Picobello Privacy Policy

Version 7 release candidate · Dated 10 September 2026 · Effective only after controller approval and publication

Publication status: This repository copy is a release candidate, not an approved production notice. It describes the server-side, de-identified aggregate statistics planned for the analytics dashboard in addition to the controller, email, regional-processing, retention and rights information for the current service configuration. Controller approval, market-specific lawful-basis decisions, provider/transfer evidence and publication records are still required before this version is treated as effective.

Picobello is a family chores and rewards app operated by Picobello Software UG (haftungsbeschränkt) ("Picobello", "we", "us"). A parent or guardian creates and manages the family account. Children use profiles created and authorized by that adult.

This policy explains the current app and its related cloud, website, authentication, notification, subscription, support, export and deletion services. It focuses on the EU General Data Protection Regulation ("GDPR"). Additional local rules may apply. We do not claim that the app or its current guardian-verification method is suitable for every country merely because this policy is available there.

In short: we do not show third-party advertising, sell personal data, use product-analytics SDKs, track users across apps, provide public child profiles, or allow children to contact strangers. We do process family and child data needed for accounts, household tasks, rewards, synchronization, security, parent-requested features, and de-identified aggregate usage statistics to improve the app.

1. Controller and contact

The controller is Picobello Software UG (haftungsbeschränkt), registered office Berlin, with the business address c/o The Base Berlin One, Pestalozzistraße 5-8, Apt. 216, 13187 Berlin, Germany.

The company is represented by its managing director, Felix Parey, and is registered in the commercial register of Amtsgericht Charlottenburg under HRB 291439 B.

Privacy and support email: support@picobelloapp.com

No Data Protection Officer has been appointed for Picobello at this time. If an appointment becomes required, this policy will be updated with the DPO's contact details. Privacy requests can currently be sent to the address above.

2. Who uses Picobello

The child label is an app role, not a legal determination that a person is a minor. The role currently supports ages 4–18. For a person below the applicable digital-consent threshold, the parent or legal guardian provides the required authorization. At or above that threshold, the app can present a self-consent transition so the young person can make the consent-based choices that belong to them. A person recorded as 18, or otherwise legally an adult, receives the authority, notices, choices and rights that apply to an adult; guardian authorization is not relied on as that adult's consent.

Parents should use a nickname rather than a child's full legal name and should not enter medical, religious, location, behavioral or other sensitive information into names, support messages or household configurations.

3. Information we process

3.1 Parent account and authentication

Depending on the sign-in method, we process:

Passwords are handled by Firebase Authentication. Picobello does not store a readable copy of a parent's password in its Firestore application records.

3.2 Child profiles

For a child profile we process:

Age and gender are ordinary personal data in this app, not special-category data by themselves. We do not try to infer a child's sexual orientation, health, religion or other sensitive characteristic from them.

3.3 Family configuration, quests and rewards

We process family membership and the choices needed to provide the service, including:

The app stores an iPad parent-switch passcode verifier and salt when that shared-device feature is enabled. It does not store the four-digit passcode in readable form.

3.4 Limited personalization

During parent setup, the app filters the quest catalog and filters or preselects reward-shop items using the children's age, selected gender and the parent's material/non-material reward preference. For a family with more than one child, an item can remain available when it matches at least one child; selecting the "other" profile value does not exclude items by gender. This calculation occurs in the app and is used only to help the parent configure the family. The parent makes the final selection.

This is limited profiling or personalization under data-protection law. It is not advertising and does not make a legal or similarly significant decision about a child. The resulting family selections are synchronized; a separate behavioral advertising profile is not created.

3.5 Pairing and connected sessions

An authenticated parent can create a six-digit child household code. The code:

The parent can see join activity, receives a join notification when enabled, and can revoke the grant or later revoke child sessions. A separate co-parent code is intended for one credentialed adult account and is consumed after a successful adult join.

For pairing and abuse prevention we process a grant ID, family and creator IDs, role, hashed challenge, claim/session identifiers, status, attempt counts and creation, expiry, use, last-seen or revocation timestamps. Infrastructure may receive the request IP address; rate-limit records use rotating or pseudonymous hashes rather than storing the raw address in the rate-limit document.

We do not intentionally collect a child device's user-assigned name, hardware model, precise location, locale, time zone or Apple vendor identifier for the current pairing flow.

3.6 What family members can receive

The current repository rules and backend are designed to isolate one family's private data from another family. Deployed-rule evidence and the historical-access assessment remain release requirements, so this statement must not be treated as proof about an earlier or unverified production deployment. Within an authenticated family:

The current interface may display fewer fields than the service response. Family members should therefore be treated as intended household recipients, not as unrelated third parties.

3.7 Notifications

If notifications are enabled, we process an APNs or FCM push token, the associated user/family identifier, token-update time, language and notification preferences. Messages may identify an event type and, depending on the event, may include a child's display name, a task or catalog reward name, and a requested reward quantity. The operating system may display notification text on the lock screen according to the device's settings.

Core functionality remains available without push notifications. Local reminders are stored on the device until delivered, cancelled or removed by the operating system.

3.8 Subscription information

For the subscription or trial currently required to activate a new family, we process the product and entitlement, a StoreKit app-account token, original transaction identifier, signed transaction during server verification, and active, expiry, revocation or transfer state. Apple processes payment-card and billing information; Picobello does not receive the full payment-card number.

3.9 Aggregate usage statistics to improve the app

We use aggregate usage statistics to improve the app. A scheduled Cloud Function produces de-identified demographic statistics from active child profiles: a population count, the proportion with a known age, an average age, and counts in the broad bands 4–6, 7–9, 10–12, 13–15 and 16–18. The function does not write child IDs, family IDs, exact-age rows or activity rows to the aggregate record. The entire demographic publication is withheld until at least 10 active profiles exist, and any age band with fewer than 10 profiles is omitted. Only this thresholded aggregate reaches the separate administrator dashboard.

This server-side aggregation is kept separate from Firebase Analytics and from individual activity data. Picobello does not join Firestore ages to Firebase Analytics identifiers or build a derived dataset that combines an individual's age with activity. The dashboard works only on the de-identified aggregate output and cannot read child or family documents directly.

Separately, a parent may choose whether Picobello receives first-party onboarding timing statistics. That optional telemetry remains consent-based and is not required for the demographic aggregation described above. Withdrawing or declining that choice stops future optional onboarding telemetry; it does not change the narrowly scoped, de-identified aggregate processing described in this section.

3.10 Privacy requests, exports and deletion

We process the requester and child/family identifiers, request type, scope, status, correspondence and timestamps needed to handle access, portability, correction, restriction, objection, authorization withdrawal, session revocation and deletion requests received through the in-app privacy tools or our privacy-support channel. To fulfill a verified access or portability request, we may temporarily compile a concentrated copy of family data in a protected Cloud Storage object, an expiring download link or another protected electronic file.

An automatically compiled file does not necessarily include every short-lived security or purchase-idempotency record. The privacy-support process therefore performs any supplementary, verified search required for a complete access response.

Deletion jobs use minimized hashed receipts and tombstones to prevent restoration or duplicate processing without retaining the deleted child's readable profile. The main profile and family records are covered, but a shop-purchase idempotency receipt can remain until its 30-day expiry and a short-lived pairing-claim record can remain until scheduled cleanup. Closing and testing those cascade gaps is a release prerequisite.

3.11 Local storage and operational data

The app keeps SwiftData records, pending synchronization operations, cached profile/family information and preferences on the device for offline use and fast startup. Some identifiers and settings are stored in UserDefaults; authentication credentials are managed by the platform and Firebase SDKs. Device backups may contain app data according to the user's Apple backup settings.

Google/Firebase and hosting infrastructure may process IP address, App Check/App Attest data, app version, request time, error and security logs. We use this operational data for delivery, debugging, fraud prevention and security, not product measurement.

Support emails may contain the sender's address, message and any information the sender chooses to include. Please do not send passwords, authentication tokens or unnecessary child information.

3.12 Transactional and support email

Picobello uses Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) to deliver requested sign-in codes, email-verification messages, password-reset messages, support-email verification codes, support requests and confirmation copies. Resend receives the sender and recipient email addresses, subject, message body, authentication code or link, delivery headers and status information. Support messages may also contain the topic, the requester's message, limited account or family references used to investigate the request, and any attachments the requester chooses to send.

These are transactional or user-requested support messages, not advertising. Picobello does not enable open or click tracking for them and does not use them to build an advertising profile. Resend processes this customer message data as a service provider/processor for Picobello. Resend may process its own account, billing and service-usage data as an independent controller under its privacy policy.

To reduce automated abuse of the public support form, Picobello uses Cloudflare Turnstile. When a visitor starts one of the protected support actions, Cloudflare may process the visitor's IP address, browser and device signals, challenge result and related technical metadata. The resulting one-time token is sent to Picobello's backend for validation. Turnstile is used for support-form security, not advertising or product analytics. See Cloudflare's privacy policy for the provider's information.

4. Why we process information and our GDPR bases

For the EEA and other jurisdictions that use the GDPR framework, the following bases are used or assessed by purpose and market. Where consent is required, we request it separately and provide a way to withdraw it:

We do not use child data for advertising, cross-app tracking, data-broker sharing or individual-level engagement analytics. We do not use solely automated decisions that create legal or similarly significant effects.

5. Providers and other recipients

We disclose only what is necessary to:

We do not sell personal data or share it for cross-context behavioral advertising. The current app does not contain third-party advertising, Firebase Analytics, another product-analytics SDK, open chat or public child profiles.

6. International processing

The configured Firestore production and development databases, and the content Storage bucket, are in Google's europe-west3 region (Frankfurt, Germany). General-purpose Cloud Functions and scheduled jobs run in europe-west1 (Belgium); resource-triggered functions that must be colocated with Firestore or Storage run in europe-west3. Google, Apple, Cloudflare and other providers may nevertheless process information in the United States or other countries. Resend stores customer data in the United States, including message content and delivery logs.

Where GDPR transfer restrictions apply, Picobello uses an applicable legal mechanism, such as an adequacy decision or the provider's data-processing terms incorporating Standard Contractual Clauses and supplementary safeguards. Resend states that its DPA covers U.S. transfers through the EU Standard Contractual Clauses and the UK Addendum, with the EU-U.S. Data Privacy Framework as an additional mechanism. Current provider and transfer evidence can be requested through the contact above.

7. Retention

Current application-level retention is:

Provider logs, security investigations, support correspondence, subscription/accounting records and backups may follow different periods required by configuration or law. Resend's own account, billing and usage records are governed by its privacy policy as controller. Deletion receipts currently record a 90-day target for expiry of residual backups. Production backup, log and support periods must not be longer than necessary and are reviewed in the controller's internal retention schedule.

8. Security

Measures in the current design include encrypted transport, Firebase Authentication, App Check/App Attest, deny-by-default database and storage rules, server-validated family membership and roles, short-lived pairing codes, rate limits, revocable sessions, restricted backend-only lifecycle collections, expiring exports and scheduled deletion.

No service is completely secure. The repository contains an incident runbook and record template, but the controller must assign and test the 24/7 roles, authority/vendor contacts, restricted incident system and family-safe communication routes before production. If a personal-data breach occurs, Articles 33 and 34 require investigation, documentation and notification when their respective thresholds are met.

9. Rights and choices

Subject to applicable law, a parent, guardian or child may request:

To request access, a portable copy or export, correction, restriction, objection, authorization withdrawal or other privacy support, use the in-app privacy tools or email support@picobelloapp.com. Account deletion, child-profile deletion, connected-session revocation and notification choices remain available through the applicable parent-controlled app settings. The operating procedure requires proportionate identity and parental-authority checks and escalation of family-conflict or child-safety concerns instead of automatic disclosure to every family member. Where appropriate, copies containing child or family data are delivered through a protected download or protected electronic file rather than in the body of an ordinary email. A request sent by email may be processed by Resend during delivery.

If another parent with an independent Apple, Google or verified-email sign-in remains in the family, deleting one parent's account removes that parent and their access but does not delete family data still administered by the remaining credentialed parent or parents. Deleting the final independently credentialed parent account starts deletion of the family, every child profile and any parent profiles that only joined through an invite code. A child profile can also be deleted separately through the applicable parent-controlled flow.

You may complain to the data-protection authority in the EU/EEA country where you live or work or where you believe an infringement occurred. Withdrawing consent does not affect processing already carried out lawfully, and limited records may remain where a legal obligation or appropriately documented legal claim requires them.

10. Children and additional markets

A short English/German child-facing privacy explanation and privacy center are available in the app. Parents control creation of cloud child profiles below the applicable digital-consent threshold, while the app provides a self-consent transition at or above that threshold. The child-facing explanation is supplemental; this full notice controls if the two versions differ.

Countries outside the EEA may require different age thresholds, direct notices or a specific method of verifiable parental consent. In particular, an authenticated parent account and attestation must not be assumed to satisfy every U.S. COPPA use case. Picobello must complete the applicable market and consent review before intentionally offering under-13 child data processing in the United States or another market with additional requirements.

11. Changes

We may update this policy when the app, providers, legal basis, recipients or retention change. We will change the version and date and provide additional notice or request renewed authorization where required. The guardian-authorization flow shows the exact bundled policy and terms versions recorded in its receipts. Other legal screens may show a newer remote version; a release procedure must determine when re-notice or renewed authorization is required.

12. Contact

Picobello Software UG (haftungsbeschränkt)

c/o The Base Berlin One, Pestalozzistraße 5-8, Apt. 216, 13187 Berlin, Germany

Managing director: Felix Parey

Commercial register: Amtsgericht Charlottenburg, HRB 291439 B

support@picobelloapp.com