Privacy policy of the app
This is a translation for your convenience. Only the German version is legally binding.
New compared with version datenschutz-2026-12:
- Notice of a different time (sections 2, 4, 5 and 6). If a handover on the same day takes place at a different time than the plan says, one parent can tell the other, with the time and, if desired, a fixed reason. The plan does not change as a result. The notice is deleted at the end of the day.
- Starting alone (sections 2 and 4). A parent can enter and use the plan before the other parent has joined.
- Payment via the App Store (sections 2, 3, 4, 5, 6 and 8). Whoever unlocks the family buys a subscription from Apple. Apple is the merchant; we learn that a family is unlocked and until when.
- The silent nudge for the calendar and the grace period when signing in (sections 2, 5 and 6).
- Help with wording and the parents' message channel have been removed. Neither exists in the app any longer, and sections 2, 5 and 8 no longer mention them.
The reference to the children's text in section 7 still names version kinderhinweis-2026-16.
This policy describes what the app does with your data. It does not describe an intention, but what has been built: where something is not stored, there is also no technical provision for storing it.
1. Controller
Datargo GmbH
Omniturm Frankfurt
Neue Mainzer Str. 52-58
60311 Frankfurt am Main
Represented by Andreas Mallek
Local Court (Amtsgericht) Friedberg (Hessen), HRB 9742
Email: [email protected]
No data protection officer has been appointed; the requirements of Section 38 BDSG (German Federal Data Protection Act) are not met. Data protection enquiries go to the address above.
2. What is processed, for what purpose and on what legal basis
| Data | Purpose | Legal basis |
|---|---|---|
| Name, email address, login credentials | Account and sign-in | Art. 6(1)(b) GDPR (contract) |
| Care plan: rhythm, handover days, times, handover locations, holiday periods | The purpose of the app: where is the child, when, with whom | Art. 6(1)(b) GDPR |
| Deviations from the plan with period and response deadline | Agreeing on an individual case | Art. 6(1)(b) GDPR |
| Notice of a different time: the child, the planned handover, the time given for the same day, an optional reason from a fixed selection (on the way, work, appointment, other reason), who sent it and when. No free text | Telling the other household that a handover today takes place at a different time, without changing the plan | Art. 6(1)(b) GDPR |
| Starting alone: a plan that one parent entered before the other joined, marked as entered and not yet agreed | Using the app before the other parent agrees | Art. 6(1)(b) GDPR |
| Subscription via the App Store: an account identifier that our server issues per account and that Apple records in the purchase; for the purchase, the identifier of the original transaction at Apple, the product (monthly or yearly), end of term, status (active, grace period, billing problem, expired, revoked), environment (test or production) and the time of the last message from Apple; the unlocked family and until when; records of messages received from Apple. No payment data | Unlocking the family while the subscription runs, and reconciling this with Apple | Art. 6(1)(b) GDPR; for retention after the end of the term, Art. 6(1)(f) GDPR (clarifying refunds and queries); insofar as tax or commercial law obligations exist, Art. 6(1)(c) GDPR |
| Sign-in: a device's session with a refresh key that changes with every renewal; for 60 seconds afterwards the previous key remains recognisable as a check value | Staying signed in without two simultaneous renewals signing the device out | Art. 6(1)(b) GDPR |
| A child's appointments: title, start, end, location, whether both must agree, by when agreement is required and whether it has been given, plus who entered it | Doctor, parents' evening, school report: what is in a child's day, for both households | Art. 6(1)(b) GDPR; a title can be health data, see the paragraph on appointments below |
| Calendar subscription: a secret link per parent and child, which child and which family it applies to, when it was created, and whether titles and locations are included | Your own care times and the child's appointments in a calendar of your choice | Art. 6(1)(b) GDPR |
| Calendar on the device: which entries the app has written to which calendar (on the device, not on our servers), and an appointment you take over from one of your calendars: title, start, end, location | Seeing the plan where your everyday life already is, without entering it twice | Art. 6(1)(b) GDPR |
| The child's first name and date of birth | The plan relates to a specific child | Art. 6(1)(b) GDPR, for accounts under 16 additionally Art. 8(1) GDPR |
| Persons authorised to pick up: name, relationship, scope | Answering the question at the school door | Art. 6(1)(b) GDPR |
| Tasks and whether they are done | Everyday life between two households | Art. 6(1)(b) GDPR |
| Lists for a day: title, items, the child and the day they apply to, and who created them; templates for them, held by the parent who created them. Not what has been ticked off | What is needed on a given day, readable for both households and the child | Art. 6(1)(b) GDPR, for accounts under 16 additionally Art. 8(1) GDPR, and insofar as health data of the child appears in an item, Art. 9(2)(c) GDPR as with the free text for a care assignment |
| Documents about a child: the file (PDF or photo), title, category (health, school, ID documents, care), the children it concerns, who filed it and when; plus when a parent consented to the processing | Paperwork about the children in one place, for both parents | Art. 6(1)(b) GDPR, and because such documents often contain health data, additionally Art. 9(2)(a) GDPR (explicit consent, see below) |
| Notifications on the phone: the device token that iOS issues for this, the device language, your switches per category (including for the notice of a different time), and a delivery log of category, day and result. Plus the silent nudge: a delivery without a sentence and without content that wakes the app in the background so it can reconcile the calendar on the device; nothing of it is stored | Letting you know when something is waiting for you, without content on the lock screen, and keeping the calendar on the device up to date | Art. 6(1)(b) GDPR |
| Free text for a care assignment (e.g. notes for a babysitter) | Handover to a third person | Art. 6(1)(b) GDPR, and insofar as health data of the child appears in it, additionally Art. 9(2)(c) GDPR |
| Messages between a child account and one parent (private line) | A child should be able to turn to one parent alone, without going through a service outside this app | Art. 6(1)(b) GDPR, for accounts under 16 additionally Art. 8(1) GDPR |
| Health note about a child: a sentence of at most 280 characters, written by a parent, plus who wrote it and when | Handover to the person looking after the child: what they need to know in an emergency (allergy, auto-injector, medication) | Art. 6(1)(b) GDPR and Art. 9(2)(c) GDPR (vital interests of the child) |
| A child's objection to a sentence about their body: the time and the child account that pressed it, on the health note as on the free text of an assignment. No free text, no reason | A child should be able to object to a sentence about their own body without having to talk about it | Art. 6(1)(c) GDPR in conjunction with Art. 16 GDPR, and for the sentence itself the same basis as in the row above |
It must be said what the health note does NOT rest on. The app does not obtain separate explicit consent under Art. 9(2)(a) GDPR for it, and that would also be the wrong basis here: a child under 16 cannot give it themselves, and a basis that may have been withdrawn in an emergency is unsuitable for information that a carer needs in exactly that emergency. It is therefore based on Art. 9(2)(c) GDPR. What keeps it narrow in return is laid down in the design of the software: one line per child, at most 280 characters, no previous version, and the children's text explains to the child in their own language that this sentence exists, who reads it and that they can object to it.
Special categories under Art. 9 GDPR arise in three places, and only in these three. The first is the health note above: the field exists for it, and the app does not analyse it. The second are the free text fields (such as a note for a babysitter or an item on a list). The third are the documents about a child; for them the paragraph on documents further below applies.
The free text fields are not intended for such data, but the data ends up in them anyway. "EpiPen in the outer pocket" is health data, no matter which field someone types it into, and the software can neither prevent nor detect this. A controller who knows this and does not name the legal permission for it is processing without one; the Regulation does not provide for shifting that responsibility onto the user (Art. 24, Art. 25(2) GDPR). **These fields are therefore based on the same legal basis as the health note, Art. 9(2)(c) GDPR**, and subject to the same time window (section 4).
What naming a legal basis does not improve: the intended field remains the health note, because there is exactly one line of it per child, because it can carry an end date and because both parents and the child can read it at any time. A sentence in the free text of an assignment has none of this: it applies without an end, it does not replace the note but stands beside it, and it reaches the persons who have access in the relevant time window. It carries a child's objection just like the note itself (section 4).
It must be said what the documents rest on. A vaccination record or a doctor's letter is not an emergency, and the basis of the health note (vital interests) does not cover it. Moreover, the app cannot tell what a file contains. Before a parent files their first document, the app therefore asks them explicitly whether they consent to documents about their children being stored here, even if they contain health data (Art. 9(2)(a) GDPR), and records when they agreed. They can withdraw consent in the app at any time. The documents they have filed are then deleted; the app first offers to save them on their own device.
It must be said who knows what about payment. Apple is the merchant: Apple concludes the purchase contract with you, collects the price, renews the subscription and refunds it. We do not see your payment data or your Apple ID. We learn from Apple which subscription belongs to which account identifier, until when it runs and whether it has been refunded or revoked. One subscription unlocks exactly one family. **The app does not show any other member who in the family pays**: the assignment of a purchase to an account is visible only to the person the purchase belongs to, including in the access report (section 8).
It must be said what the notice of a different time is not. It is not an agreement: the plan remains, nobody replies, and it is not recorded whether or when the other parent has read it. A new notice for the same handover replaces the old one, and there is no count of how often someone has sent one.
It must be said what leaves the app via appointments and calendars, and where it goes. Appointment titles and locations go into a subscription and into an existing calendar only after an explicit choice; only a dedicated "Claro" calendar that the app creates carries them by default. A child account does not put its plan into any calendar. In the app, appointments are shown to both parents and, insofar as they apply, to the child (section 4). They reach a calendar outside the app in two ways, and a parent chooses both themselves:
- The calendar subscription is a secret link. Whoever has it can read without signing in: your own care times, the handovers at their edges and the child's appointments, up to 90 days ahead. It reaches back 30 days, and a stay that began earlier appears with its actual start, even if that lies further back; an appointment appears in it until it is deleted two days after its end. It never contains the other household's times, the name of a parent or an appointment that is still to be decided. Without an explicit choice it contains the neutral version: "Noah is here" and "Appointment for Noah", without appointment titles and without location. The link is stored in the settings of your calendar program and in the log of every point through which it is retrieved; whoever creates the subscription anew renders the old link unusable.
- The calendar on the device. The app writes the same entries to a calendar on your iPhone. For this it needs full access from iOS, and iOS thereby opens **all calendars on this device**, including shared and work calendars: iOS does not offer a narrower permission that allows an app to change or delete its own entries. On every reconciliation, the app reads the calendar it writes to in order to find its own entries there, and when taking over appointments, the calendars you select for that. The only thing from your calendars that leaves the phone is an appointment you explicitly take over: it becomes an appointment in the app like any other, and its title is then visible to the other household. If the app creates its own "Claro" calendar for its entries, it contains titles and locations; in a calendar that already exists, the neutral version appears first, and titles and locations only after an explicit choice.
Appointments may come from the other parent. Whoever enters an appointment writes its title and location, and in the full version both appear word for word in your calendar. If you choose the full version for a calendar that others can also read, such as your employer's, they also read what the other parent wrote. The neutral version carries no word that anyone typed.
A title can be health data. "Paediatrician" or "Vaccination" says something about a child's health, and the app can neither prevent nor detect this. The basis on which the free text for a care assignment rests (Art. 9(2)(c) GDPR) depends on its time window, and an appointment has none: both parents and the child read it until it is deleted two days after its end. We therefore do not name this basis for appointments. What the app does is keep the title narrow: it does not analyse it, shows it only within the family, and outside the app it appears only in the dedicated "Claro" calendar or wherever you explicitly choose the full version. Only write in a title what the other household needs for planning; what protects a child in an emergency belongs in the health note.
3. What is explicitly NOT processed
These are not promises for the future but properties of the software:
- No location, no tracking of whereabouts. There is no field for it.
- No record of who failed to keep to what. A rejected or expired proposal is deleted, not marked as rejected. The data model has no "rejected" state and no version history of a plan.
- No read status, no counters, no presence indicator.
- No tracking, no analytics tools, no advertising identifiers. The app does not include any third-party libraries for these purposes.
- No record of whether a child has called the anonymous counselling service.
- No tick marks on the server. What someone ticks off on a list stays on their device. No parent sees what has been ticked off in the other household or by the child.
- No recycle bin for documents. A deleted document is deleted, also for the other parent, and it is not recorded anywhere as deleted.
- No payment data. Card number, bank details and billing address stay with Apple.
- No history of notices. How often a parent has given notice of a different time is not recorded anywhere.
- No capture location in photos. Before storing a photo, the server removes the embedded metadata, including capture location, time and device.
4. Who sees which data
Within a family, the role decides, not curiosity:
- Both parents see the plan, the deviations and the pick-up list.
- A child with their own account sees where they are and when they change households, and explicitly not what the adults are currently negotiating.
- Grandparents and carers see only what they need for their own assignment, not the family's plan.
The notice of a different time is seen by the other parent in the plan, as a notification on the phone if they have switched it on, and as a moved handover entry in their calendar. A child, grandparents and carers do not receive it. After the day, the calendar shows only the time at which the handover entry stood, without who gave the notice and without a reason.
A plan that one parent entered alone is initially seen only by that parent, in the app and in their calendar. The other parent sees it as soon as they join, as entered and not yet agreed.
Whether a family is unlocked is seen by both parents. **Who bought the subscription is seen only by the person who bought it.**
The health note about a child can be read by both parents and by the child themselves, at any time and without a reason; only a parent can write and delete it. A carer reads it **only within the time window of their own care assignment**, and this window begins two hours before a confirmed assignment and ends one hour after it. Outside it, the note is not delivered to them. The same window applies to the free text for a care assignment and to the emergency card, and it also applies to a parent: what is attached to an assignment, they read during the period in which the children are with them according to the plan, not beyond.
One exception, and it is the reason this processing exists at all. If several sentences about the body of the same child apply on one day, and they do not say the same thing, then the person currently looking after the child receives, within their own window, all of these sentences, including the one from an assignment that was earlier that day and belonged to another person. Without this exception, they would read a sentence that the software knows is contradicted by a second one, and would have neither the second one nor the information that it exists. That is the case in which a carer looks for emergency medication in the wrong place, and this processing is directed against it (Art. 9(2)(c) GDPR).
Its limits are narrow, and all four are enforced on the server:
- Only where sentences contradict each other. If only one sentence about this child applies on a given day, there is nothing to compare, and the exception does not apply.
- Only within the reader's own window. It begins two hours before their own assignment and ends one hour after it. Outside it they receive nothing, not even their own sentence.
- Only about the child they look after. A sentence about a child who does not appear in their assignment does not reach them. A text is indivisible: if it also mentions a sibling, it is included, because it cannot be split without losing its meaning.
- Without author. As soon as several sentences about the same body apply, the author is no longer delivered for any of them, not even for the health note itself. What remains is the day. Otherwise, from two named adults and a reported contradiction, one could infer to whom the error is attributed, and this software does not decide that.
A child's objection appears where the note it is directed against appears: with both parents and, within the same window as the note, with the carer. It names the child and nothing else.
Documents are seen by both parents, every document, regardless of who filed it; there is no private compartment. A child, grandparents and carers do not see any documents, not even within the time window of a care assignment. A document can be changed and deleted only by the person who filed it; the other parent can keep their own copy. Titles and content are stored encrypted, and the master key without which they cannot be read is not stored in the database.
Lists for a day are seen by both parents and by the child they apply to, provided the child's account carries the consent whose text explains the lists. Templates are seen only by the person who created them.
A child's appointments (section 2) are seen by both parents, regardless of who entered them, and without the name of the person who entered them. A child sees the appointments that apply, and none that the parents are still deciding on. Grandparents and carers do not see them.
Putting a plan into a calendar outside the app is possible only for a parent, and only for their own care times including handovers and the child's appointments: a child account, grandparents and carers can neither create a subscription nor use the calendar on the device.
These limits are enforced on the server, not in the app: what someone may not see is not delivered, not merely hidden.
5. Recipients
There is no processor that sees your content.
- Servers: The data is stored on servers of Datargo GmbH in the European Union. There is a transfer to a third country in three places, and all of them are listed below: notifications via Apple, the reconciliation of a subscription with Apple, and what a calendar retrieves that you yourself keep there.
- Notifications via Apple. A notification to your iPhone is delivered by the Apple Push Notification service of Apple Inc.; there is no other way to reach an iPhone. For this, Apple receives your phone's device token, the category, the sentence of the notification and a link into the app that carries the identifiers of the family and the child as numbers. No sentence names a child, a parent, a day or any content, and no number appears on the icon. A silent nudge for the calendar carries only the device token and no sentence, no link and no category. Apple also processes this data in the USA; according to its own statements, Apple safeguards such transfers with the Standard Contractual Clauses of the EU Commission. You choose which categories reach you in the app, and iOS lets you switch notifications off entirely.
- Apple as merchant and the App Store Server API. You buy a subscription from Apple (for customers in the European Union, to our understanding, Apple Distribution International Ltd., Ireland). Apple sends our server signed messages about purchase, renewal, refund and expiry. For reconciliation, our server queries Apple's App Store Server API for the status of a subscription and sends only the identifier of the original transaction for this, nothing else. The purchase itself is governed by Apple's terms and privacy policy. Apple also processes data in the USA; according to its own statements, Apple safeguards such transfers with the Standard Contractual Clauses of the EU Commission.
- Sheets you pass on yourselves (such as the pick-up list for the school) leave the app through your own action. What happens to them is your decision.
- Calendars you connect yourselves. Where the subscription or the calendar on the device carries the entries is your decision: iCloud, Google, your employer's Exchange account or a calendar only on the iPhone. The provider of that calendar receives the entries, and with a work calendar your employer can read them, a deputy can see them and its retention can keep them. If the provider is located outside the European Union, for example in the USA, the entries reach a third country: with the subscription, because its service retrieves the link from our server; with the calendar on the device, because the iPhone synchronises the calendar with it. Both happen because you keep the calendar there, and the data is then also subject to that provider's terms. We do not pass anything on to any calendar provider on our own initiative.
6. Storage period
- A proposal for a deviation is deleted as soon as the response deadline has expired, without a trace.
- An accepted deviation leaves the coordination two days after its end. As a period and side it then remains for 45 days after its end, without who proposed it, without its response deadline and without the time at which it was accepted: otherwise the plan and calendar would show the past weeks as if it had never existed. After that, this too is deleted.
- A notice of a different time is deleted at the end of the day on which the handover takes place, at the latest 25 hours after the planned handover. A new notice for the same handover replaces it immediately. What then remains in the calendar is only the time at which the past handover entry stood, without who gave the notice, without a reason and without the time of sending; this too is deleted 31 days after the handover. The delivery of this notice stays in the delivery log for one hour.
- A superseded care plan is deleted when it is replaced. There is no previous version.
- Account and plan data remain as long as the account exists.
- A health note about a child remains until a parent replaces or deletes it. There is one line per child: whoever replaces it overwrites it, and no previous version is created. If a note carries a day until which it applies, it disappears when that day ends, without anyone having to remember. A child's objection belongs to the version it is directed against and falls with it: if a parent rewrites the note, the objection is gone.
- Messages on the private line are deleted at the latest 48 hours after being written. The deadline is a constraint in the database schema; longer storage cannot be entered there; a service deletes whatever has expired every quarter of an hour. A reply inherits the deadline of the message it replies to and disappears with it. The child can delete their line themselves at any time before then.
- A list for a day is deleted after that day ends. If someone opens the app, this happens then; otherwise a service removes it as soon as the day is over in every time zone, in Germany at the latest in the afternoon of the following day. Templates remain until their parent deletes them.
- A document remains until the parent who filed it deletes it, withdraws their consent or has their account deleted.
- An appointment is deleted two days after its end. Whoever cancels it earlier deletes it immediately; if it applied, the other parent learns that an appointment was cancelled, and nothing else. An open appointment that does not come about leaves the person who asked, for seven days, a conclusion of their question that does not say whether it was declined or nobody replied.
- A calendar subscription remains until you revoke it, create it anew or have your account deleted. If your membership in the family ends, the link delivers an empty calendar.
- Notifications: The delivery log is deleted after 30 days, a device token 30 days after its revocation or 180 days after the device's last contact, the switches together with the account.
- Entries in the calendar on the device are deleted by the app when you switch off synchronisation, sign out, have your account deleted or no longer have access to a child. It deletes stays and handovers 30 days after their end, an appointment together with its deletion two days after its end. Between two reconciliations an entry may be out of date. What the app cannot reach: copies that your calendar provider or your employer has already made, and entries after an uninstallation of the app or after you have revoked its calendar access. They remain in your calendar until you delete them yourselves.
- Purchase data remains while the subscription runs and is deleted 90 days after the end of the term, a refunded or revoked subscription 90 days after the revocation. The family's unlock goes with it. Records of messages received from Apple are deleted after 30 days. The account identifier for purchases remains as long as the account exists.
- Sign-in: The previous refresh key ceases to be valid 60 seconds after it has been replaced; the session ends when signing out or when the account is deleted.
- The silent nudge is not stored.
- After a deletion see section 8.
7. Child accounts
An account of their own for a child under 16 requires the consent of a person with parental responsibility (Art. 8(1) GDPR). Without it, the account has no function.
Before use, the child receives a text of their own in their own language; it is available at any time under the identifier kinderhinweis-2026-16, including without signing in. Older versions remain available under their own identifier, so that it can be looked up what a consent given back then referred to.
The child can switch off their own view themselves at any time, without giving a reason, and only the child can switch it back on. The parents learn that it is off, not why and not how often. Switching it back on deletes this record completely.
The private line. A child with their own account can write to one parent alone. The other parent learns nothing about this, not even that something was written, and not as a number either. These messages do not appear in any plan, do not create any process and, for the reason of the 48-hour deadline stated above, do not appear in the access report under Art. 15 GDPR either; the access report says so explicitly. There is no read receipt, no search across older messages and no way to forward them from within the app. What the recipient does with a message they have received lies beyond what software can prevent; the children's text tells the child this in their own language.
No calendar. A child account can neither create a calendar subscription nor write its plan to a calendar on the device: no text that a child receives before use explains a calendar. A subscription that was created for a child account before this version delivers an empty calendar.
Any person with parental responsibility can withdraw consent at any time; the account then immediately has no function.
8. Your rights
Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21).
You can trigger access and portability directly in the app, under Settings. You receive a machine-readable file with everything stored for your account. The documents you have filed are listed in it as a directory; you save the files themselves in the app under Settings, Documents, each individually or all at once.
You can also trigger erasure in the app. Two things need to be said about it, and said beforehand:
- What concerns only you is deleted. Your open proposals, your calendar retrievals, your invitations, your entries on the pick-up list that apply to you alone. Also your templates for lists and the documents you have filed; the other parent can keep their own copy beforehand. Beforehand, the app deletes the entries it has written to the calendar on this device; it cannot reach copies at your calendar provider (section 6).
- What also concerns others remains. A care plan is an agreement between two households and concerns a child; deleting it unilaterally would interfere with the rights of others (Art. 17(3)(e) GDPR). The same applies to persons authorised to pick up who were entered jointly.
A subscription does not end when the account is deleted. You can cancel it only with Apple, in the settings of your Apple account. After the deletion, the purchase remains stored without being assigned to a person until the end of its retention period (section 6), and the family remains unlocked until the end of the paid term.
For complete deletion of your account, write to [email protected]. We respond within the period set out in Art. 12(3) GDPR.
Right to lodge a complaint: You can lodge a complaint with a supervisory authority; the authority responsible for us is the Hessian Commissioner for Data Protection and Freedom of Information (Hessischer Beauftragter für Datenschutz und Informationsfreiheit), Postfach 3163, 65021 Wiesbaden.
9. Changes
This policy carries an identifier. If something material changes, a new version with a new identifier is created; the old one remains available under its identifier, so that it can be traced what applied at the time a consent was given.