Privacy Policy
Last updated: August 1, 2026
Photos and records handled by toymark stay on your device by default. Cloud sync and web sharing send data to our server only when you explicitly turn them on. App usage analytics is confirmed with you the first time you open the app, and is sent only if you agree; you can change this anytime in Settings.
1. Principles
toymark (“the App”) handles sensitive information such as children’s photos and growth records. We keep only what is needed, only where it belongs (on your device by default). Photo and record contents leave your device only when you explicitly opt in to cloud sync or web sharing (sections 10 and 11), and we never sell or provide them to third parties.
2. Information we do not collect
With cloud sync and web sharing off (the default), the iOS app does not collect or transmit any of the following. Data sent when you opt in is described in sections 10 and 11 (app analytics is sent only if you agree to it at the first-launch prompt; see section 7 for optional anonymous events, and section 12 for website analytics).
- Contact details such as name, email, or phone (except when you voluntarily email us)
- Children’s photos or record data
- Location
- Device identifiers or advertising IDs
- Behavioral logs or tracking that identify a device or person (even with analytics on, we only send anonymous aggregate events without device identifiers, as in section 7)
- Information via cookies or tracking technologies in the app
3. Information stored on device
The App stores the following on your device to provide features. By default it is not sent over the internet (for what is sent when you opt in to cloud sync or web sharing, see sections 10 and 11; for iOS backups, see section 15).
- Child display names and birthdays (used for age-in-months labels)
- Photos you capture or pick, and cutout/outline results
- Toy information and records
4. Location and EXIF from photos
When you import a photo, location and other EXIF metadata are stripped from the saved image.
5. Camera and photo library access
The App may ask for camera and photo library permission to capture or select photos. Images are used only to create records and, by default, are not sent externally (for opt-in cloud sync, see section 10). You can change permissions anytime in system Settings.
6. External transmission and third parties
The App does not embed third-party analytics SDKs, ads, or external trackers. Optional analytics in section 7 is our own anonymous aggregate for product improvement. Data sent when you opt in to cloud sync or web sharing (sections 10 and 11) goes only to our own server. In all cases, we do not sell, provide, or share collected information with third parties.
For why iOS device backups (iCloud or encrypted local) may include the App’s data, and why that is not "external transmission" by the App, see section 15, "About iOS backups."
7. Optional app analytics
The App can measure usage to improve the service. The first time you open the App, we ask whether you agree to this. Only if you agree do we send the following anonymous events; if you decline, nothing is sent. You can change your choice anytime in Settings.
- When (events): app open, record saved, cutout success/failure, sync enabled
- What: display language, app version, and OS type (e.g. iOS) only
- What we never send: device or advertising IDs, child name/birthday/age, photos, toy names, memos, or other content that could identify someone
- You can turn it off anytime; sending stops completely when off
8. House ads and sponsor slots
The App may show house ads and sponsor slots. Ad creatives are fetched anonymously over HTTPS using only non-identifying values (the slot type, your language, and the app version). We do not send any device or advertising identifier, and we never personalize ads based on your child, records, or usage. The App does not send impression or tap events; we measure only via server-side delivery logs and UTM parameters on the destination link. Ad slots are labeled "PR", and tapping one opens the link in your external browser. If an ad cannot be fetched, the slot is simply hidden.
9. Payments and in-app purchases
The App offers an optional paid upgrade, "toymark Plus." Payments are processed by Apple (the App Store); the App never receives or stores your payment details such as card numbers. Your purchase entitlement is determined on your device through the App Store and is not sent to our servers. We do not collect any device or advertising identifier for purchases, and we never link purchase information to your child’s name, birthday, photos, or records. We use no third-party billing or analytics SDK.
The App also offers an optional paid auto-renewable subscription, "toymark Cloud," for syncing your family’s records across multiple devices (see Section 10 for the full picture of cloud sync). To verify whether this subscription is active, the App sends the signed proof of purchase (JWS) your device receives from the App Store to our server, which verifies Apple’s signature. After verification, our server stores only the subscription’s expiration date and an irreversible hash of the original transaction ID (HMAC-SHA256) — never the raw receipt, transaction ID, or JWS. The subscription expiration date is stored per household (your billing unit) and is never linked to your child’s name, birthday, or records.
10. Cloud sync and accounts (optional)
The App has an optional cloud sync feature that backs up your records to our server and shares them within your family (members of the same household). Cloud sync is off by default and runs only after you sign in and turn it on. Unless you do, none of the data in this section is ever sent.
- What is stored on our server when sync is on: your child’s display name and birthday, toy information and records, and images from which EXIF metadata (such as location) has already been stripped
- Signing in creates an account, and your account information (email address and sign-in credentials) is also stored on our server
- This data is used only to share with your family (members of the same household), and is always transmitted encrypted (TLS). We do not write your child’s name or birthday to server logs
- We do not sell or provide this data to third parties (see section 6)
- You can delete your account and all of your data on our server at any time — in the app (Settings > "Delete account") or by email. See the "Account Deletion" page on this site for details
11. Web sharing (optional)
The App can publish a toy’s timeline as a read-only web page to show to family and friends. A share page is created only when you explicitly perform the share action, and you can revoke it at any time. Creating a share requires signing in, so even with cloud sync off, your account information is stored on our server as described in section 10.
- What a share page contains: cutout images, the toy’s name, record dates, and the age in months at each record. Memos are included only if you choose to include them when sharing
- Your child’s name and birthday are never included on a share page
- Share pages use a hard-to-guess URL, are excluded from search engines (noindex), have an expiration date, and can be revoked (deleted) from the app at any time
12. Website analytics
This website (toymark.toys) uses Google Analytics (Google LLC) to understand and improve site usage. Analytics applies only to the website, not the iOS app (app analytics is separate and is sent only if you agree to it at the first-launch prompt; see section 7).
- We use cookies to collect page views, referrers, approximate region, and browser type.
- We do not collect name, email, phone, or other personally identifying data. IP addresses are anonymized.
- Collected data is sent to and processed by Google under Google’s privacy policy.
- You can disable cookies in your browser or use Google’s opt-out add-on to stop analytics.
13. Children’s privacy
The App is designed around children’s information, and protecting it is our top priority. By default it never leaves your device. If you opt in to cloud sync, your child’s name and birthday are stored on our server solely for sharing within your family (section 10), and web share pages never include them (section 11). Even with analytics on, we never send child names, birthdays, ages, photos, toy names, or memos as analytics events.
14. Deleting data
On-device records can be deleted in the app or by uninstalling the app. However, if you have iCloud Backup (or an encrypted local backup) turned on, a copy from before deletion may remain in your Apple backup until the next backup runs and updates it. This is not something the App sends — it is how iOS backups work. See section 15, "About iOS backups," for details.
If you used cloud sync or web sharing, the data stored on our server can be deleted at any time by deleting your account — in the app, or via the steps on the "Account Deletion" page on this site (see section 10).
Even if you cancel your "toymark Cloud" subscription or it lapses, your on-device data is unaffected. Regardless of your subscription status, the copy of your data stored on our server can always be deleted at any time by deleting your account — in the app, or via the steps on the "Account Deletion" page on this site. We have not yet set a timeline for automatic deletion.
15. About iOS backups
If you have iCloud Backup, or an encrypted local backup via Finder or a computer, turned on for your iPhone, the App’s data — including photos and records — is included in that backup, just like most other apps. This is standard iOS behavior; the App itself is not separately sending anything externally.
iCloud Backup is stored encrypted by Apple. If you also enable Advanced Data Protection, your iCloud Backup is end-to-end encrypted, so no one — including Apple — can read its contents except you.
Creating, storing, and restoring backups is handled by iOS and Apple (or your Finder backup destination); the App never creates, accesses, or transmits these backups itself. If you prefer not to back up this data, you can turn off iCloud Backup in Settings > [your name] > iCloud > iCloud Backup.
16. Changes to this policy
If we change this policy, we will post the update on this page with a new last-updated date.
17. Contact
Questions about this policy: email us at the address below.