MAPLE ROOST PRIVACY POLICY
Last Updated: August 4, 2026
Version: 1.10.1
1. INTRODUCTION
Maple Roost LLC, a Florida limited liability company ("Maple Roost," "we," "us," or "our"), is committed to protecting your privacy and the privacy of the children whose information is tracked in our baby tracking application ("App"). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our App.
Our Privacy Commitment: We do not sell or rent personal information for third-party marketing purposes. We do not use personal data for advertising or for any purposes unrelated to the Maple Roost App's core features.
2. INFORMATION WE COLLECT
2.1 Personal Information You Provide
- Account information (name, email address, password)
- Profile information (parent/caregiver details)
- Child information (name, date of birth, gender, photos)
- Activity data (feeding, sleeping, diaper changes, growth measurements)
- Health records you choose to enter, including vaccinations, medications, symptoms, doctor appointments, and other health events, and optional feeding-safety details you choose to enter (for example, eczema severity or a doctor-diagnosed food allergy), used only to gently tailor First Foods guidance — never to diagnose or score your child
- Notes and observations about your child
- Communication preferences
- Authentication and security data: if you enable two-factor authentication, a verification factor and one-time recovery codes (stored only as cryptographic hashes), plus limited records of the devices you have signed in on
2.2 Information About Children Under 13
We collect only the child information you choose to enter and only what is needed to provide the App's features. The categories you may choose to enter include:
- Child's name and date of birth
- Growth and development tracking data
- Activity logs (feeding, sleep, diaper changes, etc.)
- Photos (only if uploaded by parent/guardian)
- Health and milestone information, including vaccinations, medications, symptoms, doctor appointments, and other health events the parent chooses to record, and optional feeding-safety details (for example, eczema severity or a doctor-diagnosed food allergy) used only to gently tailor First Foods guidance — never to diagnose or score your child
2.3 Automatically Collected Information
- Device information (device type, operating system, app version) — the technical basics needed to deliver the service and app updates
- Technical logs our servers generate when your app talks to them (for example, request and error logs). We do not use any third-party analytics or crash-reporting service, and we do not track which features you use or how long you spend in the app.
- Sign-in reliability diagnostics (first-party): when the app starts, it records which storage path your sign-in used (a one-word status like "secure"), whether stored sign-in copies were present, whether the previous session ended unexpectedly, the app version, build, and update channel, and a random device identifier we generate (not a hardware identifier). This is uploaded only to our own servers, only while a family member is signed in — never for guests using a Sitter Pass — and contains none of your content: no names, no photos, no health data, no location, and nothing your family recorded. We use it solely to verify that security upgrades to how your sign-in is stored never sign anyone out.
- IP address: collected as technical and security data when you use the App and when you sign consents. An IP address can approximate your city or region but is not GPS or device-level precise location data. See Section 2.4 for our full location statement.
2.4 Location Data
We do not collect GPS or device-level precise location data. We do collect IP addresses (technical/security data), which can approximate a city or region. The IP address collected at the time of consent signing is recorded server-side from your device's request to our own servers when consent is saved — no third-party service is involved — and is used for fraud-prevention and consent records.
2.5 Information We Do NOT Collect
- Social Security Numbers or government identity numbers
- Payment card information (all billing handled by Apple; see Section 4.4)
- GPS or device-level precise location
- Biometric data
- Audio or video recordings (other than photos you upload)
- Information from third-party social media (unless you explicitly connect)
The optional Face ID, Touch ID, or passcode app lock uses your device's built-in authentication, handled entirely by Apple on your device. Your biometric data never leaves your device and is never collected, transmitted to, or stored by us. Likewise, if you enable the optional Face Suggestions feature, face data is created, stored, and used only on your device and is never sent to or collected by us (see Section 3.1).
3. HOW WE USE INFORMATION
3.1 Primary Purposes — Including Automated Processing
- Provide baby tracking and monitoring services
- Store and organize your child's activity data
- Generate reports and insights about your child's patterns
- Facilitate sharing with authorized caregivers
- Provide customer support
- Nap prediction: Sleep data is processed by Maple Roost's own predictive model, which runs on your device. This data is not sent to any third-party AI provider. The model estimates the next nap window based on your child's historical sleep patterns. The resulting estimate (the predicted time, the actual time, and the difference between them) is saved to your account so that both parents' devices show the same prediction; that derived estimate is not client-side encrypted (see Section 5.1).
- On-device summaries and recaps (Private AI): We can generate short written recaps, summaries, titles, and highlights from information you have already entered (for example, a weekly recap of your child's activities). This processing happens on your device. Your and your child's information is not sent to OpenAI, to our servers, or to any other third-party AI provider to produce it. Where your device offers built-in (on-device) intelligence we may use it; otherwise we use on-device templates. A summary saved to your account is stored and synced like the other content you create. These summaries are produced automatically and may be incomplete or imperfect.
- On-device face suggestions (optional): If you turn on Face Suggestions, the App analyzes the photos you have added to detect faces and suggest name tags, entirely on your device. Face data (including face geometry and the numerical face representations used for matching) is created, stored, and used only on your device, is never sent to Maple Roost's servers or any third party, and is deleted from the device when you turn the feature off. Only the name tags you explicitly confirm are saved with a memory, protected like your other content. This feature is off unless you enable it.
- Daily motivational quotes: Short motivational quotes shown in the App are generated using the OpenAI API. No personal data about you or your child is included in those prompts.
3.2 Secondary Purposes
- Improve and develop new App features
- Send important updates and notifications
- Ensure App security and prevent fraud
- Comply with legal obligations
- Conduct research (only with aggregated, de-identified data)
3.3 Children's Information
Information about children under 13 is used ONLY for:
- Providing the tracking services requested by parents
- Generating reports for parents/guardians
- Ensuring the child's safety and well-being through the App
- Complying with legal requirements
4. INFORMATION SHARING AND DISCLOSURE
4.1 We Do Not Sell or Rent Your Information
We do not sell or rent personal information for third-party marketing purposes. We do not use children's personal information for any commercial purpose beyond operating the App.
4.2 Authorized Sharing
We may share information only in these limited circumstances:
- With Your Consent: When you explicitly authorize sharing
- Caregiver Access: With caregivers you have granted access to
- Service Providers: With vendors who help operate the App, under their published terms of service and data-processing terms (see Section 4.4)
- Legal Requirements: When required by law or to protect safety
- Child safety: If we become aware of apparent child sexual abuse material or child exploitation, we report it — including related account information — to the National Center for Missing & Exploited Children (NCMEC) as required under applicable law, including 18 U.S.C. § 2258A, and we preserve the material and related records as required by law. We do not scan or review your content: entries and photos protected by your Memory Key are encrypted on your device, so we act on what is reported to us
- Business Transfers: In the event of a merger, acquisition, or sale of substantially all assets, your information may be transferred to the successor entity. Any successor is bound by this Privacy Policy and may not use your personal information for third-party marketing without obtaining fresh consent.
4.3 Children's Information Sharing
Children's information is shared ONLY:
- With the parent/guardian who provided consent
- With caregivers explicitly authorized by the parent
- When required by law (child safety, court orders)
- With the service providers that help us operate the App, under their published terms of service and data-processing terms (see Section 4.4)
4.4 Third-Party Service Providers
We work with the following third-party service providers to operate our App. We use each of them under their own published terms of service, privacy commitments, and data-processing terms, for the specific service function described:
- Supabase — Hosting, database, and file storage. Supabase provides encryption in transit and at rest at the infrastructure level. Your data resides on Supabase-managed servers.
- OpenAI — Used to generate the daily motivational quotes shown in the App; no personal data about you or your child is included in those prompts. We rely on OpenAI's published API data-usage terms, under which data submitted through the API is not used to train its models by default. The App's on-device summaries and recaps (Section 3.1) do not use OpenAI or any third-party AI service.
- Expo (exp.host push service and EAS Update) — Routes push notifications to your device and delivers over-the-air updates to the App. Expo relays notifications through Apple Push Notification service (APNs) and Google Firebase Cloud Messaging (FCM) as downstream transports. For notifications, only the notification payload and your device push token are transmitted; these notification payloads may include your child's first name and the activity being reported (for example, that a sleep session started) so co-caregivers receive a meaningful alert. Live lock-screen timers (Live Activities) are delivered directly to your device via Apple's push service (APNs) from our servers and carry the same limited content — your child's first name, the activity, and its timing. For over-the-air updates, your device asks Expo whether a newer version of the App is available. That check sends only the technical details needed to serve the right version — your platform, the app's version and release channel, an identifier for the update currently installed, and a random installation identifier — together with the ordinary request information (such as an IP address) that any web request carries. No information about you or your child is included in an update check.
- Resend — Delivers our transactional emails (for example, sign-in and verification codes) to the email address on your account. Only your email address and the message being sent are shared, for delivery only.
- Cloudflare — Routes email sent to our @mapleroost.app addresses (for example, privacy@, coppa@, and legal@) to our mailbox. Anything you send us at those addresses, including anything about your child that you choose to write, passes through Cloudflare in transit.
- Apple App Store — Handles all in-app purchase billing for subscriptions and premium features. We do not receive or store your payment card information. Apple handles your purchase as its own business, under its own terms — not on our behalf — and Apple's privacy policy governs its handling of payment data.
- RevenueCat — Manages subscription entitlements, so the App knows what your account is entitled to. We send RevenueCat your Maple Roost account identifier together with the purchase information Apple provides. No information about your child is sent to RevenueCat.
- Netlify — Hosts our public website at mapleroost.app, including these legal documents, the Handoff (guest pass) claim page, and the public Emergency Card page described in Section 4.6. When one of those links is opened, Netlify processes that request — including the link's token and ordinary request information such as an IP address — in order to serve the page, which means the sanitized emergency information you choose to publish is served through Netlify.
The IP address recorded when you accept our legal documents (for fraud prevention and consent record-keeping) is captured server-side from your device's request to our own servers at the moment consent is saved; no third-party service is involved. It is stored as part of the fraud-prevention and consent audit record.
4.5 Caregiver Handoffs (guest passes)
You may create a Handoff — a temporary, time-limited guest pass — that lets a babysitter or other caregiver — using an anonymous guest session, with no account of their own — view your child's profile and emergency information and — unless you choose a view-only pass — log activities such as feedings, sleep, and diaper changes during a window you set (up to seven days). You choose the scope (for example, whether the child's photo is shared, or a view-only pass that cannot log anything) and you can revoke a Handoff at any time.
4.6 Emergency Sharing You Initiate
If you create an Emergency Card for your child, a sanitized subset of that child's medical information (for example, allergies, medications, conditions, and emergency contacts) is made available at a public web link encoded in a QR code, so first responders can access it without an account. You may optionally protect this link with a PIN. The link, the printed card, the Apple Wallet pass, and any NFC tag you write all carry this access and are shareable by you; anyone who has them can view the sanitized record until you regenerate the QR code. Insurance ID numbers, the PIN, and the underlying access token are never shown on the public page.
4.7 Files You Generate and Share
Some features let you generate and share files that contain your child's information and photos — for example, a monthly keepsake PDF, a printable emergency card, or a photo you choose to save or share from the App using your device's share sheet (including saving it to your device's photo library). When you use your device's share options to send these files, the recipient, and any app you choose to share with, are outside our control and are governed by their own terms.
5. DATA SECURITY
5.1 Security Measures
- Encryption in transit and at rest: Provided at the infrastructure level by our hosting providers (principally Supabase).
- Client-side (on-device) encryption: Maple Roost uses client-side encryption for your sensitive family data. When you create a Memory Key (recovery key), the entries, notes, and photos you record are encrypted on your device with keys held by you (your Memory Key, and on Apple devices your device keychain), which we never receive. Because the keys stay with you, we do not hold the keys to that content — so we cannot read those encrypted entries and photos, and they are stored on our servers only in encrypted form. That statement is about who holds the keys to that specific content. It is not a broader guarantee about the security of our systems, and it does not extend to the data listed below as not client-side encrypted. This also means we cannot recover it for you: if you lose your Memory Key and your device's keychain copy is not available, we cannot read or restore that content — not even at your request. If you have not created a Memory Key, this on-device encryption is not in effect for your account, and what you record is stored in readable form on our servers. Creating a Memory Key protects what you record from that point forward; it does not reach back and re-protect content that was already stored in readable form, and earlier readable copies — including photos — can remain on our servers. Some data is intentionally not client-side encrypted so the app can function: your child's name and basic profile details, emergency-profile information shown to responders, notification content, the nap-time estimates described in Section 3.1, data and PDFs you export, and basic scheduling metadata (dates and which child an entry belongs to). During an earlier rollout period a readable server-side copy was briefly kept as a safety net so no memory would be lost while the feature stabilized; that safety-net copy has since been removed.
- Secure authentication and access controls
- Optional two-factor authentication (2FA): you can protect your account with an authenticator app; one-time recovery codes are stored only as cryptographic hashes
- App lock (on by default; you can turn it off in Settings): the App can require Face ID, Touch ID, or your device passcode to open it on your device. This uses your device's built-in authentication, and your biometric data never reaches us
- Periodic security reviews, automated checks that run on every change to our code, dependency updates, and remediation of the issues we find
- Access to production systems limited to the small number of people who operate the service
- Secure cloud infrastructure with industry-standard protections
5.2 Data Retention
We follow a single, consistent retention schedule:
- While your account is active: All account and child data is retained to provide the Services.
- After a deletion request: Your personal data is removed promptly from our active production systems. Records of a child who has a designated co-parent pass to that co-parent instead of being deleted (see "Shared children" below); children with no co-parent are deleted.
- Shared children: A child's records are family records. If a child on your account has a designated co-parent, that child's profile, entries, and photos are not deleted when you delete your account — they pass intact to the co-parent, and your name is removed from entries you authored. Entries you logged in the child's shared record — including feeding and nursing details — remain part of the child's record with authorship removed, and where both parents kept a scrapbook for the same month, the surviving parent's copy is retained. A child with no co-parent is permanently deleted with your account.
- What can remain in a surviving family's records: When a child's records pass to a co-parent, some traces of your account can persist inside that family's surviving records: opaque storage identifiers (upload-path segments inside their encrypted photo files and stored links), your entries with authorship removed, and — if our best-effort cleanup of internal uploader-metadata fields on surviving photo files does not complete — those metadata fields until it does.
- Encrypted backups: Residual copies in our hosting provider's encrypted backups are overwritten on the standard backup-retention cycle, within 90 days.
- Consent and acceptance records: Records of your consent acceptances (including timestamps and IP addresses captured for fraud prevention) are retained longer where required by applicable law.
- Security audit records: Minimal security audit records (sign-in and account-lifecycle events) may be retained for a limited period for fraud and abuse prevention.
- Limited transaction records: Billing and transaction records are retained as required by Apple App Store policies and applicable financial regulations.
- Aggregate/de-identified data: Aggregated, de-identified analytics that cannot be linked back to you are not subject to deletion timelines.
You can request deletion of your data at any time via the App or by contacting privacy@mapleroost.app.
6. COPPA COMPLIANCE (CHILDREN UNDER 13)
6.1 Parental Consent
- Before any child information is collected, we take two steps, and these are the only two steps we take. When you create your account, you verify your email address (a one-time code sent via our authentication system) and accept the Terms of Use and this Privacy Policy with a single checkbox that is never pre-checked; the full documents are available to read before accepting and at any time in Settings → Legal. Then, when you add your child's profile and before any child information is collected, you give explicit parental consent to our children's-information practices by checking an acknowledgment of the COPPA Parental Consent Notice. Maple Roost is designed for use only by adults, and children may not create accounts or use the App; a child's information reaches us from a parent or guardian, not from the child. We may strengthen or change this process as legal requirements and available technologies evolve. See Section 12 of the COPPA Parental Consent Notice.
- Parents can review, modify, or delete their child's information at any time
- Parents can revoke consent and request data deletion at any time
6.2 Limited Collection
- We collect only information necessary for the App's functionality
- No behavioral advertising to children
- No sharing of children's information for commercial purposes
6.3 Parental Rights
Parents have the right to:
- Review their child's personal information
- Request correction or deletion of information
- Refuse further collection or use of information
- Receive notification of material changes to this policy
7. YOUR PRIVACY RIGHTS
7.1 Access and Data Export
You may export a copy of your data through the App at any time, or request one by contacting us. The "Export everything" option bundles your account information, activity records, and the photos you have uploaded into a single file — assembled and (where applicable) decrypted on your device — that you can save or share. A data-only export (without photos) is also available. Exports are available whether or not you have an active subscription.
7.2 Other Controls
- Correct inaccurate information in the App
- Delete your account and your associated personal data (see Section 5.2 for timelines, and for what happens to a child shared with a co-parent)
- Control sharing and privacy settings
- Opt out of non-essential communications
- Choose notification preferences
7.3 State-Specific Rights
If you are a resident of California or other states with similar privacy laws, you may have additional rights including:
- California Privacy Rights Act (CPRA): Enhanced rights to know what personal information we collect, delete your information, correct inaccurate data, and obtain a copy in a portable format
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights
- Data Minimization: We collect only the minimum personal information necessary for our services
- Other State Laws: We recognize and will facilitate similar rights under other applicable state privacy laws
We do not sell or share personal information for cross-context behavioral advertising. To exercise these rights, contact us at privacy@mapleroost.app.
8. INTERNATIONAL USERS
If you use the App from outside the United States, your information may be transferred to and processed in the United States, where privacy laws may differ from your jurisdiction.
9. THIRD-PARTY SERVICES
The App may contain links to third-party services or integrate with external platforms. This Privacy Policy does not apply to those services. We are not responsible for the privacy practices of third-party services and encourage you to review their privacy policies before using them.
10. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy periodically. We will:
- Post the updated policy with a new effective date, in the App (More → Legal) and at mapleroost.app/privacy
- For a material change, show you in the App what changed, in plain language, and ask you to accept the updated policy before you continue using the App
- Obtain new parental consent where the law requires it for a change affecting children's information
11. DATA BREACH NOTIFICATION
In the unlikely event of a data breach affecting your information, we will notify affected users without unreasonable delay and as required by applicable law. That notice will:
- Describe what happened, what information was involved, and what we are doing about it
- Tell you what steps you can take to protect yourself
12. CONTACT INFORMATION
For privacy-related questions or requests:
- Email: privacy@mapleroost.app
- Maple Roost LLC, 7901 4th St N, STE 300, St. Petersburg, FL 33702, USA
For COPPA-related inquiries:
- Email: coppa@mapleroost.app
For exercising your privacy rights (access, deletion, correction):
- Email: privacy@mapleroost.app
- Include your full name, email address, and specific request
13. GOVERNING LAW
This Privacy Policy is governed by the laws of the State of Florida, without regard to conflict of law principles.
14. EFFECTIVE DATE
This Privacy Policy is effective as of August 3, 2026.