Privacy Policy
Last Updated: June 14, 2026
What this Privacy Policy means in plain language
The full legal text is below. As a quick overview for English-speaking parents in the US, UK, Canada, Australia and New Zealand: Baby Soma stores only the information you log inside the app - child profile basics, sleep sessions, optional photos, and AI chat questions. We do not sell that data, we do not share it with third-party advertisers, and we honor deletion requests within 7 days. The policy aligns with the UK Data Protection Act 2018, GDPR for any EU/EEA users on the site, the California Consumer Privacy Act (CCPA), and Apple's App Store Review guidelines.
- -Right to access: ask us for a copy of all the data tied to your account, in a machine-readable format.
- -Right to correction: edit or correct any sleep entry, child profile field, or family member detail directly in the app.
- -Right to deletion: email support@babysoma.app and we delete the account, every child profile, all sleep history, family chat, and AI consultant logs within 7 days.
- -Right to opt out of personalized ads: deny App Tracking Transparency on iOS, or revoke it any time in iOS Settings → Privacy & Security → Tracking.
- -Your account and subscription: anything you buy on babysoma.app is tied to an account you control. You can cancel a website subscription anytime at babysoma.app/account, and close your account and delete all your data whenever you want by emailing support@babysoma.app (removed within 7 days).
1. Introduction
Welcome to Baby Soma ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the "App").
By using the App, you consent to the data practices described in this policy.
2. Information We Collect
A. Information You Provide to Us
We collect information that you voluntarily provide when using the App:
- Account Information: When you register, we collect your email address or phone number. If you use social login (Apple or Google), we receive your public profile information and email.
- Child Profile Data: To provide sleep tracking and analysis, we collect your child's name, birth date, and gender. You may optionally upload a profile photo.
- Sleep Data: We collect the sleep logs you enter, including sleep start/end times, wake windows, and sleep quality notes.
- AI Chat Interactions: When you use our AI Sleep Coach, the text of your questions and the context of your child's sleep data are processed to generate responses.
- Family Collaboration Data: When you use the Family feature, we collect information about family members you invite (email addresses or phone numbers) and store family chat messages, including text messages, photos, and voice messages that you send within the family chat.
- Daily Digest Preferences: We store your preferences for receiving daily summaries and insights about your child's sleep patterns.
- Sleep Settings and Preferences: We collect your sleep coach settings, including desired wake-up times, bedtime preferences, sleep issues, notification preferences, and lullaby player settings.
B. Information Collected Automatically
- Device Information: We collect device ID (IDFA/IDFV), device model, operating system version, and IP address.
- Usage Data: We track how you interact with the App, such as features used, time spent, and buttons tapped.
- Advertising Data: If you use the free version of the App, we use Google AdMob to display advertisements. AdMob may collect your device identifier (IDFA) to show personalized ads (if you have granted permission via App Tracking Transparency).
- App Tracking Transparency (ATT): We request permission to track your activity across other companies' apps and websites to show you personalized ads and measure ad performance. You can grant or deny this permission when prompted, and change your choice at any time in iOS Settings > Privacy > Tracking. If you deny tracking permission, you will still see ads, but they will be less relevant to you.
- Push Notification Tokens: We collect and store Firebase Cloud Messaging (FCM) tokens to send you push notifications about family chat messages, sleep reminders, and growth spurt alerts.
- Live Activity Data: When you use the sleep tracking feature, we may use iOS Live Activities and Dynamic Island to display real-time sleep status on your lock screen and Dynamic Island.
- Session Analytics (Microsoft Clarity): We use Microsoft Clarity to understand how users interact with the App. Clarity collects anonymized session replay data and heatmaps (tap and scroll patterns). No personal data such as names, sleep logs, or chat messages is recorded. Clarity does not track you across other apps or websites. You can opt out of analytics in the App settings.
C. Permissions We Request
The App may request the following device permissions to provide specific features:
- Photo Library: To allow you to upload profile pictures for your child and share photos in family chat. You can also save photos from family chat to your device.
- Camera: To take photos directly for family chat messages or profile pictures.
- Microphone: To record and send voice messages in family chat.
- Notifications: To send you reminders about sleep schedules, family chat messages, and important alerts.
You can manage these permissions at any time in your device settings. Denying permissions may limit certain features but will not prevent you from using core sleep tracking functionality.
3. How We Use Your Information
- Core Functionality: To track your child's sleep, calculate wake windows, predict growth spurts, and generate personalized sleep schedules.
- AI Analysis: We use OpenAI services (GPT-4o-mini model) to analyze your child's sleep patterns and provide personalized advice in the AI Chat.
- Account Management: To manage your account, subscriptions, and sync data across devices via Firebase.
- Advertising: To display rewarded video ads via Google AdMob (for non-premium users). With your permission via App Tracking Transparency, we use your device identifier (IDFA) to show personalized ads based on your interests and measure ad performance across other apps and websites. This helps us provide free access to the App while generating revenue to support development.
- Improvement: To analyze usage trends and improve the App's performance and features.
- Family Collaboration: To enable family members to share access to a child's profile, communicate via family chat, and receive real-time updates about the child's activities.
- Notifications: To send push notifications about sleep reminders, family chat messages, growth spurt alerts, and other important updates you've chosen to receive.
- Daily Insights: To generate and deliver daily digest summaries of your child's sleep patterns and provide actionable recommendations.
- Cloud Storage: To store uploaded photos and voice messages in Firebase Cloud Storage for family chat functionality.
4. Sharing of Your Information
We do not sell your personal data. We share information only with the following third-party service providers who assist us in operating the App:
- Google Firebase: For authentication, database storage (Firestore), cloud functions, cloud storage (for photos and voice messages), analytics, and push notifications (FCM).
- OpenAI: We send anonymized sleep data and your questions to OpenAI to generate AI responses.
- Google AdMob: For delivering advertising content.
- RevenueCat / Apple StoreKit: For processing subscription payments.
- Microsoft Clarity: For anonymized session replay, heatmaps, and usability analytics. Clarity does not collect personal information or sleep data.
- Meta Platforms (Facebook / Instagram): On our website babysoma.app - especially the checkout - we use the Meta Pixel and the Meta Conversions API to measure ad performance and conversions. We share with Meta hashed (SHA-256) identifiers - your email, phone, name, city, region, postal code, country and account ID - together with the Meta cookies (_fbp / _fbc), your IP address and browser user agent. Identifiers are hashed before they leave our servers. We use this only for advertising measurement and optimization, and we never sell this data.
- Website payment processors (Stripe, NOWPayments, Coinbase Commerce): To process the card and cryptocurrency subscription payments you make on babysoma.app. They receive the payment details you enter and your email so the subscription can be granted.
Exactly what we send to Meta (Facebook / Instagram) from the website
When you browse babysoma.app and use the checkout - and only after you accept marketing cookies - we send the following to Meta through the Pixel (in your browser) and the Conversions API (from our server) to measure and optimize advertising. Personal identifiers are irreversibly hashed with SHA-256 before sending, so Meta receives hashes, not your raw details:
- Hashed email address
- Hashed phone number
- Hashed first and last name
- Hashed city, region/state, postal code and country
- Your Baby Soma account ID (external_id), to match events to your account
- The Meta browser cookies _fbp and _fbc (advertising identifiers)
- Your IP address and browser user agent
- The action and its context: page view, offer view (ViewContent), checkout started (InitiateCheckout), trial started (StartTrial) and purchase (Purchase) - with the amount and currency for a purchase
We never send your child's data, sleep logs, family chat or AI chat to Meta, and we do not sell this data. If you decline marketing cookies in the cookie banner, the Pixel stays off and no website advertising data is sent.
Sharing Within Family Groups
- All invited family members (guardians) can view the child's sleep data, settings, and growth information.
- Family chat messages, photos, and voice messages are shared with all members who have access to that child's profile.
- You control who has access by sending invitations. You can remove family members' access at any time from the Family section.
- Each family member sees the same synchronized data in real-time through Firebase Firestore.
5. Medical Disclaimer
Baby Soma is not a medical device. The insights, sleep schedules, and AI advice provided by the App are for informational purposes only and do not constitute medical advice, diagnosis, or treatment. Always seek the advice of your pediatrician or qualified health provider with any questions regarding your child's health or sleep.
6. Data Retention and Deletion
- Delete Account: You can delete your account and all associated data at any time directly within the App settings (Settings -> Delete Account). Upon request, your data is permanently removed from our servers.
- Family Chat Data: When you delete your account, all family chat messages, photos, and voice messages you created are also deleted. However, data shared with other family members will remain in their access until they also delete their accounts or remove the child profile.
- Invitation Data: Pending invitations are automatically expired after a certain period and can be manually cancelled at any time.
- Cloud Storage: Uploaded media files (photos and voice messages) are permanently deleted when the associated messages or accounts are deleted.
7. Data Security
- Encryption: All data transmitted between your device and our servers is encrypted using SSL/TLS protocols.
- Firebase Security Rules: We use Firestore Security Rules to ensure that only authorized users (account owners and invited guardians) can access child profile data and family chat messages.
- Authentication: We use Firebase Authentication with secure token-based access control.
- Cloud Storage Security: Uploaded files are stored securely in Firebase Cloud Storage with access restricted to authorized family members only.
While we strive to use commercially acceptable means to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure.
8. Children's Privacy (COPPA)
Our App is intended for use by parents and guardians (users over 18). We do not knowingly collect personal information directly from children under 13. The data about children is provided solely by the parent/guardian who has the legal authority to do so.
9. Your Rights and Choices
- Access and Update: You can view and edit your account information, child profiles, and settings at any time within the App.
- Delete Data: You can delete specific sleep sessions, chat messages, or your entire account through the App settings.
- Manage Family Access: You can invite, view, and remove family members' access to your child's profile at any time.
- Notification Preferences: You can control which types of push notifications you receive in the App's settings or your device's notification settings.
- Advertising Preferences: You can limit ad tracking through your device's privacy settings (iOS: Settings > Privacy > Tracking).
- Export Data: Contact us if you wish to receive a copy of your data.
10. International Users
Your information may be transferred to and maintained on servers located outside of your state, province, country, or other governmental jurisdiction where data protection laws may differ. By using the App, you consent to the transfer of your information to the United States and other countries where our service providers operate.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last Updated" date. Significant changes will be communicated through the App or via email.
12. Google User Data and Limited Use
When you choose to sign in with Google, Baby Soma accesses a limited set of Google user data through Google Sign-In (Google OAuth).
- Data accessed: your name, email address, and profile picture from your basic Google profile, obtained only after you explicitly sign in with Google.
- How we use it: solely to create and authenticate your Baby Soma account and to identify you inside the app. We do not use Google user data for advertising or any unrelated purpose.
- Sharing: we do not sell Google user data. We do not share it with third parties, except with Google Firebase Authentication, which processes it on our behalf to operate the sign-in. We never share it with advertisers.
- Storage and protection: Google user data is stored securely in Google Firebase (Google Cloud) and protected by Firestore Security Rules, with access restricted to your account.
- Retention and deletion: we retain this data while your account is active. You can delete it at any time in Settings -> Delete Account, or by emailing support@babysoma.app, and we remove it within 7 days.
Baby Soma's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
13. Contact Us
If you have questions about this Privacy Policy, please contact us at:
APPROVEX LLC
5830 East 2nd Street
Ste 7000 #18761
Casper, Wyoming 82609
Email: support@babysoma.app
© 2026 · Baby Soma · All rights reserved.