Privacy policy
Last updated: 27 September 2026
1. Who are we?
Chup is a product of Inprovo, based in the Netherlands. We are responsible for the processing of personal data as described in this privacy policy. You can reach us via info@chup.nu.
2. What data do we collect?
When using Chup, we process personal data that you provide to us yourself.
Account details: name, email address and an encrypted password. For family members you add: name and optionally an email address and profile photo.
Usage data: the content you create within the app, such as chores, calendar items, rewards and point balances. This data is linked to your family account.
Photos and documents in the photo vault: these are encrypted on your device before reaching our servers, with a key that can only be opened with your vault password or recovery code. Chup doesn't know that password and therefore can't view these files. See section 5a. Messages and financial data are stored encrypted on our servers.
Linked calendars: if you link a calendar yourself, we process the appointments from it. See section 7a.
Email tracking: the emails Chup sends contain a small, invisible image, and the buttons run via our own domain. This lets us see whether and when an email was opened and whether you clicked the button. We only use this to improve our emails and to check, if there are questions, whether an email arrived. If you don't want this, turn off automatic image loading in your email programme; you can also unsubscribe from introductory emails via the link at the bottom.
Contact details: if you fill in our contact form, we process your name, email address and message. When signing up for updates, we process your email address and optionally your name.
3. Why do we collect this data?
We only process your data to provide and improve our service: making your account and the app function, sending emails you expect (such as confirmations and password resets), and informing you about Chup if you've signed up for that.
We don't sell your data to third parties and don't use it for advertising or profiling.
4. Legal basis
We process your data on the following legal bases from the GDPR: performance of the agreement (Article 6(1)(b)) for your account and use of the app, consent (Article 6(1)(a)) for our newsletter (after double confirmation), and legitimate interest (Article 6(1)(f)) for security, fraud prevention and measuring our emails. Linking a calendar happens at your request, as part of the agreement; you can always disconnect a link again.
5. Storage and security
Your data is stored on secure servers within the European Union (Hetzner, Germany). All connections run via HTTPS. We take appropriate technical and organisational measures to protect your data against unauthorised access, loss or misuse.
5a. The photo vault: end-to-end encrypted
Photos and documents in the photo vault are end-to-end encrypted. This means:
- Encryption on your device: files are encrypted on your phone or computer before reaching our servers. Location data and other metadata from photos are removed in the process.
- A family key behind your vault password: we only store your family's key in encrypted form, derived from the vault password chosen by your family's administrator and from a recovery code you're shown once. Chup knows neither of these and therefore can't open the key.
- Our servers can't read your files: we only store encrypted data. Even if our servers were hacked, an attacker couldn't read your photos.
- Each file has its own key: every photo and document is encrypted with a unique key, so that compromising one file doesn't lead to access to other files.
- Devices: each family member opens the vault with the vault password and can have a device remembered. If the administrator changes the password, all devices will need to unlock again. On the children's kiosk, a parent can open the vault once for the photo background; that tablet then keeps the key itself.
- Sharing with a linked family: the administrator can share a folder with a family you're linked to. The key to that folder is then passed on via a share code that you provide yourselves; the other family stores it encrypted with its own family key. Chup can't read shared folders either. You can stop sharing at any time, but whatever the other family has already viewed, they've seen.
Important: if you lose both the vault password and the recovery code, no one will be able to open the photos any more, not even Chup. They will then be irretrievably lost. This is inherent to end-to-end encryption; you agree to this when setting up the vault. So keep the recovery code somewhere safe, not in your email.
Web version limitation: when you use Chup via a web browser (instead of the app), our server delivers the program code that carries out the encryption. In theory, an attacker who took over our server could deliver altered code. The Chup app (via the App Store) doesn't have this limitation, because the code there is delivered as a fixed binary. We take measures to reduce this risk, including a strict Content Security Policy and integrity checks on our code.
6. Retention periods
We keep account details for as long as your account is active. An account without a paid subscription that hasn't been used for 90 days will be deleted; you'll receive several emails about this beforehand. After deletion, you can still restore your account within 30 days by logging in again. After that, all your data, including encrypted photos and files, will be permanently and irreversibly erased. We keep contact messages for a maximum of 12 months. We keep registration details until you unsubscribe.
7. Processors and third parties
To deliver our service, we use a limited number of processors:
- Hetzner (Germany) - server hosting and file storage (encrypted files)
- Separate recovery server (EU) - encrypted backup of family keys, with a different provider than our main server
We also use processors for sending emails and error logging. All processors are based in the EU or process data under appropriate safeguards in line with the GDPR. We have entered into a data processing agreement with each processor. An up-to-date overview of our processors can be requested via info@chup.nu.
Cloud storage import: if you choose to import photos from Dropbox, Google Drive or OneDrive, Chup temporarily grants itself read access to the folders you've selected. Imported photos are encrypted on your device before being stored on our servers. You can disconnect the link at any time.
7a. Linked calendars
You can link calendars yourself in Chup. This only happens if you (or a parent in your family) choose to, and for each link you choose which family member the appointments belong to.
Via a link (for example Magister, Somtoday, Zermelo, Parro, Social Schools, Voetbal.nl or an iCal link from your own calendar): Chup fetches the appointments from that link and adds them to your family calendar. Such a link acts as a key to the calendar; we therefore store it encrypted. If you disconnect the link, we delete the link and the imported appointments.
School holidays: we source these from the Dutch government's open data. We only pass on the region, no personal data.
Via your account with Google Calendar, Microsoft Outlook or Apple iCloud: you log in with Google or Microsoft and grant permission there yourself; with iCloud you enter an app-specific password that you create with Apple and can also revoke there. Chup only uses this access for what you set up in the app:
- Reading: your email address (to show which account is linked), the list of your calendars (so you can choose which ones you want to see in Chup) and the appointments in the calendars you choose.
- Writing: only if you turn this on, Chup adds the appointments you create in Chup to the calendar you choose, and changes or deletes them there if you do so in Chup. Chup doesn't change or delete other appointments in your calendar.
- Storage: we store the access keys (tokens or the app-specific password) encrypted. Imported appointments are kept in your family calendar on our servers in the EU, just like appointments you make yourself.
- Disconnecting: always possible in Chup, under Settings, External calendars. We then remove the access keys, the imported appointments and the appointments Chup had added to your calendar. You can also revoke access at Google, Microsoft or Apple themselves.
We only use data from your linked calendars to display and update the calendar in Chup. We don't use it for advertising, sell it, pass it on to others, or use it to train AI models. Chup staff don't view it, except when you explicitly give permission for a support query, or when it's legally required or necessary for security.
Google: Chup's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. (The use and transfer of data received by Chup via Google adheres to the Google API Services User Data Policy, including the Limited Use requirements.)
8. Cookies
Chup only uses functional cookies that are strictly necessary for the app to work, such as session and security cookies. We don't place any tracking cookies and don't use any third-party analytics.
9. Your rights
Under the GDPR, you have the right to access, rectification, erasure, restriction of processing, data portability and withdrawal of consent. You also have the right to lodge a complaint with the Dutch Data Protection Authority. To exercise your rights, please contact us at info@chup.nu. We respond to your request within 30 days.
10. Processing register
A complete overview of all processing of personal data is available in our processing register, in accordance with Article 30 of the GDPR.
11. Changes
We may update this privacy policy from time to time. In the event of material changes, we'll inform you by e-mail or via the app. The most up-to-date version is always available on this page.