Data controller: Geovany Garcia
Contact: ledinfranco@gmail.com
Last updated: July 23, 2026 Version: 2.0
CyberSpark is a mobile application for defensive cybersecurity training and IT certification preparation. This policy explains what information we process when you use the app, why, for how long, and what rights you have over it.
It applies only to the CyberSpark Android application. It does not cover third-party websites you may reach from within it.
The honest summary: the app collects the minimum needed to work. There is no advertising, no behavioral analytics, no cross-app tracking, and we sell nothing to anyone. Most of what you do inside the app never leaves your phone.
When you sign in with Google, we receive and store:
Email address
Google Sign-In
Identify your account and provide support
Display name
Google Sign-In
Personalize the interface
Profile picture URL
Google Sign-In
Show your avatar
User identifier (UID)
Firebase Authentication
Link your progress to your account
Last sign-in timestamp
Server generated
Security and account maintenance
We never receive your password.
Authentication is handled entirely by Google.
Completed modules and lessons
Show and preserve your progress
Subscription status (free or PRO)
Grant access to the matching content
Account role (user or administrator)
Internal access control for the content panel
The following is stored only in your phone's local storage. It reaches no server, ours or anyone else's:
Your progress in the labs and the skill path
Your best scores on the practice exams
Your language preference
Confirmation that you have read the educational use notice
It is erased when you uninstall the app or clear its data from system settings.
The metadata and steganography tools work on images you explicitly choose. Processing happens entirely on your device. Neither the images nor their metadata are uploaded, copied or transmitted to any server. The app accesses only the specific files you pick, not your whole gallery.
We do not show ads or integrate advertising networks
We do not use behavioral analytics or tracking tools
We do not build advertising profiles or make automated decisions about you
We do not access your contacts, messages, calls, calendar or installed app list
We do not use your GPS location
We do not sell or transfer your personal data to third parties
We do not record audio or video
Internet
Sign in, sync your progress and process the subscription
Network and Wi-Fi state
Detect connectivity and measure the quality of the network you are already on
Image access
Only when you open the metadata or steganography tools, and only for the files you select
Storage write (Android 9 and earlier)
Save the resulting image when you ask for it
Every permission is requested at the moment the relevant feature needs it, and you may deny it: the rest of the app keeps working.
Firebase Authentication (Google)
Sign-in
Email, name, identifier
Cloud Firestore (Google)
Store your account and progress
The data in sections 2.1 and 2.2
Google Play Billing
Subscription charges
Handled entirely by Google; we only learn whether the subscription is active
Google Play Services
In-app updates
Technical data handled by Google
We have no access to your payment data. Not the card number, not the billing address, nothing equivalent.
When you type a web address into this tool, the app makes a request to that site to read its public response headers, exactly as a browser would. That site will see your IP address. The address you type is neither stored nor sent to our servers.
For users in the European Economic Area and the United Kingdom, we process your data on the following GDPR bases:
Create your account and grant access
Performance of a contract (Art. 6(1)(b))
Store your progress
Performance of a contract (Art. 6(1)(b))
Manage the subscription
Performance of a contract (Art. 6(1)(b))
Keep the service secure
Legitimate interest (Art. 6(1)(f))
Meet legal and tax obligations
Legal obligation (Art. 6(1)(c))
Account and progress
While the account remains active
After a deletion request
Erased within a maximum of 30 days
Accounts inactive for over 24 months
Deleted on our own initiative
Purchase records
As required by applicable tax law, handled by Google Play
Data stored on your device
Until you uninstall the app or clear its data
You can request full deletion of your account and all associated data by writing to ledinfranco@gmail.com from the same email address you signed in with.
Upon receiving the request:
We confirm it within 7 days.
We delete your user document, your progress and your sign-in record.
We confirm in writing once deletion is complete, always within 30 days.
The subscription is separate: cancel it from Google Play → Payments and subscriptions. Deleting your account does not automatically cancel an active subscription or trigger a refund.
Data held locally on your phone is removed by uninstalling the app.
Google Firebase infrastructure may store and process data on servers located outside your country, including the United States. For these transfers Google applies the safeguards required by European law, including the standard contractual clauses approved by the European Commission. Details are available in Google's privacy policy.
All communication between the app and the servers travels encrypted over TLS.
Database access is restricted by Firestore security rules: each user can read and write only their own data.
We store no passwords of any kind.
Administrative access is role-limited and reserved for content management.
No system is infallible. Should a security breach affect your personal data, we will inform you and notify the competent authority within the deadlines set by applicable law.
You may request:
Access to the personal data we process about you
Rectification of inaccurate data
Erasure of your data (section 7)
Restriction of processing
Portability of your data in a machine-readable format
Objection to processing based on legitimate interest
Withdrawal of consent at any time, without retroactive effect
To exercise them, write to ledinfranco@gmail.com. We respond within 30 days.
If you live in the European Economic Area, you may lodge a complaint with your national data protection authority. If you live in California, the CCPA grants you equivalent rights of access, deletion and non-discrimination for exercising them; we state expressly that we do not sell or share personal information as the CCPA defines those terms.
We may update this policy when app features or applicable law change. The current version will always be published on this same page, with its version number and date.
If a change materially affects how we process your data, we will notify you inside the app before it takes effect.
Geovany Garcia
Email: ledinfranco@gmail.com
For any question about this policy or to exercise your rights, write to that address with "Data protection" in the subject line.