Privacy Policy
Effective date: March 19, 2026
TinySteps ("we", "our", or "us") operates the TinySteps mobile application (the "App"). This Privacy Policy explains how we collect, use, and protect your information when you use our App.
1. Information We Collect
Account information. When you create an account we collect your email address and, if you choose password-based authentication, a securely hashed password. If you sign in with Google or Apple, we receive your name and email from the identity provider. We do not receive or store your Google or Apple password.
Child profile information. During onboarding you provide your child's first name and date of birth. This information is used solely to personalize activity recommendations by age.
Activity and session data. When you complete a daily activity we store your feedback rating (e.g., "loved it", "it was okay", "not ready yet"), which activity was presented, and whether it was completed or skipped. This data drives the recommendation engine and your progress dashboard.
Device information. If you enable push notifications we collect your Apple Push Notification service (APNs) device token so we can deliver daily reminders. We also store your preferred notification time and timezone.
Subscription information. Subscription purchases are processed entirely by Apple through the App Store. We receive a transaction receipt to verify your subscription status but do not collect or store payment details such as credit card numbers.
2. How We Use Your Information
- To provide and personalize the App's core features — daily activity recommendations, progress tracking, and streak calculations.
- To authenticate your account and keep it secure.
- To send push notifications when you have opted in.
- To verify and manage your subscription status.
- To improve the App through aggregated, non-identifying usage patterns.
3. Data Storage and Security
Your data is stored in a PostgreSQL database hosted on Amazon Web Services (AWS) in the US. All data in transit is encrypted via TLS. Database credentials are managed through AWS Secrets Manager. We follow industry-standard security practices including parameterized queries, hashed passwords (bcrypt), and least-privilege access controls.
4. Data Sharing
We do not sell, rent, or share your personal information with third parties for marketing purposes. We may share data only in the following circumstances:
- Service providers. AWS hosts our infrastructure. Google and Apple provide authentication services. These providers process data on our behalf under their respective privacy policies.
- Legal requirements. We may disclose information if required by law, court order, or governmental regulation.
5. Children's Privacy
TinySteps is a tool for parents, not for children. The App is not directed at children under 13 and we do not knowingly collect information directly from children. The child profile information (name and date of birth) is provided by the parent and used only to personalize recommendations.
6. Your Rights
You can:
- Access and update your account and child profile information at any time through the App's Settings screen.
- Delete your account through Settings. Account deletion begins a 30-day grace period, after which all your data — account information, child profiles, and activity history — is permanently removed from our systems.
- Opt out of notifications at any time through the App's notification settings or your device's system settings.
7. Data Retention
We retain your data for as long as your account is active. If you delete your account, all personal data is permanently deleted after a 30-day grace period. Aggregated, non-identifying analytics data may be retained indefinitely.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy in the App or by email. Your continued use of the App after changes constitutes acceptance of the updated policy.
9. Contact Us
If you have questions about this Privacy Policy or your data, contact us at privacy@tinystepsapp.com.