New here? Read the plain-English summary first →
Privacy Policy
Plain-English Summary
- Who we are: The Truly Perfect LLC, a Texas limited liability company — the data controller for The Perfect Start. Contact: support@thetrulyperfect.com.
- We collect the baby and parent data you enter, your account credentials, and payment metadata.
- We do NOT sell your data. Ever. To anyone.
- We do NOT track you across other apps or websites. Zero third-party analytics or advertising SDKs.
- No advertising. No behavioral profiling. No data brokers.
- AI features use a deflection-first architecture — most responses are served client-side from our knowledge base without any third-party API call. When a live LLM call is needed, context is first redacted of personal data and then sent to Google Cloud Vertex AI — Gemini 2.5 Flash (primary), then Gemini 2.5 Pro, then Anthropic Claude (direct) (all US-hosted). A few real-time features (recall lookups, air-quality lookups) instead query official government data APIs directly with a minimal lookup term (e.g., a product name or your ZIP code) — see Section 8 and Section 5. You can opt out in Settings → AI Features.
- HushBaby cry detection is 100% on-device. Microphone audio never leaves your phone.
- HealthKit data is never used for advertising and never sold or shared with third parties for marketing.
- Baby data is treated with the same protection as adult health data; you (the parent) are the consent giver for all data about your child.
- You can export all your data or delete your account at any time from within the app.
- Read below for the full picture.
- Introduction and Data Controller
- Data We Collect
- How We Use Your Data
- Legal Basis for Processing (GDPR)
- Third-Party Processors
- Apple HealthKit
- HushBaby On-Device Processing
- AI and Machine Learning Features
- Children's Data (COPPA)
- Caregiver Access
- Data Retention
- Audit & Compliance Records
- Security Measures
- Your Rights — GDPR (Art. 15–22)
- California Residents — CCPA / CPRA
- Washington Residents — My Health My Data Act
- International Data Transfers
- Breach Notification
- Data Protection Impact Assessment
- Automated Processing and AI Decisions
- Government and Legal Requests
- Cookies and Web Tracking
- Lodging a Complaint
- Changes to This Policy
- Contact
1. Introduction and Data Controller
The Perfect Start is a postpartum and newborn tracking application for parents. The app is built with Capacitor and is available as an iOS app and as a Progressive Web App (PWA) at https://start.thetrulyperfect.com. This Privacy Policy is issued by The Truly Perfect LLC (Texas limited liability company), operator of The Perfect Start.
Data Controller: The Truly Perfect LLC
Email: support@thetrulyperfect.com (general support)
This Privacy Policy explains what personal data we collect, why we collect it, the legal basis on which we process it, who we share it with, how long we keep it, and the rights you have. This policy applies to all users of the App and website. By creating an account or using the App, you acknowledge that you have read this policy.
We take privacy seriously — the data you share with us is deeply personal, including information about your body, your recovery, your newborn, and your family. We have designed our data practices to minimise collection and to be transparent.
2. Data We Collect
A. Account and Authentication Data
- Email address and password hash (passwords are hashed by Supabase Auth — we never see plaintext passwords)
- Apple Sign In identity token (if you use "Sign in with Apple")
- Google OAuth token (web only, if you use "Sign in with Google")
B. Parent and Family Profile Data
- Parent name, partner name, family name
- Preferred language (English or Spanish), theme preference
- Bedtime preference, feeding type preference, commitment tier
- Birth method (vaginal, cesarean)
- Pediatrician name
- Maternal conditions you voluntarily report (e.g., preeclampsia history, gestational diabetes, postpartum anemia)
- Dietary profile (vegan, vegetarian, pescatarian, omnivore)
- Food allergies (fish, shellfish, gelatin, soy, dairy, eggs, tree nuts, peanuts)
- Health history flags you voluntarily enter (GDM history, PCOS, hypertension, MTHFR, Type 2 diabetes, hypothyroid, hyperthyroid)
C. Baby Data (COPPA Notice: see Section 9)
- Baby name, date of birth
- Feeding logs: type (breast, bottle, formula), ounces, side, timestamp
- Nap and night sleep logs
- Diaper logs: type (wet, dirty, mixed), color notes, timestamp
- Cry logs
- Developmental milestones
- Growth measurements: weight, length, head circumference
- Solids introduction log including reaction notes
- Pump log
- Vaccine records
- Baby photo avatars (if you upload one)
- Milestone celebration photos (if you upload them)
- Photo-to-Log classification photos (diaper, rash, or spit-up) — if you use this optional, consent-gated feature. Not stored by us; sent directly to Anthropic's API for classification and discarded server-side after the result is returned.
- Multiple babies supported (twins, siblings, etc.)
D. Maternal Recovery and Health Data (GDPR Art. 9 Special Category)
- Daily check-ins: mood, energy, pain, sleep, and bleeding scores
- PHQ-9 (Patient Health Questionnaire) depression screening scores. (The app previously used the Edinburgh Postnatal Depression Scale (EPDS); EPDS was discontinued and replaced by PHQ-9. Scores recorded under the prior EPDS tool remain visible on your recovery timeline, labeled as a discontinued screening.)
- Vital readings you enter: blood pressure, heart rate, body temperature, weight, SpO2, blood glucose
- Lab results you manually enter or scan (hemoglobin, TSH, ferritin, Vitamin D, B12, and others)
- Medications and supplements (Perfect Stack tracking)
- Appointment records
E. Apple HealthKit Data
If you grant HealthKit permission, the app reads and writes the following categories: body weight, blood pressure, heart rate, and body temperature. See Section 6 for full details.
F. AI Conversation History
- Insurance Strategy Advisor chat conversation turns and AI-generated memory summaries are stored in our database to maintain context across sessions.
- All other AI feature conversations (Home Insight, AI Companion, Mom Well-Woman, Lab Results) are not persisted on our servers beyond the current response session.
G. Insurance Data (Sensitive Financial)
- Insurance plan details: company name, plan name, deductible, deductible-met amount, out-of-pocket maximum and met amounts, HSA and FSA balances, in-network status, notes
- Medical bills: provider name, amount, date, payment status, notes
H. Payment Metadata
- Your plan tier, trial end date, subscription period end date, cancel-at-period-end flag
- Stripe customer ID (web users only). We do not store credit card numbers — Stripe handles all payment card data under PCI-DSS.
- RevenueCat associates your Supabase user UUID with your iOS in-app purchase record. No health data or personal profile data is sent to RevenueCat.
- Referral relationships and promo code redemption records
I. Device and Technical Data
- IP address (captured by Vercel edge servers and Supabase on each request)
- Device model, operating system version, and app version (from Apple device metadata)
- Push notification device token — Apple Push Notification Service (APNs) on iOS, or Firebase Cloud Messaging (FCM) on Android — and notification preferences (quiet hours, category-level filtering)
- Standard web server access logs (URL requested, user agent, response code)
J. Crash Logs and Error Telemetry
- Server-side Edge Function error logs: function name, error message, and timestamp. These do not contain user health data.
- Client-side errors and crashes may be captured by Sentry (Functional Software, Inc.), a third-party error-monitoring service, to help us diagnose and fix faults. Crash diagnostics are enabled by default for users outside the EU/UK and disabled by default for users in the EU/UK (region is inferred from your device's timezone). Before any error is transmitted, we apply automated redaction that removes personal and personal-health information (names, dates of birth, email and postal addresses, identifiers, and free-text content) from error messages, stack traces, request URLs, and diagnostic breadcrumbs. We do not attach identity information (no name, email, or account ID) to error events, and we do not use session recording or replay. See Section 5 for Sentry's role as a processor. We do not use any advertising or analytics SDK.
K. Miscellaneous App Data
- Partner link: when you create a partner link, we store both user UUIDs and a short-lived 6-character accept code that expires after 10 minutes.
- Send Love messages: plaintext messages you send to your linked partner — stored with Row Level Security so only you and your linked partner can read them. Not end-to-end encrypted.
- Caregiver session data: scoped, time-boxed access sessions for temporary caregivers — link-based, revocable by you at any time.
- Story Builder: baby name, character nicknames, story theme, tone, and length used to generate personalized children's stories.
- OCR scanning: base64-encoded lab/insurance document images sent for extraction; original images are not retained after processing.
- In-app feedback text you submit voluntarily.
3. How We Use Your Data
We use your data only to provide, personalize, and improve The Perfect Start. We do not use your data for advertising, behavioral profiling, or any purpose other than running the App for you.
- Account authentication: Email and password hash used by Supabase Auth to authenticate and maintain your session.
- Baby tracking: Feeding, sleep, diaper, cry, milestone, growth, solids, pump, and vaccine data are stored under your account and displayed on your dashboards and reports.
- Maternal recovery tracking: Check-ins, PHQ-9 scores (and any legacy EPDS scores from before the tool was discontinued), vitals, lab results, medications, and appointments are stored to show your personal recovery timeline and generate printable health summaries.
- AI-powered features: Context data is sent to AI providers as described in Section 8. Most KB-answerable queries are served client-side without any third-party API call (see Section 8 — Deflection-First Architecture).
- Baby medicine safety: Medication logs are checked at entry time against our safety database — forbidden medications are blocked, age-restricted medications generate warnings, and dose-interval reminders are issued. See Section 8.
- HushBaby cry detection: No data leaves your device. See Section 7.
- HealthKit sync: Weight, blood pressure, heart rate, and body temperature readings you pull from HealthKit are saved to your Supabase account as maternal recovery vitals.
- Push notifications: Your push token is used to send notifications you configure. The token is sent to a Supabase Edge Function which calls Apple APNs (iOS) or Google Firebase Cloud Messaging (Android) to deliver the notification.
- Partner Link and Send Love: Partner link codes route to your partner's account. Send Love messages are stored and delivered to your linked partner.
- Subscriptions and billing: Payment data is processed by Stripe (web) or RevenueCat (iOS). We use the resulting subscription status to control feature access.
- Email: Resend is used to send account-related (transactional) emails such as partner invitation links and password reset links, and — if your subscription lapses or you cancel — a limited series of win-back / re-engagement emails (promotional; see Section 4 and Section 5).
- Service reliability: Server logs and crash/error telemetry are used to maintain uptime, diagnose failures, and improve performance.
- Feedback: In-app feedback is used to improve the product. We read it internally; we do not share it with third parties.
4. Legal Basis for Processing (GDPR)
If you are located in the European Union or European Economic Area, the General Data Protection Regulation (GDPR) requires us to identify a legal basis for each category of processing. Health and recovery data constitutes "special-category" data under GDPR Article 9, requiring explicit consent as its legal basis.
- Account creation and authentication — Contractual necessity (Art. 6(1)(b)): processing is necessary to perform the service you have requested.
- Baby tracking data — Explicit consent (Art. 9(2)(a) and Art. 6(1)(a)): baby data is special-category data submitted by you as the parent consent-giver. You provide explicit consent when you create an account and when you actively enter baby data. You may withdraw consent at any time by deleting the data or your account.
- Maternal health and recovery data — Explicit consent (Art. 9(2)(a)): health, vitals, screening scores, and lab results are special-category data. Consent is given explicitly when you enter this data and can be withdrawn at any time.
- HealthKit data — Explicit consent (Art. 9(2)(a) and Art. 6(1)(a)): HealthKit access requires a separate, explicit iOS permission grant by you. You may revoke it at any time in iOS Settings.
- AI conversation data — Explicit consent (Art. 6(1)(a) and Art. 9(2)(a)): by using AI features, you consent to the relevant context being sent to our AI processors (when a live API call is made). You may opt out in Settings → AI Features.
- AI knowledge-base improvement — Legitimate interests (Art. 6(1)(f)): we store redacted versions of the questions you ask to expand our local knowledge base and improve service quality and safety; you may object at any time (see Your Rights). Where the underlying question contains health context, we additionally rely on your explicit consent (Art. 9(2)(a)) given when you use AI features.
- Subscription billing and payment processing — Contractual necessity (Art. 6(1)(b)): required to fulfill your subscription agreement.
- Transactional service emails — Legitimate interest (Art. 6(1)(f)): sending operational emails necessary for the App to function is proportionate to your expectation when creating an account.
- Server logs and error telemetry — Legitimate interest (Art. 6(1)(f)): we have a legitimate interest in maintaining service reliability and security. You have the right to object to this processing by contacting us.
- Consent records (GDPR Art. 17(3)(e)): We retain an anonymized, one-way SHA-256 hash of your consent record for 7 years for legal-defense purposes. This hash cannot be reversed to identify you and is not used for any other purpose. This retention falls under Art. 17(3)(e) — establishment, exercise, or defense of legal claims — and cannot be erased on request within this period.
- Win-back / re-engagement emails — Legitimate interest (Art. 6(1)(f)), subject to applicable e-marketing law: if you cancel or lapse, we may send a limited series of win-back emails (for example, a reactivation discount offer) to your registered email address. These are promotional in nature. Every such email includes an unsubscribe mechanism, and you can opt out at any time.
5. Third-Party Processors
We use the following third-party processors. For each, we name the entity, its jurisdiction, the data it receives, its purpose, and the transfer mechanism used for cross-border transfers from the EEA.
Supabase, Inc.
Jurisdiction: United States | Transfer mechanism: Standard Contractual Clauses (SCCs) in Supabase Data Processing Agreement
Purpose: Primary backend — PostgreSQL database, authentication, Edge Functions, and cloud storage.
Data received: All app data (account, profile, baby logs, maternal data, insurance data, messages, photos, story library).
Privacy policy: supabase.com/privacy
Stripe, Inc.
Jurisdiction: United States | Transfer mechanism: EU-U.S. Data Privacy Framework certification
Purpose: Web-only subscription checkout and billing portal.
Data received: Payment card information collected directly by Stripe. We receive only a Stripe customer ID and billing status. Your email may be shared with Stripe for billing communications.
Privacy policy: stripe.com/privacy
RevenueCat, Inc.
Jurisdiction: United States | Transfer mechanism: SCCs in RevenueCat Data Processing Agreement
Purpose: iOS in-app subscription management.
Data received: Your Supabase user UUID and Apple App Store purchase receipt. No health data or personal profile data.
Privacy policy: revenuecat.com/privacy
Anthropic, PBC (Claude)
Jurisdiction: United States | Transfer mechanism: Standard Contractual Clauses in the Anthropic Commercial Data Processing Addendum; UK International Data Transfer Addendum for UK users
Purpose: (1) Fallback AI provider for text-based AI features — used when Google Vertex AI returns low confidence or a query requires longer-context, multi-step reasoning; and (2) Photo-to-Log photo classification — when you use the diaper, rash, or spit-up photo-classification feature, your photo is sent directly to Anthropic's API for classification. Both uses are accessed directly via Anthropic's paid API (no third-party gateway).
Data received: For text AI features, the same redacted, contextual query data described in Section 8 (relevant health-log context, profile fragments, question text). For Photo-to-Log, the photo you choose to classify (diaper, rash, or spit-up). We do not include direct account identifiers (email, account ID) in AI prompts, and we apply automated PII and personal-health-data redaction before transmission of text-based AI context; photo classification is gated behind your explicit in-app AI-photo consent (Settings → Privacy) and is not sent unless you have granted that consent.
Data use: Processed under Anthropic's Commercial Terms and DPA on paid-API, no-training terms — your data is not used to train Anthropic's models. Text AI query data is retained only briefly for safety and abuse-prevention purposes. Photos sent for classification are not stored by us before or after the request — the app forwards the photo bytes to Anthropic's API and discards them server-side immediately after receiving the classification result.
Privacy policy: anthropic.com/privacy
Google LLC / Google Cloud — Vertex AI (Gemini)
Google provides Gemini large language models through Google Cloud Vertex AI — Gemini 2.5 Flash (primary), with Gemini 2.5 Pro as fallback, then Anthropic Claude (direct). This is our primary AI provider chain: when the app cannot answer your question locally and a live AI call is required, your redacted query context (see Section 8) is sent directly to Google Cloud Vertex AI for processing in the United States (us-central1 region). Google acts as our processor under the Google Cloud Data Processing Addendum, on paid-API terms under which your data is not used to train Google's models and is not retained beyond what is necessary to provide the service.
Jurisdiction: United States (us-central1) | Transfer mechanism: Standard Contractual Clauses incorporated in the Google Cloud Data Processing Addendum (which covers Vertex AI); UK International Data Transfer Addendum for UK users
Privacy policy: policies.google.com/privacy | Google Cloud DPA
OpenAI, Inc.
Jurisdiction: United States | Transfer mechanism: SCCs in OpenAI Data Processing Addendum
Purpose: Story Builder premium features only — HD text-to-speech narration (tts-1-hd model) and cover image generation (DALL-E 3).
Data received: Generated story text (for TTS); a safe, child-appropriate image prompt derived from story theme and character description (for DALL-E 3). OpenAI does not retain request data beyond the API call per their API data policy.
Privacy policy: openai.com/policies/privacy-policy
Vercel, Inc.
Jurisdiction: United States | Transfer mechanism: SCCs in Vercel Data Processing Addendum
Purpose: Web hosting and serverless API functions, including web-side subscription checkout.
Data received: Standard server access logs: IP address, request URL, user agent, response code.
Privacy policy: vercel.com/legal/privacy-policy
Apple, Inc. (Sign in with Apple, In-App Purchase, HealthKit, APNs)
Jurisdiction: United States | Transfer mechanism: EU-U.S. Data Privacy Framework certification
Purpose: Authentication (Sign in with Apple), iOS in-app purchase processing (IAP), on-device health data access (HealthKit), and push notification delivery (APNs).
Data received: Apple manages your Apple ID identity for Sign in with Apple; Apple processes IAP transactions directly; HealthKit data remains on your device unless you explicitly pull it into the app; APNs device token and notification payload.
Privacy policy: apple.com/legal/privacy
Resend, Inc.
Jurisdiction: United States | Transfer mechanism: SCCs in Resend Data Processing Agreement
Purpose: Email delivery — both transactional account-related emails (e.g., partner invitation links, password reset links, account alerts) and, where you have an eligible account, win-back / re-engagement emails (see Section 3 and Section 4 — these are promotional in nature).
Data received: Recipient email address and email content (e.g., your partner's email address when you send a partner invite; your first name and a reactivation offer for a win-back email).
Privacy policy: resend.com/legal/privacy-policy
Google LLC — Firebase Cloud Messaging (FCM)
Jurisdiction: United States | Transfer mechanism: Standard Contractual Clauses incorporated in the Google Cloud / Firebase Data Processing Addendum; UK International Data Transfer Addendum for UK users
Purpose: Push-notification delivery on Android devices (the iOS equivalent is Apple APNs, listed above). FCM is the transport that delivers the notifications you configure (e.g., feeding and plan reminders) to your Android device.
Data received: Your FCM device token and the notification payload. Notification text may include your baby's first name (e.g., "Today's plan for [baby] is ready"). No health logs, lab values, or account email are sent to FCM.
Privacy policy: firebase.google.com/support/privacy
Functional Software, Inc. (Sentry)
Jurisdiction: United States | Transfer mechanism: Standard Contractual Clauses (+ UK International Data Transfer Addendum for UK users) incorporated in Sentry's Data Processing Addendum
Purpose: Client-side application crash and error monitoring — capturing unhandled errors so we can diagnose and fix faults in the app. (Performance/timing tracing is not enabled.) Crash diagnostics are enabled by default for users outside the EU/UK and disabled by default for EU/UK users (region is inferred from your device's timezone; when it cannot be determined, diagnostics default to off).
Data received: Diagnostic error events — error type and message, stack trace, the app release version and environment, and browser/OS/device type. Before transmission we apply automated redaction that strips personal and personal-health data (names, dates of birth, email and postal addresses, identifiers, and free-text content) from error messages, stack-trace frames, request URLs, and diagnostic breadcrumbs. We do not attach identity information (no name, email, or account ID) to error events, the SDK is not configured to collect default personal data (such as IP address or request headers), and we do not use session recording or replay.
Privacy policy: sentry.io/privacy | Sentry DPA
U.S. Government Data APIs (recall and air-quality lookups)
For the real-time lookup features described in Section 8, a minimal lookup term is sent directly to the following official U.S. government services. These are public-sector data sources, not commercial processors; no DPA/SCC mechanism applies to a U.S. government API.
U.S. FDA — Food Enforcement API (api.fda.gov): receives the product/food term you ask about, to look up matching recalls.
U.S. Consumer Product Safety Commission (CPSC) — SaferProducts (www.saferproducts.gov): receives the product term you ask about, to look up matching recalls.
U.S. EPA — AirNow API (www.airnowapi.org): receives your home ZIP code, to retrieve the current air-quality index for your area.
We do not send your name, account identifier, email, or health logs to these services.
We do not use any third-party analytics services (no Mixpanel, Amplitude, Segment, Firebase Analytics, or similar). We do not use any advertising networks or tracking pixels.
6. Apple HealthKit
If you grant permission, The Perfect Start reads and writes the following HealthKit data categories on iOS: body weight, blood pressure, heart rate, and body temperature.
When you tap "Pull from HealthKit" for any of these values, the reading is transferred from the HealthKit store on your device into The Perfect Start and saved to your Supabase account as part of your maternal recovery vitals — meaning it leaves your device and is stored on our servers.
Similarly, when you enter a vital in the app and we write it to HealthKit, the data exists both in our Supabase database and in your iOS Health app.
HealthKit data is:
- Never used for advertising or marketing purposes
- Never sold to any third party
- Never shared with third parties for their independent marketing purposes
- Not sent to any AI/LLM model unless you explicitly include it in a question to an AI feature
- Shared only with Supabase (our database) and with AI processors only if you explicitly direct it in a query
You can revoke HealthKit permission at any time in iOS Settings → Privacy & Security → Health → The Perfect Start. Revoking permission does not delete readings already saved to your Supabase account; you can delete those via Settings → Delete Account or by contacting us.
7. HushBaby — On-Device Cry Detection
HushBaby is The Perfect Start's cry-detection feature. Here is exactly how it works:
- When you enable "Active Listening," the app requests microphone permission and opens a microphone stream.
- Audio is processed entirely on your device using the Web Audio API's
AnalyserNode. The algorithm analyzes frequency-band ratios in the 300–2000 Hz range to distinguish cry patterns. - No audio is ever recorded. No audio is ever uploaded. No audio ever leaves your device.
- There is no cloud call, no machine-learning model download, and no third-party service involved in cry detection.
- When you toggle off Active Listening, or when the app goes to the background, the microphone stream is fully stopped and released.
The only data that leaves the device from HushBaby is the event log entry (time, duration, type) written to your Supabase account when you confirm a cry event — the same as any other manual log entry.
7a. Location Data — Environmental Check
The Environmental Check feature (Superfund sites and water-quality alerts) may use your location. Here is exactly how it works:
- How location is obtained: You choose one of two methods: (a) you type a 5-digit US ZIP code, or (b) you press an explicit "Use my current location" button which calls the browser geolocation API (
navigator.geolocation.getCurrentPositionwithenableHighAccuracy: false). The OS permission prompt is shown at that moment — never at app launch. - Where it goes: Your coordinates or ZIP are used to search a bundled on-device dataset (EPA Superfund sites, water-quality violations). No location data is sent to any external API, EPA server, or third party. All lookups run entirely on your device.
- GPS precision: We request coarse location only (
enableHighAccuracy: false), typically accurate to 100–300 metres. This is sufficient for a 25-mile radius search. - Server storage: Your GPS coordinates are never sent to our servers. Your ZIP code is recorded in our internal analytics table (Supabase) as part of a usage signal, linked to your account, to help us improve the feature. It is not shared with any third party. Retention follows our standard 24-month signal retention period (Section 10).
- Your control: The feature is gated behind a "Location" toggle in Settings → Privacy → Location. When the toggle is off, the Environmental Check screen is hidden entirely. You can clear your saved ZIP or GPS at any time using the "Change location" link inside the feature.
8. AI and Machine Learning Features
The Perfect Start uses AI to deliver personalized guidance and summaries. This section discloses which features use AI, exactly what data is sent, which AI provider processes it, whether conversations are stored, and how to opt out.
Deflection-First Architecture
Our AI system uses a deflection-first design: before making any third-party API call, the app checks a curated, on-device knowledge base (KB) of vetted content covering common newborn care, postpartum recovery, and feeding questions. If a KB hit with sufficient confidence is found, the answer is served entirely client-side — no data leaves your device and no API call is made. Only questions that cannot be confidently answered from the KB are escalated to a live API call to our LLM providers. This minimizes data exposure and reduces latency.
Source Citation Transparency
Every AI response — whether served from the KB or generated by a live API call — cites at least one verified source. Sources include recognized authorities such as the American Academy of Pediatrics (AAP), Centers for Disease Control and Prevention (CDC), World Health Organization (WHO), and National Institutes of Health (NIH). Citations appear inline in the AI response so you can verify the underlying guidance.
AI Rate Limits
To protect service availability and prevent abuse, AI features are subject to the following rate limits: 20 AI questions per day for standard use. Users receive one burst day per calendar month during which the limit is raised to 50 questions. Deflection-first KB hits (served client-side) do not count toward your daily limit. Rate limit state is stored locally on your device and reset at midnight in your local time zone.
Content Moderation Layer
All user inputs to AI features pass through a content moderation layer before any API call is made. This layer screens for profanity, hate speech, and harm-intent patterns. Inputs containing language indicating a mental health crisis, suicidal ideation, or immediate physical danger are intercepted and routed to safety resources — including the 988 Suicide and Crisis Lifeline (call or text 988 in the US) and the Postpartum Support International (PSI) helpline (1-800-944-4773) — rather than to an AI model. This routing happens automatically and does not require you to ask for help.
Baby Medicine Safety Database
The medication logging feature includes a runtime safety database that performs checks at the time you log a medication for your baby. Specifically:
- Forbidden medications are blocked: Medications that are contraindicated for infants (e.g., aspirin, codeine) cannot be logged; the app blocks the entry and explains why.
- Age-restricted medications generate warnings: Medications appropriate only above a certain age trigger a visible warning that is confirmed before logging.
- Dose-interval reminders: If you attempt to log the same medication sooner than the recommended dosing interval, the app notifies you of the minimum wait time. This check is performed locally on your device using the logged timestamp — no server call is made.
This safety database is included in the app bundle and updated with app releases. It is not a substitute for your pediatrician's guidance; always consult your healthcare provider for medication decisions.
AI Providers
Local-first: most questions are answered on your device from our built-in knowledge base, with no data sent to any third-party AI. When a question cannot be answered locally and a live AI call is required, we first apply automated PII and personal-health-data redaction (names, dates of birth, phone numbers, email addresses, street addresses, ZIP codes, government IDs, and payment-card numbers) to minimise the personal data transmitted.
Primary AI provider (live API): Google Cloud Vertex AI — Gemini 2.5 Flash (primary), with Gemini 2.5 Pro as fallback, then Anthropic Claude (direct) (Google LLC / Anthropic, PBC, processed in the United States, us-central1). Both operate on paid-API, no-training terms — your data is not used to train their models. Story Builder narration and cover images use OpenAI directly (US) for premium features only. We do not route LLM prompts through any third-party AI gateway or routing layer. Separately, the Photo-to-Log photo-classification feature (diaper, rash, spit-up) sends your photo directly to Anthropic's API for classification — see "Feature-by-Feature Disclosure" below and the Anthropic, PBC entry in Section 5.
Real-Time Government Data Lookups
A small number of features answer your question by querying an official government data API directly, rather than by sending your question to an LLM. These lookups happen on a fast path before the LLM redaction step described above, so the redaction applied to LLM prompts does not apply to them; instead, only the minimal lookup term needed for the query is sent. Specifically:
- Product / food recall checks: the product or food term you ask about is sent to the U.S. FDA Food Enforcement API (api.fda.gov) and the U.S. Consumer Product Safety Commission (CPSC) SaferProducts service (www.saferproducts.gov) to look up matching recalls.
- Air-quality checks: your home ZIP code is sent to the U.S. EPA AirNow API (www.airnowapi.org) to retrieve the current air-quality index for your area.
These are U.S. government services. We do not send your name, account identifier, email, or health logs to them — only the lookup term (a product name, or your ZIP code) required to perform the query. See Section 5 for the recipient listing.
Feature-by-Feature Disclosure
- Home AI Insight: Sends recent feeding, sleep, diaper, and mood aggregates plus baby age and date of birth (when a live call is made). Not stored on our servers beyond the current session.
- AI Companion (general chat): Sends your question plus relevant profile context (when a live call is made). Not stored.
- Insurance Strategy Advisor: Sends your conversation turns plus insurance profile data (plan details, bill amounts). Routes to our live AI providers (Google Vertex AI primary, Anthropic Claude fallback). Conversation history IS stored in our database so the AI maintains context across sessions. An AI-generated memory summary is also stored. Retained for [retention period — provided on request]. You may request earlier deletion by contacting us.
- Mom Well-Woman guidance: Sends your maternal health profile and question (when a live call is made). Not stored.
- Lab Results commentary: Sends your lab values (when a live call is made). Not stored.
- Milestone summaries: Sends your baby's age and tracked milestones (when a live call is made). Not stored.
- Story Builder — text generation: Baby name, character nicknames, story theme, length, and tone are sent to Google Cloud Vertex AI (Gemini, default) and Anthropic Claude (premium) to generate a personalized children's story. Not stored beyond the current generation request. If you save the story, the story text is stored in your Supabase library.
- Story Builder — HD narration (premium): Generated story text is sent directly to OpenAI (tts-1-hd model) for audio narration. Audio is returned to the user and cached client-side. Not persistently stored on our servers.
- Story Builder — cover image (premium): A safe, age-appropriate image prompt (story theme and character description, not story text) is sent directly to OpenAI (DALL-E 3). If saved, the image is stored in your Supabase library. Not retained by OpenAI beyond the API request per their data policy.
- OCR document scanning: Sends a base64-encoded lab or insurance document image to a Supabase Edge Function, which forwards it to Google Cloud Vertex AI (Gemini vision) for text extraction. Image not retained after processing. Extracted values saved to your account.
- Photo-to-Log photo classification: If you use the diaper, rash, or spit-up photo-classification feature, your photo is sent directly to Anthropic's API (Claude, vision) to classify its contents. This feature is consent-gated — it will not send a photo unless you have granted AI-photo consent in Settings → Privacy. The photo is not stored by us before or after the request; it is forwarded to Anthropic for classification and discarded server-side immediately after the result is returned.
What We Do NOT Send to AI
We do not include your name, email address, account UUID, or any direct account identifiers in AI prompts. Only contextual health and tracking data you have entered — and that is relevant to the specific AI feature you are using — is included.
No Solely-Automated Decisions
AI responses in The Perfect Start are informational and educational only. No decision with legal or significant effect on you is made solely by automated means. You always retain decision authority. See Section 18.
Opting Out of AI Features
You can disable AI features at any time in Settings → AI Features.
All AI responses are educational and informational only. They are not medical advice. See our Medical Disclaimer.
Improving our knowledge base (secondary use)
To make the app faster and reduce the need for live AI calls, we store the questions you ask our AI features after automated PII and personal-health-data redaction, and a member of our team reviews them to expand our on-device knowledge base so future users get faster local answers. No user-identifying content is ever published in the knowledge base. Our lawful basis is our legitimate interest (Art. 6(1)(f) GDPR) in improving the safety and quality of the service — balanced against your rights through a legitimate-interests assessment — and, where the underlying question contains health context, your explicit consent (Art. 9(2)(a)) given when you use AI features. Redacted questions are reviewed and then deleted within 7 days of review, and in any case within a 90-day maximum retention period, after which they are deleted or fully anonymised. You can access or delete the questions associated with your account at any time (see "Your Rights").
Children's data and US consumer health-privacy
The Perfect Start handles information about infants as well as parents. We process children's data only to provide the service to you, the parent, and we do not knowingly allow children to use the app directly, consistent with the US Children's Online Privacy Protection Act (COPPA). Health-adjacent information you provide is processed for your benefit only — we do not sell or "share" it for targeted advertising — and we apply redaction before any AI processing. We treat this category consistently with the Washington My Health My Data Act, the California Confidentiality of Medical Information Act (CMIA) and CCPA/CPRA, and similar US state consumer-health-privacy laws. AI processing of any health-adjacent data is consent-gated, and you may disable AI features at any time.
9. Children's Data — COPPA
The Perfect Start is designed for adult parents (18 and older). Infants and children do not and cannot create accounts. All data about your baby is submitted by you — the adult parent — and is stored under your adult account. You are the consent giver for all data about your child.
How we treat baby data:
- Baby data (name, date of birth, feeding logs, diaper logs, sleep logs, milestones, growth measurements, photos) is treated with the same level of protection as adult health data.
- Baby data is never used for advertising, behavioral profiling, or shared with third parties for their independent purposes.
- Baby data is stored under your account and subject to Row Level Security — only your authenticated session (and your linked partner) can access it.
- You may delete all baby data at any time from within the app (Settings → Delete Account), or by contacting us at support@thetrulyperfect.com.
- If two parents share one account, both parents have access to the same baby data record. Both parents share responsibility for data entered under the account.
We do not knowingly collect personal information directly from children under 13. All baby and child information is entered by the adult parent. If you believe a child under 13 has somehow created an account independently, contact us immediately at support@thetrulyperfect.com and we will delete the account promptly.
GDPR Article 8 — Children's Consent to Information Society Services
GDPR Article 8 governs consent to information society services given directly by a child. That provision does not apply to The Perfect Start because babies and infants are not data subjects of this service — they do not create accounts, interact with the app, or provide consent in any form. All data about your child is submitted by you, the adult parent, in your capacity as the account holder and data controller for your child's information. The data subject of The Perfect Start is the adult parent, not the child. Baby data is processed under the adult parent's explicit consent (GDPR Art. 9(2)(a) and Art. 6(1)(a)), not under any mechanism involving child consent. This analysis is consistent with the guidance of EU supervisory authorities that parental-consent-based services — where the adult is the service account holder and the data about the child is submitted by the parent — fall outside the direct scope of Art. 8.
9a. Caregiver Access
The Perfect Start includes an optional Caregiver Session feature that lets you grant a temporary caregiver (e.g., a grandparent, babysitter, or nanny) limited, scoped access to your baby's care information via a time-limited link.
GDPR Recipient Disclosure (Art. 4(9))
When you create a caregiver guest link, the caregiver becomes a "recipient" of personal data within the meaning of GDPR Article 4(9). All caregiver access is governed by these Terms and our Privacy Policy. You remain the data controller for any baby or family data the caregiver views during their session.
What Caregivers Can See
- Feed logs (type, amount, timestamp)
- Sleep logs (nap and night sleep events)
- Diaper logs (type, color notes, timestamp)
- Developmental milestones
- Basic baby info: name, age, weight
What Caregivers Cannot See
- PHQ-9 (Patient Health Questionnaire) scores, any legacy EPDS scores, and any other mental health data
- Parent lab results and maternal health records
- AI chat history (Insurance Advisor, AI Companion, Mom Well-Woman, or any other AI conversation)
- Payment information, subscription tier, or billing records
- Mom's personal medical data (vitals, medications, appointments)
- Account settings, linked partner information, or promo code history
Authorization and Consent
Caregiver access requires: (1) parent authorization — you create the link and a consent record is written to our database at the moment of link generation; and (2) caregiver acknowledgment — before viewing any data, the caregiver must complete a privacy acknowledgment consisting of five checkboxes confirming they understand the scope and limitations of their access. Both events are time-stamped.
Session Logging and Audit Trail
All caregiver sessions are logged in the caregiver_access_log table with a timestamp, session ID, and the scope of data accessed. You can view the full caregiver access history from Settings → Caregiver Access History at any time.
Right to Revoke
You may revoke any active caregiver link at any time from within the App. Revocation is immediate — the link becomes invalid and the caregiver's session is terminated. Revocation does not delete the session log entry, which is retained for your audit trail.
10. Data Retention
We retain personal data only as long as necessary for the purposes described in this policy. Specific retention periods by data type:
- Account data (email, name, authentication credentials): Retained for as long as your account is active. Upon account deletion, deleted immediately from our live database; purged from Supabase point-in-time-recovery backups within 30 days.
- Health logs and baby tracking data: Retained for as long as your account is active. Deleted immediately upon account deletion.
- AI conversation history (Insurance Advisor): Retained for [retention period — provided on request]. You may request earlier deletion by contacting us.
- Server access logs (Vercel and Supabase): 90 days, then automatically purged per provider defaults.
- Crash logs and error telemetry: 180 days, then purged.
- Payment records (Stripe / RevenueCat): 7 years to comply with tax and accounting legal obligations. Payment records cannot be deleted on request within this period due to legal requirements.
- Consent records (anonymized SHA-256 hash — GDPR Art. 17(3)(e)): 7 years for legal-defense purposes. The hash cannot be reversed and is not used for any other purpose. This retention period cannot be shortened on request as it falls under the Art. 17(3)(e) legal claims exemption.
- Database backups: Supabase maintains point-in-time-recovery backups for up to 30 days after deletion of your data. These exist for disaster recovery and expire automatically.
- Partner link accept codes: Expire after 10 minutes.
- OCR client-side document hash cache: 7 days locally on your device to avoid re-scanning.
- AI provider retention: When a live AI call is made, redacted query context processed by Google Cloud Vertex AI — Gemini 2.5 Flash (primary), with Gemini 2.5 Pro as fallback, then Anthropic Claude (direct) — is handled under those providers' paid-API data policies. Both operate under no-training terms — your data is not used to train their models — and retain API request data only for a limited period for safety and abuse-prevention purposes before deletion. We do not route any data through third-party AI gateways.
Retention by Database Table (Per-Category Disclosure)
The following table provides per-category retention periods for the primary data tables in our system, as required by GDPR Art. 5(1)(e) storage-limitation principle:
| Data Category / Table | Retention Period | Lawful Basis (GDPR) | Notes |
|---|---|---|---|
consent_records |
7 years (anonymized SHA-256 hash only) | Legitimate interest (Art. 6(1)(f) — legal defense under Art. 17(3)(e)) | GDPR Art. 17(3)(e) legal-claims exemption. Hash is irreversible and not linked back to account after deletion. |
insurance_chats |
[retention period — provided on request] | Contract (Art. 6(1)(b)) | Insurance Strategy Advisor conversation history is retained for [retention period — provided on request]. Deleted immediately on account deletion. |
lab_ocr (extracted text) |
Not retained server-side after extraction | Consent (Art. 6(1)(a) + Art. 9(2)(a)) | Document images sent for OCR are processed in-memory in our Edge Function and immediately discarded. Only the structured extracted values (lab result fields) are saved to your account. |
feed_log, sleep_log, diaper_log, and other baby/health logs |
Active account life | Consent (Art. 6(1)(a) + Art. 9(2)(a)) | Retained while your account is active. Deleted immediately upon account deletion request. |
| PHQ-9 scores (Patient Health Questionnaire; legacy EPDS scores also retained where previously recorded) | Retained until account deletion | Explicit consent (Art. 9(2)(a)) | Mental health screening scores are stored as part of your maternal recovery timeline. The app currently uses PHQ-9; scores recorded under the prior EPDS tool (now discontinued) remain visible, labeled accordingly. Deleted in full upon account deletion. Never shared with third parties. |
ai_rate_limits |
Current month + prior month only | Legitimate interest (Art. 6(1)(f) — service integrity) | Rate-limit counters are stored for the current and immediately preceding calendar month, then automatically purged. Used only to enforce per-user AI query limits. |
| Account deletion grace period | 30-day grace period, then full purge | Legitimate interest (Art. 6(1)(f) — accidental-deletion recovery) | After you request deletion, personal data remains in a soft-deleted state for 30 days (to allow accidental-deletion recovery), then is permanently purged. Anonymized consent_records hashes survive under the 7-year legal-defense exemption. |
| Vercel server / CDN access logs | 30 days | Legitimate interest (Art. 6(1)(f) — security) | IP address, request URL, and user-agent retained by Vercel per their standard log-retention policy. No personal health data is present in access logs. |
| Crash / error logs | 90 days | Legitimate interest (Art. 6(1)(f) — debugging) | Stack trace, function name, and error message only. No personal health data is included in error logs. |
| HealthKit readings (iOS-side cache) | Active account life | Explicit consent (Art. 9(2)(a)) | HealthKit readings pulled into the app are stored in your Supabase account. iOS-side cache is managed by the Health app and subject to Apple's data policies. Deleted on account deletion. |
| Backup data | 30 days rolling | Legitimate interest (Art. 6(1)(f) — disaster recovery) | Encrypted database backups retained on a 30-day rolling window. Single-region storage. Backup data is purged beyond the rolling window automatically. |
After you delete your account, we will confirm deletion by email within 5 business days. You may also contact us to request confirmation that your data has been purged from all backup systems after 30 days.
An internal Record of Processing Activities is maintained per GDPR Art. 30 and is available to supervisory authorities upon request via the contact channel above.
10a. Audit & Compliance Records
To meet our security, legal, and compliance obligations under GDPR Article 30 and applicable US law, we maintain immutable audit logs of certain account-level and system-level events. These records are tied to your user ID while your account is active, and are not used for marketing, advertising, or behavioral profiling, and are never sold to third parties.
Categories of Audit Records We Keep
- Account deletions: Timestamp of deletion request and confirmation.
- Baby record deletions: Deletion timestamp and an aggregate count of records deleted.
- Caregiver access grants and revocations: Timestamp, session ID, and scope of access (see
caregiver_access_logtable disclosed above). - Data export requests (GDPR Art. 15 right of access): Timestamp and format of any export you initiate from Settings → Export Data.
- Vaccine record changes: Addition, update, or deletion of a vaccine record — timestamp and record identifier.
- Medication entries: Addition of a baby medication log entry — timestamp, medication name, and safety-check result.
- Safety alert dismissals: When you dismiss a safety alert (e.g., a medication dose-interval warning), that dismissal is logged — timestamp and alert type.
- Pediatrician summary exports: When you export or share a pediatrician summary report — timestamp and report type.
- Baby profile field changes: Changes to baby name, date of birth, or sex — old and new values and timestamp.
- Partner / co-parent additions and removals: Timestamp and the anonymized partner user ID when a partner link is created or dissolved.
- Emergency contact changes: Additions, updates, or removals of emergency contact information — timestamp.
- Legal document views: Each time you open this Privacy Policy, our Terms of Service, our Medical Disclaimer, or any other legal document within the App, we record the document name, document version, and timestamp. This record constitutes the Art. 30 GDPR records-of-processing entry for consent and awareness of the legal terms governing your use.
- Consent acceptances: Recorded in the
consent_recordstable as described in Section 4 (GDPR lawful basis). Includes document version, acceptance timestamp, and a one-way SHA-256 hash of your consent event. - Personal-health-data access events (Art. 9): Access events involving personal health data are logged as part of our audit controls under our security program (GDPR Art. 32).
- AI educational content displays: Each time AI-generated educational content (tips, daily insights, rationale cards) is shown to you, we record the surface (e.g., home screen, AI Assistant), content category, and whether the "educational only — not medical advice" disclaimer was visible. This supports our security program (GDPR Art. 32) and our medical-disclaimer obligations.
- AI disclaimer acknowledgments: When you acknowledge the "AI is educational only, not medical advice" disclosure — at onboarding or first AI use — we record the exact text of the disclaimer shown, its version, and the timestamp of acknowledgment.
- Medication safety override dismissals: If you are shown a medication safety warning (e.g., age-unsafe dosage, potential interaction) and choose to proceed, that dismissal is logged — warning category, medication name, and timestamp. Full warning text and any override note are included only in category-level summary; actual clinical content is not stored.
- Granular consent toggle changes: Each time you flip a privacy or consent toggle in Settings → Privacy or during onboarding, we record which toggle changed, its previous and new value, and the context (onboarding vs. settings). This provides the per-toggle revocation record required by GDPR Art. 7(3) and complements the existing
consent_recordstable. - Authentication events: Login, logout, password reset requests, and new-device sessions are logged with timestamp and device/platform information. IP address is captured best-effort (may be null on native mobile). This supports our security program (GDPR Art. 32) and security monitoring.
- Subscription lifecycle events: Checkout initiation, subscription activation, renewal, cancellation, refund, and grace-period events are logged — subscription plan, Stripe customer ID, and timestamp. Payment card data is never included. This record supports financial dispute resolution and regulatory audit.
- Sensitive maternal record changes: Additions, edits, removals, or sealing of sensitive records in the Maternal Recovery section (PPD/PHQ-9 high-risk flags — and legacy EPDS high-risk flags, where applicable — professional referral events, medical emergency acknowledgments) are logged — category and action only. Actual PHQ-9 or EPDS answers, clinical notes, or personal crisis content are never stored in this log; only the event category and timestamp are recorded.
Retention of Audit Records
Audit records are retained for as long as your account is active. After account deletion, audit records are anonymized — your user ID is replaced with a one-way cryptographic hash — and retained for the legally required minimum period:
- Personal-health-data access audit logs: [retention period — provided on request], for security and accountability purposes (Art. 5(2)).
- GDPR Art. 30 records of processing: Retained for the duration of processing activity plus a reasonable period thereafter for regulatory inspection, per supervisory authority guidance.
- All other audit records: 7 years, consistent with legal-claims defense periods, unless a shorter period is required by applicable law.
After the applicable retention period, anonymized audit records are permanently purged from our systems.
Your Rights Over Audit Records
- Right of access: You may request a copy of your audit log at any time via Settings → Privacy → Request My Audit Log, or by emailing support@thetrulyperfect.com. This extends the Deletion History view already available in the App to cover all audit categories listed above.
- Right to be forgotten: When you delete your account, audit records are anonymized (user ID replaced with a hash) but retained for the legal minimum period described above. Full deletion of audit records — where no legal hold exists — may be requested in writing to support@thetrulyperfect.com. We will respond within 30 days with confirmation of what, if anything, can be deleted immediately and what is subject to a legal hold.
The per-category retention table in Section 10 documents the primary health-data tables. Audit log tables (personal_health_data_audit_log, caregiver_access_log, consent_records, and related compliance tables) are separately governed by this Section 10a and by GDPR retention requirements, which take precedence over any shorter period that would otherwise apply.
11. Security Measures
- Encryption in transit: All network communication uses HTTPS with TLS 1.3.
- Encryption at rest: All data stored in Supabase is encrypted at rest using AES-256.
- Row Level Security (RLS): Every table in our database has Row Level Security enabled. Your data can only be accessed by your authenticated session — no other user can read it.
- Password security: Passwords are hashed by Supabase Auth using bcrypt. We never have access to your plaintext password.
- Multi-factor authentication (MFA): MFA is available for your account via Supabase Auth. We recommend enabling it in Settings.
- Rate limiting: AI endpoints and authentication endpoints are rate-limited to prevent abuse.
- CORS: Cross-Origin Resource Sharing is restricted to our exact app domains.
- Security headers: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Content-Security-Policy, and Permissions-Policy headers are set on all web responses.
- No third-party analytics or trackers: We have no analytics SDKs, no tracking pixels, and no advertising networks in the App.
- Regular security reviews: We conduct periodic internal security reviews of our Supabase RLS policies, Edge Function permissions, and API access controls.
No method of transmission or storage is 100% secure. If you become aware of a security vulnerability or concern, please contact us immediately at support@thetrulyperfect.com.
12. Your Rights — GDPR (Articles 15–22)
If you are located in the European Union, European Economic Area, or United Kingdom, you have the following rights regarding your personal data. We will respond to all rights requests within 30 days (extendable to 90 days for complex requests, with notice).
- Right of access (Art. 15): Request a copy of all personal data we hold about you, including the categories, purposes, and recipients. Exercise via Settings → Export Data (JSON + CSV export) or email us.
- Right to rectification (Art. 16): Update or correct inaccurate data — most data can be edited directly in the app. Contact us for data you cannot edit directly.
- Right to erasure — "right to be forgotten" (Art. 17): Delete your account and all associated data via Settings → Delete Account, or by emailing us. Payment records are subject to a 7-year legal retention obligation. Anonymized consent hashes are retained for 7 years under Art. 17(3)(e). Neither can be erased within those periods.
- Right to restriction of processing (Art. 18): Request that we limit processing of your data — for example, while we verify its accuracy or consider an objection you have raised. Contact us to exercise this right.
- Right to data portability (Art. 20): Export your complete data archive (JSON and CSV per log type) via Settings → Export Data. You may transfer this to another provider.
- Right to object (Art. 21): You have the right to object to processing based on legitimate interest (e.g., server-side error telemetry). Contact us and we will cease that processing unless we can demonstrate compelling legitimate grounds.
- Right to withdraw consent (Art. 7(3)): You may revoke HealthKit permission in iOS Settings at any time. You may disable AI features in Settings → AI Features at any time. You may delete your account at any time to withdraw all consent.
- Rights related to automated decision-making (Art. 22): You have the right not to be subject to solely automated decisions that produce legal or similarly significant effects. See Section 18 for our automated processing disclosure.
To exercise any right, use the in-app tools (Settings → Export Data or Settings → Delete Account) or email support@thetrulyperfect.com. We may need to verify your identity before fulfilling a request.
13. California Residents — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you additional rights.
Rights Under CCPA / CPRA
- Right to know: You have the right to know what personal information we collect about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties with whom we share it. This policy provides that disclosure.
- Right to delete: You have the right to request that we delete personal information we have collected about you. We will delete your data upon account deletion (Settings → Delete Account) or written request. Payment records are subject to the 7-year legal retention exception.
- Right to correct: You have the right to request correction of inaccurate personal information we maintain about you.
- Right to opt out of sale or sharing: We do not sell your personal information to third parties. We do not share your personal information with third parties for cross-context behavioral advertising. There is nothing to opt out of with respect to sale.
- Right to limit use of sensitive personal information (SPI): Health data, financial data, and precise geolocation are classified as Sensitive Personal Information (SPI) under CPRA. We use SPI only to provide the services you request — we do not use SPI to infer characteristics about you beyond what is necessary to deliver the App. You may request that we limit use of your SPI by contacting us.
- Right to non-discrimination: We will not discriminate against you for exercising any of your CCPA rights — no denial of goods or services, no difference in price or quality, no penalization.
- Shine the Light (Cal. Civ. Code § 1798.83): California residents may request information about our disclosure of personal information to third parties for their direct marketing purposes during the prior calendar year. We do not share personal information with third parties for their direct marketing purposes, so there is nothing to report.
- Authorized agents: A California resident may designate an authorized agent to submit a CCPA request on their behalf. We will require written proof of authorization and may verify your identity directly before fulfilling the request. Submit authorized agent requests to support@thetrulyperfect.com.
California — Sensitive Personal Information (CPRA)
Some information we process — health and medical information, and mental-health information such as your PHQ-9 screening responses (and any legacy EPDS screening responses) — is "sensitive personal information" (SPI) under the CPRA (Cal. Civ. Code §1798.140(ae)). We use SPI only to provide and secure the features you request and not to infer characteristics about you. Because we limit SPI use to these permitted purposes the CPRA "right to limit" may not apply; nevertheless you may direct us to limit use of your SPI, disable AI features any time in Settings → AI Features, or email support@thetrulyperfect.com.
We do not "sell" or "share" (for cross-context behavioral advertising) your personal information or SPI (Cal. Civ. Code §1798.120). Your California rights: to know/access, delete, correct, opt out of sale/sharing, limit use of SPI, and non-discrimination for exercising them. To exercise, email support@thetrulyperfect.com or use Settings → Your Data; we respond within 45 days (extendable by 45 where permitted). You may use an authorized agent.
To exercise any California right, email support@thetrulyperfect.com or use the in-app tools in Settings.
14. Washington Residents — My Health My Data Act
Washington Consumer Health Data (My Health My Data Act)
Much of what you provide — feeding, sleep, growth, maternal-health, PHQ-9 (and any legacy EPDS), lab, and medication data — is "consumer health data" under the Washington My Health My Data Act (MHMDA, RCW 70.372). We are a direct-to-consumer service and not a HIPAA covered entity, so this data is not regulated by HIPAA; the MHMDA applies instead.
- Collection & consent: we collect consumer health data to provide the features you use. AI features are enabled by default and you can disable them any time in Settings → AI Features.
- Sharing: we do not sell consumer health data; we share it only with processors that help us provide the service (hosting, AI processing) under data processing agreements.
- Your rights: confirm whether we process your consumer health data, access it, delete it (we direct our processors to delete it), and withdraw consent — email support@thetrulyperfect.com or use Settings → Your Data.
- No geofencing: we do not use geofences around healthcare facilities to identify, track, or collect data from consumers.
For MHMDA-specific requests, contact: support@thetrulyperfect.com.
15. International Data Transfers
The Perfect Start is operated in the United States. If you access the App from the European Union, European Economic Area, United Kingdom, or other regions with data protection laws, be aware that your data will be transferred to and processed in the United States and, for certain AI features, other countries.
We rely on Standard Contractual Clauses (SCCs) approved by the European Commission (pursuant to EU Commission Implementing Decision 2021/914) as the primary safeguard for EEA-to-third-country transfers. Each processor's transfer mechanism is listed in Section 5.
We do not rely on consent to transfer as the legal mechanism for international data transfers under GDPR. All transfers rely on SCCs or other adequacy mechanisms as noted in Section 5.
To obtain a copy of the applicable SCCs or for transfer-related questions, contact support@thetrulyperfect.com.
Our live-AI providers — Google LLC (Google Cloud Vertex AI) and Anthropic, PBC — process data in the United States. For data subjects in the EEA and UK, these transfers are made under the Standard Contractual Clauses (and, for the UK, the UK International Data Transfer Addendum) incorporated in each provider's Data Processing Addendum, and we maintain a transfer risk assessment for them. Before any such transfer we apply automated PII and personal-health-data redaction to minimise the personal data involved.
16. Breach Notification
In the event of a personal data breach that is likely to result in a risk to the rights and freedoms of individuals, we commit to:
- 72-hour notification to supervisory authority: We will notify the relevant EU/EEA Data Protection Authority within 72 hours of becoming aware of the breach, as required by GDPR Article 33, unless the breach is unlikely to result in a risk to individuals.
- Individual notification: Where the breach is likely to result in a high risk to your rights and freedoms, we will notify you directly without undue delay, in plain language, describing the nature of the breach, the data affected, the likely consequences, and the steps we are taking to address it.
- US state breach notification: We will comply with applicable state breach notification laws (including California, Washington, and other US states with notification requirements) within the legally required timeframes.
- Breach log: We maintain an internal log of all actual and suspected breaches, regardless of whether notification is required, for internal review and regulatory inspection.
If you discover or suspect a security incident involving your data, please notify us immediately at support@thetrulyperfect.com.
17. Data Protection Impact Assessment (DPIA)
We have conducted a Data Protection Impact Assessment (DPIA) as required by GDPR Article 35. A DPIA is triggered by the nature of our processing, which includes:
- Large-scale processing of special-category health data (maternal health, baby health)
- Systematic processing of mental health screening data (PHQ-9; legacy EPDS records also processed)
- Use of AI/ML systems to generate personalized health guidance
- Transfer of health context data to third-country AI processors
Our DPIA identifies the risks associated with these processing activities and the technical and organizational measures we have implemented to mitigate them (including RLS, AES-256 encryption, TLS 1.3, prompt anonymization, deflection-first AI architecture, content moderation, and AI opt-out controls).
If you are an EU/EEA resident and wish to request a summary of the DPIA findings relevant to your data, contact us at support@thetrulyperfect.com.
18. Automated Processing and AI Decisions
The Perfect Start uses AI-generated content to provide personalized guidance, tips, and summaries. This section discloses our automated processing practices in compliance with GDPR Article 22.
- No solely-automated decisions with legal or significant effect: We do not make any decisions about you — including decisions about eligibility, pricing, access to services, or any other legally significant matter — using solely automated means without human involvement. All AI outputs are informational and educational.
- AI-generated content is advisory only: Responses from the AI Companion, Mom Well-Woman, Lab Results commentary, Home Insight, and Milestone Summaries are generated by a large language model based on the data you provide. These responses are not medical diagnoses, treatment recommendations, or clinical opinions. Always consult a qualified healthcare provider for medical decisions.
- You retain decision authority: Every AI response is a suggestion or summary. You decide how to act on it. The App is designed to support your decisions, not to make decisions for you.
- Profile-based personalization: We use the profile data you enter (birth method, health history flags, dietary preferences, baby age) to tailor AI prompts so responses are more relevant to your situation. This is limited to within-app personalization and does not result in automated profiling with external effects.
- Your right to contest: If you believe an AI response has had an adverse effect on you or has been used to make a decision about you, contact us at support@thetrulyperfect.com to request human review.
19. Government and Legal Requests
We believe in protecting your data from government overreach. Our policy for handling government, law enforcement, and legal process requests is as follows:
- Legal review for all requests: Every government or law enforcement request for user data is reviewed by us (and legal counsel where necessary) before any response. We do not voluntarily disclose user data to government authorities without a valid legal process.
- Notification where permitted: We will notify you of a government request for your data unless we are legally prohibited from doing so (e.g., by a court-issued non-disclosure order) or unless doing so would create an imminent risk of harm.
- Narrowing requests: We will challenge overly broad requests and seek to narrow them to the minimum data necessary.
- Transparency reporting: We commit to publishing an annual transparency report disclosing the number and categories of government requests received, to the extent permitted by law. The first report will cover calendar year 2026.
20. Cookies and Web Tracking
The Perfect Start's native iOS app does not use cookies.
The Progressive Web App (PWA) at start.thetrulyperfect.com uses the following:
- Session storage and localStorage: Used to maintain your login session and cache app state between page loads. These are first-party only and are cleared when you log out or clear your browser data.
- Supabase Auth cookies: A first-party authentication cookie is set by Supabase Auth to maintain your logged-in session. It is strictly necessary and cannot be opted out of while using the web app.
- No third-party cookies: We do not set any third-party cookies. We do not use advertising cookies, tracking pixels, or analytics cookies of any kind.
- Vercel analytics: Vercel server-side access logging records your IP address, browser, and page requested for operational purposes. No client-side tracking scripts are loaded.
21. Lodging a Complaint
If you are not satisfied with how we handle your personal data or respond to your rights requests, you have the right to lodge a complaint with your local supervisory authority. Relevant authorities include:
- European Union (general): The Data Protection Authority in your EU member state of residence. A list of all EU DPAs is available at edpb.europa.eu.
- United Kingdom: Information Commissioner's Office (ICO) — ico.org.uk
- Ireland: Data Protection Commission (DPC) — dataprotection.ie
- Spain: Agencia Española de Protección de Datos (AEPD) — aepd.es
- Mexico: Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) — inai.org.mx
- California: California Privacy Protection Agency (CPPA) — cppa.ca.gov
- Washington State: Washington State Attorney General — atg.wa.gov
Before lodging a formal complaint, we encourage you to contact us first at support@thetrulyperfect.com so we have the opportunity to address your concern directly.
22. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes — such as adding a new data category, a new AI processor, or changing your rights — we will:
- Update the "Effective date" and "Last updated" date at the top of this page
- Display an in-app banner on your next login describing the nature of the change
- Send an email notification to your registered email address for significant changes
For minor, non-material changes (such as clarifications, grammar corrections, or updated links), we will update the "Last updated" date only, without in-app or email notification.
All prior versions of this policy are available on request by emailing support@thetrulyperfect.com.
Your continued use of the App after the effective date of an updated policy constitutes your acknowledgment of the changes. If you do not agree with the updated policy, you may delete your account at any time.
23. Contact
Data Controller:
The Truly Perfect LLC
General support: support@thetrulyperfect.com
Use these addresses for any of the following:
- GDPR rights requests (access, rectification, erasure, portability, restriction, objection)
- CCPA / CPRA rights requests
- Washington MHMDA rights requests
- Data export or account deletion requests
- Questions about this Privacy Policy
- Security vulnerability disclosures
- Government or legal process inquiries
- DPIA summary requests
- SCC copies or international transfer questions
We will respond to all privacy-related inquiries within 5 business days and to formal rights requests within 30 days.