1. Responsible person
Tim Kaltenbrunner
Schönauring 58
8052 Zurich
Switzerland
-Mail: tim.kaltenbrunner@gmail.com
2. What data is collected?
Babyphone Timmy only processes data that is necessary for connection and protection against misuse. In detail:
- Firebase Anonymous Auth UID – An automatically generated app-related pseudonymous identifier. It does not contain a name, email address or password, but remains on the device until the local app data or the anonymous Firebase account is reset.
- Firestore session data – Encrypted SDP offers and responses and encrypted ICE candidates. These technical connection data are required to establish the WebRTC connection. SDP/ICE data is removed from Firestore immediately after the connection is successfully established. The pseudonymous session data record and encrypted technical metadata will be completely deleted after 24 hours at the latest.
- Pairing codes —Temporary 4-digit codes for pairing two devices. The code can be exchanged locally between the two devices via Bluetooth, QR code or link. Not the plain text code is transmitted to Firestore, but only a document identifier derived with SHA-256. Since the short code is intentionally easy to read, this hash does not replace access control; The connection is protected by anonymous authentication, security rules, short validity and the additional ECDH key exchange with a visible security number. Pairing documents are deleted after one hour at the latest.
- App check and misuse protection data — Firebase App Check transmits attestation or integrity tokens and technically necessary device/app signals to Google or, on Apple devices, to Apple so that backend calls can be assigned to a real app installation and misuse can be limited.
3. Which data is NOT collected?
Babyphone Timmy is built in such a way that, if possible, no personal data is processed:
- No decrypted audio or video content on servers —Audio and video are end-to-end encrypted via WebRTC. If a direct connection is not possible, a TURN server only forwards the encrypted data stream. We do not record audio or video or store the content.
- No email addresses, no passwords – The app uses anonymous authentication only.
- No location data —No location data is collected or stored.
- No cookies in app and static website — The app and this website do not set their own cookies. After switching to the Discourse page, the external forum can use technically necessary cookies for registration and sessions.
- No advertising, no tracking — No advertising or marketing analysis, no tracking pixels, no advertising networks are used, and no profiling takes place. Only Firebase Crashlytics is used for crash and stability diagnostics in release versions (see point 6).
- No advertising IDs – The app does not access advertising IDs.
4. Legal basis
The processing of the data mentioned under point 2 takes place on the following legal basis:
Swiss Data Protection Act (DSG)
The primary applicable law is the Swiss Federal Data Protection Act (DSG, in force since September 1, 2023):
- Art. 31 Para. 1 DSG (legitimate interest) — The processing of technical connection data and anonymous authentication are carried out in the overriding legitimate interest of providing the app functionality and protecting the app from misuse.
DSGVO / UK GDPR (for EU/EEA and UK users)
For users in the European Union or the European Economic Area, the GDPR also applies; For users in the United Kingdom, the UK GDPR also applies:
- Art. 6 Paragraph 1 Letter b GDPR (contract fulfillment) — The technical connection data is required to provide the app functionality.
- Art. 6 Paragraph 1 Letter f GDPR (Legitimate interest) — Anonymous authentication serves the legitimate interest of protecting the app from misuse.
5. Payment processing (subscription or one-time purchase)
Babyphone Timmy is offered as a paid monthly subscription or as a one-time premium purchase via the Google Play Store or Apple App Store. Payment processing is carried out entirely by the respective app store. We receive none Payment data (e.g. credit card numbers or bank details). For server-side purchase verification, the backend processes the product identifier as well as the purchase, transaction or receipt token provided by the store and the authorization result determined from this. These technical proofs of purchase may be associated with an anonymous app UID, but do not contain any credit card or banking information for us.
Information on data processing by the respective app store can be found here:
- Google Play: policies.google.com/privacy
- Apple: apple.com/legal/privacy
6. Third Party
Google Firebase
Provider: Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.
Services: Firebase Authentication (anonymous), Cloud Firestore, Cloud Functions, Firebase App Check and Firebase Hosting.
Data protection: firebase.google.com/support/privacy
Dhire country transfer: USA. The EU Commission’s Standard Contractual Clauses and the Swiss-US Data Privacy Framework apply.
Own TURN server
An own TURN server operated in Switzerland is preferred when a direct WebRTC connection is not possible.
Service: Forwarding of the already end-to-end encrypted WebRTC data stream. In particular, IP addresses, port, time and connection metadata are required for technical operation; Audio and video content cannot be decrypted and will not be recorded.
Storage period: Operational logs are limited to what is necessary for security, error analysis and capacity control and are periodically deleted.
Cloudflare
Provider: Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Service: TURN relay server (Cloudflare Calls) for the WebRTC connection.
Only encrypted WebRTC traffic is forwarded. Cloudflare does not have access to the content of the communication (audio/video).
Data protection: cloudflare.com/privacypolicy
Third country transfer: USA. The standard contractual clauses of the EU Commission and the Swiss-US Data Privacy Framework apply.
Google Firebase Crashlytics
Provider: Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.
Service: Crash and stability reports for release versions of the app. If the app crashes or encounters a fatal error, a diagnostic report is sent to Firebase Crashlytics so the error can be resolved.
Processed data: crash stack traces, app version, device model and operating system version, time of the crash and a Crashlytics installation identifier. This data does not include your name, email address, or audio or video data.
Legal basis: Art. 6 Para. 1 lit. f GDPR / Art. 31 Para. 1 DSG (legitimate interest in the stability and freedom from errors of the app).
Storage period: Crash reports are retained by Firebase Crashlytics for up to 90 days.
Data protection: firebase.google.com/support/privacy
Third country transfer: USA. The standard contractual clauses of the EU Commission and the Swiss-US Data Privacy Framework apply.
Discourse forum
For support questions and feature requests, the website links to an externally hosted discourse forum at babyphone-timmy.discourse.group. When you visit the forum or create an account there, Discourse or the respective forum host processes, among other things, the account, post, session and security data required for forum operation. The app itself remains separate and still does not use classic user accounts. Information about data protection at Discourse can be found at discourse.org/privacy.
7. Storage period
- Session data (SDP and ICE candidates): They are deleted immediately after the connection is established; pseudonymous session metadata after 24 hours at the latest.
- Pairing documents: They will be deleted after one hour at the latest.
- Anonymous auth UIDs: They generally remain in place until the anonymous account or local app data is reset. They do not contain any direct master data, but are pseudonymous identifiers.
- Proof of Purchase: Store tokens and transaction data are only processed or stored as necessary for purchase verification, recovery, fraud prevention and premium eligibility assignment.
8. Your rights
According to the Swiss DSG (Art. 25-29 DSG)
You have the following rights in particular under the Swiss Data Protection Act:
- Right to information (Art. 25 DSG) — You can request information about the data you process.
- Right to data release and transfer (Art. 28 DSG) — You can receive your data in a common format.
- Right to rectification (Art. 32 Para. 1 DSG) — You can request the correction of incorrect data.
- Right to deletion — You can request the deletion of your data, provided there is no legal retention requirement to the contrary.
Supervisory authority (Switzerland): EFederal Data Protection and Information Commissioner (EDÖB), www.edoeb.admin.ch
After GDPR / UK GDPR (for users in the EU/EEA and the UK)
For users in the European Union or the European Economic Area and the United Kingdom, the following additional rights apply:
- Information (Art. 15 GDPR) — You can request information about the data you process.
- Correction (Art. 16 GDPR) — You can request the correction of incorrect data.
- Delete (Art. 17 GDPR) — You can request the deletion of your data.
- Restriction of processing (Art. 18 GDPR) — You can request the restriction of processing.
- Data portability (Art. 20 GDPR) — You can receive your data in a common format.
- Contradiction (Art. 21 GDPR) — You can object to the processing.
- Complaint to the supervisory authority — You have the right to complain to a data protection supervisory authority in your country. In the UK you can contact the Information Commissioner's Office (ICO): ico.org.uk.
No matter where you live, you can contact us to exercise your access and deletion rights; we will respond within the scope of applicable law.
9. Data protection for children
Babyphone Timmy is intended for use by adults (parents and caregivers). The App is not directed at children and we do not knowingly collect personal information from children. The app is operated by the supervising adult; The "baby" device only transmits live audio and optionally video via peer-to-peer to the paired parent device. We never collect, record or store this audio and video (see points 2 and 3). If we have received personal data from a child, please contact us - we will delete it immediately.
10. USA — Privacy rights in California and other states
We do not "sell" or "share" your personal information within the meaning of the California Consumer Privacy Act (CCPA/CPRA), or process it for cross-context behavioral advertising or targeted advertising. We do not use or disclose sensitive personal information for purposes that would trigger a right to restriction.
Residents of California and other US states with comprehensive data protection laws (such as Virginia, Colorado, Connecticut, Oregon, Texas and Utah) may exercise their rights under applicable law, including information, access, correction and deletion, by sending a message to tim.kaltenbrunner@gmail.com. We will not penalize you for exercising these rights.
11. Applicable Law
The Swiss Federal Data Protection Act (DSG) applies to data processing by Babyphone Timmy. The General Data Protection Regulation (GDPR) also applies to users in the European Union or the European Economic Area; For users in the United Kingdom, the UK GDPR also applies.
12. Hosting
This website is provided by Google through Firebase Hosting. Google and the backend/TURN services used can process technically necessary access and security protocols. We do not use these protocols for advertising, reach measurement or user profiles. Information about data protection at Firebase Hosting can be found at firebase.google.com/support/privacy.