Last updated: 30 September 2026
This Privacy Policy explains which personal data is processed when you use the RoutiPlan app for iPhone and iPad, for which purposes, who receives it and which rights data subjects have. It is based on the Swiss Federal Act on Data Protection (FADP) and, where applicable, takes the EU General Data Protection Regulation (GDPR) into account. The German version is authoritative.
Controller
Xvision Solutions
Mario Mueller
Waldhaus 5
3432 Lützelflüh
Switzerland
office@xvision.solutions
Principles
- RoutiPlan is an app for organising family life. Data is only processed to the extent required for these features.
- RoutiPlan contains no advertising, does no tracking across other companies’ apps or websites and does not sell data.
- Shared content is only visible to members of the respective family. This separation is enforced on the server at database level.
- Family data is stored with Supabase in a project located in Zurich, Switzerland.
Data we process
Account and sign-in
An account is required to use RoutiPlan. The following is processed:
- email address and password when signing in with email. The password is stored by the authentication service only as a cryptographic hash; we have no access to the password in plain text.
- with “Sign in with Apple”, an identifier provided by Apple and the email address passed on by Apple, which may be a private relay address from Apple
- user ID, session and sign-in information, and the times of registration and sign-in
The authentication service sends emails to the address on file to confirm the email address and to reset the password.
Profile
- display name
- optional profile picture
Family and membership
- family name
- members of the family and their role (parent or child)
- invitation codes for a co-parent or a child. A code is valid for seven days.
Child profiles
Child profiles are created and managed by a parent. The following may be processed:
- name
- a symbol or an optional photo
- optional date of birth, used to sort the family route
- personal colour, greeting and display language
- the setting whether the child may see the shopping list
- points balance
A child does not need their own account. If a parent wishes, a child can get their own account through an invitation code; the information under “Account and sign-in” then applies.
Family content
- tasks with title, assigned person, due date and point value
- completion reports, approvals or rejections by parents and the resulting point transactions
- rewards, their visibility for specific children and redemptions
- events with title, time, participating family members and, where applicable, a source reference or link
- shopping list with items, quantities and who added an item
- recipes with ingredients, instructions and an optional image
Sharing an event with another family
A parent can share a single event with another family using a code that is valid for seven days. Once redeemed, the other family can read this one event, including its title and time. No other content of your family becomes accessible as a result.
Notifications
If you allow notifications, RoutiPlan processes a device token generated by Apple, the environment (development or production) and the link to the respective family member. Notifications are delivered through the Apple Push Notification service (APNs). The content of a notification is passed to Apple in the process, for example a note that an approval is waiting or the title of a task that is due soon.
You can turn off notifications at any time in the iOS or iPadOS settings.
Technical data
Technically necessary data is generated when the server is accessed, in particular IP address, time, requested function and error messages. The hosting provider logs this data to ensure operation and security.
Data on the device
The following is stored on the device:
- the sign-in session in the iOS keychain
- app settings such as language and appearance
- a cache for profile and recipe images
- optional demo data. It is marked as demo data, stays exclusively on the device and is never transferred to the cloud. It can be removed again in Settings.
Crash and error diagnostics
To detect and fix crashes and technical errors, RoutiPlan uses the Sentry service. When a crash or technical error occurs, the app sends a technical report, in particular the type and code of the error, the affected area of the app, technical steps before the error, device model, operating system, app version and build, and information on the stability of the app session (start, end, crash).
Reports contain no family content such as tasks, events, names, photos or recipes, no email address and no user ID. Screenshots, screen recordings and recording of interactions are disabled. The IP address is technically used for the transmission but is not stored as part of the reports. Reports are stored in Sentry’s EU region (Germany) and deleted when the retention period expires, at the latest after 90 days.
No analytics or advertising services
RoutiPlan uses no usage analytics services and no advertising identifiers. Should this change, this Privacy Policy will be updated beforehand.
Children’s data
RoutiPlan is intended for parents and legal guardians who organise their family life. Children use RoutiPlan within a family managed by their parents.
- Parents decide which information about their children is entered. Only information needed for family organisation should be entered; date of birth and photo are optional.
- A child only gets their own account through an invitation code created by a parent. By inviting the child, the parent confirms that they permit and supervise the child’s use.
- Children only see their own tasks, the events relevant to them, their points balance, the rewards visible to them and, if parents allow it, the shopping list.
- Parents can edit and delete child profiles at any time.
- Children’s data is not used for advertising, profiling or any purpose other than operating the app.
Purposes
We process data to:
- provide and secure the account and sign-in
- manage the family, its members and roles
- synchronise tasks, events, rewards, points, the shopping list and recipes between the family’s devices
- deliver notifications, if allowed
- ensure secure and stable operation, prevent misuse, and detect and fix crashes and errors
- answer support requests
- comply with legal obligations
Legal bases
Where the GDPR applies, we base processing on the following legal bases:
- performance of the contract of use to provide the app’s features (Art. 6(1)(b) GDPR)
- legitimate interests in secure, stable and abuse-free operation, including crash and error diagnostics (Art. 6(1)(f) GDPR)
- consent, for example for notifications or voluntary information such as photos (Art. 6(1)(a) GDPR). For children, consent is given by the parents where required by applicable law.
- compliance with legal obligations (Art. 6(1)(c) GDPR)
Under the FADP, processing takes place within the purposes stated above and in line with the principles of proportionality, purpose limitation and data security.
Recipients and processors
Personal data is only disclosed where this is necessary for operation, required by law or the data subject has consented. Service providers process data on our behalf and only for the agreed purposes.
- Supabase, Inc. (USA) provides the database, authentication, file storage, server functions and real-time synchronisation. The project is located in Zurich, Switzerland.
- Apple Inc. (USA) or Apple Distribution International Ltd. (Ireland) for distribution through the App Store, “Sign in with Apple” and the delivery of notifications. Apple’s privacy policy also applies to these services.
- Functional Software, Inc. (Sentry, USA) for crash and error diagnostics. Reports are stored in Sentry’s EU region (Germany).
- Other family members see their family’s shared content according to their role.
- Another family only sees a single event if a parent explicitly shares it with a code.
- Authorities only receive data where there is a legal obligation.
Transfers abroad
Family data is stored in Zurich, crash and error reports in Germany. Some of the service providers named above are based in the USA or use sub-processors abroad, for example for operation, support or the delivery of notifications. Data is only disclosed to, or accessed from, a country without an adequate level of data protection if appropriate safeguards are in place, in particular certification under the Data Privacy Framework or standard contractual clauses recognised by the Swiss Federal Data Protection and Information Commissioner (FDPIC) or the European Commission.
Retention and deletion
- Content is stored for as long as the account and the family exist or until it is deleted in the app.
- Invitation and event codes expire after seven days.
- You can delete your account at any time in the app under Settings. If there are other parents in the family, only your own membership is removed; shared content remains available to the remaining parents. If the last parent deletes their account, the family and all related content, including child profiles, are deleted.
- Your profile picture is deleted from file storage together with your account; children’s photos and recipe images together with the family.
- Device tokens for notifications are deleted when you sign out on the device concerned and together with the related family member.
- Crash and error reports are deleted after 90 days at the latest.
- Deleted data may remain in backups until the hosting provider’s regular backup cycles expire and is then overwritten.
- Data on the device is removed when the app is deleted.
- Statutory retention obligations remain reserved.
Data security
We take appropriate technical and organisational measures, in particular encrypted transmission (TLS), access rules at database level (row level security), private file storage with short-lived signed links and storing the sign-in session in the keychain. Absolute security cannot be guaranteed for electronic transmission and storage. Please protect your sign-in details, invitation codes and unlocked devices.
Your rights
Within the scope of applicable law, data subjects have the right to access, rectification, erasure, restriction of processing, objection and data portability. Consent can be withdrawn at any time with effect for the future; this does not affect the lawfulness of processing carried out before the withdrawal. Where processing is based on legitimate interests, data subjects can object to it at any time on grounds relating to their particular situation. Parents can exercise these rights on behalf of their minor children.
Please send requests to office@xvision.solutions. To avoid disclosing data to unauthorised persons, we may ask for proof of identity.
You also have the right to lodge a complaint with a supervisory authority. In Switzerland, this is the Federal Data Protection and Information Commissioner (FDPIC); in the EU, the supervisory authority in your place of residence.
Paid optional features
RoutiPlan is currently free of charge. Should optional extra features be offered for a fee in the future, purchases will be made through Apple In-App Purchase. Payment data is processed exclusively by Apple; we only receive the purchase confirmation needed to unlock the feature. This Privacy Policy will be updated accordingly beforehand.
Changes
This Privacy Policy may be updated if RoutiPlan, the services used or legal requirements change. The version published in the app and on routiplan.app applies. We will inform you of material changes in an appropriate manner.
Contact
If you have questions about data protection, contact us at office@xvision.solutions.
This website
This static website is provided through GitHub Pages by GitHub, Inc. (USA). When you visit it, GitHub processes technical data, including your IP address, in particular to keep the service secure. More information is available in the GitHub Privacy Statement. Where data is transferred to the USA, GitHub relies on certification under the Data Privacy Framework or on standard contractual clauses. The legal basis is our legitimate interest in providing the website securely (Art. 6(1)(f) GDPR).
The website sets no cookies, embeds no analytics, advertising or social media services and loads no fonts or scripts from third parties. Your choice of light or dark appearance is stored only in your browser’s local storage under routiplan-site-theme and is not transmitted. You can remove this setting by clearing the website data.
Contact by email
If you send us an email, we process your email address and the content of your message to answer your request. The email link opens your own email app; no form entries are collected on this website.
Back to homepage