Your data, explained plainly

Privacy statement

This statement applies to the KYSTA application and the public website at www.kysta.app. It explains what data is processed, why it is needed, how long it is kept, and the choices available to you.

Updated 27 July 2026 · payments

Short version

  • KYSTA does not sell personal data.
  • The public landing page does not use advertising or analytics trackers.
  • App data is used to provide your goals, check-ins, reflections, reminders, receipts, progress and rewards.
  • Reflective notes and short-text context are encrypted at rest.
  • You can export your linked data and clear your tracking profile from Settings.

1. Controller and contact

KYSTA, Dorpsweg 46A, 1697 KB Schellinkhout, the Netherlands, is the controller for personal data processed through the KYSTA service. KYSTA is registered with the Dutch Chamber of Commerce under number 89960017.

Privacy questions and requests can be sent to privacy@kysta.app. General product and account support is available at support@kysta.app.

2. Data KYSTA processes

  • Identity and profile: device identity, display name, locale, timezone, profanity preference and optional verified email address.
  • Tracking content: onboarding answers, selected goals, custom goals and activities, check-ins, measurements, daily reflections, notes, schedule choices and calculated progress.
  • Potentially sensitive content: information you choose to record may reveal health, mental wellbeing, dependencies, sexuality, finances or other special-category information.
  • Notifications: reminder preferences, timezone and web-push subscription details when notifications are enabled.
  • Service and security: session identifiers, request and error metadata, IP address and user-agent data in security logs, support-access audit records, plan entitlement and voucher state, plus the version and time of your legal document acceptance.
  • Billing and payment: billing country, verified account email, selected plan and billing period, Mollie customer, payment, mandate and subscription references, payment status, invoice number, amounts, VAT and service period. KYSTA does not receive or store your full bank or card details.

3. Purposes and legal bases

PurposeLegal basis
Provide identity, sync, goals, logging, receipts, exports and account controlsPerformance of the service contract
Process sensitive information you deliberately choose to recordExplicit consent, which can be withdrawn
Send optional reminders and account email codesConsent and performance of the requested service
Secure KYSTA, prevent abuse, diagnose failures and audit administrator support accessLegitimate interests in service security
Maintain legally required financial recordsLegal obligation, where paid plans apply
Start, administer and cancel a paid Plus subscription and make invoices availablePerformance of the subscription contract and legal obligations

KYSTA does not use your tracking content for advertising and does not sell it. If consent is withdrawn, processing based on that consent stops; processing already performed lawfully is not retroactively invalidated.

4. Storage and retention

Profile and tracking data is retained while your KYSTA profile is active or until you delete it. Push subscription data is retained until notifications are disabled, the subscription expires, or the tracking profile is cleared. Expiring validation codes become unusable after their validity period.

Security and support audit records are retained only while needed to protect the service, investigate incidents, meet legal obligations or establish legal claims. Where immediate deletion from a backup is not technically possible, data is isolated from normal use and removed through the backup lifecycle.

Invoices, payment references and related financial administration are normally retained for seven years where Dutch tax law requires it, including after a tracking profile or subscription is ended. Failed or abandoned checkout records are retained only as long as needed for reconciliation, security and dispute handling.

5. Recipients and transfers

Data may be processed by infrastructure, database, email-delivery and web-push providers acting for KYSTA, by Mollie as the payment service provider for paid subscriptions, and by authorised support personnel where access is necessary and audited. Mollie receives the verified account email, amount, currency, billing country and KYSTA payment references needed to complete and administer the transaction. Only the data needed for each service is shared.

KYSTA prefers processing in the European Economic Area. If a provider processes data outside the EEA, KYSTA requires a lawful transfer mechanism such as an adequacy decision or approved contractual safeguards.

6. Cookies and device storage

The app uses strictly necessary session and CSRF protection mechanisms. It also keeps an effective-user-scoped offline working copy and an idempotent evidence outbox on your device so the app can remain useful through connection loss. Authentication secrets are not stored in browser storage.

The public landing page does not use advertising cookies, behavioural analytics or cross-site tracking. Hosting systems may process limited access logs for delivery and security.

7. Security

KYSTA uses HTTPS, scoped database access, audited administrator support sessions and field-level encryption for reflective notes and short-text context. No internet service can promise absolute security, so controls are reviewed and updated as the service changes.

8. Progress calculations and automated decisions

KYSTA automatically calculates progress, streaks, status messages and earned rewards from your saved evidence. These calculations are motivational product features; they do not make decisions that produce legal or similarly significant effects.

9. Your rights

Depending on the processing and applicable law, you may request access, correction, erasure, restriction, portability, or object to processing. You may withdraw consent at any time and lodge a complaint with the data protection authority where you live or work.

Profile details can be corrected in Profile. A machine-readable JSON backup and evidence CSV are available in Settings. The clear data control removes your tracking profile. You can also email privacy@kysta.app. Requests are handled without undue delay and normally within one month.

10. Children

KYSTA is not directed at children. Anyone below the digital-consent age that applies in their country should not use the service without valid parent or guardian authorisation.

11. Changes to this statement

Material changes will be dated and communicated in the app where appropriate. Earlier processing remains governed by the statement that applied at that time.