sotto.

Privacy

Last updated 14 August 2026 · Createful Ltd, United Kingdom

Sotto handles a child's location. That deserves a policy someone can actually read, so this one says what is collected, why, and how long it lives — and is equally specific about what is never collected at all.

The short version

  • Sotto stores something only when a child presses a button.
  • Each check-in holds three things: which button, the time, and one location fix from that moment.
  • That location is deleted after 30 days. The fact the check-in happened lasts a year, without the coordinates.
  • There is no background tracking. Not disabled — absent. Nothing in the app reports position between check-ins.
  • Nothing is sold, and there is no advertising or analytics profiling.

Who we are

Sotto is made and operated by Createful Ltd, a company registered in the United Kingdom, which is the data controller. Reach us at support@createful.com.

What we collect

DataWhy
Guardian email address and password (stored only as a hash) To sign in, to verify the address, and to send a check-in by email if a notification hasn't been answered. Other guardians in your family always see your name; they see your email address only if you switch that on in Settings — it's off unless you do
Guardian display name — “Mum”, “Auntie Jo” So a child's screen says a name they recognise instead of an email address
Guardian phone number (optional) Only to power the child's “Call Mum” button. Nothing is ever sent to it by us
Child's first name and an emoji To tell one child from another. No surname, no date of birth, no email, no photograph — deliberately
Check-ins: which button, the time, and one location fix The service itself
Delivery records: whether a notification or email was accepted, delivered, seen or answered So the child can see whether their message landed, and so we can answer “why didn't I get it?”
Check-in requests: which guardian asked, which child, and when To send the nudge, to hold a guardian to the limits on how often they can send one, and so the child's own app can tell them how many times they were asked today. Never whether they saw it or answered — there is no field for that anywhere in the system
Device details: model, OS version, and a notification token To send notifications, and to let a guardian recognise and unlink a phone that's been lost or handed on

What we never collect

  • Location between check-ins. There is no background location capability in the app at all.
  • When the app is opened or closed, or how long it is used.
  • Contacts, photos, messages, browsing, or anything from other apps.
  • Advertising identifiers. Sotto carries no advertising or third-party analytics SDK.
  • Whether a child saw a check-in request, opened the app after one, or chose not to reply. A guardian is told that they asked, and nothing else — not even whether the phone was switched on.

One honest detail: while the Emergency page is open, the phone prepares a location fix so help isn't waiting on a signal. It stays on the device and is only ever sent if the child chooses to tell their family as they call. Leaving the page stops it.

Children's data

A child never signs themselves up. A guardian creates the profile and must approve that specific phone before it can send anything, so consent comes from the person holding parental responsibility, and we record who gave it and when.

The app is designed to the UK's Age Appropriate Design Code. In practice that means the child can see, in their own app and in plain words, exactly what each button sends and who receives it; they choose which guardians a check-in goes to; they can rename those guardians to whatever they call them; and there is no profiling, no advertising, and nothing that nudges them to share more.

And using Sotto stays the child's choice as they grow. There is no age cut-off — a young adult heading out is exactly who a quiet check-in serves — and no birthdate is collected to police one. The exit needs no permission at any age: deleting the app stops everything, silently, and tells nobody. That was designed in from the start, and their own app says so in plain words.

Location, specifically

A location fix is captured at the moment a check-in is sent, and never otherwise. iOS asks permission the first time and that permission is the operative control — refuse it, and Sotto still works: the check-in simply arrives without a pin, and everyone is told it did.

Coordinates are stored on their own, are never included in notification or email text (which can sit unencrypted on a lock screen or in an inbox), and never appear in our logs.

Asking how they are

A guardian can send a child a wave — a nudge to check in. It is the one thing in Sotto that a grown-up starts, and it was built so that it still moves no data on its own: the child sees a prompt, and nothing leaves their phone unless they choose to send a check-in exactly as they would have unprompted.

Silence stays silent. We record that a guardian asked, and when. We do not record whether it reached the phone, whether the child looked, or whether they answered — and because there is nowhere to put that, it cannot be reported later. The guardian's app shows them one thing: that they asked.

A guardian can send three a day at most, no sooner than half an hour apart, and that interval does not shorten if a child stays quiet. The child can keep waves off their lock screen — that is the default — or go quiet for a few hours; their family sees no difference either way. Sotto never sends a wave on anyone's behalf, and never tells a guardian that a child has gone quiet.

How long we keep it

DataKept for
Location coordinates30 days, then deleted
Check-in history, without coordinates1 year
Check-in requests24 hours
Delivery records90 days
Security and account audit records2 years
A deleted child profileErased within 30 days — profile, devices, check-ins, and location, which goes immediately
A deleted guardian accountEverything identifying — email, name, phone, password, devices — erased within 30 days. One thing deliberately remains: the record that someone was told about a child's check-in and answered it. That is part of the child's history, not the departing adult's, so it stays — attached to an entry that no longer names anyone

These run automatically, not on request. A guardian removing a child erases that child's location data immediately, and the rest follows within the window above.

Who processes it for us

  • Railway — hosting and the database, in the European Union (Amsterdam), encrypted at rest.
  • Apple — delivers notifications to iPhones.
  • Resend — sends the emails Sotto falls back to.
  • Sentry — error reporting, configured to strip coordinates, email addresses, phone numbers and tokens before anything is sent.

There are no other recipients. Nothing is sold or shared for marketing.

Our lawful bases

  • Providing the service (contract) — accounts, check-ins, delivery, and the location fix that makes a check-in useful.
  • Consent of the holder of parental responsibility — for a child's data, given by the guardian who creates and approves the profile.
  • Legitimate interests — keeping accounts secure and preventing abuse.

Your rights

You can ask for a copy of the data we hold, ask us to correct or delete it, or object to how we use it. A guardian can do this for their child. Most of it is available in the app right away: a guardian can remove a child, which erases their check-ins and locations, and can delete their own account entirely from Settings.

Write to support@createful.com and we'll reply within one month. If you're unhappy with our answer you can complain to the UK Information Commissioner's Office at ico.org.uk.

Changes

If we change what Sotto collects, this page changes first — and the app's own “What gets sent, and when” screen changes with it, because that screen is the promise the child actually reads.