TandemGrown privacy policy
Version 2 · 8 October 2026
This policy explains what data TandemGrown processes, why, for how long and how you can control it. We wrote it to be understood without a law degree; if anything is unclear, write to us.
Who is responsible
TandemGrown is an app by Javier Partida Valle (Spain), the controller of your data. For any privacy question or to exercise your rights: info@tandemgrown.com.
What data we process
- Your account: your email and, if you sign in with Google, your Google account identifier and name. Your password is handled by Firebase Authentication and we never see it.
- Your family: the name other members see you by, who manages the family and the code to invite other members.
- Your babies' data: name, sex (if you choose to enter it), date of birth and weeks of gestation.
- Care records: feeds (breast, bottle, pumping and solids, with foods, reactions and possible allergens), sleep, nappies, growth (weight, length and head circumference), medicines and doses, and the notes you write. Each record stores who made it and when.
- Your consent: the date you gave it, the version of this policy you accepted and the app version.
- Technical connection data: so that sign-in and syncing work, Firebase processes data such as your IP address and device type, also for security.
Care records and growth, medicine and gestation data are children's health data, a special category of data protected by Article 9 of the GDPR.
We do not collect your location, contacts, photos or advertising identifiers, and the app has no analytics or advertising.
What we use it for
Only so that you and the people you invite to your family can record and check your babies' care on your devices, and to manage your account. We do not use it for advertising, we do not sell it, we do not build profiles and we make no automated decisions about you or your babies.
Legal basis
- Health data: your explicit consent (Article 9(2)(a) GDPR), which you give when you start using the app. You can withdraw it at any time from Settings → Privacy; withdrawing it does not affect what was processed before.
- Account and family data: providing the service you ask us for (Article 6(1)(b) GDPR).
- Consent record and technical security data: our obligation to be able to prove consent and our legitimate interest in protecting the service (Articles 6(1)(c) and 6(1)(f)).
Who can see your data
- The members of your family in the app: they see the babies, their records and the name you appear under. You decide who you invite, and whoever manages the family can remove members.
- Google (Google Ireland Limited), through Firebase, as a processor: it stores the data and handles sign-in following our instructions and under a GDPR-compliant contract.
We do not share your data with anyone else, unless required by law.
Where it is stored
Family data is stored in Google Cloud Firestore, in the European Union (Madrid). Firebase Authentication sign-in may process your email and technical data outside the EU, in particular in the United States; those transfers are covered by the EU-US Data Privacy Framework and the European Commission's standard contractual clauses.
On your phone, the app keeps a copy of your family's data to work offline, plus your preferences (theme, language and units). That copy is not included in Android backups and is not moved to another phone when you switch phones: when you sign in on the new one, the data comes back from Firestore.
How long we keep it
- While your account exists and you keep your consent.
- If you delete your account, we delete it immediately together with your consent and, if you were the only member, your family, its babies and all their records. Google removes them from its internal systems and backups within about 180 days at most.
- If you do not use the app for 24 months, we will email you and, if you do not sign in within the following 30 days, we will delete your account as if you had done it yourself.
- If you share the family and leave it or delete your account, the babies and records are kept for the other members (including the ones you created, as they are part of the babies' history) and your name is deleted.
- If you withdraw your consent, you cannot use the app until you give it again; if you never do, the inactivity period applies.
How we protect it
- Everything travels encrypted between your phone and Firebase, and Google encrypts the stored data.
- The database rules only let a family's members access it, with their account.
- The app does not write your data to the phone's system log or include it in backups.
Your rights
You can access, rectify or erase your data, restrict or object to its processing, ask for portability and withdraw your consent by writing to info@tandemgrown.com. We will reply within one month at most.
You can download a copy of your and your family's data, free and whenever you want, from Settings → Download my data: it is a JSON file you can keep or take to another app. And you can correct any record from the app itself.
You can delete your account and its data whenever you want from Settings → Delete account. If you no longer have the app, follow the steps at https://tandemgrown.com/delete-account and we will delete it within a month.
If you think we have not handled your data properly, you can complain to the Spanish Data Protection Agency (https://www.aepd.es) or to the authority of your country.
Children
The app is used by adult parents or guardians to record their babies' data; it is not aimed at children. By consenting, you confirm that you are an adult and have parental responsibility or guardianship for the babies you record.
Changes to this policy
If we change this policy in a way that affects your data, we will tell you in the app and ask for your consent again. The current version is always at https://tandemgrown.com/privacy.