PKU Family is not a medical application, not a medical device, and does not provide
medical services. It is a tool for voluntary, self-managed home tracking of food intake
and phenylalanine (Phe) consumption, used by the person following a low-phenylalanine diet
and/or their legal guardian. The app does not diagnose conditions, does not replace
consultation with a physician, dietitian, or other healthcare professional, and must not be
used as the sole basis for treatment, diet, or dosage decisions. All Phe-limit data, dietary
information, and recommendations — including responses from the in-app AI assistant «Phoebe»
— are provided for informational purposes only; any medical decisions should be made by the
user together with their treating physician.
This Privacy Policy ("Policy") describes what data the PKU Family mobile application
(package identifier com.family.pku, the "App") collects and processes, for what
purpose, on what legal basis, with whom it is shared, and how you can manage it.
By using the App, you confirm that you have read this Policy. If you create a child profile
or provide a child with access to the App, you confirm that you are the child's parent or
legal guardian and are acting on their behalf in accordance with the "Children and Minor
Users" section below.
For any questions regarding the processing of personal data, or
requests to access, correct, or delete your data, please contact us at the e-mail above.
We respond within 30 days.
2. What Data We Collect
2.1. Adult user account data (parent / patient over 18)
E-mail address and password (the password is stored and verified by Firebase
Authentication; we never see or store it in plain text);
Name;
Role within the app ("adult patient" or "parent");
Date of birth and weight (provided voluntarily, used only to calculate the personal
phenylalanine limit);
The configured daily phenylalanine limit (mg);
Technical usage metadata — registration date, consecutive-day usage streak, last active
date.
2.2. Child profile data (created and managed by the parent)
A child profile can only be created by an adult user (parent/guardian) inside their own
account. The child accesses their profile using an access code that the parent provides —
a separate registration (e-mail/password) for the child is neither required nor supported.
The child's name or initials, date of birth or age;
The daily phenylalanine limit;
The list of allowed foods and meals (the "fridge") configured by the parent;
The access code for the profile (randomly generated, known only to the parent and
child);
The device identifier (anonymous Firebase UID) used to sign in with the code — used
solely so that only the device the parent shared the code with can read and write that
child's data.
2.3. Food diary data
Records of foods and meals eaten, and meal times;
Calculated phenylalanine, protein, fat, carbohydrate, and calorie values for each
entry;
Photos of meals that the user attaches for recognition — stored locally on the
user's device and never uploaded to our databases; when used with the AI assistant, a
photo is temporarily sent to the recognition model (see 2.4) solely to analyze its
contents.
2.4. The "Phoebe" AI assistant
The App includes a conversational assistant, "Phoebe," implemented via Firebase AI Logic on
top of the Google Gemini (Vertex AI) model. When you interact with Phoebe, we
process:
The text of your messages and conversation history (stored in our database to continue
the conversation and let the assistant "remember" your preferences);
Photos and documents you voluntarily attach to a message (e.g., a photo of a meal or a
product label) — sent to the model for content recognition;
Voice input — converted to text using the device operating system's speech recognition
(Android Speech Services / Apple Speech), locally or via the OS's own service; audio
is never sent to or stored on our servers.
Phoebe's replies are generated automatically by an AI model and may contain inaccuracies —
it is a supporting tool, not a medical one (see the disclaimer at the top of this
document).
2.5. Technical and diagnostic data
Firebase Cloud Messaging push token — used to deliver notifications (e.g., that a parent
or child added an entry to the shared diary);
Device/app authenticity attestation data (Google Play Integrity API / Apple App Attest)
— used to distinguish requests from the genuine app from automated or spoofed requests, in
particular when guarding against brute-forcing a child's access code;
Local app settings (enabled reminders, meal times, onboarding state) — stored locally on
the device (SharedPreferences) and not transmitted to us, except where duplicated in the
user profile for cross-device sync.
2.6. Camera, microphone, and photo library access
Permission
What it's used for
Camera
Scanning product barcodes; photographing meals for recognition by
Phoebe
Photo library
Attaching an existing photo of a meal or document to a message
sent to Phoebe
Microphone
Voice input for chat messages to Phoebe (converted to text by the
OS)
None of these permissions are used for covert recording, location tracking, or background
data collection — access is requested immediately before a specific user action and can be
revoked at any time in OS settings.
3. How We Use Data
Creating and maintaining your account, signing in to the App;
Keeping a food diary and calculating phenylalanine intake against the configured
limit;
Syncing data between a parent's account and their children's profiles;
Powering the Phoebe AI assistant — answering questions about food, suggesting recipes,
recognizing food from photos;
Push and local notifications about meals and diary activity;
Protecting the App from automated or fraudulent access (App Check, Play Integrity, rate
limiting on child access-code attempts);
Fixing bugs and keeping the App running reliably.
We do not use your data for targeted advertising, do not show third-party ads in the
App, and do not profile users for marketing purposes.
4. Legal Basis for Processing
Depending on your jurisdiction, data is processed on the basis of:
consent given by the user (or their legal guardian, for a child) at registration
and when creating a profile;
performance of a contract — providing the functionality the user requested by
installing and using the App;
legitimate interest of the developer — security, abuse prevention (e.g., guarding
against brute-forcing a child's access code), and technical diagnostics.
You may withdraw consent at any time by deleting your account (see Section 7); this does not
affect the lawfulness of processing carried out before withdrawal.
5. Who We Share Data With
We do not sell personal data and do not share it with third parties for advertising or
marketing purposes. Data is processed by the following infrastructure providers
(sub-processors), acting as data processors on our behalf:
Storing account credentials, diary and profile databases, sending push
notifications, protecting against automated requests
Google Cloud Vertex AI (Gemini model)
Processing messages and attachments in
the Phoebe chat to generate a response
Google Play Integrity API / Apple App Attest
Verifying the authenticity of
the installed app and device
All listed providers process data under their own privacy policies and the data processing
agreements (DPAs) we have entered into with them. Data may also be disclosed where required
by law, court order, or a lawful request from a government authority.
6. Children and Minor Users
PKU Family is built for families in which a child follows a phenylketonuria diet, so some
data in the App inevitably relates to minors. Our approach:
A child profile can be created only by an adult user (parent/legal guardian)
inside their own account — self-registration by a child is not technically possible;
The child accesses their profile using a code the parent shares with them personally;
sign-in is anonymous (no e-mail, password, or other direct identity identifiers) —
technically this is an anonymous Firebase session tied only to the device and the code;
The parent can view and change, at any time, all data available to the child (allowed
foods, meals, Phe limit) and can fully delete the child's profile;
We do not show ads, do not collect location data, and do not use child-profile data for
marketing, profiling, or disclosure to third parties for advertising purposes;
If you believe a child provided us with data without appropriate parental consent, email
support@mschess.app and we will delete the
relevant profile and data.
7. Data Retention and Deletion
Account and diary data are retained for as long as the account is active;
You can delete a child's profile at any time from the App's settings — this removes its
data from our database;
To delete your own account and all associated data, email
support@mschess.app from the address used to
register — we will delete the data within 30 days, except where longer retention is
required by law;
Local data (cache, chat photos, settings) is removed automatically when the App is
uninstalled from the device.
8. Your Rights
Depending on your jurisdiction — including under the GDPR for users in the EU/EEA, the
CCPA/CPRA for California residents, and Russian Federal Law No. 152-FZ "On Personal Data"
for users in Russia — you have the right to:
request a copy of the personal data we process about you;
request correction of inaccurate data;
request deletion of your data ("right to be forgotten");
withdraw previously given consent;
restrict or object to specific processing;
receive your data in a machine-readable format (right to data portability);
lodge a complaint with your country's data protection supervisory authority.
All data is transmitted over an encrypted connection (HTTPS/TLS);
Access to data in the database is restricted by Firestore security rules: a user can
only read and modify their own data and the data of children linked to their account; a
child's device can only access the profile it is bound to via the access code;
Account passwords are stored and handled exclusively by Firebase Authentication and are
never transmitted to us in plain text;
The App uses App Check / Play Integrity to reject requests that do not originate from a
genuine copy of the App.
Despite these measures, no method of transmission over the internet is 100% secure — we
cannot guarantee absolute security, but we take reasonable technical and organizational
measures to protect your data.
10. International Data Transfers
The Google Firebase and Google Cloud infrastructure we use may process and store data on
servers located outside your country of residence. Google provides appropriate transfer
safeguards (including, where applicable, the EU Standard Contractual Clauses) under its own
policies and certifications.
11. Cookies and Third-Party Analytics
The App does not use advertising SDKs, third-party trackers, or analytics services
(such as Google Analytics, the Facebook SDK, or similar). The only external services involved
in the App's operation are listed in Section 5 and are used exclusively to make the App
function.
12. Changes to This Policy
We may update this Policy as the App evolves or as applicable law changes. The effective
date of the current version is shown at the top of this document. For material changes
(e.g., affecting how children's data is processed), we will notify users within the App.
13. Contact
For any questions about this Policy or about how your data is
processed, contact:
support@mschess.app