Tootsie Tales is a private, end-to-end encrypted family album. It is built so that a parent or guardian can preserve a child's earliest memories inside a closed family circle, where the content stays readable only to the people they invite. This Privacy Policy explains what personal data we process, why we process it, the legal bases we rely on, who we share it with, and the rights you have. Because the app is designed around a child's memories, the protection of children's data is the throughline of everything described below.
This policy is written primarily under Brazil's Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018). It also addresses the EU General Data Protection Regulation (GDPR) and UK GDPR for users in Europe and the United Kingdom, and the US Children's Online Privacy Protection Act (COPPA) and the California Consumer Privacy Act (CCPA/CPRA) where they apply to you.
1. Who we are
The data controller (in Portuguese, controlador) responsible for your personal data is Francis Gregori Munis Soluções Web e Mobile (Empresário Individual), enrolled under CNPJ 35.654.676/0001-83, established in Brazil. Throughout this policy we refer to this controller as "we", "us", or "the provider".
The product is Tootsie Tales, a native mobile application for iOS and Android, available through the domain tootsietales.app. The product is currently pre-launch.
We have appointed a person responsible for data protection (in Portuguese, encarregado, comparable to a Data Protection Officer). You can reach our privacy contact and encarregado at support@tootsietales.app.
2. Scope and definitions
This policy applies to the Tootsie Tales mobile apps and to the tootsietales.app marketing website. A short, separate section at the end describes the website, because it processes far less data than the app.
A few terms are used throughout:
- Account holder: the adult (a parent or guardian) who creates an account, sets up a private space for a child, and invites others. The account holder must be of legal age.
- Child: the person whose memories are preserved. Children do not create accounts and do not use the app directly. Their data is provided by the account holder.
- Family member and fan/viewer: people the account holder invites. Roles are Admin (owner), Family member (member), and Fan or viewer. Owners control who can view a space and who can add to it.
- Data subject (in Portuguese, titular): the individual to whom the personal data relates, whether the account holder, an invited member, or the child.
- Blind vault: our end-to-end encryption model, under which sensitive content is encrypted on the device before it ever reaches us, so we never hold the keys or the readable content.
3. What data we collect
Account data about adults
When you create and use an account, we process your email address, your display name, an optional profile photo, a cryptographic public key generated for your account, your device push tokens and platform, your notification preferences, your subscription tier and its expiry date, and, if you choose to delete your account, an optional free-text reason you may leave.
Authentication is handled by Firebase Authentication. You can sign in with email and password, with Google, or with Apple.
Data about the child, provided by the parent
To organize a child's timeline, the account holder provides the child's name, birthday, and gender. These three fields are stored as readable metadata, because they are needed to structure and label the timeline.
The heart of the album is the content the family adds about the child: photos, videos, audio, captions, locations, letters, and comments. All of this content is end-to-end encrypted on the device and is unreadable by us. In addition, the app stores growth measurements (height and weight) and milestones, which are kept as readable metadata.
Technical data
We process your device push token and platform to deliver notifications. Your IP address is used only transiently to rate-limit requests and is not stored in a user profile. We keep server error logs to keep the service reliable, and those logs are scrubbed of sensitive data.
Payment data
Subscriptions are processed by the app stores (Apple App Store and Google Play) through RevenueCat. We store only the resulting plan tier and its expiry date. We never receive or store your card details or store receipts.
The Tootsie Tales mobile app contains no third-party advertising and no analytics or tracking SDK. We do not build advertising profiles of you or your child.
4. How we use your data and our legal bases
We process personal data to provide the service you ask for: to create and secure your account, to store and organize the memories you add, to deliver invitations and notifications, to manage your subscription, and to keep the service safe and reliable.
Under the LGPD (articles 7 and 11, and article 14 for children) and, where applicable, the GDPR (articles 6 and 9, and article 8), we rely on the following legal bases (in Portuguese, bases legais):
- Performance of the contract and provision of the service: to operate the account, store your content, and deliver the core features you signed up for.
- Your consent: given by the account holder for the processing that supports the family album, which you can revoke at any time.
- Compliance with legal obligations: where the law requires us to retain or disclose certain data.
- Legitimate interest, for limited operational purposes only: for example, rate-limiting and error monitoring to keep the service secure and available.
For a child's personal data, processing is carried out in the child's best interest and under the responsibility and authorization of the parent or guardian who holds the account, consistent with LGPD article 14 and GDPR article 8.
5. Children's data
Tootsie Tales is intended to be used by adults (parents and guardians) to preserve their own child's memories inside a private circle. Children do not create accounts and do not use the app. We do not knowingly collect personal data directly from children, we do not target advertising to children, and we do not build advertising or behavioral profiles of them.
The account holder is responsible for the content they add about their child and for the family members they choose to invite. When you invite others and share memories about your child, you confirm that you have the authority to do so as the child's parent or guardian.
We handle children's data in line with COPPA (in the United States, for children under 13), LGPD article 14 (Brazil), and GDPR article 8 (EU and UK) as applicable to your situation.
Honest note on age verification: the product relies on the adult account holder's authority and representations. There is no separate automated age-verification flow, and the account holder must be of legal age. If you believe a child has provided us data directly, or that an account was created without proper authority, contact support@tootsietales.app and we will act on it.
6. Encryption and what we can and cannot access
Tootsie Tales is end-to-end encrypted, a model we call a blind vault. Sensitive content is encrypted on your device with AES-256-GCM before it is uploaded, using per-item keys that are wrapped by a per-child group key. The keys stay with your family. We never receive your keys or your readable content.
Recovery is handled with a 10-word recovery phrase, stretched with Argon2id, which protects an encrypted backup of your keys. On iPhone, an unlocking secret may sync through iCloud Keychain to make recovery smoother.
Being transparent about this matters, so here is exactly what we can and cannot read.
Readable by us (metadata)
- The child's name, birthday, and gender.
- Roles and relationships within a family space.
- The kind of an entry, its audience, and its dates.
- Tag names.
- Technical metadata about media: kind, size, type, and a moderation attestation.
- Letter delivery dates.
- Growth values (height and weight).
- Album titles.
- Account data: email, name, profile photo, and subscription state.
Never readable by us
- The bytes of your photos, videos, and audio.
- Captions and locations.
- Comment text.
- Letter titles and bodies.
- Any encryption key.
7. Sharing and subprocessors
We do not sell personal data, and we do not use children's data for advertising or profiling. We share data with the following service providers (subprocessors) strictly to run the service, and each receives only what it needs:
- Google Firebase Authentication: account authentication. Receives your email and authentication identifiers.
- Google Firebase Cloud Messaging: push notifications. Receives device push tokens. Push messages carry no memory content, only generic text and deep-link data.
- Cloudflare R2: encrypted media storage. Receives only opaque ciphertext.
- RevenueCat: subscription management. Receives your account's user identifier and entitlement data. Card and receipt data is handled by Apple and Google, not by RevenueCat on our behalf.
- Resend: sending invitation emails. Receives the invitee's email address, the child's name, the role, and an invite link that never contains a key.
- Sentry: backend error monitoring. Configured not to send personal data and to scrub sensitive values.
- Railway: hosting and database.
- Apple App Store and Google Play: app distribution and subscription billing.
8. International transfers
Some of the providers listed above process data on servers located outside Brazil, which means your data may be subject to an international transfer. When this happens, we commit to using providers that offer adequate safeguards and to putting appropriate contractual protections in place, consistent with LGPD article 33 and Chapter V of the GDPR.
9. Retention and deletion
We keep your content until you delete it. There is currently no fixed automatic retention schedule that removes content after a set period. Invitations, however, expire after a limited time.
You are in control of deletion. From within the app you can delete individual entries, individual media items, and whole children, and you can permanently delete your entire account. Deleting your account is irreversible: it removes your profile, the children you own and all of their content (including deleting the stored encrypted objects), your memberships, your key backup, and your registered devices.
Honest note on retention: because there is no fixed automatic schedule today, content persists until you or another authorized member removes it. If we introduce automatic retention rules in the future, we will update this policy and explain them clearly.
10. Your rights and how to exercise them
Under the LGPD (article 18), as a data subject (titular) you have the right to: confirmation that we process your data; access to your data; correction of incomplete, inaccurate, or outdated data; anonymization, blocking, or deletion of unnecessary or excessive data; portability; information about the entities we share data with; and the ability to revoke consent. If the GDPR, UK GDPR, or CCPA/CPRA applies to you, you have equivalent rights, including access, correction, deletion, portability, and, under CCPA, the right to know and to opt out of any sale (note that we do not sell personal data).
To exercise any of these rights, contact us at support@tootsietales.app. We will verify your request, respond within the timeframes required by applicable law, and let you know if we need more information to act.
On data portability specifically, please be aware of two honest limits. First, there is not yet an automated export feature in the app; if you want a copy of your account data, request it at support@tootsietales.app and we will provide it. Second, because your content is end-to-end encrypted, only your own devices can decrypt your media. We can provide the encrypted objects and the readable metadata we hold, but we cannot decrypt the protected content for you, because we do not have your keys.
If you believe we have not handled your data properly, you have the right to lodge a complaint with the Brazilian data protection authority, the ANPD (Autoridade Nacional de Proteção de Dados), or with your local data protection authority in the EU or the UK.
11. Security
Security is central to how Tootsie Tales is built. We protect your data with:
- End-to-end encryption at rest, the blind vault described above.
- TLS encryption for data in transit.
- Strict access controls, so that people who are not members of a space cannot even see that a child exists.
- Per-IP rate limiting to reduce abuse.
- On-device content moderation before upload.
- Screenshot protection within the app.
- Careful handling of secrets and keys.
No system is perfectly secure. However, because sensitive content is encrypted on your device, a breach of our systems would expose only ciphertext for the protected fields, not your readable memories.
12. The marketing website
The tootsietales.app landing site is separate from the app and processes much less data. When you join the waitlist, we collect your email address and store it so we can notify you at launch. We use privacy-respecting product analytics and a Google advertising tag to measure interest in the product.
The website uses cookies and local storage for your language preference and for analytics. You can control cookies through your browser settings.
13. Changes to this policy
We may update this policy as the product evolves or as the law requires. When we make a material change, we will update the date at the top of this page and, where appropriate, notify you through the app or by email. The current version always governs.
14. How to contact us
For any privacy question, to reach our encarregado (data protection officer), for legal notices, or for help with the product, write to support@tootsietales.app.