BabyLedgerBabyLedger
功能App 介紹Plus常見問題 清醒時間
ENEnglishPLPolskiDEDeutschESEspañolFRFrançaisITItalianoPTPortuguêsJA日本語KO한국어ZH繁體中文
下載 App

Privacy Policy

Last updated: 20 July 2026

This Privacy Policy explains how Taqo Łukasz Jach ("we", "us", "our") collects, uses and protects personal information when you use the BabyLedger mobile application for iOS and Android, including its widgets and Apple Watch companion app (the "App"). BabyLedger is an app for parents and legal guardians to keep a diary of their baby’s daily activities - the child is never the user. By creating an account or using the App, you acknowledge that you have read and understood this Privacy Policy.

Information we collect

We follow data minimization: we collect only what the App needs. The App contains no ads, no advertising identifiers and no marketing analytics.

Your account information: your email address and password, or sign-in via Apple or Google (from which we receive your email address and a basic account identifier); an optional display name (we encourage a pseudonym); and app preferences such as language, theme, volume unit and time format.

Your child’s information, entered by you: a nickname (please do not enter a full name), date of birth and optionally a due date. Avatars are generated color graphics - the App does not collect child photos.

Activity diary, entered by you: time-stamped records such as feeding (breast, bottle - with side, duration, amount), sleep (start, end, duration) and diaper changes (type, time), plus which caregiver logged each entry.

Caregiver sharing: when you invite another caregiver, we collect the invitee’s email address and the role and permission level you assign, and we send them an invitation email on your behalf.

Push notifications (optional): if you enable the optional Live Activity feature, we store the push device tokens needed to deliver notifications - on Android a Firebase Cloud Messaging (FCM) registration token, on iOS Apple Push Notification service (APNs) Live Activity tokens - together with the platform and a random per-install device identifier. No push token is collected while the feature is off (the default).

Subscription information: if you purchase a subscription, payment is handled by Apple or Google. We receive only subscription status (plan, active/expired, platform) via RevenueCat - never your payment card details.

Technical data strictly required to operate the service: authentication tokens, server request logs kept by our hosting provider, and a log of transactional emails sent to you. We do not profile you and we do not store your location - the App requests no GPS, contacts or camera access.

How we use your information

We use your information to provide the service - your account, saving entries, and sync between your devices and invited caregivers (Art. 6(1)(b) GDPR, performance of a contract). Your child’s data is processed based on your consent as parent or legal guardian (Art. 6(1)(a) GDPR).

We send transactional emails only: sign-in links, password reset, email verification, caregiver invitations and notifications when a caregiver joins or leaves (Art. 6(1)(b) GDPR). We do not send marketing emails.

When you invite a caregiver, we process the invitee’s email address to deliver the invitation, based on our and your legitimate interest in enabling shared care (Art. 6(1)(f) GDPR). The invitation email links to this Privacy Policy.

Optional push notifications - Live Activity updates on your and invited caregivers’ devices - are sent based on your consent (Art. 6(1)(a) GDPR) and can be disabled anytime in Settings.

We also process data for subscription verification (Art. 6(1)(b)), for security, abuse prevention and service stability (Art. 6(1)(f), legitimate interest), and to comply with legal obligations such as purchase records (Art. 6(1)(c)).

Push notifications

The optional Live Activity feature mirrors a running session (for example a sleep timer) on your lock screen and on the devices of caregivers you have invited. The App asks for notification permission only when you turn it on, and you can turn it off again anytime in Settings.

A notification payload contains only what is needed to display it: your child’s nickname, the activity type (e.g. sleep started or ended) and its start time. It never contains feeding amounts, diary details, notes or your email address.

Delivery uses the platform push services: on iOS, notifications are sent directly to Apple’s Push Notification service (APNs); on Android, they are delivered through Google’s Firebase Cloud Messaging (FCM), which means the payload transits Google’s servers. This is one more reason we recommend using a nickname rather than your child’s full name.

Push device tokens are deleted when you disable Live Activity or sign out, when Apple or Google report a token as invalid, and automatically after 60 days without being refreshed.

Data storage and security

Your records are stored locally on your device (so the App works offline) and synced to our cloud backend hosted by Supabase in the European Union (Frankfurt). Database-level Row Level Security ensures each user can access only their own data and the children they have been granted access to.

We protect your data with encryption in transit (TLS) and at rest (AES-256), Row Level Security at the database level, rate-limited token-based caregiver invitations, and data minimization. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security. You are responsible for keeping your credentials confidential and for choosing who you share a child’s data with.

If a security incident affects personal data, we will notify the supervisory authority within 72 hours where required, and notify you by email if your data may have been affected.

Sharing your information

We do not sell, rent or trade personal information, and we never share it for marketing purposes.

We share data with caregivers you invite: they see the shared child’s profile and activity records according to the permission level you set (viewer/editor), and you can revoke access at any time.

We use service providers (processors) who operate parts of the service on our behalf and process data only on our instructions: Supabase (database, authentication, file storage and backend functions; EU, Frankfurt), Resend (delivery of transactional emails; USA, under Standard Contractual Clauses), Cloudflare (cloud infrastructure services, including backup delivery of transactional emails; USA, under Standard Contractual Clauses), RevenueCat (subscription verification; USA, under Standard Contractual Clauses), Apple and Google (app distribution, sign-in, payments; platform standard terms), Apple APNs (delivery of push notifications and Live Activity updates to iOS devices) and Google Firebase Cloud Messaging (delivery of push notifications to Android devices; USA, under Standard Contractual Clauses).

Where a provider processes data outside the European Economic Area, we rely on appropriate safeguards, in particular the European Commission’s Standard Contractual Clauses.

We may also disclose information when required by law - to comply with a legal obligation, court order or lawful request by authorities, or to protect the rights and safety of us or our users - and in a business transfer such as a merger, acquisition or sale of assets, in which case this Privacy Policy will continue to apply.

Our website

This Privacy Policy also covers our website, babyledger.app. The website is served through Cloudflare, which provides hosting, content delivery and protection against attacks; to do this, Cloudflare processes visitors’ IP addresses and technical request logs on our behalf (Art. 6(1)(f) GDPR, our legitimate interest in delivering and securing the site; USA, under Standard Contractual Clauses).

The website itself uses no analytics or tracking and sets no cookies of its own; Cloudflare may set strictly necessary security cookies (e.g. bot protection).

Account deletion

You can delete your BabyLedger account, and the data linked to it, yourself at any time - no request or waiting period. In the BabyLedger app, open Settings → Delete Account, read the summary and confirm. We email a 6-digit code to your account address; entering that code deletes the account immediately and irreversibly. This works whichever way you sign in - email and password, Apple or Google.

If you no longer have access to the app, email hello@babyledger.app from the address linked to your account with the subject "Delete my account". We verify that the request comes from the account holder and complete the deletion within 30 days, as required by the GDPR.

Deleted immediately: your profile (email address, display name, preferences and consent records), every child you own together with their full activity diary, your caregiver links and pending invitations, your push device tokens, and your stored subscription status.

Kept after deletion: entries you logged for a child owned by another caregiver stay with that family, but the reference to you is cleared, so they are no longer linked to your account. We also keep anonymized deletion markers (record ID and time) so the deletion reaches every synced device, encrypted database backups for up to 7 days before they rotate out, server logs for up to 90 days, the transactional email log for 12 months, and purchase records for as long as tax and accounting law requires. BabyLedger stores no photos or uploaded files.

Deleting your account does not cancel a paid subscription: cancel it in your App Store or Google Play account settings. Apple, Google and RevenueCat keep their own records of your transactions under their policies.

Data retention

We keep your account and activity diary for as long as your account exists. This includes your full history: on the Free plan, entries older than the visible history window are hidden behind the plan limit but are not deleted - they remain stored and become visible again if you upgrade to Plus. When you delete your account, your profile, children and all their records are erased immediately (cascading deletion); backup copies rotate out within our provider’s standard cycle (up to 7 days). An entry you delete in the App can be restored during a 30-day undo window, after which its content is permanently erased; only an anonymized deletion marker (record ID and deletion time) is kept so the deletion reliably reaches every synced caregiver device.

We may delete accounts (with all their data) that have not been signed in to for 24 months and have no active subscription. We will warn you by email at least twice before any such deletion; signing in again is enough to keep your account.

Caregiver invitations expire 7 days after creation. Push device tokens are deleted when you disable Live Activity or sign out, when the platform reports them invalid, and automatically after 60 days without being refreshed. Server logs are kept for up to 90 days. The log of transactional emails is kept for 12 months. Purchase records are kept as long as required by tax and accounting law.

Your rights

Under the GDPR you have the right to access your data and to data portability (Plus subscribers can export their records directly in the App; anyone, including Free users, can request a copy of their data free of charge at the email below), rectification (edit your profile, child and entries in the App), erasure (Settings → Delete Account: immediate, irreversible cascading deletion confirmed by an email code), restriction and objection (e.g. revoking another caregiver’s access or disabling push notifications in Settings, which deletes this device’s push tokens), and to withdraw consent at any time without affecting the lawfulness of prior processing.

You may also lodge a complaint with your data protection supervisory authority - in Poland, the President of the Personal Data Protection Office (PUODO), ul. Stawki 2, 00-193 Warsaw, uodo.gov.pl. To exercise a right you cannot exercise in the App, contact us at the email below.

Children’s privacy

The App is directed at adult caregivers. We do not create accounts for children and do not knowingly collect personal information directly from children. All child data is entered by a parent or legal guardian, based on their consent (Art. 8 GDPR), and is used exclusively to provide the App’s features to that family. We strongly recommend using a nickname for your child rather than a full name. If you believe a child has provided us with personal information directly, contact us and we will delete it.

Changes to this policy

We may update this Privacy Policy from time to time. We will announce material changes by email to the address linked to your account or via a notice in the App, and by publishing the new version with an updated date in the header. Continued use of the App after changes take effect constitutes acceptance. If you do not agree with a change, you may delete your account and stop using the App.

Contact us

For privacy matters: Taqo Łukasz Jach, Kołłątaja 1A, 46-203 Kluczbork, Poland, VAT ID (NIP): PL7511625650. Email: hello@babyledger.app - please mark your message "Attention: Privacy Policy".

BabyLedgerBabyLedger

一本給疲憊雙手的安靜日誌。

免費工具
  • 清醒時間計算機
法律
  • 隱私權
  • 服務條款
  • 免責聲明
© 2026 BabyLedger · All rights reserved