This Privacy Policy explains how Andras Molnar ("we," "us," or "our") handles information in connection with the Kids Art & Photo Organizer mobile application (the "App") and the website on which this Privacy Policy is published (the "Website").
The App is intended for use by adults, parents, and legal guardians. It enables users to organize family memories on their own devices. We designed the App so that photos, artwork, voice recordings, child profiles, and other memory content remain under the user's control and are not uploaded to servers operated by us.
1. Who Is Responsible for Your Information?
For personal data that we collect or otherwise control, the data controller is:
Andras Molnar
Hungary
Email: andrasapps@gmail.com
If you contact us about privacy, please use the subject line "Privacy Request – Kids Art & Photo Organizer."
2. Information Stored Locally on Your Device
The App allows you to create and organize family memories that may include:
- photos and images of artwork;
- voice recordings;
- names or nicknames;
- dates and age-related information;
- notes, captions, tags, and categories; and
- other content that you choose to add.
This content is stored locally in the App's storage on your device. We do not operate an account system or a server that receives, stores, or provides us with access to this content.
Local content remains on your device until you delete the relevant content or delete the App and its data. Using Apple's "Offload App" feature may retain the App's documents and data. Depending on your device and backup settings, local App data may also be included in an iCloud or computer backup controlled by you and processed by Apple under Apple's terms and privacy policy.
3. Exports, Backups, and Sharing Initiated by You
The App may allow you to export, back up, or share content using the system tools and destinations that you select. We do not receive a copy of content merely because you use Apple's share sheet or another device-level sharing feature.
If you create an encrypted App backup, the backup is protected using the password that you choose. We do not receive or retain the backup or its password and cannot recover a lost password.
When you send content to another person, application, cloud-storage provider, printer, or other destination, that destination may process the content under its own terms and privacy policy. You are responsible for ensuring that you have the authority to share content relating to another person, including a child.
4. Optional Product Analytics
During onboarding, the App asks whether you consent to optional product analytics. Analytics remain disabled unless you make an affirmative choice to enable them. Refusing analytics does not prevent you from using the App's core or paid features.
If you consent, we use Amplitude to process limited, pseudonymous analytics information, such as:
- a randomly generated, App-specific analytics identifier;
- App interaction events, such as opening a feature or completing a non-content action;
- event and session timestamps;
- App version and operating-system version;
- general technical information such as device model, language, and locale; and
- purchase or subscription status only if required to measure the use of premium features, without payment-card information.
We do not send photos, artwork, voice recordings, names, notes, captions, tags, child profiles, precise location, advertising identifiers, contacts, or the contents of your memories to Amplitude.
Network requests necessarily make an IP address available to the receiving infrastructure while the request is transmitted. We configure Amplitude not to retain the IP address or use it to store location information. Amplitude is configured to use its European Union data region.
We use analytics only to understand how the App is used, identify broad usability or reliability issues, and improve the App. We do not use analytics for advertising, cross-app tracking, profiling children, or selling personal information.
For users in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, the legal basis for optional analytics is your consent. You may withdraw consent at any time in the App's settings. Withdrawal disables future analytics collection and resets the local analytics identifier. It does not affect the lawfulness of processing that occurred before withdrawal.
We retain identifiable analytics events for no longer than 12 months, after which they are deleted or irreversibly aggregated. You may also request earlier deletion as described in Section 13. Because we do not maintain user accounts, we may need the App-generated analytics identifier displayed in the App's privacy settings to locate the relevant pseudonymous record.
5. Purchases and Subscriptions
Purchases, subscriptions, and restores are processed through Apple and RevenueCat. Depending on the transaction and configuration, Apple and RevenueCat may process:
- purchase history and transaction identifiers;
- product, subscription, entitlement, and renewal status;
- transaction dates, currency, storefront, and general country or region information;
- an anonymous or pseudonymous App User ID; and
- technical information necessary to validate transactions, prevent fraud, provide entitlements, and restore purchases.
We do not receive your full payment-card number or payment credentials. Apple processes payments independently under its own terms and privacy policy. RevenueCat processes purchase and entitlement information to provide purchase validation, subscription management, analytics, fraud prevention, and restoration functionality.
For users in the EEA, the primary legal basis for this processing is performance of the purchase contract and providing requested App functionality. We may also process limited transaction information to comply with legal obligations and for our legitimate interests in preventing fraud, resolving disputes, and maintaining accurate entitlement records.
Purchase and entitlement information is retained for as long as reasonably necessary to provide and restore purchased features, resolve billing or entitlement issues, prevent fraud, and comply with applicable tax, accounting, consumer-protection, and legal requirements. Apple may retain transaction information independently under its own retention rules.
6. Device Permissions
The App may request the following permissions only when needed for a feature that you choose to use:
- Photos: to select or add photos and images to the App;
- Microphone: to create a voice recording; and
- Camera, if offered: to capture a photo or image directly in the App.
Where available, the App uses system pickers or limited-access mechanisms instead of requesting broader access. Granting a permission allows the App to perform the requested function on your device; it does not give us remote access to the selected content.
You can review or revoke permissions at any time in iOS Settings. Some related App features may not work if the required permission is denied, but unrelated features will remain available.
7. Support Messages and Privacy Requests
If you contact us by email, we receive the information that you choose to provide, which may include your name, email address, message, attachments, and technical details relevant to your request.
We use this information to respond to you, provide support, investigate problems, comply with legal obligations, and establish or defend legal claims. For users in the EEA, the legal basis is our legitimate interest in providing support and operating the App, performance of a contract where the request relates to purchased functionality, and compliance with legal obligations where applicable.
We normally retain support correspondence for up to 24 months after the matter is closed. We may retain it longer when reasonably necessary for an unresolved dispute, security investigation, legal claim, or mandatory legal retention period.
Please do not include children's photos, recordings, or other sensitive information in a support message unless it is strictly necessary. If such information is not needed to handle the request, we may delete it.
8. Website Information
The Website does not use advertising cookies or behavioral advertising. Our hosting provider, Vercel, may automatically process limited technical information when the Website is accessed, such as an IP address, browser and device information, requested URL, date and time, and security or diagnostic logs. This processing is necessary to deliver and secure the Website, prevent abuse, and diagnose technical failures.
For users in the EEA, this processing is based on our legitimate interests in maintaining a secure and functional Website. Technical logs are retained only for the period configured by the hosting provider and as reasonably necessary for security, abuse prevention, and troubleshooting.
9. Children's Privacy
The App is a tool for adults, parents, and legal guardians and is not intended to be used independently by children. The App allows an adult user to store content relating to children locally on the user's own device, but we do not receive or have access to that content merely because it is stored in the App.
We do not knowingly collect personal information online directly from a child. Optional analytics relate to the adult user's interaction with the App and must not include children's names, images, recordings, profiles, or other memory content.
If you permit a child to interact with the App on your device, you are responsible for supervising that use and for deciding what content may be created, stored, exported, or shared. If you believe that a child has provided personal information directly to us without appropriate authorization, contact us and we will investigate and delete the information where required.
10. How We Share Information
We do not sell personal information. We do not share personal information for cross-context behavioral advertising, targeted advertising, or third-party marketing.
We may disclose limited information to the following categories of recipients:
- Amplitude, for optional product analytics;
- RevenueCat, for purchase validation, entitlement management, subscription analytics, fraud prevention, and purchase restoration;
- Apple, for App distribution, device services, backups selected by the user, purchases, and subscriptions;
- Vercel, for Website hosting, delivery, security, and technical logs;
- Google, where our Gmail account processes support emails; and
- professional advisers, public authorities, courts, or other parties where disclosure is reasonably necessary to comply with law, protect legal rights, investigate fraud or security incidents, or protect users and others.
Where a service provider processes personal data on our behalf, we require it to process the data only for authorized purposes and subject to contractual, confidentiality, security, and data-protection obligations consistent with applicable law. Some providers, including Apple, may also act as independent controllers for their own processing.
If the App or relevant business assets are transferred as part of a merger, acquisition, financing, reorganization, or sale, information held by us may be transferred subject to appropriate safeguards and continued compliance with applicable law.
11. International Data Transfers
We are established in Hungary. Amplitude analytics data is configured for processing in Amplitude's EU data region. Some other service providers may process information in the United States or other countries outside your country of residence.
Where personal data is transferred from the EEA, the United Kingdom, or Switzerland to a country that has not been recognized as providing an adequate level of protection, the transfer is protected by an applicable legal mechanism, such as the European Commission's Standard Contractual Clauses, an adequacy decision, or another lawful safeguard provided by the relevant service provider.
You may contact us for additional information about the safeguards applicable to a particular transfer.
12. Data Security
We use reasonable technical and organizational measures designed to protect the limited personal data that we process. These measures include data minimization, local-first storage of memory content, encrypted network transmission by our service providers, access restrictions, and password-based encryption for App backups created through the relevant feature.
No storage or transmission method is completely secure. You are responsible for protecting access to your device, maintaining secure device credentials, selecting a strong backup password, and storing exported files in a safe location.
13. Your Privacy Rights and Choices
Depending on where you live, you may have the right to:
- request access to personal data that we hold about you;
- request correction of inaccurate personal data;
- request deletion of personal data;
- request restriction of processing;
- receive certain data in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent; and
- lodge a complaint with a competent data-protection authority.
You can manage local memory content directly in the App and may delete individual items or delete the App and its data. You can disable optional analytics in the App's settings.
To exercise a right concerning information processed by us or our processors, email andrasapps@gmail.com with the subject "Privacy Request – Kids Art & Photo Organizer." We may request information reasonably necessary to verify the request and locate the relevant record. Because the App does not use accounts and analytics identifiers are pseudonymous, we may be unable to associate a record with you unless you provide the relevant App-generated identifier.
We normally respond to valid requests within one month, subject to extensions permitted by applicable law. Rights may be limited where an exemption applies, where we cannot reasonably identify the relevant data, or where retention is required by law or necessary for legal claims.
If you are in the EEA, you may complain to the supervisory authority in the country where you live or work. In Hungary, the supervisory authority is the Hungarian National Authority for Data Protection and Freedom of Information (NAIH): https://www.naih.hu/.
14. Automated Decision-Making
We do not use personal data to make decisions based solely on automated processing that produce legal effects or similarly significant effects concerning you.
15. Third-Party Privacy Policies
For more information about relevant third-party practices, please review:
- Apple: https://www.apple.com/legal/privacy/
- Amplitude: https://amplitude.com/privacy
- RevenueCat: https://www.revenuecat.com/privacy
- Vercel: https://vercel.com/legal/privacy-policy
- Google: https://policies.google.com/privacy
These third-party policies govern processing carried out by those organizations in their own capacity. We are not responsible for destinations that you independently select when exporting, backing up, or sharing content.
16. Changes to This Privacy Policy
We may update this Privacy Policy to reflect changes to the App, our service providers, legal requirements, or our data practices. We will publish the updated version on this page and change the "Last updated" date. If a change materially affects how we process personal data, we will provide additional notice in the App where reasonably appropriate and obtain new consent where required by law.
17. Contact Us
If you have questions, concerns, or requests concerning this Privacy Policy or our privacy practices, contact:
Andras Molnar
Hungary
Email: andrasapps@gmail.com
