1. Who is responsible for the data
Mippo's is developed and maintained by Marcelo Contatto, an individual (natural person), under the n2t studio brand. He is the data controller and also the person in charge of personal data processing (the encarregado, or data protection officer), and can be contacted by e-mail at contato@mippos.com. Support is provided exclusively by e-mail.
2. What data we process
We process only what Mippo's needs to work:
- From the family's adults (whoever created the family and whoever was invited): username, what the children call the adult (optional), role (guardian or caregiver), e-mail (required for whoever creates the family and optional for invited adults; it only takes effect after being confirmed through a link sent to it), password and 4-digit PIN for the grown-ups' area (both stored only as an irreversible cryptographic hash), a record of the acceptance of these documents (person, family, role, version and hash of the accepted text, date, IP address and browser) and access records (date, time and IP address). Each star, confirmed notice or badge keeps the name of whoever recorded it.
- From the children, provided by the guardian: name or nickname, birthday (day and month only, without the year, if the guardian wants the name card to celebrate on the day), the chosen character, color and pattern, stars, goals, coupons and the texts the adults write when recognizing an effort, logging a conversation or taking stars away.
- “I did it!” notices: when the child says they have completed an agreement, we keep which agreement, the date and time, and the guardian's response. Notices without a response expire after 7 days.
- Badges and trophies: the badges given by the guardian (with the optional message), the achievements calculated from the child's own stars and goals, and which of them the child chose to show on their card. There is no ranking or comparison between children.
- Children's devices connected by a guardian: the name given to the device, which child it opens for, which adult connected it, the date of connection and the last use. The IP address of the connection is kept in that adult's access records, for security.
- Family activity log: adults who joined or were removed, role changes, child profiles deleted or restored, devices connected or disconnected and scheduled deletions, with the date and who did it. All of the family's guardians see this log.
- Passes and payments: the family's passes (which one, the dates and who gave or bought it) and, when someone buys a pass, the order: the pass, the amount, the status, the Mercado Pago payment number or the Google Play order number, the date and who bought it. We never receive card data.
- Optional content: goal photos sent by the guardian (objects or places, never people) and product links. When a photo is received, the server deletes its metadata, such as location (GPS), date and device model.
- Messages to support: when an adult with a confirmed e-mail writes in Help › Contact us, we keep the type (question, suggestion or problem), the message, the team's replies and technical details of the device (open screen, device type, browser and screen size), in order to understand and solve the issue. We ask that no one write children's data there.
- Usage numbers: to improve the app, the team only follows aggregate counts (for example, how many families gave stars in a week), without names, e-mails or data of any child.
From the children, we do not ask for or keep photos, year of birth, e-mail, phone number, address, location, contacts or biometric data. The adults' e-mail is used only to confirm the account, send the new-password link and send security and family notices (for example, a device connected, an adult who joined or was removed, a change of e-mail or password, a scheduled deletion); we do not send advertising. We ask that you not write sensitive data in the records.
Optional crochet Mippos notice
An adult can ask, on the home page, for an e-mail when the crochet Mippos, Mippo’s future shop, arrive. This sign-up is separate from the app account and does not use children's data. We keep only the e-mail, the text and version of the authorization, the date of the request and of the confirmation, and cryptographic hashes of the confirmation and cancellation links. The legal basis is the adult's specific consent (art. 7, I, of the LGPD).
We send a link that is valid for 24 hours. The notice only becomes active after confirmation. Unconfirmed requests are discarded after that period in the daily cleanup. Confirmed sign-ups are kept for up to 12 months or until the notice is canceled or completed, whichever comes first. To cancel and delete the sign-up, use the link in the confirmation e-mail or write to contato@mippos.com.
The e-mail provider Resend, Inc. (United States) receives the address and the content of the confirmation and of the notice. Hosting and backups follow the providers and periods in this policy. We do not automatically add account e-mails to this list. This request only allows the confirmation and the arrival notice, with no newsletters or additional advertising.
3. What we use it for and on what legal basis
- Creating and maintaining the account and providing the service (stars, goals, coupons, agreements, support): performance of the contract with you (art. 7, V, of the LGPD).
- Processing the children's data: specific and highlighted consent from one of the parents or the legal guardian (art. 14, § 1), given when creating the family and recorded with the date, version and hash of the text, IP address and browser. Without this consent up to date, the server does not release the children's data.
- Keeping access records (date, time and IP) for six months, to investigate improper access and defend rights in any legal proceedings: legitimate interest (art. 7, IX) and regular exercise of rights (art. 7, VI). The period follows the reference of art. 15 of the Brazilian Internet Civil Rights Framework (Marco Civil da Internet, Law No. 12,965/2014).
- Recovering access to the account, by sending a new-password link to the e-mail you registered: performance of the contract (art. 7, V).
- Sending security and family notices by e-mail and keeping the activity log: legitimate interest (art. 7, IX) in protecting the accounts and the children, and performance of the contract (art. 7, V).
- Notifying you on your phone of what the children asked for (“I did it!”, goal completed, coupon to use), only if you turn on notifications on that device: performance of the contract (art. 7, V). The notification carries the name of the child and of the agreement, goal or coupon, and is sent encrypted to your device. You can turn it off whenever you want in Your account, and signing out also turns it off.
- Signing in with fingerprint or face, if you turn it on: the phone keeps a key that only opens with your fingerprint, your face or the screen lock, and we keep only the public part of that key, the device name and the dates. We do not collect or receive biometric data. Basis: performance of the contract (art. 7, V).
- Preventing fraud and protecting accounts, such as limiting password attempts and running an anti-bot check in the browser itself: legitimate interest (art. 7, IX), always respecting your rights.
The legitimate interest assessment (access records and security notices) can be requested from the data protection officer. We do not use the app's data for advertising, we do not sell data and we do not make automated decisions about you or the children. The crochet Mippos notice depends on a separate sign-up and the adult's specific authorization.
4. Children's data
We process children's data in their best interest, in accordance with art. 14 of the LGPD, the Statute of Children and Adolescents (Estatuto da Criança e do Adolescente, Law No. 8,069/1990) and Law No. 15,211/2025 (ECA Digital). In practice:
- Only the mother, father or legal guardian creates the family and gives consent for the children's data. Invited caregivers accept the Terms and this Policy, but do not give this consent.
- The child does not create an account or provide data; the profiles are registered and managed by a responsible adult.
- We collect the minimum necessary and only for the app to work.
- In the kid view, a plain-language explanation tells what Mippo's keeps about the child and who can see it.
- The kid view has no advertising, shopping links, adults' notes or communication with third parties, and we do not build behavioral profiles of children.
- The grown-ups' area is protected by the guardian's 4-digit PIN or, before one exists, by the account password. On an adult's device, not even the Back button leaves the kid view without that PIN. Devices connected only for the child do not keep an adult's password or session and do not access the grown-ups' area.
- The “I did it!” notice records only which agreement, the date and the time; stars always depend on an adult's confirmation.
- Deleting a child's profile requires the guardian's password. The profile stays in the trash for 7 days, where it can be restored, and is then permanently deleted.
- The guardian can revoke consent at any time by deleting the profiles or the family, and can remove any invited adult.
5. What each adult in the family sees
- Guardians (mothers, fathers, legal guardians): see and manage everything in the family, including conversations, stars taken away and the activity log; invite and remove adults, connect devices and download the data.
- Caregivers (for example, grandparents, aunts and uncles, babysitter): access the children's data with the guardian's authorization, only to follow them and celebrate their achievements. Of the conversations and stars taken away, they see only the ones they wrote themselves. They do not change rules, goals or profiles, do not connect devices and download only their own login's data.
- Child's device: shows only that child's view, without adults' notes or shopping links.
- The Mippo's team, for support and security: sees logins, e-mails, roles, passes, purchases and the family's access and activity records, and only the number of children (never their names or records). On request or for security, it can generate a new-password link (it never sees or sets passwords), end sessions, write in the app, give or revoke passes, suspend a login in case of abuse or fraud and schedule the family's deletion. Every action is logged.
- Removing an adult requires the password of whoever removes them. The removed adult receives a notice by e-mail, and whoever removed them can also disconnect the devices they connected.
6. Who we share data with
We do not sell or rent data. We share it only with:
- The family's own adults invited by the guardian, according to each one's role.
- Mercado Pago (Mercado Pago Instituição de Pagamento Ltda., Brazil), when someone buys a pass: payment takes place on Mercado Pago's page, which processes the data entered there (such as card, CPF, the Brazilian taxpayer number, and e-mail) under its own privacy policy. We send it only the pass and the amount; we receive back the status and the payment number.
- Google Play (Google LLC, United States), when someone buys a pass in the Google Play app: payment takes place in Google Play itself, which processes the Google account and payment method data under Google's privacy policy. We receive only the pass purchased, the order number and the purchase status.
- Processors that provide services to us, under contract and a duty of confidentiality, each only for the stated purpose:
- Fly.io, Inc. (United States), with servers in São Paulo, Brazil: hosting of the app and the database.
- Tigris Data, Inc. (United States), which may store them outside Brazil: storage of the database backups.
- Resend, Inc. (United States): sending the service's e-mails (confirmation, new password, security and family notices); receives the address and content of each e-mail.
- ntfy.sh (servers outside Brazil): technical alerts for the team; receives only technical error messages and internal numbers of deleted records, without names, e-mails or family texts.
- Phone notification service (Google, Apple or Mozilla, depending on the device and browser; they may be outside Brazil): delivers the notifications you turned on. It carries the message encrypted, without being able to read it.
- Porkbun, LLC (United States), which forwards the messages, and Google LLC (Gmail, United States), where they are read: receiving the messages sent to contato@mippos.com.
- Authorities, when there is a legal obligation or a court order.
Google (Gemini, United States) is used only by the administrator to create illustrations for the ideas catalog and does not receive data from families or children.
A product link saved in a goal opens the store's website. Mippo's does not send your data to the store: it only learns what you do there, if you click the link, under its own privacy policy. Mippo's does not take part in affiliate programs and earns nothing from these links, which appear only to adults.
The updated list of processors, with each one's country and transfer mechanism, is available on request from the data protection officer, at contato@mippos.com.
8. How long we keep data
- Account and family: for as long as they exist, including the activity log.
- Deleted child profile: 7 days in the trash, where it can be restored; then it is permanently deleted.
- Family deletion: it is scheduled for 7 days. During that period, the other adults receive an e-mail and can download the data, and whoever created the family can cancel. After that, we delete profiles, goals, stars, coupons, photos, history, activity log and the login of every adult, and we delete or anonymize the support messages.
- Adult who leaves or is removed: we delete their login immediately and delete or anonymize their support messages; the records they made remain in the family's history, with the name used at the time.
- Support messages: up to 12 months after they are resolved, or until the account is deleted, whichever comes first.
- Invitations for adults: valid for 24 hours (guardian) or 48 hours (caregiver), only once, and we keep only a cryptographic hash of the code.
- Paid orders and passes: five years, as a sales record required by tax law; if the family is deleted, we remove the buyer's name from them. Passes given as gifts are deleted with the family.
- Access records: six months, including after the account is deleted, for the security and defense-of-rights reasons described above; after that they are deleted automatically.
- New-password links: valid for 30 minutes and deleted the next day. E-mail confirmation or change: the link is valid for 24 hours; an e-mail not confirmed within that period is discarded. If e-mail sending is down, we keep the address for up to 60 days, so that we can send the link when it is back.
- Log of the team's actions in the administration area: 12 months.
- Backups: kept in a separate location and overwritten within 30 days; deleted data disappears from them within that period. If we need to restore a backup, we reapply the deletions made after it, so that nothing deleted comes back.
9. How we protect data
Passwords and the grown-ups' area PIN stored with one-way hashing (bcrypt), a protected connection (HTTPS), HttpOnly and SameSite cookies, content security policies in the browser, limits on password and PIN attempts, our own anti-bot check at sign-up, password recovery and device connection, single-use, short-lived new-password links, a password to delete profiles and remove adults, e-mail notices when a device is connected, an adult joins or an e-mail or password changes, removal of photo metadata, an administration area that asks for the password again every 30 minutes and logs the team's actions, continuous backups in a separate location and the option to end all sessions when changing the password.
10. Security incidents
No system is completely immune. If there is a security incident that may cause relevant risk or harm, we will contain it, assess what was affected and notify the National Data Protection Authority (Autoridade Nacional de Proteção de Dados, ANPD) and the affected families, as required by art. 48 of the LGPD and the ANPD's regulations, stating what happened, what data was involved, the risks and what we did. Any suspicion involving children's data is treated as the highest priority.
Noticed something strange in your account or found a flaw? Write to contato@mippos.com with the subject “Security”.
11. Your rights and how to exercise them
Under art. 18 of the LGPD, you can request: confirmation that we process your data; access; correction; anonymization, blocking or deletion of unnecessary data; portability; deletion of data processed with consent; information about sharing; information about the possibility of not consenting and its consequences; and revocation of consent. Children's rights are exercised by their parents or legal guardians.
- In the app itself, in Your account: Download my data (access and portability: guardians receive the family's data, including photos and support messages; caregivers, their own login's data) and Delete the account (deletion and revocation; for whoever created the family, the deletion is scheduled for 7 days; for invited adults, Leave this family). The step-by-step guide, including without the app, is at mippos.com/en/delete-account. Profiles and goals can be corrected at any time.
- By e-mail, with the data protection officer: contato@mippos.com. We may ask you to confirm that you are the data subject, for example by writing from the registered e-mail. We reply within 15 days.
You can also file a complaint with the National Data Protection Authority (ANPD), at gov.br/anpd.
12. International transfer
The database is on servers in São Paulo, but some processors are United States companies or store data outside Brazil (see section 6). These transfers are made under art. 33 of the LGPD, through standard contractual clauses and the data processing agreement (DPA) of each processor, which require them to protect the data with safeguards compatible with the LGPD.
The list of processors and the mechanism used with each one are available on request from the data protection officer, at contato@mippos.com.
13. Changes to this policy
When we change something relevant, we will notify you in the app and ask for a new acceptance before you continue. The version and the date of update are at the top of this page.
14. Contact and data protection officer
Controller and data protection officer: Marcelo Contatto · contato@mippos.com.