Privacy Policy

Last updated: August 2026

Protecting your personal data is important to us. Below we inform you in accordance with Art. 13 and 14 GDPR about the processing of your personal data when you visit and use yappidoo.

1. Data Controller

The data controller within the meaning of the GDPR is:

Christoph Klöppner
Benzstr. 3
37083 Göttingen
Germany
Email: hallo@yappidoo.de

For data protection inquiries: datenschutz{'@'}yappidoo.de

2. Hosting & Infrastructure

This website is hosted on servers of Hetzner Online GmbH, Industriestr. 25, 91710 Gunzenhausen, Germany. The .de domain is registered with United Domains AG, Gautinger Str. 10, 82319 Starnberg, Germany. Hetzner acts as a data processor pursuant to Art. 28 GDPR under a data processing agreement. Server location: Germany.

Web analytics with Matomo

We run Matomo Analytics exclusively on our own servers in Germany (matomo.yappidoo.de). No data is shared with third parties.

We only collect statistics after you consent via the banner. Until then we send no data to Matomo at all. With your consent we collect only the bare minimum we need to improve yappidoo.

Processed data (only after consent): truncated IP, anonymised device/browser properties, pages viewed, click paths, dwell time.

Legal basis: Art. 6(1)(a) GDPR and § 25(1) TTDSG (your explicit consent via the banner).

Retention: at most 6 months, after which raw data is automatically deleted.

You can withdraw your consent at any time via the “Analytics settings” link in the footer.

3. Personal Data Processed

In the course of using yappidoo, we process the following personal data:

  • Registration data: email address, password (encrypted/hashed), language setting, consent timestamp
  • Profile information: family nickname, postcode and city (for regional matching – no street or house number), optional profile photo
  • Children's data: first name, date of birth, name and city of the kindergarten/nursery, availability, preferences – entered exclusively by the custodial parents
  • Usage data: IP address (security and operations), login timestamp, audit log (action, time, IP address, plus the acting account's user ID and email address at the time of the action)
  • Push notifications: subscription data issued by your browser (endpoint URL, public device key p256dh, authentication token auth, truncated user agent) – only upon your explicit consent (see section 11 for details)
  • Playdate messages: text content exchanged between the two participating families after a playdate has been confirmed (see section 10 for details and encryption)

Note on children's data: Data about children is processed solely on the initiative of custodial parents. The app is not directed at children. Special protection applies pursuant to Art. 8 GDPR.

4. Purpose and Legal Basis of Processing

We process your data for the following purposes and on the following legal bases:

  • Provision of the service, account management, playdate coordination — Art. 6(1)(b) GDPR (contract performance)
  • Storage of consents, push notifications — Art. 6(1)(a) GDPR (consent)
  • Security, abuse prevention, audit logging — Art. 6(1)(f) GDPR (legitimate interest)
  • Sending transactional emails (confirmation, password reset) — Art. 6(1)(b) GDPR (contract performance)
  • Chat feature between confirmed playdate partners — Art. 6(1)(b) GDPR (contract performance)

Operator moderation: to ensure safety and meet legal obligations, the yappidoo team may view, correct and delete family and child profiles — and also does so at the request of an affected family (Art. 6(1)(f) GDPR, legitimate interest; Art. 6(1)(c) GDPR where legally required). When a child profile is deleted, its friendships, meetups, messages about those meetups, match suggestions, saved time slots and saved meetup preferences are removed with it (cascading deletion). Every such action is recorded in the audit log (see sections 3 and 5).

5. Retention Periods

Your data is stored only for as long as necessary for the respective purpose:

  • Account data and profile: until account deletion
  • After account deletion: immediate deletion of all personal data
  • Audit logs (GDPR compliance; incl. IP address to protect against misuse, Art. 6(1)(f) GDPR): 90 days
  • IP addresses in server logs: max. 7 days
  • Playdate messages: automatically deleted when the playdate is cancelled, expires or one of the participating families deletes their account – and at the latest after 100 messages per playdate (oldest message is removed automatically)
  • Push subscriptions: until you withdraw consent, delete your account, or the browser's push service reports the subscription as permanently invalid (automatic deletion on HTTP status 404/410)
  • Push send log (action type, HTTP status code, success flag – no message content): max. 90 days
  • In-app notifications (bell icon in the app): max. 90 days, then deleted automatically

6. Disclosure to Third Parties

Your data is generally not passed on to third parties. The only exception is the hosting provider Hetzner Online GmbH, which acts as a data processor exclusively following our instructions. No data is shared with advertising networks, social networks or other commercial third parties.

7. Cookies and Local Storage

yappidoo uses only technically necessary cookies and local storage mechanisms. Specifically:

  • Session token (cookie): to maintain your login session
  • Language setting (localStorage): to save your preferred language
  • No tracking, analytics or advertising cookies are used.

8. Your Rights (Art. 15–22 GDPR)

You have the following rights regarding your personal data:

  • Right of access (Art. 15 GDPR) – you can request a copy of your data at any time in the app under "Download my data".
  • Right to rectification (Art. 16 GDPR) – you can correct inaccurate data at any time in the profile settings.
  • Right to erasure (Art. 17 GDPR) – you can delete your account and all associated data at any time in the app under "Delete account".
  • Right to restriction of processing (Art. 18 GDPR)
  • Right to data portability (Art. 20 GDPR) – JSON export of your data is available in the app.
  • Right to object (Art. 21 GDPR) – you can object to processing based on legitimate interest by email.
  • Right to withdraw consent (Art. 7(3) GDPR) – possible at any time with effect for the future.

To exercise your rights, please contact: datenschutz@yappidoo.de

9. Right to Lodge a Complaint

You have the right to lodge a complaint with a data protection supervisory authority regarding the processing of your personal data. The competent supervisory authority for Lower Saxony is:

Die Landesbeauftragte für den Datenschutz Niedersachsen (State Commissioner for Data Protection Lower Saxony)
Prinzenstraße 5, 30159 Hannover, Germany
www.lfd.niedersachsen.de

10. Messages Between Families (Chat Feature)

After both sides have confirmed a playdate, the two participating families (Family A and Family B) can exchange text messages directly within the app. The same applies to the friends chat between two families whose children are friends (see the last item). The following rules apply:

  • Scope and behaviour: Up to 100 messages with a maximum of 500 characters each can be exchanged per playdate. Once the limit is reached, sending a new message automatically deletes the oldest one (FIFO). Messages are intended solely for the other family participating in the confirmed playdate; they are not shared with any other users or third parties.
  • Legal basis: Processing is based on Art. 6(1)(b) GDPR (contract performance) and serves exclusively the direct coordination between the two participating families (e.g. meeting point, time, short-notice adjustments).
  • Encryption at rest: All message contents are symmetrically encrypted before being stored, using the authenticated XSalsa20-Poly1305 scheme (libsodium / secretbox). Each message is assigned its own random nonce; the encryption key is derived from our application secret (APP_SECRET). As a result, message contents are unreadable in database backups or in the event of a pure database breach without knowledge of the application secret.
  • Not end-to-end – operator access: This is explicitly NOT end-to-end encryption. Because the decryption key is held on our application servers, technically privileged operator staff (administrators with shell access to the application environment) can in principle decrypt and read messages. Such access only takes place in justified exceptional cases, in particular: (a) to comply with legal obligations, e.g. on the basis of a court or official order (Art. 6(1)(c) GDPR); (b) to prevent or investigate abuse, harassment or criminal acts within the app (Art. 6(1)(f) GDPR, overriding legitimate interest); (c) for technical error diagnosis with the prior explicit consent of the families concerned.
  • Automatic deletion: Messages are automatically and irrevocably deleted as soon as the playdate is cancelled, cancelled by an administrator or marked as expired after its date. In addition, messages are deleted if one of the participating families deletes their account or if the underlying playdate itself is removed for technical reasons (cascade deletion).
  • Notifications about new messages: A new message creates an in-app notification for the recipient. That notification only stores the meta information that a new message exists for a specific playdate (including the sending family's nickname); the actual message text is never mirrored into the notification table.
  • Access and data export (Art. 15 and Art. 20 GDPR): As long as messages still exist, they are included in the data export ("Download my data") in plaintext – both messages you sent and messages the other family sent to you. Once messages have been deleted automatically (playdate cancelled, expired or account deletion), they can no longer be provided.
  • Friends chat: In addition, two families whose children are friends with each other can chat directly. Up to 200 messages of at most 500 characters each are stored per family pair (FIFO as above). The same rules as for the playdate chat apply to encryption, operator access, notifications, and access/data export. Legal basis: Art. 6(1)(b) GDPR. The messages are automatically and irreversibly deleted as soon as the last friendship between the two families ends or one of the participating families deletes their account (storage-limitation principle, Art. 5(1)(e) GDPR).

Note on your own responsibility: Please do not send particularly sensitive personal data within the meaning of Art. 9 GDPR (e.g. health data, religious or political beliefs) via the chat feature. Responsibility for the content and lawfulness of messages sent lies with the sending family.

11. Push Notifications (Web Push)

yappidoo can – exclusively on the basis of your explicit consent – inform you via Web Push notifications about events in the app (e.g. new match suggestions, playdate requests, confirmed or cancelled playdates, reminders, new chat messages, family invitations and service messages from the operator). The following rules apply to this feature:

  • Data processed: When you activate the push feature, we store per device the subscription data issued by your browser, namely the subscription endpoint (URL of the vendor-specific push service), the device's public encryption key ("p256dh"), an authentication token ("auth"), and – to distinguish between several devices within your account – a truncated user-agent string and the timestamp of registration. These values are generated by your browser and are technically required so that the push service can deliver the notification to the specific device that registered.
  • Legal basis: Processing is based on your explicit consent pursuant to Art. 6(1)(a) GDPR. Consent is given in two steps: first by activating the push feature in your profile and confirming the browser's or operating system's permission prompt, then on a per-event-type basis via a master switch and individual switches for each event type. Without this consent we store no push data and send no push notifications.
  • Transfer to push services in third countries (in particular the USA): The technical delivery of the push notification is necessarily routed through the push service belonging to your browser or operating system. These are typically: Apple Push Notification Service operated by Apple Inc. (USA) for Safari, iOS and macOS; Firebase Cloud Messaging / Web Push operated by Google LLC (USA) for Chrome, Edge and Android; Mozilla autopush operated by the Mozilla Corporation (USA) for Firefox. Selection and location of these services are determined by your browser or operating system and lie outside our sphere of influence. Where this entails a transfer to the USA, it relies cumulatively on (i) your explicit consent as a derogation under Art. 49(1)(a) GDPR and (ii), to the extent the respective recipient is certified under the EU-US Data Privacy Framework, on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). You are expressly informed that in third countries – in particular the USA – government access may exist against which no effective legal remedies may be available under applicable law.
  • Pseudonymity vis-à-vis the push service (VAPID): We authenticate ourselves to the push services exclusively via the VAPID protocol (Voluntary Application Server Identification, RFC 8292). Transmitted in this process are only a technical contact email address (the mailto VAPID subject), our public VAPID key and the message encrypted for the specific device. No identification data relating to you, your family or your children is transferred to the push service.
  • Content of the push notification: Each push notification contains only the following fields: a short title and body translated into your language (e.g. "New match request" or "Reminder for your playdate tomorrow"), a click URL through which the app navigates to the corresponding location when you tap the notification, and technical display metadata (icon, grouping tag). The actual content of a chat message is never transmitted inside a push notification. The notification is additionally encrypted on the application level with the device's public key before being handed over to the push service; decryption only takes place locally in your browser.
  • Send log: For diagnostics, abuse prevention and quality assurance we store a technical send log for each push notification dispatched, consisting of: user reference, action type (e.g. "new_match"), HTTP status code of delivery and a success flag. The actual content of the push notification (title, body, URL) is expressly NOT stored in the send log. The legal basis for this is Art. 6(1)(f) GDPR (legitimate interest in reliable push delivery and detection of systemic errors).
  • Retention and automatic deletion: Push subscriptions are stored until you withdraw your consent, delete your account, or the push service reports the subscription as permanently invalid (HTTP status 404 or 410); in that case we delete the affected subscription automatically and without delay. The send log is automatically deleted after at most 90 days.
  • Withdrawal and controls: You may withdraw your consent at any time with effect for the future, without affecting the lawfulness of processing based on consent up to that point (Art. 7(3) GDPR). Withdrawal is possible (a) via the master push switch in your profile settings (disables all push notifications), (b) via the individual event switches (disables only specific push types), (c) by revoking push permission in your browser or operating system settings, and (d) by deleting your account. Upon withdrawal, the associated subscription data is deleted.

12. Updates to this Policy

We reserve the right to update this privacy policy as necessary to reflect changes in the law or changes to our service. The current version is always available at /legal/datenschutz.

14. SMS one-time password (OTP login)

Users who have stored a mobile number in their profile can alternatively sign in using an SMS one-time password (OTP). The following rules apply to this feature:

  • Purpose: Authentication via a one-time password sent by SMS, as an alternative to password-based sign-in.
  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract) — the feature is voluntarily activated by storing a mobile number in the profile.
  • Recipients and transfers: SMS is sent via CM.com B.V., Konijnenberg 30, 4825 BD Breda, the Netherlands, as a data processor. CM.com is an EU company; no third-country transfer takes place.
  • Retention: OTP tokens are automatically deleted after at most 24 hours. They are immediately invalidated after use or expiry (15 minutes).
  • Withdrawal: The feature can be deactivated at any time by removing the mobile number from the profile. No separate right of objection is required, as no legitimate interest serves as the legal basis.
  • Number confirmation: Before an emergency/mobile number is stored in your profile, we send a one-time confirmation code via SMS to ensure the number belongs to you. The number is only stored after successful confirmation and is unique per family. Processor (CM.com B.V.), legal basis (Art. 6(1)(b) GDPR) and the retention of confirmation codes are as stated above.

15. Recommendations and affiliate links (Amazon Partnernet)

yappidoo shows editorially selected product recommendations with affiliate links to Amazon on a dedicated recommendations page (/recommendations). A subset is shown as a teaser on the dashboard and as a clearly marked "Ad" in the marketplace list.

  • What data is processed: The selection of products on the recommendations page and in the dashboard teaser is based on the age of the children in your family profile (union of all children) and the current season (calendar month). The product ad in the marketplace list is selected without using any personal data; it simply rotates page by page through the editorially approved products. No profiling on the basis of location, kindergarten or behavioural data takes place.
  • What happens when you click an Amazon link: When clicked, you are redirected to Amazon Europe Core S.à r.l. (38 avenue John F. Kennedy, L-1855 Luxembourg). Amazon sets its own cookies, which allow yappidoo to be credited a commission for qualifying purchases within 24 hours. yappidoo itself receives only aggregated, non-personal statistics from Amazon (number of clicks, conversion rate, payout amount) — no identifying information, no purchase lists.
  • Controller after the click: After you click an Amazon link, Amazon Europe Core S.à r.l. is the data controller. Privacy notice: https://www.amazon.de/gp/help/customer/display.html?nodeId=201909010
  • Opt-out: Parents can disable the display of advertising at any time in their profile under "Ads & recommendations". This hides the recommendation teasers and the navigation link to the recommendations page; in addition, events marked as "Ad" no longer appear in the event list, the calendar view or the bookmarks, and no product ad appears in the marketplace list (a short note is shown in its place). The recommendations page and individual event ads remain accessible via direct URL for transparency reasons.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in funding the free service without profiling) in combination with Art. 6(1)(a) GDPR (consent through the active click action regarding the data processing by the third-party provider Amazon).

16. Origin Tracking via Kindergarten Landing Pages

If you register through a kindergarten landing page, we internally store which invitation page your registration came from. This information is used solely to evaluate how many families found yappidoo through which kindergarten partnerships. It is not shared with third parties and will be deleted after 12 months (Art. 6(1)(f) GDPR — legitimate interest in measuring effectiveness). You may object to this processing at any time by emailing datenschutz{'@'}yappidoo.de.

17. Weather Display on the Dashboard (Open-Meteo)

If you have stored a city in your family profile, we show the current weather for your region on the dashboard. To do so we fetch the weather data from the Open-Meteo service:

  • Recipient: Open-Meteo (operated within the EU/EEA — no transfer to a third country takes place).
  • Data transmitted: only the geographic coordinates derived server-side from the city stored in your family profile. Your IP address and any other personal data are not transmitted to Open-Meteo — the request is made from our server, not from your browser.
  • Legal basis: Art. 6(1)(f) GDPR (legitimate interest in showing you helpful weather information for planning playdates).
  • Retention: The fetched weather data is only cached briefly (max. 30 minutes) and is not stored permanently.
  • Objection: You may object to this processing at any time under Art. 21 GDPR by removing the city from your family profile or by emailing datenschutz{'@'}yappidoo.de.

18. Groups and forum

yappidoo lets families join groups and post in a group's internal forum (e.g. to plan shared outings or birthdays).

  • Data processed: group name and description, members' family nickname and avatar, and the forum posts and replies you write yourself.
  • Recipients: this data is visible to all members of the respective group. Additional families can join the group via an invite link.
  • Legal basis: Art. 6(1)(b) and (f) GDPR (providing the group feature you use, and our legitimate interest in exchange between families).
  • Retention: posts are stored until you delete them or the group is deleted; memberships until you leave. A block record is retained to enforce a block.
  • Withdrawal and deletion: you can delete your own posts at any time, leave a group, or – as group admin – delete the entire group.
  • Events and RSVPs: group members can create events (title, date, time, location, description). Your RSVP (yes/maybe/no) and your event comments are visible to all members of the respective group.
  • Retention and reminders for events: events, RSVPs and event comments are stored until the event or the group is deleted; when you delete your account, your RSVPs and comments are removed. If you said yes to an event, we remind you shortly before it starts via notification — you can switch this off in your notification settings.
  • Saved posts: when you save a topic or a comment, we store the link between your user account and that post so we can show it in your personal saved list. Your saved list is private and cannot be seen by other group members or by the author of the post. Legal basis: Art. 6(1)(b) GDPR (providing the feature you are using). The entry is deleted as soon as you unsave it, the post is deleted, you leave the group or are blocked, or you delete your account.

Operator moderation: to ensure safety and meet legal obligations, the yappidoo team may view and delete groups, forum posts and events and remove or block members (Art. 6(1)(f) GDPR).

19. Yappidoo ambassadors (referral programme)

When you apply to become an ambassador for a kindergarten, we process the name and, if provided, the city of the kindergarten you chose – it does not have to be your children's kindergarten – as well as your optional reason. The legal basis is your consent through actively applying (Art. 6(1)(a) GDPR).

Families who sign up via your personal link are attributed to you internally. You only ever see aggregated numbers – never which families signed up. Kindergarten-wide numbers are shown only if you consented to kindergarten statistics and at least three families are present.

The "signed up via ambassador link" attribution is stored for at most 12 months and then deleted automatically. You can withdraw your ambassadorship in the app at any time (withdrawal of consent).

Once your ambassadorship is approved, the fact that you are an ambassador is visible to other families you are in contact with through suggestions (matches), friendships, playdates or an invitation – as a small marker next to your family name. The name of your kindergarten is not shown. The legal basis is our legitimate interest in a functioning referral community (Art. 6(1)(f) GDPR); you can end the ambassadorship at any time in your profile, which removes the marker.

20. Marketplace (listings, location, messages, moderation, AI)

When you use the marketplace, we process additional personal data. The following explains what and on which legal basis.

  • Listings: title, description, photos, category and attributes, price and the visibility you choose. Depending on visibility (KiTa only, city, radius, nationwide) this is visible to other logged-in, verified parents. Legal basis: Art. 6(1)(b) GDPR (providing the marketplace). Retention: until you delete the listing or your account, at the latest until the automatic deletion described in section 21.
  • Location/radius: When you create a listing you enter the postal code of the pickup location. We convert it once into coordinates and the corresponding city (geocoding via Google Maps Platform; transfer to the USA under Art. 44 et seq. GDPR based on the EU Standard Contractual Clauses). Your exact address is never shown to other users — only the city and an approximate distance. You share the exact pickup address — if at all — yourself in the chat. Legal basis: Art. 6(1)(b) GDPR. You can change or remove the location per listing at any time.
  • Messages: the chat about a listing is stored encrypted and takes place exclusively in the app (see section 10). Each chat keeps at most the latest 200 messages – older ones are deleted automatically. The listing's provider can delete a chat entirely; at the latest when the listing is deleted (including the automatic deletion described in section 21), all related chats and messages are irrevocably deleted. Legal basis: Art. 6(1)(b) GDPR. Access by the operator occurs only in justified exceptional cases (Art. 6(1)(c) and (f) GDPR).
  • Moderation: listings are checked before publication (via a maintainable word list and an automated content check) and can be approved, rejected, blocked or deleted by administrators. We store moderation data (status, reason, reviewer, timestamp). Legal basis: Art. 6(1)(f) GDPR (platform safety, abuse prevention) and Art. 6(1)(c) GDPR (legal obligations, incl. the Digital Services Act). You are notified of the outcome (approval/rejection/blocking). For decisions made by administrators this notification includes the reason. If you revise a rejected or blocked listing, it is reviewed again before being published.
  • AI assistance: for the automated content check and the optional creation of a listing draft from your free text, we transmit the text you enter to our processor Anthropic PBC, USA (Art. 28 GDPR, data processing agreement; third-country transfer under Art. 44 et seq. GDPR based on the EU Standard Contractual Clauses). Only the entered text is transmitted — no other profile or child data. No storage for training purposes takes place (zero data retention agreed). Legal basis: Art. 6(1)(b) GDPR (creation) or Art. 6(1)(f) GDPR (moderation).
  • Public seller profile: a listing shows a display name (nickname) and an approximate region — never your exact address, surname or contact details. We follow the principle of data minimisation (Art. 5(1)(c) GDPR).
  • Reports: you can report other users' listings. We store the reason, your optional details, a reference to your account and review notes (status, reviewer, timestamp) to process the report and prevent abuse of the reporting feature. Your identity is not disclosed to the reported user. Reports are deleted at the latest when the affected listing is deleted. Legal basis: Art. 6(1)(f) GDPR (platform safety) and Art. 6(1)(c) GDPR in conjunction with Art. 16 Digital Services Act (notice-and-action).
  • Bookmarks: if you save a listing, we store the link between your account and the listing so we can show it in your personal bookmark list. Your bookmark list is private and visible neither to other users nor to the listing's provider. Legal basis: Art. 6(1)(b) GDPR (providing the feature you use). The entry is deleted as soon as you remove it, the listing is deleted (including the automatic deletion described in section 21) or you delete your account.
  • Confirmation of image rights: When you upload photos for a listing, you confirm via checkbox that you hold the necessary rights to the images and that people shown in them have agreed to their publication. We store the time of this confirmation per image for as long as the listing and its image are stored. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in being able to prove the authorization of published images in the event of a dispute).

Note: you are primarily responsible for the content of your listings; yappidoo is (jointly) responsible for published listing content and moderates it. Please do not include personal data of third parties or sensitive data in listings.

21. Retention and automatic deletion of marketplace listings

In line with the storage-limitation principle (Art. 5(1)(e) GDPR), marketplace listings are kept only as long as they are actively used. If a listing receives no views from other users for a period of 10 to 14 days, it is automatically hidden and, after a further 7 days, irreversibly deleted — including all uploaded images. Listings marked as sold are automatically and fully deleted 30 days after being marked. We notify you before the final deletion. This feature collects no additional personal data; in particular, we do not store which person viewed a listing.

22. Word filter in messages and posts

To keep yappidoo family-friendly, we check chat messages (playdates, marketplace and friends chat), forum posts and event comments against a word list maintained by the yappidoo team, on our servers. If a new chat message or forum post contains a listed term when you send it, we reject it right away and do not store it – you'll see a note with the affected word and can adjust your text. Messages and posts that are already stored, as well as event comments containing a listed term, are additionally replaced with asterisks when displayed; this way the filter also catches words that were added to the list only later. The check runs exclusively on our servers; no additional data is stored, no profiles are created and no content is shared with third parties. The original text you stored is not altered by this masking. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a safe, family-friendly platform and in protecting our users, especially families with children).

23. Events (public family calendar)

In the Events section, parents can post public family events (e.g. festivals, outings, courses). Approved events are visible to all registered families.

  • Data processed: title, description, category, date and time, location, recommended age range, an optional external link and an optional image.
  • Bookmarks: if you save an event, we store the link between your account and the event so we can show it in your personal bookmark list and remind you before it starts.
  • Recipients: approved events are visible to all logged-in users. The identity of the family that posted the event is not shown — only administrators see it as part of moderation. Your bookmark list is private and not visible to other users.
  • Legal basis: Art. 6(1)(b) GDPR (providing the feature you use) for posting and bookmarking events. Visibility to all users results from your active publication of the event.
  • Moderation: an event's title and description are checked against a word list maintained by the yappidoo team, on our servers, already when you submit it (see section 22); if an event contains a listed term, it is rejected and not published — you'll see a note with the affected word and can adjust your text. Before an event becomes visible to others, the yappidoo team also reviews it. For this we store moderation data (status, reviewer, review time; if rejected or blocked, additionally the reason). You are notified of the outcome — including the reason if rejected or blocked. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a safe, family-friendly offering).
  • Retention and automatic deletion: events are automatically deleted 90 days after the event ends, including any uploaded image. You can delete your event, the image and your bookmark yourself at any time before that. For events marked as an ad with their own visibility period, the 90-day period starts at the later of the two: the end of the event or the end of the visibility period. For recurring events, the last date of the series counts as the end of the event.
  • Reminders: for saved events you can receive a push reminder shortly before they start. Like all push notifications, this requires your consent and can be switched off per action in your profile (see section 11).
  • Address and radius search: if you enter an address when posting an event, we convert it once into coordinates (geocoding via Google Maps Platform; transfer to the USA under Art. 44 et seq. GDPR based on the EU Standard Contractual Clauses). The address is part of the event's public content and visible to all registered families like the other details listed in this section. The coordinates are used solely to enable radius search for other families. If you use the radius search yourself, you enter a postal code for it; this is also converted once into coordinates (likewise geocoding via Google Maps Platform; transfer to the USA under Art. 44 et seq. GDPR based on the EU Standard Contractual Clauses), used solely for the search and not stored in your profile; the mapping of postal code to coordinates is merely cached for up to 30 days without any link to your account. Legal basis: Art. 6(1)(b) GDPR. You can change or remove the address at any time.
  • AI-generated images for imported events: Events we take from publicly accessible event calendars do not carry an image from the source. Instead, our team can have an illustration generated. To do so we transmit the title, description and category of the event to our processor Anthropic PBC, USA (creating the image description; Art. 28 GDPR, data processing agreement; third-country transfer under Art. 44 et seq. GDPR based on the EU Standard Contractual Clauses, zero data retention agreed) and to Google (Gemini API, USA) to render the image. The transfer to Google is made to the USA under Art. 44 et seq. GDPR and relies cumulatively on Google's Data Processing Addendum with EU Standard Contractual Clauses as well as, to the extent Google is certified under the EU-US Data Privacy Framework, on the European Commission's adequacy decision of 10 July 2023 (Art. 45 GDPR). We access the Gemini API through a paid account; under Google's terms of service, the transmitted data is therefore not used to improve Google's products. Only the data listed above about a publicly announced event is transmitted — no user, family or child data. Images created this way are visibly labelled "AI-generated" in the app, additionally carry a machine-readable AI-generated marker embedded in the image file (Art. 50(2) of Regulation (EU) 2024/1689), and do not show the actual event. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a clear and appealing presentation of the event calendar).
  • AI images for events you create yourself: If you post your event without a photo of your own, you can have an illustration generated once on request. For this, we transmit the title, description and category of your event to our processor Anthropic PBC, USA (creation of the image description; Art. 28 GDPR, data processing agreement; third-country transfer under Art. 44 et seq. GDPR based on the EU Standard Contractual Clauses, zero data retention agreed) and to Google (Gemini API, USA) to generate the image. The transfer to Google in the USA takes place under Art. 44 et seq. GDPR and is based cumulatively on Google's data processing addendum with EU Standard Contractual Clauses and, insofar as Google is certified under the EU-US Data Privacy Framework, on the adequacy decision of the European Commission of 10 July 2023 (Art. 45 GDPR). We use the Gemini API via a paid account; under Google's terms, the transmitted data is therefore not used to improve Google products. Only the event details mentioned are transmitted — no account, family or child data. Generation happens only on your explicit click and at most once per event; the result is labeled "AI-generated" in the app and additionally carries a machine-readable AI-generated marker embedded in the image file (Art. 50(2) of Regulation (EU) 2024/1689). Legal basis: Art. 6(1)(b) GDPR (provision of the feature you requested).
  • Confirmation of image rights: When you upload your own image for your event, you confirm via checkbox that you hold the necessary rights to the image and that people shown in it have agreed to its publication. We store the time of this confirmation together with the event for as long as the image is published. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in being able to prove the authorization of published images in the event of a dispute).

24. Shared family access (two parents)

A family can be used jointly by up to two parents. The second parent gets their own user account with their own login credentials and accesses the same family data.

  • How it works and who sees what: using an invitation link from your profile ("Family" section), a second parent can join your family account. Both parents then see and can edit all family data — children's profiles, availabilities, friendships, groups, playdates, messages including previous conversations, marketplace listings and the stored emergency contact (name and phone number). The family overview also shows the other parent's email address; it is displayed within the family only and is not passed on to other families. What stays separate per parent: the sign-in (each parent's own email address and own password; passwords are not visible to anyone), the notification settings, the personal bookmark lists and the notification inbox.
  • Legal basis: Art. 6(1)(b) GDPR (performance of a contract — joint use of the family account by both parents). Data is merged solely through the active registration or confirmation of the invited parent via the invitation link; without this step nobody gains access to your family data.
  • First name to tell the parents apart: in your profile you can voluntarily provide a first name (max. 80 characters). It is visible to the members of your family and to your family's chat partners, and you can change or delete it at any time. If an invited parent signs up via an invitation link, this entry is required during registration so that both parents can be told apart; it does not have to be a legal name. Legal basis: Art. 6(1)(b) GDPR.
  • Invitation links: for each invitation link we store a randomly generated token, the inviting family, the time of creation and of expiry as well as — once used — the parent who joined and the time they joined. A link is valid for 7 days; expired and already used links are deleted by the daily automatic cleanup after a grace period of 7 days.
  • Ending the shared access: both parents can end the connection at any time in their profile ("Leave family" or "Remove partner"). The leaving parent keeps their user account and receives a new, empty family; the existing family data stays with the previous family and is no longer accessible to them. We inform both parents about the separation by email and by in-app notification. If a parent deletes their user account, the family data stays with the remaining parent.
  • Access and data export: the data export ("Download my data", see section 8) contains the family data and is available to both parents equally. Notification- and device-related data — notification inbox, push subscriptions and push delivery logs — is included only for the requesting parent.

25. Family & Friends (status posts for befriended families)

With Family & Friends your family can post short status updates (e.g. "We're at the playground") that only befriended families can see.

  • How it works and who can see it: a status post consists of free text (280 characters max) and is shown under your family name and family avatar. It is visible exclusively to families you have an active friendship with — not to other users and not publicly. Befriended families can react with an emoji from a fixed set; the reaction is visible to everyone who can see the post. Which parent wrote the post is not shown to other families, but is stored internally.
  • Data processed: the free text of the post, the time, the posting family, internally the authoring parent, and per reaction the reacting family, the chosen emoji and the time. Please do not post sensitive information — the text is visible to all befriended families.
  • Legal basis: Art. 6(1)(b) GDPR (provision of the feature you actively use). Posts are only created by your own input; nothing is shared without you actively posting.
  • Retention: status posts are visible for 24 hours and are then deleted automatically and permanently — including all reactions. You can delete your own posts at any time before that. Notifications about new posts are subject to the general periods in section 5.
  • Turning it off: in your profile (section "Family") you can switch off Family & Friends for your whole family at any time. Your family then no longer posts or sees anything, and your still-active posts are no longer shown to befriended families. Push notifications about new posts can additionally be disabled per parent in the notification settings.