Privacy Policy
This policy is ready for publication, but the real controller details and privacy/support contact must be entered before go-live.
1. Data controller and contact details
For privacy, data access, correction, deletion or other data-subject requests, you can use the contact above or the Account and data deletion page.
2. Who the service is for
Bimbi Insieme is an organizational service for parents and other authorized adults who share family management. Minors must not create accounts or use the service directly as independent users. Information about children is entered by authorized adults under their responsibility.
3. Data that may be processed
| Category | Examples |
|---|---|
| Account and identifiers | Email address, Firebase UID, family role, email verification status and technical authentication data. |
| Family and child data | Children's names, school/class, useful contacts, voluntarily shared information and data needed to connect both parents to the same family. |
| Calendar and organization | Parenting-day schedule, events, holidays, day requests, swaps, counterproposals, approvals, notes and activity history. |
| Expenses and purchases | Amounts, categories, shares, reimbursements, expense attachments and Premium subscription status. Full card or payment-method details are handled by Google Play and are not stored by Bimbi Insieme. |
| Optional health information | Only when voluntarily entered: pediatrician/doctor, allergies and medical notes. This information is not required to create an account or use the main features. |
| Attachments | Photos, receipts, files and documents voluntarily uploaded by the user. |
| Notifications and technical data | Push tokens, Firebase Installation ID, notification preferences and technical information necessary for security and operation. |
| Optional AI Assistant | Request text, strictly relevant context selected by the app and, when voice is used, audio sent for transcription. |
4. Purposes and legal bases
- Providing the service: authenticating users, creating and managing the family, and synchronizing calendars, expenses, requests and shared information. Processing is necessary to provide the requested service and manage the user relationship.
- Security and abuse prevention: email verification, anti-abuse limits, access controls, technical logs and infrastructure protection. Processing is carried out for service security and applicable compliance obligations.
- Service notifications: sending alerts about requests, calendars, expenses, events and account security. Push notifications can be disabled in settings.
- Premium features and purchases: verifying subscription status and enabling features purchased through Google Play.
- AI Assistant: only after separate user activation, processing text or voice requests. Activation can be withdrawn from the app.
- Optional health information: processed only when the user chooses to enter it so it can be made available to the other authorized parent. Before saving new or changed medical information, the app asks the user to confirm that they are authorized to share it and that it is limited to what is necessary. If it is not needed, users are advised not to enter health information.
No behavioral advertising: the current version does not integrate advertising networks, Firebase Analytics or advertising profiling.
5. Sharing within the family
Data saved in the family space is visible to other authorized members of the same family. This sharing is an essential feature of the service and is initiated by users who create or accept the family connection. The family code must not be shared with unauthorized people.
6. Service providers and recipients
- Google Firebase / Google Cloud: authentication, database, server functions, hosting, push notifications and security tools.
- Google Play: management of Android subscription purchases and renewals. Bimbi Insieme receives the identifiers and status needed to verify Premium entitlement, not full card details.
- OpenAI: only for the AI Assistant when enabled by the user. The app sends only information selected as relevant to the request; voice audio is used for transcription and is not stored in the family database.
Providers may process data as processors/service providers or under their respective contractual roles. Data is not sold to advertisers.
7. International transfers
Some providers may process data outside the European Economic Area. Where applicable, such transfers are governed by the safeguards required by law, including adequacy decisions and/or standard contractual clauses adopted by the providers.
8. Retention
- Account and family data is retained while the account/family remains active or until deletion is requested, subject to applicable retention obligations.
- If a user deletes their account while the other parent remains in the family, shared data needed to maintain the other member's family space may remain available to that member; the departing user's account, personal membership and technical tokens are removed.
- If no other member remains, the family and its related subcollections are deleted together with the account.
- Deletion requests submitted through the public form may be retained for up to 12 months to document handling, verification and completion, then deleted unless needed for legal protection or legal obligations.
- Technical and security logs are retained for limited periods according to cloud-service configuration and security needs.
- For AI features, the provider may retain API inputs and outputs for limited periods under the applicable service terms; as of the date of this policy, OpenAI states that many APIs may retain such data for up to 30 days, subject to exceptions and legal obligations.
- Administrative/accounting data that the controller is legally required to retain is kept for the applicable statutory periods and is not used for incompatible purposes.
9. Account and data deletion
Users can start deletion directly in the app from Family → Help, history and data → Account management → Delete my account. Users who can no longer access the app can use the public Account and data deletion page without reinstalling the app. External requests require identity verification before final deletion.
10. Data-subject rights
Where provided by applicable law, data subjects may request access, correction, deletion, restriction, portability and objection to processing, and may withdraw consent without affecting the lawfulness of processing carried out before withdrawal. Requests may be sent to the controller's contact details.
You may also lodge a complaint with the Italian Data Protection Authority (Garante per la protezione dei dati personali) or another competent supervisory authority.
11. Security
Bimbi Insieme uses HTTPS/TLS connections, individual authentication, email verification, Firestore access rules, server functions for sensitive operations, rate limiting, server-side secrets and Firebase security tools. No system is risk-free: in the event of an incident, procedures required by law and the services used are applied.
12. Changes to this policy
If there are material changes to purposes, providers or processing methods, this policy is updated and, where required, the app requests a new acknowledgement/acceptance of the current version.