Privacy Policy
This Privacy Policy explains how Bunky ("Bunky", "we", "us") collects, uses, shares and protects personal data when you use our web application and website at bunky.ch and app.bunky.ch (the "Service").
We are based in Switzerland and offer the Service to users worldwide. We have built our privacy practices to meet the standards of the EU/EEA General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (revFADP/revDSG), which we apply as our global baseline. Depending on where you live, additional local rights may apply.
1. Who is responsible for your data (Controller)
Bunky — operated by Jan Kralovič, Seestrasse 286, 8810 Horgen, Switzerland.
Contact for privacy matters: privacy@bunky.ch.
EU/EEA representative (Art. 27 GDPR): [to be appointed].
2. A note on tracking and advertising
Bunky does not use third-party analytics, advertising networks, tracking pixels or advertising cookies. We do not sell or share your personal data for advertising or marketing by third parties. We use only the storage strictly necessary to run the app (see §9).
3. What data we collect
Account & profile
When you sign in with Google, we receive your name, email address and Google account identifier. You may add a display avatar, preferred language, and an optional phone number (used for the emergency card shown to the other parent).
Family & children data (entered by you)
Bunky is a shared wiki for a child's information. Parents enter data about their child(ren), which may include: name, date of birth/age, general information, health information (allergies, blood group, medications, vaccinations, medical history), doctors and their specialisation/contact details, school information and timetable, contacts, custody and vacation schedules, shared expenses, notes and tasks, and emergency ("SOS") details.
Health information is a special category of personal data. We process it only to provide the Service to you, on the basis of your explicit consent, which you give when you choose to enter such data (the app records your consent). You may protect selected sensitive fields with a PIN; those fields are encrypted on your device (AES-256-GCM) before storage.
Family structure
Family membership, roles, and invitations (including the email address of a person you invite).
Waitlist
If you join our waitlist on bunky.ch, we store your email address (as a hashed identifier plus the address) and your language, to send you a confirmation and to notify you at launch. Basis: your consent.
Payment data
Subscriptions are sold and processed by our Merchant of Record (payment provider). Your card/payment details are handled by that provider — we do not receive or store your full payment details. We store only your subscription status and provider customer/subscription identifiers.
Technical data
Standard server logs generated by our hosting providers (e.g. IP address, timestamps, device/browser type) for security and to operate the Service; calendar-feed (iCal) access tokens if you enable them; and an activity/history log of actions within a family (with server-set timestamps).
4. How we use your data and our legal bases
| Purpose | Legal basis (GDPR) |
|---|---|
| Provide and operate the Service (accounts, sharing, calendars, exports) | Performance of a contract — Art. 6(1)(b) |
| Process health/other special-category data you enter | Your explicit consent — Art. 9(2)(a) |
| Send the waitlist confirmation / launch notice | Consent — Art. 6(1)(a) |
| Security, abuse prevention, service integrity | Legitimate interests — Art. 6(1)(f) |
| Retain shared family records after a parent leaves (see §7) | Legitimate interests & legal claims — Art. 6(1)(f) / 17(3)(e) |
| Comply with legal obligations | Legal obligation — Art. 6(1)(c) |
You can withdraw consent at any time (this does not affect processing already carried out).
5. Children's data
Bunky is intended for use by adults (parents/guardians). Children do not create accounts and do not enter their own data. Parents enter and control information about their child(ren) and are responsible for ensuring they are entitled to do so. The Service is not directed to children. If you believe data was entered without proper authority, contact us (§10).
6. Who we share data with (processors)
We share data with other members of your family (that is the purpose of the app) and with service providers who process data on our behalf under data-processing agreements:
| Provider | Purpose | Location |
|---|---|---|
| Google Firebase (Firestore, Authentication, Cloud Functions) | Core database, sign-in, backend | EU region (europe-west1); Google Ireland/LLC |
| Google Sign-In | Authentication | Google Ireland/LLC |
| Vercel | Web application hosting | EU/US |
| Hostinger | Marketing site & DNS | EU |
| Resend | Transactional email (invites, notices) | US |
| Polar (Merchant of Record) | Subscription payments, tax | EU/US |
We do not sell your personal data.
7. Retention
We keep account and profile data while your account is active. If you delete your account, there is a 30-day cancellable grace period; after that your authentication account and user record are deleted (see also our Account Deletion page).
Shared family records (information about a child that both parents share) are retained for the other parent and the child even after a parent leaves or deletes their account, because deleting them would remove data the other parent legitimately relies on and that may be needed for the establishment, exercise or defence of legal claims (e.g. custody). In that case we anonymise the departing parent's name (shown as "Removed parent") rather than deleting the shared content. This relies on Art. 17(3)(e) GDPR and overriding legitimate interests, and the equivalent under Swiss law.
Waitlist emails are kept until launch or until you ask us to remove them. Server logs are kept for a limited period for security.
8. International transfers
Your core data is stored in the EU (Firestore, europe-west1). Some providers (§6) may process data outside your country, including the US. Where required, such transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses and equivalent Swiss safeguards.
9. Storage on your device
To work reliably and offline, Bunky stores some data locally in your browser: functional flags (e.g. onboarding progress) and an offline copy of the emergency card (in IndexedDB). PIN-protected fields in that offline copy are stored encrypted. We do not use advertising or analytics cookies.
10. Your rights
Subject to applicable law, you have the right to: access your data; correct it; delete it (subject to the shared-records retention in §7); restrict or object to processing; data portability; and to withdraw consent. Much of this you can do directly in the app (edit/export/delete). To exercise other rights, contact us at privacy@bunky.ch.
You may also lodge a complaint with a supervisory authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or your local EU/EEA data protection authority.
11. Security
We use encryption in transit, access controls limiting data to members of your family, optional PIN encryption for sensitive fields, and an append-only activity log with server-set timestamps. No system is perfectly secure, but we take reasonable measures to protect your data.
12. Changes to this policy
We may update this policy. Material changes will be indicated by updating the "Last updated" date and, where appropriate, by notice in the app.
13. Contact
Bunky — operated by Jan Kralovič — privacy@bunky.ch — Seestrasse 286, 8810 Horgen, Switzerland.