Parent-managed task planner for kids
App: Kids Time Planner Data Controller: Erhan Serin Contact: studioperaturkey@gmail.com Effective date: 31 May 2026 Last updated: 31 May 2026
This policy is written in line with the EU General Data Protection Regulation (GDPR), the GDPR-K rules covering children under 16, Google Play Families Policy, and COPPA principles. A Turkish version is available at
/privacy-policy.tr.
Kids Time Planner is a mobile app designed for parents to manage their children’s daily task schedules. All account holders are parents; children do not sign up themselves. The app:
| Data | Source | Purpose | Retention |
|---|---|---|---|
| Email address | Signup form / Google Sign-In | Account creation, authentication, password reset, OTP delivery | While the account is active |
| Display name | Signup / Google profile | In-app greeting | While the account is active |
| Password | Signup form | Authentication | Stored encrypted by Firebase; plain text is never stored |
| Premium subscription status | Google Play | Access to premium features | While the account is active |
| FCM device token | Your device (Firebase Messaging) | Task completion notifications, weekly digest | Until the device is replaced or the account is deleted |
| PIN verifier | Local device setting | Restrict access to the parent panel | Local only (SharedPreferences); stored as a salted hash |
| Data | Purpose | Retention |
|---|---|---|
| Child name or nickname | Profile identification | Until the profile is deleted |
| Emoji / avatar choice | Visual identification | Until the profile is deleted |
| Profile photo (optional) | Visual identification | Until the profile is deleted; parent can remove anytime |
| Tasks, completion logs, stars, rewards, routines | Core app functionality | While the account is active |
Child data is bound exclusively to the parent’s Firebase UID. No other parent can access this data (enforced server-side by Firestore Security Rules).
| Data | Purpose | Retention |
|---|---|---|
| Crash logs (Firebase Crashlytics) | Debugging | Firebase default (~90 days) |
| Device OS version (collected by Firebase) | Infrastructure compatibility | Firebase default |
The app does not collect location, contacts, microphone, calendar, SMS, IMEI, or advertising identifiers.
Your data is not sold, rented, or shared with any advertising ecosystem. The following data processors are used solely to operate the service:
| Service provider | Data | Purpose | Agreement |
|---|---|---|---|
| Google Firebase (Auth, Firestore, Storage, Functions, Messaging) | All account & app data | Hosting and database | Google Data Processing Agreement (DPA) |
| Google Play Billing | Subscription receipt | Premium verification | Google Play Developer Agreement |
| Google Sign-In | Email + name | One-tap login | Google Account policy |
We may disclose data to lawful authorities when legally required (e.g., a court order).
Data is stored encrypted on Google Cloud servers selected by Firebase infrastructure. These servers may be located outside Türkiye (in the European Union or United States). In this case, international data transfers take place. Google secures such transfers under GDPR Standard Contractual Clauses (SCCs).
Under GDPR Art. 15-22 (and equivalent local laws such as Turkey’s KVKK Art. 11) you have the right to:
To exercise these rights: email studioperaturkey@gmail.com or use the Settings → Delete my account option inside the app. We respond to requests within 30 days.
isPremium field.The app runs on mobile platforms and does not use web cookies. It does not include advertising or analytics tracking SDKs. Only the following local storage mechanisms are used on-device:
We may update this policy from time to time. Material changes will be announced in advance via in-app notification or email. The “Last updated” date above will reflect the latest revision.
For questions, requests, or complaints:
Erhan Serin Email: studioperaturkey@gmail.com
This document is informational and does not constitute legal advice. If in doubt, consult a qualified lawyer or your local data protection authority.