Denne siden finnes ikke på Norsk ennå. Den vises på engelsk.
Privacy notice
How Jepify handles data
Plain language first, full detail below. Version 1.1.0, early-access edition, effective 11 October 2026.
Early-access privacy notice. This notice covers the current early-access service and website. Some provider-specific technical facts and planned product behaviours are identified as unverified or future features. Statements about planned behaviour are not claims that the feature has shipped. The controller identity is separate from the product brand.
Effective: 11 October 2026 · Version 1.1.0
Part 1: the short version
Jepify helps a family agree on a child’s everyday responsibilities, notice progress and gradually give the child more ownership. A parent or guardian creates the family account. A child uses Jepify on their own device through a profile the guardian creates: a child does not need to supply a separate email address or phone number or create or remember a password. A child still uses a technical authentication identity for secure device access.
- Who is responsible. Santeri Kangas, a private individual in Finland. Jepify is published under the DynamikUs name. Contact for privacy matters: privacy@dynamikus.com.
- What we use. The guardian’s sign-in details; the family and child profiles you create (a family name, a child nickname, how the app looks for the child); the responsibilities, notes, weekly reviews and rewards you set up; what happens to each responsibility; device and notification information needed to run the app; crash reports; and counts of how Jepify is used, made on our own servers from what happens in the app. There is no analytics tracker on your phone.
- Child usage information only with consent. Information about how a child uses the app is collected only if it has been allowed for that child. It is pseudonymous, never includes the child’s name, what responsibilities say, messages or location, is seen only by the Jepify team, and can be switched off at any time.
- What we never do. We do not sell personal data. Jepify shows no advertising and uses no one’s data for advertising. We do not track location. Children’s usage information is never shown to anyone in the family and never used to judge, score or reward a child.
- Where. The main database and server functions run in Google Cloud in Finland (EU). Some supporting services (sign-in, crash reporting, push notifications, app-integrity checks) may process data outside the EU; see section 7.
- How long. Weekly reviews and reward history, including records of rewards given and corrections, are kept for 24 months after the week ends; a week with a reward not yet marked as given is retained under the disclosed exception; standard deletion of family/profile records remains subject to backups and lawful retention exceptions described below. Copies in backups are normally deleted automatically within 90 days (section 8).
- Your rights. You can ask to see, correct, delete or move your data, object to some processing, and withdraw consent at any time. A guardian can delete the family account or remove a child’s profile (section 9.4). You can complain to the Finnish Data Protection Ombudsman. A child can exercise their own rights too.
- This website currently has no first-party analytics configured; hosting and other external resources may still process connection information (section 3.16 and Cookie policy).
Important distinctions
- Family records are not optional analytics. Responsibilities, completed actions and rewards are processed to provide the family service; optional child usage analytics have a different purpose and separate consent route.
- Terms acceptance is not privacy consent. Accepting the Terms is never treated as consent to any analytics or marketing processing.
- Guardian authority and child rights are distinct. Children’s statutory data-protection rights remain relevant even if the product interface is guardian-controlled.
- The product is not a bank. An amount marked as given is a guardian’s record of a family reward delivered outside the app, not a financial transaction by Jepify.
- The current version has no location tracking or advertising. Any future feature that changes this requires new disclosures and a suitable legal basis.
Part 2: the full notice
1. Who is responsible for your data
The controller of the personal data described here is Santeri Kangas, a private individual in Finland. If the controller changes to a company, the actual identity and contact information will be updated. Jepify is not yet run by a company, so there is no business identifier. Jepify and this website are published under the DynamikUs name; a brand change does not of itself change the named controller.
- Privacy contact, including requests to use your rights and deletion requests: privacy@dynamikus.com
- Help with the app: support@dynamikus.com
- General questions: hello@dynamikus.com
- Data protection officer: none. We are not required to appoint one. Use the privacy address above.
2. Who this notice is for
- Parents and guardians who create and run a family in Jepify. This notice is written mainly for you.
- Children who use Jepify on their own device through a child profile. A shorter, child-friendly explanation is shown inside the app; it does not replace this notice.
Jepify is not intended for a child to sign up alone. A guardian creates the family and each child profile and connects (“pairs”) the child’s own device. A shared family device is not supported.
Early access. During early access, Jepify is used only by families we have invited. Early-access families with children aged 13 or over are told how the child’s own consent rights work (section 9.2). Jepify itself does not ask for or store a child’s age.
3. What Jepify does with personal data, by purpose
Each subsection lists what data, why, the lawful basis under the GDPR, how long we keep it, who processes it and where.
Storage on your device. To work, Jepify keeps a few things on the phone: your sign-in session, a queue of actions made while the phone is offline, and items held in the phone’s secure storage. This is strictly necessary to provide the service, so under the Finnish Act on Electronic Communications Services (917/2014, section 205) it needs no separate consent.
3.1 Guardian account and sign-in
- Data: the sign-in method you choose (email address and password, Sign in with Apple, or Google sign-in); the account identifier our sign-in service issues; for Apple or Google sign-in, the identifiers and profile details that provider passes to the sign-in service; a password-reset email when you ask for one; the family your account belongs to. Passwords are handled by the sign-in service; Jepify’s own code never stores or logs your password.
- Purpose: to let you create an account, sign in securely, reset a forgotten password and reach your family.
- Lawful basis: performance of the contract with you (GDPR Art. 6(1)(b)).
- Retention: while your account exists. When you delete your account (section 9.4) it is deleted within 24 hours after the 7-day grace period; for Sign in with Apple, the app’s Apple tokens are revoked. Copies in backups are normally deleted automatically within 90 days (section 8).
- Processors: Google (Firebase Authentication). If you use Sign in with Apple or Google sign-in, Apple or Google also processes your sign-in under its own terms.
- Location: see section 7.
3.2 Family, guardian membership and child profiles
- Data: the family name you choose; the family’s time zone (taken from the guardian’s device when the family is created); guardian membership and role; for each child, a nickname (a legal name is not required), the presentation mode chosen for them (Simple & Visual, Balanced or More Mature) and when the profile was created and by whom. Jepify does not ask for a child’s age, date of birth, email, phone number, photo or avatar.
- Purpose: to set up the family as a private space, decide who may see and change what, and show each child an experience suited to them.
- Lawful basis: for the guardian’s data, performance of the contract with you (Art. 6(1)(b)). For the child’s data, our legitimate interest in providing the family service the guardian set up (Art. 6(1)(f)), weighed with particular regard to the child’s interests.
- Retention: while the family and the child profile exist. A guardian can delete the family or remove a child’s profile (section 9.4): after a 7-day grace period the data is deleted within 24 hours, and copies in backups normally within 90 days (section 8).
- Processors: Google Cloud (Cloud Firestore, Cloud Functions).
- Location: EU, Finland (Google Cloud region europe-north1).
A record of a nickname change request is kept for 30 days to prevent duplicates; it stores a one-way digest, not the nickname itself.
3.3 Connecting a child’s device (pairing) and child access
- Data: a short-lived pairing code (stored only as a keyed hash, valid for 5 minutes, limited to 5 failed attempts); a random installation identifier created by the app on the child’s device (no hardware identifiers); the device platform (iOS or Android); an access grant linking one child profile to one device, its status and, if revoked, when and by whom; a child sign-in identity issued by our sign-in service for that grant; rate-limit records. If the child scans the pairing code, the camera is used only to read the code; the app does not request the microphone.
- Purpose: to let a guardian give a child access on the child’s own device without the child having an account, to keep that access secure and revocable, and to prevent misuse of pairing codes.
- Lawful basis: for the guardian’s data, performance of the contract (Art. 6(1)(b)). For the child’s data, our legitimate interest in providing the family service the guardian set up (Art. 6(1)(f)), weighed with particular regard to the child’s interests.
- Retention: pairing codes expire after 5 minutes; access grants and device records are kept while the family exists (revoking access ends the child’s session but does not delete the child profile or its history); deleting the family or removing the child’s profile signs the child’s device out at once and deletes these records, the live pairing codes and the child sign-in identity; rate-limit records expire within 30 days.
- Processors: Google Cloud (Cloud Firestore, Cloud Functions), Google (Firebase Authentication for the child session identity).
- Location: Firestore and functions: EU, Finland (europe-north1). Firebase Authentication: see section 7.
3.4 Responsibilities, notes and daily progress
- Data: responsibilities the guardian creates for a child (title, “what done looks like”, schedule, optional due and reminder times, whether guardian acknowledgement is needed); each scheduled occurrence and what happened to it (completed independently or with help, needs fixing, acknowledged, missed, skipped, rescheduled) with times and who acted; a guardian’s optional “needs fix” note (up to 200 characters); a child’s skip or reschedule requests (fixed reasons only, no free text); the child’s own reminder-timing preference; guardian-only records about when the app suggests a child could take more ownership and the guardian’s decisions; random pseudonymous identifiers used for statistics.
- Purpose: to run the core of Jepify: show the child what to do today, record progress, let the guardian acknowledge or ask for a fix, and support gradually giving the child more ownership.
- Lawful basis: for the guardian’s data, performance of the contract (Art. 6(1)(b)). For the child’s data, our legitimate interest in providing the family service the guardian set up (Art. 6(1)(f)), weighed with particular regard to the child’s interests.
- Retention: occurrences and their history are kept while the responsibility, the child profile and the family exist, and are deleted with the child’s profile or the family (section 9.4); processed app commands are deleted after 30 days (their outcome stays in the occurrence history); command rate-limit records expire within 30 days.
- Processors: Google Cloud (Cloud Firestore, Cloud Functions, Cloud Scheduler for the timing of daily processing; the scheduler job holds only a schedule and a topic name, no personal data, and runs in Belgium).
- Location: EU, Finland (europe-north1); scheduler trigger only in EU, Belgium.
Who can see it: guardians of the family see their children’s responsibilities and progress; a child sees their own responsibilities. Guardian-only records are not visible to the child.
3.5 Weekly reviews, rewards and allowance
- Data: the family week settings and currency; weekly reviews per child (a categorical summary such as “on track” or “let’s talk”, the guardian’s allowance decision and an optional decision note, a weekly recognition snapshot); reward agreements (weekly allowance or extra rewards, with an amount and currency or a short non-money reward text of up to 80 characters); reward links and outcomes; records that a guardian recorded a reward as given outside Jepify (which reward, which guardian, when) and corrections to those records; support-level changes; request records that prevent duplicate actions.
- Purpose: to help the family run a weekly review and keep its own reward or allowance agreements consistently. Rewards are optional. Jepify records what was agreed and earned and when a guardian recorded a reward as given outside Jepify; it does not move money and holds no bank or payment details.
- Lawful basis: for the guardian’s data, performance of the contract (Art. 6(1)(b)). For the child’s data, our legitimate interest in providing the family service the guardian set up (Art. 6(1)(f)), weighed with particular regard to the child’s interests.
- Retention: each completed family week (its review, allowance decision and note, recognition snapshot, every reward outcome of that week and the records of those rewards being given and corrected) is deleted 24 months after the week ended. A week with a reward that has not yet been recorded as given is kept until it is; after that, the 24 months count from the end of the week. An open week and the current version of an active reward agreement are not deleted by this rule. All of it is also deleted when the child’s profile or the family is deleted. While kept, these records are not changed; corrections are added as separate linked records, and ordinary product controls do not allow selective removal of one reward, review or week; this product-integrity rule does not override lawful requests for rectification or erasure. Copies in backups are normally deleted within 90 days (section 8). Duplicate-prevention records expire within 30 days.
- Processors: Google Cloud (Cloud Firestore, Cloud Functions).
- Location: EU, Finland (europe-north1).
3.6 Notifications
- Data: push tokens for guardian devices and for the paired child device; the notification’s kind and opaque routing identifiers; delivery outcome. Notification text on the lock screen is fixed, generic wording; it never contains a child’s nickname, a responsibility title or any text the family wrote.
- Purpose: to remind a child about responsibilities and to tell guardians when something needs their attention.
- Lawful basis: for guardians’ notifications, performance of the contract (Art. 6(1)(b)). For notifications to the child’s device, our legitimate interest in providing the family service the guardian set up (Art. 6(1)(f)), weighed with particular regard to the child’s interests. The phone’s operating system asks for notification permission, which can be turned off in the phone’s settings.
- Retention: push tokens are kept while the device is signed in or paired; invalid tokens are removed when the delivery service reports them; tokens are deleted with the account, the family or the child’s profile.
- Processors and recipients: Expo (Expo Push Service), which passes the notification to Apple Push Notification service (iOS) or Firebase Cloud Messaging (Android, Google).
- Location: see section 7.
3.7 Security and app integrity
- Data: an app-integrity token produced on the device by Apple DeviceCheck (iOS) or Google Play Integrity (Android) and verified by Firebase App Check.
- Purpose: to check that requests come from a genuine copy of Jepify and to protect families’ data from abuse.
- Lawful basis: our legitimate interest in securing the service and preventing abuse (Art. 6(1)(f)).
- Processors and recipients: Google (Firebase App Check, Play Integrity), Apple (DeviceCheck).
- Retention and location: see section 7 and section 13.
3.8 Running the service: request handling and server logs
- Data: when the app calls our servers, the server infrastructure necessarily handles technical request information such as the IP address, app and user-agent information and the signed-in identity needed to handle the request. Our servers also write operational log entries (error categories and correlation information). These logs are designed to exclude family-written text, nicknames and passwords. They can include the random database reference of the family, child profile or record a request concerned, and entries written while handling the same request can be connected to each other.
- Purpose: to execute requests, keep data consistent, detect failures and keep the service secure. People on our team who are allowed to read the logs use them only to find and fix faults in the live service, not for usage statistics, profiling or decisions about a family or child.
- Lawful basis: for a guardian’s own requests, performance of the contract (Art. 6(1)(b)) where the processing is objectively necessary to provide the service. For requests from a child’s device, and for operating and securing the service, our legitimate interests in keeping Jepify working and secure (Art. 6(1)(f)), weighed with particular regard to children’s interests.
- Retention: log entries expire automatically, by default after 30 days (section 13.1); our own setting is still being confirmed (section 13.2). They cannot be deleted one by one.
- Processors: Google Cloud (Cloud Functions / Cloud Run, Cloud Logging).
- Location: server functions run in EU, Finland. Infrastructure log location: section 13.
3.9 Crash reports (all devices, including children’s)
- Data: when the app crashes or hits an error: the error and stack trace (with error messages redacted), app version, operating-system version, technical details about the phone such as its model, a fixed list of technical step labels, and an app-installation identifier generated by the crash-reporting service. Crash reports never include names, what responsibilities or notes say, messages or location, and Jepify adds no user ID and no identifier for the child.
- Purpose: only to find and fix crashes and keep the app working safely and reliably. Not used for usage statistics, engagement measurement, advertising or profiling.
- Lawful basis: our legitimate interests in finding and fixing crashes (Art. 6(1)(f)), weighed with particular regard to children’s interests. This is classified as essential diagnostics for the current design. That device-access classification and the Art. 6(1)(f) basis are purpose-specific, documented in the app legal-review records, and depend on the actual SDK configuration remaining within the reviewed scope. The existence of a useful diagnostic SDK does not, by itself, make arbitrary telemetry essential.
- Retention: crash reports are not linked to an account or a child, so we cannot find them by account; they expire with the crash-reporting service’s retention period (section 13).
- Processors: Google (Firebase Crashlytics).
- Location: see section 7.
3.10 App error reports through Jepify’s own system (all devices, including children’s)
- Data: categorical reports of sync and operational errors (for example: a command was rejected, sync failed, an offline queue overflowed, pairing or session failed), with only the platform, app version, operating-system major version, an error code and the hour. No child identifier and no pseudonym.
- Purpose: to keep the service working reliably, including when a child’s device is offline.
- Lawful basis: our legitimate interests in keeping the service working reliably (Art. 6(1)(f)), weighed with particular regard to children’s interests. Part of the essential processing.
- Retention: 90 days, then deleted automatically.
- Processors: Google Cloud (Cloud Functions, Cloud Logging, dedicated EU log bucket).
- Location: EU, Finland (europe-north1).
3.11 Child usage information (only with consent)
This is the only optional, consent-based processing about children.
- When: only while a valid “Allow” choice applies to that child. When a guardian connects a child’s device, they choose Allow or Don’t allow; neither is pre-selected, and the choice can be changed at any time in the child’s “Device access” screen, with the same effort either way. “Don’t allow” is never asked about again.
- Data: how the child app is used: screens and routes opened, journey steps, timings in ranges, how the app behaves offline, categorical errors and approved coarse context. Every item comes from a fixed, closed list.
- Never included: names or nicknames; what responsibilities, “done” descriptions or notes say; messages; location (precise or derived from the IP address); advertising identifiers; hardware or device identifiers; the device model; age or date of birth; the child’s presentation mode; reward amounts or currency; contacts; photos; anything typed; database or account identifiers.
- How the child is identified: by a pseudonym our server computes from a random secret value kept for that child and a server-held key that changes regularly. The app never sees or computes it, and it is never used in crash reports, guardian usage measurement or any other dataset. We treat this information as personal data while we can still connect it to the child.
- Purpose: to understand how the child experience works and improve it: where children get stuck, how long things take, how offline mode behaves.
- Never used for: advertising, maximising engagement or notifications, streaks, judging a child’s competence, autonomy scores, reward decisions, monitoring or reporting to guardians, or any automated decision about a child.
- Lawful basis: consent (Art. 6(1)(a)), given by the person entitled to give it (section 9.2).
- Who sees it: only authorised members of the Jepify team. It is never shown to anyone in the family, including the guardian.
- Retention: individual events at most 90 days, then deleted automatically. Statistical totals that contain no child pseudonym, with groups of fewer than five children suppressed: up to 24 months.
- Processors: Google Cloud (Cloud Functions, Cloud Logging, BigQuery).
- Location: EU, Finland (europe-north1).
If consent is withdrawn: optional usage collection stops, buffered events are discarded, and the child linkage secret is destroyed. Previously collected raw events expire within 90 days; this does not mean they are immediately physically erased. Events still waiting on the device are discarded, and late-arriving events are rejected.
3.12 Consent records
- Data: for each child: the current choice (Allow / Don’t allow), which version of the consent explanation was shown, where the choice was made (when pairing or in settings), when it was made or changed, and who made it (the guardian’s account identifier, or the child where the child is entitled to decide), with a change history. The child’s pseudonym secret is held with the live record only.
- Purpose: to apply the choice and to be able to show that consent was validly given or withdrawn.
- Lawful basis: while the child profile exists, compliance with our legal obligation to be able to demonstrate consent (Art. 6(1)(c) with Art. 7(1) and 5(2)). For the three years after withdrawal or deletion, our legitimate interest in establishing or defending legal claims (Art. 6(1)(f)).
- Retention: while the child profile exists, and for three years after a withdrawal or after the child profile or the family is deleted, solely as evidence of consent and compliance. When a family or a child’s profile is deleted, the child’s pseudonym secret is deleted at once, so earlier usage information can no longer be connected to the child. The retained record is minimised: no nickname, responsibility content, usage information, pseudonym secret or unrelated family information.
- Processors: Google Cloud (Cloud Firestore, Cloud Functions).
- Location: EU, Finland (europe-north1).
3.13 Guardian usage measurement
- No analytics tracker on your phone. Jepify does not include Google Analytics or any other third-party analytics tool, and nothing is stored on or read from a guardian’s phone to measure how guardians use Jepify.
- How we measure guardian use: only from events our own servers already handle when you use Jepify (for example a responsibility was created, a completion was acknowledged, a weekly review became ready), as operational events and as daily totals by event and category with no child, responsibility or family identifier, where groups of fewer than five children are suppressed. For example: how many families were active in a week. No text the family wrote and no names.
- Purpose: to understand whether Jepify works for families and improve it.
- Lawful basis: our legitimate interests in understanding whether Jepify works for families and improving it (Art. 6(1)(f)).
3.14 Product measurement from server events
Our servers record events when something happens in the family’s data. They contain categorical values only: no text the family wrote and no names. They fall into three classes:
- Operational events, needed to run, secure or reconcile the service and detect failures. Never used to measure how a child uses the product. Basis: as section 3.8.
- Child-linked product events, used to measure product use and linked to one child or one responsibility. Kept individually only while that child’s usage-information choice is Allow, using a separate server-computed key that is unlinked when consent is withdrawn. Basis: consent (Art. 6(1)(a)). Retention: 90 days.
- Aggregate product events, daily counts by event and category with no child, responsibility or family identifier, and groups under five children suppressed. Basis: legitimate interests (Art. 6(1)(f)). The counts are designed to contain no personal data, but we do not assume that they are anonymous.
Today, before any analytics dataset exists, our servers write these events only to their own logs, with categorical values only; the child-linked class does not exist yet. The event entries themselves contain no child, responsibility or family identifier, but they are stored with the server logs of the same request, which can contain such references (section 3.8). They are therefore handled like those logs and used only to find and fix faults.
3.15 Support and feedback
- Data: your email address and what you write when you contact us: support@dynamikus.com for questions and help with the app, privacy@dynamikus.com for privacy, rights and deletion requests. We do not ask for information about your child to answer a support request; if you include it, we handle it in the same way as the rest of your message. There is no in-app support or feedback feature yet.
- Purpose: to answer your question or request.
- Lawful basis: for a guardian’s own requests, performance of the contract (Art. 6(1)(b)). For other requests, our legitimate interest in answering them (Art. 6(1)(f)).
- Retention: we delete support emails 24 months after the request is closed. Records of privacy and deletion requests are covered in section 8.
- Processors: Google (Google Workspace, Gmail), which hosts the mailboxes.
- Location: see section 7.
AI-assisted support is not used. Before any family content is sent to an AI provider, this notice will be updated.
3.16 This website
- No first-party website analytics currently configured. The source configuration has no active site analytics identifier. Hosting, external fonts on some marketing pages and future embedded forms may still process technical information or use their own device technologies. If non-essential cookies or comparable storage are added, we will explain them and provide a choice where required. See the Cookie policy.
- Hosting. The site is served by Firebase Hosting, a Google service. Like any web server it records technical request logs, which include your IP address, for security and operation.
- Fonts. Most pages load their typeface from Google Fonts, which involves a request to Google when a page opens. The legal pages, including this one, load no third-party fonts.
- Early access. When you sign up for early access, the details you give (email, country, platform, optional child age band, consent to be contacted) are stored in our Google Workspace and used only to contact you about Jepify testing. We delete them when a family is invited, declines or asks to be removed, and in any case 12 months after the early-access programme ends. We never ask for a child’s name, email, exact date of birth or school on this website.
- Lawful basis: for hosting logs, our legitimate interest in operating and securing the site (Art. 6(1)(f)); for early-access details, your consent (Art. 6(1)(a)), which you can withdraw by writing to privacy@dynamikus.com.
4. Things Jepify does not do
- No current location feature. The currently described service does not collect a child’s geographical location. Any future location feature would need a new purpose assessment, appropriate lawful basis and device permissions as applicable, and updated notices before introduction.
- No advertising in the current service. The currently described app does not show adverts, send data to ad networks or collect advertising identifiers. Any future parent-directed free-tier advertising would require a separate product/privacy assessment and an updated notice before implementation; advertising to children is excluded from the present design.
- No third-party analytics tools. The app contains no Google Analytics or other third-party analytics tool (section 3.13).
- No sale of data.
- No messaging between family members in the currently described version.
- No automated decisions with legal or similarly significant effects. Jepify may suggest that a child could take more ownership of a responsibility; a guardian always decides.
- No payments. Jepify does not process payments in the current version. This notice is updated before any paid plan launches.
5. Who can see your family’s data
- Within the family: guardians of the family; each child sees their own responsibilities, reviews and rewards. Some guardian-only records are not visible to children. No one in the family sees child usage information or crash reports.
- The Jepify team: only authorised personnel, for operating, securing and improving the service, under access controls. Child usage information is restricted to an owner-level analytical role. No AI agent has read access to child usage information.
- Service providers: listed in section 6.
- Authorities: only where the law requires it.
6. Service providers and recipients
| Provider | Service | What for | Section |
|---|---|---|---|
| Google (Google Cloud / Firebase) | Cloud Firestore, Cloud Functions / Cloud Run, Cloud Scheduler, Cloud Logging, BigQuery | Hosting the app’s data and server logic; logs; backups; child usage information; server-side usage measurement | 3.2 to 3.5, 3.8, 3.10 to 3.14 |
| Google (Firebase) | Firebase Authentication | Guardian sign-in and the child session identity | 3.1, 3.3 |
| Google (Firebase) | Firebase Crashlytics | Crash reports | 3.9 |
| Google (Firebase), Apple | Firebase App Check with Play Integrity / DeviceCheck | App integrity | 3.7 |
| Expo | Expo Push Service | Sending notifications | 3.6 |
| Apple, Google | Apple Push Notification service, Firebase Cloud Messaging | Delivering notifications to the device | 3.6 |
| Apple, Google | Sign in with Apple, Google sign-in (optional) | Guardian sign-in | 3.1 |
| Google Workspace (Gmail, Forms, Sheets) | The support and privacy mailboxes; early-access sign-up | 3.15, 3.16 | |
| Firebase Hosting, Google Fonts | This website | 3.16 |
The app is built with Expo’s build service, which builds the app and does not receive users’ data. The app does not use over-the-air update services.
7. Where your data is processed and international transfers
- The main database (Cloud Firestore) and its backups, server functions and Jepify’s own log storage for error reports and child usage information are located in the EU, in Finland (Google Cloud region europe-north1). The scheduler that triggers daily processing runs in Belgium and holds no personal data.
- Firebase Authentication processes data only in the United States: Google runs it only from US data centres, and it cannot be moved to the EU. Expo Push Service runs on servers in the United States.
- Other services may process data outside the EU/EEA, including in the United States, unless an EU location is set for them: Firebase Crashlytics, Firebase App Check with Play Integrity and DeviceCheck, Firebase Cloud Messaging, Apple Push Notification service, Cloud Logging infrastructure logs and the Google Workspace mailboxes. What the providers state, and what is still being checked in our own configuration, is in section 13.
- Where data is transferred outside the EU/EEA, we rely on the provider’s EU-US Data Privacy Framework certification or on Standard Contractual Clauses, with supplementary measures where required. You can ask us for a copy of the relevant safeguards at the privacy address.
8. How long we keep data: summary
| Data | Retention |
|---|---|
| Guardian account | While the account exists; deleted within 24 hours after the 7-day grace period once you delete it |
| Family, child profiles, responsibilities, progress history | While the family or profile exists; deleted with the family or the child’s profile |
| Weekly reviews and reward history (outcomes, records of rewards given, corrections) | 24 months after the week ended; a week with a reward not yet recorded as given is kept until it is; earlier if the child’s profile or the family is deleted |
| Processed app commands; nickname-change records | 30 days |
| Duplicate-prevention and rate-limit records | Expire within 30 days |
| Pairing codes | Valid 5 minutes |
| Push tokens | While signed in or paired; invalid tokens removed |
| Crash reports | 90 days, as stated by Firebase, then deleted by the provider |
| Jepify error reports (essential) | 90 days |
| Child usage information (with consent) | 90 days for individual events; up to 24 months for totals with no child pseudonym |
| Child-linked server product events (with consent) | 90 days |
| Consent records | While the child profile exists, plus 3 years after withdrawal or after the profile or family is deleted (minimised) |
| Server request and infrastructure logs | 30 days by default; our own setting is being confirmed (section 13). Used only to find and fix faults (section 3.8) |
| Support emails | 24 months after the request is closed |
| Early-access sign-up details | Until the family is invited, declines or asks to be removed; at most 12 months after the programme ends |
| Backups of the main database | Taken daily, each normally kept 90 days. A backup is kept longer only where a technical limit makes it necessary, and never longer than 14 weeks (98 days), the most our database provider allows for scheduled backups. A copy restored from a backup to investigate a fault is deleted within 7 days of the restore. Data you delete can stay in backups until they expire and is then deleted automatically; if we ever restore a backup, deletions and consent withdrawals made after it are applied again before the data is used |
| Record that a deletion was carried out | 3 years, holding only a random reference, the type of deletion and its dates; no names or content |
Lawful bases for backups and deletion records. We keep backups because of our legitimate interests in keeping the service available and its data intact (Art. 6(1)(f); see also Art. 32(1)(c)). We keep the record that a deletion was carried out to comply with our obligation to demonstrate and re-apply erasure (Art. 6(1)(c) with Art. 5(2) and 17), and in minimised form for 3 years for our legitimate interest in establishing or defending legal claims (Art. 6(1)(f)).
9. Your rights
9.1 Rights under the GDPR
You have the right to access your personal data and get a copy; to rectify inaccurate data (guardians can edit most family data directly in the app); to erasure in the cases the law provides; to restrict processing in certain cases; to data portability for data you provided, where processing is based on consent or contract; to object to processing based on legitimate interests; to withdraw consent at any time, without affecting processing before the withdrawal; and to lodge a complaint with a supervisory authority (section 10).
How to exercise them: write to privacy@dynamikus.com. We answer within one month (extendable by two months for complex requests, in which case we tell you why). We may need to confirm that you are a guardian of the family before acting. Deletion can also be done as described in section 9.4; a copy of your data is provided on request (section 9.5).
Some information may no longer be linkable to a specific person after a linkage secret has been destroyed, and some genuinely anonymous statistics may fall outside the GDPR. Pseudonymised data remains personal data while re-identification remains reasonably possible. We will explain the technical and legal position when answering your request.
9.2 Children’s rights and who decides about usage information
- Children have their own rights concerning personal data about them. A guardian may help a younger child exercise those rights, taking account of the child’s maturity, safety, applicable law and the guardian’s legal authority.
- Usage information consent. While a guardian is legally entitled to give consent for the child, the guardian chooses Allow or Don’t allow. In Finland, a child aged 13 or over can give their own consent to information-society services (Data Protection Act 1050/2018, section 5). Once a child is entitled to decide for themselves, the guardian’s choice no longer controls it on its own: the child must be able to confirm, change or withdraw it, and is told how.
- Today. In the current version, the usage-information setting is changed by a guardian in the app. Jepify does not ask for or store a child’s age or date of birth.
- Early access. If a child in early access is entitled to decide for themselves, the child, or a guardian on the child’s behalf, can write to privacy@dynamikus.com to confirm, change or switch off usage information for that child. We act on such a request without asking for the child’s date of birth. A guardian can also switch it off at any time (section 9.3).
- Later versions. Before Jepify is offered to families outside early access, every child will be able to switch usage information off on their own device, and a guardian will be able to mark that the child decides about usage information themselves; this notice will be updated to explain how.
- A child can contact us directly at privacy@dynamikus.com about their own data, or ask their guardian to help.
9.3 Withdrawing consent
- Guardian: open the child’s Device access screen in Jepify, choose Change under “Usage information”, pick Don’t allow and save. It takes the same steps as allowing, and there is no penalty; the app works the same either way.
- What happens: optional usage collection stops. Buffered events are discarded. The documented child pseudonym linkage is destroyed, so previously collected raw events are no longer linkable through that mechanism; those raw events expire within 90 days. Withdrawal is not a claim of immediate physical deletion of every previously collected event.
- Consent record: the record of the choice and its history is kept as described in section 3.12.
- Child entitled to decide: see section 9.2.
- Guardian usage measurement (section 3.13) uses no consent and no device storage, so there is nothing to withdraw in the app; you may be able to object to it (section 9.1).
9.4 Deleting your account, your family or a child’s profile
- In the app. In-app deletion is an approved part of Jepify and is being built. When it is available: on Guardian Home, open Settings and choose Delete account and family or Remove [child]’s profile. The app tells you what will be deleted, and you sign in again to confirm. Deletion is scheduled 7 days later; until then you can choose Cancel deletion. After the 7 days, the data is deleted within 24 hours. The delete-account page says when this is live.
- By email, today. Write to privacy@dynamikus.com from the email address of your account (if you use Sign in with Apple or Google, tell us which). We check that the request comes from you and then delete without a grace period, within one month, and confirm in writing what was removed.
- Delete account and family deletes your account, the family and every child profile in it, with all responsibilities, history, weekly reviews and rewards. Remove a child’s profile deletes that child’s profile and everything recorded about that child; your account and other children are not affected.
- What is not deleted at once: copies in backups (normally deleted automatically within 90 days, section 8); technical logs, which can contain record references (section 3.8) but cannot be deleted one by one, and crash reports, which are not linked to your account; both expire automatically; child usage information already sent, which can no longer be connected to the child and expires within 90 days; the record of the usage-information choice, kept for 3 years as legal evidence; and a minimal record that the deletion was done (section 8).
- Individual records (one reward, one week, one note) cannot normally be selectively deleted through the product interface, so family history cannot be quietly rewritten. This is a product rule, not an exclusion of legal rights to erasure or correction. Children may contact us directly about their personal data (section 9.2).
- If you want a copy of your data, ask for it before you delete (section 9.5).
9.5 Getting a copy of your data
There is no export button in the app. Email privacy@dynamikus.com and we will send you, within one month, a machine-readable file of the data you provided or that your use created: your sign-in method and email, the family, child profiles, responsibilities and their history, notes, weekly reviews and decisions, reward agreements and outcomes, and the consent record. Child usage information (which we cannot connect to a person without the pseudonym secret), logs and crash reports are not included.
10. Complaints
If you think we have handled personal data unlawfully, please contact us first at privacy@dynamikus.com so we can try to fix it. You also have the right to lodge a complaint with a supervisory authority, in particular in the EU or EEA country where you live or work or where the alleged infringement took place. In Finland, the supervisory authority is the Office of the Data Protection Ombudsman (Tietosuojavaltuutetun toimisto), tietosuoja.fi.
11. Security
We protect data with access controls that keep each family’s data separate and enforce guardian and child roles on our servers, encryption in transit and at rest on Google Cloud, app-integrity checks, minimised logs that exclude family-written text, and short retention for technical data. Child usage information is pseudonymous and kept apart from other datasets. If a personal data breach is likely to put you or your child at risk, we tell you without undue delay and report it to the supervisory authority as the law requires.
12. Changes to this notice
We update this notice when our processing changes and show the date and version at the top. If a change widens what child usage information includes, who receives it or how long it is kept, it is not collected for a child until the person entitled to decide confirms the new version. Material changes are announced in the app and on this page.
13. Third-party services: what the providers state and what we are still checking
13.1 What the providers state
These facts come from the providers’ own documentation, checked on 7 October 2026. They describe the services in general, not yet our own project settings.
- Firebase Authentication: runs only from US data centres and processes data only in the United States. IP addresses are kept for a few weeks; other sign-in data is removed within 180 days after an account is deleted.
- Firebase Crashlytics: crash reports are kept for 90 days before deletion starts. Crashlytics runs on global Google infrastructure unless a data location is selected for it.
- Firebase App Check: integrity tokens are valid for at most 7 days; replay-protection tokens are kept for up to 30 days. It runs on global Google infrastructure unless a data location is selected.
- Firebase Cloud Messaging: installation identifiers are kept until they are deleted, then removed within 180 days. It runs on global Google infrastructure unless a data location is selected.
- Firebase Hosting (this website): IP data is kept for a few months.
- Cloud Logging: infrastructure logs are stored in a global location by default and kept for 30 days, unless they are routed to a regional log bucket.
- Expo Push Service: runs on Google Cloud in the United States. Expo relies on the EU-US Data Privacy Framework and provides a data-processing agreement on request.
- Google Workspace mailboxes: email can be stored at rest in Europe only on Workspace editions that include data regions.
- Transfers outside the EU/EEA: Google and Expo rely on the EU-US Data Privacy Framework and on Standard Contractual Clauses in their data-processing terms.
Sources: Firebase privacy and security, Google Cloud log regionalisation, Google Workspace data regions, Expo privacy.
13.2 What we are still checking in our own configuration
These items will be filled in here before Jepify is offered outside early access. Nothing in this list changes what Jepify collects.
- Whether an EU data location is set for Crashlytics, App Check, Cloud Messaging and Hosting in our Firebase project.
- Whether our Cloud Logging infrastructure logs are routed to an EU log bucket, and their retention.
- The data region of our Google Workspace mailboxes.
- Exactly which Apple or Google profile fields Firebase Authentication stores for Apple or Google sign-in, and the provider’s role.
- Expo’s legal entity and our signed data-processing agreement with Expo; Apple push delivery location.
- Whether inactive guardian accounts are deleted after a period.
- Retention of revoked access grants, device records and used pairing-code records.
- The final in-app deletion screens and button names.