Missioni di Famiglia
Version 3.1 — in force from 29 September 2026 · Versione italiana
Are you a kid? There is a version written for you →
This is a courtesy translation of the Italian text. The Italian version, privacy.html, is the one you accept when you sign up and the one that prevails in case of any difference. Nothing in this translation reduces the rights the GDPR gives you.
Missioni di Famiglia is an app that helps parents organise their children's small daily commitments, by assigning points and rewards. It is the parent who signs up. The children's data are entered by the parent, and stay visible only inside their family. We do not sell data, we do not run advertising, we do not profile anyone — least of all children.
Controller: M. Franchini
Registered address: Via Castellina 418/A, 41021 Fanano (MO), Italy
VAT number: IT01974770362
Email for privacy matters: assistenza@missionidifamiglia.com
Certified email (PEC): info@pec.cimone.net
Data protection officer (DPO): not appointed. On the basis of art. 37 GDPR the appointment does not appear to be mandatory for this activity: the processing is not carried out by a public authority, it does not consist of regular and systematic monitoring on a large scale, and it does not concern special categories of data on a large scale. For any privacy question you can in any case write to the email address above: we answer ourselves, directly.
Your data (parent): name or username chosen at registration; email address; password (never stored in clear text, only as a non-reversible cryptographic hash); the date the account was created and the login dates; the IP address of login attempts, kept for a short time only in order to block automated intrusion attempts.
What is recorded when we send you an email: in an internal log we keep the address we sent it to, the type of message (address confirmation, password recovery, service notices), the date and the outcome of the sending. We do not keep the text of the messages and we do not record whether you open them or click inside them: that tracking is switched off.
Proof of what you accepted. When you accept the Terms of use and this policy, we keep the exact text you saw on screen, its version, the language you signed it in, the date, the time and the network address you did it from. This is not a choice of ours: the law requires us to be able to demonstrate that you consented and to what (art. 7(1) GDPR). It also serves you: if one day we disagree about a clause, we look at the document you actually signed, not at today's one.
Your subscription data, if you activate one: the outcome, date and amount of each payment; the last four digits and the scheme of the card; the subscription and customer identifiers held by the payment provider; the data needed to issue tax documents. We never see and never store your full card number: you enter it in fields hosted by Stripe (see point 4).
The country where you live and the country of your card. At sign-up we ask you to declare the country where you reside, and at the time of payment we receive from Stripe the country code of the bank that issued the card. We keep both: we need them to meet our tax obligations, to know which law protects you as a consumer and to check that the service is offered where we may offer it (arts. 6(1)(b) and 6(1)(c) GDPR). The country of the card comes to us from the bank, not from you, and we do not use it for anything else.
Your children's data, which you enter yourself: the child's name or nickname (we suggest a nickname); age or age range, optional; the username and the password — at least four characters — that you choose to let them in; the missions assigned and the ones completed, with date and time; the points collected, the corresponding symbolic value, and any reminders and notes you write.
What the app records while your child uses it. The rewards game produces further data, all of it attached to your child's profile and visible only inside your account: the face they choose on first entry — it is a character drawn by us, taken from a closed catalogue, and of that choice we keep the code of the drawing, not an image of your child; the medals and trophies obtained, with the date; the recovery tokens received and used, with the date; the Den items they have obtained and the one they are wearing; the contents of the Vault, that is the points set aside, with the reason, the week they refer to and the date they were handed over, if any; the experiences requested and the diploma. The level and the rank are not stored at all: they are recalculated each time from the points.
These are game data, not assessments. They do not measure your child's conduct, we produce no judgements about them, we do not compare them with other children and we show none of this to anyone outside your family.
What we never process: no photographs and no videos of children — the app does not allow any to be uploaded: profiles use avatars, accessories, ranks and medals drawn by us; no data about health, school, religion or origin, nor any other «special category» (art. 9 GDPR); no geolocation data; no bank or credit card data of children — no money moves inside the app; no direct contact with children from us; no profiling, and no automated decision-making producing effects on people (art. 22 GDPR).
The marker of a free trial already taken. If you start from the free trial, at the moment the trial comes into being we keep two markers whose only purpose is to prevent the same family from starting a second one: a non-reversible cryptographic fingerprint of your email address — the address itself is never written down anywhere — and a random number, with nothing of yours inside it, in the mdf_pv cookie on the device the trial started from. We do not use your network address for this check. The details, including how long they are kept, are in point 9.
| Purpose | Data used | Legal basis |
|---|---|---|
| Creating your account, letting you in, letting you use the app | Parent's data | Performance of the contract (art. 6(1)(b) GDPR) |
| Running the missions board, the points and your children's summary | Children's data | Performance of the contract with you (art. 6(1)(b) GDPR) |
| Running the rewards: face, levels and ranks, medals, trophies, recovery tokens, Den, Vault, diploma | Children's data | Performance of the contract with you (art. 6(1)(b) GDPR) |
| Collecting the subscription and preventing payment fraud | Payment data | Performance of the contract (art. 6(1)(b)) and legal obligation of the payment provider |
| Keeping the app secure: blocking suspicious logins, minimal technical logs | Username, IP, time | Security obligation of the controller (arts. 5(1)(f) and 32 GDPR) |
| Answering you if you write to support | Email and content of the message | Performance of the contract / replying to your request |
| Demonstrating that you accepted the Terms and this policy, and which version | Signed text, version, language, date, time, IP | Legal obligation of the controller (arts. 5(2) and 7(1) GDPR) |
| Knowing how many people visit the public pages and how many reach the end of the sign-up | Visit counts, without your network address (point 9) | Legitimate interest (art. 6(1)(f) GDPR): knowing whether the service works and whether those looking for it find it |
| Issuing and keeping tax documents | Billing data | Legal obligation (art. 6(1)(c) GDPR) |
| Letting you resume the service if one day you come back | Account, children's profiles and their history | Performance of the contract (art. 6(1)(b) GDPR): the 24-month retention is agreed in the Terms of use, point 6 |
| Preventing the same family from taking the free trial more than once | Non-reversible fingerprint of the email address and random number in the mdf_pv cookie (point 9) | Legitimate interest (art. 6.1.f GDPR): giving once what is offered once |
On your children's data, we explain in full how things stand.
Your children's profiles are the service you asked us for: without them the app has nothing to show. That is why we process them in order to perform the contract with you, and we do not ask for separate consent. We do not ask for it for a precise reason, and we prefer to tell you: a consent without which the service would not work would not be freely given, and therefore would not be valid (art. 7(4) GDPR). Asking you would be a fake question.
The processing is also based on the declaration you make when you sign up: that you are at least 18 years old and that you hold parental responsibility, guardianship or foster care over the children you will add. That declaration covers every profile you create, including later ones.
We do not ask your children for consent and we do not offer the service to them: their profiles exist only inside your account, they are not independent accounts, and we have no direct relationship with them.
Which data to put in a child's profile is your decision, and you can remove them whenever you like: the functions to delete them are inside the app and you use them yourself, without asking us anything. They are described in point 7.
We never use legitimate interest for children's data.
You, the parent, see everything about your family. Each child, from their own profile, sees their own missions and their own points. No other family sees your data: there are no public leaderboards, no boards shared between families, and no social features.
Outside the app — our providers:
| Provider | What it does | Where |
|---|---|---|
| Hostinger International Ltd. | Server hosting the app and the database | European Union |
| Stripe Payments Europe, Ltd. | Collection and management of subscription payments | Ireland (European Union) |
| Brevo SAS | Sending service emails (address confirmation, password recovery, notices) | France, Belgium and Germany (European Union) — see point 5 |
About Stripe, plainly. Your card details are entered in fields hosted directly by Stripe inside our page: they do not pass through our servers, we do not see them and we do not store them. We receive and store only the outcome of the payment, the date, the amount, the last four digits and the scheme of the card, and the subscription identifier. Stripe acts partly as a processor on our behalf (art. 28 GDPR) and partly as an independent controller for the obligations the law imposes directly on it — fraud prevention and anti-money-laundering rules. For that processing Stripe answers on its own account, and its privacy policy is published on stripe.com.
About Brevo, plainly. Service emails are sent through Brevo SAS (106 bd Haussmann, 75008 Paris), which acts as a processor on our behalf (art. 28 GDPR) and receives your email address and the content of the message. Open and click tracking is switched off: we do not know whether you open our emails or what you click on, and we do not want to know. We do not use Brevo to send you advertising: we do not send any.
We do not sell, transfer or exchange data with anyone for marketing purposes.
The app's data are kept on servers located in the European Union.
For payment data only, Stripe may transfer data to the United States. Stripe adheres to the EU-US Data Privacy Framework, the framework recognised by the European Commission as providing adequate safeguards under art. 45 GDPR.
For service emails, Brevo keeps the data on servers in the European Union (France, Belgium, Germany), but our contract with it provides for transfers to the United States, Canada and India to some of its own suppliers (network infrastructure, support and technical monitoring tools). Those transfers are covered by the safeguards of art. 46 GDPR — standard contractual clauses approved by the European Commission and, where applicable, adherence to the Data Privacy Framework or an adequacy decision (that is the case for Canada). We tell you because it is true, not because your data travel the world: what passes through there is your email address and the text of service messages, nothing about your children.
Apart from the two cases above, no other transfer to third countries is envisaged; should one become necessary in future, we will adopt the safeguards provided for in arts. 44 et seq. GDPR and we will update this policy before proceeding.
| Data | Retention |
|---|---|
| Parent's account and children's profiles | For the whole duration of the subscription and for 24 months after it ends, so that you can reactivate it; then automatic deletion. If you ask for deletion yourself: within 30 days |
| Completed missions, points, reminders | As above: they remain for 24 months after the subscription ends, unless you delete them earlier |
| Rewards: chosen face, medals, trophies, tokens, Den items, Vault contents, experiences, diploma | As long as the child's profile they belong to exists: they disappear with it, and do not survive its deletion |
| Login attempt logs (with IP) | 30 days at most, then automatic deletion |
| System backups | 90 days at most, automatic rotation, encrypted backups |
| Billing and payment data (outcome, date, amount, identifiers) | 10 years, as required by law for accounting records (art. 2220 of the Italian Civil Code and tax rules) |
| Support correspondence | 24 months from the closing of the request |
| Log of service emails sent (address, type, date, outcome) | 24 months, then automatic deletion every night |
| Proof of the Terms accepted (signed text, version, language, date, time, IP) | 10 years from signing — the period within which a contract may be disputed (art. 2946 of the Italian Civil Code); then automatic deletion |
| Counts of visits to the public pages (point 9) | Rows without any network address; the key that makes them distinguishable changes every night |
| Markers of a free trial already taken (point 9) | 24 months from the trial, then automatic deletion every night; the mdf_pv cookie on the device lasts one year |
We keep nothing for ever, and deletion does not depend on our goodwill: it is an automated job that runs every night on our server and removes by itself whatever has passed the periods in this table. If you do not come back within 24 months of the end of the subscription, deletion happens by itself, without you having to ask for anything.
One thing to be aware of, and it is right that you should know: the 10 years for accounting data apply even if you delete your account. It is a legal obligation we cannot depart from, and it concerns only the accounting data of the payment — not the missions, not the points, not your children's profiles, which are deleted.
When you close your account you can ask for an export of the data before deletion: we provide it in a readable format.
At any time you can: access the data we process about you and your children; correct them if they are wrong or incomplete; delete them; restrict their processing; take them away in a machine-readable format; object to the processing in the cases provided for.
Deleting, without asking anyone. The functions are there and you use them yourself: in the settings, under Users, Suspend puts a profile on hold and Delete permanently erases it with all its history, for good; «Delete family» erases all your family's data in one go. It is immediate and final: afterwards we can no longer recover anything. If you want a copy of the data, ask for it before deleting: we send it to you within 30 days.
The only thing that remains, and only if you have had a subscription, is the accounting data of the payment, for the 10 years required by law (point 6).
How to do everything else: write to assistenza@missionidifamiglia.com. We answer within 30 days, free of charge.
Complaint: you may lodge a complaint with the Italian data protection authority — Garante per la protezione dei dati personali, Piazza Venezia 11, 00187 Rome — www.garanteprivacy.it — or with the supervisory authority of the EU country where you live or work, or bring proceedings before the courts.
The parent's data needed to create the account are essential: without them the app cannot work. The same goes for at least one child profile: it is the service itself, without it there is nothing to show. What data to put in that profile, however, remains your choice: you can use a nickname instead of the real name and you may leave out the age. The app works just the same, it will simply be a little less tailored.
And you can change your mind while filling it in. At the «Your children» step of the sign-up, every name you add appears in a list with a ✕ next to it: pressing it removes the name. Until you confirm the sign-up we have saved nothing of that name, so it is not a deletion — it is a change of mind.
Missioni di Famiglia uses only technical cookies, essential to make the service work. We do not use profiling or advertising cookies, tracking pixels, third-party analytics or social plugins. Technical cookies alone do not require consent: so we do not show you a banner, we simply tell you what is there.
On the public pages there is not even a technical cookie: anyone who merely looks at the presentation of the service receives nothing on their device. The cookies listed below appear once you start using the app.
The typefaces on these pages are served by us, from our own server: they are not loaded from Google or any other provider, so your network address does not reach anyone merely because you open one of our pages.
| Cookie | What it is for | Who sets it |
|---|---|---|
| Session cookie | Keeping you logged in while you use the app. It lasts seven days, then expires by itself | Us |
| mdfv | Remembering whether you are looking from a phone or a computer, so we can show you the right version of the page. It identifies no one | Us |
| __stripe_mid, __stripe_sid | Security of the payment operation and fraud prevention | Stripe, only on the payment page |
| mdf_pv | Remembering that a free trial has already started from this device, so that the same family does not start a second one. It contains only a random number, nothing of yours. It is written only when a trial actually starts, and it lasts one year | Us |
One free trial per family: what we keep, and for how long. The mdf_pv cookie is written only at the moment a free trial actually starts: anyone who is just looking at the pages, anyone who buys a package straight away and anyone who stops halfway through signing up does not receive it. Together with the cookie we keep, in our own archive, a non-reversible cryptographic fingerprint of your email address: the address itself is not kept, the fingerprint cannot be turned back into it and it does not tell us who you are — it only tells us, if someone asks for a second trial, that a trial has already taken place. We do not look at your network address for this check, because two different families behind the same mobile operator share a single one. We keep the fingerprint for 24 months, after which it is deleted by itself in the nightly clean-up; the cookie lasts one year and you can delete it whenever you like from your browser settings. The fingerprint remains even if you delete your family — otherwise the one-trial rule would mean nothing — but it stays detached from any account and on its own it allows no data to be reconstructed.
The check is automatic, but it decides nothing about you. If it turns out that a trial has already taken place, the only consequence is that the free trial does not start again: you can still sign up, at the same price as everyone else, and nothing else about the service changes. It is therefore not one of those automated decisions that produce legal or similarly significant effects on a person (art. 22 GDPR). And if you think it is a mistake, write to us at assistenza@missionidifamiglia.com: a person will look at it.
How many people visit our pages: we do our own statistics, in house. We count visits to the public pages and to the sign-up steps with a system of our own, on our own server: no external service, no cookies, no data leaving the house. Of each visit we keep the day, the hour, the page, the language, the site you came from, the type of device (phone, tablet, computer) and a sequence number whose only job is to avoid counting you twice if you reload the page. That number comes from a calculation that mixes your network address with a key that changes every night, at random: your network address is never written down anywhere, and from one day to the next that number does not follow you. We look only at totals: we do not recognise you and we do not use these counts to take decisions about you. Your consent is not required because we neither store nor read anything on your device (art. 122 of the Italian Privacy Code): that is why you do not see a banner.
The two Stripe cookies appear only if you reach the payment step: there is nothing from Stripe on the presentation pages, and anyone who merely looks receives none of them. They are not advertising cookies and they are not used to profile you. Their duration is set by Stripe, which states it in its own documentation.
We adopt technical and organisational measures appropriate to the risk: always encrypted connection (HTTPS); no password, yours or your children's, is stored in clear text: we keep only a non-reversible cryptographic hash; access control (each family sees only its own data); encrypted backups; minimisation of the data collected; protection against repeated login attempts. Card details do not pass through our systems.
Should a data breach occur that involves a risk to your rights, we notify the Garante within 72 hours and, if the risk is high, we tell you directly.
The service is aimed at adults: only an adult holding parental responsibility, guardianship or foster care can register, and the contract is with them. Child profiles are not independent accounts: they are sub-profiles created, suspended and deleted by the parent.
Of the children we have, and will never have, an image: the app does not allow photographs or videos to be uploaded, and profiles use avatars drawn by us. We do not address commercial communications to minors and we show no advertising of any kind. We do not profile minors and we take no automated decisions about them. We have no direct contact with them: we do not write, we do not send emails, we ask them for nothing.
The image you see next to your child's name is not a photograph of them: it is a drawn character, and they choose it. On first entry we put a grid of faces drawn by us in front of them and ask which one they want to be. Of that choice a code remains — the name of the character — and nothing else.
If you realise that a minor has registered on their own as a parent, write to us: we close the account and delete the data.
If we change anything substantial we tell you beforehand, with a notice inside the app and, if you have left your email, with a message. We keep the previous versions.
Before you set off on your missions, there is something you need to know. It is about you. Read it: it takes thirty seconds.
Inside this app it says:
And that is all. Really, there is nothing else.
Only your family. That is: you and your parents.
No other child sees your points. No other family knows you exist. There is no leaderboard where you end up against strangers.
There are people who keep the app running and fix things when they break: they look only when it is needed for the repair, and they have promised not to go snooping.
The points you earn are worth something — but the app never touches real money. The app only keeps count, like a notebook. The money is given to you by your parents, in your hand, outside the app. In here there are no credit cards, there are no payments, you cannot buy anything.
Even though you are small, your data are yours. You have real rights. You can ask your parents:
Your parents can do it whenever they want, and nobody can say no. If you agree with them, it gets done. No reason is needed.
If you do not like something, or you have not understood, or something you see in the app seems odd: talk about it with your mum or your dad. They are the ones who can write to us.
And if you prefer, they can write to us together with you at this address: assistenza@missionidifamiglia.com. We always reply.
We will never sell your things to anyone.
We will never show you advertising.
We will never use what you do to study you.
This app is for one thing only: giving you a hand to get organised, and letting you earn what you have deserved.
Good missions, agent. 🎖️