1. Controller and contact
KYSTA is the controller for personal data processed through the KYSTA service. Privacy questions and requests can be sent to privacy@kysta.app.
2. Data KYSTA processes
- Identity and profile: device identity, display name, locale, timezone, profanity preference and optional verified email address.
- Tracking content: onboarding answers, selected goals, custom goals and activities, check-ins, measurements, daily reflections, notes, schedule choices and calculated progress.
- Potentially sensitive content: information you choose to record may reveal health, mental wellbeing, dependencies, sexuality, finances or other special-category information.
- Notifications: reminder preferences, timezone and web-push subscription details when notifications are enabled.
- Service and security: session identifiers, request and error metadata, IP address and user-agent data in security logs, support-access audit records, plan entitlement and voucher state.
3. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Provide identity, sync, goals, logging, receipts, exports and account controls | Performance of the service contract |
| Process sensitive information you deliberately choose to record | Explicit consent, which can be withdrawn |
| Send optional reminders and account email codes | Consent and performance of the requested service |
| Secure KYSTA, prevent abuse, diagnose failures and audit administrator support access | Legitimate interests in service security |
| Maintain legally required financial records | Legal obligation, where paid plans apply |
KYSTA does not use your tracking content for advertising and does not sell it. If consent is withdrawn, processing based on that consent stops; processing already performed lawfully is not retroactively invalidated.
4. Storage and retention
Profile and tracking data is retained while your KYSTA profile is active or until you delete it. Push subscription data is retained until notifications are disabled, the subscription expires, or the tracking profile is cleared. Expiring validation codes become unusable after their validity period.
Security and support audit records are retained only while needed to protect the service, investigate incidents, meet legal obligations or establish legal claims. Where immediate deletion from a backup is not technically possible, data is isolated from normal use and removed through the backup lifecycle.
5. Recipients and transfers
Data may be processed by infrastructure, database, email-delivery and web-push providers acting for KYSTA, and by authorised support personnel where access is necessary and audited. Only the data needed for each service is shared.
KYSTA prefers processing in the European Economic Area. If a provider processes data outside the EEA, KYSTA requires a lawful transfer mechanism such as an adequacy decision or approved contractual safeguards.
6. Cookies and device storage
The app uses strictly necessary session and CSRF protection mechanisms. It also keeps an effective-user-scoped offline working copy and an idempotent evidence outbox on your device so the app can remain useful through connection loss. Authentication secrets are not stored in browser storage.
The public landing page does not use advertising cookies, behavioural analytics or cross-site tracking. Hosting systems may process limited access logs for delivery and security.
7. Security
KYSTA uses HTTPS, scoped database access, audited administrator support sessions and field-level encryption for reflective notes and short-text context. No internet service can promise absolute security, so controls are reviewed and updated as the service changes.
8. Progress calculations and automated decisions
KYSTA automatically calculates progress, streaks, status messages and earned rewards from your saved evidence. These calculations are motivational product features; they do not make decisions that produce legal or similarly significant effects.
9. Your rights
Depending on the processing and applicable law, you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent at any time and lodge a complaint with the data protection authority where you live or work.
Profile details can be corrected in Profile. A machine-readable JSON backup and evidence CSV are available in Settings. The clear data control removes your tracking profile. You can also email privacy@kysta.app. Requests are handled without undue delay and normally within one month.
10. Children
KYSTA is not directed at children. Anyone below the digital-consent age that applies in their country should not use the service without valid parent or guardian authorisation.
11. Changes to this statement
Material changes will be dated and communicated in the app where appropriate. Earlier processing remains governed by the statement that applied at that time.
