Privacy Policy

Last updated: October 8, 2026

Belly Birth Baby is a baby tracker for sleep, feeds, diapers and growth, made by Nibra LLC ("we", "us"). This policy explains, in plain language, what stays on your phone, what reaches our servers and when, who else is involved, and how to export or delete your data.

The short version

Tracking on your own (no account)

When you track on your own, your baby's profile (name, birth date, feeding style) and every sleep, feed, diaper and growth record, with any note or diaper photo you add, are stored only on your iPhone, using standard iOS storage. The Home Screen widget and Live Activities read the same on-phone data. We do not receive a copy and cannot see it.

A few things still leave the phone even without an account, and none of them contain your log:

Sharing with caregivers

Sharing starts only when you create an invite (Settings > Caregivers > Invite a caregiver) or join someone else's log with a code. From that moment, the following syncs to our servers so every member of your baby's log has the same timeline:

Never synced: diaper photos. They stay on the phone that took them.

Who can see it: only the active members of your baby's log, meaning the people who joined with an invite code. Invite codes work once and expire after 7 days. A caregiver who is removed, or who leaves, stops receiving new entries straight away. A removed caregiver keeps whatever their phone had already synced before they were removed; we cannot recall data that is already on someone's phone, and the app says so before you invite anyone.

Where it lives: on servers we operate on Fly.io in the European Union (Amsterdam, the Netherlands), with a PostgreSQL database in the same region. Data is encrypted in transit (HTTPS) and at rest. We will update this policy, and say so in the app's release notes, if the region changes.

Your account

You need an account only to share. You can sign in with:

Your account record holds an account ID, an email address (yours or Apple's relay address) and the display name the family sees ("Your name, as the family sees it"). Belly Birth Baby and our pregnancy app, BellyBirthBloom, use the same Nibra account service, so if you sign in to both with the same Apple ID or email, it is the same account. Neither app copies the other's logs. Because it is one account, deleting it from either app deletes it for both.

Your child's data

The records in Belly Birth Baby are about your child, and some of them (feeds, diapers, growth) are health-related. We treat them with the same care as health data about an adult:

The app is for adults who look after a baby. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 as a user. If you think a child has created an account, contact us and we will delete it.

Notifications, Live Activities and push

On-device features

Premium and payments

Premium is an optional auto-renewable subscription sold by Apple. Apple processes every payment; we never see your card or billing details. The app checks your subscription with Apple through StoreKit. If you are signed in and part of a shared log, the app also sends the signed transaction Apple gives it to our server, so the other members of your baby's log get Premium too. That record (product, dates, renewal state, transaction ID) is linked to your account and deleted with it. Manage or cancel your subscription in your Apple Account settings.

How we learn what works (product events)

To understand which parts of the app help and to test the order of first screens, the app sends short product events to our own server: for example that onboarding started or finished, which answer was chosen for a quiz question (from a fixed list, such as "Make nights easier"), that a first nap, feed or diaper was logged, that the Premium screen was shown or closed, that a trial or purchase started (with plan, price and currency), that an invite was sent or a log was joined. Each event carries a random ID created on your phone for this purpose (not your advertising identifier) and, if you are signed in, your account ID.

They never contain your baby's name, age, records, notes or any free text. They are stored on our servers in the EU, used only by us, deleted with your account if they are linked to it, and kept only as long as we need them to understand how the app is used. We rely on our legitimate interest in improving the app; you can object by writing to us, and we will delete the events linked to your phone's ID.

Ad measurement (AppsFlyer)

We advertise Belly Birth Baby outside the app. To learn whether an install or a purchase came from one of our ads, the app includes AppsFlyer's software kit in its "Strict" version, which contains no code for the advertising identifier. Belly Birth Baby itself shows no ads.

What is sent, only while the "Ad measurement" switch is on:

What is never sent: anything you log, your baby's name or age, notes, quiz answers, your email address, your name or your account ID.

No tracking prompt. The app never reads your advertising identifier (IDFA) and does not track you across other companies' apps and websites, so it does not show the App Tracking Transparency prompt.

Your choice. If your device region is in the European Economic Area, the UK or Switzerland, the switch starts off and runs only if you turn it on, which is your consent. Elsewhere it starts on based on our legitimate interest in measuring our advertising, and turning it off is your way to object. Turning it off stops the kit at once. AppsFlyer acts as our processor; its own policy is at https://www.appsflyer.com/legal/privacy-policy/.

Who else processes data for us

ProviderWhat forWhat they receive
Fly.io (EU region, Amsterdam)Hosting our servers and databaseEverything our servers hold, as described above, encrypted at rest
AppleSign in with Apple, payments (StoreKit), push delivery (APNs), speech recognition when not on deviceSign-in tokens, purchase status, push tokens and payloads, dictated audio on older devices
AppsFlyerAd measurement, only with the switch onThe events and device signals listed above
Our email delivery serviceSending sign-in codesYour email address and the code
SentryReports of errors on our serversError details, scrubbed of personal data before they are recorded

Some of these providers (Apple's push service, AppsFlyer, our email delivery service and Sentry) may process data outside the EU. Where they do, we use the safeguards the law requires for international transfers, such as the European Commission's Standard Contractual Clauses. We do not sell data, and we do not share it with data brokers or advertisers.

How long we keep data

Your rights and how to use them

These rights are provided in line with the GDPR and UK GDPR, and we honour equivalent requests from anywhere. We answer within one month.

Security

Connections between the app and our servers use HTTPS only. Your sign-in session is stored in the iOS Keychain. Access tokens are short-lived, refresh tokens are stored as hashes and revoked when you sign out or delete your account, and every request for a baby's log checks that you are one of its active members.

Changes to this policy

When we change this policy we update the date at the top and, for material changes, say so in the app's release notes before the change takes effect.

Contact us

Questions or requests about your data or this policy:

support@bellybirthbaby.app

Nibra LLC, Belly Birth Baby
bellybirthbaby.app