VAKUR
English

Privacy policy

Last updated: 6 October 2026

This English text is provided for your convenience. In case of doubt, the German version applies. Deutsch

In short

Picture and sound are never recorded and never stored on a server. They travel directly from your baby phone to your parent phone, encrypted.

There is no account. Each phone gets a random, anonymous identifier. We do not know who you are, and we store no names, e-mail addresses or phone numbers.

No advertising, no tracking, no analytics tools from third parties.

Who is responsible

Nine to Zero UG (haftungsbeschränkt), Malzer Chaussee 173, 16515 Oranienburg, Germany. Represented by Bryan Brückmann. E-mail: mail@ninetozero.de.

Anonymous device identifier

When the app starts for the first time it creates a random identifier and registers it as an anonymous user with our provider Supabase. It cannot be linked to a person. We use it to connect your two phones with each other.

Legal basis: Art. 6(1)(b) GDPR (providing the service).

Pairing

When you pair two phones we store both device identifiers, the time of pairing, the time of the last connection and a random pairing secret. The one-time code in the QR code is stored only as a hash and becomes invalid after five minutes or after one use.

Legal basis: Art. 6(1)(b) GDPR.

Connection, picture and sound

To set up the direct connection the two phones exchange short technical messages through our provider (connection offers and network addresses, that is IP addresses and ports). These messages are not stored.

Picture and sound then run directly between the two phones and are encrypted in transit (DTLS-SRTP). Only if a direct connection is technically impossible – for example between two mobile networks – is the encrypted stream forwarded by our own relay server in Germany. The relay necessarily processes both phones’ IP addresses; it cannot decrypt the content and does not store it.

Legal basis: Art. 6(1)(b) GDPR.

Technical session statistics

At the end of a monitoring session the app sends anonymous technical figures: role (baby or parent), operating system, app version, start and end time, whether a connection was established, the type of connection (direct or relay), the number of reconnections, losses and network changes, the time until the connection was established, and the baby phone’s battery level at the start and end. No content, no locations, no names.

We use these figures to keep the app reliable and to plan relay capacity. Legal basis: Art. 6(1)(f) GDPR (legitimate interest in a working product). You can object at any time by writing to us.

Purchases

The purchase is handled by Apple (App Store) or Google (Google Play) under their own terms. We receive no payment details such as card numbers.

To check and restore your purchase we use RevenueCat, Inc. (USA). RevenueCat receives the anonymous device identifier, the purchase receipt from the store with product and time, the store country, the app version and operating system and, for the duration of the request, the IP address. The transfer to the USA is covered by a data processing agreement with standard contractual clauses.

Legal basis: Art. 6(1)(b) GDPR.

On your phone

The pairing is kept in the protected storage of your phone (Keychain or Keystore). Your settings – alarm, sensitivity, volume, language, picture on or off –, the start of the trial period and the purchase status are stored in the app. This data stays on the phone.

Permissions

Camera and microphone on the baby phone: to transmit picture and sound. Microphone on the parent phone: for talk-back, only while you hold the button. Camera on the parent phone: to scan the QR code when pairing.

Notifications: alarm when the connection is lost, hints for noise or low battery. They are created on the phone itself; no push service is involved.

Running in the background: so that sound and alarm keep working when the screen is locked.

This website

This website runs on our own server at IONOS SE in Germany. When you open a page the server records the IP address, time, requested page and browser identifier in log files; they are deleted after 14 days and serve only security and troubleshooting. Legal basis: Art. 6(1)(f) GDPR.

The website uses no cookies, no tracking and loads nothing from other providers.

Who receives data

Supabase Inc. (database, anonymous sign-in, connection set-up), data centre in Frankfurt, Germany, under a data processing agreement.

IONOS SE, Germany (relay server and website hosting).

RevenueCat, Inc., USA (checking and restoring purchases), under a data processing agreement with standard contractual clauses.

Apple and Google process purchases in their own responsibility. We do not pass data on for advertising.

How long we keep data

Pairing: until you choose Forget device. A pairing replaced by a new one is deleted after 30 days.

One-time codes: valid for five minutes, deleted within 24 hours after they expire. Failed pairing attempts (protection against misuse): 24 hours.

Session statistics: 12 months.

Anonymous device identifier: deleted automatically after 12 months without use.

Purchase records at RevenueCat: as long as they are needed to restore your purchase; we delete them on request.

Your rights

You have the right to access, rectification, erasure, restriction of processing, data portability and objection (Art. 15–21 GDPR), and the right to complain to a data protection authority, for example the one responsible for us in Brandenburg, Germany.

Because we cannot identify you, please send us the device identifier shown in the app under Settings → Debug. You can delete a phone’s data yourself with Forget device and by uninstalling the app.

Children

The app is meant for parents and carers. It collects no data about the child being monitored; the child’s picture and sound are neither stored nor transmitted to us.

Changes

We update this policy when the app changes. The current version is always available on this page.