Privacy policy
Last updated: 30 September 2026
Draft: the details in square brackets are still to be completed.
This policy explains what data Moonby (the iPhone and Android apps, the web app and the website) processes, why, who we share it with and how you can control it. It applies to people who use the app, people invited into a family and people who buy or receive a gift card.
1. Data controller
The data controller is:
[NAME OR COMPANY NAME][REGISTERED ADDRESS]
VAT number: [VAT NUMBER]
Support: [SUPPORT EMAIL]
Privacy: [PRIVACY EMAIL]
For any question about your data or to exercise your rights, write to the privacy email above.
2. What data we process
We only process the data needed for the features you use:
- Account and sign-in. Email; your name if you sign in with Apple or Google and, with Google, your profile picture; Apple and Google identifiers; passkeys, of which we only receive the public key and never your fingerprint or face; sessions with IP address and device or browser type.
- Your child. Name, date of birth or due date, gender if you provide it, weight, height, feeding, sleep habits and any difficulties you describe to us.
- The diary. Sleep and night wakings, breastfeeds and bottles, meals, pumping, nappies, temperature, medicines, mood and notes, with who made each entry and the history of changes.
- You as a parent. Name, age range, role, goals, how you heard about us and, if you use them, your personal journal and information about your wellbeing, such as mood and ratings.
- Family and invitations. Members and roles, and the email addresses of the people you invite and of invitations you receive.
- AI consultant. Questions, answers, the memory of useful information about your child, and technical usage and cost data.
- Video course and notifications. Lesson progress, notification preferences, the device identifier for push notifications and recent days of use to schedule reminders.
- Subscriptions and gifts. Plan, status, amounts and Stripe, RevenueCat and store identifiers. For a gift card: the buyer’s and recipient’s names and email addresses, the message, delivery date and chosen design. Full payment card details are handled by Stripe, Apple or Google: we never receive them.
- Support. The email address, subject, platform and message you send us through the support form or from the app.
- Technical data. IP address, sometimes only as a hash, to protect sign-ins and purchases from abuse; the country estimated from your IP to suggest a currency, without storing it; essential error logs, without diary content.
3. Health data
Some information may relate to health: temperature, medicines, weight and height, sleep difficulties and notes about your child, as well as information about the parent’s wellbeing. These are special categories of data, and we process them only with your explicit consent (Article 9(2)(a) GDPR) and only for the features that use them.
This information is always optional: if you do not want to give consent, do not enter it. You can withdraw consent at any time by writing to us or deleting your account; withdrawal does not make earlier processing unlawful.
4. Why we use it and on what legal basis
- Providing the service: account, diary, predictions, statistics, family, AI consultant, video course, sounds and the notifications you turn on. Basis: performance of the contract (Article 6(1)(b) GDPR) and, for health data, your explicit consent.
- Service emails: sign-in codes, invitations, gift cards, purchase confirmations and end-of-trial reminders. Basis: performance of the contract.
- Payments, invoices and tax and accounting obligations. Basis: performance of the contract and legal obligation (Article 6(1)(c)).
- Security, preventing abuse and fraud, usage limits. Basis: our legitimate interest in protecting the service and its users (Article 6(1)(f)).
- Delivering a gift card, or an invitation to discover the app, to someone a user names: we use the recipient’s name and email address only for that delivery. Basis: the legitimate interest of the giver or inviter and our own.
- Answering support requests. Basis: performance of the contract or, if you are not yet a user, our legitimate interest in replying to you.
- Push notifications to discover the consultant, Plus and Pro: only if you turn on this category, which is off by default. Basis: consent (Article 6(1)(a)).
We do not send newsletters or promotional emails, we do not use data for advertising or commercial profiling, and we do not sell it. In the app you can choose whether to contribute to research with anonymised data: this is optional and can be withdrawn; we do not currently use any data for research and, if we start, we will inform you first.
5. The AI consultant
When you ask a question, we send OpenAI the question, the latest messages in the conversation with the names of their authors, and the context needed to answer: your child’s name, date of birth and age, time zone, feeding, sleep habits and difficulties, recent statistics, the day’s plan, the chat memory and, when needed, passages from the family’s earlier conversations and diary entries from up to 90 days, including notes, temperatures and medicines. We do not send email addresses, payment data, your personal journal or information about your wellbeing.
We use the OpenAI API without saving conversations at OpenAI. Under OpenAI’s API terms, the data is not used to train models and may be kept for up to 30 days for abuse monitoring. To search the video course, we also send OpenAI a short search phrase derived from the question.
The consultant may remember useful information you write, such as one of your child’s habits. You can view, correct or delete the memory and the conversations at any time.
Answers and predictions are generated automatically but remain suggestions: we do not make automated decisions that produce legal or similarly significant effects on you (Article 22 GDPR).
6. Who sees data within the family
Family members can see the children’s profile and diary, the conversations with the consultant and its memory, including those from before they joined, and the names of who wrote them. Your parent profile, personal journal and wellbeing information remain private.
Widgets you add to your phone’s screen may show your child’s name and sleep even on the lock screen.
7. Providers and other recipients
We only share data with the providers we need for the service, bound by data processing agreements:
- Supabase: database and scheduled jobs.
- Vercel: hosting for the website, the web app and the API, which runs in the Frankfurt region.
- OpenAI: AI consultant and video course search.
- Cloudflare: course videos; it receives the viewer’s IP address and device type.
- Stripe: web payments and fraud prevention.
- RevenueCat: verifying in-app purchases; it only receives a random identifier, not your email address.
- Resend: sending emails.
- Expo and the notification services of Apple, Google and web browsers: delivering push notifications.
- Microsoft: the mailbox where we receive support messages and feedback.
Apple and Google, for their sign-in services, stores and notifications, and Stripe, for purposes such as fraud prevention and regulatory obligations, process data as independent controllers under their own privacy policies. We disclose data to authorities only when required by law.
8. Transfers outside the European Union
Several providers are based in the United States or may process data from there. In these cases, the transfer relies on the EU-US adequacy decision (EU-US Data Privacy Framework) for certified providers, or on the standard contractual clauses approved by the European Commission. You can ask us for a copy of the safeguards by writing to the privacy email.
9. How long we keep data
- Account, profile, diary, conversations and memory: until you delete them or your account. Entries deleted from the diary remain in the family’s change history for as long as the family exists.
- Sessions: they expire after 30 days without use and then no longer give access; they are deleted when you sign out or delete your account. Sign-in codes are valid for 5 minutes.
- Days of use for scheduling reminders: only the last 90.
- Orders, payments and gift cards: 10 years for tax and accounting obligations, including after your account is deleted, no longer linked to your profile.
- Support messages: for as long as needed to handle the request and to document it in case of disputes.
- Backups: they are overwritten on a rolling basis under the database provider’s policy. Data sent to OpenAI: up to 30 days, under OpenAI’s terms.
10. Deleting your account and data
You can delete your Moonby account at any time from the app or the web app: open your profile, go to your account data and choose “Delete account”. For security, we ask you to confirm and, if you have not signed in recently, to sign in again. If you cannot sign in, write to the privacy email from your account’s address.
We immediately delete your account, sign-in methods, parent profile, preferences, notifications, support messages saved in the app and the consultant conversations you took part in. If you were the last member of the family, we also delete the family, children, diary and conversations. If other members remain in the family, the shared diary stays with them without your name.
We only keep the order and payment data required by law. Before deleting your account, you can download a free copy of your data from the same section. Deleting your account does not cancel App Store or Google Play subscriptions.
12. Your rights
You can ask to access your data, correct it, delete it, restrict its processing, receive it in a machine-readable format (portability) and object to processing based on legitimate interest. You can withdraw any consent at any time, without affecting earlier processing. You can do many of these things directly in the app, such as editing, exporting and deleting; for anything else, write to the privacy email. We reply within one month.
You can also lodge a complaint with the supervisory authority of the country where you live or work; in Italy, this is the Garante per la protezione dei dati personali.
13. Children
Moonby is intended for adults. A child’s data is entered by a parent, guardian or authorised caregiver; the child does not use the service. If we find out that an account was created by a minor, we delete it.
14. Security
We protect data with encrypted connections, restricted access to our systems, codes and tokens stored encrypted or hashed, and encrypted offline copies on your phone. No system is 100% secure: if a data breach affects you, we will notify you as required by law.
15. Changes to this policy
If we change this policy in a significant way, we will tell you by email or in the app before the changes apply. The date at the top shows the version in force.