New here? Read the plain-English summary first →

Privacy Policy

Effective date: April 28, 2026  ·  Last updated: June 24, 2026

Plain-English Summary

Contents
  1. Introduction and Data Controller
  2. Data We Collect
  3. How We Use Your Data
  4. Legal Basis for Processing (GDPR)
  5. Third-Party Processors
  6. Apple HealthKit
  7. HushBaby On-Device Processing
  8. AI and Machine Learning Features
  9. Children's Data (COPPA)
  10. Caregiver Access
  11. Data Retention
  12. Audit & Compliance Records
  13. Security Measures
  14. Your Rights — GDPR (Art. 15–22)
  15. California Residents — CCPA / CPRA
  16. Washington Residents — My Health My Data Act
  17. International Data Transfers
  18. Breach Notification
  19. Data Protection Impact Assessment
  20. Automated Processing and AI Decisions
  21. Government and Legal Requests
  22. Cookies and Web Tracking
  23. Lodging a Complaint
  24. Changes to This Policy
  25. Contact

1. Introduction and Data Controller

The Perfect Start is a postpartum and newborn tracking application for parents. The app is built with Capacitor and is available as an iOS app and as a Progressive Web App (PWA) at https://start.thetrulyperfect.com. This Privacy Policy is issued by The Truly Perfect LLC (Texas limited liability company), operator of The Perfect Start.

Data Controller: The Truly Perfect LLC
Email: support@thetrulyperfect.com (general support)

This Privacy Policy explains what personal data we collect, why we collect it, the legal basis on which we process it, who we share it with, how long we keep it, and the rights you have. This policy applies to all users of the App and website. By creating an account or using the App, you acknowledge that you have read this policy.

We take privacy seriously — the data you share with us is deeply personal, including information about your body, your recovery, your newborn, and your family. We have designed our data practices to minimise collection and to be transparent.

2. Data We Collect

A. Account and Authentication Data

B. Parent and Family Profile Data

C. Baby Data (COPPA Notice: see Section 9)

D. Maternal Recovery and Health Data (GDPR Art. 9 Special Category)

E. Apple HealthKit Data

If you grant HealthKit permission, the app reads and writes the following categories: body weight, blood pressure, heart rate, and body temperature. See Section 6 for full details.

F. AI Conversation History

G. Insurance Data (Sensitive Financial)

H. Payment Metadata

I. Device and Technical Data

J. Crash Logs and Error Telemetry

K. Miscellaneous App Data

3. How We Use Your Data

We use your data only to provide, personalize, and improve The Perfect Start. We do not use your data for advertising, behavioral profiling, or any purpose other than running the App for you.

4. Legal Basis for Processing (GDPR)

If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) requires us to identify a legal basis for each category of processing. Health and recovery data constitutes "special-category" data under GDPR Article 9, requiring explicit consent as its legal basis.

5. Third-Party Processors

We use the following third-party processors. For each, we name the entity, its jurisdiction, the data it receives, its purpose, and the transfer mechanism used for cross-border transfers from the EEA.

Supabase, Inc.

Jurisdiction: United States  |  Transfer mechanism: Standard Contractual Clauses (SCCs) in Supabase Data Processing Agreement
Purpose: Primary backend — PostgreSQL database, authentication, Edge Functions, and cloud storage.
Data received: All app data (account, profile, baby logs, maternal data, insurance data, messages, photos, story library).
Privacy policy: supabase.com/privacy

Stripe, Inc.

Jurisdiction: United States  |  Transfer mechanism: EU-U.S. Data Privacy Framework certification
Purpose: Web-only subscription checkout and billing portal.
Data received: Payment card information collected directly by Stripe. We receive only a Stripe customer ID and billing status. Your email may be shared with Stripe for billing communications.
Privacy policy: stripe.com/privacy

RevenueCat, Inc.

Jurisdiction: United States  |  Transfer mechanism: SCCs in RevenueCat Data Processing Agreement
Purpose: iOS in-app subscription management.
Data received: Your Supabase user UUID and Apple App Store purchase receipt. No health data or personal profile data.
Privacy policy: revenuecat.com/privacy

Anthropic, PBC (Claude)

Jurisdiction: United States  |  Transfer mechanism: Standard Contractual Clauses in the Anthropic Commercial Data Processing Addendum; UK International Data Transfer Addendum for UK users
Purpose: (1) Fallback AI provider for text-based AI features — used when Google Vertex AI returns low confidence or a query requires longer-context, multi-step reasoning; and (2) Photo-to-Log photo classification — when you use the diaper, rash, or spit-up photo-classification feature, your photo is sent directly to Anthropic's API for classification. Both uses are accessed directly via Anthropic's paid API (no third-party gateway).
Data received: For text AI features, the same redacted, contextual query data described in Section 8 (relevant health-log context, profile fragments, question text). For Photo-to-Log, the photo you choose to classify (diaper, rash, or spit-up). We do not include direct account identifiers (email, account ID) in AI prompts, and we apply automated PII and personal-health-data redaction before transmission of text-based AI context; photo classification is gated behind your explicit in-app AI-photo consent (Settings → Privacy) and is not sent unless you have granted that consent.
Data use: Processed under Anthropic's Commercial Terms and DPA on paid-API, no-training terms — your data is not used to train Anthropic's models. Text AI query data is retained only briefly for safety and abuse-prevention purposes. Photos sent for classification are not stored by us before or after the request — the app forwards the photo bytes to Anthropic's API and discards them server-side immediately after receiving the classification result.
Privacy policy: anthropic.com/privacy

Google LLC / Google Cloud — Vertex AI (Gemini)

Google provides Gemini large language models through Google Cloud Vertex AI — Gemini 2.5 Flash (primary), with Gemini 2.5 Pro as fallback, then Anthropic Claude (direct). This is our primary AI provider chain: when the app cannot answer your question locally and a live AI call is required, your redacted query context (see Section 8) is sent directly to Google Cloud Vertex AI for processing in the United States (us-central1 region). Google acts as our processor under the Google Cloud Data Processing Addendum, on paid-API terms under which your data is not used to train Google's models and is not retained beyond what is necessary to provide the service.
Jurisdiction: United States (us-central1)  |  Transfer mechanism: Standard Contractual Clauses incorporated in the Google Cloud Data Processing Addendum (which covers Vertex AI); UK International Data Transfer Addendum for UK users
Privacy policy: policies.google.com/privacy  |  Google Cloud DPA

OpenAI, Inc.

Jurisdiction: United States  |  Transfer mechanism: SCCs in OpenAI Data Processing Addendum
Purpose: Story Builder premium features only — HD text-to-speech narration (tts-1-hd model) and cover image generation (DALL-E 3).
Data received: Generated story text (for TTS); a safe, child-appropriate image prompt derived from story theme and character description (for DALL-E 3). OpenAI does not retain request data beyond the API call per their API data policy.
Privacy policy: openai.com/policies/privacy-policy

Vercel, Inc.

Jurisdiction: United States  |  Transfer mechanism: SCCs in Vercel Data Processing Addendum
Purpose: Web hosting and serverless API functions, including web-side subscription checkout.
Data received: Standard server access logs: IP address, request URL, user agent, response code.
Privacy policy: vercel.com/legal/privacy-policy

Apple, Inc. (Sign in with Apple, In-App Purchase, HealthKit, APNs)

Jurisdiction: United States  |  Transfer mechanism: EU-U.S. Data Privacy Framework certification
Purpose: Authentication (Sign in with Apple), iOS in-app purchase processing (IAP), on-device health data access (HealthKit), and push notification delivery (APNs).
Data received: Apple manages your Apple ID identity for Sign in with Apple; Apple processes IAP transactions directly; HealthKit data remains on your device unless you explicitly pull it into the app; APNs device token and notification payload.
Privacy policy: apple.com/legal/privacy

Resend, Inc.

Jurisdiction: United States  |  Transfer mechanism: SCCs in Resend Data Processing Agreement
Purpose: Email delivery — both transactional account-related emails (e.g., partner invitation links, password reset links, account alerts) and, where you have an eligible account, win-back / re-engagement emails (see Section 3 and Section 4 — these are promotional in nature).
Data received: Recipient email address and email content (e.g., your partner's email address when you send a partner invite; your first name and a reactivation offer for a win-back email).
Privacy policy: resend.com/legal/privacy-policy

Google LLC — Firebase Cloud Messaging (FCM)

Jurisdiction: United States  |  Transfer mechanism: Standard Contractual Clauses incorporated in the Google Cloud / Firebase Data Processing Addendum; UK International Data Transfer Addendum for UK users
Purpose: Push-notification delivery on Android devices (the iOS equivalent is Apple APNs, listed above). FCM is the transport that delivers the notifications you configure (e.g., feeding and plan reminders) to your Android device.
Data received: Your FCM device token and the notification payload. Notification text may include your baby's first name (e.g., "Today's plan for [baby] is ready"). No health logs, lab values, or account email are sent to FCM.
Privacy policy: firebase.google.com/support/privacy

Functional Software, Inc. (Sentry)

Jurisdiction: United States  |  Transfer mechanism: Standard Contractual Clauses (+ UK International Data Transfer Addendum for UK users) incorporated in Sentry's Data Processing Addendum
Purpose: Client-side application crash and error monitoring — capturing unhandled errors so we can diagnose and fix faults in the app. (Performance/timing tracing is not enabled.) Crash diagnostics are enabled by default for users outside the EU/UK and disabled by default for EU/UK users (region is inferred from your device's timezone; when it cannot be determined, diagnostics default to off).
Data received: Diagnostic error events — error type and message, stack trace, the app release version and environment, and browser/OS/device type. Before transmission we apply automated redaction that strips personal and personal-health data (names, dates of birth, email and postal addresses, identifiers, and free-text content) from error messages, stack-trace frames, request URLs, and diagnostic breadcrumbs. We do not attach identity information (no name, email, or account ID) to error events, the SDK is not configured to collect default personal data (such as IP address or request headers), and we do not use session recording or replay.
Privacy policy: sentry.io/privacy  |  Sentry DPA

U.S. Government Data APIs (recall and air-quality lookups)

For the real-time lookup features described in Section 8, a minimal lookup term is sent directly to the following official U.S. government services. These are public-sector data sources, not commercial processors; no DPA/SCC mechanism applies to a U.S. government API.
U.S. FDA — Food Enforcement API (api.fda.gov): receives the product/food term you ask about, to look up matching recalls.
U.S. Consumer Product Safety Commission (CPSC) — SaferProducts (www.saferproducts.gov): receives the product term you ask about, to look up matching recalls.
U.S. EPA — AirNow API (www.airnowapi.org): receives your home ZIP code, to retrieve the current air-quality index for your area.
We do not send your name, account identifier, email, or health logs to these services.

We do not use any third-party analytics services (no Mixpanel, Amplitude, Segment, Firebase Analytics, or similar). We do not use any advertising networks or tracking pixels.

6. Apple HealthKit

If you grant permission, The Perfect Start reads and writes the following HealthKit data categories on iOS: body weight, blood pressure, heart rate, and body temperature.

When you tap "Pull from HealthKit" for any of these values, the reading is transferred from the HealthKit store on your device into The Perfect Start and saved to your Supabase account as part of your maternal recovery vitals — meaning it leaves your device and is stored on our servers.

Similarly, when you enter a vital in the app and we write it to HealthKit, the data exists both in our Supabase database and in your iOS Health app.

HealthKit data is:

You can revoke HealthKit permission at any time in iOS Settings → Privacy & Security → Health → The Perfect Start. Revoking permission does not delete readings already saved to your Supabase account; you can delete those via Settings → Delete Account or by contacting us.

7. HushBaby — On-Device Cry Detection

HushBaby is The Perfect Start's cry-detection feature. Here is exactly how it works:

The only data that leaves the device from HushBaby is the event log entry (time, duration, type) written to your Supabase account when you confirm a cry event — the same as any other manual log entry.

7a. Location Data — Environmental Check

The Environmental Check feature (Superfund sites and water-quality alerts) may use your location. Here is exactly how it works:

8. AI and Machine Learning Features

The Perfect Start uses AI to deliver personalized guidance and summaries. This section discloses which features use AI, exactly what data is sent, which AI provider processes it, whether conversations are stored, and how to opt out.

Deflection-First Architecture

Our AI system uses a deflection-first design: before making any third-party API call, the app checks a curated, on-device knowledge base (KB) of vetted content covering common newborn care, postpartum recovery, and feeding questions. If a KB hit with sufficient confidence is found, the answer is served entirely client-side — no data leaves your device and no API call is made. Only questions that cannot be confidently answered from the KB are escalated to a live API call to our LLM providers. This minimizes data exposure and reduces latency.

Source Citation Transparency

Every AI response — whether served from the KB or generated by a live API call — cites at least one verified source. Sources include recognized authorities such as the American Academy of Pediatrics (AAP), Centers for Disease Control and Prevention (CDC), World Health Organization (WHO), and National Institutes of Health (NIH). Citations appear inline in the AI response so you can verify the underlying guidance.

AI Rate Limits

To protect service availability and prevent abuse, AI features are subject to the following rate limits: 20 AI questions per day for standard use. Users receive one burst day per calendar month during which the limit is raised to 50 questions. Deflection-first KB hits (served client-side) do not count toward your daily limit. Rate limit state is stored locally on your device and reset at midnight in your local time zone.

Content Moderation Layer

All user inputs to AI features pass through a content moderation layer before any API call is made. This layer screens for profanity, hate speech, and harm-intent patterns. Inputs containing language indicating a mental health crisis, suicidal ideation, or immediate physical danger are intercepted and routed to safety resources — including the 988 Suicide and Crisis Lifeline (call or text 988 in the US) and the Postpartum Support International (PSI) helpline (1-800-944-4773) — rather than to an AI model. This routing happens automatically and does not require you to ask for help.

Baby Medicine Safety Database

The medication logging feature includes a runtime safety database that performs checks at the time you log a medication for your baby. Specifically:

This safety database is included in the app bundle and updated with app releases. It is not a substitute for your pediatrician's guidance; always consult your healthcare provider for medication decisions.

AI Providers

Local-first: most questions are answered on your device from our built-in knowledge base, with no data sent to any third-party AI. When a question cannot be answered locally and a live AI call is required, we first apply automated PII and personal-health-data redaction (names, dates of birth, phone numbers, email addresses, street addresses, ZIP codes, government IDs, and payment-card numbers) to minimise the personal data transmitted.
Primary AI provider (live API): Google Cloud Vertex AI — Gemini 2.5 Flash (primary), with Gemini 2.5 Pro as fallback, then Anthropic Claude (direct) (Google LLC / Anthropic, PBC, processed in the United States, us-central1). Both operate on paid-API, no-training terms — your data is not used to train their models. Story Builder narration and cover images use OpenAI directly (US) for premium features only. We do not route LLM prompts through any third-party AI gateway or routing layer. Separately, the Photo-to-Log photo-classification feature (diaper, rash, spit-up) sends your photo directly to Anthropic's API for classification — see "Feature-by-Feature Disclosure" below and the Anthropic, PBC entry in Section 5.

Real-Time Government Data Lookups

A small number of features answer your question by querying an official government data API directly, rather than by sending your question to an LLM. These lookups happen on a fast path before the LLM redaction step described above, so the redaction applied to LLM prompts does not apply to them; instead, only the minimal lookup term needed for the query is sent. Specifically:

These are U.S. government services. We do not send your name, account identifier, email, or health logs to them — only the lookup term (a product name, or your ZIP code) required to perform the query. See Section 5 for the recipient listing.

Feature-by-Feature Disclosure

What We Do NOT Send to AI

We do not include your name, email address, account UUID, or any direct account identifiers in AI prompts. Only contextual health and tracking data you have entered — and that is relevant to the specific AI feature you are using — is included.

No Solely-Automated Decisions

AI responses in The Perfect Start are informational and educational only. No decision with legal or significant effect on you is made solely by automated means. You always retain decision authority. See Section 18.

Opting Out of AI Features

You can disable AI features at any time in Settings → AI Features.

All AI responses are educational and informational only. They are not medical advice. See our Medical Disclaimer.

Improving our knowledge base (secondary use)

To make the app faster and reduce the need for live AI calls, we store the questions you ask our AI features after automated PII and personal-health-data redaction, and a member of our team reviews them to expand our on-device knowledge base so future users get faster local answers. No user-identifying content is ever published in the knowledge base. Our lawful basis is our legitimate interest (Art. 6(1)(f) GDPR) in improving the safety and quality of the service — balanced against your rights through a legitimate-interests assessment — and, where the underlying question contains health context, your explicit consent (Art. 9(2)(a)) given when you use AI features. Redacted questions are reviewed and then deleted within 7 days of review, and in any case within a 90-day maximum retention period, after which they are deleted or fully anonymised. You can access or delete the questions associated with your account at any time (see "Your Rights").

Children's data and US consumer health-privacy

The Perfect Start handles information about infants as well as parents. We process children's data only to provide the service to you, the parent, and we do not knowingly allow children to use the app directly, consistent with the US Children's Online Privacy Protection Act (COPPA). Health-adjacent information you provide is processed for your benefit only — we do not sell or "share" it for targeted advertising — and we apply redaction before any AI processing. We treat this category consistently with the Washington My Health My Data Act, the California Confidentiality of Medical Information Act (CMIA) and CCPA/CPRA, and similar US state consumer-health-privacy laws. AI processing of any health-adjacent data is consent-gated, and you may disable AI features at any time.

9. Children's Data — COPPA

The Perfect Start is designed for adult parents (18 and older). Infants and children do not and cannot create accounts. All data about your baby is submitted by you — the adult parent — and is stored under your adult account. You are the consent giver for all data about your child.

How we treat baby data:

We do not knowingly collect personal information directly from children under 13. All baby and child information is entered by the adult parent. If you believe a child under 13 has somehow created an account independently, contact us immediately at support@thetrulyperfect.com and we will delete the account promptly.

GDPR Article 8 — Children's Consent to Information Society Services

GDPR Article 8 governs consent to information society services given directly by a child. That provision does not apply to The Perfect Start because babies and infants are not data subjects of this service — they do not create accounts, interact with the app, or provide consent in any form. All data about your child is submitted by you, the adult parent, in your capacity as the account holder and data controller for your child's information. The data subject of The Perfect Start is the adult parent, not the child. Baby data is processed under the adult parent's explicit consent (GDPR Art. 9(2)(a) and Art. 6(1)(a)), not under any mechanism involving child consent. This analysis is consistent with the guidance of EU supervisory authorities that parental-consent-based services — where the adult is the service account holder and the data about the child is submitted by the parent — fall outside the direct scope of Art. 8.

9a. Caregiver Access

The Perfect Start includes an optional Caregiver Session feature that lets you grant a temporary caregiver (e.g., a grandparent, babysitter, or nanny) limited, scoped access to your baby's care information via a time-limited link.

GDPR Recipient Disclosure (Art. 4(9))

When you create a caregiver guest link, the caregiver becomes a "recipient" of personal data within the meaning of GDPR Article 4(9). All caregiver access is governed by these Terms and our Privacy Policy. You remain the data controller for any baby or family data the caregiver views during their session.

What Caregivers Can See

What Caregivers Cannot See

Authorization and Consent

Caregiver access requires: (1) parent authorization — you create the link and a consent record is written to our database at the moment of link generation; and (2) caregiver acknowledgment — before viewing any data, the caregiver must complete a privacy acknowledgment consisting of five checkboxes confirming they understand the scope and limitations of their access. Both events are time-stamped.

Session Logging and Audit Trail

All caregiver sessions are logged in the caregiver_access_log table with a timestamp, session ID, and the scope of data accessed. You can view the full caregiver access history from Settings → Caregiver Access History at any time.

Right to Revoke

You may revoke any active caregiver link at any time from within the App. Revocation is immediate — the link becomes invalid and the caregiver's session is terminated. Revocation does not delete the session log entry, which is retained for your audit trail.

10. Data Retention

We retain personal data only as long as necessary for the purposes described in this policy. Specific retention periods by data type:

Retention by Database Table (Per-Category Disclosure)

The following table provides per-category retention periods for the primary data tables in our system, as required by GDPR Art. 5(1)(e) storage-limitation principle:

Data Category / Table Retention Period Lawful Basis (GDPR) Notes
consent_records 7 years (anonymized SHA-256 hash only) Legitimate interest (Art. 6(1)(f) — legal defense under Art. 17(3)(e)) GDPR Art. 17(3)(e) legal-claims exemption. Hash is irreversible and not linked back to account after deletion.
insurance_chats [retention period — provided on request] Contract (Art. 6(1)(b)) Insurance Strategy Advisor conversation history is retained for [retention period — provided on request]. Deleted immediately on account deletion.
lab_ocr (extracted text) Not retained server-side after extraction Consent (Art. 6(1)(a) + Art. 9(2)(a)) Document images sent for OCR are processed in-memory in our Edge Function and immediately discarded. Only the structured extracted values (lab result fields) are saved to your account.
feed_log, sleep_log, diaper_log, and other baby/health logs Active account life Consent (Art. 6(1)(a) + Art. 9(2)(a)) Retained while your account is active. Deleted immediately upon account deletion request.
PHQ-9 scores (Patient Health Questionnaire; legacy EPDS scores also retained where previously recorded) Retained until account deletion Explicit consent (Art. 9(2)(a)) Mental health screening scores are stored as part of your maternal recovery timeline. The app currently uses PHQ-9; scores recorded under the prior EPDS tool (now discontinued) remain visible, labeled accordingly. Deleted in full upon account deletion. Never shared with third parties.
ai_rate_limits Current month + prior month only Legitimate interest (Art. 6(1)(f) — service integrity) Rate-limit counters are stored for the current and immediately preceding calendar month, then automatically purged. Used only to enforce per-user AI query limits.
Account deletion grace period 30-day grace period, then full purge Legitimate interest (Art. 6(1)(f) — accidental-deletion recovery) After you request deletion, personal data remains in a soft-deleted state for 30 days (to allow accidental-deletion recovery), then is permanently purged. Anonymized consent_records hashes survive under the 7-year legal-defense exemption.
Vercel server / CDN access logs 30 days Legitimate interest (Art. 6(1)(f) — security) IP address, request URL, and user-agent retained by Vercel per their standard log-retention policy. No personal health data is present in access logs.
Crash / error logs 90 days Legitimate interest (Art. 6(1)(f) — debugging) Stack trace, function name, and error message only. No personal health data is included in error logs.
HealthKit readings (iOS-side cache) Active account life Explicit consent (Art. 9(2)(a)) HealthKit readings pulled into the app are stored in your Supabase account. iOS-side cache is managed by the Health app and subject to Apple's data policies. Deleted on account deletion.
Backup data 30 days rolling Legitimate interest (Art. 6(1)(f) — disaster recovery) Encrypted database backups retained on a 30-day rolling window. Single-region storage. Backup data is purged beyond the rolling window automatically.

After you delete your account, we will confirm deletion by email within 5 business days. You may also contact us to request confirmation that your data has been purged from all backup systems after 30 days.

An internal Record of Processing Activities is maintained per GDPR Art. 30 and is available to supervisory authorities upon request via the contact channel above.

10a. Audit & Compliance Records

To meet our security, legal, and compliance obligations under GDPR Article 30 and applicable US law, we maintain immutable audit logs of certain account-level and system-level events. These records are tied to your user ID while your account is active, and are not used for marketing, advertising, or behavioral profiling, and are never sold to third parties.

Categories of Audit Records We Keep

Retention of Audit Records

Audit records are retained for as long as your account is active. After account deletion, audit records are anonymized — your user ID is replaced with a one-way cryptographic hash — and retained for the legally required minimum period:

After the applicable retention period, anonymized audit records are permanently purged from our systems.

Your Rights Over Audit Records

Audit Table in the Retention Schedule Above

The per-category retention table in Section 10 documents the primary health-data tables. Audit log tables (personal_health_data_audit_log, caregiver_access_log, consent_records, and related compliance tables) are separately governed by this Section 10a and by GDPR retention requirements, which take precedence over any shorter period that would otherwise apply.

11. Security Measures

No method of transmission or storage is 100% secure. If you become aware of a security vulnerability or concern, please contact us immediately at support@thetrulyperfect.com.

12. Your Rights — GDPR (Articles 15–22)

If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights regarding your personal data. We will respond to all rights requests within 30 days (extendable to 90 days for complex requests, with notice).

To exercise any right, use the in-app tools (Settings → Export Data or Settings → Delete Account) or email support@thetrulyperfect.com. We may need to verify your identity before fulfilling a request.

13. California Residents — CCPA / CPRA

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights.

Rights Under CCPA / CPRA

California — Sensitive Personal Information (CPRA)

Some information we process — health and medical information, and mental-health information such as your PHQ-9 screening responses (and any legacy EPDS screening responses) — is "sensitive personal information" (SPI) under the CPRA (Cal. Civ. Code §1798.140(ae)). We use SPI only to provide and secure the features you request and not to infer characteristics about you. Because we limit SPI use to these permitted purposes the CPRA "right to limit" may not apply; nevertheless you may direct us to limit use of your SPI, disable AI features any time in Settings → AI Features, or email support@thetrulyperfect.com.

We do not "sell" or "share" (for cross-context behavioral advertising) your personal information or SPI (Cal. Civ. Code §1798.120). Your California rights: to know/access, delete, correct, opt out of sale/sharing, limit use of SPI, and non-discrimination for exercising them. To exercise, email support@thetrulyperfect.com or use Settings → Your Data; we respond within 45 days (extendable by 45 where permitted). You may use an authorized agent.

To exercise any California right, email support@thetrulyperfect.com or use the in-app tools in Settings.

14. Washington Residents — My Health My Data Act

Washington Consumer Health Data (My Health My Data Act)

Much of what you provide — feeding, sleep, growth, maternal-health, PHQ-9 (and any legacy EPDS), lab, and medication data — is "consumer health data" under the Washington My Health My Data Act (MHMDA, RCW 70.372). We are a direct-to-consumer service and not a HIPAA covered entity, so this data is not regulated by HIPAA; the MHMDA applies instead.

For MHMDA-specific requests, contact: support@thetrulyperfect.com.

15. International Data Transfers

The Perfect Start is operated in the United States. If you access the App from the European Union, European Economic Area, United Kingdom, or other regions with data protection laws, be aware that your data will be transferred to and processed in the United States and, for certain AI features, other countries.

We rely on Standard Contractual Clauses (SCCs) approved by the European Commission (pursuant to EU Commission Implementing Decision 2021/914) as the primary safeguard for EEA-to-third-country transfers. Each processor's transfer mechanism is listed in Section 5.

We do not rely on consent to transfer as the legal mechanism for international data transfers under GDPR. All transfers rely on SCCs or other adequacy mechanisms as noted in Section 5.

To obtain a copy of the applicable SCCs or for transfer-related questions, contact support@thetrulyperfect.com.

Our live-AI providers — Google LLC (Google Cloud Vertex AI) and Anthropic, PBC — process data in the United States. For data subjects in the EEA and UK, these transfers are made under the Standard Contractual Clauses (and, for the UK, the UK International Data Transfer Addendum) incorporated in each provider's Data Processing Addendum, and we maintain a transfer risk assessment for them. Before any such transfer we apply automated PII and personal-health-data redaction to minimise the personal data involved.

16. Breach Notification

In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we commit to:

If you discover or suspect a security incident involving your data, please notify us immediately at support@thetrulyperfect.com.

17. Data Protection Impact Assessment (DPIA)

We have conducted a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35. A DPIA is triggered by the nature of our processing, which includes:

Our DPIA identifies the risks associated with these processing activities and the technical and organizational measures we have implemented to mitigate them (including RLS, AES-256 encryption, TLS 1.3, prompt anonymization, deflection-first AI architecture, content moderation, and AI opt-out controls).

If you are an EU/EEA resident and wish to request a summary of the DPIA findings relevant to your data, contact us at support@thetrulyperfect.com.

18. Automated Processing and AI Decisions

The Perfect Start uses AI-generated content to provide personalized guidance, tips, and summaries. This section discloses our automated processing practices in compliance with GDPR Article 22.

19. Government and Legal Requests

We believe in protecting your data from government overreach. Our policy for handling government, law enforcement, and legal process requests is as follows:

20. Cookies and Web Tracking

The Perfect Start's native iOS app does not use cookies.

The Progressive Web App (PWA) at start.thetrulyperfect.com uses the following:

21. Lodging a Complaint

If you are not satisfied with how we handle your personal data or respond to your rights requests, you have the right to lodge a complaint with your local supervisory authority. Relevant authorities include:

Before lodging a formal complaint, we encourage you to contact us first at support@thetrulyperfect.com so we have the opportunity to address your concern directly.

22. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes — such as adding a new data category, a new AI processor, or changing your rights — we will:

For minor, non-material changes (such as clarifications, grammar corrections, or updated links), we will update the "Last updated" date only, without in-app or email notification.

All prior versions of this policy are available on request by emailing support@thetrulyperfect.com.

Your continued use of the App after the effective date of an updated policy constitutes your acknowledgment of the changes. If you do not agree with the updated policy, you may delete your account at any time.

23. Contact

Data Controller:
The Truly Perfect LLC
General support: support@thetrulyperfect.com

Use these addresses for any of the following:

We will respond to all privacy-related inquiries within 5 business days and to formal rights requests within 30 days.

© 2026 The Truly Perfect LLC. All rights reserved.  ·  The Perfect Start  ·  Developed by The Truly Perfect LLC  ·  Terms of Service  ·  All Legal Docs