Kylog Privacy Policy
Kylog Privacy Policy
Version: 1.0.0
Last updated: 12/09/2026
Effective date: 12/09/2026
1. Summary
This policy explains which personal data Kylog processes, what it uses it for, on what legal basis, for how long, with whom it may share it and how you can exercise your rights.
Kylog is a physical activity logging and planning application for people 18 years of age or older. It does not sell personal data, display advertising, send promotions or use workout history to make medical or advertising inferences.
2. Joint controllers
The joint controllers for Kylog’s own processing activities are:
- Bogdan Ionut Ciobanu Ciobanu, NIF/NIE 08132353J.
- Petru Alexandru Oprea, NIF/NIE X4325515C.
- Trade name: Kylog
- Common professional address: Avenida de Clara Campoamor Nr8, Portal 2, 1ºB, Loeches, Madrid, España
- General contact: support@babuin.dev
- Privacy and rights: legal@babuin.dev
Both jointly determine the essential purposes and means of processing and have agreed on their responsibilities in accordance with Article 26 of the GDPR. The common contact point is legal@babuin.dev, but you may exercise your rights against either of them. The internal distribution of tasks does not limit their obligations towards you.
No data protection officer has currently been appointed because, given the expected nature and scale of the service, one is not considered mandatory. This conclusion will be reviewed if the processing activities change.
3. Scope and sources of data
This policy applies to the Android and iOS apps, the backend, the Legal Center and Kylog’s public legal pages.
We obtain data:
- directly from you, when you register an account, configure the app or enter workouts;
- automatically from your device during operation, security and synchronization;
- from Google or Apple when you use their sign-in service; and
- from technical providers that report incidents, delivery statuses or security signals to us.
4. Data we process
4.1 Account and identity
- internal user identifier and Firebase UID;
- email address and verification status;
- display name and avatar when provided by the user or the sign-in provider;
- authentication provider used;
- session tokens and technical metadata managed by Firebase Authentication;
- IP addresses and user-agent that Firebase may process for authentication, security and abuse prevention.
Kylog does not store passwords in plain text. Firebase Authentication manages credentials in accordance with its security terms.
4.2 Preferences and device
- language, locale, time zone and preferred weight unit;
- random installation or client identifier;
- platform, app version and, when necessary, technical device name or model;
- synchronization status, record versions and timestamps;
- Firebase Installation identifiers and signals from App Check, Remote Config or equivalent services;
- notification token or identifier and its hash when functional alerts are used.
4.3 Routines and workouts
- routines, days, order and installed or custom exercises;
- names and descriptions of custom exercises;
- completed workouts, dates, duration and relationship with a routine;
- exercises, sets, repetitions, weight lifted, time, distance, rest periods, warm-up and completion status;
- titles, comments and free-text notes.
The weight lifted in a set forms part of the workout record. Kylog does not currently request or use height, date of birth, gender, experience level, body goal or independent body weight records.
4.4 Legal evidence
- document, version, language and action type;
- hashes of the content and of the statement displayed;
- decision regarding Analytics and declaration of legal age;
- server-set date and time;
- platform, app version, version code and technical request identifiers;
- cryptographic digest, signature and public key used to guarantee integrity;
- associated history and PDF receipts.
The current legal system does not need to store the IP address or user-agent within the new signed evidence.
4.5 Support, security and logs
- messages and data that you voluntarily send to support;
- request identifiers, date, route, response code and technical server log data;
- IP and network signals strictly necessary for security, diagnosis, abuse limitation and incident response;
- authentication events, administrative changes and audit trails.
You must never send passwords, tokens, medical data or third-party information in a support request.
4.6 Optional Analytics
Only after you have given your consent may Firebase Analytics process usage events, screens, interactions, app version, technical device properties, installation identifiers and approximate network-derived data according to the Firebase configuration. Kylog does not use Analytics for advertising, commercial personalization or in combination with the content of your workouts.
Analytics is disabled by default and you can withdraw your consent from Profile > Legal Center > Analytics. Withdrawal does not affect previous lawful processing and does not limit essential features.
4.7 Crash diagnostics
Firebase Crashlytics may process installation, session and crash identifiers; time; error traces; app version; operating system; device model, architecture, memory and storage; and technical signals such as root/jailbreak status. It is used to detect, prioritize and correct errors.
Kylog configures Crashlytics so that names, email addresses, tokens, notes, routines or workout content are not deliberately added to messages or custom keys. If we detect an accidental inclusion, we will restrict it and correct it.
4.8 Local photographs
When you select or take a photograph to share a summary, the image remains on your device and is delivered to the application you choose through the operating system. Kylog does not upload it to the backend, synchronize it or retain a remote copy.
Files that you save, export or share outside Kylog’s private storage remain under your control and that of the recipient application.
5. Data we do not intend to process
Kylog is not designed to collect:
- diagnoses, injuries, symptoms, treatments, medication or medical records;
- heart rate, blood pressure, sleep, nutrition, biometrics or other vital signs;
- data from Health Connect, Apple Health, wearables or medical devices;
- precise location, contact lists or social profiles;
- remote photographs or public social content;
- height, date of birth, gender or changes in body weight;
- payment card data, bank accounts, purchases, subscriptions or payment tokens; and
- data for advertising, direct marketing or commercial profiling.
Exercise histories are processed as personal data relating to ordinary physical activity, not for a medical purpose. We do not combine them to infer diseases, risks or health conditions. Do not enter medical information in free-text fields. If we receive unsolicited specially protected data, we will not use it for an additional purpose and may restrict or delete it.
If body metrics, sensors, healthcare purposes or health inferences are added in the future, a new legal and risk assessment will be conducted, this policy will be updated and explicit consent will be requested when required before the processing is enabled.
6. Purposes and legal bases
Purpose Main data Legal basis Create, authenticate and maintain the account Account, identity, session and configuration Performance of a contract, Art. 6.1.b GDPR Record and synchronize routines and workouts Workout content, identifiers and changes Performance of a contract, Art. 6.1.b GDPR Send requested reminders or functional alerts Installation, token, configuration and minimum technical content Performance of a contract and requested configuration, Art. 6.1.b GDPR; operating system permission Record terms, age and legal decisions Signed evidence, version and date Performance of a contract, legal compliance and legitimate interest in demonstrating obligations and defending claims, Arts. 6.1.b, 6.1.c and 6.1.f GDPR Security, abuse prevention and audit IP, logs, App Check, authentication and traces Legitimate interest in protecting the service and its users, Art. 6.1.f GDPR; legal obligation where applicable Detect and correct errors with Crashlytics Technical diagnostics and installation identifiers Legitimate interest in stability and security, Art. 6.1.f GDPR Measure use through Firebase Analytics Events and identifiers described Optional consent, Art. 6.1.a GDPR Handle support and rights Request, identity and necessary data Performance of a contract, legal obligation and legitimate interest depending on the request Comply with requests and defend claims Strictly necessary and blocked data Legal obligation and legitimate interest, Arts. 6.1.c and 6.1.f GDPRWhen we rely on legitimate interest, you may request information about the assessment performed and object on grounds relating to your particular situation. We will stop processing the data unless there are compelling legitimate grounds or it is necessary to establish, exercise or defend legal claims.
7. Required and optional information
The account, an authentication method, acceptance of the Terms and confirmation of legal age are necessary to provide Kylog. Without them, we cannot create or maintain access.
Specific workouts, notes, avatar and notifications depend on the features you choose to use. Analytics is entirely optional. Refusing or withdrawing Analytics does not limit essential features of the free service.
8. Recipients and providers
We do not sell or rent personal data. We only provide access when necessary to provide the service, comply with an obligation or protect rights.
8.1 Processors and technical providers
- OVH HISPANO S.L.U., for Virtual Private Server, hosted in Strasbourg (SBG) - France.
- Google LLC, Google Ireland Limited and Google Cloud EMEA Limited, depending on the service and applicable terms, for Firebase Authentication, App Check, Remote Config, Cloud Messaging, Crashlytics and, if the user consents, Google Analytics.
- Zoho, to host and deliver messages that you send to the support or privacy mailboxes.
These providers must process the data in accordance with instructions, contracts and appropriate measures when acting as processors.
8.2 Third parties acting under their own responsibility
Google Play and Apple/App Store may process the download, distribution, store security and their own accounts in accordance with their policies. Google and Apple may also act under their own terms when you choose their sign-in service. Review their notices before using these services.
8.3 Requests and exceptional operations
We may disclose data to courts, authorities or competent bodies where there is a valid obligation or request. If the project is legitimately reorganized or transferred, we will provide notice before a new controller uses data for incompatible purposes and will respect applicable rights.
9. International transfers
The main backend will be hosted in the EU/EEA by OVH HISPANO S.L.U.. However, some Google/Firebase services may process data in the United States or other countries where their subprocessors operate. Firebase Authentication operates on US infrastructure and other Firebase services may use global infrastructure.
Where a transfer outside the EEA occurs, we will use the applicable mechanism: an adequacy decision—including the EU-US Data Privacy Framework when the recipient and processing are covered—European Commission Standard Contractual Clauses and supplementary measures where necessary.
You may request information about the safeguards by writing to legal@babuin.dev.
10. Retention periods
Category Criterion or period Account, configuration, routines and workouts While the account remains open and they are necessary to provide the service; they are not automatically deleted due to inactivity Active data after requesting deletion Access is blocked and the data is deleted or anonymized without undue delay, in accordance with the technical flow Backups Rotation and deletion within a maximum of 30 days from deletion, except where there is a documented legal hold Minimum pseudonymized legal evidence Five years from deletion or termination of the relationship, blocked exclusively for liabilities; longer only in the event of an active legal hold Firebase Analytics 14 months for data associated with identifiers, subject to verified configuration; aggregated data may cease to be personal data Firebase Crashlytics 90 days before its removal from active systems and backups begins, in accordance with current Firebase informationWhere deletion applies, data may remain blocked in accordance with Article 32 of the LOPDGDD: isolated from operations and available only to judges, authorities or for liabilities during the limitation period. It will then be destroyed.
11. Security
We apply controls proportionate to risk, including authentication through Firebase, App Check, user and administrator access control, encrypted communications, DEV/production separation, backups, administrative auditing, minimization, signed legal evidence and external key management.
We review access and dependencies and have response and recovery procedures in place. No measure guarantees absolute security. If you detect a vulnerability or unauthorized access, contact support@babuin.dev without publicly disclosing details that increase the risk.
12. Automated decisions and profiling
Kylog does not make decisions based solely on automated processing that produce legal effects or significantly affect you. It does not score your health, ability, insurability, employability or risk. Functional workout metrics are not used for advertising or decisions about other people.
13. Your rights
You may request:
- access to your data and a copy;
- rectification of inaccurate data;
- erasure where applicable;
- restriction of processing;
- objection to processing based on legitimate interest;
- portability of the data you have provided and data generated through use where the legal requirements are met;
- withdrawal of consent at any time, without affecting previous processing; and
- not to be subject to decisions based solely on automated processing in the cases provided for by law.
Write to legal@babuin.dev, stating the right and the information necessary to locate your account. We may request proportionate identity verification, but we will not request more data than necessary.
Exercising these rights is free of charge unless requests are manifestly unfounded or excessive. We will normally respond within one month; if the complexity or number of requests requires an extension, we will inform you within the first month.
A comprehensive self-service download is not required. Where access or portability applies, we may provide a ZIP containing JSON/CSV through a secure channel. Any export tools that the app may offer are independent and never replace or condition the free exercise of rights.
You may also lodge a complaint with the Spanish Data Protection Agency or the competent supervisory authority of your place of residence or the place of the alleged infringement.
14. Minors
Kylog requires users to be 18 years of age. We record a declaration of legal age, not the date of birth. If you believe that a minor has created an account, write to legal@babuin.dev so that we can verify it and take proportionate measures.
15. Notifications and absence of marketing
Kylog does not use your data for promotions, offers or commercial communications. Notifications are reminders configured by you or functional, legal, security or service alerts. You can manage reminders and permissions from the app and operating system, without prejudice to essential in-app notices.
We do not sell audiences, use behavioral advertising or subscribe devices to commercial topics.
16. Legal portal and cookies
The public pages legal.babuin.dev and legal-dev.babuin.dev do not use Analytics, advertising or non-essential cookies. The server may generate technical security logs in accordance with section 4.6. The administrative panel uses strictly necessary authentication mechanisms and is not intended for the general public.
17. Changes to this policy
We will publish each version with a date, summary and stable URL. Relevant changes will be communicated within Kylog. The Privacy Policy is information about processing and is not generally “accepted”.
If a new optional purpose requires consent, it will be presented separately and disabled until you decide. A material change to the Terms may require new acceptance, but silence or inactivity will not create privacy consent.
You can view versions and receipts from the Legal Center.
18. Contact
- Privacy and rights: legal@babuin.dev
- Support: support@babuin.dev
- Professional address: Avenida de Clara Campoamor, Nr8, Portal 2, 1ºB, Loeches, Madrid, España.