Covers the two Android apps Topos Credit (demo) and Topos Pledge (demo), published on Google Play under the developer name Topos Network.
Effective 2026-09-19
Who we are
6THC OÜ (registry code 14371734), Sakala tn 22-17a, Tallinn, Estonia, is the data controller.
Privacy contact, and the address for every request below: dev@topos.network
What these apps are
- A demonstration for invited adult testers, by invitation only.
- All money in them is mock money. No real funds move, no real bank account is reached, no real credit is granted, and nothing you do creates a real financial obligation.
- The identity check accepts any photo and compares it to nothing. We recommend you do not photograph a real ID.
What we collect
What you enter in an app:
- your first and last name, and your phone number;
- a PIN, kept only as a salted hash;
- which terms and agreements you accepted, and when;
- for the identity check, a document photo and a selfie; in Topos Pledge, a source of funds band from a fixed list. We run no face matching, no liveness check and no other biometric processing on these photos;
- if you link an account for the demonstration, the account holder's name and the last four characters of the account identifier; the full identifier is not kept;
- if you invite somebody to back your credit, that person's phone number.
What the demonstration creates: your mock wallet and transactions, credit requests, backings, loans, repayments, and the event and audit logs of those. They carry your name and a reference derived from it.
From your device: the camera, when you take the identity check photos. Biometric unlock, if you enable it, is handled by Android and the app does not receive your fingerprint or face. If push notifications are switched on, a Firebase Cloud Messaging token for your app install.
To give you access: the Google account email you gave to join the test, held in the tester list in the Google Play Console and used to let you install the apps.
The apps do not collect location, contacts, SMS or call logs, or advertising identifiers, and carry no advertising, analytics or crash reporting.
On your phone, in the app's encrypted storage: a sign-in session, your name and phone number, the PIN hash and your display preferences. No balances or transaction history. Clearing the app's data removes them.
Why we use it, and on what basis
- To run the demonstration and your demo account - signing you in, showing your mock wallet and credit, letting testers find each other by phone number, and letting an operator act for the institution: performance of our agreement with you as a tester, GDPR Article 6(1)(b).
- To show the demonstration to audiences, and to reach a person you invite as a backer: our legitimate interest in demonstrating and testing the product, Article 6(1)(f). You can object at dev@topos.network.
Providing your name, phone number and identity check is needed to take part; without them we cannot give you a demo account.
We do not sell your data and do not use it for marketing. We make no automated decisions producing legal or similarly significant effects.
Who can see it
- The team operating the demonstration, through its operator consoles.
- People a demonstration is shown to. The demonstration is presented to audiences, and the consoles show testers' names, phone numbers and mock activity on screen. Please sign up with this in mind.
- Another tester you transact with sees your name and phone number.
- Amazon Web Services, which hosts the demonstration and its backups, and Google, which distributes the apps and, if push is switched on, delivers notifications. Google handles your Google account and your Play installs under its own privacy policy.
Our servers and backups are in the EU (Stockholm, Sweden). Google and AWS are US-parented, and access from outside the EEA may occur in the course of their services, under the safeguards in their data processing terms (the EU standard contractual clauses or the EU-US Data Privacy Framework).
How long we keep it
- The demonstration is reset regularly. A reset deletes the accounts testers created, with their sign-in details, identity check records, linked accounts and device tokens; a full reset deletes everything, mock transactions included.
- Backups are taken from time to time and deleted by hand. A backup taken before a reset or an erasure still holds what was there at the time, until it is deleted.
- The tester list is kept until you leave the test or the test ends.
Deleting your account and data
To have your Topos Credit (demo) or Topos Pledge (demo) account and its data deleted, email dev@topos.network with the phone number you signed up with. We close the account and:
- delete your sign-in details, identity check photos and records, linked accounts and device token;
- anonymise your name and phone number on the account and on every backing or credit you took part in;
- keep, so that a ledger balances and a record of what you accepted survives the account, your mock transactions, those records, and the system's event and audit logs. These can carry the reference derived from your name, and entries written before the erasure can carry your name. They go at the next full reset.
Tell us in the same email if you also want off the tester list.
Your rights
Under the GDPR you may ask us for access to your data, a copy of it, its correction, its erasure, a restriction of its use, its portability, and you may object to processing based on our legitimate interests. Write to dev@topos.network. You may also complain to the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, [aki.ee](https://www.aki.ee)) or to the authority where you live.
Security
HTTPS between the apps and our server, encrypted server disks, PINs kept as salted hashes, and server and console access limited to the team operating the demonstration.
Children
For invited adult testers only. Not directed at anyone under 18.
Changes
A change is published at this address with a new effective date.
6THC OÜ, company number 14371734
Estonia, Sakala tn 22-17a, 10141 Tallinn