Privacy Notice · Version 1
Your family’s privacy in Dabbli
This notice explains what stays on your iPhone, what Dabbli processes, why it is used, and the choices available to parents and guardians.
Who is responsible
Dabbli is operated by Tridip Choudhury in the Netherlands, who is the controller of the personal data described in this notice. For privacy questions or requests, email dabbli.support@gmail.com.
Who Dabbli is for
A parent or legal guardian creates and controls the account and chooses how the app is used with a child. Dabbli does not create child accounts. Parents should supervise use of the app and make the privacy choices for their family.
Information that stays on the iPhone
The child’s optional nickname, parent-selected age, challenge history, written answers, photos, audio recordings, parent reviews, scores and points are stored locally in protected app storage. Dabbli’s backend and service providers do not receive this information.
Local family information is not synchronised between devices and is excluded from Dabbli’s cloud backups. Uninstalling Dabbli, deleting local family data, or losing or damaging the device may permanently remove it.
Information Dabbli processes
- Parent account: the parent’s email address, an account identifier, sessions, security records and accepted notice versions.
- One-time codes: the recipient email address, a generic sign-in message and limited delivery information needed to send and verify a requested code.
- Optional product analytics: only after the parent actively enables usage sharing. This uses random identifiers and limited events such as completing onboarding or viewing a challenge. It never contains child work, nickname, scores or points.
- Security and diagnostics: limited technical records such as a request identifier, app/platform version, safe error code, endpoint type, status and duration. Request bodies, email addresses, one-time codes, tokens and child work are excluded from application logs.
- Support: the parent’s email, message and optional pseudonymous support ID when the parent chooses to contact support.
Why Dabbli uses this information
- Parent-account, session and one-time-code information is necessary to provide the service requested by the parent.
- Narrow security and diagnostic processing is based on Dabbli’s legitimate interest in preventing abuse, protecting accounts and keeping the service reliable. It is minimised and retained briefly.
- Optional product analytics is based on the parent’s consent. It is off unless enabled and can be withdrawn without losing app functionality.
- Support information is used to answer the parent’s request and protect the service. Records required by law may be retained for that purpose.
Service providers and international processing
Dabbli uses the following services for limited purposes:
- Railway hosts the API, PostgreSQL database and encrypted backups. The workload and database are configured in Amsterdam. Railway may also process data from the United States under its contractual transfer safeguards.
- Brevo sends requested transactional one-time-code emails and retains limited delivery records. Marketing, contact-list use and email open/click tracking are disabled.
- Cloudflare protects founder-only administration and hosts these public legal pages. The pages use no visitor analytics, cookies or tracking pixels; Cloudflare may process minimum security and network data.
- Google Gmail hosts the support mailbox. Emailing support gives Google and Dabbli the message and addressing information needed to deliver and answer it. Please do not send child work.
- Apple distributes the app and may provide platform crash or diagnostic information according to the user’s Apple privacy settings and Apple’s terms.
Providers may process data outside the European Economic Area. Dabbli limits the data sent, uses available contractual safeguards, restricts access and does not send child work to these providers.
How long information is kept
- One-time-code and rate-limit records: up to 24 hours.
- Expired or revoked session metadata: up to 30 days.
- Infrastructure IP security logs: up to 7 days.
- Operational logs and essential diagnostics: up to 30 days.
- Optional raw product-usage events: up to 90 days.
- Anonymous, thresholded weekly product totals: up to 12 months.
- Resolved support correspondence: up to 90 days.
- Child material accidentally sent to support: deleted within 7 days after it is identified.
- Encrypted backend backups: a rolling maximum of 30 days.
- A minimal account-deletion replay record: up to 35 days. It contains no email address or child information.
Deleted data may remain temporarily in isolated encrypted backups until they expire. A restored backup is not allowed to serve users until later deletion requests have been reapplied.
Your choices and rights
A parent can leave optional usage sharing off, withdraw it later, view applicable parent-account information, delete local family data, and initiate deletion of the parent account in the app. Depending on the circumstances and applicable law, parents may also request access, correction, deletion, restriction, objection or portability for applicable backend parent data.
Dabbli cannot provide a backend export of child work because it never receives that work. Parents can inspect it on the iPhone before local deletion. A request may require proportionate verification through the registered parent email.
Contact dabbli.support@gmail.com to exercise a right. You may also complain to the Dutch Data Protection Authority or another competent supervisory authority.
Support and child information
Please do not email a child’s answers, photos or audio recordings. If such material is accidentally received, access is restricted, it is not forwarded, and it is deleted within seven days after identification.
Changes to this notice
Dabbli will update this page when its data practices materially change. Material changes will also be presented in the app when appropriate and a new choice will be requested where consent is required.