Privacy Policy
Last updated: April 2026
1. Information We Collect
We collect the following personal data when you use SafeSpoon:
- Account data: your email address, used solely to authenticate your account.
- Baby profile data: your baby's first name and date of birth, used to personalise your experience.
- Allergen log data: records of food introductions including allergen type, date served, amount, preparation method, and any notes you enter.
- Reaction data: severity ratings, symptom descriptions, onset times, and optional reaction photos (JPEG/PNG, max 5 MB).
- Reminder settings: re-introduction schedules you configure.
We do not collect location data, device identifiers, or any information beyond what you explicitly enter.
2. How We Use Your Data
Your data is used exclusively to provide the app's features:
- Displaying your allergen introduction log and dashboard.
- Generating PDF and CSV exports for you to share with your paediatrician.
- Sending local reminder notifications you configure.
We do not use your data for advertising, analytics profiling, or any commercial purpose.
3. Data Storage and Security
Your data is stored on Supabase-hosted PostgreSQL infrastructure. Each user's data is protected by Row Level Security (RLS) policies — you can only ever access your own data. Reaction photos are stored in Supabase Storage with equivalent access controls.
We do not sell, rent, or share your personal data with any third party, except as required by law.
4. Your GDPR Rights
If you are in the European Economic Area (EEA) or United Kingdom, you have the following rights:
- Right of access: request a copy of the personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure ("right to be forgotten"): delete your account and all associated data permanently. You can do this at any time from the Settings screen.
- Right to restriction: request that we limit how we process your data.
- Right to data portability: export your log data as CSV from the Settings screen.
- Right to object: object to processing where we rely on legitimate interests.
To exercise any right other than account deletion or data export (both available in-app), contact us at the address below.
5. Data Retention
We retain your data for as long as your account is active. When you delete your account, all personal data — including your baby's profile, all log entries, reactions, and photos — is permanently deleted within 30 days.
6. Children's Privacy
This app records data about infants on behalf of their parent or guardian. We do not knowingly collect data directly from children. Parents and guardians are responsible for the data they enter on behalf of their child.
7. Medical Disclaimer
The information recorded in this app is for personal tracking purposes only. It does not constitute medical advice and must not be used to diagnose or treat any medical condition. Always consult a qualified paediatrician or allergist before introducing new foods to your baby. In an emergency, call your local emergency services immediately.
8. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes through the app. Your continued use of the app after changes take effect constitutes acceptance of the updated policy.
9. Contact
If you have any questions about this Privacy Policy or wish to exercise your rights, please contact us through the app's support channel.