Tita — Privacy Policy
1. Who we are
This policy explains how personal information is handled when you use the Tita beta. For the Hong Kong beta, public privacy and rights correspondence is handled through privacy@asktita.com.
Privacy contact: privacy@asktita.com.
Initial beta service territory: Hong Kong.
This Privacy Policy explains how Tita handles personal information when people visit the public website, create or use an account, join or operate a household, use care and organisation features, contact support, participate in beta research or receive service communications.
2. Our privacy principles
Tita is designed around household trust. We aim to:
- collect only information reasonably needed for the service and approved purposes;
- keep household contexts and permissions separate;
- treat children as data subjects with their own interests and rights;
- apply additional care to health, medication, care and other sensitive information;
- avoid behavioural advertising and sale of household or child personal data;
- minimise information included in notifications, logs and telemetry;
- use service providers only for defined purposes; and
- not use customer household content to train general-purpose AI models unless a materially different use is separately justified, clearly disclosed and lawfully authorised.
3. Information we may collect
Account and identity information — this may include email address, authentication/provider identifiers, display name, confirmed sex, mobile number, verification status, profile photo if provided, security information and account preferences.
Household and membership information — this may include household name, household timezone, membership, role, invitations, active-household selection, access state and household preferences.
Child information — this may include a child’s name, date of birth, relationship/context, profile information and other child-specific information entered into Tita.
Care and health-related information — depending on enabled features, this may include feeding, breastfeeding, pumping, sleep, nappies, growth and measurements, allergies, food reactions, symptoms, temperature, medication, health observations and related notes.
Family organisation information — this may include calendars, responsibilities, tasks, routines, meal plans, recipes, shopping information, notes and other household organisation content.
Helper, nanny, caregiver and contact information — this may include information about household members, helpers, nannies, caregivers, sitters, external contacts or other people recorded for household coordination.
Support and research information — this may include support requests, feedback and information you separately choose to provide during research, interviews or testing.
Technical and security information — this may include device/browser type, IP address, authentication/session events, service-worker or Push subscription state, security events, error information and diagnostic metadata.
Usage and product telemetry — where enabled, we may record bounded product events needed to operate and evaluate beta, such as signup/activation milestones, errors and critical workflow outcomes. Routine telemetry is designed not to contain raw household, child, care, note, search or health content.
Derived and AI-assisted information — some features may create summaries, classifications, estimates or other outputs based on authorised Tita information and approved sources.
4. Children’s information
Children do not create or operate accounts during this beta, but Tita may process information about children entered by adults.
A child is a data subject. Child information is not owned collectively by the household merely because household members can access an authorised shared record.
An in-product role such as Owner, Parent or Admin is not proof of legal parenthood, guardianship, custody or other legal authority.
Where we receive a rights request or authority dispute involving a child, we may need to consider the identity and authority of the requester, the child’s interests and rights, the rights of other affected people and applicable law.
5. Why we use personal information
We may use personal information to:
- create, secure and administer accounts;
- create and operate households and memberships;
- provide household organisation and child-care recording features;
- sync and preserve authorised household records across devices;
- provide reminders and service communications;
- provide support and resolve service issues;
- protect accounts, households and service integrity;
- operate beta admission and founding-benefit eligibility;
- understand bounded activation, reliability and product-performance signals;
- provide AI-assisted features where enabled;
- comply with legal obligations and respond to lawful requests; and
- conduct optional research where separately disclosed and, where appropriate, separately consented.
We do not use household or child information for behavioural advertising.
6. Lawful bases — UK users
This section applies where UK data-protection law applies. The final purpose-by-purpose lawful-basis mapping must be approved before UK beta admission.
Proposed mapping for legal review:
- Account creation and core service for the account holder — contract where processing is necessary to provide the requested service.
- Household/member/third-party information where the person is not party to the account contract — legitimate interests, subject to a documented necessity and balancing assessment, or another applicable basis.
- Security, fraud prevention and service integrity — legitimate interests and/or legal obligation where applicable.
- Required service communications — contract, legitimate interests or legal obligation depending on purpose.
- Support — contract and/or legitimate interests.
- Bounded service improvement and beta analytics — legitimate interests where the balancing test supports it; consent where required by separate storage/access or other rules.
- Marketing — consent or another specifically permitted direct-marketing basis; marketing will remain separate from service processing.
- Legal compliance — legal obligation.
- Optional research — basis depends on the research design and will be separately assessed.
Health and other special-category information — where Tita processes information that is special-category data under UK law, an Article 6 lawful basis is not enough; a separate Article 9 condition is required.
7. Hong Kong collection
Where Hong Kong’s Personal Data (Privacy) Ordinance applies, Tita will collect and use personal data for the purposes disclosed in the applicable Personal Information Collection Statement and this policy.
The signup PICS will state the purposes of collection, the classes of people to whom data may be transferred, whether requested information is obligatory or voluntary, the consequences of not providing obligatory information, and the contact details for access and correction requests.
8. Information about other people
If you enter information about another adult, child, caregiver, sitter or contact, you are responsible for doing so appropriately.
We may provide contextual notices or other mechanisms where the nature of a feature creates additional transparency requirements.
9. Household visibility and permissions
Tita uses household, membership, role, child and record-specific authority to determine access.
Shared household use does not mean every member can see every category of information. Certain information may be private, member-scoped, child-scoped, role-scoped or otherwise restricted.
We design Tita to avoid cross-household leakage when a person belongs to more than one household.
10. AI and automated processing
Where an AI-assisted feature is enabled, Tita may send the minimum approved information needed to an authorised provider or model to perform the requested function.
AI providers should not use customer household data for their own model training or unrelated purposes by default.
Tita treats AI output as a proposal, summary or derived result unless an authoritative product workflow confirms it.
11. Service providers and recipients
We may use authorised service providers for:
- cloud hosting and database/storage;
- authentication;
- application delivery and infrastructure;
- email and communications;
- Push delivery infrastructure;
- security and error monitoring;
- analytics where approved and enabled;
- AI processing where required by an enabled feature; and
- other operational services necessary for Tita.
We do not sell household or child personal data.
Third-party recipe sources are different from our service providers. When Tita shows a recipe image hosted by a publisher, or when you open a recipe link, your browser contacts that third party directly. That connection can expose the ordinary request information a browser sends, which may include your IP address, browser and device information and, depending on your browser and its settings, referrer information.
Tita does not route third-party recipe images through our own servers simply to hide that connection. Doing so would have copyright, source-terms, privacy, caching and security consequences that must be reviewed before any such change.
12. International transfers
Tita and its providers may process information in more than one country.
Before publication, we will identify the actual locations and transfer routes used by the beta release and apply any safeguards required by applicable law.
13. Retention
We keep personal information only for as long as needed for the approved purpose, account/household operation, security, legal requirements, dispute handling and permitted recovery.
Different data classes may have different retention periods. Account deletion, leaving a household, household deletion, archival/tombstone history and backup retention are not necessarily the same event.
14. Security
We use technical and organisational measures designed to protect Tita information, including authentication, household/role-based authority, server-side access controls, security logging and restricted operator access.
No system is completely secure. If we identify a personal-data incident, we will assess, contain, investigate and notify affected people or regulators where required.
15. Notifications
Notifications can appear on a lock screen or in email. We design notification content to minimise sensitive detail.
Push permission is device/browser specific. Tita cannot override a platform-level denial.
16. Cookies and similar technologies
Tita may use cookies, local storage, service-worker/browser storage and similar technologies.
The Cookie & Similar Technologies Notice explains the release-candidate inventory and the applicable consent, exception or objection controls.
We do not assume that every analytics technology requires the same consent treatment; the actual purpose and technology are classified before release.
17. Marketing
Service and security communications are separate from marketing.
We will not make household membership or beta participation conditional on agreeing to unrelated marketing. Where consent is required, it will be requested separately and can be withdrawn.
18. Optional research
Participation in interviews, recorded sessions, focus groups or other research is optional.
Where appropriate, research consent is separate from ordinary service processing and from marketing consent. General acceptance of the Terms does not by itself authorise recording or unrestricted reuse of private household content for research.
19. Your rights
Depending on where you live and the law that applies, you may have rights to ask us to access, correct, delete or restrict use of personal information, object to certain processing, receive information in a portable form, withdraw consent where processing relies on consent, or complain to a data-protection authority.
Some requests involving shared household records or children may require us to consider the rights and authority of more than one person.
To make a request: privacy@asktita.com.
We may need to verify identity and authority before acting on a request.
20. Complaints
Please contact us first at privacy@asktita.com if you have a privacy concern.
For the Hong Kong beta, you may also complain to the Office of the Privacy Commissioner for Personal Data (PCPD), Hong Kong. The PCPD recommends raising the concern with the relevant data user first where appropriate; complaint information is available from the PCPD.
21. Changes to this policy
We may update this policy as Tita changes or legal requirements evolve. Where a change materially affects how personal information is used or people’s rights, we will provide appropriate notice.
