Privacy Notice – Småbiter
Short summary
Småbiter is a logging and reference app for parents. We have built it so that:
- Your data stays on your device. We have no server that stores your data or your child's data. If you turn on iCloud sync, the data is stored in your own iCloud account with Apple.
- We do not collect analytics, telemetry, or marketing data. No tracking.
- You're in control. You can delete everything from within the App at any time. To request a copy of your data, contact us at hello@skpgroup.no.
- We do not give health advice about your child. The App is a logging and reference tool, not a medical device. Talk to your child health clinic (helsestasjon), GP or another qualified healthcare professional if you have concerns about your child’s health.
- You can complain to the Norwegian Data Protection Authority (Datatilsynet) if you believe we are mishandling personal data.
Read the full notice below for the details.
1. Who is the data controller?
The controller for personal data processed via the Småbiter App ("the App") is:
Skp Group AS
Org. no. 937 949 812
Contact: hello@skpgroup.no
2. What personal data do we process?
We process the data you enter in the App, plus a local sign-in identity from Sign in with Apple:
| Category | Examples | Sensitive? |
|---|---|---|
| Baby profile | Nickname, date of birth, feeding type | Not sensitive in itself, but linked to a health context |
| Meal log | Foods offered, date/time, optional notes | Yes – special category (health) under GDPR Art. 9 |
| Allergen and reaction log | Food + observed reaction | Yes – special category (health) |
| Supplement log | Vitamin D daily on/off | Yes – special category (health) |
| Consent log | Timestamp, notice version, what was consented to | Not sensitive |
| App preferences | Language, theme, reminder times | Not sensitive |
| Sign-in (Sign in with Apple) | Apple ID identifier and the display name you may share on first sign-in | Not sensitive. Stored only locally in the device Keychain |
We do not process email addresses, phone numbers, location data, contact lists, biometrics, or advertising/tracking IDs. We do not use cookies or equivalent tracking technologies.
3. Why do we process the data? (purposes and legal bases)
| Purpose | What we do | Legal basis (Art. 6) | For health data (Art. 9) |
|---|---|---|---|
| Provide the core service | Log, display and remind | Art. 6(1)(b) – necessary to perform the contract with you | Art. 9(2)(a) – your explicit consent as parent |
| Local sign-in | Confirm that it is you opening the App (Sign in with Apple) | Art. 6(1)(b) – necessary to perform the contract with you | Not applicable |
| Sync across your own devices via iCloud | Store data in your own iCloud account | Art. 6(1)(a) – your consent (opt-in, withdrawable) | Art. 9(2)(a) – your explicit consent |
| Maintain a consent log | Document what you have consented to | Art. 6(1)(c) – legal obligation under Art. 7 / Art. 5(2) | Not applicable |
| Respond to rights requests | Export, deletion, rectification | Art. 6(1)(c) – legal obligation | Not applicable |
| Security and integrity | Protect against data corruption on the device | Art. 6(1)(f) – our legitimate interest in keeping the service stable | Not applicable |
We do not use the data for marketing, profiling, automated decisions, research, partner sharing or machine learning. If we ever introduce such uses, we will ask for fresh consent before starting.
4. Where is the data stored? Who has access?
4.1 Locally on your device
By default, all data is stored locally on your iOS device. We have no server that receives or stores it. No one at Småbiter has access to your data.
4.2 iCloud sync (optional)
Off by default: iCloud sync is optional and stays off until you turn it on yourself under More → Privacy in the App. If you do nothing, all data stays local on your device.
If you turn on iCloud sync in the App, the data is synchronised to your own iCloud account via Apple's CloudKit service so it is available on your other devices signed in to the same Apple ID.
- Apple Inc. acts as our data processor for this synchronisation, governed by Apple's iCloud Data Processing Addendum and the Standard Contractual Clauses (SCCs) for transfers outside the EU/EEA.
- iCloud data is stored in encrypted form. You can also enable Apple Advanced Data Protection in the iCloud settings on your device for end-to-end encryption – we recommend it.
- iCloud sync involves a transfer to Apple Inc. (USA). We have assessed this and rely on Apple's SCCs together with Apple's technical and organisational measures. You can turn iCloud sync off at any time under More → Privacy in the App, and delete the copy of your data held in iCloud from the same place. The data on your device is not affected.
4.3 No other recipients
We do not share your data with third parties. We do not sell data. We do not disclose data to authorities beyond what we are legally obliged to (today we have no mechanism for such disclosure, as we store no data on any server).
5. How long do we keep the data?
| Data type | Retention |
|---|---|
| Baby profile, meal log, allergen/reaction log, supplement log, preferences | For as long as you use the App. Deleted via "Delete all data" or when you remove the App from your device. The iCloud copy is deleted when you choose “Delete iCloud copy” under More → Privacy in the App, and is also deleted by “Delete all data”. |
| Consent log | Retained for as long as you use the App, to meet our accountability obligations under Art. 7 and Art. 5(2). The log lives only on your device — we have no server that could hold a copy — so it is deleted along with everything else when you choose "Delete all data" or remove the App from your device. |
We do not automatically delete data belonging to inactive users because the App has no servers – there is no "account" to consider inactive. The data stays under your control on your device.
6. Your rights
Under GDPR you have the following rights as a data subject:
| Right | How to exercise |
|---|---|
| Access (Art. 15) | Your data is always visible directly in the App. |
| Rectification (Art. 16) | Edit entries directly in the App. |
| Erasure (Art. 17) | Delete individual entries in the App, or use "Delete all data" in the App's profile settings. |
| Restriction (Art. 18) | Stop using the affected features, or contact us. |
| Data portability (Art. 20) | Use "Export my data" under More → Privacy in the App to save all your data as a JSON file. The file is produced directly from your device – we have no copy to draw on. You can also contact us at hello@skpgroup.no. The export will contain your child's health data – share with care. The same applies to the report you can share from the App (History → Report): the image contains your child's name, date of birth, recorded allergens and reactions and your own notes, and goes wherever you choose to send it – share with care. |
| Objection (Art. 21) | Contact us at hello@skpgroup.no. |
| Withdraw consent (Art. 7) | Use "Delete all data" in the App to withdraw consent for local processing. You can withdraw consent to iCloud sync yourself under More → Privacy, where you can also delete the copy of your data held in iCloud. Withdrawal does not affect the lawfulness of processing before withdrawal. |
| No automated decisions (Art. 22) | The App makes no automated decisions about you or your child. |
For rights enquiries, contact us at hello@skpgroup.no. We respond as soon as possible and no later than within one month, in line with Art. 12(3).
7. Right to complain to the supervisory authority
If you believe we are processing personal data unlawfully, you may complain to:
Datatilsynet (the Norwegian Data Protection Authority)
PO Box 458 Sentrum, 0105 Oslo, Norway
postkasse@datatilsynet.no
www.datatilsynet.no
Feel free to contact us first, but you have every right to go directly to Datatilsynet.
8. Children
The App is intended for parents and caregivers – not the child. The parent acts as the child's legal guardian and gives consent on the child's behalf for processing of the child's health data (Art. 9(2)(a)).
We have made the following design choices to protect the child:
- We don't ask for more than is necessary (a nickname is enough – no full name).
- We process no biometrics, no location, no photos of the child, no identifiers.
- We do not profile or score the child.
- The App's content is directed at parents; no feature in the App is directed at children.
9. Security
We have implemented technical and organisational measures to safeguard your data:
- iOS default data protection (NSFileProtectionComplete) – data is encrypted when the device is locked.
- Sensitive values are stored in the iOS Keychain.
- All network traffic uses TLS 1.2 or newer.
- No third-party analytics, crash-reporting or tracking modules are included in the App.
- iCloud data is encrypted by Apple; we recommend enabling Apple Advanced Data Protection.
You contribute to security by using your device lock (passcode, Face ID, Touch ID) and two-factor authentication on your Apple ID. If you share the device with others in the family, be aware they will have the same access to the App as you do.
10. What the App is not
To avoid misunderstanding:
- The App is not a medical device (EU MDR 2017/745). It does not diagnose, assess nutritional status or provide clinical recommendations.
- The App does not replace contact with your child health clinic (helsestasjon), GP or another qualified healthcare professional.
- Småbiter is not affiliated with Helsenorge, Helsedirektoratet or any public authority.
11. Changes to this notice
We may update this notice, for example when adding features or to reflect new legal requirements.
- Material changes (new purposes, new processing, new recipients): we notify you in the App and request fresh consent before starting the new processing.
- Minor changes (clarifications, corrections): logged in the change log at the foot of this notice and take effect without separate notification.
You can always find the current version in the App, and on this page.
12. Contact
For privacy enquiries: hello@skpgroup.no.
We have not appointed a Data Protection Officer (the Art. 37 assessment is documented in our DPIA).
Change log
| Version | Date | Changes |
|---|---|---|
| 1.0 | 2026-07-18 | Initial version. |
| 1.1 | 2026-07-31 | Corrected the data-export and iCloud opt-out claims to match current app capability: self-service export and the iCloud sync toggle are not yet released, so both now route to hello@skpgroup.no in the meantime. |
| 1.2 | 2026-08-08 | The iCloud sync toggle has shipped (Settings → Privacy), with its own consent, a consent log, and the option to delete the iCloud copy. The requirement to opt out by email is therefore removed. Self-service data export is still not released. |
| 1.3 | 2026-08-12 | Clarified how long the consent log is kept. The previous wording — that the log is retained for at least 3 years after withdrawal — did not match how the App works: the log lives only on your device, and "Delete all data" deletes it along with everything else. We have no server that could hold a copy, so we no longer promise something we cannot keep. |
| 1.4 | 2026-08-23 | Clarified how a request for a copy of your data (Art. 20) is actually fulfilled. The previous wording — "we will provide your data" — could be read as though we hold a copy. We do not: the file is extracted from your own device, with our help. No change to what is processed or where. |
| 1.5 | 2026-08-23 | Two corrections to the description of existing processing — no new processing. (1) §2/§3: the sign-in identity from Sign in with Apple (Apple ID identifier and the display name you may share on first sign-in, stored only locally in the Keychain) was missing from the inventory, and "surnames" is removed from the list of what we do not process — the display name can contain a surname. (2) The path "Settings → Privacy" does not exist in the App; the correct path is "More → Privacy". §5 clarified: the iCloud copy is deleted from that screen or by "Delete all data", not from the device's iCloud settings. |
| 1.6 | 2026-08-25 | Language polish from the website review, no change to any processing, right or promise. Summary item 4 and §2, §3, §4.2, §5, §8, §9, §10: plainer phrasing – "child health clinic (helsestasjon)" glossed for English readers, "data belonging to inactive users" for precision in §5, and the "at MVP" qualifier dropped in §9 because the no-third-party-modules claim holds unqualified. |
| 1.7 | 2026-08-26 | Self-service data export has shipped ("Export my data" under More → Privacy in the App). The data-portability row now describes self-service export instead of email routing; email remains an alternative. No change to the processing. |