TinyNurture

Privacy Policy

Version: 0.1 Beta
Last updated: 14 August 2026

This policy describes processing in the free, invitation-only TinyNurture Beta for adults. It is limited to the app scope currently reviewed. Child features, subscriptions, advertising and referral programmes are not part of this Beta.

This policy describes the invitation-only adult Beta. The current public release is limited to Switzerland; Germany is not enabled.

1. Controller

Anqi Hu, trading as TinyNurture
Privacy: [email protected]
Support: [email protected]

The postal address and further provider information are available in the Legal notice.

2. Data TinyNurture processes

3. Purposes and legal bases

We process data to provide the requested account and app features, transcribe speech, analyse photos and entries, generate personal views, provide support, detect abuse and security incidents, and comply with law.

Where the GDPR applies, the legal bases include performance of a contract or pre-contract steps, explicit consent for health data, legitimate interests in secure and reliable Beta operation, and legal obligations. Under Swiss data-protection law, data is processed in accordance with legality, proportionality, purpose limitation and transparency.

Consent for health data is separate from acceptance of the Terms. It may be withdrawn for the future, although affected functions can then stop working.

4. HealthKit

TinyNurture requests only permissions needed for visible functions. HealthKit permissions can be changed in Apple settings. TinyNurture does not use HealthKit data for advertising, marketing, data brokerage, or credit or insurance decisions.

The app can write water to HealthKit when the user activates the relevant TinyNurture function. Apple processes HealthKit data under its own terms; TinyNurture does not receive general access to the user's complete Apple Health database.

5. AI, photos and voice

Text, selected health summaries and photos may be sent to an AI processing service engaged by us to produce the analysis or response requested by the user. The provider may use this data only to deliver and secure the service, and not for its own advertising or independent model training, unless we expressly agree otherwise and have the required legal basis.

An intentionally recorded audio file may be sent to a speech-to-text service engaged by us. Processing takes place in the United States. Organization-level Zero Data Retention is enabled: the provider does not retain the audio, transcript input or output after inference for reliability or abuse monitoring. The provider retains service-usage metadata that does not contain customer inputs or outputs.

Data is sent only when the user deliberately uses the relevant feature and, where required, after the user has given explicit consent. Before the first transfer, the app explains what data will be sent to an external AI or speech service and for what purpose.

AI outputs and nutrition figures are estimates. They have no legal or medical decision effect and are not used for solely automated decisions producing legal or similarly significant effects.

6. Service providers and locations

For transfers outside Switzerland, the EEA or an adequate country, we use recognised safeguards where required, including adequacy decisions, the Swiss-U.S. or EU-U.S. Data Privacy Framework and Standard Contractual Clauses. The applicable safeguard depends on the provider and contract.

We maintain an internal, current register of the providers used, processing locations and safeguards. Further information about current recipients and safeguards may be requested from [email protected].

7. Retention

8. Security

TinyNurture uses encrypted transport, separate user identifiers, server-side access controls, databases that are not publicly exposed, and encrypted backups. No system is completely secure. Report suspected security issues to [email protected] without sending sensitive details over an insecure channel.

9. Rights and choices

Depending on applicable law, users may have rights of access, correction, data copy, deletion, restriction, objection, withdrawal of consent and complaint to a supervisory authority. Requests may be sent to [email protected]. We may request reasonable identity verification.

Until complete in-app deletion and export are released, those requests will be handled through this contact. Legal retention duties and the rights of others may limit immediate or complete deletion.

10. Adults only; no child data

The current Beta is for people aged 18 or older. Users must not create a child account or submit a child's health information during this Beta. If we become aware of such data, we may delete it and suspend the account.

11. Website

This website uses no analytics, advertising or tracking cookies. When a page is requested, hosting and security providers process technically necessary connection data such as IP address, request time, requested page and browser information to deliver the site and prevent attacks.

12. Changes and complaints

We update this policy when features, providers or processing locations change. Material changes will be communicated in the app or by email where required.

For privacy questions, first contact [email protected]. The Swiss Federal Data Protection and Information Commissioner is the competent Swiss authority. Any EU representative required by Article 27 GDPR must be appointed and added here before public release in Germany.