Draft pending legal review. This text is not yet in force. Items marked
[POR COMPLETAR](to be completed) and[VERIFICAR](to be verified) are resolved with the lawyer before publication.
1. Who is responsible
Siluo is a gym app with a 3D digital twin. It is operated by an individual in Colombia, who is the controller of your personal data.
- Controller:
[POR COMPLETAR] - Identification document:
[POR COMPLETAR] - Address:
[POR COMPLETAR] - Privacy contact: [email protected]
2. Legal framework
We process your data under Colombian Law 1581 of 2012 and Decree 1377 of 2013. We also use the European Union’s General Data Protection Regulation (GDPR) as a standard, even though in the first year the app is offered only in Latin America.
3. What data we process
If you join the waitlist
- Your email address.
- The language of the page (Spanish or English).
- The sign-up source: where you came from to reach the list (a short text, for example the page or the campaign).
- The date and time of sign-up.
If you use the app
- Account: your email and technical access data (for example, the session).
- Profile: display name, birth year, height, units, language, the avatar’s base body and the avatar’s color.
- Workouts: sessions, exercises, sets, reps, weights and notes.
- Body measurements: weight, circumferences and, if you want, body fat percentage. This is health data.
- Progress photos (optional): this is health data. By default they stay only on your phone.
- Consents: what you accepted, in which version and when, and whether you revoked it.
- Subscription: when it exists, the status of your plan. Apple handles the payment; we do not see your card.
- Requests about your data: that you asked to export or delete, and when.
Sensitive data
Body measurements and progress photos are sensitive health data. We process them only with your explicit, informed consent, which is separate from the others and can be revoked at any time. Giving us this data is optional. Without that consent, the app works with the bare minimum.
Analytics
Usage analytics are turned on only if you accept them (opt-in). Events carry no personal data that identifies you. If you do not accept, nothing is sent. Technical errors in the app are reported without personal data.
4. What we use your data for
- To create and maintain your account and let you sign in.
- To store your workouts and measurements and show them to you, including your digital twin.
- To calculate your statistics and progress.
- To manage your subscription when it exists.
- To send you the access emails you need (confirmation and sign-in link).
- To answer your questions and requests.
- To tell you about the launch, if you are on the waitlist.
- To improve the app, only if you accepted analytics.
- To meet legal obligations and protect the security of the service.
We do not use your health data for advertising or to train third-party models. We never sell it.
5. Legal basis
- Your prior, express and informed authorization (Law 1581 of 2012): for the waitlist, the account, the profile, health data, photos and analytics.
- Performing the service you ask for: to store your workouts and give you the app’s features.
- Compliance with legal obligations: when the law requires us to keep or hand over information.
- Explicit consent (GDPR, art. 9) for health data, if the GDPR applies to you.
You can revoke your authorization whenever you want. Revoking does not affect what was done before you revoked.
6. Who else sees your data (processors)
We use providers that process data on our behalf and under contract. They do not use it for their own purposes.
| Provider | What for | Status |
|---|---|---|
| Supabase | Database, account access, file storage | In use |
| Resend | Access emails (confirmation and sign-in link) | In use |
| Cloudflare | Website, waitlist and incoming email (hola@, privacidad@, etc.) | In use |
| Expo (EAS) | App builds and updates; it does not receive user data | In use |
| RevenueCat | Subscription management | Future, once subscriptions exist |
| PostHog | Product analytics, only if you accept them | Future |
| Sentry | Error reporting without personal data | Future |
| Anthropic | Weekly AI reading, with your separate consent and data without identifiers | Future (later version) |
If this list changes, we will update this policy. [VERIFICAR] That each data processing agreement is signed before publication.
7. International transfers
Our providers store data in the United States (the database is in the US East region) and, depending on the service, in other countries. The United States and Spain are listed as destinations with an adequate level of protection by the Superintendence of Industry and Commerce. [VERIFICAR] If the GDPR applies to you, we use standard contractual clauses or another valid mechanism with each provider.
8. How long we keep your data
- While you have the account: we keep your data to provide the service.
- If you delete the account: we erase it within a maximum of 30 days, including photos you uploaded to the cloud. See the page Delete your account.
- Waitlist: until you unsubscribe or until a reasonable period after launch
[POR COMPLETAR](period). - Legal obligations: only what is strictly necessary, for as long as the law requires
[VERIFICAR].
9. Your rights
You have the right to:
- Know what data of yours we process and why.
- Update and rectify your data if it is inaccurate or incomplete.
- Delete your data and ask us to stop processing it.
- Revoke your authorization, at any time.
- Portability: receive your data in a format you can read and reuse.
- Ask for proof of your authorization and for information about how we have used your data.
- File a complaint with the Superintendence of Industry and Commerce of Colombia, or with the authority in your country.
How to exercise them
Write to [email protected] from the email you signed up with. Tell us what you want to do. If you are asking to delete your account, see the page Delete your account. From the app you will be able to export your data and manage your consents.
We may ask you for reasonable verification that you are the data subject before replying.
Deadlines
- Inquiries: we reply within a maximum of 10 business days. If we cannot, we will tell you and give you a new date, which will not exceed 5 more business days
[VERIFICAR]. - Claims (rectify, delete or revoke): we reply within a maximum of 15 business days. If we cannot, we will tell you and give you a new date, which will not exceed 8 more business days
[VERIFICAR].
10. Minors
Siluo is for people aged 16 or older. We do not create accounts for anyone under that age. If we find that an account belongs to a minor, we delete it. If you think this has happened, write to us at [email protected]. [VERIFICAR] That the minimum age of 16 is valid in every country where the app is offered.
11. Security
- Each person can only read and write their own data: the database enforces this with per-user access rules (RLS).
- Data travels encrypted (TLS) and is stored encrypted at rest.
- The session is kept in the phone’s secure storage.
- Progress photos stay on your phone by default. If you turn on cloud backup, they go to a private space, with temporary links; on your phone, location and camera information (EXIF) is removed and the face is blurred before they are uploaded.
- No secret server key is inside the app.
- If a security breach affects you, we will tell you and notify the authority when the law requires it.
No system is perfect. If you find a security flaw, write to [email protected].
12. What we never do
- We do not sell your data.
- We do not use your data for advertising.
- We do not share your health data with advertisers or data brokers.
- We do not track you across other apps.
13. Changes to this policy
If we change this policy, we will publish the new version here with its date. If the change is important or affects what you authorized, we will tell you in the app or by email and ask for your consent again when needed.
Last updated: 2026-10-06 (draft).