Privacy Policy
Last updated: September 25, 2026
Robin Baby — a product of Bunny Hopper Labs Inc.
Effective Date: September 25, 2026
Robin Baby is a voice-first baby tracking app that helps parents and caregivers record, organize, and understand their child's daily events. We know you're trusting us with some of the most personal information there is — your child's health, growth, and everyday moments — and we take that responsibility seriously.
This Privacy Policy explains what data we collect, why we collect it, how we use it, who we share it with, and what choices you have. We've written it in plain language because we believe you deserve clarity, not legal fog.
If you have questions, contact us anytime at hello@robinbaby.com.
Table of Contents
- 1. Who We Are
- 2. Who This App Is For
- 3. Information We Collect
- 4. How We Use Your Information
- 5. Third-Party Services We Use
- 6. How AI Processing Works
- 7. Data Sharing and Disclosure
- 8. Data Security
- 9. Data Retention and Deletion
- 10. Your Rights and Choices
- 11. Children's Privacy (COPPA)
- 12. International Data Transfers
- 13. Health Data
- 14. Advertising and Tracking
- 15. Changes to This Policy
- 16. Contact Us
1. Who We Are
Robin Baby is operated by Bunny Hopper Labs Inc., a Canadian corporation ("we," "us," or "our"). We provide a mobile application for iOS and Android and a backend service that processes your data.
- Email: hello@robinbaby.com
- Website: https://www.robinbaby.com
2. Who This App Is For
Robin Baby is designed for parents, guardians, and adult caregivers who want to track their baby's or child's daily events, health, and milestones. The app is not directed at children under 13 (or under 16 in certain jurisdictions). Only adults should create accounts and use the app. See Section 11 for more details on children's data.
3. Information We Collect
We collect the following categories of information:
3.1 Account Information
When you create an account, we collect:
- Email address — used for login via email one-time passcode (OTP), Google Sign-In, or Sign in with Apple
- Display name — so family members can identify you within a shared family
3.2 Child Profile Information
You provide information about your child to use the app's tracking features:
- Child's name and nickname
- Date of birth
- Gender
- Gestational weeks (if your child was born early — used for adjusted-age calculations)
- Profile photo (optional)
3.3 Family Information
If you share access with a partner, grandparent, or other caregiver:
- Family relationships and caregiver roles (admin or member)
- Invitation tokens (used to securely invite family members)
3.4 Timeline and Event Data
The core of the app. You create event entries — either by speaking, typing, or scanning handwritten notes — and we store the structured data that results:
- Feeding events: type (bottle, breast, solids), amount, duration
- Sleep events: start and end times, quality notes
- Diaper events: type, notes
- Medication events: medication name, dosage, time
- Symptom events: description, severity
- Temperature readings
- Growth measurements: weight, height, head circumference
- Milestone events
- Vaccination records
- Allergy and allergen tags
- Nursing diet entries
- Custom notes and free-form observations
3.5 Voice Recordings
When you use the voice input feature, the app records audio through your device microphone. This audio is sent to our backend server, where it is transcribed into text using AI services (see Section 6).
Voice recordings are processed transiently and are not stored long-term. Once the transcription is complete and the structured event data is extracted, the audio is discarded. We retain the resulting text transcript and structured event data. Text transcripts are stored as part of your event records and may be used as context for AI-powered features such as question answering.
3.6 Photos and Scanned Images
When you use the scan feature to capture handwritten notes, or attach a photo to an event:
- Images are sent to our backend for AI-powered text recognition
- Scanned images used for text extraction are processed transiently and discarded after processing
- Photos attached to events or child profiles are stored as long as your account is active
3.7 Questions and AI Answers
When you use the "Ask" feature to ask natural language questions about your child's data:
- Your questions are sent to our AI services for processing
- Your questions are saved to your local question history so you can re-ask them later. A brief preview of the answer headline is stored locally, but the full generated answer is not persisted — it is regenerated each time you revisit a question
- On the backend, questions are logged for service quality and diagnostics purposes
3.8 Doctor Summary Data
When you generate a doctor-ready PDF summary:
- The summary is generated from your existing event data based on the date range and event types you select
- Generated PDFs are created on-demand and delivered to you
3.9 Import and Export Data
- Import: If you upload CSV or data files to import historical records, those files are processed and the extracted data is stored as events in your timeline
- Export: You can export your data at any time. Export files are generated on-demand from your stored data
3.10 Device and Technical Data
We collect limited technical information to operate the app:
- Push notification tokens (Firebase Cloud Messaging) — so we can send you reminders and alerts
- Device platform (iOS or Android)
- App version
3.11 Analytics Data
We use PostHog and (on Android) Google Firebase Analytics for product analytics. This includes:
- Screen views and feature usage events
- Onboarding progress, paywall views, and conversion events (used to measure marketing campaign effectiveness)
- Device type, app version, language, and country
- An opaque random identifier (your Supabase user ID) is linked to events so we can build funnels — never your name, email address, voice notes, photos, or anything about your child
We process this data under the GDPR legal basis of legitimate interest in improving the product and measuring the effectiveness of our marketing. We minimize what is collected (no PII beyond the opaque ID), and you can object to this processing at any time by emailing hello@robinbaby.com — see Section 10.
3.12 Crash and Diagnostic Data
We use Sentry for crash and error reporting under the GDPR legal basis of legitimate interest in maintaining service reliability — a working app is what you signed up for, and we cannot maintain quality without seeing when and why it breaks. We minimize what Sentry collects:
- Crash reports and error logs (stack traces, app state at the time of a crash)
- Device type and app version
- An opaque random identifier (your Supabase user ID) so we can correlate crashes for the same account
- IP addresses are not retained (stripped at the Sentry server level)
- Request bodies, cookies, headers, and other auto-PII are blocked at the SDK level
Sentry runs without a separate consent prompt because it is necessary infrastructure for service reliability rather than behavioral tracking. You can request deletion of your Sentry data at any time by contacting hello@robinbaby.com.
3.13 Purchase Data
If you subscribe to a paid plan, RevenueCat processes your subscription:
- Subscription status and product ID
- Trial start and end dates
- Subscription period dates
- Your user ID is linked to your subscription record
Actual payment processing is handled entirely by Apple (App Store) or Google (Play Store). We never see or store your credit card number, bank details, or billing address.
3.14 Preferences
We store your preferred measurement units:
- Volume (oz/ml)
- Weight (kg/lb)
- Length (cm/in)
- Temperature (°F/°C)
4. How We Use Your Information
We use the information we collect to:
| Purpose | Data Used |
|---|---|
| Provide the core service — record, organize, and display your child's events and timeline | Account info, child profiles, event data, voice recordings, photos |
| AI-powered event extraction — convert your voice or text input into structured events | Voice recordings, text input, child names |
| Answer your questions — use AI to answer natural language questions about your child's data | Questions, event data, child profiles |
| Generate doctor summaries — create PDF reports from your data | Event data, child profiles |
| Family sharing — let multiple caregivers access and contribute to a shared timeline | Family info, invitation tokens |
| Send notifications — reminders, feeding timers, and important alerts | FCM tokens, device platform |
| Process subscriptions — manage your paid plan | Purchase data, user ID |
| Improve the app — understand which features are used and how | Analytics data |
| Measure marketing campaigns — know whether our ads reach the right people, Android only | Conversion events, opaque app installation ID, country, device type |
| Fix bugs and crashes — identify and resolve technical issues | Crash/diagnostic data |
| Import and export — let you bring in historical data or take your data with you | Import/export files |
| Personalize display — show measurements in your preferred units | Unit preferences |
We do not use your data to:
- Serve advertisements
- Build advertising profiles
- Sell to third parties
- Train AI models (see Section 6)
- Make automated decisions that produce legal or similarly significant effects
5. Third-Party Services We Use
We rely on the following third-party service providers to operate Robin Baby. Each receives only the data necessary for its specific purpose. The three exceptions are Section 5.12, Section 5.13 and Section 5.14, optional integrations you switch on yourself, in which OpenAI, Anthropic and Meta are not acting as our service providers:
5.1 Supabase (supabase.com)
- Data shared: All user data including account information, child profiles, event data, family relationships, and authentication credentials
- Purpose: Primary database hosting, user authentication, and data storage with Row-Level Security for family-level data isolation
- Privacy policy: https://supabase.com/privacy
5.2 OpenAI (openai.com)
- Data shared: Text transcripts of voice recordings, event data, user questions, and child names
- Purpose: AI-powered event extraction (GPT-4.1-nano/mini), natural language question answering, and text embeddings for semantic search
- Privacy policy: https://openai.com/privacy
- Important: Per OpenAI's published API data usage policy, data sent via their API is not used to train their models
5.3 Groq (groq.com)
- Data shared: Audio recordings (for transcription), text transcripts, and child names
- Purpose: Whisper-based speech-to-text transcription and fallback LLM event extraction
- Privacy policy: https://groq.com/privacy-policy
- Important: Data sent to Groq via their API is not used to train their models, per Groq's API terms
5.4 Google Cloud / Vertex AI (cloud.google.com)
- Data shared: Text transcripts
- Purpose: Fallback AI/LLM processing when primary services are unavailable
- Privacy policy: https://cloud.google.com/terms/cloud-privacy-notice
5.5 Firebase Cloud Messaging (firebase.google.com)
- Data shared: FCM push notification tokens, device platform
- Purpose: Delivering push notifications (reminders, alerts) to your device
- Privacy policy: https://firebase.google.com/support/privacy
5.6 RevenueCat (revenuecat.com)
- Data shared: User ID, purchase and subscription information
- Purpose: Subscription management, receipt validation, trial and renewal tracking
- Privacy policy: https://www.revenuecat.com/privacy
5.7 PostHog (posthog.com)
- Data shared: Opaque user ID, app usage events, screen views, device type, app version, country
- Data NOT shared: Name, email, voice notes, photos, child data
- Purpose: Product analytics — understanding feature usage and improving the app
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). Opt out at any time by emailing hello@robinbaby.com.
- Hosted in: United States, under the EU-US Data Privacy Framework
- Privacy policy: https://posthog.com/privacy
5.8 Google Firebase Analytics (firebase.google.com)
- Data shared: Opaque user ID, app conversion events (sign-up, paywall view, purchase), device type, app version, country
- Data NOT shared: Name, email, voice notes, photos, child data
- Purpose: Measure marketing campaign effectiveness for Google App Campaigns (Android only)
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR). Opt out at any time by emailing hello@robinbaby.com.
- Hosted in: United States, under the EU-US Data Privacy Framework
- Privacy policy: https://firebase.google.com/support/privacy
5.9 Sentry (sentry.io)
- Data shared: Opaque user ID, crash reports, session data, error logs, device type, app version
- Data NOT shared: IP addresses (stripped server-side), request bodies, cookies, name, email, voice notes
- Purpose: Crash and error reporting for service reliability
- Legal basis: Legitimate interest (Art. 6(1)(f) GDPR) in maintaining service quality
- Hosted in: United States, under the EU-US Data Privacy Framework
- Privacy policy: https://sentry.io/privacy
5.10 Google Sign-In (accounts.google.com)
- Data shared: OAuth authentication token, email address, display name
- Purpose: Optional authentication method — only used if you choose to sign in with Google
- Privacy policy: https://policies.google.com/privacy
5.11 Sign in with Apple
- Data shared: Apple ID token, email address (which may be hidden via Apple's relay), display name
- Purpose: Optional authentication method — only used if you choose to sign in with Apple
- Privacy policy: https://www.apple.com/legal/privacy
5.12 ChatGPT connector (OpenAI) — optional
Robin Baby offers an optional connector for ChatGPT. It is off unless you connect it yourself from inside ChatGPT and approve a consent screen that names the child it will cover. If you never connect it, nothing in this section applies to you.
This is a different arrangement from Section 5.2 above. There, we send data to OpenAI's API as our own service provider. Here, the data travels to OpenAI because you are using ChatGPT, so OpenAI handles it as the operator of ChatGPT under the terms and privacy policy of your own ChatGPT account — including their retention and any model-training settings on that account, which are governed by OpenAI and not by us.
- Data shared when you use it: the selected child's first name, date of birth, age, sex, gestational age at birth and time zone, plus a summary of feeding patterns over the last 30 days (counts of breast, bottle and pumping events); and, for the activities ChatGPT asks about, the event type, its local date and time, duration, your free-text notes, and the type-specific details — feed amounts and units, bottle contents, nursing side and duration, diaper type, sleep duration and whether it was a nap or overnight, pumping amounts, crying duration and reason, milestone titles, and food descriptions and suspected-allergen tags. Growth entries share the raw weight, height and head-circumference measurements you recorded. Answers to your questions, and any activity you ask Robin to log, also pass through ChatGPT. Food descriptions and suspected-allergen tags cover two kinds of entry: what the child ate, and — if you log it — what you ate while breastfeeding. Both leave the app through the connector.
- Summaries computed from those records: alongside the records themselves, responses may include totals and averages, day-by-day series, comparisons between periods, logging streaks and gaps, night-sleep analyses (wake counts, longest stretch), a short summary line per entry, automatic data-quality flags that quote a value back and note it looks implausible, and Robin's sleep forecast — a prediction of the next nap or bedtime and of today's remaining nap schedule, computed from the sleep you have logged, together with the settings it rests on (this child's configured wake and night hours, and any nap count you have fixed yourself). Apart from those settings these are derived from the data above, not additional information about you.
- Deliberately withheld: the connector cannot read or write medications, symptoms, temperature or vaccination records, it cannot see stool colour or nappy rash, and it does not return WHO growth percentiles or centile bands. It can read and write records for only one child at a time — the one you selected — and cannot reach other children or other families. Within that child it can correct and delete records as well as add them, always after asking you to confirm.
- Caregiver invites: if you ask it to, the connector can create a caregiver invite code for your family and return that code in the chat. An invite is family-wide, not limited to the selected child: anyone who redeems the code joins your family and can then see every child in it. Codes expire after seven days and can be cancelled in the Robin Baby app.
- Purpose: to let you record and ask questions about your own child's care history by talking to ChatGPT instead of opening the app.
- Special category data: food, suspected-allergen and growth information may count as data concerning health, and therefore as "special category" data under the GDPR and UK GDPR. We process it only on your explicit consent, given when you connect the connector, and only for the purpose above.
- Retention: we keep your Robin Baby records as described in Section 9. The copy that reaches your ChatGPT conversation is retained by OpenAI under your ChatGPT account's settings; deleting a Robin Baby record does not remove it from a past ChatGPT conversation. Delete the conversation in ChatGPT as well if you want it gone from there.
- Your controls: disconnect at any time from ChatGPT's connector settings. ChatGPT then discards the credentials it holds for your Robin Baby account, and the short-lived access token it was using expires within an hour. Disconnecting is also how you withdraw the consent described above; because it happens inside ChatGPT, it is ChatGPT that stops calling us. We remember which child you selected, so if you reconnect later you may not be asked to choose again — email hello@robinbaby.com if you would like that record cleared. Deleting your account removes your Robin Baby data as set out in Section 9. Disconnecting does not delete past ChatGPT conversations.
- Not medical advice: answers are informational, may be incomplete or wrong, and are not a substitute for professional medical care. See Section 13.
- OpenAI's privacy policy: https://openai.com/privacy
5.13 Claude connector (Anthropic) — optional
Robin Baby offers an optional connector for Claude. It is off unless you connect it yourself from inside Claude and approve a consent screen that names the child it will cover. If you never connect it, nothing in this section applies to you.
As with Section 5.12, this is a different arrangement from Section 5.2 above. There, we send data to OpenAI's API as our own service provider. Here, the data travels to Anthropic because you are using Claude, so Anthropic handles it as the operator of Claude under the terms and privacy policy of your own Claude account — including their retention and any model-training settings on that account, which are governed by Anthropic and not by us.
A mechanical detail about signing in, which we mention because it is not obvious. Our connector authenticates you with an OAuth client that belongs to Robin Baby, and Claude needs that client's credentials to complete the sign-in exchange on your behalf after you approve the consent screen. Today those credentials are supplied to Claude when the connector is added; if Robin Baby is later listed in Anthropic's connector directory, Anthropic will hold them centrally for that listing instead. Either way the credentials identify our application, not you, and no Robin Baby data can be reached with them until you have approved the consent screen, and then only for the child you selected.
- Data shared when you use it: the same records as the ChatGPT connector, because both use the same interface. That is the selected child's first name, date of birth, age, sex, gestational age at birth and time zone, plus a summary of feeding patterns over the last 30 days (counts of breast, bottle and pumping events); and, for the activities Claude asks about, the event type, its local date and time, duration, your free-text notes, and the type-specific details — feed amounts and units, bottle contents, nursing side and duration, diaper type, sleep duration and whether it was a nap or overnight, pumping amounts, crying duration and reason, milestone titles, and food descriptions and suspected-allergen tags. Growth entries share the raw weight, height and head-circumference measurements you recorded. Answers to your questions, and any activity you ask Robin to log, also pass through Claude. Food descriptions and suspected-allergen tags cover two kinds of entry: what the child ate, and — if you log it — what you ate while breastfeeding. Both leave the app through the connector.
- Summaries computed from those records: as in Section 5.12, responses may include totals and averages, day-by-day series, comparisons between periods, logging streaks and gaps, night-sleep analyses (wake counts, longest stretch), a short summary line per entry, automatic data-quality flags that quote a value back and note it looks implausible, and Robin's sleep forecast — a prediction of the next nap or bedtime and of today's remaining nap schedule, computed from the sleep you have logged, together with the settings it rests on (this child's configured wake and night hours, and any nap count you have fixed yourself). Apart from those settings these are derived from the data above, not additional information about you.
- Deliberately withheld: the connector cannot read or write medications, symptoms, temperature or vaccination records, it cannot see stool colour or nappy rash, and it does not return WHO growth percentiles or centile bands. It can read and write records for only one child at a time — the one you selected — and cannot reach other children or other families. Within that child it can correct and delete records as well as add them, always after asking you to confirm.
- Caregiver invites: if you ask it to, the connector can create a caregiver invite code for your family and return that code in the chat. An invite is family-wide, not limited to the selected child: anyone who redeems the code joins your family and can then see every child in it. Codes expire after seven days and can be cancelled in the Robin Baby app.
- Purpose: to let you record and ask questions about your own child's care history by talking to Claude instead of opening the app.
- Special category data: food, suspected-allergen and growth information may count as data concerning health, and therefore as "special category" data under the GDPR and UK GDPR. We process it only on your explicit consent, given when you connect the connector, and only for the purpose above.
- Retention: we keep your Robin Baby records as described in Section 9. The copy that reaches your Claude conversation is retained by Anthropic under your Claude account's settings; deleting a Robin Baby record does not remove it from a past Claude conversation. Delete the conversation in Claude as well if you want it gone from there.
- Your controls: disconnect at any time from Claude's connector settings. Claude then discards the credentials it holds for your Robin Baby account, and the short-lived access token it was using expires within an hour. Disconnecting is also how you withdraw the consent described above; because it happens inside Claude, it is Claude that stops calling us. We remember which child you selected, so if you reconnect later you may not be asked to choose again — email hello@robinbaby.com if you would like that record cleared. Deleting your account removes your Robin Baby data as set out in Section 9. Disconnecting does not delete past Claude conversations.
- Not medical advice: answers are informational, may be incomplete or wrong, and are not a substitute for professional medical care. See Section 13.
- Anthropic's privacy policy: https://www.anthropic.com/legal/privacy
5.14 Muse connector (Meta) — optional
Robin Baby offers an optional connector for Muse, the AI assistant from Meta. It is off unless you connect it yourself from inside Muse and approve a consent screen that names the child it will cover. If you never connect it, nothing in this section applies to you.
As with Section 5.12 and Section 5.13, this is a different arrangement from Section 5.2 above. Here, the data travels to Meta Platforms, Inc. because you are using Muse, so Meta handles it as the operator of Muse under the terms and privacy policy of your own Meta account — including their retention and any model-training settings on that account, which are governed by Meta and not by us.
A mechanical detail about signing in, which we mention because it is not obvious. Our connector authenticates you with an OAuth client that belongs to Robin Baby. For Muse this client has no secret: it is a public identifier, and the sign-in is protected by a one-time code exchange (PKCE) instead. Today you may be asked to enter that identifier when you add the connector in Muse; if Robin Baby is later listed in Muse's connector directory, Meta will supply it for that listing instead. Either way it identifies our application, not you, and no Robin Baby data can be reached with it until you have approved the consent screen, and then only for the child you selected.
- Data shared when you use it: the same records as the ChatGPT and Claude connectors, because all three use the same interface. See Section 5.13 for the full list: the selected child's profile and time zone, a 30-day feeding summary, and, for the activities Muse asks about, the event details, your free-text notes, food and suspected-allergen entries (for the child, and for you if you log what you ate while breastfeeding) and raw growth measurements. Answers to your questions, and any activity you ask Robin to log, also pass through Muse.
- Summaries computed from those records: the same totals, comparisons, streaks, night-sleep analyses, data-quality flags and sleep forecast described in Section 5.13, derived from the data above.
- Deliberately withheld: as with the other connectors, Muse cannot read or write medications, symptoms, temperature or vaccination records, stool colour or nappy rash, and receives no growth percentiles. It can reach only the one child you selected. Within that child it can correct and delete records as well as add them.
- Caregiver invites: if you ask it to, the connector can create a caregiver invite code for your family and return it in the chat. An invite is family-wide: anyone who redeems the code joins your family and can then see every child in it. Codes expire after seven days and can be cancelled in the Robin Baby app.
- Purpose: to let you record and ask questions about your own child's care history by talking to Muse instead of opening the app.
- Special category data: food, suspected-allergen and growth information may count as data concerning health, and therefore as "special category" data under the GDPR and UK GDPR. We process it only on your explicit consent, given when you connect the connector, and only for the purpose above.
- Retention: we keep your Robin Baby records as described in Section 9. The copy that reaches your Muse conversation is retained by Meta under your account's settings; deleting a Robin Baby record does not remove it from a past Muse conversation. Delete the conversation in Muse as well if you want it gone from there.
- Your controls: disconnect at any time from Muse's connector settings. Muse then stops using the access it holds for your Robin Baby account, and the short-lived access token it was using expires within an hour. Disconnecting is also how you withdraw the consent described above; because it happens inside Muse, it is Muse that stops calling us. We remember which child you selected, so if you reconnect later you may not be asked to choose again — email hello@robinbaby.com if you would like that record cleared. Deleting your account removes your Robin Baby data as set out in Section 9. Disconnecting does not delete past Muse conversations.
- Not medical advice: answers are informational, may be incomplete or wrong, and are not a substitute for professional medical care. See Section 13.
- Meta's privacy policy: https://www.facebook.com/privacy/policy/, and how Meta handles AI conversations: https://www.facebook.com/privacy/genai/
6. How AI Processing Works
Robin Baby uses AI (large language models) in several ways. We want to be transparent about how this works:
Voice-to-Event Processing
- You speak into the app
- Your audio is sent (encrypted) to our backend server
- Our server sends the audio to Groq for speech-to-text transcription
- The resulting text transcript is sent to Groq (or OpenAI/Vertex AI as fallback) for structured event extraction
- The AI identifies events in your speech (e.g., "She had 4 oz of formula at 2pm") and returns structured data
- The structured events are saved to your timeline
- The original audio recording is discarded — it is not stored long-term
Question Answering
- You type or speak a question (e.g., "How much did she sleep this week?")
- Your question, along with relevant event data from your timeline (which may include child names, health events, feeding records, sleep data, and other logged information), is sent to Groq (or OpenAI as fallback) for processing
- The AI generates an answer based on your data
- Your question is saved to your local question history so you can re-ask it later. A brief preview is stored locally, but the full generated answer is not persisted — it is regenerated each time you revisit a question. On the backend, questions are logged for service quality and diagnostics.
AI Model Training
- Based on their published API terms, OpenAI, Groq, and Google Cloud/Vertex AI do not use data submitted via their APIs to train their models. We select providers whose terms prohibit using customer data for model training, and we monitor their policies for changes. We encourage you to review their terms directly for the most current information.
- We do not use your data to train any AI models. Your child's data is used solely to provide you with the Robin Baby service.
- The optional ChatGPT, Claude and Muse connectors are outside the first point above. If you connect one, data reaches OpenAI as the operator of ChatGPT, Anthropic as the operator of Claude, or Meta as the operator of Muse, rather than through our API account — so the applicable retention and model-training settings are those of your own account with that assistant. See Section 5.12, Section 5.13 and Section 5.14.
7. Data Sharing and Disclosure
We do NOT:
- Sell your personal information to anyone, ever
- Share your data with advertisers or advertising networks
- Share your data for cross-app tracking
- Use your health data for marketing or advertising purposes
We DO share data with:
- Third-party service providers listed in Section 5, solely to operate the app. Each provider receives only the minimum data needed for its purpose and is bound by its own privacy commitments.
- Family members you invite — when you add a caregiver to your family, they can see and contribute to the shared child timeline. You control who has access.
- OpenAI, if you connect ChatGPT — only if you turn on the optional ChatGPT connector yourself, and only for the child you select. See Section 5.12.
- Anthropic, if you connect Claude — only if you turn on the optional Claude connector yourself, and only for the child you select. Claude also receives the OAuth client credentials it needs to sign you in after you consent. See Section 5.13.
- Meta, if you connect Muse — only if you turn on the optional Muse connector yourself, and only for the child you select. See Section 5.14.
- Law enforcement or legal process — only if we are compelled by a valid legal request (subpoena, court order, or equivalent). We will notify you unless legally prohibited from doing so.
We will NEVER share data with:
- Data brokers
- Insurance companies
- Employers
- Any party for purposes unrelated to providing the Robin Baby service
8. Data Security
We implement the following security measures to protect your data:
- Encryption in transit: All data transmitted between your device and our servers uses HTTPS/TLS encryption
- Encryption at rest: Data stored in our database is encrypted at rest using industry-standard encryption provided by our hosting infrastructure
- Row-Level Security: Our database enforces family-level data isolation, meaning one family's data is inaccessible to another family — enforced at the database level, not just the application level
- Authentication: Secure login via email OTP, Google Sign-In, or Sign in with Apple. No passwords are stored.
- Access controls: Only authorized personnel at Bunny Hopper Labs Inc. have access to production data, and only when necessary for operating and maintaining the service
No system is perfectly secure. If we become aware of a security breach that affects your personal data, we will notify you in accordance with applicable law.
9. Data Retention and Deletion
While your account is active
We retain all your data for as long as your account is active and you continue to use the app.
Voice recordings
Voice audio is processed transiently for transcription purposes and is not retained after processing is complete. Only the resulting text transcript and structured data are stored.
Account deletion
You can request deletion of your account and all associated data at any time by:
- Using the account deletion option within the app (Settings > Account > Delete Account)
- Emailing us at hello@robinbaby.com
When you request account deletion:
- Your account enters a 30-day grace period during which you can change your mind and restore your account
- After 30 days, your account and all associated data are permanently and irreversibly deleted, including:
- Your account profile
- All child profiles you created
- All event data, timeline entries, and question history
- All family relationships and invitation data
- All analytics and crash data linked to your user ID
- Data that has already been processed by third-party services (e.g., analytics events already sent to PostHog) is subject to those services' own retention policies
Subscription data
If you cancel a paid subscription, RevenueCat retains a record of your subscription history. Deleting your Robin Baby account will remove your user ID association from our systems, but RevenueCat may retain anonymized purchase records as required by Apple and Google for financial compliance.
10. Your Rights and Choices
Depending on where you live, you may have the following rights regarding your personal data:
For all users
- Access: You can view all the data we have about you and your children directly within the app
- Export / Portability: You can export your data at any time using the export feature in the app
- Deletion: You can delete your account and all associated data (see Section 9)
- Correction: You can edit your profile information, child profiles, and event data directly in the app at any time
For users in the European Economic Area (EEA), UK, and Switzerland (GDPR)
In addition to the above, you have the right to:
- Rectification: Request correction of inaccurate personal data
- Restriction: Request that we limit processing of your data in certain circumstances
- Objection: Object to processing of your data based on our legitimate interests
- Portability: Receive your personal data in a structured, commonly used, machine-readable format (CSV) via the app's export feature
- Automated decision-making: You have the right not to be subject to decisions based solely on automated processing that produce legal or similarly significant effects. Robin Baby does not make such decisions — all AI outputs are informational only.
- Object to legitimate-interest processing: Object to the processing of your data for analytics, marketing measurement, or crash reporting at any time by emailing hello@robinbaby.com. We will exclude your account from analytics processing within 7 days of your request.
- Withdraw consent for processing that requires it. Device-level permissions (microphone, camera, push notifications) can be revoked at any time through your operating system settings. Consent for the optional ChatGPT connector can be withdrawn by disconnecting it in ChatGPT's connector settings, for the optional Claude connector by disconnecting it in Claude's connector settings, and for the optional Muse connector by disconnecting it in Muse's connector settings — see Section 5.12, Section 5.13 and Section 5.14. Withdrawal does not affect the lawfulness of processing before it.
- Lodge a complaint: File a complaint with your local data protection authority
Legal basis for processing:
- Contract performance (GDPR Art. 6(1)(b)): We process account data, child profiles, event data, voice recordings, and AI inputs to provide the Robin Baby service you signed up for. This is the legal basis for the data we need to make the app work at all.
- Legitimate interests (GDPR Art. 6(1)(f)): We process product analytics (PostHog), marketing-measurement analytics (Google Firebase Analytics, Android only), and crash/error reports (Sentry) under legitimate interest. The interests pursued are: improving the product based on aggregate usage patterns, measuring whether our marketing campaigns reach the right audience, and maintaining service reliability through crash reporting. The processing is minimal (opaque user ID only, no name/email/voice/child data, no cross-app tracking), serves interests users share (a better-functioning app), and you can object via the procedures above.
- Consent (GDPR Art. 6(1)(a)): Device-level permissions (microphone, camera, push notifications) require your explicit consent through your operating system.
- Explicit consent (GDPR Art. 9(2)(a)): the optional ChatGPT, Claude and Muse connectors share data that may concern health — food and suspected-allergen entries for the child and for the nursing parent, and growth measurements — with OpenAI, Anthropic and Meta respectively. Each operates only on the explicit consent you give when connecting it, and you can withdraw that consent by disconnecting. See Section 5.12, Section 5.13 and Section 5.14.
- Legitimate interests (GDPR Art. 6(1)(f)): We process crash and error reports (Sentry) to keep the service working reliably, balanced against your privacy interests. This processing is minimal (opaque user ID, stack traces, device type — no IP, no PII), serves a clear interest the user shares (a working app), and you can object via the procedures in this section.
To exercise any of these rights, contact us at hello@robinbaby.com. We will respond within 30 days (or sooner as required by applicable law).
For users in California (CCPA/CPRA)
- You have the right to know what personal information we collect, use, and disclose
- You have the right to request deletion of your personal information
- You have the right to opt out of the sale of personal information — however, we do not sell your personal information
- You will not be discriminated against for exercising your privacy rights
Device-level permissions
You can revoke the following permissions at any time through your device settings:
- Microphone access — required for voice input features
- Camera access — required for scanning handwritten notes
- Photo library access — required for selecting photos
- Push notifications — required for reminders and alerts
Revoking a permission will disable the associated feature but will not affect the rest of the app.
11. Children's Privacy (COPPA)
Robin Baby takes children's privacy seriously.
The app is for parents, not children
Robin Baby is designed for use by adults (parents, guardians, and caregivers). The app is not directed at children under 13 and children should not create accounts or use the app directly.
Data about children, collected from parents
The app collects personal information about babies and children — including names, dates of birth, health events, and growth measurements — but this information is provided by their adult parents and caregivers. Parents are the users of the app and control all data about their children.
Parental control
- Parents decide what to record. Every piece of data about a child is entered by a parent or caregiver.
- Parents control access. Only family members explicitly invited by a parent can view a child's data.
- Parents can delete everything. Deleting an account removes all data about the associated children (see Section 9). Individual child profiles can also be removed independently.
- Parents can export data. All data about a child can be exported at any time.
Verifiable parental consent
Because only authenticated adults can create accounts and enter child data, the act of creating a child profile and entering data about a child constitutes verifiable parental consent under COPPA and PIPEDA. We verify that users meet our age requirement (18+) through the age restrictions enforced by the Apple App Store and Google Play Store.
Our commitment
- We do not knowingly collect personal information directly from children under 13
- We do not use children's data for advertising, marketing, or profiling
- We do not share children's data with third parties for any purpose other than providing the Robin Baby service (as described in Section 5)
- If we learn that a child under 13 has created an account, we will delete it promptly
If you believe a child has provided us with personal information directly, please contact us at hello@robinbaby.com and we will take immediate steps to remove that information.
12. International Data Transfers
Robin Baby is operated by Bunny Hopper Labs Inc., based in Canada. Your data is processed and stored on servers located in the United States through our third-party service providers (including Supabase, OpenAI, and Groq). If you switch on an optional connector, data also travels to the United States to OpenAI, Anthropic or Meta as the operator of the assistant you are using, not as our service provider. See Section 5.12, Section 5.13 and Section 5.14.
If you are located outside the United States or Canada (including in the European Economic Area, UK, or elsewhere), your data will be transferred to and processed in the United States. By using Robin Baby, you consent to this transfer.
We rely on the following safeguards for international data transfers:
- EU-US Data Privacy Framework (DPF): Our analytics and crash-reporting providers (PostHog, Google Firebase, Sentry) participate in the EU-US Data Privacy Framework, which the European Commission recognizes as providing adequate protection for personal data transferred from the EEA to participating US companies. You can verify any provider's participation at https://www.dataprivacyframework.gov/.
- Standard Contractual Clauses (SCCs): For service providers that do not participate in the DPF, we rely on the European Commission's Standard Contractual Clauses or equivalent transfer mechanisms.
- Encryption: All data is encrypted in transit (TLS) and at rest.
- Canada's PIPEDA: Our home jurisdiction's Personal Information Protection and Electronic Documents Act provides a framework recognized as adequate by the European Commission.
If you have concerns about international data transfers, please contact us at hello@robinbaby.com.
13. Health Data
Robin Baby stores health-related information about your child, including feeding data, sleep patterns, medication records, symptom logs, temperature readings, growth measurements, vaccination records, and allergy information.
Important points about health data:
- This data is entered and controlled entirely by you — we do not collect health data from any other source
- Health data is used solely to provide the Robin Baby service (timeline, AI answers, doctor summaries)
- Health data is never used for advertising, marketing, or profiling
- Health data is never sold or shared with insurers, employers, data brokers, or any other non-essential third party — other than a disclosure you switch on yourself, such as the optional ChatGPT, Claude or Muse connectors described below
- Health data is shared with AI providers (OpenAI, Groq, Vertex AI) only to the extent necessary to process your requests (event extraction, question answering) and is not used to train AI models
- Three exceptions, and only if you choose them: the optional ChatGPT, Claude and Muse connectors. There, OpenAI receives data as the operator of ChatGPT, Anthropic as the operator of Claude, and Meta as the operator of Muse, under the terms and settings of your own account with that assistant — including its retention and any model-training setting, which we do not control. The statement immediately above, about AI providers, describes OpenAI acting as our service provider via their API; it does not extend to any of the connectors. See Section 5.12, Section 5.13 and Section 5.14.
- You can export all health data at any time and delete it by deleting your account
Robin Baby is not a medical device and does not provide medical advice. The data and AI-generated answers in the app are for informational and tracking purposes only and should not be used as a substitute for professional medical care.
14. Advertising and Tracking
We don't show ads, we don't sell your data, and we don't track you across other apps. Here's exactly what we do and don't do:
What we never do:
- No in-app advertising. Robin Baby does not display ads of any kind. You will never see a sponsored post, banner ad, or promoted content inside the app.
- No data sold to advertisers, ever. We don't sell or share your information with data brokers, advertisers, or social media platforms.
- No cross-app tracking. We do not track you across other apps or websites you use.
- No Apple IDFA. We do not read or use Apple's Identifier for Advertisers (IDFA) on iOS.
- No third-party advertising or social-media SDKs. No Meta Pixel, no TikTok SDK, no Snapchat SDK, no Branch, no AppsFlyer, no Adjust, no LinkedIn Insight Tag.
What we do for marketing measurement (Android only):
When we run an ad to recruit new parents — for example, a Google search ad for "baby sleep tracker" — we need a way to know whether the ad worked. For this we use Google Firebase Analytics on Android, which records app-installation conversion events (sign-up, paywall view, purchase) tied to an opaque, randomly-generated app installation ID. The data goes to Google so we can measure marketing effectiveness — never to target you with ads, never to share your information with other advertisers, never to build a profile about you.
On Android, Firebase Analytics may read the Google Advertising ID (a device-level identifier Google maintains for advertising measurement) for conversion attribution. You can reset this ID at any time in your Android system settings.
For product analytics, we use PostHog to understand how features are used and where the app could be better. PostHog receives an opaque user ID (never your name, email, voice notes, photos, or anything about your child), event names, screen views, and basic device info (type, app version, country).
For crash and error reporting, we use Sentry. We've configured it to never receive your IP address, your account credentials, or any of your child's data.
All three providers process data in the United States under the EU-US Data Privacy Framework, and we process this analytics data under the GDPR legal basis of legitimate interest (Art. 6(1)(f)). If you would prefer we not process your analytics data, email hello@robinbaby.com and we will exclude your account from analytics processing.
15. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last Updated" date at the top of this page
- For significant changes, we will notify you via in-app notification or email before the changes take effect
- Continued use of Robin Baby after changes take effect constitutes acceptance of the updated policy
We encourage you to review this policy periodically.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:
- Company: Bunny Hopper Labs Inc., Kitchener, Ontario, Canada
- Email: hello@robinbaby.com
- Website: https://www.robinbaby.com
We aim to respond to all inquiries within 30 days.
This Privacy Policy is effective as of September 14, 2026. It was first published on April 7, 2026.
Robin Baby