WeanSafe Privacy Policy
WeanSafe ("we", "us", "our") is committed to protecting your privacy. This policy explains what data we collect, how we use it, and your rights under UK data protection law.
The short version: WeanSafe doesn't collect personal information. Your baby's date of birth stays on your phone. We use anonymous crash reports and usage data to fix bugs and improve the app. If you send us feedback, it's anonymous — we don't know who sent it. We don't use ads or tracking. That's it.
1. Who we are
WeanSafe is a free baby weaning food guidance app developed by Ash. For data protection enquiries, contact us at hello@weansafe.co.uk.
2. What data we collect
2a. Data stored on your device only (never sent to our servers)
- Baby's date of birth or age band — stored locally on your device. On iOS, the date of birth is stored in the Keychain (via SecureStore); on Android, in the Android Keystore (via SecureStore); on web, in localStorage. The age band is stored in AsyncStorage (or localStorage on web). This data never leaves your device and is never transmitted to any server.
2b. Data we collect via our servers
- Anonymous food database sync — when the app downloads or refreshes food data from our servers (hosted on Supabase), standard server logs may record your device's IP address and request timestamps. We do not link this to any personal information.
2c. Crash reporting (Sentry)
- If the app crashes or encounters an error, anonymous diagnostic data (device type, OS version, crash stack trace) is sent to Sentry (sentry.io) to help us fix bugs.
- IP addresses: Sentry collects your device's IP address as part of its standard transport. This is used for diagnostic purposes only (e.g. identifying regional outages) and is not linked to any personal information. IP addresses are retained in accordance with Sentry's data retention policies (typically 90 days — see https://sentry.io/privacy/).
- Legal basis: Legitimate interests (GDPR Article 6(1)(f)) — maintaining app stability and fixing bugs. See also GDPR Article 13 disclosure requirements.
- No personal data is included in crash reports. Date-of-birth values are automatically scrubbed before transmission.
- See Sentry's privacy policy: https://sentry.io/privacy/
2d. Usage analytics (PostHog)
- We use PostHog (posthog.com) to collect anonymous usage data to understand how the app is used and improve it. This includes: which screens are viewed, which foods are looked up, how search is used, and whether onboarding is completed.
- Anonymous only: We do not collect or store any user IDs, email addresses, or personal information through PostHog. Each app installation generates a random anonymous identifier that cannot be linked back to you.
- Example: We can see that "someone searched for banana" and "someone viewed the avocado page" — but we cannot see who did these things, and we cannot link them to the same person. Each event is a standalone, anonymous data point.
- IP addresses: PostHog collects your device's IP address as part of its standard transport. This is used for approximate geographic analysis only and is not linked to any personal information.
- EU hosting: PostHog data is processed and stored on EU servers for UK GDPR compliance.
- Legal basis: Legitimate interests (GDPR Article 6(1)(f)) — understanding feature usage to improve the app.
- See PostHog's privacy policy: https://posthog.com/privacy
2e. Feedback you send us
- If you choose to send feedback through the app, we store: your feedback category (e.g. "report incorrect food info"), your message text, which type of device you used (iPhone, Android phone, or web browser), and the date and time you sent it.
- No personal data is collected with feedback. We do not know who sent it — feedback is completely anonymous.
- Feedback is stored in our database (Supabase, hosted in the EU) and is used solely to improve the app.
2f. Changes to data collection
WeanSafe is currently a free app with no accounts, payments, or advertising. If we ever introduce features that require additional data collection, we will update this privacy policy before any new collection begins and notify you of material changes within the app.
3. What we do NOT collect
- We do not require you to create an account — there are no usernames, passwords, or email addresses.
- We do not collect your name or your baby's name.
- We do not use advertising SDKs, tracking pixels, or any form of targeted advertising.
- We do not sell or share any data with third parties for marketing purposes.
For details of the anonymous data we do collect (crash reports, usage analytics, and voluntary feedback), see Section 2 above.
4. Third-party services
| Service | Purpose | Data processed | Privacy policy |
|---|---|---|---|
| Supabase | Food database hosting and feedback storage | IP address (server logs only), feedback messages (anonymous) | https://supabase.com/privacy |
| Sentry | Crash reporting | Anonymous crash data, device type, OS version | https://sentry.io/privacy/ |
| PostHog | Anonymous usage analytics | Anonymous usage events, device platform, app version, IP address | https://posthog.com/privacy |
If we add third-party services in the future, they will be listed here before any new data collection begins.
5. Data retention
- On-device data — retained until you clear the app's data or uninstall the app.
- Server logs — Supabase server logs are retained according to Supabase's standard retention policy.
- Crash reports — Sentry retains crash data (including IP addresses) according to its retention policies (typically 90 days). See: https://sentry.io/privacy/
- Usage analytics — PostHog retains analytics events for up to 1 year. See PostHog's privacy policy: https://posthog.com/privacy
- Feedback — Feedback submissions are reviewed periodically and deleted within 12 months of receipt, or sooner once actioned.
6. Your rights
Under the UK Data Protection Act 2018 and UK GDPR, you have the right to:
- Access any personal data we hold about you
- Request deletion of any personal data
- Object to processing of your data
- Lodge a complaint with the Information Commissioner's Office (ICO)
How to request data deletion: Email us at hello@weansafe.co.uk. Since we do not collect personal information, there is usually nothing to delete. If you have sent feedback and would like it removed, describe your message and we will delete matching entries within 30 days. On-device data (date of birth, age band) can be deleted by clearing the app's data or uninstalling the app.
Since we collect minimal data and store no personal information on our servers, exercising these rights is straightforward. Contact us at hello@weansafe.co.uk.
7. Children's privacy
WeanSafe is designed for parents and carers of babies. The app does not collect any data from or about children. The baby's date of birth, if entered, is stored only on the parent's device and is never transmitted.
8. Data security
- All communication between the app and our servers uses HTTPS/TLS encryption.
- On-device data is stored using platform-standard secure storage mechanisms.
- We follow security best practices in our development process.
9. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page will be revised accordingly. If we make significant changes, we will notify you within the app before they take effect.
10. Contact us
If you have questions about this privacy policy or your data, contact us at:
Email: hello@weansafe.co.uk