Funily Privacy Policy
Working version — Google Play publication is blocked until the controller details are complete and legal approval is recorded.
The technical description reflects the app on 13 July 2026; it is not legal advice.
Last updated: missing — publication blocked
Data controller: missing — publication blocked
Privacy contact:
missing — publication blocked
1. Who we are
Funily is a family web and mobile (Android) app where children's chores and routines become quests, points, and a parent-approved RPG. The app is directed to families with children. A parent or guardian creates the family and manages child accounts. Independent registration of new child accounts is currently disabled. An existing solo account cannot access payments or the family economy until a guardian joins.
2. Data we collect
| Category | Data | From |
|---|---|---|
| Account | Email (mostly parents; usually none for children), username, password (hashed) | Parent, child |
| Family relationships | Parent–child link, family membership | Parent |
| Device identifiers | Device ID (Android ID), push token (FCM) | Device |
| App activity | Quests, completions, rewards, points, XP, character, duels, bosses, play times, goals and technical activation milestones | Parent, child, system |
| Outcome check-in | Closed W1/W4 answers about reminder frequency, child initiative and continued use; no comment or child name | Parent |
| User content | Quest/reward titles & descriptions (free text) | Parent, child |
| Notifications | Preferences, FCM token, routine windows and technical reminder-delivery outcome | User, device, system |
| Purchase history | Product/base plan, status, access period, renewal/cancellation, order reference and encrypted Google Play purchase token | Parent, Google Play |
| Technical | Timestamps, IP address and request path in short-lived server logs; redacted diagnostics when monitoring is enabled | System |
We do not collect: location, contacts, photos, microphone, health data, browsing history, or biometrics. Payment-instrument data such as card or bank-account numbers is collected directly by Google Play and is not accessible to Funily.
3. Why we process data (purposes & bases)
- Providing the service (accounts, quests, rewards, RPG) — necessary to perform the service. The final legal basis must be approved before publication.
- Push notifications — provide a feature enabled by the user.
- Product effectiveness — assess whether Funily actually reduces the family's burden from the parent's closed-choice answers.
- Premium subscription — verify purchases, grant access and handle renewals, cancellation and refunds.
- Security and abuse prevention — minimal logs.
- Children's data — a parent/guardian creates and controls the child account. The legal basis and consent evidence, including treatment of existing solo accounts, must be approved before public launch.
4. Who we share data with
We do not sell data and do not share it for advertising. We use processors solely to provide the service:
- Google Firebase Cloud Messaging — push notification delivery.
- Google Play — Android payments and subscription-state verification.
- Email (SMTP) provider — transactional email to the parent.
- Oracle Cloud — application and database hosting in eu-frankfurt-1 (Frankfurt, Germany).
- Stripe — only if web payments are enabled; the production integration is currently disabled.
Processor agreements and any EEA transfer mechanism require final review before publication.
5. Advertising & tracking
Funily contains no advertising or analytics SDKs and does not track users across apps. We do not perform advertising profiling, and never toward children.
6. Retention
- account, family, activity and subscription data — until account/family deletion;
- technical reminder-delivery outcomes — 90 days;
- production access and application logs — no more than 14 days;
- rolling database backups — 14 daily and 8 weekly copies; deleted data may remain in backups for up to approximately 8 weeks.
7. Your rights
You have the right to access, rectify, erase, restrict, port, and object. A parent may exercise these rights on a child's behalf. To exercise them, contact the contact published before launch or use the in-app controls.
8. Account & data deletion
A parent can delete a single child or the whole account/family in the app or at
funily.app/usun-konto/ (no app install required). After password
re-authentication and explicit confirmation, the data is permanently erased.
A machine-readable JSON family export is available before deletion.
9. Security
All traffic is encrypted (HTTPS/TLS), and passwords are stored hashed. We use family-data access controls, rate limits on sensitive endpoints, expiring API tokens, database backups, and technical monitoring designed not to send form content, cookies, account data, or exception messages.
10. Children
Funily is built for families. A child's account is set up and controlled by a parent/guardian, who consents to processing the child's data and may review, export, or delete it at any time. New independent child registration is disabled by default. The app shows children neither ads nor purchases; only a parent can see and confirm the Premium offer.
11. Changes
We will announce material changes in-app or by email. The last-updated date appears at the top.
12. Contact
Controller details will be completed before publication.