← Legal

Privacy Policy

Last updated: April 15, 2026

This Privacy Policy explains how Those Kids Creative Studio ("we", "us", "our") collects, uses, and protects your personal data when you use Screens by thosekids.studio ("the Service"). We are committed to protecting your privacy in accordance with the General Data Protection Regulation (GDPR) and Spanish data protection law (LOPDGDD).

1. Data Controller

  • Name: Those Kids Creative Studio
  • Owner: Jordi Gasau Mora
  • Address: Music Camps 7, 17244 Cassà de la Selva, Girona, Spain
  • Email: hello@thosekids.studio

2. Data We Collect

We collect the minimum data necessary to provide the Service:

  • Email address — provided at registration, used for authentication via magic links
  • Name — derived from your email prefix at account creation; you can update it
  • Screen content — the text, image URLs, and settings you enter when creating screens
  • Usage data — timestamps of account creation and screen updates

We do not collect:

  • Passwords (we use passwordless magic link authentication)
  • Payment or financial information (no paid plans currently active)
  • Location data, device fingerprints, or tracking cookies

3. Legal Basis for Processing

We process your personal data based on the following legal grounds under GDPR Article 6:

  • Contract performance (Art. 6.1.b) — your email is required to create an account and use the Service
  • Legitimate interest (Art. 6.1.f) — usage data helps us maintain and improve the Service

4. How We Use Your Data

  • To authenticate you via magic link emails
  • To associate screens with your account
  • To display your name in the dashboard interface
  • To communicate service-related updates (e.g., terms changes)

We do not use your data for advertising, profiling, or automated decision-making.

5. Data Sharing

We do not sell, rent, or share your personal data with third parties, except:

  • Email delivery — magic link emails are sent via our SMTP provider. Only your email address is shared for this purpose.
  • Legal obligations — we may disclose data if required by Spanish or EU law, or in response to valid legal process.

6. Data Storage and Security

Your data is stored in a MongoDB database. We use the following security measures:

  • Authentication tokens are stored as HTTP-only, secure cookies
  • Magic link tokens are single-use and expire after 15 minutes
  • JWT secrets are stored as environment variables, not in code
  • All data in transit is encrypted via HTTPS in production

7. Data Retention

  • Account data — retained as long as your account is active. Deleted upon account deletion request.
  • Screen content — retained as long as your account is active. Archived screens remain in the database until account deletion.
  • Magic link tokens — automatically deleted after expiration (15 minutes) via database TTL index.

8. Your Rights

Under the GDPR, you have the following rights:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate data
  • Erasure — request deletion of your account and all associated data
  • Portability — request your data in a structured, machine-readable format
  • Restriction — request that we limit processing of your data
  • Objection — object to processing based on legitimate interest

To exercise any of these rights, contact us at hello@thosekids.studio. We will respond within 30 days.

9. Cookies

We use a single essential cookie (auth_token) to maintain your authentication session. This is a strictly necessary cookie and does not require consent under GDPR. We do not use analytics cookies, advertising cookies, or any third-party tracking.

10. Public Display URLs

When you publish a screen, its content becomes accessible via a public URL. This content is visible to anyone with the link. No personal data (your name, email, or account information) is exposed on public display URLs.

11. Children's Privacy

The Service is not intended for children under 16 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.

12. International Transfers

Your data is processed and stored within the European Union. We do not transfer personal data to countries outside the EU/EEA unless adequate safeguards are in place as required by GDPR Chapter V.

13. Supervisory Authority

If you believe we have not adequately addressed your data protection concerns, you have the right to lodge a complaint with the Spanish Data Protection Agency (AEPD):

  • Website: www.aepd.es
  • Address: C/ Jorge Juan 6, 28001 Madrid, Spain

14. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a notice on the Service. The "Last updated" date at the top of this page indicates the most recent revision.

15. Contact

For any questions or requests regarding this Privacy Policy or your personal data:

  • Email: hello@thosekids.studio
  • Address: Those Kids Creative Studio, Music Camps 7, 17244 Cassà de la Selva, Girona, Spain
Screensby thosekids.studio

© 2026 Screens by thosekids.studio