Personal data processing policy
My Baby Log is an app where a family records a child's everyday life — sleep, feeding, growth, health, memories — and shares it with the people who care for them. That means we handle health data about children. This document explains exactly what we collect, why, who else sees it, how long we keep it, and what you can do about it.
1. Who is responsible
The data controller is Giovanny Manchola, a natural person domiciled in Colombia, as the developer and operator of the My Baby Log app.
For anything concerning your personal data, write to legal@mybabylog.net.
2. Scope
This policy covers the My Baby Log mobile app for iOS and Android, the
service behind it at api.mybabylog.net, and this website. It does
not cover third-party services you may reach from the app, which have their
own policies.
3. Whose data we handle
Two distinct groups of people are involved, and the difference matters:
- Caregivers — the adults who create an account and use the app: mothers, fathers, grandparents, nannies, relatives.
- The child — the infant, child or adolescent whose development is recorded. The child has no account and does not use the app; their data is entered by the caregivers.
Whoever creates a child's profile declares, in doing so, that they are that child's legal representative or act with their authorisation. That is the foundation for everything described here.
4. What data we process
We only process what caregivers enter into the app, plus the minimum the service needs to run. We do not buy data, we do not obtain it from third parties, and we do not track your activity outside the app.
| Category | What it covers |
|---|---|
| Account and identity | Email address, password (stored only as a hash, never in clear text), name, profile picture, date of birth, language, time zone and country of signup. |
| Sign-in with Google or Apple | The identifier the provider hands us and the email address associated at the time the account is linked. We never receive your Google or Apple password. |
| Sessions and devices | Device identifier, the label you give it, session tokens (stored as hashes), issue and revocation timestamps, and the push notification token. |
| Child profile | Name, sex, birth date or due date, country, measurements at birth (weight, height, head circumference, gestational weeks) and any free-text notes you add. |
| Daily routine | Feeding, sleep and diaper entries, with their times, amounts and notes. |
| Growth | Weight, height and head circumference over time. |
| Health | Blood type, allergies and their reactions, diagnosed conditions, medications with doses and schedules, medical appointments with their reason and diagnosis, illness episodes with symptoms and temperature readings, vaccination history, and the contact details of any healthcare providers you record. |
| Pregnancy | Pregnancy tracking entries, when that stage is used. |
| Memories and photos | Images you upload, their captions, developmental milestones and family events. |
| Community (optional) | Posts, comments, reactions, follows, blocks and content reports. |
| Caregivers and permissions | Who has access to which child, with what role and relationship, the invitations sent, and audit records of permission and sharing changes. |
| Location (optional) | Latitude, longitude, accuracy and capture time. It is off by default and only works if you explicitly turn it on. |
| Preferences and consents | Notification settings, goals, supply inventory, and a record of every consent you grant or withdraw, with its version and date. |
5. Children's data and health data
These two categories get heightened protection, and it is worth being explicit about how we treat them.
Data about children and adolescents
In Colombia, article 7 of Law 1581 of 2012 starts from a general prohibition on processing minors' data, and lifts it only where the processing serves the child's best interest and ensures respect for their fundamental rights. Once that is met, authorisation is granted by their legal representative, after the child has exercised their right to be heard, with their opinion weighed according to their maturity and their capacity to understand the matter.
Applied to this app, that means:
- The processing exists for the child's own benefit: keeping their health and development history, and letting the people who care for them stay coordinated.
- Authorisation is given by the legal representative, who is the person who creates the profile and accepts this policy.
- As the child grows, we expect whoever represents them to involve them in decisions about their own data — most of all in the decision to publish anything about them in Community.
Health data
Health data is sensitive data. Two concrete consequences follow:
- You are never obliged to provide it. The app works without a single medical entry: the health, vaccine and illness modules are optional.
- Processing it requires your explicit authorisation, which is what you give by accepting this policy and using those modules.
6. What we use it for
- Running the service: storing your entries and presenting them organised.
- Syncing information between the devices of caregivers who have access to the same child.
- Sending the reminders and alerts you configure (vaccines, routines, other caregivers' activity).
- Sending essential account email: address verification, password resets, security notices.
- Keeping the account secure and detecting improper access.
- Handling your requests and meeting legal obligations.
We do not use your data for advertising, we do not sell it, and we do not hand it to third parties for commercial purposes. The app ships no third-party analytics SDK.
7. Legal basis
In Colombia, processing rests on your prior, express and informed authorisation. The app asks for it before letting you in, and records which version of which document you accepted, and when.
If you are in the European Economic Area or the United Kingdom, the GDPR also protects you. There, the bases are: performance of the contract (art. 6(1)(b)) for the core features; your consent (art. 6(1)(a)) for optional features; our legitimate interest (art. 6(1)(f)) in keeping the service secure; and your explicit consent (art. 9(2)(a)) for health data.
8. Optional features with their own consent
Two features reach beyond private use among caregivers, so each has a separate consent you can grant or withdraw on its own, without losing the rest of the app:
- Community — shares information about a child beyond your direct caregivers. It stays off unless you enable it for that specific child.
- Location — records the caregiver's location. It is off by default.
Both are managed under Settings → My consents, where you can also review everything you have accepted and withdraw it.
9. Who else processes the data
We rely on the following providers to run the service. They process personal data on our behalf and on our instructions:
| Provider | Purpose | Where |
|---|---|---|
| Hetzner Cloud | Server and database holding all account information | Helsinki, Finland (European Union) |
| Cloudflare R2 | Storage for the photos you upload | Cloudflare's global network |
| Delivery of account email, and Sign in with Google when you choose it | Google's global infrastructure | |
| Apple | Sign in with Apple when you choose it | Apple's global infrastructure |
| Expo | Delivery of push notifications to your device | Expo's infrastructure |
10. International transfers
The server and the database sit in Finland, inside the European Union. If you live in Colombia, Peru or anywhere else, your data and the child's is stored there. The providers in the table above may process data from other countries as part of their own infrastructure.
11. How long we keep it
While the account is active, we keep the information so we can show it back to you — that is the point of the app. When you delete something, here is exactly what happens:
| What you delete | What happens |
|---|---|
| A child's profile | It is hidden immediately and recoverable for 30 days. After that it is permanently erased, photos included. |
| Your account | It is deactivated immediately and you can recover it for 30 days by signing in again. After that, your personal data — name, email and sign-in identifiers — is permanently erased. |
| Permission and sharing audit records | Kept for 6 months, then deleted. |
| Internal deletion markers (used to sync devices) | Kept for 90 days. |
| Email verification and password reset links | Expire after 24 hours. |
One consequence worth being clear about
Content you created about a child whom other caregivers still access does not disappear when you delete your account: it is that child's history, not your personal profile, and removing it would leave holes in their family's records. What does disappear is its link to you: those entries stop being attributed to your name or email and are shown only by your relationship, as "former caregiver — grandmother".
12. How we protect the information
- The database the app keeps on your phone is encrypted (SQLCipher, AES-256), and its key lives in the operating system's secure store.
- All traffic between the app and the server is encrypted with TLS.
- The database enforces row-level security: each caregiver's access to each child is checked in the database engine itself, underneath the application's own logic.
- Passwords are stored only as hashes. Nobody, ourselves included, can read them.
- You can lock the app with your device's biometrics, see the list of open sessions, and sign out of all of them at once.
- The app blocks screenshots of its content.
No system is invulnerable. The above describes the measures we take, not a guarantee of absolute security.
13. Your rights
As the data subject — or as the child's legal representative — you may know, update and rectify the data; request proof of the authorisation given; be informed about its use; lodge complaints with the Superintendency of Industry and Commerce; revoke the authorisation or request erasure; and access the data free of charge.
If the GDPR protects you, you also have the right to restriction of processing, to data portability, to object to processing, and to lodge a complaint with your supervisory authority.
Much of this needs no message to us: from inside the app you can edit and delete any entry, manage who has access to each child, review and withdraw your consents, close sessions, and delete your account. For anything else, write to legal@mybabylog.net.
We answer queries within a maximum of ten (10) business days and complaints within a maximum of fifteen (15) business days, extendable on the terms Law 1581 of 2012 provides where meeting those deadlines is not possible.
14. Automated decisions
We make no automated decisions producing legal effects on you or on the child. The app computes estimates — the likely time of the next feed, which vaccines are due at a given age — but those are suggestions you are free to ignore, not decisions. Nothing the app shows is medical advice.
15. Changes to this policy
If we change this document, we will publish the new version here with its date. Where the change is substantial, the app will ask you to review and accept it again before continuing.
16. Contact and complaints
Write to legal@mybabylog.net. If you believe we have not handled your request properly, you may turn to Colombia's Superintendency of Industry and Commerce. If you live in the European Economic Area, you may turn to your country's data protection authority.