PoppApp Privacy Policy
Last updated: 28 August 2026
Version: 1.0
Applies to: the PoppApp mobile application for iOS and Android (bundle identifier com.poppapp.app)
This is a translation. The Italian version is the authoritative text.
1. Who processes your data
The data controller is:
Andrea Verdecchia Via Riva di Reno 45, 40122 Bologna (BO) Italy Email: info@ollyzen.com
Write to that address with any question about this policy and to exercise the rights described in section 12. No Data Protection Officer has been appointed, because the processing does not fall within the cases where Article 37 GDPR makes one mandatory.
2. In short
PoppApp works in two substantially different ways.
| PoppApp free | PoppApp Premium | |
|---|---|---|
| Account | none | required (Apple or Google) |
| Where your data lives | on your phone only | on your phone and on our cloud servers |
| What we receive | nothing | the data you record, your email address, your user identifier |
| Usage analytics, advertising | none | none |
| Crash reporting | on, can be turned off | on, can be turned off |
| Advertising and profiling | none | none |
| Sharing with the other parent | not available | available, if you turn it on |
If you use PoppApp without subscribing and without signing in, no data about you or your child ever leaves the device. There is one exception, and we would rather state it here than bury it ten sections down: when the app closes on its own because of a fault, we receive a technical report of that failure. It contains neither your child's data nor who you are; section 3.4 says exactly what it does contain, and you can turn it off in Settings.
PoppApp contains no analytics tools, no advertising, no third-party cookies and no ad-tracking technology. That is true of both the free and the paid version. We do not sell or otherwise transfer data to anyone, for any purpose.
3. What data is processed
3.1 Data about you, the parent
Processed only if you activate a Premium subscription and sign in:
| Data | Source | Why |
|---|---|---|
| Email address | Sign in with Apple or Google | to identify your account and link it to your cloud data |
| Display name, if the provider supplies one | Apple or Google | account identification |
| User identifier (Firebase UID) | generated at first sign-in | to link your data and your subscription |
| App-generated device identifier | generated locally | to make two-parent synchronisation work |
| Subscription status (active, expired, plan) | Apple, Google, RevenueCat | to check your entitlement to Premium features |
| Date and time you last used the family group | app | to expire abandoned family groups |
If you use Sign in with Apple you may choose to hide your real email address. In that case we only receive the anonymous relay address Apple provides, which is fine.
3.2 Data about your child
This is what you type into the app. It stays on the device only on the free version, and is additionally stored on our cloud servers if you are subscribed and signed in.
- Profile: name or nickname, date of birth, sex, birth weight, the colour you picked to identify them in the interface.
- Feeding: start and end time of each feed, side used, duration.
- Nappy changes: time, type (wet, soiled or both), any free-text note you write.
- Medication: medicine name, dose, scheduled and actual administration times.
- Growth: weight and length recorded over time, with measurement dates.
- App preferences: units, light/dark theme, active reminders.
This is health data within the meaning of Article 4(15) GDPR, and it belongs to the special categories of personal data under Article 9. We treat it with the care that qualification demands, and we are explicit about it in section 4.
3.3 What we never collect
For the avoidance of doubt, PoppApp never collects, in any mode. The only thing that leaves the device on the free version too is the crash report described in 3.4, and it contains none of the following:
- your location, not even approximate;
- your contacts, calendar, photos or device files;
- advertising identifiers (IDFA on iOS, AAID on Android);
- usage statistics, in-app navigation events, time spent on screens;
- IP addresses retained by us for analytics purposes;
- biometric data: the fingerprint or face used to unlock the app is verified by the operating system and never leaves the device; we only receive a "success" or "failure" answer;
- images or video: the camera activates only when you scan the family-sharing QR code, and the image is analysed on the spot, on the device, without being stored or transmitted.
3.4 Diagnostic data: crash reports
When the app closes on its own because of a programming fault, we receive a technical report of that failure. It serves one purpose: noticing it and fixing it. Without it, the only way we would learn that PoppApp breaks on your phone is you writing to tell us.
What the report contains:
| Data | Why |
|---|---|
| The point in the program where the error occurred (stack trace) | it is the information that makes a fix possible |
| Device model, operating system version, language | the same fault often affects only one model or one version |
| PoppApp version, and whether the app was in the foreground | telling a new fault apart from one already fixed |
| Memory and storage available at the moment of the failure | many unexpected closures are out-of-memory conditions, not code faults |
| A technical identifier generated by the library, not linked to your account | grouping several reports from the same device |
What it never contains: your child's name, date of birth or any other data about them; feeds, changes, medicines, weight, length; your email address; your Firebase user identifier; the content of the notes you write. The app is written so that none of these values is ever attached to a report, and it does not transmit who you are to this supplier.
This applies on the free version too. It is the only case in which the free version sends anything off the device, and it is deliberate: the faults that break the app mostly hit people without an account, and staying blind precisely there would leave them standing.
You can turn it off, at any time and without losing any feature: Settings → Legal → Crash reporting. From that moment nothing further reaches us, including any reports still waiting to be sent from your device.
The supplier is Google's Firebase Crashlytics (section 6). Reports are kept for 90 days, after which Crashlytics deletes them automatically.
4. Legal bases
| Processing | Legal basis |
|---|---|
| Letting you use the app, managing your account, providing the subscription | Art. 6(1)(b) GDPR — performance of a contract |
| Storing, syncing and sharing your child's health data in the cloud | Art. 9(2)(a) GDPR — your explicit consent |
| Receiving crash reports in order to fix faults in the app (section 3.4) | Art. 6(1)(f) GDPR — our legitimate interest in keeping the app working. It involves no health data and no identifiers, and you can object by turning it off in Settings |
| Complying with tax and accounting obligations on purchases | Art. 6(1)(c) GDPR — legal obligation |
| Defending ourselves in a dispute | Art. 6(1)(f) GDPR — legitimate interest |
The second row deserves a plain explanation, because it is the heart of this policy. Article 9 GDPR prohibits in principle the processing of health data, and "performance of a contract" is not among the permitted exceptions. Storing your child's health data in the cloud therefore requires your explicit consent, given separately and specifically.
You give that consent when you activate a Premium subscription and sign in, after the app has explained that from that moment data will be uploaded to our servers. You may withdraw it at any time by signing out in the settings: from that instant the app returns to working entirely locally and no new data is uploaded. Withdrawal does not by itself erase what is already in the cloud; to erase that, use the account deletion described in section 12. Withdrawal does not affect the lawfulness of processing carried out beforehand.
If you do not give this consent you may keep using PoppApp free of charge, forever, with all recording features. You lose only backup, multi-device sync and sharing with the other parent.
5. Your role regarding your child's data
Your child is a minor who, for obvious reasons of age, cannot exercise their own rights. It is you, exercising parental responsibility, who decides what data to enter into the app and whether to enable cloud storage.
By entering a minor's data into PoppApp you confirm that you are entitled to do so. Where parental responsibility is shared with another person, it is for you to make sure that the other parent or guardian agrees, particularly before inviting them or anyone else into the family group. We have no way of verifying this and we do not verify it.
We remain the controller of the data that reaches our servers; you, however, choose what to enter and who to share it with.
6. Who else processes this data on our behalf
We rely on external suppliers, appointed as processors under Article 28 GDPR. They process data only on our instructions and may not use it for their own purposes. All of them concern the Premium version, except Crashlytics, which also operates on the free version unless you have turned it off.
| Supplier | What it does | What it receives |
|---|---|---|
Google Ireland Limited — Firebase Authentication, Cloud Firestore (project papp-3494b) |
authentication and cloud storage | email address, user identifier, and all the data about your child listed in 3.2 |
| Apple Inc. — Sign in with Apple | authentication | the sign-in outcome; Apple knows you used PoppApp |
| Google LLC — Sign in with Google | authentication | the sign-in outcome; Google knows you used PoppApp |
| Google Ireland Limited — Firebase Crashlytics | receiving crash reports | what is listed in section 3.4: error stack, device model, app version. No data about your child, none of your identifiers. It is the only supplier active on the free version too, unless you turn it off |
| RevenueCat, Inc. | subscription status verification | only your Firebase user identifier and transaction data. Your email address is never sent to RevenueCat, and no data about your child passes through this supplier |
| Apple Inc. and Google LLC as store operators | collecting and managing subscriptions | payment data, which they receive and process as independent controllers under their own policies |
We never receive your payment details. Card number, cardholder and bank details stay with Apple and Google: all we see is whether your subscription is active or expired.
Beyond this list, your data is disclosed only to the other member of the family group you chose to add (section 9), and to judicial or police authorities where a binding order requires it.
7. Where the data goes
The Cloud Firestore servers hosting Premium data are located in the United States.
Some of the suppliers listed above are established in the United States or carry out support activities there. In those cases the transfer relies on the standard contractual clauses approved by the European Commission in Implementing Decision (EU) 2021/914 and, where applicable, on the supplier's certification under the EU-U.S. Data Privacy Framework.
You may request a copy of the safeguards in place by writing to info@ollyzen.com.
8. How long we keep data
We are more specific here than most, because the app's architecture imposes technical retention periods you deserve to know about.
On your device. To keep the app light, the history of feeds, changes and doses is automatically removed from the phone after 45 days on the free version and after 90 days on Premium. Child profiles, configured medicines and growth measurements are never pruned and remain until you delete them or uninstall the app.
On our servers (Premium only). The complete history is kept indefinitely for as long as your account exists. If you delete the account, data is erased as described in section 12.
Family group. A group not used by either member for 180 consecutive days is marked expired and deleted.
Synchronisation log — please read this. So that both parents see the same data even after days offline, every change is written to a technical event log. When you delete a record in the app it disappears immediately from every screen and every device, but the copy carried inside the event that transported it remains in the log for up to 120 days. That content is not visible on any screen of the app and is readable only by members of your family group; it is then permanently removed by a weekly automatic clean-up. We need this window because without it a parent who has been offline for a long time would lose the other's changes. If you want immediate and complete erasure, ask us: we will do it manually.
Crash reports. They stay on Crashlytics for 90 days, then are deleted automatically. They contain no data about your child (section 3.4).
Tax data. Purchase information we are required by law to keep is retained for 10 years, as Italian accounting rules provide.
9. Sharing with the other parent
The "family" feature lets at most two accounts see and edit the same data. The link is made through a code, which you can read out loud or present as a QR code.
Before using it, you should know exactly what it entails.
- The other member sees all the data for the children in the group: profiles, feeds, changes, medicines, growth measurements, notes. There is no partial sharing.
- The other member can edit and delete that data, and their changes reach your device.
- The other member does not see your email address, your name or your subscription status.
- Anyone holding the code can join the group while a slot is free. Treat it like a password: share it only with the right person and only over a secure channel.
- When you join someone else's family group, the data on your device is replaced by the group's. The app warns you before proceeding.
- Leaving the group stops you receiving updates, but data already synchronised remains on the other member's device. We cannot retrieve it for you.
10. Device permissions
| Permission | When it is needed | What it involves |
|---|---|---|
| Camera | only to scan the family-sharing QR code | the image is analysed on the spot and never stored or transmitted |
| Face ID / Touch ID / fingerprint | only to protect access to the app, if you enable it | verification happens in the operating system; we receive only the outcome |
| Notifications | medication reminders, if you enable them | notifications are generated locally by the phone: they pass through no server and their content never reaches us |
| Exact alarms (Android only) | firing reminders at the right time | no data processed |
| Start on boot (Android only) | rescheduling reminders after a restart | no data processed |
You can revoke any of these in your operating system settings. The app will keep working, with the corresponding feature disabled.
11. Getting a copy of your data
You may ask us at any time for a copy of everything we hold on our servers, by writing to info@ollyzen.com. We send it in a machine-readable format within 30 days, as Article 20 GDPR provides.
The app has no automatic export feature. That is deliberate, not an oversight: producing that file requires reading your entire archive back from our servers, and in an app used by many families that cost falls on everyone's service availability. We would rather do it by hand, when it is actually needed, than offer a button that can degrade synchronisation for someone who is recording a feed at that moment.
If you receive that file from us, bear in mind that it contains your child's health data in plain text: from then on its security depends on where you keep it and who you forward it to. Treat it as you would a medical record, and delete it when you no longer need it.
12. Your rights
The GDPR grants you the following rights, which you can exercise by writing to info@ollyzen.com. We reply within 30 days, extendable by a further two months for particularly complex requests, with notice to you.
- Access (Art. 15): find out what data we hold and obtain a copy.
- Rectification (Art. 16): correct inaccurate data — you can also do this yourself in the app.
- Erasure (Art. 17): have your data deleted.
- Restriction (Art. 18): freeze processing pending a check.
- Portability (Art. 20): receive your data in machine-readable form, on request and within 30 days (section 11).
- Objection (Art. 21): object to processing based on legitimate interest.
- Withdrawal of consent (Art. 7(3)): withdraw consent to health-data processing at any time, without affecting the lawfulness of what was done before.
- Complaint (Art. 77): complain to the Italian supervisory authority, the Garante per la protezione dei dati personali (Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it), or to the authority in your country of residence.
We make no automated decisions producing legal effects concerning you, and we do not carry out profiling.
Deleting your account, in practice. The app settings contain "Delete account". The flow asks for biometric confirmation, then erases your data from our servers, then deletes the authentication account. It is irreversible: if you want to keep a copy, ask us for one first (section 11). Data remaining on your device is removed by uninstalling the app. Note that deleting your account does not cancel your subscription, which must be cancelled separately in your App Store or Play Store settings.
13. Children and minors
PoppApp is designed for and directed at adults — parents and carers of a newborn — and is not directed at children. It is not distributed in the App Store Kids Category or in Google Play's Designed for Families programme, and it does not knowingly collect data provided directly by children.
The infant's data in the app is entered by you, an adult, in the exercise of parental responsibility, as explained in section 5.
If you are under 16 (or under the minimum age in your country, where it is lower) you may not subscribe and must not create an account.
14. Security
We apply the measures this architecture allows:
- encrypted communications in transit over TLS to all services;
- encryption at rest on Google Cloud servers, managed by the supplier;
- server-side access rules preventing one user from reading another's data: a family group's data is accessible only to its members;
- biometric lock on the app, if you choose to enable it;
- administration console access protected by multi-factor authentication.
No system is absolutely secure, and we will not pretend otherwise. In the event of a personal data breach posing a high risk to your rights, we will inform you without undue delay and notify the supervisory authority within 72 hours, as Articles 33 and 34 GDPR require.
15. Jurisdiction-specific information
United Kingdom. If you are in the UK, references to the GDPR should be read as references to the UK GDPR and the Data Protection Act 2018. Complaints go to the Information Commissioner's Office (ico.org.uk).
Switzerland. If you are in Switzerland, the revised Federal Act on Data Protection (revFADP) applies. The competent authority is the Federal Data Protection and Information Commissioner (edoeb.admin.ch).
California. If you are a California resident, the CCPA as amended by the CPRA gives you the right to know what categories of data we collect, to have it deleted, to have it corrected and not to be discriminated against for exercising those rights. The categories collected are those in section 3; the purposes are those in section 4. We expressly state that we do not sell personal information and do not share it for cross-context behavioural advertising as those terms are defined under California law, and that we have not done so in the preceding twelve months. We do not knowingly process the data of consumers under sixteen for the purposes of a sale or sharing. To exercise your rights, write to info@ollyzen.com.
16. Changes to this policy
If we change how we process data, we update this page and the date at the top.
Where a change is substantial — a new purpose, a new supplier receiving your child's data, a longer retention period — we will flag it inside the app or by email before it takes effect, and ask for fresh consent where required.
Previous versions of this document are retained and available on request.
17. Contact
For any question, request or complaint:
Andrea Verdecchia — info@ollyzen.com Via Riva di Reno 45, 40122 Bologna (BO), Italy