Momsie

Privacy Policy

This notice explains what personal information Momsie processes, why we use it, how long we keep it, and the choices and rights available to you and your child.

Who is responsible for your information

The data controller is Saied Hassan Alsaied Abbas, trading as Momsie ("Momsie", "we", "us"). You can contact us at hello@momsie.app.

Who Momsie is for

Momsie is designed for parents and caregivers, not for use by children themselves. A parent or caregiver enters information about a baby or young child to use feeding, planning, reaction-recording and handover features. The child is a data subject even though the adult provides the information on their behalf.

What information we collect

We process information you choose to provide, including your name; your baby's first name, date of birth or age, selected avatar, food restrictions and allergies; foods and meals you save; reactions you log; shopping-list items; meal plans; and other feature choices. If you create an account with Google or Apple, we receive an account identifier and may receive your email address and name. If you enable notifications, we store a device push token.

We receive subscription entitlement information from RevenueCat and the relevant app store, but we do not receive or store your payment-card details. We also process limited app-use, diagnostic and conversion information as described below.

Why we use information and our lawful bases

We use profile and interaction information to provide the Momsie service you request, personalise guidance by developmental stage, save your choices and synchronise supported features. Our Article 6 lawful basis for this core processing is that it is necessary to perform our contract with the account holder or to take steps they request before entering that contract.

We rely on consent for optional activities where consent is appropriate, including push notifications and publication of a nursery handover. We rely on our legitimate interests to secure, diagnose and improve Momsie and to understand non-advertising product performance, where those interests are not overridden by your or your child's rights. We may also process limited information where necessary to comply with a legal obligation.

Nursery and caregiver handover links

If you choose to publish a handover, it may contain your child's first name, age in months, allergies, foods to avoid, familiar foods, texture and preparation choices, feeding routine and a note you write. Allergy and reaction information may be health-related special-category data.

Immediately before publication, you must confirm that you are the responsible parent or guardian and explicitly consent to Momsie storing and making the selected feeding and allergen information available through the private link. For this health-related processing we rely on Article 9(2)(a) explicit consent, alongside the Article 6 contract basis described above.

Anyone who receives the bearer link can open it without a Momsie account, so you should send it only to the caregiver you intend. A new handover replaces and revokes the previous one. You can revoke an active handover from Profile at any time. The link expires after 30 days. Revoked, replaced or expired handovers become unavailable immediately and are removed from the live handover database within 24 hours. Withdrawal does not affect processing that was lawful before withdrawal.

The recipient page has no advertising or behavioural analytics, is marked not to be indexed, and is served with no-store caching controls. A recipient such as a nursery is responsible for information it copies into its own records.

Storage and retention

Account, profile and supported interaction information is stored on Supabase-managed infrastructure in Ireland (eu-west-1) and some working information is stored locally on your device. We retain account information while your account is active and delete associated live cloud data when you use Profile > Delete Account, subject to information we must retain for legal reasons.

Deleted information may remain temporarily in restricted disaster-recovery backups until those backups rotate out under the provider's backup lifecycle. Backup copies are not used for ordinary product processing. Uninstalling Momsie removes local app storage but does not by itself delete cloud account data.

Food Story photos

If you choose to add a photo to your baby's Food Story, Momsie requests camera or photo-library access only when you select that option. The photo is copied to Momsie's private storage on your device and is never uploaded to Momsie, Supabase, analytics providers, or any other third party. You can delete individual Food Story photos in the app. They are also removed when Momsie clears the local Food Story for an account change or reset, and uninstalling the app removes its local storage.

Subscriptions

Subscription payments are processed by Google Play or the App Store; Momsie does not receive or store your payment-card details. RevenueCat processes your app-store account identifier and entitlement status to manage subscription access.

Push notifications

If you grant notification permission, we may send food reminders, weekly progress recaps, and age-milestone feeding tips. You can withdraw permission at any time through your device settings. We do not use push tokens to track you across other apps or services.

Service providers and international transfers

We use Supabase for authentication, database storage and handover delivery; Cloudflare to host the public website and handover page; RevenueCat for subscription status; PostHog for product analytics; Sentry for crash and error reporting; Meta for limited app-install and subscription conversion measurement without advertising identifiers; Google and Apple for optional sign-in; the app stores for subscriptions; and Expo for app infrastructure and push-notification delivery.

Some providers may process limited information outside the UK or EEA, including in the United States. Where required, we use an applicable adequacy arrangement or approved contractual safeguards. We instruct our providers to process information only for the services they supply. Handover content and bearer tokens are not sent to PostHog, Sentry, Meta or advertising services. We do not sell personal information or display third-party advertising in Momsie.

Your rights

Depending on the circumstances, you or your child may have rights to access, correct, erase, restrict or object to processing, and to receive portable information. Where we rely on consent, you can withdraw it at any time. You can download supported account data through Profile > Download my data, delete your account through Profile > Delete Account, and revoke a handover from Profile.

Contact hello@momsie.app to exercise a right or ask a privacy question. We may need to verify that you are entitled to act for the account or child. You also have the right to complain to the UK Information Commissioner's Office at ico.org.uk.

Changes to this policy

We may update this notice as Momsie evolves or legal requirements change. We will update the date below and give an additional notice where a change materially affects how we use personal information. A privacy-notice update does not override your choices or turn continued use into consent.

Contact us

Saied Hassan Alsaied Abbas, trading as Momsie
hello@momsie.app

Last updated: 30 August 2026