tuck
Get the app
How it works Safety Philosophy Blog FAQ Get the app

Privacy

Privacy policy

Last updated 25 July 2026

The short version

  • A child's account has no email address, no password and no phone number.
  • We don't sell data, we don't run adverts, and we don't profile anyone.
  • Parents can read their children's conversations. That's the product working as intended.
  • Messages are encrypted while we store them, but not end-to-end — we hold the key on purpose, so safety filtering works and parents can see.
  • You can export everything at any time, and delete it all permanently.

This summary isn't the policy — it's a signpost. The sections below are the real thing.

On this page

  1. Who we are
  2. What we collect
  3. What we don't do
  4. How we use it
  5. Our legal bases
  6. Children, consent and COPPA
  7. What parents can see
  8. Who we share it with
  9. Where your data is held
  10. How long we keep it
  11. Your rights
  12. Security
  13. Cookies and tracking
  14. Changes to this policy
  15. Contact us

Who we are

Tuck is a messaging app for children aged 6 to 16, on iPhone and iPad. It is made and operated by Songbox Technologies Ltd. Where this policy says "we", "us" or "Tuck", that's who it means.

We are the data controller for the information described here. That means we decide what is collected and why, and we're accountable for it. You can reach us any time — see Contact us.

What we collect

Tuck is built to need as little as possible. Here is all of it.

Parent accounts

You create a parent account with Sign in with Apple. Apple sends us:

  • A permanent identifier for your Apple Account — a long random string that identifies you to us and to nobody else.
  • Your email address, if you choose to share it. If you use Apple's "Hide My Email", we only ever see the private relay address Apple generates for us, never your real one.
  • Your name, if you choose to share it.

Apple only sends your email and name the first time you authorise Tuck, so we store them rather than ask again. We never see or receive your Apple password.

Children's accounts

A parent creates each child's account inside the app. A child's account holds:

  • A first name — whatever the family wants them called in the app.
  • A colour and, if they want one, an emoji avatar the child picks themselves.
  • Their settings: whether messaging is on, whether parent visibility is on, and quiet hours.

That's the lot. No email address, no password, no phone number, no age or date of birth, no photograph, no home address, no school, no location. A child cannot create an account themselves, and there is nothing for a child to fill in beyond a colour and an emoji.

To set a child up on their device, the parent's app generates a short one-time pairing code. It expires, and it can only be used once.

Messages

We store the messages children send and receive: the text, who sent it, which conversation it belongs to, and when it was sent. Tuck is text and emoji only — there is no photo or video messaging, so there are no images or recordings for us to hold.

Blocked messages

If a child tries to send a message containing blocked language or a link, we don't deliver it and we don't store it as a message. We do record the attempt in that family's activity feed, including the text that was blocked and any link it contained, so a parent can see exactly what happened and talk to their child about it. The child's own parents are notified. Nothing is shared with the other family.

"Ask a grown-up" notes

If a child wants to connect with a friend whose device isn't there, they can write a short note (up to 120 characters) asking a grown-up to sort it out. It's a to-do for their own parents. It matches no record and connects to nobody. We store it until a parent resolves or dismisses it.

Devices

For each device signed in to Tuck we store an identifier for that device, its platform (iPhone or iPad), and — if notifications are switched on — the Apple Push Notification token that lets Apple deliver an alert to it.

We do not collect advertising identifiers, contacts, photos, microphone or camera recordings, or location. The camera is used only to scan a connection QR code when two people are standing together; nothing from it is stored or uploaded.

Family activity log

So parents can see what's going on, we keep a log of consequential events in a family: a connection requested, a connection opened, a connection paused or resumed, a message blocked, another parent joining the family, a child's device being set up. Each entry records what happened, who did it, and when.

The website

tuck.chat is a plain static page. Our hosting providers keep ordinary server logs — which include IP addresses — for security, abuse prevention and reliability.

What we don't do

Some of this policy is best expressed as a list of absences.

  • No advertising. There are no adverts in Tuck and no third-party ad networks or ad SDKs anywhere in the app or on this site.
  • No selling or renting data. Not to advertisers, not to data brokers, not to anyone. Ever.
  • No behavioural profiling and no engagement tracking. Tuck has no feed and no algorithm, so there is nothing to optimise a child's attention against.
  • No analytics on this website. No analytics scripts, no tracking pixels, no cookies (see Cookies and tracking).
  • No search, no discovery, no friend suggestions, no invite links. There is no way for a stranger to find or contact a child on Tuck.
  • No photos or videos, from anyone, in either direction.

How we use it

Every use below is one of these six things. There isn't a seventh.

  • To run the app — signing you in, keeping accounts and connections, delivering messages between children who are connected.
  • To keep children safe — checking every message for links and blocked language before it is sent, and giving parents the visibility and controls the product is built around.
  • To send notifications — a new message, a connection waiting for approval, a message that was blocked. Notifications are sent through Apple to your device.
  • To let parents see and manage their family — conversations, the activity feed, per-child settings, pausing a connection, exporting or deleting data.
  • To keep Tuck secure and working — preventing abuse, spam and fraud, diagnosing faults, keeping backups.

We do not use anyone's messages to train machine learning models, and we do not read them except where it is strictly necessary to run the safety filter, investigate abuse, or comply with the law.

Our legal bases

If you're in the UK or the EU, data protection law requires us to have a lawful basis for each use. Ours are:

  • Performing our contract with you — creating and running accounts, connections, messaging and notifications. Without this data there is no app.
  • Our legitimate interests — keeping Tuck secure, preventing abuse, and keeping the family activity log that makes parental oversight possible. We've weighed these against the interests of children in particular, and kept the data to the minimum that makes the safety promise real.
  • Consent — for push notifications (which iOS asks you to allow, and you can withdraw at any time in iOS Settings). You can withdraw consent without affecting anything that happened before.
  • Legal obligations — where we're required to keep or disclose information by law.

Where a lawful basis depends on consent and the person is a child, that consent is given or authorised by their parent, who holds the account. See Children, consent and COPPA.

Children, consent and COPPA

Tuck is for children. Children's personal data is the whole point of the service, so this section matters more than any other.

A parent is always the account holder

There is no self-signup for children. A parent creates the parent account with Sign in with Apple, creates each child, and pairs their device with a one-time code. Every child on Tuck exists because a parent put them there and controls them.

We treat that arrangement as the parental consent itself: the account is held by a verified adult through Sign in with Apple, every child profile is created by that adult, and a child's device only works after the parent enters a one-time code on it. We do not use a third-party consent service, and we never ask a child to confirm anything on their parent's behalf.

For families in the United States (COPPA)

The Children's Online Privacy Protection Act gives parents specific rights over their under-13s' information. On Tuck:

  • We collect from a child only their first name, chosen colour and emoji, their settings, their device identifier and push token, and the messages they send and receive. Nothing else.
  • We never require a child to disclose more than is reasonably necessary to use Tuck as a condition of taking part.
  • We never publicly disclose a child's information, and we never make it available to other users beyond the children their parents have approved a connection with.
  • We do not use children's data for advertising, profiling or any form of behavioural targeting.
  • A parent can review everything we hold (in-app, and as a full export), refuse further collection (turn messaging off, pause a connection, or delete the child), and delete the child or the whole account at any time.

For families in the UK and EU (GDPR)

Children merit specific protection under UK and EU data protection law, and we've designed to that standard: minimal data, no profiling, no nudge techniques, high-privacy defaults, and an adult who is accountable for every child account.

  • Because a parent creates and consents for every child, that consent is given or authorised by the holder of parental responsibility — the account holder — whatever the child's age. We don't collect a date of birth: rather than deciding protections by age, we apply the same high-privacy design to every child.
  • We've written this policy so a parent can understand it. If your child wants to know what Tuck knows about them, show them What we collect — it's deliberately short.

What parents can see

This is a feature, not a footnote, so we'll be blunt about it: parents can read their children's conversations on Tuck. Every message, in every chat, at any time.

Parents can also see the family activity feed — new connections, connections paused or resumed, and every message that was blocked, including the text the child tried to send.

Parent visibility is on by default. A parent can turn it off for an individual child in that child's settings — for an older teenager, say — and turn it back on. Any parent in the family can pause a connection, and either family can pause a connection between their children.

We think children should be told that their grown-ups can see their chats. It's a fairer arrangement than surveillance, and it's the honest version of what Tuck is. Tuck won't have that conversation for you, but we'd encourage you to have it.

Who we share it with

We don't sell data and we don't share it for anyone else's purposes. We do rely on a small number of companies to run the service. They process data only on our instructions, under contract, and may not use it for their own ends.

  • Apple — Sign in with Apple (parent sign-in) and the Apple Push Notification service (delivering notifications to devices).
  • Laravel Cloud — hosting for the Tuck application and its database. This is where accounts, connections and messages live.
  • Cloudflare — hosting for the tuck.chat website and DNS for our domains.
  • Resend — sending email, such as delivering a message you send us through the contact form.

We may also disclose information where we're legally required to, where it's necessary to establish or defend legal claims, or where there is a genuine risk to a child's safety. If Tuck is ever sold or transferred, data would move with it, and you'd be told before that happened.

Each of these providers handles data only on our instructions, under the standard data processing terms that form part of their service agreements. We keep this list current: if we add a provider that touches personal data, it appears here.

Where your data is held

Tuck's application and database are hosted with Laravel Cloud in London, in the United Kingdom, so your messages are stored in the UK. Cloudflare serves the website from a global network, meaning the page you're reading may be delivered from a server near you.

Some of our providers are based in, or operate from, the United States. Where personal data is transferred outside the UK or the European Economic Area, we rely on the safeguards approved for such transfers — the UK International Data Transfer Addendum and the EU Standard Contractual Clauses — together with each provider's own compliance commitments.

How long we keep it

We keep your family's data for as long as the account exists. When you delete something, here's exactly what happens:

  • Delete a child. They disappear from the app immediately and messaging stops at once. Their data is then permanently erased 30 days later by a scheduled job.
  • Delete your account. All sessions are revoked immediately, the whole family stops working immediately, and everything — parents, children, devices, connections, conversations, messages and the activity log — is permanently erased 30 days later.
  • Delete a message. Same 30-day window, then it is gone.

The 30-day gap is an operational grace period, not a hold on your request: the data is switched off the moment you ask, and the erasure that follows is permanent and irreversible. If you need it erased sooner, ask us and we'll do it.

Server logs are kept for a short period for security and reliability.

Your rights

Depending on where you live, you have some or all of the rights below. Children have the same rights over their own data; in practice a parent exercises them on their child's behalf, because the parent holds the account.

  • Access — see what we hold. Most of it is already visible in the app.
  • Export — the parent app can produce a complete machine-readable export of everything your family holds, including conversations, at any time. It deliberately leaves out your Apple identifier.
  • Correction — fix anything that's wrong. Names and settings are all editable in the app.
  • Deletion — delete a child, or the whole account, as described above.
  • Restriction and objection — ask us to stop or limit a particular use.
  • Withdrawing consent — turn notifications off.
  • Complaining to a regulator — see Contact us.

We won't charge you for any of this, and we won't treat you differently for asking. We'll respond within one month.

Security

Everything travels between the app and our servers over an encrypted connection (HTTPS). Message text is encrypted at rest in our database using a key held on our server. Sessions are token-based, and tokens are revoked the moment you sign out or delete an account.

Tuck is not end-to-end encrypted, and that's deliberate

We want to be completely straight about this, because plenty of messaging apps advertise the opposite.

End-to-end encryption means only the two people chatting can read a message — not even the company running the app. Tuck doesn't work that way. We hold the encryption key, which means we are technically able to read message text. We chose that, for two reasons:

  • Safety filtering has to run on the server. Blocking links and blocked language on the device alone would be defeated by anyone who modified the app. Checking on the server means the rule holds for everyone, always.
  • Parents can read their children's conversations. That's the core promise of Tuck, and it isn't possible if the server can't read the text.

So: encryption at rest protects your family's messages if our storage were ever exposed. It does not, and is not meant to, hide them from us. In practice we don't read messages — access is limited to the small number of people who need it to run and support the service, and we only look where it's necessary for safety, support or a legal obligation.

No system is perfectly secure. If a breach ever affects your personal data, we'll notify the relevant regulator and the people affected as required by law, without undue delay.

Cookies and tracking

This website sets no cookies. There are no analytics, no tracking pixels, no advertising tags and no third-party scripts of any kind. That's why you haven't been asked to accept anything.

The one external request this page makes is for the Fredoka display font, which is served by Google Fonts. As with any request to another server, Google receives your IP address and basic browser information in order to send the font back. It is not used to identify you to us, and we receive nothing from it.

The Tuck app itself doesn't use cookies — it authenticates with a token stored securely on the device.

Changes to this policy

If we change this policy, we'll update the date at the top of the page. If a change materially affects your family — a new purpose, a new processor, a change to what we collect — we'll tell parents in the app or by email before it takes effect, rather than quietly editing the page.

Contact us

Questions about this policy, or about your family's data? Send us a message and a real person will reply.

If you're in the UK and you're unhappy with how we've handled your data, you can complain to the Information Commissioner's Office at ico.org.uk. If you're in the EEA, you can complain to your local supervisory authority. We'd rather you came to us first, so we can put it right.

tuck

Messaging for your child. Peace of mind for you.

Philosophy Blog FAQ Privacy Contact

© 2026 Tuck