Privacy Policy
Last updated: 28.06.2026
We take the protection of your data seriously. This Privacy Policy explains what personal data we collect when you use Taddoo, how we process it and what rights you have. Switzerland is our primary jurisdiction; the Swiss Federal Act on Data Protection (revFADP / revDSG, in force since 1 September 2023) applies. For users located in the European Union, the General Data Protection Regulation (GDPR) also applies and we comply with both regimes in parallel.
This Privacy Policy covers the Taddoo web application as well as our iOS app Tattoomii Artist (available on the Apple App Store). Both are operated by Tattoomii GmbH and process your data as described below. The same controller, processors, and rights apply across web and app.
1. Controller
Tattoomii GmbH, Badenerstrasse 541, 8048 Zurich, Switzerland.
Contact: Noa Walser, hello@tattoomii.com
We have not appointed a representative in the EU under Art. 27 GDPR because the threshold for mandatory appointment is not met. EU residents can reach us directly at the email above.
2. What data we process
- Account data: name, email, studio name, password hash, multi-factor secret, locale and theme preferences.
- Email content: through the Gmail OAuth connection, incoming and outgoing customer emails are read, stored encrypted in our database and used to generate reply drafts.
- Attachments and images: tattoo references are stored in a private storage bucket and served only through signed URLs.
- Customer data of your studio: name, email, phone, tags, notes, appointment history, free-text notes you enter for that customer.
- Usage data: technical logs (IP, browser, timestamp) to ensure operation, debug issues, and detect abuse.
- Consent records: timestamp and version of the Terms and Privacy Policy you accepted, used as evidence of consent.
- Waitlist data: email address, locale and browser user agent when signing up to the waitlist.
3. Google user data and Limited Use
To connect a Gmail mailbox, Taddoo requests the Google OAuth scopes gmail.readonly (to read incoming and outgoing customer emails), gmail.send (to send the reply you have approved) and gmail.modify (to mark a message as read after a reply is sent). We request only the narrowest scopes needed for these features and request no scope beyond them. Google user data obtained through these scopes is used solely to provide the user-facing features of Taddoo described in this policy: reading customer inquiries, extracting structured fields, generating reply drafts that a studio member reviews, and sending the reply that a studio member has approved.
Taddoo's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not use Google user data for advertising and do not sell or transfer it to third parties such as advertising platforms, data brokers, or for profiling, credit-worthiness, or lending purposes; we do not allow humans to read your Google user data except (a) with your explicit consent for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymised. Email content is transmitted to our AI sub-processors (via OpenRouter) only to generate the draft requested, and neither we nor those providers use your Google user data to develop, train, or improve generalised AI or machine-learning models.
We transfer Google user data only in the following cases: to provide or improve the user-facing features described above (including to the hosting and AI sub-processors named in section 6 below, who act strictly on our instructions); for security purposes such as investigating abuse; or to comply with applicable law. We do not transfer or sell Google user data to any third party for advertising, data brokerage, profiling, market research, or any other purpose, and we do not transfer Google user data as part of a merger, acquisition, or sale of assets. Our employees, agents, and contractors are bound to comply with these same restrictions.
4. Purpose of processing
Google user data obtained through the Gmail scopes is used only as described in section 3 above (reading customer inquiries, extracting structured fields, generating reply drafts that a studio member approves, and sending and marking those replies); it is not used for any other purpose. More generally, we process your data exclusively to deliver the Service: generating reply drafts, managing appointments, updating customer profiles, securing the platform. We do not train our own AI models on your data. We do not sell, rent, or share your data with third parties for advertising or profiling purposes.
No tracking and no advertising. Neither the Taddoo web application nor the Tattoomii Artist iOS app contains third-party advertising or analytics SDKs. We do not use an advertising identifier (such as Apple's IDFA), we do not build advertising profiles, and we do not track you across apps or websites owned by other companies in the sense of Apple's App Tracking Transparency framework. The data described above is used only to operate the Service for you.
5. Legal bases
Under Swiss revDSG processing of personal data does not generally require a specific legal basis, but it must be lawful, proportionate and transparent. For EU users (GDPR) the following legal bases apply:
- Performance of contract (Art. 6(1)(b) GDPR): account, email content, appointments, drafts.
- Legitimate interest (Art. 6(1)(f) GDPR): technical logs, abuse detection, security.
- Consent (Art. 6(1)(a) GDPR): Gmail mailbox connection, waitlist enrolment. You may withdraw consent at any time.
- Legal obligation (Art. 6(1)(c) GDPR): retention of billing and tax records.
6. Processors and third parties
We use the following processors:
- Supabase (database, storage, auth) - EU region (Ireland).
- Vercel (web hosting) - global edge, US-headquartered.
- Inngest (background jobs) - US-headquartered.
- OpenRouter (LLM routing) and the downstream model providers it routes to, namely Anthropic, OpenAI and Google - mainly US-based. We use these models under their API and business terms, which do not use submitted data to train or improve generalised AI or machine-learning models, and OpenRouter is configured so that no provider in our routing chain uses your data for training. We do not route Google user data to any model provider that reserves the right to train on it.
- Google (Gmail API for mailbox connection) - global, US-headquartered.
- Upstash (Redis cache and rate-limiting) - EU region.
We have data processing agreements (DPA / AVV) with all processors. Studios can request a copy of the DPA chain at hello@tattoomii.com.
7. International data transfers
Because we are based in Switzerland, transfers of personal data into Switzerland are considered transfers under Art. 16 revDSG and Chapter V GDPR for EU users. Switzerland has an adequacy decision from the EU Commission, so EU-to-Switzerland transfers do not require additional safeguards. For transfers to the United States (Vercel, Inngest, OpenRouter, Google, LLM providers) we rely on the EU Standard Contractual Clauses and on the Swiss FDPIC-recognised mechanisms. We do not transfer data to jurisdictions without adequate protection without additional safeguards in place.
8. Data security
We take appropriate technical and organisational measures to protect your data against unauthorised access, loss, or misuse. All data is encrypted in transit (TLS) and at rest. Gmail OAuth tokens are stored encrypted and held only briefly in an access-controlled cache. Email content and attachments live in an access-controlled database and a private storage bucket that is reachable only through short-lived signed URLs scoped to your studio (agency_id). Access to production data is restricted to authorised personnel on a need-to-know basis, protected by multi-factor authentication, and isolated per studio through row-level security. We apply rate limiting and abuse detection on our APIs. No method of transmission or storage is completely secure, so we continuously review and improve our safeguards; in the event of a data breach affecting your personal data we will notify the competent authority and, where required, you, within the statutory deadlines.
9. Automated processing and AI
We use Large Language Models to extract structured fields from incoming customer emails and to draft replies. Drafts are NEVER sent automatically: a studio member reviews and approves each draft manually. No automated individual decision-making with legal effect in the sense of Art. 22 GDPR or Art. 21 revDSG takes place.
10. Retention and deletion
We retain your data for as long as your account is active. Within 30 days after termination, personal data is deleted or anonymised, subject to statutory retention obligations (e.g. ten-year retention of accounting records under Swiss CO Art. 958f).
Account and data deletion. You can request deletion of your account and the personal data associated with it at any time by emailing hello@tattoomii.com from the address linked to your account. Because artist mailboxes in a studio are provisioned by the studio, an artist can also ask their studio administrator to remove their account; the studio administrator can request deletion of the studio account and all associated data the same way. After we receive a request we delete or anonymise the data within 30 days, except where a statutory retention obligation applies (see above). Deleting your account also disconnects any linked Gmail mailbox and removes stored email content, attachments, customer records, and drafts.
11. Your rights
You have the rights of access (Art. 25 revDSG / Art. 15 GDPR), rectification (Art. 32 revDSG / Art. 16 GDPR), erasure (Art. 17 GDPR), restriction (Art. 18 GDPR), data portability (Art. 28 revDSG / Art. 20 GDPR), and objection (Art. 21 GDPR). You may withdraw any consent at any time with effect for the future. Contact hello@tattoomii.com.
You may lodge a complaint with the competent supervisory authority. In Switzerland this is the Federal Data Protection and Information Commissioner (FDPIC, www.edoeb.admin.ch). EU residents may also complain to the supervisory authority of their habitual residence.
12. Cookies
We use only strictly necessary cookies (auth session, language and theme preferences, filter selection). No tracking or advertising cookies. No cookie banner is required because none of our cookies require consent under EU ePrivacy / Swiss FADP.
13. Children and minors
Taddoo is a business tool for tattoo studios and is not directed at children. We do not knowingly collect personal data directly from children. Where a studio enters data about its own end customers, that studio acts as the controller for its customer relationship and is responsible for any applicable age requirements. If you believe a child has provided us personal data directly, contact hello@tattoomii.com and we will delete it.
14. Changes to this policy
We may update this Privacy Policy. The current version is available on this page; the version identifier is shown under 'Last updated'. We will notify you by email of any material changes.
15. Governing law
This Privacy Policy is governed by Swiss law. Mandatory data protection rights granted by the law of your habitual residence remain unaffected. The English version of this Policy prevails in case of any discrepancy with translations.