1. Controller and contact
The controller for data processing in this app is:
RawGuide, Florian Seeger
Schellenbergstr. 9, 82110 Germering, Germany
Email: contact@rawguide.de
Phone: +49 177 4706601
2. Principle: your data stays on your device
Everything you record – children, diary, photos, sleep and meal times, milestones, vaccinations, check-ups, growth data, tasks, shopping lists and notes – is stored exclusively on your device. There is no user account and no registration. None of it is transmitted to us unless you activate one of the functions described below.
Because the data only exists on your device, it is lost irretrievably if the device is lost or replaced and you have not made a backup. You create the backup yourself and decide where it goes.
3. Anonymous sign-in (required for the cloud functions)
As soon as you use the Parent Team or the Community, the app signs you in anonymously with Firebase Authentication. This creates a random identifier with no link to your name, email address or phone number. Without it there is no technical way to tell which encrypted record belongs to which pair of devices.
Purpose: access protection for the cloud record. Legal basis: Art. 6(1)(b) GDPR (performance of the contract).
4. Parent Team – end-to-end encrypted
The Parent Team connects two devices so that both parents see the same information. The function is voluntary and switched off by default.
Pairing: one device creates a code, the other enters it. Through this the devices exchange public keys (X25519), which are held briefly in a rendezvous record and then expire. Each device calculates the shared data key on its own; the key never leaves the devices. As a check, both devices show the same security code for you to compare.
What is transmitted: the data to be synchronised (children, diary, sleep and meals, milestones, vaccination and check-up status, tasks, reminders, shopping lists and a display name you set) is encrypted on your device using AES-256-GCM and stored as an unreadable package in Cloud Firestore. We cannot read this content – we do not have the key.
What is stored alongside it in plain text: the anonymous identifier of the device that wrote last, checksums to detect changes, a marker for the type of event used for notifications (for example „task completed“) and a timestamp. No content can be derived from this.
Health-related information: your child's vaccinations, check-ups and growth data are health data within the meaning of Art. 9 GDPR. They are only transmitted if you actively set up the Parent Team – and even then only end-to-end encrypted.
Legal basis: Art. 6(1)(b) GDPR; for the health-related information additionally Art. 9(2)(a) GDPR (explicit consent by setting up the function). If you disconnect, the data key is deleted on your device and the record becomes permanently unreadable.
5. Photos in the Parent Team (only with explicit consent)
Diary photos are not transmitted by default and stay on your device, even when the Parent Team is active. Only if you switch on the setting „Share photos with partner“ (default: off) are new photos encrypted on your device before upload (AES-256-GCM) and stored as an encrypted file in Firebase Storage so that the paired device can display them.
If you delete an entry or switch sharing off again, no new photos are uploaded; the encrypted photo of a deleted entry is removed.
Because these may be pictures of a child, please consider before switching this on whether you agree to sharing them with the paired second parent. Legal basis: Art. 6(1)(a) GDPR (consent, revocable at any time by switching it off).
6. Notifications
Reminders (appointments, daily tasks, shopping day, due check-ups, backup, look back) are scheduled on your device. No data leaves your device for this.
Parent Team notifications go through a server. For this the following is stored next to the encrypted record: a push token for your device, the language you selected, your choice of notification types and – if you set quiet hours – their time window along with the offset of your device time to UTC. Delivery runs via the Expo Push Service and from there via Apple (APNs) or Google (FCM). No content is transmitted: the message only names the type of event, never the content.
Only the following are reported: task completed, shopping list finished, vaccination or doctor's appointment booked, appointment marked as done, and disconnection of the Parent Team.
Legal basis: Art. 6(1)(a) GDPR (consent via the system prompt, can be switched off at any time in settings).
7. Community (voluntary)
If you use the Community you choose a display name. Connections to other users and incoming requests are stored in the cloud so that both sides can see them. We do not require real names, email addresses or phone numbers.
Legal basis: Art. 6(1)(a) GDPR (consent through active use). You revoke it by leaving; your community data is removed in the process.
8. Premium subscription
Purchase and renewal run through the respective app store (Apple App Store or Google Play). We do not receive payment data. To check whether a valid subscription exists we use RevenueCat; an anonymous identifier and the purchase status are transmitted there.
In the Parent Team one subscription covers both parents. For this your own premium status (active or not, expiry date, whether it renews) travels inside the encrypted package so that the paired device knows whether it is still unlocked. Legal basis: Art. 6(1)(b) GDPR.
9. Crash reports
If the app crashes, a technical report is sent to Firebase Crashlytics. This records random identifiers (including the Firebase installation ID), time and app version, device model, operating system, memory, screen orientation and the technical error trace. Content from your diary or your children's data is not included. Retention is 90 days, after which deletion from live and backup systems begins. The module is only active in installed builds.
Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a functioning app).
10. Permissions on your device
The app only asks for a permission when you use the corresponding function. The data stays on your device:
- Photos and media library – to choose an image for a diary entry. A transfer only happens if you explicitly switch on photo sharing (section 5).
- Calendar – to add appointments to your device calendar and remove them again. No transfer.
- Microphone and speech recognition – to dictate a diary entry. Processing is done by your operating system's speech recognition.
- Notifications – for reminders and partner notifications (section 6).
No access to your address book: the app does not read contacts. You maintain the list of important contacts yourself inside the app.
11. Recipients and storage locations
We use the following processors:
- Google Ireland Limited (Firebase): Cloud Firestore, Firebase Storage, Firebase Authentication, Cloud Functions and Crashlytics. The encrypted Parent Team record is held in the Firestore location eur3 (Europe); the Cloud Functions run in europe-west1 (Belgium). Google's Data Processing and Security Terms apply.
- Expo (650 Industries, USA): forwarding of partner notifications. Only the push token is transmitted; the content of the message is not stored, only processed for as long as delivery takes.
- Apple (APNs) and Google (FCM): delivery of notifications to the device.
- RevenueCat Inc. (USA): checking the subscription status. RevenueCat bases the transfer on the EU Standard Contractual Clauses; the data processing agreement is part of the terms of use.
12. Retention periods
- On the device: until you delete the data or the app.
- Parent Team: until you disconnect; after that the record is unreadable without the key.
- Shared photos: until the entry is deleted or sharing is switched off.
- Push token: until you switch off partner notifications or disconnect.
- Community: until you leave.
- Crash reports: 90 days.
13. Your rights
You have the right to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21). You can withdraw consent at any time with effect for the future – in the app by switching off the respective function. You also have the right to lodge a complaint with a supervisory authority.
Note on access requests: because we cannot decrypt the content of the Parent Team, we hold no readable data about it. Your complete content is on your device and you can export it using the backup function.
14. Children
The app is aimed at parents, not at children. The information recorded does, however, concern children – partly health data. The persons with parental responsibility are responsible for these entries. Before switching on the Parent Team or photo sharing, it should be clear that both of them agree.
As of: 24.07.2026