Privacy Policy
Your baby's log lives in your iCloud Drive, not on our servers. This page explains exactly what that means.
Effective 28 September 2026
The short version
- Vivi Baby needs no account. There is no sign-up, no password and no profile, and we never learn your name or email through the app.
- Everything you log (feeds, sleep, diapers, growth, health notes, journal entries and photos) is stored as files in your own iCloud Drive and on your devices. We cannot see, read or recover it.
- You decide who else sees it. When you invite a caregiver, Apple's iCloud sharing gives them access to your family folder.
- The app contains no analytics, no advertising, no crash-reporting service and no third-party tracking SDK.
- The one exception: shared timers pass through a small relay server we run, which sees anonymous timer state only. Never names, notes, photos, measurements or history.
Where your information lives
| Information | Where it is | Reaches us? |
|---|---|---|
| Entries: feeds, sleep, diapers, pumping, routines | Your iCloud Drive + your devices | No |
| Children's names, birth dates, growth, health, vaccines, teeth, milestones, firsts | Your iCloud Drive + your devices | No |
| Journal entries, notes, checkup questions and photos | Your iCloud Drive + your devices | No |
| Settings, reminders and the dock layout | Your iCloud Drive + your devices | No |
| A running timer: its kind, start time, side and paused state, under random IDs | Our timer relay, briefly | Yes, anonymously (see below) |
| Push tokens for Live Activities | Our timer relay, encrypted | Yes, encrypted |
| Siri requests | Apple | No |
| Your name, email, contacts, location | Never accessed | No |
Who this policy is from
Vivi Baby is published by Tommy Bergeron (Brainpad Consulting), based in Quebec, Canada, referred to here as "we". This policy covers the Vivi Baby app for iPhone and Apple Watch and this website, vivibaby.app.
Under Quebec's Law 25, the person responsible for the protection of personal information must be identified. For Vivi Baby that is Tommy Bergeron, reachable at support@brainpad.org. Write to that address about anything in this policy, including a request to exercise any right described below.
No account needed, and no server for your baby's log
You do not sign up for Vivi Baby. It uses the Apple Account already on your iPhone, through iCloud Drive, and we never receive that account's name, email or identifier. We do not run a service that receives, stores or processes what you log.
The app contains no analytics framework, no crash-reporting service, no advertising identifier and no third-party tracking SDK. Its only third-party code library reads and writes YAML files. If you have chosen in iOS Settings to share analytics with app developers, Apple may send us anonymous crash reports and usage statistics under Apple's own terms; you can turn that off in Settings → Privacy & Security → Analytics & Improvements.
Your iCloud Drive
Vivi Baby stores each family as a folder named "Vivi Baby" in your iCloud Drive. Entries are Markdown files with YAML front matter, settings are YAML files, and photos are HEIC images. You can open them in the Files app or any text editor, with or without Vivi.
iCloud is your Apple account and your storage. We have no access to it and no ability to read, list or recover anything in it. What is in iCloud is governed by Apple's privacy policy and your iCloud settings, including Advanced Data Protection if you turn it on.
Each device also keeps a local index of your entries so that History, Trends and Search are fast. It is a cache built from the files, stays on that device, and is deleted with the app.
Sharing with caregivers
When you invite someone to your family, iOS shares your family folder with their Apple Account through iCloud collaboration. Everyone you invite can see and change everything in that family: entries, children's details, notes and photos. Each entry records which caregiver saved it, using the name they chose in the app. You can stop sharing with someone at any time from the Files app or in Vivi, which is handled by Apple, not us.
Shared timers and the relay
So that a timer started on one phone appears on another phone's Lock Screen within seconds, Vivi uses a small relay server that we operate on Cloudflare Workers. It is the only server of ours the app talks to. It receives:
- The state of running timers: whether it is a sleep, breastfeed, combo or pump timer, its start time, the side, whether it is paused, and when it stopped.
- Random identifiers for your family's timer channel, each timer, child and caregiver. They are generated by the app and are not linked to your name or Apple Account.
- Hashed credentials for each device in the family, so only your family's devices can read your channel.
- Live Activity push tokens issued by Apple, stored encrypted, so the relay can ask Apple's Push Notification service to update a timer on the other phones.
It never receives names, notes, photos, measurements, entry history, iCloud file locations or Apple Account identifiers. Request logging is turned off. A timer's live state is removed when the timer ends and expires after 48 hours at most; a device's membership expires after 90 days without contact; records of stopped timers are kept for seven days so every device can settle on the same result. Cloudflare may keep backup copies of stored data for up to 30 days. Like any host, Cloudflare sees the IP address that connects to it.
If the relay is unavailable, timers still sync through iCloud Drive, just more slowly.
Photos and camera
You can attach photos to entries from your library or the camera. Vivi only sees the photos you pick, and asks for camera access only when you choose to take a photo. Before saving, it resizes photos and removes location (GPS) and other EXIF metadata. Photos are stored in your family folder in iCloud Drive.
Notifications, widgets, Live Activities and Siri
- Reminders and insight notifications are scheduled on your device. Insight notifications name only the topic and your child's first name, never health details.
- Widgets and Live Activities show information such as time since the last feed on your Home Screen and Lock Screen, where anyone holding your phone can see it. You can turn them off in iOS Settings.
- The Apple Watch app talks directly to your iPhone.
- If you use Siri or Shortcuts, your voice request is processed by Apple under Apple's privacy policy. Vivi receives only the resulting action, such as "start sleep".
Insights and Sleepy Time
Insights and Sleepy Time are calculated on your device from what you have logged. Nothing is sent to us or to an AI service to produce them.
Import and export
When you import a CSV export from another baby tracker, or export your data to CSV, the file is processed on your device. Where an export goes afterwards is up to you.
This website
vivibaby.app is a static website hosted by Cloudflare. It sets no cookies and contains no analytics or advertising scripts. Cloudflare processes your IP address to deliver pages and protect the site from abuse.
If you join the launch waitlist, your email address is stored by our email provider, Brevo, only so we can tell you when Vivi Baby is available. Every email has an unsubscribe link, and we delete your address on request.
Children
Vivi Baby is used by parents and caregivers to keep a record about their children. It is not intended to be used by children. The information you record about your child stays in your iCloud Drive and is not collected by us.
Your data and your choices
Privacy laws give you rights to access, correct, export and delete the personal information a company holds about you. Apart from a waitlist email address, we hold none, and you control the rest directly:
- Export it. Export a CSV for each child from the app, or copy the files from the Vivi Baby folder in iCloud Drive.
- Delete an entry. Deleting it in the app removes the file on every device in the family.
- Delete everything. Delete the Vivi Baby folder in iCloud Drive and remove the app. Caregivers you shared with lose access when the folder is deleted.
- Stop sharing. Remove a caregiver from the shared folder in the Files app, and reset shared timer access in Vivi.
If you believe we hold information about you, write to support@brainpad.org. We will respond within 30 days, as Law 25 and PIPEDA require.
Governing law and your rights
Vivi Baby is published from Quebec, Canada, and this policy is governed by the laws of Quebec and the federal laws of Canada that apply there: the Personal Information Protection and Electronic Documents Act (PIPEDA) and Quebec's Act respecting the protection of personal information in the private sector, as amended by Law 25. Depending on where you live, you may also be covered by the GDPR in the European Economic Area and the UK, or the CCPA in California. We honour the rights these laws give you.
Law 25 requires us to keep a register of confidentiality incidents and to notify you and the Commission d'accès à l'information if an incident presents a risk of serious injury. We would do so. If you are not satisfied with how we handle a privacy question, you may complain to the Commission d'accès à l'information du Québec or to the Office of the Privacy Commissioner of Canada.
Changes to this policy
If this policy changes, the effective date at the top changes with it, and the current version always lives at this address. If a future version of Vivi Baby collects something it does not collect today, we will say so here before that version ships.
Questions about this policy: support@brainpad.org · Tommy Bergeron, Quebec, Canada · See also the Terms of Service.