Privacy
Last updated: 27 September 2026
KidsPlayTimer is an application for families. It holds information about children, which is why this text is longer than it strictly needs to be: you should be able to look up what is stored, why, for how long — and what we deliberately do not collect.
1. Controller
The controller within the meaning of Art. 4(7) GDPR is:
Nikolas Gottschalk (Einzelunternehmer)Sonnenhof 150
53119 Bonn
Deutschland
Email: kidsplaytimer-foa6uj@1stlevel.tech
No data protection officer has been appointed; the conditions of Art. 37 GDPR and section 38 BDSG are not met. Questions about data protection are answered at the address above.
2. What we do not collect
This belongs at the top, because for an application holding children's data it is the most important thing to say. KidsPlayTimer does not collect:
- no photos of children,
- no location data,
- no browsing history and no content from other apps,
- no measurement of actual device use.
The last point sometimes surprises people. KidsPlayTimer does not measure how long a device is really used — it does not read other apps and does not hook into the operating system. A timer here is an agreement you start and end together, not surveillance.
There is likewise no advertising, no cross-site tracking, no sharing or selling of data to third parties for advertising, and no analysis of a child's behaviour for any purpose other than showing it inside your own family.
3. What is processed
a) Adult account
Name, email address, a password (only a non-reversible hash is stored), chosen language, number and time format, reduced-motion preference, the time of the last re-authentication, and the version, language and time of the accepted terms.
b) Family
Family name, time zone, default language, the roles of the adults involved, start and end of the trial, access state, and your shared settings.
c) Child profiles
Nickname, an avatar from a fixed set, a broad age group, language, position in the overview and — if you set one — a four digit PIN, of which again only a hash is stored.
The nickname is free text. A real name is not needed to use the product, and a nickname that does not identify the child is the option that stores the least.
d) Time, chores and rewards
The rules you set (base time, daily cap, time windows, bonus rules), the sessions started with their beginning, end, duration, device category and optional device name, the time account including the bonus bank, the chores and rewards you create with their titles and descriptions, completed chores, approvals, star balances, redemptions and the short comments written along the way.
e) Child devices
For a paired device: display name, when it was paired, when it was last used, and a hash of its access token. The pairing code itself is also stored only as a hash and expires after 10 minutes.
f) Notifications
If you allow notifications: the push endpoint address of your browser, the associated keys, an optional device name and the language. Plus a record of delivery attempts, without the content of the message.
g) Billing
Customer number at Stripe, the type of payment method and its last four digits, subscription state, terms and invoices. Full card details never reach our servers — they are processed directly by Stripe.
These details arrive at the start: the payment method is stored before the free days begin, because the charge follows automatically when they end.
h) Logs and evidence
Security relevant events (sign-in, role change, pairing, deletion) are recorded with the time, the acting role and the object concerned. Of the IP address only a hash formed with a server key is stored, never the address in clear text.
Declarations made on the cancellation and withdrawal pages are kept as evidence: address, name, the details of the contract and the time of receipt.
i) Contact form
Email address, subject, message and — if you enter it — your name. The name is optional. The form does not store your IP address.
j) Visitor statistics
So that we know which pages are read and how visitors find us, our server counts views of the
public pages and the sign-in pages. For each view it stores: the time, the page, the response
status, the domain of the referring page (not its full address), a campaign name if one was
attached (utm_source), the country our delivery network derives from the IP address,
the preferred browser language, and the device type, browser and operating system family. It also
records whether the view came from an automated program (a bot).
Neither the IP address nor the full browser identifier is stored for this. To count the visitors of a day we form a hash from them and a random value. The random value is created anew every day and then discarded; from the following day on an entry cannot be attributed to anyone, not even by us. No cookies are set and nothing is stored on or read from your device. The family area of the application is not recorded, and the data does not leave our server.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Providing the account, family, child profiles, times, chores and rewards | Art. 6(1)(b) GDPR — performance of the contract |
| Subscription, payment and invoices | Art. 6(1)(b) GDPR; for keeping the invoices Art. 6(1)(c) GDPR together with section 147 AO and section 257 HGB |
| Notifications on your device | Art. 6(1)(a) GDPR — your consent, withdrawable at any time in the browser or in the settings |
| Contact form | Art. 6(1)(a) GDPR; for a contract related enquiry also Art. 6(1)(b) GDPR |
| Evidence of cancellation and withdrawal | Art. 6(1)(c) GDPR — sections 312k(2) and 356a(3) BGB require a confirmation of receipt |
| Visitor statistics of the public pages | Art. 6(1)(f) GDPR — legitimate interest in improving the service from aggregated figures and in recognising automated access; no access to your device, hence no consent under section 25 TDDDG |
| Security, abuse prevention, fault finding, logs | Art. 6(1)(f) GDPR — legitimate interest in running the service safely and traceably |
5. Children
Children's data reaches the application in two ways, and the difference matters for how they are informed:
- Entered by the adults: nickname, avatar, age group and the agreed rules. Art. 14 GDPR applies — the information reaches the child through the adults with parental responsibility, who read this policy.
- From the child: what happens in the child area — reporting a chore as done, asking for time, wishing for a reward. Art. 13 GDPR applies. The child area says in its own words that the parents can see these entries.
In both cases the legal basis is the contract with the adults (Art. 6(1)(b) GDPR), not the child's consent. Art. 8 GDPR therefore does not apply: it concerns a child's consent to an information society service, and nothing here rests on such a consent.
The adults with parental responsibility act for the child (sections 1626, 1629 BGB). They also exercise the child's rights under Art. 15 to 21 GDPR. As soon as a child can understand the information, the adults should explain the processing to them; the child area helps by showing in child friendly language what is stored.
In the child area a child sees only their own data — never a sibling's entries and never billing data. If there is a dispute about exercising the child's rights, write to kidsplaytimer-foa6uj@1stlevel.tech.
6. Who sees the data
Inside the family
Adults in the same family see the child profiles, times, chores and rewards. The owner also sees the subscription and the invoices. When an adult is removed from a family, their sessions and access end immediately.
Processors
We use the following service providers under Art. 28 GDPR:
| Provider | Task | Location |
|---|---|---|
| Laravel Cloud (Laravel Holdings, Inc.) | Running the application, database and background work |
Based in the USA, operated on Amazon Web Services infrastructure in an EU region
Standard contractual clauses under Art. 46(2)(c) GDPR, supported by the EU-US Data Privacy Framework where it is in force at the time of transfer |
| Cloudflare, Inc. | Delivering the pages, fending off automated attacks |
Based in the USA
Standard contractual clauses under Art. 46(2)(c) GDPR, supported by the EU-US Data Privacy Framework where it is in force at the time of transfer |
| Stripe Payments Europe, Ltd. | Handling the paid subscription and invoices |
1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, Ireland
Stripe may use sub-processors outside the EU for fraud prevention, on the basis of standard contractual clauses under Art. 46(2)(c) GDPR |
| 1stlevel.tech | Turning messages from the contact form into support tickets | Servers in the EU |
| Hostinger International Ltd. | Sending the emails for sign-in, invitations, billing and reminders | 61 Lordou Vironos Street, 6023 Larnaca, Cyprus |
Push services
A notification travels through the push service of your browser (Google (Firebase Cloud Messaging) für Chrome und Chromium-Browser; Mozilla (autopush) für Firefox; Apple (Apple Push Notification service) für Safari; Microsoft (Windows Push Notification Services) für Edge). These are not processors: which one is used is decided by your browser, not by us. They receive the endpoint address and the encrypted message. By default a notification contains no child's name; showing one is a setting you have to turn on deliberately.
Nobody else
Data is not passed on to third parties for advertising. Disclosure to authorities happens only where we are legally obliged to make it.
7. Transfers to third countries
Where the table above names a location outside the EU or the EEA, the transfer is based on the standard contractual clauses of the European Commission under Art. 46(2)(c) GDPR, supported by the EU-US Data Privacy Framework where that is in force at the time of the transfer.
A residual risk remains, and we are not going to write it away: authorities in third countries could access data without a remedy being available that fully matches European standards.
8. How long data is kept
The periods below are operating decisions, not a claim about statutory minimum periods.
| Data | Period |
|---|---|
| Account and family data | until the account or the family is deleted |
| Detailed time and chore history | 12 months, after that only as a summary that cannot be related to a person |
| Declined or expired invitations | 30 days |
| Pairing codes | 7 days after expiry |
| Unused child devices | 90 days, after which pairing has to be repeated |
| Technical logs | 30 days |
| Pseudonymised security logs | 12 months |
| Visitor statistics | 395 days; the link to a visitor already ends with the day |
| Generated export files | 24 hours |
| A contact message that could not be delivered | at most 30 days on our server; in the ticket system for as long as the case is being handled |
| Evidence of cancellation and withdrawal | 3 years — it has to outlast a dispute about when the contract ended |
| Invoices and accounting records | for the statutory retention periods (section 147 AO, section 257 HGB), regardless of an account deletion |
After the trial or the subscription ends, the data stays readable and exportable for 90 days. We send a reminder 30 and 7 days before the planned deletion. Cancelling on its own deletes nothing.
On deletion we remove the active data within 30 days; it rolls out of the backups within at most 35 days.
9. Your rights
You have the following rights in relation to the controller:
- Access to the data processed (Art. 15 GDPR),
- Rectification of inaccurate data (Art. 16 GDPR),
- Erasure (Art. 17 GDPR),
- Restriction of processing (Art. 18 GDPR),
- Data portability (Art. 20 GDPR),
- Objection to processing based on Art. 6(1)(f) GDPR (Art. 21 GDPR),
- Withdrawal of a consent with effect for the future (Art. 7(3) GDPR).
Access, export and deletion are built in: under "Data" you can download the history per child and the whole family as a file, and request deletion of a child profile or of the family. The full export and the family deletion ask for your password again. Both keep working when no subscription is running.
You can also simply write to kidsplaytimer-foa6uj@1stlevel.tech.
Right to complain
You may lodge a complaint with a data protection supervisory authority (Art. 77 GDPR), in particular in the member state of your residence, your place of work or the alleged infringement. The authority responsible for us is:
Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-WestfalenKavalleriestraße 2–4, 40213 Düsseldorf
https://www.ldi.nrw.de
10. No automated decisions
There is no automated decision making in individual cases, including profiling, within the meaning of Art. 22 GDPR. The application calculates times and stars from the rules you set yourselves; it does not judge a child and does not derive characteristics from behaviour.
11. Cookies and local storage
KidsPlayTimer sets no cookies for advertising or analytics — the visitor statistics (section 3 j) work without them. That is also why there is no consent banner: what is set is strictly necessary to operate the service (section 25(2) no. 2 TDDDG).
| Name | Purpose | Duration |
|---|---|---|
kidsplaytimer-session |
Keeps you signed in and remembers the chosen language during the visit | 120 minutes after the last activity |
XSRF-TOKEN |
Protection against forged form submissions | as above |
kpt_child_device |
Remembers a paired child device so the child area works without signing in | 90 days; "revoke access" ends it immediately |
If we use a delivery network (see section 6), its provider may set its own strictly necessary cookie to fend off automated requests. It is not used for advertising and not for cross-site tracking.
In your browser's storage the application also keeps what it needs to work offline (the installable version, cached interface files and your display settings). The areas holding family content are deliberately not cached.
12. Security
The connection is encrypted throughout. Passwords and PINs are stored only as a non-reversible hash, as are pairing codes and device tokens. Access is limited to the family in question and checked on the server with every request; a request about another family is answered without revealing that it exists. Sensitive actions such as the full export require signing in again.
13. Changes to this policy
When the application changes, this text changes with it. The version published here, with the date given above, is the one that applies. We point out substantial changes inside the application.