Privacy Policy
Effective: March 28, 2026 · Last updated: March 28, 2026
1. Who We Are
MilkPrint is operated by MilkPrint ("we," "us," or "our"). This policy applies to the MilkPrint mobile application available on iOS and Android, and the website at milkprint.app.
For questions about this policy, contact us at privacy@milkprint.app.
2. Data We Collect
Health & baby data (stored on your device only):
- Feeding logs (breastfeeding times, bottle volumes, pump sessions)
- Sleep logs (nap and nighttime duration)
- Diaper logs (wet, dirty, mixed)
- Temperature readings
- Growth measurements (weight, height, head circumference)
- Milestones and notes
This data is stored locally on your device using SQLite. It is never uploaded to our servers unless you explicitly use a feature that requires it (such as AI chat or caregiver sharing).
Account data (if you create an account):
- Phone number or email address (for authentication)
- Display name (optional)
- Baby's name and date of birth
- Country and region (for vaccine schedules and cultural content)
- Feeding method preference
Account data is stored securely in our cloud database (Supabase, hosted in the EU — Frankfurt, Germany).
Anonymous analytics:
- Screen views, feature usage, and crash reports
- Collected via PostHog with anonymous identifiers
- No personally identifiable information is included
- Used solely to improve the app experience
3. Data We Do NOT Collect
- We do not access your camera, microphone, photos, contacts, or GPS location
- We do not use advertising identifiers (IDFA/GAID)
- We do not connect to HealthKit, Google Fit, or Bluetooth devices
- We do not serve ads or share data with ad networks
- We do not sell, rent, or trade your personal data
4. How We Use Your Data
- Baby tracking: To display your logs, charts, and reports within the app
- AI features (Premium): When you ask a question in AI chat, relevant log summaries are sent to our AI provider (Anthropic) to generate a response. No raw health data is stored by Anthropic after processing.
- Weekly reports (Premium): Summary statistics are processed server-side to generate your weekly AI report
- Caregiver sharing (Family): When you invite a caregiver, selected data is synced via our cloud database so both caregivers can view it
- Subscription management: Purchase data is processed by Apple (App Store), Google (Play Store), and RevenueCat (our subscription management provider)
- Analytics: Anonymous usage data helps us understand which features are most valuable and where to improve
5. Third-Party Services
MilkPrint uses the following third-party services:
- Supabase (EU — Frankfurt): Authentication, cloud database for accounts and caregiver sharing
- Anthropic (Claude): AI chat responses and weekly report generation. Data is processed and not retained.
- RevenueCat: Subscription and in-app purchase management
- PostHog: Anonymous product analytics
- Twilio: SMS delivery for phone number verification (OTP codes)
- Apple / Google: Push notifications (if enabled), app distribution, and payment processing
We do not share data with any service not listed above.
6. Device Permissions
MilkPrint requests only one optional permission: push notifications (for feeding reminders and caregiver updates). You can decline or revoke this at any time in your device settings.
We will never request access to your camera, microphone, photo library, GPS location, contacts, Bluetooth, or health platforms (HealthKit / Google Fit).
7. Data Storage & Security
- Health data is stored locally on your device using encrypted SQLite (via MMKV for session data)
- Cloud data (accounts, caregiver sharing) is stored in Supabase with row-level security (RLS) — each user can only access their own data
- All network communication uses TLS 1.2+ encryption
- Authentication tokens are stored securely on-device and refreshed automatically
8. Data Retention
- On-device data: Retained until you delete the app or clear app data
- Account data: Retained while your account is active. Deleted within 30 days of account deletion request.
- Analytics data: Retained for 12 months in anonymized form, then automatically purged
- AI chat logs: Not retained by our AI provider after processing. Chat history is stored on your device only.
9. Your Rights
Regardless of where you live, you have the right to:
- Access your personal data — request a copy at any time
- Correct inaccurate data in your profile
- Delete your account and all associated cloud data
- Export your data via CSV or PDF from within the app (Premium)
- Withdraw consent for analytics or notifications at any time
- Object to data processing — contact us and we will accommodate
If you are in the EU/EEA, you have additional rights under GDPR including the right to data portability and the right to lodge a complaint with your local data protection authority.
10. Children's Privacy
MilkPrint is designed for parents and caregivers — not for children to use directly. We do not knowingly collect personal information from anyone under 16 years of age. The baby data entered in the app is provided by the parent or caregiver, not by the child.
11. International Data Transfers
Our cloud infrastructure is hosted in the EU (Frankfurt, Germany). If you access MilkPrint from outside the EU, your account data is still stored in the EU. Anonymous analytics data may be processed in the US by PostHog. AI requests are processed by Anthropic in the US. All transfers are protected by TLS encryption and appropriate data processing agreements.
12. Changes to This Policy
We may update this policy from time to time. If we make material changes, we will notify you via an in-app notice or email before the changes take effect. The "last updated" date at the top of this page reflects the most recent revision.
13. Contact
If you have questions about this privacy policy or your data:
- Email: privacy@milkprint.app