Privacy policy for My Starday

Last updated: October 2026

We care about your privacy. My Starday collects as little data as possible — only what the app needs in order to work. We do not sell your information and we do not use it for targeted advertising. Sharing with anyone outside the service happens only if you actively choose it (see the report-for-a-conversation section below) or when it is needed to run the service through our processors.

Controller: Papa Bravo AB, via the contact form, is the controller for the processing of your personal data.

What we collect

We process your data on the legal basis of contract (so that we can provide the app and the features you sign up for). We collect the following information about parents and families:

Children’s privacy: Children are identified only by a first name (or nickname) and a chosen emoji. We do not collect or store a child’s surname, personal identity number or contact details.

What we do not collect

How we use your data

All data is used only to provide and improve the service:

Sharing with third parties

We do not share your information with third parties for marketing. We use the following processors to run the service. They process data only on our instructions and in line with the GDPR:

Report for a conversation

If you, as a guardian, create a time-limited link to a summary of selected activity and reward statistics for a child, you can share it with an educator or therapist, for example. That happens only because you choose it. You decide what is included and you can revoke the link at any time so that it stops working. The recipient does not need a My Starday account.

If you protect the link with a code, treat that code carefully. Do not send the code and the link in the same message (for example the same SMS or email), so that an unauthorised person is less likely to get both.

Third-party sign-in (Apple and Google)

If you choose to sign in through an external service, we handle the following:

Apple’s and Google’s own privacy policies apply to their own handling of your data.

Push notifications and device tokens

If you turn on push notifications, we store a unique device token (APNs for iOS or FCM for Android) based on your consent, so that we can deliver notifications to the right device. The token is stored against your account.

Tokens are cleared automatically when you sign out, or if the platform reports that the token is invalid (for example after a device change or uninstall). We do not store a device identifier without an active push subscription. To turn push off, use Settings → Push notifications in the app, or the device’s system settings.

How long we keep your data

We keep your data while your account is active. If you delete your account, all data is deleted permanently and immediately (see below).

Delete your account

You delete your account in the app under Settings → Delete account. You confirm the deletion with your password (or verification through third-party sign-in).

Please note: All data is deleted immediately and permanently. This cannot be undone.

The following is removed, and no data remains after deletion:

Storage and security

We aim to store core application data in the EU/EEA where that applies. Some providers may process data outside the EEA; international transfers and the safeguards that apply are described in this privacy policy and reviewed on an ongoing basis. We use encrypted connections (HTTPS) and industry-standard security practices. Passwords are never stored in plain text — we use bcrypt hashing.

Cookies

On our website and in web views, we use:

Your consent choice is stored for up to one year. You can change your choices at any time via the cookie banner or under Settings → Privacy. Child routine data is not sent to advertising platforms. See also Your privacy choices.

Your rights (GDPR)

You have the following rights under the GDPR:

Contact

Questions about how we handle your data? Contact us:

contact form