Keto Pro – Legal & Compliance
Policies
- Privacy Policy — what we collect, how it is encrypted and stored, and your data rights.
- Terms of Service — subscriptions and billing, the medical disclaimer, and limitation of liability.
Legal Compliance Framework
This section summarizes how Keto Pro aligns its mobile client data practices and technical architecture with the mandatory requirements of the Apple App Store, Google Play Store, and modern cloud security baselines.
A. Apple App Store Compliance
1. Privacy Nutrition Label
In App Store Connect, Platten Industries explicitly declares the categories of data collected and their precise intent. The following technical mapping is enforced:
| Data Category | Specific Fields | Apple Privacy Tag |
|---|---|---|
| Contact Info | Email address | Contact Info → Email |
| Health & Fitness | Weight, height, body composition, macro logs | Health & Fitness |
| Usage Data | Feature usage, UI interaction events | Usage Data |
| Diagnostics | Crash logs, performance metrics | Diagnostics |
Keto Pro explicitly indicates that this data is linked directly to the user account for core functionality and is not utilized for third-party tracking or ad profiling.
2. Required Reason API Declarations
For iOS privacy manifests, Keto Pro explicitly declares its use of native APIs that access device identifiers, network file structures, and local storage, along with the approved reasons (e.g., user authentication, secure analytics, crash diagnostics).
B. Google Play Data Safety Compliance
1. Data Types and Tags
In the Google Play Console, Platten Industries completes the mandatory Data Safety declaration, mapping collected user data directly to Google’s standard taxonomic categories:
| Data Category | Example Fields | Google Data Safety Tag |
|---|---|---|
| Personal Info | Email address | Personal Info → Email |
| Health & Fitness | Weight, height, macro logs, food logs | Health & Fitness |
| Diagnostics | App crash logs, system performance metrics | Diagnostics → Crash Logs |
2. Mandatory Data Safety Statements
In the Google Play Data Safety interface, Keto Pro certifies that:
- All data is strictly encrypted in transit.
- All data is encrypted at rest using enterprise storage patterns.
- Users can easily request absolute deletion of their entire data history.
- A public web-based account deletion mechanism is actively hosted at: https://ketoproservices.com/delete-account.
C. Security & Infrastructure Alignment
1. MongoDB Atlas Configuration
- Storage Encryption: Cloud storage volumes are fully encrypted at rest using AES‑256 keys managed via secure key management systems.
- Network Transit: All active connections to the database clusters strictly require TLS/SSL verification.
- Field-Level Security: Client-Side Field-Level Encryption (CSFLE) or Queryable Encryption is implemented natively for high-risk fields (such as raw email addresses and individual weight logs) before transmission over the network.
- Network Isolation: Database access is rigidly restricted using strict IP allowlisting and secure VPC (Virtual Private Cloud) peering.
2. Mobile App Network Security
- Protocol Hardening: Enforce a minimum baseline of TLS 1.2 (preferring TLS 1.3) for all outbound API communication.
- Plaintext Banning: Cleartext/HTTP fallbacks are disabled via network security config files on both platforms (
network_security_config.xmlon Android andNSAppTransportSecurityon iOS). - Cryptographic Hardware Access: Secure user credentials, tokens, and cryptographic keys are stored exclusively using hardware-backed isolation: Keychain Services on iOS and the Android Keystore system on Android.
Get In Touch
Contact Us
Questions about this policy, a data-rights request, a billing problem, or anything else — send it here and it reaches the team directly. We aim to reply within two business days.