Tutik logo tutik ← Back to tutik.eu

Legal

Privacy Policy

Last updated: 23 September 2026

This Privacy Policy explains what personal data the Tutik app ("Tutik", the "App") and the website at tutik.eu (the "Site") collect, why, and what rights you have. We designed Tutik to be calm and privacy-respecting: we do not show ads, we do not sell your data, and we do not use advertising identifiers.

Tutik is operated by an adult parent or caregiver for use with a child. Children do not create their own accounts. This policy describes the data we process today; if that changes, we will update this page.

1. Who is responsible for your data

The data controller is Danolab s. r. o., with registered seat in Bratislava – Lamač, Slovak Republic (company reg. no. / IČO 53080700, registered in the Commercial Register of the Municipal Court Bratislava III, section Sro, insert no. 145876/B). For any privacy question or to exercise your rights, contact us at privacy@danolab.com.

2. Data we collect and why

Account and sign-in

Tutik works without an account: you never have to create one, and everything the App stores for you — a child's profile, Routine and Kids Mode settings, and your sleep log — stays only on your device until you choose to sign in. This is more private than earlier versions of the App, which created a hidden device identity and uploaded this data by default from first launch. If you sign in with Google or Apple, we receive your email address and display name from that provider to identify your account, and the data already on your device is uploaded into it so it can sync across your devices. Legal basis: performance of our contract with you (providing the App).

Technical identifiers the App creates on its own

Working without an account does not mean the App is invisible to its own infrastructure, and we would rather say so plainly. On first launch the App generates a small number of technical, pseudonymous installation identifiers it needs in order to run: a Firebase installation identifier, used by App Check to confirm that a request comes from a genuine copy of Tutik and by Firebase Cloud Messaging to address a notification to this device; and separate installation identifiers used by Firebase Analytics, Firebase Crashlytics and Firebase Performance Monitoring. They identify an installation of the App, not you: they carry no name, email address or child's data, we never attach your account identifier to them, and none of them is an advertising identifier. They are replaced if you reinstall the App or clear its data. Legal basis: our legitimate interest in operating the App securely and keeping it working; your consent where the identifier belongs to an optional feature (analytics and performance, or notifications).

Family sharing

A signed-in account can create a family group to share one Tutik Experience subscription with up to two other people (three in total). We store a family record linking the accounts by their account identifiers, an invite code used to join, and whether the owner's subscription is active. Creating or joining a family requires signing in, and joining always shows you what you are about to share and asks you to confirm before you switch to it. Legal basis: performance of our contract with you (providing the App).

Family sharing shares more than the subscription. Every member of a family sees, and can change, the same children's profiles (name, age group, avatar), their Routine and Kids Mode settings, the sleep log and sleep schedule, and the stories generated for the family, and every member can play — though only its author can change or delete — each other's custom recordings and story narrations. We do not share any of this with anyone outside the family group. Only the family owner can remove a child's profile. The owner can remove a member, or a member can leave, at any time, which ends that person's access to the shared data; a removed member's ability to play the family's recordings specifically can take up to an hour to end, for a technical reason. If the family owner deletes their Tutik account, the family is disbanded and all of its shared content is permanently deleted for every member. A member who deletes their own account (rather than the owner) simply leaves the family, and the shared content is unaffected. Joining by invite code, and this cleanup, are handled securely on our server (Firebase Cloud Functions). Legal basis: performance of our contract with you (providing the App).

Tutik Experience subscription

Tutik Experience is a paid subscription sold through the app store you bought it in — Google Play on Android, or the Apple App Store on iPhone and iPad. The store takes the payment and holds the purchase; we never see or store your card details. On Android, when you start a purchase from the App we pass your Tutik account identifier to Google Play with it, as the purchase's account identifier, so that the purchase can be matched back to your account (and, if you own a family group, shared with its members). Buying a subscription therefore requires signing in. Legal basis: performance of our contract with you (providing the paid features you bought).

So that your access stays correct even while the App is closed — after a renewal, a cancellation, a refund or a lapse — the store tells our server what happened. On Android, Google Play notifies our server of every change to your subscription, and our server then asks the Google Play Developer API for the subscription's current state. We store the answer on your account record: whether the subscription is active or has lapsed, that it came from Google Play, which plan (monthly or yearly) it is on, and whether a plan change is scheduled. Our server also keeps a private mapping from the Google Play purchase token to your account identifier, so that a later notification about the same purchase can be matched to you; it is used for nothing else and no other user can read it. Legal basis: performance of our contract with you.

If you subscribe on an iPhone or iPad, the Apple App Store takes the payment instead and the same principle applies. After a purchase or a restore, the App sends our server the signed transaction the App Store gave it; our server checks Apple's signature and asks Apple's App Store Server API for the subscription's current state, and Apple notifies our server of later changes. We store the same fields on your account record, with the App Store as the source. Our server also keeps a private mapping from the App Store's original transaction identifier to your account identifier, so that later notifications can be matched to you and one subscription is used by one account; it is used for nothing else, no other user can read it, and it is removed when you delete your account. Your account identifier is not sent to Apple. Legal basis: performance of our contract with you.

Child profile

To personalize the experience, a parent can add a child profile. A profile includes the name the parent gives the child (a given name or a nickname, the parent's choice) and an age group, and may include a chosen avatar. This is provided by the adult and used only to tailor content such as routines and stories. As described above, the profile stays only on your device until you sign in, after which it is stored under your account. Legal basis: performance of our contract; the parent provides this information on the child's behalf.

Routine and Kids Mode choices are stored separately for each child profile, including bedtime and routine steps, the exit-lock preference, and the story, song, or game identifiers the parent selects. This lets two children use different configurations. Like the child profile itself, these preferences stay only on your device until you sign in, at which point they are stored under your account; they can be changed by the parent, and are removed with the child profile or account, or by clearing the App's data on your device if you have never signed in. Legal basis: performance of our contract; the parent makes these choices on the child's behalf.

Sleep log

A parent can keep a private sleep diary: for each child you can log naps and the night's sleep — more than one entry per day is expected — noting roughly when the child fell asleep and, optionally, when they woke up (so we can show the duration), whether the entry followed the bedtime routine, and an optional note. You can also answer how the sleep went — slept, woke up, cried, or a bad sleep; a bad one stays in the diary but out of your averages. Deeper insight into their sleep rhythm over time is part of the Tutik Experience. These times are entered by you — nothing is measured, recorded, or detected by the device, and no microphone or motion sensing is involved. As with the child profile above, entries stay only on your device until you sign in; once you sign in they are stored under your account so you can see them in Settings across your devices. You can edit or delete any entry, or remove them all by deleting your account, or by clearing the App's data on your device if you have never signed in. Legal basis: performance of our contract; the parent provides this information on the child's behalf.

You can also export one child's sleep log as a CSV file — for example to show a doctor. The export is always started by you, covers a single child, and contains no account or device identifiers: the rows hold only the dates, times, durations, routine markers, and notes you entered yourself. So that you can tell one export from another — and so that a clinician can tell whose diary is whose — the file's name does contain the child's name as you entered it, together with the export date. It is created on your device, with no upload to us, and it is shared through your device's own share sheet, so you choose the recipient. Once you have shared it, the file is outside the App and we no longer control what happens to it.

Usage analytics and performance

We use Firebase Analytics to measure pseudonymous, first-party usage so we can improve the App, and Firebase Performance Monitoring to measure how quickly it starts, renders its screens, and loads data. We do not collect your name, your child's name, or free text for analytics, and we do not use advertising identifiers. Analytics does carry one attribute about a child: the coarse age band you chose for a profile (for example "3–4"), sent when a child profile is added or its age band is changed, so we can see which age groups Tutik is actually used for. No name, birth date, or other child detail is sent. You can turn this off at any time in Settings → Privacy & Data; that one switch covers both Analytics and Performance Monitoring. Legal basis: your consent.

Crash diagnostics

Firebase Crashlytics collects a report when the App stops unexpectedly: the error and its stack trace, plus basic device and App-version information. To be clear, crash reports are not covered by the analytics switch above — we rely on them to keep a bedtime app from failing in the middle of a bedtime, so released versions send them regardless of that setting. A crash report carries no name, no email address, no child's data, and no account identifier. Legal basis: our legitimate interest in providing a stable, secure App.

AI-generated stories (Tutik Experience)

If you generate a personalized story, the prompt you provide — which may include the child's name and age and the description you type or dictate — is sent to Google's Gemini model via Firebase AI to produce the story. Generated stories are saved to your account, and we keep a monthly usage counter to manage AI costs. Legal basis: performance of our contract (providing the feature you request).

If you add illustrations to a story you wrote yourself (a Tutik Experience feature), the story's title and text are sent to Google's Gemini image model via Firebase AI to generate a cover and scene pictures. Those images are stored privately in your own Firebase Storage space, are visible only to you, are deleted when you delete the story or your account, and a monthly usage counter manages the image-generation cost. Legal basis: performance of our contract (providing the feature you request).

Voice dictation

If you dictate a story prompt or recording, the App uses your device's speech-to-text capability. We process the resulting text to fulfil your request. Legal basis: performance of our contract.

Your own recordings (custom songs and parent narration)

You can record your own voice in Tutik — a lullaby or song of your own, or your own narration of a bedtime story. A recording is saved on your device and, once you are signed in, it is also uploaded to your account's own private area of our file storage (Firebase Storage), so that it survives a lost or replaced phone and can be restored on a new device. This corrects earlier versions of this policy, which said these recordings never left the device; they do leave it, and we would rather say so than let a wrong statement stand. If you have never signed in, nothing is uploaded and the recording stays on the device only.

An uploaded recording is never published, and it is shared with no one outside your account except, if you are in a family group, the other members of that family: as described above under "Family sharing," any member can play a recording you made, but only you can change or delete it. We do not listen to your recordings, run speech recognition on them, or use them to train anything. A recording is deleted from our storage when you delete it in the App, and every recording is removed when you delete your account — or, for a family's shared recordings, when the family is disbanded. Legal basis: performance of our contract with you (providing the feature you asked for).

Feedback and bug reports

When you send feedback, we receive your message and, if you choose to attach one, a screenshot, along with basic technical metadata to help us reproduce issues. Legal basis: our legitimate interest in supporting and improving the App.

Push notifications

If you enable notifications (for example a bedtime reminder), we use Firebase Cloud Messaging, which assigns a device messaging token used to deliver notifications. You can disable notifications in your device settings. Legal basis: your consent.

Home-screen widget

If you add Tutik's widget to your home screen (Android or iOS), it shows — for the child you picked for that widget — an avatar, a short calm caption (awake, sleepy, asleep), and the child's name as you entered it. Nothing new is collected or transmitted: the widget is drawn on the device from data that is already there. It is, however, a place where a child's name is on display without the device being unlocked in the App: a home-screen widget is visible to anyone who can see your screen, and on Android 16 and later a widget may also be placed on the lock screen. If you would rather the name were not shown, remove the widget — or give the profile a nickname or an initial, which the App accepts everywhere a name is used. Legal basis: performance of our contract (showing you the widget you added).

Website waitlist

If you submit your email on tutik.eu, we store your email address together with the chosen language, the page, your browser's user-agent string, and a timestamp, so we can contact you about early access. Legal basis: your consent.

On-device data

Some data stays on your device and is not sent to us, including app preferences, your selected language, and which child is currently active on this device. Cached audio and images are stored locally to enable offline playback. Recordings you make are also kept on the device, but — unlike the items in this list — they are uploaded to your account when you are signed in, as described under "Your own recordings" above.

3. Service providers and third parties

We use trusted providers to operate Tutik. They process data on our behalf or as part of their own service:

  • Google Firebase — authentication, database (Cloud Firestore), file storage, Cloud Messaging, Analytics, Performance Monitoring, Crashlytics, App Check, Cloud Functions (server-side family sharing, subscription entitlement, and account deletion), and Hosting.
  • Google Gemini (via Firebase AI) — generating personalized stories from the prompts you provide.
  • Apple and Google sign-in — if you choose to sign in with one of these providers.
  • Google Play — processes the payment and holds the purchase for a Tutik Experience subscription bought on Android. We do not receive your card details.
  • Google Play Developer API — queried by our server, and the source of the notifications it receives, to confirm the current state of your subscription so that access stays correct while the App is closed.
  • Apple App Store, App Store Server API and App Store Server Notifications — processes the payment and holds the purchase for subscriptions bought on iOS; Tutik receives the subscription status and an anonymous transaction identifier, never card data.

We do not sell your personal data and we do not share it for advertising.

4. International transfers

Our providers, including Google and Apple, may process data on servers located outside your country, including outside the European Economic Area. Where that happens, the transfer is protected by appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision.

5. Children's privacy

Tutik is intended to be set up and operated by an adult. Children do not create accounts, and we do not knowingly collect personal data directly from children. Any child information (such as a name or age group) is provided by the supervising adult to personalize the experience. If you believe a child has provided us data without a parent's involvement, contact us at privacy@danolab.com and we will delete it.

For families in the United States: we comply with the Children's Online Privacy Protection Act (COPPA). Tutik does not collect personal information from children. Information about a child is entered by the parent, children cannot create accounts or make purchases, there are no ads or advertising identifiers, and analytics is used only to improve the app, never for advertising — a parent can turn it off in Profile → Privacy & Data. A parent can review or delete a child's profile and its data at any time in the app, or by writing to privacy@danolab.com.

6. How long we keep data

We keep personal data for as long as your account is active or as needed to provide the App. If you have signed in, you can permanently delete your account at any time from within the App (Settings → Privacy & Data); this removes your account together with every child profile and their settings, sleep log entries and schedules, generated stories, usage counters, daily-story likes, any own-story illustrations and any voice recordings stored in our file storage, and any feedback reports you submitted (including an attached screenshot). If you are the owner of a family group, deleting your account also disbands the family and permanently deletes its shared content for every member, as described under "Family sharing" in Section 2; if you are a member rather than the owner, deleting your account instead only removes your own account, and the family's shared content is unaffected. If you have never signed in, there is no account to delete — you can remove everything Tutik has stored by clearing the App's data in your device's system settings. Some data may be retained for a limited period where required by law or for legitimate business needs such as security and fraud prevention. Anonymous, aggregated analytics may be retained.

If you signed in with Apple, deleting your account also revokes Tutik's Sign in with Apple tokens, so Tutik disappears from Settings → your name → Sign in with Apple.

Records attached to a purchase are treated separately: the subscription state on your account record and the server-side mapping between a purchase and your account — a Google Play purchase token on Android, an App Store original transaction identifier on iOS — are kept for as long as needed to service the subscription and to meet our accounting obligations. Deleting your Tutik account does not cancel a subscription — cancel it in Google Play (Payments & subscriptions) on Android, or in Settings → your name → Subscriptions on iOS.

7. How we protect data

We rely on the security of our providers and apply access controls so that your account data is scoped to you. For example, your stored content is readable only by your account — or, for data covered by a family group, by the other accounts in that group, as described in Section 2 — and feedback reports are accessible only to our administrators. No system is perfectly secure, but we take reasonable measures to protect your data.

8. Your rights

Under the GDPR and applicable law, you have the right to:

  • access the personal data we hold about you;
  • have inaccurate data corrected;
  • have your data erased (including by deleting your account in the App if you have signed in, or by clearing the App's data on your device if you have not);
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time, without affecting prior processing;
  • lodge a complaint with a supervisory authority.

To exercise these rights, contact privacy@danolab.com. In the Slovak Republic, the supervisory authority is the Office for Personal Data Protection of the Slovak Republic (Úrad na ochranu osobných údajov Slovenskej republiky), dataprotection.gov.sk.

9. Website storage and cookies

The tutik.eu website stores a small preference in your browser to remember your chosen language, and loads web fonts from Google Fonts. The website does not use advertising or tracking cookies. Submitting the waitlist form signs your browser into an anonymous Firebase account, used only to authorize that one write, and stores its identifier in your browser; the waitlist form then stores the email you submit as described above. This is specific to the website: the App never uses that anonymous website account, and using the App does not create a Tutik account for you. The technical installation identifiers the App does create for itself are described in Section 2.

10. Changes to this policy

We may update this Privacy Policy as the App evolves or to reflect legal requirements. When we make material changes we will update the "Last updated" date above and, where appropriate, notify you in the App. The current version is always available at tutik.eu/privacy.

11. Contact

For any privacy question, contact privacy@danolab.com, or write to Danolab s. r. o., Bratislava – Lamač, Slovak Republic.

Terms & Conditions Back to tutik.eu
tutik Tutik. Calm by design.