Privacy Policy

Last updated 7 September 2026

Bubbi is white noise for sleep, plus a shared feed and sleep log. Playing a sound collects nothing extra. An account is only so two phones can share one log.

This policy describes what the Bubbi iOS app stores, what it can copy off the device if you ask it to, the note you can send us from Support, and how to delete all of it. It applies to the app and to this website.

Who we are

Bubbi is developed by the maker of the Bubbi iOS app (bundle identifier com.bubbi.Bubbi). Questions about this policy: hello@bubbisleep.com.

The short version

What the app stores on your iPhone

All of the following stay in the app's sandbox on that device.

What Why Where
Optional voice note after a session So you can say how a night went instead of typing it Application Support on this iPhone. Never uploaded.
Session summaries, cry bouts, and settle-curve blocks History, the night-to-night guidance clock, and the curve you already saw SwiftData on this iPhone. Copied to your family's account only if sharing is on.
Your name So the log can say who wrote a feed or a sleep SwiftData on this iPhone. Copied with the shared log if sharing is on. If you skip an account, the name is stored with this phone’s install id.
Your baby's name, optional birth date, optional due date, and optional photo To address you both about the same baby, and to match the day plan to age. A due date is only asked if they were born more than three weeks early, and it never leaves this phone. Without a birth date, Bubbi uses the most cautious advice. SwiftData on this iPhone. Name and birth date may copy to the other parent. Due date and photo stay here.
Memory Wall identifiers To put photos of your baby on a week-by-week wall. Bubbi looks at photos taken since the birthday, on this iPhone, and keeps only a list of which ones belong on the wall. Turning the wall off empties that list. The camera roll is never changed. SwiftData on this iPhone. Never uploaded. Not shared with the other parent.
Labelled sessions you export Only if you tap Export. A copy of the audio and labels is written where you can move it to a Mac. Files → On My iPhone → Bubbi → eval-corpus

Accounts

Bubbi works completely without an account, and choosing “Just use it on this phone” is a normal way to use it. Every feature except the second phone works the same.

If you do sign in, the only method is Sign in with Apple. We receive a stable identifier for your Apple ID, the name you choose to share, and an email address — which is a relay address if you use Apple's Hide My Email. First run also asks for your name if Apple did not hand one over, including when you skip the account. We never see your Apple password. There is no other way to create an account, so there is no password for us to store.

Two parents join one “family” by one of them generating a four-digit code in the app and the other typing it in. Codes expire after two days, work once, and are rate-limited on the server. Joining a family means both phones read and write one shared log for each baby in the family.

The usage ping, with or without an account

Each time you open Bubbi, start or finish a sound, log a feed, meal, sleep or activity, correct or delete one of those, open the player, the day plan, the log, Journey, the memory wall, the ideas or the settings, reach one of the first-run screens, see a note asking for an App Store review, sign in, sign out, turn sharing off, or delete your account, the app tells our server that it happened. If a sleep or play is still open when you open the app, that is sent too, as the same yes it sent when it started. That is how we know the app is actually being used, and which parts of it are.

The ping is a yes/no and, for a finished sound, sleep or activity, a duration. A few of them name one more thing, from a fixed list: which of the first-run screens you reached, which of the six sounds you played, and which review note you saw. The server refuses any word that is not on those lists.

It does not include audio, the baby's name, your notes, how much they ate, which meal it was, what the activity was, the times of anything, or the settle curve. A code that did not work is counted, never stored.

If you type your name on first run, or later in Settings, that name is stored with the install id so we can tell phones apart when there is no account. It is not the baby’s name, and it is not a word on the ping’s closed list — it labels the phone, the same way a Sign in with Apple name labels an account.

The phone is identified by a random install id stored on that iPhone. If you later sign in, we can attach that ping to your account so the two sides of the log match. Deleting the app, or deleting your account, starts that id over.

A note from Support

Settings has a Support screen at the top. If you write a note there, the words you type are sent to us so we can reply in that same screen. We may also write first — a reply, or a short note such as an App Store review link. The note can leave the phone with or without an account. We store the words, when they were sent, a random install id for that iPhone, the app version, and — if you are signed in — the account the token names. We do not ask for audio, and the composer cannot attach any.

Replies we write are stored on the same thread so they can appear on your phone. A https or mailto link in a note is tappable. Only the people who run Bubbi can read the thread. It is not part of the shared family log, and the other parent cannot see it.

Opening Support, or already allowing reminders, lets this iPhone send Apple a push token so we can wake you when a new note arrives. The alert shows a short preview of the note, not the baby's name or the log. The token is stored against that install id and is not used for ads.

Deleting your account removes support notes written while you were signed in. A note written signed out stays until you ask us to remove it. Email hello@bubbisleep.com.

What is copied off the device, and only if you ask

The shared log is not copied without an account, and signing in is what asks. The screen that offers Sign in with Apple states, above the button, that signing in copies your log; the same is true of the pairing code in Settings. Either way there is a single switch — “Share nights with the other parent” in Settings — that turns it back off and stops any further copying. With sharing on, each finished session, feed, sleep, solid or play is copied to your family's private area of our database so the other parent's phone can show it. That copy contains:

It does not contain audio, and it cannot be turned back into audio: a 30-second average of a cry level is not a recording. Voice notes and raw recordings are never copied, and neither is your baby's photo or optional due date.

Nobody outside your family can read any of it. Access is enforced by server-side rules keyed to your family, not by the app.

Paid ads

When Bubbi is advertised, two Apple systems measure it. Neither is an advertising SDK, and neither reads the advertising identifier.

SKAdNetwork: the app tells Apple which step of using the app this install reached — that it opened, that first-run finished, that a sound played, that something was written in the log, or that an account was created. Apple may pass that fact to the ad network in aggregate, without naming you. The value never says which sound, what was logged, or anything about your baby.

AdServices, for Apple Search Ads: on first open the app asks Apple for an attribution token and our server exchanges it with Apple. If this install came from a Search Ad, Apple tells us the campaign, ad group, keyword and storefront — identifiers, not a name and not the words you typed. We keep those so we can see which search terms bring parents who stay. The token is discarded after the exchange. An install that did not come from a Search Ad is stored as not attributed.

We do not include an advertising SDK. We do not read the advertising identifier. We do not ask for App Tracking Transparency. We do not follow you into other companies' apps.

Reminders

If you sign in and turn on “the other parent” in Settings, this iPhone sends Apple a push token so we can wake the other phone when a feed, sleep or meal is logged. The alert says the kind, the clock, and the next window when the day plan has one. It does not say who logged it, how much, or the baby's name. A next-window clock may travel with the row so we can write that line, the same way a change timestamp does; it is not a log entry of its own. The token is stored on your account and is deleted when you turn the reminder off, sign out, or delete the account. The same token kind is also used for Support notes, stored against the install id, as described above.

If this iPhone has allowed notifications, Bubbi may also send short daytime notes: when a nap window is coming, when a sound may help them settle, to ask whether they slept, a weekly Journey card, a morning hello, or a quiet note if the app has sat unused. Those notes come from the windows this iPhone is already guessing. Never at night. When a name is saved on this iPhone, a nap, settle, sleep-check or Journey note may show it, including on the lock screen. The other parent's alert still does not.

Who processes it

Our backend is Google Firebase — Firebase Authentication, Cloud Firestore, and Cloud Functions — acting as our processor. Data is stored in Google's europe-west1 region (Belgium). Google may process it in other regions for operational purposes under their own terms.

This website is static. It does not set tracking cookies and does not embed analytics.

What we never collect

Children

Bubbi is for parents, not for children to use. A birth date is stored only to choose age-appropriate timing, and stays on the device. We do not knowingly collect personal information from children off the device.

How to delete data

When the last member of a family deletes their account, the family's shared log is deleted with it. Nights the other parent already has on their own phone stay there; we cannot reach another person's device.

Your rights

If you are in the EU/UK or another region with access, correction, or deletion rights: almost everything lives on your iPhone, so you already have it, and the steps above delete it. For anything held on our servers under an account, deleting the account removes it. To ask for a copy, or if something above does not match what you see, email hello@bubbisleep.com and we will answer plainly.

Our lawful basis for the usage ping, and for the Apple Search Ads identifiers, is that we need them to run and improve Bubbi. Our lawful basis for the shared log is your consent, given by signing in on a screen that says what signing in copies, and withdrawable at any time by turning sharing off or logging out. Our lawful basis for a Support note is that you sent it so we could reply, or that we wrote first to reach you about the app.

Changes

If what leaves the device ever changes, this page will be updated before that ships, and the App Store privacy labels will change with it. The date at the top is the last revision.

Contact

hello@bubbisleep.com · Support