Privacy Policy
Last updated: 13 September 2026 · GDPR compliantKidBox is an application designed for the shared management of family information — chat, documents, notes, activities and children's health. This policy explains transparently what data we process, why and with whom we share it.
Data Controller: KidBox — Vittorio Scocca · passboxcontact@gmail.com
Data we collect
- Personal information: email, name/alias, profile photo, access credentials, date of birth
- Contacts: names and phone numbers of family and emergency contacts entered by the user
- Family data and content: chat, notes, documents, media, calendar events, to-dos, expenses, children's health data
- Technical data: notification tokens and security logs without identifiable information
- Location data: only when location sharing is explicitly enabled
- Usage data: aggregated in-app actions (e.g. opening a document or a section), without the content of what you view — no titles, text or exact location
Legal basis for processing (GDPR Art. 6)
The processing of your personal data is based on the following legal grounds:
- Performance of a contract (Art. 6.1.b): data necessary to provide app features (account, family content, location, notifications)
- Consent (Art. 6.1.a): health data processed via Health Connect and AI features — explicit consent required and revocable at any time
- Legitimate interest (Art. 6.1.f): service security, fraud prevention, technical logs
Why we use your data
- Access and authentication
- Delivery of core features
- Notifications and service updates
- Security and continuous improvement
Location data
KidBox may collect the precise location of the device (GPS) when the family location sharing feature is explicitly enabled by the user. Location may also be collected in the background for family geofence operation, subject to explicit authorization. Location data is transmitted to Google Firebase and is not shared with third parties for advertising purposes.
Device identifiers
KidBox collects the device identifier (Firebase Instance ID / FCM token) to send push notifications. The Facebook Login SDK may collect the device advertising ID for install attribution and advertising campaign purposes. See Meta's Privacy Policy for details.
Cookies and the Meta Pixel on this website
The kidboxapp.com website may use the Meta Pixel to measure how our advertising campaigns perform: it sets Meta cookies and shares with Meta the pages you visit and technical browser data. The Pixel runs only after you consent (GDPR Art. 6(1)(a) and the ePrivacy rules), through the banner shown on your first visit; if you decline or don't answer, nothing is loaded. You can change your choice at any time from the "Cookie preferences" link at the bottom of every page. Your choice is stored only in your browser. The Pixel has nothing to do with the app or the data you enter in it. For Meta's processing see its Privacy Policy.
Sensitive data
KidBox processes health data (vital parameters, medications, medical visits, fitness data from Health Connect) classified as sensitive data under GDPR Art. 9. This data is collected exclusively on the user's explicit consent, stored in encrypted form on Google Firebase, and is not shared with third parties unless the user activates the AI feature (see AI Assistant section). Health data is never used for advertising purposes.
Health Connect (Android)
On Android, KidBox can read health data from Health Connect, exclusively after the user has granted each individual permission from the Health Connect system screen. Consent is per data type and can be revoked at any time from Health Connect settings, without uninstalling KidBox.
KidBox only reads the data types listed below and writes none of them. For each one we state the specific purpose:
- Steps — display daily activity in the Health section and calibrate the volume of the training plan.
- Heart rate (including resting heart rate) — display the latest recorded values in the Health section and adapt the intensity of the training plan.
- Weight — body metric used for the training plan and the meal plan, and to follow its trend over time.
- Height — body metric used together with weight to size the training plan and the meal plan.
- Active calories burned — energy spent during workouts, recorded by a watch or fitness app. This is the data KidBox uses to build the weekly report of the training plan (total calories for the week, alongside completed sessions and minutes performed), to pre-fill the calories of an individual completed session, and to estimate energy needs in the meal plan. Without this data the weekly report can only show duration, not actual effort.
- Exercise — type, date and duration of recorded sessions, to reconcile workouts actually performed with those planned.
Data read from Health Connect is stored encrypted on Google Firebase and shared only within the user's own family group. It is never used for advertising purposes, never sold to third parties, and never feeds profiling. It is sent to Anthropic only when the user explicitly activates an AI feature that requires it (training plan, meal plan, assistant), as described in the AI Assistant section. On account deletion it is erased together with all other data.
Sharing data with third parties
We do not sell your data. Data is shared exclusively with the following technical providers for service delivery:
- Google Firebase (Firestore, Storage, Auth, Functions, Messaging) — storage, authentication, push notifications. Privacy Policy
- Anthropic — AI processing on explicit consent (questions + family/health context selected by the user). Privacy Policy
- Meta (Facebook) — Facebook Login SDK for authentication and advertising campaign attribution (advertising ID). Privacy Policy
- Google Maps Platform — map display and address geocoding. Privacy Policy
- Google Play Billing — subscription and in-app purchase management. Privacy Policy
AI Assistant & Anthropic
Data sent to Anthropic includes your questions and the family context needed to respond (names, events, health data). Explicit consent is required before first use — revocable at any time from the app settings.
Data retention
Data is retained only for as long as strictly necessary to provide the service. Upon account deletion, all associated data is permanently erased. Usage data is also automatically erased after 90 days, even without any request.
Account deletion
You can delete your account at any time from the app settings: Profile → Delete account. See our data deletion page for details.
Data Protection Officer (DPO)
The data controller also serves as the data protection point of contact. For any enquiry regarding your personal data please contact: passboxcontact@gmail.com
Your rights (GDPR Art. 15–22)
You have the right to request erasure of your personal data at any time (right to erasure, GDPR Art. 17). You may exercise the following rights by contacting us or directly within the app:
- Access to your data (Art. 15)
- Rectification of inaccurate information (Art. 16)
- Erasure of data — right to be forgotten (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
- Withdrawal of specific consents at any time
- Right to lodge a complaint with the supervisory authority — Garante per la protezione dei dati personali (garanteprivacy.it)
Security
KidBox implements end-to-end encryption and advanced authentication measures to protect your family's data.
Contact
For any privacy question write to passboxcontact@gmail.com