Child Logbook

Privacy policy

Last updated 26 August 2026

This is the whole of what we do with your data. You are keeping a record about a child, and some of that record is about their health, so the short version matters: we store it to show it back to you, we never sell it, and we never use it to train AI models.

1. Who is responsible for your data

The controller is Mikhail Mukhau, Powstańców 41B m. 5, 05-091 Ząbki, Poland (sole trader registered in CEIDG, NIP 9512535915, REGON 521343722, VAT PL9512535915). “We” below means that business. Write to [email protected] about anything on this page and a person will answer.

We have not appointed a data protection officer. We are not required to have one, and the same address reaches whoever can actually act on a request.

This policy covers the Child Logbook app and this marketing site. It sits alongside the terms of service.

2. What we collect, and where it comes from

From you, because you typed or said it. The entries themselves — feeds, nappies, sleep, medicine and its dose, baths, walks, pumping — each with its time, its attributes and any note you added. The people you set up: a name, whether they are a child or an adult, their gender, a birth date if you gave one, and the spoken nicknames you want the app to recognise. Your settings: interface language, voice language, time zone, theme.

From your account, through Clerk. Your email address, your name if you gave one, and the credentials you sign in with. We never receive your password; Clerk holds it and tells us only that a session is valid. We keep a copy of your email and name so we can reach you about billing and support.

From your device, while a request is in flight. The audio or the text of a dictation, and ordinary request metadata — IP address, browser and device information. For the voice-assistant endpoints the IP address goes into a short-lived counter that stops one source flooding us; it is described under retention below.

From Stripe, when you subscribe. Which plan you are on, whether it is active, trialling or past due, when the period ends, and the Stripe customer and subscription ids. Card numbers go straight from your browser to Stripe and never reach us.

From a voice assistant, if you link one. The text the assistant recognised, the assistant’s own opaque id for you, and the device language and time zone it reports. No audio reaches us from an assistant — Yandex, Amazon and Google do their own speech recognition and send us words.

We do not buy data about you, and we do not collect anything from advertising networks, data brokers or social platforms.

3. What we use it for, and on what legal basis

Running the logbook — storing your entries, showing you the timeline and the day summary, letting you edit, export and import them, turning a spoken sentence into an entry, answering a question about your own log. Basis: performance of our contract with you (Art. 6(1)(b) GDPR). Without this data there is no service to provide.

The health-adjacent part of a child’s record — medicine and doses, symptoms you note, feeding and nappies. Basis: your explicit consent (Art. 9(2)(a), together with Art. 6(1)(a)). Section 4 explains this and how to withdraw it.

Accounts, sign-in and keeping accounts apart — identifying you, resolving which account a request belongs to. Basis: contract.

Payments and subscriptions — taking the payment, applying the plan you paid for, handling refunds. Basis: contract.

Invoices and accounting records — issuing invoices and keeping them. Basis: a legal obligation we are under (Art. 6(1)(c)) — Polish tax law requires the records to be kept, and we cannot delete them on request.

Security, abuse prevention and diagnostics — rate limiting, detecting and investigating errors, working out why a dictation was misread. Basis: our legitimate interests (Art. 6(1)(f)) in keeping the service up, keeping other people’s logbooks private, and fixing what is broken. We weighed that against your privacy: application logs are built so that transcripts, names, notes, tokens and cookies never enter them, and the diagnostic record of a failed dictation deletes itself after 90 days.

Support — answering your email. Basis: contract, and our legitimate interest in running a service people can get help with.

We do not profile you, we do not score you, and we do not use your data for advertising. There is no purpose in this app beyond the ones listed above.

4. The health data problem, and your consent

A record that a child was given paracetamol at 03:20, or that they had a temperature, or how they fed, is data concerning health. The GDPR treats that as a special category and forbids processing it unless a narrow exception applies. The exception we rely on is the first one: your explicit consent under Art. 9(2)(a). Nothing else here would cover it.

You give that consent when you accept the terms, create a person in the app and start logging against them. That is a deliberate act about a specific child, for one purpose — running this logbook for you — and for no other.

You can withdraw it at any time, and it costs you nothing to do so. Delete the entries, clear the logbook, or delete the account: Settings → Danger zone. The withdrawal takes effect at once. It does not make the processing before it unlawful, and it does not touch the invoices we have to keep for tax.

Withdrawing consent for a child’s health data means we can no longer keep that record. The app does not have a degraded mode for it: the data goes.

5. Whose data this is, and who agrees on their behalf

The account holder must be an adult. A child never has an account, never signs in and is never asked for anything — they are the subject of a record their parent keeps.

The consent for a child’s data is given by their parent or legal guardian, and by logging that child you confirm you are one, or that you have the guardian’s permission. We have no way to verify that, and we rely on your confirmation.

Where an account also keeps the mother’s own record — feeding, pumping — that data is hers. It needs her agreement, and she has every right in section 11 over it, exercised through the account holder or directly with us at [email protected].

6. Audio, transcripts and the AI

Audio is never stored. When you dictate in the app, your browser records a short clip, posts it, and it exists in memory for the length of that one request while the model reads it. It is never written to a disk, a bucket or a database, on our side or anyone else’s. There is no recording to retrieve, subpoena or leak.

The transcript is kept, attached to the entry it produced, so that a wrong entry can be explained rather than argued about. Delete the entry and the transcript goes with it.

A dictation we could not understand is stored separately, with the text and the reason, so we can fix the parsing. Those records expire automatically after 90 days — the database itself enforces it, not a script somebody has to remember to run.

To turn a sentence into an entry we send it to Google’s Gemini API, along with the names and nicknames of the people in your logbook so the model can tell who you meant. When you ask a question about the log, a summary of the relevant entries goes with it. Nothing else is sent: not your email, not your billing details, not your other children’s history.

We do not use your data to train AI models, and we never will. Google processes what we send on the paid tier of its API, whose terms forbid using the content to improve Google’s models. [MIGRATION TO THE PAID GEMINI TIER TO BE CONFIRMED BEFORE LAUNCH.]

7. Voice assistants

If you link Alice, Alexa or Google Assistant, what happens on the speaker is governed by Yandex, Amazon or Google, not by us. They hear you, they do the speech recognition, and they decide what to keep. We receive the recognised text and an opaque id for your device account, and we are responsible only from that point on.

Read their privacy notices before you link one, and unlink from Settings when you want it to stop. Unlinking deletes the link on our side immediately.

8. How long we keep things

Your entries, transcripts and notes: until you delete them or delete the account. We do not expire them, and we do not delete an account for being inactive. Your history stays as long as you want it, however far back it goes.

Audio: not kept at all. One request, in memory, gone.

Dictations we could not parse: 90 days, then deleted automatically by the database.

Account, people and settings: for the life of the account.

AI usage records: how many tokens a request used, how long it took and whether it worked — never what it said. Kept for the life of the account, plus a per-day total per account so we can see what the service costs to run.

Rate-limit counters: the counters that stop flooding, one of which is keyed by IP address on the assistant endpoints, are deleted about two hours after their window closes.

Assistant links: until you unlink or delete the account. The codes used to link are hashed, single-use and expire in ten minutes.

Security records: a short log of security-relevant actions — an export downloaded, an assistant linked, an account deleted — with no entry content in it. Kept for the life of the account.

Invoices and tax records: held by Stripe and kept for five years from the end of the accounting year they fall in, because Polish tax law requires it. Deleting your account does not delete these, and we cannot make an exception.

Error and performance diagnostics: [SENTRY EVENT AND REPLAY RETENTION TO BE CONFIRMED], then deleted by Sentry.

Backups: deleting your account removes the live data immediately, but a copy can survive in an encrypted backup until that backup rotates out: [BACKUP RETENTION TO BE CONFIRMED]. Backups are never used to bring a deleted account back.

9. The companies that process data for us

These are every third party that receives personal data as part of running Child Logbook. Each acts on our instructions, and each is bound by a data processing agreement. [DATA PROCESSING AGREEMENTS NOT YET SIGNED WITH EVERY PROCESSOR BELOW.] This list is the complete one; if we add a processor, this page changes before the processing starts.

WhoWhat they doWhat they receiveWhere
ClerkSign-in, sessions and account securityEmail address, name if given, credentials, and the IP address and device information used to secure a sign-inUnited States
StripePayments, subscriptions, invoices, taxName, email, billing country and address, card details entered directly into Stripe, VAT status and purchase historyIreland, with transfers to the United States
Google (Gemini API)Turns a spoken or typed sentence into an entry, and answers questions about the logThe audio or text of that one dictation, the names and nicknames in your logbook, and — for a question — a summary of the relevant entriesIreland and the United States
SentryError reports, performance traces and a sampled session replayStack traces, request metadata, your account and user id, and a replay of a small sample of sessions in which text and form input are maskedEuropean Union region
RailwayHosting for the app and for both databasesEverything the app stores, because the databases run on their infrastructure[HOSTING REGION TO BE CONFIRMED]

Two things that are not on that list, on purpose. Cloudflare is our domain registrar and DNS provider; no logbook data passes through it today, and the backup bucket in our internal plan does not exist yet and holds nothing. Cloudflare does see your IP address when Clerk shows you a bot check during sign-in, which it serves through Cloudflare. If we put Cloudflare in front of the app or start writing backups there, this table gains a row first.

Yandex, Amazon and Google Assistant are also absent: they are not our processors. They act for themselves upstream of us, as section 7 explains.

We do not sell your data, and we do not share it for anyone else’s purposes. We disclose data outside this list only where the law compels us to, and we will tell you if that happens unless we are forbidden from telling you.

10. Data that leaves the EEA

Some of the companies above process data outside the European Economic Area, principally in the United States. That is allowed only with a legal transfer mechanism, and we rely on two of them: an adequacy decision where the recipient is certified under the EU–US Data Privacy Framework, and the European Commission’s standard contractual clauses everywhere else, with the transfer risk assessment those clauses require.

Concretely: Clerk is in the United States; Stripe contracts through its Irish entity and transfers to the United States; Google processes through Google Ireland and its global infrastructure; Sentry stores in its European Union region, though Sentry is a US company and its staff may access data for support; Railway is a US company. Ask us at [email protected] for a copy of the clauses we rely on for any of them.

11. Your rights

You have all of the following, and using any of them is free and costs you nothing in service. Write to [email protected]; we answer within one month, and tell you inside that month if a complex request needs longer.

Access. Get a copy of what we hold about you and be told why we hold it. You do not have to ask us for the logbook itself — Settings → Export downloads it.

Rectification. Correct anything wrong. Entries, names, times and notes are all editable in the app; write to us for anything you cannot reach.

Erasure. Have it deleted. Settings → Danger zone deletes the account outright, without asking us first: your entries go from both databases, your subjects, settings, usage records and assistant links go with them, your Stripe subscription is cancelled and the Stripe customer deleted, and your Clerk user is deleted last. It cannot be undone, so export first. The only things that survive are the invoices tax law requires.

Restriction. Have us stop processing while a dispute about accuracy or lawfulness is resolved.

Portability. Take your data to another service in a structured, machine-readable format. Settings → Export gives you a CSV of a person’s whole logbook, on every plan, including a free one and including a person who has gone read-only after a downgrade.

Objection. Object to processing we base on legitimate interests — the security and diagnostics work in section 3. Tell us your grounds and we stop unless we can show compelling reasons that override them.

Withdraw consent. Withdraw the explicit consent for health data at any time, as described in section 4. It is as easy to withdraw as it was to give.

Complain to a supervisory authority. You can complain about us to the Polish authority: Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa, Poland. You can also complain to the supervisory authority of the EU country where you live or work, and you can go to court. You do not have to contact us first, though we would rather you did.

12. How we protect it

Separation between accounts is structural, not a filter somebody remembers to add: every database query in the app carries an account scope that can only be built from a verified session, and a cross-account test matrix runs against every one of them. A subject id that does not belong to your account resolves to your own default instead of returning someone else’s data.

Beyond that: traffic is HTTPS only; the databases are not exposed to the public internet; card data never touches our servers; assistant tokens and link codes are hashed at rest; the browser runs under a strict content security policy with per-request nonces; rate limits sit in front of the expensive and the sensitive routes; and the application log is built so that transcripts, names, notes, tokens and cookies structurally cannot enter it.

No system is perfectly secure, and we will not pretend otherwise. If a breach happens and it puts your rights at risk, we notify the supervisory authority within 72 hours and tell you without undue delay. If you find a security problem, write to [email protected] before telling anyone else.

13. Cookies, and what we do not track

The app sets two kinds of cookie, both strictly necessary, so there is no cookie banner to click through.

Clerk’s session cookies keep you signed in and protect the session. Without them the app cannot tell it is you.

One cookie of our own called selected-subject, which remembers whose day you were looking at. It holds one identifier, is not readable by scripts, and lasts a year. It exists because the server has to know which person’s day to render before the page is sent.

There is no advertising, no analytics, no tracking pixels and no third-party cookies anywhere in Child Logbook or on this site. Nobody is measuring you across the web. This marketing site sets no cookies at all and serves its own fonts, so reading it does not send a request to anyone else.

Sentry’s browser code keeps an id in your browser’s session storage to tie one visit’s errors together. It is not a cookie, it is not used for tracking, and it is gone when you close the tab.

14. Automated decisions

Nothing here makes an automated decision about you or your child in the sense of Art. 22 GDPR. There is no decision with a legal or similarly significant effect, no profiling, no scoring, no ranking of parents or children.

The AI does one job: it reads one sentence and writes the entry it describes. The entry is saved straight away and read back to you in the same breath, so you can see what it understood — and if it got it wrong, you edit it or delete it, in the app or by telling the assistant to undo it. It is a typist, not a judge.

15. Changes to this policy

We may update this policy. When a change is more than a correction of wording — a new processor, a new purpose, a shorter or longer retention — we will tell you in advance by email or in the app, and where the change needs your consent we will ask for it rather than assume it. The date at the top of this page always says which version you are reading.

16. How to reach us

Mikhail Mukhau, Powstańców 41B m. 5, 05-091 Ząbki, Poland — [email protected]. We answer in English, Polish and Russian.