Privacy policy

Effective 7 August 2026

La politique de confidentialité et les conditions générales ne sont publiées qu'en anglais. C'est la version qui fait foi, et celle qui s'applique où que vous soyez.

This policy explains what Buma collects, why, who else touches it, and what you can do about it. It covers the Buma apps for iPhone and Android, the Buma service behind them, and this website.

1. Who we are

MB Marnar, company code 306991895, Kranto g. 12, Paežerių k., LT-70205 Vilkaviškio r., Republic of Lithuania, is the controller of the personal data described here.

Write to team@bumababy.app about anything in this policy. Please use the email address on your account, so we can tell it is you asking.

2. What we collect

Your account

Your email address and display name, passed to us by Apple or Google when you sign in, along with which of the two you used. Buma has no password of its own and never sees one. If you use Sign in with Apple and choose to hide your address, we only ever receive Apple’s relay address — we do not see your real one.

Then whatever you set up afterwards: a photo of yourself or one of the illustrated characters instead, your language, time zone and whether you prefer metric or imperial, which notifications you want, how your trackers are arranged and coloured, and which of the first-run tours you have already been through.

Onboarding also asks how you heard about Buma, with a free-text box if none of the answers fit. It is the one question in onboarding that buys you nothing — it tells us which of our efforts to keep making. Section 6 covers where that answer goes.

Your baby’s profile

Name, date of birth and optionally time of birth, sex, an optional photo, birth weight and length, time zone, and — if you tell us — how many weeks into pregnancy they were born, which is what lets Buma use corrected age.

Plus the picture of their sleep you give us at the start: roughly how many naps a day, how much they sleep, what you are hoping to change, and which topics you want help with. We keep that separately from what you log, because it is what you believed was normal on day one — which is the only thing a later observation can be measured against.

What you log

Entries across the trackers Buma ships with and any you create yourself. That includes feeds — breast, bottle and solids — pumping, sleep and how hard settling was, nappies, baths, tummy time, walks, play and stories, and also temperature, medicines and doses, symptoms, vaccines, doctor visits, weight, height, head size, teeth, mood, milestones and free-text notes. Every entry records who created it and who last edited it.

Photos and memories

The image itself, its dimensions and file size, any caption you add, and the day it belongs to — read from the photo’s own capture time where it has one, so a picture taken at 23:50 files under the right day.

A memory adds words to that: an occasion from the list or one you write yourself, a title, a description, the day it happened, and which baby it was about. Photos are optional there — a first smile at 3am with no camera to hand is still worth keeping. We also record which family member reacted to which memory, and with which reaction.

Ask Buma

The messages you send and the replies. Alongside them we keep a snapshot of the log data used to answer — so “it said she slept nine hours and that’s wrong” can be traced rather than guessed at — and a record of which of Buma’s internal lookups ran to produce the answer.

Buma also keeps notes about your family so it does not have to be told the same thing every time: that a baby is allergic to dairy, that sleep training started on Monday. You can write those yourself, and Buma writes some of them itself while answering. They are listed in the app and you can edit or delete any of them.

If you rate an answer with a thumb up or down, we keep the rating and the reason you give. We also count how many messages you send each day, which is what enforces the free allowance.

Your subscription

Which product you bought, which store it came from, whether it is active and whether it will renew, and the customer identifier our billing provider uses. We never receive or store your card details. Apple and Google take the payment.

Device and diagnostics

A push notification token if you enable notifications, and a second, short-lived one per device whenever a running timer is showing on a lock screen. Plus platform, app version, language and a device identifier. Crash reports, which contain technical diagnostics rather than the contents of your log.

Buma also measures how the app is used, and — because it advertises — which ad or recommendation brought you to it. Advertising identifiers are involved in the second of those, so it has a section of its own: section 6.

Sessions

Each sign-in creates a session record. That is what lets signing out — and deleting your account — take effect immediately on every device rather than whenever a token happens to expire.

3. Health data about a child

Your entries and photos are data concerning health, which the GDPR treats as a special category. We process them on the basis of your explicit consent under Article 9(2)(a), given by choosing to record them, and you can withdraw it at any time by deleting the data or your account.

As the parent or guardian, you are the one consenting on your child’s behalf, and you are responsible for having the right to record what you record.

4. Why we process it

  • To provide the service — storing your log, syncing it between devices, sharing it with your family, working out sleep windows, answering you in Ask Buma. Performance of our contract with you.
  • To keep it working and secure — diagnostics, abuse prevention, backups. Our legitimate interests.
  • To bill you — knowing whether your subscription is active. Performance of our contract.
  • To answer you — support correspondence. Our legitimate interests.
  • To understand how Buma is used and how people find it — section 6. Our legitimate interests, and on iPhone your consent for the advertising identifier specifically.

We do not sell your data, we do not show you advertising inside Buma, and we do not use your log or your photos to train AI models. Buma does buy advertising elsewhere, and measures whether it worked — which is a different thing, and section 6 describes it rather than rounding it off.

5. Sharing inside a family

This is the part to read twice, because it is how Buma works rather than an edge case.

A family is the unit of sharing. Anyone in yours can see every baby in it and every entry, photo and memory attached to them. A caregiver can create, edit and delete entries — including ones you made; a viewer can only read. Their changes are attributed to them, so you can always see who did what.

An invite code is a request, not a key. Someone who uses your code does not join — they end up in a queue, and an existing member has to approve them before they can read anything. Codes expire within half an hour and are single-use by default. That is deliberate: a code is a short string that ends up screenshotted into a group chat, and on its own it must not be authority to read a child’s health record.

Removing someone ends their access immediately, but entries they created stay in the history, because they are part of your baby’s record rather than that person’s. Invite only people you are content to give all of it to.

Ask Buma conversations are private by default — the rest of your family cannot read them unless you share the conversation. The notes Buma keeps about your family are the exception and are shared by design: they describe the baby, so both parents can read, correct and delete the same ones.

6. Measurement and advertising

Buma shows you no adverts. It does two kinds of measurement, and one of them involves ad networks, so here is exactly what each one does.

How the app is used

We use PostHog to see which parts of Buma people actually reach. It receives which screens you open and events like “an entry was logged”, “a memory was created”, “an invite was shared” — that a thing happened and what kind, never its contents. Alongside them, a few counts about your account: how many babies and families you have, your role in them, and whether you subscribe. Your Buma user id is attached, so a funnel reads as one parent’s path rather than an anonymous crowd, and PostHog works out approximate location from your IP address.

What it deliberately never receives: your baby’s name or anyone else’s, the text of a note, the name of a tracker you invented, a live invite code, a photo, or anything you said to Ask Buma. Session replay is switched off — these screens are full of your baby’s face and health details, and recording them would be indefensible whatever the recording was for.

We do this under our legitimate interest in knowing whether Buma works. There is no switch for it in the app today; you can object by writing to team@bumababy.app and we will stop.

Which advert brought you here

We use Singular, a measurement partner, to tell whether an advert we paid for led to an install. It receives the install itself, a handful of early milestones — onboarding started, registration finished, the paywall seen, a purchase begun, a trial started — your Buma user id, and your device’s advertising and device identifiers, which are what let a click on an advert and an install be matched to each other.

No log data, no photos and no baby data ever go to it. It is told that a parent reached the paywall, never who the parent is parenting.

On iPhone, that identifier is yours to refuse. iOS asks you once, in Apple’s own dialog, before it is used. Say no and there is no advertising identifier to send; Buma behaves identically either way. You can change your mind later in Settings › Privacy & Security › Tracking. On Android the equivalent control is Settings › Privacy › Ads.

Apple and Google run their own measurement alongside this — Apple’s SKAdNetwork and Search Ads attribution, and Google Play’s install referrer. Those are designed to report campaign performance without identifying you, and are governed by their operators’ own privacy policies.

What our billing provider is told

RevenueCat handles subscriptions, and it is also where a purchase gets joined back to the campaign that produced it. Beyond the customer identifier and purchase events, we give it the device and advertising identifiers above, the campaign details Singular reports, your answer to “how did you hear about Buma?”, and your email address — the last so that a customer writing in for support can be found by the address they wrote from.

7. Who else processes it

These providers process data on our instructions, under contract, and may not use it for their own purposes.

ProviderWhat it doesWhat it receives
Google Cloud (Cloud Run, Cloud SQL)Runs the service and stores the databaseEverything in section 2 except photo files
Google Cloud StorageStores photosPhoto files and their metadata
Google Cloud Vertex AI (europe-west1)Generates Ask Buma repliesYour messages and the log context for them
AppleSign in with Apple, payments, ad measurementVerifies your identity token; campaign measurement that does not identify you
GoogleGoogle Sign-In, payments, ad measurementVerifies your identity token; campaign measurement that does not identify you
RevenueCatTracks subscription state and purchase attributionCustomer identifier, purchase events, email, device and advertising identifiers, campaign details
SingularInstall attributionInstall and early funnel events, device and advertising identifiers, your Buma user id
PostHogProduct analytics (app and website)Screens, feature events, account counts, user id, IP-derived approximate location
Google Firebase Cloud MessagingDelivers push notificationsPush tokens and the notification’s contents
Google Firebase CrashlyticsCrash reportingCrash diagnostics and device details

8. Where it is stored

Everything you log — your account, your babies, your entries, your photos and your Ask Buma conversations — is held in the European Union, and Ask Buma requests are processed in Google’s europe-west1 region. PostHog processes analytics on EU servers.

Some providers operate outside the European Economic Area. RevenueCat, Singular and Google’s Firebase services are United States companies, and the data described for them in section 7 — subscription and measurement data, never your log — is transferred there under the European Commission’s Standard Contractual Clauses.

9. How long we keep it

For as long as your account exists. Deleting an entry removes it from the app straight away; a marker is kept for a limited period so that a device which was offline learns the entry is gone rather than resurrecting it, and the record itself is then purged.

Deleting your account takes effect immediately: every session is revoked, your email address and push tokens are erased, you are removed from every family, and any family left with nobody in it is deleted with you. Your account is then closed and queued for erasure rather than wiped in the same second — we would rather describe that accurately than promise an instant purge we do not perform.

Two things deliberately survive. Your display name stays attached to entries you logged, so a co-parent’s history does not turn into a record kept by nobody. And billing records are kept for the statutory period the law requires. Everything else goes.

10. Your rights

You can ask for access to your data, correction of it, erasure of it, restriction of how we use it, a portable copy of it, and you can object to processing based on legitimate interests — which includes the analytics in section 6. Where we rely on consent, you can withdraw it without affecting what was lawful beforehand.

Export is available in the app, and so is account deletion — Settings, then Delete account. If you have already uninstalled, or you want anything else, email team@bumababy.app and we will answer within one month.

11. Children

Buma is for parents and carers, not for children. The account holder must be an adult, and the data recorded about a child is provided and controlled by that adult.

12. Security

Data is encrypted in transit. Every read and every write is checked against whether your account belongs to the family that owns the record — asking for another family’s baby returns “not found” rather than “not allowed”, so identifiers cannot be probed. Photos are served through short-lived signed links, and every session can be revoked individually.

13. This website

This site sets no advertising cookies and sells nothing about you to anyone. The only personal data it collects directly is an email address you choose to type into the launch-notification form, which we use once, to tell you Buma is out, and then to nothing else.

It also uses PostHog for product analytics — how many people read a page, which language they read it in, and whether the launch-notification form worked. What that means for you depends on which of three states you are in, and we would rather spell them out than round them off:

  • Before you answer the banner. We count the page you are reading, but store nothing on your device — no cookie, no browser storage. Close the tab and there is nothing left to recognise you by, so you are a visit rather than a person. We do this on the basis of our legitimate interest in knowing whether anyone reads the site at all.
  • If you accept. PostHog additionally stores an identifier in your browser, so return visits are recognised as the same person and we can tell twenty readers from one reader who came back twenty times.
  • If you decline. Measurement stops. Not “continues without a cookie” — stops. You said no, and that is the whole of it.

In every case PostHog receives the pages you visit and approximate location derived from your IP address. It does not receive your email, and there is no baby data on this website to receive — the app is a separate thing, covered by the rest of this policy. PostHog Inc. processes this on our instructions on EU servers. You can change your mind at any time by clearing this site’s data in your browser, which removes the stored decision and brings the banner back.

14. Changes

We will post any changes on this page and update the date at the top. If a change materially affects you, we will say so in the app before it takes effect.

15. Complaints

You can complain to the State Data Protection Inspectorate of Lithuania (vdai.lrv.lt) or to the supervisory authority where you live. We would rather you told us first, at team@bumababy.app — most things are quicker to fix than to escalate.