Privacy Policy
Effective date: July 11, 2026 · Last updated: September 1, 2026
This Privacy Policy describes how Don't Buy That Yet (“we”, “us”, or “our”) collects, uses, and shares information when you use the Don't Buy That Yet: Baby mobile application (the “App”) and the websites we operate (together, the “Services”). We built the Services around a simple idea: help you buy less, not learn more about you. We collect the minimum we need to run the audit you ask for.
1. Information we collect
Information you provide
- Your baby lists. The product names you paste or type from registries, wishlists, retailer carts, checklists, notes, or other sources so we can audit them. The combined list should contain product names only — please do not include names, addresses, or other personal details in it. We apply automated filtering to the text you submit, but the best protection is not to paste personal information in the first place.
- Household answers. Your answers to the App’s short questionnaire — for example expected due date or baby age range, home and storage type, budget range, and buying preferences. These exist only to shape the audit.
- Your check-in answers. Some time after an audit, the App may show a short check-in asking what actually happened with the items it suggested you cut, delay, or buy used — for each one, whether you bought it, didn’t buy it, or are still deciding, and whether you kept something we suggested cutting. Answering is optional and you can dismiss the check-in in one tap. We ask because it is the only way to know whether our advice was any good, and it is what lets us tell future users things like “most people who delayed this never ended up needing it.”
- A photo of a list, if you choose to send one. The App can take a photo or accept an image of a list — a registry page on screen, a handwritten note, a screenshot of a message — and read the item names out of it so you do not have to type them. If you use this, the image is sent to our server, read once, and discarded immediately. We do not store it, we do not keep a copy, we do not log it, and it is never attached to your audit or to any record we keep. Only the item names it produced are kept, exactly as if you had typed them. A photo can show far more than a list — other people, a room, an address on an envelope — so please photograph the list and not its surroundings, and treat this the same way as the note above about not pasting personal details.
- Messages you send us. If you contact us (for example by email), we receive your email address and the contents of your message.
Information collected automatically
- An account identifier. The App creates an account for you on first launch and signs in automatically. By default that account is a random identifier with no name, email address, or phone number attached to it — we never ask you for any of them.
- An Apple or Google account, only if you choose to sign in. The App can attach your Apple or Google account to the account described above, so that purchases you have already made survive reinstalling the App or moving to a new phone. This is optional and most people never do it. When you do, our authentication provider (Google Firebase) receives and stores the email address on that Apple or Google account, and the name on it if the provider supplies one; our own database stores only that you signed in, which provider, and when. Apple’s “Hide My Email” gives us a relay address instead of your real one, and works normally here.
- Basic technical data. App version, device platform and OS version, request timestamps, and IP addresses in our server logs, used for security, rate limiting, and debugging.
- First-launch attribution, when enabled. The App may record the first launch once (write-once) and send it to our backend. The record contains the capture timestamp, platform, App build, and consent schema/version. The consent schema/version is a version marker for the privacy disclosure and related collection context that applied; it is not a record that you gave affirmative consent. The record may also contain source, medium, campaign, content, and term, but each of those optional values is accepted only if it passes a strict allowlist and is 1–64 characters long. When no campaign source is configured, all five optional fields are empty. Our backend authenticates the account and derives a pseudonymous purchaser key so we can join launch attribution to purchase outcomes. This record does not contain IDFA, AAID, a device, install, or advertising identifier, a raw purchase token, email, name, phone number, or free text.
- Crash and diagnostics data. The App includes Firebase Crashlytics, a crash reporting tool provided by Google. When the App crashes, it sends Google a diagnostic report so we can find and fix the bug: the crash’s technical stack trace, the App version, your device model and operating system version, and basic device state at the moment of the crash (for example, whether the device was low on memory). Each installation of the App is given a random Crashlytics installation identifier so that multiple crash reports from the same install can be grouped together. That identifier is generated by Google, is not linked to your name, email address, or advertising identifier, and is reset if you delete and reinstall the App. We use crash data only to fix crashes. We do not use it to build a profile of you, to track you, or for advertising, and we do not attach your list text, household answers, or session tokens to crash reports.
- Two actions inside the App. When you mark a suggestion “Keep Anyway”, and when you copy your family summary to share it, the App tells our backend that it happened, attached to that audit. That is the complete list — two actions, both of which you take on purpose. Disagreeing with an audit is useful signal, and we would rather learn it from the button you actually pressed than by guessing.
- A push notification token, if you allow notifications. If you allow the App to send notifications, it registers a push token — an opaque, provider-issued identifier for your device — with our backend so we can let you know when an audit you started has finished. The token is stored on your account record. Alongside it we store the time zone your device reports — a region name such as “America/New_York”, never your precise location — used only to hold a notification until a reasonable hour where you are instead of sending it in the middle of the night; it stays on our servers and is not sent to the push delivery providers. The token is used only to deliver that one notification. It is not used for advertising, tracking, or building a profile of you, and we do not share it with anyone beyond the push delivery providers themselves — Apple (Apple Push Notification service) and Google (Firebase Cloud Messaging) — who need it to route the notification to your device.
- Website logs. Our websites are served by Cloudflare and produce standard server logs.
What we do not run
We do not run advertising trackers, and we do not use advertising identifiers. We do not run behavioral or product analytics SDKs — nothing in the App reports which screens you visit, how long you spend, or where you drop off. Crash reporting, described above, is the one third-party SDK in the App that reports anything automatically, and it reports only crashes. When enabled, first-launch attribution is separate first-party acquisition measurement, not an advertising tracker or a behavioral or product analytics SDK.
The check-in answers and the two actions described above are the exception, and we want to be straight about it rather than hide behind “we don’t do analytics”: those are things you did in the App that we record. The distinction we are drawing is between measuring you and measuring our own advice. We are not building a profile of your behavior, and we are not watching you use the App. We are checking whether the recommendations we gave were right, using answers you chose to give and two buttons you chose to press.
Information we do not collect
Apart from an email address if you choose to sign in, as described above, we do not collect your name, phone number, contacts, photo library, precise location, health records, payment details, or advertising identifiers. We do not sell personal information, and we do not share it for cross-context behavioral advertising.
One clarification, because we would rather be exact than sound better than we are: this page previously said we do not collect photos at all. That is no longer the whole truth, now that you can send a photo of a list to save yourself typing it. We do not have access to your photo library, we do not browse it, and we never take an image you did not deliberately choose or capture. The one image you send is read once and discarded, as described above. We would rather explain that plainly than leave a sentence standing that was quietly no longer accurate.
2. How we use information
- To generate your baby-list audit and savings plan — the service you asked for.
- To find out whether our recommendations were actually right, and improve the guidance every future audit gives, using de-identified check-in results as described below.
- To operate, maintain, debug, and improve the reliability of the Services.
- To protect the Services, including rate limiting, abuse prevention, and security.
- To measure first-party acquisition and join first-launch attribution to purchase outcomes using the pseudonymous purchaser key described above.
- To let you know when an audit you started has finished, if you have allowed the App to send notifications.
- To comply with legal obligations and enforce our terms.
- To respond when you contact us.
3. How artificial intelligence is used
The audit is generated with the help of large language model (“AI”) providers, such as Anthropic. When you run an audit, we send the product names from your list and your household answers to the AI provider through its commercial API so it can produce the keep / cut / delay / buy-used / buy-new recommendations.
Two smaller uses of the same providers, so there are no surprises. When you add items to your list, we may send those lines to check they look like real items and to flag anything that appears to be stray text — a copied “Add to cart”, a page heading — so it does not end up in your audit. And if you send a photo of a list, the image itself goes to the AI provider to be read, then is discarded as described above. Both are the same commercial API terms, with the same prohibition on training, as the audit itself.
- What is sent is anonymized. The request contains the list text and questionnaire answers only. It does not include your name, email address, phone number, device identifiers, or advertising identifiers. The crash reporting identifier described above is never sent to AI providers.
- Your data is not used to train AI models. We do not use your information to train AI models, and the commercial API terms we use with our AI providers prohibit them from training their models on data we send.
- Limited retention by providers. AI providers may retain API inputs and outputs for a limited period for abuse and safety monitoring under their commercial terms, after which they are deleted.
4. How we share information
We share information only with:
- Service providers that process it on our behalf and are authorized to use it only as necessary to provide services to us: cloud hosting and infrastructure (Google Cloud, in the United States), crash reporting (Google, via Firebase Crashlytics), push notification delivery (Apple, via Apple Push Notification service, and Google, via Firebase Cloud Messaging), website hosting (Cloudflare), and AI providers (such as Anthropic) as described above.
- Public authorities where required by law, subpoena, or legal process, or to protect the rights, safety, and security of our users, the public, or the Services.
- A successor entity in connection with a merger, acquisition, or sale of assets, in which case this Policy will continue to apply to previously collected data.
When collected, first-launch attribution is sent to our backend for our own first-party acquisition measurement. We do not share it with ad networks, use it for cross-app tracking, or sell it.
We may use aggregated or de-identified information that cannot reasonably be used to identify you for any lawful purpose, such as understanding which product categories are most often overbought.
5. Data retention
Audit requests and results — including your list text, household answers, and any check-in answers attached to that audit — are automatically deleted within 365 days of the audit completing. This is enforced by our database rather than by someone remembering to run a cleanup. Photos of lists are not retained at all: an image is read during the request that sends it and then discarded, so there is nothing to delete later and nothing that a 365-day window applies to. Server logs are retained on shorter cycles. Crash reports are retained by Google on Firebase Crashlytics’ own schedule, after which they are deleted; deleting and reinstalling the App resets the crash reporting identifier described above. Signing in is optional, and deleting the App removes the account session from your device but does not itself delete server-side data. You can delete your account and its data from inside the App, or request deletion of data associated with an audit without deleting the account, as described below.
Inactive accounts are deleted for you. If an account goes 365 days without any activity from the App, we delete it automatically — the account itself, its server-side record, and the data described above that is still attached to it. This runs on a schedule rather than on request, so an account it covers does not sit on our servers indefinitely. It was previously a 90-day window; we lengthened it to 365 days so that people who come back to the App after a long gap — which, for a product used across a pregnancy and a first year, is normal — still find their account rather than a blank one. This automatic deletion does not apply to an account that has bought something or that you have signed in to. Those we keep until you delete them, because deleting them would destroy a purchase you paid for or an account you can still sign back in to. You can delete either at any time from inside the App.
When collected, the write-once attribution record and pseudonymous purchaser key are retained for no more than 365 days and are deleted sooner when the associated account is deleted. We do not retain a raw purchase token.
If you allow notifications, your push notification token, and the device time zone stored with it, are kept on your account record for as long as the account is active. They are deleted when you delete your account, as described below, and — for an account the automatic deletion above covers — are swept out with that account after 365 days without App activity.
What outlives that window. When you answer a check-in, we separately keep a de-identified record of the outcome: a general product category, what the audit recommended, what you told us happened, and the item’s price if your list included one — for example “stroller · $340 · delay · didn’t buy”. These records carry no session identifier, no registry text, and nothing tying them to you or to each other beyond the single audit they came from, and that link is severed when the audit is deleted. We keep them because our advice only improves if we can see, in aggregate, how it turned out — and we would rather hold a category and an outcome indefinitely than hold your actual list and answers any longer than we do. Because they cannot be connected back to you, they cannot be individually retrieved or deleted on request, and they are not personal information.
6. Account and data deletion
To delete your account and its data in the App:open Don't Buy That Yet: Baby, choose Privacy & Data from the Welcome screen, choose Delete account & data, and confirm. This deletes the Firebase account behind your account — and with it, any email address or name Firebase held if you had signed in — the server-side account record, the audits and list text associated with it, and any first-launch attribution record, pseudonymous purchaser key, and push notification token associated with the account, then signs out the App on that device. If you had signed in with Apple, this also revokes that sign-in. The action cannot be undone, and it does not ask you for a password: the App is already signed in as you, on the device where you tap delete.
To request deletion of data without deleting your account: emailsupport@nestingwise.com and say that the request is forDon't Buy That Yet: Baby. Include the approximate date and time of the audit and enough non-sensitive list item names to help us identify it. Do not include passwords, payment details, or other sensitive information in the email. If you have signed in with Apple or Google, say so — we can locate your account from that. If you have not signed in, an audit is not linked to your name, email address, or phone number, so we may be unable to locate a record without enough audit details.
A deletion request removes personal data associated with the account or audit from our active systems. De-identified outcome records that cannot be connected back to you or to your account may remain. Images sent for list reading are discarded after processing and are not retained. Server and security logs may remain for their normal retention cycle, and crash reports are retained by Google Firebase Crashlytics under Google’s schedule. We will handle requests under the applicable law and our operational procedures; this page does not promise a specific completion time.
7. Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to opt out of certain processing. If you have signed in with Apple or Google, we can locate your account from that sign-in, and these rights are exercised normally — you do not need to supply audit details. If you have not signed in, we hold so little tied to you that some rights may be technically limited: an audit is not linked to a name or email address, so we may not be able to locate data connected to you specifically unless you can provide enough audit details. Either way, there is no automated way inside the App to request or receive a copy of your data today; contact us at the address below and we will handle the request by hand. We will not discriminate against you for exercising any of these rights. Residents of the European Economic Area and the United Kingdom may also lodge a complaint with their supervisory authority.
8. Security
All traffic between the App, our servers, and our service providers is encrypted in transit using HTTPS/TLS. We use administrative and technical safeguards appropriate to the small amount of data we hold. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
9. Children’s privacy
The Services are for adults — expecting and new parents — and are not directed at children. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact us and we will delete it.
10. International users
The Services are operated from and processed in the United States. If you use them from outside the United States, you understand that your information is transferred to and processed in the United States and in the countries where our service providers operate.
11. Changes to this policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above, and for material changes we will provide additional notice within the App or on this site. Continued use of the Services after changes take effect means you accept the revised Policy.
12. Contact us
Questions or requests about privacy: support@nestingwise.com.