Privacy Policy

Last updated: 15 April 2026

The short version: No accounts. No analytics SDKs. Your baby's photos, videos, milestones, and growth data live in your own iCloud (via Apple's CloudKit) — not on Yayby's servers. Email is optional (for order receipts only). Our backend only handles unlock purchase verification and print-book orders.

1. Who we are

Yayby ("we", "us", "our") is an iPhone and iPad application operated by Andrew Hingston, based in Australia. Contact: support@yayby.com.

2. What we collect (and what we don't)

Yayby is built to minimise the personal data we hold. The only personal data we may receive is what you explicitly provide during optional steps:

We do not collect:

3. Where your baby's content lives

Photos, videos, voice notes, milestone records, growth entries, and written notes captured in Yayby are stored in your own iCloud account, using Apple's CloudKit framework and an app-specific iCloud ubiquity container (iCloud.com.yayby.dev). This content never reaches Yayby's servers. It is governed by your Apple ID's terms and Apple's iCloud Privacy Policy.

If you choose not to enable iCloud, content is stored locally on your device only.

4. What our backend handles

Yayby operates a small Supabase-hosted edge-function API that handles narrow, transactional tasks:

No photos, videos, milestones, growth data, voice notes, or personal notes ever reach our backend.

5. Third parties we rely on

6. Data security

All communication between Yayby and our backend uses HTTPS. Sensitive on-device values (device identifiers, unlock-state dates, purchase tokens) are stored in the iOS Keychain — Apple's most secure local storage. The Prodigi webhook that notifies us of print-order status is secured with URL token verification so updates cannot be spoofed.

7. Subscriptions & purchases

Yayby's one-time unlock purchase is billed through Apple's App Store and governed by your Apple ID. We receive a transaction confirmation and an anonymous receipt — we do not see or store your full credit-card details. Printed-book orders are billed separately through Stripe; card details are handled entirely by Stripe.

8. Children's privacy

Yayby is intended for use by parents, grandparents, and caregivers to capture memories of their own children. The app is not directed at children under 13, and we do not knowingly collect personal information from children. Content captured about a child is held by the account-holder parent or guardian; Yayby has no access to it.

9. Your rights

Because we collect so little, there is little to request access to or delete from our servers. You have the right to:

10. International users

Yayby is available worldwide via the Apple App Store. Printed baby books ship internationally via Prodigi. Backend infrastructure is operated in Supabase's Tokyo region; data transfers are governed by Supabase's standard contractual clauses. Because we collect no personal content, the data-transfer surface is minimal.

11. Changes to this policy

We may update this Privacy Policy from time to time. Material changes will be reflected on this page with an updated "Last updated" date. Continued use of Yayby after a change is posted constitutes acceptance of the updated policy.

12. Contact

Questions about this Privacy Policy? Email support@yayby.com. Security vulnerabilities: security@yayby.com (or see /.well-known/security.txt).