BabySpeak
Home
← Home

Privacy Policy

Last updated: 18 August 2026

The short version: BabySpeak is for parents, not children as account holders. Audio stays on your phone. A photo leaves your phone only if you tap “Upload a photo” — it is sent once to create a cartoon and is not stored. We do not sell data and we do not train models on your baby. Questions: privacy@babyspeak.app.

1. Who we are

Data controller: Pattern Systems Ltd, a company registered in England and Wales.

Registered office: Suite 12, Victoria Hall, Rawlinson Street, Barrow-in-Furness, LA14 3UD, United Kingdom.

Contact: privacy@babyspeak.app · hello@babyspeak.app

This policy covers the BabySpeak iOS and Android apps and the website at babyspeak.app (together, the “Service”). It is written to meet the UK GDPR, the EU GDPR where it applies, the Data Protection Act 2018, the California Consumer Privacy Act as amended (CCPA/CPRA), and Apple / Google store disclosure rules.

2. Who the Service is for

BabySpeak is an entertainment app for adults (parents and caregivers). It is not directed at children and is not a “kids” app. You must be old enough to hold an App Store / Google Play account in your region (typically 13+, and 18+ to subscribe without a parent).

If you upload a photo of a child, you confirm you are that child’s parent or guardian (or have their parent’s permission) and you give the consent described in our Children’s Privacy Notice.

3. What we collect

DataWhere it livesWhy
Anonymous or signed-in account IDFirebase AuthRate limits, subscriptions, abuse prevention
Email (waitlist / affiliate / optional sign-in)FirestoreInvite you, pay affiliates, account recovery
Subscription status (not card numbers)RevenueCat + Firestore mirrorUnlock paid features
Usage counts (free gens used, daily caps)FirestoreEnforce the 5-free / paid fair-use limits
Install identifier we generate (not IDFA)Your device + hashed on serverStop people farming free translations
Mood label + caption textSent to AI providers, not stored by usWrite and voice the joke
Optional child photo (upload only)In transit to our function, then discardedMap skin / hair / style to our cartoon kit
Audio recordingsOn your device onlyPick a playful mood and build your clip
Baby profiles, clips, historyOn your deviceThe app you see
Affiliate / referral codesFirestoreCredits and commissions
Crash / diagnostics (if enabled)Expo / store toolingKeep the app stable
Website waitlist email + optional ref cookieFirestore / localStorageLaunch notify + 30-day affiliate cookie

4. What we do not do

  • We do not sell personal data.
  • We do not use your content to train our models or our providers’ models (to the extent our contracts and their APIs allow; we send only what is needed to generate a caption, voice, or avatar mapping).
  • We do not store uploaded child photos after the stylise request finishes.
  • We do not upload baby audio to our servers.
  • We do not run cross-app advertising or share data with data brokers.
  • We do not use the Apple Identifier for Advertisers (IDFA). We do not show an App Tracking Transparency prompt because we do not track you across other companies’ apps.

5. AI providers

To generate a translation we send text only (a mood label such as “sleepy”, optional first name, language, and the resulting caption) to:

  • Anthropic (Claude) — writes the caption; if you upload a photo, vision is used only to pick cartoon kit values (skin / hair / style), then the image is discarded.
  • Fish Audio and/or ElevenLabs — turns the caption into speech.

Those providers process the request as our processors. They do not receive your baby’s real recording.

6. Payments

Subscriptions are sold by Apple or Google and synced with RevenueCat. We receive entitlement status, product id and expiry. We never see your full card number.

7. Legal bases (UK / EU)

  • Contract — running the account, generating captions you asked for, subscriptions.
  • Legitimate interests — abuse prevention, rate limits, security, basic diagnostics.
  • Consent — waitlist emails, optional photo upload of a child, any future non-essential cookies or marketing.
  • Legal obligation — tax, accounting, responding to lawful requests.

8. Retention

  • On-device content stays until you delete it or uninstall the app.
  • Account / usage records: kept while the account exists, then deleted within 30 days of a deletion request (backups may take up to 90 days to expire).
  • Waitlist emails: until you unsubscribe or we shut the list.
  • Affiliate records: while the programme is active and as needed for payouts / tax.
  • Photos: not retained after stylise.

9. Your rights

Depending on where you live you may have rights to access, correct, delete, export, restrict or object to processing, and to withdraw consent. California residents may also request that we do not “sell” or “share” personal information — we do not sell or share as those terms are defined for cross-context advertising.

In-app: delete clips and profiles; Settings → Delete my account. Website: delete account. Email privacy@babyspeak.app. We will respond within one month (UK/EU) or 45 days (CCPA).

You may complain to the ICO (ico.org.uk) or your local supervisory authority.

10. International transfers

Our hosting and AI processors may be in the US or other countries. Where we transfer UK/EU personal data we use an appropriate safeguard such as the UK International Data Transfer Addendum / EU Standard Contractual Clauses.

11. Security

Transport is HTTPS. API keys live in Cloud Functions, not the app. Firestore is deny-by-default. No security measure is perfect; please use device lock-screen security.

12. Store disclosures

The exact App Privacy (Apple) and Data safety (Google) answers are published in our store pack and match this policy. See also Cookies and Children.

13. Changes

We will update this page and the “last updated” date when the Service changes in a material way.