Version: v1.5, updated 2026-08-23 — internal working notes and links to non-public files removed from the text; sub-processor DPA status corrected to reflect reality (standard terms accepted at sign-up, not separately negotiated agreements). The sub-processor registry is available in-app under "More → Settings → Privacy & data".
The previous version v1.4 (2026-08-22) brought operator details in line with the closed-testing reality and corrected the date-of-birth statement (only a coarse age is collected). Effective date: 2026-06-04 Last updated: 2026-08-23
⚠️ Status: closed testing. Tukko is not publicly released; it is distributed to a limited group of testers by personal invitation. At this stage the operator is a private individual; no legal entity has been incorporated. Full operator details (legal entity, jurisdiction, postal address) will appear here before public release.
Tukko is a children's daily-schedule app. This policy explains what data we collect, why, and how to exercise your rights under COPPA (United States), GDPR / GDPR-K (European Union), and other applicable laws.
If you have questions, contact us at privacy@tukko.eu.
Formal risk assessment: We maintain a Data Protection Impact Assessment (DPIA) under GDPR Article 35 — required because Tukko processes children's data. The full DPIA is available on request at the address in §14. It enumerates every processing category, the legal basis for each, the risks to data subjects, and the concrete mitigations we have in place. It is the same document we file with EU data protection authorities on request.
| Category | Source | Purpose | Legal basis |
|---|---|---|---|
| Email address | Parent provides at sign-up | Account auth, parental consent confirmation, account-recovery email | Contract (Art 6(1)(b) GDPR), consent (Art 6(1)(a) for COPPA) |
| Display name | Parent provides | Personalisation | Contract |
| Child first name / display nickname | Parent provides | Schedule display | Consent (Art 6(1)(a) + COPPA §312.5) |
| Child age in years (optional) | Parent provides | Jurisdictional digital-consent-age tracking (FR-071) | Legitimate interest (Art 6(1)(f)) |
| Schedule data (daily blocks, todos, rewards, points) | Parent + child enter | Core product function | Contract |
| Chat messages (parent ↔ child, parent ↔ co-parent) | Users send | Family communication | Contract |
| Avatar image (optional) | Parent uploads | Profile personalisation | Consent (Art 6(1)(a)) |
| Authentication logs (sign-in events, hashed user_id, IP-prefix) | Auto-collected | Fraud detection, COPPA §312.8 record-keeping | Legitimate interest (LIA available on request) |
| Crash reports (parent sessions ONLY) | Sentry SDK | Diagnose crashes | Consent (Art 6(1)(a)) — OFF by default; opt-in via Privacy panel |
| Product analytics events (parent sessions ONLY) | PostHog SDK | Understand feature usage to improve the product | Consent (Art 6(1)(a)) — OFF by default; opt-in via Privacy panel |
We do NOT collect:
crash_reports scope) When this scope is enabled, Tukko's Sentry SDK captures crash and error reports from parent sessions only. A typical report contains: stack traces, OS version, app version, anonymous install ID, and the screen route where the crash occurred. A built-in PII scrubber removes sensitive keys (emails, child names, schedule content, chat messages) before the event leaves the device.
analytics scope) When this scope is enabled, Tukko sends anonymous product-analytics events to PostHog from parent sessions only. We use these events to understand which features are used, where parents get stuck, and how to prioritise improvements. We do not use these events for advertising and we never sell them.
schedule_block_created), screen views, feature-usage flags, app/OS version.device_id UUID), not to the account email. The identifier is regenerated on app reinstall./engage person-profile delete endpoint server-side.analytics_toggled event so we know the opt-in happened; when they turn it OFF the opt-out runs first, so no further events (including the toggle event) are sent.Parents may withdraw consent at any time via Settings → Privacy → Revoke and delete account, or via the link in the consent-followup email. Withdrawal deletes the child's data within 30 days.
The live, versioned registry of every Tukko sub-processor is available in the app: "More → Settings → Privacy & data → Sub-processors". The table below is a snapshot at the time this policy version was published and may lag the live registry by up to one publish cycle. (A public web address will follow together with the domain, before public release.) For GDPR Art 28(2) purposes — including the 30-day notice of any new sub-processor — refer to the live page. Parents can subscribe to email notifications about new sub-processors in Settings → Privacy → "Notify me about new sub-processors" (spec 042).
| Sub-processor | Role | Region | Sub-sub-processors | DPA |
|---|---|---|---|---|
| Supabase | Database, Auth, Storage, Edge Functions | EU (Frankfurt) | AWS, Cloudflare | No separate DPA signed — deferred until incorporation |
| Sign-In with Google | Global | — | No separate DPA signed — deferred until incorporation | |
| Apple | Sign in with Apple, APNs | Global | — | Apple Developer Program terms |
| Expo | Push notifications, OTA updates | US | FCM, APNs | No separate DPA signed — deferred until incorporation |
| Sentry — Functional Software, Inc. | Crash reporting (parent opt-in only — see §3.1) | EU region | — | No separate DPA signed — deferred until incorporation |
| PostHog — PostHog Inc. | Product analytics (parent opt-in only — see §3.2) | EU region | — | No separate DPA signed — deferred until incorporation |
| Resend | Transactional email (consent confirmation, data export delivery) | EU | — | DPA not signed — execution deferred until incorporation |
We do not sell personal data and do not share it for behavioural advertising.
Tukko's primary data store is in the EU (Supabase Frankfurt region). Transfers to non-EU sub-processors rely on Standard Contractual Clauses (SCC Module 2) and the supplementary measures set out in our Transfer Impact Assessment (Schrems II / EDPB Recommendations 01/2020), available on request.
| Data | Retention | Reason |
|---|---|---|
| Account + schedule + chat | Lifetime of account + 30 days after deletion request | Contract |
| Parental consent records | 7 years | COPPA §312.8 record-keeping |
| Authentication audit log | 7 years | Legitimate interest — fraud detection (LIA available on request) |
| Data export ciphertext | 7 days from generation | Single-use security model |
| Crash reports | 90 days at Sentry | Sentry default |
| Product analytics events | Per PostHog project retention (operator-configured) | PostHog default; deletable on demand via /engage (see §3.2) |
The full retention schedule is available on request at the address in §14.
You have the right to:
core)To exercise these rights, use the in-app controls or email privacy@tukko.eu. We respond within 30 days.
In addition to the rights above, parents may:
When we materially change this policy, we will:
For non-material changes (typo fixes, contact updates), we may publish without re-consent but will still log the new hash.
Tukko does NOT use:
IDFA is not collectedTukko does use a first-party product-analytics SDK (PostHog) to understand feature usage — strictly opt-in, parent sessions only, tied to a random device identifier, and never used for advertising. See §3.2 for the full description.
This declaration maps to Apple App Privacy "Data Not Linked to You" / "No Tracking" and Google Play Data Safety "No data shared for advertising".
If Tukko is published under Apple's Kids Category (versus Productivity), additional restrictions apply: crash reporting and product analytics are disabled on all sessions (including parents), and certain external link flows are gated through a parental challenge.
For privacy questions or to exercise your rights:
Breach notifications: we notify affected users within 72 hours of becoming aware of a personal-data breach, per GDPR Art 33–34.
Version v1.5, 2026-08-23. The current text is always available at this address; we announce material changes in the app and ask for consent again.