Version 1.0 · 24 September 2026 · current

Versions: 1.0 (24 September 2026), current

KEDA PRIVACY POLICY

Version 1.0 — 24 September 2026

English translation of the Spanish original. If there is any discrepancy between the two versions, the Spanish version prevails, without prejudice to the rights granted to consumers by applicable law.

1. Introduction

KEDA is a social app owned by On Project Labs, S.L. that lets its users create, organise, discover and share leisure plans with other people. In this Privacy Policy we explain, clearly and accessibly, what personal data we process, for what purpose, on what legal basis, who we share it with and what rights you can exercise over it, in accordance with Regulation (EU) 2016/679 (GDPR) and Spanish Organic Law 3/2018 on the Protection of Personal Data and the guarantee of digital rights (LOPDGDD).

We recommend reading this policy before registering and before activating features such as geolocation, and consulting it whenever you have questions about how your data is processed.

2. Who is the data controller?

  • Company name: On Project Labs, S.L.

  • Tax ID: ESB55466650

  • Registered office: Calle Sierra Nevada, 2, 18210 Peligros (Granada), Spain

  • Data protection contact: hola@keda.social

As at the date of this policy, On Project Labs, S.L. has not appointed a Data Protection Officer (DPO). We have external specialist data protection advice, which validates decisions with implications in this area and reviews this documentation, although that does not constitute a formal appointment for the purposes of articles 37 to 39 GDPR. We will review this decision before launching to real users, and again when the volume of use of the service justifies it, in accordance with the criteria in article 37 GDPR and article 34 LOPDGDD; we will update this policy if any appointment is made. Any question relating to the protection of your data can in any event be sent to the contact channel indicated above.

3. What personal data do we process?

3.1. Account and identification data

  • Registration data: username, email address, date of birth (used to verify the minimum age: if the date given corresponds to a person under 18, you will not be able to complete your profile or use KEDA), password (stored encrypted), country and city, and email verification status. We also store your display name (different from your username), whether your account is set to public or private, and the date you last changed your username.

  • How you came to KEDA: during sign-up you can voluntarily tell us which other KEDA user invited you to join and through which channel you heard about the app. Neither piece of information is required to complete registration. The inviter data is not free text but a link between your account and that person's account: if you provide it, their account is flagged as such within your record. We do not publicly show, either to that person or to third parties, who has flagged whom.

  • Phone number: only if we activate the prize-draw system in the future and you choose to take part in a mission that requires verifying your number by SMS code. This feature is not active as at the date of this policy: while it is not, no number is requested, no SMS is sent and no phone number is stored.

3.2. Public profile and network of contacts

  • Profile: profile photograph (avatar), bio, links to your social networks, interests, verification level or badges.

  • Kudos between users: within a plan you can recognise another participant with a kudo. We record who gives a kudo, to whom and in which plan. We do not publicly show who gave each kudo, but this data is not anonymous: if the plan has few participants — particularly when there are only two people — whoever receives a kudo can work out with certainty who gave it, by simple elimination. It is therefore pseudonymised and potentially re-identifiable data, and we treat it as such.

  • Network of contacts and social activity: your followers and the people you follow; blocks between users, with their history of blocks and unblocks and the reason given; who has viewed each of your stories and when; reactions to stories and posts and likes on comments; and your activity within plans — requests to join, waiting list, invitations, and removals with their reason.

  • Attendance and reliability: your advance confirmation of attendance at a plan, cancellation and its reason, the check-in status (by QR code or by location) with the coordinates and distance to the plan location at the time of checking in, and the attendance you declare yourself. From this we calculate an attendance score and reputation points, together with the number of verified attendances, no-shows and last-minute cancellations.

3.3. Content you generate, including private messages

  • Plans and posts: title, description, dates, category and location of the plans you create; wall posts; stories, whose visibility to other users expires automatically 24 hours after being posted (the file remains associated with your account while it is active, so that in future you can look back at your own past stories; no one else can see them after that period).

  • Messaging: plan chat messages and direct (private) messages between users, as well as mentions and saved content.

  • Media: photos, videos and voice notes you attach to messages, plans, posts or stories, stored in private repositories with restrictions on the file types accepted.

We treat your direct messages with the same confidentiality as the rest of your private content, and their content is never shared with users other than the recipient. We want to be precise, however, about where that content reaches: in addition to the moderation providers described in section 3.5 and in section 7, an excerpt of up to 50 characters of the message travels to our push notification provider (Expo) within the alert sent to the recipient's device, both for direct messages and for plan chat messages. That is what allows the recipient to see a preview of the message without opening the app.

3.4. Geolocation

  • Reference location ("home"): with your prior consent, we process a reference location in order to show you content and plans within a given radius. We apply the minimum level of precision necessary for that purpose and we do not reveal your exact position to other users. If you request deletion of your account, this data is deleted immediately, without waiting for the recovery period described in section 6.

  • Plan location: latitude, longitude and city of the plans you create or join, so that they can be displayed and filtered by proximity.

  • Your position at the moment you use Discover: when you search for nearby plans or open the map, the app reads the position given by the device GPS, with the precision it offers, and sends it to our server to calculate distances and order the results. That position is not stored in any database: it is used at that moment and discarded. The minimum precision level referred to in the paragraph above applies to your reference location, not to this one.

  • Check-in location: if you confirm your attendance at a plan using your location, we store the coordinates at that moment and the distance to the plan location.

When you choose your reference location, a plan location or a city, the coordinates are sent to the geocoding service of your device's own operating system — Apple's on iPhone and Google's on Android — to obtain the city or address in return. We do not control that service.

You can withdraw the location permission at any time from your device settings. The app does not have a setting of its own for this. You can replace your reference location with another from your profile at any time; if you want to delete it without deleting your account, write to us at hola@keda.social and we will do it.

3.5. Automated content moderation and security data

  • Automated moderation: the text and images of plans, posts, comments and stories are analysed automatically before being published; for videos, a representative image is analysed. Your profile data — name, bio, photograph and links — and the text of plan chat messages are not analysed automatically. In direct and chat messages we analyse the images you send and a representative image of each video; voice notes are not analysed, and the text of your messages is only analysed if you or another user expressly reports it. Section 7 identifies the providers that carry out this analysis.

  • Behaviour when the analysis provider is unavailable: images and videos are not published and the analysis is retried; text entered during account sign-up is published and queued for later review; text in any other case waits until the analysis can be carried out.

  • Automatic classification of plans: if you do not choose a category when creating a plan, we send its title, description and area to an artificial intelligence model that assigns it a category and tags, so that it can be shown to people looking for plans of that kind.

  • Security data: breaches recorded on your account, the status and reason for any suspension, automatic hiding of content by volume of reports (see below), and reports you make or that other users submit about your account, your content or your messages (who reports, about whom, reason, description and action taken).

In addition to automated AI moderation, a plan, a post or a story is hidden automatically upon reaching 5 reports from other users, and a comment upon reaching 3, regardless of whether our moderation systems have analysed that content. This is a precautionary and reversible measure, not a confirmed sanction.

This activity has been the subject of a Data Protection Impact Assessment (DPIA), which confirms that it is necessary given the nature of the private messages analysed. We use OpenAI moderation services and artificial intelligence models as our main provider: a specific moderation service for text, and a general-purpose model for images and for classifying plans. If OpenAI is unavailable, we use Anthropic's Claude model as an alternative, with the same minimisation and confidentiality safeguards; in the case of images, Anthropic receives the file itself.

Where automated moderation requires human intervention, the review is carried out by authorised On Project Labs staff from an internal administration panel, with restricted access and subject to a duty of confidentiality. The person reviewing accesses the account data needed to resolve the case — your username, your profile photograph, your email address and your history of previous breaches, which is essential in order to assess whether a tiered suspension applies — and not other account data of yours that is not needed to resolve it. Your email address is not shown on content moderation screens: it remains hidden and is only revealed where the specific task requires it. A record is kept of who opens a case file of yours and when, in these four situations: opening your user record, opening a report about content of yours, reading the text of a report about a message, and reading the text of an appeal. That record is kept for 12 months.

Where an account or a message is deleted from that panel, the internal record of that action keeps a copy of the data affected, as evidence of what was deleted and why.

We keep an internal record of the suspensions we apply, including those applied automatically by the system, with their reason, their origin and their duration, so that we can justify them if you appeal or if an authority asks us about them. Whenever we suspend your account or hide content of yours we will tell you the reason and, where the decision was made automatically, we will say so expressly.

If an automated suspension decision affects you, you can ask from within the app for a person to review it, and we will resolve it within a maximum of 3 working days, Monday to Friday, and you will be able to check the outcome in the app itself. If what has been hidden is content of yours, you can write to us at hola@keda.social and a person will review it, with the possibility of restoring it; in that case we do not set a maximum response time. In both cases, whoever deals with your request will access only the information strictly necessary to resolve it.

3.6. Technical and session data

  • Session: IP address and user agent, recorded in your session and also in the logs our infrastructure generates for each request to the server. Those logs also include the approximate city and country inferred from your IP address.

  • Device: the make, model or name of your device, its operating system and the app version. If the app crashes, the incident report also includes the system version, the screen where it happened, the technical error trace, whether it is a real device or an emulator, and any comment you choose to write.

  • Activity within the app: your usage sessions, with their start, end, duration and the screens you visit; usage events such as opening the app, sending it to the background, viewing a plan, sharing it, or giving and removing kudos; the text of what you search for in Discover, together with the city, country, radius, filters, language and number of results; and your interactions in Discover, which include whether you swipe one way or the other, how long you look at each plan, the speed of the gesture and its position within the session.

  • Technical logs of service use: each call to the artificial intelligence services and each file upload leaves a record associated with your account, with the content affected or the file path, the provider and the cost, which we use to control spending and the security of the service.

  • Push notifications: your device token, managed through our push notification provider (Expo), needed to send you alerts about your plans, messages or service news.

3.7. Data arising from in-app purchases

  • In-app purchases: in-app purchases, currently limited to promoting plans, are handled through the Apple App Store, using the RevenueCat platform, and through Google Play when available.

We never store the full details of your payment method; these are handled directly by the platforms indicated, which act as processors. We send RevenueCat your internal user identifier and the identifier of the promotion campaign purchased.

3.8. Data we receive from third parties or other users

If another user mentions you, adds you to a plan, gives you a kudo, shares content you appear in, or names you as the person who invited them to join KEDA, we may process that information to the extent it relates to you.

In the specific case of the inviter data, what is recorded is a link between that person's account and yours. It is not publicly displayed or disclosed to other users, and it disappears in both directions when either account is deleted, as detailed in section 6.

3.9. Data you provide through the website contact form

If you write to us through the contact form at keda.social, we process your name, email address and the content of your message in order to reply to you.

Purpose Legal basis
Creating and managing your account, and providing the service (creating plans, joining plans, messaging) Performance of a contract (art. 6.1.b GDPR)
Showing you nearby content and plans through geolocation Consent, which can be withdrawn at any time (art. 6.1.a GDPR)
Sending you verification codes (OTP) and service communications by email Performance of a contract (art. 6.1.b GDPR)
Knowing which person and which channel new users come to KEDA through (inviter and acquisition channel data in section 3.1) Legitimate interest in understanding and growing the community (art. 6.1.f GDPR)
Automatically moderating content and messages to detect breaches Legitimate interest, and where applicable a legal obligation regarding the protection of minors (arts. 6.1.f and 6.1.c GDPR)
Handling reports between users and applying suspension or content-hiding measures, including appeals against them Legitimate interest, and where applicable a legal obligation (arts. 6.1.f and 6.1.c GDPR)
Recognising other users through kudos/badges within a plan Performance of a contract (art. 6.1.b GDPR), as part of the app's social functionality
Processing in-app purchases Performance of a contract and compliance with tax and accounting obligations (arts. 6.1.b and 6.1.c GDPR)
Sending you push notifications relating to the service Performance of a contract / legitimate interest (arts. 6.1.b and 6.1.f GDPR)
Verifying your identity by SMS when taking part in a prize-draw mission — feature planned, not active as at the date of this policy Performance of a contract / consent (arts. 6.1.a and 6.1.b GDPR)
Showing you our own or third-party advertising and commercial communications — feature planned, not active as at the date of this policy Consent (art. 6.1.a GDPR), which will be obtained before activating the feature
Running user acquisition advertising campaigns on Instagram and TikTok Legitimate interest (art. 6.1.f GDPR)
Ensuring the security of the service and preventing fraud or misuse Legitimate interest (art. 6.1.f GDPR)
Responding to your enquiries through the website contact form Legitimate interest in dealing with your request / consent (arts. 6.1.f and 6.1.a GDPR)
Handling support requests and the exercise of rights Compliance with a legal obligation / performance of a contract
Personalising and ordering the content and plans we show you on Home and Discover, based on your declared interests, your activity in the app — the gestures and the time you spend on each plan over the last 30 days, and the plans you dismiss —, your city and distance, and the people you follow Legitimate interest in offering a useful service (art. 6.1.f GDPR), with a right to object
Calculating an attendance and reputation score for each user from their verified attendances, no-shows and last-minute cancellations, and using it to give more or less visibility to the plans they organise Legitimate interest in the reliability of the meet-ups organised through KEDA (art. 6.1.f GDPR), with a right to object
Automatically classifying plans by category when the creator does not choose one Legitimate interest in plans reaching the people looking for them (art. 6.1.f GDPR)
Analysing use of the app to improve the service: active users, session length, most frequent and unsuccessful searches, plans by city, and notification delivery Legitimate interest (art. 6.1.f GDPR), with a right to object
Diagnosing and fixing technical errors from incident reports Legitimate interest (art. 6.1.f GDPR)
Complying with requests from competent authorities Legal obligation (art. 6.1.c GDPR)
Reporting to the competent authorities facts that may constitute a criminal offence, in particular those affecting a minor or amounting to a threat to someone's life or safety Legal obligation (art. 6.1.c GDPR), in conjunction with articles 259 and 262 of the Spanish Criminal Procedure Act, with Organic Law 8/2021 on the comprehensive protection of children and adolescents against violence, and with article 18 of Regulation (EU) 2022/2065 on Digital Services. Where the data falls within special categories, articles 9.2.f and 9.2.g GDPR

As regards the purposes based on our legitimate interest, you have the right to object at any time. The app does not yet offer a toggle for this, so today the route is to write to us at hola@keda.social, except for push notifications, which you can turn off from your device settings. If you object to personalisation, we will still show you plans, but ordered by general criteria rather than by your activity.

Two of these purposes involve building a profile about you: the one that orders what you see based on your activity, and the one that assesses your reliability as an organiser. Neither produces legal effects or similarly significantly affects you — they do not decide whether you can use KEDA, and they do not sanction you — but we prefer to declare them clearly because they influence what you see and how many people see what you organise. Among the plans we show you there are also plans whose creators have paid to promote them, identified as such.

5. Minors

Use of KEDA is restricted to people over 18. During registration we ask for your date of birth, which you declare yourself and which we do not check against any document. If the date given corresponds to a person under 18, you will not be able to complete your profile or access KEDA's features: no one will be able to find you or see your information within the app. If we nonetheless detect, or are credibly notified, that an account belongs to a person under 18, we will suspend it and delete their data, unless we must retain certain information to comply with legal obligations.

Spain is currently processing future legislation aimed at strengthening age verification obligations for users of social networks and digital platforms (beyond a simple declaration of date of birth), as part of a package of digital governance measures for the protection of minors. At European level, the European Commission is likewise rolling out a technical age verification framework linked to the Digital Services Act (DSA). On Project Labs will follow the development of this legislation closely and will strengthen the mechanisms for verifying the minimum age of access to KEDA to the extent that it becomes required or that proportionate technical solutions exist allowing it without disproportionate data processing.

6. How long do we keep your data?

  • Account and profile data: while you keep your account active. If you request deletion, your account becomes inactive immediately (invisible to other users, without normal functionality) for a period of 30 days in case you decide to recover it. During that period, your home location at exact precision is deleted immediately — it is not kept even temporarily — while the rest of your profile, content and messages remain protected and blocked, not used for any other purpose, solely in case you recover your account. After 30 days without recovery, we irreversibly delete your profile, your login account and the data that identifies you, and we delete your own content. What is not deleted, but stops being associated with your identifying data, is the content you shared in other people's spaces, as detailed below and in section 9, in addition to the information we must keep by legal obligation (for example, billing data for the period required by tax and commercial legislation, currently 6 years, or certain security information on the terms described below).

  • How you came to KEDA (inviter and acquisition channel): kept while your account is active, with no additional period or time-based expiry. When you delete your account they are deleted in both directions: the record of who you named as your inviter is deleted, and so are the links from other people who had named you.

  • Generated content (plans, messages, comments): kept while the account is active or until you delete it. If you delete your account, your authorship stops being displayed (you will appear as "Deleted user") on content you shared within a plan — whether you created it or took part in someone else's — or in a conversation, since these are spaces shared with other users: the content is kept, but stops being linked to your identifying data. We do not call this anonymisation, because whoever had a conversation with you may still recognise you in what you wrote. Your stories are always deleted in full when you delete your account, regardless of the recovery period.

  • Kudos between users: if you are the one who gave a kudo and you delete your account, the kudo remains associated with whoever received it, but your authorship stops being displayed, on the same basis as the rest of the content in shared spaces. If you are the one who received the kudo and you delete your account, the kudos you had are deleted along with the rest of your profile.

  • Notifications: we keep them for a maximum of 12 months from creation, after which they are deleted automatically, whether or not you have read them. During the 30-day grace period after requesting deletion of your account we stop sending you notifications about ordinary social activity (new followers, requests to join a plan, messages, etc.), consistent with your account being inactive during that period; if you recover the account, you will find the full history of what happened in the meantime. We do, however, continue to notify you as normal about moderation of your content, about automatic hiding of content by volume of reports, and about any suspension of your account, so that you can exercise your right of appeal on the terms of section 9.

  • Content of messages you delete: deleted immediately, unless the specific message was reported before you deleted it. In that case we keep a copy of that particular message — never of the rest of the conversation — in order to handle the report, for the period corresponding to its seriousness in accordance with the paragraph below on moderation and report data.

  • Stories: they stop being shown to other users 24 hours after being posted. From that moment they remain accessible to you, and to our moderation team where necessary, while your account is active, and they are not deleted automatically: you can delete them yourself at any time.

  • Geolocation data: a plan's location is kept while the plan exists in the app, including plans that have already taken place, and is deleted when the plan is deleted. Your home (reference location) is deleted immediately if you delete your account, without waiting for the recovery period described above, precisely because it is a particularly sensitive piece of data.

  • Moderation and report data: for ordinary breaches of our rules of conduct, the period is 12 months. After that period we delete the data that identifies you and any free text, and we keep a record without them showing that there was a breach and how it was resolved, linked to an internal identifier. That period is set by the reason for which the report was made and applies in the same way whether or not we confirm the breach on review. Where an alert may be related to a possible criminal offence (for example, serious harassment, violence or content involving minors), we may keep the necessary information for up to 5 years, or for the period indicated to us by the competent authority, even if the account involved has been deleted, in order to comply with our legal obligations or respond to a judicial or police request. If we report the facts to the authorities, the associated information is kept protected against deletion until the matter is resolved, even if that means exceeding the period above.

  • Verified phone number, if we activate the prize-draw system in the future: kept while your account is active and deleted when you delete it, on the same basis as the rest of your account and profile data.

  • Record of acceptance of the legal documents: we store which version of the Terms and Conditions and of this Policy you accepted and when, because it is the evidence of the basis on which we process your data. This record survives deletion of your account, but stops being available for any use: it is kept blocked, identified and set aside in accordance with article 32 LOPDGDD, accessible only in order to respond to a request from a judge, the Public Prosecutor or the Spanish Data Protection Agency, or to defend ourselves against a claim relating to your account, a situation which article 17.3.e GDPR excludes from the right to erasure. It is destroyed 5 years after final deletion. It contains an internal identifier, the document, its version, the language in which you accepted it, a reference to the exact text accepted, and the date: not your email address, nor your username, nor any other data of yours.

  • Data arising from purchases and promotion campaigns: for the legal retention period for accounting and tax documentation applicable in Spain, currently 6 years.

  • Content sent to the moderation providers: the text analysed by OpenAI's moderation service is not retained. The images and plan data analysed by its general-purpose model are kept for a maximum of 30 days on OpenAI's systems, solely in order to detect abusive use of its platform. Where the alternative provider, Anthropic, is involved, the general period is also 30 days, but it can reach 2 years if its system flags the content as contrary to its usage policies, and up to 7 years for the classification scores. These periods are set by the providers and are not under our control, in the same way as the logs of our infrastructure.

  • Technical and session data: each item has its own period, which we set out in the table below.

  • Website contact form data: kept for as long as needed to handle your enquiry and, at most, one year from the last contact, unless a subsequent contractual relationship arises from it.

Data Retention period What happens if you delete your account
IP address and user agent of your session While the session remains open They are deleted, because requesting deletion closes all your sessions
IP, user agent and approximate city and country recorded on each request to the server Around 90 days, a period set by our infrastructure provider that we cannot change They expire on their own within that period
Notification token and your device model While the device remains registered They are deleted when you sign out or when the provider tells us the device no longer exists
Error reports (make, model, operating system, error trace, screen and your comment if you write one) No defined period They are unlinked from your account and the report is kept without your data
Usage sessions and screens visited 12 months They are deleted
Usage events, including search history 12 months They are deleted
Discover interactions (gestures and viewing time) 12 months They are deleted
Interest profile used to order what you see While your account exists It is deleted
Technical logs of use of the AI and storage services 12 months They are deleted
Push notification queue, which includes the message excerpt 7 days if sent; 1 day if delivery fails It is deleted
Verification codes sent by email 24 hours from use or expiry They are deleted
Internal daily metrics No defined period They contain no data that identifies you

7. Who do we share your data with?

In order to provide the service, we share personal data, to the extent necessary, with:

  • Supabase, as provider of the database, file storage and authentication (including the IP addresses recorded at sign-in).

  • OpenAI, as main provider: through its moderation service it analyses the text of plans, posts, comments and stories, and through a general-purpose model it analyses images and representative video images, including those in your messages. That same model receives the title, description and area of plans in order to classify them by category. You should know what happens to what is sent to it: OpenAI does not train its models on it, but it keeps what is sent through the general-purpose model — that is, images and plan data — for a maximum of 30 days, solely in order to detect abusive use of its platform, and then deletes it; that period could be longer if a legal obligation applicable to OpenAI required it. What is sent to its moderation service, which is the text, is not retained.

  • Anthropic, as alternative provider when the OpenAI service is unavailable, for the same purposes. In the case of images it receives the full file. It does not train its models on what it receives either, but its retention works differently: as a general rule it deletes what is sent and returned within 30 days; if its own system flags content as contrary to its usage policies, it may keep it for up to 2 years, and the associated classification scores for up to 7 years. Since this provider is only involved when we are analysing content that may breach our rules, that situation is more likely here than in ordinary use.

  • Resend, for sending emails, including verification codes (OTP) and the permanent suspension notice, which contains the reason for the suspension.

  • RevenueCat, Apple (App Store) and Google (Google Play), to handle in-app purchases.

  • Apple and Google, additionally, as identity providers, when you choose to register or sign in to KEDA using your Apple or Google account.

  • Expo (650 Industries, Inc.), as push notification provider. It receives your device token and the title and text of the alert, which in the case of messages includes an excerpt of up to 50 characters of their content, and in other cases may include another person's username.

  • Google, through its Places service, when you search for a city or a venue for a plan: it receives the text you type in that search. On Android devices, Google also provides the Discover map and the venue picker map.

  • Apple and Google, through your device operating system's geocoding service, which receives the coordinates in order to return the corresponding city or address.

  • DiceBear, the service that generates the default profile image for anyone who has not uploaded a photograph: it receives your internal identifier or your username, and the IP address of whoever is viewing that screen.

  • Twilio, as SMS phone verification provider, if we activate the prize-draw system in the future and you choose to take part in a mission that requires it. While that feature is not active, no data is shared with this provider.

  • Meta (Instagram) and TikTok, as advertising platforms we use to run user and follower acquisition campaigns. We do not provide these platforms with personal data of our registered users for this purpose; however, people who interact with our ads on those networks may generate information (for example, advertising identifiers) which Meta and TikTok process as independent controllers, in accordance with their own privacy policies.

  • Other users of the app, in respect of the information you choose to share publicly or within a plan (profile, content, location within a plan, kudos you give or receive).

  • Public authorities and competent bodies, where there is a legal obligation to do so. In particular, law enforcement authorities and the courts, both where they request it from us and on our own initiative where the law requires us to report facts that may constitute a criminal offence.

We do not sell your personal data to third parties. All providers acting as processors have, or will have, the corresponding data processing agreement (DPA) in place.

8. International transfers

Several of our providers are located outside the European Economic Area, in the United States: OpenAI and Anthropic, as automated content moderation providers (main and fallback respectively), Expo (650 Industries, Inc.), as push notification provider, RevenueCat, Apple and Google, for handling in-app purchases, and Twilio, as SMS phone verification provider if we activate the prize-draw system. Supabase and Resend, despite being companies based in the United States, process KEDA's data in the European Union. Meta processes data through its EU entities and, where applicable, in the United States. TikTok, linked to ByteDance, may involve processing or transfers of data to additional third countries.

To these is added Google, through its Places service and its map service on Android devices. The location of DiceBear's servers is pending confirmation on our part. In all cases we ensure that the transfer has adequate safeguards in accordance with Chapter V GDPR. OpenAI and Anthropic base their transfers on Standard Contractual Clauses approved by the European Commission. Twilio bases its transfers on Standard Contractual Clauses. Expo (650 Industries, Inc.) is certified under the EU-U.S. Data Privacy Framework, supplemented by Standard Contractual Clauses. RevenueCat, Inc. bases its transfers on Standard Contractual Clauses. Apple and Google act as independent parties in the in-app purchase transaction, and also when you use them as identity providers to sign in.

9. What rights do you have?

You can exercise at any time your rights of access, rectification, erasure ("right to be forgotten"), restriction of processing, portability and objection, as well as the right not to be subject to decisions based solely on automated processing — including the right to appeal an account suspension resulting from our moderation system, which is resolved within a maximum of 3 working days, and to request review of content hiding in accordance with section 3.5 — by writing to hola@keda.social stating the right you wish to exercise. We may ask you for a document proving your identity in order to process the request. We will deal with your request within a maximum of one month.

When you request deletion of your account, it becomes inactive immediately and available for recovery for 30 days; after that period without recovery, we will delete your profile and your content in accordance with section 6. Your home location at exact precision is deleted immediately, without waiting for that period. You should know exactly what happens then: we irreversibly delete your profile, your login account and the data that identifies you, and we delete your own content. What is not deleted, but stops being associated with your identifying data, is the messages you exchanged with other people, your posts and comments in plans, the plans you created in which other users are taking part, and the files that form part of that content, because they form part of other people's conversations and plans. We do not call this anonymisation, because whoever had a conversation with you may still recognise you in what you wrote: it is pseudonymised information, and we continue to treat it as personal data.

The exceptions to that deletion, in addition to the above, are: information we must keep by legal obligation, including billing data; moderation evidence associated with a possible criminal offence; the record of acceptance of the legal documents, which is kept blocked and unavailable for any ordinary use; the technical and usage logs listed in section 6, until their periods expire; error reports, already unlinked from your account; and the copy that the internal moderation record keeps of the actions taken on your account or your messages.

You should know what you can do yourself and what you need to ask us for. From the app you can correct your display name, your bio, your links to social networks, your interests, your photograph, your city, your reference location, your account privacy and your username (once every 14 days), and you can delete your account. You do need to write to us, however, to exercise access and portability — there is not yet a download function for your data —, to correct your email address or your date of birth, to delete your reference location without deleting your account, to object to processing based on our legitimate interest, and to remove the data about who invited you and how you came to KEDA.

You can withdraw your consent to geolocation at any time from your device settings, and turn off push notifications from those same settings, without this affecting the lawfulness of processing carried out beforehand.

If you consider that the processing of your personal data does not comply with applicable legislation, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD), at www.aepd.es.

10. Data security

We apply appropriate technical and organisational measures to protect your personal data against unauthorised access, loss, alteration or improper disclosure, including password encryption, storage of media files in private repositories with restrictions on the file types accepted, access control — including named, restricted access to the internal moderation panel described in section 3.5 — and periodic review of the safeguards offered by our providers.

11. Changes to this Privacy Policy

We may update this policy to adapt it to legislative, technical or service changes. Each version is identified by a number and a date shown at the top of the document. We will inform you of any substantial change through the app or by email and, where the change requires it, we will ask you to expressly accept the new version.

12. Contact

For any question about this Privacy Policy or about the processing of your personal data, you can write to us at hola@keda.social.

Usamos cookies para entender cómo se usa la web y mejorarla, y para saber si nuestras campañas te han traído hasta aquí. Hasta que decidas, no se guarda ninguna. Consulta la política de privacidad.