 days before they take effect (30 days for EU/UK consumers).

14. Contact & representatives

Privacy questions or rights requests: dpo@thumber.app.
EU representative (Art. 27 GDPR): eu-rep@thumber.app.
UK representative: uk-rep@thumber.app.
Brazil Encarregado, India DPDP grievance officer, China PIPL local representative, UAE/KSA representative: dpo@thumber.app.