1. Data controller
Koudt is a personal brand operated by its owner as a natural person, domiciled in Peru. As of the date of this policy, Koudt is not a registered legal entity. The owner is the controller of the personal data described in this document, in accordance with Law No. 29733, Peru’s Personal Data Protection Law, and the additional rules detailed in the "Regulatory framework applicable by region" section.
Identification of the owner: Jair Edson Revilla Arroyo, National ID (DNI) 47681389. Address: Av. Mello Franco 630, Apartment 1608, Jesús María, Lima, Peru. For purposes of this policy, any reference to "Koudt", "we", or "the controller" refers to this owner.
Contact channel for anything related to this policy: hello.world@koudt.dev. For app-specific inquiries, additional channels are listed in the corresponding annex.
2. Aniping: what it is and what data this annex covers
This annex applies specifically to the Aniping application (package com.jrevilla.aniping on iOS and Android), an anime tracker that alerts you when a new episode of a series you follow is released, with a calendar in your time zone and recommendations based on what you already watch. Aniping does not stream or host anime episodes — it is not a streaming service.
The controller for Aniping data is the same person identified in the “Data controller” section of this document. You may contact us specifically about Aniping at aniping@koudt.dev.
3. Account and authentication
To use Aniping, you need to create an account. You can do so with an email address and password (verified through a code sent to your email), or by signing in with Google, Apple, or Discord. When you use an external provider, we receive your email address, your name and, if the provider shares it, your profile photo — we never receive your password for those services or access to your Gmail, Google Drive, Calendar, or contacts.
- Account data: first name, last name, email address, password (stored as a hash, never in plain text), time zone, and optional avatar.
- Technical session data: IP address and user agent (browser or app type) associated with your active sessions, for security purposes.
- If you use external sign-in: the account identifier with that provider and the profile that provider shares with us (email, name, photo).
You may upload a profile photo from your gallery. That image is stored on our server and is made available only through a signed, temporary link; it is not publicly accessible.
4. Your anime library and activity
Aniping stores the anime you follow, including your status for each series (watching, completed, on hold, dropped, plan to watch), episode progress and, if you add them, a rating from 1 to 10 and free-text notes. This information is the basis of the app — without it we could not alert you about episodes or show you your calendar.
We also record catalog interaction events (which series you view, search for, or dismiss) in order to calculate recommendations. This is explained in more detail in the “Recommendations and affinity profile (automated decisions)” section.
5. Push notifications
If you enable notifications, we generate a device identifier (random, generated by the app itself, and not an advertising identifier or IDFA/AAID) and an Expo notification token, associated with your account and preferences: the alerts you want (new episode, subtitles, dubbing, untranslated version), quiet hours, nightly summary and its time, and “anti-spoiler” mode (which hides revealing titles and synopses in the notification).
Notifications are sent through Expo’s service (Expo Push Service), which in turn delivers them through Apple (APNs) or Google (Firebase Cloud Messaging), depending on your device. These providers act as processors solely for the technical delivery of the notification; they do not have access to the content of your library.
6. Recommendations and affinity profile (automated decisions)
To suggest anime you are likely to enjoy, we calculate an affinity profile from your own history: the genres and tags you prefer, the series you completed or dropped, and how recently you interacted with each one. This calculation is fully automated and takes place on our own servers, without human involvement in each individual recommendation.
This profile has no legal effect and does not affect you outside the app itself: it is not used to determine pricing, access to the service, or any kind of assessment of you as a person — it only determines which “recommended for you” cards you see. It is not high-risk processing under Article 22 of the GDPR because it produces no decision with legal or similarly significant effects on you; nevertheless, you have the right to ask us to explain how it works, and recommendations are never the only way to browse the catalog — you can always search and explore freely.
You may occasionally take part in internal experiments (A/B tests) concerning how we display recommendations or the catalog. These experiments do not change the data we collect, only how information is presented to you in the app.
7. Use of artificial intelligence in Aniping
Aniping includes, but as of this policy does not activate, an embeddings system (mathematical representations of text) provided by OpenAI to improve recommendations. While it remains inactive, we use our own internal calculation instead. If activated in the future, the only text sent to OpenAI would be catalog content (anime title, synopsis, and genres) to generate its representation — never your personal library, notes, rating, or any data identifying you. See also the general “Artificial intelligence” section of this document.
We plan, with no confirmed date, to assess the use of Gemini (Google) for future app features. If implemented, we will update this section before activating it.
8. Technical diagnostics and internal logs
We use Sentry to capture technical errors and app failures (crashes). Before sending any report, we automatically filter fields such as passwords, session tokens, avatars, and name or email data, to minimize what Sentry receives. We do not send personally identifiable information by default.
Internally, we also use a server request logging tool (Laravel Telescope) for technical debugging. These logs are for internal use, are not shared with third parties, and are retained for a limited period.
9. Aniping-specific providers
- AniList and AnimeSchedule — public anime catalog, synopses, cover images, and broadcast schedules. They do not receive your data; we only query them to display their content to you.
- LibreTranslate (our own infrastructure) — automated translation of catalog text into Spanish, English, and Portuguese. It does not process user data, only catalog content.
- Expo / EAS (United States) — delivery of app updates and push notification services.
- Sentry (United States) — error diagnostics, with the filtering described above.
- Google, Apple, and Discord — only if you choose to sign in with those providers.
10. Nature of the catalog
The Aniping catalog comes from public anime metadata sources and may include titles classified as adult content under those sources’ taxonomies. If you are below the legal age applicable in your country to access that type of content, you must not interact with it. We are working to improve filtering of this type of content in the catalog.
11. Retention and deletion of your Aniping account
We retain your Aniping account data while you keep your account active. To request deletion of your account, email us at aniping@koudt.dev — we are working to enable deletion directly in the app; until then, we process it manually within no more than 30 days of your request. Deletion removes your account, session tokens, verification codes, notification tokens, preferences, library, event history, affinity profile, and profile photo.
12. Artificial intelligence
This section applies to all Koudt products and summarizes our position on artificial intelligence in one place. Product-specific details are also provided in their respective annexes (“Use of artificial intelligence in Aniping” and “Use of artificial intelligence in Saldados”).
As of this policy, no Koudt product uses artificial intelligence to process users’ personal data in production. Aniping has a built but inactive OpenAI embeddings integration, which would process only catalog text (never user data) if activated. Saldados has planned, with no confirmed date, a premium voice-dictation feature for loans using Google Gemini.
Under Regulation (EU) 2024/1689 (the European Union Artificial Intelligence Act), the artificial intelligence functions described in this document are classified as limited-risk systems: they are subject to a transparency obligation (informing you that you are interacting with an automated system), but do not fall within the high-risk categories in Annex III of that Regulation. In particular, no Koudt AI function assesses anyone’s creditworthiness, makes decisions about access to credit or employment, or carries out any form of scoring or rating of individuals — if this changes in the future, we will update this policy and assess the applicable additional obligations before launching that function.
When you activate an artificial intelligence function within an app (such as Saldados voice dictation), we will clearly tell you at the time of use and request your separate, explicit consent before any data is processed through that function, particularly before accessing the microphone.
We do not use your personal data to train artificial intelligence models, whether our own or third parties’, without your separate, explicit consent. If any AI provider we use in the future offers to use data we send it to train its own models, we will seek to contract the option that excludes this, and will state it here if that is not possible.
When an AI function shows you a result (a recommendation or voice transcription), that result is an automated suggestion, not a guaranteed truth. You always have the option to correct it, ignore it, or perform the action manually instead.
13. Common providers and data processors
In addition to the app-specific providers detailed in their own annex, Koudt uses the following common providers, which act as data processors under Koudt’s instructions:
- Cloudflare, Inc. (United States) — website hosting (Cloudflare Pages), content delivery network and, for Saldados, file storage (Cloudflare R2).
- Brevo (Sendinblue SAS, France) — transactional email delivery: account verification, password recovery, and system notifications. It is not used for marketing unless you expressly subscribe to an updates list in the future.
- Apple Inc. and Google LLC — as application distribution platforms (App Store, Google Play) and, where paid subscriptions exist, as merchant of record for those charges.
The server running Aniping’s and Saldados’ backends is hosted with an infrastructure provider located in the United States. This involves an international transfer of data outside Peru and, for users in the European Union, outside the European Economic Area — see the "International data transfers" section.
14. International data transfers
The data collected by Aniping and Saldados is stored and processed on servers located in the United States. The koudt.dev website is served through Cloudflare’s global network, which may process traffic from data centers in different countries depending on the user’s location, without this implying persistent storage beyond what is described in this policy.
For users in Peru, this constitutes a cross-border flow of personal data under Law No. 29733 and its regulations. Koudt adopts as a safeguard the selection of providers with publicly documented security policies and, where the provider offers them, recognized certifications or compliance frameworks (for example, third-party adherence to the EU-US Data Privacy Framework, where applicable to the specific provider).
For users in the European Union and the United Kingdom, this transfer is safeguarded through Standard Contractual Clauses entered into with providers that offer them, or through the provider’s adherence to the EU-US Data Privacy Framework where applicable. You can request more information about the safeguards applicable to a specific provider by writing to hello.world@koudt.dev.
15. Data retention
As a general rule, we retain personal data for as long as you maintain an active account on the relevant app, plus any additional period necessary to comply with legal obligations, resolve disputes, or enforce our agreements. Each product annex details specific timeframes where they exist (for example, the restoration period after requesting account deletion).
Diagnostic and error-monitoring logs (see each annex) are retained for the relevant provider’s default period, typically between 30 and 90 days, unless it is necessary to keep them longer to investigate a specific security incident.
16. Security
We apply reasonable technical and organizational measures to protect personal data: encryption in transit (HTTPS/TLS) across all communications between the apps, the website, and our servers; passwords stored using hash functions (bcrypt) and never in plain text; session and password-recovery tokens with expiration; and storage of sensitive credentials on the device through the operating system’s secure mechanisms (Keychain on iOS, Keystore on Android) rather than plain storage.
No system is completely secure. If you have reason to believe your interaction with our services is no longer secure, or you discover a vulnerability, contact us immediately at hello.world@koudt.dev.
17. Advertising, subscriptions, and charges
As of this policy, Aniping and Saldados are free and display no advertising. Both applications are technically prepared to offer optional paid plans in the future (premium subscriptions by tier and feature package) and, in Aniping’s case, potentially advertising for users of the free plan. This section describes how we will process your data if this is activated, so it is documented in advance.
If we activate paid subscriptions, the Apple App Store or Google Play will act as merchant of record: they process the charge and receive payment data (card and payment method), not us. We receive from Apple or Google only confirmation that you have an active subscription and its tier, not your payment data.
If Aniping displays advertising to free-plan users in the future, we distinguish two scenarios by region: if you live in the European Union or the United Kingdom, we will request prior, explicit consent before showing personalized advertising, and you may use the app with non-personalized advertising if you do not grant it; if you live in the United States or other regions without that legal requirement, personalized advertising may be enabled by default with a clear opt-out mechanism in the app settings. We will never show personalized advertising to accounts identified as belonging to minors. On iOS, any cross-app tracking by third parties for advertising purposes will first be subject to Apple’s App Tracking Transparency permission.
18. User rights
Regardless of your country of residence, you can exercise the following rights over your personal data by writing to hello.world@koudt.dev (or the app-specific email listed in the annex of the app you use). We will respond within a maximum of 30 calendar days, or sooner if applicable law requires a shorter period.
- Access: know what personal data of yours we process.
- Rectification: correct inaccurate or incomplete data.
- Erasure (right to be forgotten): request deletion of your data, subject to applicable legal exceptions (for example, accounting or record-retention obligations).
- Objection: object to specific processing where it is based on our legitimate interest.
- Portability: receive your data in a structured, commonly used format where applicable law recognizes this right.
- Restriction of processing: request that we temporarily limit use of your data while a request is resolved.
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
When an app offers account deletion directly from its interface (see the corresponding annex), that is the fastest way to exercise your right to erasure. If your request relates to an app store (for example, your payment method), you may also need to contact Apple or Google directly, since Koudt does not have access to that data.
19. Regulatory framework applicable by region
Koudt applies a single set of privacy practices to all users, but some legal obligations vary depending on your country of residence. This section summarizes the applicable framework in each case. When two frameworks directly conflict, the relevant section explains which one prevails and why (see also "Advertising, subscriptions, and billing" for the conflict between the European withdrawal right and app store refund policies).
Peru — primary framework.
As a controller domiciled in Peru, Koudt is primarily governed by Law No. 29733, the Personal Data Protection Law, and its Regulations (Supreme Decree No. 003-2013-JUS), under the oversight of the National Authority for the Protection of Personal Data (ANPD), part of the Ministry of Justice and Human Rights. This law recognizes the rights of access, rectification, cancellation (equivalent to erasure), and objection — known as ARCO rights —, exercised through the same channels described in the "User rights" section.
European Union and United Kingdom — GDPR / UK GDPR.
If you reside in the European Union or the United Kingdom, your data processing is also governed by the General Data Protection Regulation (GDPR) and, where applicable, the UK GDPR. The legal basis for each processing activity is indicated in the corresponding product annex; it is typically contract performance (providing the service you requested), consent (for example, for the contact form’s checkbox or for optional AI features), or legitimate interest (for example, fraud prevention and security). There is currently no representative designated in the European Union under Article 27 of the GDPR; we are assessing whether the volume of European users makes designating one necessary. You have the right to lodge a complaint with the supervisory authority of your country of residence.
United States — CCPA/CPRA (California).
If you reside in California, the California Consumer Privacy Act, as amended by the California Privacy Rights Act (CCPA/CPRA), grants you the right to know what categories of personal information we collect, to request its deletion, to correct it, and not to be discriminated against for exercising these rights. Koudt does not sell or share personal data for targeted-advertising consideration, so a "do not sell my data" mechanism does not apply — there is nothing to opt out of because that practice is not carried out.
Brazil — LGPD.
If you reside in Brazil, the Lei Geral de Proteção de Dados (LGPD) grants rights equivalent to those described in "User rights", and you may also file a complaint with Brazil’s National Data Protection Authority (ANPD).
Mexico — LFPDPPP.
If you reside in Mexico, this document serves as the privacy notice required under the Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP). You may exercise your ARCO rights before INAI (National Institute for Transparency, Access to Information and Personal Data Protection) if you believe we did not properly address your request.
Colombia — Law 1581 of 2012.
If you reside in Colombia, Law 1581 of 2012 and its implementing decrees apply, under the oversight of the Superintendence of Industry and Commerce (SIC). We recognize your right to know, update, rectify, and delete your data, and to revoke consent given.
Conflict-resolution rule: when one regulatory framework’s obligation is stricter than another’s for the same processing activity (for example, requiring prior consent versus allowing a later opt-out model), Koudt applies the rule that is more protective of the user within their own region, rather than imposing the strictest rule on all users worldwide. This means, for example, that the prior-consent model for advertising applies to users in the European Union, while users in the United States are offered an opt-out mechanism, in line with what each framework requires in its own territory — see the details in "Advertising, subscriptions, and billing".
20. Minors
None of Koudt’s products are directed at children under 13, and we do not knowingly collect personal data from children under that age. If you are between 13 and the age of legal majority in your country of residence, you must have authorization from your parent or legal guardian to use Aniping or Saldados and create an account.
If you are a parent or legal guardian and have reason to believe a minor in your care has provided us with personal data without your authorization, write to us at hello.world@koudt.dev and we will remove that information within a reasonable timeframe.
21. Changes to this policy
We may update this policy to reflect changes in our practices, our products, or applicable regulations. If the change is material (for example, a new type of data collected, a new provider processing sensitive data, or the activation of an artificial intelligence feature currently described as inactive), we will notify you within the app or by email before it takes effect, in addition to updating the date at the top of this document.
22. Contact
For any question about this policy or to exercise your rights, write to us at hello.world@koudt.dev. For Aniping-specific inquiries, you can also write to aniping@koudt.dev.