This Privacy Policy explains how Crystalab LLP collects and uses personal information when you use the kaldr mobile application, the kaldr website, and related support services (together, the Services).
Crystalab LLP is the controller of your personal information:
- Legal name: Crystalab LLP
- Company number: OC446298
- Registered office: 71–75 Shelton Street, London, WC2H 9JQ, United Kingdom
- Privacy contact: privacy@kaldr.app
- Support contact: support@kaldr.app
This Policy is effective from July 13, 2026.
1. Scope
kaldr is a wellness and fitness application for guided breathing and cold shower practice. It is intended only for adults aged 18 or over.
This Policy covers information processed through the Services. Third-party services, including Apple, Google, advertising partners, and app stores, also process information under their own privacy policies.
2. Information we collect
Account and authentication information
When you create or use an account, we may process:
- Your Firebase user ID
- Your display name and email address
- Your selected sign-in method
- Account creation and last sign-in information
- Authentication, password-reset, and account-security records
- Your onboarding status and starred practices
You may sign in using email and password, Google, or Apple. Google or Apple may provide us with your name, email address, provider identifier, and authentication credentials. Apple may provide a relay email address if you use Hide My Email. We do not receive your Google or Apple password.
Practice and progress information
To provide session history, synchronisation, recovery, streaks, and progress features, we process:
- The type of practice you perform
- Session start and end times, duration, and completion status
- Breathing settings, breath counts, retention times, and recovery times
- Cold-shower preparation and shower durations
- Last-used practice settings
- Streaks, totals, recent-session information, and other derived statistics
- Whether a session was completed or interrupted
- The platform and kaldr application version used for a session
These data describe wellness and fitness activity. Depending on applicable law and how they are interpreted, they may be considered health-related or sensitive information. We use them to provide features you request; we do not use them to diagnose a condition, infer a medical diagnosis, determine insurance or employment eligibility, or personalise advertising.
kaldr does not intentionally collect medical records, diagnoses, treatment information, heart rate, biometric sensor data, precise location, contacts, photos, camera recordings, or microphone recordings. It does not store raw per-breath sensor telemetry.
Information stored on your device
kaldr stores certain information locally so the app works reliably and offline. This may include:
- Appearance, haptic, and audio preferences
- Onboarding and safety-notice acknowledgements
- Authentication state
- A local Firestore cache and pending offline session writes
- Analytics, advertising, and diagnostic consent choices
- Advertising, analytics, installation, and crash-reporting identifiers used by the SDKs described below
Signing out clears the kaldr Firestore cache on that device. Other local data may remain until you clear the app's data or uninstall it.
Analytics information
With your consent, we use Google Analytics for Firebase and PostHog to understand how the Services are used and improve their design and reliability. These services may process:
- Pseudonymous installation, device, session, and analytics identifiers
- Screens viewed and features or buttons used
- General session events, such as starting or completing a practice
- Referrer, campaign, and attribution information
- Device type, operating system, language, application version, and general network information
- Approximate location derived from an IP address
- Event timestamps and performance information
We do not intentionally send your name, email address, precise retention or shower durations, session notes, or medical information to analytics providers. We do not use PostHog session replay or capture text entered into forms.
Crash reports and diagnostics
With your consent, we use Firebase Crashlytics and Sentry to detect and repair crashes and technical errors. They may process:
- Crash stack traces, error messages, technical logs, and breadcrumbs
- Pseudonymous installation, crash, and event identifiers
- Application version and configuration
- Device model, operating system and version, available memory, storage, and processor information
- Whether a device is rooted or jailbroken
- Network and IP information, approximate location derived from IP, and event timestamps
We configure diagnostic tools to limit personal information, scrub common sensitive fields, and avoid intentionally attaching your name, email address, or practice details to reports.
Advertising information
kaldr displays advertising using Google AdMob and the advertising partners identified in the consent and privacy-choices interface. Depending on your choices, location, device settings, and applicable law, advertising providers may process:
- Advertising, installation, device, and app identifiers
- IP address and approximate location
- Device, operating system, language, and app information
- Ad requests, impressions, clicks, conversions, and fraud-prevention signals
- Consent choices and whether advertising should be personalised or limited
- Activity across apps or services where you have consented to personalised or cross-context behavioural advertising
We do not provide advertising partners with your name, email address, account profile, breathing retention times, cold-shower durations, or session history.
If you do not consent to personalised advertising, kaldr may show limited, contextual, or non-personalised ads. Even limited ads may use IP addresses and limited device storage for delivery, security, fraud prevention, frequency capping, and aggregated reporting.
On Apple devices, where required, kaldr will request permission through Apple's App Tracking Transparency framework before allowing tracking across other companies' apps or websites. Refusing tracking does not prevent you from using kaldr.
Website and network information
When you visit kaldr.app, our hosting provider, Vercel, and its security systems may process request and diagnostic information such as:
- IP address and approximate IP-derived location
- Browser, operating system, device type, and user agent
- Requested page, referrer, timestamps, response status, and security events
The website does not currently set advertising cookies. If optional website analytics or advertising technologies are enabled, they will not run where consent is required until you make a choice.
Communications and marketing
If you contact us, we process your email address, message, attachments, and information needed to respond. If you separately opt in to marketing, we may send product news, offers, or surveys. You can unsubscribe at any time using the link in the message or by contacting us. Account, security, support, password-reset, and legal notices are service communications rather than marketing.
3. Why we use information and our legal bases
We use personal information for the following purposes:
- To provide the Services and perform our contract with you: creating and securing your account, recording and synchronising sessions, maintaining settings, recovering interrupted sessions, showing progress, and providing support.
- With your consent: processing health-related practice information where applicable law requires explicit consent; running optional analytics and diagnostics; accessing device identifiers or storage for advertising; personalising ads; tracking across other companies' services; and sending marketing.
- For our legitimate interests: protecting accounts and infrastructure, detecting fraud and abuse, enforcing our Terms, maintaining essential service logs, responding to support requests, and understanding aggregate service reliability, provided those interests are not overridden by your rights.
- To comply with legal obligations: responding to lawful requests, maintaining required records, protecting legal rights, and complying with tax, consumer, privacy, and regulatory duties.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that was lawful before withdrawal.
4. Advertising, sale, and sharing
Crystalab does not sell personal information for money.
Personalised advertising can involve disclosing identifiers and activity to advertising partners and may be considered a sale, sharing, or targeted advertising under some US state privacy laws even when no money is exchanged. Where those laws apply, you may opt out through Settings → Privacy choices in the app or by emailing privacy@kaldr.app. We do not knowingly sell or share the personal information of anyone under 18.
You can review or change advertising consent through the in-app privacy options. Device-level settings, including Apple's tracking control and Android advertising controls, may provide additional choices.
5. When we disclose information
We disclose information only as needed for the purposes described in this Policy:
- Google: Firebase Authentication, Cloud Firestore, Firebase Analytics, Firebase Crashlytics, Google Sign-In, Google AdMob, and consent management.
- Apple: Sign in with Apple, App Tracking Transparency, and App Store distribution.
- PostHog: product and usage analytics.
- Sentry: crash reporting, error monitoring, and diagnostics.
- Vercel: website hosting, content delivery, request logs, and security.
- Apple App Store and Google Play: app distribution and, if introduced, store-managed purchases.
- Authorised Crystalab personnel: access limited to people who need the information for development, security, support, or legal administration.
- Professional advisers and authorities: where reasonably necessary for legal advice, audits, claims, compliance, safety, or a valid legal request.
- Corporate transactions: if Crystalab is involved in a merger, reorganisation, financing, or sale, subject to appropriate confidentiality and notice requirements.
Advertising partners shown in the consent interface may act as independent controllers under their own privacy policies. Current provider information is available from Google, PostHog, Sentry, Apple, and Vercel.
6. International transfers
We offer the Services worldwide and use providers operating internationally. Your information may therefore be processed outside your country, including in the United Kingdom, European Economic Area, and United States.
The production Cloud Firestore database uses Google's nam5 United States multi-region. Other providers may process information in the region selected for our account and in locations used by their subprocessors.
Where required, we rely on adequacy regulations, the UK International Data Transfer Addendum or Agreement, European Commission Standard Contractual Clauses, provider participation in an applicable data privacy framework, and other lawful safeguards. You may contact us for more information about the safeguards relevant to your information.
7. Retention
We apply the following retention approach:
- Account, configuration, practice, and progress information is kept while your account remains active and is deleted when you delete the account, subject to limited legal exceptions.
- We do not currently delete accounts merely because they have been inactive.
- Event-level analytics information is configured to be retained for no more than 14 months unless a shorter period is required or selected.
- Crash and diagnostic events are normally retained for no more than 90 days.
- Advertising providers retain information according to your consent choices, their policies, and their fraud-prevention and legal requirements.
- Support correspondence is normally retained for up to 24 months after the matter is closed. Records needed for legal claims, regulatory compliance, or accounting may be retained for up to six years or longer where legally required.
- Website and security logs are retained according to our provider settings and only as long as reasonably needed for operations, security, and abuse prevention.
Deletion from active systems may not immediately remove information from provider backups, security logs, or records that must be retained by law. Such information is isolated from normal use and removed or anonymised under the relevant retention schedule.
8. Account deletion
You can delete your account in the app through Settings → Danger zone → Delete account. You will be asked to confirm and reauthenticate. This deletes the known Firestore account subtree, including your profile, settings, session history, and aggregate statistics, and then deletes the Firebase Authentication user.
If you cannot access the app, email privacy@kaldr.app from the address associated with your account. We will verify control by sending a message to the account email. If we reasonably doubt identity, we may request limited additional information that is proportionate to the request.
See the account deletion page for instructions.
9. Your privacy rights
Depending on where you live, you may have rights to:
- Receive information about how we process your information
- Access and obtain a copy of your information
- Correct inaccurate or incomplete information
- Delete information
- Restrict or object to certain processing
- Withdraw consent
- Receive certain information in a portable format
- Opt out of targeted advertising, sale, or sharing
- Appeal a decision concerning a privacy request
- Complain to a privacy regulator
To exercise a right, email privacy@kaldr.app. We normally respond within one month, or within the period required by applicable law. We do not discriminate against you for exercising privacy rights.
UK users may complain to the Information Commissioner's Office. EEA users may also complain to the supervisory authority where they live or work. Users elsewhere may contact their local privacy regulator.
10. Automated processing
Analytics and advertising providers may use automated systems to measure activity, select ads, prevent fraud, or create advertising audiences where you have consented. Crystalab does not use your practice information to make solely automated decisions that produce legal or similarly significant effects.
Automated security signals may flag unusually high request or session volumes, multiple accounts used to evade restrictions, or other suspected abuse. Where practicable, a person reviews relevant information before a non-urgent account termination. Immediate restrictions may be applied where necessary to protect users, data, or the Services.
11. Security
We use technical and organisational safeguards designed to protect personal information. These include encrypted transmission, provider access controls, server-side Firestore rules that restrict users to their own data, limited personnel access, and reauthentication before account deletion.
No system is completely secure. Please use a strong, unique password and tell us promptly if you believe your account or information has been compromised.
12. Adults only
kaldr is intended only for people aged 18 or over. We do not knowingly allow minors to create accounts. If you believe a person under 18 has provided information, contact privacy@kaldr.app so we can investigate and delete it where appropriate.
13. Changes to this Policy
We may update this Policy to reflect changes to the Services, providers, technology, or law. We will update the date at the top. For material changes, we will also provide reasonable advance notice by email or a prominent in-app notice where practicable or legally required. We will request fresh consent before beginning a new use where consent is required.
14. Contact and complaints
For privacy questions, rights requests, or complaints, contact:
Crystalab LLP
71–75 Shelton Street
London, WC2H 9JQ
United Kingdom
privacy@kaldr.app
For general product support, email support@kaldr.app.