Draft, not yet reviewed by a lawyer. Items in square brackets will be filled in later.

Nyamko Privacy Policy

Effective [EFFECTIVE DATE]. [LAWYER REVIEW: sections 3, 5a, 6 and 10 on the optional account, statistics and crash reports are new wording and must be reviewed by a lawyer before publication.]

In short: everything you enter about your child and family is stored only on your device. An account, de-identified usage statistics and crash reports are optional and off by default; even when you turn them on, we do not receive names, birth dates, allergies, reactions, doctor restrictions or your notes. There are no ads.

1. Who we are

Nyamko is provided by [OPERATOR NAME], [COUNTRY] ("we"). For privacy questions, write to hello@nyamko.app.

This is an early version: it exists to show how the app works and may change.

2. What data you enter

The app is used by parents and other adults who care for a child. You enter the data about the child and the family:

Data about allergies, reactions, pauses for illness or vaccination, feeding, prematurity, growth and «Tummy» entries is data concerning a child's health. Diet presets (for example "Vegetarian" or "No pork") may indirectly reveal the family's religious or philosophical beliefs. Both the GDPR (Article 9) and the Law of Ukraine "On Personal Data Protection" (Article 7) treat such data as a special category that needs extra protection. That is why this data never leaves your device — not in statistics, not in crash reports, not in the account.

Enter only what the meal plan needs. Do not enter a surname, address, document numbers or other details that make it easy to identify the child.

3. Where the data is stored

The data about your child and family is not sent to us or to anyone else. There is no sync between devices and no backup on our servers yet. There are no ads and no third-party trackers. Fonts and illustrations are bundled with the app and are not loaded from the internet. What is sent only if you choose so is described in section 5a.

The app may keep internal copies of your data on the device: a copy made before a storage-format upgrade and a copy of damaged saved data, so that nothing is lost. They stay on the device and are deleted together with all other data (see section 6).

Device backups. In the Android app, backup of the app's data is turned off. On iPhone and iPad, the app's data may be included in a device backup (iCloud, or a backup on a computer via Finder or iTunes) if you have turned it on — under Apple's rules, not ours. We have no access to such backups.

4. Legal basis and who processes the data

We do not receive the data you enter into the app and have no access to it. We therefore consider that we are not the controller of that data: you process it yourself, on your own device, for personal and family purposes — to plan meals and keep track of your child's complementary feeding. This applies only to data in the app; for web server logs see section 5.

You enter the child's data as the child's parent or another adult who cares for the child. Please enter a child's data only when you are entitled to do so.

5. What other parties see

We do not sell data, do not show ads, and do not share data for advertising or profiling.

5a. What is sent only if you choose so

De-identified usage statistics (a switch in "Privacy and terms", off by default; after the first-run setup the app asks once, about this only). If you turn it on, we receive through PostHog (a processor acting on our behalf, servers in the EU; the app does not send data to other hosts) the names of actions without their content: start, progress (25, 50, 75 %) and completion of the first-run setup (no step names or answers), "meal confirmed" (the kind of meal and "ate / refused / not given / other"), "catalogue recipe opened" (its number), "safety article opened" (its number), "103/112 screen opened" (the fact only), "search with no results" (only the screen and the query length as a range — the query text is not sent), views of the Nyamko+ sheet and purchases. Each action carries only: the youngest child's age range (under 6, 6–8, 9–11, 12–24 months, over 24), the number of children, the language, whether the colour theme was changed, the app version and a random install identifier. This is pseudonymous data: the identifier links the actions of one install to each other, but not to your name, email or account; you can reset it with "Reset identifier" — new data is then no longer linked to earlier data. Person profiles and IP-based geolocation are turned off. We never send names, birth dates, sex, prematurity, allergies, reactions or symptoms, doctor restrictions, foods a child can't have, pauses, measurements, the names of dishes and foods introduced to the child, search text or your notes. First-run events from before you answer are kept in memory only until the app is closed and are sent only if you agree.

Crash reports (a separate switch, off by default; we do not prompt for it). If an error occurs in the app, we receive through Sentry (a processor acting on our behalf, servers in the EU; the app rejects other regions) only the error type, the place in the program code (file, function, line) and the app version. The error message text is not sent.

Like any internet request, a request to these services technically carries your IP address and device or browser type (User-Agent). In the services' settings we turn off storing IP addresses; [LAWYER REVIEW: confirm once the PostHog and Sentry projects exist].

Legal basis: your consent (GDPR Art. 6(1)(a); Law of Ukraine "On Personal Data Protection", Art. 11), separately for each purpose. You can withdraw it with the same switch at any time; sending then stops, anything not yet sent is discarded and the identifier is erased from the device. Retention at the processors: no longer than [ANALYTICS RETENTION PERIOD]. To have already-sent data deleted, write to hello@nyamko.app.

Optional account. You do not need an account — the app works fully without one. Sign-in appears in the app only together with the ability to delete the account in the app. If you sign in (a one-time code by email; later Apple or Google), we store through Supabase (a processor acting on our behalf, servers in the EU) your email address, account identifier and technical sign-in data (time, session tokens, IP address in the service logs). Purpose: signing in, and later backup and a shared plan with another adult. Legal basis: performance of a contract (GDPR Art. 6(1)(b)). Right now the account does not store or copy any data about your child or family: as before, it stays only on the device, so the account does not protect against data loss when you change phones. Before backup or sync arrives, we will update this policy and ask for separate explicit consent to store data about your child's health. To delete the account: "Account" → "Delete account" (with confirmation) — the account and sign-in data are permanently deleted from the server.

6. How to delete your data

We have no copies of the data about your child and family, so we cannot restore it. "Delete all data" does not reach device backups: if your iPhone or iPad has an iCloud or computer backup, restoring from it may bring the data back. To remove it from there as well, delete that backup.

7. Your rights

Because the data is stored only with you, you can view, correct or delete it yourself in the app. If you have privacy questions, write to hello@nyamko.app. You also have the right to contact a data protection authority: in Ukraine, the Ukrainian Parliament Commissioner for Human Rights; in the EU, the supervisory authority of your country.

8. Children

Nyamko is an app for adults (18+) who care for children. Children should not use it on their own. The child's data is entered by an adult.

9. Security

Your data is as secure as your device. We recommend using a screen lock and not handing the device to others. On a shared computer, it is better not to use the web version, or to delete the data after use. If the web version is open in several tabs, they update together.

10. What will change later

Future versions are planned to include backup and sync of family data through the account (a cloud database, a shared plan with another adult) and an AI assistant (text or voice, processed on a server and through an AI provider's API). None of this exists yet. Before any data starts leaving your device, we will update this policy to state what data is sent, to whom and why, where it is stored, for how long and on what legal basis. For data about a child's health we will ask for separate explicit consent. Features that require sending data will be optional.

11. Changes to this policy

We may update this policy. The new version will carry a new date. We will announce significant changes in the app (once it supports this) or on the website.