BabyDuo — Privacy Policy
English · Deutsch · Español · Français · Italiano · Svenska
Effective 2026-09-02
Who is responsible
David Ammer, Austria — contact: support@ammerbrothers.at ("we"). Our postal address is in the legal notice. This policy covers the BabyDuo mobile app, its server and the website babyduo.at.
What data we process
Account data: a display name, your email address and — if you sign up with one — a password (stored as a salted hash, never in plain text). Every account has an email address: it is how you sign in, how you get a new password, and the only way we can reach you about your account. Sign in with Google / Apple: if you use one of these buttons, we receive from the provider only a stable user identifier and your email address, and store them to identify your account — no contacts, no profile beyond an optional first name. An account created this way has no password at all. Apple lets you hide your real address behind a relay address, which works here. We never receive your password, and deleting your account also revokes our access at Apple. App data: your swipes (likes/passes), matches with your partner, name suggestions and ratings are stored on our server so the app can work across your devices and with your partner. Push tokens: if your device supports it, a Firebase Cloud Messaging token is stored to deliver match notifications. Purchases: the ad-free pass is bought through Apple's App Store or Google Play; payment runs entirely through Apple or Google, and we never see your payment details. We receive and store only the store's transaction identifier, the product bought and the resulting pass expiry, to grant the pass, restore it on your devices and reconcile refunds.
What your partner sees
BabyDuo only works because two people share some of what they do in it. This is what crosses over, and nothing else does.
Before you are linked, someone who types your partner code sees your display name, so they know whose account they are asking to join — nothing more, and the link only happens if you accept the request.
Once you are linked, your partner sees the names you both liked (a match) and your 1–5 rating of each of them, the names you suggested — they are dealt into their deck, and once one becomes a match they are told it came from you as well, unless you turn "Reveal my suggestions" off in Settings — and whether you liked or passed a name they suggested. Your other swipes are never shown to anyone: a pass on a catalogue name stays yours alone.
Legal basis: performance of the contract you asked for (Art. 6(1)(b) GDPR) — sharing these things with the person you linked with is the service. You can end it at any time by unlinking or deleting your account.
Emails we send
We send transactional email only: the confirmation link when you register, a password-reset link when you ask for one, a note if someone tries to register an account with your address, and security notices about your own account — for example when a Google or Apple sign-in is added to an account that already has a password. There is no newsletter and no marketing mail, so there is nothing to unsubscribe from; the confirmation and reset mails are part of running the account (Art. 6(1)(b) GDPR), the sign-up note and the security notice are our legitimate interest in telling you about something that concerns your account (Art. 6(1)(f) GDPR).
Request logs
Our server writes one line per request: the time, the method and path (e.g. GET /api/names/next), the response status, how long it took, your account id if you were signed in, and the IP address the request came from. Request bodies and headers are never logged — they hold passwords and tokens — and neither is the text you type into the name search. The lines exist to find faults and to spot abuse (legitimate interest, Art. 6(1)(f) GDPR).
Two more things ride on that line, and they are worth naming rather than leaving to an "and so on": when a request fails, the error message we sent back to the app is appended as error=… (our wording, never yours); and on the deck, the name directory and the leaderboard, the filter you had set, as codes — for example countries=AT gender=f. Without the filter, a report like "I picked Austria and still got American names" could not be settled.
These lines are kept only briefly, and the limit is a size rather than a date: the server holds a small, fixed amount of log data (about 3 MB) and overwrites the oldest entries automatically as new requests come in, which in normal use means a few days. Logs are never archived and never backed up, so an overwritten line is gone.
The website
This policy also covers babyduo.at, the app's website, which the same server serves. Opening it is processed like any request to that server: the web server in front of it writes one access-log line with the time, the address of the page, the response status, your browser's identification string (user agent), the page that linked you here if your browser sends it, and your IP address — on the same basis as the request logs above (legitimate interest, Art. 6(1)(f) GDPR: finding faults and spotting abuse), bounded the same way (a small, fixed amount of log data, the oldest lines overwritten as new visits arrive, nothing archived), and never linked to an account, because the website has no sign-in.
The website sets no cookies, uses no analytics and loads nothing from anyone else: its fonts, images and store badges come from our own server, so no third party learns of your visit. The two store badges are plain links — nothing reaches Apple or Google until you tap one, and what then reaches them (your IP address and the address of the page you came from) they process under their own privacy policies.
Device check at sign-up
When you create an account, the app asks your device's operating system for proof that it is a real, unmodified device — Google Play Integrity on Android, Apple App Attest on iOS. Google or Apple process technical device data for this and give us a signed verdict; we store a key identifier for that installation, the matching public key and a counter of how often the key has been used, never linked to your name or email. This protects sign-up against automated abuse (legitimate interest, Art. 6(1)(f)).
Advertising (Google AdMob)
The app shows interstitial ads (full-screen ads between app screens) via Google AdMob. In the European Economic Area you are asked for consent first via Google's consent dialog; depending on your choice, Google and its certified ad partners may process your device's advertising ID and technical device data to show and measure ads (personalized only with your consent). You can change or withdraw your choices at any time in the app under Settings → Privacy → Privacy options. Details: Google's privacy policy and Google's ad partners.
If you decline. The app keeps working and still shows
ads, but only non-personalized ones: they are chosen from the context, not
from a profile, and they use no advertising identifier and no consent-based
storage on your device. On Android the app declares the
com.google.android.gms.permission.AD_ID permission, which is
what allows the advertising ID to be read at all — declining means it is not
read or sent. On iOS, if Apple's tracking prompt appears, declining it has
the same effect.
Who else processes your data
Two different relationships are listed below, and the difference matters. Some of these companies only do what we instruct them to — processors under Art. 28 GDPR, bound by a data processing agreement where the law requires one. Others decide for themselves what they do with the data and answer for it under their own privacy policies. Google and Apple appear in both lists, because their role depends on which of their services is involved.
Processors acting on our instructions (Art. 28 GDPR):
- Hetzner Online GmbH, Nuremberg, Germany — the server and the database the app talks to. Your account and app data live there, inside the EU.
- World4You Internet Services GmbH, Austria — the mail server that delivers the confirmation, reset and security emails described above.
- Google — Firebase Cloud Messaging, which delivers the push notifications, and Play Integrity, which answers the sign-up device check on Android.
- Apple — App Attest, which answers the same device check on iOS.
Independent controllers, under their own privacy policies:
- Google — AdMob and its certified ad partners for advertising (see the advertising section above); Google Play for purchases, where the seller is Google and not us; and Sign in with Google, where Google decides for itself what it records about the sign-in.
- Apple — the App Store for purchases, where the seller is Apple and not us, and Sign in with Apple on the same footing.
What these two do as controllers is set out in Google's privacy policy and Apple's privacy policy. Beyond the parties named here we pass your data to no one. We do not sell it and we do not share it for anyone else's advertising.
International data transfers
Google and Apple may process the data mentioned above on servers outside the European Economic Area, in particular in the USA. These transfers rely on the EU–US Data Privacy Framework and EU standard contractual clauses (Art. 46 GDPR). Hosting and mail stay inside the EU.
Legal bases (GDPR)
Providing the app, granting the ad-free pass you bought and syncing with your partner: performance of contract (Art. 6(1)(b)). Personalized advertising: your consent (Art. 6(1)(a)), revocable at any time. Security logging, the sign-up device check and abuse prevention: legitimate interest (Art. 6(1)(f)).
Retention and deletion
Your data is kept while your account exists. You can delete your account at any time in the app (Settings → Delete account); this permanently removes your account and app data from our server. Beyond that, the limits below apply on their own:
- Account and app data: until you delete the account.
- A registration whose confirmation link was never followed: deleted after 30 days.
- Sign-in, confirmation and password-reset tokens: removed 7 days after they expire.
- Push notification tokens: until you log out or delete the account, and at most 10 per account — the oldest is dropped when a newer device registers.
- Device attestation records: deleted after 12 months without use.
- Request logs: only until newer requests have overwritten them inside the 3 MB the server keeps — a few days in normal use, and never archived.
Purely local data (e.g. filters, swipe energy) lives only on your device and disappears when you uninstall.
Your rights
You have the right to access, rectification, erasure, restriction of processing and data portability. Contact us at support@ammerbrothers.at.
Objection. You may object at any time to processing we base on our legitimate interest — the request logs and the sign-up device check — on grounds relating to your particular situation (Art. 21(1) GDPR).
Withdrawing consent. Where we rely on your consent (personalized advertising), you may withdraw it at any time in the app under Settings → Privacy → Privacy options. Withdrawal takes effect from then on and does not affect the lawfulness of what was processed before it.
What you have to give us. To open an account we need an email address, either a password or a Google/Apple sign-in, and a display name — without these there is no account and no app. Everything else is optional: a family name, filters, name suggestions, ratings, a partner link and push notifications are all things you choose to add.
No automated decisions. We make no decisions about you with legal or similarly significant effect by automated means, and we do not profile you (Art. 22 GDPR).
Complaints. You may lodge a complaint with the Austrian supervisory authority: Österreichische Datenschutzbehörde, Barichgasse 40-42, 1030 Wien, Austria — dsb@dsb.gv.at, dsb.gv.at.
Children
BabyDuo is made for adults choosing a baby name and is not directed at children. You must be at least 16 to have an account. If we learn that an account belongs to someone younger, we delete it and its data.
If you live in the United States
We are an Austrian sole trader, far below the revenue and volume thresholds at which California's CCPA/CPRA start to apply, so those laws do not bind us. We give you the rights below anyway: whether a threshold was met is not something a reader should have to work out.
Categories of personal information we collect: identifiers (your email address and your account id); internet or app activity (your swipes, your matches and the names you suggested); device identifiers (your push notification token and, through Google AdMob, your device's advertising identifier); and commercial information (the store's transaction record behind an ad-free pass). Why we collect each of them, who receives it and how long we keep it are in the sections above.
We do not sell your personal information — not for money and not for anything else of value. The only thing that counts as "sharing" for cross-context behavioural advertising is personalized advertising through Google AdMob, and it happens only if you have consented to it. You can stop it in the app under Settings → Privacy → Privacy options where the app offers that control, at any time through your device's advertising settings (Android: "Delete advertising ID", or opt out of ads personalisation; iOS: Settings → Privacy → Apple Advertising, and Settings → Privacy → Tracking), and by declining the consent form when it is shown.
You have the right to know what personal information we hold about you, to have it deleted, to have it corrected, and to opt out of the sharing described above — and we will never treat you worse for exercising any of them: no higher price, no reduced service, no penalty. Write to support@ammerbrothers.at from the address your account is registered with, or delete the account yourself in the app, which does the same thing immediately.
Changes
We will update this page when the app's data processing changes; the current version is always available at this address and carries the date above.