This Privacy Policy explains how KODOLAB S.R.L. ("we", "us"), a company registered in Romania (registration no. 53158991, registered office Str George Topirceanu 38 A, Otopeni, Ilfov, Romania), collects and uses personal data in the BuzzChores mobile application (the "App").
We are the data controller for this data. You can reach us at office@kodolab.dev.
The App is not currently offered to users in the United Kingdom. If we extend availability there, we will update this policy to name a UK GDPR representative as required by law.
1. Our approach in short
2. What we collect
An email address is required to create an account — without it, you cannot use the App. Everything else below is provided voluntarily as you use the App's features.
a) Account data
- Email address — to create your account, sign you in, and send account emails.
- Password — stored only as a secure cryptographic hash; we never see it in readable form.
- Account creation and sign-in timestamps.
b) Family and profile data (entered by you)
- Family name.
- Member profiles: a name or nickname, a role (parent or child), and a colour/emoji avatar.
- Invite codes used to let a family member sign in on their own device.
c) Chore data (entered by you)
- Chore titles, optional notes, checklists, and categories.
- Due dates/times, repeat settings, reminder settings.
- Assignments, reward points, completion records (who completed what and when) and parent approvals.
d) Device data
- Notification permission and reminders scheduled locally on your device.
- If you enable push notifications, a push token that identifies your device to the notification service (it does not identify you personally).
e) Subscription data
- Whether your family is on the free trial or a paid plan, which plan, and the relevant start, renewal and expiry dates.
- A store transaction / subscription identifier and your app account identifier, used to match a purchase to your family and keep access in sync.
- We do not receive or store payment card details — Apple, Google and our subscription processor (see section 5) handle payment; we only see that a subscription is active.
f) What we do NOT collect
- No location data, contacts, photos, or microphone/camera access.
- No advertising identifiers, ad networks, or third-party tracking analytics.
- No payment card, bank or billing-address details.
3. Children's data
BuzzChores is designed to be set up and managed by parents or guardians — a child never creates their own account independently. Child profiles are created by an adult and normally contain only a first name or nickname and a colour/emoji — no email, no birthdate, no contact details.
A parent may optionally invite an older child to sign in on their own device, which requires an email address and password for that child. To do this, the parent must already be signed in to their own adult account and actively choose to create that login — a child cannot request or create it themselves.
The minimum age at which someone can consent to their own data processing without a parent varies by law: in the United States (COPPA) it is 13; under the GDPR, each EU/EEA member state sets its own threshold between 13 and 16 — for example, Romania sets it at 16. We do not check a child's age or identity, so we treat every child profile and every invited child login the same way, regardless of age or country: as requiring the parent's confirmed consent described above.
We do not knowingly collect personal data directly from a child without a parent's involvement. If you believe a child's data was provided without proper consent, contact us at office@kodolab.dev and we will delete it.
4. Why we process your data (legal bases)
- Performance of a contract — to provide the App's core features (accounts, chores, reminders).
- Legitimate interests — to keep the service secure, prevent abuse, and fix problems.
- Consent — for device notifications (you can withdraw this anytime in your device settings).
- Legal obligation — where we must keep records (e.g. accounting for paid subscriptions).
We do not carry out any automated decision-making or profiling that produces legal or similarly significant effects on you.
5. Who processes data on our behalf
We use a small number of service providers ("processors"), bound by contract to protect your data:
- Supabase — database, authentication and hosting (EU region).
- Resend — sending account emails such as confirmations, invites and password resets (EU region).
- Apple / Google — app distribution and payment processing for subscriptions.
- RevenueCat — managing subscription status on our behalf. It receives your app account identifier, purchase receipts and basic device/platform information from the app stores; it does not receive payment card data.
- Expo — delivery of push notifications, if you enable them.
We do not sell or rent personal data to anyone.
6. International transfers
Supabase and Resend process data in the EU region, so no international transfer occurs for the data they handle.
RevenueCat, Apple, Google, and Expo are US-based, so data they handle is transferred outside the EEA. The safeguard in place depends on the processor:
- RevenueCat transfers data under the European Commission's Standard Contractual Clauses.
- Apple and Google participate in transfer mechanisms including the EU-US Data Privacy Framework and/or Standard Contractual Clauses for their respective services.
- Expo states it complies with the EU-US Data Privacy Framework and GDPR.
Because a processor's certification status can change, you can check any US company's current EU-US Data Privacy Framework status at dataprivacyframework.gov/list.
7. How long we keep data
- Account and family data: for as long as your account exists.
- Chore and completion history: until you delete it or delete your account.
- After account deletion: erased or anonymised without undue delay, except where law requires retention.
8. Your rights
Under the GDPR you have the right to access, correct, delete, restrict, or object to processing of your data, and the right to data portability. To exercise any right, email office@kodolab.dev.
You may also lodge a complaint with the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or your local EU authority.
9. Security and governance
Data is transmitted over encrypted connections (HTTPS) and stored with access controls that isolate each family's data from every other family. Passwords are stored only as hashes. No system is perfectly secure, but we take reasonable technical and organisational measures to protect your information. If a breach affecting your rights occurs, we will notify you and the relevant supervisory authority as required by law.
KODOLAB has assessed that, given the App's current scale and the categories of data it processes, a Data Protection Officer is not required under Article 37 GDPR, and a formal Data Protection Impact Assessment is not currently required under Article 35 GDPR. We will revisit both assessments as the App grows or if the nature of our processing changes.
10. Changes to this policy
We may update this policy as the App evolves. We will update the "Last updated" date above and, for significant changes, notify you in the App or by email.
11. Contact
KODOLAB S.R.L.
Str George Topirceanu 38 A, Otopeni, Ilfov, Romania
Email: office@kodolab.dev