Privacy Policy - CriApp

NOTICE: Reviewed by the internal legal audit (2026-05-02) and completed with the owner's details on 2026-08-20. Sign-off by counsel licensed in Peru (governing law) is recommended before a large-scale launch campaign.

Version: 2.0.0

Last updated: 2026-08-20

Data Controller: Jose Giancarlo Palacios Loli ("CriApp", "we", "us").

Address: Huaraz, Áncash, Peru.

Data Protection Officer (DPO): dpo@criapp.smarthuaraz.cloud.

EU Representative (Art. 27 GDPR): Not applicable to CriApp v1.0 — the Service is NOT offered in the European Union, EEA, United Kingdom, or Switzerland (see §1.1 "Scope v1.0 — covered markets"). Should the Service expand to the EU in the future, CriApp will appoint a representative under Art. 27 GDPR.


1. Introduction

CriApp is a free mobile and web application supporting parents and caregivers during pregnancy and the upbringing of children aged 0-5. Privacy of your family - especially the minors in your care - is central to the Service.

This Policy describes what data we collect and why, how we protect it, with whom we share, your rights, and how to exercise them. It applies to version 1.0 of the Service in the markets listed under "Scope v1.0 — covered markets" below, with specific mentions for Peru, Mexico, Colombia, Chile, Argentina, Uruguay, Dominican Republic, Panama, Paraguay, Bolivia, Honduras, Guatemala, El Salvador, Nicaragua, Puerto Rico, and the United States (including California).

Minimum age: 18 years (or legally documented emancipation). By using CriApp you accept these practices.


1.1 Scope v1.0 — covered markets

Last scope review: 2026-05-03. This Service (CriApp v1.0) is offered exclusively in the following territories:

Included in v1.0: United States (including California) · Peru · Mexico · Colombia · Chile · Argentina · Uruguay · Dominican Republic · Panama · Paraguay · Bolivia · Honduras · Guatemala · El Salvador · Nicaragua · Puerto Rico, plus any other LATAM territory whose national data-protection compliance is zero-cost (no registration fee, no mandatory external DPO/DPD, no paid local representative).

Excluded from v1.0 (no users knowingly accepted): the European Union and the European Economic Area, the United Kingdom, Switzerland, Brazil, Ecuador, Costa Rica, Cuba, Iran, North Korea, Syria, and sanctioned territories (Crimea / Donetsk / Luhansk).

At sign-up, users whose declared country or geolocated IP falls within an excluded territory may receive a "service unavailable" notice. Residual presence of a user from an excluded territory does not imply Service recognition in their jurisdiction nor assumption of additional local obligations beyond contractual ones.

Future re-activation: the per-country annexes for excluded territories are retained at the bottom of this Policy as "Pending future expansion" so legal counsel can re-activate them without rewriting the document.


2. Categories of personal data

2.1 Adult account holder

Email, display name, optional avatar, date of birth (age verification), language, timezone, theme, notification preferences, family type (self-declared), session and refresh tokens (Better-Auth in expo-secure-store).

2.2 Children's data (entered by you)

Special category reinforced by COPPA (USA, FTC amendments April 2025), GDPR Art. 8 (children), LGPD Art. 14 (Brazil), INAI Guidelines (Mexico), Decree 1377/2013 + 090/2018 (Colombia), Law 25.326 (Argentina) and Law 29733 + DS 016-2024-JUS (Peru).

2.3 User-generated content (UGC)

Recipes, posts, comments, votes, bookmarks. Posted under your adult name; never under a child's name.

2.4 Technical data

Device model, OS, app version, system language, Expo Push token, IP at API call / login, error events (Sentry). We do not collect advertising identifiers (IDFA/GAID) because CriApp v1.0 has no advertising.

2.5 Data we do NOT collect

We do NOT collect: phone number, financial data, browsing history outside the app, device contacts, precise GPS location, biometric data (fingerprint, iris, voiceprint, facial template), genetic data, or the child's voice. The 2025 amendment to COPPA expands "personal information" to biometrics: we confirm we do NOT collect them.


3. Lawful bases (GDPR Art. 6, 9; LGPD Art. 7, 11; Peru Law 29733 Art. 13-15)

ProcessingLawful basis
Account + authContract (Art. 6.1.b GDPR)
Core trackingContract (Art. 6.1.b)
Health dataExplicit consent (Art. 9.2.a GDPR; Art. 11 LGPD; informed consent Peru Art. 14)
Children's dataParental consent (Art. 8 GDPR; LGPD Art. 14; COPPA §312.5; Peru DS 016-2024-JUS)
Push notificationsConsent (Art. 6.1.a)
Community UGCConsent (Art. 6.1.a) + legitimate interest (Art. 6.1.f)
Security / fraud logsLegitimate interest (Art. 6.1.f)
Consent records / complianceLegal obligation (Art. 6.1.c)

No automated decision-making with significant effects (GDPR Art. 22; LGPD Art. 20). Nap predictions, pediatric dose suggestions and growth curves are informational suggestions, not diagnoses. CriApp is NOT a high-risk AI system under the EU AI Act (Reg. 2024/1689).


4. Purposes

  1. Provide the Service.
  2. Proactive reminders (vaccines, doses, milestones, weekly content).
  3. Service improvement (anonymized technical analytics, error monitoring).
  4. Security (fraud and impersonation prevention).
  5. Legal compliance (data subject rights, export, erasure).

CriApp v1.0 does NOT engage in any advertising activity. See §10.


5. Storage and protection

5.1 Infrastructure

CriApp runs self-hosted infrastructure on a Hostinger VPS (Lithuania, EU). PostgreSQL, object storage (Garage S3) and authentication (Better-Auth) run on our servers. We do NOT use Supabase, Firebase, or third-party Backend-as-a-Service. We do NOT integrate Google Health Connect nor Apple HealthKit; the only health data is what you manually enter.

5.2 Encryption

5.3 Access

Authorized staff under NDA, SSH bastion + signed keys. Admin logs retained 90 days.

5.4 Retention

CategoryTerm
Active accountLifetime of account
Post-deletionFull purge within 30 days
Behavioral logs (sleep/feed/diaper)2 years from creation
Consent records5 years
Security logs90 days
Encrypted backupsRolling 7d + 4 weekly + 6 monthly
Inactive push tokens90 days
Export file7 days after generation
UGC after deletionAnonymized ("Deleted user") or removed on request

6. Subprocessors

We do NOT sell your data. We share only with subprocessors strictly necessary under DPAs compliant with GDPR/LGPD/CCPA. Full list at /legal/subprocessors (see 12-subprocessors-list-final.md).

SubprocessorRoleDataRegion
Hostinger Intl.VPS infraAllLithuania (EU)
Google / Apple OAuthLoginEmail + nameUSA
Expo (650 Industries)EAS Build / OTA / Push relayPush tokens, build metadataAWS US
SentryError monitoringStack traces, optional user IDFrankfurt (EU)
ResendTransactional emailRecipient email, contentEU/US
Backblaze B2 / Hetzner Storage BoxEncrypted off-site backupsEncrypted data (key on our servers)USA or EU

NEVER shared: child data with ad networks (CriApp v1.0 has no advertising); health data with third parties for commercial purposes; child photos with third parties beyond infra.


7. International transfers

CriApp v1.0 is NOT offered in the European Union (see §1.1). Notwithstanding, because controller infrastructure sits in EU territory (Hostinger, Lithuania), we apply, as a best-practice baseline: Standard Contractual Clauses (Decision 2021/914) for non-EU subprocessors, Transfer Impact Assessments where applicable, and EU-US Data Privacy Framework (2023 adequacy decision) where applicable. For users of v1.0 markets (LATAM + USA), transfers are additionally governed by the standard clauses and adequacy mechanisms detailed in the LATAM Annex.


8. Your rights

RightHow to exercise
AccessSettings - Data - Export
RectificationIn-app edit
Erasure / right to be forgottenSettings - Account - Delete (30-day purge)
Portability (JSON/ZIP)Settings - Data - Export
Objection / restrictiondpo@criapp.smarthuaraz.cloud
Withdraw consentSettings - Privacy
Lodge complaintSee §14

Response time: 30 calendar days (GDPR Art. 12.3; LGPD Art. 19; Peru Law 29733 Art. 19 - 20 working days in Peru).

8.1 United States — federal and state

8.2 Brazil (LGPD) — Pending future expansion (NOT in v1.0)

CriApp v1.0 does not operate in Brazil. LGPD requires an Encarregado (DPO) absent the small-business exemption under Res. CD/ANPD 2/2022; the cost of an external Encarregado (~USD 2,000/year) exceeds the v1.0 free model. To be re-activated when Phase B is evaluated. Reference text: confirmation, access, correction, anonymization/blocking/erasure, portability, deletion of consented data, information on sharing, withdrawal. Encarregado: dpo@criapp.smarthuaraz.cloud.

8.3 Mexico (LFPDPPP)

ARCO rights. Requests to dpo@criapp.smarthuaraz.cloud.

8.4 Peru (Law 29733 + DS 016-2024-JUS)

Information, access, update, inclusion, rectification, suppression, opposition, objective treatment, judicial protection (tutela), portability. Requests to dpo@criapp.smarthuaraz.cloud. Response time: 20 working days.


9. Children's data

See 05-children-privacy-notice-final-en.md. Summary:


10. Advertising

CriApp v1.0 is 100% free and ad-free. We do not display advertisements and do not collect data for advertising purposes. We do not integrate third-party ad SDKs, do not use advertising identifiers (IDFA/GAID), and do not participate in personalized advertising networks. If this changes in a future version, we will notify you in advance and request consent.


11. Security

PKCE (Better-Auth), 15-min tokens, per-row authorization by account_id, Zod validation, rate-limiting, restic off-site backups, HSTS/CSP/X-Frame-Options. Incident notification: <72h to authority (GDPR Art. 33; LGPD 3 business days - 6 for small-scale; equivalents elsewhere) and to data subjects if high risk.


12. Changes to this Policy

Material changes: in-app banner before next login + email + policy_version_accepted bump. Re-acceptance required when purpose or legal basis changes. Public versions at /legal/privacy-policy.


13. Cookies

Mobile app: no cookies. Web build: see 07-cookie-policy-web-final-en.md.


14. Supervisory authorities

Listed only the authorities of the v1.0 covered markets (see §1.1). Authorities of excluded markets (EU, UK, Switzerland, Brazil, Ecuador, Costa Rica, Cuba) will be re-listed when expansion is decided.

JurisdictionAuthorityURL
PeruANPD / MINJUSDHgob.pe/anpd
US federalFTCreportfraud.ftc.gov
CaliforniaCPPAcppa.ca.gov
MexicoINAIinai.org.mx
ColombiaSICsic.gov.co
ChilePersonal Data Protection Agency (eff. 1-Dec-2026) / Consejo para la Transparenciaconsejotransparencia.cl
ArgentinaAAIPargentina.gob.ar/aaip
UruguayURCDPgub.uy/unidad-reguladora-control-datos-personales
PanamaANTAIantai.gob.pa
Dominican Republic(no general authority)
Paraguay(forming after Law 7593/2025)
El Salvador(forming after LPDP Nov-2024)
Bolivia / Honduras / Guatemala / Nicaragua(no general authority)
Puerto RicoDACO + FTC (federal)daco.pr.gov

15. Contact

Address: Huaraz, Áncash, Peru. EU Representative: Not applicable — Service not offered in the EU in v1.0.


Authoritative version: Spanish. In case of translation conflict, the Spanish version signed by counsel prevails.


LATAM Annex — jurisdiction-specific provisions

This annex supplements the Privacy Policy and prevails over the rest only where local law is more protective of the data subject.

Argentina

Bolivia

Chile

Colombia

Costa Rica — Pending future expansion (NOT in v1.0)

Cuba — Pending future expansion (NOT in v1.0)

Ecuador — Pending future expansion (NOT in v1.0)

El Salvador

Guatemala / Honduras / Nicaragua / Venezuela

Mexico

Panama

Paraguay

Peru

Puerto Rico

Dominican Republic

Uruguay

International transfers (LATAM)

Geographic availability

CriApp is not distributed in Cuba, Iran, North Korea, Syria, or Crimea / Donetsk / Luhansk, due to OFAC sanctions and Apple/Google global policies.