Privacy Policy
Version: 0.1 Beta
Last updated: 14 August 2026
This policy describes processing in the free, invitation-only TinyNurture Beta for adults. It is limited to the app scope currently reviewed. Child features, subscriptions, advertising and referral programmes are not part of this Beta.
This policy describes the invitation-only adult Beta. The current public release is limited to Switzerland; Germany is not enabled.
1. Controller
Anqi Hu, trading as TinyNurture
Privacy: [email protected]
Support: [email protected]
The postal address and further provider information are available in the Legal notice.
2. Data TinyNurture processes
- Account and sign-in data: internal user identifier, email or Apple relay address, sign-in provider, sign-in times, and security-related IP and device information.
- Conversations and entries: messages, transcripts, replies, time context, feedback and derived records such as meals, water, activity, sleep, symptoms, mood or body weight.
- Selected HealthKit summaries: with permission, short-window averages or totals for sleep duration, steps, resting heart rate, heart-rate variability, active energy, workout count and body weight. Raw HealthKit samples, exact HealthKit timestamps and workout routes are not uploaded to TinyNurture.
- Photos: food photos selected by the user, technical image information, and generated descriptions and nutrition estimates. The app removes GPS metadata before upload where the implemented image preparation succeeds.
- Voice: an intentionally recorded audio file is transmitted for transcription. TinyNurture does not persist the audio file in its own backend after the request; the transcript can become part of the conversation.
- Calendar: calendar commitments are currently displayed on the device. Titles and details are not uploaded automatically.
- Technical data: app and operating-system version, error and security events, request time, IP address and similar connection data where required to operate and protect the service.
- Support data: emails and materials a person voluntarily provides in a request.
3. Purposes and legal bases
We process data to provide the requested account and app features, transcribe speech, analyse photos and entries, generate personal views, provide support, detect abuse and security incidents, and comply with law.
Where the GDPR applies, the legal bases include performance of a contract or pre-contract steps, explicit consent for health data, legitimate interests in secure and reliable Beta operation, and legal obligations. Under Swiss data-protection law, data is processed in accordance with legality, proportionality, purpose limitation and transparency.
Consent for health data is separate from acceptance of the Terms. It may be withdrawn for the future, although affected functions can then stop working.
4. HealthKit
TinyNurture requests only permissions needed for visible functions. HealthKit permissions can be changed in Apple settings. TinyNurture does not use HealthKit data for advertising, marketing, data brokerage, or credit or insurance decisions.
The app can write water to HealthKit when the user activates the relevant TinyNurture function. Apple processes HealthKit data under its own terms; TinyNurture does not receive general access to the user's complete Apple Health database.
5. AI, photos and voice
Text, selected health summaries and photos may be sent to an AI processing service engaged by us to produce the analysis or response requested by the user. The provider may use this data only to deliver and secure the service, and not for its own advertising or independent model training, unless we expressly agree otherwise and have the required legal basis.
An intentionally recorded audio file may be sent to a speech-to-text service engaged by us. Processing takes place in the United States. Organization-level Zero Data Retention is enabled: the provider does not retain the audio, transcript input or output after inference for reliability or abuse monitoring. The provider retains service-usage metadata that does not contain customer inputs or outputs.
Data is sent only when the user deliberately uses the relevant feature and, where required, after the user has given explicit consent. Before the first transfer, the app explains what data will be sent to an external AI or speech service and for what purpose.
AI outputs and nutrition figures are estimates. They have no legal or medical decision effect and are not used for solely automated decisions producing legal or similarly significant effects.
6. Service providers and locations
- European hosting and storage services: operation of the app, database, primary storage and backups. Core app data is stored in the EU, currently in Germany.
- AI processing services: processing of text, selected health summaries and photos. European processing locations are used for supported functions. Any change of model or location is reviewed before use.
- Authentication services: account sign-in and security. Certain sign-in data may be processed in the United States.
- Speech-to-text services: transcription of intentionally recorded audio. Processing may take place in the United States.
- Network, security and website services: DNS, secure delivery, protection against attacks and technically necessary connection logs. Depending on network routing, technical processing may also occur outside Switzerland and the EEA.
- Device and platform services: operating system, app distribution, device sign-in and health functions authorised by the user, under the terms of the relevant platform provider.
For transfers outside Switzerland, the EEA or an adequate country, we use recognised safeguards where required, including adequacy decisions, the Swiss-U.S. or EU-U.S. Data Privacy Framework and Standard Contractual Clauses. The applicable safeguard depends on the provider and contract.
We maintain an internal, current register of the providers used, processing locations and safeguards. Further information about current recipients and safeguards may be requested from [email protected].
7. Retention
- Account data, messages, transcripts, user-approved derived events and photo-analysis results are retained until account deletion or earlier user deletion, unless law requires limited retention.
- Server health summaries have a maximum rolling retention of 90 days.
- Raw photos are deleted immediately after successful analysis. Failed, abandoned or unlinked raw photos have a maximum retention of one hour. Technical enforcement and tests remain a release requirement.
- TinyNurture does not retain audio in its own backend after the transcription request. Organization-level Zero Data Retention is enabled at the speech-to-text provider as described in Section 5.
- Account and associated active data are deleted within seven days after a valid deletion request. Encrypted backups expire on a rolling 30-day basis and deleted data is not restored to production.
- Production security and application logs have a maximum retention of 30 days, except evidence isolated under a documented legal or incident hold.
- Closed support and privacy requests are retained for up to 24 months. Restricted consent and policy-acceptance evidence may be retained for the account lifetime plus three years where needed to demonstrate compliance or handle claims.
8. Security
TinyNurture uses encrypted transport, separate user identifiers, server-side access controls, databases that are not publicly exposed, and encrypted backups. No system is completely secure. Report suspected security issues to [email protected] without sending sensitive details over an insecure channel.
9. Rights and choices
Depending on applicable law, users may have rights of access, correction, data copy, deletion, restriction, objection, withdrawal of consent and complaint to a supervisory authority. Requests may be sent to [email protected]. We may request reasonable identity verification.
Until complete in-app deletion and export are released, those requests will be handled through this contact. Legal retention duties and the rights of others may limit immediate or complete deletion.
10. Adults only; no child data
The current Beta is for people aged 18 or older. Users must not create a child account or submit a child's health information during this Beta. If we become aware of such data, we may delete it and suspend the account.
11. Website
This website uses no analytics, advertising or tracking cookies. When a page is requested, hosting and security providers process technically necessary connection data such as IP address, request time, requested page and browser information to deliver the site and prevent attacks.
12. Changes and complaints
We update this policy when features, providers or processing locations change. Material changes will be communicated in the app or by email where required.
For privacy questions, first contact [email protected]. The Swiss Federal Data Protection and Information Commissioner is the competent Swiss authority. Any EU representative required by Article 27 GDPR must be appointed and added here before public release in Germany.