Overview
CradleSync is an iPhone app for adult parents and trusted caregivers. Adults create accounts and shared baby profiles; babies do not create or control accounts. Baby care, health, medicine and development information is treated as sensitive family-linked information.
This policy must always match the current version of the app. Planned features such as HealthKit, subscriptions, widgets and private family photos will be added to this policy only when a released version actually uses them.
Information we use
| Category | Examples | Reason |
|---|---|---|
| Adult account | Name, account identifier, Apple relay email or contact detail, authentication provider | Sign-in, account recovery, caregiver attribution and support |
| Baby profile | Name, date of birth or due date, gender selection, unit preference and wake-window targets | Shared setup, age-appropriate displays and guidance |
| Care and health | Feeds, bottle amounts, sleep, diapers, symptoms, notes, growth and milestones | Care logging, summaries and family collaboration |
| Medicine records | Medicine name, entered dose, instructions, schedule, administrations and contributor | Schedule recording and duplicate-dose guardrails |
| Family access | Roles, preferred interface, invitee name, invitation, claim and revocation records | Authorisation, invitations and abuse prevention |
The camera is used to recognise caregiver invitation QR codes. The previewed design does not require saving a photograph to the camera roll.
Why we use information
- Authenticate adult account holders and keep shared care records attributable.
- Provide logging, timers, summaries, hand-offs and role-appropriate interfaces.
- Synchronise authorised family data across devices.
- Protect invitations, prevent abuse and respond to support or security events.
- Meet purchase, legal and App Store obligations when those features are introduced.
The production policy will explicitly state CradleSync’s position on advertising, cross-app tracking, sale of personal information, general AI training and optional diagnostics. No claim is made in this local preview.
Your privacy choices
- Review and correct your adult profile.
- Ask an authorised admin to correct baby or care information.
- Review who has access and revoke a caregiver membership.
- Decline optional device permissions without losing unrelated functionality.
- Request a portable copy of relevant information.
- Initiate deletion of your account and understand what remains for other authorised family members.
The Privacy & Data area, export and whole-account deletion flow are scheduled requirements and are not yet complete in the development app.
Preview account deletionRetention and deletion
CradleSync will keep information only for an approved operational, safety or legal purpose. Exact active-record, audit, invitation, diagnostic, purchase and backup periods are still being defined and will be published before launch.
Deleting an account must remove the account and associated personal information unless a limited record must be retained under an approved legal or safety rule. In a shared family, contributor details may need to be removed or replaced while necessary care history remains available to other authorised caregivers. The production process will explain this before confirmation.
Deleting CradleSync information will not automatically cancel an Apple subscription; the production flow will provide Apple subscription-management guidance separately.
Children’s information
CradleSync is directed to adult parents and caregivers, not children. Babies do not sign in. Adults provide baby information to coordinate care, and must only add information they are authorised to share.
The final Australian Children’s Online Privacy Code and the laws of every launch region will be reviewed before release. A child-facing account or experience would require a new privacy assessment.
Security
Current safeguards include role-based family access, PostgreSQL Row-Level Security, expiring invitations and server-side digests for invitation tokens and PINs. Device and server safeguards will be tested against unauthorised family access, lost-device scenarios, revoked caregivers, offline replay and sensitive notification previews.
No system can promise absolute security. The final policy will accurately describe encryption, backups, incident response and provider controls without implying end-to-end encryption unless that has been implemented and independently verified.
Contact and complaints
For privacy questions, data requests or complaints, email privacy@cradlesync.app.
The accountable legal entity and postal address are awaiting owner approval and must be present before publication. The final process will explain internal complaint handling and escalation to the appropriate privacy regulator.
Policy status: Local preview · 15 August 2026
Back to CradleSync