EMOY — Privacy Policy
Effective date: 1 October 2026 Contact: support@emoy.app
What changed on 1 October 2026. Crash reports no longer include a record of each time the app is opened, and they are stripped of anything that points at your records. This page now says so. It also lists what our sign-in provider and servers log, the totals we count, and how a notification token is kept. The claims on emoy.app now say exactly what is true: no ads, no analytics tools, no screen recording, no ad trackers. Details are under "Changes" at the end.
Who we are
EMOY ("the app") is a shared care record for parents and caregivers. It is operated by the individual developer reachable at the contact address above.
The short version
- Your family's data is private to your household by default. Nothing is public, and there is no public profile.
- We do not sell your data, and we do not share it with advertisers.
- There are no ads, no analytics tools, no screen recording and no ad trackers in the app. Nothing in it reports what you tap, which screens you open, or how long you stay.
- You can delete your account and your data from inside the app, at any time, without contacting us.
What the app stores
Everything below is stored because the app cannot do its job without it. There is no secondary collection.
Your account
- Email address and password, if you sign up with them. Handled by our authentication provider; the password is stored only as a salted hash, never in readable form.
- Sign in with Google, if you choose it. We receive and store your email address, your name, a link to your Google profile photo, and Google's identifier for your account.
- Sign in with Apple, if you choose it. We receive and store your email address — or, if you choose to hide it, a private relay address from Apple — and Apple's identifier for your account. Apple shares your name only the first time you sign in.
- Display name. Used to show who logged each entry ("Logged by Ayden").
Sign-in sessions and server logs. Our authentication provider, Supabase, keeps a record of each signed-in session, including the IP address and the device and app type it was started from (the "user agent"). These are deleted along with your account. Separately, our providers' servers log the IP address of requests made to them, as almost every web service does. Those logs are kept for the provider's own retention period and are used only to run and secure the service.
With Google or Apple, your password for that account never reaches us. The app uses the name only to suggest your display name, and never uses the profile photo. Your account with Google or Apple is governed by their own privacy policies.
Your child's profile
- Name, date of birth and sex.
- Birth weight and birth length, if entered. Optional.
- Which kinds of feeds and activities you choose to track, and how often you expect to log them.
Sex is stored because growth percentiles are calculated against sex-specific WHO/CDC reference tables. It is not used for anything else.
Care records
- Sleep, feeding, nappy changes and activities — start and end times, plus details for each kind: feed volumes and units, nursing side and duration, nappy contents, colour and size, activity type.
- Growth measurements — weight, length, the date measured, and any note.
- Milestones — which developmental or "first" milestones were reached, when, and any note.
Photos and videos
- Photos and videos you add, and any milestone they are attached to.
- These are stored in private storage. They are never public. They are served only through short-lived signed links to people you have shared with.
Camera and microphone. If you record a video inside the app, we use the camera and the microphone to make that recording — the sound is part of the video you chose to record. The app never records audio on its own, in the background, or at any time other than a recording you started. If you only ever add photos from your existing library, neither is used at all.
If you use the AI assistant
EMOY has an assistant that answers questions about your own child's record. It is in limited early access: only households we have invited can use it, and within those households only the guardians, not caregivers or Circle members. If your household has not been invited, nothing in this section happens to your data.
Each time a guardian asks it something, we send Anthropic, which runs the AI model, the following:
- Your question, in your own words.
- Your recent messages in that conversation, up to the last ten questions and answers, so a follow-up makes sense.
- A summary of your child's record, built fresh for that question from what your household has logged. It is listed in full below.
The summary contains:
- Your child's name, date of birth, sex and age, and the app's internal identifier for the child's record.
- Which kinds of feeds, milk and activities your household has chosen to track.
- Your time zone, which is used to work out which day an entry falls on.
- Averages over the last 7 complete days for sleep, feeds, bottle volume, nursing time, solids and nappy changes. These are the same figures the Summary screen shows.
- Every sleep, feed, nappy change and activity from the last 7 days: its type, its start and end times, how long it lasted, the details recorded with it (such as an amount, a nursing side, nappy contents, or whether a solid food was liked), and the display name of whoever logged it.
- Every growth measurement: the date, weight, length, percentile and any note.
- Every milestone recorded: which one, when, and any note.
Photos and videos are never sent. Neither are your other children's records, your Circles, comments, or anyone's email address.
Which model answers. The assistant runs on Anthropic's Claude Opus 5.5. If Anthropic's automated safety systems stop that model from answering, the same request may be run again on Claude Opus 5 and then on Claude Opus 4.8, both run by Anthropic under the same terms. Before it answers, your question and the two messages before it in the conversation are also sent to Claude Sonnet 5.5, which sorts the question (for example, to spot an emergency); it is not sent the summary of your child's record. Your request is never sent to any other model.
Anthropic is our service provider. It processes this to produce the answer, on our behalf, under its Commercial Terms and Data Processing Addendum, which says: "Customer is the controller and Anthropic is Customer's processor." What Anthropic's own documents say, as of 29 September 2026:
- Training. The Commercial Terms say: "Anthropic may not train models on Customer Content from Services."
- Retention. Anthropic's privacy center says: "For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation". We have no separate agreement with Anthropic that shortens this.
- Exceptions. The same page says: "We retain inputs and outputs for up to 2 years and trust and safety classification scores for up to 7 years if your chat is flagged by our automated trust and safety systems as violating our Usage Policy", and that it "may retain your chats or sessions as required by law or as necessary to combat violations of our Usage Policy". We cannot waive either on your behalf.
These are Anthropic's published terms, quoted from their pages on the date above. They are not something we can check from outside, and Anthropic can change them. If they change in a way that matters, we will update this page.
What we keep, and who can read it. Your question and the assistant's answer are saved as a conversation in our database (Supabase), so you can look back at what it said. We also save any earlier drafts of that answer that our automated safety checks rejected, and technical details of how it was produced: which model answered, how much processing it used, and the results of those checks. The summary of your child's record is not saved; it is rebuilt for every question. This is the most sensitive text in the app, so it is worth being exact about who can read it: only you. Not the other guardians in your household, not a caregiver, not anyone in a Circle. That is enforced by the database, not by a policy: a conversation is readable only by the account that wrote it. We also keep a monthly count of questions and processing used per household, with no text in it, to apply usage limits.
How long conversations are kept. Your conversations in a household are kept until 18 months pass without you asking anything there. The clock is per person and per household: your activity keeps your own conversations, and no one else's. When it runs out, all of your conversations in that household are deleted. They are also deleted if you leave the household or stop being one of its guardians, and immediately if you delete your account. An automatic job checks every night.
Deleting them sooner. There is not yet a way to delete a single conversation in the app. Email support@emoy.app from the address on your account and we will delete your conversations, or tell you why we cannot, within 30 days. Deleting your account deletes them at once.
Who you share with
- Your household and its members, and each member's role.
- Your Circles, who is in them, and which categories each Circle can see.
- Comments and reactions people leave on shared photos and milestones.
- A record of anyone removed and blocked from a household or Circle, so they cannot rejoin with a shared invite code.
Diagnostics
When something goes wrong, the app sends a crash report to Sentry so that failures on real devices can be found and fixed. A small sample of launches, about one in ten, also sends performance data, such as how long the app took to start. That is all. The app does not send Sentry a record of each time it is opened (Sentry calls these "sessions"), and it does not send what you tap.
A crash report carries what went wrong. That means the error itself, your device model and system version, the app version, and a short trail of what the app was doing just before, such as which kind of server request failed. Before a report leaves your phone, the app removes every web address's query string and replaces every record identifier with a placeholder. The trail never includes the app's own log lines or your taps. Identifying request data is disabled and session replay (screen recording) is not enabled. Crash reports are not associated with your account.
One limit, stated plainly. When the crash happens in the phone's own system code rather than in the app's, Sentry's built-in component writes the report, and the app cannot strip it in the same way. Such a report can include the web addresses of the app's most recent requests to our servers. Those addresses contain internal record identifiers, dates and the kind of data asked for (such as "sleep entries"), never what an entry, note or comment says, and never a photo. An address that opens a photo or video stops working an hour after the app asked for it. We intend to close this gap in a future version of the app.
Sentry does not store your IP address. It may use the connection a report arrives on to note an approximate location at country level.
Each crash report carries a random identifier created on your phone the first time the app runs, so we can tell whether a failure affected one person many times or many people once. It is not your account, email or name, it is not stored alongside your account anywhere, and reinstalling the app replaces it with a new one.
Totals, never reports about you
To know whether EMOY is working for families, we look at totals from records the app already stores — for example, how many households logged something this week. These are counts, never a report about you, and nothing extra is collected to produce them.
Notifications
Notifications are off until you turn them on, and there are two kinds.
- Reminders about your child's age are scheduled on your phone. Nothing is sent to a server and nobody else is told.
- Notifications about what someone else did — a photo added, a milestone logged, a reply to you — are sent from our server, because the thing being announced happened on somebody else's phone.
For the second kind we store a notification token for each device you turn them on for, and the time zone of that device, which is what lets an overnight notification be held until morning rather than waking you. We also store when the token was last confirmed, so that tokens for phones that no longer use the app can be removed. That date is updated at most once a week, or when the token changes, so it is not a record of when you open the app. Signing out removes the token for that phone.
A notification is delivered through Expo's push service to Apple or Google, and it carries the text you would see on your lock screen — which names your child ("New photos of Louie") and who did the thing. It never carries a photo. Your child's first name therefore passes through those services in order to be displayed. That is how notifications work on both platforms; the alternative is a notification that cannot say what it is about.
Stored only on your own device
Your appearance preference (day/night), your measurement units, and whether you have seen the introductory walkthrough. These never leave your phone.
What the app does NOT do
- No advertising, and no advertising identifiers.
- No analytics tools. Nothing reports what you tap, which screens you open, or how long you stay.
- No ad trackers: nothing follows you across other apps or websites because you use EMOY.
- No selling, renting or sharing of personal information with third parties for their own purposes.
- No access to your device's contacts or location, and no health data from Apple Health or Google Fit.
- No use of your photos or your child's data to train machine-learning models. If that ever changes it will be opt-in: you would be asked first, and nothing is used unless you choose it.
Why we process this data
To operate the service you asked for: to record and display your child's care, to synchronise it between the caregivers in your household in real time, to show the slices you have chosen to share with your Circle, to keep the app working (diagnostics), and to know whether it is working for families (the totals described above).
Where GDPR applies, our lawful basis is performance of a contract for the core service, and legitimate interests for diagnostics and for counting totals. Health-related data (growth measurements, care records) is processed on the basis of your explicit consent, given by choosing to enter it, and you may withdraw that consent by deleting the data or your account.
About the child's data
The information in this app is *about* a child but is provided *by* an adult caregiver who holds the account. The app is not directed at children, is not offered in the Kids Category, and we do not knowingly allow anyone under 13 to create an account.
The adult account holder is responsible for what they enter and for whom they invite into a Circle.
Who else is involved
We use the service providers below. They process data on our behalf, under their own security commitments, and are not permitted to use it for their own purposes.
| Provider | What they do | What they see |
|---|---|---|
| Supabase | Database, authentication and file storage | All app data described above, plus the IP address and user agent of each signed-in session and request logs |
| Sentry | Crash reporting, with performance data from a sample of launches | Diagnostic data only, with record identifiers removed, and a random identifier made on your phone; no account or child data |
| Anthropic | Runs the AI model behind the assistant, in limited early access for invited households only | Only when you use the assistant: your question, your recent messages in that conversation, and the summary of your child's record listed above |
| Expo (EAS) | Delivers app updates, and delivers notifications to Apple and Google | When the app checks for an update, which it does each time it starts: the app version and platform, and a random identifier the update system creates on your phone. For a notification: its token and the text shown on the lock screen |
Security
- All traffic between the app and our servers is encrypted in transit (HTTPS).
- Data is encrypted at rest by our database and storage provider.
- Access is enforced at the database level by row-level security rules, not only in the app: a household's records are readable only by that household's members, and a Circle member can read only the categories that Circle has been granted.
- Photos and videos are held in a private bucket and are never publicly addressable.
No system is perfectly secure, and we cannot guarantee absolute security.
About Anthropic specifically. What Anthropic's terms say about training on what is sent and about how long it keeps it is quoted, with links, under "If you use the AI assistant" above.
One thing account deletion cannot reach. Anything already sent to a service provider has left our systems. Deleting your account removes what we hold; it cannot reach back into somebody else's.
How long we keep it
We keep your data for as long as your account exists. The one exception is AI assistant conversations, which are deleted after a period without use, as described under "If you use the AI assistant".
- Delete your account — Settings → Delete my account. This permanently deletes your login and removes your access. If you are the only member of a household, that household and everything in it is permanently deleted. If others remain, the shared record stays intact for them, with your entries no longer attributed to you. If you signed in with Apple, we also ask Apple to revoke EMOY's access to your Apple ID.
- Leave a household or Circle — removes your access without deleting the shared record.
Deletion is immediate and cannot be undone. Backups may retain data for a short period before being cycled out.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict processing, and to complain to a data protection authority.
Most of this is available directly in the app: your data is visible to you, editable by you, and deletable by you. For anything else, contact us at the address above and we will respond within 30 days.
Changes
If this policy changes materially, we will update the effective date above and notify you in the app before the change takes effect.
1 October 2026. This page and emoy.app now say only what is literally true about what the app sends.
- Crash reports no longer include "sessions", a record sent each time the app is opened. Performance data now comes from about one launch in ten instead of every launch. Before any report leaves your phone, web addresses lose their query strings and record identifiers are replaced, and the app's own log lines and your taps are no longer included.
- A notification token's "last confirmed" date is now updated at most once a week. It used to be updated each time the app was opened, which made it a record of when you used the app. This page never mentioned it; it now does.
- New on this page: what our sign-in provider and servers log (IP address and user agent), that Sentry may note an approximate country, the totals we count, and the random identifier the update system uses.
- emoy.app used to say "Nothing counting how you use the app" and "No trackers from other companies". It now says "No analytics tools" and "No ad trackers", which are the claims this page can back word for word.
30 September 2026. The AI assistant is now in limited early access for households we have invited. The previous version of this page said it did not exist yet and marked Anthropic as "not yet in use", and that stopped being true when the first invited household outside our own could use it. This page now lists what is sent to Anthropic, including every part of the summary of your child's record, and quotes what Anthropic's terms say about keeping and training on it. This page used to say Anthropic does not keep what is sent "by default". Anthropic's privacy center says it deletes it within 30 days, so the page now quotes that instead. It also says what we store, that only you can read your conversations, that they are kept until 18 months pass without you using the assistant in that household, and how to have them deleted sooner. Nothing else on this page has changed.
17 September 2026. Two corrections, both making this page match what the app already does. Nothing about how the app works has changed.
This page said the app records whether a child was born prematurely and their gestational age, and uses them for growth percentiles. It never recorded either; that text described a design that was not built, and it has been removed.
This page also described signing in only with an email address and password. The app has offered Sign in with Google and Sign in with Apple since it launched, and it now says what each one shares with us, and that deleting your account also revokes EMOY's access to your Apple ID.
8 September 2026. One change, and it is a loosening, so we would rather say so plainly than dress it up.
The commitment not to train machine-learning models on your photos or your child's data previously admitted no exception at all. It now names one: we would have to ask you first, and nothing would be used unless you chose it. Nothing about how the app works today has changed, and no data has ever been used this way. We are setting the condition out now rather than quietly revising a promise later.
3 September 2026. Two changes.
Notifications about what someone else did — a photo added, a milestone logged, a reply — are now sent from our server, so they can reach you when the thing happened on somebody else's phone. The previous version of this policy said push notifications were not used, which was true when it was written. We now describe what is stored for them, what a notification carries, and that it passes through Expo, Apple and Google to be shown.
We also added Anthropic to the list of services, ahead of an assistant that answers questions about your own child's record. The feature is not built. It is described here first so that the policy is already accurate the day it works, rather than catching up afterwards.
25 August 2026. First published.