Privacy Policy
Effective Date: 30 July 2026
1. INTRODUCTION, SCOPE AND DATA CONTROLLER
[Growbaby] (the "Company", "We", or "Our App") is a platform offering caregivers of babies aged 0-3 cry analysis, soothing sounds, development tracking, an AI-powered parenting assistant, and media (collage/growth journal) tools. Our App is intended for parents; babies' data is processed with the parents' explicit consent and under their control. This document details how we collect, process, and protect your and your child's personal data and sensitive data when you use our Services.
1.1. PRIVACY AND DATA USE STATEMENT: GrowBaby uses your personal health data, including your baby's development, height, weight, cry measurements, sleep patterns, or health conditions (we call this "Health Data"), solely to provide the core functioning of the service we offer. Identity-free, voice-derived research measurements may be used solely for product development within the research pipeline described in Section 4.
1.2. Protection of Health Data: No personal data belonging to you or your baby is sold or shared with third parties for advertising, retargeting, or data-mining purposes. No advertising network is integrated into the App. Operational data is shared only with the service providers listed in Sections 5 and 7, within a limited sub-processor relationship for the purpose of delivering the service.
1.3. Analytics, Attribution and App Performance: To measure the App's operational performance, manage paywall processes, optimize the user experience, resolve technical errors, and analyze the effectiveness of our advertising campaigns (attribution), we use third-party analytics, attribution, subscription, and crash-reporting SDK infrastructures (Mixpanel, Airbridge, RevenueCat, Sentry). Details of these tools, their permission mechanisms, and preference management are described in Section 7.
2. CHILDREN'S PRIVACY AND VERIFIABLE PARENTAL CONSENT (COPPA & GDPR ART. 8)
By its very function, our App processes data belonging to children under 13 (particularly ages 0-3). Under the Federal Trade Commission's (FTC) COPPA rules (16 CFR Part 312), our App is closed to independent use by children and operates entirely under parental control; data about the child is entered by the parent into the parent's own account.
Child Data Collected and Processed: By the nature of the services it provides (the Growy AI assistant, development tracking, and the soothing sound engine), our App securely stores in a live database (Supabase) developmental data about your child entered manually by the parent in the profile area, such as date of birth/gestational week, sex, health conditions, and sleep and feeding patterns.
Provided, however, that audio (cry acoustic features) and visual content (skin analysis or local collage/journal photos) processed via the device microphone or camera in the AI assistant and cry-analysis flows is NOT STORED and NOT COLLECTED as a persistent media/audio file on our Company's servers, as detailed in Sections 4 and 8 of this Policy.
Photos you upload to the chatbot interface for Skin Analysis are not permanently stored by our Company on its own servers. To technically perform the analysis, these images are transmitted to the sub-processor's servers subject to the integrated AI provider's (OpenAI) own published API data-use and security policies. Under that provider's current public commitments, data transmitted via the API is not used to train AI models and is subject to temporary retention periods (up to 30 days) applied by the provider for cybersecurity/abuse monitoring. The user acknowledges that these processes are carried out within the third-party provider's own privacy policies and technical infrastructure limits, that our Company has no de facto supervisory authority over the external provider's internal systems, and expressly consents to the processing of images under these conditions so that the analysis can be performed.
Verifiable Parental Consent (VPC): Under COPPA Section 312.5, before allowing you to upload any data about your child to our system, we must verify that you are the legal parent or guardian. This verification is obtained through your active checking of the consent box on the registration screen bearing the statement: "I am the legal parent/guardian of the child I am registering, and I give my explicit consent to the processing of my child's development and health information as described in the Explicit Consent text, for the provision of the service."
Digital Declaration, Self-Verification and Release of Liability: Registering on the platform, creating a user account, and actively checking the parental consent box on the registration screen conclusively establish that: (i) you have provided our Company with a legally valid 'Verifiable Parental Consent' under applicable law, (ii) you are the legal parent, guardian, or custodial authority of the child(ren) whose data is processed, and (iii) this act constitutes a 'Digital Self-Verification and Electronic Declaration' performed by you. Our Company relies on this digital consent in good faith and cannot be held obligated to investigate its accuracy. All legal, administrative, financial, and criminal liability arising from identity, age, or custody declarations submitted by checking the consent box that prove untrue, misleading, or erroneous rests exclusively with the user. The Company reserves the right of full recourse against the user for any direct or indirect damages, penalties, and compensation that our Company, our affiliates, or our infrastructure providers may incur due to the user's false or negligent declaration.
Parental Rights and Withdrawal: Parents may at any time view their child's profile and records in-app, request a copy of the records via support@growbaby.ai, request the complete deletion of this data, and refuse further data collection. You can remove Growy memory records, all chatbot data, and the growth journal photos on your device in bulk from the Profile > Manage My Data screen; you can manage your analytics and research preferences from the switches on the same screen (see §7.4); and you can delete your account at any time from the Profile > Delete Account menu. If you revoke your device's microphone permission, the cry-analysis feature will not function. No data about your child may be used for marketing, profiling, or advertising purposes. The Company applies reasonable security procedures to facilitate the exercise of these parental rights.
3. CATEGORIES OF PERSONAL DATA WE COLLECT, PURPOSES OF PROCESSING AND LEGAL BASES
The table below details, for transparency purposes, the categories of data we process, the purposes of processing, the legal bases we rely on (including the bases under GDPR Articles 6 and 9), and retention principles, with the concepts of U.S. state laws (CCPA/CPRA) also taken into account. Given the nature of our App, the child health inputs we process qualify as "Special Categories of Personal Data" under the GDPR. The data categories have been prepared with consistency with Apple App Store privacy disclosures and Google Play Data Safety forms in mind.
Data Category
Example Data Types
Purposes of Processing
Legal Basis
Retention
>
A. Identifiers
Caregiver first and last name, baby's name, email address, account identifier (User ID), transaction history, IP address, device identifier. (Account passwords are stored as hashes in the authentication provider's own secure store and never reach the Company.)
Account management, security verification, user support, and fraud prevention.
Performance of a Contract (Art. 6/1-b) & Business Necessity.
Retained for as long as the account remains active. Upon account deletion, deleted immediately from our primary systems. In cases of fraud, abuse, or legal dispute, limited records may be retained for the period required by applicable law.
>
B. Voice-Derived Acoustic Features (Sensitive Data)
Frequency (Hz) and acoustic feature values resolved in real time from the baby's cry via the device microphone. (The system never creates, stores, or transmits an audio file at any stage; raw audio never leaves the device.)
Computing the physical characteristics of the cry in real time via on-device AI (Edge AI) to trigger the appropriate soothing sound engine. (No biometric identification is performed; no voiceprint is generated.)
Explicit Consent (Art. 9/2-a) + Parental Consent.
Raw audio and audio recordings never leave the device; instantaneous features are processed on-device. While the "Contribute soothing research" preference is on (this preference is on by default and can be permanently turned off), identity-free numerical measurements derived from sound are transmitted to a separate research database (see §7.2).
>
C. Consumer Health and Development Data (Sensitive PI)
User inputs regarding the baby's developmental week, health conditions, allergies, feeding, and sleep patterns. (The system performs no medical triage or history-taking.)
Maintaining continuity in chatbot conversations and building a personalized basic context. This context (including the child profile and health conditions) is transmitted to the OpenAI infrastructure via a secure API channel during response generation (see §7).
Explicit Consent (Art. 9/2-a) + COPPA + MHMDA (Explicit Consent).
Retained for as long as the account remains active or until the user deletes all chatbot data from the Profile > Manage My Data screen. The content of a deleted record is permanently destroyed immediately; only a content-free marker remains that prevents the same information from being re-learned from your chat history. Upon account deletion, everything is destroyed.
>
D. Visual Data
Baby photos taken or selected via in-app camera or gallery access, growth collages, and images uploaded to the Growy Chatbot Skin Analysis module. (On Android, photo selection from the gallery occurs through the operating system's own photo picker; only the file you select is provided to the app, and no read permission for your entire photo library is requested.)
1. Collage/Growth Journal: creating keepsake content locally on the device. 2. Skin Analysis: obtaining an instant, general AI interpretation of the photo via a third-party AI provider (OpenAI API).
Performance of a Contract (Art. 6/1-b) + Explicit Consent (Art. 9/2-a) + Parental Consent.
1. Collage/journal photos are never transmitted to Company servers at any stage; they remain entirely local on the device and are not included in Company backups. 2. Skin Analysis images are not stored by the Company and are never written to disk; they are transmitted to the OpenAI API for instant analysis. If the user saves or reports an analysis, only the AI-generated analysis text is stored; the photo itself is never stored.
>
E. Internet / Network Activity (Logs and Usage)
In-app interaction events, error logs, and de-identified statistical data derived from matching cry measurements with effective sound layers under the "Soothing Sounds" feature.
App optimization, feature development (analyzing which sound works for which cry profile), and technical security.
Legitimate Interest (Art. 6/1-f) & Business Necessity.
Operational data is retained for the life of the account. Research measurements are held in a separate research database in rows containing no identity column; they are de-identified rather than strictly anonymous (see §6 and §7.2).
>
F. Financial Information
Transaction records and subscription history generated by in-app purchases/subscriptions. (Credit card information never reaches the Company; payments are processed through the Apple App Store and Google Play Billing, which hold the card data.)
Executing subscription transactions and revenue tracking.
Performance of a Contract (Art. 6/1-b) + Legal Obligation.
Retained for the duration of the subscription. Upon account deletion, subscription event records are retained with their direct link to the personal account severed. Records subject to statutory retention obligations may be retained for the period required by applicable law.
>
G. Communications, Location, Inputs and Outputs
Communication messages, IP-derived approximate (city-level) location, questions asked to the Chatbot (Prompts), responses received (Outputs), survey responses, app ratings, and chat feedback.
Improving service quality, resolving support requests, providing conversation continuity and basic context, proactive system security, Trust & Safety monitoring, and building a research pool stripped of user identity.
Legitimate Interest (Art. 6/1-f) + CPRA Sensitive Data Consent.
1. Live system data is retained in pseudonymized form for the life of the account; the user may delete their chatbot history in-app at any time. 2. Transfers to the research pool contain no user identity; however, because network logs (IP) and timestamps are technically processed by the infrastructure, the data is de-identified rather than strictly anonymous. 3. Support messages and error reports may be retained for the period necessary to exercise legal defense rights. (The Trust & Safety retention exception is reserved.)
>
H. Marketing, Advertising and Attribution Data
On iOS, the device advertising identifier (IDFA), only if the user expressly grants permission on the App Tracking Transparency (ATT) prompt; on Android, the advertising identifier (GAID), subject to device-level controls. Where permission is granted, this advertising identifier is shared with our attribution provider, Airbridge, to measure which ad or link the installation came from. Also: clicked ad channel/campaign information, installation source, the attribution provider's own device-matching identifiers, and subscription/purchase conversion events.
Measuring which advertising campaigns drive installs, optimizing marketing budgets, preventing fraudulent installs (ad fraud), and analyzing subscription conversions.
ATT Permission on iOS (Apple framework) + Explicit Consent / Legitimate Interest (for measurement not involving the advertising identifier).
Retained for as long as the account remains active. If ATT permission is not granted or is withdrawn, no processing based on the advertising identifier takes place; the user may also completely stop analytics and attribution data collection via the Profile > Manage My Data > Share usage analytics switch (see §7.4).
>
4. ARTIFICIAL INTELLIGENCE (AI) SAFEGUARDS AND PROCESSING FLOWS
Our data-processing architecture, in line with Apple App Store and Google Play Store privacy guidelines and our AI provider's (OpenAI) API standards, is as follows:
Cry Analysis, Feature Extraction and Recording Prohibition: Our App never records, stores, or transmits the baby's crying sounds to its servers as a media/audio file during analysis; raw audio never leaves the device. The system only extracts the physical features of the instantaneous sound input received via the microphone (for example, acoustic frequency values / Hz) on the device (feature extraction), and the sound engine plays the appropriate layers based on these features. While the "Contribute soothing research" preference is on (it is on by default and can be permanently turned off in Manage My Data), numerical measurement rows containing no identity column, showing which sounds proved effective for which measurement profile, are transmitted to a separate research database. This data is de-identified rather than strictly anonymous (see §6 and §7.2).
Chatbot, Conversation Memory and Triage Prohibition: Basic data you voluntarily enter in the health and development area is stored in the database for the purpose of remembering conversation context (basic conversation memory) and is transmitted to the OpenAI infrastructure as child-profile context during response generation (see §7). No medical triage, in-depth history-taking, or diagnostic operation of any kind is performed through our App. Users can remove the memory records created about their children and all chatbot data in bulk from the Profile > Manage My Data screen; the content of a deleted record is permanently destroyed, and only a content-free marker remains that prevents the same information from being re-learned from your chat history. Conversation memory is not used for ad targeting or marketing purposes and is not shared with any third party for those purposes.
Media Generation, Skin Analysis and Third-Party API Limits: The in-app photo capture, gallery access, and collage/growth journal features operate exclusively locally on the user's own mobile device (On-Device Processing), and these images are not transmitted to Company servers. On Android, photo selection from the gallery occurs through the operating system's own photo picker; only the file you select is provided to the app, and no read permission for your entire photo library is requested. However, if the user uses the 'Skin Analysis' module via the Growy AI Assistant and uploads a photo of the baby's skin, that image is transmitted to external servers, without being stored by our Company on its own servers, subject to the AI provider's (OpenAI) own published API data-use policies, so that the analysis can be performed. In this transmission, only the baby's age in months is sent along with the image; no name, date of birth, user ID, or account identifier is included in the request. Under the provider's current commitments, data transmitted via the API is not used for model training and is retained for a maximum of 30 days for abuse monitoring, then deleted. The user acknowledges that our Company has no de facto supervisory authority over the external provider's internal systems and expressly consents to the processing of images under these conditions so that the analysis can be performed.
Scientific Studies and De-Identified Data: We may convert your personal data and your child's data into de-identified statistical data by severing the direct identity link to you or your child. We may use this data to conduct scientific research and improve our product. We declare that we will maintain this de-identified information in that form and that users have the right to turn off their data contribution to this research flow at any time from within the app (via the Profile > Manage My Data > Contribute soothing research switch). This contribution is on by default.
Disclaimer Regarding AI Accuracy (A Note About Accuracy): Our AI services (chatbot, cry analysis, etc.) generate results by predicting words and sound patterns; the results produced are probabilistic estimates and may not always be entirely factually accurate. These outputs do not constitute definitive medical diagnosis or advice and are intended for support purposes only; for every significant matter concerning your child's health, you must consult a healthcare professional (such as a pediatrician), and you must seek immediate medical attention in an emergency. Registering on the platform and beginning to use the Services means you fully understand and accept that all outputs provided by AI-based services are probabilistic estimates, do not guarantee absolute accuracy, and in no way constitute medical advice, examination, diagnosis, or treatment. You declare that, to the maximum extent permitted by applicable mandatory law, our Company, our affiliates, and our infrastructure providers cannot be held legally liable for any direct, indirect, material, or moral damage arising from any action, medical practice, or omission you undertake in reliance on these outputs, and that you accept using the platform with knowledge of these risks.
Trust & Safety Monitoring: To detect and prevent misuse of our systems, unlawful activity (in particular child abuse or exploitation), and violations of our Terms of Service, we may review your Inputs (Prompts) and Outputs through automated security tools or our authorized personnel. By registering on the platform and accepting this text, you acknowledge that transparent notice of these security and audit activities has been provided to you and that you consent to monitoring and review operations within this scope.
No Automated Decision-Making with Legal Effects: The cry analysis and Chatbot suggestions offered by our App are ABSOLUTELY NOT used as "Automated Decision-Making" or "Profiling" tools producing legal effects concerning your baby's health or concerning you (for example, insurance coverage, employment, or official medical diagnosis). Our system is intended for advice and support purposes only.
5. DATA SHARING AND PROHIBITION ON SALE
Express Statement: [Growbaby] does not share your or your child's Personal Data or Sensitive Health Data with third parties for commercial or advertising purposes, does not sell it under any circumstances (Do Not Sell), and does not transfer it to third parties for Cross-Context Behavioral Advertising (Do Not Share). Your data is shared exclusively with the following 'Service Providers' and legal recipient categories, within a technical sub-processor relationship, so that the in-app Services can be operationally delivered:
Cloud Infrastructure Providers: Supabase cloud storage servers for encrypted data storage, and Railway infrastructure for the API layer.
AI Service Providers: For chatbot functions, chat texts and child-profile context are transmitted to the OpenAI language-model infrastructure via secure API channels; no user ID, account, or session identifier is included in this transmission.
Analytics, Payment and Attribution Infrastructures: Third-party SDK infrastructures (Mixpanel, Airbridge, RevenueCat, Sentry) are used to measure app performance, manage paywall processes, and run attribution analyses. Data transmitted to these services is processed under the relevant provider's Data Processing Addendum (DPA) and privacy policies; details and preference management are in Section 7.
Affiliates: We may share your personal data, in accordance with this Policy, with our affiliates that control [Growbaby], are controlled by it, or are under common control with it.
Government Authorities: We may share information in good faith with public authorities or law enforcement to comply with a legal obligation, prevent fraud or misuse of our services, and prevent serious harm to you or others.
California Shine the Light Law: Under California Civil Code § 1798.83, our users residing in California have the right to inquire whether we share their personal data with third parties for direct-marketing purposes.
Business Transfers: If [Growbaby] enters into a commercial transaction such as a sale of all or part of its assets, a merger, financing, acquisition, or bankruptcy proceedings, personal data belonging to our users and their children may be transferred to the relevant third parties, provided the security standards of this Privacy Policy and applicable laws are observed.
Third-Party Integrations and Social Media Sharing: When you share media content you created through our App on third-party platforms (Instagram, TikTok, WhatsApp, etc.) of your own volition, the privacy and security of that data will be governed entirely by the relevant third-party platform's privacy policies. [Growbaby] accepts no control over or responsibility for data you take outside its own systems.
6. REGIONAL PRIVACY RIGHTS AND ADDITIONAL NOTICES
Technical research measurements collected to gauge system performance are transferred to a separate research database; this transfer contains no user identity, but because network logs (IP) and timestamps are technically processed by the infrastructure, the data has the status of a de-identified statistical pool rather than strictly anonymous data.
A. U.S. Consumer Rights (Under CCPA/CPRA)
If you reside in California (or in states granting similar rights, such as Virginia, Colorado, Utah, or Connecticut), you have the following rights over data held about you:
Right to Know: To request a report of what data is collected about you, its categories, and the purposes of processing.
Right to Delete: To request deletion of data about you and your baby in our systems. Deletion occurs immediately in our primary systems; backup copies expire automatically within our infrastructure provider's backup cycle (see §8).
Right to Correct: To correct information that is inaccurate or incomplete.
Right to Limit Use of Sensitive PI: To request that your child's health and development data be used only at the minimum level strictly necessary to use the App. You may at any time turn off processing activities that are not strictly necessary for the provision of the service (analytics/attribution and the sound-research contribution) using the switches on the Profile > Manage My Data screen (see §7.4).
Right to Non-Discrimination: To face no penalty in service quality or price for exercising these rights.
Authorized Agent: California residents may designate a formally authorized agent to exercise their rights. Before requests from authorized agents are processed, written and signed proof that the consumer granted this authority must be provided.
Right to Appeal: Residents of Virginia, Colorado, Connecticut, and other relevant states have the right to appeal a denial of their request by writing to support@growbaby.ai following notice of the decision.
Submission Channels and Response Time: To exercise your rights, you may use the relevant in-app settings or reach us at support@growbaby.ai. Your requests will be answered within 45 days at the latest. Users can directly and instantly remove their photos and chatbot history themselves via the in-app Profile > Manage My Data screen; this operation immediately destroys chatbot data from our live systems. Because growth journal photos are kept only on your device, their deletion takes place on your device; and because skin analysis photos are never stored on our servers, there is no additional photo to remove from a server.
B. Additional State-Specific Notices (U.S.)
The Growbaby app's soothing sound and cry-analysis feature uses artificial intelligence technology that runs entirely on-device (edge). This technology:
NEVER RECORDS audio files and NEVER TRANSMITS them to Company servers;
DOES NOT CREATE a voiceprint or any individual biometric identifier;
Processes only instantaneous acoustic frequency features (sound waveform parameters in Hz);
While the "Contribute soothing research" preference is on, voice-derived numerical measurements containing no direct identity link are transferred to the R&D pool as de-identified statistical data (see the §6 introduction and §7.2);
Under no circumstances is biometric data suitable for individual identification generated, matched, or stored.
Washington My Health My Data Act (MHMDA) and Nevada Health Privacy Laws: Health and symptom data you type into the Chatbot is "Consumer Health Data" and is ABSOLUTELY NOT sold. Furthermore, using geofencing technologies to serve you targeted advertising or track you around any hospital or clinic is strictly prohibited; the App does not collect precise location data and does not request location permission. [Growbaby] uses Sensitive Personal Information only for limited purposes permitted under CCPA Regulations § 7027(m), such as 'providing the Services and ensuring security', and does not process this data for the purpose of inferring characteristics about consumers.
C. European (EEA) and United Kingdom (UK) Data Subject Rights (GDPR & UK GDPR)
As residents of the European Economic Area and the United Kingdom, you have the following legal rights over your data:
Access and Portability: You may request a copy of your data via support@growbaby.ai.
Rectification and Erasure (Right to Be Forgotten): You may correct inaccurate data or, by deleting your account, have your data deleted immediately from our primary systems; backup copies expire automatically within our infrastructure provider's backup cycle.
Objection and Restriction: Your right to object to processing based on our legitimate interest is reserved.
Complaint: If you are not satisfied with our practices, you may lodge a complaint with the Data Protection Authority in your own country (e.g., CNIL in France, BfDI in Germany, ICO in the United Kingdom).
7. INTERNATIONAL DATA TRANSFERS AND CROSS-BORDER PROCESSING
7.1. [Growbaby] operates globally. You expressly acknowledge the following regarding the processing of your data:
Data Controller and Center of Operations: Our parent company, the data controller, is established in Türkiye. The general administration of our Services, software development processes, central technical support activities, and customer relations are carried out by our head office and technical teams in Türkiye.
Supabase Database: Your personal data is stored on secure cloud servers provided by Supabase as the primary database infrastructure, located within the European Union (Frankfurt, Germany - eu-central-1). Our infrastructure applies provider-level storage encryption, TLS transport encryption, and Row Level Security (RLS) protocols.
Authentication (Sign in with Apple & Google Sign-in): Third-party authentication services, Sign in with Apple and Google Sign-in, are used for account creation and login. The related authentication operations take place within Apple's and Google's corporate privacy policies and security infrastructures, respectively. If you use the "Hide My Email" option with Sign in with Apple, only the alias email address generated by Apple reaches the Company.
OpenAI API: Chat texts, child-profile context (including name, age/date of birth, sex, allergies, and health conditions), and skin-analysis images are transmitted to the OpenAI infrastructure (USA) for response generation. Inputs are not used for model training by default and are retained for a maximum of 30 days for abuse monitoring, then deleted.
RevenueCat & Airbridge: Data-processing flows are run over system identifiers for subscription management and campaign attribution measurement (see §7.3 and §7.4).
Sentry: In the Sentry integration used for app crash and error reporting, users' plain identities are not collected; fields containing email, password, tokens, and child name/ID are masked ([redacted]) before events are sent, and only anonymized error logs and hashed values (e.g., child_id_hash) are processed.
International Data Transfers and Legal Safeguards: Although storage of your data on servers within the EU is the principal arrangement, due to our central operations in Türkiye, OpenAI (USA), and the technical architectures of global infrastructure providers, your data may be transferred outside your country of residence, the European Economic Area, or Türkiye. These international transfers are carried out with the necessary technical and administrative security measures in place, within the framework of applicable legal regulations, Standard Contractual Clauses (SCCs), and the relevant service providers' data processing agreements (DPAs).
7.2. SERVER, DATABASE AND DATA-FLOW INFRASTRUCTURE
The Growbaby app's technical infrastructure is built on secure cloud servers, an API layer, and external data-processing services:
Primary Database (Supabase - Prod): The primary database project where your personal and operational data resides is hosted on Supabase infrastructure located within the European Union (Frankfurt, Germany - eu-central-1).
API Server (Railway): The App's data gateway and API layer runs on Railway infrastructure in the European Union (Amsterdam, Netherlands) region.
Research Database (Separate Supabase Project): The research pipeline collecting de-identified statistical measurements derived from sound is hosted in a Supabase project separate from the primary project, in the European Union (Ireland - eu-west-1) region. Although the feature rows collected on this pipeline contain no direct user identity, temporary network metadata (IP addresses and transaction timestamps) is technically processed by the system for infrastructure security and transport; for this reason, the data is de-identified rather than strictly anonymous.
Integrations and Services Receiving Data: To ensure service quality, subscriptions, notifications, and stability, the following services receive data within a limited scope:
OpenAI API: Provider: OpenAI, L.L.C. (USA). Data received: chat texts, child-profile context, and skin-analysis photos uploaded by the user (transmitted directly to the API; NOT STORED on Growbaby servers). Purpose: AI-powered response generation and skin-condition assessment. Privacy Policy: https://openai.com/policies/privacy-policy
Mixpanel: Provider: Mixpanel Inc. Data received: in-app activity events, session and feature-usage statistics (only events we define; autocapture is disabled). The identifier is transmitted as a hashed (djb2) value, never raw, and events are sent to Mixpanel's EU endpoint (api-eu.mixpanel.com). Purpose: user behavior analysis and product development. Privacy Policy: https://mixpanel.com/legal/privacy-policy
Airbridge & RevenueCat: Data is processed over system identifiers for campaign attribution measurement (Airbridge) and subscription management (RevenueCat) (see §7.3 and §7.4).
Sentry: Provider: Functional Software Inc. Data received: app crash reports, error logs, device-state information (personal fields are masked before transmission). Purpose: app stability monitoring and bug fixing. Privacy Policy: https://sentry.io/privacy
Expo & Resend: The related communication and notification data is processed in delivering system notifications (Expo push) and sending transactional emails (Resend).
7.3. THIRD-PARTY SDKs AND DATA-SHARING TRANSPARENCY
To improve service quality, optimize the user experience, manage subscription processes, and measure marketing attribution performance, the Growbaby app uses exclusively the following software development kits (SDKs) within the App:
a) RevenueCat (Subscription Management): Subscription statuses and system identifiers are processed to manage in-app purchases and subscription flows. RevenueCat is not an attribution or analytics tool; it operates as a mandatory component under performance of the contract.
b) Mixpanel (Analytics and Engagement): In-app activity data is processed for user behavior analysis, session durations, and product development; data is processed via hashed values (djb2), not raw identifiers.
c) Airbridge (Attribution and Campaign Measurement): To measure marketing campaign performance and installation attributions, attribution data (installation source and campaign information), the app user identifier, approximate (city-level) location derived from the IP address, and the provider's own device-matching identifier are processed. On iOS, the advertising identifier (IDFA) is read only if the user grants permission on the App Tracking Transparency (ATT) prompt, and is then shared with Airbridge (see §7.4).
d) Sentry (Crash Reporting): Used for app stability and crash reporting (see §7.2).
Third-party SDK integrations within our App are operated with regard to the user's operating-system-level permission preferences (including the ATT framework on iOS). The data categories collected by the App itself are declared in the privacy manifest required by Apple and in store privacy disclosures; third-party SDKs' own manifest declarations are the responsibility of the relevant providers.
7.4. AD ATTRIBUTION DATA, TRACKING PERMISSION (ATT) AND CONSENT MANAGEMENT
The Growbaby app uses Airbridge (attribution) and Mixpanel (product analytics) infrastructures to measure the effectiveness of marketing campaigns, analyze subscription conversions, and perform attribution measurements. Subscription management runs through RevenueCat and is not a tracking/analytics activity.
In-App and Operating-System-Level Preference Management (Opt-Out): Our users can easily manage their research and data-sharing preferences from within the app at any time. In this context:
iOS App Tracking Transparency (ATT) and the Advertising Identifier (IDFA): On iOS devices, the app displays a tracking permission prompt under Apple's App Tracking Transparency (ATT) framework. Your device's advertising identifier (IDFA) is read only if you expressly grant permission on this prompt, and is shared with our attribution provider (Airbridge) to measure which ad or link the installation came from. If you do not grant permission, or later withdraw it from iOS Settings > Privacy & Security > Tracking, the app does not access your advertising identifier and no tracking based on the advertising identifier takes place.
Product Analytics and Attribution Preference (Share usage analytics): When you turn off Profile > Manage My Data > Share usage analytics in the app, both product analytics (Mixpanel) and the attribution SDK (Airbridge) completely stop collecting data. This switch operates independently of the ATT preference: ATT controls only access to the advertising identifier, while this switch controls data collection by the analytics and attribution SDKs.
Sound Research Contribution Preference (Contribute soothing research): This switch is a separate preference mechanism controlling the transmission of identity-free, voice-derived numerical research measurements to the separate research database, and can be managed at any time from Profile > Manage My Data > Contribute soothing research. This contribution is on by default and can be permanently turned off at any time. It has no connection to advertising or analytics.
Operating-System-Level Controls: For iOS devices: you can turn off "Allow Apps to Request to Track" or revoke permission for this specific app from Settings > Privacy & Security > Tracking (Apple ATT Framework). For Android devices: you can disable ads personalization and reset or delete the advertising identifier (GAID) via the privacy or Google ads options in your device settings.
The user is also expressly informed that:
Declining or withdrawing tracking permission does not mean that all data processing ends. Even in that case, third-party attribution and analytics SDK providers may perform limited measurement and probabilistic attribution within their own technological infrastructures, without using the advertising identifier, by using their own device/installation identifiers together with non-advertising-identifier parameters such as IP address, device configuration, and timestamps.
These server-side processing activities are carried out entirely within, and under the responsibility of, the relevant SDK provider's own privacy policies; Snaiper Teknoloji A.Ş. has no direct control over these activities. The Company is obligated not to access the advertising identifier unless permission is granted, and to configure the integrated SDKs in accordance with the user's permission status.
The Profile > Manage My Data > Share usage analytics switch can be used to stop all in-app analytics and attribution data collection; additional operating-system-level measures (resetting the advertising identifier, using a VPN, etc.) may also be taken to limit measurement.
8. DATA SECURITY AND RETENTION PERIODS (SECURITY STANDARDS)
Given the seriousness of the user and child data it hosts, Snaiper Teknoloji A.Ş. takes industry-standard technical and administrative security practices and best practices as its reference in data security. Our Company is not a "covered entity" or "business associate" under the U.S. Health Insurance Portability and Accountability Act (HIPAA); however, it adopts strict security measures in data security. In this context, the following measures are applied in our infrastructure:
Encryption and Infrastructure Security: Your personal data is processed through recognized and trusted cloud and infrastructure providers. All of your data is encrypted with TLS in transit (the minimum-version policy is managed by the infrastructure providers) and protected at rest by provider-level encryption mechanisms. On the device, session tokens and sensitive local state are stored encrypted in the operating system's secure store (iOS Keychain / Android keystore). Our data-security architecture includes audit logs for critical operations, and authentication and session-security protocols preventing unauthorized access. The entire API surface is protected on a default-deny basis; unauthenticated requests are rejected.
Pseudonymization, Access Control and Isolation: Operational processes such as analytics logs and usage data are processed not under your real names but via system-assigned unique user identifiers and hashed values (pseudonymization); this data has the legal status of 'pseudonymized data'. At the database level, multi-tenant isolation is established via Row Level Security (RLS) on a default-deny basis: one family can under no circumstances see another family's records. Access to data that can be re-linked to identity is limited to authorized technical personnel, solely for user support, debugging, or legal necessity.
Security Disclaimer: Although we make industry-standard reasonable efforts to protect your personal information, no data transmission or storage system over the internet can be guaranteed 100% secure. You accept that security measures are by nature circumventable, that we do not control the internet, and the risk that unauthorized persons may use malicious software to access systems. In the event of unauthorized disclosure of your data, to the maximum extent permitted by applicable mandatory law, our Company bears no strict (no-fault) liability. You are responsible for the security of your password and the physical security of your device.
Retention: The baby development information you upload, your account data, and your chatbot history are stored on our servers for as long as you keep your account active. When you delete your account, your data is deleted immediately from our primary database systems. Backup copies expire automatically within our infrastructure provider's (Supabase) own backup cycle and are kept encrypted and inaccessible during that period. Collage/growth journal photos are never sent to our servers or backup systems at any stage and remain on the local device. Photos uploaded to the Skin Analysis module within the Growy Chatbot are not stored by our Company in any system and are never written to disk; therefore no photo data exists in our backups. If the user saves or reports a skin analysis, only the AI-generated analysis text is stored; the photo itself is never stored.
Account Deletion, Its Scope and Exceptions: You can delete your account instantly from the in-app Profile > Delete Account menu, or request deletion via the form at growbaby.ai/delete-account or via support@growbaby.ai. Deletion occurs immediately and irreversibly in our primary systems. By way of exception: (i) in shared family structures, the family record and shared records are transferred to the other caregiver to protect that caregiver's rights and data; (ii) subscription event records are retained with their direct link to the personal account severed; (iii) subscription and attribution service providers (RevenueCat, Airbridge) may continue to hold user-identifier records in their own systems subject to their own retention policies; and (iv) copies in the backup infrastructure expire within their own cycle. Deleting your account does not automatically cancel a subscription running through the App Store or Google Play; you must separately cancel your subscription in the relevant store's subscription settings.
Error Reports and Security Notices: Error reports (crash reports), technical support requests, or security notices you send us may be retained for the period necessary to ensure system security and to exercise our legal defense rights.
Legal and Security Exceptions (Retention Exceptions): Even if you request deletion of your account, we may lawfully retain a limited set of your personal data for the periods required by applicable law, for legitimate security and legal reasons such as addressing fraud, abuse, or violations of our policies, maintaining financial transaction records, or complying with legal/regulatory obligations (subpoenas, court orders, etc.).
Trust & Safety Retention Exception: [Growbaby] reserves the right, within the legitimate-interest exceptions recognized by applicable privacy laws, to retain your Inputs (Prompts) and Outputs for an extremely limited period in a secure and isolated environment "solely for Trust & Safety purposes", in order to investigate misuse of the system, resolve security violations, and provide information to law enforcement, even if you have exercised your general right to deletion.
By creating an account on this platform and accepting this policy, you acknowledge that no 100% secure data transmission or storage system exists in the internet environment and that you knowingly accept third-party risks such as cyberattacks. The user accepts that, to the maximum extent permitted by applicable mandatory law, our Company bears no strict (no-fault) liability in the event of unauthorized disclosure of data or a cyberattack.
The Growbaby app's cry analysis and soothing sound engine run entirely locally on the user's own mobile device (on-device / edge AI). At no stage does the App record, store, or transmit a raw audio file to its servers. The system creates no persistent biometric identifier suitable for individual identification within the scope of BIPA (740 ILCS 14/10) or similar legal regulations.
Instantaneous sound features are processed on the device; only while the "Contribute soothing research" preference is on are identity-free numerical measurements transmitted to the separate research database (see §7.2).
Additional Notice for Illinois (U.S.) Residents: By using the App and activating the cry-analysis feature, the user expressly acknowledges and declares that the App's audio-analysis architecture operates within the technical principles set out above, that no biometric data retained within the meaning of BIPA is generated, and that these processing flows comply with the law.
9. MOBILE SDKs, TRACKING PREFERENCES AND GLOBAL PRIVACY CONTROL (GPC)
To measure our App's operational and technical performance, manage in-app purchase and subscription (paywall) processes, optimize the user experience, resolve technical errors, and analyze the effectiveness of our advertising campaigns (attribution), mobile SDK technologies from third-party analytics, attribution, subscription, and crash-reporting infrastructure providers are used. These SDKs are not advertising networks; your personal data is not sold for advertising and is not shared for cross-context behavioral advertising (see §5).
No cookies are used in the mobile app; a cookie is a browser technology, and the App does not operate through a web view. Because Global Privacy Control (GPC) is a browser/HTTP signal, it cannot technically be processed in a native mobile app; however, since the App already does not "sell" personal data within the meaning of the CCPA/CPRA and does not "share" it for behavioral advertising, the protection to which the GPC signal corresponds is provided in practice. Users can manage their analytics and attribution preferences via the in-app Profile > Manage My Data > Share usage analytics switch; when this switch is turned off, both product analytics and the attribution SDK stop collecting data. Profile > Manage My Data > Contribute soothing research is a separate switch and controls only the identity-free sound-research contribution. On iOS, access to the advertising identifier is subject to your choice on the App Tracking Transparency (ATT) prompt displayed by the app, and this choice can be changed at any time from Settings > Privacy & Security > Tracking; on Android, operating-system-level advertising identifier controls are also available (see §7.4).
10. CHANGES TO THE PRIVACY POLICY AND UPDATE PROCEDURE (MODIFICATIONS TO PRIVACY POLICY)
10.0. The Company reserves the right, at its sole discretion, to unilaterally amend or renew this Privacy Policy at any time in line with the addition of new features, changes to the business model, or updates in international legislation. The updated version of the Policy takes effect the moment it is published within the App or on the Company website.
10.1. Typographical corrections, formatting changes, and updates that describe existing practice more clearly do not constitute material changes. Where a material change directly affecting Users' rights and obligations is made to the privacy policy, Users will be given the necessary notice via an in-app notification, the email address registered to their account, or a prominent on-screen alert, and, where mandatory laws so require, active renewed consent (Opt-in) will be requested for changes expanding the scope of data processing before such processing begins. Your continued use of the App after changes are published means you have read the current terms and accept them within the scope of your existing permissions.
10.2. Continued use of the App and the Services (including Growy AI) after such change notice, or renewed consent where required, constitutes acceptance of the current terms. Users who do not accept the updated terms retain the right to immediately cease using the Services and delete their accounts.
10.3. If any retention period in the Policy is invalidated by a local authority as "excessive or disproportionate", the retention period in question will not be eliminated entirely; it will be deemed automatically adapted to the "maximum permissible period" allowed by the authority or by law.
11. DISPUTE RESOLUTION
11.1. General Principle and Governing Law: The interpretation and application of this Privacy Policy, the parties' rights and obligations, and any dispute that may arise from our App's data-processing activities are governed by the laws of the Republic of Türkiye and Turkish law, without regard to conflict-of-laws rules. However, the consumer-protection rights and data-privacy safeguards you hold under the mandatory laws of your country/region of residence, which cannot be waived by contract, are reserved.
11.2. Special Provisions for United States (U.S.) Residents (Binding Arbitration and Class Action Waiver): If you reside in the United States, the following provisions are binding at the level of federal law (Federal Arbitration Act) with respect to any legal claim, dispute, or controversy that may arise between you and the Company:
Binding Arbitration: The User and the Company agree that all disputes arising in connection with this Privacy Policy, the privacy of personal data, data-breach claims, or the Services will be resolved exclusively through binding individual arbitration, instead of official courts. The arbitration will be administered by the American Arbitration Association ("AAA") under its Consumer Arbitration Rules.
Remote, Document-Based Proceedings: To safeguard the fairness and accessibility of the agreement, the arbitration will be conducted remotely, entirely on written submissions/documents, by telephone, or by video conference, without requiring the parties' physical attendance. The arbitrator's award is final and binding and may be entered for enforcement in any court of competent jurisdiction.
Class Action Waiver: THE USER AND THE COMPANY AGREE THAT ANY DISPUTE MAY BE BROUGHT TO ARBITRATION ONLY IN AN INDIVIDUAL CAPACITY, AND THAT THEY WAIVE THE RIGHT TO PARTICIPATE AS A PLAINTIFF, CLASS REPRESENTATIVE, OR CLASS MEMBER IN ANY CLASS ACTION, REPRESENTATIVE ACTION, CONSOLIDATED ARBITRATION, OR PRIVATE ATTORNEY GENERAL ACTION. The arbitrator may not consolidate more than one person's claims and may not preside over any form of class or representative proceeding.
11.3. Special Provisions for European Economic Area (EEA) and United Kingdom (UK) Residents (Mandatory Amicable Resolution Precondition): If you reside in a European Union member state or the United Kingdom, nothing in this policy removes or restricts your mandatory consumer and data-subject rights recognized by local law. However, to resolve disputes between the parties as quickly and effectively as possible, the following process will be operated:
Informal Resolution First: Before applying to an official court or initiating an administrative complaint process with any claim of infringement relating to data privacy or the Services, the User is obligated to notify the claim exclusively and in writing to "support@growbaby.ai". For 30 (thirty) days from receipt of the notice, the Company and the User will make reasonable efforts to resolve the dispute informally, in good faith, and through amicable negotiations. The parties accept, as a contractual good-faith obligation, that no formal legal process will be initiated before this 30-day amicable resolution period has been exhausted.
Local Jurisdiction and Complaint Rights: If the informal negotiation process above fails, your right to initiate legal proceedings remains legally reserved.
11.4. Competent Courts for Türkiye and the Rest of the World: Users in all countries not covered by the mandatory binding arbitration or mandatory local consumer-jurisdiction exceptions above accept, declare, and undertake in advance that the Istanbul (Çağlayan) Courts and Enforcement Offices have exclusive jurisdiction over the resolution of any dispute and over the recognition/enforcement of arbitral awards, that Turkish law will apply, and that they accept the personal jurisdiction of these courts.
12. TIME LIMIT TO BRING A CLAIM & STATUTE OF LIMITATIONS
To the maximum extent permitted by applicable mandatory law, the User is obligated to bring any legal claim, allegation, or cause of action arising from or relating to this Privacy Policy, use of the App, or the Services provided (including the Growy AI assistant and Skin Analysis) to formal legal channels (arbitration or court) within the time limits set out below:
A. For United States (U.S.) Residents: The relevant arbitration process must be initiated no later than 1 (ONE) YEAR from the date on which the event or violation giving rise to the claim or cause of action occurred.
B. For European Economic Area (EEA) and United Kingdom (UK) Residents: To the maximum extent permitted by consumer-protection legislation (the UK Consumer Rights Act 2015 and relevant EU Directives), the User must bring any claim of non-conformity, privacy infringement, or contractual claim arising from the Services or the App to the mandatory informal resolution process referred to in Section 11 or to the relevant local courts no later than 2 (TWO) YEARS from the date the event occurred or should reasonably have been discovered.
C. For Türkiye and the Rest of the World: Subject to the mandatory provisions of the Turkish Code of Obligations and the Law on the Protection of Consumers, all compensation and defect claims arising from this relationship must be brought before formal legal authorities no later than 2 (TWO) YEARS from the date the event occurred.
If the geographic time limits above are exceeded, the relevant claim, right, or cause of action will be deemed permanently and conclusively time-barred, and the User will be deemed to have waived those rights in advance.
13. SEVERABILITY AND AUTOMATIC SUBSTITUTION OF STATUTORY PERIODS
If any indemnity, waiver, limitation of liability, or time limit on legal claims contained in this document (in particular the geographic time limits set out in Section 12) is declared partially or wholly invalid, void, or unenforceable by a competent court, arbitrator, or administrative authority of the User's country/region of residence on the grounds of constituting an "unfair term" or of conflicting with mandatory legislation:
(a) Survival of the Document: Such invalidity or nullity will in no way affect the validity, legitimacy, or enforceability of the other provisions of this document; all remaining clauses will continue to be binding between the parties.
(b) Automatic Minimum-Period Substitution (Savings Clause): Where the 1- or 2-year time limits provided in Section 12 are deemed invalid or an "unfair term" on the grounds that they constitute a limitation period that cannot be contractually shortened under the relevant local consumer-protection legislation, those time limits will not be eliminated entirely; instead, they will be deemed automatically raised to, revised as, and substituted by the "minimum statutory period permitted by law" that the mandatory laws of the relevant country allow to be set by contract.
14. CONTACT INFORMATION AND REPRESENTATIVES
European Union (EEA) and United Kingdom (UK) Representative Note: Our Company is in the process of structuring its global presence; our users residing in Europe and the United Kingdom may submit any application, question, or notice concerning their data-protection rights (including requests under the GDPR and UK GDPR) directly and centrally to our Company's Data Protection Operations Group via the email address support@growbaby.ai. All applications made through this channel will be resolved with priority and care within the mandatory statutory periods.
For any legal request, question, or complaint regarding this privacy policy and your rights, you can reach our Company:
Company Legal Name: Snaiper Teknoloji Anonim Şirketi
Physical Address / Türkiye Head Office: İnkılap Mah. Dr. Adnan Büyükdeniz Cad. Kelif Plaza 3.Blok No:2 İç Kapı No:1 Ümraniye/İST
Email: support@growbaby.ai