Privacy Policy
Last updated: July 5, 2026
TinyLayers helps parents decide what their baby should wear. This policy explains,
in plain English, what data the TinyLayers app collects, why, where it goes, and
what your rights are. The short version: we collect the minimum we need, we never
sell your data, we show no ads, and we use no advertising or analytics trackers.
Who we are
TinyLayers is the data controller for the personal data described in this policy.
You can reach us at support@twobricklabs.com
for any privacy question or request.
What we collect
We collect only what the app needs to work:
- Account data. Your email address and how you signed in (Apple,
Google, or an emailed 6-digit code), plus the account identifier created by our
authentication provider. There are no passwords. If you sign in with Apple or
Google and choose to share your name, we store it with your account so we can
greet you; you can use Apple's "Hide My Email" if you prefer.
- Child profile data, entered by you. Your baby's first name (or
any nickname you choose), an age band, an optional birthdate, and whether your baby
tends to run warm, typical, or cool. You control exactly what you enter — a
nickname works just as well as a real name.
- Check-ins and recommendations. When you use the app: the mode
(sleep, nap, going out, stroller, carrier, car seat), the temperature you entered
or fetched, how your baby felt (cool / comfortable / warm), what your baby wore,
and a timestamp.
- Settings. Your temperature unit (°C/°F), appearance, and
reminder preferences. Daily reminder notifications are scheduled locally on your
device — nothing about them is sent to us.
- Approximate location — only if you ask for weather. For outdoor
modes you can fetch current weather. With your permission, the app reads your
coarse, low-accuracy location and sends only those coordinates to our weather
service. We do not store your location in your account, we do not track your
movements, and location is never used to guess your baby's room temperature.
- Purchase status and app identifiers. Whether you have
TinyLayers Premium, a trial, or another app-store entitlement managed through Apple
and RevenueCat. RevenueCat may use an app-user identifier or device-level
identifier to manage purchases and restores. We never see your payment card
details.
- Technical diagnostics. We do not currently add a third-party
crash reporting or performance analytics SDK. If we later collect crash logs,
launch time, hang rate, or similar app diagnostics, we will use them only to keep
TinyLayers working, avoid including baby names or health-adjacent details, and
update this policy and our App Store privacy answers first.
What we do not collect
- No advertising or analytics trackers (no ad SDKs, no behavioral analytics).
- No precise location tracking.
- No phone number, physical address, or other user contact information beyond
your sign-in email and optional account name.
- No contacts, photos, microphone, or health-record access.
- No medical records or clinical diagnostic data. TinyLayers is a
dressing-guidance app, not a medical device, and its data is not health data in a
clinical sense.
- No data from children. The app is for parents and guardians (18+). All
information about a baby is entered by the parent, about their own child — we
never interact with or collect data from children directly.
Children's data — how we handle it
TinyLayers necessarily processes information about infants (a first name or
nickname, age band, optional birthdate, and comfort check-ins), because that is what
the app is for. This data is always entered and controlled by the parent or guardian,
who is our user. We treat it as sensitive: it is protected by row-level security so
only your account can read it, it stays in the EU (see below), it is never used for
advertising or profiling, never sold, and you can delete it at any time from inside
the app. We deliberately do not require a real name or exact birthdate — an age band
and a nickname are enough for the app to work.
How we use your data (purposes and legal bases)
- To provide outfit guidance and run the app (child profile,
check-ins, settings, temperatures) — performance of our contract with you (GDPR
Art. 6(1)(b)).
- To create and secure your account and sync your data across devices
(email, sign-in provider, synced profiles and history) — performance of contract
(Art. 6(1)(b)) and our legitimate interest in keeping accounts secure
(Art. 6(1)(f)).
- To fetch local weather when you request it (approximate
coordinates) — your consent, given via the location permission prompt
(Art. 6(1)(a)). You can decline or revoke it in your device settings at any time;
the app still works with manually entered temperatures.
- To manage subscriptions, trials, entitlements, and purchase restores
(purchase status via RevenueCat/Apple) — performance of contract
(Art. 6(1)(b)) and compliance with legal obligations such as tax and accounting
records (Art. 6(1)(c)).
- To send sign-in codes and essential service emails (email
address) — performance of contract (Art. 6(1)(b)). We do not send marketing email
without a separate opt-in.
- To respond to support requests — legitimate interest in helping
our users (Art. 6(1)(f)).
We do not use your data for advertising, we do not build marketing profiles, and we
do not carry out automated decision-making with legal or similarly significant
effects.
Where your data lives
TinyLayers is local-first: your data is stored on your device. If you use Premium
sync, your data is also stored in our Supabase database hosted in the
European Union (AWS eu-west-2, London, United Kingdom). Every synced
table is protected by row-level security, meaning the database itself enforces that
only your signed-in account can read or write your rows.
Service providers (processors)
We share data only with the providers we need to run TinyLayers, and only the
minimum each one needs:
- Supabase — database, authentication, and serverless functions
(EU/UK region). Processes your account, synced profiles, check-ins, and settings.
- RevenueCat (USA) — subscription management. Processes an
anonymous app-user identifier and purchase/entitlement status. RevenueCat does not
receive your baby's data.
- Apple — App Store payments, and Sign in with Apple if you choose
it. Your relationship with Apple is governed by Apple's own privacy policy.
- Google — Sign in with Google, if you choose it. We receive only
your email address and basic profile from Google, and we use it solely to sign you
in, consistent with the Google API Services User Data Policy, including its Limited
Use requirements.
- Resend (USA) — delivers our sign-in code emails from
tinylayers.pro. Processes your email address for delivery only.
- MET Norway (Norwegian Meteorological Institute) — our weather
provider. Our server forwards only approximate coordinates to fetch current
weather and near-term forecast; no account identifier, name, or other personal
data is sent with the request.
We never sell or rent personal data, we do not "share" personal data for
cross-context behavioral advertising (as defined by California law), and no third
party is allowed to use your data for its own purposes.
App Store privacy label summary
We keep our App Store privacy answers aligned with this policy. Based on the current
app design, the data categories we expect to disclose are:
- Name — optional account name and baby name/nickname, used for
app functionality, linked to your account, not used for tracking.
- Email Address — used for passwordless sign-in, sync, account
support, and service emails, linked to your account, not used for tracking.
- Device ID — used by app services such as RevenueCat to manage
purchases, restores, fraud prevention, and app functionality. It may be linked to
your account or purchase status, and is not used for tracking.
- Purchases — subscription, trial, entitlement, and restore
status, used for app functionality, linked to your account or app-user identifier,
not used for tracking.
- Coarse Location — used only when you ask for outdoor weather.
It is used for app functionality, not stored in your account by TinyLayers, and
not used for tracking.
We do not collect Other User Contact Info such as phone numbers or
postal addresses. We also do not currently collect Crash Data or
Performance Data through our own crash or performance SDK; if that
changes, we will update both this policy and the App Store privacy label before
release.
International transfers
Your synced data is stored in the EU/UK. Some of our providers (RevenueCat, Resend,
and Apple/Google for sign-in and payments) process limited data in the United States.
Where personal data leaves the EEA, the UK, or a country with an adequacy decision,
we rely on appropriate safeguards — primarily the European Commission's Standard
Contractual Clauses (and the UK Addendum / International Data Transfer Agreement),
and, where a provider is certified, the EU–US Data Privacy Framework. You can
request a copy of the relevant safeguards at
support@twobricklabs.com.
How long we keep data
- On your device: until you delete it (per profile, or all at once
via Settings → Delete my data) or uninstall the app.
- Synced data: for as long as your account exists. When you delete
your account, your synced profiles, check-ins, and settings are deleted from our
servers.
- Account/auth records: deleted with your account.
- Purchase records: retained by Apple/RevenueCat as required for
tax, accounting, and fraud-prevention obligations.
- Support emails: kept as long as needed to resolve your request,
then deleted on a rolling basis.
Account and data deletion
You can delete everything from inside the app — no email required:
- Settings → Delete my data removes every profile, check-in, and
setting from your device.
- Settings → Delete account deletes your account and your synced
data from our servers, and removes everything from your device.
You can also email support@twobricklabs.com and
we will delete your account and data for you. Deleting your account does not cancel
an active subscription — manage that in your App Store subscription settings.
Your rights
Depending on where you live, you have some or all of these rights, and we honor
them for everyone regardless of location:
- Access a copy of your personal data (GDPR Art. 15; CCPA right to
know; Australian Privacy Principle 12).
- Correct inaccurate data (GDPR Art. 16; CCPA; APP 13) — you can
edit profiles and settings directly in the app.
- Delete your data (GDPR Art. 17; CCPA right to delete) — built
into the app as described above.
- Portability — receive your data in a machine-readable format
(GDPR Art. 20).
- Restrict or object to processing based on legitimate interests
(GDPR Arts. 18 and 21).
- Withdraw consent at any time (e.g. revoke location permission in
device settings) without affecting the rest of the app.
- Non-discrimination — we never treat you worse for exercising a
privacy right (CCPA/CPRA).
To exercise any right, use the in-app controls or email
support@twobricklabs.com. We respond within one
month (GDPR) or 45 days (CCPA). We may need to verify you control the account, which
we do by confirming access to your sign-in email — we never ask for a password,
because there are none. Since we do not sell or share personal data for advertising,
there is nothing to opt out of under "Do Not Sell or Share"; we also honor Global
Privacy Control signals where applicable.
Security
Measures we take include:
- Row-level security on every synced database table — enforced by the database,
not just the app.
- Passwordless authentication (Apple, Google, or one-time email codes), so there is
no TinyLayers password to steal or reuse.
- Encryption in transit (TLS) for all connections, and encryption at rest at our
database host.
- Secrets and provider keys kept server-side only; weather requests are proxied
through our own server function.
- Least-privilege access, data validation at every boundary, and no logging of baby
names, tokens, or purchase receipts.
No system is perfectly secure, but we design so that a breach of any one layer
exposes as little as possible. If a breach affects your personal data, we will notify
you and the relevant authorities as required by law.
Not medical advice
TinyLayers provides general dressing guidance based on common TOG sleepwear guidance
and safe-sleep recommendations from trusted public health sources. It is not medical
advice, and data in the app is not a medical record. Always consult a health
professional for concerns about your child's health.
Changes to this policy
If we change this policy in a meaningful way, we will update the date at the top and
notify you in the app before the change takes effect. We will never retroactively
reduce your rights over data we already collected without asking you first.
Complaints
We would like the chance to fix any concern first — email
support@twobricklabs.com. You also have the
right to complain to a supervisory authority: in the EU, your national data
protection authority; in the UK, the Information Commissioner's Office (ICO); in
Australia, the Office of the Australian Information Commissioner (OAIC); in the US,
your state Attorney General.
Contact
support@twobricklabs.com