KiezPilot
Berlin for families, made simple

English · Deutsche Version

KiezPilot: Privacy Policy

Effective date: 14 June 2026 · Last updated: 29 September 2026

KiezPilot ("the app", "we") helps parents in Berlin find family-relevant places and events. We built the app to be private by design: in this version we collect no name, no email address, no phone number, and no other information that directly identifies you.

This policy explains what limited data the app does process, why, and your rights under the EU General Data Protection Regulation (GDPR).

1. Who is responsible (controller)

Ramzi Merhej
Neuenburger Straße 22a
10969 Berlin, Deutschland
Email: privacy@kiezpilot.com

(See also our Impressum.)

2. What we process, why, and on what legal basis

2.1 Your KiezPilot identifier

When you first open the app, it creates a random, device-bound identifier (a UUID). In this version there is no sign-up: we never ask for or store your name, email address, phone number, or a password.

Against that identifier, our server stores exactly the following, to the extent you provide it:

On top of that come your contributions and ratings (§2.4), photos you contribute (§2.13), your push subscription if you turn on severe-weather alerts (§2.9), the usage records (§2.10), and the places and events you save (favorites, §2.3).

Because the identifier is stable and that information is linked to it, we treat the identifier and that information as pseudonymous personal data under the GDPR. Authentication is handled by our processor Supabase (see §4).

Do you have to provide any of this? No. There is no statutory or contractual obligation to give us any of it, and you do not have to provide any of it in order to use the app. If you leave it out, the recommendations are simply more general. The only thing that is necessary is the identifier itself: without it we cannot provide the parts of the app that need a server.

2.2 Location

If you grant location permission, the app uses your device location while you are using the app to find places and events near you. Your coordinates are sent to our backend to return nearby results. For weather-aware suggestions and official weather warnings, the app calls the Bright Sky weather API (see §4) directly from your device; Bright Sky receives your coordinates rounded to about 1 km (two decimal places; the precise ones are never sent for this) and, unavoidably, as with any internet connection, your device's IP address. We do not store those requests. The app likewise fetches the public-holiday and school-holiday calendar directly from openholidaysapi.org (see §4); no location and no identifier is sent with it. We do not build a movement profile, do not track you in the background, and do not store your location as a history.

2.3 Your saved places, and what stays only on your device

When you save a place or an event (favorites), we store that choice against your identifier (§2.1) so it is not lost if the app’s local data is cleared. We store only which place or event you saved and when. Nothing about why, and nothing about where you were. The app keeps its own copy on your device and reads from that, so your saved items work offline. When you delete your data (§6), the saved places are deleted too.

We store your language against your identifier on our server (§2.1) in addition to the local copy; the severe-weather settings described in §2.9 are likewise stored on our server. Purely visual display preferences with no link to your identifier stay only on your device and are removed when you uninstall the app. (When you open a place’s or an event’s detail page, that also creates a usage record on our server; see §2.10.)

2.4 Community contributions (optional)

If you choose to add or correct information about a place (e.g. "is it fenced in?", "report outdated info"), that contribution is saved against your identifier (§2.1) and may be shown to other parents as "reported by parents". Please do not include any personal information in free-text contributions. How we handle reported content, and how you can flag something, is on the Report content page.

2.5 Map tiles

Maps are rendered using map images ("tiles") from OpenStreetMap. To deliver those images, the OpenStreetMap Foundation necessarily receives your device's IP address when a map loads. The OpenStreetMap Foundation decides about that processing on its own account; for this it is not our processor but its own controller. It is governed by the OpenStreetMap Foundation Privacy Policy.

2.6 Technical/operational logs

Our backend provider Supabase processes technical data (such as IP address and request metadata) transiently for security and to operate the service. This is standard processor logging and is not used to identify or profile you. Retention: these logs are deleted automatically at Supabase after 7 days (the retention of the plan we are on); we do not export them and do not analyse them per person. Cloudflare also processes connection data in order to serve the kiezpilot.com website; see §4 and §2.11.

2.7 Product analytics

We use no third-party product-analytics tool. We previously trialed PostHog (EU-hosted infrastructure); capture was switched off in the app code on 26 August 2026, and the PostHog project, with whatever trial data was still in it, was deleted on 6 September 2026. What we do measure ourselves (place and event views, search metrics, and which recommendations were shown, on our own server) is set out in full in §2.10; that is not third-party analytics, but it is measurement, and we name it here so the two sections do not read as a contradiction. If we ever use a third-party analytics tool, it will only run with your explicit consent (off by default), and we will update this policy first. The app asks you this question once, when you first open it: "May we measure how the app is used?", with two equally prominent buttons, Accept and Only necessary. Nothing is pre-selected. Your answer is stored only on your device, is never sent to us, and you can change it at any time under Settings → Privacy. While no third-party tool is in use, your answer changes nothing in practice; it is the switch such a tool would have to pass. Your answer does not affect the technical logs (§2.6), the crash reports (§2.8) or the usage records (§2.10): those rest on Art. 6(1)(f), not on your consent. We do not use any advertising or cross-app-tracking technologies.

2.8 Crash reporting

If the app crashes or encounters a technical error, we use Sentry (our project sits in Sentry's European data region, in Germany) to receive a technical report so we can fix the problem. A report contains:

Your IP address is not stored with the report: the SDK is configured with PII sending switched off and does not pass it on. Network traces collected on the way to an error have their coordinates stripped on your device before the report is sent. We know neither your name nor your email address, so we cannot and do not pass them on.

2.9 Severe-weather alerts (optional)

If you switch on severe-weather alerts (off by default; you turn them on with an explicit tap), we send you a push notification when the German Weather Service (Deutscher Wetterdienst, DWD) issues a severe-weather warning for your area. To do this we store, linked to your identifier (§2.1):

2.10 Usage records (server-side)

In addition to the purely local data described in §2.3, our server stores a few usage signals, linked to your identifier (§2.1), to measure whether the app’s recommendations actually help:

These records are not shown back to you in the app (no history, no “recently viewed” list) and are not used to target you individually with advertising; they exist solely for internal product measurement (e.g. “do rainy-day recommendations actually get opened?”).

2.11 Link and QR-code counts (website)

When you scan one of our QR codes or open a /go link on kiezpilot.com, we increment a counter in our own database. That counter has exactly four fields: channel, operating-system group (iOS, Android, other), Berlin calendar day, and a number. Neither your IP address, nor any identifier, nor a timestamp finer than the day is written into it, and no cookie is set.

For the redirect to work at all, our website provider Cloudflare receives, as with any page request, your IP address and your browser's identification (user agent); the redirect reads the user agent to decide whether to send you to the App Store or to Google Play, and that is where the operating-system group comes from. We do not pass the channel label, or anything else from this request, on to Apple or Google; either way you land on our plain store listing.

2.12 When you write to us

If you send us an email (hello@kiezpilot.com, privacy@kiezpilot.com) or report a piece of content (Report content), we process your message, your sender address, and whatever you tell us in it, in order to deal with your request. The email travels through Cloudflare Email Routing and arrives in a Google mailbox (Gmail); both act as our processors for this (§4).

For messages to hello@kiezpilot.com we also keep a copy in our own database at Supabase (§4, Frankfurt), so that enquiries do not sit unnoticed in a mailbox. What we keep: your sender address and display name, the subject, the text of your message, the date and time, and (as a note, not as a file) the filename, file type and size of any attachment. We do not store the attachments themselves there; they stay in the mailbox only.

2.13 Photos you contribute (optional)

You can contribute a photo of your own to a place or an event in the app. Before anything is uploaded, the app scales the photo down on your device and removes the metadata embedded in the image, including where it was taken. Only adults can contribute photos: with the licence grant you confirm that you are 18 or older. We do not ask for a date of birth.

Under your identifier (§2.1) we store:

Without your name. We do not ask for your name and we do not store it. A published photo is credited "Foto: KiezPilot-Community".

Review and publication. We look at every photo before it appears. We do not publish photos in which a person is recognisable. Only after we approve a photo do we show a copy publicly: in the app and on kiezpilot.com, on the page of the place or event and in the preview that appears when someone shares that page. Under your licence grant the photo may also appear in KiezPilot's app-store listings.

Withdrawing. While your photo is still in review, you can withdraw it in the app; the app then deletes the uploaded file. To withdraw a photo that has already been published, email hello@kiezpilot.com; we then take it out of the app and off the website.

2.14 Information about establishments from public sources (Art. 14 GDPR)

This section is not addressed to the people who use the app, but to people whose details we take from public sources without collecting them from those people directly.

What. KiezPilot shows parents places and activities for families, such as playgrounds, museums, courses, clubs and doctors' practices. For these establishments we store business details: name, address, phone number, website, opening hours and, where the source gives one, an email address. We also keep the entry as the source delivers it. Mostly these details concern companies or organisations. They are personal data where they concern an individual, for example a doctor's practice named after the doctor.

Where from. Publicly available sources, mainly OpenStreetMap, the Berlin open-data portal (daten.berlin.de) and the establishments' own websites. All sources are listed on the Data sources page.

Why. So that parents can find and reach an establishment. We show these details in the app, and some of them on kiezpilot.com. Where the source gives an email address we store it, but we do not currently display it.

We publish this information here instead of writing to each person concerned, because notifying each person individually would involve a disproportionate effort given the number of entries (Art. 14(5)(b) GDPR).

What we do NOT do

3. Children's data

KiezPilot is a tool for parents and caregivers and is not directed at children. Children get no identifier and no profile with us; there is nothing a child could use the app with.

What we store. For each child you add, we store exactly two things: the birth month and the birth year. Nothing else: no name, no gender, no exact date of birth, no photo, no health or childcare information. The app computes the age from month and year to filter suggestions; we do not additionally store the age.

Where it comes from. From you. You enter it as the parent or caregiver; a caregiver without parental responsibility may only do this with the legal representative's authority. We do not collect it from your child and we obtain it from no other source. This policy is at the same time the Art. 14 GDPR information for the child whose details you enter here.

What it is for. Only to filter and sort places and events by age suitability. We do not use it for advertising, we do not build a profile of your child from it, and we do not pass it to anyone who is not named in §4.

The information sits with Supabase (§4) as part of your pseudonymous profile; it is not linked to a name, an email address, or a phone number, because we hold none of those.

4. Who receives your data, in what role, and where

Processors (they process data only on our instructions, under a data-processing agreement):

Independent controllers (they decide about the processing themselves; we cannot instruct them, and their own privacy policies apply):

PostHog (product analytics) used to be integrated and no longer is: the project was deleted on 6 September 2026 (§2.7). It is therefore no longer a recipient.

Transfers to third countries, said plainly. Our database and authentication run in Frankfurt, and the crash reports sit in Sentry's German region. Even so, "your data never leaves the EU" would be false: Supabase is a company established in Singapore; Sentry, Cloudflare, Expo and Google are established in the USA; and the push and update paths lead there. Each of those transfers is covered by the safeguards named above: an adequacy decision, the EU-US Data Privacy Framework, or Standard Contractual Clauses under Art. 46(2)(c) GDPR. You can obtain a copy of the relevant safeguards on request at privacy@kiezpilot.com.

5. How long we keep data

Your record and your contributions are kept until you delete them or request deletion (see §6). Beyond that, three fixed limits apply even if you never ask us:

Alongside those, the periods stated in each section apply to the individual kinds of data:

Data stored on your device remains until you uninstall the app. Reinstalling the app creates a new identifier; the old record stays on our servers at first, can no longer be attributed by us to any person, and is deleted after those same 24 months at the latest.

Backups. Once a week we take a full backup copy of the database. Those copies sit separately from the running service, are never read by the app or the website, exist solely to recover from data loss, and expire automatically after 90 days. A single row cannot be lifted out of such a copy, which is why the copy expiring is how the deletion is completed there too: within 90 days of your deletion at the latest. If we ever had to restore a backup, we re-apply every deletion made after the point that copy was taken immediately afterwards; that is a fixed step of our restore procedure.

6. Your rights

Under the GDPR you have the right of access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and objection (Art. 21). We hold no name, email address, or phone number, so exercising some of these rights requires you to give us your identifier (§2.1) and we will tell you how to read it.

7. Changes to this policy

We may update this policy; the "Last updated" date above reflects the current version. Material changes will be surfaced in the app.

8. Contact

Data protection: privacy@kiezpilot.com · everything else, and all channels: Contact · illegal content: Report content.