1. What we keep (and what we don’t)
- The name or nickname the adults choose for each child (a full name isn’t needed).
- The birthday, if the adults want, with day and month only, no year.
- The character and colors chosen.
- Routine tasks done, stars, goals, coupons and medals, with the notes the adults write.
We don’t keep photos of children, voice, location, contacts, documents, school or biometrics. The child’s screen has no text field: the child taps, drags and listens.
2. What the child sees
- No ads, purchases, chat or contact with other people.
- No links out of the app: the product links of goals show only to the adults.
- No comparing or ranking children.
- The child’s screen never talks about payment.
- Leaving it takes the adults’ password or PIN.
3. Who can see it
- The family’s adults: whoever created it, other parents and invited caregivers. The activity log shows every parent what each adult did.
- The children’s devices, connected with a one-time code and disconnectable at any time.
- The Mippo's team, only to answer help requests. The team’s screens don’t show children’s names. The admin area asks for the password every 30 minutes plus a second factor (an authenticator app’s code), and every action is logged.
- No one else. We don’t sell data or use it for advertising.
4. Where the data lives and who protects each part
- App and database: Fly.io servers (a US company) in the São Paulo region, in ISO 27001-certified data centers. Fly.io has a SOC 2 Type II audit. The database disk is encrypted by Fly.io, with keys it manages.
- Backups: made every 5 seconds and kept for 30 days at Tigris (a US company, SOC 2 Type II audit). Before leaving the server, each backup is encrypted with a key only Mippo's holds: Tigris stores only ciphertext. Today Tigris may keep the backups outside Brazil; we are pinning them to São Paulo.
- Emails: sent through Resend (US, SOC 2 Type II audit), which receives only the adult’s email address and the notice’s text, never children’s names.
- Phone notifications: end-to-end encrypted; Google’s and Apple’s services only carry the encrypted message.
- Payments: made at Mercado Pago or Google Play. Card and Pix details stay with them; Mippo's never sees them.
The contracts with these providers and international transfers are in the Privacy Policy.
5. What the app itself does
- Always-encrypted connection (HTTPS required).
- Passwords stored with bcrypt: not even the team can read them.
- New-password links, email-confirmation links and access codes stored only as a fingerprint (SHA-256), single-use and short-lived.
- No third-party scripts on the pages: no analytics, no ads, no trackers.
- Attempt limits and a small proof of work against bots.
- Each family isolated from the others on every route, with automated tests, and attack tests against a copy of the app (the latest on 10/4/2026, with no critical flaws).
6. What you control
- Download all the family’s data, in Your account.
- Delete a child: they stay 7 days in the trash, then leave for good.
- Delete the family: 7 days to change your mind; then everything is erased, and backups expire within 30 days.
- Disconnect devices and remove adults at any time.
- See the family’s activity log.
7. If something goes wrong
If there is a data incident, we tell the parents and the authorities, as the law requires. Found a security flaw? Write to contato@mippos.com (the address is also in /.well-known/security.txt). We answer as soon as we can.
8. Risk assessment
We assessed how children’s data is handled in a data protection impact assessment, reviewed at every relevant change. In short: the app keeps little, has no advertising and sells no data, and the main risks (one family reaching another’s data, a stolen session, data loss) have tested measures. The assessment can be requested at contato@mippos.com.