← Back to mamalytics.app

Privacy Policy

Effective date: 20 July 2026 Version: 1.4.0


1. Who we are and how to reach us

This Privacy Policy describes how Mamalytics (“Mamalytics”, “we”, “us”, “our”) collects, uses, shares and protects information about you when you use the Mamalytics mobile app and the related website at mamalytics.app (together, the “Service”).

  • Data controller (entity): MAMALYTICS LTD, a private company limited by shares incorporated in England & Wales on 24 June 2026. The controller is established in the United Kingdom for UK-GDPR purposes.
  • Registered office / postal address: 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ, United Kingdom.
  • Company number: 17300475.
  • ICO registration: Registered with the UK Information Commissioner’s Office for the data-protection fee (Tier 1). Registration reference ZC186246 (registered 30 June 2026; renewal due 29 June 2027).
  • Privacy contact email: info@mamalytics.app.
  • Data Protection Officer: We have not appointed a Data Protection Officer. For any data-protection question, use the privacy contact email above.
  • EU representative: We have not appointed an EU representative. The Service is operated from the United Kingdom and is not marketed to users in the European Economic Area during the beta.

Where the Service operates. Mamalytics is currently offered as a beta. It is operated from the United Kingdom, and United Kingdom data-protection law — the UK General Data Protection Regulation (“UK-GDPR”) and the Data Protection Act 2018 — governs how we handle your personal data. The beta is primarily intended for users in the United Kingdom. We do not restrict access by country, but the Service is not tailored to, and may not be compliant with, the local data-protection law of every country from which it can be reached; if you use the Service from outside the United Kingdom you do so on that basis.

Whose data this policy covers. The Service began as a pregnancy companion, and most of the data we hold is about you, the pregnant or postpartum user. As your journey progresses, the Service also holds information about your baby — a second data subject whose details (birth measurements, growth readings, developmental milestones and newborn logs) you enter in your capacity as their parent (see §8). If you choose to invite a co-parent to a child’s information, that adult becomes a third person whose access we record. Where this policy refers to “your data”, it includes the baby information you enter; the safeguards for special-category health data apply to your baby’s health information as well as your own.

If you have questions about this policy, or wish to exercise any of the rights described below, email us at info@mamalytics.app. We aim to respond within 30 days (sooner where required by law).

2. Data we collect

We collect only what we need to run the Service. Categories below are grouped by source. Pregnancy is special-category health data under UK-GDPR Art. 9 — that classification drives most of the safeguards below.

Account data. When you sign up we receive your email address, an Auth0 user identifier (the JWT sub claim), and (optionally) a display name and profile picture from your chosen identity. We do not store your password — Auth0 handles authentication on our behalf.

Profile data — entered by you in onboarding and editable in Settings.

  • Optional: first name, last name, date of birth, country (ISO 3166-1 alpha-2), timezone.
  • Pregnancy details: due date, last menstrual period, conception date, current pregnancy week (derived), pregnancy type (singleton / twins / multiples), whether this is your first pregnancy.
  • Pre-pregnancy weight and height.
  • Pre-existing conditions, allergies, current medications.
  • Your preference for whether your health background is included in AI chat context (the in-app “Share health with Mamalytics” toggle).
  • Notification preferences: weekly-guide push and daily-summary push. (No other notification channels exist today.)
  • Analytics opt-in preference.

Health metrics (yours and your baby’s). Numeric measurements logged over time. Before birth these are your own readings — for example blood pressure, weight, blood glucose, fetal heart rate — plus any custom metric the app supports. After birth you can also log postpartum recovery measurements about yourself (for example bleeding / lochia, healing and pain, mood, and breastfeeding) and newborn measurements about your baby (for example weight, length, head circumference, temperature, feeds, wet and dirty nappies, and sleep). Each entry includes a value, optional secondary value, unit, optional notes, timestamp and source (manual entry, AI-extracted from a chat message, or image-extracted from a photo you uploaded). Measurements about your baby are linked to the specific child they describe.

Daily logs. Mood tags (multi-select), symptom tags (multi-select) and a free-text note you enter for a given day. We also aggregate these tags into read-only mood- and symptom-frequency views and gentle, non-diagnostic pattern observations; this is a projection of the data you already entered and creates no new category of data.

Journey and birth information. Which phase of your journey you are in (pregnancy, postpartum, or ended), your baby’s date of birth, and — if you use the compassionate “end journey” path following a loss or a decision to stop — the date you ended the journey. We do not store a reason for ending the journey. We also record when you complete onboarding and, much later, if and when you acknowledge the optional “journey complete” milestone.

Your baby’s information (a second data subject). When you record a birth, we store your baby’s details — optionally a name, sex, birth weight, birth length, head circumference (with units) and gestational age at birth. If you track more than one baby, we store one record per child. From these readings we derive WHO/CDC growth percentiles (with corrected age for babies born preterm); the reference data is fixed public data held in the app, not information about you. This is health information about your child, which you enter as their parent (see §8).

Developmental milestones. If you track your baby’s development, we store which milestones you mark as achieved, the date you record and any note you add. Milestones are shown against public, non-diagnostic reference content (CDC “Learn the Signs. Act Early.”).

Shared feed and sleep timers. A running feed or sleep timer for your baby is kept on our servers (not just on your device) so that a co-parent you have invited sees the same live timer. It records start / stop times, the feeding method and, for feeds, which side. It is deleted when the timer is stopped or the child is removed.

Co-parent sharing. If you invite a second parent to a child’s information, we store the sharing grant — which adult has access to which child, in which role, and when access was granted, accepted, revoked or ended — and, optionally, the inviter’s stated relationship to the baby. The invite link contains a signed, single-use, time-limited token; we store only a one-way hash of that token, never the token itself. When a sharing relationship ends (you revoke a co-parent, the co-parent leaves, or you cancel an unclaimed invite), we keep a record of who had access and when as a security and audit trail rather than deleting it immediately (see §6). A co-parent only ever sees your baby’s information — never your own pregnancy or health data, chat history or reflections (see §9).

Kick sessions. Start and end times, total count, and the timestamps of individual kicks recorded during fetal-movement counting sessions. An in-progress session is also cached on your device for up to 12 hours.

Contraction-timer sessions. Tap events recorded during a contraction-timing session are held on your device only; we do not synchronise this data to our servers in the current build.

Chat messages. The text of messages you send to, and receive from, the Mamalytics AI companion, plus the message type (text / voice / image), the sender (you or AI), and metadata such as the AI model used. We retain conversation history so the AI can refer back to it during future conversations.

Voice recordings. When you record a voice message, the audio file is sent to our servers for transcription and is stored in an encrypted object-storage bucket so that you can replay the message in chat. The transcript is also saved as the chat message content.

Photos uploaded for metric extraction. When you take or pick a photo for our image-extraction feature, the image is forwarded to Anthropic’s Claude vision model for analysis. The image bytes themselves are not persisted to disk or to cloud storage: they are held in memory only for the duration of the request, and only the numbers extracted from them (and the resulting Message row noting that an image was sent) are saved.

Push-notification tokens. A device-issued Expo push token (which Expo in turn relays to Apple’s APNs or Google’s FCM) so we can deliver the notifications you have opted in to.

Subscription state. If you purchase a Mamalytics Premium subscription, RevenueCat sends us your subscription identifier, tier and entitlement state. Payment details (card number, billing address, App Store / Play Store account) are handled by Apple, Google and RevenueCat — we never see them.

Device and app data. App version, platform (iOS or Android), operating-system version, locale, and the device-bound identifiers used by Apple, Google and Expo to deliver app updates and push notifications. We do not use Apple’s App Tracking Transparency (advertising) identifier; we do not display the ATT prompt.

Product telemetry (Mixpanel). Where you have opted in (see §5), we send anonymised usage events to Mixpanel. We maintain the full event allowlist internally as the single source of truth. No event ever includes your email, your Auth0 identifier, raw health values, your chat-message text or any other directly identifying field. You are identified to Mixpanel only by the irreversible hashed identifier described in §5. Analytics is off by default for everyone; you can switch it on in Settings → Privacy → Share anonymous usage data.

Audit log. When we perform privileged operations on your account — for example through the internal admin dashboard or when you delete your account — we record the action, the resource affected, the actor’s IP address and user agent, and a timestamp. Audit-log entries do not contain message content. Audit-log entries persist after account deletion (see §6).

AI-usage log. For each AI call we make on your behalf (chat reply, image extraction, summary generation, reflection generation), we record the AI model, the token counts in and out, latency, the purpose of the call, and your account identifier. We use this only to monitor cost, performance and abuse. We do not log message content in this log.

Feedback. If you submit feedback through Settings → Send Feedback, we store the feedback text, your app version and platform. Feedback may contain personal or health content because it is free-text; it is visible to authorised members of the Mamalytics team for triage.

Server logs. Our API records technical request data (IP address, request path, response code, timing) for operational and security purposes. We do not log the body of your chat messages.

Marketing-site analytics (Cloudflare Web Analytics). On mamalytics.app we use Cloudflare’s cookieless analytics. No cookies are set and no cross-site identifier is created.

Marketing-list email (Resend — landing site only). If you opt in to launch updates on mamalytics.app, we store your email address for double-opt-in confirmation and subsequent newsletter delivery. This is separate from your in-app account; deleting your in-app account does not unsubscribe you from the newsletter and vice versa.

We do not collect: precise geolocation, contacts, calendar entries, microphone or camera content outside of audio you record or photos you upload, advertising identifiers, social-graph information, biometric identifiers, or any data from third-party data brokers.

We use the data described in §2 for the purposes set out below. The lawful basis under UK-GDPR is given in square brackets.

  • Operate the AI companion. Your chat messages, profile information and (where you have opted in) selected health background are sent to Anthropic’s Claude API so Mamalytics can respond. [Art. 6(1)(b) performance of our agreement with you, plus Art. 9(2)(a) explicit consent for the special-category health content you choose to send.]
  • Transcribe voice messages. Audio you record is sent to OpenAI’s Whisper API for transcription, then back into the chat pipeline above. [Art. 6(1)(b); Art. 9(2)(a).]
  • Extract metrics from photos. Photos you upload are sent to Anthropic’s Claude vision model so the structured numbers can be saved to your health log. The image bytes themselves are not retained (§2). [Art. 6(1)(b); Art. 9(2)(a).]
  • Extract metrics from chat. When you mention a measurable value in chat (for example “BP 130/85”), we save a structured HealthMetric row so you can see it on charts and trends. This extraction happens automatically when a measurable value is detected; it does not require a separate toggle. You can delete any extracted metric individually from the health-log screen. [Art. 6(1)(b); Art. 9(2)(a).]
  • Classify new metric types. When you log a metric we have not seen before, we use Anthropic’s Claude Haiku model to classify it (for example mapping “preg test line” to a category) so it appears correctly in charts. [Art. 6(1)(f) legitimate interest in offering useful health-tracking features.]
  • Generate daily summaries and reflections. We re-process your logged metrics, daily logs and chat history into a nightly daily summary and into per-cadence reflections — short AI-written narratives covering a week, a month, a trimester, an end-of-pregnancy recap, and (after birth) a tapering weekly → monthly → quarterly postpartum cadence. Daily summaries and the end-of-pregnancy recap are available to all users; the other reflections are viewable on Premium. [Art. 6(1)(b); Art. 9(2)(a).]
  • Support your journey through birth and into postpartum. We use your journey phase, birth date and baby’s age to switch the app from a pregnancy experience to a postpartum one, to generate the end-of-pregnancy recap and postpartum reflections, and to show age-appropriate content. Where you use the “end journey” path, we suppress celebratory content; we do not store a reason. [Art. 6(1)(b); Art. 9(2)(a).]
  • Track your baby’s health and development. We store and display the newborn measurements, developmental milestones and WHO/CDC growth percentiles you record for your child. Growth percentiles are computed on our servers from fixed public reference data; milestones use public, non-diagnostic reference content. These features are free. [Art. 6(1)(b) performance of our agreement with you; for the special-category health data about your child, Art. 9(2)(a) explicit consent given by you as the holder of parental responsibility for that child — see §8.]
  • Enable co-parent sharing. Where you invite a second parent, we create and manage an access grant so they can view and log your baby’s information (never your own). [Art. 6(1)(b) performance of our agreement with you and the invited co-parent; Art. 9(2)(a) explicit consent, given by you as the holder of parental responsibility, to share your child’s health information with the co-parent you choose.]
  • Show mood and symptom patterns. We aggregate the mood and symptom tags you record in your diary into read-only frequency views and gentle, non-diagnostic observations. This is your own data and the feature is free. [Art. 6(1)(b).]
  • Run safety checks. Before any AI reply is generated, your message passes through a four-layer safety pipeline (prompt-injection detection, psychiatric-emergency detection, harmful-content block, off-topic deflection). This pipeline operates server-side and is not user-toggleable. Questions that look like requests for dosing, diagnosis or lab interpretation are no longer blocked outright; they reach the AI, which is instructed to respond with appropriate care framing and to point you back to your own clinician. [Art. 6(1)(f) legitimate interest in protecting users from foreseeable AI-safety harms.]
  • Send notifications. We deliver the weekly-guide and daily-summary push notifications you have opted in to. Delivery flows via Expo Push to Apple’s APNs or Google’s FCM. [Art. 6(1)(a) consent for push delivery; consent recorded by your OS-level notification permission grant + per-channel toggles.]
  • Authenticate you. Auth0 verifies your identity each time you sign in. [Art. 6(1)(b).]
  • Process subscriptions. RevenueCat brokers our integration with Apple In-App Purchase and Google Play Billing; we receive your subscription tier so the right features are unlocked. [Art. 6(1)(b).]
  • Operate, secure and debug the Service. Server logs, the audit log, the AI-usage log and rate-limiting protect against abuse and let us diagnose problems. [Art. 6(1)(f) legitimate interest in keeping the Service available, safe and accurate.]
  • Enforce a minimum supported app version. Our boot-time version-status check tells the app whether the running build is supported, recommended for update, or blocked. [Art. 6(1)(f) legitimate interest in shipping security fixes across the install base.]
  • Improve the product. Where you have opted in, we analyse anonymised Mixpanel telemetry to understand which features are useful and where users get stuck. Analytics is off by default for everyone; you must affirmatively opt in. [Art. 6(1)(a) consent.]
  • Comply with legal obligations and respond to lawful requests from authorities. [Art. 6(1)(c).]

No training of AI models on your data. Neither Mamalytics nor any of our AI processors trains, fine-tunes or otherwise improves models on your content under the contracts in force at the date of this policy. If those contractual commitments change, we will update §4 and §11 of this policy and (if the change is material) ask you to re-consent before continuing to use the Service.

No solely-automated decisions with legal effect. We do not make decisions about you by purely automated means that would produce legal effects or similarly significantly affect you (UK-GDPR Art. 22). AI-generated content (chat replies, summaries, reflections) is informational and is not a clinical decision.

4. Third-party processors

We rely on the following processors to run the Service. Each receives only the data needed for its specific function and is subject to a data-processing agreement (DPA).

ProcessorServiceWhat they receiveRegion of processingPurpose
Anthropic, PBCClaude Sonnet 4.6 + Haiku 4.5 (text + vision)Your chat message text, recent prior chat messages for context, your pregnancy week / trimester / due-date or your baby’s age, your country, recent metric aggregates, and (if you have opted in) your health background. Where the AI looks up your own past readings or messages to answer a question, those results are returned into the same conversation. Image bytes (for the vision feature). Aggregated metrics and summaries (for reflections). Your internal user identifier is not sent.United StatesAI chat replies, vision-based metric extraction, daily summaries, per-cadence reflections, pregnancy recap, metric auto-classification. Anthropic’s commercial terms commit to not training on customer API data.
OpenAI, L.L.C.Whisper transcription (whisper-1)Audio bytes you record (≤ 120 s, ≤ 10 MB) and the audio MIME type. Your internal user identifier is not sent.United StatesSpeech-to-text transcription of voice messages so they can be processed by the chat pipeline. OpenAI’s API terms exclude submitted content from training by default.
Auth0 (Okta, Inc.)Identity (OIDC / PKCE)Your email and password (handled by Auth0; we never see the password), optional display name and profile picture, and authentication metadata; we receive a JWT in return.Processed in the region configured for our Auth0 tenantSign-up, sign-in, JWT issuance, password recovery, optional MFA.
RevenueCat, Inc.Subscription brokerageYour internal user identifier (as app_user_id), product identifier, purchase / expiry timestamps, receipts relayed from Apple or Google.United StatesSubscription state, webhook events, restore-purchases.
Apple Inc.App Store + In-App Purchase + APNsApp-distribution data; payment and Apple ID for in-app purchase; APNs delivery for push (relayed via Expo).United States (Apple)Hosting (App Store), payment, push delivery.
Google LLCGoogle Play + Play Billing + FCMApp-distribution data; payment and Google account for in-app purchase; FCM delivery for push (relayed via Expo).United States (Google)Hosting (Play Store), payment, push delivery.
Expo (Exponent, Inc.)Push notifications + build pipelineExpo push tokens (device identifier); notification title, body and data payloads (e.g. { screen: 'diary', date }).United StatesPush delivery via Apple APNs and Google FCM; mobile build pipeline.
Amazon Web Services, Inc. or Google Cloud (Alphabet Inc.)S3 / GCS object storageAudio file bytes from voice messages, stored at key path voice/{userId}/{messageId}.<ext>.United States (default storage region)Storage of voice-message audio for in-app replay.
Mixpanel, Inc.Product analyticsHashed anonymous identifier (see §5); a fixed allowlist of 24 events with bucketed / enum-only properties (pregnancy_trimester bucket, plan_tier, app_version, platform). Events include co-parent-sharing actions, but with no child, host or partner identifier, and a host’s and partner’s hashed identifiers are never linked. No PII, no raw health values, no chat-message text, no email, no internal user identifier.United StatesEngagement and funnel analysis. Off by default for everyone.
Railway CorporationManaged Postgres + Redis + API hostingAll operational data described in §2 that is stored server-side: User, Message, DailySummary, HealthMetric, KickSession, Feedback, Subscription, AuditLog, AIUsageLog, PushToken, plus rate-limit counters and job-queue payloads in Redis.United StatesApplication database, cache and job queue; API hosting.
Cloudflare, Inc.CDN + Cloudflare Pages + Cloudflare Web AnalyticsMarketing-site traffic to mamalytics.app; cookieless visit metrics.Global edgeHosting and protection of the marketing site; cookieless analytics.
Resend, Inc.Email delivery (landing site only)Email address you provide on mamalytics.app to receive launch updates.United StatesNewsletter double-opt-in confirmation and delivery.
Your device’s share sheet + the messaging channel you chooseCo-parent invite delivery (user-initiated, not a Mamalytics processor)A co-parent invite link containing a signed, single-use, time-limited token (https://mamalytics.app/invite?token=…).Wherever the channel you choose operatesWhen you invite a co-parent, the invite link leaves your device through whatever channel you pick — for example SMS, email or a messenger app. That channel is operated by a third party outside our control. Treat the link like a password: anyone who obtains it before it expires or is used could accept the invitation.

We review processors periodically. If we add or change a processor, we will update this policy and, where the change is material, surface it in-app for re-consent (see §11).

5. Anonymised user identifiers in product analytics

When we send events to Mixpanel, we identify you using an anonymised identifier — never your email, never your Auth0 identifier and never our internal user identifier. The identifier is computed on your device as the first 32 hexadecimal characters of SHA-256(User.id + salt), where the salt is a value bundled into each app build (delivered via the EXPO_PUBLIC_MIXPANEL_HASH_SALT environment variable).

This means:

  • Mixpanel cannot reverse the identifier back to your account.
  • Anyone with access to Mixpanel cannot link your activity to your email or to records in our database.
  • If we ever need to break the mapping (for example after a security incident), rotating the salt in the next app release intentionally severs Mixpanel continuity.

We never put your email, Auth0 identifier, raw health values or message text into a Mixpanel payload. The 24-event allowlist enforces this in code; raw trackMixpanel(...) calls outside the allowlist wrapper are forbidden by code review.

Default state. Analytics is off by default for all users at the time of writing — your account is created with analyticsOptIn = false. You must affirmatively opt in at Settings → Privacy → Share anonymous usage data (or during onboarding step-0) before any Mixpanel event is sent.

6. How long we keep your data

CategoryRetention
Account, profile and notification preferencesUntil you delete your account.
Chat messages (text, image-message rows, voice-transcript rows)Until you delete the message individually, bulk-delete from the chat screen, or delete your account.
Voice audio files (the audio object in object storage)Kept only so you can replay the message in chat; we aim to delete the stored audio within 90 days of upload, and delete it sooner on request.
Health metrics (yours and your baby’s), kick sessions and daily logsUntil you delete the row individually, bulk-delete it, remove the relevant child (for baby measurements), or delete your account.
Your baby’s information (child profile, newborn measurements, developmental milestones, shared feed / sleep timers)Until you remove that child (“Remove from Mamalytics”), delete the individual row, or delete your account. Removing a child permanently erases that child’s data and ends any co-parent’s access to that child.
Co-parent sharing grants and invitesA revoked, left or cancelled sharing grant is soft-deleted: we keep the who / when record of the sharing relationship as a security and audit trail, and hard-delete it when the child or your account is deleted.
Daily summaries and reflectionsUntil you delete your account.
Push tokensUntil logout (where the deregistration call succeeds) or account deletion.
Subscription record (in our database)Until you delete your account. Receipts and entitlement history retained separately by RevenueCat, Apple and Google per their policies.
Mixpanel eventsPer Mixpanel’s data-retention policy and our Mixpanel project settings. Because the identifier is anonymised client-side (§5), Mixpanel events are not linked to your account.
Server logsRetained for a limited period for security and operational purposes, then deleted.
AI-usage logUntil you delete your account (entries are linked by user identifier).
Audit logRetained for a limited period after account deletion for security, fraud-prevention and compliance reasons.
Marketing-list email (Resend, landing site only)Until you unsubscribe via the link in any newsletter email. Independent of your in-app account.

Account deletion. You can delete your account at any time from Settings → Account → Delete account in the mobile app, or by emailing info@mamalytics.app. When you delete your account, our database cascade-deletes the categories above marked “until you delete your account”. The deletion is completed within 30 days. Limitations to be aware of:

  • Your identity record at Auth0 is not currently deleted automatically when you delete your in-app account. If you want your Auth0 identity removed, email info@mamalytics.app and we will arrange it.
  • Audit-log entries persist for the period set above.
  • Voice audio objects depend on the configured S3 / GCS lifecycle to expire; we also delete on demand on request.
  • RevenueCat, Apple and Google retain transaction records per their own retention policies for billing, refunds and tax purposes.

Removing a single child. You can permanently remove one child and all of that child’s data (measurements, milestones, timers and any co-parent access to that child) at any time — from the child’s settings, using “Remove from Mamalytics” — without deleting your account. This is a per-child erasure control. Audit-log entries recording that the removal happened persist for the period set above; your own health data is unaffected.

Start fresh. You can also use “Start fresh” to clear your tracking data while keeping your account.

We retain narrow categories beyond account deletion only where the law requires us to (for example tax or fraud-prevention records). Any such retained record is kept separately from the operational data and is not used for product purposes.

7. Your rights under UK-GDPR

UK-GDPR (and the Data Protection Act 2018) give you the following rights in respect of your personal data:

  • Right of access (Art. 15). Request a copy of the personal data we hold about you.
  • Right to rectification (Art. 16). Ask us to correct inaccurate or incomplete personal data.
  • Right to erasure (“right to be forgotten”) (Art. 17). Ask us to delete your personal data. The in-app Delete account action exercises this right. You can also erase one child’s information on its own — including your baby’s measurements, milestones and any co-parent access — using Remove from Mamalytics in that child’s settings, without closing your account.
  • Right to restriction of processing (Art. 18). Ask us to stop processing your personal data while we resolve a dispute about its accuracy or use.
  • Right to data portability (Art. 20). Receive a machine-readable copy of the personal data you provided to us. Email info@mamalytics.app to request an export.
  • Right to object (Art. 21). Object to processing we have based on legitimate interests.
  • Rights related to automated decision-making (Art. 22). We do not make solely-automated decisions about you that produce legal effects or similarly significant effects (see §3).
  • Right to withdraw consent (Art. 7(3)). Where we rely on your consent (for example for analytics opt-in or for including your health background in AI context), you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, email info@mamalytics.app from the email address associated with your account. We will respond within one month (extendable by up to two further months for complex requests, in which case we will explain the delay within the first month).

Right to complain to the ICO. If you are dissatisfied with how we have handled your personal data, you have the right to lodge a complaint with the Information Commissioner’s Office at https://ico.org.uk/make-a-complaint/. You also have the right to a judicial remedy.

Special-category health data. We process special-category personal data (information about your pregnancy, symptoms, medications, mental-health proxies and so on). We rely on your explicit consent under Art. 9(2)(a) for this processing. You can withdraw that consent by switching off “Share health with Mamalytics” in Settings (which stops future inclusion of your stored health background in AI context) or by deleting your account.

If you use the Service from outside the United Kingdom, additional rights may apply under your home data-protection regime. We handle all users’ personal data to the UK-GDPR standard described in this policy; contact info@mamalytics.app if you would like to discuss rights specific to your jurisdiction.

8. Children and your baby

This section covers two distinct things: the minimum age of you, the account holder, and the processing of your baby’s information.

8.1 Minimum age of the account holder

Pregnancy may occur from puberty onward, and we recognise that some users may be minors in their jurisdiction. You must be at least 18 to use the Service. At sign-up we ask you to confirm you meet the minimum age and, where you supply a date of birth, we check it and do not permit an account to be created for someone below the minimum age.

In the UK, the minimum age for a child to give consent to information-society services without parental authorisation is 13 under UK-GDPR Art. 8(1) as implemented by DPA 2018 s.9. Our 18-year minimum sits well above that.

If you believe we have inadvertently collected information from a user below the relevant age, contact info@mamalytics.app and we will delete it.

8.2 Your baby’s information

When you record a birth and use the postpartum and infant-care features, the Service stores health and developmental information about your baby — birth measurements, growth readings, feeds, sleep, nappies and developmental milestones (see §2). Your baby is a second data subject and this is special-category health data about a child.

You enter this information in your capacity as the child’s parent, exercising parental responsibility on their behalf. Where the information is special-category health data about your child, we rely on your explicit consent under Art. 9(2)(a), given by you as the holder of parental responsibility, both to hold that information and — if you choose to invite one — to share it with a co-parent (see §2 and §9). A co-parent can view and add to your baby’s information but never sees your own pregnancy or health data.

9. Security

We use a layered approach to protect your data:

  • All traffic between the app and our servers is encrypted in transit using TLS 1.2 or higher.
  • Data at rest in our managed Postgres database is encrypted by our managed-database provider.
  • Voice audio objects in S3 / GCS are stored with provider-default encryption at rest.
  • Authentication is delegated to Auth0, which enforces password complexity and, where you have enabled it, multi-factor authentication. We never see or store your password.
  • All authenticated API endpoints validate a JWT issued by Auth0; Socket.io connections validate the same JWT via Auth0’s JWKS.
  • We rate-limit endpoints (per IP and per user) to defend against abuse.
  • We run a four-layer safety pipeline on every chat message before any AI processing happens (prompt-injection detection, psychiatric-emergency detection, harmful-content block, off-topic deflection). The pipeline is regression-tested before each release against an adversarial corpus (47 must-block payloads, zero bypass) plus false-positive controls and dedicated physical- and paediatric-emergency probe sets.
  • Where you invite a co-parent to a child, our access controls scope what they can see to that child’s information only. Your own pregnancy and health data, your chat history and your reflections are structurally excluded from a co-parent’s view.
  • We log privileged actions to an audit log.
  • We never log the body of your chat messages in operational server logs.
  • Secrets-scanning runs on every commit to prevent accidental disclosure of credentials.

Who can read your data internally. Authorised members of the Mamalytics team can access your account-level data — your profile, messages, summaries, reflections, metrics, kick sessions, your baby’s records and feedback submissions — through an internal admin dashboard for support, abuse moderation, and to investigate incidents. Admin actions are recorded in the audit log.

No system is perfectly secure. If you suspect unauthorised access to your account, contact info@mamalytics.app immediately. Where a personal-data breach is likely to result in a risk to your rights and freedoms, we will notify the ICO within 72 hours of becoming aware (UK-GDPR Art. 33) and notify you without undue delay where the risk is high (Art. 34).

10. International transfers

The Mamalytics data controller is established in the United Kingdom. Most of our processors are located in the United States, and your data is transferred to them in the course of providing the Service. The transfer mechanisms we rely on are:

  • From the UK to the US (and to any other country without a UK adequacy regulation): the UK International Data Transfer Agreement (IDTA), or the UK Addendum to the EU Standard Contractual Clauses, together with a Transfer Risk Assessment. Where a US processor self-certifies under the UK Extension to the EU-US Data Privacy Framework, we may rely on that framework as the basis for the transfer instead. We select the appropriate instrument for each processor.

Co-parent invite links are different: they are not sent to a Mamalytics processor at all. When you share an invite, the link travels through whatever messaging channel you choose (SMS, email, a messenger app), which may operate outside the UK and is outside our control. The token in the link is signed, single-use and short-lived, but anyone who obtains the link before it expires or is used could accept the invitation — so share it only with the person you intend to invite.

You can request copies of the relevant transfer instruments by emailing info@mamalytics.app.

11. Changes to this policy

We may update this Privacy Policy from time to time. When we do, we will:

  1. Update the version number and effective date in §12.
  2. Add a row to the revision-history table in §12.
  3. For changes we consider material, present a re-consent prompt the next time you open the app. You will not be able to continue using the Service until you accept the updated policy. If you do not want to accept the new policy, the re-consent prompt offers a Delete my account instead action so you can exercise your erasure right and exit cleanly.

Examples of material changes include adding a new third-party processor that receives health data, expanding the categories of data we collect, broadening how we use existing data, and changes to the lawful bases or transfer mechanisms in §3 and §10. Non-material changes (typo fixes, clarifying rewrites that do not change meaning, contact-detail updates) do not trigger re-consent.

Geographic expansion. The current release is a UK-operated beta. If we begin to actively offer or market the Service in markets outside the United Kingdom — for example in the EEA or the United States — we will publish a revised Privacy Policy with the additional regional disclosures required by the relevant regime (for example UK-GDPR’s EU representative provisions, EU SCCs, CCPA / CPRA disclosures, or the Washington My Health My Data Act standalone consumer-health-data privacy policy). We will treat that step as a material change requiring re-consent.

Last updated: July 20, 2026 · Version 1.4.0