TinyLayers

Privacy Policy

Last updated: July 5, 2026

TinyLayers helps parents decide what their baby should wear. This policy explains, in plain English, what data the TinyLayers app collects, why, where it goes, and what your rights are. The short version: we collect the minimum we need, we never sell your data, we show no ads, and we use no advertising or analytics trackers.

Who we are

TinyLayers is the data controller for the personal data described in this policy. You can reach us at support@twobricklabs.com for any privacy question or request.

What we collect

We collect only what the app needs to work:

  • Account data. Your email address and how you signed in (Apple, Google, or an emailed 6-digit code), plus the account identifier created by our authentication provider. There are no passwords. If you sign in with Apple or Google and choose to share your name, we store it with your account so we can greet you; you can use Apple's "Hide My Email" if you prefer.
  • Child profile data, entered by you. Your baby's first name (or any nickname you choose), an age band, an optional birthdate, and whether your baby tends to run warm, typical, or cool. You control exactly what you enter — a nickname works just as well as a real name.
  • Check-ins and recommendations. When you use the app: the mode (sleep, nap, going out, stroller, carrier, car seat), the temperature you entered or fetched, how your baby felt (cool / comfortable / warm), what your baby wore, and a timestamp.
  • Settings. Your temperature unit (°C/°F), appearance, and reminder preferences. Daily reminder notifications are scheduled locally on your device — nothing about them is sent to us.
  • Approximate location — only if you ask for weather. For outdoor modes you can fetch current weather. With your permission, the app reads your coarse, low-accuracy location and sends only those coordinates to our weather service. We do not store your location in your account, we do not track your movements, and location is never used to guess your baby's room temperature.
  • Purchase status and app identifiers. Whether you have TinyLayers Premium, a trial, or another app-store entitlement managed through Apple and RevenueCat. RevenueCat may use an app-user identifier or device-level identifier to manage purchases and restores. We never see your payment card details.
  • Technical diagnostics. We do not currently add a third-party crash reporting or performance analytics SDK. If we later collect crash logs, launch time, hang rate, or similar app diagnostics, we will use them only to keep TinyLayers working, avoid including baby names or health-adjacent details, and update this policy and our App Store privacy answers first.

What we do not collect

  • No advertising or analytics trackers (no ad SDKs, no behavioral analytics).
  • No precise location tracking.
  • No phone number, physical address, or other user contact information beyond your sign-in email and optional account name.
  • No contacts, photos, microphone, or health-record access.
  • No medical records or clinical diagnostic data. TinyLayers is a dressing-guidance app, not a medical device, and its data is not health data in a clinical sense.
  • No data from children. The app is for parents and guardians (18+). All information about a baby is entered by the parent, about their own child — we never interact with or collect data from children directly.

Children's data — how we handle it

TinyLayers necessarily processes information about infants (a first name or nickname, age band, optional birthdate, and comfort check-ins), because that is what the app is for. This data is always entered and controlled by the parent or guardian, who is our user. We treat it as sensitive: it is protected by row-level security so only your account can read it, it stays in the EU (see below), it is never used for advertising or profiling, never sold, and you can delete it at any time from inside the app. We deliberately do not require a real name or exact birthdate — an age band and a nickname are enough for the app to work.

How we use your data (purposes and legal bases)

  • To provide outfit guidance and run the app (child profile, check-ins, settings, temperatures) — performance of our contract with you (GDPR Art. 6(1)(b)).
  • To create and secure your account and sync your data across devices (email, sign-in provider, synced profiles and history) — performance of contract (Art. 6(1)(b)) and our legitimate interest in keeping accounts secure (Art. 6(1)(f)).
  • To fetch local weather when you request it (approximate coordinates) — your consent, given via the location permission prompt (Art. 6(1)(a)). You can decline or revoke it in your device settings at any time; the app still works with manually entered temperatures.
  • To manage subscriptions, trials, entitlements, and purchase restores (purchase status via RevenueCat/Apple) — performance of contract (Art. 6(1)(b)) and compliance with legal obligations such as tax and accounting records (Art. 6(1)(c)).
  • To send sign-in codes and essential service emails (email address) — performance of contract (Art. 6(1)(b)). We do not send marketing email without a separate opt-in.
  • To respond to support requests — legitimate interest in helping our users (Art. 6(1)(f)).

We do not use your data for advertising, we do not build marketing profiles, and we do not carry out automated decision-making with legal or similarly significant effects.

Where your data lives

TinyLayers is local-first: your data is stored on your device. If you use Premium sync, your data is also stored in our Supabase database hosted in the European Union (AWS eu-west-2, London, United Kingdom). Every synced table is protected by row-level security, meaning the database itself enforces that only your signed-in account can read or write your rows.

Service providers (processors)

We share data only with the providers we need to run TinyLayers, and only the minimum each one needs:

  • Supabase — database, authentication, and serverless functions (EU/UK region). Processes your account, synced profiles, check-ins, and settings.
  • RevenueCat (USA) — subscription management. Processes an anonymous app-user identifier and purchase/entitlement status. RevenueCat does not receive your baby's data.
  • Apple — App Store payments, and Sign in with Apple if you choose it. Your relationship with Apple is governed by Apple's own privacy policy.
  • Google — Sign in with Google, if you choose it. We receive only your email address and basic profile from Google, and we use it solely to sign you in, consistent with the Google API Services User Data Policy, including its Limited Use requirements.
  • Resend (USA) — delivers our sign-in code emails from tinylayers.pro. Processes your email address for delivery only.
  • MET Norway (Norwegian Meteorological Institute) — our weather provider. Our server forwards only approximate coordinates to fetch current weather and near-term forecast; no account identifier, name, or other personal data is sent with the request.

We never sell or rent personal data, we do not "share" personal data for cross-context behavioral advertising (as defined by California law), and no third party is allowed to use your data for its own purposes.

App Store privacy label summary

We keep our App Store privacy answers aligned with this policy. Based on the current app design, the data categories we expect to disclose are:

  • Name — optional account name and baby name/nickname, used for app functionality, linked to your account, not used for tracking.
  • Email Address — used for passwordless sign-in, sync, account support, and service emails, linked to your account, not used for tracking.
  • Device ID — used by app services such as RevenueCat to manage purchases, restores, fraud prevention, and app functionality. It may be linked to your account or purchase status, and is not used for tracking.
  • Purchases — subscription, trial, entitlement, and restore status, used for app functionality, linked to your account or app-user identifier, not used for tracking.
  • Coarse Location — used only when you ask for outdoor weather. It is used for app functionality, not stored in your account by TinyLayers, and not used for tracking.

We do not collect Other User Contact Info such as phone numbers or postal addresses. We also do not currently collect Crash Data or Performance Data through our own crash or performance SDK; if that changes, we will update both this policy and the App Store privacy label before release.

International transfers

Your synced data is stored in the EU/UK. Some of our providers (RevenueCat, Resend, and Apple/Google for sign-in and payments) process limited data in the United States. Where personal data leaves the EEA, the UK, or a country with an adequacy decision, we rely on appropriate safeguards — primarily the European Commission's Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement), and, where a provider is certified, the EU–US Data Privacy Framework. You can request a copy of the relevant safeguards at support@twobricklabs.com.

How long we keep data

  • On your device: until you delete it (per profile, or all at once via Settings → Delete my data) or uninstall the app.
  • Synced data: for as long as your account exists. When you delete your account, your synced profiles, check-ins, and settings are deleted from our servers.
  • Account/auth records: deleted with your account.
  • Purchase records: retained by Apple/RevenueCat as required for tax, accounting, and fraud-prevention obligations.
  • Support emails: kept as long as needed to resolve your request, then deleted on a rolling basis.

Account and data deletion

You can delete everything from inside the app — no email required:

  • Settings → Delete my data removes every profile, check-in, and setting from your device.
  • Settings → Delete account deletes your account and your synced data from our servers, and removes everything from your device.

You can also email support@twobricklabs.com and we will delete your account and data for you. Deleting your account does not cancel an active subscription — manage that in your App Store subscription settings.

Your rights

Depending on where you live, you have some or all of these rights, and we honor them for everyone regardless of location:

  • Access a copy of your personal data (GDPR Art. 15; CCPA right to know; Australian Privacy Principle 12).
  • Correct inaccurate data (GDPR Art. 16; CCPA; APP 13) — you can edit profiles and settings directly in the app.
  • Delete your data (GDPR Art. 17; CCPA right to delete) — built into the app as described above.
  • Portability — receive your data in a machine-readable format (GDPR Art. 20).
  • Restrict or object to processing based on legitimate interests (GDPR Arts. 18 and 21).
  • Withdraw consent at any time (e.g. revoke location permission in device settings) without affecting the rest of the app.
  • Non-discrimination — we never treat you worse for exercising a privacy right (CCPA/CPRA).

To exercise any right, use the in-app controls or email support@twobricklabs.com. We respond within one month (GDPR) or 45 days (CCPA). We may need to verify you control the account, which we do by confirming access to your sign-in email — we never ask for a password, because there are none. Since we do not sell or share personal data for advertising, there is nothing to opt out of under "Do Not Sell or Share"; we also honor Global Privacy Control signals where applicable.

Security

Measures we take include:

  • Row-level security on every synced database table — enforced by the database, not just the app.
  • Passwordless authentication (Apple, Google, or one-time email codes), so there is no TinyLayers password to steal or reuse.
  • Encryption in transit (TLS) for all connections, and encryption at rest at our database host.
  • Secrets and provider keys kept server-side only; weather requests are proxied through our own server function.
  • Least-privilege access, data validation at every boundary, and no logging of baby names, tokens, or purchase receipts.

No system is perfectly secure, but we design so that a breach of any one layer exposes as little as possible. If a breach affects your personal data, we will notify you and the relevant authorities as required by law.

Not medical advice

TinyLayers provides general dressing guidance based on common TOG sleepwear guidance and safe-sleep recommendations from trusted public health sources. It is not medical advice, and data in the app is not a medical record. Always consult a health professional for concerns about your child's health.

Changes to this policy

If we change this policy in a meaningful way, we will update the date at the top and notify you in the app before the change takes effect. We will never retroactively reduce your rights over data we already collected without asking you first.

Complaints

We would like the chance to fix any concern first — email support@twobricklabs.com. You also have the right to complain to a supervisory authority: in the EU, your national data protection authority; in the UK, the Information Commissioner's Office (ICO); in Australia, the Office of the Australian Information Commissioner (OAIC); in the US, your state Attorney General.

Contact

support@twobricklabs.com