Privacy Policy
1. General provisions
This privacy policy applies to the Strong Kids mobile app (Android and iOS) and its administration platform (hereinafter — “the Service”). The Service is intended for children aged 4 to 16 and their parents. By using the Service, you agree to this policy.
2. Data we collect
2.1 Parent / guardian data
- Email address (for registration)
- Password (stored encrypted, bcrypt hash)
- Selected language
- Parent zone PIN code (stored encrypted, bcrypt hash)
2.2 Child data
- Child's name (entered by the parent)
- Age group (4–6, 7–10, 11–13, 14–16)
- Avatar (selected from pre-prepared options)
- School and class assignment (if the school participates in the project)
2.3 Exercise data
- Exercise results (points, repetitions, duration)
- Motion analysis data (anonymous error codes, e.g. “heel rising”) — NOT body contours or extreme points
- Session history (date, time, results)
- Automatic diagnosis results (if generated from exercise errors)
2.4 Camera data — IMPORTANT
- The camera is used ONLY to recognize body posture in real time during exercises
- Video recordings are NEVER stored and NEVER transmitted to any server
- Motion recognition happens only on the phone (on-device):
- iOS: Apple Vision framework
- Android: Google ML Kit Pose Detection
- Only anonymized results (numbers, error codes) are sent to the server — not images
3. How we use data
- To display exercise results (charts, tables)
- To generate diagnostic recommendations
- To create school reports (project participants only)
- To automatically assign corrective exercise blocks
- To deliver and improve the Service
- To detect and fix errors (via Sentry)
4. Data storage
- Data is stored on the Supabase platform, on servers within the European Union (EU region)
- We use Row Level Security (RLS) — each user sees only their own data
- App-side data is stored in encrypted internal phone storage
- Data is retained while the user has an active account, or until a deletion request
5. Data transfer to third parties
Strong Kids does not sell and does not share your personal data with third parties, except in the following cases:
| Service | Purpose | Data |
|---|---|---|
| Supabase | DB and authentication | Email, encrypted password, child data |
| Sentry | Error monitoring | Technical events (NO personal data) |
| RevenueCat | Subscription management (if B2C) | User ID, purchase information |
| Apple App Store / Google Play | App distribution | According to Apple / Google privacy policies |
6. Children's privacy (COPPA / GDPR-K)
- The Service is intended for children, so we comply with COPPA (US) and GDPR Kids (EU) requirements
- A child's account is created only by a parent/guardian through their own account
- A child's direct identifiers (name) are visible only to parents and to school administrators/teachers if participating in the project
- In class and school leaderboards, child data is shown anonymously or aggregated
- We do not use children's data for advertising
- We do not collect children's direct contact details (email, phone)
7. Your rights (GDPR)
You have the right to:
- Obtain a copy of your data
- Correct incorrect data
- Delete your account and all data
- Restrict data processing
- Transfer data to another service provider
To exercise these rights, contact: info@strongkids.lt
8. Security
- All data transmissions are encrypted with HTTPS / TLS
- Passwords and PIN codes are stored as bcrypt hashes (never plaintext)
- Real-time monitoring with Row Level Security — every request is checked server-side
- Regular security audits
9. Cookies
The mobile app does not use cookies. The administration platform uses only essential cookies for authentication.
10. Changes to this privacy policy
We will notify you of changes through the app or by email. Continued use of the Service after changes constitutes acceptance of the new policy.
11. Contacts
Questions or complaints regarding privacy:
- Email: info@strongkids.lt
- Address: Chemijos g. 27C-62, LT-51331 Kaunas, Lithuania
- Website: https://strongkids.lt/
Supervisory authority in Lithuania: State Data Protection Inspectorate (VDAI), https://vdai.lrv.lt/
