Legal
Privacy Policy
Last updated: 20 August 2026 · Effective date: 20 August 2026
This Privacy Policy explains how Fooshi (“we”, “us”, “our”), operating the Baby Tempo mobile application (the “App”), collects, uses, stores, and shares personal data.
Baby Tempo helps caregivers log and share newborn care information (for example sleep, feeding, nappies, temperature, and weight). This Policy is written for caregivers who create accounts. Data about babies is personal data relating to children and is treated with particular care.
Contact: baby-tempo@fooshi.co
1. Controller
The data controller for Baby Tempo is:
- Operator: Fooshi
- Product: Baby Tempo
- Email: baby-tempo@fooshi.co
- Legal entity name: Fooshi Digital Solutions
If you have questions about this Policy or your data, contact us at the email above.
2. Scope
This Policy applies to:
- the Baby Tempo iOS App;
- related backend services that power the App;
- caregiver invite landing pages used to join a shared baby profile; and
- our communications with you about the App (for example support email).
It does not apply to third-party websites or services we do not control (for example Apple, Google, or messaging apps you use to share an invite link).
3. Who this App is for
Baby Tempo is intended for adults (parents and other caregivers) who track care for a baby.
You must only create an account and enter baby information if you are legally allowed to do so, and if you have the right to share that information with other caregivers you invite.
We do not knowingly allow children to create their own accounts. If you believe a child has created an account, contact us and we will delete it.
4. Categories of personal data we process
Depending on how you use the App, we may process:
4.1 Account and identity data
- Sign-in provider (Apple or Google) and the provider’s user identifier
- Display name (if provided by the identity provider)
- Email address associated with the identity provider (this may be an Apple Hide My Email / Private Relay address)
- App preferences (language, week-start day, measurement units)
- Session and authentication tokens needed to keep you signed in
We do not store passwords. Sign-in is handled by Apple or Google.
4.2 Baby profile data
- Baby’s name
- Date of birth, or expected date of birth
- Whether birth has been confirmed
- Trial / subscription entitlement status linked to that baby profile
4.3 Care event data (often sensitive / health-related)
Logs you (or another invited caregiver) create for a baby, including:
- Sleep-related events (nap, night waking, wake up, bed time) and related details
- Feeding and nursing events (including side, type, quantity where entered)
- Pumping events (side, quantity where entered)
- Pee and stool events (including type/colour where entered)
- Temperature readings
- Weight readings
- Event times, durations, timezone context, and which caregiver created or edited the event
We do not currently collect photos, camera data, microphone recordings, precise location/GPS, device contacts, or HealthKit data for Baby Tempo MVP.
4.4 Sharing and membership data
- Baby memberships and roles (admin / editor)
- Caregiver invite tokens, creation time, expiry, and whether an invite was used
- Membership changes (invite accepted, caregiver revoked, caregiver left, admin succession)
4.5 Subscription and purchase data
- App Store purchase / entitlement status (for example monthly, yearly, or lifetime premium)
- Trial window for a baby (start/end related to birth confirmation)
- Information needed to verify purchases with Apple (transaction identifiers and signed transaction data)
Payment card details are processed by Apple, not by us.
4.6 Technical, usage, and support data
- Device and app technical information reasonably needed to operate the service (for example app version, locale, crash or error diagnostics if enabled)
- Product analytics events limited to identifiers and enums (for example event type, baby ID, auth provider). We design analytics not to include baby names, free-text notes, email addresses, or exact clinical measurements
- Content of support emails you send us
4.7 Data we do not sell
We do not sell your personal data.
5. Sources of data
We obtain data from:
- You, when you sign in, create baby profiles, log events, change settings, or contact support
- Other caregivers you invite (or who invite you) on a shared baby profile
- Apple and/or Google, when you sign in
- Apple, when you purchase, restore, renew, or cancel an in-app subscription or lifetime purchase
- Your device, for technical operation of the App (for example secure storage of session tokens)
6. Purposes and legal bases (GDPR)
We process personal data for the following purposes. Where GDPR applies, the legal bases are:
| Purpose | Examples | Legal basis |
|---|---|---|
| Provide the App | Account creation, authentication, storing and displaying care logs, syncing shared baby profiles, Live Activities for ongoing events | Performance of a contract (Art. 6(1)(b)) |
| Caregiver sharing | Creating invite links, accepting invites, role management | Performance of a contract (Art. 6(1)(b)) |
| Subscriptions & freemium | Trial windows, paywall, verifying App Store purchases, applying shared premium access per baby | Performance of a contract (Art. 6(1)(b)); legitimate interests for fraud prevention / entitlement integrity (Art. 6(1)(f)) |
| Security & integrity | Rate limiting, session management, audit logs for membership/entitlement changes, abuse prevention | Legitimate interests (Art. 6(1)(f)); legal obligation where applicable (Art. 6(1)(c)) |
| Product improvement | Aggregate product analytics (for example onboarding completion, feature usage) | Legitimate interests (Art. 6(1)(f)). If we rely on consent for a specific analytics tool in your region, we will obtain it |
| Support | Responding to emails at baby-tempo@fooshi.co | Legitimate interests (Art. 6(1)(f)); contract where the request relates to your account |
| Legal compliance | Responding to lawful requests, defending legal claims, keeping required records | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
Special category / child-related care data
Temperature, weight, feeding, stool/pee, and similar care logs can reveal health-related information about a baby. We process this data because it is necessary to provide the tracking service you request.
Where an additional condition under Art. 9 GDPR is required, we rely on explicit consent and/or the fact that you manifestly make the data public within the closed caregiver circle you control by entering it and inviting others. You can withdraw consent by deleting events, removing a baby (where you are admin), leaving a baby, or deleting your account — subject to the effects described in section 11.
7. How caregiver sharing works
If you are the admin of a baby profile, you can create a single-use invite link (valid for 24 hours). Anyone who opens a valid unused link and signs in can become an editor for that baby.
Editors can view, create, edit, and delete care events for that baby. All caregivers on a baby share one record.
Important:
- Do not share invite links with people who should not see the baby’s care data.
- An invite is not tied to a specific email address in advance.
- Admin can revoke an accepted caregiver later. Unused invite links expire after 24 hours.
- If you leave a shared baby, other caregivers may keep the baby’s data. If you are the sole admin and delete your account, sole-admin babies are archived/removed according to our deletion process; shared babies may continue for remaining caregivers with admin succession.
8. Recipients and processors
We may share personal data with:
| Recipient | Role |
|---|---|
| Apple | Sign in with Apple; App Store payments; App Store Server notifications related to subscriptions |
| Google Sign-In (when you choose Google) | |
| Hosting / database providers | Cloud hosting and managed PostgreSQL storage for the App backend (currently operated on infrastructure such as DigitalOcean / managed Postgres) |
| Invite landing host | A web page that opens the App from an invite link (for example a Lovable-hosted invite URL) |
| Analytics provider | Product analytics (PostHog is planned; when enabled, configured to avoid baby names, emails, and exact clinical values in event properties) |
| Other caregivers | People you invite (or who invited you) to the same baby profile |
| Professional advisers / authorities | Only where required by law or to protect rights, safety, and security |
We require processors to process personal data only on our instructions and with appropriate safeguards.
We do not use the App data for advertising networks or sell data to data brokers.
9. International transfers
Our servers and some processors may be located outside your country of residence (including outside the European Economic Area / UK).
Where we transfer personal data internationally, we use appropriate safeguards required by applicable law, such as the European Commission’s Standard Contractual Clauses, adequacy decisions, and/or additional technical and organisational measures.
10. Retention
We keep personal data only as long as needed for the purposes above:
- Account and profile data: for as long as your account remains active, then deleted or anonymised after account deletion (subject to short technical backup windows)
- Care events and baby profiles: while the baby profile remains active for at least one caregiver; archived or deleted when removed according to App rules and erasure requests
- Invite tokens: until used or expired (24 hours), then retained only as needed for security/audit
- Subscription / transaction records: as needed to provide entitlements and meet accounting/legal obligations
- Support emails: for as long as needed to resolve your request and maintain a reasonable support history
- Audit / security logs: for a limited period necessary for security, dispute resolution, and compliance
After deletion requests, residual copies may remain briefly in encrypted backups until those backups rotate.
11. Your rights
Depending on where you live (especially if GDPR/UK GDPR applies), you may have the right to:
- Access your personal data
- Rectify inaccurate data
- Erase your data (“right to be forgotten”)
- Restrict processing
- Object to processing based on legitimate interests
- Data portability (where applicable)
- Withdraw consent where processing is based on consent
- Lodge a complaint with a supervisory authority
How to exercise rights in the App
- Correct data: edit baby info and care events in the App where available
- Delete account / erase data: use Settings → Delete my data (or contact baby-tempo@fooshi.co)
- Leave a baby: remove yourself from a shared baby without deleting other caregivers’ access
- Support / other requests: email baby-tempo@fooshi.co
Account deletion removes your account and sessions. Sole-admin babies are archived/removed. Shared babies may remain available to remaining caregivers, and admin may transfer according to App rules. We will not provide another caregiver’s personal account data to you without a lawful basis.
Complaints
You may lodge a complaint with your local data protection authority. If Fooshi is established in the EU/EEA, you may also contact the authority in our country of establishment. [Supervisory authority name/link — complete when registered address is set.]
12. Security
We use technical and organisational measures appropriate to the risk, including:
- encryption in transit (TLS)
- encryption at rest on managed database infrastructure
- server-side authorisation checks for every baby membership and event change
- hashed refresh tokens and secure on-device storage of session tokens (Keychain)
- rate limiting on sensitive endpoints (sign-in, invite acceptance)
- audit logging for membership and entitlement changes
- least-necessary analytics properties
No method of transmission or storage is 100% secure. Please protect your device and do not share invite links broadly.
13. Children’s privacy and parental responsibility
Baby Tempo stores information about babies, entered by adult caregivers.
You are responsible for:
- ensuring you have authority to create and manage the baby profile;
- deciding which caregivers receive invite links; and
- the accuracy of the information you log.
We do not provide medical advice. Care logs are for personal organisation and caregiver coordination only.
14. Cookies and similar technologies
The iOS App itself does not use browser cookies. Session tokens are stored securely on device.
Invite landing pages or marketing pages may use strictly necessary technologies to open the App or operate the site. If we add non-essential cookies (for example analytics on a website), we will update this Policy and, where required, request consent.
15. Automated decision-making
We do not use automated decision-making that produces legal or similarly significant effects about you.
Any future “soft” timing suggestions in the App (for example contextual reminders based on recent logs) are informational only, are not medical advice, and do not replace professional judgement.
16. Changes to this Policy
We may update this Privacy Policy from time to time. We will change the “Last updated” date and, where required, provide additional notice in the App or by email.
Continued use of the App after an update means you acknowledge the revised Policy, except where applicable law requires explicit consent for a particular change.
17. Contact
Privacy / support: baby-tempo@fooshi.co
18. Publishing checklist (internal — remove before going live)
- Full legal entity name
- Registered address and country
- Governing supervisory authority
- Confirm hosting region(s) and list processors accurately
- Confirm whether PostHog (or other analytics) is live at launch
- Confirm whether Sentry/crash reporting is live at launch
- Public URL of this Privacy Policy
- Cross-link Terms & Conditions URL
- Lawyer review (recommended before App Store submission)