Privacy Policy

Last Updated: May 31, 2026

At Babileto, we respect your privacy and are committed to protecting the personal data you share with us.

1. Information We Collect

We collect information that you provide directly to us when creating an account, editing your profile, or posting content. This includes:

  • Account Credentials: Username, email address, password, and birth date (collected strictly to verify age compliance under EU regulations).
  • Profile Information: Professional skills, experience, and profile bio.
  • User Content: Text posts ("papiros"), comments, and votes.

Google OAuth Integration

If you choose to sign up or log in using your Google Account, we receive access to certain public information from your Google profile through the standard Google OAuth API:

  • Your primary email address (used to identify your account and send security alerts).
  • Your public profile name and profile picture (used to pre-fill your display name and avatar, which you can customize at any time).

Note: We do not access or store your Google password, nor do we request access to your contacts, Google Drive, or any other Google service.

2. How We Use Your Information

We process your personal data for the following legitimate purposes:

  • To provide, maintain, and secure the Babileto platform and its features.
  • To authenticate your identity during login.
  • To enforce our age verification policy (restricting access to users aged 16 and older).
  • To calculate and update your "Trust Score" dynamically to prevent spam and bot attacks.
  • To process user appeals and compliance requests under the EU Digital Services Act (DSA).

3. Data Retention and Deletion (GDPR Rights)

We retain your personal data only for as long as necessary to fulfill the purposes outlined in this policy. If you decide to delete your account, all personal data (including email, profile information, and Google OAuth associations) will be permanently purged from our active databases.

Under the General Data Protection Regulation (GDPR), if you are located in the European Union, you have the following rights:

  • Right of Access: You can request a copy of the personal data we store about you.
  • Right to Rectification: You can edit your profile details at any time.
  • Right to Erasure (Right to be Forgotten): You can request the complete deletion of your account.
  • Right to Restriction and Objection: You can object to certain automated classifications (such as your "Trust Score") or request human review of automated decisions.

4. Third-Party Services

We do not sell, rent, or trade your personal data with third parties. Your data is stored on secure, partitioned servers managed by Supabase and routed globally through Cloudflare. All data transfers are encrypted in transit using SSL/TLS protocols.

5. Contact and Data Controller

If you have any questions, concerns, or wish to exercise your data protection rights, please contact our Data Protection Officer:

Babileto Technologies Ltd.

Email: [email protected]

Address: European Union / Madrid Compliance Office