1. Data we process
KisoDesk does not request sensitive personal data. Accessibility or interface preferences are used only as functional application settings and are not intended to collect information about health, disability, ethnic origin, religion, political opinions, sexual orientation, or other sensitive data.
- Account: email address, profile name when applicable, alias selected by the user, role, language, keyboard layout, and accessibility preferences.
- Authentication: a password stored as a hash when the account is created with a password, or the data necessary to sign in with Google when that method is used.
- Learning: courses, lessons, progress, speed, accuracy, practice time, errors, keys used, and events necessary to calculate typing metrics.
- Social features: friendships, requests, blocks, presence, last connection, and shared statistics according to the available preferences.
- Ranking: alias, speed, accuracy, level, practice language, position, and result date when applicable.
- Technical data: IP address, user agent, logs, session identifiers, diagnostic data, and technical requests generated by the infrastructure or providers used.
- Local data: theme, keyboard layout, font, text size, keyboard visibility, decision regarding non-essential technologies, guest progress, and local text history.
2. How we use the data
- Create and manage accounts and sessions.
- Allow sign-in with a password or Google, depending on the method selected.
- Provide lessons, save progress, and generate typing statistics.
- Customize the keyboard layout, interface, font, text size, and other usage preferences.
- Display general rankings and rankings by language.
- Operate social features, including friendships, presence, last connection, and statistics visible according to account preferences.
- Protect accounts, prevent abuse, detect unauthorized activity, and diagnose errors.
- Allow data downloads and account deletion from the profile.
- Respond to support, privacy, and security requests.
- Comply with legal obligations and defend claims.
- If Google AdSense is activated in the future, display and measure advertising, prevent fraud, and, where applicable, personalize ads with the information and consent required by applicable law.
3. Basis and principles of processing
Processing is carried out primarily to provide the requested service, manage accounts, maintain sessions, save progress, generate statistics, operate rankings and social features, allow data downloads or deletion, and protect the platform.
KisoDesk processes data in accordance with applicable law. When information is necessary to provide the service or fulfill obligations arising from the relationship with the user, additional consent will not be requested unless required by applicable law.
KisoDesk also uses internationally recognized privacy principles as a reference, including transparency, purpose specification, data minimization, accuracy, limited retention, security, user control, and accountability. This reference does not constitute certification or a statement of full compliance with foreign laws that do not apply.
For purposes that require consent, consent will be requested where appropriate and may be withdrawn without retroactive effect. If new purposes are added that are different from or unnecessary to provide the service, this Notice will be updated before the new processing begins when required.
4. Providers and recipients
KisoDesk uses technology providers to operate infrastructure, hosting, authentication, resource delivery, and security. The email integration is prepared but is not active until a provider is configured.
When these providers process personal data on behalf of KisoDesk and under its instructions, they will act as processors or service providers and will use the information only to provide the contracted functions.
Google Cloud Platform hosts and operates technical components of the service. Google also acts as an authentication provider when the user chooses to sign in with a Google account.
The application loads flag images from flagcdn.com. When those resources are requested, the provider may receive customary technical data, such as the IP address, user agent, date, time, and referrer URL.
Cloudflare Turnstile may be used conditionally to prevent bots and abuse. When activated, Cloudflare may receive technical connection data necessary to verify the request. Google AdSense and advertising are not active; before they are enabled, the information will be updated and the necessary controls will be applied.
The data subject may object to disclosures or transfers that require consent by using the privacy email address. This objection will not affect disclosures or transfers necessary to provide the service, maintain the relationship with the user, protect rights, prevent abuse, or comply with legal obligations.
5. Transfers and processing in other jurisdictions
KisoDesk may use technology providers located in different jurisdictions to host, operate, protect, and maintain the service.
When those providers act as processors, they will process data on behalf of KisoDesk and in accordance with the relevant instructions and purposes.
When data is disclosed or transferred to a third party other than a processor, it will be handled under the circumstances permitted by applicable law, including cases necessary to provide the service, comply with legal obligations, protect rights, or where consent exists.
The use of Google Cloud Platform, Google OAuth, Cloudflare Turnstile when active, and flagcdn.com may involve processing technical or account data in other jurisdictions, according to the service configuration and each provider's applicable policies.
6. Retention
- The access_token cookie has a maximum duration of 2 hours, and the refresh_token cookie has a maximum duration of 7 days.
- Account and progress data is retained while the account remains active or while necessary to provide the service, operate rankings and social features, comply with legal obligations, address requests, prevent abuse, resolve incidents, or defend rights.
- Ranking and social-feature data is retained while the account is active or while necessary to operate those functions, unless the user changes their preferences, deletes the account, or exercises an applicable right.
- Local backups generated during deployments are retained for up to 30 days. Technical logs are rotated by size and kept for as long as necessary to operate, protect, and diagnose the service.
- When personal data is no longer necessary, it will be deleted, anonymized, or blocked before deletion, as applicable, unless it must be retained because of an applicable obligation.
7. Rights and requests
You may request access to, correction, deletion, or objection regarding your personal data, and you may withdraw consent for processing activities that require it, where applicable.
From the profile, the application allows you to download a structured copy of the data associated with the account and request its deletion through the available mechanisms.
Users can limit the disclosure of data visible in rankings or social features, review or change the decision regarding non-essential technologies, and block other users through the application's controls.
You may also submit requests related to privacy, limitation of data use or disclosure, and the exercise of rights through the email address listed in this Notice.
8. Minors
The service is not directed to minors.
To create an account and use the service independently, a person must have reached the legal age of majority under the law applicable in their place of residence.
If KisoDesk detects that an account belongs to a minor, it may limit unnecessary processing and evaluate suspension, deletion, blocking, or regularization of the account in accordance with applicable law and the protection of the person's rights.
9. Security
KisoDesk applies administrative, technical, and physical measures intended to protect personal data against damage, loss, alteration, destruction, unauthorized use, access, or processing.
These measures may include access controls, authentication, secure password storage, protected session management, HttpOnly cookies, abuse prevention, technical logs, internal restrictions, and other measures proportionate to the risk and technological development.
No system is infallible. If an incident significantly affects users' rights, KisoDesk will make the communications and take the actions required under applicable law.
10. Changes to this Privacy Notice
This Notice may be updated to reflect legal, technical, or operational changes.
Updates will be published on this page with the corresponding last-updated date.
When a change is relevant, it will be communicated through a visible notice in the application or another available electronic method.
If a new purpose requires consent, the corresponding processing will not begin until consent is obtained when required by applicable law.
11. Controller and contact
Privacy email: kisodesk.project@gmail.com.