Privacy Policy
Effective date: April 14, 2026
The short version: Nurture collects your baby's daily data (feeds, sleep, diapers, moods, and your notes) so AI can find patterns and help your day feel more predictable. We send that data to AI providers for processing. We never sell your data. You can delete everything at any time.
1. Who We Are
Nurture ("we," "us," "our") is a mobile application operated by Noah Willman. This policy describes how we collect, use, store, and protect information when you use the Nurture iOS app and its backend services.
2. Information We Collect
2.1 Account Information
When you sign in with Apple, we receive:
- Your name (as provided by Apple Sign-In)
- A unique user identifier issued by Apple
We do not receive or store your Apple ID email address unless Apple provides it during sign-in and you consent to sharing it. We do not collect passwords.
2.2 Baby Information
You provide the following about your child:
- Name
- Date of birth
- Gender (boy, girl, or other)
- Photo (optional -- stored as a URL reference only)
2.3 Daily Logging Data
When you log events, we store:
| Event Type | Data Stored |
|---|---|
| Sleep | Start/end timestamps, duration |
| Feeding | Timestamps, method (breast/bottle/solid), duration, side, amount, fullness rating |
| Diaper | Timestamp, type (pee/poop/both), optional notes |
| Mood | Timestamp, observed mood |
| Notes | Free-text notes you write (e.g., "got vaccines today," "teething seems rough") |
All events include the timestamp of when they occurred and when they were logged.
2.4 Voice Input
If you use the "Just tell me" dictation feature, your audio is sent to OpenAI's Whisper service for transcription. We do not store the audio. Only the resulting text transcript is retained and processed.
2.5 AI-Generated Data
Our AI systems generate and store the following based on your logging data:
- Baby profile -- a summary of your baby's learned rhythms, typical durations, and patterns
- Daily schedule outlook -- a projected shape of the day based on observed patterns
- Annotations -- structured context extracted from your notes (e.g., vaccine, teething, illness), with automatic expiration
- Recommendations -- gentle suggestions about what may be coming next
2.6 Subscription Information
If you subscribe to Nurture Pro, Apple processes your payment. We receive from Apple:
- A transaction identifier
- The product purchased
- Subscription expiration date
We do not receive or store your payment method, credit card number, or Apple ID billing details.
2.7 Information We Do NOT Collect
- We do not collect your location
- We do not collect device identifiers for advertising
- We do not use cookies or web tracking
- We do not collect health data through Apple HealthKit
- We do not collect contact lists, photos (beyond the optional baby photo), or other device data
3. How We Use Your Information
We use your data for the following purposes:
- Pattern recognition: Analyzing your baby's event history to surface rhythms and build a daily outlook
- Suggestions: Generating gentle, non-prescriptive heads-up notifications based on observed patterns
- Chat: Answering your questions about your baby's data (e.g., "When was her last nap?")
- Profile building: Maintaining a living summary of your baby's evolving routines
- Family sharing: Allowing caregivers you invite to view and log events for your baby
- Subscription management: Verifying your subscription status to enable Pro features
4. Third-Party Services
We use the following third-party services to operate Nurture:
| Service | Purpose | Data Shared |
|---|---|---|
| Supabase | Database and authentication | All account and baby data described above, stored encrypted at rest |
| Anthropic (Claude) | AI reasoning -- schedule generation, chat, profile building, annotation extraction | Baby name, age, gender, recent events (last 24-48 hours), profile summary, active annotations, timezone |
| OpenAI | AI reasoning and audio transcription (Whisper) | Same baby context as above for reasoning; raw audio bytes for transcription (not retained by us after transcript is returned) |
| Apple | Authentication (Sign in with Apple) and subscription billing | User identity token, transaction lifecycle events |
| Vercel | Application hosting | API requests are processed through Vercel's serverless infrastructure |
AI and training: We do not use your data to train AI models. Anthropic and OpenAI process your data solely to generate responses for your account. Refer to Anthropic's Privacy Policy and OpenAI's API Data Usage Policy for their data handling commitments. Both providers commit to not training on API inputs.
5. Family Sharing
You may invite other people (a partner, grandparent, or caregiver) to access your baby's data by generating an invite code. When someone claims your invite code:
- They gain read and write access to your baby's events, schedule, and annotations
- They can log events on your baby's behalf
- You (the baby's owner) can revoke their access at any time
Invited caregivers do not gain access to your personal account information -- only to the shared baby's data.
6. Data Retention
- Events: Retained indefinitely until you delete your baby or individual events
- Annotations: Automatically expire based on the context (e.g., a teething annotation may expire after 48 hours; a vaccine annotation after 72 hours). Expired annotations remain in the database but are no longer surfaced in the app or sent to AI
- AI-generated profiles and schedules: Overwritten on each regeneration cycle (nightly for profiles, daily for schedules)
- Audio: Not retained. Transcribed in real time and discarded
- Invite codes: Expire after their set window if unclaimed
7. Data Deletion
You have full control over your data:
- Delete individual events: Remove any single logged event from within the app
- Delete your baby: This permanently and irreversibly deletes all data associated with your baby, including all events, annotations, AI-generated profiles, schedules, and recommendations. This action cascades to all caregivers -- they will also lose access.
- Delete your account: Contact us at the email below to request full account deletion. We will delete your profile, all associated baby data, and caregiver relationships.
Deletion is permanent. We do not maintain backups of deleted data beyond standard database replication windows (typically 7 days for disaster recovery, after which deleted data is fully purged).
8. Data Security
- All data is transmitted over HTTPS/TLS
- Database is encrypted at rest (Supabase infrastructure)
- Access is enforced through authenticated API checks and baby-sharing permissions so users only see their own baby's data (or babies they've been invited to as caregivers)
- API authentication uses JWT tokens verified against Supabase Auth on every request
- No API keys or credentials are stored on-device
9. Children's Privacy
Nurture is designed for parents and caregivers, not for use by children. We do not knowingly collect information directly from children. The baby data stored in Nurture is provided by the parent or caregiver and is used solely to support the parent's caregiving.
We comply with the Children's Online Privacy Protection Act (COPPA) and do not collect personal information from children under 13. Baby data entered by parents is considered the parent's data about their child, not data collected from the child.
10. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you and your baby
- Correct inaccurate data
- Delete your data (see Section 7)
- Export your data -- contact us to request a machine-readable export of your event history
- Object to processing -- you may stop using the app at any time and request deletion
For California residents (CCPA): We do not sell personal information. We do not share personal information for cross-context behavioral advertising.
For EU/EEA residents (GDPR): Our legal basis for processing is your consent (provided when you create an account and log data) and legitimate interest (providing the service you requested). You may withdraw consent at any time by deleting your data and ceasing use of the app.
11. International Data Transfers
Your data may be processed in the United States, where our infrastructure providers (Supabase, Vercel, Anthropic, OpenAI) operate. By using Nurture, you consent to this transfer. We rely on our providers' data protection commitments and standard contractual clauses where applicable.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you through the app or by updating the effective date at the top of this page. Continued use of Nurture after changes constitutes acceptance of the updated policy.
13. Contact Us
For questions, data requests, or concerns about this privacy policy:
Email: privacy@nurture-app.com