Privacy Policy
Your baby's story stays yours.
Effective 8 September 2026 · Applies to the Nini app and this website.
Nini is made by Nikola Popović ("we"). This policy says, in plain words, what we collect, why, who touches it, and what you can do about it. If anything here is unclear, write to hello@niniparenting.app.
The short version: no ads, no selling data, no profiling. Everything you enter is there so the app can work for you, and you can export or delete all of it from inside the app.
1. What we collect
Your account
- Name, email address and a password hash — or, if you sign in with Apple or Google, the identifier and email they share with us.
- Your language, unit system, timezone and appearance setting.
- Whether you are on a trial or a subscription, and when it renews or ends (see Purchases).
Your child
- Name, date of birth, sex (for the growth charts), and an optional due date for babies born early.
- An optional photo. It is stored privately and served through short-lived links; it is never public.
- Everything you log: sleep, feeds, nappies, pumping, health entries (temperature, medicine, vitamin D, symptoms), notes, growth measurements, milestones, and foods tried, with any reactions you record.
- Your onboarding answers (for example, whether this is your first baby).
Your conversations with Nini
- The questions you ask the assistant and the answers it gives, kept so you can read them back.
- A photo, if you attach one to a question. It is stored privately like a child's photo and shown back to you through a short-lived link.
- A voice note, if you hold the microphone instead of typing. It is turned into words and the recording is discarded; only the words are kept, as your question.
Your device
- A push notification token, only if you turn notifications on.
- Basic diagnostics when the app crashes (device model, OS version, the error) — never the content of your logs or conversations.
What we never collect
- Card or bank details. Purchases go through Apple or Google; we only learn that a subscription exists and when it ends.
- Your contacts, your location, or anything from other apps.
- Advertising identifiers. There are no ads and no ad tracking.
2. Why, and on what basis
| Purpose | Data | Legal basis (GDPR) |
|---|---|---|
| Running the app: your log, the predictions, sharing with a partner | Account, child, logs | Performance of our contract with you |
| Answering your questions with the assistant | Your question, a summary of recent logs, the child's age | Performance of our contract |
| Nap-window and daily reminders | Push token, prediction | Your consent — off until you turn them on |
| Subscriptions and the free trial | Purchase status from the store | Performance of our contract |
| Keeping the app working and safe | Crash diagnostics, request logs | Our legitimate interest in a working, secure service |
| Answering you when you write to us | Your email and message | Our legitimate interest in supporting you |
We do not use your data for advertising, we do not sell it, and we do not build profiles of you or your child for anyone.
3. Who processes it
We use a small number of providers to run Nini. Each one acts on our instructions, only for the purpose named, and under a data processing agreement.
| Provider | What for | What they see |
|---|---|---|
| Our hosting provider | Running the servers and database | Everything stored in the app, encrypted at rest |
| OpenAI | Generating the assistant's answers; turning voice notes into words | Your question, a photo you attach to it, a voice note, and a short summary of your child's recent logs and age. Not used to train their models. |
| RevenueCat | Subscription status | Your account id, the product and the dates — no payment details |
| Apple and Google | Sign-in (if you choose it), purchases, push delivery | What their own policies describe |
| Expo | Delivering push notifications | Your push token and the notification text |
| Sentry | Crash reports | Device, OS, the error — never log content |
Some of these providers are in the United States. Where data leaves the EEA, it travels under the European Commission's Standard Contractual Clauses or an adequacy decision.
4. The assistant, honestly
- When you ask Nini a question, we send it to OpenAI together with a short, aggregated summary of your child's recent logs (for example: average nap length this week, the last temperature taken) and their age. We do not send your child's name to the model as an identifier beyond what appears in your own message.
- A photo you attach to a question is sent to OpenAI with it, once, shrunk, so the assistant can say what it sees. Only the photo you chose, only for that question; the profile photo of your child is never sent. The assistant will describe, not diagnose.
- A voice note is sent to OpenAI to be turned into words and is not stored by us afterwards. The words come back to you before anything is sent, so you can check them.
- Your conversations are not used to train AI models, by us or by OpenAI.
- The assistant is not a doctor and never diagnoses. It will tell you to see a paediatrician for anything medical, and to contact emergency services for anything urgent.
5. Retention and deletion
- Your data stays as long as your account does. There is no silent expiry of your child's history.
- Delete your account from Settings in the app. Nothing is removed for 7 days, and signing in during that time cancels the deletion. After that, your account, your children's profiles, every log, photo and conversation are erased. Where a partner is still a caregiver of a child, that child's log stays with them; only your account and the notes you wrote go.
- Export a copy of everything as a file from Settings; the link lasts seven days.
- Backups are kept for up to 30 days and then overwritten.
- Records we must keep by law (for example, of a purchase) are kept for the period the law requires and nothing else.
How to delete your account, step by step: Delete your account.
6. Children
Nini is for adults — the parents and carers of babies and toddlers. The information about a child is entered by you, the parent, and is processed for you. We do not knowingly collect any information directly from a child, and the app is not designed to be used by children.
7. Your rights
Wherever you live, you can access, correct, export and delete your data from inside the app. If you are in the EEA, the UK or Switzerland you also have the rights to restrict or object to processing, to withdraw consent (for example, to notifications) at any time, to data portability, and to complain to your data protection authority. We will answer any request within 30 days.
8. Security
Data travels encrypted (TLS) and is stored encrypted at rest. Access to production systems is limited to the people who run them and is logged. Photos are stored privately and served through links that expire. If we ever learn of a breach that affects you, we will tell you and the relevant authority without undue delay.
9. Changes
If we change this policy in a way that matters, we will tell you in the app before it takes effect. The effective date at the top is always the current version.
Contact
Nikola Popović
hello@niniparenting.app