PRIVACY POLICY
MomsLife
Effective date: 24 August 2026
This notice is provided under Articles 13 and 14 of the EU General Data Protection Regulation (GDPR) and the UK GDPR.
1. Data controller
The controller is DIS Mobile Solutions S.R.L. (“we”, “us”).
Registered office: str. Alecu Russo, 24, ap. 130, mun. Chisinau, Republic of Moldova, 2044
IDNO: 1025600062529
Privacy contact: admin@dismobilesolutions.com
We have not appointed a Data Protection Officer because we are not required to do so under Article 37 GDPR for our current processing. We are established in the Republic of Moldova. GDPR still applies where we offer the Service to people in the EEA or the UK (Art. 3(2)). We have not designated an EU representative under Art. 27 GDPR; if we appoint one, we will publish those details here.
2. What we collect (source: you, and your device)
Account data (if you sign in): email, display name, sign-in method (email, Google or Apple), Firebase user ID, email verification status. Google or Apple may also provide a profile photo URL.
On-device profile: optional photo stored only on the device; the name you choose; language; push/email notification flags; an app-lock flag (not biometric data).
Child context you choose to add: first name or nickname and approximate age. We do not create an account for a child. Do not enter a full legal name, ID document, medical file, or other sensitive identifiers.
Chat: messages you send and replies you receive. If the live assistant is on, message text and optional child context are sent to our API (Fly.io) and to a language-model provider (currently OpenAI, or another compatible provider we configure) to generate a reply.
Technical data: data needed to run the app; crash reports via Firebase Crashlytics (non-debug builds); a Firebase Cloud Messaging token if you enable push.
Analytics events via Firebase Analytics (for example screen opened, onboarding finished, sign-in method, whether a chat message was sent). We do not put message text or children’s names in analytics events.
Guest use: you can chat without an account. No account record is created. Child details and chat may still sit on the device. Live assistant still sends chat content to our API and the model provider.
We do not receive Face ID, Touch ID or fingerprint templates. We do not currently collect payment-card data. We do not sell personal data.
3. Purposes and legal bases (GDPR Art. 6 and Art. 9)
Provide the Service you ask for (account, chat, personalised replies): Art. 6(1)(b) — contract.
Optional child nickname/age: Art. 6(1)(a) — consent (you can skip adding a child and still chat).
Push and email notifications: Art. 6(1)(a) — consent. You can withdraw it in the app and in system settings.
Crash reporting (service integrity and security): Art. 6(1)(f) — legitimate interests. We have an interest in a stable, safe app; events do not include chat text; you may object (section 8).
Product analytics without message content: Art. 6(1)(f) — legitimate interests in understanding whether the product works. You may object. Where a national law requires consent for this analytics, we will treat it as consent-based.
Support emails you send us: Art. 6(1)(b) or 6(1)(f).
Legal obligations (for example a binding request from an authority): Art. 6(1)(c).
Special-category data (Art. 9). We do not ask for health data. If you type information about health, pregnancy, or mental wellbeing into the chat so that the assistant can reply, that may be special-category data. We process it only to generate that reply, on the basis of your explicit consent by sending the message (Art. 9(2)(a)). We do not use it for advertising, scoring, or insurance. Prefer not to send medical records or another person’s data.
We do not make solely automated decisions that produce legal or similarly significant effects about you (Art. 22). Assistant replies are informational support, not decisions that determine your rights.
4. Recipients
Processors / service providers acting on our instructions:
- Google Firebase (Authentication, Analytics, Crashlytics, Cloud Messaging) — Google LLC / Google Ireland Limited;
- API hosting — currently Fly.io;
- language-model provider — currently OpenAI, or another provider we configure.
Independent controllers when you choose their sign-in: Google (Google Sign-In) and Apple (Sign in with Apple), under their own policies.
5. Transfers outside the EEA/UK
Some providers are in, or may access data from, the United States. Where required we rely on:
- an adequacy decision (Art. 45), including the EU–US Data Privacy Framework if the provider is certified; and/or
- Standard Contractual Clauses (Art. 46 GDPR).
6. Retention
Account data: for the life of the account, then deleted or anonymised after a deletion request, unless we must keep a limited record (for example to handle a legal claim).
Chat: processed to generate a reply. We do not offer a cloud chat-history product. Hosting or security logs may be kept for a short period, generally no longer than 30 days, unless a longer period is needed to investigate an incident.
On-device data: until you delete it, sign out (local child data and local avatar are cleared) or uninstall the app.
Crash and analytics: according to Firebase defaults and our configuration.
7. Children
The Service is for adults 18+. We do not knowingly collect data directly from children (Art. 8). Limited child-related data is provided by a parent or guardian for personalisation only. It is not used for marketing, advertising profiles, or sale.
If you think we hold a child’s data in error, email admin@dismobilesolutions.com. We will delete it.
8. Your rights
You may request: access (Art. 15); rectification (Art. 16); erasure (Art. 17); restriction (Art. 18); portability (Art. 20); objection to processing based on legitimate interests, including analytics (Art. 21); withdrawal of consent at any time (Art. 7), without affecting processing before withdrawal.
Email admin@dismobilesolutions.com from the address on your account. We will respond within one month, or inform you if we need more time (up to two further months for complex requests).
In the app you can also edit your name, change password (email accounts), turn off notifications, disable app lock, sign out, or delete the app.
You may lodge a complaint with a supervisory authority in the EEA/UK of your habitual residence, place of work, or place of the alleged infringement (Art. 77 GDPR).
9. Security (Art. 32)
We use HTTPS to our API. Authentication is handled by Firebase. App lock biometrics stay on the device. No transmission or storage is 100% secure. Do not put unnecessary sensitive data in chat.
10. No sale, no advertising profiles
We do not sell personal data. We do not share it with third parties for their own advertising. Analytics and crash tools are used to operate and improve MomsLife.
11. Changes
We may update this Policy. The current text is the version served by GET /v1/legal/privacy and shown in the app. The effective date at the top changes when we make material updates.
12. Contact
DIS Mobile Solutions S.R.L.
str. Alecu Russo, 24, ap. 130, mun. Chisinau, Republic of Moldova, 2044
IDNO: 1025600062529
admin@dismobilesolutions.com