Privacy policy for the Babu app
Last updated:
This is a translation for convenience. The legally binding version is the German one. Deutsche Fassung
The short version
With syncing switched off, nothing you record leaves your device. Babu writes everything to a database on the phone first. If you use the app on your own and do not share with a second parent, you need no account, and no data is transmitted to us or to anyone else.
If you switch syncing on in order to share with a second device, the data is stored on servers in the European Union. We ask for your explicit consent before that happens, because this is health data.
The app contains no analytics, advertising or tracking components. There is no profiling, no cross-device recognition and no sharing for advertising purposes.
Controller and data protection officer
The controller within the meaning of Article 4(7) GDPR is:
«Vorname Nachname»«Strasse und Hausnummer»
«PLZ» «Ort»
Deutschland
«kontakt@example.com»
No data protection officer has been appointed at present. Because health data is processed, an obligation to appoint one may follow from section 38(1) sentence 2 of the German Federal Data Protection Act regardless of headcount. That assessment is under way; any appointment will be published here. For data protection enquiries, please write to «kontakt@example.com».
What the app processes
Everything comes from what you enter yourself. The app does not read your contacts, your location, your photos or health data from other apps.
About the child
First name or nickname, date of birth, optionally the due date and whether the child was born prematurely (both are needed to calculate corrected age), and optionally sex.
Daily records
Sleep (start, end, type, time to fall asleep, night wakings, settling method, notes), feeds (time, type, side, amount, solids, duration), nappies, expressed milk and its storage, temperature readings, medication, growth measurements, crying episodes, teeth, milestones, activities, daily mood, and day markers such as illness or travel.
Household
A household groups the people caring for the same child. We store a display name, a role, the time of joining, and, for every entry, which member made it. That attribution is deliberate: it answers the question of who fed the baby last.
Account and purchase data
With syncing switched on, a user identifier and the email address used to sign in, plus the entitlement status (trial, subscription or one-off purchase) and its expiry. We receive no payment details; those stay with Apple and Google.
Technical data
Syncing transmits the usual connection data (IP address, time, size of the transfer). It is needed to operate the service and to prevent abuse, and is not analysed to study usage behaviour.
Why this is health data
An infant’s patterns of sleep, feeding and excretion allow conclusions about their state of health. They are therefore health data within the meaning of Article 4(15) and Article 9 GDPR.
The Court of Justice of the European Union reads Article 9 broadly: it is enough that a state of health can be inferred by combination or deduction (judgment of 4 October 2024, Case C-21/23). We therefore apply that stricter standard throughout, including where a milder classification would be defensible.
The data subject is primarily the child. Consent is given by those with parental responsibility (Article 8 GDPR). The app is intended for adults only and is not designed for use by children.
Purposes and legal bases
Running the app on your device
Purpose: to store and display what you record, and to estimate the next sleep window from it. This happens entirely on your device. The legal basis is Article 6(1)(b) GDPR (performance of the contract).
Syncing between devices
Purpose: so that both parents see the same picture. The legal basis is your explicit consent under Article 9(2)(a) GDPR. Performance of the contract is not sufficient here, because Article 9(1) prohibits processing health data in principle and only the exceptions in paragraph 2 permit it.
Consent is obtained before the first transfer, on a dedicated screen that names what goes where. Without consent, syncing stays off and the app remains fully usable.
Purchases and entitlement
Purpose: to check whether the household has a valid trial, subscription or one-off purchase. The legal basis is Article 6(1)(b) GDPR.
Security
Purpose: to detect and prevent abuse of our interfaces. The legal basis is Article 6(1)(f) GDPR; the legitimate interest is the secure operation of the service.
Withdrawing consent
You may withdraw your consent at any time with effect for the future by switching syncing off in the app’s settings. This does not affect the lawfulness of processing carried out beforehand. If you also want the data already transferred to be removed from the server, delete your account; the page on deleting your account explains exactly what happens.
Who else receives the data
We share no data for advertising or analytics. The following providers process data on our behalf; data processing agreements under Article 28 GDPR are in place with all of them.
Supabase (database and sign-in)
Supabase operates the database and the sign-in. The project is configured for a region in the European Union; under Supabase’s data processing agreement, data is stored and primarily processed in the region the customer selects. Where transfers cannot be avoided technically, the European Commission’s standard contractual clauses apply.
What is transferred: all records you have released for syncing, plus the household details.
RevenueCat (purchase handling)
RevenueCat validates the purchase receipts from both stores and tells the app whether the household has a valid entitlement. The company is based in the United States. The transfer relies on the European Commission’s standard contractual clauses.
What is transferred: a pseudonymous household identifier, the store receipt, and technical details about the device and app version. Information about the child and the daily records are not transmitted to RevenueCat.
RevenueCat engages sub-processors of its own, including Amazon Web Services, Snowflake, Cloudflare, Google LLC, Elastic, Sentry, OpenAI and Anthropic. The current list is published at revenuecat.com/dpa.
Apple and Google
Your contract of purchase is with Apple Distribution International or Google Commerce Limited. Those companies process your payment and account data as controllers in their own right, not on our behalf. We receive no payment details from them.
How long the data is kept
On your device, data stays until you delete it or remove the app. The “delete all data” function in the settings deletes it immediately and completely, not merely flags it.
On the server, data stays as long as the household exists. When you delete an individual entry, a deletion marker remains at first so that the second parent’s device can pick the deletion up; that marker and the associated data are removed for good after 90 days.
If you delete your account and you are the last member of the household, the household and everything attached to it is deleted immediately and without any retention period. A request under Article 17 GDPR is not a sync operation and is therefore not given a deadline.
Purchase and receipt data is subject to the commercial and tax retention periods of the store operators and is held by them, not by us.
No automated decision-making
The app calculates an estimate for the next sleep window from what you enter. That estimate is a suggestion to help you plan; it produces no legal effect and no similarly significant impact. There is no automated individual decision-making, including profiling, within the meaning of Article 22 GDPR.
Babu is a tool for recording and organising. It is not a medical device, makes no diagnosis, gives no treatment advice and measures no vital signs.
Your rights
Under the GDPR you have the right to
- request access to the data held about you (Article 15),
- have inaccurate data corrected (Article 16),
- request erasure (Article 17),
- request restriction of processing (Article 18),
- receive your data in a common format and transmit it elsewhere (Article 20),
- object to processing based on a legitimate interest (Article 21), and
- withdraw a consent you have given (Article 7(3)).
Two of these you can exercise without going through us: the app’s settings offer an export of all your data as a file (Article 20) and complete deletion (Article 17). Both remain available even when no subscription is active.
For anything else, reach us at «kontakt@example.com».
You may also lodge a complaint with a supervisory authority (Article 77 GDPR). The authority responsible for us is Bayerisches Landesamt für Datenschutzaufsicht (BayLDA), Postfach 1349, 91504 Ansbach. You may also contact the authority where you habitually reside.
Security
Traffic between the app and the server is encrypted with TLS throughout. Access to a household’s data is limited to its members; the database enforces this at row level, not merely in the app.
The local database is stored in an area of the device that is excluded from automatic backup to the manufacturer’s cloud, so your records do not end up in a third-party backup unnoticed.
Changes to this policy
When the app changes, this policy changes with it. The date at the top of the page states the current version. Where a change requires fresh consent, we ask for it in the app rather than assuming it quietly.