Privacy
Effective 3 August 2026
The short version
Your family's data lives in your family's own private area of our database, locked to your family alone. It is never sold, never shared, never used for advertising, and never analysed for anything beyond showing you your own baby's patterns. There are no ads, no trackers and no analytics. When you ask us to delete it, we delete all of it.
What we collect
Only what your family logs: your baby's profile (name, date of birth, and optionally sex and gestation at birth for the growth charts), care entries (feeds, sleep, nappies, expressing, growth measurements, health notes, medicines, vaccinations, appointments, milestones, reminders, and any notes you add), the photos you attach to a milestone where your logbook has photos turned on, and the first names caregivers pick for "who logged this".
If you turn reminders on, we also store the technical subscription or device push token your phone needs to receive them. It is registered only when you switch reminders on, and removed when you switch them off or delete your logbook. It is the only device identifier we hold.
If you connect the optional integrations in Settings, we also store what they need to run: your iCloud shared-album link, and for calendar sync the CalDAV address and the app-specific password you create for it. They live only in your family's own private area and are wiped when you delete your logbook. If you send us a message from the in-app support card, that message (and the name you attach to it) is forwarded to us over Telegram; it is not stored in the app.
If you turn on the weather line, we store the town you choose: its name and a rough position, rounded to about a kilometre. Only that position is sent to our weather service to fetch the forecast, and only the town name you type is sent when you search for one. Nothing about you, your family or your baby ever goes with either, and your device's own location is never read.
No accounts, and we never see payment details. When you sign up without an invite code we ask for your email address, used only to send you a short verification code (or, if a person reviews your request instead, your logbook's details); it is not stored in the app itself, and you can ask us to erase it at any time at karo@appeningnow.com. If you subscribe to Little Logbook Plus, the purchase is made with Apple through your Apple account: Apple handles the payment and never shares your card details with us. Inside the app we don't know who you are, but your family's records are stored together as your family's records, so we treat all of it as personal data and protect it accordingly.
LittleAi, and what it is sent
LittleAi is the one part of Little Logbook that asks an outside service for help. Nothing is sent unless you use it: LittleAi only when you open it and ask a question, and the optional quick-add box only when you type a sentence into it. In the iPhone app, LittleAi also asks your permission before its first question, per device, and you can withdraw that at any time in Settings under LittleAi; nothing is sent from that phone once you do. The web app does not yet show that permission screen, so there the control is simply whether you use LittleAi at all.
When you ask it something, we send your question and the last few messages of that conversation, along with your baby's first name, date of birth, the words you use for them, and how many weeks they were born at if you have recorded it. If answering needs your real records, the relevant ones go too: today's feeds, nappies and expressing, your recent feeds and nappy changes, growth measurements, and whether today's medicine has been given.
Your photos are never sent. Neither are your notes, your health entries, your milestones, or anything belonging to another family. Your conversation is not kept once you close it. A general answer with nothing personal in it may be saved in your own logbook so the same question returns instantly next time, and those are deleted along with everything else if you delete your family's data.
Where it lives
Your family's records live in your family's own private area of our database, owned by a database login that belongs to your family and to nobody else. Every request the app makes switches into that login first, and while it is switched in it can reach nothing outside your family's area, so a query that strayed towards another family's records would be refused by the database itself rather than answered. That is what keeps families apart: not a rule the app remembers to follow, but a permission it does not hold.
The database lives in the EU (Amsterdam); the app itself is served from London, UK. Both are reachable only over HTTPS, behind your family's PIN. Until August 2026 each family had a whole database of their own. Families now share one EU database, divided into the separate, individually locked areas described above.
If your logbook has milestone photos enabled, the photos live under your family's own keys in Cloudflare's object storage, and the app hands them out only to your logbook, as links that expire within the hour. Unlike the database, we can't yet promise that photos stay in the EU: we are moving photo storage to an EU-only bucket, and this page will say so once that is done.
Any encrypted backups we keep of the database expire automatically, with the oldest copies gone within six months. Backups are our safety net against mistakes, not a guarantee of recovery, so if you want a copy you can rely on, use the export in Settings.
Your data, your call
You can download everything, or delete your whole logbook, yourself from Settings at any time. Deletion removes your live data (including any photos) immediately, and any backups as they expire. No email, no form, no waiting on us.
Under UK GDPR you also have the right to access, correct, and object to how your data is used, and you can withdraw your consent at any time by deleting your data. Questions or requests: karo@appeningnow.com.
What we never do
No advertising, no analytics, no tracking, no selling or sharing of your data, and no profiling beyond showing your own family its own baby's patterns. The app contains no advertising or analytics software of any kind, and nothing leaves your logbook except the flows described on this page (reminders, LittleAi if you have agreed to it, the optional integrations and quick-add box, support messages, and the operational notifications listed below).
The services that help us run it
A small set of processors host or handle data strictly on our instructions:
- Vercel and Railway: Vercel serves the app from London, UK; Railway hosts the database holding your family's records in the EU (Amsterdam).
- Cloudflare: object storage for milestone photos, where photos are enabled (see "Where it lives" above about photo residency).
- Expo and Apple: delivering reminder notifications, only if you turn reminders on. Apple's notification network is global, so the small technical message behind each notification passes through servers in the US on its way to your phone.
- Anthropic: the company that makes the model behind LittleAi, and the only recipient of what LittleAi is sent (see "LittleAi, and what it is sent" above). The optional quick-add box goes the same way: type "fed 60ml at 3am" in plain words and that one sentence is sent to be understood, after which we keep only the structured entry it produces, never the sentence itself. Anthropic processes both on our instructions under its API terms, retaining them briefly for abuse prevention, and does not use them to train its models.
- Brevo: sends the short verification-code email when you sign up without an invite code. It is given your email address and the code, nothing else, and only at that moment; Brevo is an EU (French) company.
- RevenueCat: keeps track of whether a family's Little Logbook Plus subscription is active, so the app knows what to unlock. It receives an anonymous identifier and Apple's receipt information, never your name, email, payment details or anything your family has logged. RevenueCat is a US company.
- Open-Meteo: the forecast and the town search behind the optional weather line on Today, and only where a family has turned it on. It is sent nothing but a rough position (about a kilometre) or the town name you type into the search box. There is no account and no key, so there is nothing for it to attach a request to.
- Telegram: how our own operational notifications reach us. When you sign up, your signup details are sent to us over Telegram so we know to expect you, and if your logbook has to be set up by hand, your family's PIN reaches us the same way so that we can send it to you. When you use the in-app support card, your message and the name you attach are relayed to us the same way; and when a logbook is deleted, we get a short notice naming it. Telegram is not an EU company, so these messages transit its infrastructure.
- GitHub: until August 2026 the automation that built each new family's app ran on GitHub, so signup details (family name, baby's name and date of birth, caregiver first names, contact detail and PIN) passed through GitHub's systems (US) while the logbook was being created. New logbooks are created directly by our own app in London and no longer touch GitHub.
Who's responsible, and the legal bit
The data controller is Appening Now, contactable at karo@appeningnow.com. Because a baby's health information is sensitive ("special category") data, we process it only with your explicit consent, given when you sign up, and only to run the logbook for you. Data is held until you delete it.
One piece of small print: to slow down anyone trying to guess a PIN, we keep a count of failed unlock attempts against the network address they came from. It is used only for that, and the count for an address is cleared when it unlocks successfully.
If you're ever unhappy with how your data is handled, you can complain to the UK regulator, the ICO, at ico.org.uk.