1. Summary
- On-device audio analysis. Raw audio is not continuously sent to our servers for sound classification. Live listen is encrypted in transit and discarded by our relay as it passes. Optional event clips are handled as described below.
- Event metadata cloud sync. Timestamps and classifications (not audio) reach a Postgres database row-level-security-gated to your household.
- Optional cloud clips + photos. Short audio clips and photos captured on baby events (cry, fuss, baby voice) may be held in encrypted Supabase Storage for approximately 90 days by default so paired Viewers can play them back. This processing requires a separate, optional Media consent on the Monitor. Declining it does not prevent core monitoring.
- No selling, no advertising, no ML training on your audio, photos, or your child’s voice. No biometric identifiers within the meaning of the Illinois BIPA (see Section 17).
- Privacy and deletion requests. Email hello@babyradar.co; we verify identity first (Section 14) to prevent abuse. Per-event cloud deletion and account deletion are not currently available as self-service in this release.
Contract acceptance and optional media. On iOS launch, you must affirmatively accept the Terms, this Policy, and the EULA to use the Service. That contractual acceptance does not by itself enable optional camera, event-clip, or cloud-media processing. A Monitor user receives one separate Media prompt covering camera use, event audio clips, and cloud storage, and may decline it without losing core sound detection, alerts, or timeline features. Camera features also require operating-system camera permission. We store the accepted document or prompt version and acceptance time locally on the device.
2. Who we are
The Service is provided by Lunana Global Inc., a Delaware corporation. For purposes of this Policy and of laws such as the EU/UK General Data Protection Regulation and the California Consumer Privacy Act, Lunana is the “controller” or “business” that decides how your personal information is processed. Contact: hello@babyradar.co.
3. Information we collect
3.1 Information you give us
- Account information: no email or password is required. On first launch we create an anonymous user ID (via Supabase Auth’s anonymous sign-in) so paired devices recognize each other.
- Pairing information: pair codes, cryptographic identifiers, role (Monitor or Viewer), and the device display name where supplied by the operating system.
- Support communications sent to hello@babyradar.co.
3.2 Information collected automatically
- Device information: device model, operating-system version, app version, language, time zone, and pseudonymous identifiers. The pairing device identifier is stored in the device Keychain and may survive reinstallation; the anonymous cloud-authentication identifier is separate. We use these to operate, secure, support, and diagnose the Service.
- Diagnostics and crash reports: stack traces, error codes, approximate battery level, network type (Wi-Fi or cellular), and performance metrics. Crash reports do not include audio.
- Usage analytics: aggregate, pseudonymous events such as “session started,” “pair completed,” “notification delivered,” or “live listen tapped.” We do not log the content of any audio event.
- Audio event metadata generated on-device: the outputs of the on-device classifier, such as “baby voice at 01:42:18, 12 seconds” or “adult voice at 02:05:04.” These metadata records describe a sound detection, not the sound itself. They are stored on your device and, as described in Section 3.3, synchronized through our managed cloud database to your paired Viewers.
- Event audio clips (Monitor, opt-in): for each baby event (cry, fuss, baby voice), a short m4a clip covering the sound window (with brief pre/post roll, which may incidentally include speech or other people in the room) is uploaded to encrypted Supabase Storage bucket
event-clips, normally held for approximately 90 days by default, and then scheduled for deletion. Object paths are row-level-security-gated to your household device identifier. You may decline the Media prompt during Monitor setup; when declined, clips remain on the Monitor only and reach a Viewer only through direct peer-to-peer transfer. - Event photos (Monitor, opt-in): for each baby event, a single JPEG (plus a small thumbnail) is captured with the Monitor’s camera and uploaded to encrypted Supabase Storage bucket
event-photos, normally held for approximately 90 days by default, and then scheduled for deletion. Same RLS scope and same opt-in gating as clips above. Requires Media consent and operating-system camera permission; without either, capture or upload is suppressed. Photos have no peer-to-peer fallback; when Media consent is declined, no photo reaches the Viewer at all. Signed URLs used by paired Viewers to fetch photos are time-limited and minted per request; no permanent public URL is generated. - On-demand live video (iOS, opt-in): when a paired Viewer taps Watch Live, that remote request activates the Monitor camera and negotiates a 1:1 WebRTC video stream between Monitor and Viewer. Media may traverse our TURN relay when direct P2P is blocked by NAT; the relay forwards encrypted media packets and does not ordinarily receive the media keys. No live-video data is written to our servers or Supabase. Sessions auto-terminate after 10 minutes or on Viewer disconnect.
- Lock-screen photo previews (iOS): push notifications for baby events on iOS may include a photo thumbnail rendered on your lock screen by iOS. The thumbnail is fetched by the iOS notification service extension using a time-limited signed URL delivered in the push payload. You can suppress lock-screen previews at any time in iOS Settings > Notifications > BabyRadar > Show Previews.
- Relay session metadata: when you start a live listen, our relay logs the session start time, end time, approximate duration, and connection quality for up to seven (7) days so we can diagnose outages. The relay does not record audio.
- Subscription and purchase records: purchase information returned by Apple or Google to verify an active subscription. We use RevenueCat to manage and verify subscriptions; RevenueCat receives the store product identifier, the purchase date, the transaction ID, and a per-install identifier. Neither we nor RevenueCat receives your credit-card number or your full Apple ID or Google Account credentials.
- Marketing-attribution events: if you arrive through a Meta advertising campaign, the Meta SDK may receive app activation and deferred-link information. The iOS app uses Firebase Analytics without advertising-ID support. The Meta SDK may collect the iOS advertising identifier (IDFA) for install-ad attribution only if you grant Apple’s App Tracking Transparency permission; otherwise attribution uses Apple’s aggregated SKAdNetwork postbacks. We never report sound, event, photo, video, or pairing data to Meta.
3.3 Cloud event-metadata sync
From version 2.0, your event timeline (timestamps, sound classifications, durations, confidence scores, and a pointer to the on-device audio clip — not the audio itself) is mirrored to a managed Postgres database operated by Supabase Inc. so paired Viewers can read the timeline without waking the Monitor. Row-level-security rules tied to your anonymous device identifier ensure no household can read another household’s events. Event metadata is encrypted at rest and in transit (TLS 1.2+). On a Monitor with Media consent enabled, short baby-event audio clips and photos are additionally written to encrypted Supabase Storage (see §3.2) for approximately 90 days of Viewer playback by default, then are scheduled for deletion. Without Media consent, clips stay on the Monitor and reach the Viewer only through direct peer-to-peer transfer; photos are not uploaded at all and are not delivered to the Viewer.
4. What we do not collect
We have designed the Service to minimize personal data. We do not:
- record or transmit audio from the monitored room except (a) the transient encrypted live-listen stream you initiate, and (b) short baby-event clips you have affirmatively consented to store in cloud for approximately 90 days of paired-viewer playback;
- use the Monitor’s camera except (a) a single still on a baby event, and (b) an on-demand WebRTC video stream requested from a paired Viewer, both requiring your Media consent and operating-system camera permission;
- process cloud-stored clips, photos, or the live-video stream for any purpose beyond serving them back to paired devices in your household — no ML training, no analytics beyond object counts, no advertising signals;
- derive voiceprints, face-print biometric identifiers, or any other biometric identifier from stored clips or photos, of anyone in the home;
- collect precise location data;
- collect your contact list, calendar, health records, or data from other apps on your phone;
- collect your child’s name, date of birth, medical information, biometric identifiers, or any clinical data;
- create voice prints or voice-based biometric identifiers of anyone in the home;
- use your nursery content for advertising or include it in marketing-attribution events;
- sell or rent your personal information to anyone;
- use your household audio, your child’s voice, or your sleep-event timeline to train machine-learning models.
5. Your baby and your child
5.1 Not directed to children
BabyRadar is for parents and caregiving adults. A child does not interact with the Service. The Service is not “directed to children” under COPPA (15 U.S.C. §§ 6501 et seq.; 16 C.F.R. Part 312), the UK Age Appropriate Design Code, or Article 8 GDPR. We do not knowingly allow a child under 13 to create an account; email hello@babyradar.co and we will reset any such account.
5.2 Our voluntary child-data commitments
Regardless of whether COPPA applies, we commit that we:
- hold child audio clips and photos in cloud storage only when the parent or authorized Monitor operator has affirmatively opted in via the in-app Media consent, normally for approximately 90 days, and never use child audio, photos, event metadata, or sleep-timeline records to train, fine-tune, or evaluate any machine-learning model;
- never create voiceprints or any biometric identifier of a child (or anyone else in the home);
- never sell, rent, advertise against, or commercially disclose any child-related data;
- will raise every reasonable legal objection before producing child-related data in a custody, divorce, or family-court subpoena (see Section 9); and
- delete child-related event metadata within thirty (30) days of account deletion.
6. How we use information
We use the information described above to:
- provide, operate, and maintain the Service, including pairing your Monitor and Viewer devices and delivering live-listen and push notifications;
- verify your subscription status with Apple and grant access to paid features;
- respond to your support requests and communicate with you about the Service;
- diagnose, debug, and improve the Service (for example, to investigate why a notification was delayed);
- detect, prevent, and respond to fraud, abuse, security incidents, and unlawful activity, including reports that someone is using the Service to surveil a person without consent (see Section 10);
- comply with law, respond to lawful requests, and enforce our Terms;
- protect the rights, property, or safety of Lunana, our users, or the public, including the safety of a child we reasonably believe is at risk.
Where required by law (for example, under the GDPR), we rely on the following legal bases: performance of our contract with you (providing the Service), our legitimate interests (operating and improving the Service, preventing abuse, securing our systems), compliance with legal obligations, and, where applicable, your consent or vital-interests grounds (for situations involving risk to life or physical safety).
7. How we share information
We share personal information only as described below. We do not sell personal information.
- Between your paired devices. The whole point of the Service is to route notifications and live listen from your Monitor to your Viewers. Pairing metadata and event notifications are shared between the devices you pair. We do not share them with any other household.
- With our service providers (sub-processors) listed in Section 8, who process data on our behalf under written agreements that restrict their use of the data to the purposes we specify.
- For legal reasons: as described in Section 9.
- Corporate transactions. If Lunana is involved in a merger, acquisition, financing, reorganization, or sale of assets, personal information may be transferred to the successor entity, subject to confidentiality obligations at least as protective as those in this Policy. We will notify you of any change in ownership that materially affects your personal information.
- With your consent for any other purpose we disclose to you.
8. Our service providers
We rely on the providers below. They process information under their applicable terms and data-protection commitments. We may update this list as providers change and will give notice of material changes as described in Section 21.
- Apple Inc. (US) — App Store distribution, in-app purchases, APNs push notifications (including delivery of time-limited signed URLs for photo thumbnails rendered by the iOS notification service extension).
- Google LLC (US) — Google Play distribution and purchases for Android, Firebase Analytics for pseudonymous app-usage and diagnostic events, and aggregated advertising attribution where applicable.
- Supabase Inc. (US) — managed Postgres for the event-metadata cloud sync (§3.3) and anonymous authentication.
- Supabase Storage (US-East region) — encrypted object storage for optional Monitor event audio clips (bucket
event-clips) and event photos (bucketevent-photos), with row-level-security policies keyed to your household device identifier and 90-day default scheduled retention. - Google Cloud Platform (US) — WebSocket relay routing live-listen audio frames in memory between paired devices; not written to disk.
- Google Compute Engine (coturn) (US) — TURN relay for on-demand live video (WebRTC) when direct peer-to-peer is blocked by NAT. Forwards encrypted media packets; does not decrypt or persist media.
- RevenueCat, Inc. (US) — subscription verification for Apple App Store and Google Play purchases. Receives store product ID, purchase date, transaction ID, and pseudonymous device/account ID; no payment-card data or store account credentials.
- Meta Platforms, Inc. (US) — limited install-attribution events, app activation, and deferred-link resolution. If you grant Apple’s App Tracking Transparency permission, Meta may also receive IDFA for attribution. BabyRadar does not provide Meta with any audio, event, photo, video, or pairing data.
- Google Workspace (US) — customer support email.
9. Law enforcement and legal process
We will disclose personal information to government authorities, courts, or other third parties only when we are legally required to do so or, in our reasonable good-faith view, when disclosure is necessary to prevent imminent physical harm.
We will review every legal demand we receive. Where we believe a subpoena, court order, or other request is facially invalid, overbroad, or issued in bad faith, we will object, move to quash, or otherwise resist it before disclosing anything.
For live-listen audio and live-video streams, we do not retain the media itself and cannot produce recordings after the session ends. With your Monitor’s Media consent, however, cloud-stored event audio clips and event photos may be producible in response to valid legal process during their 90-day default retention window; we will apply our objections process (see the preceding paragraph) before doing so. For other request categories, what we can produce is limited to account information, event metadata, pairing history, and diagnostic logs, and only to the extent we hold it.
We regard civil subpoenas seeking child-related data in the context of a custody, divorce, paternity, or family-court matter as presumptively sensitive. We will raise every reasonable legal objection available to us before producing anything, and will notify the account holder where we are legally permitted to do so.
10. Abuse, surveillance, and misuse reports
Using BabyRadar to surveil another person without consent is prohibited under Terms §5. If you believe someone has paired a Monitor against you, email hello@babyradar.co with subject “Abuse Report” and what you know about the device location, who controls it, and why consent is absent. We will investigate, preserve relevant records, cooperate with law enforcement and court orders, and suspend accounts pending investigation where appropriate. Nothing here waives your right to contact law enforcement, a domestic-violence hotline, or a lawyer directly.
If you are in immediate danger in the US, call 911 or the National Domestic Violence Hotline at 1-800-799-7233. Outside the US, contact local emergency services.
11. Data retention
Ninety (90) days is the default active-storage period for optional cloud event media. Routine deletion begins after that period and may take limited time to propagate; it is not a promise that every object will remain available for the full period. We may delete media sooner for security, abuse prevention, account termination, service changes, storage limits, or a verified request. Limited copies may remain longer in protected backups, legal holds, or records we must retain by law, and will not be restored to active use except for recovery, security, or legal compliance.
- Account information: life of the account, plus up to 30 days after deletion for recovery and billing.
- Event metadata + sleep-timeline: life of the account unless deleted sooner following a verified request or as required by law. Self-service deletion is not currently available in this release.
- Diagnostics + crash reports: ~90 days, then aggregated or deleted.
- Relay session metadata: up to 7 days.
- Event audio clips (Supabase
event-clipsbucket): approximately 90 days from object upload by default, then scheduled for deletion from active storage. - Event photos (Supabase
event-photosbucket): approximately 90 days from object upload by default, then scheduled for deletion from active storage. - TURN relay session metadata (coturn on GCE): connection-tuple metadata retained on the relay host’s log rotation schedule for outage diagnosis; the stream itself is never persisted.
- Local device copies of clips and photos: may remain on the Monitor or Viewer until removed by the app, the operating system, or deletion of the app or its data. We do not remotely enforce a device-side deletion schedule in this release.
- Support communications: up to 2 years after ticket close, unless you ask us to delete sooner.
- Legal / tax / compliance + legal-hold records: as long as required by law.
When retention ends we delete, anonymize, or put data beyond further use.
12. Security and breach notification
- Encryption in transit: TLS 1.2+ on every hop between your phones, our servers, and our sub-processors.
- Encryption at rest on our managed Postgres (Supabase) for event metadata (§3.3).
- Live-listen audio: passes through the relay in memory only, not written to disk, logged, or retained. The relay decrypts the TLS envelope to route the frame, so audio is not end-to-end encrypted in the cryptographic sense; we are evaluating client-side E2E for a future release.
- Access controls: least-privilege for staff, MFA on admin accounts, audit logging, periodic reviews.
- Cloud object storage: Supabase Storage buckets
event-clipsandevent-photosare private, encrypted at rest by the provider, and gated by row-level-security policies keyed to your household’s anonymous device identifier. Lunana and Supabase administrative systems can technically access objects for operational purposes under written agreements. We do not routinely inspect content; limited authorized access may occur for support, security, abuse investigation, service recovery, or legal compliance. - Signed URLs: Viewer access to a clip or photo uses time-limited, per-request signed URLs; no permanent public URL is generated. Anyone holding a valid bearer URL can fetch the object during its lifetime, so treat these URLs as sensitive.
- Live-video WebRTC: streams use DTLS-SRTP encryption in transit between paired devices. Our TURN relay forwards encrypted media packets and does not ordinarily receive the media keys. Signaling for key negotiation is routed by Lunana infrastructure; a signaling-layer compromise remains a theoretical residual risk we consider in our threat model.
No system is perfectly secure. Keep your Apple ID credentials and pair codes confidential; sharing a pair code grants live-listen access to your nursery.
If a security incident affects your personal information we will notify affected people and regulators when and within the time required by applicable law. Under GDPR, notice to a supervisory authority may be required within 72 hours after awareness; notice to affected people is governed by a separate risk threshold and must be made without undue delay when required.
Security researchers: please report to hello+security@babyradar.co. We acknowledge valid reports within 5 business days and will not pursue legal action against good-faith researchers who follow coordinated disclosure.
13. Your rights
Depending on where you live, you may have some or all of the following rights:
- Access a copy of the personal information we hold about you.
- Correct information that is inaccurate or incomplete.
- Delete your account and associated personal information.
- Restrict or object to certain processing.
- Port your data to another service in a machine-readable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local data-protection authority.
To exercise a right, email hello@babyradar.co with “Privacy Request” in the subject line. We will respond within the time required by applicable law (in any event within forty-five (45) days for U.S. state privacy laws and thirty (30) days for GDPR / UK GDPR). We will not discriminate against you for exercising these rights.
14. Identity verification for rights requests
Before honoring an access, correction, deletion, portability, or opt-out request:
- Standard requests: confirm details associated with your account from the device that holds it, or respond to a one-time code sent to the email on file.
- Deletion / correction: same, plus up to a 48-hour cooling-off period and a second confirmation from the account’s device. Guards against compromised email accounts and stolen phones.
- Authorized agents (CCPA/CPRA, certain GDPR rights): written authorization signed by you plus proof of the agent’s identity.
If we cannot verify, we will say so and will not act. Appeal by replying with “Appeal” in the subject line; appeals are reviewed by a different team member.
15. Automated decision-making
BabyRadar uses on-device models to classify sounds (cry, fuss, parent voice, ambient, door, footsteps, etc.) and to decide which events trigger a notification. These automatic decisions do not produce legal or similarly significant effects within the meaning of GDPR Article 22 — they affect your timeline and notifications, not access to credit, employment, housing, education, healthcare, or any other right or benefit. You may correct any individual event in the app, dispute a classification by email, and disable notifications in iOS Settings. We do not use your audio, your child’s voice, or sleep-event timeline data to train or evaluate any model.
16. California residents
This Section supplements the rest of this Policy under the California Consumer Privacy Act as amended (CCPA/CPRA).
16.1 Categories collected (last 12 months)
Identifiers (device IDs, optional email); commercial info (purchase history); internet and network activity (diagnostics, analytics); audio recordings (with your Monitor’s Media consent, short baby-event clips retained approximately 90 days by default; transient live-listen streams we do not retain); visual information (with your Monitor’s Media consent and operating-system camera permission, event photos retained approximately 90 days by default); audio-derived event metadata (on-device-generated); and inferences drawn from these used to operate the Service. Disclosed only to the sub-processors in §8 for operational purposes.
16.2 Sensitive personal information
Under CPRA, information is not automatically “sensitive” merely because it concerns a minor. Audio recordings and photographs collected by the Service are personal information but do not meet the enumerated CPRA SPI categories in Cal. Civ. Code § 1798.140(ae) unless specifically used for the enumerated purposes (for example, biometric processing for unique identification), which we do not perform. Account login credentials, where used, are processed only for purposes permitted by CPRA § 1798.121(a).
16.3 No sale or sharing
We do not “sell” or “share” personal information as those terms are defined by CCPA/CPRA and have not in the past 12 months, including with respect to minors under 16.
16.4 Your California rights
Rights to know, access (portable), delete, correct, limit SPI use, and freedom from retaliation. Submit via hello@babyradar.co. Authorized agents require written authorization from you. “Shine the Light” (Cal. Civil Code § 1798.83): we make no direct-marketing third-party disclosures.
17. Illinois biometric-processing statement
Our on-device classifier reads short audio windows into volatile memory, applies a mel transform, runs a small neural network, and emits a sound-category label with confidence. Classifier operation is not used to identify any individual, and no per-speaker profile is built across windows.
With your Monitor’s Media consent, short baby-event audio clips are held in cloud storage for approximately 90 days by default for paired-viewer playback. These clips are held as opaque audio data and are not processed to derive voice prints, voice biometric identifiers, or any characteristic that BIPA defines as a “biometric identifier” or “biometric information” (740 ILCS 14/10). We do not analyze, transcribe, cluster, or otherwise process the clips beyond serving them back to your paired household. Photographs are expressly excluded from BIPA’s biometric-identifier definition; event photos likewise are not processed to derive any biometric identifier.
We represent that we do not capture, store, retain, transmit, sell, lease, trade, profit from, or disclose any biometric identifier or biometric information, including any voiceprint, and we do not use any Service output to identify any individual. If identification features are ever added, we will obtain a subject-specific written release and implement a BIPA-compliant retention and destruction policy before doing so.
18. Other U.S. state privacy laws
If you reside in Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, or Rhode Island, your rights under the relevant state comprehensive privacy law (VCDPA, CPA, CTDPA, UCPA, TDPSA, OCPA, MCDPA, and analogous statutes) are substantially similar to those for California residents in Sections 13 and 16: access, portability, correction, deletion, opt-out of sale or sharing for cross-context behavioral advertising (we do neither), and opt-out of profiling with legal effects (we do none). Exercise via hello@babyradar.co with your state in the subject. We honor Global Privacy Control / Sec-GPC. Identity verification under Section 14 applies. Appeal a denial by replying with “Appeal”; if denied, contact your state attorney general.
19. EEA, UK, and Swiss residents
If you are in the European Economic Area, the United Kingdom, or Switzerland, Lunana is the data controller. The legal bases we rely on are set out in Section 6. You have the rights listed in Sections 13 and 14. You may lodge a complaint with the data protection authority in your country of residence. A full list is available at edpb.europa.eu.
Privacy requests from EU/EEA residents may be sent directly to hello@babyradar.co.
UK residents may contact us directly at hello@babyradar.co.
Privacy contact. Questions about European data-protection rights may be sent to hello+dpo@babyradar.co. This contact designation does not represent that Article 27 or Article 37 applies in every jurisdiction.
20. International transfers
We use service providers located in the United States and other countries. Optional event audio clips and event photos are stored in Supabase Storage’s US-East region. When we transfer personal information from the EEA or Switzerland to a country that has not received an adequacy decision, we rely on the European Commission’s Standard Contractual Clauses (including those incorporated by our providers’ data processing addenda) or other lawful transfer mechanisms. For restricted UK transfers, we rely on the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the EU SCCs, together with a transfer risk assessment as required by the UK ICO. A copy of applicable safeguards is available on request.
Lunana’s Privacy Officer is accountable for our Canadian privacy practices. Canadian residents may request access or correction, withdraw consent subject to legal or contractual restrictions and reasonable notice, or submit a complaint using the contact details in Section 22. Personal information may be processed in the United States and therefore may be accessible to courts, law enforcement, or national-security authorities under applicable U.S. law.
21. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will give reasonable notice, such as by posting the updated Policy with a new “Last updated” date, sending email to the address associated with your account, or displaying a notice within the Service. Your continued use of the Service after the effective date constitutes your acceptance of the updated Policy. If a change is material or requires consent under applicable law, we may require renewed acceptance in the app or present a separate feature-specific consent before the changed processing begins.
22. How to contact us
Lunana Global Inc.
555 Burrard Street
Vancouver, BC V7X 1M8
Canada
General email: hello@babyradar.co
Privacy requests: hello@babyradar.co with “Privacy Request” in the subject line
Privacy Officer: hello+dpo@babyradar.co
Security disclosures: hello+security@babyradar.co
DMCA copyright notices: see Terms of Service Section 11
We aim to respond within five (5) business days for general inquiries, and within the legally required period for rights requests (45 days for U.S. state privacy laws; 30 days for GDPR / UK GDPR).