Version 2026-08-01

Privacy policy

This page is maintained by the operator of Lekkompis and explains how we handle personal data under the EU General Data Protection Regulation (GDPR) and Swedish data protection law (dataskyddslagen, SFS 2018:218). It is not an independent certification.

1. Who is responsible (data controller)

[Your company name] (placeholder), org. no. [Swedish org. number, e.g. 559XXX-XXXX] (placeholder), [Street address, postal code, city] (placeholder). Contact: [privacy@yourdomain.se] (placeholder). Data protection contact: [dpo@yourdomain.se — optional] (placeholder).

The bracketed values above are placeholders that the app owner must replace with their real legal entity details before launch.

2. What data we collect

  • Account data: email address and password (stored hashed by our authentication provider), or your Google account identifier if you sign in with Google.
  • Family profile: your name, neighbourhood/area, short bio, parenting values, interests and languages spoken at home.
  • Children's data: first name, birth date (used only to compute an age; the exact date is never shown to other families), optional gender and interests. Children have no accounts and cannot log in.
  • Activity data: play dates, invites, proposed times, chat messages, RSVPs, saved venues, and safety reports or blocks you create.
  • Technical data: minimal logs needed to run and secure the service.

We do not collect special categories of data (health, religion, ethnicity, political views) and ask you not to enter such data in free-text fields.

3. Why we use it and on what legal basis

  • Providing the service (matching families, invites, chat) — performance of a contract, Art. 6(1)(b).
  • Children's profile data — provided by you as the parent/guardian on the basis of your consent, Art. 6(1)(a), which you may withdraw at any time by editing or deleting the child profile.
  • Safety, moderation and abuse prevention — legitimate interest, Art. 6(1)(f).
  • Optional product emails — consent, Art. 6(1)(a), withdrawable in your settings.
  • Legal obligations such as responding to authorities — Art. 6(1)(c).

4. Who can see your data

Other signed-in families can see your family profile: your name, area, bio, values, interests, languages, and your children's first names, ages and interests. They can never see your email address, your children's exact birth dates, or your contact details. Chat messages are visible only to the two families in that invite thread. You can turn off discoverability in Family → Privacy & data at any time.

5. Processors and transfers

  • Lovable Cloud (database, authentication, hosting)Stores account, profile and message data (EU).
  • Google Maps / PlacesLooks up suggested meeting places you search for (EU/US (Standard Contractual Clauses)).
  • Lovable AI GatewayGenerates optional draft texts and place suggestions when you ask for them (EU/US (Standard Contractual Clauses)).

Where a processor transfers data outside the EU/EEA, the transfer relies on the European Commission's Standard Contractual Clauses.

6. How long we keep data

  • Family and child profile data: Until you delete your account.
  • Pending play date invites: Deleted automatically after 180 days.
  • Invite chat messages: Deleted automatically after 365 days.
  • Invite change history (audit log): Deleted automatically after 365 days.
  • Safety reports: Kept up to 730 days for abuse prevention.

7. Your rights

You have the right to access, rectify, erase, restrict and object to processing of your data, and the right to data portability. You can exercise access, portability and erasure yourself in the app under Family → Privacy & data (download a JSON copy, or delete your account and all associated data). For anything else, contact [privacy@yourdomain.se] (placeholder).

You may also lodge a complaint with Integritetsskyddsmyndigheten (IMY) https://www.imy.se. The Swedish Authority for Privacy Protection handles GDPR complaints in Sweden.

8. Security

Data is stored in the EU with access controls enforced at the database level, so each family can only read the data they are entitled to. Passwords are never stored in plain text. We do not claim any specific certification (such as ISO 27001 or SOC 2).

9. Changes

When we make material changes we publish a new version here and ask you to accept it the next time you use the app.

HomeTerms of useCookies