Privacy Policy
Last updated: 2026-04-20
The short version. Your data is yours. We use it only so the helper can help you. We don't sell anything. You can download or delete everything any time.
What we collect.
- Your account: email, name, avatar (if you sign in with Google), language, time zone.
- Your baby's profile: name, birth date, weight, gender, temperament, notes, feeding type — all optional except birth date.
- What you track: sleeps and feedings.
- Your chat with Kessi and the summaries it makes.
- Technical records: IP and browser at sign-in and key events — so we can spot suspicious activity.
What we never collect. Precise location, your contacts, photos, fitness-tracker data. No third-party advertising trackers.
Why we use your data. Only so Kessi can give advice that fits your baby. Nothing else.
Who sees it.
- Anthropic — the company that makes the AI model. Receives the text of your chat so Kessi can reply. Won't use your messages to train their model.
- OpenAI — helps with searching your history and checking message safety. Same rule — no training on your data.
- Google / Apple — only if you choose to sign in through them.
- Our servers (hosting and error monitoring) — the technical infrastructure that keeps the app running. All proper data-protection agreements are in place.
Payment data. When you pay for Premium:
- Card numbers, CVV and other raw payment details never touch our servers. They're handled by the payment provider (YooMoney for Russia; Stripe or Lemon Squeezy for the international channel).
- We only receive technical payment identifiers (operation_id / provider_event_id), the amount, and the payer (matched by the email on your account). These records live in the `payment_events` table for at least 5 years — that's what Russian bookkeeping law (402-FZ) requires.
- A tax receipt (for self-employed sellers under the NPD regime) is generated manually through the "My Tax" service and emailed to you.
- Refunds (when applicable — see the Refund Policy) are processed through the YooMoney dashboard; we don't receive any extra financial data in the process.
How long we keep it.
- While you use SleepBaby — your data stays with you.
- If you delete your account — exactly 30 days in a "trash bin" (sign in with the same email to restore). After that everything is wiped, no traces.
- Sign-in and security records are kept up to 7 years (legally required) but with your name and email stripped — only the fact that something happened, not who.
What you can do with your data.
- Download it all: Settings → "Download my data".
- Edit it: Settings → Baby profile.
- Delete it: Settings → "Delete my account".
- If something seems off, write to us: privacy@sleepbaby.example
This is for parents, not kids. Children don't use the app themselves. We don't show them ads or build profiles on them.
Where your data lives. Mainly on European servers (Frankfurt). Sometimes part of the data may be processed in the US — we have all the necessary agreements for that.
Security. Everything is encrypted, both moving and at rest. Sessions expire on a schedule, there's protection against brute-force attempts. We track sign-ins so we can notice anything suspicious.
If anything changes. We'll tell you in the app, in advance.