PARENTSY PRIVACY POLICY
Last updated: 10 August 2026 Version: 1.4
This Privacy Policy explains how personal data is processed when you use the Parentsy mobile app for iOS and Android and the technically necessary web interfaces used for sign-in, legal notices, support and Account deletion.
Registered Parentsy Accounts and interactive functions are reserved for individuals aged 18 or over. Suitable app-public content may be read without an Account and without an age check. Parentsy does not provide child Accounts. Because users may voluntarily provide information about their family, children, pregnancy or health, we treat such information with particular care and provide additional visibility and consent choices where appropriate.
1. Controller
The controller within the meaning of the General Data Protection Regulation (“GDPR”) is:
Parentsy group ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε.
ΑΛΕΞΑΝΔΡΟΥΠΟΛΕΩΣ 20 11527 ΑΘΗΝΑΙΩΝ Greece
G.E.MI. No.: 193668503000 VAT No.: 803279075 Tax Office: KEFODE Email: contact@parentsy.app
referred to below as “Parentsy”, “we”, “us” or “our”.
Please direct data-protection requests to privacy@parentsy.app.
2. Scope and important information about visibility
This Privacy Policy primarily describes processing under the GDPR and applicable Greek data-protection law, in particular Law 4624/2019 and, for electronic communications and access to terminal equipment, Law 3471/2006. Any additional mandatory privacy rights of users outside the European Economic Area remain unaffected. Supplementary privacy notices may apply in individual countries, or functions may be restricted by region.
2.1 Services covered
This Privacy Policy applies to:
the Parentsy app for iOS and Android;
technically necessary sign-in, legal-notice, support and Account-deletion pages;
guest and registered use;
Communities, posts, comments, Safe Spaces, Organize Rooms and direct messages;
Parent Discovery and approximate local functions;
reporting, moderation, support and feedback;
push notifications and optional analytics and diagnostic functions.
2.2 App-public content
Content with the visibility setting “everyone”, “public” or a comparable setting may be accessed inside the Parentsy app by technical guest sessions and registered users without a preceding age check, displayed with your display name or nickname and Community association, shown in app feeds or in-app recommendations, copied by other users, captured in screenshots or shared outside Parentsy.
Legal notices and contact, support and Account-deletion information may be available without a user Account.
Please do not publish personal data about children or other individuals where you are not authorised to do so or where the selected visibility is unnecessary.
2.3 Access-restricted does not mean absolutely confidential
Safe Spaces, Organize Rooms and direct messages are technically access-restricted. Other authorised members can nevertheless copy, photograph, screenshot or share content outside Parentsy. Parentsy cannot completely prevent this.
Direct messages and Room content should not be understood as end-to-end encrypted unless the app expressly states otherwise. Our systems and appointed infrastructure providers must be able to process the content technically. Particularly sensitive secrets, access credentials, identity documents, full addresses and unnecessary health data should not be transmitted through Parentsy.
3. Overview of legal bases
We process personal data only where a legal basis applies. Depending on the processing, the following legal bases may apply in particular:
Article 6(1)(b) GDPR – contract or steps before entering into a contract: provision of the Parentsy functions you request, the Account, publication, communication, Rooms and support.
Article 6(1)(a) GDPR – consent: optional analytics, crash diagnostics, device location, certain profile-visibility settings, special categories of personal data and, where applicable, advertising.
Article 6(1)(f) GDPR – legitimate interests: IT security, prevention of abuse and fraud, moderation, enforcement of our rules, protection of users and children, improvement of core functions that do not rely on consent, and the establishment, exercise or defence of legal claims.
Article 6(1)(c) GDPR – legal obligation: compliance with statutory disclosure, retention, reporting or platform obligations.
Article 6(1)(d) GDPR – vital interests: exceptionally, where there is a specific and serious threat to life or physical integrity.
Parentsy does not normally process special categories of personal data. Where data provided by a user includes special categories within the meaning of Article 9(1) GDPR, depending on the circumstances we additionally rely in particular on:
your explicit consent under Article 9(2)(a) GDPR;
Article 9(2)(e) GDPR, where you have clearly made your own data public yourself; or
Article 9(2)(f) GDPR, where processing is necessary for the establishment, exercise or defence of legal claims.
The specific purposes and legal bases are described below.
4. Processing activities in detail
4.1 Guest access and technical guest session
Suitable app-public content may be read without registration and without an age check. When you choose guest use or first request backend content required for it, Parentsy may create or restore a technical guest session so that the content can be delivered securely and safety rules can also be applied to guests.
For this purpose, we process in particular:
a randomly generated local guest identifier;
a technical Firebase user identifier;
session and authentication information;
IP address, timestamps, app version, operating system and technical request information;
security and App Check signals.
The random guest identifier is stored in the app’s local storage on the device and generally remains until the app is uninstalled, app data is deleted, a reset occurs or the guest session is converted to a registered Account. On conversion, the same technical user identifier may continue to be used so that data already associated with the guest is not lost.
No age-assurance data, date of birth, identity-document copy, biometric age estimate or external age token is processed for ordinary guest reading.
Purposes: providing guest use and app-public content, session stability, access control, preventing abuse and IT security. Legal basis: Article 6(1)(b) GDPR where guest use is requested and Article 6(1)(f) GDPR for the secure and abuse-resistant provision of app-public content and infrastructure. Local device access: storage of the identifier required for the guest session is technically necessary for the requested or clearly provided guest function, taking account of Greek Law 3471/2006 and the applicable national implementation of ePrivacy requirements. Retention: locally until one of the events described above; inactive technical guest Accounts are deleted or irreversibly disassociated after twelve months without activity, unless security or legal reasons require otherwise.
4.2 Registration, sign-in and Account linking
For registered Accounts, and depending on the chosen sign-in method, we process:
Firebase user identifier;
email address;
sign-in provider and linking status;
email-verification status;
sign-in and security timestamps;
information about magic links and technical sign-in processes;
for Google Sign-In, basic Account data released by Google;
for Sign in with Apple, data released by Apple, noting that Apple may provide name and email only on the first sign-in;
the 18+ self-declaration made through the account-creation action, age-policy version, declaration method, registration flow, authentication provider, language, app version and server timestamp;
the accepted Terms version and document hash, together with the version of the Privacy Policy made available during the account-creation flow.
The 18+ self-declaration is made by successfully completing creation of a new Account after an immediately displayed notice. It is not verified proof of age or identity. For this launch requirement, we do not request a date of birth, identity-document copy, biometric age estimate or external age token. An optional date of birth entered later in the profile is a separate profile field and is not used as proof that the Account holder meets the contractual minimum age. If a social-auth or magic-link action only signs the user into an existing Account, the provider dialogue is cancelled or the flow fails, we do not record a new Terms acceptance or age declaration as a result.
Magic links and comparable sign-in links are confidential. We seek to prevent the tokens they contain from being recorded in analytics, support or diagnostic logs.
Purposes: checking the contractual Account requirement, documenting the self-declaration, making the legal documents available, demonstrating acceptance of the Terms, creating the Account, sign-in, Account recovery, provider linking, prevention of duplicate Accounts and Account security. Legal basis: Article 6(1)(b) GDPR for registration, the Account and the contractual age requirement; Article 6(1)(c) and (f) GDPR for necessary compliance, evidence, security and prevention of abuse. Retention: Account and authentication data until Account deletion; security-related sign-in records generally for up to 90 days and, for specific abuse or security cases, for as long as necessary for investigation and the establishment, exercise or defence of legal claims. Terms, privacy-information and age-declaration evidence is retained in accordance with sections 4.20 and 12.
Google and Apple also process data under their own responsibility in connection with their respective sign-in services. Their privacy information applies in addition.
4.3 Profile and master data
You may provide in particular the following profile data:
nickname or display name;
profile image;
parent or caregiver role and, where applicable, gender or audience information;
optional biography;
optional date of birth;
languages, interests and contact or activity preferences such as “open to”;
approximate location area.
We distinguish between your private profile document and a reduced, app-visible profile projection. The information shown to other users depends on the relevant function and your visibility settings. The private profile document is generally accessible only to you and specially authorised Parentsy administrators. Reduced app-visible profile data may be accessible to app sessions, including technical guest sessions, where this is provided for public profiles or content.
Purposes: profile display, suitable Communities, access to audience-protected areas, personalisation, communication and Parent Discovery. Legal basis: Article 6(1)(b) GDPR. For wholly optional visibility or Discovery settings, processing may be based on Article 6(1)(a) GDPR. Retention: until amendment, removal or Account deletion; app-visible profile projections are generally removed within 30 days after deactivation or Account deletion.
4.4 Information about children, pregnancy and family stage
You may optionally provide data concerning your children or a pregnancy, in particular:
child’s name
status “born” or “expected”;
date of birth or estimated due date;
gender;
a broad child or family stage derived from that information;
where applicable, number of children.
The raw data, including your child’s name, exact date of birth or due date and gender, is stored only in your private profile. This information is used to keep your profile synchronised across your devices and to calculate your child’s age and broad stage correctly, and it is not shown publicly by default. Depending on an express visibility setting, you may separately choose to show limited information on your public profile or in Parent Discovery, such as the number of children, broad child or family stage, or gender. Your child’s name and exact date of birth or due date are never shown publicly, regardless of your visibility settings.
Information about pregnancy, health or development may constitute special categories of personal data. Before storing or using such optional information, we obtain explicit consent where required. You may withdraw consent for the future at any time and delete the information or disable its visibility.
You may separately choose to mention your children, or upload photos of them, in posts, Communities, Rooms or chats. This voluntary content is user-generated content and is governed by the general publication and visibility rules described elsewhere in this Policy, including sections 2.2, 4.6 and 7, rather than by the structured profile fields described in this section.
You may provide data about children or other individuals only where you are legally entitled to do so. Please do not use children’s full names, exact addresses, school or class details, regular routes, pick-up times, access codes or unnecessary health information.
Purposes: voluntary personalisation, keeping your profile synchronised across your devices, calculating your child’s age and broad stage, suitable content and Communities, optional Parent-Discovery attributes and profile display requested by you. Legal basis: Article 6(1)(a) or (b) GDPR; for special categories, additionally in particular Article 9(2)(a) GDPR. Retention: until the information is deleted, consent is withdrawn or the Account is deleted.
4.5 Parent Discovery and recommendations of other parents
Where you enable Parent Discovery, other registered users may be suggested based on profile characteristics you have chosen to share. Factors may include in particular:
approximate location area;
interests and languages;
voluntary “open to” information;
derived child stage;
profile completeness;
approximate recent activity;
blocks and security restrictions.
You can control whether you appear in Parent Discovery and whether area, child stage or “open to” information is shown. Precise movement or residential coordinates are not stored for this purpose.
Purposes: finding suitable contacts and local networking. Legal basis: Article 6(1)(b) GDPR for the enabled function; optional visibility and location use may be based on Article 6(1)(a) GDPR. Retention: until the underlying data changes, Discovery is disabled or the Account is deleted.
4.6 Communities, posts, comments and app display
When you use Communities, we process in particular:
Communities you create or follow;
posts, titles, text, images and comment histories;
post type, audience and Community association;
display name, user identifier and timestamps;
optional approximate location snapshot;
moderation and visibility status.
A post may be assigned to several suitable Communities based on its content, Community metadata, audience and approximate location context. A similarity check may point to comparable existing posts.
App-public content may be read by technical guest sessions and registered users without a preceding age check and shown in app feeds, Community views, profiles or in-app recommendations. Safe-Space content, private Rooms and direct messages are not included in app-public feeds.
Purposes: publication and display according to your visibility choice, Community communication, in-app discoverability, moderation and prevention of abuse. Legal basis: Article 6(1)(b) GDPR; moderation and security under Article 6(1)(f) or (c) GDPR. Article 9(2)(e) GDPR may additionally apply where you voluntarily make your own special-category data app-public; for protected sensitive content, we obtain explicit consent where required. Retention: until the content or Account is deleted, subject to the disassociation, moderation and retention rules described in section 13.
4.7 Safe Spaces
Safe Spaces restrict access according to defined audience and profile rules, for example to Moms or Dads. For this purpose, we process the parent-role or audience information necessary to assess eligibility, as well as membership and access data.
Safe-Space content is not published outside the intended protected area of the app. For analytics events, Safe-Space content identifiers are reduced where technically provided for; this does not guarantee complete anonymity from Parentsy.
Purposes: eligibility checks, protected discussion, moderation and prevention of abuse. Legal basis: Article 6(1)(b) GDPR; optional sensitive information or content additionally on the basis of consent under Article 6(1)(a) and, where applicable, Article 9(2)(a) GDPR; security under Article 6(1)(f) GDPR. Retention: membership until leaving or Account deletion; content under the general content rules.
4.8 Organize Rooms, threads, messages, polls and events
In private Organize Rooms, we process in particular:
Room ID, name, description, invitation and membership data;
roles and administrator permissions;
threads, messages, replies, pins and images;
polls and votes;
events, dates, RSVP status and aggregated participant numbers;
safety, moderation and audit data.
Under the intended access rules, Room content is accessible only to members and specially authorised Parentsy administrators. Invitation codes or links may allow people to join; a recipient may be able to forward such a link. Room administrators manage membership but do not automatically receive access to confidential platform reports outside their remit.
Purposes: private group organisation, communication, scheduling and participant coordination, safety and moderation. Legal basis: Article 6(1)(b) GDPR; security and prevention of abuse under Article 6(1)(f) GDPR. Retention: until deletion by authorised users, dissolution of the Room or Account deletion; on Account deletion, direct attribution to the author may be removed while the contribution remains under section 13.
4.9 Direct messages
For direct messages, we process:
participant identifiers;
message content and, where applicable, images;
timestamps and delivery or status information;
block, report and moderation information.
Only participants in the relevant thread should be able to read direct messages. Parentsy may have reported or otherwise safety-relevant messages reviewed by specially authorised individuals to the extent necessary for moderation, support, prevention of harm or compliance with legal obligations.
Purposes: communication between participants, safety, blocking and reporting. Legal basis: Article 6(1)(b) GDPR; security and moderation processing under Article 6(1)(f) or (c) GDPR. Retention: until the thread or content is deleted as provided; on Account deletion, attribution to the author may be removed while messages may remain to preserve the course of the conversation. Any statutory right to erase personal content remains available.
4.10 Interactions, memberships and blocks
We process likes, bookmarks, Community follows, Room memberships, RSVP details, blocks and comparable interactions.
Purposes: requested interactions, personalisation, Community state and functionality, and protection against unwanted contact. Legal basis: Article 6(1)(b) GDPR; anti-abuse measures under Article 6(1)(f) GDPR. Retention: until withdrawal, deletion of the underlying content or Account deletion; security blocks may be retained in limited form to prevent circumvention.
4.11 Approximate location and local functions
If you enable location functions, the app may briefly process device coordinates while in use. These are passed to the operating system’s native geocoder to derive an approximate area.
For user locations, Parentsy generally stores only:
city;
country or country code;
area or sub-locality;
an approximate geohash with limited precision.
We do not store a user’s street, house number or postal code as part of the described location profile and do not maintain a continuous location history. There is no background location tracking. The current approximate resolution may be cached in memory for up to ten minutes.
Depending on the function, you may use a stored profile area or the device’s currently resolved approximate area. The operating system may separately request location permission.
Purposes: local feeds, Parent Discovery, assignment to suitable Communities or posts and optional local networking. Legal basis: consent under Article 6(1)(a) GDPR for device location; storage of an approximate profile area chosen by you additionally under Article 6(1)(b) GDPR. Retention: device coordinates only for resolution and the short memory cache; approximate profile area until amendment, deletion or Account deletion.
The native geocoder and operating system may process data under their own responsibility. The privacy settings and notices of the device or operating-system provider apply.
4.12 Reports, moderation and platform complaints
When a report or moderation case is handled, we may process:
report ID, target type and target identifier;
reason for the report and optional free text;
status, timestamps and processing steps;
user identifier, display name and email address of the reporter;
necessary information about the reported individual or Account, including user identifier, display name, email address, parent role or audience information, and membership-since date;
reported content and necessary evidence preservation;
moderation decisions, reasons, sanctions, appeals and audit trail.
Canonical reports containing the reporter’s identity are generally accessible only to the reporter and specially authorised Parentsy administrators. Where relevant, Community administrators receive only a server-side redacted projection without the reporter’s identity or free text. Sensitive reports and reports concerning Community owners or administrators remain exclusively with platform moderation.
Reports and moderation cases are transferred to Atlassian Jira Service Management so that they can be handled, escalated and documented in a structured manner. The identification, Account, content and case data listed above may be transferred to Atlassian. The ticket reference is stored in the Parentsy system.
We may preserve reported content even where it is no longer visible in the app where this is necessary for investigation, protection of affected individuals, handling an appeal, compliance with a legal obligation or the establishment, exercise or defence of legal claims.
Purposes: handling reports, moderation, protecting users and children, combating illegal content, fraud and abuse, evidence and legal defence. Legal basis: Article 6(1)(f) GDPR; Article 6(1)(c) GDPR for statutory platform, disclosure or reporting obligations; where applicable in emergencies, Article 6(1)(d) GDPR. Where special categories are involved, in particular Article 9(2)(f) GDPR or relevant consent. Retention: generally until the end of the third calendar year following closure of the case. Longer, regularly reviewed retention may be necessary for repeated abuse, pending appeals, serious security or child-safety cases, litigation or statutory obligations.
4.13 Support and feedback
If you contact support or send feedback, we process in particular:
title, category and message text;
attachments, where provided;
user identifier, email address and display name;
app version, platform, device data and timestamps;
support history and processing status.
Support and feedback data may be processed in Firestore and Atlassian Jira Service Management. Please do not send unnecessary health data, child data, passwords or complete identity documents.
Purposes: handling your request, troubleshooting, product improvement and evidence. Legal basis: Article 6(1)(b) GDPR for contract-related requests; Article 6(1)(f) GDPR for general feedback, quality and legal defence. Retention: generally 24 months after final closure of the request; longer only where a continuing need, legal obligation or dispute exists.
4.14 Push notifications
With your device permission, Parentsy may send push notifications through Firebase Cloud Messaging. For this purpose, we process:
FCM token and technical installation identifier;
platform and device category;
notification type and destination within the app;
depending on the notification, display name or text preview;
delivery and error information.
Depending on your operating-system settings, content may be visible on the lock screen. Use the device and app settings to disable notifications or previews where other individuals have access to your device.
Purposes: delivering activity, security and function notifications requested by you. Legal basis: consent under Article 6(1)(a) GDPR; necessary security communications may alternatively be sent by email or within the app under Article 6(1)(b) or (f) GDPR. Retention: until deregistration, invalidation, Account deletion or generally after 180 days without device activity. Following a deletion instruction, technical installation identifiers may continue to be processed in accordance with the provider’s backup and deletion cycles.
4.15 Firebase Analytics – only with consent
Parentsy uses Firebase Analytics only where you have first given separate consent. Optional Analytics collection is disabled before consent. You may withdraw consent at any time in the privacy settings.
Depending on use, the following may be collected:
functions accessed and technical events;
app version, platform, device category and approximate technical information;
time, count and interaction values;
user, post, Community, Room or feature IDs;
campaign or source information, where enabled.
For Safe-Space events, content identifiers are reduced or not logged where technically provided for. Search text is not collected as a plain-text analytics value; only the length of a search may be processed. Despite these minimisation measures, Analytics events may constitute pseudonymous personal data.
We configure retention of user-related and event-related Analytics data to two months. Aggregated statistics that can no longer be associated with individual users may be retained for longer for product and business analysis.
Purposes: voluntary usage analysis, identifying errors and funnels, and improving the app. Legal basis: Article 6(1)(a) GDPR and, where information is stored on or read from your terminal equipment, your consent under applicable terminal-equipment privacy rules. Recipients: Google/Firebase and their subprocessors. Retention: user-related and event-related data for two months; evidence of consent under sections 4.20 and 12.
4.16 Firebase Crashlytics – only with consent
Parentsy uses Firebase Crashlytics only where you have first given separate consent. Crashlytics may process in particular:
crash reports, stack traces and error states;
app version, operating system, device model and technical device states;
Crashlytics or Firebase installation identifiers;
time and affected app function;
after sign-in, the Firebase user identifier as a user identifier;
technical custom values set by us for error analysis.
We must not intentionally transmit message text, passwords, Magic-Link tokens, complete email addresses, precise user locations or unnecessary child data as Crashlytics keys or log messages.
Purposes: stability monitoring and diagnosing and fixing technical errors. Legal basis: Article 6(1)(a) GDPR and, where applicable, your consent under applicable terminal-equipment privacy rules. Recipients: Google/Firebase and their subprocessors. Retention: crash and related installation data generally for 90 days in accordance with the retention cycles provided for the service.
4.18 Camera, photo library and sharing
When you select or capture an image for a profile or post, the app accesses the camera or photo library only following your action and subject to the device permission you choose.
When you use the operating system’s sharing function, Parentsy passes the content or link you select to the destination you choose. From that point, the selected third party processes the data under its own terms.
Purposes and legal basis: carrying out the upload or share action selected by you, Article 6(1)(b) GDPR; device permission based on your choice. Retention: uploaded media until the content or Account is deleted; local permissions until changed in the device settings.
4.19 App Check, security logs and prevention of abuse
For security, we use measures including Firebase App Check, server-side access rules, authorisation and membership checks, rate limits, audit data, blocks and authoritative server functions.
The following may be processed:
IP address, timestamps, app version and platform;
technical device, app-integrity and App Check signals;
user and session identifier;
failed access attempts and security-relevant actions;
rate-limit, moderation and abuse signals.
Purposes: protecting Accounts, data, infrastructure and users; detecting and preventing bots, scraping, fraud, spam, security attacks and circumvention of rules. Legal basis: Article 6(1)(f) GDPR; where applicable Article 6(1)(c) GDPR. Our legitimate interest is a secure and functional Community service. Retention: general security logs generally for 90 days; confirmed security incidents and circumvention data for as long as necessary for prevention, investigation and legal defence, subject to regular review.
4.20 Evidence of Terms acceptance, privacy information, age declaration and consent choices
When you successfully complete creation of a new Account and thereby accept the Terms of Use and make the 18+ self-declaration, when the Privacy Policy is made available to you during the account-creation flow, when you give or withdraw an optional consent, or when you change another legally relevant setting, we process in particular:
user identifier;
legal-document, declaration or consent type;
version number and document hash where applicable;
language, registration flow, authentication provider and app version;
server timestamp, declaration method—including the account-creation action—and status;
necessary technical evidence data.
For the Privacy Policy, we record which relevant version was made available during the account-creation flow. This record is neither acceptance of the Privacy Policy nor consent to all processing described in it. Optional consent-based processing is documented separately and remains revocable. A mere sign-in to an existing Account, a cancelled provider dialogue or a failed registration flow does not create new evidence of Terms acceptance or of the 18+ self-declaration.
Purposes: demonstrating conclusion of the contract, acceptance of the Terms, fulfilment of transparency obligations, the contractual 18+ self-declaration and your optional consent choices. Legal basis: Article 6(1)(b), (c) and (f) GDPR. Retention: while the Account exists and generally until the end of the third calendar year after Account deletion, rejection or withdrawal; longer where a dispute or statutory obligation is pending.
4.21 Publicly accessible legal, contact and support area
When you access the publicly available legal, contact, support or Account-deletion area, the following may be processed in particular: IP address, time, requested resource, browser or device information, referrer and security logs.
This area contains only the information necessary for legal notices, contact, support and Account deletion.
Purposes: providing legally and contractually required information, support, Account deletion, IT security and error analysis. Legal basis: Article 6(1)(b), (c) and (f) GDPR. Our legitimate interest is the secure and demonstrable provision of this information and these contact routes. Retention: ordinary server logs generally for 30 days; security-relevant logs under the periods in section 12.
5. Legitimate interests and balancing of interests
Where we rely on Article 6(1)(f) GDPR, we pursue in particular the following interests:
providing a secure, stable and abuse-resistant service;
protecting users, children, employees and third parties;
detecting fraud, spam, grooming, harassment, illegal content and circumvention of rules;
moderation and enforcement of the Terms of Use;
preserving the context of Community discussions after Account deletion;
handling and evidencing complaints, reports and security cases;
establishing, exercising and defending legal claims;
protecting our infrastructure and economic viability.
In balancing interests, we consider in particular the nature of the data, visibility, users’ reasonable expectations, the particular vulnerability of children, possible consequences of processing and available safeguards. Where your interests, fundamental rights or freedoms override our interests, we do not process the data on this basis.
6. Special categories of personal data
Parentsy is not a health record or medical service and does not normally collect or process special categories of personal data. Free-text content and protected Communities may nevertheless contain information about pregnancy, fertility, childbirth, physical or mental health, disability, religion, sexuality or other specially protected matters.
The following principles therefore apply:
Structured sensitive information is voluntary and used only for clearly identified functions.
Where required, we obtain explicit consent before processing.
Private or Safe-Space content is not used for personalised advertising.
Direct messages and protected content are not used as advertising-profile or lookalike signals.
Sensitive content is not published outside the in-app audience chosen by the user and is not used for advertising or general profiling.
Data about other individuals may be entered only with sufficient authority.
In reporting and legal cases, sensitive information may be processed and preserved to a limited extent for safety or legal defence.
You may withdraw consent at any time for the future. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Data about children and other third parties
Parentsy does not provide registered Accounts to minors; registered Accounts and interactive functions are reserved for individuals aged 18 or over. Suitable app-public content may be available without registration and without an age check. We do not intentionally request profile, family or content data directly from children. Users may nevertheless voluntarily provide information about their own children or children in their care.
Anyone who provides data about a child or another person confirms that they are legally entitled to do so. Parents, persons with parental responsibility or other data subjects may contact us at privacy@parentsy.app if they believe data about them or a child is being processed without authorisation.
We review such requests and erase, correct or restrict data where the statutory conditions are met. To prevent abusive deletion requests, we may request reasonable evidence of identity or parental responsibility.
This section addresses information that you or other users choose to include in posts, comments, Rooms, direct messages or other content. It does not affect the structured child-profile fields described in section 4.4, which are private by default; your child’s name and exact date of birth or due date are never made public, regardless of your visibility settings.
Please do not publish in particular:
children’s full names and exact dates of birth;
residential addresses, real-time locations or regular routes;
school, nursery, class, pick-up times or access codes;
intimate images or unnecessary health data;
photographs or other content that reveal a child’s exact location, school, routine or other identifying details, unless you are authorised and it is appropriate to share them;
data about another person’s child without authorisation.
More generally, we encourage caution before sharing any photo of a child, even where this is permitted. Photos can reveal more than intended – faces, school uniforms, house numbers, street signs or other recognisable locations – and, once shared, other users in that space may save, screenshot or forward them, including in access-restricted areas such as Safe Spaces, Rooms or direct messages (see section 2.3). Where possible, consider cropping or blurring identifying details, avoiding images that reveal a child’s school, routine or exact location, and sharing only with audiences you trust. The app will show a reminder of this kind when you attach a photo in Communities, Rooms or chats.
8. Sources of personal data
We obtain personal data:
directly from you during registration, profile management, publication, communication, reporting or support;
from your device and the app, such as technical data, location following permission or push tokens;
from Google or Apple where you use their sign-in service;
from other users, for example where they mention you, communicate with you or report you;
from automated inferences, such as broad child stage, rankings, risk or moderation signals;
from authorities, rights holders or other notice providers where they submit legally relevant information to us.
Where data was not collected directly from you, we provide information in accordance with Article 14 GDPR unless a statutory exception applies, in particular where provision of the information would be impossible or disproportionate or would endanger the rights of others.
9. Recipients and categories of recipients
9.1 Other app users
Depending on your visibility choice, profile information and content are disclosed to:
technical guest sessions and registered app users;
members of particular Communities, Safe Spaces or Rooms;
participants in direct messages;
Community or Room administrators within their permissions;
individuals to whom other users pass screenshots, quotations, exported content or app links.
Regardless of your visibility choice, your child’s name and exact date of birth or due date (see section 4.4) are never disclosed to other users under this section.
9.2 Parentsy personnel and appointed persons
Specially authorised employees, moderators and service providers receive access only to the extent necessary for operation, support, security, moderation, legal compliance or administration. Access is restricted by role and, for sensitive actions, logged where provided for.
9.3 Google/Firebase
Depending on the function enabled, we use in particular:
Firebase Authentication;
Cloud Firestore;
Cloud Storage;
Cloud Functions;
Firebase Cloud Messaging;
Firebase App Check;
Firebase Analytics with consent;
Firebase Crashlytics with consent;
Google Sign-In;
potentially, at a later date, Google AdMob and UMP.
Depending on the service and contractual configuration, Google Cloud EMEA Limited, Google Ireland Limited, Google LLC and their subprocessors may process data. Cloud Functions are configured in the project in the europe-west3 region. This does not mean that all Google or Firebase data is processed exclusively within the European Economic Area. In particular, authentication, support, security, analytics, diagnostics or global infrastructure data may be processed outside the EEA.
Google processes part of the services as our processor and certain services or data under its own responsibility. The allocation of roles depends on the service and contractual terms.
9.4 Apple
For Sign in with Apple and on Apple devices, Apple Distribution International Limited, Apple Inc. and affiliated companies may process the data required for sign-in, push infrastructure, app-store operation and device functions. Depending on the function, Apple acts under its own responsibility or as a technical provider.
9.5 Atlassian Jira Service Management
We use Jira Service Management for reports, moderation, support and feedback. Atlassian Pty Ltd, affiliated Atlassian companies and subprocessors may process the data listed in sections 4.12 and 4.13 as processors. Data region, subprocessors and international transfers depend on our Atlassian contract and chosen configuration.
9.6 Operating-system, device and selected third-party providers
For native geocoding, push delivery, camera, photo library or sharing, Apple, Google or a third party chosen by you may process data under its own responsibility.
9.7 Authorities, courts, advisers and corporate transactions
We may disclose data:
where required by law;
to prevent a specific threat;
to courts, authorities or law-enforcement bodies;
to lawyers, insurers, auditors or other advisers subject to professional confidentiality;
in connection with financing, restructuring, a merger, acquisition or sale, where legally permitted and protected by appropriate safeguards.
9.8 No sale of personal data
We do not sell personal data. Disclosure to service providers for the purpose of providing the functions described is not a sale.
10. International data transfers
Some recipients or subprocessors are located outside the European Economic Area or access data from outside it. This may apply in particular to Google/Firebase, Apple and Atlassian services.
Depending on the recipient, we base such transfers on:
an adequacy decision of the European Commission under Article 45 GDPR, including the EU-U.S. Data Privacy Framework where the relevant U.S. recipient is validly certified;
the European Commission’s Standard Contractual Clauses under Article 46(2)(c) GDPR;
supplementary technical and organisational safeguards;
exceptionally, a statutory derogation under Article 49 GDPR.
Where we rely on the EU-U.S. Data Privacy Framework, we check and document that the relevant U.S. recipient is validly certified at the time of transfer. For recipients or processing not covered, we use the Standard Contractual Clauses provided for in the relevant data-processing agreement and, where necessary, supplementary safeguards.
A copy or summary of the relevant safeguards may be requested at privacy@parentsy.app, insofar as this does not adversely affect trade secrets or third-party rights.
11. Automated processing, ranking and moderation logic
Parentsy uses automated or rule-based systems in particular for:
assigning posts to Communities based on audience, terms, metadata and approximate location context;
identifying similar posts;
ranking Home, Nearby and Parent-Discovery content;
recalculating aggregated counters;
redacted forwarding of certain reports to competent Community administrators;
removing unsuitable content from in-app feeds, search surfaces and recommendations.
Material ranking factors may include recency, Community relevance, voluntary interests, approximate location, language, interaction, profile completeness and security restrictions. Content from direct messages and private Rooms is not used as a basis for personalised advertising.
You may challenge a moderation decision through contact@parentsy.app or the designated in-app function.
12. Retention periods and deletion concept
We store personal data only for as long as necessary for the relevant purpose, while consent remains valid, or where statutory or legitimate retention reasons apply. The following periods apply in particular:
The following exceptions apply:
For pending disputes, security cases, circumvention of restrictions or statutory obligations, we retain necessary data until completion and expiry of relevant limitation or retention periods.
Data in backups is excluded from normal product access and overwritten or deleted according to the defined backup cycles. Depending on the Google service, complete removal from live and backup systems may take up to 180 days after an effective deletion instruction.
Recipients, screenshots, quotations or other copies made by users may remain outside our control for longer.
Fully anonymised data that can no longer be associated with an individual is no longer subject to the GDPR and may be retained for statistics or product planning.
13. Account deletion and treatment of existing content
You may initiate Account deletion through the function provided in the app or through the external Account-deletion page linked in the app-store listings and in the app. Alternatively, contact privacy@parentsy.app. Fresh authentication is required to protect against misuse.
The technical deletion process includes in particular:
removal of the public profile;
deletion of user-related files in the designated user-storage area;
removal of memberships, bookmarks, likes, tokens and notifications;
disassociation or replacement of author fields in posts, comments, Room content and direct messages;
replacement of the private profile with a limited deletion tombstone;
subsequent deletion of the authentication Account.
To preserve understandable conversation histories, content may remain after direct Account and profile attribution has been removed. This disassociation does not necessarily mean that every free-text item is fully anonymous. If you included identifying information in content, you may delete the content yourself before Account deletion or later ask us to review the specific content.
Reporting, moderation, security, support and legal-case data is not automatically deleted in full with the Account where it is needed to protect others, comply with legal obligations or establish, exercise or defend legal claims. We limit such data to what is necessary and apply the periods in section 12.
Account deletion is generally implemented in the operational Parentsy system within 30 days. Different provider and backup cycles remain unaffected.
14. Your data-protection rights
Subject to the statutory conditions, you have the right to:
access under Article 15 GDPR;
rectification of inaccurate data under Article 16 GDPR;
erasure under Article 17 GDPR;
restriction of processing under Article 18 GDPR;
data portability under Article 20 GDPR;
object under Article 21 GDPR;
withdraw consent under Article 7(3) GDPR;
receive information about automated decisions and exercise rights under Article 22 GDPR, where applicable;
lodge a complaint with a data-protection supervisory authority under Article 77 GDPR.
You can amend or delete many details directly in your profile. Consent and optional visibility choices can be managed in the privacy settings. For further requests, contact privacy@parentsy.app.
We may request information necessary to confirm your identity. We use it only to handle the request. The statutory rights of other individuals, confidential reporting data and statutory exceptions may limit the scope of access or erasure.
We generally respond to requests within one month. For complex or numerous requests, the period may be extended to the extent permitted by law; we will inform you in good time.
15. Withdrawal of consent
Consent may be withdrawn at any time for the future, in particular through the Parentsy privacy settings or by email to privacy@parentsy.app.
Withdrawal must be as easy as giving consent. Following withdrawal, we stop the relevant future processing and arrange for deletion or disassociation of data based solely on consent, unless another legal basis or retention obligation applies.
Withdrawal does not affect the lawfulness of processing based on consent before its withdrawal.
16. Right to object
16.1 Objection on grounds relating to your particular situation
Where we rely on Article 6(1)(e) or (f) GDPR, you have the right to object at any time on grounds relating to your particular situation. We will then no longer process the relevant data unless we demonstrate compelling legitimate grounds that override your interests, rights and freedoms, or processing is necessary for the establishment, exercise or defence of legal claims.
16.2 Direct marketing
You may object at any time, without giving reasons, to the processing of personal data for direct marketing. Parentsy does not use data from child, pregnancy, Safe-Space, Room, direct-message, reporting or moderation areas for personalised direct marketing;
Please send objections to privacy@parentsy.app.
17. Requirement to provide data
Without certain data, individual services cannot be provided:
For an Account, we need a technical user identifier, the 18+ self-declaration and, depending on the login method, an email or provider identifier.
For publication, we need the content, audience, author attribution and timestamp.
For Rooms and direct messages, we need membership or participant information.
For security and legal obligations, we need certain log and moderation data.
Profile biography, interests, child or pregnancy data, current device location, Parent Discovery, Analytics, Crashlytics and marketing communications are not required for basic Account use unless the specific function transparently states otherwise.
18. Security
We use appropriate technical and organisational measures, including:
encrypted transmission;
encryption of stored data as provided by the infrastructure provider;
role-based and rule-based access control;
server-side membership, participant, audience and administrator checks;
Firebase App Check for security-relevant server functions;
separate private and app-visible data projections;
limited location precision;
rate limits and protection against abuse;
redacted report projections for Community administrators;
audit trails for moderation measures;
tests of key access and exploit paths;
protection of administrative access and restricted access rights.
No system is absolutely secure. Please protect your email Account and device, treat Magic Links as confidential and report suspicious access without delay to contact@parentsy.app.
Where a personal-data breach occurs, we assess the risk and notification obligations and inform supervisory authorities and affected individuals in accordance with applicable law.
19. Competent supervisory authority
You may lodge a complaint with any competent data-protection supervisory authority, in particular the authority at your place of residence, place of work or the place of the alleged infringement.
The supervisory authority generally competent for Parentsy is:
Hellenic Data Protection Authority (HDPA) Kifissias 1–3 115 23 Athens Greece Email: contact@dpa.gr Website: www.dpa.gr
20. Changes to this Privacy Policy
We update this Privacy Policy where functions, service providers, processing activities or legal requirements change.
For material changes, we provide clear information in the app, on the legal-notice webpage or by email. Where new processing requires consent, we do not begin it before the relevant consent is obtained.
The current version is available in the app and on the Parentsy legal-notice page. Previous versions are archived appropriately.
21. Data-protection contact
For privacy questions, data-subject rights or notices concerning unauthorised publication of data about children or other individuals:
Parentsy group ΜΟΝΟΠΡΟΣΩΠΗ Ι.Κ.Ε. ΑΛΕΞΑΝΔΡΟΥΠΟΛΕΩΣ 20 11527 ΑΘΗΝΑΙΩΝ Greece G.E.MI. No.: 193668503000 VAT No.: 803279075 Email: privacy@parentsy.app Account deletion: through the external Account-deletion page linked in the app and app-store listings General support: contact@parentsy.app Child safety: contact@parentsy.app, subject “Child Safety”