Security & Privacy

Your data belongs to you

Toddli was built by a parent, for parents. We will never sell your data, never use it to train AI models, and never store more than what is strictly needed to run the app.

Encryption in transit and at rest

All data is transmitted over HTTPS / TLS 1.3. Data at rest is encrypted using AES-256 via Supabase's managed infrastructure. Your baby's logs never travel or sit unprotected.

Row-Level Security (RLS)

Toddli uses Supabase with Row-Level Security enabled on every table. Each query is scoped to the authenticated user's own data at the database level — not just in application code. Other users cannot read, write, or even detect your records.

Hosted in Singapore

All backend infrastructure runs in Supabase's Singapore (ap-southeast-1) region. Your data stays in Singapore and is subject to the PDPA (Personal Data Protection Act) — one of Asia's strongest data protection frameworks.

AI transparency

The AI assistant is powered by providers including OpenRouter, Groq, and OpenAI. Your data is never used to train any AI model. Conversations are sent to the provider only to generate a response, then discarded. We do not store chat history on AI provider servers.

We never sell your data

Toddli's business model is a subscription app. We have zero financial incentive to sell, rent, or broker your data to advertisers, data brokers, or any third party. This is a promise, not just a policy — it is core to why Toddli exists.

Export your data anytime

You own your records. Export everything — feeding logs, sleep sessions, growth measurements, vaccine history, notes — as CSV, JSON, or PDF, at any time, directly from the app. No waiting period, no support ticket required.

Minimal data collection

We collect only what is necessary for the app to function: your email, your baby's profile, and the logs you create. We do not run third-party ad SDKs or analytics trackers inside the app. Crash reporting uses privacy-respecting tooling only.

Questions? Contact us directly

If you have a security concern, want to request deletion of your data, or need clarification about how we handle your information, reach us at hello@toddli.app. We respond within 48 hours.