Lalu

Wersja polska

Draft — this document is not in force until it is published.

Privacy Policy

Version 1 · last updated October 4, 2026

Effective from TODO (YYYY-MM-DD).

Lalu is a shared care diary for a baby: feeds, sleep, diapers, pumping, medicines, temperatures and your own events, with photos and voice notes. What you record about your child is health data — the most sensitive kind of personal data. This policy says plainly what we collect, why, who sees it and how to take it with you or delete it.

In short: four promises

  1. We do not sell data about your child or share it with anyone outside the family you build in the app — except the copies for the family's parents described in sections 4, 5 and 8.
  2. Data about your child never reaches advertising networks — not even indirectly, as a signal for targeting. There are no ads in the web app.
  3. You can take your data with you — the CSV export is always free, also when Premium has ended.
  4. You can delete it for good — with one button in the app, without writing e-mails.

1. Who we are and how to reach us

The controller of your personal data is TODO - the owner's full name and the business name of the sole proprietorship (D-35), TODO - the registered business address from CEIDG, TODO (NIP, REGON) ("we").

We have not appointed a data protection officer. Write to privacy@babylalu.com about anything in this policy — a person reads every message.

If you live in the United Kingdom, see section 14. If you live in the United States, see section 15 and our Consumer Health Data Privacy Policy.

2. Who this policy is about

Lalu is meant for parents and other adult caregivers. It is not designed for children to use.

3. What we collect

You do not have to give us anything. Without an account the diary works and stays on your device. An account needs your e-mail address and a name. Your child's data needs your consent (section 4).

You give us

What Details
Your account name, e-mail address, password (we keep only an irreversible Argon2id hash of it), language, time zone, units; when you last used the app; whether you have used the free Premium trial (each person can use it once)
Sign-in with Google or Apple (if you choose it) from Google or Apple we receive only an account identifier, your e-mail address and your name. With Apple we also keep, encrypted, a key Apple gives us — only to cut the link with Apple when you delete your account
The family its name, the people in it, their roles, the date they joined and, if set, the last day of a caregiver's access
Your child name, date (and time) of birth, optionally the due date, sex, birth weight and a profile photo
Your consent when it was given, by whom and which version of the text was shown
The diary — health data feeds (breast, bottle, solids, reactions), sleep, diapers (colour, consistency), pumping, medicines given and medicine schedules (name, dose, reason), temperatures, your own events, notes, photos and voice notes added to entries
Who did what the author and time of every entry and change, and the history of changes with the values before and after

Nothing in the app asks for your address, phone number, national ID number or contacts. Photos lose their hidden location data (EXIF, including GPS) on your phone, before they are even saved.

The app records automatically

What Why
Your devices: a name you can recognise, the platform, when each was last used so you can see where you are signed in and sign a device out
A notification address for this device (if you allow notifications) to deliver notifications
IP address, time, request and browser in our server's access log; failed sign-ins and sign-outs in a separate security log to protect accounts and find attacks
Error reports (section 7) to fix bugs — never the content of your entries

We do not use analytics, advertising or tracking tools, and we do not track you across other websites or apps.

Purpose Data Legal basis (GDPR)
Your account, the app, keeping the diary in sync between devices and caregivers, e-mails about your account account, family, devices performing our contract with you — art. 6(1)(b)
Keeping the diary about your child the child's profile and all diary entries, photos and voice notes your explicit consent as the child's parent or legal guardian — art. 9(2)(a) and art. 6(1)(a)
Keeping data about pumping pumping entries and their photos and notes the explicit consent of the person who pumps, given by her, for one family — art. 9(2)(a) and art. 6(1)(a)
Copies of a child's diary for the family's other parents after a consent withdrawal, and for a parent removed by the owner (sections 4 and 5) the child's diary as CSV files, without photos, voice notes or other people's pumping under legal review — the basis will be named here before publication
People seen or heard by chance in a photo or voice note their image or voice our legitimate interest in keeping the note the family made — art. 6(1)(f)
Payments for Premium see section 7 the contract — art. 6(1)(b); tax and accounting records — art. 6(1)(c)
Security: limiting attempts, the security log, telling every family member when someone joins, is removed or loses access IP address, sign-in events, family membership our legitimate interest in protecting accounts and your child's data — art. 6(1)(f)
Fixing errors error reports without health data our legitimate interest in a working app — art. 6(1)(f)
E-mails to an inactive account and its deletion (section 8) e-mail address, last use our legitimate interest in not keeping data longer than needed — art. 6(1)(f)
One free trial per person the record that you used the trial our legitimate interest in preventing abuse of the trial — art. 6(1)(f)
Answering your requests about your data and keeping a record of them your request and our answer legal obligation — art. 6(1)(c)

Consent to your child's data. Before a child can be added, the app asks for two separate things: your consent to processing your child's health data to keep the diary — the child's profile and everything you record about the child — and your statement that you have parental responsibility or are an authorised caregiver. The consent is not hidden in the Terms. Without it the child cannot be added. If we change the text of the consent, the app asks again for each child — we never assume that you agreed to a new text.

Withdrawing consent is possible at any time in More → Children. It deletes the child's profile and the whole diary for every caregiver, with no way to restore it: the child disappears from the app at once and from our servers within 24 hours. The only thing kept is a copy: before you withdraw, the app offers you a CSV copy, and the family's other parents get a link to one by e-mail; these copies are deleted after 30 days. Withdrawal does not make earlier processing unlawful.

Lactation consent is asked in the breast pump panel, before the first entry, of the person who pumps — nobody can give it for her. Without it nobody can log her pumping, not even another caregiver. She can withdraw it in More → Settings → Data; her pumping entries then disappear from every device at once.

We do not make decisions about you by automated means and do not profile you. Statistics and reminders in the app are arithmetic on what you typed. We do not use your data to train artificial intelligence models, including large language models.

5. The family: who sees what

The diary belongs to the family, not to one person.

6. Where your data is kept

7. Who receives data

We share data only with the people you invite to your family (section 5) and with the service providers below. Except where the table says otherwise, they process it on our behalf under data processing agreements and only for the purposes in this policy. We do not sell data and do not give it to data brokers or advertisers.

Recipient What they get Where, and the safeguard for transfers outside the EEA
Server and database hosting all account and diary data EU
Object storage (the provider is being selected) export files, photos and voice notes EU
Encrypted backup storage encrypted copies, without the key to read them EU, a location other than the server
Transactional e-mail your e-mail address, name and the content of our e-mails (links, never diary entries) EU
Sentry (error reports) what failed, the screen or address in the app where it happened, the browser or system version, a pseudonymous identifier of the family and of the change that failed; no health data, no content of entries and no IP address — your browser sends error reports to our server, which forwards only an allowed list of fields. Kept for the shortest period Sentry offers, at most 90 days stored in Sentry's EU data region (Germany); Sentry's staff in the USA may access it for support, under the EU–US Data Privacy Framework or standard contractual clauses
Stripe (payments, only if a family buys Premium) the e-mail address of the person who buys — not always the family's owner — their language and the family's identifier; nothing about children or the diary. Card details, and the billing address where tax requires it, are entered on Stripe's page and kept by Stripe; we never see the card. Stripe is also an independent controller for its own legal duties, such as fraud prevention EU and USA, under the EU–US Data Privacy Framework or standard contractual clauses
Push services of your browser or phone (Google, Apple, Mozilla, Microsoft) the notification address of your device and an encrypted message they cannot read, holding only its type and one identifier — never a child's name, a medicine or a dose may be outside the EEA; the safeguard is under legal review

Have I Been Pwned. When you choose a password, we check the first 5 characters of an irreversible fingerprint of it against a public list of leaked passwords. This is not personal data — it cannot be traced back to you or your password — and your e-mail address never leaves our server.

Google and Apple are not our service providers when you sign in with them. You choose them yourself, they act as separate controllers under their own privacy policies, and we send them nothing about your child.

Transfers outside the European Economic Area. Diary data stays in the EU. The table names the safeguard for each recipient that may process data outside the EEA. Write to us for a copy.

We may disclose data when the law requires it, for example to a court or an authority, and only to the extent required.

8. How long we keep it

Data How long
Your account as long as you have it; after deletion it is erased at once (section 9)
The diary as long as the family keeps it
An entry you delete hidden at once — you can undo right after deleting; erased for good with its history after 90 days
A child you delete 7 days to restore it, then erased with all entries, photos and voice notes
A child whose consent was withdrawn hidden at once, erased from our servers within 24 hours, without the 7 days
Pumping entries after the lactation consent is withdrawn erased at once
Technical records of syncing 30 days; records of conflicting edits up to 90 days
CSV export the download link works 24 hours; the file is then deleted
Copies e-mailed when an account is deleted, a parent is removed or a consent is withdrawn 30 days
A signed-out device in your device list deleted 30 days after its sign-in expires
Security log (sign-ins, sign-outs, IP addresses) 365 days
Access log of our front server (IP address, time, request, browser) 14 days
Logs of the services running the app limited in size (3 files of 10 MB per service) and overwritten
Background tasks that failed 7 days
Server monitoring (performance and background tasks) 7 days
Payment events received from Stripe 90 days
Error reports the shortest period Sentry offers, at most 90 days
Your requests about your data and our answers 3 years
Payment and invoice records as long as tax and accounting law requires — in Poland generally 5 years after the end of the year of payment, and 10 years for records of sales taxed through the EU VAT one-stop shop (OSS)
Encrypted backups deleted data leaves all backups within 60 days at most (30 days of rotation and up to 30 days of the storage provider's version protection)
An inactive account see below

Inactive accounts. An account is active when someone signs in to it or the app on one of its devices renews its session — this happens on its own whenever you use the app online. After 36 months without any activity we send an e-mail with the date of deletion — at least 30 days later, normally when 48 months have passed — and a reminder 7 days before it. Signing in cancels the deletion. On that date the account is deleted the same way as with "Delete account" (section 9), without a CSV copy — the e-mails tell you how to take one before. Two exceptions: an account that started a subscription still in force is not deleted; and if you own a family that others still use and no other parent can take it over, your account stays its owner until another parent joins or you sign in. We do this because a child's health records should not be kept forever "just in case".

Copies on your devices stay until you sign out, leave the family or remove the app. A device that never connects to the internet again keeps its copy — we cannot erase it remotely.

9. Your rights and how to use them

Most rights work directly in the app, at once:

Right How
Access and a copy of your data (art. 15, 20) More → Settings → Data → CSV export — entries in open CSV files, free, also after Premium ends. The CSV files list photos and voice notes but do not contain them: the diary backup (More → Settings → Data → Diary backup) holds those kept on your device, and we send the rest on request to privacy@babylalu.com
Correction (art. 16) edit any entry, your child's profile or your account
Erasure (art. 17) delete an entry or a child; More → Account → Delete account
Withdrawing consent (art. 7(3)) More → Children → the child → Withdraw consent; the lactation consent in More → Settings → Data
Restriction (art. 18) and objection (art. 21) write to privacy@babylalu.com
Signing out other devices More → Account → Devices

Deleting your account works in two ways, because a child's data belongs to the family:

You can also write to privacy@babylalu.com. We answer within one month; for complex requests we may extend this by two more months and will tell you why. We may ask you to confirm a request from the e-mail address of your account. Using your rights is free.

Complaints. You may complain to a supervisory authority — in Poland the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych, ul. Stawki 2, 00-193 Warszawa, uodo.gov.pl), or the authority of the EU country where you live or work. We would be glad to hear from you first.

Data about your child when they grow up. A child whose data a parent recorded can ask us to delete it, also when they are an adult — write to privacy@babylalu.com.

10. Data stored in your browser — no cookies for tracking

Lalu does not use cookies for advertising or analytics. To work, the app stores in your browser or phone:

All of this is strictly necessary to provide the app you asked for, so we do not ask for separate consent. Signing out deletes the diary, the cached data and the session key from the device.

Stripe's payment page and Google's or Apple's sign-in pages are their sites and use their own cookies under their own policies.

11. Notifications

What travels through the push service is only the type of the notification and one identifier, encrypted so the service cannot read it. The text is put together on your device from the diary already stored there — for example "Medication time" with the name of the medicine — so a notification your device shows can name a medicine from your diary and can appear on the lock screen. Your phone's or browser's settings decide whether notification content shows there.

In the app you choose which notifications each family sends you and whether this device shows them at all (More → Settings → Notifications). The e-mail telling you that someone joined, was removed from or lost access to your family always arrives, because it protects your child's data.

12. How we protect your data

No system is perfect. If a breach puts your rights at risk, we will tell the supervisory authority within 72 hours and tell you directly, in plain language, when the risk to you is high — and with data about a child we assume it is.

13. Not a medical device

Lalu records what you type and does simple arithmetic on it — totals, times, intervals. It does not diagnose, does not assess your child's condition and does not calculate doses. Reference information in the app is general and the same for everyone. If you are worried about your child's health, contact a doctor; in an emergency, call your local emergency number.

14. If you live in the United Kingdom

The UK GDPR and the Data Protection Act 2018 apply to you. Everything above applies to you in the same way, with these differences:

15. If you live in the United States

16. Changes to this policy

We will update this policy when the app or the law changes, and show the date above. We tell you about important changes in the app or by e-mail before they take effect. If a change concerns what you consented to, we ask for your consent again — we never treat continued use as agreement. If ads ever come to the mobile apps, they will get nothing about your child, and we will update this policy before they appear. Earlier versions are available on request.

See also our Terms of Service. Polityka prywatności po polsku.