Privacy Policy

Effective date: [SET AT LAUNCH]. Data controller: [LEGAL ENTITY NAME], reachable at support@whybabywhy.app. This policy describes every category of data the Why Baby Why app and website handle, where it goes, and how to remove it.

What Why Baby Why does

A caregiver records a crying episode — sound only, or video with sound — and receives a neutral written description of what is audible, stored in a private timeline alongside the caregiver's own routine notes. The app does not tell you why your baby is crying and does not provide medical advice.

Accounts

Why Baby Why creates an anonymous account on first use — no email, name, or password is requested. If you choose Sign in with Apple, Apple shares your email address (or a private relay address) with us to link your account across devices. Anonymous accounts carry no real email address. Session records are stored without your IP address or device user-agent — both are deliberately discarded on write.

Child information

A child profile stores a nickname and an approximate age anchor — never a date of birth. The nickname is encrypted at rest, and the encryption is bound to your profile and account, so a record copied out of one account cannot be decrypted under another. Routine-log entries (feeding, sleep, diapers, and related care events) sync to our servers and are linked to your account.

Sharing with people you invite

Sharing is off until you turn it on for a specific child. You share by showing a one-time code that expires after 24 hours; we store only a hash of it, never the code itself, and the code travels in the part of a link that browsers never send to a server. No email address or phone number is exchanged, and people who share a child see each other only as a role and the name the family chose to display, which is encrypted at rest like the child's nickname.

Everyone you invite sees that child's whole log and who recorded each entry. People invited as caregivers can also add and change entries and record cries under their own consent; people invited to view only can do neither. You can change someone's access or remove them at any time, and anyone can leave. Removing someone, or leaving, stops that phone from seeing the child's log and deletes the copy it kept.

Deleting your account removes you from every child you were invited to. For a child you own and share, we ask first whether to hand it over to another caregiver or delete it for everyone — we never decide that for you.

Cry recordings and videos

When you record an episode or choose an existing video from your photo library, that recording is uploaded to our storage and sent to Google Gemini for processing under Google's paid-service data-processing terms. Google may retain API data for a limited period for abuse and security monitoring. What we send with the recording is deliberately minimal: the child's age in days, a small set of fixed-choice context values, and fixed-choice summaries of up to five recent episodes (age, time-of-day bucket, and what the caregiver reported helping). No name, no free-text notes, no date of birth.

Why Baby Why deletes its own copy of the recording after processing and keeps the structured description and related processing records — not the recording itself. No recording is uploaded without your consent, and consent is checked on our servers — not just in the app — every time media leaves the device. Withdrawing consent stops new uploads and removes stored media and pending analyses.

Photos

Your photo library is opened only when you choose it: to pick a video for an episode, or to attach a photo or video note to your routine log. Media notes stay on the device and are never uploaded.

Purchases

Subscription status comes from Apple. From Apple's signed record we keep a small set of normalized fields — whether the subscription is active, when it expires, the period type, and Apple's transaction identifiers — so your access follows your account and refunds are honored. We never see or store your payment details.

Who processes data on our behalf

Google (Gemini API — describes the audio in a recording), Cloudflare (application hosting and media storage), and Neon (database hosting) process data to run the service. Apple processes purchases and optional sign-in. Sentry receives a report when the app crashes or hits an error, so we can fix it; those reports carry no IP address, no account details and no part of a recording. We do not sell data, do not use advertising SDKs, and the app contains no third-party analytics or attribution SDKs.

Your rights and controls

From Settings you can export your data (a downloadable archive of your account's records) and delete your account. Deletion removes stored media first, then every server record, and is immediate and permanent. If you have an active subscription, cancel it in your Apple ID settings — deleting the account does not stop Apple's billing. You can also reach us at support@whybabywhy.app for any request about your data.

Website

This website serves no cookies and runs no first-party scripts. Our hosting provider, Cloudflare, may collect aggregate, cookieless performance measurements.

Changes

If this policy changes in a way that affects recordings or child information, the app will ask for your consent again before any further media leaves your device — this re-consent is enforced by version checks on our servers.