Privacy Policy — Archistratix Baby Name Vote
Effective from: 23 September 2026 Operator: Archistratix s. r. o., Company ID 94644132, registered office Petrzilkova 2705/32, 158 00 Prague, Czech Republic — contact: support@archistratix.eu
This document describes exactly what the Archistratix Baby Name Vote app does with your data. It is written from the app's actual implementation, not from a generic template.
1. What data the app collects
| Data | Source | Why |
|---|---|---|
| entered at sign-in / received from your Google or Apple account | identifying your account, sign-in code | |
| Display name | from your Google/Apple profile, or derived from your email | shown next to your votes and in the family member list |
| Avatar and colour | randomly assigned at first sign-in | telling family members apart visually |
| Votes for names | your activity in the app | the core function of the app — family voting |
| Names you add | your activity in the app | the family's shared list of names |
| Role in the family (admin/contributor/viewer) | set by the family admin | access control |
| Phone number | the field is reserved in the data model but is not actively collected today (the app has no phone sign-in) | — |
The app does not collect: your location, phone contacts, photos, biometric data, content from other apps, or advertising identifiers (the app has no ads).
2. Where the data lives
All data is stored in Cloud Firestore (Google Firebase), in a project operated by the app's owner. Data is stored on Google servers in the European Union (europe-west region). Transfers are always encrypted (HTTPS/TLS).
Sign-in is handled by Firebase Authentication; if you sign in with Google or Apple, that provider verifies your identity and passes the app only your email and name.
An unfinished form stays on your phone. If you start creating a family and leave before finishing, the draft name, gender and selected calendars are saved to browser storage on the device. They are never sent anywhere. The only purpose is that you do not come back to an empty form — typically after switching to your mail app to fetch the sign-in code. The draft is deleted after seven days, once the family is created, on sign-out, and when the account is deleted.
An invite code waits on your phone too. When you receive an invite to a family — by link or as a code to type in — the eight-character code and a note about whether it arrived by link are saved to browser storage on the device. The reason is the same as for the form: so the invite is not lost while you switch to your mail app to fetch the sign-in code. The app sends the code to the server only at the moment it actually joins you to the family. Whether the invite arrived by link shows up in the anonymous usage statistics (see section 3c); the code itself never does. The stored code is deleted after seven days, as soon as you join the family, on sign-out, and when the account is deleted.
Apart from these two items, the app keeps only its own flags on the device — the chosen language, whether you have seen the intro screens, when it last asked for a rating, and whether you have seen the announcement of the chosen name. None of them are sent anywhere.
3. Who the app shares data with
The app does not sell your data and does not pass it to third parties for their own purposes. It uses only these processors, strictly to operate the app:
- Google Firebase (Authentication, Firestore, Cloud Functions, Cloud Messaging, Crashlytics) — data storage, sign-in, notifications, crash reports.
- Resend — delivery of sign-in code emails.
- RevenueCat — subscription and purchase management.
- Anthropic — AI name suggestions; only the text of your request is sent, never your account data.
3b. Diagnostic data (error reports)
So that problems can be fixed before more people run into them, the app sends error reports automatically. A report contains:
- the error message and the technical stack trace,
- the app version, platform (iOS/Android/web) and selected language,
- your user ID and family ID,
- a record of what the app was doing just before the error (the operational log),
- up to the last 40 steps before the error: names of screens, buttons and server functions, their durations and error codes. Nothing you type gets in — the app only lets short technical names through.
Before sending, the app masks email addresses, invite codes and family content throughout the report — candidate names, the final name, member names, the family name and the child's surname. Up to version 3.27.0 those details could appear in reports.
Reports go to two places:
- the Firebase database, where only the app's author can read them,
- the author's support mailbox (support@archistratix.eu), and only for the first occurrence of each kind of error.
Reports are never used for profiling or advertising and are not combined with data from other apps. Diagnostic data is deleted automatically after 30 days.
3c. Usage statistics
To show where people get stuck, the app collects anonymous usage statistics. What is measured:
- which screens were opened, in what order and how long they lasted,
- counts of actions, votes and errors within one session,
- steps of onboarding, the new-family form and sign-in,
- app version, platform and selected language.
Not measured: names, emails, invite codes or anything from your family's content. The app only allows a fixed list of named values through; free text cannot get in at all.
Records are built in memory and one summary record is sent at the end of a session. Until you sign in, no user ID is attached — the record is stored without one and cannot be tied to a specific person. After sign-in the record carries your user ID so that retention can be measured.
Retention (how many people come back after 1 and 7 days) is computed from a one-way fingerprint of the account: the user ID is combined with a server-side secret and hashed. The ID cannot be recovered from it. Fingerprints are kept for 8 days and then delete themselves; only the resulting percentage is kept.
Where the account came from — a short label such as "invite", a campaign name from the link, or "direct" — is stored with the account at sign-up. It is used only to learn which ways into the app work, and is deleted together with the account.
Two things are stored on your device for this: your objection, if you make one (a "statistics off" flag), so that it applies before sign-in and after sign-out too, and — until you sign up — that where-from label. The session identifier lives in memory only and disappears when the app closes.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — operating and improving the app.
- Retention: 90 days for individual records; aggregated daily counts, which contain no personal data, are kept indefinitely.
- How to turn it off: Settings → General → Privacy → Anonymous usage statistics, or — before signing in — the Turn off link next to "Anonymous usage statistics" on the welcome screen. It takes effect immediately, discards whatever is pending, and stays off after sign-out.
3e. IP address and abuse protection
Two parts of the app can be called without signing in: sending a sign-in code to an email address, and sending the statistics of a session that did not end with a sign-in. So that nobody can call them endlessly (and exhaust the email budget or flood the database), the server counts requests per caller IP address for both: at most 8 code requests and 12 statistics batches from one address within a ten-minute window. Only the address and a counter are stored — no link to an account, an email or the content of the request.
- Legal basis: legitimate interest (Art. 6(1)(f) GDPR) — protecting the service from abuse.
- Retention: the record is deleted automatically within 24 hours (daily clean-up), even though the window itself lasts only 10 minutes.
- Firebase (Google) additionally keeps IP addresses in its own operational logs under its own terms — see section 3.
3d. A log you send yourself
Settings → General → Privacy has a Send log to support button. It is used only when you tap it — nothing is sent this way automatically. It uploads the app's operational log (the same one you can view in the app), passed through the same masking as error reports, and shows you a short code to put in your email to us. The legal basis is your own request. Only the app's author can read the log and it is deleted after 30 days.
4. How long the app keeps data
Data is kept for as long as your account and your family exist in the app. Sign-in codes expire within minutes. Crash reports are kept according to Firebase Crashlytics defaults.
5. Your rights (GDPR)
You have the right to access your data, to have it corrected, to data portability and to erasure. Erasure (deleting your account) is available directly in the app, without needing to contact us. For anything else, write to support@archistratix.eu.
Note: names, votes and other content you share with your family remain available to the other members after your account is deleted — this is shared family data, not only yours.
6. Children
The app is intended for parents and family members choosing a name for a baby — it is not aimed at children and does not knowingly collect data from children under 13.
7. Changes to this policy
If something substantial changes (for example a new data processor is added), the app will tell you at your next sign-in and the date at the top of this document will be updated.
8. Contact
Archistratix s. r. o. Company ID 94644132 Petrzilkova 2705/32, 158 00 Prague, Czech Republic Email: support@archistratix.eu