Your family’s details deserve plain language
Privacy Policy
Last updated 10 August 2026
1. Scope and operator
This policy explains how the operator of Ugly Baby Tracker, identified on your checkout receipt (“we”, “us” or “our”), manages personal information. It applies to visitors, account holders and information entered about children or other household members.
2. Information we collect
Account and service information. We collect account details such as email address, password hash, verification state, account identifiers, access or subscription status, legal-consent records and Stripe customer, subscription or payment identifiers. Support submissions contain your query, submission time and relevant account identifiers. Server and security logs may contain IP address, browser details, requested pages, timestamps and diagnostic events.
Baby-tracking information. Authorised users may enter a child’s name, nickname or pseudonym, birthday and sex; poops; pees; feeds; pumping records and amounts; sleep start and wake times; weight; height; food or allergen introduction counts; feeding-side settings; and display preferences. The baby-tracking categories are limited to these records.
The tracker does not provide fields for diagnoses, symptoms, medications, treatment plans, clinician notes or medical-device readings. We do not obtain a child’s clinical or medical records from hospitals, doctors, government health systems, wearables or monitoring devices.
The service automatically records technical information such as when an entry was submitted and which authorised account submitted it. It calculates display information such as durations, counts, summaries and WHO reference centile comparisons from user-entered records.
Some baby-tracking information may be health information or sensitive information under applicable privacy law. We treat it accordingly. Describing information as health-related for privacy purposes does not mean that the service provides medical advice, healthcare or clinical monitoring. The account holder is responsible for having authority to provide information about a child and for limiting household access appropriately.
3. How we collect and use it
We collect information directly when you register, use the tracker, change settings, pay or request support; automatically when the service handles a request; and from Stripe or Resend when they return payment, subscription or delivery status. Baby-tracking content comes only from authorised users; we do not obtain it from healthcare providers or connected monitoring devices.
We use baby-tracking information only to store and display household records, make them available to authorised family members, create requested exports, and generate the histories, durations, counts, summaries and reference charts described above. We do not use it to infer a diagnosis, produce a medical risk score, recommend care, generate predictive schedules, or provide health, hydration, feeding or safety alerts.
We use other personal information to operate and secure accounts, provide subscriptions, send essential account messages, respond to support, diagnose faults, prevent abuse and meet legal obligations. We do not sell, rent or trade personal information. We do not disclose it to advertisers, data brokers, social networks, analytics providers or other third parties for their own advertising, marketing or unrelated purposes.
4. Cookies and analytics
The only cookie set by Ugly Baby Tracker is an essential, HTTP-only session cookie used to keep you signed in and protect requests. It is not an advertising or tracking cookie. We do not use advertising cookies, analytics cookies, tracking pixels, third-party behavioural analytics, cross-site tracking or behavioural advertising. Our public content-delivery configuration is not used to add advertising or analytics cookies. We will update this policy before introducing any materially different cookie or analytics practice.
5. Who receives information
We do not sell or share personal information for advertising, data brokerage, behavioural analytics or another party’s unrelated purposes. We disclose only the limited information needed by the following service providers to operate the service:
DigitalOcean. Our intended production configuration stores the application, account information, baby-tracking records, support requests, operational logs and backups on a DigitalOcean Droplet in its Sydney, Australia region. DigitalOcean processes this information as our infrastructure provider.
Cloudflare. Cloudflare provides global content delivery and security services for the public landing page only. It may process the public page requested, IP address, browser or device details, timestamps, cache and security signals, and similar request metadata. Signed-in tracker pages are intended to be served directly from the Australian application host, and Cloudflare is not used to serve or cache baby-tracking records.
Stripe. Stripe receives the account email address, an internal billing reference, payment information entered directly into Stripe, and customer, subscription, transaction and fraud-prevention information needed to provide checkout and billing. We do not send baby-tracking records to Stripe.
Resend. Resend receives the recipient email address, transactional message and verification or invitation link, and provides message-delivery status. We do not send baby-tracking records to Resend.
We may also disclose only the information reasonably necessary to professional advisers who are subject to confidentiality obligations, or to regulators, courts and law-enforcement bodies where disclosure is lawfully required. Providers may independently process limited service, security or account information as described in their own privacy policies.
6. Overseas processing
The intended primary hosting location for the application database, baby-tracking records, support conversations and private screenshot attachments is DigitalOcean’s Sydney, Australia region. DigitalOcean support, security or account administration may involve personnel or systems outside Australia.
Cloudflare operates a global network, so public-page content and request metadata may be processed in Australia and other countries, including the United States and countries in Europe. Resend states that it processes information in the United States. Stripe operates globally and states that cross-border transfers can include the United States and India. We take reasonable steps required by Australian privacy law when personal information is processed or disclosed overseas, and will update this policy before materially changing the intended location of private tracker records.
Read the current DigitalOcean Privacy Policy, Cloudflare Privacy Policy, Stripe Privacy Policy and Resend Privacy Policy.
7. Storage, security and retention
We use access controls, password hashing, encrypted transport in production, tenant separation, request protections and restricted operational access. No online system can be guaranteed completely secure. We retain account and tracker information while the account is active and afterwards only for as long as reasonably required for backup recovery, disputes, fraud prevention and legal or accounting obligations. Support conversations are stored in the private application database. Uploaded screenshots are decoded, rewritten to remove metadata, stored outside the public web directory and made available only to the requestor and support administrators. Backups may retain deleted information until they rotate out.
8. Access, correction and deletion
You can correct many child and tracker records in the service. The Account page provides self-service deletion of the account, child profiles, tracker history, preferences, family access, sessions and stored support requests after an exact typed confirmation. A live Stripe subscription is canceled first; if Stripe cannot confirm cancellation, local deletion does not proceed. You may also ask for access to, correction of, or deletion of personal information by using Support. Stripe records, rotating backups, security logs and records required for legal, billing, fraud-prevention or dispute purposes may remain for the applicable retention period.
9. Complaints
Submit a privacy complaint through Support with enough detail for us to investigate. We will acknowledge it and aim to respond within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
10. Children, breaches and policy changes
The service is for adult account holders recording information on behalf of their household; children must not create accounts. If a data breach is likely to cause serious harm, we will assess it and notify affected people and regulators where required. We may update this policy as the service or law changes. Material changes will be highlighted in the service or sent to the account email before or when they take effect.
11. Contact
Signed-in account holders can contact the privacy contact through Support. If you cannot sign in, use the operator contact details on your Stripe receipt. Privacy requests are handled by the service operator.