moppet is an app for keeping a private, shared record of a child's care across a household. The data controller is Roebling Foundry LLC, a limited liability company registered in New York, United States. If you have any question about your data or this policy, contact us at privacy@mymoppet.com.
Our representative in Europe. Because we are based outside Europe, we have appointed DataRep (a trading name of Data Protection Representative Limited, 77 Camden Street Lower, Dublin, D02 XE80, Ireland) as our data protection representative in the European Union and EEA under Article 27 of the GDPR, in the United Kingdom under Article 27 of the UK GDPR, and in Switzerland under Article 14 of the Swiss FADP. If you are in one of those places, you can raise any question about your data or exercise your rights through DataRep by emailing datarequest@datarep.com with "moppet" in the subject line, by using the web form at www.datarep.com/data-request, or by writing to DataRep at any of their locations across the EU, EEA, UK, and Switzerland. If you write by post, mark your letter for "DataRep", not moppet, or it may not reach them. Contacting DataRep does not limit your right to contact us directly at privacy@mymoppet.com, or to complain to your data protection authority.
Our legal representative under the EU Digital Services Act. We have also appointed DataRep (Data Protection Representative Limited) as our legal representative for the purposes of Article 13 of the Digital Services Act. You can contact them about Digital Services Act matters at digitalrequest@datarep.com, by post to DataRep, The Cube, Monahan Road, Cork, T12 H1XY, Republic of Ireland, or by telephone at +353 (1) 919 8899. If you write by post, mark your letter for "DataRep", not moppet, or it may not reach them. These Digital Services Act contact channels are separate from the data-protection channels described above.
This policy explains what personal data moppet processes, why, where it is stored, and the rights you have.
You give us:
Your child's due date: it is optional, we never work it out for ourselves, and you can clear it at any time. If your child arrived early, the date they were due tells moppet how far along they are rather than how many days have passed since the birth, so the rhythm it expects of them, the point at which it decides a feed is overdue, the age at which feed reminders stop arriving overnight, and the age at which they stop altogether, are read at the age their body is running. Those four things are the whole of what it changes. It does not change the age moppet shows you, which stays the age since birth, because that is the age you and your doctor mean. It does not change a medicine or a dose. The dose chart is read from your child's weight, and the age it checks before it will show a row at all is the age since birth. It does not change which caregivers receive reminders, or which kinds they get: those stay what each of you chose in your own settings. It does change how long feed reminders keep coming, and feed reminders only. Where the guidance of the American Academy of Pediatrics or the NHS applies, moppet stops sending them at around 18 months, and with a due date on file it reads that point at the age your child's body is running, so a child who arrived early can go on receiving them for a few weeks longer than the date of birth alone would suggest. Feed reminders stop by 2 years since the birth in every case, whatever the due date says. Everywhere else, and for nap and diaper reminders everywhere, moppet already goes quiet no earlier than the point any correction can reach, so nothing about those changes. Leave it blank and nothing reads it. Because it says something about how your child was born, we treat it as health-related information about them, in the same way as the entries above (see section 5).
Overnight, moppet does not send feed reminders on the daytime rhythm at all. A child who is hungry at night wakes and says so, so a nudge on the usual cadence tells a caregiver nothing they were not about to learn. Instead moppet stays quiet and watches for the case the child is not raising: a gap since the last feed much longer than is normal for a child of that age. In the evening that draws one reminder. In the deepest hours of the night moppet holds even that until morning, unless the gap has grown far beyond what is normal at any age; while a child is young enough for overnight reminders at all, a gap of that size still draws its one reminder at any hour, because it should. It reads the clock in the child's time zone, not the caregiver's, so someone caring for your child from another country does not change when a nudge arrives. This uses records moppet already holds: the feeds you have logged, the date of birth, and the due date if you entered one. Sleep records are not used to decide whether to send a feed reminder. Where NHS guidance applies, and in the United States where moppet follows it because no American body publishes the figure, feed reminders stop arriving overnight once a child is about a year old, the way nap and diaper reminders already do; elsewhere they keep coming overnight until they stop altogether at 2 years. Medicine reminders are not affected and still arrive whenever a dose is due, at any hour.
Created automatically:
Crash diagnostics: when something in the app goes wrong, it sends us a diagnostic report so we can find out what broke. Where the fault is in moppet's own code, the report is rebuilt from a fixed list of allowed fields before it leaves your device, rather than filtered, so anything we have not explicitly allowed is dropped. That report contains the place in our code where it happened, a short fixed list of technical labels such as which screen you were on and whether the entry was a create or an edit, your device model, its operating system version, which release of moppet you are running, and the error message with email addresses and long number sequences stripped out. Where the fault is in your device's own system layer, below our code, the crash reporter sends that report itself and we cannot rebuild it first: it carries the error, the stack it happened on, and the device and system details the reporter collects. Neither kind carries a trail of what you did before the crash, and neither carries anything the app sent or received over the network. No entry, note, or measurement is attached to a report. The one place a value could appear is inside the error message, which is why that text is stripped before it is sent. Neither kind is tied to your account, so we cannot tell whose report it is. We use them only to keep the app working. Section 6 says who processes them.
What we deliberately do not do: moppet contains no product analytics, no advertising identifiers, no third-party trackers, and no cookies for tracking. Nothing measures how you use the app. We do not build profiles of you and we do not sell or share your data with anyone for their own purposes.
Some entries (for example temperature, medication, health notes, growth) may be health data about your child. Where that is the case, we rely on your explicit consent (Art. 9(2)(a)). We ask for it on its own screen, before any health-related entry can be recorded, and we record the date you gave it. It is not inferred from your use of the app.
You can withdraw that consent at any time in Settings. Withdrawing stops the processing it covers. On the device you withdraw on, moppet stops showing and syncing your household's entries, and anything it had queued to send stops being sent. For the account as a whole, we delete the notification tokens we hold, so reminder notifications stop going to any of your devices. We delete the Live Activity tokens with them, so another caregiver's running timer stops appearing on your lock screen. A medication reminder that another of your devices has already placed on its own lock screen is cleared the next time you open moppet there. Your data is not deleted by withdrawing: from the screen you are returned to you can still export a copy of it, or delete your account. You can also delete any entry, or your whole account, at any time (see section 8).
We use a small number of processors who act only on our instructions:
| Processor | Purpose | Location |
|---|---|---|
| Supabase (hosted on AWS) | Database, authentication, real-time sync | European Union (AWS eu-central-1, Frankfurt) |
| Vercel | Web hosting (mymoppet.com) | United States |
| DeepL (DeepL SE) | On-demand translation of a free-text note into another caregiver's language | European Union (Germany) |
| Anthropic (Claude) | Reads a typed medication instruction or a photo of a medicine label to fill in a schedule. Translates a note whenever the language it was written in, or the language it is being read in, is one of the five DeepL does not cover. If you import a file from an unrecognized baby-tracking app, reads its column headings, up to 20 entries, and the repeated values of any short-list column, which can include caregiver names, to work out which column is which. Words the short interpretation of your child's sleep and feeding patterns that the Rhythm tab shows, from a summary of the patterns moppet has already worked out, which carries no entry, no note, no name, and no date | United States |
| Apple | Sign in with Apple authentication. App Store purchases (Apple is the merchant for a subscription bought there, as Google is for one bought on Google Play). On an iPhone or iPad, delivery to your device of reminder notifications and of the timer-stop alert. For a timer another caregiver is running, delivery of both the instruction that puts it on your lock screen, which carries the kind of timer and the time it started, and the instruction that clears it once they stop. Those last two reach Apple directly rather than through Expo | Per Apple's terms |
| Google (Firebase Cloud Messaging, Google Play) | On an Android phone or tablet, two separate things. The last hop that delivers reminder notifications and the timer-stop alert to your device, carrying the same contents the Expo row describes, through Firebase Cloud Messaging. And, if you subscribe on an Android phone, Google Play purchases: Google is the merchant for that subscription, exactly as Apple is for an App Store one. Google is not used for sign-in, and Google never receives your child's records. For a timer another caregiver is running, the instruction that puts it on your lock screen and the instruction that clears it once they stop reach you the same way, through Firebase Cloud Messaging, carrying the kind of timer and the time it started and no name of any kind. On an iPhone those two reach Apple directly instead; on Android they pass through Expo like any other notification | United States |
| RevenueCat | Subscription status management (which subscription you hold and whether it is active, never your child's care data) | United States |
| Expo / EAS | App build and over-the-air updates. Delivery of reminder notifications, which carry your child's first name and, for a medication reminder, the medicine and the dose. Delivery of the timer-stop alert, which carries the caregiver's display name and the times the timer covered. Expo passes each of those to Apple on an iPhone or iPad and to Google on an Android device, which is the last hop to the phone itself. Those are the notifications. The lock-screen timer instructions in the Apple row above do not pass through Expo on an iPhone or iPad; on an Android device they do, because Android has no equivalent of Apple's direct route | United States |
| Microsoft 365 | Account email in both directions: sending you sign-in codes, the link that confirms your address, password recovery codes, and the one-time welcome message, all from hello@mymoppet.com, and receiving the mail you send to hello@mymoppet.com, support@mymoppet.com, and privacy@mymoppet.com. We do not send your child's care data by email | United States |
| Sentry (Functional Software, Inc.) | Crash diagnostics: the fault reports described in section 3, which have no entry from your records attached and are not tied to your account | European Union (Frankfurt, Germany) |
Note translation. When a caregiver opens a note written in a language other than their own, the note text is sent for translation on demand, and the translation is cached, so this happens only once for each note and each reading language. Two languages decide where the text goes: the one the note was written in, and the one it is being read in. DeepL, in the EU, receives the note when both of those are among the sixteen languages DeepL covers. Anthropic, in the United States, receives the note when either one of them is one of the five DeepL does not cover. A note typed in Tagalog therefore leaves the EU even when the caregiver reading it has chosen French, and a note typed in French leaves the EU when the caregiver reading it has chosen Tagalog. DeepL processes the text only to perform the translation, under our agreement (paid API and Data Processing Addendum), and it does not use your text to train its models. The Medication help paragraph below sets out Anthropic's terms, and they are the same for a note as for a medication instruction. Notes on an entry record the language they were typed in, so one already in your language is never sent. Three kinds do not record one: your child's profile notes, a medication schedule's notes, and notes imported from another app. None of those is sent automatically. Each one shows a Translate option, and it is sent only if you tap it, so the language can be detected. Because they record no language, they go to DeepL unless the caregiver reading them has chosen one of the five. The result is then cached.
Medication help. When you use the medication feature, the instruction you type or the photo of a medicine label you add is sent to Anthropic's Claude model, which reads the details into a schedule for you. Claude also translates a note whenever the language it was written in, or the language it is being read in, is one of the five DeepL does not cover: Tagalog, Vietnamese, Swahili, Yoruba, and Igbo. Anthropic processes this text only to perform the task, under its commercial terms, and does not use it to train its models. Anthropic holds what is sent for up to 30 days. Anthropic is in the United States.
Pattern interpretation. The Rhythm tab can show a short sentence or two about what several of your child's sleep and feeding patterns mean together. moppet works out the patterns itself, on your device, and then sends a summary of them to Anthropic's Claude model to put into words. That summary is a list of short statements such as that bedtime is moving earlier, how strong each is, your child's age in months, and a few sentences of general guidance for that age. It carries no entry from your record, no note, no name, no date, and no caregiver's name. Claude returns the wording, moppet checks it against the same patterns before showing it, and the sentence is kept on your device. This happens when the patterns have changed, at most twice a day for each child. Anthropic processes the summary only to perform the task, under its commercial terms, and does not use it to train its models. Anthropic holds what is sent for up to 30 days. Anthropic is in the United States.
Import help. If you import your history from another baby-tracking app and moppet does not recognize the file's format, you can ask it to work out the columns. What is sent to Anthropic's Claude model is the column headings, up to 20 entries, and, for any column that holds only a few repeated values, the list of those values, which can include caregiver names. Claude returns a description of which column is which. Your file itself stays on your device, and nothing is imported until you confirm the preview. moppet stores nothing from this step. Anthropic holds what is sent for up to 30 days and does not use it to train its models. Anthropic is in the United States. This only happens when you choose it.
Crash diagnostics. When the app hits a fault, the report described in section 3 is sent to Sentry, which stores it in the European Union, in Frankfurt, Germany. Sentry processes it only to show it to us, under our agreement with them. A report from moppet's own code is rebuilt before it leaves your device: a fixed list of allowed fields is kept, everything else is dropped, and the error message has email addresses and long number sequences removed. A crash in your device's own system layer is sent by the crash reporter directly, so it is not rebuilt first, and it carries what section 3 describes. Sentry is a United States company, and while the reports themselves stay in the EU, our own account details with them are held in the United States.
Where your data is stored. Your household records and your child's care data are stored in the EU (Supabase, in Frankfurt, Germany). Four features send specific text elsewhere: note translation, medication reading (Anthropic, in the US), on-demand import column-mapping (Anthropic, in the US), and the wording of the pattern interpretation on the Rhythm tab (Anthropic, in the US, from a summary that carries no entry, note, name, or date). Note translation goes to DeepL in the EU when DeepL covers both the language a note was written in and the language it is being read in. It goes to Anthropic in the US when either of those two languages is one of the five DeepL does not cover. Reminders are a fourth: if you turn them on, each notification is delivered through Expo in the United States and then by the company that runs your phone's notification service, which is Apple on an iPhone or iPad and Google on an Android device, also in the United States, and it carries your child's first name, or for a medication reminder the name of the medicine and the dose. That is the notification text itself, not access to your record. The alert that another caregiver stopped a timer is a fifth: it travels the same way, through Expo and then Apple or Google in the United States, and it carries that caregiver's display name and the times the timer covered. Settings has a switch that turns that one off. Another caregiver's running timer appearing on your lock screen is a sixth. On an iPhone or iPad it takes a shorter route, going to Apple alone rather than through Expo; on an Android phone it travels the same way the reminders do, through Expo and then Google in the United States. Either way it carries the kind of timer, such as nursing, and the time it started, with no name of any kind. That one stays off until you switch it on in Settings. Crash diagnostics stay in the EU (Sentry, in Frankfurt, Germany), and no entry from your records is attached to one. Apart from those, your child's care data is not transferred outside the EU or EEA. App builds and over-the-air updates run through Expo and EAS in the US, which handle the app itself, not your child's care data. The mymoppet.com web address is served by Vercel (US), which delivers the app interface but does not store or access your household data. If you buy a subscription, Apple processes the payment and RevenueCat (US) manages the subscription's status, and neither ever receives your child's care data. These processors act only on our instructions. We do not sell or share your data, and we use no one else.
Support correspondence. When you email hello@mymoppet.com, support@mymoppet.com, or privacy@mymoppet.com, we record the message in our own systems in the EU (Supabase, in Frankfurt, Germany) so we can handle it and keep track of what was asked, and it is routed automatically for triage. What we record by default is who sent it, when, the subject line, and a preview of up to 500 characters. When we need the substance of a message, for example to answer a request or to read an attachment, the full message and its attachments are fetched and stored in the same place. Your child's care data is not part of this: it covers only what you choose to put in the email.
International data transfers. Some of these processors are in the United States (see the table above), and one of two safeguards recognised by Chapter V of the GDPR applies to each of them. For Anthropic, Apple, Expo, Google, Microsoft, RevenueCat and Supabase we rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum and the Swiss provisions where they apply, as the safeguard required by Article 46 of the GDPR. For Sentry and Vercel we rely instead on their certification under the EU to US Data Privacy Framework and its UK and Swiss extensions, with the Standard Contractual Clauses as a fallback if that certification stops applying to them. You can request a copy of the safeguards we use by emailing privacy@mymoppet.com.
We keep your data for as long as your account is active. When you delete your account (Settings › Account › Delete account), we remove it from our live systems straight away, and it stops being visible to you or any caregiver at once. Copies can remain for a short time in our hosting provider's encrypted daily backups, which roll off within 7 days. A household that only you belong to is deleted along with all its entries. Co-caregivers' households remain with them.
Deleting a single entry is different from deleting your account. It removes the entry from the record everyone reads, and the privacy dashboard shows that it was deleted and by whom, so the caregivers who share the household can see what changed. The entry itself is held until you delete your account, which removes it with everything else. If you want an individual entry erased sooner than that, email privacy@mymoppet.com.
How long our processors keep it. A crash report is held by Sentry for 30 days on our current plan and is then deleted. That period is fixed when the report arrives, so changing our plan later does not extend a report already sent. Text sent to DeepL for translation is held only for as long as producing the translation requires, and is deleted afterwards under our agreement with them. It is never used to train their models. A note sent to Anthropic instead is held for up to 30 days. That happens when one of the two languages is one of the five DeepL does not cover, as section 6 describes.
Correspondence. Email you send to hello@mymoppet.com, support@mymoppet.com, or privacy@mymoppet.com is kept for six years from the date of the message, and is then deleted automatically. We keep it for one reason: so that a legal claim can be established, exercised or defended, which is the ground Article 17(3)(e) of the GDPR provides, and, where a message describes your child's health, the ground Article 9(2)(f) provides. Six years is the longest period in which such a claim can still be brought against us. Deleting your account does not delete correspondence you sent us. You can ask us to delete it sooner by emailing privacy@mymoppet.com, and we will unless we still need it for a claim.
Under the GDPR you have the right to:
To exercise any right that cannot be done in-app, email privacy@mymoppet.com. We answer within one month, as the GDPR requires, and we will tell you if a complex request needs up to two months more. We verify that a request comes from the account holder before acting on it.
Your data is protected by row-level security (each household can only see its own data) and is encrypted in transit. Access ends immediately when a caregiver is removed. A recent copy of your household's entries, covering up to the last seven days, is also kept on your own device so the app keeps working when you have no signal. That copy stays on the device. It is removed when you sign out, when you delete your account, and if you withdraw consent to health-data processing. If a caregiver is removed from the household, the copy already on their device stops updating and is erased within seven days.
moppet is used by adult caregivers to record information about their own child. It is not intended for use by children, we do not market it to children, and we do not knowingly allow children to create accounts. Accounts are for adults aged 18 and over, as our Terms require. Separately, if we learn that a child under 13 has created an account, we will delete it.
Your child's records belong to you. Everything moppet holds about your child is entered by you (or a caregiver you invited), and you stay in control of it. You can edit or delete any entry, export everything as a CSV, and delete the whole account at any time (see sections 7 and 8). We use your child's information only to provide the app to your household, never for advertising, profiling, or sale, and there are no third-party trackers (see section 3).
For US families: moppet is a service for adults and is not directed to children under 13. We do not collect personal information from children. The information you record about your child is provided by you, the parent or caregiver, and is handled as described in this policy.
For EU families: your child's health-related entries are special-category data processed with your explicit consent, as described in section 5, and stored in the EU (see section 6).
This section is for California residents and uses the terms of the California Consumer Privacy Act, as amended by the California Privacy Rights Act (together, the "CCPA"). It restates, in California's language, the same practices described above.
Personal information we collect. In the last 12 months we have collected:
We do not collect precise geolocation, biometric information, financial account details, or your activity across other websites and apps. Apple processes subscription payments, so we never receive your card details.
Where it comes from. We collect most of this directly from you, the caregiver, when you create an account and log entries. Your subscription status is the exception: it comes from Apple, through RevenueCat, when you buy a subscription and each time it renews or lapses.
How we use it. Only to run moppet for your household, keep it secure, and complete a subscription you buy. These are the business purposes described in sections 4 and 6. We do not use or disclose your sensitive personal information for anything other than providing the service, so the CCPA's right to limit the use of sensitive personal information does not change how we handle it.
We do not sell or share your personal information. We have not sold personal information, and we have not shared it for cross-context behavioral advertising, in the last 12 months, and we will not. This is true for everyone, including anyone under 16. We run no advertising and use no third-party trackers.
Who we disclose it to. We disclose personal information only to the service providers listed in section 6, and only so they can perform their service for us.
Your California rights. You have the right to:
How to exercise them. Most of these are built into the app: edit entries and your profile to correct data, the export button in Settings › Privacy & your data for a copy, and Settings › Account › Delete account to delete. For anything you cannot do in the app, email privacy@mymoppet.com. We will verify the request against your account, respond within the timeframes the CCPA requires, and you may use an authorized agent to make a request for you.
Shine the Light. We do not disclose personal information to third parties for their own direct marketing, so California's "Shine the Light" law (Civil Code section 1798.83) does not apply.
We will update this policy as moppet evolves and change the "Last updated" date above. For material changes we will let you know in the app or by email.
moppet is a product of Roebling Foundry LLC (New York, United States). Privacy contact: privacy@mymoppet.com. In the EU, EEA, UK, or Switzerland you can also contact our representative, DataRep (see section 1).