Tiny Huddle
Privacy policy
Last updated August 25, 2026
Tiny Huddle is a family command center at https://tinyhuddle.app. This policy explains what we collect, why we collect it, with whom we share it, and how we protect it. It is written for the parent who creates the household account.
Who this is for
One parent signs in with an email and password. That parent owns exactly one household. Children and other family members are profiles inside that household. They are not separate email accounts, and Tiny Huddle does not collect a child’s email address, phone number, or advertising identifier.
Information we collect
We collect only what the household needs to run the Family Display and Admin Page:
- Parent account email and password (password is stored by our authentication provider, not in readable form).
- Household name, timezone, locale, temperature unit, and optional location used for current weather.
- Family-member profiles: display name, optional photo, color, and a kid or parent label used only as a filter.
- Routines, points, rewards, redemptions, household to-dos, and calendar events created or imported for that household.
- A four-digit admin PIN, stored so only that parent can unlock the Admin Page.
- If you connect Google Calendar, the Google user data described in Google Calendar.
How we use it
We use this information to sign you in, show your family’s day on the iPad, keep routines and points consistent, display current weather, and sync the Google calendar you selected. We do not sell household data. We do not use it for advertising. We do not build profiles of children for anyone outside your household.
Google user data is used only to provide and improve Tiny Huddle’s user-facing calendar features. We do not use Google user data to train artificial intelligence or machine-learning models.
Google Calendar
Connecting Google is optional and happens in Admin after you unlock with your PIN. When you authorize Tiny Huddle, we access this Google user data:
- The Google account email and basic profile needed to show which Google account is connected. A household may connect more than one Google account.
- Your Google Calendar list, so you can choose which calendars appear on Tiny Huddle, including extra calendars assigned to one family member.
- Event details on those selected calendars, including title, start and end times, all-day dates, description, location, recurrence, and status.
- OAuth tokens that let Tiny Huddle keep reading and writing those calendars until you disconnect.
We use that Google user data to show the family calendar, refresh events, and create, edit, or delete events on the family calendar you designate and on extra calendars that are shown when someone at the Family Display or Admin asks us to. Who an event is for (Everybody or specific family members) stays in Tiny Huddle and is not written back to Google. You can disconnect Google in Admin. That stops future sync; it does not erase events already stored in Google.
Sharing, transfer, and disclosure of Google user data
We do not sell Google user data. We do not transfer or disclose your information to third parties for purposes other than the ones provided in this policy. We do not share, transfer, or disclose Google user data to advertisers, ad networks, data brokers, or information resellers.
We share, transfer, or disclose Google user data only as follows:
- Google. We send calendar reads and writes back to Google so the calendar you connected stays in sync with the actions you take in Tiny Huddle.
- Cloudflare. Tiny Huddle runs on Cloudflare Workers. Cloudflare processes requests that include Google user data only to host and operate this application.
- Supabase. Encrypted Google tokens and cached calendar events for your household are stored in Supabase so the Family Display can load your schedule.
- People at your Family Display. Anyone using the signed-in household device can see the Google Calendar events you chose to show and can add, edit, or delete events on the designated family calendar.
- Legal requests. We may disclose Google user data if required by law, a valid legal process, or to protect the safety of a person.
Weather lookups use the household location you set. They do not receive Google user data. We do not transfer Google user data to other Tiny Huddle families.
How we protect Google user data
Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information.
- Google user data is sent over HTTPS in transit.
- Google refresh tokens are encrypted at rest with AES-GCM before they are stored. The encryption key is kept as a server secret, not in the browser.
- OAuth tokens are never sent to the browser and are not written to application logs.
- Household calendar data is isolated with row-level security so one Tiny Huddle account cannot read another household’s Google user data.
- Connecting or disconnecting Google Calendar requires the signed-in owner and a valid admin PIN unlock.
Who can see household data
Only the signed-in owner’s household can read or change that household’s data. Anyone standing at the Family Display can see that household’s schedule, complete routines, add or check off to-dos, and add or edit calendar events. Changing routines, rewards, points, family members, calendar connections, or settings requires the admin PIN. We do not share household data with other Tiny Huddle families.
Processors we use
Tiny Huddle runs on Cloudflare. Account and household data are stored in Supabase. Weather uses the location you set. If you connect Google Calendar, Google processes that calendar data under Google’s terms. These providers see only what they need to operate the service, as described in Sharing, transfer, and disclosure of Google user data.
Cookies and sessions
We use cookies and similar storage to keep you signed in and to remember an admin PIN unlock on that device. We do not use third-party advertising cookies.
How long we keep data
We keep household data while the parent account exists. If you disconnect a calendar, we stop using those tokens for new sync and we delete the stored Google refresh token for that connection. Cached Google Calendar events for that household are no longer refreshed. To delete your account and household data, including Google tokens and cached Google Calendar events we stored, contact us from the parent email on the account. We will remove the household we can identify from that request.
Children
Tiny Huddle is meant for families. We do not require personal information from a child to create a profile. Collect only a display name and, if you want, a photo. Do not put a child’s email, school ID, or other sensitive identifiers into Tiny Huddle.
Changes and contact
We will update this page if our practices change. The date at the top is the latest version. Questions about privacy can be sent from the parent email on your Tiny Huddle account, or by writing through https://tinyhuddle.app.
