App privacy

krinIA app privacy policy

This page describes how Clanksy processes the data collected through the krinIA mobile app and the web dashboard (krinIA for the centre's owner, Clanksy Control for internal administration). Last revised: 14 July 2026.

Data controller

Andrea Emanuele, empresario individual (autonomo), trading name "Clanksy", NIF Z2547626J, Calle Marva 12, planta 7, puerta 14, 46007 Valencia, Spain, provider of the krinIA product. Contact: legal@clanksy.ai.

Data collected through the app

Account phone number (E.164) and email
Collected during authentication with a one-time code (OTP) and for operational communications. Used to identify the centre's owner and link them to their business. Kept for as long as the account is active. Deletable on request.
Camera and photo library (optional)
The app may ask for access to the camera and photo library only when the owner chooses to upload a photo (e.g. photos of the centre or of the work done, for marketing content). No background access. The photos uploaded are kept as marketing assets of the centre; the permission can be revoked at any time from the device settings.
Device identifier + push token
Generated automatically by the operating system. Used to send push notifications for HITL approvals (reviews, Instagram posts, offers) and operational alerts. Deleted automatically when the app is uninstalled or push permissions are revoked.
Content of customer WhatsApp messages
The messages sent and received by the centre's end customers through the krinIA system are stored in the internal database in order to: (1) manage the conversation, (2) generate reports for the owner, (3) adapt the assistant's replies to the centre's context (instructions and internal memory: no training of external AI models).
Voice calls (if the voice receptionist is active)
We do NOT record the call audio. The transcript is processed at runtime to extract information useful to the service (customer preferences, booking requests), then the full transcript is deleted within 4 hours of the call. We keep only: a condensed AI summary (50-200 characters), the outcome (e.g. "booked", "escalated to manager", "info"), call duration, caller number. No audio, no permanent text transcription.
Bookings, customers, reviews
Operational data of the centre (customer name, phone, services booked, reviews received) synchronised via Booksy/Treatwell/Fresha email forwarding or entered through the app. Kept for the duration of the subscription.
App usage data (internal analytics)
Interaction events (which tabs you open, which approvals you make, LLM costs per turn). Used to improve the product. No third-party analytics such as Google Analytics or Mixpanel.

Instagram connection (Meta)

If the owner connects the centre's Instagram account (optional feature, from the app's Settings), krinIA connects through "Instagram API with Instagram Login": the owner logs in directly with their own Instagram Business or Creator account and authorises krinIA to publish the content they approve. A Facebook Page is not required.

Permissions requested
instagram_business_basic (to identify the connected Instagram Business or Creator account), instagram_business_content_publish (to publish the posts and reels that the owner approves in the app).
Data kept
Access token (encrypted at rest), ID and username of the connected Instagram account, list of the permissions granted and the token expiry date. We do not collect or keep the personal data of followers or of those who comment on the posts.
What we use them for
To publish on Instagram only the content that the owner explicitly approves in the app (never automatic publication in the background).
How to revoke
At any time from the app (Settings → Revoke connection): krinIA revokes the token with Meta and deletes the credentials. You can also remove "Krinia" from the Instagram settings (Settings → Authorised apps and websites): Meta notifies us and we delete the linked credentials. Full instructions at krinia.com/data-deletion.

What we use the data for

What we do NOT do

Personalisation of the assistant for the owner

To give you an assistant that works the way you like, Krinia stores the operational preferences you tell it ("remember that...") and learns from your choices in using the service (for example how you edit the drafts before approving them), including the personal context information that you voluntarily choose to share in chat. Legal basis: performance of the contract (art. 6.1.b GDPR) and legitimate interest in improving the service (art. 6.1.f). We never store health-related data. You can see, correct or delete at any time everything Krinia remembers about you from the "Your profile with Krinia" section in the app, or disable the feature entirely. Retention: items that are no longer active are deleted after 24 months.

Technical providers

Data is processed through these providers, with access limited to what is necessary:

Transfers outside the EU

The data of the centre's customers (database, backups, AI processing on LLMs, embeddings and voice transcription) stays on EU infrastructure: Railway region europe-west4 Amsterdam for database and workflows, Google Cloud Vertex AI European endpoint for the AI processing, Scaleway (France) for disaster recovery and Brevo (France) for the transactional emails. fal.ai, Expo and Cloudflare are based in the USA: they receive only data that does not include the centre's end customers (marketing prompts and assets, push token, encrypted network traffic). For these residual transfers, the Standard Contractual Clauses (SCC) approved by the EU Commission (Decision 2021/914) apply, or the EU-US Data Privacy Framework where the provider is certified. For specific questions write to legal@clanksy.ai.

Retention

We keep the centre's operational data (customers, bookings, conversations) for the entire duration of the subscription. After the account is deleted, we keep the data in "cold storage" mode for 30 days to allow recovery in case of error, then permanent deletion.

For specific data of the centre's end customers (e.g. a customer who asks to be deleted via WhatsApp with the STOP keyword): immediate deletion + permanent opt-out.

User rights

You have the right to: access, rectification, erasure, restriction, portability, objection. You can also withdraw your consent where the processing is based on consent.

To exercise your rights write to us at legal@clanksy.ai. For complaints, you can contact the Italian Garante della Privacy (garanteprivacy.it) or the Spanish AEPD (aepd.es).

Security

Automated decisions

The app uses artificial intelligence to: (1) classify the intent of customer messages, (2) generate draft replies, (3) propose operational actions (recall, offers). All decisions with an impact on the end customer require explicit confirmation from the centre's owner via the app (HITL mode, Human In The Loop). No automatic decision is applied without human supervision for actions visible to the end customer (reviews, IG posts, WhatsApp marketing offers).

Minimum age

The app is intended for owners of beauty centres who are of legal age. We do not intentionally collect data from minors. If you believe that a minor has provided data by mistake, write to us and we will delete it immediately.

Updates

If we materially change how we process data, we will update this page and will notify you via the app or WhatsApp before it takes effect. Minor changes (wording, refinements) are published without notice.