Law 21.719

Updated July 26, 2026 · The law takes effect on December 1, 2026

Law No. 21.719 completely modernizes personal data protection in Chile: it replaces the Law No. 19.628 regime, creates the Personal Data Protection Agency, and takes effect on December 1, 2026.

Kimcura is used by school students, many of them minors. That places us in the most demanding part of the law. In July 2026 we audited our own source code against the law and against Google Play's Families Policy, and we publish the full result here: what we already comply with, and what we do not yet.

This page is updated when the real status of a row changes, not when our intentions change. An item marked pending is an item that is not yet implemented.

See also the Privacy Policy and the Data Safety Form.

25/31 requirements implemented
ImplementedPartialPending

Lawful basis and consent

What the law requires

Every processing operation must rest on an identifiable lawful basis.

What we do

Every category of data we process has its basis stated in the Privacy Policy: performance of the service, consent, or legitimate interest.

Implemented
What the law requires

Consent must be free, specific, unambiguous, informed, and demonstrable by the controller.

What we do

We record every consent decision with its date, the policy version accepted, and the method. Withdrawal is recorded as a new event rather than erasing the previous one.

Implemented
What the law requires

Withdrawing consent must be as easy as giving it.

What we do

Privacy preferences live in the You tab and can be changed at any time, without contacting us and without losing access to the app.

Implemented
What the law requires

Consent-based processing cannot occur before the consent exists.

What we do

Product analytics starts disabled and sends no events until the person accepts. The age screen and the consent screen themselves are not tracked.

Implemented
What the law requires

Legitimate interest requires a balancing test against the data subject's rights, especially for minors.

What we do

We no longer rest analytics and behavioural telemetry for minors' accounts on legitimate interest: they now require consent. The app works fully if consent is refused.

Implemented

Children and adolescents

What the law requires

The controller must be able to tell a child from an adolescent from an adult in order to apply different rules.

What we do

A neutral age screen appears before any collection, on first launch. It does not hint which answer unlocks more features, and cannot be retried.

Implemented
What the law requires

Processing data of children under 14 requires the authorization of the parent or legal guardian.

What we do

An account declared as under 14 is held pending and sends no data until confirmation arrives from the responsible adult's email. We are assessing with legal counsel whether this verification method is sufficient or needs strengthening.

Partial
What the law requires

All processing of minors' data must serve the best interests of the child.

What we do

Social features — comments, the 3D plaza with strangers, and duels — are off by default on under-14 accounts and are only enabled if the responsible adult explicitly authorizes them.

Implemented
What the law requires

Profiling of minors demands particular caution and a solid basis.

What we do

The personalized feed can be turned off entirely. With personalization off, the model stops learning from that person and content is served without profiling.

Implemented
What the law requires

No behavioural advertising or advertising identifiers directed at minors.

What we do

Kimcura has no advertising of any kind, no ad SDK, and does not read the device advertising identifier.

Implemented

Data subject rights

What the law requires

Right of access: to know what data is processed and obtain a copy.

What we do

From within the app you can download a file with everything we hold: profile, comments, reactions, skill vector, telemetry, PvP record, inventory, and consents.

Implemented
What the law requires

Right to portability: to receive data in a structured, commonly used format.

What we do

That same download is delivered as JSON — a structured, machine-readable, non-proprietary format.

Implemented
What the law requires

Right to erasure: to obtain deletion of personal data.

What we do

Deleting your account in the app now also erases everything living outside the accounts table: comments, reactions, telemetry, skill vector, inventory, record, and notifications.

Implemented
What the law requires

Exceptions to erasure must be narrow, justified, and time-bound.

What we do

Only moderation records survive deletion, in pseudonymized form: they exist to protect other people from conduct that already occurred. They have a defined retention period.

Implemented
What the law requires

Right to rectification: to correct inaccurate or incomplete data.

What we do

Username, bio, and grade are editable from the profile. For anything else, the email request has a named owner and a response deadline.

Implemented
What the law requires

Right to object to certain processing, including profiling.

What we do

There is a switch to turn off feed personalization and another for analytics, both independent and with no loss of functionality.

Implemented
What the law requires

A rights-request channel with response deadlines.

What we do

contacto@kimcura.cl, with a named owner and a request log. Anything resolvable in the app is resolved in the app, without writing to us.

Implemented

Transparency and information

What the law requires

Information given to the data subject must be accurate: a policy that misdescribes the processing breaches the principle.

What we do

We audited the policy against the source code in July 2026 and corrected four discrepancies we found, including the real scope of analytics and providers that were not listed.

Implemented
What the law requires

The information must be accessible at the point of collection.

What we do

The policy, the data safety form, and this page are linked from inside the app and from the Google Play listing.

Implemented
What the law requires

For minors, information must be given in language they can understand.

What we do

The consent screen explains each option in one plain sentence. We have not yet published a full version of the policy written for 11-year-old readers.

Partial

Security and confidentiality

What the law requires

Technical and organizational measures appropriate to the risk of the processing.

What we do

In July 2026 we commissioned a security audit of the entire codebase. Its remediation plan is underway and is the reason several rows on this page changed status. For obvious reasons we do not detail open findings on a public page.

Partial
What the law requires

Protective measures must be effective, not nominal.

What we do

We fixed user blocking so it fails safe: if the server cannot verify who you blocked, it does not seat you in the plaza, rather than seating you unprotected.

Implemented
What the law requires

Notification of security breaches to the Agency without undue delay, and to data subjects where risk is high.

What we do

We have a written procedure covering detection, severity assessment, deadlines, and who decides to notify.

Implemented

Retention and minimization

What the law requires

Data cannot be kept indefinitely: each purpose has a retention period.

What we do

We defined a retention period per data type and an automated process that applies deletion. Raw behavioural telemetry is no longer kept without limit.

Implemented
What the law requires

Only data necessary for the stated purpose may be processed.

What we do

We removed the microphone permission the app declared without using, and stopped keeping the email of suspended accounts: we store a hash, which blocks re-registration equally well and is not readable.

Implemented
What the law requires

Minimization is served when the service can be provided without identifying the person.

What we do

Kimcura can be used in full as a guest, with no email, no name, and no photo.

Implemented

Governance and accountability

What the law requires

Record of processing activities.

What we do

We maintain the record with purpose, lawful basis, data and subject categories, recipients, transfers, and retention, for each activity.

Implemented
What the law requires

Impact assessment for high-risk processing, such as systematic profiling of minors.

What we do

We carried out the impact assessment covering the exercise recommender and behavioural telemetry, which are our highest-risk processing.

Implemented
What the law requires

Designation of a data protection officer where required.

What we do

An internal privacy owner is assigned. Formal designation of a data protection officer is under assessment with legal counsel.

Partial
What the law requires

Processing agreements with every provider processing data on the controller's behalf.

What we do

We are formalizing processing agreements with all our providers. Until they are signed, this row stays pending even though the providers already apply their own measures.

Pending
What the law requires

International transfers require a legal mechanism recognized by the law.

What we do

Our data is hosted in the United States and we have always disclosed this. The formal transfer mechanism is being prepared with legal counsel, to be in place before December 1, 2026.

Pending