Privacy Policy

Last updated: July 5, 2026

TinyLayers helps parents decide what their baby should wear. This policy explains, in plain English, what data the TinyLayers app collects, why, where it goes, and what your rights are. The short version: we collect the minimum we need, we never sell your data, we show no ads, and we use no advertising or analytics trackers.

Who we are

TinyLayers is the data controller for the personal data described in this policy. You can reach us at support@twobricklabs.com for any privacy question or request.

What we collect

We collect only what the app needs to work:

What we do not collect

Children's data — how we handle it

TinyLayers necessarily processes information about infants (a first name or nickname, age band, optional birthdate, and comfort check-ins), because that is what the app is for. This data is always entered and controlled by the parent or guardian, who is our user. We treat it as sensitive: it is protected by row-level security so only your account can read it, it stays in the EU (see below), it is never used for advertising or profiling, never sold, and you can delete it at any time from inside the app. We deliberately do not require a real name or exact birthdate — an age band and a nickname are enough for the app to work.

How we use your data (purposes and legal bases)

We do not use your data for advertising, we do not build marketing profiles, and we do not carry out automated decision-making with legal or similarly significant effects.

Where your data lives

TinyLayers is local-first: your data is stored on your device. If you use Premium sync, your data is also stored in our Supabase database hosted in the European Union (AWS eu-west-2, London, United Kingdom). Every synced table is protected by row-level security, meaning the database itself enforces that only your signed-in account can read or write your rows.

Service providers (processors)

We share data only with the providers we need to run TinyLayers, and only the minimum each one needs:

We never sell or rent personal data, we do not "share" personal data for cross-context behavioral advertising (as defined by California law), and no third party is allowed to use your data for its own purposes.

App Store privacy label summary

We keep our App Store privacy answers aligned with this policy. Based on the current app design, the data categories we expect to disclose are:

We do not collect Other User Contact Info such as phone numbers or postal addresses. We also do not currently collect Crash Data or Performance Data through our own crash or performance SDK; if that changes, we will update both this policy and the App Store privacy label before release.

International transfers

Your synced data is stored in the EU/UK. Some of our providers (RevenueCat, Resend, and Apple/Google for sign-in and payments) process limited data in the United States. Where personal data leaves the EEA, the UK, or a country with an adequacy decision, we rely on appropriate safeguards — primarily the European Commission's Standard Contractual Clauses (and the UK Addendum / International Data Transfer Agreement), and, where a provider is certified, the EU–US Data Privacy Framework. You can request a copy of the relevant safeguards at support@twobricklabs.com.

How long we keep data

Account and data deletion

You can delete everything from inside the app — no email required:

You can also email support@twobricklabs.com and we will delete your account and data for you. Deleting your account does not cancel an active subscription — manage that in your App Store subscription settings.

Your rights

Depending on where you live, you have some or all of these rights, and we honor them for everyone regardless of location:

To exercise any right, use the in-app controls or email support@twobricklabs.com. We respond within one month (GDPR) or 45 days (CCPA). We may need to verify you control the account, which we do by confirming access to your sign-in email — we never ask for a password, because there are none. Since we do not sell or share personal data for advertising, there is nothing to opt out of under "Do Not Sell or Share"; we also honor Global Privacy Control signals where applicable.

Security

Measures we take include:

No system is perfectly secure, but we design so that a breach of any one layer exposes as little as possible. If a breach affects your personal data, we will notify you and the relevant authorities as required by law.

Not medical advice

TinyLayers provides general dressing guidance based on common TOG sleepwear guidance and safe-sleep recommendations from trusted public health sources. It is not medical advice, and data in the app is not a medical record. Always consult a health professional for concerns about your child's health.

Changes to this policy

If we change this policy in a meaningful way, we will update the date at the top and notify you in the app before the change takes effect. We will never retroactively reduce your rights over data we already collected without asking you first.

Complaints

We would like the chance to fix any concern first — email support@twobricklabs.com. You also have the right to complain to a supervisory authority: in the EU, your national data protection authority; in the UK, the Information Commissioner's Office (ICO); in Australia, the Office of the Australian Information Commissioner (OAIC); in the US, your state Attorney General.

Contact

support@twobricklabs.com