EMOY.

EMOY — Privacy Policy

Effective date: 1 October 2026 Contact: support@emoy.app

What changed on 1 October 2026. Crash reports no longer include a record of each time the app is opened, and they are stripped of anything that points at your records. This page now says so. It also lists what our sign-in provider and servers log, the totals we count, and how a notification token is kept. The claims on emoy.app now say exactly what is true: no ads, no analytics tools, no screen recording, no ad trackers. Details are under "Changes" at the end.

Who we are

EMOY ("the app") is a shared care record for parents and caregivers. It is operated by the individual developer reachable at the contact address above.

The short version

What the app stores

Everything below is stored because the app cannot do its job without it. There is no secondary collection.

Your account

Sign-in sessions and server logs. Our authentication provider, Supabase, keeps a record of each signed-in session, including the IP address and the device and app type it was started from (the "user agent"). These are deleted along with your account. Separately, our providers' servers log the IP address of requests made to them, as almost every web service does. Those logs are kept for the provider's own retention period and are used only to run and secure the service.

With Google or Apple, your password for that account never reaches us. The app uses the name only to suggest your display name, and never uses the profile photo. Your account with Google or Apple is governed by their own privacy policies.

Your child's profile

Sex is stored because growth percentiles are calculated against sex-specific WHO/CDC reference tables. It is not used for anything else.

Care records

Photos and videos

Camera and microphone. If you record a video inside the app, we use the camera and the microphone to make that recording — the sound is part of the video you chose to record. The app never records audio on its own, in the background, or at any time other than a recording you started. If you only ever add photos from your existing library, neither is used at all.

If you use the AI assistant

EMOY has an assistant that answers questions about your own child's record. It is in limited early access: only households we have invited can use it, and within those households only the guardians, not caregivers or Circle members. If your household has not been invited, nothing in this section happens to your data.

Each time a guardian asks it something, we send Anthropic, which runs the AI model, the following:

The summary contains:

Photos and videos are never sent. Neither are your other children's records, your Circles, comments, or anyone's email address.

Which model answers. The assistant runs on Anthropic's Claude Opus 5.5. If Anthropic's automated safety systems stop that model from answering, the same request may be run again on Claude Opus 5 and then on Claude Opus 4.8, both run by Anthropic under the same terms. Before it answers, your question and the two messages before it in the conversation are also sent to Claude Sonnet 5.5, which sorts the question (for example, to spot an emergency); it is not sent the summary of your child's record. Your request is never sent to any other model.

Anthropic is our service provider. It processes this to produce the answer, on our behalf, under its Commercial Terms and Data Processing Addendum, which says: "Customer is the controller and Anthropic is Customer's processor." What Anthropic's own documents say, as of 29 September 2026:

These are Anthropic's published terms, quoted from their pages on the date above. They are not something we can check from outside, and Anthropic can change them. If they change in a way that matters, we will update this page.

What we keep, and who can read it. Your question and the assistant's answer are saved as a conversation in our database (Supabase), so you can look back at what it said. We also save any earlier drafts of that answer that our automated safety checks rejected, and technical details of how it was produced: which model answered, how much processing it used, and the results of those checks. The summary of your child's record is not saved; it is rebuilt for every question. This is the most sensitive text in the app, so it is worth being exact about who can read it: only you. Not the other guardians in your household, not a caregiver, not anyone in a Circle. That is enforced by the database, not by a policy: a conversation is readable only by the account that wrote it. We also keep a monthly count of questions and processing used per household, with no text in it, to apply usage limits.

How long conversations are kept. Your conversations in a household are kept until 18 months pass without you asking anything there. The clock is per person and per household: your activity keeps your own conversations, and no one else's. When it runs out, all of your conversations in that household are deleted. They are also deleted if you leave the household or stop being one of its guardians, and immediately if you delete your account. An automatic job checks every night.

Deleting them sooner. There is not yet a way to delete a single conversation in the app. Email support@emoy.app from the address on your account and we will delete your conversations, or tell you why we cannot, within 30 days. Deleting your account deletes them at once.

Who you share with

Diagnostics

When something goes wrong, the app sends a crash report to Sentry so that failures on real devices can be found and fixed. A small sample of launches, about one in ten, also sends performance data, such as how long the app took to start. That is all. The app does not send Sentry a record of each time it is opened (Sentry calls these "sessions"), and it does not send what you tap.

A crash report carries what went wrong. That means the error itself, your device model and system version, the app version, and a short trail of what the app was doing just before, such as which kind of server request failed. Before a report leaves your phone, the app removes every web address's query string and replaces every record identifier with a placeholder. The trail never includes the app's own log lines or your taps. Identifying request data is disabled and session replay (screen recording) is not enabled. Crash reports are not associated with your account.

One limit, stated plainly. When the crash happens in the phone's own system code rather than in the app's, Sentry's built-in component writes the report, and the app cannot strip it in the same way. Such a report can include the web addresses of the app's most recent requests to our servers. Those addresses contain internal record identifiers, dates and the kind of data asked for (such as "sleep entries"), never what an entry, note or comment says, and never a photo. An address that opens a photo or video stops working an hour after the app asked for it. We intend to close this gap in a future version of the app.

Sentry does not store your IP address. It may use the connection a report arrives on to note an approximate location at country level.

Each crash report carries a random identifier created on your phone the first time the app runs, so we can tell whether a failure affected one person many times or many people once. It is not your account, email or name, it is not stored alongside your account anywhere, and reinstalling the app replaces it with a new one.

Totals, never reports about you

To know whether EMOY is working for families, we look at totals from records the app already stores — for example, how many households logged something this week. These are counts, never a report about you, and nothing extra is collected to produce them.

Notifications

Notifications are off until you turn them on, and there are two kinds.

For the second kind we store a notification token for each device you turn them on for, and the time zone of that device, which is what lets an overnight notification be held until morning rather than waking you. We also store when the token was last confirmed, so that tokens for phones that no longer use the app can be removed. That date is updated at most once a week, or when the token changes, so it is not a record of when you open the app. Signing out removes the token for that phone.

A notification is delivered through Expo's push service to Apple or Google, and it carries the text you would see on your lock screen — which names your child ("New photos of Louie") and who did the thing. It never carries a photo. Your child's first name therefore passes through those services in order to be displayed. That is how notifications work on both platforms; the alternative is a notification that cannot say what it is about.

Stored only on your own device

Your appearance preference (day/night), your measurement units, and whether you have seen the introductory walkthrough. These never leave your phone.

What the app does NOT do

Why we process this data

To operate the service you asked for: to record and display your child's care, to synchronise it between the caregivers in your household in real time, to show the slices you have chosen to share with your Circle, to keep the app working (diagnostics), and to know whether it is working for families (the totals described above).

Where GDPR applies, our lawful basis is performance of a contract for the core service, and legitimate interests for diagnostics and for counting totals. Health-related data (growth measurements, care records) is processed on the basis of your explicit consent, given by choosing to enter it, and you may withdraw that consent by deleting the data or your account.

About the child's data

The information in this app is *about* a child but is provided *by* an adult caregiver who holds the account. The app is not directed at children, is not offered in the Kids Category, and we do not knowingly allow anyone under 13 to create an account.

The adult account holder is responsible for what they enter and for whom they invite into a Circle.

Who else is involved

We use the service providers below. They process data on our behalf, under their own security commitments, and are not permitted to use it for their own purposes.

ProviderWhat they doWhat they see
SupabaseDatabase, authentication and file storageAll app data described above, plus the IP address and user agent of each signed-in session and request logs
SentryCrash reporting, with performance data from a sample of launchesDiagnostic data only, with record identifiers removed, and a random identifier made on your phone; no account or child data
AnthropicRuns the AI model behind the assistant, in limited early access for invited households onlyOnly when you use the assistant: your question, your recent messages in that conversation, and the summary of your child's record listed above
Expo (EAS)Delivers app updates, and delivers notifications to Apple and GoogleWhen the app checks for an update, which it does each time it starts: the app version and platform, and a random identifier the update system creates on your phone. For a notification: its token and the text shown on the lock screen

Security

No system is perfectly secure, and we cannot guarantee absolute security.

About Anthropic specifically. What Anthropic's terms say about training on what is sent and about how long it keeps it is quoted, with links, under "If you use the AI assistant" above.

One thing account deletion cannot reach. Anything already sent to a service provider has left our systems. Deleting your account removes what we hold; it cannot reach back into somebody else's.

How long we keep it

We keep your data for as long as your account exists. The one exception is AI assistant conversations, which are deleted after a period without use, as described under "If you use the AI assistant".

Deletion is immediate and cannot be undone. Backups may retain data for a short period before being cycled out.

Your rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict processing, and to complain to a data protection authority.

Most of this is available directly in the app: your data is visible to you, editable by you, and deletable by you. For anything else, contact us at the address above and we will respond within 30 days.

Changes

If this policy changes materially, we will update the effective date above and notify you in the app before the change takes effect.

1 October 2026. This page and emoy.app now say only what is literally true about what the app sends.

30 September 2026. The AI assistant is now in limited early access for households we have invited. The previous version of this page said it did not exist yet and marked Anthropic as "not yet in use", and that stopped being true when the first invited household outside our own could use it. This page now lists what is sent to Anthropic, including every part of the summary of your child's record, and quotes what Anthropic's terms say about keeping and training on it. This page used to say Anthropic does not keep what is sent "by default". Anthropic's privacy center says it deletes it within 30 days, so the page now quotes that instead. It also says what we store, that only you can read your conversations, that they are kept until 18 months pass without you using the assistant in that household, and how to have them deleted sooner. Nothing else on this page has changed.

17 September 2026. Two corrections, both making this page match what the app already does. Nothing about how the app works has changed.

This page said the app records whether a child was born prematurely and their gestational age, and uses them for growth percentiles. It never recorded either; that text described a design that was not built, and it has been removed.

This page also described signing in only with an email address and password. The app has offered Sign in with Google and Sign in with Apple since it launched, and it now says what each one shares with us, and that deleting your account also revokes EMOY's access to your Apple ID.

8 September 2026. One change, and it is a loosening, so we would rather say so plainly than dress it up.

The commitment not to train machine-learning models on your photos or your child's data previously admitted no exception at all. It now names one: we would have to ask you first, and nothing would be used unless you chose it. Nothing about how the app works today has changed, and no data has ever been used this way. We are setting the condition out now rather than quietly revising a promise later.

3 September 2026. Two changes.

Notifications about what someone else did — a photo added, a milestone logged, a reply — are now sent from our server, so they can reach you when the thing happened on somebody else's phone. The previous version of this policy said push notifications were not used, which was true when it was written. We now describe what is stored for them, what a notification carries, and that it passes through Expo, Apple and Google to be shown.

We also added Anthropic to the list of services, ahead of an assistant that answers questions about your own child's record. The feature is not built. It is described here first so that the policy is already accurate the day it works, rather than catching up afterwards.

25 August 2026. First published.