boukd . Legal

Privacy Policy.

How we collect, use and protect your data - written so you can actually understand it. Built for the Kenya Data Protection Act (2019), GDPR-class principles and an end-to-end-encrypted messaging fabric.

v1.1 . Effective 30 August 2026
Lilos Dynamics . Data Controller . [email protected]

1. Introduction

In short. This is what data boukd holds about you, why, who we share it with, and what you can do about it. We follow the Kenyan Data Protection Act and apply GDPR-level standards everywhere.

This Privacy Policy explains how Lilos Dynamics ("boukd", "we") collects, uses, shares and protects information about you when you use the boukd mobile and web apps, our APIs and our related services (the "Service"). It applies alongside our Terms of Service and any product-specific notices we show you in-app.

Where the Kenya Data Protection Act, 2019 (the "DPA") and equivalent laws apply (e.g. the GDPR for users in the European Economic Area, the UK GDPR for users in the United Kingdom, NDPR for users in Nigeria), we have designed our practices to meet the higher of the two standards.

2. Who is the controller

Lilos Dynamics is the data controller for personal data processed via the Service, except where we expressly act as a data processor on behalf of an Agency or Bookable workspace using our enterprise tools - in which case our customer is the controller and our processing is governed by a separate Data Processing Addendum.

Our Data Protection Officer can be reached at [email protected].

3. Data we collect

In short. The basics to make an account, the things you do on boukd, the messages you exchange (encrypted), device and network info to keep you safe, and payment details when you transact.
CategoryExamplesSource
Identity & account First / last name, account type, email, phone (E.164), country code, password hash, profile picture, agency name (if any), date of birth (where required for age-gating). You, at sign-up.
Verification (KYC) Government ID image, ID number, selfie/liveness video, proof of address, business registration, tax ID, beneficial ownership info, sanctions screening result. You + verification partners.
Bookable profile Bio, rates, service categories, availability, Studio media, livestream metadata, ratings, reviews. You.
Tribe & social Who you follow, who follows you, posts, comments, likes, reactions, shares, story views. You + other Users.
Bookings & transactions Booking details, scheduled times, location (when you choose to share it), prices, taxes, payment method last-4 / mobile-money number, payout method, escrow state, refund history. You + payment processors.
Messaging metadata Conversation IDs, participant IDs, timestamps, delivery / read receipts, message size, encrypted ciphertext, device public keys. The Service.
Device & network Device model, OS, app version, locale, time zone, push token, IP address, approximate location derived from IP, crash reports, performance traces. Your device.
Cookies & storage Session cookies on web, secure key-value storage on mobile (AsyncStorage / Keychain / Keystore). Your browser / device.
Support & safety Tickets, abuse reports, evidence you submit, decisions, takedown notices. You + other Users.

4. How we use it

In short. To run the app, process payments, keep you safe, give you a good time, and meet our legal obligations. We do not sell your personal data.
  • Provide the Service - create your account, host your content, deliver messages, run livestreams, match Bookables and tribe members.
  • Payments & payouts - process bookings, hold funds in escrow, calculate fees, prevent fraud, run KYC and AML checks, settle taxes.
  • Personalisation - sort your feed, suggest Bookables to follow, surface livestreams you might enjoy.
  • Safety & integrity - detect spam, harassment, ban evasion, payment fraud, unauthorised access; investigate abuse reports.
  • Communication - service announcements, security alerts, OTP codes, receipts, and (where you've opted in) marketing.
  • Legal compliance - respond to lawful orders, defend legal claims, exercise or defend our rights.
  • Improve boukd - measure performance, debug crashes, run experiments, train safety models on aggregated or properly de-identified signals.

We do not sell your personal data.

ActivityLawful basis (DPA s.30 / GDPR Art.6)
Creating your account, delivering bookings, paymentsPerformance of a contract
KYC / AML, sanctions screening, tax reporting, lawful accessLegal obligation
Marketing communications you have opted intoConsent (withdrawable at any time)
Security, anti-fraud, abuse moderation, product improvementLegitimate interests, balanced against your rights
Sensitive data (e.g. ID images, biometric liveness)Substantial public interest / explicit consent under DPA s.46

6. Who we share with

In short. Other Users see the parts of your profile you make public. Service providers help us run the platform under strict contracts. Authorities only get data via valid legal process.
  • Other Users - public profile fields, posts, livestreams, reviews you publish; the masked destination of your messages where you initiate them.
  • Bookables / tribe members in a transaction with you - name, contact details needed to deliver the booking, reviews you've left.
  • Sub-processors - see Section 7.
  • Payment partners - Safaricom (M-Pesa), card networks, bank rails, mobile-money operators, anti-fraud bureaus.
  • Authorities - only on receipt of a binding legal request that we have reviewed and not successfully challenged. See Section 12.
  • Acquirers - if boukd is sold, merged or restructured, the buyer will be notified of, and bound by, this Privacy Policy. We will give you notice and a meaningful opportunity to delete your account before any change of controller.

7. Sub-processors

We engage carefully selected sub-processors under written contracts that meet DPA s.42 (and Article 28 GDPR where relevant) requirements. The principal categories at the date of this Policy are:

CategoryPurposeRegion
Cloud hosting (Cloudflare R2, managed Postgres, Redis)App hosting, storage, CDNGlobal, with primary data plane in EU/Africa where available
Payment processing (Safaricom M-Pesa, card networks, mobile-money APIs)Payments, payouts, refundsKenya / region of payment
Communications (Gmail SMTP / Resend; Africa's Talking; Twilio)Transactional email, SMS, OTPKenya, EU, US
Analytics & crash reportingPerformance, stabilityEU / US (privacy-first vendors only)
Identity verificationKYC, AML, liveness, sanctions screeningKenya / EU
Customer supportHelp desk, ticketingEU / US

A current sub-processor list is maintained at boukd.app/legal/sub-processors. We will give at least thirty (30) days' notice before adding or replacing a sub-processor that handles your personal data, and you may object on reasonable grounds.

8. International transfers

In short. Some of our partners are outside Kenya. When that happens, we rely on contracts and safeguards approved by the Office of the Data Protection Commissioner (ODPC).

Where personal data is transferred outside Kenya, we rely on one or more of the safeguards recognised under DPA s.49: explicit consent for the transfer; necessity for performance of the contract with you; standard data protection clauses; binding corporate rules; or transfer to a country with an adequate level of protection. For transfers to the United States we additionally rely on processor-level certifications (e.g. EU-US Data Privacy Framework, ISO 27001, SOC 2).

9. Retention

DataRetentionReason
Account profileLife of account + 30 days grace after deletion requestAllow restore on accidental deletion
KYC documents7 years from end of relationshipAnti-money-laundering regulations
Booking & payment records7 yearsTax and accounting law
Encrypted messages on the serverUntil you or the other party delete the conversation, or 365 days for AI-bot conversations, whichever is shorterService operation
Push tokens, session tokensUntil logout / token expiryService operation
Server logs30 days (90 days for security-relevant logs)Operations, security
Abuse reports & moderation decisions3 years from decisionRepeat-offender detection, defence of claims

After the retention period, we delete or irreversibly anonymise the data. Aggregated, non-identifying statistics may be kept indefinitely for product analytics.

10. Security

In short. TLS in transit, encryption at rest, hardware-backed keys for the most sensitive secrets, and a tightly scoped, audit-logged human access policy.
  • TLS 1.2+ for all network traffic; HSTS on web.
  • At-rest encryption (AES-256) on databases and object storage.
  • Per-conversation E2EE for Pulse messages (see Section 11).
  • HSM-protected keys for the lawful escrow path.
  • Argon2id / bcrypt password hashing.
  • Two-factor authentication via OTP for sign-in and sensitive actions.
  • Role-based access control with quarterly access reviews.
  • Vulnerability disclosure programme: [email protected]  PGP available on request

11. End-to-end encryption

In short. Your messages are encrypted on your device with keys we cannot read. Even if our servers were fully compromised, the attacker would only see ciphertext.

Pulse - boukd's messaging fabric - uses X25519 device key pairs, a per-conversation symmetric key wrapped to each participant device, and XChaCha20-Poly1305 authenticated encryption for message envelopes. boukd's servers store ciphertext and a small set of routing metadata (sender, recipient, timestamp). We do not have the plaintext of your messages.

12. Lawful access & escrow

In short. We never quietly read messages. There is one narrow exception: a Kenyan court order or equivalent legal process. Even then, multiple senior officers must each approve; every step is logged in a tamper-evident chain; we publish summary statistics annually.

Each per-conversation key is additionally wrapped to an HSM-backed escrow public key. Decryption of the wrapped key is gated by an M-of-N multi-signature ceremony involving independent senior officers. Every approval, denial and key release is recorded in a hash-chained audit log that is reviewable by our independent legal counsel.

We will only invoke this path:

  • on receipt of a valid Kenyan court order, ODPC directive, mutual legal assistance request, or equivalent legal process from a competent jurisdiction we have reviewed;
  • where required by anti-terrorism, anti-money-laundering or child-safety law that we cannot lawfully challenge; or
  • to investigate a clearly suspected, time-critical threat to life - in which case we will seek post-hoc judicial review.

We publish an annual Transparency Report with the number of requests received, how many were challenged, narrowed or refused, and how many resulted in disclosure.

13. Your rights

In short. See your data, fix it, take it with you, delete it, restrict our use of it, object to it, withdraw consent. We aim to action requests within 30 days.

Under the DPA (and GDPR / UK GDPR where applicable), you have the right to:

  • Access a copy of the personal data we hold about you;
  • Rectify inaccurate or incomplete data;
  • Erase your data (subject to legal retention obligations such as KYC);
  • Restrict certain processing;
  • Object to processing based on legitimate interests, including profiling;
  • Withdraw consent where processing is based on consent;
  • Portability - receive your data in a structured, machine-readable format;
  • Lodge a complaint with the Office of the Data Protection Commissioner of Kenya (or your local supervisory authority).

14. How to exercise them

You can exercise most rights directly in-app at Settings to Privacy & data:

  • Download my data - generates a portable export.
  • Delete my account - schedules deletion after a 30-day grace period.
  • Manage notifications & consents - fine-grained marketing toggles.

For anything you cannot do in-app, write to [email protected]. We will verify your identity and respond within thirty (30) days (extendable by sixty days for complex requests, with notice). There is no fee unless your request is manifestly unfounded or excessive.

15. Cookies & analytics

On the boukd web app we use a small number of strictly necessary cookies (session, CSRF, locale) and, with your consent, a privacy-first analytics cookie that does not build cross-site profiles of you. On mobile we use platform secure storage (iOS Keychain, Android Keystore, AsyncStorage) to keep you signed in. You can clear these at any time from your browser or device settings.

16. Children

boukd is not intended for children under sixteen (16). We do not knowingly collect personal data from children under 16. If we become aware that we have, we will delete it promptly. Some features (payments, payouts, Tembo, Bookable profiles) are restricted to adults - see Section 3 of the Terms.

17. AI & automated decisions

In short. We use ML for safety, recommendations and our @boukd-bot concierge. We don't make decisions with legal effect about you (like permanent bans or payout freezes) without a human in the loop.

We use machine-learning systems to rank your feed, recommend Bookables, detect abuse, prevent fraud, and power the @boukd-bot concierge. Your conversations with the bot may be used to improve safety classifiers in aggregate; we do not train general-purpose foundation models on your private messages. Decisions that have a legal or similarly significant effect on you (account closure, payout freezes lasting more than 7 days, denial of a Tembo loan) include human review, and you have the right to contest them by writing to [email protected].

18. Breach notification

If we become aware of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the Office of the Data Protection Commissioner within 72 hours as required by DPA s.43, and notify affected Users without undue delay where the risk is high.

19. Changes

We may update this Privacy Policy. If a change is material, we will notify you in-app and by email at least thirty (30) days before it takes effect. Past versions will be available at boukd.app/legal/privacy-history.

20. Contact & complaints

Lilos Dynamics
Nairobi, Kenya
Data Protection Officer: [email protected]
Privacy & data requests: [email protected]
Security disclosures: [email protected]

If you are not satisfied with our response, you may lodge a complaint with the Office of the Data Protection Commissioner of Kenya (odpc.go.ke) or your local supervisory authority.

v1.1 . Effective 30 August 2026 . Document ID: BOUKD-LEGAL-PRIV-0001