Tovvle — Privacy Policy

Last updated: 17 June 2026

Tovvle is a private family organiser — chores, a shared “wallet” of IOUs, shopping, calendar, appointments and a family-only feed. This policy explains what we store, why, and the choices you have. We built Tovvle privacy-first: your family’s data is isolated to your family, health notes are encrypted, and there are no advertising or analytics trackers.

Who we are

Tovvle is operated by RebelWorks (Nellina & Thomas Verdianz), based in Vienna, Austria — the data controller under the EU GDPR. Contact for privacy questions: privacy@tovvle.com.

What we store

What we do not do

Where your data lives, and family isolation

Data is stored with our processor Supabase in the EU (Frankfurt, eu-central-1). Every record is tagged to your family, and database row-level security ensures a signed-in member can only ever read or write their own family’s data — never another family’s. Health and feed data are further restricted (parent-or-self).

Children’s data

Tovvle is adult-first. A parent sets up the family and adds children as sub-profiles under verifiable parental consent. In Austria the digital-consent age is 14. Health/medical data and any social-feed participation require separate, explicit parental consent, recorded in the app, and can be withdrawn at any time. Children’s data is processed only to run the family’s shared organiser.

Legal bases (GDPR Art. 6 & 9)

Your rights

To exercise any right, email privacy@tovvle.com.

Retention

We keep your data while your family uses Tovvle. When you delete your account, your family’s data (including children’s) is removed.

Changes

We’ll update this page if our practices change, and note the date above.

Pre-launch note: Tovvle is in private testing ahead of its app-store release. This policy reflects how the app handles data today; the operating entity will move to a registered Austrian GmbH before public launch, and this page will be updated accordingly.