Skip to content Oktober-Aktion: Fleißstern forever, €17.99 instead of €34.99 – only until 31 October
Fleißstern

Privacy Policy

In short: we only process what Fleißstern needs in order to work. There are no ads, no tracking and nothing passed on to third parties for advertising.

1. Controller

Marcze Media UG (haftungsbeschränkt)
Marienstraße 15
12459 Berlin
Deutschland

Email: hallo@fleissstern.de

2. Visiting the website

When you visit fleissstern.de, our host processes data that is technically necessary: IP address, date and time, the address requested, the amount of data transferred, browser and operating system. This is needed to deliver the page and to protect it from misuse (Art. 6(1)(f) GDPR).

The website does not embed any fonts, scripts, videos or maps from other servers and sets no cookies when you simply visit.

Language: If you switch language, the website stores a cookie (fs_sprache) containing “de” or “en” so that your choice still applies on your next visit. It contains nothing else, lasts a year and can be deleted in your browser at any time. The legal basis is our legitimate interest in showing you the site in your language (Art. 6(1)(f) GDPR).

Anonymous visitor counts: So that we can see which pages are read and where visitors come from, we count page views on our own server – without cookies, without scripts and without third-party services. All we store is the page requested, the time to the minute, the domain of the page you came from, campaign details from the address (such as “utm_source”), device type, browser and operating system as well as country and federal state. We estimate country and state from your IP address using a database on our own server (IP geolocation data by DB-IP.com, CC BY 4.0).

We do not store your IP address for this. To be able to count visitors and visits, we build a pseudonymous daily code from the IP address and the browser identifier. The key for it is generated afresh every midnight and the old one deleted – after that the code cannot be linked to anyone. The counted views themselves do not lead back to a person; we delete them after 25 months. The legal basis is our legitimate interest in improving the website (Art. 6(1)(f) GDPR). We do not count the browser version or the apps.

Sharing: Below the guide articles there are plain links to WhatsApp, Facebook, Pinterest, Telegram and email. They load nothing from those services – only when you tap one does the relevant page or app open, and from then on their privacy notices apply. ‘Share …’ opens your device's share menu, and so does ‘Instagram’ (on phones and tablets only) – with an image made up of the cover picture, headline and intro that your device draws itself, and the address in your clipboard. ‘Copy link’ puts the address in your clipboard. All of that happens on your device only.

If your browser sends ‘Do Not Track’ or ‘Global Privacy Control’, we do not count your visits. You can object to the counting at any time (Art. 21 GDPR) – most easily with one of those settings, or informally by email.

3. Hosting

Fleißstern runs at ALL-INKL.COM – Neue Medien Münnich, Hauptstraße 68, 02742 Friedersdorf, Germany. The host processes the data on our behalf on servers in Germany (Art. 28 GDPR).

4. Account and family

When you create an account, we store:

  • your email address, your name and your password – the password only as a hash that cannot be reversed – and whether you created the account in the browser or in an app,
  • the details about your family: what your children call you, time zone and start of the week,
  • the details about your children: first name or nickname, colour and symbol – and a profile photo if you choose one,
  • Tasks, completions – including the photo where a task asks for photo proof –, rewards, wishes and star entries.

We need this to provide Fleißstern to you (Art. 6(1)(b) GDPR). You enter the details about your children as their parent. Please use a first name or a nickname only.

Children's profile photos: A photo is optional. Before we store it we crop it to a square, scale it down to 512 pixels and redraw it – so the details cameras write along (such as place, device and time taken) are not stored. The photo is kept on our server in Germany and can only be retrieved by the members of your family; on a child's iPhone, only their own photo. If you remove the photo or the child, we delete the file immediately. On an iPhone without an account the photo stays on the device.

Photos as proof: If a task asks for a photo, your child takes it in the app or in the browser when ticking the task off. So that you can see it on your other devices and in the browser, we upload it to our server. Before that we scale it down to 1600 pixels at most and redraw it – so the details cameras write along (such as place, device and time taken) are not stored. Only the parents in your family and the child who did the task can retrieve the photo. If you reject the completion or take it back, we delete the photo immediately, otherwise 30 days after the day of the task – on the server and, at the next sync, on your devices too. On an iPhone without an account the photo stays on the device.

The data stays stored until you delete your account. You can do that at any time in the settings; account and family are then removed for good. The settings also let you download all your data as a file.

5. Signing in and security

After you sign in we set a cookie called “fleissstern_sitzung”. It contains nothing but a random identifier to keep you signed in, and is strictly necessary for that (§ 25(2) no. 2 TDDDG). It lasts 30 days or until you sign out. In the iPhone app a random identifier in the device keychain does the same job; it lasts a year or until you sign out.

For every sign-in we store the IP address and browser identifier so that we can spot misuse. So that nobody can try out passwords or connection codes, we briefly count sign-in and connection attempts by IP address. We delete the counters after a few hours and the sign-in details when the session ends (Art. 6(1)(f) GDPR).

If you reset your password, your browser briefly keeps the link from the email in session storage until the new password is saved.

6. Emails and contact

We only send you emails that belong to your account: confirming your address, links to reset your password and notices about changes to your account – and replies when you have written to us. Only if you allow it do we also ask you once by email how you like Fleißstern. There is no newsletter. Sending runs through our host's mail server.

Contact form: If you write to us using the form on the contact page, we store your name, your email address, the topic you chose and your message in order to reply (Art. 6(1)(b) GDPR, for general questions (f)). The message is also sent by email to our inbox; if you want, we send you a confirmation of receipt with the number of your enquiry. So that the form cannot be misused for spam, we briefly count messages by IP address and email address, as described in section 5. If you choose the topic ‘beta test’, we also store device, operating system and version in order to invite you to the right test. For the invitation we add your email address as a tester with Apple (TestFlight) or Google (Google Play); their privacy notices apply there. We keep our replies and internal notes with the enquiry. Once an enquiry is settled we delete it after a year, unanswered ones after two years at the latest – sooner on request. If you email us directly, the same applies.

Asking for a rating: If you allow it when you register or in the settings, we send you a single email about a week after you registered asking you to rate Fleißstern – and only if your family is using Fleißstern by then (Art. 6(1)(a) GDPR). For this we store since when you allowed it and when the email was sent. You can withdraw your consent at any time: in your account settings or through the link in the email.

Rating form: If you rate Fleißstern using the form on our website, we store your stars, your text, the name and the detail you enter, together with your account – so that we can read it and so it is clear that it comes from a family that uses Fleißstern (Art. 6(1)(f) GDPR). The rating is also sent by email to our inbox. We only show it on our website if you allowed that with the checkbox (Art. 6(1)(a) GDPR), and only with the name you give. You can withdraw that permission at any time and we will take the rating down. It stays stored until you ask us to delete it or you delete your account.

Ratings in the App Store and Google Play: We regularly retrieve the ratings that are publicly visible for Fleißstern in the App Store or on Google Play: stars, title, text, date and the name shown there, plus the average score. That is how we see what you like and what you don't (Art. 6(1)(f) GDPR). On our website we only show the average score with the number of ratings – individual ratings only with that person's permission.

7. The apps for iPhone and Android

Without an account the app stores children, tasks, rewards, stars and photos on your device only and sends none of it to us. It schedules reminders directly on the iPhone. It only uses the camera when you use photo proof or scan a QR code to connect or join, and only with your permission.

Rating inside the app: After a while the apps occasionally ask for a rating using Apple's or Google's rating dialogue. What you enter there goes straight to Apple or Google; we only learn about it once the rating is public in the store.

With an account: When you sign in in the app and connect your family, the app transfers children, tasks, completions, rewards, wishes and star entries to our server and syncs them with the browser and your other devices (Art. 6(1)(b) GDPR). The details in section 4 apply – including to profile photos and photos used as proof.

Android app: The Android app always works with an account, like the browser version: children, tasks, completions, rewards, wishes and star entries are kept on our server, and the details in section 4 apply. The app stays signed in with a random identifier held encrypted on the device. It picks photos through Android's photo picker or takes them with the camera app – only when you or your child taps that. It reads invitation and QR codes with the code scanner in Google Play services on the device; the camera image never leaves the device.

Children's phones: When you connect a child's iPhone or Android phone with a code, we store the device type for it (‘iPhone’, for instance), when it was connected and when it last checked in, plus a random access identifier, stored only as a hash. The device receives the family's tasks and rewards, but only that child's own stars and wishes. Connection codes are valid for 15 minutes and are only held as a hash; we delete them a day after they expire. You can disconnect a device at any time; we delete the details about it 30 days later.

Premium: You buy Premium through the App Store or, in the Android app, through Google Play. In the App Store Apple handles the payment; Apple's privacy policy applies to it. So that Premium works on all your family's devices, the app sends the receipt signed by Apple to our server. We check the signature and store Apple's transaction number, the product and how long it is valid for. We do not learn your name or your payment details in the process. We delete these details together with your account. Apple also tells us directly about renewals, cancellations, payment problems and refunds (App Store Server Notifications) so that Premium is correct on every device. Those messages contain the same purchase details, again without names or payment data; we delete our log of them after 90 days.

Purchases through Google Play: Google handles the payment (Google Ireland Limited); Google's privacy policy applies to it. After the purchase the Android app sends the purchase token from Google to our server. We use it to ask the Google Play Developer API whether and until when the purchase is valid, confirm it there and store token, product and period with your family. So that a passed-on purchase is of no use to anyone, the app gives Google an identifier for your account when you buy – a hash value your account cannot be read from. We do not learn your name or your payment details. Google can tell us about renewals, cancellations and refunds; in those cases too we ask Google for the current state. The legal basis is Art. 6(1)(b) GDPR. We delete these details together with your account.

Notifications on a child's phone: If you allow notifications on a child's iPhone or Android phone, we store the push token Apple or Google issues for it and whether it comes from a test build or the finished app. We use it to send a message through the Apple Push Notification service (Apple Distribution International Ltd., Ireland) or, on Android, through Firebase Cloud Messaging when you approve a reward – with the name of the reward and the name your child knows you by. The legal basis is Art. 6(1)(b) GDPR. We delete the token as soon as the device is disconnected or Apple or Google tells us it is no longer valid. Notifications can be switched off at any time in the iPhone settings.

Notifications for parents: If you turn notifications on in the app settings, we store, for your session on that device, the push token from Apple or Google, whether it comes from a test build or the finished app, and which notifications you want. We then send you a message through the Apple Push Notification service or Firebase Cloud Messaging when a child has ticked off a task for you to confirm or wishes for a reward – with the name of the child and of the task or reward. If you also switch on the evening reminder, we send one message a day at around 6 pm if tasks are still open for today – with the name of the child and one open task. All we remember for this is the day of the last reminder, stored with your family. The legal basis is Art. 6(1)(b) GDPR. We delete the token as soon as you switch notifications off in the app, sign out on the device, or Apple or Google tells us it is no longer valid.

Stars for screen time: If you switch screen time on for a child, we store your settings for it: how many minutes a star is worth, how much time there is each day without stars and how much at most. Which apps and websites are blocked, and how long they are used, stays on the device where you set the block up – your child's iPhone or a family device with the children's view. Apple only gives the app encrypted identifiers for this, and those do not reach us. The iPhone only tells us whether the block is set up and how many apps, categories and websites it covers, so that you can see it in your settings. When your child trades stars for time, the entry goes to our server like any other star entry. The legal basis is Art. 6(1)(b) GDPR. We delete the settings together with the child or your family, and the device's reports together with the device.

Prize draws: If you enter a prize draw, we store that and when your account entered and which family it belongs to – in order to run the draw, pick the winners, notify them by email and unlock Premium for them (Art. 6(1)(b) GDPR). We delete the entries six months after the draw. The fact that your family won stays stored as the reason for the unlocked Premium until you delete your account. The details are in the terms of the respective prize draw.

Vouchers: If you redeem a voucher in the browser, we store which code was redeemed by which family and account, and when. That is the only way each code is valid as often as intended, and it lets us check if there are questions. We delete these details together with your family. Offer codes for the App Store, on the other hand, are redeemed with Apple; we only learn about them from the receipt.

8. Recommending Fleißstern

Every family can recommend Fleißstern with a link of their own. For that we give the family a random code and store it with them. When someone opens the link, the website places a cookie (fs_freund) with that code in their browser; it lasts 30 days and goes away as soon as a family has been created. If you create an account before there is a family, we keep the code with the account until the family exists – even if you only set it up in the app later. If a family comes of it, we store which family recruited which and when Premium was given for it. Both families get a free month of Premium as soon as the new family really uses Fleißstern; the recommending family only ever learns the number, never the name. The legal basis is Art. 6(1)(f) GDPR – our interest in making Fleißstern better known – and, for the bonus, Art. 6(1)(b) GDPR. If you delete your account, the entry with your family disappears.

9. Error logs

If an error occurs on the server, we write a technical message to a log so that we can fix it. We delete the logs after three months (Art. 6(1)(f) GDPR).

10. Your rights

You have the right to information about your data (Art. 15 GDPR), to rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18) and data portability (Art. 20). You can object to processing based on legitimate interests (Art. 21). Just send us an email about it.

You can also complain to a data protection authority, for example the one in your federal state (Art. 77 GDPR).

Last updated: September 2026