BabyNest

Privacy Policy

Effective July 25, 2026

BabyNest is a baby wellness tracking and caregiver coordination service. This policy explains what information the service handles, why it is used, how caregivers share it, and the choices available to account holders.

1. Scope

This policy applies to the BabyNest mobile application, the BabyNest API, and this website. BabyNest is a wellness and caregiving tool. It is not a medical diagnostic product, does not replace a pediatrician, and does not provide emergency care.

BabyNest accounts are intended for parents, guardians, and other adult caregivers. Children should not create or operate accounts themselves.

2. Information we collect

Depending on the features you use, BabyNest may process:

Google sign-in

If you choose Continue with Google, BabyNest receives a Google account identifier, your email address and its verification status, and basic profile details such as your name. We use this information to create or authenticate your BabyNest account. BabyNest does not receive your Google password and does not request access to Gmail, Drive, Contacts, Calendar, or other Google content.

3. How we use information

We use information to operate the features requested by caregivers, including:

4. Caregiver sharing

Household information is available to caregivers who accept an invitation sent to their exact email address. Household roles determine what each caregiver may do. Owners manage roles; parents and caregivers may edit baby records; viewers may read records but cannot edit them.

When a caregiver is removed, future access is disabled. Historical records may continue to identify the caregiver who created them so the remaining household has an accurate care history. Removing a caregiver also pauses their household reminders and suppresses pending reminder deliveries.

5. Private photos and optional image review

Private photos are stored in a private S3-compatible object store. They are not publicly listable. BabyNest uses time-limited signed URLs when an authorized caregiver uploads or views a photo.

Stool photo review, if enabled in the future, is limited to visual logging and risk flagging and is not a diagnosis. The production feature remains disabled until its processing provider, retention, geographic processing, caregiver disclosure, and consent requirements are approved. If enabled, explicit caregiver consent is required before a review is queued.

6. Service providers and disclosure

Infrastructure and service providers may process information only as needed to host the service, store private media, deliver notifications, provide authentication, maintain security, and perform other requested BabyNest functions. BabyNest may also disclose information when required by law, to protect the service or its users, or as part of a business transaction subject to appropriate safeguards.

BabyNest does not use Google account information to access unrelated Google services.

7. Retention

BabyNest keeps active account and household information while it is needed to provide the service. Session records expire according to configured authentication lifetimes. Operational and security records are retained only for approved operational periods.

Deleting an account removes or anonymizes account information as described below. Information belonging to a household shared with other active caregivers may remain available to that household. Residual copies may remain temporarily in protected backups until those backups expire under the applicable backup schedule.

8. Export and deletion

Account export

You can request an account export from Settings. The export contains account, membership, baby, activity, reminder, notification, media metadata, insight, and sanitized audit information visible to your account. It excludes passwords, raw tokens, private object keys, signed media URLs, raw provider identifiers, and other security secrets.

Account deletion

You can delete your account from Settings. Deletion revokes sessions, removes notification and reminder state owned by the account, disables future authentication, archives non-owner memberships, and anonymizes retained historical attribution.

If you are the only caregiver for a household, the household and its records are deleted and private-media cleanup is initiated. If other active caregivers remain, shared household records and media remain available to them. Ownership is transferred when required to preserve that shared household.

After sign-out or successful deletion, the mobile app clears locally cached baby and event information, sync cursors, offline changes, and stored session data from that device.

9. Security

BabyNest uses HTTPS, short-lived access tokens, rotating refresh tokens, server-side session revocation, household authorization, private media storage, signed media URLs, rate limiting, and security auditing. No internet service can guarantee absolute security, but BabyNest applies safeguards intended to reduce unauthorized access, alteration, disclosure, and loss.

10. Your choices

You can review and update supported account and baby information in the app, manage notification preferences, remove your own uploaded media where supported, export your account information, leave or manage caregiver relationships according to your role, and delete your account.

Depending on where you live, applicable law may provide additional rights such as access, correction, deletion, restriction, objection, or portability. Requests may be made using the contact method below.

11. Changes to this policy

We may update this policy as BabyNest changes or as legal and operational requirements evolve. The effective date at the top identifies the current version. Material changes will be communicated through the service or another appropriate channel.

12. Contact

For privacy questions or requests, contact [email protected]. Account export and deletion are also available directly in BabyNest Settings.