Privacy Notice – Småbiter

Version 1.8 · Effective from 18 July 2026 (last updated 10 September 2026) · Norsk versjon is authoritative

Short summary

Småbiter is a logging and reference app for parents. We have built it so that:

  1. Your data stays on your device. We have no server that stores your data or your child's data. If you turn on iCloud sync, the data is stored in your own iCloud account with Apple.
  2. We do not collect analytics, telemetry, or marketing data. No tracking.
  3. You're in control. You can delete everything from within the App at any time. To request a copy of your data, contact us at hello@skpgroup.no.
  4. We do not give health advice about your child. The App is a logging and reference tool, not a medical device. Talk to your child health clinic (helsestasjon), GP or another qualified healthcare professional if you have concerns about your child’s health.
  5. You can complain to the Norwegian Data Protection Authority (Datatilsynet) if you believe we are mishandling personal data.

Read the full notice below for the details.

1. Who is the data controller?

The controller for personal data processed via the Småbiter App ("the App") is:

Skp Group AS
Org. no. 937 949 812
Contact: hello@skpgroup.no

2. What personal data do we process?

We process the data you enter in the App, plus a local sign-in identity from Sign in with Apple:

CategoryExamplesSensitive?
Baby profileNickname, date of birth, feeding typeNot sensitive in itself, but linked to a health context
Meal logFoods offered, date/time, optional notesYes – special category (health) under GDPR Art. 9
Allergen and reaction logFood + observed reactionYes – special category (health)
Supplement logVitamin D daily on/offYes – special category (health)
Consent logTimestamp, notice version, what was consented toNot sensitive
App preferencesLanguage, theme, reminder timesNot sensitive
Sign-in (Sign in with Apple)Apple ID identifier and the display name you may share on first sign-inNot sensitive. Stored only locally in the device Keychain

We do not process email addresses, phone numbers, location data, contact lists, biometrics, or advertising/tracking IDs. We do not use cookies or equivalent tracking technologies.

3. Why do we process the data? (purposes and legal bases)

PurposeWhat we doLegal basis (Art. 6)For health data (Art. 9)
Provide the core serviceLog, display and remindArt. 6(1)(b) – necessary to perform the contract with youArt. 9(2)(a) – your explicit consent as parent
Local sign-inConfirm that it is you opening the App (Sign in with Apple)Art. 6(1)(b) – necessary to perform the contract with youNot applicable
Sync across your own devices via iCloudStore data in your own iCloud accountArt. 6(1)(a) – your consent (opt-in, withdrawable)Art. 9(2)(a) – your explicit consent
Maintain a consent logDocument what you have consented toArt. 6(1)(c) – legal obligation under Art. 7 / Art. 5(2)Not applicable
Respond to rights requestsExport, deletion, rectificationArt. 6(1)(c) – legal obligationNot applicable
Security and integrityProtect against data corruption on the deviceArt. 6(1)(f) – our legitimate interest in keeping the service stableNot applicable

We do not use the data for marketing, profiling, automated decisions, research, partner sharing or machine learning. If we ever introduce such uses, we will ask for fresh consent before starting.

4. Where is the data stored? Who has access?

4.1 Locally on your device

By default, all data is stored locally on your iOS device. We have no server that receives or stores it. No one at Småbiter has access to your data.

4.2 iCloud sync (optional)

Off by default: iCloud sync is optional and stays off until you turn it on yourself under More → Privacy in the App. If you do nothing, all data stays local on your device.

If you turn on iCloud sync in the App, the data is synchronised to your own iCloud account via Apple's CloudKit service so it is available on your other devices signed in to the same Apple ID.

4.3 No other recipients

We do not share your data with third parties. We do not sell data. We do not disclose data to authorities beyond what we are legally obliged to (today we have no mechanism for such disclosure, as we store no data on any server).

5. How long do we keep the data?

Data typeRetention
Baby profile, meal log, allergen/reaction log, supplement log, preferencesFor as long as you use the App. Deleted via "Delete all data" or when you remove the App from your device. The iCloud copy is deleted when you choose “Delete iCloud copy” under More → Privacy in the App, and is also deleted by “Delete all data”.
Consent logRetained for as long as you use the App, to meet our accountability obligations under Art. 7 and Art. 5(2). The log lives only on your device — we have no server that could hold a copy — so it is deleted along with everything else when you choose "Delete all data" or remove the App from your device.

We do not automatically delete data belonging to inactive users because the App has no servers – there is no "account" to consider inactive. The data stays under your control on your device.

6. Your rights

Under GDPR you have the following rights as a data subject:

RightHow to exercise
Access (Art. 15)Your data is always visible directly in the App.
Rectification (Art. 16)Edit entries directly in the App.
Erasure (Art. 17)Delete individual entries in the App, or use "Delete all data" in the App's profile settings.
Restriction (Art. 18)Stop using the affected features, or contact us.
Data portability (Art. 20)Use "Export my data" under More → Privacy in the App to save all your data as a JSON file. The file is produced directly from your device – we have no copy to draw on. You can also contact us at hello@skpgroup.no. The export will contain your child's health data – share with care. The same applies to the report you can share from the App (History → Report): the image contains your child's name, date of birth, recorded allergens and reactions and your own notes, and goes wherever you choose to send it – share with care.
Objection (Art. 21)Contact us at hello@skpgroup.no.
Withdraw consent (Art. 7)Use "Delete all data" in the App to withdraw consent for local processing. You can withdraw consent to iCloud sync yourself under More → Privacy, where you can also delete the copy of your data held in iCloud. Withdrawal does not affect the lawfulness of processing before withdrawal.
No automated decisions (Art. 22)The App makes no automated decisions about you or your child.

For rights enquiries, contact us at hello@skpgroup.no. We respond as soon as possible and no later than within one month, in line with Art. 12(3).

7. Right to complain to the supervisory authority

If you believe we are processing personal data unlawfully, you may complain to:

Datatilsynet (the Norwegian Data Protection Authority)
PO Box 458 Sentrum, 0105 Oslo, Norway
postkasse@datatilsynet.no
www.datatilsynet.no

Feel free to contact us first, but you have every right to go directly to Datatilsynet.

8. Children

The App is intended for parents and caregivers – not the child. The parent acts as the child's legal guardian and gives consent on the child's behalf for processing of the child's health data (Art. 9(2)(a)).

We have made the following design choices to protect the child:

9. Security

We have implemented technical and organisational measures to safeguard your data:

You contribute to security by using your device lock (passcode, Face ID, Touch ID) and two-factor authentication on your Apple ID. If you share the device with others in the family, be aware they will have the same access to the App as you do.

10. What the App is not

To avoid misunderstanding:

11. Changes to this notice

We may update this notice, for example when adding features or to reflect new legal requirements.

You can always find the current version in the App, and on this page.

12. Contact

For privacy enquiries: hello@skpgroup.no.

We have not appointed a Data Protection Officer (the Art. 37 assessment is documented in our DPIA).

Change log

VersionDateChanges
1.02026-07-18Initial version.
1.12026-07-31Corrected the data-export and iCloud opt-out claims to match current app capability: self-service export and the iCloud sync toggle are not yet released, so both now route to hello@skpgroup.no in the meantime.
1.22026-08-08The iCloud sync toggle has shipped (Settings → Privacy), with its own consent, a consent log, and the option to delete the iCloud copy. The requirement to opt out by email is therefore removed. Self-service data export is still not released.
1.32026-08-12Clarified how long the consent log is kept. The previous wording — that the log is retained for at least 3 years after withdrawal — did not match how the App works: the log lives only on your device, and "Delete all data" deletes it along with everything else. We have no server that could hold a copy, so we no longer promise something we cannot keep.
1.42026-08-23Clarified how a request for a copy of your data (Art. 20) is actually fulfilled. The previous wording — "we will provide your data" — could be read as though we hold a copy. We do not: the file is extracted from your own device, with our help. No change to what is processed or where.
1.52026-08-23Two corrections to the description of existing processing — no new processing. (1) §2/§3: the sign-in identity from Sign in with Apple (Apple ID identifier and the display name you may share on first sign-in, stored only locally in the Keychain) was missing from the inventory, and "surnames" is removed from the list of what we do not process — the display name can contain a surname. (2) The path "Settings → Privacy" does not exist in the App; the correct path is "More → Privacy". §5 clarified: the iCloud copy is deleted from that screen or by "Delete all data", not from the device's iCloud settings.
1.62026-08-25Language polish from the website review, no change to any processing, right or promise. Summary item 4 and §2, §3, §4.2, §5, §8, §9, §10: plainer phrasing – "child health clinic (helsestasjon)" glossed for English readers, "data belonging to inactive users" for precision in §5, and the "at MVP" qualifier dropped in §9 because the no-third-party-modules claim holds unqualified.
1.72026-08-26Self-service data export has shipped ("Export my data" under More → Privacy in the App). The data-portability row now describes self-service export instead of email routing; email remains an alternative. No change to the processing.