The controller for the processing described in this document is:
We have not appointed a data protection officer, as we consider that the conditions in Article 37 GDPR are not met: we carry out no regular and systematic monitoring on a large scale and process no special categories of data.
The controller is established in Chile and the app is distributed internationally, including in the European Union and the United Kingdom. Regardless of the country you use the app from, you can exercise your rights over your data by writing to the contact email above, and your request will be handled.
As regards the data Google collects through AdMob, Google acts as an independent controller on the terms set out in its own terms and policies. We do not receive, access or have any way of retrieving that data.
This policy covers the "Anatomy" mobile app for Android and iOS and the site where this document is hosted. It does not cover the practices of Google, Apple or any other company whose services you use outside the app; for those, see their own policies, linked in the annex.
Anatomy is an educational human anatomy app. It includes ten organs in interactive, photorealistic 3D (brain, eye, lungs, heart, liver, pancreas, kidneys, intestine, skin and stomach). For each organ it offers a description, six facts (size, weight, location, tissue, blood supply and daily fact), around 35 labelled hotspots on the model with their detail text, and eight related diseases. It also includes a quiz mode played directly on the 3D model (of the "tap the left ventricle" kind) and a four-screen tutorial flow.
All of that content ships inside the app binary and works offline. There are no accounts, no subscriptions and no in-app purchases. The app is currently available in English and Spanish, with plans to expand to thirteen languages. It is intended for people aged 13 and over.
It is an educational and informational application: it makes no diagnosis, does not assess your health and is not a substitute for consulting a healthcare professional. That matters for privacy too, because it means the app does not need — and never asks for — any information about you.
This is not a statement of intent: it is what was verified by reading the app's source code.
The app stores ten preferences in local device storage (DataStore). All of them are booleans, integer counters or timestamps. None identifies anyone, none is transmitted and none ever leaves your device.
| Technical key | Stored value | What it is for | Type |
|---|---|---|---|
onboarding_visto | Onboarding seen | So the welcome flow is not shown again on every launch | boolean |
consentimiento_rechazado | Consent declined | To remember that you said no and not ask again | boolean |
numero_arranques | Launch count | Local counter used to decide when it makes sense to ask for a rating | integer |
acciones_completadas | Completed actions | Local counter used for the same purpose | integer |
fecha_ultima_review | Date of last review prompt | So you are not asked to rate the app twice in a row | timestamp |
version_ultima_review | Version of last review prompt | So you are not asked to rate a version you already rated | integer |
recompensa_desde | Reward valid from | Start of the ad-free period earned with a rewarded video | timestamp |
recompensa_hasta | Reward valid until | End of that same period | timestamp |
ultima_oferta_recompensa | Last reward offer | So the rewarded video is not offered over and over | timestamp |
tutoriales_vistos | Tutorials seen | So tutorials you already completed are not repeated | boolean |
Storage of Google's own SDKs. The ten values above are all that our code stores. Independently of that, the Google components integrated into the app (the UMP consent platform and the ads SDK) maintain their own local storage on the device, for example to keep your consent decision.
To the extent these values could be regarded as personal data because they are tied to your device, they are processed because they are necessary to provide the service you asked for: an app that behaves consistently across sessions and does not replay onboarding (strictly necessary storage for the purposes of Article 5(3) of Directive 2002/58/EC and, so far as applicable, legitimate interests under Article 6(1)(f) GDPR). They are erased entirely when you uninstall the app and, on Android, also when you use the system option to clear the app's data.
On Android, our application's own manifest declares a single permission: android.permission.INTERNET, which is what allows ads to be shown. No dangerous permission is declared or requested: no camera, no location, no contacts, no storage, no microphone.
On iOS, the app requests no system permission other than the App Tracking Transparency prompt described in section 10.
Versions: Android 8.0 (API 26) or later, with target API 37; on iOS, the app is built with Kotlin Multiplatform and Compose.
The 3D viewer runs inside a web component (WebView) that loads only files bundled inside the app. On Android it is served through WebViewAssetLoader on the virtual domain appassets.androidplatform.net; on iOS, through a custom anatomy://bundle scheme. Even though an address beginning with https:// appears in the code, it is a local virtual origin resolved by the operating system inside the device: it generates no network request and sends nothing to any server.
The app is free and is funded by advertising from Google AdMob (SDK com.google.android.gms:play-services-ads 25.4.0 on Android and GoogleMobileAds 13.7.0 on iOS). The formats shown are: anchored banner, interstitial, rewarded video and app open ad.
This data is collected and processed by Google directly from your device. It does not pass through us: we never see it, never store it, and cannot export or delete it on your behalf. Google's processing is governed by its Privacy Policy and by How Google uses information from sites or apps that use our services.
You may choose to watch a rewarded video and, in exchange, you get twenty minutes with no banners and no ad when you reopen the app. It is entirely voluntary. The start and end of that period are stored as two timestamps on your device (see section 6) and are not disclosed to anyone.
The app integrates Google's User Messaging Platform (UMP) (version 4.0.0 on Android and 3.1.0 on iOS), which presents a consent form compliant with the IAB Europe Transparency and Consent Framework (TCF). The form lets you accept or refuse the processing of your data for advertising purposes and lists the vendors involved.
If you decline, the app makes no ad request whatsoever. No personalised advertising is shown, and no non-personalised advertising either: no ad is requested at all. The app keeps working with all of its content.
On iOS, the system additionally shows the App Tracking Transparency prompt. The string declared in the app's Info.plist reads, in Spanish: "Se usa el identificador de tu dispositivo para mostrarte anuncios más relevantes. La app funciona igual si lo rechazas." — that is, your device identifier is used to show you more relevant ads, and the app works exactly the same if you decline. If you deny the permission, the operating system does not provide the advertising identifier (IDFA) and it is not used to personalise ads.
Withdrawing consent does not affect the lawfulness of processing carried out before withdrawal, and it does not limit any feature of the app.
On Android, the app uses two Google Play services:
Both are Google Play Services components and are governed by Google's Privacy Policy. Neither sends data to any system of ours.
If you write to ai.krossly@gmail.com, we will process your email address and whatever you tell us, for the sole purpose of replying to you. The legal basis is our legitimate interest in handling user enquiries (Article 6(1)(f) GDPR) and, where you are exercising a right, compliance with a legal obligation (Article 6(1)(c)). We will keep that correspondence for 24 months and then delete it. Please do not send us health information or any other sensitive data: we do not need it in order to help you.
If you are in the European Economic Area, the United Kingdom or Switzerland, these are the legal bases for each processing activity:
| Processing | Data | Legal basis |
|---|---|---|
| Storing your preferences on the device so the app works consistently across sessions | The ten local values in section 6; they never leave the device | Storage strictly necessary to provide the service you request (Article 5(3) of Directive 2002/58/EC) and, so far as this amounts to processing of personal data, legitimate interests under Article 6(1)(f). In most cases these values are not even personal data, as they identify no one. |
| Storing or accessing information on your device for advertising purposes and serving personalised ads | Advertising identifier, IP address, ad interaction data | Consent, Article 6(1)(a) GDPR and Article 5(3) of Directive 2002/58/EC (ePrivacy), obtained through the UMP/TCF form and, on iOS, complemented by the ATT permission. Withdrawable at any time. |
| Delivering and measuring the ad, preventing ad fraud and invalid traffic, and keeping the advertising system secure | Minimal technical ad delivery data, processed by Google | Legitimate interests, Article 6(1)(f), on the terms and for the purposes Google declares, where the user has allowed ad requests. |
| Responding to your messages and handling rights requests | Your email address and the content of your message | Legitimate interests, Article 6(1)(f); legal obligation, Article 6(1)(c), where you are exercising a right. |
We make no automated decisions producing legal or similarly significant effects concerning you (Article 22 GDPR). We process no special categories of data (Article 9).
You have the right to request access to your data, its rectification or erasure, restriction of processing, portability, and to object to processing based on legitimate interests. You may also withdraw your consent at any time (see section 10) and lodge a complaint with a supervisory authority.
One important — and honest — limitation: since we have no server, no accounts and no identifier of yours, we cannot identify you or link a request to you. In those circumstances, Article 11 GDPR allows us not to acquire additional information merely to identify you. In practice:
For any privacy question, write to ai.krossly@gmail.com. We will respond within one month of receiving the request, extendable in accordance with Article 12(3) GDPR.
You may complain to the supervisory authority of your country of residence: the directory is on the European Data Protection Board website. In the United Kingdom, to the Information Commissioner's Office. You may also complain to the authority of Chile, where we are established, if such an authority exists there.
We transfer data to no country, because we receive none. The data Google collects through AdMob may be processed on servers located outside your country, including in the United States. The safeguards applicable to those transfers are declared by Google in its own policy and we cannot verify them ourselves: see Google's Privacy Policy.
| Data | Where it lives | How long | How to erase it |
|---|---|---|---|
| The ten local preferences | On your device only | Until you erase them | Uninstall the app. On Android you can also use Settings → Apps → Anatomy 3D: Human Body Organs → Storage → Clear data. |
| Local storage of Google's SDKs (for example, your consent decision) | On your device only | Until you erase it or reset it from the consent form | Uninstall the app or clear the app's data |
| Advertising data | In Google's systems | According to Google's retention periods | Through Google's mechanisms: delete or reset your advertising ID in system settings and manage your data in My Ad Center. |
| Email correspondence | In our mailbox | 24 months | Write to us and we will delete it. |
Since there are no accounts, there is no "delete account" procedure: uninstalling the app removes everything the app had stored on your device.
This section is addressed to California residents under the California Consumer Privacy Act, as amended by the California Privacy Rights Act.
| Category (§ 1798.140) | Collected? | Who collects it | Purpose |
|---|---|---|---|
| A. Identifiers (advertising identifier, IP address) | Yes | Google AdMob, directly from your device. Not us. | Advertising, frequency capping, fraud prevention |
| F. Internet or other electronic network activity (impressions, clicks, ad interaction) | Yes | Google AdMob | Ad delivery and measurement |
| G. Geolocation data (approximate, derived from IP: country or city; never GPS) | Yes | Google AdMob | Region-relevant advertising and legal compliance |
| B. Customer records information (name, address, payment details) | No | — | — |
| C. Protected classification characteristics | No | — | — |
| D. Commercial information (purchases) | No | — | There are no purchases in the app |
| E. Biometric information | No | — | — |
| H. Sensory information (audio, video) | No | — | The app uses neither microphone nor camera |
| I. Professional or employment information | No | — | — |
| J. Education information | No | — | — |
| K. Inferences reflecting preferences or characteristics | Not by us | Google may draw inferences for advertising purposes | See Google's policy |
| Sensitive personal information (§ 1798.140(ae)): social security number, precise geolocation, health, contents of communications, etc. | No | — | We neither collect nor use sensitive information, so the right to limit its use does not apply |
We do not sell personal information for money, and have not done so in the preceding twelve months. That said, when advertising is personalised, the use of your advertising identifier to serve you ads across contexts may constitute "sharing" (disclosure for cross-context behavioural advertising) under the CPRA. You can stop it at any time using the mechanisms in section 10. We also do not sell or share the personal information of consumers under 16 years of age; we do not knowingly collect it.
Because there are no accounts and we hold no identifiers, the effective opt-out mechanism is the device's own: delete or reset your advertising identifier and turn off ad personalisation (see section 10). You may also write to ai.krossly@gmail.com with the subject line "CCPA" and we will confirm in writing what this document already states: that we retain no personal information about you and therefore have nothing to delete or correct in our systems. We will verify requests to the extent the law requires and it is materially possible.
On opt-out preference signals such as Global Privacy Control: that signal is designed for web browsers, and this application offers no web browsing; its practical mobile equivalent is deleting or resetting the advertising identifier in system settings.
If you reside in Virginia, Colorado, Connecticut, Utah, Texas or another state with a comprehensive privacy law, you have equivalent rights of access, correction, deletion and portability, as well as the right to opt out of targeted advertising and profiling. They are exercised in the same way as above: through your device settings and by writing to ai.krossly@gmail.com. We process no sensitive data and carry out no profiling with legal or similarly significant effects.
Anatomy is not directed to children under 13 and we do not knowingly collect personal data from children under 13. The app is intended for people aged 13 and over, does not take part in Google Play's "Designed for Families" programme or the App Store's kids categories, and is not subject to Google Play's Families Policy.
Nor do we knowingly collect data from users under 16 in the European Union for advertising purposes. If you are a parent or guardian and believe a child in your care has used the app, note that there is no account and no data in our hands to delete: simply uninstall the app (which erases all local data) and, if you wish, reset the device's advertising identifier. You are welcome to write to ai.krossly@gmail.com with any question.
Google Play requires the store listing to include a "Data safety" form and the linked privacy policy to be consistent with it.
| Data type | Collected? | Shared? | Required? | Purpose | Collected by |
|---|---|---|---|---|---|
| Device or other IDs (advertising identifier) | Yes | Yes | Optional in the EEA, UK and Switzerland (subject to your consent). Elsewhere, you can restrict it from system settings. | Advertising or marketing; fraud prevention and security | Google AdMob |
| Approximate location (derived from IP address) | Yes | Yes | Same as the row above | Advertising or marketing | Google AdMob |
| App activity: ad interactions (impressions, clicks) | Yes | Yes | Same as the row above | Advertising or marketing; ad performance measurement by Google | Google AdMob |
| Personal info (name, email, address, user IDs) | No | No | — | — | — |
| Financial info, messages, photos and videos, files, contacts, calendar, web browsing history, health and fitness info, precise location, audio | No | No | — | — | — |
| App activity relating to the educational content (organs viewed, quiz results) | No | No | — | Neither collected nor transmitted: the app contains no analytics | — |
On iOS, the app's privacy manifest (iosApp/iosApp/PrivacyInfo.xcprivacy) declares the following data types and API usage reasons:
| Declared item | Detail declared in the manifest |
|---|---|
| Device ID | Not linked to your identity; not used for tracking; purpose: third-party advertising |
| Advertising Data | Declared in the manifest. |
| Coarse Location | Declared in the manifest; in practice derived by the ad provider from the IP address. |
| File timestamp API access reason | Code C617.1 |
| User Defaults API access reason | Code CA92.1 |
The best security measure in this app is structural: data that is never collected cannot leak. There is no server to attack, no user database and no credentials to steal. The values the app stores stay in the private storage the operating system reserves for the application, with whatever protection the device itself applies to that storage. The only network connections that exist are those made by Google's advertising SDK.
If we change what the app does, we will update this document before releasing the new version and change the "last updated" date and version number in the header. If the change is material (for example, if analytics, user accounts or a server of our own were ever added), we will announce it inside the app and, where the law requires it, ask for your consent again. The current version is always published at https://modismoshispanos.com/en/anatomy/privacidad.
For any privacy question, or to exercise your rights:
Governing law and jurisdiction: the laws of the Republic of Chile —
| Component | Version | Platform | Collects data? |
|---|---|---|---|
Google AdMob (com.google.android.gms:play-services-ads) | 25.4.0 | Android | Yes |
Google Mobile Ads (GoogleMobileAds) | 13.7.0 | iOS | Yes |
| Google User Messaging Platform (UMP) | 4.0.0 | Android | Manages and stores your consent decision |
| Google User Messaging Platform (UMP) | 3.1.0 | iOS | Manages and stores your consent decision |
| Google Play In-App Review and In-App Update | review-ktx 2.0.2 and app-update-ktx 2.1.0 | Android | Processed by Google Play |
| Version | Date | Changes |
|---|---|---|
| 1.0 | 7 August 2026 | First version of the document. |
| 1.1 | 7 August 2026 | Accuracy review against the verified source code: local preference types corrected, storage by Google's own SDKs added, the Android manifest statement narrowed to the app's own manifest, unverifiable claims about third parties and about the store age rating removed, and the annex of placeholders and open items added. |
This section is for the developer's internal use. It must be deleted (together with the box in the header) before publishing the document, along with its entry in the table of contents.