Release draft: the bracketed operator, contact, location, and retention fields must be completed and reviewed for every launch country before this page is published or real family data is accepted.
[[LEGAL_OPERATOR_NAME]] (“we”, “us”, or “our”) operates Your Baby's First 1000 Days. Our registered or principal address is [[POSTAL_ADDRESS]], [[COUNTRY]]. Questions and privacy requests can be sent to [[PRIVACY_EMAIL]]. General support is available at [[SUPPORT_EMAIL]].
The app is designed for parents, guardians, caregivers, and clinicians who are adults. It is not directed to children, does not create child user accounts, and should not be used independently by a child. An adult account holder may enter information about a child for whom they have legal authority or valid permission. If you believe a child's information was entered without appropriate authority, contact us so we can investigate and, where required, delete it.
Until an adult deliberately uses the cloud Health area or imports device data, the app can keep onboarding details, reading position, notes, highlights, bookmarks, checklist progress, display and language preferences, saved answers, growth entries, tracker entries, and vaccine-reminder preferences in local app storage on that device. The bundled book and page images are also cached for reading. Device data can be lost if the app is removed or its storage is cleared and is not an encrypted medical vault.
Depending on the features an adult chooses, we may collect:
On Android, microphone access is requested only after the user starts voice search. The app passes audio to the speech-recognition service installed on the device and receives text alternatives. The app does not intentionally retain the raw recording. The device or speech-service provider may process audio under its own terms, and an online speech engine may send it to that provider. Users can type instead and can deny or revoke microphone permission. Text-to-speech uses an installed Android speech engine; selected network voices may contact that engine's provider.
The app's Smart Answer Finder searches the bundled book on the device. The current release does not send questions to an external AI model.
We use service providers only as needed to operate the selected features. The current implementation uses Supabase for authentication, database, private file storage, server functions, purchase records, and access entitlements; Razorpay to create and process website payments and send payment-status webhooks; Resend for adult invitation email; and operating-system notification and speech services when enabled. Their processing location and contractual terms must be confirmed by the operator before launch. We may also disclose information when required by law, to protect people or the service, or during a corporate transaction subject to appropriate safeguards.
The native mobile apps do not embed Razorpay checkout or another third-party payment SDK. Website checkout is separate from mobile-app-store purchasing. The current service does not include third-party advertising, cross-app tracking, third-party analytics, or a crash-reporting SDK.
Adults can invite family members or clinicians and can create time-limited doctor links with selected data categories and view limits. A person holding an active link may view the permitted information, so users should send links through a trusted channel and revoke them when no longer needed. Parents can remove member access and revoke links in the app.
Active account and Health information is retained while the account is active and until the adult deletes individual records, a child profile, or the account, subject to legal holds. Soft-deleted structured health records remain recoverable for 30 days. Production backups are retained for [[BACKUP_RETENTION_PERIOD]], after which deleted information is removed or rendered inaccessible according to the operator's backup process. Security, deletion-receipt, and audit records are retained for [[AUDIT_RETENTION_PERIOD]] unless a longer period is legally required.
The app provides export, consent withdrawal, child deletion, and account deletion controls. Account deletion first attempts to remove private files and then removes the account and associated records. Withdrawing consent signs the user out but does not itself delete stored information.
Data is sent using HTTPS. Private database rows and storage buckets use authenticated access controls and family roles; file previews use expiring signed URLs. We also use restricted server secrets, rate limits, and audit records. No service can guarantee absolute security. The operator must maintain backups, access reviews, monitoring, incident response, and legally required breach notifications.
Information may be processed outside the user's state, province, or country where our providers operate. Before launch, the operator must identify the hosting region and document any legally required transfer mechanism: [[HOSTING_REGION_AND_TRANSFER_MECHANISM]].
Subject to local law, an adult user or authorised guardian may request access, correction, export, deletion, restriction, or objection; withdraw consent; or complain to a privacy regulator. The app provides self-service export, sharing revocation, consent withdrawal, and deletion controls. Requests can also be sent to [[PRIVACY_EMAIL]]. We may need to verify the requester's identity and authority.
We may update this policy when the app, providers, or legal requirements change. Material changes will be presented in the app for renewed acceptance where appropriate. The effective date and version at the top identify the current policy.