Your data, explained plainly

Privacy statement

This statement applies to the KYSTA application and the public website at kysta.app. It explains what data is processed, why it is needed, how long it is kept, and the choices available to you.

Updated 25 July 2026

Short version

  • KYSTA does not sell personal data.
  • The public landing page does not use advertising or analytics trackers.
  • App data is used to provide your goals, check-ins, reflections, reminders, receipts, progress and rewards.
  • Reflective notes and short-text context are encrypted at rest.
  • You can export your linked data and clear your tracking profile from Settings.

1. Controller and contact

KYSTA is the controller for personal data processed through the KYSTA service. Privacy questions and requests can be sent to privacy@kysta.app.

2. Data KYSTA processes

  • Identity and profile: device identity, display name, locale, timezone, profanity preference and optional verified email address.
  • Tracking content: onboarding answers, selected goals, custom goals and activities, check-ins, measurements, daily reflections, notes, schedule choices and calculated progress.
  • Potentially sensitive content: information you choose to record may reveal health, mental wellbeing, dependencies, sexuality, finances or other special-category information.
  • Notifications: reminder preferences, timezone and web-push subscription details when notifications are enabled.
  • Service and security: session identifiers, request and error metadata, IP address and user-agent data in security logs, support-access audit records, plan entitlement and voucher state.

3. Purposes and legal bases

PurposeLegal basis
Provide identity, sync, goals, logging, receipts, exports and account controlsPerformance of the service contract
Process sensitive information you deliberately choose to recordExplicit consent, which can be withdrawn
Send optional reminders and account email codesConsent and performance of the requested service
Secure KYSTA, prevent abuse, diagnose failures and audit administrator support accessLegitimate interests in service security
Maintain legally required financial recordsLegal obligation, where paid plans apply

KYSTA does not use your tracking content for advertising and does not sell it. If consent is withdrawn, processing based on that consent stops; processing already performed lawfully is not retroactively invalidated.

4. Storage and retention

Profile and tracking data is retained while your KYSTA profile is active or until you delete it. Push subscription data is retained until notifications are disabled, the subscription expires, or the tracking profile is cleared. Expiring validation codes become unusable after their validity period.

Security and support audit records are retained only while needed to protect the service, investigate incidents, meet legal obligations or establish legal claims. Where immediate deletion from a backup is not technically possible, data is isolated from normal use and removed through the backup lifecycle.

5. Recipients and transfers

Data may be processed by infrastructure, database, email-delivery and web-push providers acting for KYSTA, and by authorised support personnel where access is necessary and audited. Only the data needed for each service is shared.

KYSTA prefers processing in the European Economic Area. If a provider processes data outside the EEA, KYSTA requires a lawful transfer mechanism such as an adequacy decision or approved contractual safeguards.

6. Cookies and device storage

The app uses strictly necessary session and CSRF protection mechanisms. It also keeps an effective-user-scoped offline working copy and an idempotent evidence outbox on your device so the app can remain useful through connection loss. Authentication secrets are not stored in browser storage.

The public landing page does not use advertising cookies, behavioural analytics or cross-site tracking. Hosting systems may process limited access logs for delivery and security.

7. Security

KYSTA uses HTTPS, scoped database access, audited administrator support sessions and field-level encryption for reflective notes and short-text context. No internet service can promise absolute security, so controls are reviewed and updated as the service changes.

8. Progress calculations and automated decisions

KYSTA automatically calculates progress, streaks, status messages and earned rewards from your saved evidence. These calculations are motivational product features; they do not make decisions that produce legal or similarly significant effects.

9. Your rights

Depending on the processing and applicable law, you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent at any time and lodge a complaint with the data protection authority where you live or work.

Profile details can be corrected in Profile. A machine-readable JSON backup and evidence CSV are available in Settings. The clear data control removes your tracking profile. You can also email privacy@kysta.app. Requests are handled without undue delay and normally within one month.

10. Children

KYSTA is not directed at children. Anyone below the digital-consent age that applies in their country should not use the service without valid parent or guardian authorisation.

11. Changes to this statement

Material changes will be dated and communicated in the app where appropriate. Earlier processing remains governed by the statement that applied at that time.