Privacy Policy
- Who we are
- What the app records
- What stays on your devices
- Signing in
- Synchronization and caregiver sharing
- Sleepy Time
- Luna Baby Plus purchases
- Photos
- Importing from another app
- Analytics, diagnostics and tracking
- Service providers
- How we protect information
- How long we keep information
- Your choices and rights
- Children
- Where information is processed
- Our website
- Changes to this policy
- Contact
1. Who we are
Luna Baby is made by Scoop Systems, Inc. (“Luna”, “we”, “us”). We are the controller of the information described in this policy. You can reach us at support@hellolunababy.com; see Contact for details.
2. What the app records
Luna Baby only records what you or another caregiver in your household enters. There are no hidden collection points: the app has no advertising identifiers, no location services, no contacts or calendar access, no microphone or camera access, and no background uploads while you are signed out.
| Information | Where it comes from | Why we process it |
|---|---|---|
| Child profile: the name you give your child, birth date or due date, and optional sleep-profile preferences (time zone, prematurity, typical daytime hours, your goals from onboarding). | You enter it during onboarding or in Settings. | To organize records per child, calculate age-appropriate guidance and show the right time zone. |
| Care records: sleep, nursing, bottle and pumping, solids, diapers and potty, growth measurements, medicine, temperature, activities and contractions, each with times, amounts, units and optional notes. | You enter them, start timers, or import them (see Importing). | This is the product: the log, reports, timers and Sleepy Time all run on these records. |
| Photos attached to solids and feeding entries. | You pick them with the iOS photo picker. | To show the photo with the entry. See Photos. |
| Account identifiers: a one-way hash of the Sign in with Apple or Google account identifier, a random installation ID for each installed copy of the app, and session credentials. | Created when you sign in. | To recognize your account and devices without storing your email address or name. |
| Household and caregiver information: which accounts belong to your household, each caregiver’s role, the label you give a caregiver (for example “Dad”), and which children each caregiver may see. | You create invitations and set scopes in Settings → Family. | To share records with the people you choose and no one else. |
| Purchase information: the App Store transaction and product identifiers, purchase and expiry dates and subscription status for Luna Baby Plus. | Apple sends it to the app after a purchase; the app forwards the signed transaction to us. | To unlock Plus features for your household and keep them unlocked across your devices and caregivers. |
| Support messages you send us by email. | You write to us. | To answer you. |
We do not read HealthKit, and we do not collect your location, your contacts, your device’s advertising identifier, or any information from your child’s own devices. Some of what you record about your child, such as growth, temperature and medicine, is health information; we process it only to show it back to you and the caregivers you authorize, and, where the GDPR applies, on the basis of your explicit consent, which you give by recording it and can withdraw by deleting the records or your account. Luna Baby does not read the rest of your photo library; the photo picker runs outside the app and only hands over the items you choose.
3. What stays on your devices
The app keeps a complete copy of your household’s records in a database on your iPhone, protected by iOS data protection so that it is encrypted while your phone is powered off, and available without a network connection. Your iPhone also stores:
- App preferences (appearance, report settings, the selected child, care-board layout, recent entry defaults) in the app’s own settings storage.
- Sign-in session credentials and the installation ID in the iOS Keychain, restricted to this device.
- A small read-only snapshot of current timers and recent care so that Home Screen widgets, Lock Screen Live Activities and the Apple Watch app can show them. The snapshot is stored in the app’s private shared container on the same device and is never sent anywhere.
- Temporary export files (see Your choices and rights), protected with the strongest iOS file protection class and excluded from backups. The app deletes export packages older than 24 hours the next time you open it or create another export.
The Apple Watch app talks only to the paired iPhone through Apple’s Watch Connectivity channel; it does not contact our servers itself.
Because the on-device database lives in the app’s normal storage, it is included in the iPhone backups you make with iCloud or a computer. Those backups are governed by Apple’s terms and encryption, not by us. If you sign out, the app removes the signed-in household’s cached records from the device.
4. Signing in
You can use Luna Baby without an account. Signing in is required for synchronization, caregiver sharing, Luna Baby Plus and hosted Sleepy Time.
Sign in with Apple and Sign in with Google are handled by Apple and Google respectively. The app receives a signed identity token from the provider and sends it to the Luna service, which verifies the token and derives a one-way hash of the provider’s stable account identifier. The token may contain your email address or name; the Luna service does not persist them and keeps only that hash, the provider name and the time. For Sign in with Apple we also keep an encrypted provider refresh token so that we can revoke the link with Apple when you delete your account; it is used for nothing else. If you choose Apple’s “Hide My Email”, nothing changes on our side because no address is stored.
When you use Sign in with Google, Google’s own Privacy Policy applies to the sign-in step, which runs inside Google’s sign-in software. When you use Sign in with Apple, Apple’s Privacy Policy applies to that step.
5. Synchronization and caregiver sharing
When you are signed in and connected, the app uploads your household’s child profiles, care records and timers to the Luna service and downloads changes made by other caregivers or from your other devices. Each change is sent as a whole, in order, and is acknowledged before the app treats it as saved.
Records belong to the household, not to one account. If you invite a caregiver, they see the children you select and can add and edit records for those children. Caregiver invitations are shared as a private link or code that you hand over yourself; we do not send emails or text messages on your behalf. The household owner can change a caregiver’s label and scope or remove them at any time. The Luna service stops authorizing that caregiver at once; their device stops showing and syncing your records the next time it reaches the service, and a device that is offline keeps its existing local copy until it reconnects.
Deleting your own account does not delete a child’s shared history that another caregiver in the household still relies on. Deleting a child, or deleting the household as its last owner, is what removes the child’s records for everyone.
6. Sleepy Time
Sleepy Time estimates when your child may next be ready to sleep. On your device it uses your child’s age and the most recent completed sleep. When you are signed in, the Luna service can compute a more detailed estimate from a minimized set of inputs: the child’s corrected age, recent sleep and wake-window history, the schedule preferences you set, and the current time context. Names, notes, photos, feeding, diaper, medicine and other unrelated records are not part of those inputs.
Sleepy Time is guidance, not a medical device, diagnosis or safety monitor. It may decline to give an estimate when there is not enough history. Issued estimates and their request receipts carry a 90-day retention limit and are deleted within a reasonable period after it is reached.
7. Luna Baby Plus purchases
Luna Baby Plus is an auto-renewing subscription sold through Apple’s App Store using Apple’s StoreKit. Apple processes your payment; we never see your payment card, billing address or Apple ID. After a purchase, restore or renewal the app sends Apple’s signed transaction to the Luna service, which verifies it with Apple’s App Store Server API and records the transaction identifier, product, dates and status against your household. Apple also sends us server notifications when a subscription renews, lapses, is refunded or is revoked so that access stays accurate.
Subscription terms, prices, renewal and cancellation are described in our Terms of Service.
8. Photos
A photo you attach to an entry is stored with the entry in the app’s database on your iPhone (see What stays on your devices). Photo bytes stay on your iPhone: only a reference (the byte count and a content hash) travels with the synchronized record, so other caregivers see that a photo exists but not the image itself. We will update this policy before any release uploads photo bytes.
9. Importing from another app
Settings → Data & Privacy → Import lets you choose a CSV file exported from Huckleberry. The file is read and converted entirely on your device; nothing is uploaded during import. You confirm the time zone and the destination child before anything is saved, and imported records keep their original timestamps and units so you can audit them later. Records created by import synchronize like any other record once you are signed in.
10. Analytics, diagnostics and tracking
Luna Baby contains no third-party analytics, attribution, advertising or crash-reporting software, and it does not track you across other companies’ apps or websites. We do not use the advertising identifier. There are no tracking domains in the app, and the app’s privacy manifest declares no tracking.
The app has an optional, off-by-default usage-measurement setting. Until you turn it on, nothing is measured, and no measurement service is configured in the current release. If a future release enables it, it would record only pre-defined event names such as “timer recovered” or “sync attempted” against a random identifier, never record contents, notes, names or child data, and you could turn it off at any time, which would also delete what had been recorded.
Apple may share crash and usage reports with us if you have opted in to sharing analytics with app developers in iOS Settings. Those reports are governed by Apple and do not contain your records.
Our servers keep operational logs and metrics: request timings, status codes, error codes and pseudonymous identifiers. They never contain record contents, names, tokens or request bodies.
11. Service providers
We use a small number of providers to run Luna Baby. Each processes information only on our instructions and for the purposes above.
| Provider | What they do for us | What they receive |
|---|---|---|
| Apple Inc. | App distribution, App Store payments and subscriptions, Sign in with Apple, StoreKit, and (if we enable notifications in a future release) push delivery. | Purchase and subscription status under Apple’s terms; identity tokens during sign-in. |
| Google LLC | Sign in with Google, and Google Cloud infrastructure that hosts the Luna service: Cloud Run, Cloud SQL (PostgreSQL), Cloud KMS, Secret Manager and Cloud Logging/Monitoring. | Identity tokens during Google sign-in; the encrypted service database and encrypted backups; operational logs and metrics. |
If we later enable the Luna assistant, it would use Google Cloud Vertex AI as the model provider, only for the message you send, with per-message consent for any photo, and without using your data to train models. That feature is not enabled in the current release.
We do not sell personal information, share it for cross-context behavioral advertising, or disclose it to data brokers. We disclose information only to the providers above, to comply with law or a valid legal request, to protect the rights and safety of Luna, our users or others, or as part of a merger, acquisition or sale of assets, in which case this policy continues to apply to the transferred information.
12. How we protect information
- All traffic between the app and the Luna service uses TLS.
- Names, care record contents, caregiver labels, sign-in refresh credentials and other sensitive fields are individually encrypted in our database with keys managed by Google Cloud KMS, in addition to disk and backup encryption. Session and provider identifiers are stored as one-way hashes.
- Every request is authorized against your account, household and child grants before any record is read or written.
- On your iPhone, the database, onboarding drafts and export files use iOS data protection, and credentials live in the Keychain.
- Access to production systems is limited to the people who operate the service and is logged.
No system is perfectly secure. If we learn of a breach that affects your information, we will notify you as required by law.
13. How long we keep information
- Household records (children, care records, timers, caregiver grants) are kept while the household exists. Deleting a child removes its records; deleting the household as its last owner removes everything.
- Sleepy Time estimates and their receipts carry a 90-day retention limit and are deleted within a reasonable period after it.
- Sign-in sessions are removed when you sign out, when they expire, or when your account is deleted.
- Purchase records are kept for as long as we must retain financial records and satisfy App Store obligations, even after account deletion, because they document a paid transaction.
- Account deletion leaves a minimal record that the deletion happened (an operation ID, timestamps and per-category outcomes, with no personal content) so that a deleted account cannot be silently restored. The credential the app uses to check deletion progress expires 30 days after completion.
- Support emails are kept for as long as needed to resolve your request and for a reasonable period afterwards.
- Operational logs are kept for a limited period for security and reliability and then deleted.
14. Your choices and rights
Most of what you might want to do is built into the app, under Settings → Data & Privacy:
- Export my data produces a package with your household’s records in structured JSON and a readable CSV, plus a manifest describing exactly what is and is not included, protected on your device until you choose to save or share it.
- Edit and delete any record, child or caregiver grant directly in the app.
- Sign out to remove the household’s cached records from that device.
- Delete account starts a server-side deletion of your account, sessions, devices, caregiver grants and everything owned only by your account, then removes the app’s local data. Records shared with remaining caregivers stay with the household, as described above. The app shows progress and confirms completion.
Depending on where you live, you may also have legal rights to access, correct, delete or receive a copy of your personal information, to object to or restrict certain processing, to withdraw consent, and to complain to a supervisory authority. To exercise a right you cannot complete in the app, email support@hellolunababy.com. We will verify that the request comes from the account holder before acting on it, and we will not discriminate against you for exercising your rights. We do not use personal information for automated decisions that have legal or similarly significant effects on you.
15. Children
Luna Baby is for parents and caregivers. It is not directed to children, and you must be at least 18 years old to create an account. The information about your child that you record is provided by you, the parent or caregiver, and is processed only to provide the service to you. We do not knowingly collect information directly from anyone under 13, and we do not use information about children for advertising or profiling. If you believe a child has provided us information directly, contact us and we will delete it.
16. Where information is processed
The Luna service runs on Google Cloud in the United States. If you use Luna Baby from outside the United States, your information is transferred to and processed there. Where the law requires safeguards for such transfers, we rely on the contractual protections in our agreements with our providers, including standard contractual clauses where they apply.
Where the GDPR or UK GDPR applies, our legal bases are: performance of our contract with you (providing the app, synchronization, sharing, Plus and support), your explicit consent for the health information you record about your child and for any optional measurement setting, and our legitimate interests in keeping the service secure and reliable.
17. Our website
This website (hellolunababy.com, including this page) sets no cookies, uses no analytics or advertising trackers, and loads nothing from third parties, so it shows no cookie banner: there is nothing to consent to. It is hosted on GitHub Pages, which keeps ordinary web-server access logs (such as your IP address, the page requested and the time) for the purpose of serving the pages and protecting the service; those logs are governed by GitHub’s privacy statement. We do not receive or use them.
18. Changes to this policy
When we change this policy we will update the date at the top and, for material changes, tell you in the app before the change takes effect.
19. Contact
Scoop Systems, Inc.
c/o Incorporating Services, Ltd. (registered agent)
3500 South DuPont Highway, Dover, DE 19901, United States
Email: support@hellolunababy.com
If you have an unresolved privacy concern, you may also contact your local data protection authority.