tiger.mom
HomeBlogPrivacy

tiger.mom Privacy Policy

Effective date: August 24, 2026 Controller: Theodor Steiner, Tokyo, Japan
EU representative (Art. 27 GDPR): Susanne Steiner, Im Bruckenwasen 1, 73207 Plochingen, Germany
Contact: hi@tiger.mom — please use email for all privacy inquiries; postal mail to the EU representative is forwarded to the controller
Canonical URL: https://tiger.mom/privacy

tiger.mom is an accountability app that can block distracting apps and review proof of progress toward goals. This policy explains what data tiger.mom uses, why it uses it, and the choices available to you.

The short version

  • Your goals are private. Sign in to back them up.
  • Your Screen Time selections and tiger.mom memory stay on your device.
  • tiger.mom reads only the proof you choose to submit. Apple Health access is limited to workouts and your daily step count, and requires Apple's separate permission.
  • On devices using Google Cloud AI, tiger.mom sends the selected proof and the current review context to Google Gemini only after you sign in and explicitly allow Cloud AI. Signing in does not grant that permission by itself.
  • Cloud AI permission, Apple Health permission, and the optional “Help make tiger.mom better” contribution are separate choices.
  • tiger.mom sends crash and error diagnostics so we can find things that break. These never contain your proof, effort reports, or the names of apps you block, and you can turn them off in Settings.
  • You can revoke Cloud AI or the optional contribution in the app. You can delete your account and associated tiger.mom server data from the app.

Goals and account sync

If you sign in, tiger.mom stores your goal names, activities, schedules, preferred integrations, unlock rule, and app-group names and time thresholds in your account. This provides recovery after reinstalling. These records are private by default and are not published. They are retained until you delete them or delete your account.

Data that stays on your device

tiger.mom stores your selected distracting apps and a short AI-generated memory of prior reviews only on your device. Apple's Family Controls framework represents selected apps with privacy-preserving tokens; tiger.mom never uploads those tokens or receives a list of your complete device usage or browsing history. After reinstalling, you must select the apps again.

GitHub authorization tokens are stored in the iOS Keychain. If you connect GitHub, tiger.mom requests contribution counts needed for the proof you select; it does not read your source code.

Account data

An account is optional for local blocking, goals, and purchasing Pro, but is required for Google Cloud AI and server-backed review history. When you use Sign in with Apple, tiger.mom stores Apple's account identifier and, if Apple shares them, your name and email address. It also stores authentication tokens, your privacy-consent records, and an opaque RevenueCat customer identifier.

This data is used to provide and secure your account, synchronize your private goals and schedule, enforce per-user limits, remember your privacy choice across reinstalls, and support account deletion. The legal basis is performance of our service contract and, for optional processing, your consent.

Proof reviews and effort reports

For a review, tiger.mom uses the message, goals, screenshots, and integration proof that you choose to submit. On the current Google Cloud AI route, the app sends that material and the current conversation context to Google Gemini for transient extraction and evaluation. It is not used by tiger.mom for advertising. The app shows the processing route and asks for Cloud AI consent before the first transmission. You may revoke that consent in Settings.

After a review, tiger.mom's server stores your effort message, the verdict and coach response, goal name, prompt version, and feedback you provide. Without the optional contribution described below, stored proof is reduced to a content-free record of its source, type, and time; selected screenshot bytes are not stored by tiger.mom.

Apple Health and fitness data

If you connect Apple Health, tiger.mom requests read-only access to workouts and your step count. It does not write Health data or read your complete Health record. For a workout you attach, the app previews the minimized fields used for review: activity type, start and end time, duration, recording source, device model when available, and whether the workout was entered manually. For steps it reads one number — your total for the current day — together with the window it covers and the names of the apps or devices that counted it. Steps you typed into Health by hand are excluded from that total. No per-sample, hourly, or location data is read.

On the Google route, those fields or a Health/Fitness screenshot are sent to Google only under the explicit Cloud AI permission. HealthKit permission alone does not authorize that transfer. tiger.mom does not store structured Health fields in proof history. During the friends-and-family beta only, a Health/Fitness screenshot you deliberately attach may be stored under the separate optional contribution described below.

Optional contribution to improve tiger.mom

“Help make tiger.mom better” is off by default. If you turn it on, tiger.mom may store the material you submit—including review messages, extracted proof, verdicts, feedback, usage events, and screenshots—to train, evaluate, and improve its models and product. For the current private friends-and-family TestFlight beta, this can include a Health/Fitness screenshot you deliberately attach. Structured Apple Health workout fields remain redacted from stored proof history. Screenshot collection is disabled in App Store production builds.

Friends-and-family testers receive this unusually broad beta disclosure before joining and must separately opt in inside the app. Before a public external beta, tiger.mom will exclude Health/Fitness screenshots and health-derived content from improvement storage, introduce time-based retention and restricted owner access, and require a new consent before any external fine-tuning use.

You can turn the contribution off at any time to stop future collection. Data already used in a completed training run cannot necessarily be removed from that trained model, but the underlying stored account data is deleted when you delete your account.

Purchases

Apple processes subscription payments. RevenueCat receives an anonymous or account-linked customer identifier and purchase information such as products, renewals, refunds, and entitlement status so tiger.mom can unlock and restore Pro. RevenueCat never receives your proof, effort messages, Health data, or AI conversation. Purchasing Pro does not require a tiger.mom account.

Crash and error diagnostics

tiger.mom reports crashes and errors so we can find problems we would otherwise only hear about as “it stopped working.” This is separate from the optional contribution above: it is on by default, it carries no content you created, and it has its own switch.

A diagnostic report contains the technical facts of a failure: what operation failed (for example “sign-in”, “connect GitHub”, “purchase”), a fixed error code, a crash stack trace, the app version and build, the device model and iOS version, and your numeric tiger.mom account ID when you are signed in. Reports from the Screen Time extensions are written to your device first and sent the next time you open the app.

Diagnostic reports never include your effort reports, proof screenshots or extracted proof text, Apple Health data, AI conversations, your name, your email address, your Apple identifier, or the names of the apps you have chosen to block. Reports are scrubbed on the device and again on our server before sending, and authentication tokens and request contents are removed.

The legal basis is our legitimate interest in providing a secure, working, and reliable app (Art. 6(1)(f) GDPR). You may object at any time: turn off You → Settings → “Share diagnostics” and collection stops immediately. Turning it off does not affect any other feature.

Diagnostics are processed by Sentry on infrastructure in the European Union and retained for 90 days, after which they are deleted automatically.

Service providers

tiger.mom uses:

  • Apple for Sign in with Apple, HealthKit, Family Controls, and App Store purchases;
  • Google Firebase AI Logic / Vertex AI for consented Cloud AI reviews and Firebase App Check device attestation;
  • Fly.io for the API and PostgreSQL account/report storage;
  • Fly Tigris for closed-beta proof screenshot storage when the optional contribution is enabled;
  • RevenueCat for subscription products, purchases, and entitlement status; and
  • Sentry (Functional Software, Inc.) for crash and error diagnostics, processed in the European Union.

These providers process data under their applicable terms and data-protection commitments. Processing may occur outside your country; where required, appropriate contractual transfer safeguards are used.

Retention and deletion

Raw screenshots saved on your iPhone for conversation history are deleted after five days and replaced by a placeholder. Account data, effort reports, consent records, optional contribution events, and server-side closed-beta contributed screenshots are currently kept until you delete your account. Crash and error diagnostics are kept for 90 days and then deleted automatically, whether or not you delete your account. Authentication tokens are rotated and are removed on logout or account deletion. Local data remains until you clear it or delete the app. Apple and RevenueCat may retain transaction records as required for billing, fraud prevention, tax, and legal compliance.

Use You → Your Account → Delete account to delete your tiger.mom account, reports, consent records, usage events, and stored beta screenshots. Deleting tiger.mom does not cancel an Apple subscription; subscriptions are managed through Apple.

Your rights and choices

Depending on where you live, you may have rights to access, correct, export, delete, restrict, or object to processing of your personal data, and to withdraw consent. Withdrawing consent does not affect processing that already occurred lawfully. You may also complain to your local data-protection authority.

Cloud AI and optional contribution controls are available in the app. For an access or privacy request, email hi@tiger.mom.

Children

tiger.mom is not directed to children under 13, or the equivalent minimum age in their country, and we do not knowingly collect their personal data.

Changes

We may update this policy when the product or its data practices change. The effective date above will be updated, and material changes requiring consent will be presented before the new processing begins.

© 2026 tiger.mom — made with tough love.