Privacy Policy

Effective October 3, 2026 · Applies to the Kimcura mobile app (Android) and the web version at kimcura.cl

Who we are and scope of this policy

Kimcura is a math-learning app designed for students in Chile. It comes in two forms: the mobile app for Android and the web app that runs on this very site, kimcura.cl. The data controller is Bravo Ciencia y Tecnología SpA.

This Privacy Policy explains what personal data we process when you use Kimcura in either form, what we use it for, who we share it with, and what rights you have. Where the mobile app and the web version behave differently, we say so.

This policy is effective as of October 3, 2026. It was rewritten that day from a review of the code and of the production infrastructure, which is why it also states plainly what does not yet work the way we would like. For any question or request about your data, write to us at contacto@bcyt.cl.

What data we collect

Data stored on our servers

  • Account data: if you choose to sign in with Google, your email address, your Google display name and your Google profile-picture URL. The picture is not shown to other people; on the web version only you see it, next to your own comments. Every account — including guest accounts — is assigned an internal identifier (UUID) and a random public username (for example, “blue-fox-1234”), which you can edit. You may also write an optional bio of up to 160 characters.
  • Age and consent: we ask for the month and year of your birth (not the day). Your age band (under 14, 14 to 17, or adult) is derived from it. On the server we store your age band and the history of your consent decisions, including your acceptance of the Terms and of this policy; on the web version the birth month and year are also stored on your account. If you declare you are under 14, we also store the email of the responsible adult you give us.
  • Onboarding answers: your goal, your grade, your plans after school and how comfortable you feel in each topic area. They are stored on your account so you do not have to answer again when you sign in on another device.
  • Content you create: comments and replies on exercises (500 characters max), likes and saves.
  • Progress and gameplay: your math skill-mastery vector and your target vector (seeded from your grade and level); your attempts at practice tests and quizzes, with the answer to each question, the score and the time; your XP total and your scores in practice events, which feed the leaderboards; your cumulative PvP duel win/loss tally; and the avatar cosmetics you own and wear.
  • Usage telemetry (only if you accept it): interaction events — impressions, dwell time, solves, wrong attempts, skips, scroll-backs, feed switches, session start and end, app foreground/background —; the fact that you liked, saved, shared, opened the comments or commented (the length of the comment is recorded, not its text); opening hints, solutions, the scratchpad and the theory panel; and video playback. Each session also carries the device model, operating system and app version (on the web version, your browser’s identification string), snapshots of your skill vectors and the signals the recommender used. It does not include a unique hardware identifier.
  • Safety and moderation: user reports (reason, optional detail and a copy of the reported comment), reports of faulty exercises (reason, optional detail and a copy of the problem statement), user-to-user blocks, and sanctions applied by moderators (mutes and suspensions).
  • Notifications: the log of your in-app notifications, with a copy of the comment text that triggered them. If you allow push notifications on your Android device, we also store a notification token (generated by Expo), a random identifier for that installation of the app, and your per-type notification preferences. The web version does not use push notifications.
  • Kimcura Plus subscription: whether your account has Plus, until when and through which channel (app store, Mercado Pago or promo code). If you subscribe from the web version we store the payer email you provide, the plan, the amount, the currency, the subscription status and the identifiers of the subscription and of each charge at Mercado Pago. If you redeem a promo code, we store which account redeemed it. We never receive or store your card details.
  • Emails and privacy requests: a record of the emails we send you and of whether you asked to stop receiving promotional ones. If you ask to delete your account or download your data from this site, we store the email you type, the reason and the date, even if that email matches no account.

Data that is transmitted but not stored

  • Multiplayer: your position, pose, emotes (from a fixed list, no free text), outfit and username in the 3D plaza are relayed in real time to the other players and live only in memory for seconds.
  • Presence: while Kimcura is open, it sends a signal every few seconds with a random identifier that changes every session, to count how many people are online. It is not tied to your account and is not stored. On the web version that signal is sent from every page, including this one.
  • Searches: what you type in the search box is sent to the server to answer you and is not stored.
  • Technical connection data: like any internet service, our servers receive your IP address and the data your browser or app sends (browser type, language). The IP is used to limit abuse. See “Security” about access logs.

Data that stays only on your device or browser

Streaks, missions, hearts, practice statistics, the recap of your last session, the vocational test result, the state of the model that personalizes your feed, exercises preloaded to open the app faster, an image of your 3D avatar (a drawing generated by the app, not a photograph), your language, sound and text-size preferences, and the parental controls (PIN, restrictions and minutes used today). Handwriting recognition happens on your device: your strokes are neither stored nor sent.

We do not collect location, contacts, photos, camera, microphone or audio, advertising identifiers, or card or bank-account details.

How we use your data

We use your data to:

  • Run the app and personalize your learning: your skill vector determines which exercises are recommended to you (“For You”). If you allow it, your recent activity and telemetry also tune the feed to your tastes.
  • Power social and multiplayer features: your username, bio, avatar outfit, PvP tally and comments are shown to other players in the 3D plaza, on duel cards and in the feed. The leaderboards show your username, your outfit and your XP or score to anyone using Kimcura, even if you turned social features off. For the plaza to work, the other players’ apps also receive your internal identifier, although it is not shown on screen.
  • Keep the app safe: an automatic Spanish/English filter screens comments (profanity, contact details and links); flagged comments are hidden and a human team reviews reports through an admin dashboard. That dashboard can look accounts up by email.
  • Manage your account and subscription: sign-in, enforcement of suspensions, and knowing whether you have access to Kimcura Plus.
  • Product analytics: understand how the app is used so we can improve it, based on usage telemetry, which is keyed to your internal user identifier. It is not anonymous.
  • Push notifications (Android app): alert you when someone replies to or likes one of your comments, and send you team announcements and promotions. All four types start switched on for every account and each can be switched off separately in You ▸ Settings; you can also disable them all from your operating system’s settings.
  • Emails: the privacy-flow ones (codes and download links) and, if your account has an email, service notices and promotional emails. Every promotional email carries a link to stop receiving them; service notices cannot be switched off.

We do not sell your data and we do not show ads.

Legal bases for processing

We process your data under Law No. 19.628 on the Protection of Private Life, as reformed by Law No. 21.719, on the following bases:

  • Performance of the service: what is needed to provide the app — your account, your skill vector, your progress, your practice-test attempts, your XP and your leaderboard scores, your likes and saves, your onboarding answers, your subscription state and the delivery of notifications.
  • Consent: behavioural telemetry, taste-based feed personalization, and the social and multiplayer features (comments, the plaza with other people, and duels). The three are presented to you separately on the consent screen, after the age question. Telemetry starts switched off for everyone and no event is sent until you switch it on. For people aged 14 or over, personalization and social features start switched on on that screen and you can switch them off right there or later; for under-14s all three stay off. You can change any of them at any time from You ▸ Privacy, without writing to us and without losing access to the app.
  • Legitimate interest: security, content moderation, abuse prevention (including rate-limiting requests by IP address), counting how many people are online, and preventing suspended accounts from re-registering.

We want to be precise about one point: these preferences are applied by the app itself. If you turn telemetry off, the app stops sending it; our servers do not currently run a second check that would reject that data.

Who we share data with (processors and third parties)

We do not sell or transfer your data for commercial purposes. We share it only with these providers:

  • Supabase (infrastructure on AWS, us-east-1, USA): runs authentication and the main database where account and app data lives.
  • Google (only if you choose “Sign in with Google”): acts as identity provider; it knows you sign in to Kimcura and gives us your email, name and profile photo URL. On the web version, that photo is loaded directly from Google’s servers.
  • Microsoft Azure (Chile Central region): hosts our servers — the web app and the app’s services — and file storage. It serves the images, sounds, videos and 3D models (the mobile app and some videos on the web version download them directly from that storage, which therefore receives your IP address) and keeps, in a private container, the archive with the copy of your data when you request one.
  • RevenueCat Inc. (USA): keeps Kimcura Plus subscription state. In the Android app it receives your account’s internal identifier every time you sign in, whether or not you have a subscription, together with the purchase information the store provides. It also records subscriptions made through Mercado Pago and redeemed promo codes, and when you delete your account it is asked to revoke the subscription and delete your record.
  • Google Play: processes payment for subscriptions bought in the Android app. Neither RevenueCat nor we see your card details.
  • Mercado Pago: processes payment for subscriptions bought on the web version. We send it the payer email you provide, the plan, the amount and your account’s internal identifier, and redirect you to its page to pay; you type your card details there and they never pass through Kimcura. Mercado Pago handles that payment data as a controller in its own right, under its own terms.
  • Expo, Inc. (USA) and Google LLC — Firebase Cloud Messaging (USA): deliver push notifications on Android, only if you allowed notifications. They receive your notification token and the content of each notification, which may include the username of the person who replied to you and an excerpt of their comment. They receive neither your email nor the rest of your account data.
  • Twilio Inc. — SendGrid (USA): sends our emails: the codes and links of the privacy flow, service notices and promotional emails. It receives your email address and the content of those messages.

When you pay or sign in you pass through pages run by Mercado Pago, Google and Supabase, which may use their own cookies under their own policies.

We may also disclose data if a competent Chilean authority requires it under the law.

Cookies and local storage on this website

kimcura.cl is the web version of the app, and to work it uses first-party cookies and your browser’s local storage. It uses no advertising, analytics or tracking cookies, loads no third-party trackers, and there are no third-party cookies on our pages.

Cookies

  • kc_session (up to 400 days): keeps you signed in. It contains the session tokens and a copy of your account data (identifier, email, name, username, and your age, consent and onboarding answers). It is signed so it cannot be tampered with, and page scripts cannot read it.
  • kc_flow (up to 400 days): remembers which entry step you are on (welcome, age, questionnaire).
  • kc_pkce (10 minutes): protects Google sign-in while it is happening.
  • kc_consent (up to 400 days): your age band and whether an adult’s authorization is pending, so the server knows which screen to show you.
  • kc_lang and kc_text_scale (up to 400 days): the language and text size you chose.

The first four are strictly necessary for the application to work; the last two store preferences you choose. That is why we show no notice asking you to accept cookies. If we ever added non-essential cookies (web analytics, for example), we would ask for your consent before turning them on.

Browser local storage

Here the web version stores what the mobile app stores on the phone: your age answer and your consent decisions (including the responsible adult’s email, if you gave it), the parental controls (PIN, restrictions and minutes used), the feed-model state, preloaded exercises, missions, streaks, local results, your avatar image, and sound and display preferences. The browser does not encrypt this storage.

Signing out clears the session and your consent decisions, but the birth month and year you declared is remembered in that browser, so the age question cannot be answered again with a different date. The rest of the local data stays until you clear the site’s data from your browser settings.

The mobile app does not use browser cookies.

Guest mode

You can use Kimcura without an email or Google account by choosing to continue without an account. An anonymous account is still created on the server, with an internal identifier and a random username, but no email, no real name and no photo.

The age question and consent apply exactly as they do to a registered account. The same activity data is collected as for a registered account, and telemetry only if you switch it on.

On the web version the guest account is created when the age question is completed. If the guest session expires, the site automatically creates a new guest account on your next visit; what the server stored for the previous account is no longer within your reach. To avoid losing your progress, link your account with Google: you keep what you had.

You can delete your guest account from the app, just like a registered one. Data download works for guests too: since the account has no email, the download link arrives as an in-app notification. The web channels (kimcura.cl/account_deletion and kimcura.cl/account_data) require an email, so they don’t apply to guest accounts. Subscribing from the web version requires signing in with Google.

Children's privacy

Kimcura is aimed at school students, including minors, and we designed it to minimize the risks to them.

Age question. We ask for the month and year of your birth with a neutral question that does not hint which answer unlocks more features. In the mobile app it is asked before the account is created. On the web version it is asked right after you choose how to enter; if you enter with Google, we receive your email, name and photo before that question. It is a declaration: we do not verify age with documents. In the mobile app, signing out clears the answer and it is asked again; on the web version the browser remembers it.

Under 14. Telemetry, taste-based personalization and the social features (comments, the plaza with other people, and duels) stay switched off. We ask for the email of your parent or responsible adult and store it.

We have to be honest about what is missing: sending the confirmation email to that adult is not working yet, so today no adult can authorize those features remotely and they stay off. Meanwhile the account can be used, which means we do process the data needed for the service: the account, the onboarding answers, progress and practice-test attempts, XP and scores — which appear on the leaderboards next to the random username —, the identifier RevenueCat receives and, if allowed on the phone, push notifications, including promotional ones until they are switched off. We know Law No. 21.719 will require the adult’s prior authorization and we have it as pending work before the law takes effect; the status is published on our Law 21.719 page.

Ages 14 to 17. You can consent on your own. Telemetry, personalization and social features are optional and are your choice.

On-device parental controls. In You ▸ Settings ▸ Parental controls, the responsible adult can set a 4-digit PIN to block social features, require the PIN before any purchase, set a daily screen-time limit and define hours during which the app cannot be used. All of this is stored only on the device and is never sent to our servers or to third parties. In the mobile app the PIN is kept in the system’s secure storage and the restrictions in the app’s regular storage; on the web version both sit in the browser’s local storage, unencrypted, and are not cleared on sign-out. Removing the PIN lifts the restrictions.

No advertising: no ads, no ad SDK, and we do not read the device advertising identifier. No real name required: your public identity is a random username. No sensitive device data: we do not collect location, contacts, photos or audio.

Protection in social features: the moderation filter automatically blocks the exchange of contact details (phone numbers, social handles, links) in comments, and multiplayer emotes come from a closed list with no free text. User reporting and blocking are available, with human review.

If you are a parent or guardian and want to access, correct or delete the data of a minor in your care, or have us stop processing it, write to contacto@bcyt.cl with the minor’s username.

How long we keep your data

A daily automated process applies these periods:

  • Behavioural telemetry (events and sessions): 24 months.
  • Reports of users and of exercises: 24 months from when they are created.
  • Temporary mutes: 24 months after they end.
  • Web deletion/download requests (email, reason and date): 12 months, as evidence the request was handled.
  • The record of each data download we prepare: 30 days.
  • Practice-event scores on the leaderboards: 60 days.

Other data is kept as follows:

  • Account and progress data (including practice-test attempts, XP and PvP tally): for as long as your account exists.
  • User-to-user blocks: for as long as both accounts exist.
  • Suspensions and permanent mutes: for as long as they are in force, with no expiry. To prevent a suspended account from re-registering we store its email, together with a hash of that email. Our aim is to keep only the hash; we have not completed that yet.
  • Push-notification token: until you sign out or delete your account; if you uninstall the app, it is removed when the delivery service tells us the token is no longer valid.
  • 3D plaza presence (position, emotes): memory only, gone within seconds.
  • Your data-download archives: the link is valid for 7 days. After that the file sits inaccessible in a private container; automatic deletion of that file is not configured yet.
  • Data kept only on your device or browser: until you uninstall the app or clear the site’s data.

And some records currently have no defined period: the responsible adult’s email given by an under-14; Mercado Pago subscription and charge records, including the payer email; the record of redeemed promo codes; the log of emails sent and the list of people who asked not to receive promotional emails; and our servers’ access logs, which contain IP addresses.

Deleting your account erases everything tied to it, with these exceptions, which are kept: reports, mutes and suspensions (for the periods above), Mercado Pago records, the record of the promo code you redeemed, the email logs and promotional opt-out record, any responsible-adult email that was provided, and the deletion request itself for 12 months. Moderation records are kept pseudonymized, not anonymous: they remain personal data and your right to erasure still applies to them — you can request their deletion by email and we will assess it case by case, weighing the protection of the other people involved.

Security

We apply technical and organizational measures to protect your data:

  • The connection between your device or browser and our servers is encrypted (HTTPS), and the connection to the database is encrypted too.
  • Every service verifies the session of whoever makes the request and takes the account identity from that session, not from data sent by the app.
  • The database enforces row-level access controls that prevent direct client access to service tables.
  • In the mobile app session tokens are kept in the system’s secure storage; on the web version, in a signed cookie that page scripts cannot read.
  • We do not integrate advertising SDKs or third-party crash-reporting services.
  • Social content goes through an automatic filter plus human review.

We also want to say what is not yet resolved. Inside our own infrastructure, part of the traffic between services travels unencrypted or without certificate validation, within the server’s private network. And our API server’s access logs record the IP address and the requested address of every request, currently with no automatic deletion period; the web application keeps no access logs.

No system is 100% secure; if an incident affecting your personal data ever occurs, we will notify you as required by law.

Your rights and how to exercise them

Under Law No. 19.628 as reformed by Law No. 21.719 you have the rights of access, rectification, erasure, objection and portability. Nearly all of them can be exercised without writing to us:

  • Access and portability: request a copy of your data from You ▸ Privacy or at kimcura.cl/account_data, confirming a single-use code we email you. We prepare a .7z archive with one CSV file per table — a structured and commonly used format — including profile, comments, reactions, skill vector, telemetry, practice-test attempts, PvP record, leaderboards, cosmetics inventory, notifications, subscription state, your consent history and the moderation records. We deliver it as a download link valid for 7 days: by email, or as an in-app notification if your account is a guest account. That archive does not yet include some things we do store: your onboarding answers and birth month stored on the account, Mercado Pago records, redeemed promo codes and the email log. If you want them, ask at contacto@bcyt.cl.
  • Erasure: delete your account in the app or at kimcura.cl/account_deletion, confirming a code we email you; both paths let you download a copy of your data first. Your account and what is tied to it are erased — comments, reactions, telemetry, skill vector, practice-test attempts, leaderboard entries, cosmetics, record, blocks, notifications, and your push-notification tokens and preferences. If you have Kimcura Plus through Google Play, it is revoked with a refund of the latest payment; if you bought it through Mercado Pago, it is cancelled. What is kept after deletion is detailed under “How long we keep your data”.
  • Objection: you can turn off telemetry, feed personalization and social features independently, at any time, from You ▸ Privacy; switch off each type of push notification in You ▸ Settings; and stop receiving promotional emails with the link each one carries. To receive them again you would need to write to us.
  • Rectification: username and bio are editable from your profile. To correct anything else, write to us.

For anything else write to contacto@bcyt.cl, ideally from the email associated with your account or quoting your username. There is a named owner and we respond within the legal deadlines. You may also file a complaint with Chile’s Personal Data Protection Agency.

International data transfers

Our servers and file storage are in Chile (Microsoft Azure, Chile Central region). But the main database and authentication run in the United States, on Supabase (AWS, us-east-1), so nearly all of your data is stored there. Also in the United States are RevenueCat (subscription state), Expo and Google Firebase Cloud Messaging (push-notification delivery), Twilio SendGrid (emails) and Google (sign-in). Mercado Pago processes web-version payments on its own infrastructure, which may be outside Chile.

Law No. 21.719 requires a legal mechanism for these transfers. We are formalizing it alongside the processing agreements with each provider, to have it in place before the law takes effect on December 1, 2026; today it is still pending. We publish the status of this work, unvarnished, on our Law 21.719 page.

The rights described in this policy apply regardless of where your data is stored.

Changes to this policy

We may update this policy when the app or applicable law changes. We will always publish the current version on this page with its effective date, and every consent decision you make is recorded together with the policy version in force at that moment. If a change is significant — for example, new types of data collected or new providers — we will endeavour to announce it with an in-app announcement or by email. Today the app does not automatically ask for consent again when the policy changes.

Contact

For questions, rights requests or privacy complaints, write to contacto@bcyt.cl. Include the word “Privacy” in the subject line and your Kimcura username so we can locate your account. If you are writing as the parent or guardian of a minor, please say so in your message.