Baby Name Vote

Privacy Policy — Archistratix Baby Name Vote

Effective from: 23 September 2026 Operator: Archistratix s. r. o., Company ID 94644132, registered office Petrzilkova 2705/32, 158 00 Prague, Czech Republic — contact: support@archistratix.eu

This document describes exactly what the Archistratix Baby Name Vote app does with your data. It is written from the app's actual implementation, not from a generic template.

1. What data the app collects

DataSourceWhy
Emailentered at sign-in / received from your Google or Apple accountidentifying your account, sign-in code
Display namefrom your Google/Apple profile, or derived from your emailshown next to your votes and in the family member list
Avatar and colourrandomly assigned at first sign-intelling family members apart visually
Votes for namesyour activity in the appthe core function of the app — family voting
Names you addyour activity in the appthe family's shared list of names
Role in the family (admin/contributor/viewer)set by the family adminaccess control
Phone numberthe field is reserved in the data model but is not actively collected today (the app has no phone sign-in)—

The app does not collect: your location, phone contacts, photos, biometric data, content from other apps, or advertising identifiers (the app has no ads).

2. Where the data lives

All data is stored in Cloud Firestore (Google Firebase), in a project operated by the app's owner. Data is stored on Google servers in the European Union (europe-west region). Transfers are always encrypted (HTTPS/TLS).

Sign-in is handled by Firebase Authentication; if you sign in with Google or Apple, that provider verifies your identity and passes the app only your email and name.

An unfinished form stays on your phone. If you start creating a family and leave before finishing, the draft name, gender and selected calendars are saved to browser storage on the device. They are never sent anywhere. The only purpose is that you do not come back to an empty form — typically after switching to your mail app to fetch the sign-in code. The draft is deleted after seven days, once the family is created, on sign-out, and when the account is deleted.

An invite code waits on your phone too. When you receive an invite to a family — by link or as a code to type in — the eight-character code and a note about whether it arrived by link are saved to browser storage on the device. The reason is the same as for the form: so the invite is not lost while you switch to your mail app to fetch the sign-in code. The app sends the code to the server only at the moment it actually joins you to the family. Whether the invite arrived by link shows up in the anonymous usage statistics (see section 3c); the code itself never does. The stored code is deleted after seven days, as soon as you join the family, on sign-out, and when the account is deleted.

Apart from these two items, the app keeps only its own flags on the device — the chosen language, whether you have seen the intro screens, when it last asked for a rating, and whether you have seen the announcement of the chosen name. None of them are sent anywhere.

3. Who the app shares data with

The app does not sell your data and does not pass it to third parties for their own purposes. It uses only these processors, strictly to operate the app:

3b. Diagnostic data (error reports)

So that problems can be fixed before more people run into them, the app sends error reports automatically. A report contains:

Before sending, the app masks email addresses, invite codes and family content throughout the report — candidate names, the final name, member names, the family name and the child's surname. Up to version 3.27.0 those details could appear in reports.

Reports go to two places:

Reports are never used for profiling or advertising and are not combined with data from other apps. Diagnostic data is deleted automatically after 30 days.

3c. Usage statistics

To show where people get stuck, the app collects anonymous usage statistics. What is measured:

Not measured: names, emails, invite codes or anything from your family's content. The app only allows a fixed list of named values through; free text cannot get in at all.

Records are built in memory and one summary record is sent at the end of a session. Until you sign in, no user ID is attached — the record is stored without one and cannot be tied to a specific person. After sign-in the record carries your user ID so that retention can be measured.

Retention (how many people come back after 1 and 7 days) is computed from a one-way fingerprint of the account: the user ID is combined with a server-side secret and hashed. The ID cannot be recovered from it. Fingerprints are kept for 8 days and then delete themselves; only the resulting percentage is kept.

Where the account came from — a short label such as "invite", a campaign name from the link, or "direct" — is stored with the account at sign-up. It is used only to learn which ways into the app work, and is deleted together with the account.

Two things are stored on your device for this: your objection, if you make one (a "statistics off" flag), so that it applies before sign-in and after sign-out too, and — until you sign up — that where-from label. The session identifier lives in memory only and disappears when the app closes.

3e. IP address and abuse protection

Two parts of the app can be called without signing in: sending a sign-in code to an email address, and sending the statistics of a session that did not end with a sign-in. So that nobody can call them endlessly (and exhaust the email budget or flood the database), the server counts requests per caller IP address for both: at most 8 code requests and 12 statistics batches from one address within a ten-minute window. Only the address and a counter are stored — no link to an account, an email or the content of the request.

3d. A log you send yourself

Settings → General → Privacy has a Send log to support button. It is used only when you tap it — nothing is sent this way automatically. It uploads the app's operational log (the same one you can view in the app), passed through the same masking as error reports, and shows you a short code to put in your email to us. The legal basis is your own request. Only the app's author can read the log and it is deleted after 30 days.

4. How long the app keeps data

Data is kept for as long as your account and your family exist in the app. Sign-in codes expire within minutes. Crash reports are kept according to Firebase Crashlytics defaults.

5. Your rights (GDPR)

You have the right to access your data, to have it corrected, to data portability and to erasure. Erasure (deleting your account) is available directly in the app, without needing to contact us. For anything else, write to support@archistratix.eu.

Note: names, votes and other content you share with your family remain available to the other members after your account is deleted — this is shared family data, not only yours.

6. Children

The app is intended for parents and family members choosing a name for a baby — it is not aimed at children and does not knowingly collect data from children under 13.

7. Changes to this policy

If something substantial changes (for example a new data processor is added), the app will tell you at your next sign-in and the date at the top of this document will be updated.

8. Contact

Archistratix s. r. o. Company ID 94644132 Petrzilkova 2705/32, 158 00 Prague, Czech Republic Email: support@archistratix.eu