BabyStory ("the App") is a baby care logging app that lets parents and invited family members record feedings, sleep, diapers and other daily care events, and keep a shared photo album for their baby.
This policy explains what information the App collects, why it is collected, how it is stored and shared, and what choices you have. If you have questions, contact us at nerdens.seong@gmail.com.
1. Who is responsible for your data
The developer of BabyStory is the controller of the personal data described below.
- Contact: nerdens.seong@gmail.com
The App has no separate server of its own. It uses Google Firebase (Firebase Authentication, Cloud Firestore, and Cloud Storage for Firebase) as its backend. Google acts as our data processor.
2. Information we collect
We only collect information that you or your invited family members enter into the App. We do not buy, scrape, or import personal data from any other source.
2.1 Account information
| Data | Purpose | Notes |
|---|---|---|
| Email address | Sign-in identifier, account recovery, service notices | Handled by Firebase Authentication |
| Password | Authentication | Handled by Firebase Authentication. It is stored as a salted hash by Google; the App never stores or transmits your password in plain text and cannot read it |
| Display name (optional) | Shows who recorded an entry to your family members | Stored in Cloud Firestore |
2.2 Baby profile
- Baby's name (or nickname you choose)
- Baby's date of birth
- An optional baby profile photo
This information is entered voluntarily by you, the adult guardian, and is used to label records and to calculate the baby's age and age-relative statistics inside the App.
2.3 Care records
Records you create for a baby, which may include:
- Record type: breastfeeding, bottle feeding, solid food, pumping, diaper, sleep, bath, temperature, medicine, or a free-form memo
- Start time and, for timed activities, end time
- Amount in milliliters (bottle feeding, pumping)
- Body temperature in degrees Celsius
- A free-text note you type
- The account that created the record and the creation time
Some of this information (body temperature, medicine, feeding) may be considered health-related data about your baby under the GDPR and similar laws. We process it only to provide the logging and statistics features you asked for, and never for advertising, profiling, or analysis of any kind.
2.4 Photos
- Images you explicitly select from your device's photo library and upload
- An optional caption and the date you assign to each photo
Photos are resized on your device before upload and are stored as image files in Cloud Storage for Firebase. The App does not read, store, or use location (GPS/EXIF) information from your photos, and it does not scan or analyze the content of your images.
The App requests photo library access only at the moment you choose to add a photo, and only to let you pick the images you want to upload. The App does not browse or upload anything you have not selected. It does not request camera, microphone, contacts, location, or health-app permissions.
2.5 Family sharing information
- Invite codes generated by a baby's owner (a 6-character code with an expiration date)
- Membership records showing which accounts have joined which baby, each member's role (owner or member), and when they joined
2.6 Technical information processed by our provider
Google Firebase processes standard operational data required to run the service — for example the IP address of a request, timestamps, and error information — for security, abuse prevention, and reliability. See the Firebase Privacy and Security documentation for details.
3. What we do NOT do
The following statements reflect the actual code of the App, which contains no advertising, analytics, or tracking libraries:
- No advertising. The App shows no ads and contains no advertising SDK.
- No analytics or usage tracking. The App does not include Firebase Analytics, Crashlytics, or any third-party analytics, attribution, or crash-reporting SDK.
- No cross-app or cross-site tracking, and no advertising identifier (IDFA/AAID) is requested or used. The App does not present an App Tracking Transparency prompt because it does not track you.
- No sale or sharing of personal information for advertising or any other commercial purpose.
- No profiling or automated decision-making based on your data.
- No access to your contacts, calendar, location, microphone, or health data.
4. How we use your information
We use the information above only to:
- Create and authenticate your account and keep you signed in;
- Store, display, and let you edit your baby's care records and photos;
- Calculate in-App summaries and statistics (for example daily feeding totals or sleep duration), which are computed for you and are not shared with anyone;
- Share records among the family members invited to the same baby;
- Keep the service secure — for example by enforcing access rules and expiring invite codes;
- Respond to your support requests.
Legal bases (EEA/UK users)
- Performance of a contract (Art. 6(1)(b) GDPR) — providing the account, records, photos, and sharing features you asked for.
- Consent (Art. 6(1)(a), and Art. 9(2)(a) for health-related entries such as temperature or medicine) — you decide what to record, and you may withdraw consent at any time by deleting the entries or your account.
- Legitimate interests (Art. 6(1)(f)) — keeping the service secure and preventing abuse.
5. Who can see your data
- Family members you invite. Everyone who joins a baby using that baby's invite code can see and edit that baby's profile, care records, and photos, and can see the display name of other members. Only the owner can create invite codes or remove members. You should share invite codes only with people you trust.
- Google (as our processor). Your data is stored in Google Firebase. Google processes it on our instructions under Google's data processing terms.
- Nobody else. We do not sell, rent, or share your personal information with advertisers, data brokers, or any other third party.
We may disclose information if we are legally required to do so by a valid legal process, but we have no other reason or mechanism to hand your data to anyone.
Server-side access control. Access is enforced by Firebase Security Rules on Google's servers, not just in the app: a request for a baby's profile, care records, or photos is rejected unless the requesting account is a member of that baby. Uploaded photo files are protected by the same membership check. The download links the App generates to display your photos contain an unguessable token and are never published anywhere; if you forward such a link to someone else, that person could open that image, so treat photo links as private.
6. Where your data is stored (international transfers)
- Cloud Firestore records and Cloud Storage photo files are stored in Google's asia-northeast3 (Seoul, Republic of Korea) region.
- Firebase Authentication account data (email address, password hash, display name) is operated by Google as part of its global identity infrastructure and may be processed on servers outside your country, including in the United States.
Where personal data of EEA/UK users is transferred outside those regions, the transfer relies on the European Commission's Standard Contractual Clauses as incorporated into Google's terms.
If you are a user in the Republic of Korea, this constitutes notice of outsourcing (위탁) and overseas transfer of personal data to Google LLC and its affiliates for the purpose of cloud hosting, authentication, and file storage, for as long as you use the service.
7. How long we keep your data
- Your account, baby profiles, care records, and photos are kept for as long as your account exists, so that your history remains available to you.
- A care record or photo you delete in the App is removed from our database, and a deleted photo's image file is removed from storage as well. Deleted items are not recoverable by you.
- Removing a baby removes it from the App for you and your family members. Its historical records and photo files may remain in our database until we purge them; email us if you want them erased immediately.
- Invite codes expire automatically 7 days after they are created.
- When you request account deletion, we delete your account and the personal data associated with it without undue delay and in any event within 30 days, except where we are required to retain something by law.
- Records inside a baby that is shared with other family members remain visible to the remaining members if they continue to use the baby's record; if you want that shared content removed entirely, tell us in your deletion request.
Backups held by our provider are overwritten on a rolling basis.
8. Your rights and choices
You can, at any time:
- Access and correct your data directly in the App — profile name, baby profile, every care record, and every photo caption are editable.
- Delete individual care records, photos, or a whole baby record in the App.
- Leave a shared baby, which removes your access to it.
- Sign out on any device.
You may also contact nerdens.seong@gmail.com to:
- Request deletion of your account and its data;
- Request a copy of the personal data associated with your account (portability);
- Ask us to restrict or object to processing;
- Withdraw consent you previously gave.
We will verify that the request comes from the email address registered to the account before acting on it, and we will respond within 30 days.
EEA/UK users have the right to lodge a complaint with their local data protection supervisory authority. Users in the Republic of Korea may contact the Personal Information Protection Commission (privacy.go.kr, +82-118). California residents: we do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we do not use personal information for cross-context behavioral advertising.
9. Children's privacy
BabyStory is designed for adult parents and guardians. The App is not directed to children, and we do not knowingly allow anyone under the age of majority in their country (16 in the EEA unless national law sets a lower age, 14 in the Republic of Korea, 13 in the United States) to create an account.
Information about a baby or child stored in the App — name, date of birth, care records, photos — is entered voluntarily by the adult account holder about their own child or a child in their care, and is visible only to the family members that adult invites. We do not use children's information for advertising, analytics, profiling, or any purpose other than displaying it back to the family.
If you believe a child has created an account, contact nerdens.seong@gmail.com and we will delete it.
10. Security
- All communication between the App and Firebase uses TLS encryption.
- Data stored in Cloud Firestore and Cloud Storage is encrypted at rest by Google.
- Passwords are hashed and managed by Firebase Authentication; neither the App nor the developer can see your password.
- Access to every document and file is checked on the server by Firebase Security Rules against your account's membership of the baby in question.
- Invite codes are randomly generated, cannot be listed or enumerated, and expire after 7 days.
No method of transmission or storage is completely secure, so we cannot guarantee absolute security. Please use a strong, unique password and share invite codes only with people you trust.
11. Changes to this policy
If we change this policy, we will update the "Last updated" date at the top and publish the revised version at this URL. For material changes — for example, if we ever began collecting a new category of data — we will provide notice in the App or by email before the change takes effect.
12. Contact
Questions, requests, or complaints about this policy or your data:
We aim to respond within 30 days.