BabyDaily Privacy

Privacy Policy

This Privacy Policy explains how the BabyDaily app and official website collect, use, share, retain, and delete personal information and how users can exercise their rights.

Privacy Policy

This is BabyDaily's comprehensive Privacy Policy. It covers data collection and use, service providers, security measures, retention and deletion, user rights, and contact methods.

Document version
privacy-policy-v2026-07-26
Effective date
2026-07-26

1. Scope and Operator

This Privacy Policy applies to the BabyDaily mobile application, official website, and related support services provided by the individual operator of BabyDaily.

BabyDaily processes personal information only as needed to provide and protect the service and works to comply with applicable privacy laws and app marketplace policies.

Privacy inquiries and requests to exercise data rights may be sent to zorleno.co@gmail.com.

2. Personal and Sensitive Data We Process

BabyDaily may process information you provide, information generated through service use, and information obtained through device features you permit.

Category
Account and authentication
Data
Email address, name or nickname, encrypted password, Google or Apple account identifier, member identifier, and consent status, version, and timestamp
Source and Purpose
Registration, sign-in, identity verification, account security, and consent records
Category
Baby and caregiver information
Data
Baby name or nickname, sex, birth date, expected birth date, caregiver relationship and role, invitation, and membership information
Source and Purpose
Baby profiles, caregiver invitations, shared care, and access control
Category
Care records and user content
Data
Feeding, sleep, diaper, pumping, health, growth, and other care records; notes, photos, diary entries, community posts, comments, and reports
Source and Purpose
Record storage, synchronization, statistics, family sharing, diary, and community features
Category
Device and service usage
Data
Operating system, device model, app version, IP address, device or app identifiers, push token, and access, usage, synchronization, and error logs
Source and Purpose
Notifications, security, abuse prevention, troubleshooting, and service improvement
Category
Advertising and purchases
Data
Advertising consent status, advertising identifier and ad interactions, subscription product and status, transaction identifier, and purchase restoration information
Source and Purpose
Consent-aware advertising, subscription entitlement, purchase restoration, and fraud prevention
Category
Customer support
Data
Email address, inquiry type and content, attachments, processing status, and response history
Source and Purpose
Support, identity verification, troubleshooting, account deletion, and dispute handling

3. Why We Process Data

  • Provide registration, sign-in, social sign-in, account management, and consent records
  • Store and synchronize care records, generate statistics, and manage baby profiles
  • Provide caregiver invitations, permission management, and family sharing
  • Provide photos, diaries, community posts, comments, and reporting features
  • Deliver care reminders, invitation notices, community notices, and service notifications
  • Verify subscription status, restore purchases, and provide paid features
  • Provide advertising and privacy options according to consent and regional requirements
  • Analyze errors, protect security, prevent abuse, respond to support requests, and improve the service
  • Meet legal obligations and respond to disputes or rights-infringement reports

4. Sharing and Service Providers

BabyDaily does not sell personal information. The providers below may process data as necessary to operate the service. Content may also be shown to caregivers you invite or other users according to the visibility settings you select.

Provider or Recipient
Supabase
Purpose and Data
Account information, care records, content, files, and operational logs for authentication, databases, storage, and server functions
Provider or Recipient
Google and Apple
Purpose and Data
Account identifiers, transaction information, device identifiers, and push tokens for social sign-in, app distribution and billing, and Firebase Cloud Messaging
Provider or Recipient
Google Mobile Ads and User Messaging Platform
Purpose and Data
Advertising consent status, advertising identifiers, device information, and ad interactions for advertising and privacy-choice management
Provider or Recipient
Sentry
Purpose and Data
Member identifier, email, app version, device information, and error or diagnostic logs for troubleshooting and performance analysis. Automatic default PII transmission is disabled.
Provider or Recipient
RevenueCat
Purpose and Data
App user identifier and transaction or subscription information for subscription products, entitlement status, and purchase restoration
Provider or Recipient
Resend and operational support systems
Purpose and Data
Email address, inquiry content, attachments, and processing history for receiving and answering support requests
Provider or Recipient
Invited caregivers and community users
Purpose and Data
Baby profiles and care records shared under user-selected permissions, or posts and comments made visible through community features

5. Device Permissions and Your Choices

  • Camera: used only when you choose to take a photo.
  • Photo selection: BabyDaily uses an operating-system picker such as Android Photo Picker to access only the photos you select and does not request broad read access to your entire photo library on supported systems.
  • Notifications: used after your permission to provide care reminders, invitations, community notices, and service notifications.
  • Advertising privacy options: where required, Google UMP requests consent and lets you reopen privacy options from app settings.
  • You may deny optional permissions and continue using service features that do not require those permissions.

6. Retention and Deletion

We retain personal information only for as long as needed for the stated purposes. After a verified account deletion, data is deleted or de-identified from active systems without undue delay. Backup copies may remain until the applicable backup cycle expires, and information required by law or for disputes may be kept separately for the required period.

Data
Account, baby profile, caregiver relationship, care records, and user content
Retention Standard
Until account deletion is completed, except where legal retention or protection of another user's rights requires limited retention
Data
Push tokens and device links
Retention Standard
Until no longer needed for notifications, logout, token expiry, or account deletion
Data
Error, diagnostic, and security logs
Retention Standard
For the minimum period needed for troubleshooting, security, and abuse prevention, or the provider's contracted retention period
Data
Contract and cancellation records
Retention Standard
Five years where required by the Korean Act on Consumer Protection in Electronic Commerce
Data
Consumer complaint and dispute records
Retention Standard
Three years where required by the Korean Act on Consumer Protection in Electronic Commerce
Data
Service access records
Retention Standard
Three months where required by applicable communications-secrecy law

7. Security Measures

  • We use encrypted transport such as HTTPS/TLS and secure password handling provided by our authentication provider.
  • Access is restricted based on member and caregiver permissions, with server-side access controls and least-privilege practices.
  • Production secrets and credentials are separated from source code and limited to authorized people and systems.
  • We review error and security logs and limit unnecessary personal information in diagnostic data.
  • If a security incident is confirmed, we take steps to contain harm and provide notices required by applicable law.

8. Your Rights and Account Deletion

You may request access, correction, deletion, restriction, withdrawal of consent, or deletion of your account. A request may be limited where required to protect another person's rights or meet a legal obligation.

You may request deletion through app settings or the public account deletion page at https://babydaily.zorleno.com/en/account-deletion. Uninstalling the app does not by itself delete the server account or associated data.

We may verify your identity before completing a request to protect your account. Privacy requests may also be sent to zorleno.co@gmail.com.

9. Children's Data and International Processing

BabyDaily member accounts are intended for users aged 14 or older. Baby information is entered by a parent or caregiver for care-record purposes; the service is not designed for a baby to create an account directly.

Depending on provider infrastructure, information may be processed outside your country of residence. We work to apply contractual protections, access controls, encryption, and safeguards required by applicable law.

10. Changes and Contact

This Privacy Policy is effective July 26, 2026. We may update it when the service, SDKs, law, or data practices change. Material changes will be announced in the app or on the official website.

App and service: BabyDaily

Operator: Individual operator of BabyDaily

Privacy contact: zorleno.co@gmail.com