Privacy Policy

What technical data Babyphone Timmy needs, what is not collected and when data will be deleted again.

Stated: August 2026

1. Responsible person

Tim Kaltenbrunner
Schönauring 58
8052 Zurich
Switzerland
-Mail: tim.kaltenbrunner@gmail.com

2. What data is collected?

Babyphone Timmy only processes data that is necessary for connection and protection against misuse. In detail:

3. Which data is NOT collected?

Babyphone Timmy is built in such a way that, if possible, no personal data is processed:

4. Legal basis

The processing of the data mentioned under point 2 takes place on the following legal basis:

Swiss Data Protection Act (DSG)

The primary applicable law is the Swiss Federal Data Protection Act (DSG, in force since September 1, 2023):

DSGVO / UK GDPR (for EU/EEA and UK users)

For users in the European Union or the European Economic Area, the GDPR also applies; For users in the United Kingdom, the UK GDPR also applies:

5. Payment processing (subscription or one-time purchase)

Babyphone Timmy is offered as a paid monthly subscription or as a one-time premium purchase via the Google Play Store or Apple App Store. Payment processing is carried out entirely by the respective app store. We receive none Payment data (e.g. credit card numbers or bank details). For server-side purchase verification, the backend processes the product identifier as well as the purchase, transaction or receipt token provided by the store and the authorization result determined from this. These technical proofs of purchase may be associated with an anonymous app UID, but do not contain any credit card or banking information for us.

Information on data processing by the respective app store can be found here:

6. Third Party

Google Firebase

Provider: Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.
Services: Firebase Authentication (anonymous), Cloud Firestore, Cloud Functions, Firebase App Check and Firebase Hosting.
Data protection: firebase.google.com/support/privacy
Dhire country transfer: USA. The EU Commission’s Standard Contractual Clauses and the Swiss-US Data Privacy Framework apply.

Own TURN server

An own TURN server operated in Switzerland is preferred when a direct WebRTC connection is not possible.
Service: Forwarding of the already end-to-end encrypted WebRTC data stream. In particular, IP addresses, port, time and connection metadata are required for technical operation; Audio and video content cannot be decrypted and will not be recorded.
Storage period: Operational logs are limited to what is necessary for security, error analysis and capacity control and are periodically deleted.

Cloudflare

Provider: Cloudflare Inc., 101 Townsend St, San Francisco, CA 94107, USA.
Service: TURN relay server (Cloudflare Calls) for the WebRTC connection.
Only encrypted WebRTC traffic is forwarded. Cloudflare does not have access to the content of the communication (audio/video).
Data protection: cloudflare.com/privacypolicy
Third country transfer: USA. The standard contractual clauses of the EU Commission and the Swiss-US Data Privacy Framework apply.

Google Firebase Crashlytics

Provider: Google LLC, 1600 Amphitheater Parkway, Mountain View, CA 94043, USA.
Service: Crash and stability reports for release versions of the app. If the app crashes or encounters a fatal error, a diagnostic report is sent to Firebase Crashlytics so the error can be resolved.
Processed data: crash stack traces, app version, device model and operating system version, time of the crash and a Crashlytics installation identifier. This data does not include your name, email address, or audio or video data.
Legal basis: Art. 6 Para. 1 lit. f GDPR / Art. 31 Para. 1 DSG (legitimate interest in the stability and freedom from errors of the app).
Storage period: Crash reports are retained by Firebase Crashlytics for up to 90 days.
Data protection: firebase.google.com/support/privacy
Third country transfer: USA. The standard contractual clauses of the EU Commission and the Swiss-US Data Privacy Framework apply.

Discourse forum

For support questions and feature requests, the website links to an externally hosted discourse forum at babyphone-timmy.discourse.group. When you visit the forum or create an account there, Discourse or the respective forum host processes, among other things, the account, post, session and security data required for forum operation. The app itself remains separate and still does not use classic user accounts. Information about data protection at Discourse can be found at discourse.org/privacy.

7. Storage period

8. Your rights

According to the Swiss DSG (Art. 25-29 DSG)

You have the following rights in particular under the Swiss Data Protection Act:

Supervisory authority (Switzerland): EFederal Data Protection and Information Commissioner (EDÖB), www.edoeb.admin.ch

After GDPR / UK GDPR (for users in the EU/EEA and the UK)

For users in the European Union or the European Economic Area and the United Kingdom, the following additional rights apply:

No matter where you live, you can contact us to exercise your access and deletion rights; we will respond within the scope of applicable law.

9. Data protection for children

Babyphone Timmy is intended for use by adults (parents and caregivers). The App is not directed at children and we do not knowingly collect personal information from children. The app is operated by the supervising adult; The "baby" device only transmits live audio and optionally video via peer-to-peer to the paired parent device. We never collect, record or store this audio and video (see points 2 and 3). If we have received personal data from a child, please contact us - we will delete it immediately.

10. USA — Privacy rights in California and other states

We do not "sell" or "share" your personal information within the meaning of the California Consumer Privacy Act (CCPA/CPRA), or process it for cross-context behavioral advertising or targeted advertising. We do not use or disclose sensitive personal information for purposes that would trigger a right to restriction.

Residents of California and other US states with comprehensive data protection laws (such as Virginia, Colorado, Connecticut, Oregon, Texas and Utah) may exercise their rights under applicable law, including information, access, correction and deletion, by sending a message to tim.kaltenbrunner@gmail.com. We will not penalize you for exercising these rights.

11. Applicable Law

The Swiss Federal Data Protection Act (DSG) applies to data processing by Babyphone Timmy. The General Data Protection Regulation (GDPR) also applies to users in the European Union or the European Economic Area; For users in the United Kingdom, the UK GDPR also applies.

12. Hosting

This website is provided by Google through Firebase Hosting. Google and the backend/TURN services used can process technically necessary access and security protocols. We do not use these protocols for advertising, reach measurement or user profiles. Information about data protection at Firebase Hosting can be found at firebase.google.com/support/privacy.