Privacy Policy
Last updated 29 August 2026
BeeLucy is a shared log for one baby and the people caring for them. This policy describes exactly what the app stores, why it stores it, who else can see it, and how to get rid of it. It describes the app as built: there is no advertising, no analytics, and nothing here is sold.
Who is responsible for your data
MB BeeLucy, registered in Lithuania, is the data controller for the information described below. You can reach us at hello@beelucy.com about anything in this policy, including a request to exercise your rights.
We are not required to appoint a Data Protection Officer and have not appointed one. Your emails are read by us directly.
What BeeLucy does not do
Some of the clearest things we can tell you are the things that are absent. BeeLucy contains:
- No advertising, and no advertising networks.
- No analytics, product-measurement, or crash-reporting service. We do not know how many screens you opened, or when. The only thing we ever ask you for is the optional note on the way out, described below.
- No tracking of you across other apps or websites, and no advertising identifier. The app never shows iOS’s tracking prompt because it has nothing to ask for.
- No profiling and no automated decision-making.
- No selling, renting, or sharing of your information for anyone else’s marketing. Not now, and not as a change of mind later — a change of ownership is the only way that could ever happen, and we would tell you before it did.
- No access to your location, contacts, photos, calendar, or microphone. The white noise is generated mathematically on your device; nothing is recorded or listened to.
What we hold
Your account. You sign in with Google or with Apple, so we never see or store a password. Your provider passes us the profile they hold for you — normally your name, your email address, and a link to your profile picture — along with a stable account identifier. If you use Sign in with Apple and choose Hide My Email, the only address we ever receive is Apple’s relay address.
Your caregiver profile. The display name you choose (which starts as “Parent”), and your notification preferences for each baby record: whether notifications are on, whether you want them when something is logged and when something ends, and any types you have muted.
The baby record. Its name, the date of birth if you enter one, its six-character invite code, and which account created it.
The log. For each entry: the date and time it happened, an end time if it has one, which types it carries, an optional note you type, and which caregiver created it and last changed it. Plus the types themselves — their names, icons, and colours.
Push tokens. If you turn notifications on, one token per device, and whether that device is iOS or Android. A token identifies the installation, not you.
On your device, and nowhere else: your sign-in session, your clock and units preferences, and a copy of the most recent entries in a shared container so the home-screen widget can draw itself without launching the app. Signing out clears the session copy.
What you write to us. If you email us, we hold your message and the address you sent it from for as long as it takes to answer you properly. It is joined to nothing else in this list — unless you are asking us to do something to your account, in which case answering you means working out which account you mean.
Why you left, if you say. On the way out of Delete account the app optionally asks why, as tick-boxes and a free-text note. What you write is stored on its own, with no account identifier, no email address, and no way back to the account it came from — the record is written at the moment that account is deleted, so there is nothing left to attach it to. We store which platform it came from, and nothing else about you. We keep it for up to 24 months and read it only to decide what to fix.
The other side of that: because we cannot connect the note to you, we cannot find it again to remove it if you later ask. That is why the app asks you to leave personal details out of the box, and why every question there is optional — skipping them changes nothing about the deletion itself.
Why we hold it, in law
- To perform our contract with you (GDPR Article 6(1)(b)): your account, the baby record, the log, syncing it between caregivers, and invite codes. Without these the app cannot do the one thing it exists to do.
- With your consent (Article 6(1)(a)): push notifications. You give it through your device’s permission prompt and can withdraw it at any time, in BeeLucy’s Settings or in your device settings, without affecting anything else.
- For our legitimate interests (Article 6(1)(f)): keeping the service running, secure, and free of abuse, answering you when you write to us, and understanding why people leave from the optional note described above. We have weighed this against your interests and it involves no profiling.
Who else can see it
Other caregivers on the same baby record. This is the point of the app rather than a side effect: everyone on a record sees its whole log and history, its types, and each caregiver’s display name — including entries logged before they joined. Anyone who has your invite code can join and gain that access, so treat the code as you would a key.
Service providers who process data on our instructions, under contract, and for no purpose of their own:
- Supabase — the database, sign-in, live sync, and the server-side function that deletes accounts. Your data is stored in the European Union.
- Expo (Expo Application Services) — relays push notifications to Apple and Google, and serves over-the-air app updates. Based in the United States.
- Apple Push Notification service and Google Firebase Cloud Messaging — the final delivery of a notification to a device.
- Fastmail — our mailbox. If you write to us, your message and the address you sent it from sit there. Based in the United States.
Google and Apple also act as independent controllers for the sign-in step itself, under their own privacy policies. We tell them nothing about you; they tell us who you are.
We will also disclose information where the law requires it, but not otherwise, and we would resist a request that looked improper.
A notification carries readable content: the baby record’s name, the display name of whoever logged the entry, and the names of the types on it. That text passes through Expo’s push service and then Apple’s or Google’s, and it can appear on a lock screen. If you would rather it did not, turn notifications off in Settings — everything else keeps working.
Where it is stored, and transfers
The database — everything in “What we hold” apart from what stays on your device — is hosted in the European Union and does not leave it in the ordinary course of running the app.
Three flows reach the United States. Push notifications, because they are relayed by Expo: this covers your push tokens and the notification text described above. Update checks, because the app fetches over-the-air updates from Expo: this involves your IP address, device model, and app version, and no account data. And email, because our mailbox is hosted by Fastmail: whatever you write to us is stored there. All three rest on the European Commission’s Standard Contractual Clauses, and on each provider’s own certification where it applies.
Children
BeeLucy is for adults. Accounts are for people aged 18 or over, and the app is neither directed at children nor designed to appeal to them.
A baby’s name and date of birth are information about a child, and we treat them as what they are: entered by a caregiver, about their own child, for their own use. The child has no account, and we never collect anything from a child directly. If you believe a child has created an account, email us and we will delete it.
How long we keep it
- Your account and profile: until you delete your account.
- Log entries and types: for as long as the baby record exists. An entry belongs to the record rather than to whoever typed it, so if you leave a record or delete your account, entries stay but stop being attributed to you.
- The baby record: until its owner deletes it, which permanently removes every entry and type on it, for every caregiver at once.
- Push tokens: until you sign out, turn notifications off, or Apple or Google tell us the app has been uninstalled.
- Email you send us: while your question is open, and afterwards only for as long as the thread is still good for something — a bug report until the bug is fixed, say. What no longer has a reason to be there gets deleted.
- Deletion feedback: up to 24 months, unattached to any account.
- Backups: our database provider keeps encrypted backups on a rolling basis, so a copy of deleted data can persist there for up to 30 days before it is overwritten.
Deleting your account
In the app: Settings → Preferences → Delete account. It is permanent, it runs immediately, and it removes your sign-in identity, your profile, your caregiver memberships, your notification preferences, and your push tokens. Entries you logged remain on the baby record without your name on them, so the other caregivers keep the history they rely on.
If you own a baby record, deletion asks you to deal with it first — open Baby details and either hand ownership to another caregiver or delete the record. This is deliberate: deleting a record erases everyone’s history, and it should never happen as a side effect of closing your own account.
If you have already removed the app, email hello@beelucy.com from the address you signed in with and we will delete the account for you.
Your rights
Under the GDPR you may ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, and to receive it in a portable form. Where we rely on consent you may withdraw it at any time. Exercising any of these costs nothing and we will answer within one month.
Much of it you can do yourself: Preferences edits your profile, Baby details edits the record, any entry can be changed or deleted, and Delete account does what it says. For anything else, email hello@beelucy.com. If you think we have handled your data badly, please tell us first — and you have the right to complain to the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, L. Sapiegos g. 17, Vilnius, ada.lt) regardless of what we say.
Security
Everything travels over encrypted connections. The database enforces row-level security, so the credentials in your copy of the app can only ever reach records you are a member of — the rule is applied by the database itself rather than by the app asking nicely. The app carries no administrative key; account deletion runs server-side for exactly that reason.
No service can promise perfect security, and we will not pretend otherwise. If a breach ever puts your rights at risk, we will tell the supervisory authority within 72 hours and tell you without undue delay.
Changes to this policy
If we change it, we update the date at the top. If a change materially affects you — new data, a new recipient, a new purpose — we will tell you in the app before it takes effect, and ask again for consent where consent is what it rests on.