Política de privacidad

Última actualización: 17/07/2026

Borrador v2 · pendiente de revisión legal — la entidad, el correo de contacto, la fecha de entrada en vigor y la ley aplicable son marcadores y se completarán antes de su vigencia.
La traducción a este idioma llegará tras la revisión legal; a continuación se muestra el texto completo en inglés.

Kolibio Privacy Policy

Effective date: {{EFFECTIVE_DATE}} · Operator: {{COMPANY_LEGAL_NAME}} · Privacy contact: {{CONTACT_EMAIL}}

Kolibio is an iOS app that helps restaurant operators manage inventory, documents, costs, orders, and payroll estimates. This policy explains how data you create while using Kolibio is handled. Please read it before use.

1. What we collect and store (Data Collection)

⚠️ This section must be rewritten (cloud shipped 2026-07-21). Current reality: the app has real accounts (Sign in with Apple) and a cloud server; your business data syncs to our servers, which are the source of truth, with a local cache and an offline write queue on device. The text below is retained only as a reference for the rewrite:

CategoryContentsLocation
AccountDisplay name, linked email, local identifierDevice only
Organization & storesBrands, store names, store address & coordinatesDevice only
Business dataVendors, invoices, orders, inventory, costs, prices, dishes & recipesDevice only
Employee dataNames, positions, pay rates/records, attendance hours, punch-in location coordinates & distanceDevice only
FilesInvoice/menu images & PDFs, Excel files you selectApp sandbox
AI keyYour own OpenAI API key (if enabled)iOS Keychain (encrypted)
Plan/credit recordsPlan selection, credit counters (no real billing yet)Device only

We (the developer) cannot access any of the above. We do not collect your business data or build a profile of you.

2. How data is used (Data Use)

Data is used solely to provide features on your device: cost and margin calculation, inventory deduction, payroll estimates, charts, and local reminders. All computation happens on-device.

3. When data leaves your device (Third Parties)

Only two flows send data off the device, both under your control:

(a) AI recognition (OpenAI) — off by default; requires your explicit opt-in and consent.

If you enter your own OpenAI API key in Settings → AI Recognition, turn the feature on, and confirm consent, then when you start an invoice/menu scan, the images or PDF pages you capture or select are sent to OpenAI (api.openai.com) for recognition. These images may contain business information such as vendor names and prices. Requests go directly from your device to OpenAI using your key and are governed by OpenAI's terms and privacy policy; we never receive or see your images or results. You can disable the feature or delete the key at any time; when disabled, recognition uses on-device OCR only, with zero network requests. Employee timecard/attendance files are never sent to AI and are always parsed on-device.

(b) Advertising (Google AdMob).

The app includes the Google Mobile Ads SDK for the optional rewarded-video feature. When an ad is shown, Google may collect device identifiers (such as IDFA, subject to your App Tracking Transparency choice), IP address, and device signals for ad serving and measurement, governed by Google's privacy policy. The system ATT prompt appears before the first ad; declining does not affect core features (ads may become non-personalized). If you never use the ad feature, no ads are shown.

Beyond these two flows, we do not sell, share, or upload any of your data. Any "data sharing" style toggles in Settings are local placeholders and send nothing externally.

4. Permissions

  • Camera/Photos: only for invoice/menu recognition and image selection you initiate.
  • Location (while using): only for (i) pinning your store address during setup and (ii) verifying distance to the store when an employee punches in/out (punch coordinates are stored on-device only, for the owner to review attendance anomalies).
  • Notifications: local reminders only (inventory, documents, orders), sent by your phone, no server involved.
  • Face ID: only for the optional app lock / sensitive-action lock you enable. It is an access gate, not data encryption.
  • All permissions can be revoked anytime in system settings.

5. Special note on employee data

If you (the owner) enter employees' names, pay, attendance, or enable location-verified punch-in, you are the data controller for that personal information. You should ensure: (i) a lawful basis under local law; (ii) employees are informed (including that punch-in records location); (iii) the data is used only for workforce management. Kolibio merely stores this data on your device on your behalf and does not upload or access it.

6. Retention and deletion

  • Data stays on your device until you delete it: Profile → Account Data → Clear Local Data wipes all business data and redeemed benefits; uninstalling the app removes its data from the device.
  • Original files you import/capture live in the app sandbox and are removed by clearing data or uninstalling.
  • Because there is no cloud, there is no server-side copy for us to retain or delete — we hold no copy of your data.
  • Backups are your responsibility: use iOS backups; loss from device changes, uninstalls, or system failure cannot be recovered by us.

7. Your rights

You have full control over all data on your device: view, edit, or delete at any time. Since we collect no personal data, requests under GDPR/CCPA and similar laws addressed to us as a controller generally have no corresponding data on our side; for data processed by OpenAI or Google, please exercise rights under their respective policies. For any privacy question or request, contact {{CONTACT_EMAIL}}; we will respond within a reasonable period.

8. Children

Kolibio is intended for restaurant operators, not for people under 16. We do not knowingly collect children's personal information.

9. Security

The API key is stored in the iOS Keychain; other data is protected by the iOS sandbox and device encryption. Please set a device passcode and use irreversible actions such as "Clear Data" with care.

10. Future cloud features

This commitment is now due: accounts, cross-device sync, and platform AI recognition all shipped on 2026-07-21. This policy must be rewritten for the new data flows before launch, with prominent in-app consent. Team collaboration and remote push are not yet implemented.

11. Changes & contact

Material changes will be announced in the app with an updated effective date. Questions: {{CONTACT_EMAIL}} ({{COMPANY_LEGAL_NAME}}).