EEA Privacy Notice
Last updated: August 2026
Version 0.1 (August 2026). Internal compliance sign-off — not externally legally verified.
We care about your privacy. My Starday collects only what is needed to run the service. We do not sell your information. Sharing outside the service happens only when you actively choose it (for example, professional share links) or when required for operation through our processors. Optional analytics and marketing run only with your consent.
Data controller: Papa Bravo AB. Contact us via the contact form.
This notice applies to families using My Starday in the European Economic Area (EEA), including Ireland. For children’s data, see our separate Child Privacy Notice. For optional cookies and similar technologies, see Your privacy choices.
What we collect
We process personal data to provide the app and features you register for. The legal basis is typically performance of a contract (GDPR Article 6(1)(b)) and, where applicable, consent or legitimate interests as described below.
Parent account
- Email address and name — account sign-in, communication, and personalisation
- Password — stored as a bcrypt hash, never in plain text
- Apple Sign In / Google Sign-In — email and name from the provider when you choose that sign-in method; if you use Apple’s “Hide My Email”, we store the relay address Apple provides
- Optional parent PIN — hashed, for re-authentication to parent settings
- Push preferences and notification settings
- Preferred language — stored on your family record
Family record
- Country and market region — to apply the correct legal and product rules
- Timezone — to determine schedule day boundaries
- Subscription / in-app purchase state — access control via RevenueCat-linked fields (no card numbers stored in our database)
Child profile
- First name or nickname and emoji — how the child is shown in the app
- Username and PIN — child login; PIN stored as a hash; failed attempts may trigger lockout and audit logging
- Optional profile photo — when uploaded, stored via Cloudflare R2 or local disk hosting
- Optional birthday — for age-appropriate experience only
- View settings — which UI elements the child sees
We do not collect for children: surname, national ID, email address, or phone number. There is no code path in My Starday that stores these for child profiles.
Core product data
- Schedules, activities, and routines you create for your family
- Activity completions and daily logs — what was done and when
- Stars and streaks — earned and redeemed rewards
- Rewards and redemptions in the treasure chamber
- Optional parent ratings or comments on activities
Optional observations (parent or pedagog entered only)
If you or a linked educator use reporting features, you may optionally enter structured notes such as mood, sleep quality, meals, or behaviour, or free-text observations by time of day. This content is entered by adults only; children do not fill in these forms.
My Starday is a routine and family organisation tool, not a medical or clinical records service. We do not ask you to enter diagnoses, medication, or other medical information. If you choose to write health-related details in free text, we treat that content as sensitive: we do not use it for analytics, marketing, profiling, or automated inference, and we do not share it beyond what is needed to store and display it for your family.
Professional share links
If you create a time-limited link to share selected activity and reward information about a child with a professional (for example, a teacher or therapist), that happens only on your initiative. You choose what is included, may password-protect the link, and can revoke it at any time. Links expire after seven days by default. Recipients do not need a My Starday account.
Technical and operational data
- Session cookies and refresh tokens — to keep you signed in securely (httpOnly cookies; refresh tokens hashed in our database)
- Push device tokens — when you enable notifications (web push endpoint, or APNs/FCM on native apps)
- In-app notification history — pruned after seven days
- Product analytics events — pseudonymised product analytics linked to a family identifier, with allowlisted metadata (see below)
- Newsletter opt-in — if you subscribe separately to marketing email
How we use your data
We use personal data only to operate and improve My Starday:
- Show children their daily schedules and track progress
- Manage stars, rewards, and family membership
- Send transactional email (verification, password reset, account notices)
- Deliver push notifications you have enabled
- Respond to messages you send via our contact form
- Measure product usage through consent-gated analytics where enabled
Child routine and completion data is not sent to advertising platforms. Marketing scripts (Google Analytics 4, Meta Pixel, Google Ads) load only after you opt in via the cookie banner. Server-side product analytics use an allowlisted set of event types and do not include child completion payloads in marketing tools.
Processors and subprocessors
We use the following service providers who process data on our instructions under GDPR Article 28 (verified August 2026):
- Self-hosted PostgreSQL on VPS — primary application database (all account, family, schedule, and reward data at rest). Hosted on our VPS in Stockholm, Sweden (EU/EEA).
- Inleed / Yelles AB — VPS infrastructure provider for the web application, API, and static assets (Stockholm, Sweden, EU/EEA).
- Resend — transactional email to parent addresses (United States; transfers covered by Resend’s DPA including EU Standard Contractual Clauses).
- Cloudflare R2 — uploaded profile photos and object storage in an EU jurisdiction bucket (Cloudflare Customer DPA).
- Apple — Sign in with Apple and APNs push delivery (global Apple infrastructure; EEA transfers per Apple’s privacy terms including SCCs).
- Google — Google Sign-In on web (United States / global Google infrastructure; Google API terms and transfer safeguards including DPF/SCCs where applicable).
- Google Analytics 4 (optional, consent-gated) — website usage measurement (United States when enabled; Google data processing terms + SCCs; off by default).
- Meta (Facebook Pixel) (optional, consent-gated) — marketing measurement (United States when enabled; Meta Data Processing Terms + EU transfer addendum; off by default).
- Google Ads (optional, consent-gated) — conversion measurement (United States when enabled; off by default).
Not currently active on prod VPS: Neon database hosting (our live database runs on the VPS above, not Neon). RevenueCat subscription sync and Google FCM push are configured in code but not enabled on our prod server until native in-app purchase rollout; when enabled, RevenueCat will process subscription entitlement data under its DPA including EU SCCs, and store billing remains via Apple App Store / Google Play.
Vendor data processing agreements and transfer mechanisms are documented in our internal compliance registers. This notice reflects verified prod VPS configuration as of August 2026.
Push notifications
If you enable push notifications, we store a device token linked to your account to deliver notifications to the correct device. Tokens are removed when you log out or when the platform reports the token is invalid (for example, after uninstalling the app). You can disable notifications in Settings → Push notifications or in your device system settings.
Cookies and similar technologies
On our website and in web views, we use:
- Strictly necessary cookies — always active. Session cookies (
access_token,refresh_token) and CSRF protection required for secure sign-in. - Preferences — stored locally (for example, theme choice).
- Analytics — Google Analytics 4; off by default until you consent via the cookie banner.
- Marketing — Meta Pixel and Google Ads tags; off by default until you consent.
Your consent choice is stored for up to one year in the cc_consent cookie and in localStorage. You can change your choices at any time via the cookie banner or on Your privacy choices. When signed in, you can also manage choices under Settings → Privacy.
Product analytics
We record certain product events server-side in an analytics_events table as pseudonymised product analytics linked to a family identifier, with allowlisted event types and metadata. These events help us understand how the product is used. They are deleted when you delete your account. Aggregated daily snapshots (without family identifiers) may be retained for operational metrics.
Retention
- Account data — kept while your account is active
- Notification log — pruned after seven days
- Refresh tokens — default thirty-day expiry
- Professional share links — seven-day default expiry; revocable earlier by you
- Analytics events — until account deletion
Export your data
You can download a ZIP archive of your family data (CSV files) from Settings → Export data. For security, exports are limited to one request per twenty-four hours per parent account.
Delete your account
You can delete your account immediately in the app under Settings → Delete account, confirmed with your password or third-party sign-in verification.
Warning: Deletion is immediate and permanent for family-scoped data, including:
- Parent account (name, email, authentication data)
- All child profiles in the family
- Schedules, routines, activities, and daily logs
- Stars, rewards, redemptions, and streaks
- Push tokens, refresh tokens, and family-scoped analytics events
- Uploaded avatars and family invitations
Exceptions: The following may be retained for legal or operational reasons:
- Admin audit log — security and impersonation audit trail
- Contact messages — correspondence you sent to support
- Aggregated analytics snapshots — daily metrics without family identifiers
Security
We aim to host core application data in the EU/EEA where applicable. Some service providers may process data outside the EEA; international transfers and applicable safeguards are described below and are being verified before Ireland launch. We use encrypted connections (HTTPS) and industry-standard practices. Passwords and PINs are stored using bcrypt hashing. Child-scoped API access is enforced on the server. Destructive parent actions require CSRF protection.
Your rights under GDPR
If you are in the EEA, you have the following rights regarding your personal data:
- Access — request a copy of your data (export in Settings or via the contact form)
- Rectification — correct inaccurate data in profile and settings
- Erasure — delete your account and family data as described above
- Restriction and objection — contact us if you wish to restrict or object to certain processing
- Data portability — receive your data in a structured format via export
- Withdraw consent — for optional analytics and marketing at any time via the cookie banner or Settings
- Complaint to a supervisory authority — see the Ireland section below
To exercise any right, use in-app settings where available or contact us via the contact form.
Ireland
If you are in Ireland, you have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority for data protection. Visit dataprotection.ie for contact details and guidance.
Papa Bravo AB is established in Sweden. Integritetsskyddsmyndigheten (IMY) is our lead supervisory authority for cross-border processing. If you are in Ireland, you may also lodge a complaint with the Data Protection Commission (DPC).
Related documents
- EEA Terms of Service
- Child Privacy Notice
- Your privacy choices (cookies and optional analytics)
Contact
Questions about this notice or how we handle your data?