Sugarmum.me← Back home

Privacy Policy

This policy explains how we process personal data when you use Sugarmum.me, in accordance with the EU General Data Protection Regulation (GDPR) and the German Federal Data Protection Act (BDSG).

1. Controller

tino24/7 GmbH, Ringbahnstr. 42, 12099 Berlin, Germany.
Email: kontakt@tino247.de · Phone: +49 1579 2330082.

2. Hosting & infrastructure

The service is hosted on Google Firebase (Firebase Hosting, Authentication, Cloud Firestore, Cloud Storage) provided by Google Ireland Ltd., Gordon House, Barrow Street, Dublin 4, Ireland. When you access the site, Google automatically processes technical data such as your IP address, browser type, and access times in server logs. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in secure, reliable operation). A data processing agreement (Art. 28 GDPR) is in place with Google.

3. Account & authentication

To use the app you are signed in anonymously via Firebase Authentication, which creates a random user identifier stored on your device. No name or email is required for this. Legal basis: Art. 6(1)(b) GDPR (provision of the service).

4. Data you provide in the app

When you use the app you may provide a first name, age, role selection, likes, chat messages, profile settings, and a profile photo. This data is stored under your anonymous user ID in Cloud Firestore and Cloud Storage and is used solely to provide the app’s features. Legal basis: Art. 6(1)(b) GDPR. Photos you upload via the camera are captured on your device only after you grant the browser camera permission.

5. Abuse prevention (Firebase App Check / reCAPTCHA)

We use Firebase App Check with Google reCAPTCHA v3 to protect our backend from abuse and fraud. reCAPTCHA analyses usage data (including IP address and device/browser information) in the background to distinguish humans from automated requests. Provider: Google. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in security). See Google’s privacy policy: policies.google.com/privacy.

6. Analytics

If enabled, we use Google Analytics for Firebase to understand how the app is used (aggregated usage statistics). This processing takes place only with your consent, Art. 6(1)(a) GDPR, which you can withdraw at any time with effect for the future.

7. Web fonts

We load the “Instrument Serif” and “Schibsted Grotesk” fonts from Google Fonts. When doing so, your browser connects to Google servers, transmitting your IP address. Legal basis: Art. 6(1)(f) GDPR (consistent presentation).

8. Local storage

The app stores some state (e.g. your in-app preferences) in your browser’s local storage so the experience persists between visits. This data stays on your device.

9. Transfers to third countries

The above Google services may process data in the USA. Such transfers are safeguarded by EU Standard Contractual Clauses and/or the EU–US Data Privacy Framework, where applicable.

10. Retention

We retain personal data only as long as necessary for the purposes described or as required by law. You can request deletion of your data at any time (see your rights below).

11. Your rights

Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20), and to object to processing (Art. 21). Where processing is based on consent, you may withdraw it at any time (Art. 7(3)). To exercise these rights, contact us at kontakt@tino247.de.

12. Right to lodge a complaint

You have the right to lodge a complaint with a supervisory authority. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information (Berliner Beauftragte für Datenschutz und Informationsfreiheit).

13. Age restriction

This service is intended exclusively for adults (18 years and older).

14. Changes to this policy

We may update this privacy policy to reflect changes to the service or legal requirements. The current version always applies.