1. Who We Are
In It Together (“the App,” “our Service”) is a co-parenting coordination application that helps families manage tasks, calendars, chat, health tracking, sleep and feeding logs, finances, and related parenting data. The App is operated by NAAN LLC (“we,” “us,” “our”).
If NAAN LLC transfers its operations to a successor entity, this Privacy Policy will remain in effect and the successor entity will assume all obligations described herein. We will notify you of any such change.
This Privacy Policy applies to all versions of the App (iOS, Android, and web) and any companion hardware devices we may offer, including the Baby Station Puck. By using the App, you agree to the collection, use, and sharing of your information as described in this Policy.
2. Information We Collect
We minimize data collection to what is necessary to provide the App’s features. We collect information in three categories.
2.1 Information You Provide Directly
- Account Information: Phone number (used for authentication via one-time passcode), display name, and optional profile photo.
- Family & Member Data: Family name, member roles (e.g., Owner, Parent, Step Parent, Grandparent, Nanny, Babysitter), caregiver types, and access permissions you configure.
- Children’s Information: Names, dates of birth, optional photos, and notes you add about your children.
- Tasks & Events: Task titles, descriptions, priorities, due dates, assignments, subtasks, recurring schedules, comments, calendar event details, and location names or coordinates when you choose to add them.
- Chat Messages: Text messages, emoji reactions, and read-receipt states within family chat channels you create.
- Health Records: Medications, allergies, vaccines, insurance card details, pediatrician information, and other health-related information you enter for your children.
- Sleep & Feed Data: Sleep session start/stop times, sleep type (nap vs. night), quality ratings, feeding type (breast or bottle), amounts, durations, side (left/right), and associated notes.
- Diaper Data: Diaper change logs including type (wet, dirty, mixed, diarrhea, dry), timestamps, and notes.
- Finance & Expense Data: Expense amounts, categories, descriptions, split allocations between parents, budget targets, and settlement records. (Available when this feature launches.)
- Voice Input Data: When you use our voice-logging feature, we capture a temporary audio recording to convert your speech to text. The audio is processed for transcription only and is not persistently stored. We retain the resulting text transcript and the structured event data parsed from it. Each voice-logged record is tagged with source: “voice” so you can identify how it was created.
2.2 Information Generated Automatically
- Device Tokens: Firebase Cloud Messaging (FCM) tokens for delivering push notifications.
- Usage Analytics: Anonymized and aggregated interaction data (e.g., feature usage counts, session duration) collected via Firebase Analytics. This data cannot identify you personally.
- Crash & Performance Data: Diagnostic data collected via Firebase Crashlytics, which may include device model, OS version, and error stack traces. It does not include your personal content.
- Log Data: Server-side logs may include IP addresses, access timestamps, and request metadata, retained for security and debugging only.
2.3 Information We Do Not Collect
We want to be explicit about data we do not access:
- We do not access your phone’s contacts, photo library, or files (beyond photos you explicitly upload as profile pictures or child avatars).
- We do not collect precise GPS location in the background. Location coordinates are stored only when you manually add a location to a calendar event.
- We do not use cookies or tracking pixels in the mobile App. (See Section 11 for the web version.)
- We do not collect biometric identifiers. Voice audio used for voice-logging is processed transiently for speech-to-text conversion and is not used to create voiceprints or biometric templates.
3. How We Use Your Information
We use collected information solely for the following purposes:
- Provide, operate, and maintain the App’s co-parenting features, including real-time synchronization between family members.
- Authenticate your identity and secure your account via phone OTP.
- Deliver push notifications about tasks, events, messages, and reminders you have configured.
- Process voice input to create structured event logs (e.g., converting a spoken phrase into a diaper change or feed record).
- Improve the App through aggregated, anonymized analytics.
- Diagnose and fix bugs using crash reports and performance data.
- Respond to your support requests and communications.
- Comply with legal obligations and enforce our Terms of Service.
4. Legal Bases for Processing
Depending on your jurisdiction, we process your personal information under one or more of the following legal bases:
- Contract Performance: Processing necessary to deliver the features described in our Terms of Service.
- Consent: Where you have given explicit consent, such as enabling microphone access for voice logging or opting into push notifications. You may withdraw consent at any time.
- Legitimate Interest: Processing for our legitimate business interests (e.g., improving the App, diagnosing bugs), balanced against your rights.
- Legal Obligation: Processing necessary to comply with applicable laws or respond to valid legal process.
5. How We Share Your Information
We do not sell, rent, or trade your personal information. We share data only in the following limited circumstances:
5.1 Within Your Family Group
Data you enter is visible to other members of your family group based on the permissions configured by you or the family Owner. You control who is in your family group and can remove members at any time.
5.2 Service Providers
We use third-party service providers that process data on our behalf. These providers are contractually bound to use your data only as we instruct and to maintain appropriate security.
| Provider | Purpose | Data Processed |
|---|---|---|
| Google Firebase (Firestore, Auth, FCM, Crashlytics, Analytics) | Infrastructure, authentication, notifications, crash reporting, anonymized analytics | App data, phone number, device tokens, crash logs, anonymized usage events |
| Google Cloud Speech-to-Text | Voice-to-text transcription | Temporary audio stream (not stored after transcription) |
| Google Places API | Location autocomplete for calendar events | Search queries when you type a location (no persistent tracking) |
| RevenueCat (future) | Subscription management | Purchase tokens, subscription status (no health or child data) |
We will update this table as we add or change service providers. We will not introduce a new provider that processes your health, child, or chat data without updating this Policy and, where required by law, obtaining your consent.
5.3 Legal Requirements
We may disclose your information if required by law, regulation, legal process, or governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others, investigate fraud, or respond to a government request.
5.4 Business Transfers
If NAAN LLC is involved in a merger, acquisition, or asset sale, your information may be transferred as part of that transaction. We will notify you before your data becomes subject to a different privacy policy.
6. Children’s Privacy (COPPA Compliance)
The App is designed for use by adults (parents and caregivers). It is not directed at children under 13 (or under 16 in jurisdictions where that threshold applies), and we do not knowingly collect personal information directly from children.
All information about children stored in the App — such as names, birth dates, health records, and tracking data — is entered and managed exclusively by authorized adult family members. Children do not create accounts, interact with the App, or provide data to us directly.
If we learn that we have inadvertently collected personal information directly from a child under 13, we will delete that information promptly. If you believe a child has provided us information directly, please contact us at the address in Section 19.
7. Sensitive Data & Health Information
The App stores data that may be classified as “sensitive” or “health data” under certain laws, including sleep patterns, feeding records, diaper logs, medications, allergies, and temperature readings. We treat all such data with heightened care:
- This data is collected solely because you choose to enter it to coordinate care for your child.
- We do not use health-related data for advertising, profiling, or any purpose other than providing the App’s features to your family.
- This data is encrypted in transit (TLS 1.2+) and at rest within Google Firebase’s infrastructure (AES-256).
- Access is restricted to members of your family group via Firestore security rules that enforce family-level data isolation.
- We do not share health-related data with insurers, employers, data brokers, or any third party except the infrastructure providers listed in Section 5.2.
8. Voice & Audio Data
Several U.S. states (including Illinois, Texas, and Washington) have laws governing biometric data and audio recordings. Here is how we handle voice data:
- Purpose: Voice audio is captured solely to transcribe your speech into text for event logging (e.g., you say “dirty diaper” and the App logs a diaper change).
- Processing: Audio is streamed to Google Cloud Speech-to-Text (or processed on-device when offline) for transcription. The audio stream is not stored by us after the transcript is generated.
- No Biometric Use: We do not create, store, or use voiceprints, speaker identification models, or any biometric identifiers derived from your voice.
- Consent: The App requests microphone permission before first use of voice logging. You can revoke this permission at any time in your device settings.
- Transcript Retention: The text transcript is stored on the resulting event document for debugging and accuracy improvement. You can delete any voice-logged event, which removes the associated transcript.
9. Hardware Companion Device (Baby Station Puck)
We are developing an optional hardware device (the “Puck”) for bedside logging. When available, the Puck will:
- Transmit event data (diaper, feed, sleep logs) to your In It Together account via Wi-Fi and Firestore.
- Not include a microphone or camera. It does not record audio or video.
- Require pairing to an authenticated In It Together account. It cannot operate independently or share data outside your family group.
- Receive over-the-air (OTA) firmware updates. Update metadata (device ID, firmware version) will be transmitted to our servers.
We will update this section with additional detail before the Puck ships. No personal data from the Puck will be shared with third parties beyond the service providers listed in Section 5.2.
10. Data Storage & Security
10.1 Infrastructure
All data is stored on Google Firebase (Cloud Firestore and Firebase Authentication), hosted in the United States. Data is encrypted in transit using TLS 1.2 or higher and encrypted at rest using AES-256 within Google’s infrastructure.
10.2 Access Controls
- Firestore security rules enforce family-level data isolation. Users can only read and write documents belonging to their own family.
- Authentication requires phone OTP via Firebase — no passwords are stored.
- Role-based permissions (Owner, Parent, Step Parent, Grandparent, Nanny, Babysitter) are enforced both client-side and server-side.
10.3 Offline Data
The App uses Firestore’s offline cache (approximately 20 MB) so features work without connectivity. Cached data is stored locally on your device and syncs when connectivity resumes. This local cache is subject to your device’s own security protections (passcode, biometric lock, device encryption).
10.4 Breach Notification
While we implement industry-standard security measures, no method of electronic storage or transmission is 100% secure. In the event of a data breach affecting your personal information, we will notify affected users consistent with applicable breach notification laws and within the timeframes those laws require.
11. Cookies & Tracking Technologies
The mobile App does not use cookies or tracking pixels. If you access the App via the web, Firebase may use essential cookies for authentication and session management. We do not use advertising cookies or third-party tracking technologies in any version of the App.
We honor Do Not Track (DNT) browser signals. Because we do not engage in cross-site tracking, no additional action is taken when a DNT signal is detected.
12. Data Retention
- Active Accounts: We retain your data for as long as your account is active and you have not requested deletion.
- Deleted Accounts: If you delete your account, we will delete or anonymize all your personal data within 30 days, except where retention is required by law (e.g., financial transaction records, legal hold requirements).
- Voice Audio: Transient only. Not stored after transcription is complete.
- Text Transcripts: Stored on the event document. Deleted when the event is deleted or the account is deleted.
- Crash Logs: Retained for up to 90 days, then automatically purged by Firebase Crashlytics.
- Analytics Data: Aggregated and anonymized. Cannot be traced back to individual users. Retained indefinitely in aggregate form.
- Completed Tasks: Displayed in the App for a rolling 30-day window but retained in Firestore for the life of the account to support historical reference. Deleted upon account deletion.
13. Your Rights
Depending on where you live, you may have some or all of the following rights:
| Right | Description | How to Exercise |
|---|---|---|
| Access | Request a copy of the personal data we hold about you. | Contact us or use the in-app export feature (coming soon). |
| Correction | Request correction of inaccurate data. | Edit directly within the App, or contact us. |
| Deletion | Request deletion of your personal data and account. | Use the in-app account deletion feature, or contact us. |
| Portability | Receive your data in a structured, machine-readable format. | Contact us. We will provide a JSON export. |
| Opt-Out of Sale | Opt out of the “sale” of personal information. | Not applicable — we do not sell your data. |
| Withdraw Consent | Withdraw previously given consent (e.g., microphone, notifications). | Adjust permissions in device settings, or contact us. |
| Appeal | Appeal a decision regarding your privacy request. | Contact us. We will respond within the timeframe your state requires. |
| Non-Discrimination | Exercise your rights without discriminatory treatment. | We will never penalize you for exercising your privacy rights. |
We will respond to verified requests within 30 days (or sooner where required by applicable law). We may ask you to verify your identity before processing a request to protect your account.
14. State-Specific & International Disclosures
14.1 California (CCPA / CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act. In the preceding 12 months:
- Categories of personal information collected: identifiers (phone number, name), health-related data (sleep, feed, diaper, medication records), geolocation (event locations only), internet/electronic activity (anonymized usage analytics), and audio data (voice logging transcripts).
- We have not sold personal information to any third party.
- We have not shared personal information for cross-context behavioral advertising.
- We do not use or disclose sensitive personal information for purposes beyond those necessary to provide the App.
You may designate an authorized agent to submit requests on your behalf. Contact us at the address in Section 19.
14.2 Washington (My Health My Data Act)
If you are a Washington resident, the health-related data you enter (sleep, feed, diaper, medication, temperature, and allergy data) may constitute “consumer health data” under the Washington My Health My Data Act. We collect this data only with your consent and solely to provide the App’s tracking features. We do not sell consumer health data. We do not use geofencing in connection with health data or health service facilities.
14.3 Illinois, Texas & Other Biometric Privacy States
The App’s voice-logging feature does not collect biometric identifiers or biometric information as defined under the Illinois Biometric Information Privacy Act (BIPA), Texas Capture or Use of Biometric Identifier Act, or similar state laws. Audio is processed transiently for speech-to-text and is not used to identify individuals. See Section 8 for full details.
14.4 Other U.S. States
Residents of states with comprehensive privacy laws (including but not limited to Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, and Maryland) may have rights similar to those listed in Section 13. We will honor verified requests consistent with applicable state law. If your state provides a right to appeal, you may appeal by contacting us; we will respond within the timeframe required by your state.
14.5 International Users (GDPR / UK GDPR)
If you access the App from the European Economic Area, United Kingdom, or Switzerland:
- Legal bases for processing are described in Section 4.
- Data is transferred to the United States, where our infrastructure is hosted. We rely on Standard Contractual Clauses and Google’s data processing agreements to provide appropriate safeguards for international data transfers.
- You have the right to lodge a complaint with your local data protection supervisory authority.
- Our data protection contact is listed in Section 19.
15. Location Data
The App stores location coordinates only when you explicitly add a location to a calendar event using the in-app search (powered by Google Places API). We do not track your location in the background. We do not use geofencing. Location data is shared only within your family group.
16. Push Notifications
We use Firebase Cloud Messaging (FCM) to deliver push notifications about tasks, events, chat messages, and reminders. You can disable notifications at any time through your device settings. We store only the FCM device token needed to deliver notifications and delete it when you log out or delete your account.
17. Third-Party Links & Services
The App may contain links to third-party websites or services (e.g., a pediatrician’s website you save in health records). We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- An in-app notification or banner.
- A push notification (if you have notifications enabled).
- Updating the “Last Updated” date at the top of this Policy.
Your continued use of the App after a material change constitutes acceptance of the updated Policy. If you do not agree with the changes, you may delete your account as described in Section 13.
19. Contact Us
If you have questions about this Privacy Policy, want to exercise your privacy rights, or have a concern about your data, contact us:
Email: naanlabs@gmail.com
Entity: NAAN LLC
We aim to respond to all inquiries within 30 days or sooner where required by law.