Legal
Privacy policy.
Last updated: 9 September 2026
Little Bean ("Little Bean", "we", "us") makes a mobile app for parents to track their baby's feeding, sleep, diapers, and growth. This policy explains what personal data we collect, why, who we share it with, and the rights you have. It covers both the app and this website. We are the data controller for this data. Questions: legal@littlebean.app.
What we collect
When you subscribe to the monthly note: your email address, the page you subscribed from, your device type, and the time you signed up. You can unsubscribe from any note in one tap.
When you create an account: your email address, a password (stored only in hashed form, never in plain text) or a magic-link sign-in, your name, and an optional profile photo.
About your baby, entered by you: your baby's name, date of birth, and sex, an optional photo, and the entries you log: feedings, diaper changes, sleep, and growth measurements, each with optional notes. Some of this relates to your child's health.
When you invite a caregiver: the email address of the person you invite.
Technical and subscription data: your subscription status and, if you enable notifications, a device push token. If the app crashes, we receive a report tied only to an anonymous account identifier, with no name, email, or baby data attached.
Product analytics: the app uses PostHog, hosted in the European Union, to understand which screens and features are used, so we can improve the app. These events are tied to a pseudonymous account identifier and never include your baby's entries, name, or photos.
We do not collect your precise location and we do not run advertising.
We do not send any data about you or your baby to an artificial-intelligence service unless you turn on the Little Bean Assistant (shown as Ask in the app), which is off unless you choose to enable it. If you do, your questions and the figures calculated from your entries are sent to Amazon Web Services, on servers in the European Union, where Anthropic's Claude model produces the answer, and your question is also sent to a Google service, on servers in the European Union, to find the right guide passage. Your name, your email address, your baby's name, and your photos are never sent. Turning the Assistant off in Settings stops this.
AI processors and model training prohibitions
The Little Bean Assistant uses cloud infrastructure provided by Amazon Web Services and Google Cloud, with all processing taking place within European Union member states. Text generation is processed by Amazon Bedrock using EU-only inference profiles, which route requests solely across data centres inside the EU. Text embeddings, which find the right guide passage for your question, are processed by Google Vertex AI within the EU.
Under our cloud providers' applicable service terms and data processing agreements, neither Google, Amazon Web Services, nor third-party model developers such as Anthropic are permitted to use your questions, inputs, or the answers generated for you to train or improve their AI models.
Assistant data retention and safety screening
The two providers keep what we send for different lengths of time. Amazon Bedrock operates under a zero data retention model: your question and the guide text sent with it are processed in memory to produce the answer and are not stored or logged afterwards. Google Vertex AI does not operate zero data retention. It caches what we send for up to 24 hours to run the feature, and prompts flagged by its safety classifiers are held in secure logs for up to 90 days for automated abuse detection.
Both providers run automated screening for severely illegal content, which is the only case in which content can be kept outside the retention described above. Content flagged by that screening may be stored as an exception, reviewed by authorised staff to confirm the violation, and reported to law enforcement or to the statutory bodies the law requires. Ordinary questions that are not flagged are never read by a person and are never stored by our providers beyond the periods described above.
How we use it
We use it to create and run your account, store and show the entries you log, sync data with caregivers you invite, manage your subscription, send service messages, keep the app secure, and diagnose crashes. Our legal bases under the GDPR are performing our contract with you, your consent, and our legitimate interest in keeping the service secure. We do not sell your personal data, and we never will.
Room, the babyphone
When you use Room, the picture and sound go directly from the phone in the room to the phones looking in. We never store or record them, and neither does anyone else. They exist only while someone is looking and are kept by nobody afterwards, including us.
To set that connection up, and to carry it when the two phones cannot reach each other directly, the app uses Cloudflare's connection service (STUN and TURN), served from the Cloudflare data centre nearest to each phone, which for phones in Europe is inside the EU. Cloudflare receives the network addresses of the phones taking part and, while it is relaying, the stream itself. The stream is encrypted between your phones, so Cloudflare cannot see or hear it. When the app asks Cloudflare for connection details it sends nothing about you, your account or your baby.
Room uses the camera and microphone only while it is on, and only on the phone you have chosen to leave in the room.
Emails we send you
We send two kinds of email. Service emails keep your account working: sign-in codes, caregiver invitations, subscription and trial notices, the summaries you have switched on, and reminders that help you finish setting up. We send these on the basis of our contract with you and our legitimate interest in making the service work.
We also occasionally email account holders about our own features and offers, such as a discount or a free month. We send those on the basis of our legitimate interest in telling our own customers about our own service, and we tell you so when you sign up. You can refuse them at any time: every one carries a one-tap unsubscribe link that needs no sign-in, and unsubscribing stops the offers without affecting service emails or your account.
The monthly note is separate from both of these. Subscribing to it does not create an account, unsubscribing from it does not affect one, and you can leave it in one tap from any note.
We do not share your address with anyone else for their own marketing, and we never will.
Who we share it with
We use a small number of providers purely to operate the service. Each receives only what it needs:
- Supabase — database, authentication, and file storage, hosted in the European Union.
- RevenueCat — subscriptions; receives an anonymous account identifier and transaction details, no name, email, or baby data.
- Sentry — crash and error reporting, hosted in the EU; receives only an anonymous identifier and your subscription status.
- PostHog — product analytics, hosted in the EU; receives app usage events (screens opened, features used) tied to a pseudonymous account identifier, never your baby's entries, name, or photos.
- Resend — sends caregiver invitation emails; receives the inviter's name, the baby's first name, and the invited email address.
- Cloudflare (this website) — hosts littlebean.app and provides privacy-first Web Analytics. It sets no cookies, collects no personal data, and does not track you across sites; it only counts aggregate page views and where visits come from.
- Cloudflare (Room) — the connection service behind Room, described above. It receives the network addresses of the phones taking part and, when relaying, the encrypted stream, which it cannot see or hear.
- Expo — delivers push notifications, when you enable them; receives a device push token.
- Apple App Store and Google Play — process subscription payments. We never see or store your card details.
We may also disclose data if the law requires it. We do not sell your data to anyone, ever.
Where your data is held
Your account data, baby logs, and photos are stored in the European Union. If you use the app from outside the EU, your data is still processed in the EU.
How long we keep it
We keep your account data and logs for as long as your account exists. When you delete your account from within the app, we immediately delete your profile, your baby profiles, your logs, your photos, and your sign-in record. Copies in routine encrypted backups are purged on our provider's normal backup cycle. Crash reports are deleted on Sentry's standard retention schedule. Caregiver invitations expire after 7 days. Waitlist data is kept until you ask us to delete it, or until one year after the app launches, whichever comes first.
Your rights
If you are in the European Union or the United Kingdom, you have the right to access your data, correct it, delete it, restrict or object to how we use it, withdraw consent, and ask for a copy of your data. You can act on most of these directly in the app: edit your profile and baby details, export your data from Settings as a PDF report or a CSV file (choose a date range; the CSV is machine-readable, one row per entry), and delete your entire account from Settings. For any other request, email legal@littlebean.app and we will respond within 30 days. You also have the right to complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or your local supervisory authority.
For users in California (CCPA): you have the right to know what personal information we collect, to request its deletion, and to not be discriminated against for exercising your rights. We do not sell personal information, so there is no sale to opt out of.
Children
Little Bean is for use by parents and guardians. The account holder is an adult or, if under 18, acts with their own parent or guardian's agreement. Data about a baby is entered by the parent or guardian about their own child. The app is not directed to children, and we do not knowingly collect personal information directly from a child under 13 (or under 16 in the EU/EEA). The information recorded about a baby is provided by you, the parent or guardian, not by the child. If we learn that a child has created an account, we will delete it.
Changes to this policy
If we change this policy, we will update the date at the top and, for significant changes, notify you in the app or by email.
Contact
Questions or requests: legal@littlebean.app. Little Bean, Netherlands.