EEA Privacy Notice

Last updated: August 2026

Version 0.1 (August 2026). Internal compliance sign-off — not externally legally verified.

We care about your privacy. My Starday collects only what is needed to run the service. We do not sell your information. Sharing outside the service happens only when you actively choose it (for example, professional share links) or when required for operation through our processors. Optional analytics and marketing run only with your consent.

Data controller: Papa Bravo AB. Contact us via the contact form.

This notice applies to families using My Starday in the European Economic Area (EEA), including Ireland. For children’s data, see our separate Child Privacy Notice. For optional cookies and similar technologies, see Your privacy choices.

What we collect

We process personal data to provide the app and features you register for. The legal basis is typically performance of a contract (GDPR Article 6(1)(b)) and, where applicable, consent or legitimate interests as described below.

Parent account

Family record

Child profile

We do not collect for children: surname, national ID, email address, or phone number. There is no code path in My Starday that stores these for child profiles.

Core product data

Optional observations (parent or pedagog entered only)

If you or a linked educator use reporting features, you may optionally enter structured notes such as mood, sleep quality, meals, or behaviour, or free-text observations by time of day. This content is entered by adults only; children do not fill in these forms.

My Starday is a routine and family organisation tool, not a medical or clinical records service. We do not ask you to enter diagnoses, medication, or other medical information. If you choose to write health-related details in free text, we treat that content as sensitive: we do not use it for analytics, marketing, profiling, or automated inference, and we do not share it beyond what is needed to store and display it for your family.

Professional share links

If you create a time-limited link to share selected activity and reward information about a child with a professional (for example, a teacher or therapist), that happens only on your initiative. You choose what is included, may password-protect the link, and can revoke it at any time. Links expire after seven days by default. Recipients do not need a My Starday account.

Technical and operational data

How we use your data

We use personal data only to operate and improve My Starday:

Child routine and completion data is not sent to advertising platforms. Marketing scripts (Google Analytics 4, Meta Pixel, Google Ads) load only after you opt in via the cookie banner. Server-side product analytics use an allowlisted set of event types and do not include child completion payloads in marketing tools.

Processors and subprocessors

We use the following service providers who process data on our instructions under GDPR Article 28 (verified August 2026):

Not currently active on prod VPS: Neon database hosting (our live database runs on the VPS above, not Neon). RevenueCat subscription sync and Google FCM push are configured in code but not enabled on our prod server until native in-app purchase rollout; when enabled, RevenueCat will process subscription entitlement data under its DPA including EU SCCs, and store billing remains via Apple App Store / Google Play.

Vendor data processing agreements and transfer mechanisms are documented in our internal compliance registers. This notice reflects verified prod VPS configuration as of August 2026.

Push notifications

If you enable push notifications, we store a device token linked to your account to deliver notifications to the correct device. Tokens are removed when you log out or when the platform reports the token is invalid (for example, after uninstalling the app). You can disable notifications in Settings → Push notifications or in your device system settings.

Cookies and similar technologies

On our website and in web views, we use:

Your consent choice is stored for up to one year in the cc_consent cookie and in localStorage. You can change your choices at any time via the cookie banner or on Your privacy choices. When signed in, you can also manage choices under Settings → Privacy.

Product analytics

We record certain product events server-side in an analytics_events table as pseudonymised product analytics linked to a family identifier, with allowlisted event types and metadata. These events help us understand how the product is used. They are deleted when you delete your account. Aggregated daily snapshots (without family identifiers) may be retained for operational metrics.

Retention

Export your data

You can download a ZIP archive of your family data (CSV files) from Settings → Export data. For security, exports are limited to one request per twenty-four hours per parent account.

Delete your account

You can delete your account immediately in the app under Settings → Delete account, confirmed with your password or third-party sign-in verification.

Warning: Deletion is immediate and permanent for family-scoped data, including:

Exceptions: The following may be retained for legal or operational reasons:

Security

We aim to host core application data in the EU/EEA where applicable. Some service providers may process data outside the EEA; international transfers and applicable safeguards are described below and are being verified before Ireland launch. We use encrypted connections (HTTPS) and industry-standard practices. Passwords and PINs are stored using bcrypt hashing. Child-scoped API access is enforced on the server. Destructive parent actions require CSRF protection.

Your rights under GDPR

If you are in the EEA, you have the following rights regarding your personal data:

To exercise any right, use in-app settings where available or contact us via the contact form.

Ireland

If you are in Ireland, you have the right to lodge a complaint with the Data Protection Commission (DPC), the Irish supervisory authority for data protection. Visit dataprotection.ie for contact details and guidance.

Papa Bravo AB is established in Sweden. Integritetsskyddsmyndigheten (IMY) is our lead supervisory authority for cross-border processing. If you are in Ireland, you may also lodge a complaint with the Data Protection Commission (DPC).

Related documents

Contact

Questions about this notice or how we handle your data?

Contact form