Picobello Privacy Policy
Version 7 release candidate · Dated 10 September 2026 · Effective only after controller approval and publication
Publication status: This repository copy is a release candidate, not an approved production notice. It describes the server-side, de-identified aggregate statistics planned for the analytics dashboard in addition to the controller, email, regional-processing, retention and rights information for the current service configuration. Controller approval, market-specific lawful-basis decisions, provider/transfer evidence and publication records are still required before this version is treated as effective.
Picobello is a family chores and rewards app operated by Picobello Software UG (haftungsbeschränkt) ("Picobello", "we", "us"). A parent or guardian creates and manages the family account. Children use profiles created and authorized by that adult.
This policy explains the current app and its related cloud, website, authentication, notification, subscription, support, export and deletion services. It focuses on the EU General Data Protection Regulation ("GDPR"). Additional local rules may apply. We do not claim that the app or its current guardian-verification method is suitable for every country merely because this policy is available there.
In short: we do not show third-party advertising, sell personal data, use product-analytics SDKs, track users across apps, provide public child profiles, or allow children to contact strangers. We do process family and child data needed for accounts, household tasks, rewards, synchronization, security, parent-requested features, and de-identified aggregate usage statistics to improve the app.
1. Controller and contact
The controller is Picobello Software UG (haftungsbeschränkt), registered office Berlin, with the business address c/o The Base Berlin One, Pestalozzistraße 5-8, Apt. 216, 13187 Berlin, Germany.
The company is represented by its managing director, Felix Parey, and is registered in the commercial register of Amtsgericht Charlottenburg under HRB 291439 B.
Privacy and support email: support@picobelloapp.com
No Data Protection Officer has been appointed for Picobello at this time. If an appointment becomes required, this policy will be updated with the DPO's contact details. Privacy requests can currently be sent to the address above.
2. Who uses Picobello
- Parents and guardians create adult accounts, configure the household, create and authorize child profiles, choose tasks and rewards, review activity, manage subscriptions and control connected sessions.
- Children use an authenticated child session or a shared family device to view and complete quests, earn and spend coins, use the family reward shop and view age-appropriate privacy information.
- Additional parents can join only through the adult joining flow and their own credentialed adult account.
The child label is an app role, not a legal determination that a person is a minor. The role currently supports ages 4–18. For a person below the applicable digital-consent threshold, the parent or legal guardian provides the required authorization. At or above that threshold, the app can present a self-consent transition so the young person can make the consent-based choices that belong to them. A person recorded as 18, or otherwise legally an adult, receives the authority, notices, choices and rights that apply to an adult; guardian authorization is not relied on as that adult's consent.
Parents should use a nickname rather than a child's full legal name and should not enter medical, religious, location, behavioral or other sensitive information into names, support messages or household configurations.
3. Information we process
3.1 Parent account and authentication
Depending on the sign-in method, we process:
- email address, display name and selected avatar;
- Firebase Authentication user ID and account status;
- Sign in with Apple or Google account identifier and basic identity information supplied by that provider;
- email verification, sign-in and password-reset session information, including short-lived codes or link metadata;
- family ID, role, tutorial status and account timestamps; and
- authentication, App Check, rate-limit and security metadata.
Passwords are handled by Firebase Authentication. Picobello does not store a readable copy of a parent's password in its Firestore application records.
3.2 Child profiles
For a child profile we process:
- an internal child and family identifier;
- the display name or nickname entered by the parent;
- a selected in-app avatar;
- exact age, initially supplied by the parent and currently limited by the iOS setup flow to ages 4–18; the child can later correct or update it in child settings, and the resulting value is synchronized and may be received by the same-family recipients described in section 3.6;
- the selected gender/profile value "boy", "girl" or "other";
- child tutorial status;
- Firebase authentication and revocable session identifiers; and
- the guardian-authorization status associated with the profile.
Age and gender are ordinary personal data in this app, not special-category data by themselves. We do not try to infer a child's sexual orientation, health, religion or other sensitive characteristic from them.
3.3 Family configuration, quests and rewards
We process family membership and the choices needed to provide the service, including:
- selected areas, quests, reward-shop items, currency and subscription status;
- quest assignments, eligible child IDs, availability and completion state;
- assignment, expiry and cooldown timestamps;
- parent approvals or disallow decisions and related coin changes;
- custom family coin prices, timing and eligibility settings;
- coin balances, daily and total completion counts;
- purchased or redeemed reward items, quantities, status and timestamps; and
- a short activity feed containing quest or reward events.
The app stores an iPad parent-switch passcode verifier and salt when that shared-device feature is enabled. It does not store the four-digit passcode in readable form.
3.4 Limited personalization
During parent setup, the app filters the quest catalog and filters or preselects reward-shop items using the children's age, selected gender and the parent's material/non-material reward preference. For a family with more than one child, an item can remain available when it matches at least one child; selecting the "other" profile value does not exclude items by gender. This calculation occurs in the app and is used only to help the parent configure the family. The parent makes the final selection.
This is limited profiling or personalization under data-protection law. It is not advertising and does not make a legal or similarly significant decision about a child. The resulting family selections are synchronized; a separate behavioral advertising profile is not created.
3.5 Pairing and connected sessions
An authenticated parent can create a six-digit child household code. The code:
- is valid for 10 minutes;
- may be used by more than one child device while it remains valid;
- lets a device presenting the valid code receive the active children's internal IDs, display names and avatars so the child can select the correct profile; and
- can create a revocable authenticated session for the selected child without a second approval tap on the parent's device.
The parent can see join activity, receives a join notification when enabled, and can revoke the grant or later revoke child sessions. A separate co-parent code is intended for one credentialed adult account and is consumed after a successful adult join.
For pairing and abuse prevention we process a grant ID, family and creator IDs, role, hashed challenge, claim/session identifiers, status, attempt counts and creation, expiry, use, last-seen or revocation timestamps. Infrastructure may receive the request IP address; rate-limit records use rotating or pseudonymous hashes rather than storing the raw address in the rate-limit document.
We do not intentionally collect a child device's user-assigned name, hardware model, precise location, locale, time zone or Apple vendor identifier for the current pairing flow.
3.6 What family members can receive
The current repository rules and backend are designed to isolate one family's private data from another family. Deployed-rule evidence and the historical-access assessment remain release requirements, so this statement must not be treated as proof about an earlier or unverified production deployment. Within an authenticated family:
- parents can administer family configuration and receive child profile, progress, activity, inventory, pairing and session information;
- a device presenting a valid but not-yet-consumed child code receives only the pairing roster described above;
- an authenticated child session can receive the same-family roster fields currently supplied by the service: member ID and role, family ID, display name, avatar, coin balance, daily and total quest counts and, for child members, age, gender and tutorial status; and
- child sessions can receive same-family assignment and configuration state needed by the quest and shop experience, while raw user records are self-only and detailed activity and inventory are restricted to the child or an authorized parent.
The current interface may display fewer fields than the service response. Family members should therefore be treated as intended household recipients, not as unrelated third parties.
3.7 Notifications
If notifications are enabled, we process an APNs or FCM push token, the associated user/family identifier, token-update time, language and notification preferences. Messages may identify an event type and, depending on the event, may include a child's display name, a task or catalog reward name, and a requested reward quantity. The operating system may display notification text on the lock screen according to the device's settings.
Core functionality remains available without push notifications. Local reminders are stored on the device until delivered, cancelled or removed by the operating system.
3.8 Subscription information
For the subscription or trial currently required to activate a new family, we process the product and entitlement, a StoreKit app-account token, original transaction identifier, signed transaction during server verification, and active, expiry, revocation or transfer state. Apple processes payment-card and billing information; Picobello does not receive the full payment-card number.
3.9 Aggregate usage statistics to improve the app
We use aggregate usage statistics to improve the app. A scheduled Cloud Function produces de-identified demographic statistics from active child profiles: a population count, the proportion with a known age, an average age, and counts in the broad bands 4–6, 7–9, 10–12, 13–15 and 16–18. The function does not write child IDs, family IDs, exact-age rows or activity rows to the aggregate record. The entire demographic publication is withheld until at least 10 active profiles exist, and any age band with fewer than 10 profiles is omitted. Only this thresholded aggregate reaches the separate administrator dashboard.
This server-side aggregation is kept separate from Firebase Analytics and from individual activity data. Picobello does not join Firestore ages to Firebase Analytics identifiers or build a derived dataset that combines an individual's age with activity. The dashboard works only on the de-identified aggregate output and cannot read child or family documents directly.
Separately, a parent may choose whether Picobello receives first-party onboarding timing statistics. That optional telemetry remains consent-based and is not required for the demographic aggregation described above. Withdrawing or declining that choice stops future optional onboarding telemetry; it does not change the narrowly scoped, de-identified aggregate processing described in this section.
3.10 Privacy requests, exports and deletion
We process the requester and child/family identifiers, request type, scope, status, correspondence and timestamps needed to handle access, portability, correction, restriction, objection, authorization withdrawal, session revocation and deletion requests received through the in-app privacy tools or our privacy-support channel. To fulfill a verified access or portability request, we may temporarily compile a concentrated copy of family data in a protected Cloud Storage object, an expiring download link or another protected electronic file.
An automatically compiled file does not necessarily include every short-lived security or purchase-idempotency record. The privacy-support process therefore performs any supplementary, verified search required for a complete access response.
Deletion jobs use minimized hashed receipts and tombstones to prevent restoration or duplicate processing without retaining the deleted child's readable profile. The main profile and family records are covered, but a shop-purchase idempotency receipt can remain until its 30-day expiry and a short-lived pairing-claim record can remain until scheduled cleanup. Closing and testing those cascade gaps is a release prerequisite.
3.11 Local storage and operational data
The app keeps SwiftData records, pending synchronization operations, cached profile/family information and preferences on the device for offline use and fast startup. Some identifiers and settings are stored in UserDefaults; authentication credentials are managed by the platform and Firebase SDKs. Device backups may contain app data according to the user's Apple backup settings.
Google/Firebase and hosting infrastructure may process IP address, App Check/App Attest data, app version, request time, error and security logs. We use this operational data for delivery, debugging, fraud prevention and security, not product measurement.
Support emails may contain the sender's address, message and any information the sender chooses to include. Please do not send passwords, authentication tokens or unnecessary child information.
3.12 Transactional and support email
Picobello uses Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) to deliver requested sign-in codes, email-verification messages, password-reset messages, support-email verification codes, support requests and confirmation copies. Resend receives the sender and recipient email addresses, subject, message body, authentication code or link, delivery headers and status information. Support messages may also contain the topic, the requester's message, limited account or family references used to investigate the request, and any attachments the requester chooses to send.
These are transactional or user-requested support messages, not advertising. Picobello does not enable open or click tracking for them and does not use them to build an advertising profile. Resend processes this customer message data as a service provider/processor for Picobello. Resend may process its own account, billing and service-usage data as an independent controller under its privacy policy.
To reduce automated abuse of the public support form, Picobello uses Cloudflare Turnstile. When a visitor starts one of the protected support actions, Cloudflare may process the visitor's IP address, browser and device signals, challenge result and related technical metadata. The resulting one-time token is sent to Picobello's backend for validation. Turnstile is used for support-form security, not advertising or product analytics. See Cloudflare's privacy policy for the provider's information.
4. Why we process information and our GDPR bases
For the EEA and other jurisdictions that use the GDPR framework, the following bases are used or assessed by purpose and market. Where consent is required, we request it separately and provide a way to withdraw it:
- Parent account, subscription and requested family service: Article 6(1)(b), taking steps requested by the parent and performing the service contract.
- Child profile, gameplay and personalization: where consent is selected as the applicable basis, Articles 6(1)(a) and 8 together with an approved guardian-verification method; alternatively, a documented child-focused basis and balancing assessment where legally available. The current guardian record is evidence of an action, not by itself an Article 6 basis. The parent can withdraw authorization and request profile deletion.
- Optional push notifications: Article 6(1)(a) where consent is required, or delivery of the specifically requested service. Permission can be withdrawn in the app or device settings.
- Requested authentication and support email: Article 6(1)(b) for account-related messages and requested support, or Article 6(1)(f) where necessary to protect the service and prevent abuse. Resend's processing is limited to delivering those messages on our instructions.
- Aggregate usage statistics to improve the app: Article 6(1)(f), our legitimate interest in understanding the broad age mix and service performance needed to improve Picobello, subject to the documented child-focused legitimate interest assessment. Safeguards include server-only aggregation, broad age bands, a minimum group size of 10, omission of smaller groups, no identifiers or individual activity in the aggregate, restricted administrator access, and no Firebase Analytics linkage.
- Optional onboarding timing statistics: Article 6(1)(a). This separate first-party telemetry is collected only after the parent chooses it and can be stopped for the future by withdrawing that choice.
- Authentication security, abuse prevention, service integrity and limited legal-defense records: Article 6(1)(f), our legitimate interests in keeping a child-focused family service secure, after taking the child's interests and rights into account.
- Privacy rights, regulatory, tax, accounting and breach duties: Article 6(1)(c), where a specific legal obligation applies.
We do not use child data for advertising, cross-app tracking, data-broker sharing or individual-level engagement analytics. We do not use solely automated decisions that create legal or similarly significant effects.
5. Providers and other recipients
We disclose only what is necessary to:
- Google/Firebase and Google Cloud: Authentication, Firestore, Cloud Functions, Cloud Storage, Cloud Messaging, App Check, Hosting and operational logs. Google Sign-In is used only when the parent selects it.
- Apple: Sign in with Apple, App Attest, APNs, StoreKit, App Store distribution and subscription services.
- Cloudflare: Turnstile challenge and token validation for abuse prevention on the public support form. Cloudflare receives the technical signals needed to provide that security service.
- Resend (Plus Five Five, Inc.): transactional and support-email delivery. Resend receives the email addresses, message content, codes or links, support text or attachments and delivery metadata needed to send those messages. Resend's current GDPR materials and Data Processing Agreement state that customer data is stored in the United States, that its Article 28 DPA includes EU Standard Contractual Clauses and the UK Addendum where applicable, and that it participates in the EU-U.S. Data Privacy Framework. The relevant safeguards can be requested from Picobello.
- Authorized family members: according to the family visibility described above.
- Authorized support, security, legal or professional advisers: only where appointed, needed and covered by approved confidentiality and access controls.
- Authorities or other recipients required by law: after validating the request where legally permitted.
- A successor operator: if the service is reorganized or transferred, subject to applicable notice, child-data and consent requirements.
We do not sell personal data or share it for cross-context behavioral advertising. The current app does not contain third-party advertising, Firebase Analytics, another product-analytics SDK, open chat or public child profiles.
6. International processing
The configured Firestore production and development databases, and the content Storage bucket, are in Google's europe-west3 region (Frankfurt, Germany). General-purpose Cloud Functions and scheduled jobs run in europe-west1 (Belgium); resource-triggered functions that must be colocated with Firestore or Storage run in europe-west3. Google, Apple, Cloudflare and other providers may nevertheless process information in the United States or other countries. Resend stores customer data in the United States, including message content and delivery logs.
Where GDPR transfer restrictions apply, Picobello uses an applicable legal mechanism, such as an adequacy decision or the provider's data-processing terms incorporating Standard Contractual Clauses and supplementary safeguards. Resend states that its DPA covers U.S. transfers through the EU Standard Contractual Clauses and the UK Addendum, with the EU-U.S. Data Privacy Framework as an additional mechanism. Current provider and transfer evidence can be requested through the contact above.
7. Retention
Current application-level retention is:
- parent, child, family, current assignment, balance and inventory records: while the relevant account/profile is active, followed by the applicable deletion process;
- detailed user activity feed: 7 days in Firestore, with scheduled daily cleanup; local SwiftData synchronization also removes activity older than 7 days;
- demographic analytics publication: only the latest thresholded aggregate is retained and replaced by the next scheduled run; it contains no child or family identifiers, exact-age rows or activity rows;
- optional onboarding event records: 30 days; resulting daily aggregate records: approximately 25 months;
- shop-purchase idempotency receipts: 30 days;
- child pairing code: valid for 10 minutes; grant and claim records are scheduled for deletion 15 minutes after expiry or consumption/revocation, with cleanup running every 15 minutes;
- pairing rate-limit records: the applicable 10-minute attempt window;
- email sign-in sessions: 10 minutes; email-verification codes: 15 minutes; abandoned anonymous bootstrap accounts become eligible for deletion after 24 hours and, because cleanup runs every 24 hours, can ordinarily remain for roughly 24–48 hours or longer if the job is delayed;
- transactional and support email content and delivery logs held by Resend: Resend currently publishes 30 days for its Free, Pro and Scale plans, with backups persisting for 7 days; Enterprise retention can be configured differently. The applicable Resend account plan and DPA control the exact provider period, and account termination is followed by deletion within the period stated in that DPA (currently up to 90 days);
- support requests and attachments retained in Picobello's support record: up to 730 days from submission, unless a shorter deletion occurs or a legal hold or unresolved legal duty requires controlled retention;
- active child sessions: until revoked or the child/account is deleted; revoked session evidence: 90 days;
- privacy-rights request records: 180 days from submission, unless a legal hold or unresolved duty requires controlled retention;
- export file and link: up to 72 hours; minimized terminal export-job receipt: a further 7 days;
- child/account deletion jobs, receipts and tombstones: 90 days;
- guardian authorization, terms and notice receipts: 2,555 days (approximately seven years), minimized when a child is deleted;
- admin audit records: 365 days; and
- push tokens: currently until the app switches away from or removes the associated profile, the provider reports the token invalid, or the token is otherwise deleted. Turning off an individual in-app notification preference suppresses that category but does not itself remove the token; an inactivity ceiling and complete disable/delete path remain release actions.
Provider logs, security investigations, support correspondence, subscription/accounting records and backups may follow different periods required by configuration or law. Resend's own account, billing and usage records are governed by its privacy policy as controller. Deletion receipts currently record a 90-day target for expiry of residual backups. Production backup, log and support periods must not be longer than necessary and are reviewed in the controller's internal retention schedule.
8. Security
Measures in the current design include encrypted transport, Firebase Authentication, App Check/App Attest, deny-by-default database and storage rules, server-validated family membership and roles, short-lived pairing codes, rate limits, revocable sessions, restricted backend-only lifecycle collections, expiring exports and scheduled deletion.
No service is completely secure. The repository contains an incident runbook and record template, but the controller must assign and test the 24/7 roles, authority/vendor contacts, restricted incident system and family-safe communication routes before production. If a personal-data breach occurs, Articles 33 and 34 require investigation, documentation and notification when their respective thresholds are met.
9. Rights and choices
Subject to applicable law, a parent, guardian or child may request:
- access to personal data and information about its use;
- a portable copy where applicable;
- correction of inaccurate information;
- deletion;
- restriction or objection;
- withdrawal of consent or guardian authorization; and
- revocation of connected child sessions.
To request access, a portable copy or export, correction, restriction, objection, authorization withdrawal or other privacy support, use the in-app privacy tools or email support@picobelloapp.com. Account deletion, child-profile deletion, connected-session revocation and notification choices remain available through the applicable parent-controlled app settings. The operating procedure requires proportionate identity and parental-authority checks and escalation of family-conflict or child-safety concerns instead of automatic disclosure to every family member. Where appropriate, copies containing child or family data are delivered through a protected download or protected electronic file rather than in the body of an ordinary email. A request sent by email may be processed by Resend during delivery.
If another parent with an independent Apple, Google or verified-email sign-in remains in the family, deleting one parent's account removes that parent and their access but does not delete family data still administered by the remaining credentialed parent or parents. Deleting the final independently credentialed parent account starts deletion of the family, every child profile and any parent profiles that only joined through an invite code. A child profile can also be deleted separately through the applicable parent-controlled flow.
You may complain to the data-protection authority in the EU/EEA country where you live or work or where you believe an infringement occurred. Withdrawing consent does not affect processing already carried out lawfully, and limited records may remain where a legal obligation or appropriately documented legal claim requires them.
10. Children and additional markets
A short English/German child-facing privacy explanation and privacy center are available in the app. Parents control creation of cloud child profiles below the applicable digital-consent threshold, while the app provides a self-consent transition at or above that threshold. The child-facing explanation is supplemental; this full notice controls if the two versions differ.
Countries outside the EEA may require different age thresholds, direct notices or a specific method of verifiable parental consent. In particular, an authenticated parent account and attestation must not be assumed to satisfy every U.S. COPPA use case. Picobello must complete the applicable market and consent review before intentionally offering under-13 child data processing in the United States or another market with additional requirements.
11. Changes
We may update this policy when the app, providers, legal basis, recipients or retention change. We will change the version and date and provide additional notice or request renewed authorization where required. The guardian-authorization flow shows the exact bundled policy and terms versions recorded in its receipts. Other legal screens may show a newer remote version; a release procedure must determine when re-notice or renewed authorization is required.
12. Contact
Picobello Software UG (haftungsbeschränkt)
c/o The Base Berlin One, Pestalozzistraße 5-8, Apt. 216, 13187 Berlin, Germany
Managing director: Felix Parey
Commercial register: Amtsgericht Charlottenburg, HRB 291439 B