Privacy Policy

This policy covers the collabDoo website and the collabDoo app (listed in the App Store as “collabDoo”) by Code Piraten GmbH. It is a translation of the German version, which prevails in case of doubt.

1. General

Protecting your personal data is important to us. We process your data in accordance with applicable data protection law, in particular the EU General Data Protection Regulation (GDPR) and the relevant national provisions.

“Processing” means any operation performed on personal data, such as collection, recording, organisation, storage, adaptation, retrieval, consultation, use, disclosure, transmission, dissemination, restriction, erasure or destruction. “Personal data” means any information relating to an identified or identifiable natural person.

2. Controller and data protection officer

Controller:
Code Piraten GmbH
Am Ruhmbach 44, 45149 Essen, Germany
E-mail: kontakt@codepiraten.com

External data protection officer:
Jens Reininghaus
c/o ETL Rechtsanwälte GmbH Rechtsanwaltsgesellschaft
Eiler Straße 3B, 51107 Cologne, Germany
E-mail: info@dsb-r.de

3. Processing when visiting the website

When you access our website, the following data is automatically stored in server log files: date and time of access, browser type and version, operating system, previously visited page (referrer URL), amount of data transferred and access status, IP address and requesting provider.

This data is processed to enable use of the website, to improve our offering and to defend against unlawful cyber attacks. Legal basis: Art. 6(1)(f) GDPR. Log files are deleted after 14 days at the latest.

Cookies and tracking: The website sets no cookies and uses no analytics or tracking services. Fonts and all other content are served from our own server; no third-party content is loaded.

4. Processing when using the app

a) Account

To use the app, an adult creates an account – with an e-mail address and password or via Sign in with Apple. We store the e-mail address, the password exclusively as a hash (bcrypt), the time of registration and logins, and session tokens (as a checksum only). With Sign in with Apple we receive a pseudonymous identifier from Apple and – depending on your choice – your e-mail address or a relay address. Legal basis: Art. 6(1)(b) GDPR (performance of a contract).

b) Household, members and profiles

Account holders create households and maintain members (profiles) within them with a display name, avatar or photo, role and optionally a PIN (stored as a hash). Profiles for children and guests have no account of their own, no e-mail address and no separate login; they are created and managed exclusively by the account holder within their household. The account holder is responsible for ensuring that the consent of the legal guardians has been obtained before creating profiles of minors.

c) Content

All content you create in the app – areas, objects, knowledge entries, tasks, routines, completions with time and person, comments, checklists, readings, signatures, points, goals, rewards, absences – is stored on our servers so that all members of a household can access it. Uploaded images and documents are stored encrypted (AES-256-GCM); images are re-encoded on upload and stripped of metadata (including location data). Legal basis: Art. 6(1)(b) GDPR.

d) Notifications

If you allow push notifications, we store your device token and deliver notifications (e.g. reminders, overdue or offered tasks, confirmations) via the Apple Push Notification Service (APNs) of Apple Inc. Apple receives the content of the notification and may transfer data to third countries, in particular the USA. Apple is certified under the EU-US Data Privacy Framework. Notifications can be switched off per event type in the app and limited by quiet hours. Legal basis: Art. 6(1)(a) GDPR (consent via the system prompt), revocable in your device settings.

e) E-mails

We send transactional e-mails (e.g. password reset, invitations) to the account e-mail address via an e-mail service provider engaged by us. We do not send marketing e-mails without separate consent.

f) Widgets, Siri and NFC

Widgets, Siri shortcuts and Live Activities process your task data exclusively on your device and retrieve it from our server. With Siri shortcuts, voice data is processed by Apple; Apple’s privacy policy applies. NFC tags you write in the app contain only a link to an object or task in your household – no personal data.

g) Hosting

Application, database and files are operated on servers in Germany. No analytics, advertising or tracking services are used in the app.

5. Retention and deletion

Your data is stored for as long as your account or the household exists. You can delete members, households and your account at any time in the app; the associated content including files, completions and points is deleted completely. Backups are kept for 14 days and then overwritten automatically. Statutory retention obligations (Art. 6(1)(c) GDPR) remain unaffected.

6. Recipients

Within your household, your content is visible to the other members according to their role. In addition, we use carefully selected service providers as processors (Art. 28 GDPR): for e-mail delivery and – if push notifications or Sign in with Apple are enabled – Apple Inc. Data is not shared for advertising purposes.

7. Your rights as a data subject

You have the right at any time to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). Please direct requests to the contact details in section 2. You can also delete your account, household and members directly in the app.

8. Right to object and to withdraw consent

You may object at any time, on grounds relating to your particular situation, to processing based on Art. 6(1)(e) or (f) GDPR. You may withdraw any consent given at any time with effect for the future; the lawfulness of processing up to the withdrawal remains unaffected.

9. Right to lodge a complaint

If you believe your data protection rights have been violated, you may contact the supervisory authority of your federal state or the authority responsible at our registered office (State Commissioner for Data Protection and Freedom of Information of North Rhine-Westphalia).

10. Automated decisions

No automated decision-making with legal effect within the meaning of Art. 22 GDPR takes place. The app uses rule-based automations, such as the temporary lock-out of an account or profile after several failed login or PIN attempts and the automatic assignment of tasks according to the rules you define (rotation, fair distribution). These have no legal effect; review by a human is possible at any time.

11. Data security

We use technical and organisational security measures to protect your data against accidental or intentional manipulation, loss, destruction or unauthorised access – including transport encryption (TLS), encrypted file storage, hashed passwords and PINs, tenant isolation, access limits and daily backups. Our measures are continuously improved in line with technological development. An overview is available under privacy & security.

12. Questions and comments

If you have questions or comments about data protection, please use the contact details in section 2.

Last updated: September 2026

Melvin

Melvin · Development

“I build features I would use at home myself.”

Meet the whole team →