Chilldora GmbH · info@chilld.de
The following information will provide you with an easy to navigate overview of what will happen with your personal data when you visit this website. The term "personal data" comprises all data that can be used to personally identify you. For detailed information about the subject matter of data protection, please consult our Data Protection Declaration, which we have included beneath this copy.
The data on this website is processed by the operator of the website, whose contact information is available under section "Information about the responsible party (referred to as the "controller" in the GDPR)" in this Privacy Policy.
We collect your data as a result of your sharing of your data with us. This may, for instance be information you enter into our contact form.
Other data shall be recorded by our IT systems automatically or after you consent to its recording during your website visit. This data comprises primarily technical information (e.g., web browser, operating system, or time the site was accessed). This information is recorded automatically when you access this website.
A portion of the information is generated to guarantee the error free provision of the website. Other data may be used to analyze your user patterns. If contracts can be concluded or initiated via the website, the transmitted data will also be processed for contract offers, orders or other order enquiries.
You have the right to receive information about the source, recipients, and purposes of your archived personal data at any time without having to pay a fee for such disclosures. You also have the right to demand that your data are rectified or eradicated. If you have consented to data processing, you have the option to revoke this consent at any time, which shall affect all future data processing. Moreover, you have the right to demand that the processing of your data be restricted under certain circumstances. Furthermore, you have the right to log a complaint with the competent supervising agency.
Please do not hesitate to contact us at any time if you have questions about this or any other data protection related issues.
We are hosting the content of our website at the following provider:
The provider is Webflow, Inc., 398 11th Street, 2nd Floor, San Francisco, CA 94103, USA (hereinafter referred to as "Webflow"). When you visit our website, Webflow records various logfiles, including your IP address.
Webflow is a tool for the creation and hosting of websites. Webflow stores cookies or other recognition technologies that are required for the depiction of the site, for the provision of certain website functions and to guarantee its security (necessary cookies).
For details, please consult the data privacy policy of Webflow: https://webflow.com/legal/eu-privacy-policy.
We use Webflow on the basis of Art. 6(1)(f) GDPR. The transfer of data to the United States is based on the standard contract clauses of the EU Commission. The company is certified in accordance with the "EU-US Data Privacy Framework" (DPF). For more information: https://www.dataprivacyframework.gov/participant/6365.
We use the "Cloudflare" service provided by Cloudflare Inc., 101 Townsend St., San Francisco, CA 94107, USA. Cloudflare offers a content delivery network with DNS that is available worldwide. As a result, the information transfer that occurs between your browser and our website is technically routed via Cloudflare's network.
The use of Cloudflare is based on our legitimate interest in a provision of our website offerings that is as error free and secure as possible (Art. 6(1)(f) GDPR). Data transmission to the US is based on the Standard Contractual Clauses (SCC) of the European Commission. Details: https://www.cloudflare.com/privacypolicy/.
The company is certified in accordance with the "EU-US Data Privacy Framework" (DPF). For more information: https://www.dataprivacyframework.gov/participant/5666.
The operators of this website and its pages take the protection of your personal data very seriously. Hence, we handle your personal data as confidential information and in compliance with the statutory data protection regulations and this Data Protection Declaration.
We herewith advise you that the transmission of data via the Internet (i.e., through e-mail communications) may be prone to security gaps. It is not possible to completely protect data against third-party access.
The data processing controller on this website is:
Chilldora GmbH
Brandenburgische Str 10
12167 Berlin
Phone: +49 (0) 15170361942
E-mail: info@chilld.de
Unless a more specific storage period has been specified in this privacy policy, your personal data will remain with us until the purpose for which it was collected no longer applies. If you assert a justified request for deletion or revoke your consent to data processing, your data will be deleted, unless we have other legally permissible reasons for storing your personal data (e.g., tax or commercial law retention periods).
If you have consented to data processing, we process your personal data on the basis of Art. 6(1)(a) GDPR or Art. 9(2)(a) GDPR, if special categories of data are processed according to Art. 9(1) DSGVO. If your data is required for the fulfillment of a contract or for the implementation of pre-contractual measures, we process your data on the basis of Art. 6(1)(b) GDPR. Furthermore, if your data is required for the fulfillment of a legal obligation, we process it on the basis of Art. 6(1)(c) GDPR. Furthermore, the data processing may be carried out on the basis of our legitimate interest according to Art. 6(1)(f) GDPR.
We only disclose personal data to external parties if this is required as part of the fulfillment of a contract, if we are legally obligated to do so, if we have a legitimate interest in the disclosure pursuant to Art. 6(1)(f) GDPR, or if another legal basis permits the disclosure of this data.
A wide range of data processing transactions are possible only subject to your express consent. You can also revoke at any time any consent you have already given us. This shall be without prejudice to the lawfulness of any data collection that occurred prior to your revocation.
IN THE EVENT THAT DATA ARE PROCESSED ON THE BASIS OF ART. 6(1)(E) OR (F) GDPR, YOU HAVE THE RIGHT TO AT ANY TIME OBJECT TO THE PROCESSING OF YOUR PERSONAL DATA BASED ON GROUNDS ARISING FROM YOUR UNIQUE SITUATION. THIS ALSO APPLIES TO ANY PROFILING BASED ON THESE PROVISIONS. IF YOU LOG AN OBJECTION, WE WILL NO LONGER PROCESS YOUR AFFECTED PERSONAL DATA, UNLESS WE ARE IN A POSITION TO PRESENT COMPELLING PROTECTION WORTHY GROUNDS FOR THE PROCESSING OF YOUR DATA, THAT OUTWEIGH YOUR INTERESTS, RIGHTS AND FREEDOMS OR IF THE PURPOSE OF THE PROCESSING IS THE CLAIMING, EXERCISING OR DEFENCE OF LEGAL ENTITLEMENTS (OBJECTION PURSUANT TO ART. 21(1) GDPR).
IF YOUR PERSONAL DATA IS BEING PROCESSED IN ORDER TO ENGAGE IN DIRECT ADVERTISING, YOU HAVE THE RIGHT TO OBJECT TO THE PROCESSING OF YOUR AFFECTED PERSONAL DATA FOR THE PURPOSES OF SUCH ADVERTISING AT ANY TIME. THIS ALSO APPLIES TO PROFILING TO THE EXTENT THAT IT IS AFFILIATED WITH SUCH DIRECT ADVERTISING. IF YOU OBJECT, YOUR PERSONAL DATA WILL SUBSEQUENTLY NO LONGER BE USED FOR DIRECT ADVERTISING PURPOSES (OBJECTION PURSUANT TO ART. 21(2) GDPR).
In the event of violations of the GDPR, data subjects are entitled to log a complaint with a supervisory agency, in particular in the member state where they usually maintain their domicile, place of work or at the place where the alleged violation occurred.
You have the right to have data that we process automatically on the basis of your consent or in fulfillment of a contract handed over to you or to a third party in a common, machine-readable format.
Within the scope of the applicable statutory provisions, you have the right to demand information about your archived personal data, their source and recipients as well as the purpose of the processing of your data at any time. You may also have a right to have your data rectified or eradicated. If you have questions about this subject matter, please do not hesitate to contact us at any time.
You have the right to demand the imposition of restrictions as far as the processing of your personal data is concerned. To do so, you may contact us at any time. The right to demand restriction of processing applies in the following cases:
For security reasons and to protect the transmission of confidential content, this website uses either an SSL or a TLS encryption program. You can recognize an encrypted connection by checking whether the address line of the browser switches from "http://" to "https://" and also by the appearance of the lock icon in the browser line.
Our websites and pages use what the industry refers to as "cookies." Cookies are small data packages that do not cause any damage to your device. They are either stored temporarily for the duration of a session (session cookies) or they are permanently archived on your device (permanent cookies). Session cookies are automatically deleted once you terminate your visit.
Cookies can be issued by us (first-party cookies) or by third-party companies (so-called third-party cookies). Third-party cookies enable the integration of certain services of third-party companies into websites.
You have the option to set up your browser in such a manner that you will be notified any time cookies are placed and to permit the acceptance of cookies only in specific cases. You may also exclude the acceptance of cookies in certain cases or in general or activate the delete-function for the automatic eradication of cookies when the browser closes. If cookies are deactivated, the functions of this website may be limited.
If you contact us by e-mail, telephone or fax, your request, including all resulting personal data (name, request) will be stored and processed by us for the purpose of processing your request. We do not pass these data on without your consent.
These data are processed on the basis of Art. 6(1)(b) GDPR if your inquiry is related to the fulfillment of a contract or is required for the performance of pre-contractual measures. In all other cases, the data are processed on the basis of our legitimate interest in the effective handling of inquiries submitted to us (Art. 6(1)(f) GDPR) or on the basis of your consent (Art. 6(1)(a) GDPR) if it has been obtained.
If you join our waitlist, we store the email address you provide, the time of signup, and — where present — the campaign parameters of the link you used (e.g. which social-media channel brought you here). This data is stored in our own database, hosted by Supabase Inc.; processing currently takes place on servers in the USA, safeguarded by the EU standard contractual clauses that form part of our data processing agreement with Supabase. It is used solely to inform you about the launch of Chilld and to understand which channels our signups come from. It is not shared with third parties and is deleted once the purpose no longer applies or upon your request (info@chilld.de).
Processing is based on your consent (Art. 6(1)(a) GDPR), which you can revoke at any time with effect for the future.
To understand how visitors find this website, we record anonymous page views in our own database: the page visited, the referring website's domain, and campaign parameters (UTM). No cookies are set for this, no IP addresses or device identifiers are stored, and a new random identifier is used for every page view, so no usage profiles can be created. If your browser sends a "Do Not Track" signal, no statistics are recorded. This processing is based on our legitimate interest in measuring the reach of our website (Art. 6(1)(f) GDPR).
To process user requests via chat, we use Brevo Chat. The provider is Sendinblue GmbH, Köpenicker Straße 126, 10179 Berlin, Germany. When using Brevo Chat, cookies and other recognition technologies (e.g., IDs) are used. This enables us to recognize you on your next visit and to assign your previous chat history to you.
The use of Brevo Chat is based on Art. 6(1)(f) GDPR. For more information, please refer to Brevo's Data Privacy Policy: https://www.brevo.com/de/legal/privacypolicy/.
To ensure that fonts used on this website are uniform, this website uses so-called Google Fonts provided by Google. When you access a page on our website, your browser will load the required fonts into your browser cache to correctly display text and fonts.
To do this, the browser you use will have to establish a connection with Google's servers. As a result, Google will learn that your IP address was used to access this website. The use of Google Fonts is based on Art. 6(1)(f) GDPR.
For more information on Google Fonts: https://developers.google.com/fonts/faq and Google's Data Privacy Declaration: https://policies.google.com/privacy?hl=en.
The company is certified in accordance with the "EU-US Data Privacy Framework" (DPF). For more information: https://www.dataprivacyframework.gov/participant/5780.
We have integrated Google Drive on this website. The provider is Google Ireland Limited ("Google"), Gordon House, Barrow Street, Dublin 4, Ireland. Google Drive allows us to include an upload area on our website where you can upload content. When you upload content, it is stored on Google Drive's servers.
The use of Google Drive is based on Art. 6(1)(f) GDPR. The company is certified in accordance with the "EU-US Data Privacy Framework" (DPF). For more information: https://www.dataprivacyframework.gov/participant/5780.
This section covers the Chilld app for iPhone and iPad. It is separate from the website sections above: the app does not use the website's cookies, chat or analytics.
The app is fully usable anonymously. On first use it creates an anonymous identifier so your saved content belongs to you on this device; no name, email address or phone number is required. You only create an account if you want your saved content to follow you to another device — in that case we store your email address and, for a Chilld account, a password hash (never the password itself). Legal basis: Art. 6(1)(b) GDPR (performance of the service you requested).
The core of the app is that you describe a parenting situation in your own words, by typing or by speaking. Voice is converted to text on your device by Apple's on-device speech recognition — the audio recording is never transmitted to us or to anyone else.
Situations you mark as private stay on your device and are not transmitted.
If, and only if, you have agreed to it in the app, the text you write is sent to a third-party AI service so that the app can understand you in your own language and write an answer. The app asks you for this permission before anything is sent, names the recipient, and lists exactly what is sent. You can withdraw or give this permission at any time under Settings → AI companion; if you decline, the app answers you with an on-device reflection instead and nothing leaves your device.
Recipient: OpenAI, L.L.C., 1455 3rd Street, San Francisco, CA 94158, USA ("OpenAI").
What is transmitted: the text you wrote or dictated; your child's age in months, your family setup (parenting solo or with a partner) and the parenting approach you selected, in each case only if you have provided them; and, in the conversation feature, your child's first name, again only if you have provided it, together with every message of that conversation, word for word — including messages from earlier sessions, because the conversation is kept on your device until you switch the AI companion off. Calling this “a short recap”, as an earlier version of this page did, understated it.
What is not transmitted: your audio recording, your name, your email address, your account identifier, and any situation you keep private.
Purpose: solely to generate the reflection and the conversational replies shown to you. The data is not used for advertising, not used to build a profile about you, and not sold by us. According to OpenAI's published API terms, content submitted through its API is not used to train OpenAI's models.
How it is transmitted: your text is passed through our own server function (hosted by Supabase) so that no key and no account of yours is handed to OpenAI; OpenAI receives the text without any account identifier of yours.
Legal basis: your consent, Art. 6(1)(a) GDPR, which you can revoke at any time with effect for the future (Settings → AI companion). Because parenting descriptions can touch on health, we treat this as consent within the meaning of Art. 9(2)(a) GDPR as well.
Transfer to the USA: your text is transferred to a company in the United States. We do not currently have EU standard contractual clauses or another appropriate safeguard under Art. 46 GDPR in place with OpenAI, and there is no adequacy decision covering this transfer. It therefore takes place solely on the basis of your explicit consent under Art. 49(1)(a) GDPR. You should be aware that US authorities may have access rights to data held by US providers, and that you may not have the same enforceable rights and legal remedies there as within the EU. If you would rather not accept this, decline the AI companion in the app (or switch it off under Settings → AI companion) — the app then answers you entirely on your device.
Storage: the text is processed to produce the answer and is not stored by us for that purpose beyond what you choose to save in the app. According to OpenAI's published policy, it retains API content for a limited period for abuse monitoring and then deletes it.
Before any AI is involved, the app checks your text locally on your device against a fixed list of crisis and medical indicators, in order to show you emergency numbers and help lines. This check runs entirely on your device and its result is not transmitted. The app records on your device that such a notice was shown; this record does not leave your device.
If you post a question to the community or request feedback from an expert, the content you submit, and your anonymous or account identifier, are stored in our database (hosted by Supabase Inc.; processing currently takes place on servers in the USA, safeguarded by the EU standard contractual clauses in our data processing agreement with Supabase) so that the answer can reach you. Legal basis: Art. 6(1)(b) GDPR.
If you allow notifications, we store the device token issued by Apple in order to send you the reminders you asked for. You can withdraw this at any time in iOS Settings or in the app. Legal basis: Art. 6(1)(a) GDPR.
We count which steps of the app are used (for example "a reflection was started"), in our own database. We never transmit the text you wrote into these statistics. There is no third-party analytics or advertising SDK in the app, and no data is used to track you across other companies' apps or websites. Legal basis: Art. 6(1)(f) GDPR (understanding whether the app works).
You can delete your account and all associated content in the app under Settings → Delete account. This removes your user record and your rows from our database. You can also reach us at any time at info@chilld.de.