Privacy Policy

Last updated: September 2026

App privacy, optional network services and local family data.

1. About this policy

Danilo Gonçalo Silvestre Sebastião, an independent operator in Portugal trading as From Tiny Hands, is responsible for the data practices described here. This policy explains the data practices of the From Tiny Hands mobile app. The marketing website and Shopify store are separate services: visiting them sends network information to their hosting providers, and purchases or support requests can involve information you choose to provide. This policy is a description of our practices, not a certification of legal compliance.

2. Local family profiles

No online account is required. A grown-up may create local child profiles containing a name or nickname, age, avatar and ingredient or support preferences. These fields stay on the device and are not automatically attached to Kitchen Chat or narration requests. Do not enter unnecessary sensitive information.

3. What stays on your device

Family profiles, recipe progress, journal entries, planner, milestones, game statistics, settings and saved kitchen photos are kept locally. Photos are stored in IndexedDB. There is no public feed or child-to-child messaging. Device or iCloud backups are controlled by your device settings.

4. Optional Kitchen Chat

Kitchen Chat is a grown-up cooking helper. After consent, questions are sent over HTTPS through Lovable hosting and Lovable AI Gateway to an OpenAI model. Requests include cooking text, app language and generic recipe context. No profile, profile ID, avoid-list or photo is attached. Updated versions send only the current question; older versions may include recent chat messages. Do not type names, ages, contact details, health information or other personal information: a text filter cannot detect every personal detail. In bundled-audio releases, leaving Chat off prevents background requests to our AI and audio services. Older app versions may still make narration requests.

5. Narration and audio

Bundled-audio releases play pre-generated narration and kitchen sound files stored inside the app. ElevenLabs is used before release to generate authored instructions, vocabulary and fixed sound effects, not to process end-user narration requests in those releases. Older versions may still request generated audio through our backend. No child voice recording is uploaded, and the app does not use the microphone to record children. Unrecognized legacy phrases may use device speech.

6. Network information and external services

Like any internet request, calls to our backend expose an IP address and HTTP headers, including user-agent information, to Lovable hosting and its Cloudflare security infrastructure. Cloudflare may set a short-lived bot-protection cookie; it is not an advertising cookie. The current backend does not read or store IP addresses for application rate limiting. Hosting and security-provider logs remain separate from our application code. Its explicit AI and speech-provider payloads do not include the user’s IP address, child profiles, advertising identifiers or a persistent user identifier. Lovable, Cloudflare, Lovable AI Gateway, OpenAI and ElevenLabs process requests according to their applicable terms and privacy policies. A specific processing region or zero-retention arrangement is not guaranteed by this policy.

7. Payments

Subscriptions use Apple In-App Purchase. Apple processes purchases and restores; the app reads product prices and subscription entitlement/transaction information. We do not receive payment card numbers or billing addresses. Apple subscription billing is not attached to a child profile. Deleting local data does not cancel an Apple subscription.

8. Advertising, analytics and parental access

The audited app contains no advertising SDK, third-party behavioral analytics SDK, IDFA access, cross-app tracking or public user-generated content. We do not sell app data or share it for advertising. Grown-up areas, purchasing opportunities, Kitchen Chat and outgoing legal/support/shop links are protected by a parental gate. Parental gating does not itself constitute verifiable parental consent under every applicable law.

9. Retention and deletion

Local records remain until removed by the user or the app is deleted; backups can remain under your device or backup settings. Use the Parent Hub’s Delete Everything control to reset local family data, and the album’s delete controls to remove individual photos. Updated versions also erase the photo database before completing Delete Everything. Chat messages are held in screen memory rather than an app conversation database. Requests set store:false for AI response storage, but that is not a promise of zero provider logs. Provider security, operational and legal retention may apply; no fixed retention period has been confirmed for this deployment. Local deletion cannot erase provider logs or cancel Apple subscriptions.

10. Your choices and contact

Core picture-led cooking works without Kitchen Chat. You can decline or withdraw chat consent in the grown-up settings and turn narration off. If you contact support, the message and contact details you supply are processed to answer you. For privacy questions or requests, email hello@fromtinyhands.com, call +351 935 658 980, or write to Apartado 000013, EC Odivelas, 2676-901 Odivelas, Portugal. This is a correspondence address.

11. Changes

We update this page when app data practices change. Review the app’s release notes and keep the installed app updated. Material changes will be reflected in this policy.