Privacy Policy
Release candidate · 1.0-rc-2026-09-08 · Reference implementation, not a live publication.
Version 1.0 Effective date: [PUBLICATION DATE]
1. Who we are
Newbie Parents is operated by JARGONAUT LABS PTE. LTD. (UEN 202639127H), a Singapore company. In this Privacy Policy, “Newbie Parents”, “we”, “us” and “our” refer to that company.
Our interim Data Protection Officer is Frank Tan. For privacy, access, correction, consent-withdrawal or deletion questions, contact jargonautlabs@gmail.com. Our website is https://newbieparents.app.
This Policy explains how we collect, use, disclose, protect and retain personal data when you use the Newbie Parents mobile apps, our website and any private web client that we make available.
2. What the service is
Newbie Parents is a private shared-care tracker for families. Account holders can create or join a family space, record a child's day-to-day care and view information according to their role.
The public service does not currently collect baby profile photos, provide self-service report/export, use Telegram, offer advertising or sell personal data. If we introduce a new feature that materially changes the data we collect or why we use it, we will update this Policy and give an appropriate notice before that new processing begins.
3. Information we collect
Account and authentication information
We collect the information needed to create and secure your account, such as your email address, authentication identifiers, sign-in method, verification and recovery records, session records and a display name. If you use Google sign-in, Google provides the identity information permitted by the sign-in flow. We do not ask for your NRIC number or account-holder date of birth as part of ordinary registration.
This information is required to create and use an account, authenticate you, recover access, prevent unauthorised use and associate your actions with the correct family record.
Family membership and invitations
We collect family membership, role, child scope, inviter, invitation recipient email, invitation status and expiry, acceptance records, ownership-transfer records and family-specific display names. A family name may be generated from the first child's preferred name and later changed by an Owner.
This information is required to create private family spaces, deliver and validate invitations, enforce Owner, Caregiver and Helper access, show who added a record and preserve security evidence.
Child profile information
An Owner or Caregiver provides a child's preferred name and date of birth when creating the child profile. They may also provide sex where the field is offered, timezone, expected or actual birth details used for corrected-age calculations, and the limited profile and care information made available by the release candidate. This may include allergies, active conditions, current medication instructions and a short care note.
A child's preferred name and date of birth are required to create a child profile because age-dependent calculations and guidance must not guess a child's age. Expected due date and other offered profile fields are optional unless the screen clearly says otherwise. If a legacy or incomplete profile lacks a reliable date of birth, the app must suppress age-dependent recommendations rather than estimate one. Do not add information that is not needed for the family's use of the service.
Care logs and health-related information
Family members may record feeding, breastfeed, bottle, pumping, diaper, sleep, solids, medicine administration, temperature, observed symptoms, growth, milestones and notes when those features are available to their role and the public release. Records can include times, durations, amounts, units, selected categories and user-entered text.
This information is optional: the family chooses what to record. It is used to maintain the shared care history, show current and recent activity, support timers, calculate deterministic summaries and display sourced general guidance. Missing information is not treated as zero, a failure or a medical conclusion.
Solids and allergen information
The service may record foods offered, allergen exposure, reactions or observations, serving information and notes. It uses these entries to show the family's own record and applicable sourced general guidance. It does not diagnose an allergy.
Device, app and notification information
We may receive app version, operating system, device type, language/locale, timezone, IP address and limited request, security and diagnostic metadata generated when the service is used. If you enable notifications, we process a platform push token, notification preference and delivery status. Notification permission is optional and can be changed in the app or device settings.
We use this information to deliver the service, format dates and times, secure accounts, investigate faults and abuse, and send the notifications you choose. We do not use an advertising identifier for behavioural advertising.
Support and privacy requests
If you contact us, we collect your message, email address, request details, correspondence and the minimum verification and case notes needed to respond. Please do not email identity documents, medical records or unnecessary details. We will ask for additional evidence only when it is genuinely needed and will use a less intrusive method where reasonably available.
Security and limited operational records
We keep limited records of authentication, membership and invitation events; Terms/privacy versions shown or accepted; deletion and rights requests; administrative actions; and security incidents. We use these to protect families, demonstrate requests and permissions, investigate incidents and meet legal or store obligations.
We do not intentionally put child names, care notes, medicine details, symptoms or authentication secrets into operational logs.
4. Information another family member provides
Newbie Parents is a shared service. Another family member may provide your invitation email or family display name, and may record information about a child before you join. Once you join, members may see the name associated with your contributions and the records you add according to their role.
If you provide information about another person or a child, you are responsible for having the right or permission to provide it and for keeping it relevant and accurate. Do not use Newbie Parents to publish private information outside the family space.
5. Why we collect, use and disclose information
We process information only for purposes that are reasonably necessary for the service or otherwise permitted by law. These purposes are to:
- create, authenticate, recover and secure accounts;
- create family and child spaces and enforce membership, role and child scope;
- send, accept, expire, cancel and audit invitations and ownership transfers;
- store, synchronise and display family-entered care records;
- operate timers, summaries, Insights and source-labelled general guidance;
- send optional service notifications selected by the user;
- provide support and handle access, correction, withdrawal and deletion requests;
- prevent, detect, investigate and respond to security incidents, misuse and technical failure;
- maintain limited operational, consent/notice and audit evidence; and
- comply with applicable law, binding legal process and app-store obligations.
We do not sell personal data. We do not disclose family content to data brokers or use it for behavioural advertising. Processing by the service providers in section 7 is not a sale: they process data to provide, secure or support Newbie Parents under their applicable terms and our instructions, where applicable.
6. Who in a family can see and change information
- Owner: can access the family's children and records, manage members and roles, invite people, accept or initiate ownership changes, manage child profiles and close the family. “Owner” is an app-administration role; it is not proof of a legal family relationship.
- Caregiver: can access the family's shared history and routine records, add and manage care records within the product rules, and invite a Helper only for a child the Caregiver can access. A Caregiver can remove only a Helper they personally invited, subject to the documented rules.
- Helper: can access only the children explicitly shared with them. For those children, a Helper can see the current day, active timers, the most recent feed/sleep/diaper record across the day boundary and the limited Care card. A Helper can add Bottle, Diaper, Solids, Nap, Night sleep, Medicine, Temperature, Symptoms and Note records and edit or delete only their own entries within 24 hours. A Helper cannot see long-term History, Insights or Growth; log Breastfeed, Growth or Milestone; manage members; or change child profiles.
The app must show a role's effect before an invitation or ownership transfer is accepted. Access ends when a membership or child scope is removed, although records can remain visible to authorised family members as described in sections 9 and 10.
7. Service providers and other disclosures
We use service providers to operate Newbie Parents. Depending on the release and feature used, they may include:
- Convex for authentication, database, real-time synchronisation and related backend services;
- Vercel for the website, legal/deletion pages, authentication-related routing and any private web client we continue to operate;
- Google for Google sign-in and, where applicable, email, support or Android platform services;
- Resend for account, recovery and invitation email delivery;
- Apple and Google for app distribution, platform services, diagnostics and optional push delivery; and
- other infrastructure or security subprocessors disclosed by those providers.
We give providers only the information reasonably needed for their function. They may process technical and account metadata in addition to content routed through their service. We review available processor terms, security information, subprocessors and deletion controls before launch and periodically after launch.
We may also disclose information when reasonably necessary to comply with binding law or legal process; protect a person from serious harm; investigate fraud, abuse or a security incident; or support a corporate transaction with appropriate confidentiality, due diligence and notice. A user database is not treated as an ordinary saleable asset, and any transfer of control over personal data must have a lawful, disclosed purpose and appropriate protection.
8. Overseas storage and processing
Newbie Parents is operated from Singapore, but our service providers and their subprocessors may store or process personal data outside Singapore, including in the United States, Ireland and other locations where they operate. The exact location depends on the production region, account configuration and platform used.
We take reasonable steps to use contracts, provider assurances, security measures and due diligence intended to provide protection comparable to the Singapore PDPA for overseas transfers. We do not promise that data remains only in Singapore.
9. How long we keep information
These periods are Newbie Parents product policies based on the purpose of each category; they are not universal statutory periods. We may use a shorter period where practical. A binding legal hold, active security investigation or legal requirement may require a limited exception, which we document and remove when the exception ends.
| Category | Normal retention |
|---|---|
| Active account, family, child profile and care content | While the relevant account/family/child is active, unless a user deletes an individual entry sooner |
| Data covered by account deletion, child deletion or family closure | Access ends immediately; deletion from active systems completed within 30 days |
| Pending invitation | Usable for 7 days; token hash deleted when accepted, cancelled, expired or invalidated; recipient email deleted within 30 days after terminal status |
| Minimal membership, invitation and security audit events | 12 months from the event |
| Terms, privacy-notice and authority evidence | Account life plus 24 months |
| Privacy, access, correction, deletion and support cases | 24 months after the case is completed |
| Exceptional identity or legal evidence | Restricted and deleted within 30 days after resolution unless law requires longer |
| Push token and notification preference | Disabled and deleted when permission is withdrawn, the endpoint is invalid, or the account is deleted |
| Ordinary operational logs | 30 days or less; provider-native shorter retention applies where available |
| Security incident and material security-event records | 12 months, longer only for an active investigation or legal requirement |
| Operator-created backup, if one is made | 30 days unless isolated for an active incident/restore; then delete after the need ends |
Convex documents that manual and daily backups are available for up to 7 days and weekly backups for up to 14 days when those features are enabled. We will state those periods as active facts only after checking the production configuration. Deleted information may remain inaccessible in a rotating backup until that backup expires. A restore must reapply deletion records before restored data is served.
10. Account deletion, child deletion, family closure and leaving
Delete account
You can initiate account deletion at More → Settings → Account → Delete account. We also provide a working deletion route at https://newbieparents.app/account-deletion for a person who no longer has the app. We may require recent sign-in or other proportionate verification.
Deletion immediately ends sessions, memberships, pending invitations, push endpoints and access. We complete deletion of live account data within 30 days. We also delete every care entry authored by that account, including structured entries and free text, so shared family history and summaries may change. We do not silently transfer authorship to someone else.
We may retain only the minimal evidence described in section 9 for security, rights handling, accepted legal versions and binding legal requirements. That evidence does not retain the deleted person's child-care content.
Leave family
Leaving a family ends future access but does not delete the account or the records already contributed while the account remains active. If the person later deletes their account, their contributed entries are deleted as described above.
Delete a child or close a family
Only an Owner can delete a child or close a family under Settings → Family. Access and writes end immediately, and the affected live content is deleted within 30 days. Deleting the last child closes the family. Backup expiry and local-device limits still apply.
Local devices and offline copies
When a signed-in device learns that access has ended, the app clears its local family data and rejects queued writes. We cannot instantly erase a copy from a device that remains offline, has been altered or is outside our control. Users should sign out and remove the app from devices they no longer control. Screenshots, manual copies and information another person separately recorded outside Newbie Parents are not under our technical control.
11. Security
We use administrative, technical and organisational measures designed for the sensitivity of family and child information. These include authenticated access, family- and child-scoped authorisation, role limits, session and invitation controls, encrypted network transport, restricted administrator access, audit/security records, secrets management, provider review, dependency and release checks, and incident-response procedures.
No service or storage method is completely secure. We do not promise that Newbie Parents will never experience a security incident. If an incident occurs, we will investigate, contain and assess it and make notifications required by applicable law.
12. Access, correction and consent withdrawal
You can correct many account, profile and care details in the app, subject to role and authorship rules. You may also contact jargonautlabs@gmail.com to request access to personal data in our possession or control, information about its use or disclosure during the applicable preceding period, or correction of an error or omission.
We will verify the request proportionately, search the relevant systems, protect other people's data and apply any legal exceptions. We respond as soon as reasonably possible. If we cannot complete an access or correction request within 30 calendar days, we will tell you in writing when we expect to respond.
Where processing depends on consent, you may withdraw that consent with reasonable notice by changing the relevant optional setting or contacting us. We will explain the likely effect. Withdrawal does not undo processing that was lawful before withdrawal and may mean that an optional feature stops working. Where the requested effect is to end essential account or family processing, the practical routes may be leaving a family, deleting the account, deleting a child or closing the family.
The PDPA's data portability obligation is not represented as an active right until the applicable regulations take effect. We do not currently promise a self-service report or export feature; a valid access request is handled through the process above.
13. Children's information and authority
The service is used by account holders to record information about children. It is not directed to a child to create and manage their own tracking account.
If you provide a child's information, you confirm through the Terms that you are the child's parent or guardian, or are validly acting on their behalf. An invited Owner, Caregiver or Helper must use the information only within the access granted to them and the role shown in the app.
“Owner” is only an app-administration role. We do not verify or adjudicate custody, guardianship or family relationships, and we do not change access merely because conflicting family claims are sent to support. Families must resolve those issues outside the app. We comply with binding legal process when required.
14. Links, sources and third-party services
Newbie Parents may link to hospitals, public agencies, clinical guidance and other third-party websites. A source link identifies the basis of general guidance; it does not mean the third party endorses Newbie Parents. Those services have their own terms and privacy practices, and we are not responsible for their content or availability.
If Newbie Parents later displays commercial or affiliate content, it will be clearly disclosed and kept outside clinical, safety, government, insurance, logging and Insights decisions. Such a feature is not active merely because this Policy describes how a future disclosure would work.
15. Changes to this Policy
We may update this Policy to reflect a changed service, provider, legal requirement or practice. We will keep a version and effective date. If a change materially affects what we collect, why we use it or who receives it, we will give a clear in-app or email notice before the change takes effect where reasonably practicable and record the version shown. Editorial or clarity changes do not require a new checkbox.
16. Contact
Privacy, access, correction, consent withdrawal and deletion: jargonautlabs@gmail.com
Interim Data Protection Officer: Frank Tan
Operator: JARGONAUT LABS PTE. LTD. (UEN 202639127H) Website: https://newbieparents.app