Privacy Policy for WalkyPop
Last updated: September 2026 · Deutsche Fassung
1. Controller
Robert BeutelspacherHagstr. 26
74193 Schwaigern
Germany
Email: hi@turbobarn.com
This English text is a convenience translation of the German Datenschutzerklärung, which is the authoritative version.
2. What this is about
WalkyPop is a check-in app for families. A child holds a balloon until it pops and thereby sends “I'm here!” to the paired adults, who reply with an emoji from a fixed list. Popping the balloon is all the child's side can do.
Two things up front, because they answer most questions:
WalkyPop never collects location data, at any time or in any form. There is no tracking, no maps, no geofences, no movement history: the app does not even request the location permission.
WalkyPop has no user accounts. There is no registration, no email address, no password. Each device signs in anonymously and receives a random identifier (UUID). This identifier is all that links your device to our servers; it cannot be attributed to a person.
3. What data is processed
3.1 Only on your device
This information never leaves your device and never reaches our servers: the four custom emoji slots, the chosen skin tone of the hand emoji, the notifications switch and the app's technical settings. The camera also works on the device only: when scanning an invitation code, no image is stored or transmitted, only the recognized code.
3.2 On our server
- A random, anonymous user identifier (UUID) per device
- The device's role: child or adult
- A freely chosen display name (at most 60 characters). You decide what goes there; a nickname is enough
- Optionally a profile photo. It is scaled down to at most 512 × 512 pixels before upload and stored in a private bucket that only the paired family members can access
- The device's language (two-letter code, e.g. “en”), so that messages arrive in the right language
- Which devices are paired with each other, and the invitation codes through which the pairing came about
- For each check-in: when the balloon popped, when the check-in reached us, when an adult saw it and when it was reset
- For each reply: the chosen emoji (from a fixed list of 24) and the skin tone level (a number from 0 to 5)
- For each pop request: which adult sent it when to which child, whether it arrived and was seen, and the optional note (at most 60 characters). This note is the only free text in WalkyPop; there is no chat
- The settings per child: balloon shape, balloon color, whether and on which weekdays at which times to remind, the associated time zone, and which adults have turned off the reminder notice
- Which secondary device (such as a watch) belongs to which child
- If you have enabled notifications: your device's push token, a technical address assigned by the push service, and the platform (iOS, Android or watch). No other device and no other app can read the token
- Whether an entitlement for “WalkyPop Plus” exists, where it comes from (trial or purchase), when it ends and, for a purchase, the transaction number the store assigned to it
What is NOT processed: location data, contacts, address book, calendar, photos other than the one self-chosen profile picture, camera images, advertising identifiers (IDFA), usage statistics, behavioral profiles.
3.3 Notifications (push)
Notifications are optional: the app asks once after the first pairing, and there is a switch in your own profile. Off means: the token is removed from our server and nothing is delivered to the device any more.
Delivery runs through the platforms' push services: Firebase Cloud Messaging (Google Ireland Limited, Dublin, or Google LLC, USA) for phones and the Apple Push Notification service (Apple Distribution International Ltd., Cork, or Apple Inc., USA) for the Apple Watch. These services see the token and the content of the notification. The content is brief: for a check-in the child's name and “I'm here!”, for a reply the emoji, for a pop request the sender's name, a fixed sentence and the optional note, for a reminder a fixed sentence, for a replaced device only a notice to that effect. Of Firebase we use Cloud Messaging only: no Firebase Analytics, no crash statistics.
Google and Apple act as processors under Art. 28 GDPR for this. Where data reaches the USA in the process, this is based on the EU Commission's Standard Contractual Clauses and on the EU-US Data Privacy Framework, to which both companies are certified.
4. Where the data is stored and who processes it
4.1 Database and file storage
Supabase (Supabase Inc.). This project's data is stored in the eu-central-1 region (Frankfurt am Main, Germany). Processing under Art. 28 GDPR. Like any server, Supabase briefly logs access (including the device's IP address) to detect outages and abuse; these logs are deleted automatically after a few days.
4.2 Error telemetry
Sentry (Functional Software Inc.), EU data region. If the app crashes or an unhandled error occurs, the following is reported: the technical stack trace, the device model, the operating system version and the app version. Expressly not transmitted are IP addresses, screenshots and session recordings; these features are turned off. The report contains no names, no photos and no messages.
4.3 Purchases
The purchase itself runs entirely through the App Store or Google Play; we receive no payment details, no card number and no name. For purchase and payment, Apple and Google are controllers in their own right; their privacy policies apply.
To validate the receipt and manage the subscription we use RevenueCat (RevenueCat Inc., USA). Transmitted there are the anonymous user identifier, the receipt or purchase token issued by the store, the purchased product with price and currency, platform, app version and device language; like any server, RevenueCat logs the IP address of the request. The transfer to the USA is based on the EU Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR), which RevenueCat incorporates in its data processing agreement.
Beyond that we pass data on to no one. We do not sell data. There is no advertising and no tracking.
5. Legal bases
- Pairing, check-ins, replies, pop requests, settings, notifications and purchase: Art. 6(1)(b) GDPR (performance of the user agreement)
- Profile photo and display name: Art. 6(1)(a) GDPR (consent; both are voluntary and can be changed or deleted at any time)
- Error telemetry: Art. 6(1)(f) GDPR (legitimate interest in a working, error-free app)
6. How long data is kept
- Check-ins including replies: 30 days, then deleted automatically every night
- One-time codes for connecting a second device: one day
- Pop requests including the note: until you delete the device or the 12-month limit applies
- Push token: until you turn off notifications or delete the device; if the push service reports a token as invalid, it is removed immediately
- Error reports at Sentry: at most 90 days
- Anonymous identifiers without an associated profile: nightly
- Profile, photo, pairings and settings: until you delete them, and at the latest after 12 months without any use of the app. Then the anonymous identifier is deleted automatically together with everything attached to it. Exempt are devices with an active purchase for the family and deliberately profile-less secondary devices
7. Deletion by you
In the app, at the very bottom of the adult view: “Delete this phone and all data”. On Apple Watch: “Reset watch”. Both delete this device's anonymous identifier together with profile, photo, pairings, check-ins and settings on our server. The process is final and cannot be undone.
Uninstalling the app alone does not delete the server data immediately; it then falls under the 12-month limit from section 6.
8. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). You may withdraw any consent given at any time with effect for the future.
An honest note on access requests: Because WalkyPop has no accounts, we cannot attribute a request to a person. We can only disclose what is stored for an anonymous user identifier, and only if you can tell us that identifier. That is the price of having no accounts, and the reason why deletion lives directly in the app, where your device knows its own identifier.
You also have the right to lodge a complaint with a supervisory authority. The competent authority is the State Commissioner for Data Protection and Freedom of Information of Baden-Württemberg:
Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-WürttembergHeilbronner Straße 35
70191 Stuttgart
Telefon: 0711 615541-0
E-Mail: poststelle@lfdi.bwl.de
baden-wuerttemberg.datenschutz.de
9. Children
WalkyPop is intended for use within families. A child device is set up by an adult and paired with that adult's device; a child's name and photo are assigned by the adults. Consent under data protection law is given by the parent or guardian.
The child view contains no advertising, no purchases, no outbound links and no way to enter free text. Access to the settings is protected by a reading task that a child who does not read yet cannot solve.
10. Changes
If what the app processes changes, we change this policy beforehand, not afterwards. The date above states the current version.