Privacy Policy
Draft ยท Last updated: July 20, 2026
Duckling is a place where families record some of the most personal information there is โ when a baby ate, slept, and grew. We wrote this policy to be actually read. The short version:
1. What we collect
- Account information: your name, email address, and passkey credentials (we never see or store a password with a passkey).
- Child profile information you choose to add: a name, and optionally a photo, date of birth, and sex (used only for growth-reference charts and age-appropriate features โ both optional).
- The entries you log: feeds, sleep, diapers, foods, milestones, words, notes, growth check-ins, and similar โ including who on your care team logged each one, and edit history.
- Voice input: when you use voice logging, your audio is streamed to a speech-to-text processor, transcribed, and discarded โ we do not keep audio recordings. The transcript that produced an entry is kept with that entry so you can always see what was understood.
- Device & technical data: device type, app version, time zone, crash reports (scrubbed of entry content), and sync metadata.
- Product analytics: which features get used, measured with counts and identifiers โ never the content of health-related entries (no medicine names, no symptom text).
2. What we use it for
- Running Duckling: syncing your family's timeline across devices and caregivers, rendering your displays and summaries, sending the notifications you've turned on.
- Parsing what you say or type into structured entries (see ยง4, AI processing).
- Keeping the service safe: abuse prevention, rate limiting, security monitoring, audit trails of account and access changes.
- Improving the product, using aggregated or de-identified usage measurements.
3. What we don't do
- We do not sell identifiable data about you or your child, and we don't share it with data brokers or ad networks.
- We do not show ads in the app today; if we ever introduce anything ad- or recommendation-like, it will not be based on selling or sharing identifiable family data, and we'll update this policy conspicuously first.
- We do not use your family's data to train AI models without your explicit opt-in.
- We do not build advertising profiles of children. Obviously. It's grim that this needs saying.
4. AI processing, honestly described
Duckling's core feature is turning natural language into structured entries. That processing happens on our servers, using third-party AI providers under contracts that prohibit them from retaining your content or training on it (zero-retention terms). What gets sent: the text of what you said or typed, plus the minimum context needed to file it correctly (your children's first names as you entered them, recent entries, your time zone). A caregiver's request only ever includes context for the children they've been granted access to.
5. Who processes data for us
We use a small number of infrastructure providers ("processors") to run Duckling. The current list โ kept accurate as a matter of policy, not marketing:
| Processor | What for |
|---|---|
| Render | Application hosting |
| Neon (PostgreSQL) | Primary database |
| Cloudflare R2 | Private media storage (photos you attach) |
| Speech-to-text provider(s) | Voice transcription (transcribe-and-discard) |
| Anthropic | Language parsing of entries (zero-retention) |
| Resend | Email (invites, digests you opt into) |
| PostHog | Product analytics (no health-entry content) |
| Crash reporting | Stability monitoring (content-scrubbed) |
6. Security
- Passkey-first sign-in; no shared logins โ every caregiver has their own account with their own access.
- Encryption in transit (TLS 1.3) and at rest, including per-child encryption keys for sensitive content, so deleting a child's data destroys the keys that could read it.
- Access controls enforced server-side, per child, per caregiver โ the server denies, clients merely hide.
- An account-activity trail: role changes, exports, and deletions are recorded and visible to guardians.
7. Deletion โ the two clocks
When you delete your account (or a child's profile), two things happen on two published clocks:
- Immediately: access ends everywhere, and the encryption keys for that data are destroyed โ live systems can no longer read it.
- Within 30 days: residual copies in backups and processor systems expire and are purged.
Devices that were offline at deletion time are prevented from re-uploading deleted data when they reconnect. You can export everything (CSV/JSON) before deleting โ export is always available and always free.
8. Children's privacy
Duckling accounts belong to adults (18+). Information about children in Duckling is entered by their parents and guardians, for their own family's use โ Duckling does not collect information directly from children, and the app is not directed at children. We treat all child-related records as sensitive data under this policy. Where consumer-health and children's-privacy laws (such as COPPA and state health-data statutes) apply to us, we design to meet them.
9. Your choices & rights
- Export your family's data anytime, in open formats.
- Correct or delete any entry (guardians can manage the whole account).
- Delete a child's profile or the entire account โ see ยง7.
- Regional rights (GDPR, CCPA/CPRA, and similar): access, correction, deletion, and portability requests via privacy@happyduckling.app.
10. Changes to this policy
If we change this policy in a way that matters, you'll see it in the app before it takes effect โ not buried in an email footer. The date at the top always tells you the current version.
11. Contact
Questions, concerns, or rights requests: privacy@happyduckling.app (placeholder address for this draft).