Draft — this document is not in force until it is published.
Privacy Policy
Effective from TODO (YYYY-MM-DD).
Lalu is a shared care diary for a baby: feeds, sleep, diapers, pumping, medicines, temperatures and your own events, with photos and voice notes. What you record about your child is health data — the most sensitive kind of personal data. This policy says plainly what we collect, why, who sees it and how to take it with you or delete it.
In short: four promises
- We do not sell data about your child or share it with anyone outside the family you build in the app — except the copies for the family's parents described in sections 4, 5 and 8.
- Data about your child never reaches advertising networks — not even indirectly, as a signal for targeting. There are no ads in the web app.
- You can take your data with you — the CSV export is always free, also when Premium has ended.
- You can delete it for good — with one button in the app, without writing e-mails.
1. Who we are and how to reach us
The controller of your personal data is TODO - the owner's full name and the business name of the sole proprietorship (D-35), TODO - the registered business address from CEIDG, TODO (NIP, REGON) ("we").
- Privacy questions and requests: privacy@babylalu.com
- Help with the app: support@babylalu.com
- Website: https://babylalu.com, the app: https://app.babylalu.com
We have not appointed a data protection officer. Write to privacy@babylalu.com about anything in this policy — a person reads every message.
If you live in the United Kingdom, see section 14. If you live in the United States, see section 15 and our Consumer Health Data Privacy Policy.
2. Who this policy is about
- You, if you use the app — a parent who starts the diary or a caregiver invited to it (another parent, a nanny, a grandparent).
- Your child, whose diary it is. A child cannot agree to anything, so a parent decides for them (section 4).
- A person who pumps breast milk — data about pumping is data about her own health, so she gives her own consent (section 4).
- Other people who may appear by chance in a photo or be heard in a voice note.
Lalu is meant for parents and other adult caregivers. It is not designed for children to use.
3. What we collect
You do not have to give us anything. Without an account the diary works and stays on your device. An account needs your e-mail address and a name. Your child's data needs your consent (section 4).
You give us
| What | Details |
|---|---|
| Your account | name, e-mail address, password (we keep only an irreversible Argon2id hash of it), language, time zone, units; when you last used the app; whether you have used the free Premium trial (each person can use it once) |
| Sign-in with Google or Apple (if you choose it) | from Google or Apple we receive only an account identifier, your e-mail address and your name. With Apple we also keep, encrypted, a key Apple gives us — only to cut the link with Apple when you delete your account |
| The family | its name, the people in it, their roles, the date they joined and, if set, the last day of a caregiver's access |
| Your child | name, date (and time) of birth, optionally the due date, sex, birth weight and a profile photo |
| Your consent | when it was given, by whom and which version of the text was shown |
| The diary — health data | feeds (breast, bottle, solids, reactions), sleep, diapers (colour, consistency), pumping, medicines given and medicine schedules (name, dose, reason), temperatures, your own events, notes, photos and voice notes added to entries |
| Who did what | the author and time of every entry and change, and the history of changes with the values before and after |
Nothing in the app asks for your address, phone number, national ID number or contacts. Photos lose their hidden location data (EXIF, including GPS) on your phone, before they are even saved.
The app records automatically
| What | Why |
|---|---|
| Your devices: a name you can recognise, the platform, when each was last used | so you can see where you are signed in and sign a device out |
| A notification address for this device (if you allow notifications) | to deliver notifications |
| IP address, time, request and browser in our server's access log; failed sign-ins and sign-outs in a separate security log | to protect accounts and find attacks |
| Error reports (section 7) | to fix bugs — never the content of your entries |
We do not use analytics, advertising or tracking tools, and we do not track you across other websites or apps.
4. Why we use it and on what legal basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Your account, the app, keeping the diary in sync between devices and caregivers, e-mails about your account | account, family, devices | performing our contract with you — art. 6(1)(b) |
| Keeping the diary about your child | the child's profile and all diary entries, photos and voice notes | your explicit consent as the child's parent or legal guardian — art. 9(2)(a) and art. 6(1)(a) |
| Keeping data about pumping | pumping entries and their photos and notes | the explicit consent of the person who pumps, given by her, for one family — art. 9(2)(a) and art. 6(1)(a) |
| Copies of a child's diary for the family's other parents after a consent withdrawal, and for a parent removed by the owner (sections 4 and 5) | the child's diary as CSV files, without photos, voice notes or other people's pumping | under legal review — the basis will be named here before publication |
| People seen or heard by chance in a photo or voice note | their image or voice | our legitimate interest in keeping the note the family made — art. 6(1)(f) |
| Payments for Premium | see section 7 | the contract — art. 6(1)(b); tax and accounting records — art. 6(1)(c) |
| Security: limiting attempts, the security log, telling every family member when someone joins, is removed or loses access | IP address, sign-in events, family membership | our legitimate interest in protecting accounts and your child's data — art. 6(1)(f) |
| Fixing errors | error reports without health data | our legitimate interest in a working app — art. 6(1)(f) |
| E-mails to an inactive account and its deletion (section 8) | e-mail address, last use | our legitimate interest in not keeping data longer than needed — art. 6(1)(f) |
| One free trial per person | the record that you used the trial | our legitimate interest in preventing abuse of the trial — art. 6(1)(f) |
| Answering your requests about your data and keeping a record of them | your request and our answer | legal obligation — art. 6(1)(c) |
Consent to your child's data. Before a child can be added, the app asks for two separate things: your consent to processing your child's health data to keep the diary — the child's profile and everything you record about the child — and your statement that you have parental responsibility or are an authorised caregiver. The consent is not hidden in the Terms. Without it the child cannot be added. If we change the text of the consent, the app asks again for each child — we never assume that you agreed to a new text.
Withdrawing consent is possible at any time in More → Children. It deletes the child's profile and the whole diary for every caregiver, with no way to restore it: the child disappears from the app at once and from our servers within 24 hours. The only thing kept is a copy: before you withdraw, the app offers you a CSV copy, and the family's other parents get a link to one by e-mail; these copies are deleted after 30 days. Withdrawal does not make earlier processing unlawful.
Lactation consent is asked in the breast pump panel, before the first entry, of the person who pumps — nobody can give it for her. Without it nobody can log her pumping, not even another caregiver. She can withdraw it in More → Settings → Data; her pumping entries then disappear from every device at once.
We do not make decisions about you by automated means and do not profile you. Statistics and reminders in the app are arithmetic on what you typed. We do not use your data to train artificial intelligence models, including large language models.
5. The family: who sees what
The diary belongs to the family, not to one person.
- People invited to the family see the child's entire history, including entries made before they joined. The app says this to the person creating the invitation before anything is shared. There is no partial access.
- A "View only" member reads and does not write. A caregiver or a viewer can have a last day of access; after it the access ends by itself and the family is told.
- Everyone in the family sees who added or changed each entry.
- When someone joins, is removed or loses access, every member is told — by notification and e-mail. Nobody joins or is removed silently.
- Leaving the family neither moves the history nor deletes it — the diary stays with the family. Before leaving, any member can download a CSV copy (More → Settings → Data → CSV export). The family's diary is removed at once from the device where they leave and from their other devices when those next connect; a device that still holds entries not yet sent keeps them, read-only, until its owner saves or removes them.
- A parent removed from the family by its owner gets an e-mail with a link to a CSV copy of what they could see at that moment — without other people's pumping entries — valid for 30 days. A caregiver or a viewer who is removed, or whose access ends, gets no copy.
6. Where your data is kept
- On your device first. The diary works without an account and without the internet. It is kept in the browser's or phone's storage for the app (a small database called IndexedDB). We do not encrypt it in the app — it is protected by the encryption of your device and its screen lock, which is on by default on modern phones. Keep your device locked; on a computer, turn on disk encryption (BitLocker on Windows, FileVault on a Mac).
- The diary backup file (More → Settings → Data → Diary backup) is a JSON file with the whole diary. It is not encrypted — keep it like medical records and do not send it by e-mail or put it in shared folders.
- On our servers in the European Union, once you create an account. Before you have an account, your diary does not leave your device.
- Encrypted backups are made every day and kept in another EU location. The server can create them but cannot read them — the key that opens them is kept offline and is never on our server or at the storage provider.
7. Who receives data
We share data only with the people you invite to your family (section 5) and with the service providers below. Except where the table says otherwise, they process it on our behalf under data processing agreements and only for the purposes in this policy. We do not sell data and do not give it to data brokers or advertisers.
| Recipient | What they get | Where, and the safeguard for transfers outside the EEA |
|---|---|---|
| Server and database hosting | all account and diary data | EU |
| Object storage (the provider is being selected) | export files, photos and voice notes | EU |
| Encrypted backup storage | encrypted copies, without the key to read them | EU, a location other than the server |
| Transactional e-mail | your e-mail address, name and the content of our e-mails (links, never diary entries) | EU |
| Sentry (error reports) | what failed, the screen or address in the app where it happened, the browser or system version, a pseudonymous identifier of the family and of the change that failed; no health data, no content of entries and no IP address — your browser sends error reports to our server, which forwards only an allowed list of fields. Kept for the shortest period Sentry offers, at most 90 days | stored in Sentry's EU data region (Germany); Sentry's staff in the USA may access it for support, under the EU–US Data Privacy Framework or standard contractual clauses |
| Stripe (payments, only if a family buys Premium) | the e-mail address of the person who buys — not always the family's owner — their language and the family's identifier; nothing about children or the diary. Card details, and the billing address where tax requires it, are entered on Stripe's page and kept by Stripe; we never see the card. Stripe is also an independent controller for its own legal duties, such as fraud prevention | EU and USA, under the EU–US Data Privacy Framework or standard contractual clauses |
| Push services of your browser or phone (Google, Apple, Mozilla, Microsoft) | the notification address of your device and an encrypted message they cannot read, holding only its type and one identifier — never a child's name, a medicine or a dose | may be outside the EEA; the safeguard is under legal review |
Have I Been Pwned. When you choose a password, we check the first 5 characters of an irreversible fingerprint of it against a public list of leaked passwords. This is not personal data — it cannot be traced back to you or your password — and your e-mail address never leaves our server.
Google and Apple are not our service providers when you sign in with them. You choose them yourself, they act as separate controllers under their own privacy policies, and we send them nothing about your child.
Transfers outside the European Economic Area. Diary data stays in the EU. The table names the safeguard for each recipient that may process data outside the EEA. Write to us for a copy.
We may disclose data when the law requires it, for example to a court or an authority, and only to the extent required.
8. How long we keep it
| Data | How long |
|---|---|
| Your account | as long as you have it; after deletion it is erased at once (section 9) |
| The diary | as long as the family keeps it |
| An entry you delete | hidden at once — you can undo right after deleting; erased for good with its history after 90 days |
| A child you delete | 7 days to restore it, then erased with all entries, photos and voice notes |
| A child whose consent was withdrawn | hidden at once, erased from our servers within 24 hours, without the 7 days |
| Pumping entries after the lactation consent is withdrawn | erased at once |
| Technical records of syncing | 30 days; records of conflicting edits up to 90 days |
| CSV export | the download link works 24 hours; the file is then deleted |
| Copies e-mailed when an account is deleted, a parent is removed or a consent is withdrawn | 30 days |
| A signed-out device in your device list | deleted 30 days after its sign-in expires |
| Security log (sign-ins, sign-outs, IP addresses) | 365 days |
| Access log of our front server (IP address, time, request, browser) | 14 days |
| Logs of the services running the app | limited in size (3 files of 10 MB per service) and overwritten |
| Background tasks that failed | 7 days |
| Server monitoring (performance and background tasks) | 7 days |
| Payment events received from Stripe | 90 days |
| Error reports | the shortest period Sentry offers, at most 90 days |
| Your requests about your data and our answers | 3 years |
| Payment and invoice records | as long as tax and accounting law requires — in Poland generally 5 years after the end of the year of payment, and 10 years for records of sales taxed through the EU VAT one-stop shop (OSS) |
| Encrypted backups | deleted data leaves all backups within 60 days at most (30 days of rotation and up to 30 days of the storage provider's version protection) |
| An inactive account | see below |
Inactive accounts. An account is active when someone signs in to it or the app on one of its devices renews its session — this happens on its own whenever you use the app online. After 36 months without any activity we send an e-mail with the date of deletion — at least 30 days later, normally when 48 months have passed — and a reminder 7 days before it. Signing in cancels the deletion. On that date the account is deleted the same way as with "Delete account" (section 9), without a CSV copy — the e-mails tell you how to take one before. Two exceptions: an account that started a subscription still in force is not deleted; and if you own a family that others still use and no other parent can take it over, your account stays its owner until another parent joins or you sign in. We do this because a child's health records should not be kept forever "just in case".
Copies on your devices stay until you sign out, leave the family or remove the app. A device that never connects to the internet again keeps its copy — we cannot erase it remotely.
9. Your rights and how to use them
Most rights work directly in the app, at once:
| Right | How |
|---|---|
| Access and a copy of your data (art. 15, 20) | More → Settings → Data → CSV export — entries in open CSV files, free, also after Premium ends. The CSV files list photos and voice notes but do not contain them: the diary backup (More → Settings → Data → Diary backup) holds those kept on your device, and we send the rest on request to privacy@babylalu.com |
| Correction (art. 16) | edit any entry, your child's profile or your account |
| Erasure (art. 17) | delete an entry or a child; More → Account → Delete account |
| Withdrawing consent (art. 7(3)) | More → Children → the child → Withdraw consent; the lactation consent in More → Settings → Data |
| Restriction (art. 18) and objection (art. 21) | write to privacy@babylalu.com |
| Signing out other devices | More → Account → Devices |
Deleting your account works in two ways, because a child's data belongs to the family:
- A family nobody else uses (usually your own) is erased completely — the diary, its history, deleted entries, photos and voice notes.
- In a family you share with others, your account is anonymised: your name and e-mail address are removed, and entries you made stay as part of the child's records, with no name attached. Your consent to lactation data is withdrawn and your own pumping entries are erased. If you own a shared family, ownership passes to its longest-standing other parent; if there is none, the app asks you to hand over ownership first.
- Before deleting, we e-mail you a link to a CSV copy of the diaries you could see, valid for 30 days. The e-mail carries only the link, never the file.
You can also write to privacy@babylalu.com. We answer within one month; for complex requests we may extend this by two more months and will tell you why. We may ask you to confirm a request from the e-mail address of your account. Using your rights is free.
Complaints. You may complain to a supervisory authority — in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority of the EU country where you live or work. We would be glad to hear from you first.
Data about your child when they grow up. A child whose data a parent recorded can ask us to delete it, also when they are an adult — write to privacy@babylalu.com.
10. Data stored in your browser — no cookies for tracking
Lalu does not use cookies for advertising or analytics. To work, the app stores in your browser or phone:
- the diary and the queue of entries waiting to be sent (IndexedDB, the browser's database for the app);
- the key of your signed-in session and a few device settings (local storage);
- the state of a Google or Apple sign-in in progress (local storage, at most 10 minutes);
- the app's own files, so it opens offline (the service worker's cache — never your diary).
All of this is strictly necessary to provide the app you asked for, so we do not ask for separate consent. Signing out deletes the diary, the cached data and the session key from the device.
Stripe's payment page and Google's or Apple's sign-in pages are their sites and use their own cookies under their own policies.
11. Notifications
What travels through the push service is only the type of the notification and one identifier, encrypted so the service cannot read it. The text is put together on your device from the diary already stored there — for example "Medication time" with the name of the medicine — so a notification your device shows can name a medicine from your diary and can appear on the lock screen. Your phone's or browser's settings decide whether notification content shows there.
In the app you choose which notifications each family sends you and whether this device shows them at all (More → Settings → Notifications). The e-mail telling you that someone joined, was removed from or lost access to your family always arrives, because it protects your child's data.
12. How we protect your data
- Encrypted connections (TLS) and strict browser security rules (Content Security Policy).
- Passwords checked against lists of leaked passwords and kept only as an Argon2id hash.
- Short-lived device sessions, a list of signed-in devices, "Sign out" for each and for all others.
- Each family's data is separated from every other family's and checked by automated tests; another family's data simply does not exist for you.
- Invitation links and codes expire (7 days, a code 15 minutes) and can be revoked at any time.
- No health data in logs, error reports, web addresses or names of export files.
- Photos and voice notes are kept privately and fetched only through short-lived signed links.
- Daily encrypted backups, with a restore test every quarter.
No system is perfect. If a breach puts your rights at risk, we will tell the supervisory authority within 72 hours and tell you directly, in plain language, when the risk to you is high — and with data about a child we assume it is.
13. Not a medical device
Lalu records what you type and does simple arithmetic on it — totals, times, intervals. It does not diagnose, does not assess your child's condition and does not calculate doses. Reference information in the app is general and the same for everyone. If you are worried about your child's health, contact a doctor; in an emergency, call your local emergency number.
14. If you live in the United Kingdom
The UK GDPR and the Data Protection Act 2018 apply to you. Everything above applies to you in the same way, with these differences:
- Our UK representative under article 27 of the UK GDPR is TODO - name and UK address of the representative under UK GDPR art. 27, before 1.0 (F8-16) - the web app serves UK users from the first day (D-84). You can contact them instead of us about anything in this policy.
- Your data is kept in the European Union. The UK recognises the EU as providing adequate protection, so no additional safeguard is needed.
- You can complain to us at privacy@babylalu.com — we acknowledge every complaint within 30 days — and to the Information Commissioner's Office (ico.org.uk, 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF).
15. If you live in the United States
- Our Consumer Health Data Privacy Policy explains how we handle consumer health data under the laws of Washington, Nevada and Connecticut and how to use your rights there, including how to appeal a decision.
- We do not sell personal data, including consumer health data, and do not use it for targeted advertising or profiling. We have nothing to opt you out of, but you may still write to us.
- Depending on your state, you may have the right to know what we hold, to get a copy, to correct and to delete it, and to withdraw consent. Use the app (section 9) or write to privacy@babylalu.com. We act within 30 days; the law allows up to 45. If we decline, you can appeal by replying to our answer or writing to privacy@babylalu.com with "Appeal" in the subject; we decide within 45 days (60 days in Connecticut) and, if we still decline, tell you how to contact your state's Attorney General.
- We do not knowingly collect personal information from children under 13. Information about your child comes from you, the parent or caregiver.
- Your data is stored on servers in the European Union.
16. Changes to this policy
We will update this policy when the app or the law changes, and show the date above. We tell you about important changes in the app or by e-mail before they take effect. If a change concerns what you consented to, we ask for your consent again — we never treat continued use as agreement. If ads ever come to the mobile apps, they will get nothing about your child, and we will update this policy before they appear. Earlier versions are available on request.
See also our Terms of Service. Polityka prywatności po polsku.