Privacy policy
Your plan belongs to your family.
Last updated: 7 October 2026
The short version
- We collect only what we need to build and share your plan.
- We never sell your data, never show ads and never track you across other apps or websites.
- Gift links show only the items you choose, never your due date or answers.
- You can export or delete your data from the app at any time (You → Export my data / Delete plan).
1. Who is responsible for your data
BabyPlanned is operated by BabyPlanned, based in Spain, who is the data controller for the personal data described in this policy.
Contact for any privacy matter, including data protection requests and the Brazilian “encarregado” role: support@babyplanned.com. We are a small team and have not appointed a formal Data Protection Officer because the law does not require one for our processing; this address reaches the person responsible.
2. What data we collect
- Account data: your email address, used to sign you in with one-time codes. Codes and session tokens are stored only as cryptographic hashes; codes expire after 10 minutes and sessions after 30 days.
- Household answers: what you tell us to shape your plan, such as your due date or your baby’s birth date, home type, climate, how you travel, laundry rhythm and feeding plans, and optional names (yours or your baby’s) if you enter them.
- Plan state: the decisions you make (have, borrowed, gifted, waiting, skipped), quantities, notes, checklists and activity history.
- Family sharing: email addresses of partners or caregivers you invite, their role and whether they accepted.
- Gift lists: the items you share, and for each guest who reserves a gift, the name they give and their verified email address.
- Purchase status: whether your subscription is active and when it renews or expires. Payments are handled entirely by Apple or Google; we never receive your card details. Subscription status reaches us through RevenueCat using an anonymous app user ID.
- Technical data: server logs (IP address, time, requested address, device/browser type and error details) used for security and troubleshooting.
We do not collect location data, contacts, photos, advertising identifiers or health records. The app does not currently send push notifications; if we add them, we will store a device push token only after you allow notifications, and update this policy.
3. Sensitive data: your due date
A due date or the fact that you are expecting can reveal information about health and pregnancy, which is a special category of data under GDPR and sensitive data under the LGPD. We process it only because you choose to enter it, on the basis of your explicit consent (GDPR Article 9(2)(a); LGPD Article 11(I)). Entering a date is optional: you can use “Just planning” instead.
You can withdraw consent at any time by removing the date from your answers or deleting your plan. Withdrawal does not affect processing that already took place.
4. Why we use your data, and our legal bases
- To provide the service (build, sync and share your plan, sign you in, run family sharing and gift lists, unlock your subscription): performance of our contract with you (GDPR Art. 6(1)(b); LGPD Art. 7(V)), and explicit consent for pregnancy-related data as explained above.
- To let gift guests reserve items: our legitimate interest and the family’s in avoiding duplicate gifts, and the guest’s request (GDPR Art. 6(1)(b) and (f)).
- To send service emails (sign-in codes, invitations): performance of the contract. We do not send marketing emails without your separate consent.
- To keep the service secure and fix problems (server logs, abuse prevention): our legitimate interest in a safe, working service (GDPR Art. 6(1)(f); LGPD Art. 7(IX)).
- To comply with the law and respond to lawful requests: legal obligation (GDPR Art. 6(1)(c); LGPD Art. 7(II)).
We do not use your data for advertising, profiling or automated decisions with legal or similarly significant effects. Any AI-assisted explanation in the app works only on catalog content; it does not decide what goes into your plan.
5. Who we share data with
We use a small number of service providers (processors) who act only on our instructions under data processing agreements:
- Hetzner Online GmbH (Germany): hosting and database. Your plan data is stored in the EU.
- RevenueCat, Inc. (USA): subscription status management.
- Apple and Google: app distribution, in-app purchases and payments, as independent controllers under their own privacy policies.
- one.com (Denmark, mail.one.email): delivery of transactional emails such as sign-in codes and invitations.
- Expo / 650 Industries, Inc. (USA): app build and update tooling; if we enable push notifications, delivery of notifications.
People you choose can also see data: invited caregivers see the shared household plan, and gift guests see only the items on the gift list and whether they are reserved. We may disclose data if required by law or to protect rights and safety. We never sell or “share” personal information for cross-context behavioural advertising.
6. International transfers
Our main storage is in the EU. Where a provider processes data outside the EEA, UK or Brazil (for example in the USA), we rely on an adequacy decision such as the EU-US Data Privacy Framework where the provider is certified, or on the European Commission’s Standard Contractual Clauses (with the UK Addendum and, for Brazil, the ANPD standard clauses where applicable), plus additional safeguards. You can ask us for a copy of the relevant safeguards.
7. How long we keep data
- Unfinished drafts (answers never turned into an account): up to 30 days.
- Your plan and account: for as long as you keep them. Deleting your plan in the app removes it from our live systems immediately.
- Backups: deleted data disappears from rolling backups within 30 days.
- Gift links: expire after the period you choose (up to 30 days) and can be revoked at any time; guest details are deleted with the household.
- Invitations: expire after 7 days if not accepted.
- Server logs: up to 30 days, unless needed to investigate a security incident.
- Sign-in codes: 10 minutes. Sessions: 30 days.
8. Your rights
Depending on where you live, you have the right to access your data, correct it, delete it, receive it in a portable format, restrict or object to processing, and withdraw consent at any time. Brazilian residents also have the rights in LGPD Article 18, including confirmation of processing, anonymisation and information about sharing. California residents have the right to know, delete and correct, and the right not to be discriminated against for exercising these rights; we do not sell or share personal information.
Most rights are self-service in the app: You → Export my data gives you a copy in a machine-readable format, and You → Delete plan erases your household. For anything else, email support@babyplanned.com from the address linked to your plan. We reply within one month (15 days for LGPD confirmation requests) and may need to verify your identity.
Instructions for deletion are also on our delete account page.
9. Complaints
We’d like to help first: support@babyplanned.com. You can also complain to a supervisory authority, in particular where you live or work:
- Spain: Agencia Española de Protección de Datos (AEPD), aepd.es
- United Kingdom: Information Commissioner’s Office (ICO), ico.org.uk
- Brazil: Autoridade Nacional de Proteção de Dados (ANPD), gov.br/anpd
- Other EU countries: your local data protection authority
10. Children
BabyPlanned is for adults (18+) preparing for or caring for a baby. It is not directed at children and we do not knowingly collect data from children. Information about a baby (such as a birth date or optional name) is provided by parents or caregivers to plan their care. If you believe a child has given us data, contact us and we will delete it.
11. Cookies and tracking
This website uses no advertising or analytics cookies and no third-party trackers. We use only what is strictly necessary to make it work (for example, keeping you verified while reserving a gift), which does not require consent. The app does not use Apple’s App Tracking Transparency because it does not track you, and it contains no advertising SDKs.
12. Security
Data is encrypted in transit (HTTPS). Sign-in codes and sessions are stored as hashes, access to production systems is restricted, and gift links contain unguessable tokens that expire. No system is perfectly secure; if a breach affects your data, we will notify you and the authorities as the law requires.
13. Changes
We will update this policy when our practices change and change the date above. If the change is significant, we will tell you in the app or by email before it applies.
14. Contact
BabyPlanned · support@babyplanned.com