Privacy Policy
Last updated: October 8, 2026
Belly Birth Baby is a baby tracker for sleep, feeds, diapers and growth, made by Nibra LLC ("we", "us"). This policy explains, in plain language, what stays on your phone, what reaches our servers and when, who else is involved, and how to export or delete your data.
The short version
- Your log starts on your phone. Everything you record about your baby is stored on your iPhone. You do not need an account to track, and nothing you log is sent to us while you track on your own.
- Sharing is your choice. If you invite a caregiver or join one with a code, your baby's log syncs through our servers in the European Union (Amsterdam, the Netherlands) so everyone in the family sees the same timeline. Diaper photos never leave the phone that took them.
- An account is only for sharing. Sign in with Apple or a one-time code sent to your email. Your account holds an account ID, an email address and the name the family sees.
- You control your child's records. You decide what is recorded about your baby and who can see it. As parents and caregivers you are the controllers of your child's records; we store and sync them on your instructions and use them for nothing else.
- No ads, never sold. Belly Birth Baby shows no ads, and we never sell your data or your baby's data.
- Ad measurement, with a switch. Our ad measurement partner, AppsFlyer, is told about installs, a few steps in the app and purchases so we can see which of our ads work. It never receives anything you log. Switch it off in Settings > Privacy; it starts off in the EEA, the UK and Switzerland.
- Export and delete. Export your log as CSV at any time. If you have an account, export what our servers hold and delete your account from Settings > Account.
Tracking on your own (no account)
When you track on your own, your baby's profile (name, birth date, feeding style) and every sleep, feed, diaper and growth record, with any note or diaper photo you add, are stored only on your iPhone, using standard iOS storage. The Home Screen widget and Live Activities read the same on-phone data. We do not receive a copy and cannot see it.
A few things still leave the phone even without an account, and none of them contain your log:
- Product events to our own server, described under "How we learn what works" below.
- Ad measurement events to AppsFlyer, if the switch is on, described under "Ad measurement (AppsFlyer)".
- Purchases, which Apple handles.
Your account
You need an account only to share. You can sign in with:
- Sign in with Apple: Apple gives us an identity token that our server checks with Apple. If you hide your email, Apple gives us a private relay address instead. Your name from Apple is not sent to our server; it may suggest the name your family sees, which you can change.
- A 6-digit code by email: we send a one-time code to the address you type. Codes expire after 10 minutes and are stored only as a hash.
Your account record holds an account ID, an email address (yours or Apple's relay address) and the display name the family sees ("Your name, as the family sees it"). Belly Birth Baby and our pregnancy app, BellyBirthBloom, use the same Nibra account service, so if you sign in to both with the same Apple ID or email, it is the same account. Neither app copies the other's logs. Because it is one account, deleting it from either app deletes it for both.
Your child's data
The records in Belly Birth Baby are about your child, and some of them (feeds, diapers, growth) are health-related. We treat them with the same care as health data about an adult:
- You are in charge. Parents and caregivers are the controllers of their child's records: you choose what to record, whether to share it, and with whom. We process the log only to store it, sync it between the members you chose and show it back to you.
- No account for a child. A child never uses the app and we never create an account for a child.
- Not used for anything else. Your child's records are never used for advertising, never sent to AppsFlyer, never sent to our product-event store, and never sold.
- Equal rights for every member. Every member of a shared log can export it and can edit or delete records in it.
- When you leave or delete your account, the log stays with the other members, because it is equally theirs; your name is removed from the records you logged. When the last member leaves or deletes their account, the log is closed at once (no one can open or join it) and permanently erased within 90 days.
The app is for adults who look after a baby. It is not directed at children, and we do not knowingly collect personal data from anyone under 16 as a user. If you think a child has created an account, contact us and we will delete it.
Notifications, Live Activities and push
- Nap-window reminders are scheduled on your phone. The app asks for notification permission only when you turn reminders on in Settings, and nothing about them is sent to us.
- Live updates between caregivers. When sharing is on, your phone registers with Apple's Push Notification service (APNs) and gives our server its push token and Live Activity tokens. When another member logs something, our server asks Apple to deliver a silent push that tells your phone to fetch the change, and for a running nap or feed, a Live Activity update that shows your baby's first name, nap or night, the start time and, for nursing, the side and whether it is paused. Notes, diapers, growth and caregiver names are never put in a push. Apple stores a push only until it is delivered (here, at most one hour). Tokens are deleted when you sign out, delete your account, or when Apple reports them invalid.
- No marketing notifications. We never send promotional push notifications.
On-device features
- Notes and Ask about your baby (Premium) are written by Apple's on-device language model on iPhones that support Apple Intelligence. Your log is not sent to us or to Apple for this.
- Dictation in Ask uses speech recognition on your iPhone when your device supports it. On devices that do not, iOS sends the audio to Apple's speech service to turn it into text, under Apple's privacy policy. The app asks for microphone and speech permission only when you tap Dictate.
- Soothe (the night light and sounds) generates its sounds on the phone. It never uses the microphone.
How we learn what works (product events)
To understand which parts of the app help and to test the order of first screens, the app sends short product events to our own server: for example that onboarding started or finished, which answer was chosen for a quiz question (from a fixed list, such as "Make nights easier"), that a first nap, feed or diaper was logged, that the Premium screen was shown or closed, that a trial or purchase started (with plan, price and currency), that an invite was sent or a log was joined. Each event carries a random ID created on your phone for this purpose (not your advertising identifier) and, if you are signed in, your account ID.
They never contain your baby's name, age, records, notes or any free text. They are stored on our servers in the EU, used only by us, deleted with your account if they are linked to it, and kept only as long as we need them to understand how the app is used. We rely on our legitimate interest in improving the app; you can object by writing to us, and we will delete the events linked to your phone's ID.
Ad measurement (AppsFlyer)
We advertise Belly Birth Baby outside the app. To learn whether an install or a purchase came from one of our ads, the app includes AppsFlyer's software kit in its "Strict" version, which contains no code for the advertising identifier. Belly Birth Baby itself shows no ads.
What is sent, only while the "Ad measurement" switch is on:
- that the app was installed and opened for the first time;
- that onboarding was started and completed;
- that a first care action was logged, as one label from a fixed list (start nap, feed, diaper, soothe);
- that the Premium screen was shown or closed, with a short label for where it was opened;
- that a free trial or a subscription started, with the plan (annual or monthly), the price and the currency;
- that you signed in for the first time, and whether with Apple or an email code;
- the standard device signals the kit collects without the advertising identifier: your IP address, device model, iOS version, app version, language, and Apple's identifier for vendors (a number that is the same across our apps on your phone and is not the advertising identifier).
What is never sent: anything you log, your baby's name or age, notes, quiz answers, your email address, your name or your account ID.
No tracking prompt. The app never reads your advertising identifier (IDFA) and does not track you across other companies' apps and websites, so it does not show the App Tracking Transparency prompt.
Your choice. If your device region is in the European Economic Area, the UK or Switzerland, the switch starts off and runs only if you turn it on, which is your consent. Elsewhere it starts on based on our legitimate interest in measuring our advertising, and turning it off is your way to object. Turning it off stops the kit at once. AppsFlyer acts as our processor; its own policy is at https://www.appsflyer.com/legal/privacy-policy/.
Who else processes data for us
| Provider | What for | What they receive |
|---|---|---|
| Fly.io (EU region, Amsterdam) | Hosting our servers and database | Everything our servers hold, as described above, encrypted at rest |
| Apple | Sign in with Apple, payments (StoreKit), push delivery (APNs), speech recognition when not on device | Sign-in tokens, purchase status, push tokens and payloads, dictated audio on older devices |
| AppsFlyer | Ad measurement, only with the switch on | The events and device signals listed above |
| Our email delivery service | Sending sign-in codes | Your email address and the code |
| Sentry | Reports of errors on our servers | Error details, scrubbed of personal data before they are recorded |
Some of these providers (Apple's push service, AppsFlyer, our email delivery service and Sentry) may process data outside the EU. Where they do, we use the safeguards the law requires for international transfers, such as the European Commission's Standard Contractual Clauses. We do not sell data, and we do not share it with data brokers or advertisers.
How long we keep data
- On your phone: until you delete it. Swipe any record on the Log tab to delete it; deleting the app removes everything stored on the phone.
- Shared logs on our servers: for as long as the log has members. A record you delete is kept as a deletion marker for 90 days, so the deletion reaches every member's phone, and is then erased.
- Your account: until you delete it. Deleting it is immediate (see below).
- Sign-in codes: 10 minutes. Push tokens: until you sign out, delete your account, or Apple reports them invalid.
Your rights and how to use them
- Access and portability. Export your baby's log as a CSV file at any time from Settings > Family & data > Export everything (CSV). If you have an account, Settings > Account > Export my data downloads everything our servers hold for you, including every shared log you belong to, as a JSON file.
- Correction. Tap any record to change it.
- Deletion. Settings > Account > Delete account deletes your account and everything linked to it on our servers immediately: sign-in details, memberships, push tokens, linked product events and your Premium record. Shared logs stay with their other members without your name, as explained under "Your child's data". Everything on your phone stays until you delete it or delete the app.
- Leaving a shared log. Settings > Caregivers > Leave stops you seeing new entries; what is already on your phone stays.
- Objection and consent. Switch ad measurement off in Settings > Privacy. To object to product events, write to us.
- Complaints. If you are in the EEA, the UK or Switzerland, you can complain to your local data protection authority. We would rather hear from you first.
These rights are provided in line with the GDPR and UK GDPR, and we honour equivalent requests from anywhere. We answer within one month.
Security
Connections between the app and our servers use HTTPS only. Your sign-in session is stored in the iOS Keychain. Access tokens are short-lived, refresh tokens are stored as hashes and revoked when you sign out or delete your account, and every request for a baby's log checks that you are one of its active members.
Changes to this policy
When we change this policy we update the date at the top and, for material changes, say so in the app's release notes before the change takes effect.
Contact us
Questions or requests about your data or this policy:
Nibra LLC, Belly Birth Baby
bellybirthbaby.app