Tiptoe is a baby development journal from Ebenezer Labs LLC, Pennsylvania, United States. We are responsible for the personal information we handle through Tiptoe. This policy explains what stays on your iPhone, what goes to our service providers, and the choices you have.
For privacy questions or requests, email support@ebenezerlabs.ai or visit Tiptoe Support.
1. Information we handle and why
- Your account: your email address, name when supplied, account identifier and sign-in session information. These let you sign in and connect your record to your account.
- Your child's profile: the name or nickname, birth date, due date, sex and age preferences you enter. Tiptoe uses these to organize the record and show age-matched developmental context.
- Your observations: answers, developmental observations, dates, notes and corrections. These build your child's journal and the summaries you see. Saved questions, calendar entries and generated reports are also part of your device record.
- Optional photos: images you choose to attach to observations. Tiptoe removes location and other sensitive embedded image metadata before saving them. The people and details visible in the image remain.
- Purchases: subscription and access status supplied by Apple. Apple handles payment; we do not receive your payment-card details.
- Service and support information: sign-in and delivery logs, sync and deletion records, and messages you send us. These help operate the service, resolve problems, prevent abuse and respond to requests.
Optional app diagnostics are off by default and stay on the device. They exclude child names, dates, notes, photos and sign-in secrets. We may receive aggregate App Store reports from Apple, not advertising profiles linked to your child's record.
We do not sell your personal information, share it for targeted advertising, or use it for ads or cross-app tracking.
2. What stays on your iPhone
You can use Tiptoe without creating a Tiptoe account. Your record is saved on your iPhone first. Connecting an account and allowing your child's data into cloud storage are separate choices. If you allow cloud storage, child profiles, observations and notes are sent to our backend, and optional photos can be uploaded to private storage. This is not a promise that every part of your device record is backed up.
Saved questions, calendar entries and generated reports remain local or in files you export; they are not part of that sync. Notifications and optional diagnostics are local too. Family is a local view of saved records and appointment notes; it does not send invitations or share data with other people. If you share an exported card or file yourself, the recipient receives a separate copy.
3. Service providers and US hosting
- Supabase: hosts our account system, cloud database and private photo storage. Our project's primary region is US East, Ohio.
- Resend: delivers sign-in and account-security emails through US East, North Virginia. It receives your email address, email content such as a sign-in code, and delivery information—not your child's journal for this purpose.
- Apple and Google: provide sign-in when you choose their sign-in option. Their own privacy terms also apply to their identity services. Apple separately handles App Store subscriptions and billing.
Our hosting and email providers use other providers to deliver their services. Their support, security and other processing may take place outside the primary hosting region. We may also disclose information when required by law or when necessary to protect people's safety, investigate misuse or secure the service.
If you live outside the United States, using cloud features involves transferring information to the United States, where privacy laws may differ. Supabase's and Resend's data-processing agreements include standard contractual clauses for applicable international transfers, including UK adaptations. These are contractual safeguards for personal information; they do not mean all processing stays in your country. Read the Supabase agreement and Resend agreement, or contact us for information about safeguards relevant to your request.
4. How long we keep information
We keep your cloud account and journal information while your account exists, unless you ask us to delete it. There is no automatic deletion just because you stop using the app. Device-only information remains until you remove it using the app's data controls.
In-app account deletion promptly restricts access to your cloud record when the service accepts the request and queues it for removal. Clearing live database rows, private photos and the sign-in account is a separate cleanup process; it can still be pending after your device has been cleared. Contact us if a request fails or you need confirmation of completion.
Our daily database backups have a seven-day retention window. Database information saved before live deletion can remain in those backups until it ages out of that window. Database backups contain photo-storage metadata, not the photo files themselves. Seven days is not a promise that every copy held by every provider is erased within seven days of your request.
Sign-in, security, email-delivery and support records are separate from the journal and its database backups. We keep information needed to handle a request, protect the service or meet a legal obligation only as long as needed for that purpose. Providers also have their own operational retention rules. We cannot remove copies of files you have exported or shared from someone else's device.
5. Access, export, correction and deletion
Open Today → profile → Your data for device export and deletion controls. Signed-in users can also request a cloud export or account deletion. Account and data controls are available through Manage account & data during account setup and on the paywall; you do not need to buy a new subscription to make a privacy request.
- Review and correct your child's profile and observations in the app.
- Prepare a device data export, then choose whether to share the file. Cloud exports are separate and do not include photo files or every sign-in-provider record. Contact us for help accessing information not included in an export.
- Turn off child-cloud permission to stop future consent-gated sync. This does not erase information already in the cloud; use account deletion for that.
- Use the signed-in account deletion control to request cloud removal. Deleting only local data or uninstalling the app does not delete your cloud account.
- Cancel subscriptions separately through Apple. Deleting your Tiptoe account does not stop Apple billing.
For access, correction, export or deletion help, email support@ebenezerlabs.ai. We may ask for enough information to verify your identity and authority to act for a child, but do not send passwords, sign-in codes, a child's photos or a full journal export in your first message.
EU and UK residents: where applicable, you can ask to access, correct, erase or receive a portable copy of personal information, restrict its use, or object to processing. Where processing relies on consent, you can withdraw it without affecting processing before withdrawal. You can also complain to your local data-protection authority.
California residents: where applicable, you can ask what personal information we collect, use or disclose, request a copy, and ask for correction or deletion. You have rights to opt out of sale or sharing for cross-context behavioral advertising and to limit certain uses of sensitive information. We do not sell or share information for those advertising purposes or use your child's information for advertising. We will not discriminate against you for exercising a privacy right.
An authorized representative can contact us on your behalf; we may need proof of their authority. We respond within the deadlines required by applicable law and explain any lawful exception or extension. If you disagree with our response, reply to the same address and ask us to review it.
6. Children's privacy
Tiptoe is for adult parents and authorized caregivers, not for children to operate. The adult is the account holder; information about a child is entered by that adult. You must have authority to provide and manage the child's information.
We do not knowingly collect personal information directly from children. If you believe a child has created an account or provided information directly, contact us so we can investigate and remove it as appropriate. Parents and guardians can use the controls and contact route above to manage their child's information.
7. Security
Tiptoe uses encrypted connections, access controls around cloud records, private photo storage and iOS-protected local files. Uploaded photos are not public. Cloud storage is not end-to-end encrypted: authorized service administration can access information to operate and protect the service. No system is completely secure. Report suspected unauthorized access to support@ebenezerlabs.ai without including sign-in secrets or private child content.
8. Changes to this policy
We will update this page and its effective date when our practices change. For significant changes, we will also provide a notice in the app or by email where appropriate, and ask for consent when required. You can always find this policy from Tiptoe Support.