Skip to main content
Back to home

Privacy Policy

Last updated: July 16, 2026

1. Scope

This policy explains how Care by Talia processes personal data for the Talia iOS app, the public Care by Talia website, in-home support, and the separately offered Digital Newborn Guide. The iOS app is intended for parents and caregivers, not for children to use independently.

2. Data We Process

  • Account and authentication: email address, internal user ID, sign-in provider, consent version and time, authentication events, and essential session cookies.
  • Parent and baby profile: parent name and role; baby name, birth or due date, age/stage, feeding preferences, goals, and user-supplied notes such as allergies, prematurity, NICU history, or clinician instructions.
  • Care and activity logs: feed, sleep, diaper, pumping and recovery entries, timestamps, durations, notes, milestones, and journey progress.
  • Chat and AI content: messages, generated responses, conversation context, approved-source citations, and tool actions such as a log the user asks Talia to save.
  • Subscription and entitlement: Apple product ID, transaction identifiers, entitlement state, renewal/expiry information, and App Store notification metadata. Apple handles payment-card details; Care by Talia does not receive them.
  • Diagnostics and security: request time, route, error and performance information, device/browser information, and network identifiers that may be processed in hosting, security, and service logs.
  • Public-site services: contact details and booking information for in-home support, plus email and purchase/delivery information for the separately offered Digital Newborn Guide.

3. How We Use Data

  • Authenticate accounts and record signup consent.
  • Provide profiles, tracking, journey, chat, export, support, and account-deletion features.
  • Personalize the app using data the parent or caregiver supplied.
  • Verify Apple subscriptions and maintain entitlement state.
  • Send transactional account and service email.
  • Protect the service, investigate failures, and measure reliability and performance.
  • Meet legal, accounting, fraud-prevention, and security obligations where applicable.

4. AI and Approved Knowledge Processing

Chat messages and relevant account context may be sent to OpenAI to generate a response. Context can include the parent and baby profile, recent care logs, saved user-supplied notes, prior conversation context, and approved Knowledge Book excerpts needed for the question. Do not enter information you do not want processed for chat.

Talia may answer material pregnancy, postpartum, feeding, sleep, developmental, or baby-care questions only from human-approved Knowledge Book sources. When an adequate approved source is unavailable, the app is designed to refuse rather than rely on general model knowledge. Talia is not a healthcare provider and does not provide diagnosis, treatment, medication instructions, or emergency care.

5. Processors and Other Recipients

We do not sell personal data or use it for third-party advertising. We use the following service providers only for the stated operational purposes:

  • Supabase: authentication, account database, row-level access controls, and app-data storage.
  • Vercel: application hosting, request delivery, operational logs, and performance/error diagnostics.
  • OpenAI: AI response generation and approved-knowledge retrieval processing.
  • Resend: transactional email delivery.
  • Apple: Sign in with Apple, in-app purchases, subscription management, and App Store transaction verification.
  • Google: Google account sign-in when the user selects it.
  • Payhip and its payment processors: checkout and delivery for the Digital Newborn Guide offered on the public website, not inside the iOS app.
  • Isracard: payment processing where used for separately contracted public-site services.

These providers process data under their own service terms and privacy commitments. Data may be processed in countries outside the user's country when required to operate these services.

6. Retention and Deletion

  • Account, profile, baby, log, chat, journey, and subscription records: retained while the account is active. They are removed from the active app database when in-app account deletion succeeds.
  • OAuth signup intent: valid for 10 minutes. A completed, cancelled, expired, or replayed intent cannot authorize signup consent.
  • Exports: generated on request and returned directly; the app does not keep a separate export copy.
  • Apple purchase history: Apple independently retains transaction records under Apple's policies. Account-linked entitlement and notification records in the Talia database are included in account deletion unless retention is legally required.
  • Processor backups, security logs, diagnostics, and transactional email records: retained according to the configured service-provider rotation and legal requirements. Exact maximum periods depend on the final production account settings and must be confirmed in the App Store privacy submission before release.

Deletion from active systems does not necessarily remove data immediately from encrypted backups or independent provider records. Residual copies are removed as those systems rotate, unless continued retention is legally required.

7. Choices, Consent, and User Rights

Depending on applicable law, users may request access, correction, export, restriction, objection, or deletion.

  • Profile and baby information can be updated in Settings.
  • App data can be exported from Settings as JSON or CSV.
  • Users can stop optional AI processing by not sending chat messages.
  • Consent can be withdrawn by deleting the account in Settings or by contacting support. Withdrawal does not invalidate processing already completed lawfully.
  • Deleting a Talia account does not cancel an Apple subscription; subscriptions must also be managed through Apple ID subscription settings.

8. Security

The app uses authenticated access, server-side ownership checks, database row-level security, encrypted transport, limited service credentials, and server-authoritative subscription verification. No internet service is risk-free; users should protect their account credentials and avoid entering unnecessary sensitive information.

9. Children's Privacy

Care by Talia is designed for adult parents and caregivers. We do not knowingly create accounts for children under 13. Baby information is supplied and controlled by the parent or caregiver.

10. Cookies and Tracking

The app uses essential cookies for authentication, consent integrity, security, and session management. It does not contain third-party advertising or cross-app tracking and does not use advertising cookies.

11. Changes and Contact

Material policy changes will be communicated through the app, website, or email where appropriate.

Privacy questions or requests: support@care-by-talia.com.

Privacy Policy — Care by Talia