Mesegép
Privacy Policy
Controller: Szabó András, 1165 Budapest, Zsélyi Aladár utca 27/2., Hungary. Privacy contact: privacy@mesegep.hu.
Terms Account deletion Community Guidelines Copyright Safety
1. The controller and its contact details
| Controller | András Szabó, natural person (hereinafter: the “Controller” or “Mesegép”) |
|---|---|
| Address / postal contact | 1165 Budapest, Zsélyi Aladár utca 27/2., Hungary |
| App store operator name | András Szabó |
| Privacy contact | privacy@mesegep.hu |
The Controller is not obliged to designate a separate data protection officer (DPO) under Article 37 of the General Data Protection Regulation (hereinafter: GDPR – Regulation (EU) 2016/679 of the European Parliament and of the Council) and has not designated one. Privacy-related matters may be addressed to the Controller at the email address above.
2. Subject, scope and governing language of this notice
This notice applies to the processing of personal data carried out within the screen-free family storytelling and audio management service provided on the Android, iOS and web interfaces of Mesegép (hereinafter: the Service), uniformly across all platforms.
The Hungarian-language version of this notice is authoritative. The English and Croatian versions are translations provided solely to aid understanding and are for information only; in the event of any discrepancy, the Hungarian text applies.
3. Definitions
In this notice, personal data, processing, processor, recipient, data subject, consent and the other relevant terms have the meanings defined in Article 4 of the GDPR. Household means the family access unit created within the Service, having a shared content library and membership.
4. Who the Service is for
The Service is intended for adult guardians, parents and family account managers. It is not a service provided to children; a child is not an independent account manager of the application (see also section 12).
The adult user is responsible for holding all the necessary rights and appropriate consents to upload, share or publicly publish a child's voice, a child's name, family stories, photographs, music, audio or other personal data, including – where necessary – the consent of other guardians concerned. To that extent, the adult user may qualify as an independent controller in respect of the content they upload concerning third parties (including children), while the Controller processes such content in accordance with the user's instructions, to the extent necessary to provide the Service.
5. Categories of data processed, purpose, legal basis and retention period
The Controller processes personal data solely for operating, securing and supporting the Service, for legal compliance and to deliver the functions requested by the user. The Controller does not sell personal data.
The legal bases refer to Article 6(1) of the GDPR: (b) performance of a contract; (f) legitimate interest of the Controller (or a third party); (c) compliance with a legal obligation; (a) consent of the data subject.
| Data category | Purpose and legal basis | Retention period |
|---|---|---|
| Account data: email address, name, language setting, registration data, session tokens | Provision of the Service [Art. 6(1)(b)]; legitimate interest [Art. 6(1)(f)] in security and abuse prevention | For the life of the account; tokens until they expire or are revoked; deletion and security traces for as long as necessary |
| Household data: membership, role, invitations, invitees' email addresses | Provision of family access [Art. 6(1)(b)]; legitimate interest [Art. 6(1)(f)] in access control | For the duration of the membership or invitation, and for as long as necessary for security/audit purposes |
| Content data: uploaded or recorded audio, titles, metadata, playlists, link imports, public publication | Management of content as performance of the contract and at the user's request [Art. 6(1)(b)]; for public publication, the user's express action; legitimate interest [Art. 6(1)(f)] in handling abuse | Until deletion or withdrawal of consent; until removal from the public catalogue; deleted media may be retained for up to 45 days before final deletion; it may remain in backups for up to 99 days |
| Device data: device identifiers, assignment, status, commands sent, software version, connection events, technical and crash logs | Operation of the device as performance of the contract [Art. 6(1)(b)]; legitimate interest [Art. 6(1)(f)] in secure operation and troubleshooting | According to the active device and troubleshooting need; crash logs by default for up to 395 days |
| Device permissions: Bluetooth setup, local device permissions | Provision of the Service [Art. 6(1)(b)] and the permission granted on the device. The application delivers the Wi-Fi network name and password to the Mesegép device locally, over Bluetooth | The Controller's servers store the Wi-Fi network name and password only if the user explicitly opts in to saving them for later reuse; saved Wi-Fi passwords are stored encrypted, are household-scoped, and can be deleted by the user at any time. Without this opt-in the servers do not store them; local permissions are managed by the device operating system |
| Service emails (account, login, support, service notifications) | Performance of the contract [Art. 6(1)(b)] | For as long as necessary for the account and for legal and security records |
| Error and crash monitoring (via the Sentry service), AI-assisted issue analysis and feedback spam screening, feedback screenshots submitted by the user, and support/debug reports | Legitimate interest [Art. 6(1)(f)] in bug fixing and security; on submitting feedback or writing to support, the user's request. A feedback screenshot is sent only when the user submits feedback. A support/debug report is sent when the user chooses the support or diagnostic flow, and the same kind of redacted technical report is attached automatically to error and crash reports. Sentry may use AI-assisted tools to analyse issue context and screen feedback for spam for these purposes. The Controller has not authorised use of this data to train AI models | Error and crash monitoring data and feedback screenshots are retained for as long as necessary for security and bug fixing. Support/debug data handled for a support case is retained up to 180 days after closure, then may be used for up to 90 more days only in aggregated internal form for bugfix strategy |
| Closed test and research application: email address submitted for email verification; for submitted applications, email address, name, telephone number (optional), country and city, postal shipping address, children's ages, device colour choice, motivation and the consents given | Handling the application, shipping the test devices, keeping in touch with participants and participation in research on the basis of the data subject's consent [Art. 6(1)(a)]. The application can be modified or deleted at any time using the unique link received by email | For email-verification links, up to 30 days; for submitted applications, until the research is concluded, for a maximum of 3 years, after which deletion; the applicant may also delete their data at any time using the link received |
| Invite-only research survey: optional answers and notes, completion status and timestamps, email address, app user, household and device identifiers, device name, language, secret link and pseudonymous research keys used for comparison | Research into Mesegép use and product development on the basis of the data subject's consent [Art. 6(1)(a)]. Answers may be compared with Mesegép usage data and with another invited adult's answers in the same household; household members cannot see one another's answers | For the research period, for a maximum of 3 years. The respondent can use the secret link at any time to remove direct identifiers and revoke the link; research answers and pseudonymous research keys remain without direct identifiers |
For application and other questions concerning the closed test and research programme, the Controller may be contacted at applications@mesegep.hu.
6. Processing based on legitimate interest
Where the legal basis for processing is the legitimate interest under Article 6(1)(f) of the GDPR, the Controller has carried out a balancing test, in the course of which it established that the interest in secure and abuse-free operation, in bug fixing and in access control is proportionate to the rights and freedoms of data subjects, and that these purposes cannot be achieved in a less restrictive way. A summary of the balancing test may be requested at privacy@mesegep.hu. The data subject may object at any time, on grounds relating to their particular situation, to such processing (see section 10).
7. Recipients and processors
The Controller processes personal data primarily on its own servers and storage. The following recipients and processors within the meaning of Article 28 of the GDPR may be involved in the Service:
- András Szabó and the Service's own servers;
- Resend – email-sending service, when the Service sends an email;
- Sentry – error and crash monitoring, AI-assisted issue analysis and feedback spam screening, and receiving feedback and support/debug diagnostics submitted by the user;
- Apple and Google – solely for app store distribution;
- the source site specified by the user – only if the user requests a link import.
The Controller maintains a processor agreement compliant with Article 28 of the GDPR with the processors. Beyond the above, the Controller does not transfer the data to third parties and does not sell it.
8. Transfers to third countries
Some platforms or processors may also process data outside the European Economic Area (EEA). In such cases the Controller applies appropriate safeguards under Chapter V of the GDPR, in particular the Commission's adequacy decision (Article 45), the standard contractual clauses (SCC, Article 46) or the provider's other appropriate safeguards, where this is necessary. A copy of the safeguards may be requested at privacy@mesegep.hu.
9. Data security
In accordance with Article 32 of the GDPR, the Controller applies technical and organisational measures proportionate to the risk, including access control, token-based session management, and protection of the transmission and storage of data. The Controller's servers store the Wi-Fi network name and password only when the user explicitly opts in to saving them for later reuse; the saved Wi-Fi passwords are stored encrypted and the user can delete them at any time. Without this opt-in the servers do not store them.
In the event of a personal data breach, the Controller acts in accordance with Articles 33–34 of the GDPR: where justified, it notifies the supervisory authority within 72 hours and – where required – informs the data subjects.
10. Rights of the data subject
The data subject has the following rights under the GDPR:
- access to the data processed (Article 15);
- rectification (Article 16);
- erasure / the “right to be forgotten” (Article 17);
- restriction of processing (Article 18);
- data portability (Article 20);
- objection to processing based on legitimate interest (Article 21);
- withdrawal of consent in the case of processing based on consent, without affecting the lawfulness of processing prior to withdrawal (Article 7(3)).
Within the Service, the user can change their name and the application language, delete their own content and – where authorised – household or public content, and revoke Bluetooth and similar permissions in the device settings.
The data subject may submit a request to exercise their rights at privacy@mesegep.hu. The Controller fulfils the request generally within 30 days; for complex or numerous requests this deadline may be extended by up to two further months under Article 12(3) of the GDPR, of which the Controller will provide information. Exercising rights is free of charge; in the case of a manifestly unfounded or excessive request, the Controller may act in accordance with Article 12(5).
11. Remedies
If the data subject considers that their data processing request has not been resolved, or that their rights relating to data processing have been infringed, they may:
- lodge a complaint with the supervisory authority (Article 77 of the GDPR). In Hungary this is the National Authority for Data Protection and Freedom of Information (NAIH) – 1055 Budapest, Falk Miksa utca 9–11.; postal address: 1363 Budapest, Pf. 9.; ugyfelszolgalat@naih.hu; www.naih.hu;
- turn to a court (Article 79 of the GDPR and the relevant provisions of Act CXII of 2011 [the Information Act]). The action may also be brought before the tribunal having jurisdiction over the data subject's place of residence or stay.
12. Children
Mesegép is not a service directed at children, in particular not at children who have not reached the age of 16 – the age of digital consent applicable in Hungary under Article 8 of the GDPR. In other countries this age limit may vary between 13 and 16 years under local law. A child is not an independent account manager of the application.
If anyone believes that a child's personal data has come into the Controller's possession without authorisation, please report it at privacy@mesegep.hu; the Controller will examine such data without undue delay and delete it as necessary.
13. Automated decision-making and profiling
The Controller does not make decisions based solely on automated processing within the meaning of Article 22 of the GDPR that produce legal effects concerning the data subject or similarly significantly affect them.
14. Account deletion and data retention after the account ends
The consequences of account deletion and the details of retention are described in the Account Deletion Guide. After deletion of the account, the Controller – for legal reasons, and in order to handle matters relating to intellectual property (copyright), abuse prevention and child protection – retains a minimal moderation record (display name and email address) linked to existing reports, moderation actions and publisher bans, on the basis of legitimate interest [Art. 6(1)(f)] and legal obligation [Art. 6(1)(c)].
15. Amendment of this notice
The Controller may amend this notice if the Service, legal requirements or app store publications change. The Controller will provide information about material changes in the application or by email. The text in force at any given time is available at https://mesegep.hu/privacy/.