Mission: Family Privacy Policy
Last updated: 7 May 2026
We care about transparency. In short: we collect only the data necessary for the service to work, we do not sell it to anyone, children's names are anonymised before being passed to AI models, and you can export or delete your data at any time.
1. Personal data controller
The controller of your personal data is:
Szymon Wąsik Systemy Informatyczne, ul. Stalowa 34/34, 05-800 Pruszków, Poland, NIP 7792188559, REGON 528805350, phone +48 572 514 230, GDPR email: rodo@misjarodzina.ai, general email: kontakt@misjarodzina.ai.
We have not appointed a Data Protection Officer (DPO) because we are not required to (see the DPO-need analysis). Send any questions about personal data to rodo@misjarodzina.ai.
2. What data we collect and for what purpose
2.1 Account data
| Data category | Purpose | Legal basis (GDPR) |
|---|---|---|
| Email address, Google ID | Authentication, communication with you | Art. 6(1)(b) – contract performance |
| Date and time of registration, terms acceptance | Demonstration of consent and contract performance | Art. 6(1)(c) – legal obligation |
| Preferred parenting style | Personalisation of AI Assistant responses | Art. 6(1)(b) – contract performance |
| Subscription status | Management of access to paid features | Art. 6(1)(b) – contract performance |
| Source of your first visit (UTM parameters from the link, e.g. "instagram") — stored once at registration | Measuring the effectiveness of our own promotion channels — no cookies, no third parties | Art. 6(1)(f) – legitimate interest |
2.2 Child profile data
We collect only the data necessary for the AI Assistant to operate (data minimisation principle):
| Data | Notes |
|---|---|
| Child's alias / first name | First name or invented alias only – never a surname. Before being sent to AI, replaced with the [CHILD:<grammatical-form>] placeholder (e.g. [CHILD:nom], [CHILD:dat]) — the mechanism handles full Polish inflection. |
| Month and year of birth | Used to tailor advice to the child's age. We collect month and year only – the exact date of birth is neither required nor stored. |
| Main parenting challenge | Picked from a predefined list. |
| Neurodiversity notes (optional) | Provided voluntarily; may constitute sensitive data (GDPR art. 9) – processed solely on the User's explicit consent for the purpose of personalising advice. |
2.3 AI Assistant conversation history
We store the content of conversations to give you access to history and to continue threads. Conversations are linked to your account and child profile. Legal basis: GDPR art. 6(1)(b).
Assistant response ratings (👍/👎): If you mark an assistant response as helpful or unhelpful, we store that rating with the message ID. The rating can be changed or removed at any time by clicking again. If you submit a rating, you authorise us to review the entire context of that conversation (including earlier messages in that session) solely to improve the quality of assistant responses. No conversation content is passed to third parties for this purpose; the review is performed exclusively by the Mission: Family team. Legal basis: GDPR art. 6(1)(f) (legitimate interest – service improvement).
2.4 Payment data
Full card processing (card number, CVV, 3-D Secure authentication data) is performed exclusively by our payment provider — Stripe Payments Europe, Limited. We do not store or process card numbers. On our side we store:
- the provider's customer and transaction identifier (Stripe customer ID and the payment / session ID),
- the reference that lets us charge subsequent periods automatically (a payment-method identifier attached to the Stripe customer) — used exclusively for automatic charges of subsequent subscription periods (see point 2.4a),
- the amount, date and status of each transaction (success / failed / refunded), refund history,
- subscription status (active, trialing, cancelled, expired) and dates of billing-period boundaries.
Legal basis: GDPR art. 6(1)(b) (contract performance) and art. 6(1)(c) (legal obligation — accounting records under the Polish Accounting Act).
2.4a Recurring card token
After the first successful payment, we retain the reference that allows automatic charges, returned by Stripe (a payment-method identifier attached to the Stripe customer). This reference:
- is used exclusively for automatic charges for subsequent subscription periods (and for refunds and one-off top-ups on plan change),
- does not allow reconstruction of the card number or use outside our Stripe integration,
- is deleted on subscription cancellation + 24 months, or immediately upon your request to rodo@misjarodzina.ai.
Legal basis: GDPR art. 6(1)(b) (contract performance — recurring billing). You can cancel your subscription in account settings at any time — the reference will then no longer be used for new charges.
2.5 Technical data (logs)
We automatically record IP addresses, browser type, and session identifiers for security and diagnostics. Logs are kept for up to 12 months. Legal basis: GDPR art. 6(1)(f) (legitimate interest – system security).
2.6 Site traffic statistics (Umami — self-hosted)
To measure how users use the Service, we use self-hosted Umami. The tool does not use cookies and does not create persistent identifiers that allow users to be tracked across sessions. The information collected includes: URL of the visited page, referrer, device and browser type, and a short-lived identifier generated from a hashed IP address (rotated daily). On that basis we produce only aggregated traffic statistics – they do not allow identification of a natural person. We host the tool ourselves on our own infrastructure (Render — server in Frankfurt; Supabase database — EU), described in point 4; we do not use a separate third-party analytics provider. Legal basis: GDPR art. 6(1)(f) (legitimate interest – evaluation and improvement of the Service).
2.7 Newsletter (voluntary signup)
If you subscribe to the newsletter — in account settings or on a free-material download page — we process your e-mail address and consent metadata (date, signup source, consent text version, confirmation date; GDPR Art. 7(1)). Signups outside an account require address confirmation (double opt-in). We do not measure opens or clicks in the newsletter — no tracking pixels. You can unsubscribe at any time, without logging in — via the link in the footer of every message or your mail client's one-click unsubscribe; withdrawing consent does not affect the lawfulness of prior sending. After unsubscribing, the address stays with us marked "unsubscribed" (proof of consent withdrawal); on request to rodo@misjarodzina.ai we delete it entirely. Legal basis: GDPR Art. 6(1)(a) (consent) and Art. 10 of the Polish Act on Providing Services by Electronic Means. Delivery is handled by the processor Resend, Inc. (section 4.8).
3. Special protection of children's data
- The Service is intended for parents and guardians. We do not collect data directly from children and do not allow children to create accounts.
- Child profile data is stored on servers in the European Union (Frankfurt) and is subject to a least-access policy.
- Anonymisation before AI: Before any data is sent to external language models, the child's name/alias is automatically replaced with the placeholder
[CHILD:<grammatical-form>]— the mechanism handles Polish inflection (7 cases), diminutives, and typos. After the response is received, the placeholder is mapped back to the name in the correct form. AI models never receive the real name or the exact date of birth of your child — only the month and year of birth.
4. Processors – third parties processing data
We use external services as data processors within the meaning of GDPR art. 28. We have concluded appropriate data processing agreements with them.
4.1 Supabase, Inc. (database and authentication)
- Purpose: PostgreSQL database hosting (accounts, child profiles, conversation history), Supabase Auth (authentication), pgvector (knowledge-base vectors).
- Transferred data: all user data and child-profile data stored in the Service.
- Location: Frankfurt (EU, region
eu-central-1). The direct data transfer takes place entirely within the EU.
4.2 Anthropic, PBC (Claude models)
- Purpose: generation of AI Assistant responses.
- Transferred data: message content with children's names anonymised, child's age (expressed as a range, not a date of birth).
- Model training: Anthropic does not use data submitted via the API to train its models.
- Retention on the Anthropic side: up to 30 days for security and abuse-detection purposes, per Anthropic's privacy policy.
- Location: USA. The transfer is based on the EU Standard Contractual Clauses (SCC) approved by the European Commission.
4.3 OpenAI, LLC (text-embedding-3-small model)
- Purpose: creation of vector representations of user queries to retrieve relevant fragments of the knowledge base (RAG). This data is not used by OpenAI to generate responses visible to the user.
- Transferred data: message content after children's names are anonymised.
- Model training: OpenAI does not use data submitted via the API to train its models.
- Location: USA. The transfer is based on SCC.
4.4 Vercel Inc. (frontend hosting)
- Purpose: hosting the user interface of the Service.
- Transferred data: HTTP request metadata (IP address, user-agent, URL, referrer) necessary to deliver content.
- Cookies: Vercel hosting does not set its own cookies or use browser fingerprinting.
- Location: USA. The transfer is based on EU Standard Contractual Clauses (SCC) and a Data Processing Addendum with Vercel Inc.
4.5 Render Inc. (API layer hosting)
- Purpose: hosting the backend application (FastAPI) handling all requests from the user interface – including messages to the AI Assistant, conversation history storage and PDF generation.
- Transferred data: HTTP request metadata (IP, user-agent) and API request content. Children's names are anonymised before reaching the AI models, but application code running on the Render infrastructure operates on pre-anonymisation data.
- Location: USA (the Frankfurt region is unavailable in the production plan). Transfer based on EU Standard Contractual Clauses (SCC) and a Data Processing Addendum with Render Services, Inc.
4.6 Cloudflare, Inc. (DNS, CDN, PDF file storage)
- Purpose: DNS for the Service domains, the CDN/proxy layer protecting against abuse, and storage of generated PDF files (Cloudflare R2 Object Storage).
- Transferred data: HTTP request metadata (IP, user-agent, URL) when the proxy is active, and the contents of generated materials (PDF files).
- Cookies: when the proxy layer is active, Cloudflare may set a technical cookie
__cf_bmused exclusively for bot protection. The cookie is technically necessary and is not used for profiling or advertising. - Location: Cloudflare's global network; PDF files stored in the EU region. Transfer based on SCC and a DPA with Cloudflare, Inc.
4.7 Google Ireland Ltd. (Workspace: Gmail + Sign in with Google)
- Purpose (Gmail / Workspace): hosting the
kontakt@misjarodzina.aiandrodo@misjarodzina.aimailboxes that receive correspondence from Users exercising the right of contact with the controller (including requests under GDPR art. 15–22). - Purpose (OAuth): optional user authentication via the “Sign in with Google” flow. You can opt out of this sign-in method — email/password registration is also available.
- Transferred data: email correspondence (content, headers, attachments) reaching our Workspace mailboxes; on OAuth login — email address and Google account identifier. No child profile data or AI Assistant conversation content is passed to Google.
- Location: Workspace Data Region set to Europe → mailbox storage in the EEA. OAuth — global. Transfer based on the SCC included in the Google Workspace Data Processing Addendum and Google LLC's certification under the EU-US Data Privacy Framework.
4.8 Resend, Inc. (transactional e-mail and newsletter delivery)
- Purpose: delivering authentication e-mails (signup confirmation, password reset, magic link) as the external SMTP provider for Supabase Auth, billing e-mails, and — with your consent — the newsletter (section 2.7) together with its signup-confirmation e-mail.
- Data shared: the User's e-mail address and the message content. Conversation content and child profile data are never shared with Resend.
- Retention at Resend: delivery metadata (logs) – up to 30 days.
- Location: USA. Transfer based on SCCs and the DPA concluded with Resend, Inc.
4.9 Stripe Payments Europe, Limited (payment provider)
- Purpose: handling Plus subscription payments (payment gateway), automatic charging of subsequent periods and refund handling.
- Transferred data: email address, first name, amount and transaction identifier, payment description (e.g. „Plus — monthly”). Full card processing (card number, CVV, 3-D Secure) is performed solely by Stripe — we do not store card numbers. The reference that allows automatic charges of subsequent periods (a payment-method identifier attached to the Stripe customer) is stored on our side (see point 2.4a).
- Location: Ireland (EEA) — Stripe Payments Europe, Limited, 1 Grand Canal Street Lower, Grand Canal Dock, Dublin 2, D02 H210, Ireland, company number 513174.
- Processor relationship / transfer basis: data is processed in the EU/EEA under the Stripe Services Agreement and Stripe's separate Data Processing Agreement (DPA), in accordance with Stripe's Privacy Policy.
- Status: active — paid plans are live. Stripe's terms and privacy policy are available at stripe.com/legal.
4.10 inFakt Sp. z o.o. (accounting and invoicing)
- Purpose: issuing and posting invoices, archiving accounting documents per art. 74 of the Polish Accounting Act (after paid plans go live).
- Transferred data: invoice-buyer data — first and last name or company name, address, NIP (if provided), invoice number and amount. Child profile data and conversation content are not passed on.
- Location: Poland (EEA) — inFakt Sp. z o.o., ul. Szlak 49, 31-153 Kraków, NIP 9452121681, KRS 0000325203.
- inFakt sub-processors: Google Ireland, Microsoft Ireland, Amazon Web Services (USA + Luxembourg) — transfers to the USA are protected by SCC and DPF on inFakt's side.
4.11 Advertising and marketing — Google Ads (off-site)
We promote the service through Google Ads — campaigns appear in Google Search and across Google's display network outside of misjarodzina.ai. We do not place any ads on the site itself (no Google AdSense, no Meta Pixel) and we do not collect data for remarketing or conversion-measurement purposes.
When you click our ad and land on the site, the URL may contain a ?gclid=... parameter — that is an identifier assigned by Google for click attribution on the Google Ads side. We do not use this parameter on our side (no conversion tag), we do not store it and do not link it to your account.
Google Ads is not a data processor acting on our behalf — that's a B2B relationship between the controller and Google as an advertising platform.
5. Where we store data
| Data | Infrastructure provider | Location |
|---|---|---|
| Accounts, child profiles, conversation history | Supabase (PostgreSQL) | EU – Frankfurt (AWS eu-central-1) |
| Generated PDF files | Cloudflare R2 | EU |
| Vectors (knowledge base) | Supabase pgvector | EU – Frankfurt |
| User interface | Vercel Inc. | USA (SCC + DPA) |
| API layer and aggregated traffic statistics (Umami) | Render Services, Inc. | USA (SCC + DPA) |
| DNS, CDN proxy | Cloudflare, Inc. | Global network (SCC + DPA) |
| Authentication email delivery logs | Resend, Inc. | USA (SCC + DPA) |
| Payment data (subscriptions) | Stripe Payments Europe, Limited | Ireland (EEA) |
| Invoice data | inFakt Sp. z o.o. | Poland (EEA) + AWS USA (sub-processor, SCC) |
| Correspondence (kontakt@, rodo@) | Google Workspace (Gmail) | Workspace Data Region: Europe (SCC + DPF) |
6. How long we keep data
| Data category | Retention period |
|---|---|
| Account data and child profiles | Until account deletion + a 30-day grace period (for removal from backups) |
| AI Assistant conversation history | Until account deletion, or earlier on request |
| Generated PDF files | Until account deletion, or earlier on request |
| Accounting records (invoices, payments) | 5 years from the end of the tax year (legal obligation) |
| Reference for automatic charges (Stripe) | Until subscription cancellation + 24 months, or immediately on request to rodo@misjarodzina.ai |
| Technical and security logs | 12 months |
| Correspondence to rodo@misjarodzina.ai | 3 years from the last message in the thread |
| Data on the Anthropic / OpenAI side | Up to 30 days (provider policy) |
7. Whom we share data with
We do not sell or rent your personal data. We share data exclusively:
- with the processors listed in point 4 (Supabase, Anthropic, OpenAI, Vercel, Render, Cloudflare, Google, Resend, Stripe and inFakt) – solely to the extent necessary to provide the service,
- with public authorities – only where required by mandatory provisions of law.
8. Your rights (GDPR)
As a data subject you have the following rights:
| Right | What it means |
|---|---|
| Access (art. 15) | You may request a copy of the data we hold about you. |
| Rectification (art. 16) | You may ask us to correct inaccurate data. |
| Erasure (art. 17) | The “right to be forgotten” – you may request deletion of your data. We will erase it unless the law requires us to retain it. |
| Restriction of processing (art. 18) | You may request restriction of the processing of your data. |
| Portability (art. 20) | You may export your data in a structured format (JSON) via account settings or by email request. |
| Objection (art. 21) | You may object to processing based on the controller's legitimate interest. |
| Complaint to the supervisory authority | You have the right to lodge a complaint with the President of the Personal Data Protection Office (UODO), ul. Stawki 2, 00-193 Warsaw, Poland, uodo.gov.pl. |
To exercise the rights above, write to rodo@misjarodzina.ai. We will respond within 30 days.
9. Data security
- We use encryption of data in transit (TLS 1.2+) and at rest.
- Access to user data is controlled by Row Level Security (RLS) rules at the database level – each user sees only their own data.
- Download links for generated PDF files are signed and expire after 1 hour.
- Children's names are never recorded in system logs and never reach external AI models in clear form.
- In case of a personal data breach that may pose a high risk to the rights or freedoms of natural persons, we will inform you without undue delay.
10. Cookies and tracking technologies
10.1 Which cookies we use
The Service uses only technically necessary and functional (first-party) cookies. We do not use analytical, advertising, or third-party tracking cookies. The traffic measurement tool we use (Umami — self-hosted, described in points 2.6 and 4.4) also does not write any cookies. Below is the full list of cookies used in the Service:
| Cookie name | Provider | Purpose | Lifetime |
|---|---|---|---|
sb-<project>-auth-token | Supabase Auth | Stores the authentication session token. Necessary to keep you signed in between pages. | Until sign-out or session expiry (max 7 days) |
sb-<project>-auth-token-code-verifier | Supabase Auth | PKCE verifier used during Google OAuth sign-in. Removed after the sign-in flow completes. | Duration of the OAuth flow (a few minutes) |
__cf_bm | Cloudflare | Set when the domain is behind the Cloudflare proxy layer. Used solely for bot protection. Not used for profiling or advertising. | 30 minutes from the last request |
active_child | Mission: Family (first-party) | Functional cookie. Remembers which child profile is currently selected in the dashboard so we can filter the content shown. Stores only the selected profile's identifier and is set after your action. | 1 year |
NEXT_LOCALE | Mission: Family (next-intl) | Functional cookie. Remembers your chosen interface language (Polish, English, Spanish). | 1 year |
Local Storage (technology related to cookies): the cookie_notice_dismissed key (boolean value) remembers that you dismissed the information banner so we don't show it again. The value does not identify the user.
10.2 Legal basis
The cookies above are either technically necessary to provide the service you've requested (sign-in, session persistence) or functional — they remember your preferences (chosen language, selected child profile) and are set only in response to your actions in the Service. They are first-party cookies that are not used for tracking. Under art. 173(3) of the Polish Telecommunications Act and recital 25 of the ePrivacy Directive, the use of technically necessary cookies does not require your consent – we are only required to inform you of their use, which we hereby do.
10.3 Managing cookies
You can remove or block cookies in your browser settings. Note that blocking the above cookies will prevent sign-in to the Service.
Instructions for popular browsers:
- Chrome: Settings → Privacy and security → Cookies and other site data
- Firefox: Settings → Privacy & Security → Cookies and Site Data
- Safari: Preferences → Privacy → Manage Website Data
- Edge: Settings → Cookies and site permissions
11. Changes to the Privacy Policy
We will notify you of material changes to the Privacy Policy by email at least 14 days in advance. The date of the most recent update is always visible at the top of this page.
12. Contact
For matters concerning personal data protection, please contact us:
Szymon Wąsik Systemy Informatyczne, ul. Stalowa 34/34, 05-800 Pruszków, Poland, NIP 7792188559, REGON 528805350, phone +48 572 514 230, GDPR email: rodo@misjarodzina.ai, general email: kontakt@misjarodzina.ai.