Privacy policy
This policy covers the myBabyNUTRI mobile app for iOS and Android and the website mybabynutri.com. Last updated: September 2026.
Who we are
myBabyNUTRI is developed and operated by myBabyNUTRI (“we”), based in Greece. We are the data controller for the personal data described here. You can reach us at info@mybabynutri.com.
The short version
- The app stores what you log about your child (feeds, sleep, growth, foods, allergens, health notes) so you can see it on any of your devices and share it with caregivers you invite.
- We never sell your data and we never show your child's data to anyone you have not invited.
- Subscriptions are handled by Apple and Google. We only receive a purchase receipt to unlock Premium.
- The free tier shows adverts; ad, analytics and attribution SDKs receive device identifiers, not your child's records.
- You can delete your account and its data at any time, in the app or by email, and single records in the app. See Delete your account.
What we collect and why
1. Account data
When you create an account we store your email address, a display name, a hashed password (or, if you sign in with Apple or Google, or signed in with Facebook in an older version, the identifier and email those providers give us) and the tokens that keep you signed in. We use this to run your account, secure it and contact you about it.
2. Child profiles and tracking records
You choose what to enter. Typically this is a child's name or nickname, date of birth, sex (needed for the correct WHO growth chart) and the records you log: breast, bottle and pumping sessions, solids and snacks, sleep, nappies, weight, length and head circumference, allergen introductions and reactions, vaccines, milestones, wellbeing entries and free-text notes, plus recipes you add and photos you attach to a meal. Some of this is health-related data. We process it only to provide the features you asked for: showing your logs, charts and history, generating your daily food suggestions and weekly insights, and exporting PDFs you request. The legal basis is the performance of our contract with you and, for health-related data, your explicit consent, which you can withdraw by deleting the data or your account.
3. Caregiver sharing
If you invite a partner or caregiver, they see the child profiles and records you share and can add records. Invitations are sent to the email address you enter. You can remove a caregiver at any time in the app.
4. AI-generated suggestions and insights
Weekly insights, some food suggestions and the timing of reminders are produced with the help of an external language-model provider (DeepSeek). For a weekly insight our server sends the child's age in months, counts and averages of the sleep and feeding you logged that week, and the names of foods eaten. To choose when to send a reminder and which one, it sends a pseudonymous summary: the child's age band (or that the baby is not born yet), recent app activity and your time zone. The child's name, your name, email address, account identifier and device identifiers are not sent; the child's name is added to the insight on our own server. The insight text is shown to you and is not stored on our server.
5. Purchases
Premium subscriptions are sold by Apple's App Store or Google Play under their terms. We receive a purchase receipt or token, which our server verifies with Apple or Google to unlock Premium and keep it in sync across your devices. We do not receive your card or bank details. We store the receipt or token and the transaction identifiers, which we also keep after an account is deleted to prevent refund fraud.
6. Analytics, crash reports and attribution
To understand how the app is used and to fix problems, we use Firebase Analytics (Google), which receives usage events with an app-instance identifier; from version 3.6.24 it receives no account identifier. We also record which adverts were shown and which purchases were made, without linking these events to your account. To measure whether our advertising campaigns bring in new users, the app includes the TikTok App Events SDK and Meta (Facebook) App Events. These SDKs receive device identifiers (such as the advertising identifier where you have allowed it), coarse usage events (for example “app opened”, “subscription started”) and technical information about the device. They do not receive your child's records. In the EEA, the UK and Switzerland they start only if you agree in the privacy choices form (More → Privacy Options lets you change it). From version 3.6.24, on iOS they start only if you allow tracking when the app asks; on Android you can reset or delete your advertising ID in system settings.
7. Advertising
The free tier shows adverts served by Google AdMob. AdMob and its partners may use device identifiers and coarse location derived from your IP address to select adverts and limit repetition. Premium removes adverts. You can opt out of personalised advertising in your device settings.
8. Push notifications
If you allow notifications, we use Firebase Cloud Messaging to deliver reminders and insights. The device token is stored with your account and removed when you sign out or delete the account.
9. Photos
Photos of your child and of you on a profile, and recipe photos, stay on your device. A photo you attach to a meal entry is uploaded to our server and deleted with the entry or the account.
10. Website
The website is static and does not set cookies of its own. Fonts are loaded from Google Fonts, which receives your IP address when the page loads. If you use the support form, we receive the name, email address and message you enter and use them only to reply.
Where your data lives
Account and tracking data is stored on servers we operate in the European Union and is encrypted in transit (TLS). Firebase, AdMob, TikTok, Meta and DeepSeek process the limited data described above under their own terms, and some of that processing happens outside the EU.
How long we keep it
Your data stays as long as your account exists. When you delete your account, everything described in sections 1 to 3, 8 and 9 is removed immediately from our live systems; residual copies can remain in server backups until those backups are deleted in our backup rotation. Our server's request logs are deleted after 30 days, and expired sign-in tokens 30 days after they expire. Purchase records and transaction identifiers may be kept to prevent refund fraud and for the period required by tax law. Usage events that are not linked to your account may be kept. Data our analytics and advertising partners received is handled under their own policies.
Children
The app is for parents and caregivers and is not directed at children. The information you enter about your child is processed on your instructions as their parent or guardian. We do not knowingly create accounts for anyone under 16.
Your rights
Under the GDPR you can ask for access to your data, correction, deletion, restriction, portability, or object to processing. Most of this you can do directly in the app; for anything else email info@mybabynutri.com. You can also complain to your national data protection authority; in Greece this is the Hellenic Data Protection Authority (dpa.gr).
Changes
When we change this policy we update the date at the top and, for significant changes, tell you in the app.
The information in the app is general educational content and is not medical advice.