Privacy Policy

Ciało · Effective date: 01/01/2023 · Last updated: 09/05/2026

1.Data Controllers

The Ciało service is operated jointly on Android and iOS. The data controllers are:

We act as joint controllers within the meaning of Article 26 of the GDPR. We jointly determine the purposes and means of processing your personal data through a shared backend infrastructure used by both platforms.

The essence of our joint-controller arrangement is as follows: we share responsibility for the App's data processing, we use a common backend, and we have agreed on a single contact point for handling your requests. Regardless of which platform you use, you may exercise all of your rights against either of us — we coordinate internally.

Single point of contact for any privacy-related matter, on both platforms:
cialo.dev@gmai.com

2.Scope of this Policy

This Policy describes how we process personal data when you use the Ciało mobile application on Android or iOS (the “App”). It applies to both platforms; where the platforms differ, we say so.

3.Data We Collect

We collect only the data needed to operate the App and provide its features.

3.1. Account and authentication

3.2. Device and technical data

3.3. Beacon and venue presence

3.4. Health and fitness data (step count)

3.5. In-app activity, diagnostics and crashes

3.6. User-generated content (the “wall” feature)

3.7. Barcode / QR scanning (Android only)

3.8. What we do not collect

4.Purposes and Legal Bases

PurposeLegal basis (GDPR Art. 6)
Providing the App and your account(b) performance of a contract
Detecting beacon presence and awarding event rewards(b) performance of a contract
Reading step count for activity-based rewards(a) consent (granted via the Health Connect / Motion & Fitness permission)
Sending push notifications about events and rewards(a) consent or (f) legitimate interest
Diagnostics, analytics and crash reporting(f) legitimate interest in improving the App
Security and abuse prevention(f) legitimate interest
Compliance with legal obligations(c) legal obligation

You may withdraw any consent at any time without affecting the lawfulness of processing carried out before the withdrawal.

5.Recipients of Data

We share data only with trusted processors and partners that act on our instructions or are necessary to operate the App:

Some providers may process data outside the European Economic Area (in particular in the United States). In such cases we rely on appropriate safeguards, in particular Standard Contractual Clauses approved by the European Commission and any additional measures required by applicable law.

6.Data Retention

7.Your Rights

Under the GDPR you have the right to:

You can exercise any of these rights against either joint controller. The simplest path is to write to cialo.dev@gmail.com — we coordinate internally and will action your request within 30 days. You can also delete your account and the data associated with it directly in the App at Settings → Account → Delete account.

8.Device Permissions

The App uses the following system permissions. You can revoke any of them at any time in your device settings; some App features will then stop working.

Android

iOS

9.Children

The App is not directed to persons under [16 years of age] and we do not knowingly collect their data. If we learn that data of a person under that age has been provided without a guardian’s consent, we will delete it without undue delay.

10.Security

11.Third-Party Services

The App integrates third-party SDKs and services governed by their own privacy policies:

The iOS build of the App also links the Facebook SDK and Google Sign-In SDK as part of its build configuration. These SDKs are not used by any active sign-in flow (sign-in is provided exclusively via Auth0), but they are listed here in the interest of full transparency. Their respective privacy policies apply if they collect any data:

12.International Transfers

Where data is transferred outside the European Economic Area, we rely on Standard Contractual Clauses approved by the European Commission and on any additional safeguards required by applicable law. You can request a copy of the safeguards in place by writing to cialo.dev@gmail.com.

13.California and US State Privacy Rights

If you are a resident of California, Colorado, Connecticut, Virginia or another US state with a comprehensive privacy law, you have the right to know, access, correct, delete and opt out of the “sale” or “sharing” of your personal information. We do not sell personal information and we do not share it for cross-context behavioral advertising. To exercise these rights, contact cialo.dev@gmail.com.

14.Changes to This Policy

We may update this Policy from time to time. We will inform you of material changes in the App or by email at least [14 days] before they take effect. The current version is always available at [link to policy].

15.Contact

For any privacy-related matter, on either platform, the simplest path is the shared contact:

cialo.dev@gmail.com