Privacy Policy
Last updated:
This policy explains what information the Chuwe app handles, where it is stored, and what control you have over it. It is written to be understood on a single read.
Chuwe is a tracking and organization tool. It does not provide medical diagnosis, treatment, or medical advice and is not a substitute for guidance from a pediatrician or other healthcare professional.
1. What Chuwe is
Chuwe is a mobile app for tracking a baby's routine: feeding, breastfeeding, pumping, sleep and diaper changes. It is built for parents and caregivers.
By default, Chuwe works with no account and no connection: there is no sign-up, no user, and everything you type stays on your phone.
Starting with version 1.7.0, anyone who wants to share a baby’s history with another caregiver can create an account and turn on cloud sync, an optional feature described in sections 22 through 25. If you never turn it on, none of that applies to you: Chuwe keeps working exactly as it always has.
2. What data it processes
Chuwe processes only what you type into the app:
- the name or nickname you give the baby;
- the sessions you log, with their date, time and duration;
- any notes you choose to add to a session;
- your preferences: language, unit, time format, theme and which activities you want to track.
All of it is saved in the app's private storage, inside your own device. If you never turn on cloud sync (section 22), none of it leaves the device, not even if you turn on the technical metrics in section 13. If you do turn it on, a copy of what you log about your baby is also stored on our server, so the rest of your family can see it, as sections 22 through 25 describe.
Without cloud sync, Chuwe does not ask for or collect your name, email address, phone number, location, contacts or photos. If you turn sync on, we do need to know who you are when you sign in — an email address, or the Google or Apple account you sign in with — as section 23 explains. The free version does show ads, and the Google SDK that serves them processes certain technical device data of its own: section 11 sets out exactly which. If you authorize the performance metrics in section 13, the services that collect them — EAS Observe and, starting with version 1.6.0, Google Firebase — process a further set of technical data, described there.
If you send us feedback from the app, or write to support, we receive whatever you write in that message, as section 27 explains.
3. Feeding information
If you log bottles, the time, the amount, the unit and the milk type you pick — formula or breast milk — are saved. This data stays on your device.
4. Breastfeeding
If you log nursing, the start and end time, the total duration and the time on each side are saved. The timer runs entirely on the device.
5. Pumping
If you log pumping, the session duration and the amount expressed are saved. This data stays on your device.
6. Sleep
If you log sleep, the start and end time of each nap or night-sleep period are saved. Chuwe does not use the camera. The microphone is only ever turned on if you use voice logging, an optional feature described in the next section.
7. Voice logging
Voice logging is an optional Chuwe Premium feature. The microphone never turns itself on: it switches on only when you tap "Dictate" in the logging menu, and off again the moment you finish speaking or leave that screen.
While it is listening, the audio is processed by the operating system's own speech recognizer, on the device. Chuwe never records that audio to a file, never sends it to any server, and never shares it with anyone: the app has no server-side speech recognition mode at all.
What the recognizer understood is shown on screen for you to review before saving. That transcript lives only on that screen: it is discarded the instant you save the entry or cancel it, is never stored on the device, and is never part of the backups you export.
On phones with no local speech recognition for your language, the dictate option does not appear at all; manual logging keeps working exactly as it always has.
8. Preferences
Your settings — language, unit, time format, decimal separator, theme and which activities you track — are stored alongside everything else, on the device. They exist only so the app behaves the way you want.
9. Backups
Chuwe can export everything to a .json file. Your device writes that file and you decide what to do with it: keep it, email it, put it in whichever cloud you use, or delete it.
The exported file is not encrypted and contains everything you have logged, including the baby's name. Treat it like any other personal document.
Chuwe receives no copy of that file and does not know where you keep it.
11. Advertising
The free version of Chuwe shows ads served by Google AdMob. Chuwe Premium shows none at all: with the purchase active the advertising SDK is never even initialised, so your device never contacts the ad network.
To serve an ad, the Google SDK processes technical data about the device and about the request itself:
- the system's advertising identifier, where one is available;
- the IP address, and the approximate country inferred from it;
- the device model and the operating system version;
- information about the ad itself: which one was shown, whether it was seen and whether it was tapped.
Nothing you log in Chuwe reaches the ad network. The ads receive no baby name, no feeds, no sleep, no diapers, none of your notes and no other information from the app, and none of it is ever used to decide what you are shown.
On iPhone, Chuwe does not ask for Apple's tracking permission and does not use the IDFA advertising identifier, so ads on iOS are always non-personalised.
If you are in the European Economic Area or the United Kingdom, you will see Google’s consent form before any ad loads. You can return to that choice at any time from Settings → Ad preferences.
Google acts here as an independent provider and handles that information under its own policies, published at policies.google.com/technologies/ads.
12. Notifications
Chuwe's reminders are local notifications, scheduled by the app on your own device. They do not pass through any push server of ours.
They need the system notification permission. You can revoke it at any time in your phone settings; the app keeps working without them.
13. Analytics
Through version 1.1.0, Chuwe includes no usage analytics of our own: we do not measure which screens you open, how long you spend in the app, or which buttons you tap. The impression and click measurement the ad network performs is a separate matter, applies only to the free version, and is described in section 11.
Starting with version 1.2.0, Chuwe can send technical performance and error metrics to EAS Observe, the analytics service from Expo, the platform the app is built on. It is off by default: the first time you turn it on you will see an explicit prompt, and you can withdraw your authorization at any time from Settings. Versions before 1.2.0 send none of this.
When you authorize it, this is sent: how long the app takes to start and to show each screen, the screen name, the device model, the operating system version, battery level, the device thermal state, and a random identifier for that one app installation. That identifier is not derived from your hardware or from any account, and it is not used to link your activity in Chuwe with other apps; on Android, an automatic system backup can carry it over across a reinstall.
Starting with version 1.6.0, under that same authorization, Chuwe also sends usage events to Google Firebase: what type of entry you created and how you created it — from a timer or from a quick-log shortcut, for instance — whether you completed the app's introduction, and whether you saw the Chuwe Premium screen. Firebase assigns your installation its own identifier, separate from the one EAS Observe uses, with the same properties: random, not derived from your hardware or from any account, and not used to link your activity in Chuwe with other apps. Versions before 1.6.0 send none of this.
On iOS, this measurement does not use the IDFA advertising identifier or the IDFV vendor identifier; on Android it does not use the advertising ID or the Android device identifier (SSAID). That is the difference between an installation carrying a label that lets it be linked to other apps and one that does not: Chuwe always stays in the second case.
Starting with version 1.8.2, with the same authorization, Firebase also receives whether the app asked you for a rating and at what moment — for example, after a purchase or after exporting a backup —, whether you opened the store page from Settings, whether you started, sent or cancelled a piece of feedback and which category and overall rating it had, and whether you tapped “Share Chuwe” or “Contact support”. Never the text of your feedback (section 27).
Starting with version 1.8.3, with the same authorization, Firebase also receives: the name of each screen you open; whether you started or discarded a timer and what kind it was (breastfeeding, pumping, nap or night sleep); whether an entry was made by voice, never what you said; whether you opened the Chuwe Premium screen from Settings, from “Remove ads” or from the family plans; whether you started, completed or restored a purchase and for which plan, never the price or the receipt; and whether you archived or restored a baby’s profile, without their name. Firebase also stores three characteristics of your installation so these figures can be grouped: whether you use the free version, Premium or a family plan; how many active babies you have, in ranges (one, two, or three or more); and the language you chose in Chuwe.
None of what you log about your baby is part of this measurement, whether it is collected by EAS Observe or by Firebase: not feedings, not diapers, not sleep, not notes, not the name you give the baby, not the date or the identifier of any session.
If what is measured changes in the future, this policy will be updated and it will be disclosed before it starts running.
14. Crash reporting
Until you authorize the metrics in section 13, Chuwe sends no crash reports. If the app fails, nothing reaches us unless you write to us.
Starting with version 1.2.0, if you authorize those metrics, unhandled JavaScript errors that occur while you use the app are included in the same technical upload: what kind of error it was and on which screen, never the content of whatever you had logged at the time. Withdrawing authorization in Settings stops these reports too. Versions before 1.2.0 send no crash reports under any circumstances.
Starting with version 1.6.0, under that same authorization, Chuwe also sends native iOS and Android crashes — the ones that were not collected before — to Firebase Crashlytics: which part of the system failed and on which device model and operating system version, never the content of whatever you had logged at the time. Withdrawing authorization in Settings stops these reports too, and versions before 1.6.0 send no native crash reports under any circumstances.
Apple and Google may separately offer to share system diagnostics with developers. That is controlled by you in your device settings and governed by their own policies.
15. Third parties
Chuwe is distributed through the App Store and Google Play. Downloads, updates and any purchase are governed by the policies of Apple and Google, who act independently of us.
The free version additionally integrates Google AdMob to show ads, on the terms in section 11. Starting with version 1.2.0, if you authorize the metrics in section 13, the app sends that technical data to EAS Observe, the analytics service from Expo; starting with version 1.6.0, under that same authorization, it also sends it to Google Firebase, described in sections 13 and 14. Beyond that, the app integrates no social networks and no external storage providers, and with Chuwe Premium no ad network is contacted at all.
If you turn on cloud sync, we additionally engage Amazon Web Services (AWS) as a data processor: it hosts account identity (Amazon Cognito), the connection between your phone and our server (AWS AppSync), the storage of your family’s records (Amazon DynamoDB), the sign-in code email (Amazon SES), and the server’s technical logs (Amazon CloudWatch). AWS acts only on our instructions, never its own, and does not use that information for anything other than running Chuwe.
If you choose to sign in with Google or with Apple, that provider receives the fact that someone with that account signed in to Chuwe — the same as with any app that offers “Sign in with Google” or “Sign in with Apple” — but never receives any data about your baby from us: no names, no records, no notes.
If you send us feedback from the app (section 27), it is received by a service of ours hosted on AWS (AWS Lambda, in the Ireland region), which forwards it to us by email with Amazon SES. This happens whether or not you use cloud sync, and AWS likewise acts only on our instructions.
16. Retention
Without cloud sync, your information stays only on the device for as long as the app is installed. If you uninstall Chuwe, the operating system deletes the app's storage, and your records with it.
So if you want to keep them, or move them to another phone, export the file before uninstalling.
With sync turned on, your family’s records stay on our server for as long as the family exists: they are deleted when the owner deletes the family, or when the account that created it is deleted with nobody else in it (section 25). The server’s technical logs — which carry none of your baby’s data — are kept for a limited time meant for debugging errors, and are then deleted automatically.
If a sign-in email cannot be delivered, is slow to arrive or is marked as spam, we keep the address, the date, the reason the mail server gave and the subject of the message (which is always the same and does not include the code) for 30 days, so we can help you. We never keep the body of the message. If the email bounces or the recipient marks it as spam, the address also goes on a “do not send” list at Amazon SES, and you will not receive sign-in codes until we remove it; you can ask us to do so by writing to support@chuweapp.com.
Feedback you send us arrives in our support inbox as an email, and we keep it for as long as we need to deal with it and for 24 months at most. The service that forwards it does not keep the text: its technical logs only record the category, the platform and whether sending succeeded, and are deleted after 30 days.
17. Security
Chuwe's data lives in the private area iOS and Android reserve for each app, protected by the system itself and by your device lock.
No measure is absolute. Keep your system updated, use a screen lock, and store exported files somewhere you trust.
If you turn on sync, the connection between your phone and our server always travels encrypted (TLS), and the records we keep on the server are encrypted at rest. You only see and change your own family’s records: every request is checked against who you are and which family you belong to before it is answered.
The only session data we keep on your phone is what lets you stay signed in without signing in every time; it is stored in the operating system’s own secure storage (iOS Keychain or Android Keystore), never in the file you export or in any backup.
18. Children's privacy
Chuwe is intended for adults: parents and caregivers. It is not designed to be used by children and does not collect information directly from them.
Information about the baby is entered by an adult and stays under that adult’s control, on their own device.
That is why Chuwe is not declared as an app directed at children, which would place it under rules it does not belong to. The ad network is, however, asked to serve only the most general content rating, suitable for all audiences.
19. Your rights
Without cloud sync, all of your information is on your device and not in our systems, so you exercise your rights directly from the app:
- access: everything logged is visible in the history and the calendar;
- portability: the .json export hands you your complete data in an open format;
- rectification: any session can be edited;
- erasure: deleting a session, meal, event or milestone removes it from everything you see in Chuwe, but it stays hidden, with its notes, in the file on your phone and in any backup you export, so a deletion can be undone and, later, synchronised. To erase everything, use Settings → Export / import → Delete all data (which also deletes the safety copies), or uninstall the app.
Without sync, we cannot hand over or delete data on your behalf, because we never hold it. If you turned on cloud sync, we do hold something of yours on the server, and you can ask to access it or delete it: section 25 explains how, what is deleted and what is kept.
20. Changes to this policy
If this policy changes, the date in the header is updated. Material changes — for example, if analytics is ever added — will also be announced inside the app.
21. Contact
For any privacy question, write to us at support@chuweapp.com.
22. Cloud sync (Family Cloud Sync)
Starting with version 1.7.0, Chuwe optionally offers cloud sync, to share a baby’s history among several caregivers in the same family. It is off out of the box: nothing you log leaves the device until you explicitly create or join a family in the cloud.
Once you turn it on, what you and the rest of your family log about each baby is uploaded to our server:
- the family’s baby profiles;
- the sessions you log: feeds, breastfeeding, pumping, sleep and diapers;
- solid food, observed events and milestones;
- any custom foods you have created.
It does not upload your phone’s settings: language, unit, time format, theme, which activities you track, or your reminders. Those belong to each phone, not to the family, and stay put.
Your family’s records are stored in the AWS region chosen by whoever creates the family, among the regions we offer at the time. Today that list holds a single region: eu-west-1. Only members of that family can read or write to it: every request to the server is checked against who you are and which family you belong to before it is answered. This information is never used for ads or for the analytics described in sections 11 and 13.
If you never turn sync on, none of sections 22 through 25 applies to you: Chuwe keeps working with no account and no connection, as section 1 describes.
23. Accounts and sign-in
Creating or joining a family in the cloud requires an account. You have a single Chuwe identity, hosted in eu-west-1, regardless of which region your family’s records live in: one account directory, one account per person.
These are the ways to sign in, and you can use whichever you prefer:
- with your email address and the password you created when you opened the account;
- with a one-time code we email you, sent through Amazon SES;
- with a passkey, if you registered one;
- with your Google account;
- with Sign in with Apple.
When you create the account with an email address, the sign-in screen asks you for a password. Amazon Cognito, our identity provider, stores that password; we do not see it and do not store it ourselves. With Google or Apple there is no password or passkey of ours.
If you sign in with Google or with Apple, that provider receives the fact that someone with that account signed in to Chuwe, the same as with any app that offers “Sign in with Google” or “Sign in with Apple”. We never send them any data about your baby.
When you create the account, the sign-in screen suggests you register a passkey. Of it we store only the public key and some metadata; the private key never leaves your device or your password manager, and we never see it. The domain you will see when you save it is auth.chuweapp.com, which is ours, not a third party’s.
If you delete your account, your password and your passkeys are deleted too: they live in Amazon Cognito and go with your account.
Without deleting the account, you can see your passkeys and remove the ones you do not want from the app, in Settings → Family → Passkeys; a removed passkey stops working for signing in to Chuwe. Either way, the entry that may remain in your phone’s keychain is yours to remove, from your phone’s own settings.
Face ID, Touch ID or your fingerprint are never data Chuwe receives, stores or processes: they are the verification your phone’s own operating system performs to unlock your passkey’s private key, and that verification never leaves the device.
24. Purchases and the Family Cloud Sync subscription
The subscription that turns on sync for your whole family is bought through the App Store or Google Play, under the same rules as any purchase inside Chuwe (section 10): the store handles the payment and Chuwe never sees your card, your billing address, or any other payment detail.
When you buy, the app sends the store an anonymous identifier of your account — not your email, not your name — so the store can later tell us which account a purchase belongs to. Apple calls it appAccountToken and Google calls it obfuscatedAccountId; both are that same anonymous identifier.
When Apple or Google notify us of a purchase, a renewal, a cancellation or a refund — after we check that the notification is genuinely theirs — we store on our server one ledger row per subscription with:
- its status: active, in a free trial, in billing retry, cancelled, refunded…;
- what was bought and its renewal or expiry dates;
- the identifier the store itself gives that notification, so it is never processed twice.
None of that includes your card or your payment method: that never reaches our server, only Apple or Google.
Anyone who already bought Chuwe Premium can activate three months of Family Cloud Sync without paying again. To do that we verify with the store that the Premium purchase is genuinely yours, the same way a subscription is verified. This gift is granted once per Premium purchase, forever: if you delete your account after claiming it, we keep a hash of that purchase — not your email, not your name, not your account identifier — solely so the same purchase cannot claim a second gift under a new account.
Deleting your account also deletes this purchase history, except for that unidentified hash, as section 25 describes.
25. Deleting your cloud account
You can ask us to delete your account in two ways:
- from the app: Settings → Family → Delete my account, with two confirmation steps because it cannot be undone;
- without the app, by writing to support@chuweapp.com, or from chuweapp.com/delete-account, the page that explains the same procedure for anyone who no longer has Chuwe installed.
Deleting your account deletes, on our server:
- your account and your place in every family you were in;
- a family you owned that had nobody else in it, with everything it contains;
- your purchase and subscription history (section 24);
- your password and any passkeys you had registered (section 23).
It does not delete: the records of a family with other people in it — those stay with them, without you —, the unidentified hash from section 24 for the three-month gift, or your recorded history on this phone, which deleting the account does not touch: it stays exactly where it was, whether or not it was also on your family’s server. It also does not delete what another caregiver already downloaded to their own phone before you left the family.
If you own a family with other people in it, you have to remove them or dissolve the family first: the app asks you to before letting you continue, so nobody is left out without knowing it.
If you write in to ask without using the app, we process the request within 15 days at the latest.
If you signed in with Apple, we cannot revoke that authorization on your behalf: the managed sign-in we use does not let us. We delete everything of ours, and to also remove the Apple connection, go to appleid.apple.com → Sign-In & Security → Sign in with Apple → Chuwe → Stop using Sign in with Apple, or on your iPhone, Settings → your name → Sign-In & Security → Sign in with Apple.
26. This website (chuweapp.com)
This site sets no cookies of its own. If you accept it in the notice shown when you visit, we use Google Analytics, through Google Firebase (the same provider as in section 13), to learn how many people visit and how they use it. Until you accept, or if you decline, nothing from Google is loaded.
With your permission, we collect:
- which pages you visit and when, and from what type of device and browser;
- your approximate country or region, which Google infers from the connection;
- the language of the page;
- whether you tap the App Store or Google Play buttons, and whether you reach the plans section.
We never collect what you type, your name, your email, or any data from the app or about your baby.
To tell one visit from another, Google Analytics stores cookies in your browser (_ga and _ga_…). We turn off Google signals and ad personalisation: nothing measured here is used for advertising. Google may process this data outside your country, including in the United States, and we keep it for 2 months. Your answer to the notice is stored only in your browser.
You can change your choice at any time from «Cookie preferences», at the bottom of every page. If you decline, we stop measuring and delete those cookies.
27. Ratings, feedback and support
Starting with version 1.8.2, Chuwe may occasionally ask you to rate it on the app store. That request is shown by Apple’s or Google’s own system, and your answer is handled by the store: Chuwe does not know whether you rated it or what you wrote. So as not to ask too often or at a bad moment, the app keeps a few counters on your device only — since when you have used it, on how many different days, and how many times and when it asked. None of that leaves your phone or goes into backups.
In Settings → “Help Chuwe” you can send us feedback. It is optional and is only sent when you tap “Send”. We receive:
- your overall rating, if you choose one (from “Love it” to “Bad”);
- the category you choose, for example “Bug or error” or “Missing feature”;
- the text you write;
- the app version, whether you use iOS or Android, and the app language.
We do not send your name, your email, your account, any identifier or anything you log about your baby. The only thing we cannot control is what you write, so please do not include your baby’s name or details. Because we do not know who sent each piece of feedback, we cannot reply to it; if you want a reply, use “Contact support”.
“Contact support” opens your email app with a message addressed to support@chuweapp.com, with the app version, the system and the language already filled in. If you send it, we receive your email address and what you write, and use them only to reply to you. If there is no connection when you send feedback, the app offers to send it by email in the same way.
“Share Chuwe” opens the system share menu with a message and the link to chuweapp.com. You choose who to send it to and how; Chuwe does not know who you sent it to.
We use feedback only to decide what to improve in Chuwe. If you want us to delete a piece of feedback, write to support@chuweapp.com telling us what you wrote and when, and we will find it and delete it.
