BabyDaze Privacy Policy
Last updated 2026-09-20.
BabyDaze exists to keep videos of a child private to the people who love them. This policy explains what we collect, why, and what we never do with it.
What we collect
| Data | Why | Where it lives |
|---|---|---|
| Apple account identifier and, if you choose to share it, email address | To sign you in | Supabase Auth (encrypted at rest) |
| Legacy phone number, for accounts created before Apple-only sign-in | To preserve the existing account during migration | Supabase Auth and our database |
| Name, optional profile photo, avatar colour, relationship label | So people in a circle recognise you | Profile details in our database; optional photo in private Cloudflare R2 storage |
| Journal details: child's name, birthday, timezone, colour | To build the calendar | Our database |
| Clips and photos, their recorded audio, captions, when they were recorded | The product | Cloudflare R2 in a private bucket; served only with short-lived signed links |
| Who is in each circle and their roles | To enforce who can see what | Our database |
| Comments, reports, who watched, screenshot events | Shown to the circle or to parents as described in the app | Our database |
| Precise location, accuracy, and an expiring nearby-camera token | Only if an adult turns on nearby Group Cam while the app is in the foreground | Our database for a matching lease of at most 30 seconds |
| Notification settings and device notification identifiers | To send the notifications you turn on | Our database, Apple, and Google Firebase |
Nearby Group Cam is optional and off until an adult turns it on from its foreground screen. When it is on, BabyDaze sends a fresh latitude, longitude, and accuracy sample to the private matching service so it can find an eligible family camera nearby. The service keeps that sample for no more than 30 seconds, removes it immediately when the person turns nearby location off, leaves the screen, backgrounds the app, changes account or access, or loses authorization, and returns only opaque candidates rather than another person’s coordinates or distance. We do not use location for advertising or tracking.
We do not collect contacts (the contact picker stays on your phone), advertising identifiers, or information about your browsing outside BabyDaze. Google Firebase processes crash reports, technical errors, app-use events (screens visited, sign-in steps, recording or importing, posting outcomes, playback starts and watch time, comments, invitations, and notification choices), and performance measurements such as startup, playback, and posting time, connection type, measured video-transfer speed, buffering, video dimensions, and preloading results. Temporary random playback-visit identifiers connect related technical events without identifying the video. These reports include app version, device and operating-system information, timestamps, and a Firebase installation identifier. We do not attach your BabyDaze account, family names, captions, private media, or signed media links to these reports. Automatic network tracing and advertising measurement are disabled. We do not upload delayed Apple MetricKit payloads.
How access works
Every request is checked against the journal's rules in our database. A clip or profile photo is only delivered through a short-lived link that we create for people the rules allow. Parents can see everything in their journal, including who watched, clips waiting for review, and reports from that journal.
Children
Children are the subjects of journals, not users. We do not knowingly collect information from children, require account holders to affirm that they are adults during setup, and let parents control and delete every journal about their child.
Sharing
We do not sell data and we do not share it with advertisers. The only third parties that process your data are the providers that run the service: Supabase (database, authentication, functions), Cloudflare (video storage and delivery), Apple (sign-in and push notifications), and Google Firebase (crash reporting, app analytics, performance monitoring, and push notification delivery). Optional sharing with Google advertising, benchmarking, and account-specialist services is disabled.
We disclose data when the law requires it, and we report child sexual abuse material to the National Center for Missing and Exploited Children or the equivalent authority.
Your choices
- Turn notifications on or off, per kind and per journal, in Settings.
- Leave any circle, or remove your own clips, at any time.
- When you choose Save to Photos or Share video for an optional covered-video export, that file leaves BabyDaze and is handled by Photos or the destination you select under its own terms and privacy practices.
- Delete your account in Settings. Your videos, comments, and profile are deleted from every journal, including shared journals. Journals where you are the only parent are deleted with all their clips. Deletion is confirmed after live media is removed and Apple sign-in access is revoked. Residual copies may remain in encrypted service backups for up to 30 days before being overwritten through the providers' normal backup cycle, unless a longer period is legally required.
- Ask us for a copy of your data: chris@carmylabs.com.
Security
Data is encrypted in transit and at rest. Video links are signed and expire. Sign-in uses Apple authentication. You can add a Face ID lock to the app in Settings.
International
Our providers store data in the region you choose when the project is created. If you use BabyDaze from elsewhere, your data is transferred to that region.
Changes
We will tell you in the app before material changes take effect.
Contact
Carmy Labs
310-895-8146