Kanso Space Privacy Policy
Last updated:
This Privacy Policy describes how Kanso Space ("we", "our" or "the app") collects, uses, stores and protects your personal information when you use our service.
Data controller: José Antonio Yébenes Gálvez, developer of Kanso Space. You can contact him at the address given in section 8.
1. Information We Collect
1.1. Account and Profile Information
When you create a Kanso Space account, we collect your email address and authentication data (through Google Sign-In, Apple Sign-In or email and password). Your public profile (visible to other users you share a Space with) stores your public name and an optional profile photo.
1.2. User Content
We collect and store the content you voluntarily create, upload or share in the app, including:
- Text notes, web links and bookmarks.
- Image files and audio recordings sent to your spaces.
- Tags, categories and semantic similarity vectors associated with your notes.
- Place names and dates that the Artificial Intelligence extracts from the content itself, and your device's time-zone offset at the moment of saving, which is needed to interpret those dates correctly. The app does not access your device's location.
- The history of your conversations in the conversational chat with the Artificial Intelligence.
1.3. Device Permissions
The app requests specific permissions only when they are needed to provide its features:
- Microphone (RECORD_AUDIO): Used exclusively to let you record voice notes inside the app. Recordings are uploaded to our secure servers (Firebase Storage) and processed by Artificial Intelligence models to generate automatic transcriptions and summaries.
- Camera and Photo Library: Used to let you select or capture photos and videos and include them in your notes and spaces.
- Notifications: Used to send you the alerts described in section 1.6. You can turn them off at any time in the app's settings or your device's settings.
1.4. Purchase and Subscription Data
To manage paid subscriptions (Kanso Pro), we use the RevenueCat service and the payment systems of the Apple App Store and the Google Play Store. We do not store your credit card details or banking data on our servers. We collect only anonymous transaction identifiers, subscription status and expiry date in order to validate your access to Pro features.
1.5. Usage, Diagnostics and Analytics Data
To understand how the app is used and to improve it, we collect usage data through Google Analytics for Firebase and Firebase Crashlytics:
- Usage events: which screens you visit and which actions you take (creating a note, opening the chat, applying a filter, viewing the paywall, completing onboarding…), together with when they happen.
- Never the content: these events do not include the text of your notes, your images, your audio or what you type in the search box. For a search we record only how many characters it had and how many results it returned, never the words.
- Account characteristics: whether you have an active Pro subscription, how many spaces and notes you have, whether you take part in any shared space, and your chosen theme and language.
- Identifiers: an installation identifier that Firebase generates for your copy of the app and, when you are signed in, your internal user identifier. We do not use advertising identifiers (Apple's IDFA or Android's Advertising ID).
- Crash reports: if the app crashes, Crashlytics sends the device model, the operating system and app versions and the technical error trace, associated with your user identifier so that we can reply if you write to us. These reports are only sent from published versions of the app.
- Subscription events: RevenueCat sends your subscription milestones directly to Google Analytics (sign-up, start of the trial period, renewal, cancellation, expiry or billing issue), linked through the installation identifier described above. They help us know how many people find the Pro plan useful, not to target advertising at you.
The lawful basis for this processing is our legitimate interest in maintaining and improving the service. This data is not sold, is not shared with advertising networks and is not used to build advertising profiles. If you wish to object to this processing, you can request it at the contact address in section 8.
1.6. Push Notifications
If you turn on notifications, we store a notification identifier (a Firebase Cloud Messaging token) for each device you sign in on. We use it only to let you know that someone has saved a note in one of your shared spaces or that one of your notes has finished processing. The identifier is deleted when you sign out on that device and when you delete your account.
2. Use of Information and AI Processing
We use your information for the following legitimate purposes:
- Intelligent Processing (Google Gemini / Google AI API): Your text notes, audio, images and links are processed by automated AI models to generate summaries, titles, automatic categorisation, metadata extraction and answers to the questions you ask about your library. When you save a link, our servers download the public page it points to in order to summarise it. Processing is carried out through Google's official APIs in a secure environment and your data is not used to train public models or for advertising purposes.
- Shared Spaces: If you join or create a shared space, your name and profile picture will be visible to the other members of that space, as will the notes you publish in it.
- Product Improvement: The usage data and crash reports described in section 1.5 are used to detect errors, understand which features are useful and decide what to work on. They are not used for advertising or to make automated decisions that affect you.
- Security and Integrity Verification: We use secure infrastructure services such as Google Firebase App Check (including Play Integrity on Android, App Attest on iOS and reCAPTCHA Enterprise on the Web) to protect the API and verify the authenticity of the device.
We process your account and your content because it is necessary to provide the service you have requested (performance of the contract). Usage, diagnostics and security data are processed on the basis of our legitimate interest in maintaining, protecting and improving the service.
3. Sharing Data with Third Parties
We do not sell or rent your personal information to third parties for commercial or advertising purposes. We share information only with trusted service providers that are necessary to operate the app:
- Google Firebase / Cloud Platform: Secure storage of the database (Firestore) and files (Storage), authentication, delivery of notifications (Cloud Messaging) and cloud processing.
- Google AI / Gemini API: Automated content processing and Artificial Intelligence.
- RevenueCat, Apple and Google: Management and validation of in-app purchases and subscriptions. RevenueCat also shares your subscription milestones with Google Analytics for Firebase, as described in section 1.5.
- Google Analytics for Firebase and Firebase Crashlytics: Measurement of app usage and reception of crash reports.
International transfers: Your content is stored primarily in Google data centres located in the European Union. Some of these providers may process data outside the European Economic Area, in particular in the United States; in that case, the transfer takes place with the safeguards provided for by the General Data Protection Regulation, such as the EU-U.S. Data Privacy Framework or the standard contractual clauses approved by the European Commission.
4. Data Retention and Deletion
We keep your personal data for as long as you keep your Kanso Space account active. You can request the complete and permanent deletion of your account and all associated data at any time directly from the Settings section inside the app, or through our dedicated data deletion page at Delete Account.
5. Your Privacy Rights (GDPR)
In accordance with applicable data protection law, you have the right to:
- Access the personal data stored in our service.
- Request the rectification of inaccurate data.
- Request the erasure and deletion of your account and content.
- Object to or restrict the processing of your data.
- Request the portability of your data in a commonly used format.
You can exercise these rights by writing to the contact address in section 8. If you believe we have not handled your request properly, you have the right to lodge a complaint with the data protection authority of your country; in Spain, the Agencia Española de Protección de Datos (www.aepd.es).
6. Children
Kanso Space is not directed at children under 14, or at anyone below the minimum age required by the law of their country to consent to the processing of their personal data. We do not knowingly collect data from children under that age; if you become aware that a child has provided us with data, please write to us and we will delete it.
7. Changes to this Policy
We may update this Privacy Policy to reflect changes in the app or in the law. The date of the last update appears at the top of this document and, when the change is significant, we will let you know inside the app. This policy is available in Spanish and English with the same content; in the event of any discrepancy between the two versions, the Spanish version prevails.
8. Contact
If you have questions or concerns, or wish to exercise your rights under this Privacy Policy, you can contact our support team at:
Support email: yebenes.dev@gmail.com
