Privacy Policy
Last updated: May 9, 2026 Applies to: BabyNote (the “Service”)
BabyNote takes your privacy seriously and complies with applicable data protection laws, including the GDPR, CCPA/CPRA, and Korea’s Personal Information Protection Act. This policy describes what information the Service collects, how it is used, and how it is protected.
1. Information We Collect
Account / Authentication
- Email address, password (stored as a hash), display name
Child Profile (entered directly by you)
- Name, date of birth, sex
Activity Records
- Feedings / sleeps / diapers / growth measurements / formula and diaper inventory
- Routines (walks, baths, supplements, snacks)
- Health records (symptoms such as cough, vomiting, rash, injury)
- Pediatrician profile, vaccination schedule
- Photos you attach (e.g., solid food, rash, injury)
Automatically Collected
- Device identifier (to maintain your session)
- Crash logs (for error monitoring)
We do not collect location data, contacts, or camera access beyond the photo attachment feature you explicitly trigger.
2. How We Use Information
| Purpose | Data Used |
|---|---|
| Account identification / login | Email, password |
| Core record-keeping service | Child profile, activity records |
| Family sharing | Account identifier, child ID |
| Statistics and charts | Activity records |
| Smart notifications (formula low, vaccines due) | Activity records |
| Error diagnostics | Crash logs |
| Payment processing | Payment token (RevenueCat) |
3. Data Retention
We delete your data immediately upon account deletion, with the following legally required exceptions:
- Payment records: 5 years (per Korean e-commerce law)
- Fraud prevention records: 1 year (security)
For users in the EU/UK, we comply with GDPR Article 17 (right to erasure) within 30 days unless legal retention is required.
4. Third Parties
We do not sell your personal information. We use the following processors to operate the Service:
| Processor | Purpose | Data Shared |
|---|---|---|
| Supabase Inc. (United States) | Database and authentication hosting | Account, child, and activity data |
| Sentry (United States) | Error monitoring | Crash logs (no personal data) |
| Google Maps Platform | Pediatrician search autocomplete | Search query strings |
| RevenueCat (United States) | Payment verification | Payment token |
Each processor adheres to its own privacy policy and our data protection requirements. We maintain Data Processing Agreements where applicable.
5. Your Rights
You can exercise these rights at any time:
- Access: In-app menu → Settings → Export Data (CSV)
- Correction / Deletion: Edit or delete each record directly
- Account Deletion: Settings → Account → Delete account (all data wiped immediately)
- Contact: support.babynote@gmail.com
EU/UK users (GDPR): You may also lodge a complaint with your local data protection authority.
California users (CCPA/CPRA): You have the right to know, delete, correct, and opt-out of sale (we don’t sell data). Send requests to the contact email above.
6. Security Measures
- All network traffic is encrypted via HTTPS/TLS 1.2+
- Postgres Row Level Security (RLS) isolates each user’s data
- Passwords are hashed with bcrypt
- Payment information is never stored directly — Apple, Google, and RevenueCat handle all card data
7. Children’s Privacy
This app is designed for parents and guardians to record their children’s care information. Children do not register accounts themselves. All child profile data is entered by an adult parent/guardian and is protected under this policy.
We comply with COPPA (US, children under 13), Korea’s PIPA (under 14), and GDPR-K (EU, under 16 in most member states).
8. Changes to This Policy
We will notify you of material changes via in-app notice or email before they take effect.
9. Data Protection Officer / Contact
- Name: BabyNote development team
- Email: support.babynote@gmail.com
- For users in Korea: Personal Information Dispute Mediation Committee (kopico.go.kr, 1833-6972)
- For users in the EU/UK: contact your local data protection authority