Privacy

Effective 28 July 2026

The short version

Your family's data lives in your family's own private database. It is never sold, never shared, never used for advertising, and never analysed for anything beyond showing you your own baby's patterns. There are no ads, no trackers and no analytics. When you ask us to delete it, we delete all of it.

What we collect

Only what your family logs: your baby's profile (name, date of birth, and optionally sex and gestation at birth for the growth charts), care entries (feeds, sleep, nappies, expressing, growth measurements, health notes, medicines, vaccinations, appointments, milestones, reminders, and any notes you add), and the first names caregivers pick for "who logged this".

If you turn reminders on, we also store the technical subscription or device push token your phone needs to receive them. It is registered only when you switch reminders on, and removed when you switch them off or delete your logbook. It is the only device identifier we hold.

If you connect the optional integrations in Settings, we also store what they need to run: your iCloud shared-album link, and for calendar sync the CalDAV address and the app-specific password you create for it. They live only in your family's own database and are wiped when you delete your logbook. If you send us a message from the in-app support card, that message (and the name you attach to it) is forwarded to us over Telegram; it is not stored in the app.

No accounts and no payment details. When you sign up we ask for one contact detail (an email address or phone number), used only to send you your family's PIN and to reach you about your signup; it is not stored in the app itself, and you can ask us to erase it at any time at karo@appeningnow.com. Inside the app we don't know who you are, but your family's records are stored together as your family's records, so we treat all of it as personal data and protect it accordingly.

LittleAi, and what it is sent

LittleAi is the one part of Little Logbook that asks an outside service for help, so it is the only part that asks your permission first. It is off until you agree, the agreement is per device, and you can withdraw it at any time in Settings, under LittleAi. Nothing is sent from that phone once you do.

When you ask it something, we send your question and the last few messages of that conversation, along with your baby's first name, date of birth, the words you use for them, and how many weeks they were born at if you have recorded it. If answering needs your real records, the relevant ones go too: today's feeds, nappies and expressing, your recent feeds and nappy changes, growth measurements, and whether today's medicine has been given.

Your photos are never sent. Neither are your notes, your health entries, your milestones, or anything belonging to another family. Your conversation is not kept once you close it. A general answer with nothing personal in it may be saved in your own logbook so the same question returns instantly next time, and those are deleted along with everything else if you delete your family's data.

Where it lives

Each family gets a completely separate app and its own isolated database. Your database lives in the EU (Amsterdam); the app itself is served from London, UK. Both are reachable only over HTTPS, behind your family's PIN. Families never share a database, so your data cannot leak into anyone else's view by design.

If your logbook has milestone photos enabled, the photos live in your family's own private space in Cloudflare's object storage, separate from every other family's. Unlike your database, we can't yet promise that photos stay in the EU: we are moving photo storage to an EU-only bucket, and this page will say so once that is done.

Any encrypted backups we keep of a logbook's database expire automatically, with the oldest copies gone within six months. Backups are our safety net against mistakes, not a guarantee of recovery, so if you want a copy you can rely on, use the export in Settings.

Your data, your call

You can download everything, or delete your whole logbook, yourself from Settings at any time. Deletion removes your live data (including any photos) immediately, and any backups as they expire. No email, no form, no waiting on us.

Under UK GDPR you also have the right to access, correct, and object to how your data is used, and you can withdraw your consent at any time by deleting your data. Questions or requests: karo@appeningnow.com.

What we never do

No advertising, no analytics, no tracking, no selling or sharing of your data, and no profiling beyond showing your own family its own baby's patterns. The app contains no advertising or analytics software of any kind, and nothing leaves your instance except the flows described on this page (reminders, LittleAi if you have agreed to it, the optional integrations and quick-add box, support messages, and the operational notifications listed below).

The services that help us run it

A small set of processors host or handle data strictly on our instructions:

  • Vercel and Railway: Vercel serves your family's app from London, UK; Railway hosts your family's database in the EU (Amsterdam).
  • Cloudflare: object storage for milestone photos, where photos are enabled (see "Where it lives" above about photo residency).
  • Expo and Apple: delivering reminder notifications, only if you turn reminders on. Apple's notification network is global, so the small technical message behind each notification passes through servers in the US on its way to your phone.
  • Anthropic: the company that makes the model behind LittleAi, and the only recipient of what LittleAi is sent (see "LittleAi, and what it is sent" above). The optional quick-add box goes the same way: type "fed 60ml at 3am" in plain words and that one sentence is sent to be understood, after which we keep only the structured entry it produces, never the sentence itself. Anthropic processes both on our instructions under its API terms, retaining them briefly for abuse prevention, and does not use them to train its models.
  • Telegram: how our own operational notifications reach us. When you sign up, your signup details and your family's PIN are sent to us over Telegram so we can set you up and send you the PIN; when you use the in-app support card, your message and the name you attach are relayed to us the same way; and when a logbook is deleted, we get a short notice naming the instance. Telegram is not an EU company, so these messages transit its infrastructure.
  • GitHub: the automation that builds your family's private app runs on GitHub when you sign up, so your signup details (family name, baby's name and date of birth, caregiver first names, your contact detail, and your PIN) pass through GitHub's systems (US) during provisioning.

Who's responsible, and the legal bit

The data controller is Appening Now, contactable at karo@appeningnow.com. Because a baby's health information is sensitive ("special category") data, we process it only with your explicit consent, given when you sign up, and only to run the logbook for you. Data is held until you delete it.

One piece of small print: to slow down anyone trying to guess a PIN, we keep a count of failed unlock attempts against the network address they came from. It is used only for that, and the count for an address is cleared when it unlocks successfully.

If you're ever unhappy with how your data is handled, you can complain to the UK regulator, the ICO, at ico.org.uk.

littlelogbook.appSupport Join