Baby Bothie Privacy Policy
TestFlight beta (US/Canada)
Baby Bothie is an iPhone app for adults. A parent captures a photo of their baby with the back camera and a photo of themselves with the front camera, and the app combines those two real photos into one image of them together. The combining is AI-assisted, and every combined image is disclosed as such.
The short version
- Your photo library lives only on your iPhone. Our servers keep no copies of your images.
- To combine two photos, they pass through our server's memory only to a named AI image provider. We tell you exactly who, and exactly how long they can retain photos — the real number, even when it isn't a flattering one.
- No one trains AI models on your photos — not us, and not the providers we enable (verified per provider before we enable them).
- Children never use Baby Bothie and we never collect data from children. You must be 18+ and the parent or legal guardian of every child in a photo you submit.
- You can delete your account and data in the app. We state plainly what deletion cannot reach.
- No ads. No selling or sharing your data. No tracking you across apps. No face-recognition databases.
1. Who the service is for
Baby Bothie is a general-audience app directed to adults (18+) — parents and legal guardians. Children never operate the app, have no accounts, and we never knowingly collect personal information from a child. Children appear only as subjects of photos their own parent or guardian chooses to submit, with that adult's explicit consent (see §6).
2. Information we collect
| Data | Source | Why | Where it lives |
|---|---|---|---|
| Name and email address | Sign in with Apple (you may use Apple's private relay email) | Account creation, beta invitations, deletion requests | Firebase Authentication (Google Cloud) |
| User ID | A Firebase account identifier (UID) created at sign-in | Ties your account, consent record, and analytics together; enforces per-user beta limits | Firebase; also used as your analytics identifier |
| Photos you capture (the two source photos) and the combined images | You, in the app | Solely to create your combined image (see §3 for the full journey) | Your iPhone; transiently in our server's memory and with the enabled provider(s) listed in §4 |
| Usage analytics | The app, via PostHog, only after you accept the consent screen | Beta research: which features are used, which model versions people prefer, where errors happen | PostHog. We instruct PostHog to discard IP addresses at ingestion and disable geolocation; events are restricted to an approved allowlist; session replay and autocapture are off. Analytics never contain photos, image data, names, or GPS. |
| Feedback text (optional) | The in-app feedback box (1–2,000 characters) | Improving the beta | PostHog, linked to your UID. The form asks you not to include names, medical details, or other personal information. |
| Consent and processing records | Created server-side when you consent or generate | Proof of consent; request status, error and cost accounting — metadata only, never image data | Firestore (Google Cloud); generation records auto-delete no later than 45 days after the request finishes |
What we do not collect: contacts, location/GPS, microphone audio (the app has no microphone permission), health data, advertising identifiers, browsing history. We do not track you across other companies' apps or websites, and there are no third-party ad or tracking SDKs in the app.
If you decline the consent screen, analytics are never enabled for you.
3. Your photos' exact journey
- Capture, on your iPhone. Both photos are taken in the app. Before anything leaves your device, the app strips photo metadata (no location, no device serial data — pixels only) and normalizes the images.
- Both originals are saved to your on-device library first (see §5). If that fails, nothing is sent.
- Encrypted upload to our server. The two photos travel over an encrypted connection to our processing function on Google Cloud (US). The function holds image bytes in memory only — it never writes your photos to our storage, logs, or databases.
- Sent to the enabled AI provider(s). The function forwards the two photos to each provider currently enabled in the app (§4) to create the combined image(s).
- Returned to your iPhone. Combined images stream back to your device and are stored in your on-device library. Our server keeps no copy of any image — not the originals, not the results.
- What remains server-side is metadata about the request (status, timing, error category, cost) with no image content, deleted no later than 45 days after the request completes.
The app asks you to keep it open during combining; some versions can take up to 3 minutes.
4. The AI providers we use (our processors)
We name every processor, link its terms, and disclose its actual, verified retention window. A provider is enabled in the app only after we have verified its configuration and documented it in our internal, dated processor checklist. The in-app consent screen always lists the providers currently enabled and their current windows; if the list or the terms materially change, the app asks for your consent again before any further processing.
| Provider | Status in the beta | Training on your photos | Retention |
|---|---|---|---|
Google — Gemini API (paid tier) (models gemini-3-pro-image, gemini-3.1-flash-image) |
Enabled | No. Google states paid-tier API content is not used to train its models. | Google may retain submitted prompts and outputs in abuse-monitoring logs for up to 55 days, then deletes them. We have requested zero-data-retention treatment from Google; until it is granted and verified, 55 days is the honest number and the one we disclose. |
| fal.ai (ByteDance Seedream image model, hosted by fal) | Not enabled yet. Will be enabled only after fal confirms in writing that, with our storage-off configuration, no input or output media persists after processing and that our content is not used to train models. | Pending written confirmation — a gate for enablement | We call fal with its storage-off configuration (no stored payloads, results returned directly, short-lived object expiry). Enablement is gated on written verification of this exact route. |
OpenAI (gpt-image-2) |
Disabled. OpenAI's own policy requires zero data retention before processing photos of children under 13; this route stays off unless OpenAI approves zero data retention for us. | No (OpenAI does not train on API content by default) | If ever enabled under zero data retention: no stored content, except that OpenAI always scans image inputs for child-sexual-abuse material and retains flagged images for human review — a safety carve-out that survives zero data retention and that we disclose rather than hide. |
Things we deliberately do not use with these providers: no grounding/search features, no provider file-storage APIs, no context caching — each would carry its own retention.
All providers process data in the United States. If you use the beta from outside the US, your photos and data are transferred to and processed in the US.
5. Your on-device library
- Your Baby Bothie library (originals and combined images) is stored only on your iPhone, in the app's protected storage, encrypted at rest by iOS.
- The library is excluded from device backups — so "on-device only" stays literally true; it does not sync to iCloud through us.
- Saving an image to Apple Photos is always your explicit choice (the app requests add-only Photos access). Once exported, that copy is governed by your Apple settings and may sync via iCloud Photos — see §7.
- Signing out hides your library on that device; deleting your account removes it (§7).
6. Guardian consent — the gate in front of everything
Before your first combination, the app requires three explicit acknowledgements:
- You are 18 or older and the parent or legal guardian of every child whose photo you submit;
- You permit Baby Bothie to send the two selected photos to the processors listed on the consent screen (the enabled rows of §4, with their retention windows shown);
- You understand the combined output is AI-generated and that beta usage analytics are collected.
We record a consent receipt (consent version, processor configuration version, timestamp, app build). If the processor list or any disclosure materially changes, you must re-consent before further processing. You can withdraw consent at any time in Settings → Privacy and consent: this blocks further combining, disables analytics, purges any locally queued analytics, and starts deletion of your analytics data — while keeping your account and your on-device library intact.
7. Deletion
Delete your account in Settings. The flow re-confirms your identity with Apple, then: your Apple sign-in token is revoked, analytics stop, and all server-side data (account, consent records, request metadata) and your analytics identity are deleted. Your local library is removed from the device. If a combination is in progress, it is stopped as soon as technically possible; work already sent to a provider may briefly complete but its output is not delivered or kept.
Service levels: data on our servers (Firebase) is deleted within 24 hours; analytics data (PostHog) within 30 days. The app shows "deletion pending" until confirmed, and you receive a receipt code to check status without an account.
What deletion cannot reach — said plainly:
- Copies you saved to Apple Photos. Those live in your Apple account and may have synced through iCloud Photos; delete them there.
- Provider safety-retention windows described in §4 (e.g., Google's up-to-55-day abuse-monitoring logs age out on Google's schedule; any CSAM-flagged material at a provider is retained under that provider's legal obligations).
- A minimal, non-identifying deletion record (not linked to you) kept up to 30 days so we can prove the deletion completed.
Other retention limits, regardless of deletion: server request metadata ≤45 days after each request; raw analytics no later than 90 days after the beta ends (after which only aggregate statistics, with free-text feedback excluded, are kept for research write-ups).
8. Children's privacy
COPPA governs data collected online from children. Baby Bothie is not directed to children, provides no child accounts, and collects no data from children; the user is always the parent or guardian, who provides the photos and the consent (§6). We honor the spirit of COPPA anyway: minimal data, short retention, verified processor terms, and parental deletion rights over everything we hold. If we learn a child has created an account, we will delete it.
9. What we never do
- No advertising, and no advertising SDKs.
- No sale of personal data; no sharing beyond the named processors above (plus our infrastructure providers, Google Firebase and PostHog, named in §2).
- No tracking across apps or websites; no data broker anything.
- No face-recognition or identification databases — we do not identify people; we combine two photos you chose into one image for you alone.
- No training of AI models on your photos — ours or anyone's (§4).
10. Security
Encryption in transit everywhere; on-device files protected by iOS encryption with backup exclusion; server functions verified by Apple App Check; image bytes confined to function memory; access to production systems restricted to the founder; provider requests authenticated and never logged with image content. No system is perfectly secure — if a breach affects your data, we will notify you promptly at your account email. [Counsel: state-specific breach-notification language to be completed.]
11. Your rights
Depending on your state or country, you may have rights to access, correct, delete, or export your personal data, and to non-discrimination for exercising them. Most of these are built into the app (consent withdrawal, deletion, on-device data). For anything else, contact hello@babybothie.com. We respond within 30 days. [Counsel: state-law rights inventory and appeal-process wording to be completed.]
12. Changes to this policy
We will post changes here with a new effective date. Material changes — especially anything touching §4 — additionally require fresh in-app consent before further processing (§6).