Tiptoe is a baby milestone journaling and educational application from Ebenezer Labs LLC (“Ebenezer Labs,” “we,” “us,” or “our”). This draft explains the information Tiptoe is designed to handle, why it is used, and the controls available to an adult account holder.
Tiptoe is for parents and other authorized adult caregivers. It is not directed to children and does not permit a child to create an account.
1. Information Tiptoe Handles
1.1 Adult account and family information
- Account identifiers and sign-in information supplied through approved identity providers.
- Family membership, invitation status, and owner, caregiver, or viewer role.
- Subscription and entitlement status supplied by the applicable app store.
1.2 Baby profile and milestone information
- A nickname, optional avatar, birth date, due date when corrected age is used, and selected milestone interests.
- Milestone check-ins, first-seen dates, notes, corrections, saved questions, saved insights, appointments, and report history.
- Caregiver attribution and timestamps needed to show who added or changed shared information.
1.3 Optional private media
If private milestone photos are enabled and you choose to attach one, Tiptoe is designed to rewrite the image and remove GPS plus sensitive EXIF, TIFF, and IPTC metadata before persistence. Private media is not intended to be public. The production feature will remain disabled until private storage, signed access, revocation, retention, and deletion propagation are verified.
1.4 Diagnostics and analytics
Tiptoe is designed to use a restricted event taxonomy for product and reliability measurement. Child names, dates, notes, milestone content, photos, authentication tokens, and arbitrary free text are prohibited from analytics payloads. Analytics consent defaults off. Any production crash, performance, or analytics provider will be disclosed before it is enabled.
2. How Information Is Used
- To calculate chronological or corrected age and personalize milestone context.
- To save check-ins and derive Today, Calendar, Insights, Messages, and reports.
- To let authorized adults collaborate under explicit roles and permissions.
- To provide subscriptions, local notifications, exports, deletion, security, support, and service reliability.
- To comply with law, enforce our terms, investigate security incidents, and protect users and the service.
We do not sell child or family information. Tiptoe is not designed for behavioral advertising or cross-app tracking.
3. Local Storage and Future Cloud Sync
Tiptoe is local-first. Sensitive local files are designed to use iOS Data Protection and backup exclusion where appropriate. When production account and Family features are enabled, authorized data will be transmitted over encrypted connections to the documented Tiptoe backend so it can synchronize across approved devices and family members. Private child media will use private—not public—storage.
4. Sharing and Service Providers
Information may be shared with family members you authorize and with service providers needed to operate authentication, hosting, storage, app-store subscriptions, notifications, security, diagnostics, and support. Providers may process information only for contracted service purposes. We may also disclose information when required by law or necessary to protect rights, safety, and service integrity.
5. Your Controls
- Edit or delete baby and milestone information in the app.
- Export locally held Tiptoe data.
- Revoke a family member’s access when you have permission to manage membership.
- Control local notification categories, times, and quiet hours.
- Control optional analytics consent.
- Request account and server-data deletion once production accounts are enabled.
Production deletion will not be represented as complete until local data and applicable authentication, database, private storage, notification, analytics, and entitlement records have reached their documented terminal state or a legally required retention exception is disclosed.
6. Retention
Local data remains on the device until you delete it, delete the relevant baby, or delete all Tiptoe data. Production server retention periods, backup treatment, audit-record exceptions, and verified-deletion timelines must be approved and inserted here before this notice becomes effective.
7. Security
Tiptoe is designed with deny-by-default authorization, baby-scoped access, private media paths, device-protected local files, restricted analytics, and auditable deletion boundaries. No system can guarantee absolute security. Security concerns can be reported to security@ebenezerlabs.ai.
8. Educational and Health Boundary
Tiptoe provides educational milestone context and parent-controlled journaling. It does not diagnose, predict development, replace professional medical advice, or determine whether a child is “normal,” ahead, or behind. Contact a qualified healthcare professional about health or developmental concerns.
9. Children’s Privacy
Tiptoe stores information about a baby only when entered by an authorized adult account holder. A child cannot create or manage a Tiptoe account. The final age, consent, and child-data provisions require legal review before launch.
10. Contact and Rights Requests
Ebenezer Labs LLC
Privacy and legal: legal@ebenezerlabs.ai
Product support: support@ebenezerlabs.ai
Website: https://ebenezerlabs.ai
Jurisdiction-specific privacy rights, appeal procedures, controller address, subprocessors, international transfer terms, retention periods, and effective date must be finalized through legal review.