Legal
FunTaskTik — Privacy Policy
- Version:
- 1.1
- Last updated:
- August 26, 2026
1. Data controller
The controller of the personal data processed through FunTaskTik is:
Controller: Sebastian Puigserver Janer Status: natural person Trade name of the service: FunTaskTik Contact email: funtasktik.contact@gmail.com Website: https://funtasktik.com Country: Spain
FunTaskTik is the trade name of the service and is not currently a legal entity separate from the controller identified above.
2. Scope of this Policy
This Privacy Policy applies to the FunTaskTik mobile application, the official website and associated services that expressly state that they are subject to it.
FunTaskTik is a family organisation tool intended for registered adult users. Depending on the features available, it allows users to manage user accounts, families, members and family profiles, including profiles that an adult may use to represent minors, as well as tasks, calendars, lists, reminders and notifications.
Creating a registered FunTaskTik account is reserved for persons aged 18 or over. FunTaskTik does not currently request date of birth and does not operate its own documentary age-verification system. Adult eligibility is established contractually during registration and does not make a Member's role field an age datum.
This Privacy Policy complements the Terms and Conditions of Use and the Children and Parental Responsibility Policy.
3. Sources of data
Personal data processed by FunTaskTik may come from different sources.
3.1 Data provided directly by the user
A registered user may provide data when they:
- create or manage their account;
- create or administer a family;
- create or edit members;
- create tasks, lists and other family content;
- configure language and other preferences;
- contact support or exercise their rights;
- complete applicable legal processes.
3.2 Data provided by authorised adult users of a family
Certain Member data may be entered by an authorised adult user of a family.
This may occur, for example, when an administrator creates:
- a managed family profile with
role = "child"; - an adult pending registration.
In these cases, the person entering the data must have lawful authority to do so and must limit the information to what is necessary to use FunTaskTik.
The child, adult or admin classification within a Family is a functional classification of the Member and does not by itself constitute verification of age, date of birth or legal adulthood of the person represented.
3.3 Pending adults whose data are not obtained directly from them
An administrator may create a pending adult Member using information such as name, avatar and email address before that person has a registered account.
The purpose of this processing is to manage pending family membership and allow the person, if they later register using that email address, to join the existing Member without creating a duplicate.
Where FunTaskTik processes data relating to an adult that were not obtained directly from that person, the information required by applicable law will be provided at the first contact or communication with that person and, in any event, within the applicable legal period, unless a legal exception applies.
The data of a pending adult who does not complete registration will not be retained indefinitely. FunTaskTik's architecture establishes a maximum period of 30 days for an uncompleted pending adult membership, unless it is deleted earlier by an administrator or a legal ground temporarily justifies a different retention period.
3.4 Technical data generated through use of the service
Certain technology services may generate or process technical data required for authentication, security, backend operation and notifications, such as identifiers, tokens, device information, IP addresses, user agents or limited technical logs.
4. Categories of data processed
4.1 Adult user account
Registered FunTaskTik accounts are intended for persons aged 18 or over. During registration, the user must declare that they meet this requirement together with acceptance of the Terms and Conditions. Under the current model, FunTaskTik does not need to collect date of birth for this purpose.
To create and manage an account, we may process:
- name;
- email address;
- avatar;
- internal Firebase Authentication identifier;
- language preference;
- reference to the active family where applicable;
- legal status/versions of documents acknowledged or accepted when the Legal Gate is implemented;
- technical information necessary for authentication, security and operation.
FunTaskTik currently uses email and password authentication through Firebase Authentication. The authentication service may process credentials and technical data required to authenticate and protect the account. FunTaskTik does not need to display or store the user's password in readable plain text.
4.2 Families and Members
Family Member profiles may contain:
- name;
- avatar;
- role;
- registration status;
- internal membership identifiers;
- creation date;
- joining date where applicable;
- email address where the Member is a pending or registered adult;
- technical relationship with a registered account through internal identifiers where applicable.
4.3 Managed family profiles and profiles representing minors
Under the current model, an unregistered Member may exist only within a Family and may be created, modified or deleted by authorised adult users.
Where an adult uses a Member with role = "child" to represent a minor, that profile:
- does not have its own Firebase Authentication account;
- does not have a global
Users/{uid}document; - does not require its own email address or password;
- is not an independent registered FunTaskTik user.
It may contain data such as:
- name;
- avatar;
- role;
- internal identifiers;
- creation date;
- tasks, assignments and family activity related to that profile.
FunTaskTik does not currently request the age or date of birth of these Members. Accordingly, role = "child" is a functional classification selected by the adult and does not prove a specific age. Likewise, using a different role does not change the real age or legal status of the person represented.
Where the data actually relate to a minor, they are processed with particular regard to the principle of data minimisation and the enhanced protection applicable to minors.
4.4 Tasks, calendar, lists and family activity
FunTaskTik may process data entered by users to use its features, such as:
- task titles and descriptions;
- dates and times;
- recurrence;
- assignments;
- completion status;
- historical references required for task consistency;
- list names;
- list and shopping-list items;
- equivalent information entered through future features compatible with this Policy.
Users should avoid entering sensitive personal data or unnecessary information in titles, descriptions, tasks or lists.
4.5 Devices and Push notifications
Where the device and user allow notifications, FunTaskTik may process:
- internal device identifier;
- Firebase Cloud Messaging (FCM) token;
- platform;
- token type;
- enabled/disabled status;
- update date;
- minimum identifiers needed to route and process a notification.
The FCM token is used to deliver notifications to the relevant user and not for advertising or the creation of commercial profiles.
4.6 Camera and QR codes
FunTaskTik may request camera access for specific features, such as reading QR codes used in the family-joining flow.
Permission may be managed through the operating system. FunTaskTik does not use camera access for advertising or commercial profiling.
4.7 Support, security and exercise of rights
If a user contacts FunTaskTik, we may process:
- contact email;
- content of the request;
- information necessary to respond or reasonably verify identity;
- technical data strictly necessary to investigate security or operational incidents.
4.8 Legal evidence
When the versioning system and Legal Gate are implemented, FunTaskTik may retain limited evidence of legal actions, for example:
- user who performed the action;
- document;
- version;
- type of action, such as acceptance or acknowledgement;
- date and time;
- application version.
It is not necessary to store a complete copy of the legal document within the user's profile.
5. Purposes and legal bases
FunTaskTik does not rely on a single legal basis for all processing activities.
| Purpose | Main data | Main legal basis | | --- | --- | --- | | Create, authenticate and manage an account | account, email, identifiers, preferences | performance of the contractual relationship and provision of the requested service (Art. 6(1)(b) GDPR) | | Provide family features to the registered user | Family, Member, Tasks, Lists and settings | performance of the contractual relationship with the registered user (Art. 6(1)(b) GDPR) | | Process minimum data relating to other Members necessary for family organisation | Member profiles, assignments and shared family data | legitimate interest in coherently providing a shared family service, subject to minimisation and balancing of rights (Art. 6(1)(f) GDPR) | | Create and manage a pending adult | name, email, avatar and pending membership | legitimate interest in managing a pending family invitation/membership, with information duties where data originate from a third party (Art. 6(1)(f) and Art. 14 GDPR) | | Manage profiles representing minors created by an authorised adult | minimum profile data and family activity | legitimate interest in providing the family organisation requested by the responsible adult, with enhanced protection for the minor (Art. 6(1)(f) GDPR); consent where a specific processing activity legally requires it (Art. 6(1)(a) GDPR) | | Send Push notifications and manage devices | Device, FCM token, language and minimum routing data | provision of the requested feature and, where applicable, consent relevant to the specific processing activity (Arts. 6(1)(b) and 6(1)(a) GDPR, as applicable) | | Schedule local reminders | Tasks and settings on the device | performance of the contractual relationship and provision of the requested feature (Art. 6(1)(b) GDPR) | | Security, abuse prevention and protection of accounts and the service | identifiers and minimum technical data | legitimate interest in protecting FunTaskTik, its users and its systems (Art. 6(1)(f) GDPR) | | Handle support and requests | contact data and content of the enquiry | performance of the relationship with the user and/or legitimate interest in handling incidents and requests | | Comply with legal obligations | strictly necessary data | compliance with legal obligations (Art. 6(1)(c) GDPR) | | Retain evidence necessary to establish, exercise or defend legal claims | legal evidence and strictly necessary data | legitimate interest and, where applicable, compliance with legal obligations |
Where processing is based on consent, the person may withdraw it at any time, without affecting the lawfulness of processing carried out before withdrawal.
Acknowledging that the Privacy Policy has been read during registration does not constitute general consent for all FunTaskTik processing activities.
6. Information shared within a Family
FunTaskTik is a shared family service.
Certain data may be visible or usable by other authorised members of the same Family depending on available features and permissions, for example:
- Member names and avatars;
- roles;
- tasks and assignments;
- task status;
- lists and list items;
- other shared family information necessary for operation of the service.
Family data are not considered content intended for public publication.
Users should be aware that information they enter in shared family spaces may be viewed by Members of that Family who have access to the relevant feature.
7. Minors and parental responsibility
FunTaskTik is designed and marketed as a service for registered adult users.
Under the current model, minors do not have independent registered FunTaskTik accounts. An authorised adult may create within their Family a Member representing a minor and is responsible for the family management of that profile, the data entered and supervision of any use they allow the minor to make.
A Member's role is an internal functional classification and does not constitute age verification. FunTaskTik does not currently request the age or date of birth of family Members.
FunTaskTik applies the following minimisation rules where a Member represents a minor:
- Firebase Authentication is not created for the minor merely because the profile is created;
- no child
Users/{uid}document is created; - no child email is requested;
- no child password is requested;
- profiles representing minors are not used for personalised advertising;
- profiles representing minors are not used to create commercial profiles.
The adult who creates or manages data relating to a minor must have the necessary responsibility, representation, authorisation or lawful authority and must limit the data to what is necessary for family organisation.
In Spain, where processing of a minor's data is legally based on consent, the minor may provide that consent themselves only from the age of 14, without prejudice to cases where another law requires the involvement of persons exercising parental responsibility or guardianship. Below 14 years of age, where processing is based on consent, consent from the holder of parental responsibility or guardianship must be obtained under the legally applicable conditions.
This rule does not mean that all FunTaskTik processing involving minors' data is based on consent. The applicable legal basis depends on the specific purpose.
Before introducing registered accounts for minors, verification or collection of age/date of birth, features marketed directly to minors, photographs uploaded by minors, voice, location, contacts, public messaging, direct purchases, advertising or individual analytics concerning minors, a new review of architecture, privacy, child protection and, where applicable, Google Play declarations must be carried out.
8. Notifications and privacy
FunTaskTik distinguishes between:
- remote Push notifications, used for certain business events such as a new task assignment;
- local reminders, scheduled and managed by the device where the feature is available.
The user can manage notification permissions through the operating system.
Depending on device settings, notification content may be displayed on the lock screen or other system surfaces. The user should use operating-system privacy controls if they wish to restrict that display.
FunTaskTik seeks to minimise the information included in payloads and technical logs and does not use the FCM token for advertising purposes.
9. Technology providers and recipients
To provide the service, FunTaskTik currently uses Google/Firebase infrastructure, including:
- Firebase Authentication;
- Cloud Firestore;
- Firebase Cloud Messaging;
- Cloud Functions for Firebase and Google Cloud services required for backend operation.
Google may act as a processor of customer data under the processing and security terms applicable to the Firebase services used.
Data may also be disclosed where necessary:
- to authorities, courts or public administrations where there is a valid legal obligation;
- to advisers or providers strictly necessary to handle an obligation, incident or claim, subject to appropriate safeguards.
FunTaskTik currently:
- does not sell personal data;
- does not use advertising;
- does not use user or minor data for personalised advertising;
- does not currently include Google Sign-In/OAuth as an authentication method;
- does not currently include RevenueCat or Google Play Billing as monetisation systems.
Future incorporation of new SDKs, providers, advertising, analytics, payment systems or additional authentication will require prior review of this Policy where it affects data processing.
10. International transfers and location of processing
When Firebase/Google is used, certain data may be processed outside Spain and the European Economic Area.
In particular, Firebase states that Firebase Authentication processes data exclusively in data centres located in the United States. Other Firebase services may use global infrastructure and, where the product allows it, resources configured in a specific location.
Accordingly, FunTaskTik does not claim that all data processed through Firebase remain exclusively within the European Economic Area.
Where a transfer of personal data is subject to the GDPR and is made to a third country, the legal mechanisms provided for in the Google/Firebase processing terms and applicable law will apply. These mechanisms may include, as applicable, an adequacy decision or recognised frameworks such as the EU-U.S. Data Privacy Framework for certified entities, and/or the European Commission's Standard Contractual Clauses.
11. Data retention
FunTaskTik does not retain personal data indefinitely without a purpose.
The following periods or criteria apply:
11.1 Global account
Data necessary for the account are retained while the account remains active and for as long as necessary to provide the service.
When global account deletion is completed, personal data that should disappear will be deleted or anonymised, except for data that must be retained temporarily due to a legal obligation or to establish, exercise or defend legal claims.
11.2 Shared family data
Tasks, Lists, Items and other family-scoped data may be retained while the relevant Family exists and the data are necessary to provide the service to its Members.
A Member leaving or an account being deleted does not necessarily require deletion of shared data that must legitimately remain for other Members. Where necessary, personal references to the deleted user must be removed, detached or anonymised.
11.3 Pending adults
A pending adult who does not complete registration will be retained for a maximum of 30 days from creation. After that period, the pending membership and associated personal data must be deleted, unless a legal ground justifies a different temporary retention period.
11.4 Devices and tokens
Device data and Push tokens are retained while necessary to keep the device associated with and enabled for the user.
On logout, the Device must be disabled in accordance with FunTaskTik's technical lifecycle. Invalid tokens may be disabled, and Devices associated with the user must be deleted when global account deletion is completed.
11.5 Support and security
Communications and technical data used for support or security will be retained only for as long as necessary to resolve the incident, protect the service and address related potential liabilities.
11.6 Legal evidence
Strictly necessary evidence of acceptance of Terms or acknowledgement of legal versions may be retained for as long as necessary to demonstrate compliance and, thereafter, for applicable statutory limitation periods relating to potential claims.
During any retention period after the active relationship, data must be restricted to the purpose justifying retention and may not be reused for advertising or marketing.
11.7 Data managed by providers
Technology providers may retain backups, technical logs or recovery periods in accordance with the terms of their services and legal obligations. FunTaskTik will use available tools to request or perform deletion where appropriate.
12. Security
FunTaskTik adopts reasonable technical and organisational measures intended to protect personal data against loss, alteration, unauthorised access or disclosure.
Measures and system principles include:
- authentication through Firebase Authentication;
- Firestore security rules and authorisation controls;
- separation between global account, Family and membership through Members;
- data minimisation;
- reduction of sensitive information in logs;
- avoiding unnecessary logging of emails, full FCM tokens or full payloads in backend logs;
- a Device lifecycle allowing a device to be disabled on logout;
- separation between remote Push and local reminders;
- use of encrypted connections and security measures provided by Firebase/Google infrastructure for the services used.
Firebase states that its services encrypt data in transit and that services used by FunTaskTik such as Authentication, Cloud Firestore, Cloud Functions and Cloud Messaging apply encryption at rest.
No system connected to the Internet can guarantee absolute security.
13. Advertising, analytics and automated decision-making
In the current version:
- FunTaskTik does not contain advertising;
- FunTaskTik does not sell personal data;
- FunTaskTik does not use personal data for personalised advertising;
- the current architecture does not include Firebase Analytics as a user-analytics system;
- FunTaskTik does not make decisions based solely on automated processing that produce legal effects concerning a user or similarly significantly affect them.
If this changes in the future, this Policy must be reviewed and, where applicable, consent obtained or legally required controls provided.
14. Rights of individuals
Where applicable, individuals may exercise rights recognised under data-protection law, including:
- access;
- rectification;
- erasure;
- objection;
- restriction of processing;
- data portability;
- withdrawal of consent where processing is based on consent;
- the right not to be subject to certain decisions based solely on automated processing where applicable.
Requests may be sent to:
funtasktik.contact@gmail.com
FunTaskTik may request reasonable verification of identity to prevent one person from accessing, modifying or deleting another person's data.
For requests relating to a minor, it may also be necessary to verify the responsibility, representation or lawful authority of the applicant.
The data subject may lodge a complaint with the Spanish Data Protection Agency (AEPD) or with the competent supervisory authority.
15. Account and data deletion
Removing or leaving a Member from a Family and deleting a global account are different operations.
15.1 Removing a Member
Removing a family membership may delete:
Families/{familyId}/Members/{memberId};- the registered user's active-family reference where applicable.
The global account may continue to exist.
15.2 Deleting the global account
Global deletion must reconcile related data before the user's identity is removed.
When global deletion is completed, FunTaskTik must delete or detach the relevant identity and associated personal data. In particular, the procedure is designed so that:
- the user's Firebase Authentication identity ceases to exist;
Users/{uid}ceases to exist;- the user's Devices cease to exist;
- no registered Members retain the deleted UID.
Shared data belonging to a surviving Family may remain where necessary for other Members, but personal references to the deleted user must be removed, detached or anonymised where appropriate.
If a surviving Task was assigned to the deleted Member, responsibility must be reconciled in accordance with Family rules. Historical creation references that no longer need to identify the user may be anonymised.
If the person is the last valid administrator of a Family, it may be necessary to resolve the continuity or deletion of that Family before completing global account deletion.
15.3 Request channels
Requests for deletion or exercise of the right to erasure may be sent to:
funtasktik.contact@gmail.com
FunTaskTik's canonical web route for the account-deletion resource is:
https://funtasktik.com/eliminar-cuenta
The application may also provide direct access from Settings / Account / Delete account.
FunTaskTik may request reasonable verification of identity before carrying out deletion to prevent fraudulent or unauthorised requests.
16. Versioning and evidence of information
This is Privacy Policy v1.1.
The application must centrally use:
CURRENT_PRIVACY_VERSION = "1.1"
PRIVACY_LEGAL_DATE = "2026-08-26"
During registration, the Privacy Policy must be presented separately from the Terms and Conditions.
The intended action is:
☐ I have read the Privacy Policy.
This action evidences that privacy information has been provided and does not amount to general consent for all processing.
Where processing legally requires specific consent, it must be requested separately.
An update to this Policy will not automatically require a new action from the user. A new acknowledgement, acceptance or consent will be requested only where the nature of the change and applicable law require it.
17. Changes to this Policy
FunTaskTik may update this Policy where there are changes to:
- features;
- categories of data;
- purposes or legal bases;
- providers;
- international transfers;
- security architecture;
- applicable law.
Each relevant version must be identified by a version number and update date.
The canonical public version must be available on FunTaskTik's official domain and be consistent with the version presented in the application and with declarations made in Google Play.
18. Contact
For any privacy enquiry or exercise of rights:
Controller: Sebastian Puigserver Janer Trade name: FunTaskTik Email: funtasktik.contact@gmail.com Website: https://funtasktik.com Country: Spain
---
FunTaskTik — Privacy Policy Version 1.1 — 26/08/2026

