thayu labs
LEGAL

Universal Privacy Policy

Effective: February 15, 2026 · Last updated: February 15, 2026

1. Introduction

At Thayu Labs Ltd (“we,” “us,” “our”), we are committed to protecting your privacy and personal data. This Privacy Policy explains how we collect, use, share, store, and protect your information when you use our mobile applications and related services, including but not limited to: Sentii, Thimo, Nyimbo Cia Ngai, Muse, Resonance, and any future applications we may publish (collectively, the “Services”).

This Privacy Policy is designed to comply with the Kenya Data Protection Act, 2019, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), the U.S. Children’s Online Privacy Protection Act (COPPA), Brazil’s Lei Geral de Proteção de Dados (LGPD), the UK Data Protection Act 2018, and the requirements of the Apple App Store and Google Play Store.

2. Information We Collect

2.1 Information You Provide Directly

2.2 Information Collected Automatically

2.3 Information from Third-Party Sources

3. How We Use Your Information

We process your information for the following purposes and corresponding legal bases:

PurposeLegal Basis (GDPR)
Provide and operate the ServicesContractual necessity
Create and manage your accountContractual necessity
Process payments and subscriptionsContractual necessity
Communicate with you (alerts, updates, support)Legitimate interest / Consent
Analyse usage patterns and improve our ServicesLegitimate interest
Personalise your experience and contentLegitimate interest / Consent
Display advertisementsConsent / Legitimate interest
Detect fraud, prevent abuse, and ensure securityLegitimate interest / Legal obligation
Comply with legal obligationsLegal obligation
Enforce our Terms of ServiceLegitimate interest

4. Advertising

Some of our Services display advertisements provided by third-party ad networks. These networks may use device identifiers, usage data, and other information to serve personalised ads. Our advertising partners may include:

Your Choices: You can opt out of personalised advertising by adjusting your device settings:

Where required by law (including under GDPR and Apple’s App Tracking Transparency framework), we will request your consent before enabling personalised advertising or cross-app tracking.

5. Data Sharing & Third-Party Services

We do not sell your personal information. We may share your data in the following limited circumstances:

All service providers are contractually obligated to protect your data and use it only for the purposes we specify.

6. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including countries that may not provide the same level of data protection. Where we transfer personal data from the European Economic Area (EEA), United Kingdom, or other regions with data transfer restrictions, we implement appropriate safeguards, including:

Firebase and Google services may process data in data centres located globally. For more information on Google’s data processing practices, visit Google’s privacy policy.

7. Cookies & Tracking Technologies

Our mobile apps and any associated web services may use the following technologies:

You can manage cookie preferences through your browser settings and tracking preferences through your device settings (see Section 4).

8. Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes described in this Privacy Policy and to comply with our legal obligations:

9. Data Security

We implement industry-standard technical and organisational measures to protect your personal data from unauthorised access, loss, misuse, alteration, or destruction. These measures include encryption of data in transit (TLS/SSL) and at rest, access controls, regular security assessments, and secure development practices.

While we strive to protect your data, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security.

10. Children’s Privacy

We take children’s privacy seriously and comply with the U.S. Children’s Online Privacy Protection Act (COPPA), the EU GDPR provisions regarding children’s data (Article 8), and the UK Age Appropriate Design Code.

11. Your Rights Under the Kenya Data Protection Act, 2019

If you are a Kenyan resident, you have the following rights under the Data Protection Act, 2019:

To exercise these rights, contact us at thayulabs@gmail.com. You may also lodge a complaint with the Office of the Data Protection Commissioner of Kenya at www.odpc.go.ke.

12. Your Rights Under the GDPR (EU/EEA/UK Users)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have the following rights under the General Data Protection Regulation:

Legal Bases for Processing: We process your data based on: (a) your consent; (b) the performance of a contract with you; (c) our legitimate interests (e.g., fraud prevention, service improvement); or (d) compliance with legal obligations. See the table in Section 3 for specific legal bases per purpose.

EU Representative: As a small business, we are currently in the process of appointing an EU representative. In the meantime, please direct any inquiries to thayulabs@gmail.com.

Data Protection Officer: For data protection inquiries, please contact us at thayulabs@gmail.com.

You may lodge a complaint with your local supervisory authority. A list of EU Data Protection Authorities is available at edpb.europa.eu.

13. Your Rights Under the CCPA/CPRA (California Residents)

If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA):

Categories of Personal Information Collected: Identifiers (name, email, phone, IP address, device IDs); internet or electronic network activity (usage data, browsing history within our apps); geolocation data (approximate); commercial information (purchase and subscription history); and inferences drawn from the above.

To exercise your rights, email us at thayulabs@gmail.com or use the in-app privacy settings where available. We will verify your identity before processing your request.

14. Users in Other Jurisdictions

Brazil (LGPD): If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados, including the right to access, correct, delete, and port your data. Contact us at thayulabs@gmail.com to exercise these rights.

Other Jurisdictions: We respect the privacy rights granted to you by the laws of your country of residence. If you have questions about your specific rights, please contact us.

15. Apple App Tracking Transparency (ATT)

On iOS 14.5 and later, we comply with Apple’s App Tracking Transparency framework. Before tracking your activity across apps and websites owned by other companies for advertising or sharing your data with data brokers, we will present the ATT prompt requesting your permission. You may change your preference at any time in Settings > Privacy & Security > Tracking.

If you opt out of tracking, we will not use your IDFA (Identifier for Advertisers) and will limit ad personalisation accordingly.

16. “Do Not Track” Signals

Some web browsers transmit “Do Not Track” (DNT) signals. At this time, there is no universally accepted standard for how to respond to DNT signals. However, where required by law (such as under the Global Privacy Control standard recognised by the CCPA), we will honour such signals as opt-out requests for the sale or sharing of personal information.

17. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. If we make material changes, we will notify you by posting the updated policy within our apps and, where practicable, by sending a notification at least 30 days before the changes take effect. The “Last Updated” date will be revised. Your continued use of the Services after the updated Privacy Policy takes effect constitutes your acceptance of the changes.

18. Contact Us

Thayu Labs Ltd
P.O. Box 6367–00100 GPO, Nairobi, Kenya
Email: thayulabs@gmail.com

For privacy-specific inquiries, please use the subject line “Privacy Inquiry” in your email.

For complaints under the Kenya Data Protection Act, you may contact the Office of the Data Protection Commissioner at www.odpc.go.ke.