Saltar al contenido
Kylog · Babuin

Versión 1.0.0

Kylog Privacy Policy

Kylog Privacy Policy

Version: 1.0.0

Last updated: 12/09/2026

Effective date: 12/09/2026

1. Summary

This policy explains which personal data Kylog processes, what it uses it for, on what legal basis, for how long, with whom it may share it and how you can exercise your rights.

Kylog is a physical activity logging and planning application for people 18 years of age or older. It does not sell personal data, display advertising, send promotions or use workout history to make medical or advertising inferences.

2. Joint controllers

The joint controllers for Kylog’s own processing activities are:

  1. Bogdan Ionut Ciobanu Ciobanu, NIF/NIE 08132353J.
  2. Petru Alexandru Oprea, NIF/NIE X4325515C.

Both jointly determine the essential purposes and means of processing and have agreed on their responsibilities in accordance with Article 26 of the GDPR. The common contact point is legal@babuin.dev, but you may exercise your rights against either of them. The internal distribution of tasks does not limit their obligations towards you.

No data protection officer has currently been appointed because, given the expected nature and scale of the service, one is not considered mandatory. This conclusion will be reviewed if the processing activities change.

3. Scope and sources of data

This policy applies to the Android and iOS apps, the backend, the Legal Center and Kylog’s public legal pages.

We obtain data:

4. Data we process

4.1 Account and identity

Kylog does not store passwords in plain text. Firebase Authentication manages credentials in accordance with its security terms.

4.2 Preferences and device

4.3 Routines and workouts

The weight lifted in a set forms part of the workout record. Kylog does not currently request or use height, date of birth, gender, experience level, body goal or independent body weight records.

4.4 Legal evidence

The current legal system does not need to store the IP address or user-agent within the new signed evidence.

4.5 Support, security and logs

You must never send passwords, tokens, medical data or third-party information in a support request.

4.6 Optional Analytics

Only after you have given your consent may Firebase Analytics process usage events, screens, interactions, app version, technical device properties, installation identifiers and approximate network-derived data according to the Firebase configuration. Kylog does not use Analytics for advertising, commercial personalization or in combination with the content of your workouts.

Analytics is disabled by default and you can withdraw your consent from Profile > Legal Center > Analytics. Withdrawal does not affect previous lawful processing and does not limit essential features.

4.7 Crash diagnostics

Firebase Crashlytics may process installation, session and crash identifiers; time; error traces; app version; operating system; device model, architecture, memory and storage; and technical signals such as root/jailbreak status. It is used to detect, prioritize and correct errors.

Kylog configures Crashlytics so that names, email addresses, tokens, notes, routines or workout content are not deliberately added to messages or custom keys. If we detect an accidental inclusion, we will restrict it and correct it.

4.8 Local photographs

When you select or take a photograph to share a summary, the image remains on your device and is delivered to the application you choose through the operating system. Kylog does not upload it to the backend, synchronize it or retain a remote copy.

Files that you save, export or share outside Kylog’s private storage remain under your control and that of the recipient application.

5. Data we do not intend to process

Kylog is not designed to collect:

Exercise histories are processed as personal data relating to ordinary physical activity, not for a medical purpose. We do not combine them to infer diseases, risks or health conditions. Do not enter medical information in free-text fields. If we receive unsolicited specially protected data, we will not use it for an additional purpose and may restrict or delete it.

If body metrics, sensors, healthcare purposes or health inferences are added in the future, a new legal and risk assessment will be conducted, this policy will be updated and explicit consent will be requested when required before the processing is enabled.

6. Purposes and legal bases

Purpose Main data Legal basis Create, authenticate and maintain the account Account, identity, session and configuration Performance of a contract, Art. 6.1.b GDPR Record and synchronize routines and workouts Workout content, identifiers and changes Performance of a contract, Art. 6.1.b GDPR Send requested reminders or functional alerts Installation, token, configuration and minimum technical content Performance of a contract and requested configuration, Art. 6.1.b GDPR; operating system permission Record terms, age and legal decisions Signed evidence, version and date Performance of a contract, legal compliance and legitimate interest in demonstrating obligations and defending claims, Arts. 6.1.b, 6.1.c and 6.1.f GDPR Security, abuse prevention and audit IP, logs, App Check, authentication and traces Legitimate interest in protecting the service and its users, Art. 6.1.f GDPR; legal obligation where applicable Detect and correct errors with Crashlytics Technical diagnostics and installation identifiers Legitimate interest in stability and security, Art. 6.1.f GDPR Measure use through Firebase Analytics Events and identifiers described Optional consent, Art. 6.1.a GDPR Handle support and rights Request, identity and necessary data Performance of a contract, legal obligation and legitimate interest depending on the request Comply with requests and defend claims Strictly necessary and blocked data Legal obligation and legitimate interest, Arts. 6.1.c and 6.1.f GDPR

When we rely on legitimate interest, you may request information about the assessment performed and object on grounds relating to your particular situation. We will stop processing the data unless there are compelling legitimate grounds or it is necessary to establish, exercise or defend legal claims.

7. Required and optional information

The account, an authentication method, acceptance of the Terms and confirmation of legal age are necessary to provide Kylog. Without them, we cannot create or maintain access.

Specific workouts, notes, avatar and notifications depend on the features you choose to use. Analytics is entirely optional. Refusing or withdrawing Analytics does not limit essential features of the free service.

8. Recipients and providers

We do not sell or rent personal data. We only provide access when necessary to provide the service, comply with an obligation or protect rights.

8.1 Processors and technical providers

These providers must process the data in accordance with instructions, contracts and appropriate measures when acting as processors.

8.2 Third parties acting under their own responsibility

Google Play and Apple/App Store may process the download, distribution, store security and their own accounts in accordance with their policies. Google and Apple may also act under their own terms when you choose their sign-in service. Review their notices before using these services.

8.3 Requests and exceptional operations

We may disclose data to courts, authorities or competent bodies where there is a valid obligation or request. If the project is legitimately reorganized or transferred, we will provide notice before a new controller uses data for incompatible purposes and will respect applicable rights.

9. International transfers

The main backend will be hosted in the EU/EEA by OVH HISPANO S.L.U.. However, some Google/Firebase services may process data in the United States or other countries where their subprocessors operate. Firebase Authentication operates on US infrastructure and other Firebase services may use global infrastructure.

Where a transfer outside the EEA occurs, we will use the applicable mechanism: an adequacy decision—including the EU-US Data Privacy Framework when the recipient and processing are covered—European Commission Standard Contractual Clauses and supplementary measures where necessary.

You may request information about the safeguards by writing to legal@babuin.dev.

10. Retention periods

Category Criterion or period Account, configuration, routines and workouts While the account remains open and they are necessary to provide the service; they are not automatically deleted due to inactivity Active data after requesting deletion Access is blocked and the data is deleted or anonymized without undue delay, in accordance with the technical flow Backups Rotation and deletion within a maximum of 30 days from deletion, except where there is a documented legal hold Minimum pseudonymized legal evidence Five years from deletion or termination of the relationship, blocked exclusively for liabilities; longer only in the event of an active legal hold Firebase Analytics 14 months for data associated with identifiers, subject to verified configuration; aggregated data may cease to be personal data Firebase Crashlytics 90 days before its removal from active systems and backups begins, in accordance with current Firebase information

Where deletion applies, data may remain blocked in accordance with Article 32 of the LOPDGDD: isolated from operations and available only to judges, authorities or for liabilities during the limitation period. It will then be destroyed.

11. Security

We apply controls proportionate to risk, including authentication through Firebase, App Check, user and administrator access control, encrypted communications, DEV/production separation, backups, administrative auditing, minimization, signed legal evidence and external key management.

We review access and dependencies and have response and recovery procedures in place. No measure guarantees absolute security. If you detect a vulnerability or unauthorized access, contact support@babuin.dev without publicly disclosing details that increase the risk.

12. Automated decisions and profiling

Kylog does not make decisions based solely on automated processing that produce legal effects or significantly affect you. It does not score your health, ability, insurability, employability or risk. Functional workout metrics are not used for advertising or decisions about other people.

13. Your rights

You may request:

Write to legal@babuin.dev, stating the right and the information necessary to locate your account. We may request proportionate identity verification, but we will not request more data than necessary.

Exercising these rights is free of charge unless requests are manifestly unfounded or excessive. We will normally respond within one month; if the complexity or number of requests requires an extension, we will inform you within the first month.

A comprehensive self-service download is not required. Where access or portability applies, we may provide a ZIP containing JSON/CSV through a secure channel. Any export tools that the app may offer are independent and never replace or condition the free exercise of rights.

You may also lodge a complaint with the Spanish Data Protection Agency or the competent supervisory authority of your place of residence or the place of the alleged infringement.

14. Minors

Kylog requires users to be 18 years of age. We record a declaration of legal age, not the date of birth. If you believe that a minor has created an account, write to legal@babuin.dev so that we can verify it and take proportionate measures.

15. Notifications and absence of marketing

Kylog does not use your data for promotions, offers or commercial communications. Notifications are reminders configured by you or functional, legal, security or service alerts. You can manage reminders and permissions from the app and operating system, without prejudice to essential in-app notices.

We do not sell audiences, use behavioral advertising or subscribe devices to commercial topics.

16. Legal portal and cookies

The public pages legal.babuin.dev and legal-dev.babuin.dev do not use Analytics, advertising or non-essential cookies. The server may generate technical security logs in accordance with section 4.6. The administrative panel uses strictly necessary authentication mechanisms and is not intended for the general public.

17. Changes to this policy

We will publish each version with a date, summary and stable URL. Relevant changes will be communicated within Kylog. The Privacy Policy is information about processing and is not generally “accepted”.

If a new optional purpose requires consent, it will be presented separately and disabled until you decide. A material change to the Terms may require new acceptance, but silence or inactivity will not create privacy consent.

You can view versions and receipts from the Legal Center.

18. Contact