Privacy Policy
Privacy Policy
Preamble
With the following privacy policy, we would like to inform you about what types of your personal data (hereinafter also referred to as “data”) we process for what purposes and to what extent as part of providing our application.
The terms used are not gender-specific.
Last updated: February 11, 2025
Table of Contents
Preamble
Data Controller
Overview of Processing Activities
Relevant Legal Bases
General Information on Data Storage and Deletion
Rights of Data Subjects
Provision of the Online Service and Web Hosting
Use of Cookies
Registration, Login, and User Account
Contact and Inquiry Management
Push Notifications
Web Analytics, Monitoring, and Optimization
Plug-ins and Embedded Features and Content
Data Controller
Michael Karp
Storkower Straße 108
10407 Berlin
Email: m.karp-flat@hotmail.com
Overview of Processing Activities
The following overview summarizes the types of data processed, the purposes of processing, and the affected persons.
Types of Processed Data
Basic data
Contact data
Content data
Usage data
Metadata, communication, and procedural data
Log data
Categories of Affected Persons
Communication partners
Users
Purposes of Processing
Provision of contractual services and fulfillment of contractual obligations
Communication
Security measures
Audience measurement
Organizational and administrative procedures
Feedback
User profile creation
Provision of our online services and user-friendliness
Information technology infrastructure
Relevant Legal Bases
Legal Bases under the GDPR:
Below, we provide an overview of the legal bases under the General Data Protection Regulation (GDPR) on which we process personal data. Please note that national data protection regulations may also apply in addition to the GDPR, depending on your or our place of residence or establishment. If more specific legal bases apply in individual cases, we will inform you in this privacy policy.
Consent (Art. 6(1) Sentence 1 lit. a GDPR) – The data subject has given their consent to the processing of their personal data for one or more specific purposes.
Contract Performance and Pre-contractual Requests (Art. 6(1) Sentence 1 lit. b GDPR) – Processing is necessary for the performance of a contract to which the data subject is a party or to take steps at the request of the data subject prior to entering into a contract.
Legitimate Interests (Art. 6(1) Sentence 1 lit. f GDPR) – Processing is necessary for the purposes of legitimate interests pursued by the controller or a third party, provided that such interests are not overridden by the interests or fundamental rights and freedoms of the data subject.
National Data Protection Regulations in Germany
In addition to the GDPR, national data protection regulations apply in Germany. These include, in particular, the Federal Data Protection Act (BDSG), which contains specific provisions on the right to information, the right to deletion, the right to object, the processing of special categories of personal data, processing for other purposes, data transfers, and automated decision-making in individual cases, including profiling.
Note on the GDPR and Swiss DSG
This privacy policy serves both to provide information under the Swiss Federal Act on Data Protection (DSG) and the GDPR. For better clarity and broader application, we use the GDPR terminology, even when referring to the Swiss DSG. However, the legal meaning of the terms remains determined according to Swiss law where applicable.
General Information on Data Storage and Deletion
We delete personal data that we process in accordance with legal provisions as soon as consent is revoked or no further legal basis exists for processing. This applies in cases where the original processing purpose ceases to exist or when the data is no longer required.
Exceptions:
Data may be retained for longer periods if required by legal obligations or specific interests, such as for commercial or tax law compliance or legal claims.
Retention Periods under German Law:
10 years – For books and records, annual financial statements, inventories, reports, opening balances, and supporting documentation (§ 147(1) No. 1 AO, § 14b(1) UStG, § 257(1) No. 1 HGB).
8 years – For accounting documents such as invoices and cost receipts (§ 147(1) No. 4 and 4a AO, § 257(1) No. 4 HGB).
6 years – For business correspondence and other tax-relevant documents (§ 147(1) Nos. 2, 3, 5 AO, § 257(1) Nos. 2, 3 HGB).
3 years – For potential warranty and damage claims, based on standard industry practice and legal limitation periods (§§ 195, 199 BGB).
Rights of Data Subjects
Under the GDPR, data subjects have the following rights:
Right to Object – You have the right to object at any time to the processing of your personal data based on Art. 6(1) lit. e or f GDPR.
Right to Withdraw Consent – You can withdraw previously given consent at any time.
Right of Access – You have the right to request confirmation as to whether your data is being processed and to receive additional details, including a copy of the data.
Right to Rectification – You may request correction of incorrect or incomplete personal data.
Right to Deletion and Restriction of Processing – You have the right to request deletion or restriction of processing in accordance with legal requirements.
Right to Data Portability – You have the right to receive your personal data in a structured, commonly used, and machine-readable format.
Right to File a Complaint – You have the right to file a complaint with a supervisory authority if you believe that the processing of your personal data violates GDPR.
Provision of Online Services and Web Hosting
We process users’ data to provide our online services. This includes processing users’ IP addresses to deliver content and functions to their devices.
Processed Data Types:
Usage data (e.g., page views, interactions, operating system, browser type)
Metadata, communication, and procedural data (e.g., IP addresses, logs, timestamps)
Legal Basis:
Legitimate Interests (Art. 6(1) lit. f GDPR)
Log File Retention:
Server logs (IP addresses, accessed files, timestamps) are stored for a maximum of 30 days and then deleted or anonymized unless further retention is required for security reasons.
Use of Cookies
We use cookies for various purposes, including functionality, security, and analytics.
Types of Cookies:
Session Cookies – Deleted when you close your browser.
Persistent Cookies – Remain stored beyond the session for remembering preferences, login status, or analytics (up to 2 years).
Legal Basis:
Consent (Art. 6(1) lit. a GDPR)
Legitimate Interests (Art. 6(1) lit. f GDPR)
Cookie Management:
Users can revoke their consent at any time or object to processing via browser settings.
Registration, Login, and User Account
Users can create a user account. During registration, users are informed of the required mandatory information, which is processed for the purpose of providing the user account based on contractual obligations. The processed data includes login information, such as the username, password, and email address.
When using our registration and login functions, as well as when utilizing the user account, we store the IP address and the timestamp of each user action. This storage is based on our legitimate interests as well as those of the users to protect against misuse and unauthorized use. These data are generally not shared with third parties unless required to enforce our claims or if there is a legal obligation to do so.
Users may receive notifications via email about account-related activities, such as technical changes.
Types of Processed Data
Basic data (e.g., full name, contact details, customer number, etc.)
Contact data (e.g., email addresses)
Content data (e.g., text or image-based messages and posts, including author information and creation timestamps)
Usage data (e.g., page views, session duration, click paths, intensity and frequency of usage, device types, and operating systems, interactions with content and features)
Log data (e.g., log files related to logins, data retrieval, or access times)
Affected Persons
Users (e.g., website visitors, online service users)
Purposes of Processing
Fulfillment of contractual services and obligations
Security measures
Organizational and administrative procedures
Provision of our online services and user-friendliness
Storage and Deletion
Data is deleted according to the section “General Information on Data Storage and Deletion.” User account data is deleted upon account termination.
Legal Bases
Contract performance and pre-contractual inquiries (Art. 6(1) Sentence 1 lit. b GDPR)
Legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR)
Additional Notes on Processing Procedures, Methods, and Services
User Profiles Are Not Public
User profiles are not publicly visible or accessible.
Deletion of Data Upon Termination
If users terminate their accounts, their account-related data will be deleted unless legal requirements mandate retention, or the user has given consent for further storage.
No Obligation to Retain Data
It is the users’ responsibility to back up their data before terminating their account. We are entitled to permanently delete all user data stored during the contract period.
Contact and Inquiry Management
When users contact us (e.g., by mail, contact form, email, phone, or social media) or within the context of existing user and business relationships, the information provided by the inquiring person is processed to respond to the request and take any necessary actions.
Types of Processed Data
Basic data (e.g., full name, contact details, customer number, etc.)
Contact data (e.g., mailing and email addresses, phone numbers)
Content data (e.g., text or image-based messages and posts, including author information and timestamps)
Usage data (e.g., page views, session duration, click paths, intensity and frequency of usage, device types, and operating systems, interactions with content and features)
Meta, communication, and procedural data (e.g., IP addresses, timestamps, identifiers, involved persons)
Affected Persons
Communication partners
Purposes of Processing
Communication
Organizational and administrative procedures
Feedback collection (e.g., through online forms)
Provision of our online services and user-friendliness
Storage and Deletion
Data is deleted according to the section “General Information on Data Storage and Deletion.”
Legal Bases
Legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR)
Contract performance and pre-contractual inquiries (Art. 6(1) Sentence 1 lit. b GDPR)
Additional Notes on Processing Procedures, Methods, and Services
Contact Form
When contacting us via the contact form, email, or other communication methods, we process the provided personal data to respond appropriately. This typically includes information such as name, contact details, and any additional details necessary for handling the request. We use this data solely for the intended purpose of communication.
Legal Bases:
Contract performance and pre-contractual inquiries (Art. 6(1) Sentence 1 lit. b GDPR)
Legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR)
Push Notifications
With the users’ consent, we may send “push notifications.” These are messages displayed on users’ screens, devices, or browsers even when they are not actively using our online service.
To subscribe to push notifications, users must confirm their browser or device prompt for receiving push notifications. This consent process is documented and stored. The storage is necessary to track whether users have agreed to receive push notifications and to provide proof of their consent. For this purpose, a pseudonymous identifier of the browser (a “push token”) or the device ID of a device is stored.
Push notifications may be required for contractual obligations (e.g., technical and organizational information relevant to using our online services).
Affected Persons
Communication partners
Purposes of Processing
Communication
Provision of our online services and user-friendliness
Storage and Deletion
Data is deleted according to the section “General Information on Data Storage and Deletion.” Push notification data is deleted upon account termination.
Legal Bases
Consent (Art. 6(1) Sentence 1 lit. a GDPR)
Legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR)
Web Analytics, Monitoring, and Optimization
Web analytics (also referred to as “audience measurement”) is used to analyze visitor traffic on our online services. This can include behavioral, interest-based, or demographic information (e.g., age, gender) collected in pseudonymous form.
With audience measurement, we can determine the most frequently used features or content of our online services and identify areas for optimization. Additionally, we may use A/B testing to compare different versions of our online services.
Unless otherwise stated, profiles may be created and stored on a user’s browser or device for these purposes. This may include visited websites, interactions with elements, technical information (e.g., browser type, operating system), and usage times. If users consent to location tracking, location data may also be processed.
We store users’ IP addresses but apply an IP masking procedure (i.e., pseudonymization by shortening the IP address) for user protection. No clear user data (e.g., names or email addresses) is stored in the context of web analytics, A/B testing, or optimization. Instead, only pseudonymous data is recorded.
Legal Bases
If we request user consent for third-party services, the legal basis is consent (Art. 6(1) Sentence 1 lit. a GDPR).
Otherwise, data is processed based on our legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR) in efficient, economic, and user-friendly services.
Types of Processed Data
Usage data (e.g., page views, session duration, click paths, intensity and frequency of usage, device types, operating systems, interactions with content and features)
Meta, communication, and procedural data (e.g., IP addresses, timestamps, identifiers, involved persons)
Affected Persons
Users (e.g., website visitors, online service users)
Purposes of Processing
Audience measurement (e.g., access statistics, identifying returning visitors)
Creating user-related profiles
Provision of our online services and user-friendliness
Storage and Deletion
Data is deleted according to the section “General Information on Data Storage and Deletion.” Cookies and similar storage methods may be stored for up to two years on user devices unless otherwise specified.
Security Measures
IP masking (pseudonymization of IP addresses)
Additional Notes on Processing Procedures, Methods, and Services
Google Analytics
We use Google Analytics to measure and analyze the usage of our online services. Google Analytics uses pseudonymous user identifiers to associate analytics data with a device rather than a specific user.
Google Analytics does not log or store individual IP addresses for EU users. Instead, IP address data is used only to derive general location data before being deleted.
For details on how Google Analytics processes data, refer to Google Analytics Privacy Policy.
Plug-ins and Embedded Features and Content
We integrate functional and content elements into our online services that are retrieved from the servers of their respective providers (hereinafter referred to as “third parties”). These elements may include graphics, videos, or maps (collectively referred to as “content”).
The integration of such content always requires that the third-party providers process the users’ IP addresses, as they cannot deliver the content to users’ browsers without it. The IP address is therefore necessary for displaying these contents or functions. We strive to use only content from providers who process the IP address solely for delivering the content.
Third-party providers may also use pixel tags (invisible graphics, also called “web beacons”) for statistical or marketing purposes. Pixel tags allow an analysis of visitor traffic on specific pages. The pseudonymous information collected may also be stored in cookies on users’ devices and may include technical details about the browser, operating system, referring websites, visit times, and usage behavior on our online services. This data may also be linked to similar information from other sources.
Legal Basis Information
If we request users’ consent for the use of third-party services, the legal basis for data processing is consent. Otherwise, user data is processed based on our legitimate interests (i.e., interest in providing efficient, economical, and user-friendly services).
We also refer to the section on cookies in this privacy policy for further details.
Processed Data Types
Usage data (e.g., page views, time spent, click paths, intensity and frequency of use, device types, operating systems, interactions with content and features)
Meta, communication, and procedural data (e.g., IP addresses, timestamps, identifiers, involved persons)
Affected Persons
Users (e.g., website visitors, users of online services)
Purpose of Processing
Provision of our online services and user-friendliness
Storage and Deletion
Data is deleted according to the “General Information on Data Storage and Deletion” section. Cookies may be stored on user devices for up to 2 years, unless otherwise specified.
Legal Bases
Consent (Art. 6(1) Sentence 1 lit. a GDPR)
Legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR)
Privacy Policy for In-App Purchases and Anonymous IDs
Data Collection and Usage
Collected Data
We collect anonymous IDs generated by RevenueCat to facilitate in-app purchases and track purchase history.
Purpose of Data Collection
This data is collected to manage in-app purchases and allow users to restore their purchases if needed.
Use of Data
The anonymous IDs are used to ensure continuous functionality within the app and provide necessary support when required.
Privacy and Disclosure
Data Sharing
The collected data is not shared with third parties, except where necessary to process in-app purchases or as required by law.
User Control Over Their Data
Users can view their anonymous ID and send it via email directly from the app. We do not collect or store users’ email addresses or other contact details.
User Communication
Communication Handling
Any communication related to sharing the anonymous ID via email is handled through the user’s chosen email client. We do not access or collect users’ email addresses.
Data Security
Security Measures
We implement technical and organizational measures to ensure the security of user data. No personal information is collected beyond what is necessary for in-app purchases.
Data Breach Notification
In case of a data breach affecting stored anonymous IDs, users will be appropriately informed.
Legal Compliance
Compliance with Laws
This policy complies with relevant data protection laws and regulations, such as the GDPR.
User Rights
Users have the right to access, correct, and request the deletion of their stored data.
Changes to the Privacy Policy
Notification of Changes
Any updates to this privacy policy will be communicated to users through an updated policy within the app.
Photo Upload and Storage
1. Photo Upload in the App
Parents can choose to upload photos of their child from their gallery or take a photo directly with their camera. This is optional and can be skipped at any time.
Photo uploads are only possible from the parent’s account.
Each child can have only one uploaded photo.
Each task or reward can have up to 3 uploaded photos.
Photos are stored on Firebase as Base64-encoded strings.
Uploaded photos are visible to the parent and child accounts.
2. Security Recommendation
To ensure the privacy and security of your child, we strongly recommend avoiding the upload of photos that contain:
Sensitive information (e.g., addresses, private data)
Faces of children
3. Purpose of Data Storage
Uploaded photos are used solely to:
Personalize the app experience
Manage user accounts
Facilitate task and reward management
4. Data Sharing
Uploaded photos are not shared with third parties, except where legally required.
5. Your Rights
Users have the right to:
Delete uploaded photos at any time
Disable access to uploaded photos
These actions can be performed within the user account settings or by contacting us directly.
6. Security Measures
We implement technical and organizational security measures to protect your personal data from unauthorized access and misuse. However, please note that data transmission over the Internet can never be 100% secure.
Additional Notes on Processing Procedures, Methods, and Services
Google Fonts (Retrieved from Google Servers)
We retrieve fonts (and icons) to ensure a technically secure, maintenance-free, and efficient use of typography, ensuring proper display and compliance with potential license restrictions.
The IP address of the user is transmitted to Google so that fonts can be provided in the user’s browser.
Additional technical data (e.g., language settings, screen resolution, operating system, and device type) are also transmitted to optimize font rendering.
This data may be processed on a Google server in the USA.
How Google Fonts Works
When a user visits our online services, their browser sends an HTTP request to the Google Fonts Web API. These requests include:
User IP address (not stored or analyzed by Google)
Requested URL of the font on Google’s servers
HTTP headers, including the user-agent (browser type, operating system version) and the referring URL (website that requested the font)
Google’s Data Processing Policy
Google does not create user profiles or use the data for targeted ads based on Google Fonts requests.
Data collected is logged only for maintenance and statistics regarding the popularity of different fonts.
Users can read more about Google’s policies here:
Google Fonts Privacy Policy: https://policies.google.com/privacy
Google Fonts FAQ: https://developers.google.com/fonts/faq/privacy?hl=en
Legal Bases
Legitimate interests (Art. 6(1) Sentence 1 lit. f GDPR)
