Privacy Policy
Last updated: 13 September 2026 · GDPR compliantKidBox is an application designed for the shared management of family information — chat, documents, notes, activities and children's health. This policy explains transparently what data we process, why and with whom we share it.
Data Controller: KidBox — Vittorio Scocca · passboxcontact@gmail.com
Data we collect
- Personal information: email, name/alias, profile photo, access credentials, date of birth
- Contacts: names and phone numbers of family and emergency contacts entered by the user
- Family data and content: chat, notes, documents, media, calendar events, to-dos, expenses, children's health data
- Technical data: notification tokens and security logs without identifiable information
- Location data: only when location sharing is explicitly enabled
- Usage data: aggregated in-app actions (e.g. opening a document or a section), without the content of what you view — no titles, text or exact location
Legal basis for processing (GDPR Art. 6)
The processing of your personal data is based on the following legal grounds:
- Performance of a contract (Art. 6.1.b): data necessary to provide app features (account, family content, location, notifications)
- Consent (Art. 6.1.a): health data processed via Health Connect and AI features — explicit consent required and revocable at any time
- Legitimate interest (Art. 6.1.f): service security, fraud prevention, technical logs
Why we use your data
- Access and authentication
- Delivery of core features
- Notifications and service updates
- Security and continuous improvement
Location data
KidBox may collect the precise location of the device (GPS) when the family location sharing feature is explicitly enabled by the user. Location may also be collected in the background for family geofence operation, subject to explicit authorization. Location data is transmitted to Google Firebase and is not shared with third parties for advertising purposes.
Device identifiers
KidBox collects the device identifier (Firebase Instance ID / FCM token) to send push notifications. The Facebook Login SDK may collect the device advertising ID for install attribution and advertising campaign purposes. See Meta's Privacy Policy for details.
Cookies, statistics and the Meta Pixel on this website
The kidboxapp.com website may use two third-party tools, each only after you consent (GDPR Art. 6(1)(a) and the ePrivacy rules), through the banner shown on your first visit. If you decline or don't answer, nothing is loaded.
- Google Analytics 4 (statistics): counts visits, pages viewed and clicks towards the App Store, Google Play and the web app, so we know which content helps. It sets Google cookies (
_ga). Google Signals and advertising signals are disabled. Google Privacy Policy - Meta Pixel (advertising): measures how our campaigns perform; it sets Meta cookies and shares with Meta the pages you visit and technical browser data. Meta Privacy Policy
You can accept statistics only, both or neither, and change your choice at any time from the "Cookie preferences" link at the bottom of every page; withdrawing consent to statistics deletes the Google Analytics cookies. Your choice is stored only in your browser. These tools concern the website, not the app or the data you enter in it.
"Ask KidBox" chat on this website
The website has a chat that answers questions about the product. Many answers are already written into the page and send nothing. Other questions you type are sent to our servers (Google Firebase, EU) and, to generate the answer, to Anthropic (United States), together with the two previous exchanges. We keep the text of the questions for 30 days, with no name, email or other identifier, to count the most frequent questions and improve the answers; answers may stay in an anonymous cache for 7 days. To limit abuse, the IP address is used only in encrypted (hashed) form in a counter that is deleted after 2 days. The conversation stays in your browser only while the tab is open. Don't type personal or health data in the chat: for help with your account, use the support inside the app. Legal basis: legitimate interest in answering information requests (GDPR Art. 6.1.f). Anthropic Privacy Policy
Sensitive data
KidBox processes health data (vital parameters, medications, medical visits, fitness data from Health Connect) classified as sensitive data under GDPR Art. 9. This data is collected exclusively on the user's explicit consent, stored in encrypted form on Google Firebase, and is not shared with third parties unless the user activates the AI feature (see AI Assistant section). Health data is never used for advertising purposes.
Health Connect (Android)
On Android, KidBox can read health data from Health Connect, exclusively after the user has granted each individual permission from the Health Connect system screen. Consent is per data type and can be revoked at any time from Health Connect settings, without uninstalling KidBox.
KidBox only reads the data types listed below and writes none of them. For each one we state the specific purpose:
- Steps — display daily activity in the Health section and calibrate the volume of the training plan.
- Heart rate (including resting heart rate) — display the latest recorded values in the Health section and adapt the intensity of the training plan.
- Weight — body metric used for the training plan and the meal plan, and to follow its trend over time.
- Height — body metric used together with weight to size the training plan and the meal plan.
- Active calories burned — energy spent during workouts, recorded by a watch or fitness app. This is the data KidBox uses to build the weekly report of the training plan (total calories for the week, alongside completed sessions and minutes performed), to pre-fill the calories of an individual completed session, and to estimate energy needs in the meal plan. Without this data the weekly report can only show duration, not actual effort.
- Exercise — type, date and duration of recorded sessions, to reconcile workouts actually performed with those planned.
Data read from Health Connect is stored encrypted on Google Firebase and shared only within the user's own family group. It is never used for advertising purposes, never sold to third parties, and never feeds profiling. It is sent to Anthropic only when the user explicitly activates an AI feature that requires it (training plan, meal plan, assistant), as described in the AI Assistant section. On account deletion it is erased together with all other data.
Sharing data with third parties
We do not sell your data. Data is shared exclusively with the following technical providers for service delivery:
- Google Firebase (Firestore, Storage, Auth, Functions, Messaging) — storage, authentication, push notifications. Privacy Policy
- Anthropic — AI processing on explicit consent (questions + family/health context selected by the user). Privacy Policy
- Meta (Facebook) — Facebook Login SDK for authentication and advertising campaign attribution (advertising ID). Privacy Policy
- Google Maps Platform — map display and address geocoding. Privacy Policy
- Google Play Billing — subscription and in-app purchase management. Privacy Policy
AI Assistant & Anthropic
Data sent to Anthropic includes your questions and the family context needed to respond (names, events, health data). Explicit consent is required before first use — revocable at any time from the app settings.
Data retention
Data is retained only for as long as strictly necessary to provide the service. Upon account deletion, all associated data is permanently erased. Usage data is also automatically erased after 90 days, even without any request.
Account deletion
You can delete your account at any time from the app settings: Profile → Delete account. See our data deletion page for details.
Data Protection Officer (DPO)
The data controller also serves as the data protection point of contact. For any enquiry regarding your personal data please contact: passboxcontact@gmail.com
Your rights (GDPR Art. 15–22)
You have the right to request erasure of your personal data at any time (right to erasure, GDPR Art. 17). You may exercise the following rights by contacting us or directly within the app:
- Access to your data (Art. 15)
- Rectification of inaccurate information (Art. 16)
- Erasure of data — right to be forgotten (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
- Withdrawal of specific consents at any time
- Right to lodge a complaint with the supervisory authority — Garante per la protezione dei dati personali (garanteprivacy.it)
Security
KidBox implements end-to-end encryption and advanced authentication measures to protect your family's data.
Contact
For any privacy question write to passboxcontact@gmail.com