Privacy Policy

Bunky — shared family wiki for co-parents · Last updated: 11 September 2026 · Version 1.2

This Privacy Policy explains how Bunky ("Bunky", "we", "us") collects, uses, shares and protects personal data when you use our web application and website at bunky.ch and app.bunky.ch (the "Service").

We are based in Switzerland and offer the Service to users worldwide. We have built our privacy practices to meet the standards of the EU/EEA General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP/revDSG), which we apply as our global baseline. Depending on where you live, additional local rights may apply.

1. Who is responsible for your data (Controller)

Bunky — operated by Kralovic Services (Jan Kralovič), a sole proprietorship registered in Switzerland, Seestrasse 286, 8810 Horgen, Switzerland · UID CHE-317.332.653.
Contact for privacy matters: privacy@bunky.ch.

2. A note on tracking and advertising

Bunky does not use third-party analytics, advertising networks, tracking pixels or advertising cookies. We do not sell or share your personal data for advertising or marketing by third parties. We use only the storage strictly necessary to run the app (see §9).

3. What data we collect

Account & profile

When you create an account — with Google Sign-In or with an email address and password — we store your name, email address and account identifier. With Google Sign-In these come from your Google account. Your password is handled by our authentication provider (Google Firebase Authentication) and is never stored in our database. You may add a display avatar, preferred language, and an optional phone number (used for the emergency card shown to the other parent).

Family & children data (entered by you)

Bunky is a shared wiki for a child's information. Parents enter data about their child(ren), which may include: name, date of birth/age, general information, health information (allergies, blood group, medications, vaccinations, medical history), doctors and their specialisation/contact details, school information and timetable, contacts, custody and vacation schedules, shared expenses, notes and tasks, and emergency ("SOS") details.

Health information is a special category of personal data. We process it on the basis of each parent’s explicit consent (Art. 9(2)(a) GDPR). Consent is asked for separately — it is not part of accepting our Terms, and the rest of Bunky works without it — and each parent gives their own, as the child’s guardian. When you consent, we record on our server what you consented to, the version of this policy you were shown, and the time. You may protect selected sensitive fields with a PIN; those fields are encrypted on your device (AES-256-GCM) before storage.

Family structure

Family membership, roles, and invitations (including the email address of a person you invite).

Waitlist

If you join our waitlist on bunky.ch, we store your email address (as a hashed identifier plus the address), your language, and basic technical details of the signup: your browser’s user-agent string and, where present, the campaign parameters (utm_*) in the link you arrived on and the address of the referring website. Those last two tell us which channel a signup came from; they are recorded only the first time you sign up and are capped in length. To limit abuse of the form we also keep a short-lived counter against a hashed version of your IP address — the raw address is never stored. We use this to send you a confirmation, to notify you at launch, and to understand which channels reach people. Basis: your consent, and our legitimate interest in preventing abuse of the form.

Payment data

Subscriptions are sold and processed by our Merchant of Record (payment provider). Your card/payment details are handled by that provider — we do not receive or store your full payment details. We store only your subscription status and provider customer/subscription identifiers.

Technical data

Standard server logs generated by our hosting providers (e.g. IP address, timestamps, device/browser type) for security and to operate the Service; calendar-feed (iCal) access tokens if you enable them; and an activity/history log of actions within a family (with server-set timestamps).

4. How we use your data and our legal bases

PurposeLegal basis (GDPR)
Provide and operate the Service (accounts, sharing, calendars, exports)Performance of a contract — Art. 6(1)(b)
Process health/other special-category data you enterYour explicit consent — Art. 9(2)(a)
Send the waitlist confirmation / launch noticeConsent — Art. 6(1)(a)
Security, abuse prevention, service integrityLegitimate interests — Art. 6(1)(f)
Retain shared family records after a parent leaves (see §7)Contract with the remaining parent — Art. 6(1)(b); legal claims — Art. 17(3)(e); legitimate interests — Art. 6(1)(f)
Comply with legal obligationsLegal obligation — Art. 6(1)(c)

You can withdraw consent at any time (this does not affect processing already carried out).

5. Children's data

Bunky is intended for use by adults (parents/guardians). Children do not create accounts and do not enter their own data. Parents enter and control information about their child(ren) and are responsible for ensuring they are entitled to do so. The Service is not directed to children. If you believe data was entered without proper authority, contact us (§10).

6. Who we share data with (processors)

We share data with other members of your family (that is the purpose of the app) and with service providers who process data on our behalf under data-processing agreements:

ProviderPurposeLocation
Google Firebase (Firestore, Authentication, Cloud Functions)Core database, sign-in, backendEU region (europe-west1); Google Ireland/LLC
Google Sign-InAuthenticationGoogle Ireland/LLC
VercelWeb application hostingEU/US
HostingerMarketing site & DNSEU
ResendTransactional email (invites, notices)US
Polar (Merchant of Record)Subscription payments, taxEU/US

We do not sell your personal data.

7. Retention

We keep account and profile data while your account is active. If you delete your account, there is a 30-day cancellable grace period; after that your authentication account and user record are deleted (see also our Account Deletion page).

Shared family records (information about a child that both parents share) are retained for the other parent and the child even after a parent leaves or deletes their account. The other parent holds that information on their own footing: they need it to care for the child under their contract with us (Art. 6(1)(b) GDPR) and, for health information, on the basis of their own consent as the child’s other guardian (Art. 9(2)(a)). Retention may also be necessary for the establishment, exercise or defence of legal claims (Art. 17(3)(e) GDPR), and the equivalent under Swiss law.

The departing parent’s name stays on the entries they created. In a two-parent family the remaining parent knows who the other parent is, so replacing the name with a label would not make anyone less identifiable — while it would make the family’s shared history, and any court export drawn from it, inconsistent about who did what.

If you withdraw your consent for health information, we stop relying on it for you and you can no longer add health information for the children in that family. Health information already in the family stays while the other parent’s own consent is still active, because they hold it on their own footing (above). When no parent’s consent remains, we stop processing that family’s health information for anyone; it is deleted together with the family’s records, or earlier on request at privacy@bunky.ch. Withdrawal does not affect processing already carried out.

Waitlist emails are kept until launch or until you ask us to remove them. Server logs are kept for a limited period for security.

8. International transfers

Your core data is stored in the EU (Firestore, europe-west1). Some providers (§6) may process data outside your country, including the US. Where required, such transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses and equivalent Swiss safeguards.

9. Storage on your device

To work reliably and offline, Bunky stores some data locally in your browser: functional flags (e.g. onboarding progress) and an offline copy of the emergency card (in IndexedDB). PIN-protected fields in that offline copy are stored encrypted. On the marketing site bunky.ch we keep two small values for the duration of your visit: your chosen language, and the campaign parameters described in §3, so that they survive until you submit the form. We do not use advertising or analytics cookies.

If you switch on current medications on the emergency card, that offline copy also contains the medication name, dosage and timing — unencrypted, so that the card can be read in an emergency without signing in or entering a PIN. This is off by default, it is one switch per child, and you can turn it off at any time; the medications are then removed from the offline copy the next time the card is refreshed.

10. Your rights

Subject to applicable law, you have the right to: access your data; correct it; delete it (subject to the shared-records retention in §7); restrict or object to processing; data portability; and to withdraw consent. Much of this you can do directly in the app (edit/export/delete), including withdrawing your consent for health information. To exercise other rights, contact us at privacy@bunky.ch.

You may also lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or your local EU/EEA data protection authority.

11. Security

We use encryption in transit, access controls limiting data to members of your family, optional PIN encryption for sensitive fields, and an append-only activity log with server-set timestamps. No system is perfectly secure, but we take reasonable measures to protect your data.

12. Changes to this policy

We may update this policy. Material changes will be indicated by updating the "Last updated" date and, where appropriate, by notice in the app.

13. Contact

Bunky — operated by Kralovic Services (Jan Kralovič)privacy@bunky.chSeestrasse 286, 8810 Horgen, Switzerland · UID CHE-317.332.653.


This is a plain-language privacy notice describing the actual data practices of the Service. If anything here is unclear, or you want to exercise a right described above, write to privacy@bunky.ch.