Tukko Privacy Policy

Version: v1.5, updated 2026-08-23 — internal working notes and links to non-public files removed from the text; sub-processor DPA status corrected to reflect reality (standard terms accepted at sign-up, not separately negotiated agreements). The sub-processor registry is available in-app under "More → Settings → Privacy & data".

The previous version v1.4 (2026-08-22) brought operator details in line with the closed-testing reality and corrected the date-of-birth statement (only a coarse age is collected). Effective date: 2026-06-04 Last updated: 2026-08-23


1. Who we are

⚠️ Status: closed testing. Tukko is not publicly released; it is distributed to a limited group of testers by personal invitation. At this stage the operator is a private individual; no legal entity has been incorporated. Full operator details (legal entity, jurisdiction, postal address) will appear here before public release.

Tukko is a children's daily-schedule app. This policy explains what data we collect, why, and how to exercise your rights under COPPA (United States), GDPR / GDPR-K (European Union), and other applicable laws.

If you have questions, contact us at privacy@tukko.eu.

Formal risk assessment: We maintain a Data Protection Impact Assessment (DPIA) under GDPR Article 35 — required because Tukko processes children's data. The full DPIA is available on request at the address in §14. It enumerates every processing category, the legal basis for each, the risks to data subjects, and the concrete mitigations we have in place. It is the same document we file with EU data protection authorities on request.

2. Who this policy applies to

3. What data we collect

CategorySourcePurposeLegal basis
Email addressParent provides at sign-upAccount auth, parental consent confirmation, account-recovery emailContract (Art 6(1)(b) GDPR), consent (Art 6(1)(a) for COPPA)
Display nameParent providesPersonalisationContract
Child first name / display nicknameParent providesSchedule displayConsent (Art 6(1)(a) + COPPA §312.5)
Child age in years (optional)Parent providesJurisdictional digital-consent-age tracking (FR-071)Legitimate interest (Art 6(1)(f))
Schedule data (daily blocks, todos, rewards, points)Parent + child enterCore product functionContract
Chat messages (parent ↔ child, parent ↔ co-parent)Users sendFamily communicationContract
Avatar image (optional)Parent uploadsProfile personalisationConsent (Art 6(1)(a))
Authentication logs (sign-in events, hashed user_id, IP-prefix)Auto-collectedFraud detection, COPPA §312.8 record-keepingLegitimate interest (LIA available on request)
Crash reports (parent sessions ONLY)Sentry SDKDiagnose crashesConsent (Art 6(1)(a)) — OFF by default; opt-in via Privacy panel
Product analytics events (parent sessions ONLY)PostHog SDKUnderstand feature usage to improve the productConsent (Art 6(1)(a)) — OFF by default; opt-in via Privacy panel

We do NOT collect:

3.1 Crash reports (crash_reports scope)

When this scope is enabled, Tukko's Sentry SDK captures crash and error reports from parent sessions only. A typical report contains: stack traces, OS version, app version, anonymous install ID, and the screen route where the crash occurred. A built-in PII scrubber removes sensitive keys (emails, child names, schedule content, chat messages) before the event leaves the device.

3.2 Product analytics (analytics scope)

When this scope is enabled, Tukko sends anonymous product-analytics events to PostHog from parent sessions only. We use these events to understand which features are used, where parents get stuck, and how to prioritise improvements. We do not use these events for advertising and we never sell them.

4. How children's data is protected

Parents may withdraw consent at any time via Settings → Privacy → Revoke and delete account, or via the link in the consent-followup email. Withdrawal deletes the child's data within 30 days.

5. Who we share data with (sub-processors)

The live, versioned registry of every Tukko sub-processor is available in the app: "More → Settings → Privacy & data → Sub-processors". The table below is a snapshot at the time this policy version was published and may lag the live registry by up to one publish cycle. (A public web address will follow together with the domain, before public release.) For GDPR Art 28(2) purposes — including the 30-day notice of any new sub-processor — refer to the live page. Parents can subscribe to email notifications about new sub-processors in Settings → Privacy → "Notify me about new sub-processors" (spec 042).
Sub-processorRoleRegionSub-sub-processorsDPA
SupabaseDatabase, Auth, Storage, Edge FunctionsEU (Frankfurt)AWS, CloudflareNo separate DPA signed — deferred until incorporation
GoogleSign-In with GoogleGlobalNo separate DPA signed — deferred until incorporation
AppleSign in with Apple, APNsGlobalApple Developer Program terms
ExpoPush notifications, OTA updatesUSFCM, APNsNo separate DPA signed — deferred until incorporation
Sentry — Functional Software, Inc.Crash reporting (parent opt-in only — see §3.1)EU regionNo separate DPA signed — deferred until incorporation
PostHog — PostHog Inc.Product analytics (parent opt-in only — see §3.2)EU regionNo separate DPA signed — deferred until incorporation
ResendTransactional email (consent confirmation, data export delivery)EUDPA not signed — execution deferred until incorporation

We do not sell personal data and do not share it for behavioural advertising.

6. International data transfers

Tukko's primary data store is in the EU (Supabase Frankfurt region). Transfers to non-EU sub-processors rely on Standard Contractual Clauses (SCC Module 2) and the supplementary measures set out in our Transfer Impact Assessment (Schrems II / EDPB Recommendations 01/2020), available on request.

7. How long we keep data

DataRetentionReason
Account + schedule + chatLifetime of account + 30 days after deletion requestContract
Parental consent records7 yearsCOPPA §312.8 record-keeping
Authentication audit log7 yearsLegitimate interest — fraud detection (LIA available on request)
Data export ciphertext7 days from generationSingle-use security model
Crash reports90 days at SentrySentry default
Product analytics eventsPer PostHog project retention (operator-configured)PostHog default; deletable on demand via /engage (see §3.2)

The full retention schedule is available on request at the address in §14.

8. Your rights

You have the right to:

To exercise these rights, use the in-app controls or email privacy@tukko.eu. We respond within 30 days.

9. Children's rights (COPPA + GDPR-K)

In addition to the rights above, parents may:

10. Security measures

11. Changes to this policy

When we materially change this policy, we will:

For non-material changes (typo fixes, contact updates), we may publish without re-consent but will still log the new hash.

12. Tracking technology declaration

Tukko does NOT use:

Tukko does use a first-party product-analytics SDK (PostHog) to understand feature usage — strictly opt-in, parent sessions only, tied to a random device identifier, and never used for advertising. See §3.2 for the full description.

This declaration maps to Apple App Privacy "Data Not Linked to You" / "No Tracking" and Google Play Data Safety "No data shared for advertising".

13. Apple Kids Category contingency

If Tukko is published under Apple's Kids Category (versus Productivity), additional restrictions apply: crash reporting and product analytics are disabled on all sessions (including parents), and certain external link flows are gated through a parental challenge.

14. Contact

For privacy questions or to exercise your rights:

Breach notifications: we notify affected users within 72 hours of becoming aware of a personal-data breach, per GDPR Art 33–34.


Version v1.5, 2026-08-23. The current text is always available at this address; we announce material changes in the app and ask for consent again.