Skip to content
Kimda
HomeSupportPrivacy
🌐 English
  • Čeština
  • Slovenčina
  • Русский
  • English
  • Deutsch
  • Français
  • Español
  • Italiano
  • Polski
  • Português
  • Nederlands
  • Українська
  • Türkçe
  • العربية
  • 中文
  • 日本語
  • 한국어
  • हिन्दी
  • Tiếng Việt
  • ไทย
  • Ελληνικά
  • Română
  • Magyar
  • Svenska
  • Norsk
  • Dansk
  • Suomi
  • Hrvatski
  • Български
  • Српски
  • עברית
  • Bahasa Indonesia
🎨 Theme

Kimda

Privacy Policy

Last updated: 18 September 2026

This is a translation. The Czech version is legally binding.

This document describes what data the Kimda app (“the app”, “we”) collects, why, how long it keeps it and what rights you and your children have. The app is designed to be used by the whole family, including children – which is why we take particular care in protecting data.

1. Who is the data controller

The data controller is Ivo Slávka, who operates the Kimda app as a natural person. Contact email for privacy questions: privacy@kimda.app.

2. What data we collect

  • Account details: first name, last name, phone number, role (parent/child), selected language.
  • We use the phone number exclusively for identity verification (SMS code) and sign-in – the app does not otherwise message anyone at that number or share it with third parties other than the SMS verification provider (Twilio, see section 4).
  • Family details: family name, who belongs to it, each member’s role and settings (pocket money split percentages, currency).
  • Task details: task name, points, when it was completed/approved/rejected, and photos if the task requires a photo.
  • Plans, routines and reminders: who a task is assigned to, the scheduled day and time, completion status, delay, rotation order and whether a reminder was sent.
  • Rewards and goals: the family rewards catalogue, reward requests, savings goals and the amounts a child has moved towards a goal. From this data, the parent overview derives aggregate completion, timeliness and fairness of assignment; it does not create a public ranking of children.
  • In-app financial data: points, virtual pocket money and how it is split – these are internal app points, not real banking/payment details. The app has no access to any bank account or payment card.
  • Technical data: push notification token (to deliver notifications), basic server logs (request time, error states) for operating and securing the app.

3. Task photos

Photos that a child uploads for a task can be seen only by members of the same family (parents and children in the app). They are not public, and the app does not share them with any other app or social network. Photos are stored on the app’s server (or with the chosen cloud storage, if the app operator uses this setting), and a parent can request their deletion at any time.

4. Which third parties we share data with

  • Twilio (phone verification by SMS code) – the phone number is sent to Twilio solely for the purpose of delivering and verifying the SMS code.
  • Expo/push notifications – to deliver notifications to the app, we use the Expo service, which receives the technical push token, a generic notification text/emoji and a generic technical event type. We do not send database IDs, names, task names or amounts in push messages. Expo forwards the message to Apple’s or Google’s push service.
  • RevenueCat (processing of subscriptions via the App Store / Google Play, for parent accounts only) – processes the family identifier, purchase history, the Apple receipt or Google purchase token, time of last use and technical device data (e.g. device type and operating system). It does not receive the name or phone number of any parent or child from Kimda. RevenueCat advertising/attribution integrations and manual collection of advertising identifiers are not enabled in the app.
  • Sentry (technical error logs from the app, for fixing bugs) – the app is configured not to send it personal data (name, phone number, sign-in token) or IP addresses.
  • Hosting provider (e.g. Railway/Render) – this is where the app runs and where the data is stored in the database.
  • Private object storage provider (e.g. Cloudflare R2 or AWS S3) – stores profile photos and photos of completed tasks, transferred in encrypted form, in a non-public bucket; access to them remains controlled by the authenticated Kimda backend.

We do not sell data, share it with advertisers or use it for targeted advertising.

5. Parental consent and children’s roles

Only an adult may set up the app (the “parent” role and a new family). An account with the “child” role is only ever created after joining with an invite code that only the parent knows – so a child can only take part with the knowledge and consent of the parent who shares the code. By registering in the “parent” role, you confirm that you are of legal age and that you have the legal right to consent to the processing of your children’s data in the app.

6. How long we keep data

We keep data in the app for as long as the family actively uses the app. Unattached photos that could not be assigned to a profile or task are automatically deleted by the server after 24 hours. Before public launch, operational logs and backups must have a specific retention period set and described in internal documentation according to the chosen hosting. You can request deletion of the entire family or of a specific member at any time – see section 7.

7. Your rights

You have the right to request at any time:

  • access to all data the app keeps about your family,
  • correction of inaccurate data,
  • deletion of an individual member’s account (parent or child) – directly in the app (Profile → Delete account), the app irreversibly removes/anonymizes the name, phone number, photo and push token, and also deletes all photos you uploaded for your tasks, so the account can no longer be used to sign in or be identified. The app deliberately does not delete the rest of the task and payment history (task name, points and when it was approved), even after the account is deleted – the user’s free-text note is deleted, and the history remains linked to the rest of the family (otherwise their mutual accounting would no longer add up), but it is tied only to an anonymized record, not to your name or contact details,
  • cascading deletion of the entire family – when the last parent explicitly confirms deletion of the entire family, we anonymize all its members and photos and, in addition, replace free texts and the names of custom tasks, goals and rewards with neutral values. Before completing, the backend asks RevenueCat to permanently delete the family’s customer record; in the event of a temporary error, the request is safely retried. RevenueCat carries out the deletion asynchronously. This does not cancel a subscription managed by the App Store or Google Play – the parent must cancel it separately in the settings of the relevant store,
  • export of data in a readable format.

Send your request to privacy@kimda.app. We will respond within 30 days at the latest.

8. Security

The app does not use passwords (sign-in only via a verified phone number); access to the app is protected by a sign-in token with limited validity. In production, communication between the app and the server takes place over HTTPS. Photos are kept in non-public storage, and before releasing them the backend verifies the account and membership of the same family.

9. Changes to this policy

We will inform you in the app of any material change to this policy before it takes effect.

10. Contact

Questions about personal data protection: privacy@kimda.app

Kimda – the family app for chores and pocket money
Privacy Policy Terms of Use Support Account deletion

© 2026 Ivo Slávka, Czech Republic · support@kimda.app