Privacy Policy
In short
- Cuddleya has no user account, no server of its own, no ads, no analytics, no tracking and no third-party software.
- What you enter lives on your device and, as long as you are signed in to iCloud and do not turn it off, in your own iCloud. The provider cannot access it.
- Other people see your entries only if you explicitly invite them.
- The provider receives personal data only when you get in touch or take part in a TestFlight test (section 2).
1. Controller
Stefan Venekamp
c/o Block Services
Stuttgarter Str. 106
70736 Fellbach, Germany
Email: cuddleya@icloud.com
No data protection officer has been appointed, as there is no legal obligation to do so (Art. 37 GDPR, Section 38 BDSG).
2. What the provider processes itself
The provider is responsible for processing in the following three cases only. The data you enter in the app is not among them (see section 3).
2.1 When you write to us
If you write to cuddleya@icloud.com, we process your email address, your message and anything you attach in order to answer you. The legal basis is Art. 6(1)(b) GDPR where your request concerns use of the app, otherwise Art. 6(1)(f) GDPR (legitimate interest in answering requests and improving the app). The mailbox is hosted by Apple (iCloud Mail). Apple may process data in the USA and relies on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses for this. We delete the correspondence once your request is settled, unless a statutory retention period applies.
Under “iCloud Sync” → “Diagnostics” the app shows a log of the last few minutes of syncing. With “Share log” you can pass it on yourself, for example as an attachment to a support email. It contains the app version, iOS version and device model, times, states and error codes, and technical identifiers of children and entries. Share links are removed and names appear only as “<private>”. You see it before sending, and it is only transmitted if you send it yourself.
2.2 This website
This website is served by GitHub Pages of GitHub, Inc. (88 Colin P. Kelly Jr. Street, San Francisco, CA 94107, USA). When you visit, GitHub processes technically necessary connection data, in particular your IP address, time, requested page and browser identifier, as a host under its own responsibility. The provider receives no server logs. The legal basis is Art. 6(1)(f) GDPR (legitimate interest in operating the site securely). GitHub is certified under the EU-US Data Privacy Framework; the EU Standard Contractual Clauses apply in addition.
The domain cuddleya.de and its name resolution are provided by netcup GmbH (Emmy-Noether-Straße 10, 76131 Karlsruhe, Germany), where technical DNS query data arises in Germany.
This website sets no cookies, stores nothing on your device, loads no third-party fonts or scripts and does not count visits.
2.3 App Store and TestFlight
The app is distributed by Apple, which is responsible for purchase, download and testing. Apple shares information with the provider under its own rules:
- App Store: aggregated download and usage figures, and crash reports only if you agreed in iOS Settings to share with app developers.
- TestFlight: if you take part in a test, the provider sees the email address and name you were invited with, plus any feedback, screenshots and crash reports you send through TestFlight.
The legal basis is Art. 6(1)(b) GDPR (running the test) or (f) (fixing errors). This data is held by Apple in App Store Connect. Retention and deletion follow Apple's rules for TestFlight.
3. The data in the app
Depending on what you use, Cuddleya stores:
- About your child: name, date of birth, due date, sex and optionally a photo. The app scales the photo down and saves it again without metadata such as the location where it was taken.
- Entries: sleep (including where), breastfeeding, bottle, solids (including foods and reactions), pumping, diapers (including stool and rash), medication (name, dose, reason), measurements (height, weight, head circumference, temperature), markers (e.g. “unusual day”), appointments and notes, each with time and time zone. Deleted entries stay in the trash for 30 days.
- Who made an entry: a random identifier for this installation of the app, the pseudonymous identifier iCloud uses to attribute your entries to your account (people you share with have it in their app, not as a name), and, if you set one in the Child tab under “Your name for others”, a name that people you share with see next to your entries.
- For the sleep forecast: a model per child and a log of earlier forecasts. The app calculates both only on the device. They are not synced or exported, but are part of backups.
- Settings such as notifications, units and display.
Much of this is health data, mostly about your child and partly about you (e.g. breastfeeding and pumping). It leaves your device only in the ways described in section 4. None of them leads to the provider.
If you use Cuddleya for your own family, this is a purely personal or household activity to which the GDPR does not apply (Art. 2(2)(c)). The provider does not process this data, has no access to it and is not a processor for it.
4. Where the data lives and who sees it
- On your iPhone
- In the app's database. While a sleep or breastfeeding timer runs, a Live Activity on the lock screen and in the Dynamic Island shows your child's name and the timer.
- On your Apple Watch
- Through Apple's WatchConnectivity, the iPhone sends your children's names and dates of birth and any running timers to the watch. New entries made on the watch travel the same way to the iPhone. The watch can show your child's name on the watch face.
- In your iCloud
- If you are signed in to iCloud, syncing is on from the start. The app then stores the details of your children (including the photo), the entries including the trash, and who made them in the private CloudKit database of your iCloud account, so that your devices show the same data. For syncing, the app receives invisible notifications from Apple's iCloud services, not from the provider. Apple encrypts the data in transit and on its servers. It is not end-to-end encrypted; Apple manages the keys. The provider cannot see this database. Storage at Apple is governed by Apple's iCloud terms and privacy policy; within the EU the iCloud provider is Apple Distribution International Ltd., Ireland. You can turn syncing off in the Child tab with “Sync with iCloud”. What is already in iCloud stays there until you delete it (section 7).
- With people you invite (optional)
- You can share a child with others through iCloud, for example your partner. This works by invitation only. The invitation carries the child's name, and Apple's sharing dialog shows participants each other's names or contact details from their Apple Accounts. Invited people see everything about that child: details, photo, entries and the names shown with entries. They can also add and change entries, edit the child's details, archive the child (which applies for everyone), and create exports, backups and reports. What they enter is stored in your iCloud. If you stop sharing, they receive no further data; the app hides the child on their devices and deletes it there later. Copies they made themselves beforehand are not affected.
- In backups
- By default the app makes a backup on your device at most once a day when you open it and something has changed since the last one; the three most recent automatic backups are kept. You can turn this off in the Child tab under “Backups” with “Back up daily”. A backup is a complete copy of the app's database: all children, including those shared with you, all entries including the trash, and the sleep forecast data, but not the settings. Backups are excluded from the iOS device backup. A backup leaves the device only if you pass it on yourself with “Share”, for example to the Files app or via AirDrop. A backup you pass on is not encrypted, and its file name contains the random installation identifier. You can also read backups back in from a file.
- In exports (optional)
- “Export Data” in the Child tab creates an unencrypted file with all children (including the photo) and all entries, including the trash. You decide where it goes through the share menu. The app can also read such a file back in.
- In reports (optional)
- The app creates PDF reports on the device. You decide where one goes through the share menu.
- In your iPhone backup
- As with most apps, the app's data, its settings and the stored location value are part of your iPhone backup (iCloud Backup or computer) if you use one. This also applies when syncing is off. Only the app's own backups are excluded.
5. Permissions
You can revoke every permission in iOS Settings.
- Location: the first time you open the “Today” view, the app asks once for your location, only so the day axis can show sunrise and sunset. The app rounds the position to about one kilometre and stores only this rounded value in its settings on the device. It is not synced, shared or exported and is not included in backups, reports or the diagnostics log. If you revoke the permission later, the app keeps using the stored value until you delete the app. Without location the app works as usual, just without sun times.
- Notifications: the app's only notification is the hint about the next sleep window. It is scheduled locally on the device and names your child, including on the lock screen. You can adjust this in iOS Settings. The provider sends no push messages.
- Photos: for your child's photo the app uses the iOS photo picker. It sees only the one picture you choose, not your library.
6. Transfers to third countries
The provider itself transfers no data to third countries. If you use iCloud, Apple may process data outside the EU, in particular in the USA, based on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses. For the website, see section 2.2 (GitHub).
7. Retention and deletion
- Entries are kept until you delete them. Deleted entries first go to the trash for 30 days, and with syncing on also in iCloud. After that, or as soon as you choose “Empty Trash”, they are removed from your iCloud too.
- “Delete Permanently” on a child you own (under “Archived Children”) removes it with all its entries from iCloud as well, for everyone it is shared with.
- Entries you make for a child shared with you are stored in the iCloud of the person who shared it and remain there, even if you leave the share.
- Deleting the app removes its data and backups on the device. The exception is the random installation identifier in the keychain, which survives a reinstall. Data in your iCloud remains until you delete it in the app or in iOS Settings under iCloud storage management. Copies in iPhone backups remain until those backups are deleted.
- Backups, exports and reports you passed on remain wherever you put them.
- Emails to the provider are deleted once the request is settled.
8. Your rights
For the processing in section 2 you have the right of access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction (Art. 18), data portability (Art. 20) and objection (Art. 21) against the provider. Write to cuddleya@icloud.com. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR).
You manage the data in the app yourself: you can view, change and delete it at any time and take it with you as an export, backup or report.
9. No automated decisions
Cuddleya makes no automated decisions within the meaning of Art. 22 GDPR and builds no profiles for advertising or analytics. The sleep forecast evaluates your entries only on your device. It is guidance and does not replace medical advice.
10. Changes
If the app changes in a way that affects privacy, we update this policy. The current version at cuddleya.de/en/privacy.html applies.