Privacy policy
Applies to the Babytakt app (Android and iOS) and to this website. Last updated: 14.09.2026. The German version is authoritative.
This is a courtesy translation. The legally binding version is the German Datenschutzerklärung.
1. Controller
bork.media — Thomas Borkowski
Leipziger Str. 35, 44577 Castrop-Rauxel, Germany
E-mail: hello@babytakt.app
We are not legally required to appoint a data protection officer.
2. The app on your phone
2.1 What Babytakt stores
Babytakt keeps a database in the app's private folder. Only the app itself can access it; other apps cannot read it. It contains what you enter yourself:
- entries for meals (nursing, bottle, solids), diapers and sleep — each with a time
- health details: weight and height, temperature, medication and vaccinations
- your own notes and moments, to which you can attach a picture
- about the child: name, date of birth and, if you choose one, a photo
- your settings (color, font, visible buttons)
This is the same on both platforms: on Android the database sits in the app's private folder, on iOS in the app's protected container. In both cases only Babytakt itself can access it.
This data is not transferred to us. We have no access to it and do not even learn that you use the app. Delete the app and it is gone.
2.2 Where the entries come from: from you
Every line in the app was typed in by you. Babytakt measures nothing, reads no sensors, pairs with no scale and no thermometer, imports nothing from other apps or health records, and buys no data anywhere. There is no second source. What the app holds is there because a parent or an invited person wrote it down.
So there is nothing we could know about you that you do not. No derived values, no assessment, no prediction. The app computes averages and intervals from your own entries, nothing more, and the result stays on the device.
Health details — weight, height, temperature, medication, vaccinations — are specially protected under Art. 9 GDPR. The same applies to them as to everything else, only with extra care: without family sync they never leave the phone. With sync they travel encrypted, and the health area carries its own key: whoever was not given it when invited cannot read those entries — nobody in the group and nobody at our end. If you would rather not keep them at all, simply leave the fields empty; the app does not ask.
2.3 Permissions
On Android, Babytakt requests exactly two permissions — no others are declared in the app. iOS adds none:
| Permission | What for |
|---|---|
| Vibration | A short confirmation when an entry is saved. At night, without looking. |
| Internet | Exclusively for family sync (section 3). Without a group, the app opens no connection. |
Babytakt demands no access to contacts, location, microphone or your photos — you pick a picture through the system chooser, which hands the app only that one image.
2.4 What is not in the app
No ads. No advertising ID. No analytics or statistics services. No crash reports to third parties. No push services. No Firebase or Google Play Services libraries. No fonts or images loaded from anywhere at startup.
2.5 Deleting — any time, without asking us
Because the data sits with you, the right to erasure (Art. 17 GDPR) is built into the app and needs no request to us:
- Single entries: tap, delete — gone at once.
- A child: the profile sits in “Recently removed” for three days and can be restored. After that the profile, all its entries, moments and pictures are deleted for good, on every device in the group.
- Everything: in the settings you delete the whole history in one go. If you want to keep it, write a backup file first (section 4).
- The app: uninstalling takes the database with it. What you backed up into a folder yourself stays there — you delete that where it lies.
3. Family sync (optional)
When several people track the same child — the other parent, grandparents, daycare —
you can create a group and invite the others. Only then does the app talk to a server,
and only to our own at sync.babytakt.app. If you never enable sync, this
entire section does not apply to you.
3.1 End-to-end encrypted
The app encrypts your entries on the phone before transferring them (AES-256-GCM). The key is created on the device, kept in the protected key store (Android Keystore or iOS Keychain) and handed directly to the other phone when you invite it — it never reaches the server. What sits there is a package nobody can open: not us, not the data center operator, nobody with access to the disk.
3.2 What sits on the server
| Stored | Why |
|---|---|
| The encrypted package per device | So the other devices can fetch the latest state. A new package replaces the old one. |
| Random group and device identifiers | To match packages to the right group. They are random and contain no names. |
| A hash of the device token | Device authentication. The token itself is not stored, only its checksum. |
| Two timestamps per device | Created and last seen — for cleanup and the device list. |
| Open invitations | Expire automatically after 10 minutes (QR code) or 24 hours (link). |
Not stored: names, e-mail addresses, phone numbers, device models, advertising IDs. The server does not know who you are and cannot derive it from the data.
3.3 Abuse prevention
So that nobody can guess join codes, five attempts per minute and IP address are allowed. For this, the IP address sits briefly in memory and is not stored permanently. A group holds at most ten devices. The legal basis is our legitimate interest in secure operation (Art. 6(1)(f) GDPR).
3.4 Logs
The service writes neither packages nor tokens nor join codes into its logs. Access logs exist only to the technically necessary extent, with truncated IP addresses, and are deleted after a few days.
3.5 Deletion
- Remove a device: In the settings you can eject any device from the group — its package and its access are deleted with it.
- Dissolve the group: Deletes packages, invitations and access of the whole group immediately and completely.
- By itself: Groups with twelve months of no activity are deleted automatically.
Your entries on the phone remain untouched in every case. The legal basis for sync is Art. 6(1)(b) GDPR — without this processing, the feature you requested cannot exist.
3.6 Pictures in sync
Pictures attached to moments travel encrypted like everything else. They sit separately from the entries at the service and are deleted there once every device in the group has fetched them, after 30 days at the latest. The original stays on the phone it came from.
If you do not want photos in the group, switch Pass on photos off in the settings: the texts are then synced and the pictures are not. On the other devices the moment appears without its picture.
4. Backup files
Babytakt can write your history into a file that you store yourself — on the phone, in your cloud, wherever you like. This file is not encrypted, so that it is still readable in ten years. Where you put it is your decision; if it lands in a third-party cloud, that provider's privacy policy applies there. We never see the file.
The same holds for the daily backup: you pick a folder once, and from then on the app writes a new file there by itself and keeps the most recent ones. That path does not go through our service and is therefore not end-to-end encrypted — it goes straight into the folder you chose. Pick a folder in a cloud and the file travels on under that provider's rules; pick none and nothing happens.
5. This website
The site runs on our own server at dogado GmbH, Antonio-Segni-Straße 11, 44263 Dortmund, Germany; a data processing agreement is in place. When you visit, technically necessary access data arises (requested page, time, browser identifier, IP address). It serves secure operation (Art. 6(1)(f) GDPR) and is deleted shortly.
No cookies. No tracking. No analytics. No embedded third-party content. Fonts are served by this server itself — in particular, there is no connection to Google Fonts. If you write us an e-mail, we process your details only to reply.
5.1 Your choice between day and night
If you set the light or dark appearance at the top right, the browser remembers this
choice in local storage (key babytakt-schema, value hell or
dunkel). This is not a cookie: the entry stays on your
device, is never sent along, and can be removed any time with your browser data. If you
never touch the switch, nothing is stored — your system setting applies.
5.2 The contact form
When you submit the form, we transfer your name, e-mail address and message
to our own delivery service at api.bork.media — the same server, the same
controller, no form provider and no third-party service. From there the content lands in
our inbox as an e-mail. There is no database: what you write exists afterwards only as an
e-mail and is deleted once your request is settled and no retention duty stands in the
way. The legal basis is Art. 6(1)(b) or (f) GDPR (answering your request). You can always
write to us directly instead — the address is in the legal notice.
5.3 Spam protection (ALTCHA)
So that the form is not flooded by machines, we use ALTCHA. Unlike common captchas it runs on our own server: no picture puzzles, no Google reCAPTCHA or hCaptcha, no cookies, no data flowing to third parties. Your browser receives a random task, computes it in the background and sends the result along — only these random values are processed, nothing about you. In addition, an invisible extra field catches automated submissions.
So that nobody can fire the form every second, the service briefly counts requests per IP address (five in ten minutes) and the random values used. Both sit only in memory, are discarded after a few minutes and are never stored permanently. The legal basis is our legitimate interest in an abuse-free form (Art. 6(1)(f) GDPR).
6. Installation through the app stores
Babytakt is distributed through the Google Play Store and the App Store. When you download and update, Google Ireland Limited and Apple Distribution International Ltd. process data of your store account under their own responsibility — we have no influence on this and learn nothing beyond anonymous totals in the respective developer console (for example: how many installations exist in total). Google's and Apple's privacy policies apply.
7. Data about your child
Babytakt is made for parents, not for children. What is recorded about the child is entered by the parents and stays in their hands: on their devices, in sync only encrypted. There is no profiling, no comparison with other children, no automated decision-making and no sharing with third parties — not even in anonymized form for research or advertising.
So we collect nothing about your child. We provide a notebook and a sealed envelope; what goes into it and who may read it is your decision — for the health details even per invited person (section 3). If the child later grows old enough to decide for themselves, the whole history is with you and can be handed over or deleted without us ever knowing.
8. Recipients
Beyond the hoster (dogado GmbH, Dortmund) there are no recipients. No data is transferred to countries outside the EU; all servers are located in Germany.
9. Your rights
You have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and objection (Art. 21 GDPR). Because we keep no accounts, we cannot match you to any record — the data sits with you, and the answer sits in the app: you can view, back up and delete it yourself at any time.
You can complain to any supervisory authority; the one responsible for us is the Landesbeauftragte für Datenschutz und Informationsfreiheit Nordrhein-Westfalen, Kavalleriestraße 2–4, 40213 Düsseldorf, Germany.
10. Changes
If a feature arrives that touches new data, we change this text beforehand and update the date at the top. Older versions are available on request.
11. Reporting abuse
The service only carries encrypted packages; we do not see their content and cannot check it. If a group is used for something unlawful, write to us at hello@babytakt.app. Anything that narrows down the device or the group helps — for instance the invitation link that brought you in.
We look at every report and may suspend the device concerned or the whole group; the basis for that is in the terms of use. Whoever reports gets an answer. Whoever is suspended learns the reason as soon as we can name it, and may object.