bluon.day Privacy Policy
Last updated: 19 July 2026
This privacy policy describes the processing of personal data connected with the use of bluon.day, the shared family diary with AI suggestions, available as a web application and as an Android app. It is provided under Regulation (EU) 2016/679 ("GDPR") and concerns this Application only. It is addressed both to registered Users and to the other people whose data may appear in a diary (people in the User's care, invited members, people mentioned in to-dos): the latter are also covered by the Privacy notice for people in your care, family members and invited members.
Data Controller
Blu Oberon S.r.l.
via Tadino, 52 — 20124 Milano (Italia) · VAT no. IT08399040966
Contact email address: privacy@bluoberon.it
Blu Oberon acts as an independent controller for all the data described in this privacy policy, including the data the User enters about other people.
Who the Service is for
bluon.day is reserved for people of legal age. Legal age is confirmed by an express declaration at first sign-in and, for those joining a circle, when the invitation is accepted. Minors cannot be Users: they have no account and do not access the Application. The adult User may, however, note in the diary certain deliberately limited data about the people in their care — for example children or family members. How this data is processed is explained below, under «Data on people in the User's care».
Types of data collected
- Sign-in identification data: the email address always; name and profile picture only for those who sign in with Google, which provides them at the time of sign-in.
- Google Calendar events (title, date and time, place), read in order to display them in the diary and modified only on the User's initiative.
- Google Tasks activities, read and updated in order to keep to-dos aligned between bluon.day and the User's Google account.
- Content created in the Application: to-dos and appointments (title, category/scope, date, time, place, status, assignments and beneficiary) and, if the User uses voice with the assistant Daisy, the dictated text and its transcription.
- Data on people in the User's care. The User may create in the diary the profile of a person they care for (a child, a parent, a family member): a name or an alias, the care relationship (e.g. «daughter», «mum») and, if linked, the identifier of a bluon device. The people in the User's care may also include minors: they are not the ones using the Application, but their data — within the minimal limits just described — is processed by Blu Oberon so that the adult's diary can refer to them. The User enters this data under their own responsibility, typically in the exercise of parental responsibility or of a family care relationship, and undertakes to inform the people concerned (or those who represent them). This data stays in the diary of whoever entered it, is not shared with the other members of the circle together with the assigned to-dos and is never used for advertising or profiling. The details, written for those who are not Users, are in the Privacy notice for people in your care, family members and invited members.
- Your circle and the invitees (if the User uses it): the name or alias the User gives to each member, the relationship, the role and the status of the invitation. Before the invitation is accepted, Blu Oberon keeps for each invitee name or alias, relationship, role, status and expiry of the invitation, visible only to the User who entered them; it does not keep the email address or any other contact details of the invited person. The roles (guest, admin, super) involve solely different permissions to view and assign within the circle; private scopes are not visible to any other member, not even to administrators.
When the User assigns a to-do to a member who has accepted the invitation, that member sees — in their own account — the title, category, date, time and status of the to-do and the name of the User who assigned it, and can mark it as done. They do not see other to-dos, they do not see the other members of the circle and they do not see the beneficiaries indicated with «@». Access is revoked at any time by removing the member from the circle, with immediate effect; the member, in turn, can leave the circle from their own Profile.
- bluon/Semiperdo wristband (if linked): the identifier (UUID) of the wristband associated with the account, read via NFC to confirm activities.
- Data for push notifications (subscription endpoint and device time zone), only if the User turns reminders on.
- Essential usage data (monthly count of the AI features used, technical infrastructure logs), for the operation and security of the service.
- Subscription data (only for Plus subscribers): subscription status and a customer identifier from the payment provider. Card data is processed directly by Stripe: bluon.day neither sees nor stores it.
The Application uses only technical session cookies (authentication). It does not use profiling cookies, third-party analytics tools, advertising or remarketing.
Health-related data
bluon.day is not designed to process health data and never asks for it. We expressly ask you not to enter diagnoses, conditions, medicines, treatments or medical reports in the titles of to-dos and in the other free-text fields: for a reminder, a neutral wording is enough (e.g. «Andrea's appointment»). As a further precaution, the Application automatically excludes texts that appear to refer to health from artificial intelligence flows and from extended notifications. If, despite this request, a text of that kind is entered in a free-text field, it remains technically stored for the sole purpose of allowing the User to modify or delete it, and it is never used for health-related, profiling or advertising purposes.
Purposes and legal bases of processing
- The User's account, diary, circle and subscription (creation and management of the account, to-dos, reminders, AI suggestions, voice capture, Plus plan) — performance of the contract with the adult User, Art. 6.1.b GDPR.
- Synchronisation with Google Calendar and Google Tasks — performance of the contract, Art. 6.1.b GDPR, when it is the User who turns it on. The Google authorisation screen (OAuth) is the technical authorisation to access that data, and can be revoked at any time from the Google account settings.
- Ordinary data on people in the User's care and names/aliases of invitees before acceptance — legitimate interest, Art. 6.1.f GDPR, of the User and of the Controller in an effective family organisation with data reduced to a minimum. The related balancing assessment (LIA) is documented internally and is kept available for the supervisory authority.
- Sending push reminders — consent, Art. 6.1.a GDPR: notifications are optional and consent can be withdrawn at any time from the browser or device settings.
- Accounting and tax obligations connected with subscriptions — legal obligation, Art. 6.1.c GDPR.
- Security, abuse prevention and counting of AI features — legitimate interest of the Controller, Art. 6.1.f GDPR.
How and where data is processed
Data is processed by electronic means, with appropriate security measures: the Application's data resides on databases in the European Union (Ireland) and the Application runs on infrastructure with functions in Europe (Dublin). Google access tokens live solely in an encrypted session cookie: they are never exposed to the browser or saved in the database. Access to data is strictly separated per user.
Third-party services used
Registration and authentication
There are two ways to sign in, at the User's choice: with your own Google account (Google Ireland Ltd.), or with a sign-in link sent by email, valid for a few minutes and for one use only. In both cases bluon.day does not store passwords. The sign-in link is delivered through Brevo (Sendinblue SAS, France) and only a cryptographic fingerprint of it remains in the database, not the link itself.
Synchronisation with Google Calendar and Google Tasks is an optional feature, separate from signing in: those who sign in with the email link grant no permission over their Google data, and can link it later — or never.
Calendar and tasks synchronisation — Google Calendar API and Google Tasks API
Used to read and update, at the User's request, events and tasks in their Google account. The use of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements: such data is used only to provide the visible features of the Application, is not sold, is not used for advertising and is not read by humans, except with explicit consent, legal obligations or security reasons.
Artificial intelligence features — Anthropic (Anthropic, PBC — USA)
The AI features fall into two groups, with different rules.
- Voice capture and suggestions: these are actions started by the User. When the User uses them, the dictated text or the titles and times of commitments are sent to Anthropic for the sole purpose of generating the requested to-do or suggestions, with automatic exclusion of texts potentially referring to health.
- Morning brief (Plus): it is switched off by default and is turned on only by an express choice of the User. When it is on, every morning only the number of the day's commitments and their times are sent to Anthropic (e.g. «3 commitments at 9:00, 12:30, 17:00»): neither the User's name nor the titles of the to-dos are sent. It can be switched off at any time from the settings, with immediate effect.
Data sent through the API is not used to train the models. A data processing agreement (DPA) is in place with Anthropic incorporating the standard contractual clauses approved by the European Commission; the transfer to the United States is described in the section «Transfers outside the EU».
Voice capture — browser/device recognition
Voice recognition takes place through the features of the User's browser or operating system. Depending on the device, the audio may be processed locally or by the provider of the recognition service (e.g. the maker of the browser or of the system). Blu Oberon does not receive and does not store the audio recording: it processes only the transcribed text, which the User sees and confirms.
Payments and subscriptions — Stripe (Stripe Payments Europe, Ltd. — Ireland)
Plus subscriptions and the related payments are managed by Stripe. Payment takes place on pages hosted by Stripe: card data is collected and processed directly by Stripe and does not pass through, and is not stored by, bluon.day. On subscribing, the User's name and email address are shared with Stripe for customer management and tax obligations. The Controller keeps only a customer identifier and the subscription status, which are needed to activate and manage the plan. Stripe's privacy policy: stripe.com/privacy.
Hosting and infrastructure — Vercel Inc. · Database — Turso (CHISELSTRIKE Inc.)
Technical delivery of the Application (functions run in the EU) and storage of application data on databases in the EU region (Ireland).
Circle invitations
To invite someone into your circle, bluon.day does not ask for and does not store their email address or any other contact details: it generates a link that the User shares themselves through whichever channel they prefer, and no communication goes out from our systems to the invitee. Until acceptance, however, Blu Oberon processes some minimal data about the invitee entered by the User: name or alias, relationship, role, status and expiry of the invitation, visible only to the User who entered them. Whoever opens the link sees only the name of the person who invited them, and nothing is shared in either direction until they accept. The link is valid for 7 days, usable once only and lapses on acceptance; on expiry, the token and the status of the invitation are deleted or rendered unusable. The Privacy notice for people in your care, family members and invited members also applies to invitees.
Push notifications — browser/device push service
Reminders are delivered through the push service of the User's browser (e.g. Google, Mozilla, Apple). By default the content is generic — for example «Reminder at 15:00» — and does not include the title of the to-do. The User can optionally turn on the «Show the title in notifications» option, after a warning about the risk that the title may appear on the device's lock screen; even with the option on, titles potentially referring to health remain excluded from extended notifications. The morning brief notification (Plus) contains only the numerical summary described above.
Transfers outside the EU
Some providers may process data in the United States: in particular Anthropic (AI features) and, for certain technical components, Vercel, Stripe and the push services. Depending on the provider, the transfers are based on the EU–US adequacy decision (Data Privacy Framework, for providers that are certified) or on the standard contractual clauses of the European Commission, supplemented where necessary by additional measures. We do not claim safeguards that we have not verified: an up-to-date list of the providers and of their respective safeguards can be requested at privacy@bluoberon.it.
Retention period
- Account and profile (including people in the User's care and the circle) — for as long as the account exists, that is until it is deleted by the User.
- To-dos and appointments — until the User deletes them; the history of activity and statistics can be viewed for 12 months.
- Circle invitations — the link is valid for 7 days: on expiry, the token and the status of the invitation are deleted or rendered unusable.
- Technical and security logs — for a short period, the time needed to ensure operation and to investigate any abuse.
- Billing data — 10 years, as a tax and accounting legal obligation.
- Technical backups — for a limited time window, after which they are overwritten.
- Data sent to Anthropic — kept by the provider for the period set out in the data processing agreement (DPA), then deleted.
The push subscription is removed when it expires or when the User withdraws the permission. The User can delete the account and the linked data from the Application (Profile → «Delete my account»), following the instructions on the page Deleting your account, or by writing to the Controller: deletion erases the data and cancels the subscription. Only the data already lawfully received by other members of the circle (the to-dos assigned to them, in their account) and the data subject to tax and accounting obligations may survive, within the limits of the law.
Rights of data subjects
Under Arts. 15–22 GDPR, every data subject has the right to:
- access their data and obtain a copy of it;
- rectify or update it;
- obtain its erasure ("right to be forgotten");
- restrict or object to the processing, including where it is based on legitimate interest;
- receive it in a structured and portable format (in the app: "Export my to-dos");
- withdraw at any time the consents given, without affecting the lawfulness of the previous processing.
These rights belong not only to Users, but to anyone affected by the processing: people in the User's care, invited members, people mentioned in to-dos. For minors and for other people who are represented, the request may be submitted by whoever exercises parental responsibility or is otherwise entitled to do so. Requests can be sent to privacy@bluoberon.it; those who are not Users will find practical guidance in the Privacy notice for people in your care, family members and invited members. bluon.day's access to the Google account can be revoked directly at myaccount.google.com/permissions.
Complaint to the supervisory authority
Every data subject has the right to lodge a complaint with the competent supervisory authority in their country of residence or, as the Controller is established in Italy, with the Italian Garante per la protezione dei dati personali (garanteprivacy.it).
Changes to this privacy policy
The Controller may update this privacy policy at any time, publishing the updated version on this page with the relevant date. In the event of substantial changes, the User will be informed in the Application.