Privacy Policy
Last updated: December 2024
Your privacy is critically important to us. This policy explains how Sprout Diary collects, uses, and protects your personal information.
Quick Overview
Here's what you need to know about your privacy at Sprout Diary:
Encrypted & Secure
All your journal entries and photos are encrypted and stored securely.
Private by Default
Only you and invited family members can access your content.
Never Sold
We will never sell or share your data with third parties for marketing.
You're in Control
Export or delete your data anytime. It's your information.
1. Information We Collect
1.1 Information You Provide
When you use Sprout Diary, you provide us with:
- Account Information: Email address, name, password
- Profile Information: Profile photo, family pod name, child profiles
- Journal Content: Journal entries, photos, videos, voice recordings
- Milestone Data: Developmental milestones, dates, descriptions
- Payment Information: Processed securely through our payment provider
1.2 Automatically Collected Information
We automatically collect certain information when you use our service:
- Device Information: Device type, operating system, app version
- Usage Data: Features used, time spent, interaction patterns
- Log Data: IP address, browser type, access times
- Analytics: Aggregated usage statistics to improve our service
2. How We Use Your Information
We use your information to:
- Provide, maintain, and improve Sprout Diary services
- Store and sync your journal entries across devices
- Process payments and manage subscriptions
- Send important service notifications and updates
- Provide customer support and respond to inquiries
- Generate AI-powered insights (Pro feature, opt-in only)
- Analyze usage patterns to improve user experience
- Prevent fraud, abuse, and security issues
3. Data Storage and Security
We take your data security seriously:
- Encryption: All data is encrypted in transit (TLS/SSL) and at rest
- Secure Storage: Data stored on enterprise-grade cloud infrastructure (Supabase/AWS)
- Access Controls: Strict access controls and authentication required
- Regular Backups: Automatic backups to prevent data loss
- Security Monitoring: Continuous monitoring for security threats
- Data Isolation: Pod-based architecture ensures family data stays separate
4. Data Sharing and Disclosure
We do not sell your personal information. We only share data in these limited circumstances:
- Within Your Pod: Content is shared with family members you invite
- Service Providers: Trusted partners who help us operate (hosting, payment processing, analytics)
- Legal Requirements: When required by law or to protect rights and safety
- Business Transfers: In the event of a merger or acquisition (with notice)
- With Your Consent: When you explicitly authorize sharing
4.1 Third-Party Services
We use the following trusted third-party services:
- Supabase: Database and authentication (PostgreSQL on AWS)
- RevenueCat: Subscription management and payment processing
- Google Gemini API: AI-powered features (Pro only, opt-in)
- Expo: Mobile app infrastructure and push notifications
5. Children's Privacy
Sprout Diary is designed for families with children, and we take children's privacy seriously:
- Parents/guardians must be at least 18 years old to create an account
- Child profiles are managed by adult family members
- We comply with COPPA (Children's Online Privacy Protection Act)
- Children's data is not used for advertising or marketing
- Parents have full control over their children's information
- Parents can delete child profiles and all associated data at any time
6. Your Rights and Choices
You have the following rights regarding your data:
- Access: Request a copy of your personal data
- Correction: Update or correct inaccurate information
- Deletion: Request deletion of your account and all data
- Export: Download your journal entries and photos (PDF/JSON)
- Portability: Transfer your data to another service
- Opt-Out: Disable AI features, analytics, or marketing emails
- Restrict Processing: Limit how we process your data
To exercise these rights, contact us at contact@sproutdiary.com
7. Data Retention
We retain your data for as long as your account is active or as needed to provide services. When you delete your account, we permanently delete your data within 30 days, except where we're required to retain it by law (e.g., tax records, legal disputes).
8. Cookies and Tracking
We use cookies and similar technologies to:
- Keep you logged in and remember your preferences
- Understand how you use our service (analytics)
- Provide personalized experiences
- Improve security and prevent fraud
You can control cookies through your browser settings. Note that disabling cookies may affect functionality.
9. International Data Transfers
Your data may be transferred to and processed in countries other than your own. We ensure appropriate safeguards are in place to protect your information in compliance with applicable data protection laws (GDPR, CCPA, etc.).
10. Changes to This Policy
We may update this Privacy Policy from time to time. We'll notify you of significant changes via email or in-app notification. Your continued use of Sprout Diary after changes constitutes acceptance of the updated policy.
11. Contact Us
If you have questions or concerns about this Privacy Policy, please contact us:
Email: contact@sproutdiary.com