Privacy Policy
Last updated: February 2026
This Privacy Policy explains how Klioso (“App”, “Service”) collects, uses, shares, and protects personal data when you use our mobile app, PWA, websites, and booking pages.
1. Controller (Who we are)
Klioso — Operated by an individual in Ukraine.
Location: Mykolaiv, Ukraine
Contact (privacy & support): support@klioso.app
This Privacy Policy is governed by the laws of Ukraine, with mandatory application of the GDPR for users located in the European Economic Area (EEA) and UK where applicable.
2. Scope
This Policy applies to:
- Klioso iOS app
- Klioso PWA / web app and websites (e.g., klioso.app)
- booking pages accessible via shared links
This Policy does not cover third-party websites/services you may access via links; their privacy policies apply.
3. Roles / Types of users
We process data related to:
- Professionals (account holders) using Klioso
- Clients/visitors accessing booking pages via a professional’s link (may be anonymous)
4. Data you provide
Depending on use, you may provide:
- Name (optional)
- Email address
- Phone number
- Profile photo (optional)
- Business name and service descriptions (optional)
- Work address/location (optional)
- Working hours/availability
- Service prices
- Client notes and service history
- In-app messages/content
5. Data collected automatically
We may collect technical and usage data such as:
- IP address
- Device type and operating system version
- Time zone and system language
- App/site interaction events (basic analytics)
- Crash logs and diagnostics
Identifiers: We may use Apple IDFV for app functionality/diagnostics. We do not use IDFA.
6. Booking pages
Professionals may share booking links. Clients/visitors may provide booking-related data (e.g., name, phone, email, appointment details) to schedule an appointment.
7. Authentication SMS (Firebase)
We may send SMS verification codes for registration/sign-in. These SMS messages are delivered using Google Firebase Authentication and its underlying SMS delivery partners. We process phone numbers and related verification metadata for this purpose.
8. Payments & subscriptions (Web/PWA vs iOS)
A) Web/PWA purchases (Paddle)
If you purchase on our website or PWA, payments are processed by Paddle.com as our Merchant of Record. Paddle processes payment details (such as card information), billing, invoicing, and applicable taxes under Paddle’s own privacy policy. We may receive limited information such as your email, purchase status, and transaction identifiers.
B) iOS purchases (Apple In-App Purchase)
If you purchase a subscription in the iOS app, payment is processed by Apple via In-App Purchase and Apple’s policies apply. We may receive limited information such as subscription status and transaction identifiers.
Payment card data: We do not store full payment card details on our servers.
9. Messaging reminders (WhatsApp/SMS)
Client reminders via messaging apps (e.g., WhatsApp) may be offered in the future. If enabled, we will share necessary data with the selected messaging provider (such as phone number, message template/content, and delivery metadata) solely to send reminders.
10. Storage & processing (Firebase)
We use Google Firebase (including Authentication and Firestore) to operate the Service. Data may be stored/processed on infrastructure located in the United States and/or Europe, depending on Firebase configuration and user location.
11. Data retention
- We retain data while your account is active.
- After you request account deletion, we delete personal data within 30 days, unless retention is required by law or for legitimate purposes (e.g., fraud prevention, accounting where applicable).
- We may retain limited purchase/transaction references as required for legal or accounting reasons.
12. Sharing with service providers
We may share data with trusted providers strictly to operate the Service, including: Google (Firebase), Apple, Paddle, SMS delivery partners, Email/push providers. We do not sell personal data.
13. Communications
We may send push notifications, transactional emails, marketing emails (optional), and verification SMS.
14. Cookies & web tracking
On websites/booking pages we may use essential cookies, analytics cookies, and marketing technologies (with consent).
15. Your rights (GDPR)
Where applicable, you may have the right to access, correct, delete, or export your data, and withdraw marketing consent. Contact support@klioso.app.
16. Children
Klioso is not intended for individuals under 18.
17. Security
We use SSL/TLS encryption in transit, encryption at rest, and access controls.
18. Changes
We may update this Policy. Material changes may be communicated via in-app notice or email.