How your data flows

Plain-English summary. The full legal text is in our Privacy Policy.

When you sign up

Your email and password are stored on our database server (Supabase, hosted in the United States). Passwords are hashed using bcrypt — even we can never read your password. Only YOU can see your own data; the database enforces this with row-level security.

When you log a baby feed, sleep period, or growth entry

The entry stays on our database server. We never share it with any third party. You can export or delete every entry from Settings → Your Data.

When you ask the AI

Your question and relevant context (e.g., your baby's age, today's feed and sleep logs) are first stripped of personal identifiers, then sent to Google Cloud Vertex AI — Gemini 2.5 Flash (primary), with Gemini 2.5 Pro as fallback, then Anthropic Claude (direct) — for a response. Neither provider retains your data beyond what is necessary for the API call, and neither uses it to train their models. We do NOT store your prompt or the AI's reply unless you save it to your journal.

When you use HushBaby

HushBaby briefly accesses your microphone to detect your baby's cry level. The audio recording is discarded immediately — only the derived distress score is stored. No audio is ever sent to our servers or to any third party.

When you scan a document

The image is sent to our server, run through OCR (text extraction), and only the extracted values are saved. The image itself is discarded immediately after extraction.

When you connect Apple Health

Apple Health stores your data on your iPhone. When you allow our app to read activity, sleep, and heart rate, your phone sends only those numbers to our app — Apple itself does NOT see what we read. You can revoke access in iPhone Settings → Privacy & Security → Health → The Perfect Start. Apple does not see the data we read.

When you receive an email from us

We send through Resend. Email triggers: account verification, password reset, caregiver access link. Subject lines are generic; we never include health details in the subject or body of automated emails.

When you visit the web version

The web version is hosted by Vercel. Vercel logs your IP address, the URL you requested, and your browser type for 90 days for security and performance. Vercel does NOT see any health data — that lives in our database, not in the page URL.

When you pay

Payments go through Apple's In-App Purchase system. We never see your credit card number. RevenueCat receives the subscription receipt only — no health data.

When you use Story Builder narration

When you generate a narrated audio story, your story text is sent to OpenAI for voice synthesis (Text-to-Speech). When you generate a cover image, your story text is also sent to OpenAI DALL-E for image generation. OpenAI does not retain your data beyond the API call per their API Data Usage Policy (openai.com/policies/api-data-usage-policies). We do not store the audio file on our servers — it is streamed directly to your device. The cover image is stored in your account. Your story text itself is stored in our database under your account.

When you share access with a caregiver

When you generate a caregiver access link, we send them a one-time code. They see ONLY: your baby's feeds, sleep, and growth entries. They do NOT see your PHQ-9 scores, lab results, payment info, or account email. Every access is logged and you can revoke any time from Settings → Caregiver Access.

Last updated: 2026-05-03  |  Full Privacy Policy  |  Questions: support@thetrulyperfect.com